You are in AUTONOMOUS MODE. Do NOT ask questions. Do NOT pause for confirmation.
Execute every phase below in sequence, making decisions based on what you find.
============================================================
PHASE 0 — INPUT
$ARGUMENTS may contain:
--helm — generate a Helm chart instead of plain manifests
--namespace <name> — target namespace (default: app name)
--replicas <n> — initial replica count (default: 2)
--ingress <domain> — configure ingress with this domain
--istio — include Istio service mesh annotations
--argocd — generate ArgoCD Application manifest
--kustomize — generate Kustomize overlays for dev/staging/prod
- A specific resource to generate:
deployment, service, ingress, hpa, configmap, secret, pdb
- If no arguments, generate the full manifest set as plain YAML
============================================================
PHASE 1 — APPLICATION ANALYSIS
Scan the project to determine Kubernetes requirements:
Container image:
- Check for existing Dockerfile — extract EXPOSE port, HEALTHCHECK, CMD
- If no Dockerfile, note that one is needed (reference
deploy/docker skill)
- Determine image name from: git remote URL, package.json name, go.mod module
Ports and protocols:
- Read application config for listen port (default: 3000/8080)
- Check for gRPC (protobuf files), WebSocket endpoints, metrics endpoint (
/metrics)
Resource requirements — estimate based on stack:
- Node.js: 128Mi-512Mi memory, 100m-500m CPU
- Go: 64Mi-256Mi memory, 50m-250m CPU
- Java/Spring: 512Mi-1Gi memory, 250m-1000m CPU
- Python: 128Mi-512Mi memory, 100m-500m CPU
Dependencies:
- Database: detected from Prisma, SQLAlchemy, GORM, etc.
- Cache: Redis/Memcached references
- Message queues: RabbitMQ, Kafka, NATS
- External services: API calls, third-party integrations
Health endpoints:
- Check for
/health, /healthz, /ready, /readyz, /live, /livez
- If none found, note to create them
Environment variables:
- Scan for
process.env., os.Getenv, os.environ references
- Categorize as: config (ConfigMap) vs secrets (Secret)
============================================================
PHASE 2 — GENERATE NAMESPACE AND RBAC
Create k8s/namespace.yml with standard Kubernetes labels:
app.kubernetes.io/name
app.kubernetes.io/managed-by: skill-deploy-k8s
Create k8s/serviceaccount.yml with matching labels.
============================================================
PHASE 3 — GENERATE CORE MANIFESTS
Create all manifests in k8s/ directory (or helm/{app-name}/templates/ if --helm).
Deployment (k8s/deployment.yml):
apiVersion: apps/v1
- Minimum 2 replicas for HA
- Rolling update strategy:
maxSurge: 1, maxUnavailable: 0
- Pod anti-affinity: prefer spreading across nodes
- Resource requests AND limits (always set both)
- Liveness probe: HTTP GET on health endpoint,
initialDelaySeconds: 15, periodSeconds: 10
- Readiness probe: HTTP GET on ready endpoint,
initialDelaySeconds: 5, periodSeconds: 5
- Startup probe (for slow-starting apps like Java):
failureThreshold: 30, periodSeconds: 10
terminationGracePeriodSeconds: 30
- Security context:
runAsNonRoot: true, runAsUser: 1001, fsGroup: 1001, seccompProfile: RuntimeDefault, allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities.drop: ["ALL"]
- Environment from ConfigMap and Secret refs
- Image pull policy:
IfNotPresent for tagged, Always for latest
Service (k8s/service.yml):
type: ClusterIP (default — use Ingress for external access)
- Target port matching container port
- Named port for service mesh compatibility
Ingress (k8s/ingress.yml, if domain provided):
networking.k8s.io/v1
- TLS with cert-manager annotation:
cert-manager.io/cluster-issuer: letsencrypt-prod
- nginx SSL redirect:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
- Path-based routing (
/ -> service)
HPA (k8s/hpa.yml):
autoscaling/v2
- Min replicas: 2, Max replicas: 10
- CPU target: 70%, Memory target: 80%
- Scale-down stabilization: 300s (prevent flapping)
- Scale-up stabilization: 60s
- Scale-down policy: max 25% reduction per 60s
PodDisruptionBudget (k8s/pdb.yml):
minAvailable: 1 for small replica counts
ConfigMap (k8s/configmap.yml):
- Non-sensitive configuration values extracted from env analysis
Secret (k8s/secret.yml):
- Placeholder secret with
stringData (not base64 in source)
- Clearly marked as "REPLACE BEFORE APPLYING"
NetworkPolicy (k8s/networkpolicy.yml):
- Default deny ingress
- Allow ingress only from ingress controller namespace
- Allow egress to database/cache services and DNS (kube-dns port 53)
============================================================
PHASE 4 — HELM CHART (if --helm)
Generate Helm chart structure under helm/{app-name}/:
Chart.yaml, values.yaml, values-dev.yaml, values-staging.yaml, values-prod.yaml
templates/: deployment, service, ingress, hpa, pdb, configmap, secret, serviceaccount, networkpolicy, _helpers.tpl, NOTES.txt
values.yaml — parameterize all environment-specific values:
image.repository, image.tag, image.pullPolicy
replicaCount, resources.requests, resources.limits
ingress.enabled, ingress.hosts, ingress.tls
autoscaling.enabled, autoscaling.minReplicas, autoscaling.maxReplicas
env as key-value map
_helpers.tpl — standard helper templates: fullname, name, chart, labels, selectorLabels
============================================================
PHASE 5 — KUSTOMIZE (if --kustomize)
Generate Kustomize structure under k8s/:
base/ with kustomization.yaml and all core manifests
overlays/dev/ — 1 replica, lower resources, debug logging
overlays/staging/ — 2 replicas, production-like resources, info logging
overlays/prod/ — 3+ replicas, full resources, warn logging, PDB enabled
============================================================
PHASE 6 — ISTIO / SERVICE MESH (if --istio)
- Pod annotation:
sidecar.istio.io/inject: "true"
- Namespace label:
istio-injection: enabled
- Generate
VirtualService for traffic routing
- Generate
DestinationRule for connection pool settings
- Generate
PeerAuthentication for mTLS (STRICT mode)
============================================================
PHASE 7 — ARGOCD (if --argocd)
Generate argocd/application.yml:
- Source from git remote with
targetRevision: HEAD
- Path to k8s/ or helm/ directory
- Sync policy: automated with prune and self-heal enabled
============================================================
SELF-HEALING VALIDATION (max 2 iterations)
After completing deployment/infrastructure changes, validate:
- Verify all generated files are syntactically valid (YAML, JSON, HCL, Dockerfile).
- Run validation commands if available (terraform validate, docker build --check, kubectl dry-run).
- Verify no secrets, credentials, or sensitive values are hardcoded.
- If validation fails, diagnose and fix the specific syntax or config error.
- Repeat up to 2 iterations.
IF STILL FAILING after 2 iterations:
- Document what failed and the exact error
- Include partial output if available
============================================================
OUTPUT
## Kubernetes Manifests Generated
### Files Created
{list all generated files with one-line descriptions}
### Resource Summary
| Resource | Name | Key Settings |
|----------|------|--------------|
| Namespace | {ns} | -- |
| Deployment | {name} | {replicas} replicas, {memory} memory |
| Service | {name} | ClusterIP, port {port} |
| Ingress | {name} | {domain}, TLS enabled |
| HPA | {name} | {min}-{max} replicas |
| PDB | {name} | minAvailable: 1 |
### Apply Commands
kubectl apply -f k8s/namespace.yml
kubectl apply -f k8s/
### Pre-Apply Checklist
- [ ] Replace placeholder secrets in k8s/secret.yml
- [ ] Verify container image is pushed to registry
- [ ] Ensure namespace exists in target cluster
- [ ] Configure cert-manager ClusterIssuer if using TLS
- [ ] Review resource limits for your workload
============================================================
NEXT STEPS
- Build and push the container image (run
deploy/docker if needed)
- Replace placeholder secrets with real values (or use external secrets operator)
- Apply manifests to a dev cluster first:
kubectl apply -f k8s/ -n {namespace}
- Verify pods are running:
kubectl get pods -n {namespace}
- Check probes:
kubectl describe pod -n {namespace}
- Consider GitOps with ArgoCD or Flux for automated deployments (use
--argocd)
============================================================
SELF-EVOLUTION TELEMETRY
After producing output, record execution metadata for the /evolve pipeline.
Check if a project memory directory exists:
- Look for the project path in
~/.claude/projects/
- If found, append to
skill-telemetry.md in that memory directory
Entry format:
### /k8s — {{YYYY-MM-DD}}
- Outcome: {{SUCCESS | PARTIAL | FAILED}}
- Self-healed: {{yes — what was healed | no}}
- Iterations used: {{N}} / {{N max}}
- Bottleneck: {{phase that struggled or "none"}}
- Suggestion: {{one-line improvement idea for /evolve, or "none"}}
Only log if the memory directory exists. Skip silently if not found.
Keep entries concise — /evolve will parse these for skill improvement signals.
============================================================
DO NOT
- Do NOT use
apiVersion: extensions/v1beta1 — use current stable APIs
- Do NOT set resource limits without requests (always set both)
- Do NOT use
latest tag in deployment manifests — use specific tags or SHA digests
- Do NOT store real secrets in YAML files committed to git
- Do NOT set
replicas in Deployment when HPA is enabled (HPA manages replicas)
- Do NOT use
hostNetwork: true or hostPort without explicit justification
- Do NOT use
privileged: true in security context
- Do NOT skip liveness/readiness probes — they are required for production
- Do NOT use
LoadBalancer service type without considering cost — prefer ClusterIP + Ingress
- Do NOT overwrite existing manifests without reading them first
- Do NOT generate manifests for services not detected in the project
1---2name: k8s3description: Generate production-grade Kubernetes manifests — Deployments with probes and security contexts, Services, Ingress with TLS, HPA, PDB, NetworkPolicy, ConfigMaps, Secrets — with optional Helm charts, Kustomize overlays, Istio mesh, and ArgoCD GitOps4---56You are in AUTONOMOUS MODE. Do NOT ask questions. Do NOT pause for confirmation.7Execute every phase below in sequence, making decisions based on what you find.89============================================================10PHASE 0 — INPUT11============================================================1213$ARGUMENTS may contain:14- `--helm` — generate a Helm chart instead of plain manifests15- `--namespace <name>` — target namespace (default: app name)16- `--replicas <n>` — initial replica count (default: 2)17- `--ingress <domain>` — configure ingress with this domain18- `--istio` — include Istio service mesh annotations19- `--argocd` — generate ArgoCD Application manifest20- `--kustomize` — generate Kustomize overlays for dev/staging/prod21- A specific resource to generate: `deployment`, `service`, `ingress`, `hpa`, `configmap`, `secret`, `pdb`22- If no arguments, generate the full manifest set as plain YAML2324============================================================25PHASE 1 — APPLICATION ANALYSIS26============================================================2728Scan the project to determine Kubernetes requirements:2930**Container image**:31- Check for existing Dockerfile — extract EXPOSE port, HEALTHCHECK, CMD32- If no Dockerfile, note that one is needed (reference `deploy/docker` skill)33- Determine image name from: git remote URL, package.json name, go.mod module3435**Ports and protocols**:36- Read application config for listen port (default: 3000/8080)37- Check for gRPC (protobuf files), WebSocket endpoints, metrics endpoint (`/metrics`)3839**Resource requirements** — estimate based on stack:40- Node.js: 128Mi-512Mi memory, 100m-500m CPU41- Go: 64Mi-256Mi memory, 50m-250m CPU42- Java/Spring: 512Mi-1Gi memory, 250m-1000m CPU43- Python: 128Mi-512Mi memory, 100m-500m CPU4445**Dependencies**:46- Database: detected from Prisma, SQLAlchemy, GORM, etc.47- Cache: Redis/Memcached references48- Message queues: RabbitMQ, Kafka, NATS49- External services: API calls, third-party integrations5051**Health endpoints**:52- Check for `/health`, `/healthz`, `/ready`, `/readyz`, `/live`, `/livez`53- If none found, note to create them5455**Environment variables**:56- Scan for `process.env.`, `os.Getenv`, `os.environ` references57- Categorize as: config (ConfigMap) vs secrets (Secret)5859============================================================60PHASE 2 — GENERATE NAMESPACE AND RBAC61============================================================6263Create `k8s/namespace.yml` with standard Kubernetes labels:64- `app.kubernetes.io/name`65- `app.kubernetes.io/managed-by: skill-deploy-k8s`6667Create `k8s/serviceaccount.yml` with matching labels.6869============================================================70PHASE 3 — GENERATE CORE MANIFESTS71============================================================7273Create all manifests in `k8s/` directory (or `helm/{app-name}/templates/` if `--helm`).7475**Deployment** (`k8s/deployment.yml`):76- `apiVersion: apps/v1`77- Minimum 2 replicas for HA78- Rolling update strategy: `maxSurge: 1`, `maxUnavailable: 0`79- Pod anti-affinity: prefer spreading across nodes80- Resource requests AND limits (always set both)81- Liveness probe: HTTP GET on health endpoint, `initialDelaySeconds: 15`, `periodSeconds: 10`82- Readiness probe: HTTP GET on ready endpoint, `initialDelaySeconds: 5`, `periodSeconds: 5`83- Startup probe (for slow-starting apps like Java): `failureThreshold: 30`, `periodSeconds: 10`84- `terminationGracePeriodSeconds: 30`85- Security context: `runAsNonRoot: true`, `runAsUser: 1001`, `fsGroup: 1001`, `seccompProfile: RuntimeDefault`, `allowPrivilegeEscalation: false`, `readOnlyRootFilesystem: true`, `capabilities.drop: ["ALL"]`86- Environment from ConfigMap and Secret refs87- Image pull policy: `IfNotPresent` for tagged, `Always` for `latest`8889**Service** (`k8s/service.yml`):90- `type: ClusterIP` (default — use Ingress for external access)91- Target port matching container port92- Named port for service mesh compatibility9394**Ingress** (`k8s/ingress.yml`, if domain provided):95- `networking.k8s.io/v1`96- TLS with cert-manager annotation: `cert-manager.io/cluster-issuer: letsencrypt-prod`97- nginx SSL redirect: `nginx.ingress.kubernetes.io/ssl-redirect: "true"`98- Path-based routing (`/` -> service)99100**HPA** (`k8s/hpa.yml`):101- `autoscaling/v2`102- Min replicas: 2, Max replicas: 10103- CPU target: 70%, Memory target: 80%104- Scale-down stabilization: 300s (prevent flapping)105- Scale-up stabilization: 60s106- Scale-down policy: max 25% reduction per 60s107108**PodDisruptionBudget** (`k8s/pdb.yml`):109- `minAvailable: 1` for small replica counts110111**ConfigMap** (`k8s/configmap.yml`):112- Non-sensitive configuration values extracted from env analysis113114**Secret** (`k8s/secret.yml`):115- Placeholder secret with `stringData` (not base64 in source)116- Clearly marked as "REPLACE BEFORE APPLYING"117118**NetworkPolicy** (`k8s/networkpolicy.yml`):119- Default deny ingress120- Allow ingress only from ingress controller namespace121- Allow egress to database/cache services and DNS (kube-dns port 53)122123============================================================124PHASE 4 — HELM CHART (if --helm)125============================================================126127Generate Helm chart structure under `helm/{app-name}/`:128- `Chart.yaml`, `values.yaml`, `values-dev.yaml`, `values-staging.yaml`, `values-prod.yaml`129- `templates/`: deployment, service, ingress, hpa, pdb, configmap, secret, serviceaccount, networkpolicy, `_helpers.tpl`, `NOTES.txt`130131**values.yaml** — parameterize all environment-specific values:132- `image.repository`, `image.tag`, `image.pullPolicy`133- `replicaCount`, `resources.requests`, `resources.limits`134- `ingress.enabled`, `ingress.hosts`, `ingress.tls`135- `autoscaling.enabled`, `autoscaling.minReplicas`, `autoscaling.maxReplicas`136- `env` as key-value map137138**_helpers.tpl** — standard helper templates: `fullname`, `name`, `chart`, `labels`, `selectorLabels`139140============================================================141PHASE 5 — KUSTOMIZE (if --kustomize)142============================================================143144Generate Kustomize structure under `k8s/`:145- `base/` with `kustomization.yaml` and all core manifests146- `overlays/dev/` — 1 replica, lower resources, debug logging147- `overlays/staging/` — 2 replicas, production-like resources, info logging148- `overlays/prod/` — 3+ replicas, full resources, warn logging, PDB enabled149150============================================================151PHASE 6 — ISTIO / SERVICE MESH (if --istio)152============================================================153154- Pod annotation: `sidecar.istio.io/inject: "true"`155- Namespace label: `istio-injection: enabled`156- Generate `VirtualService` for traffic routing157- Generate `DestinationRule` for connection pool settings158- Generate `PeerAuthentication` for mTLS (STRICT mode)159160============================================================161PHASE 7 — ARGOCD (if --argocd)162============================================================163164Generate `argocd/application.yml`:165- Source from git remote with `targetRevision: HEAD`166- Path to k8s/ or helm/ directory167- Sync policy: automated with prune and self-heal enabled168169170============================================================171SELF-HEALING VALIDATION (max 2 iterations)172============================================================173174After completing deployment/infrastructure changes, validate:1751761. Verify all generated files are syntactically valid (YAML, JSON, HCL, Dockerfile).1772. Run validation commands if available (terraform validate, docker build --check, kubectl dry-run).1783. Verify no secrets, credentials, or sensitive values are hardcoded.1794. If validation fails, diagnose and fix the specific syntax or config error.1805. Repeat up to 2 iterations.181182IF STILL FAILING after 2 iterations:183- Document what failed and the exact error184- Include partial output if available185186============================================================187OUTPUT188============================================================189190```191## Kubernetes Manifests Generated192193### Files Created194{list all generated files with one-line descriptions}195196### Resource Summary197| Resource | Name | Key Settings |198|----------|------|--------------|199| Namespace | {ns} | -- |200| Deployment | {name} | {replicas} replicas, {memory} memory |201| Service | {name} | ClusterIP, port {port} |202| Ingress | {name} | {domain}, TLS enabled |203| HPA | {name} | {min}-{max} replicas |204| PDB | {name} | minAvailable: 1 |205206### Apply Commands207kubectl apply -f k8s/namespace.yml208kubectl apply -f k8s/209210### Pre-Apply Checklist211- [ ] Replace placeholder secrets in k8s/secret.yml212- [ ] Verify container image is pushed to registry213- [ ] Ensure namespace exists in target cluster214- [ ] Configure cert-manager ClusterIssuer if using TLS215- [ ] Review resource limits for your workload216```217218============================================================219NEXT STEPS220============================================================2212221. Build and push the container image (run `deploy/docker` if needed)2232. Replace placeholder secrets with real values (or use external secrets operator)2243. Apply manifests to a dev cluster first: `kubectl apply -f k8s/ -n {namespace}`2254. Verify pods are running: `kubectl get pods -n {namespace}`2265. Check probes: `kubectl describe pod -n {namespace}`2276. Consider GitOps with ArgoCD or Flux for automated deployments (use `--argocd`)228229230============================================================231SELF-EVOLUTION TELEMETRY232============================================================233234After producing output, record execution metadata for the /evolve pipeline.235236Check if a project memory directory exists:237- Look for the project path in `~/.claude/projects/`238- If found, append to `skill-telemetry.md` in that memory directory239240Entry format:241```242### /k8s — {{YYYY-MM-DD}}243- Outcome: {{SUCCESS | PARTIAL | FAILED}}244- Self-healed: {{yes — what was healed | no}}245- Iterations used: {{N}} / {{N max}}246- Bottleneck: {{phase that struggled or "none"}}247- Suggestion: {{one-line improvement idea for /evolve, or "none"}}248```249250Only log if the memory directory exists. Skip silently if not found.251Keep entries concise — /evolve will parse these for skill improvement signals.252253============================================================254DO NOT255============================================================256257- Do NOT use `apiVersion: extensions/v1beta1` — use current stable APIs258- Do NOT set resource limits without requests (always set both)259- Do NOT use `latest` tag in deployment manifests — use specific tags or SHA digests260- Do NOT store real secrets in YAML files committed to git261- Do NOT set `replicas` in Deployment when HPA is enabled (HPA manages replicas)262- Do NOT use `hostNetwork: true` or `hostPort` without explicit justification263- Do NOT use `privileged: true` in security context264- Do NOT skip liveness/readiness probes — they are required for production265- Do NOT use `LoadBalancer` service type without considering cost — prefer `ClusterIP` + Ingress266- Do NOT overwrite existing manifests without reading them first267- Do NOT generate manifests for services not detected in the project