Kubernetes Manifest Generator
Expert in generating production-grade Kubernetes manifests, Helm charts, and Kustomize overlays with security and reliability built in.
Activation Triggers
Activate on: "Kubernetes manifest", "K8s YAML", "Helm chart", "HPA", "PodDisruptionBudget", "Ingress", "NetworkPolicy", "Kustomize", "deployment config", "service mesh", "resource limits"
NOT for: Docker image building → docker-multi-stage-optimizer | Cluster provisioning → terraform-module-builder | CI/CD → github-actions-pipeline-builder
Quick Start
- Define the workload — Deployment, StatefulSet, or Job based on use case
- Set resource requests/limits — always specify both CPU and memory
- Add reliability primitives — HPA, PDB, health probes, topology spread
- Secure the workload — NetworkPolicy, SecurityContext, RBAC
- Package for environments — Helm chart or Kustomize overlays for dev/staging/prod
Core Capabilities
| Domain |
Technologies |
| Workloads |
Deployment, StatefulSet, DaemonSet, Job, CronJob |
| Autoscaling |
HPA (CPU/memory/custom), VPA, KEDA event-driven |
| Networking |
Ingress (nginx/traefik), Gateway API, NetworkPolicy, Service Mesh |
| Reliability |
PDB, TopologySpreadConstraints, PriorityClasses, Pod Anti-Affinity |
| Packaging |
Helm 3, Kustomize, Timoni (CUE-based) |
Architecture Patterns
Production Deployment Template
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .name }}
labels:
app.kubernetes.io/name: {{ .name }}
app.kubernetes.io/version: {{ .version }}
spec:
replicas: 3
strategy:
rollingUpdate:
maxSurge: 1
maxUnavailable: 0 # Zero-downtime deploys
selector:
matchLabels:
app.kubernetes.io/name: {{ .name }}
template:
spec:
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: {{ .name }}
image: {{ .image }}
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
livenessProbe:
httpGet: { path: /healthz, port: 8080 }
initialDelaySeconds: 10
readinessProbe:
httpGet: { path: /readyz, port: 8080 }
initialDelaySeconds: 5
topologySpreadConstraints:
- maxSkew: 1
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: DoNotSchedule
HPA + PDB Pairing
HPA ensures enough pods exist for load:
minReplicas: 3 → maxReplicas: 20
├─ CPU target: 70%
└─ Custom metric: requests_per_second target 1000
PDB ensures enough pods survive disruptions:
minAvailable: 2 (or maxUnavailable: 1)
└─ Guarantees service during node drains, upgrades
Gateway API (replaces Ingress, K8s 1.31+)
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: api-routes
spec:
parentRefs:
- name: main-gateway
rules:
- matches:
- path: { type: PathPrefix, value: /api/v1 }
backendRefs:
- name: api-service
port: 8080
weight: 90
- name: api-service-canary
port: 8080
weight: 10 # 10% canary traffic
Anti-Patterns
- No resource limits — pods consume unbounded resources and starve neighbors. Always set both requests and limits.
- Missing health probes — K8s cannot detect unhealthy pods. Define both liveness (restart stuck pods) and readiness (stop routing to unready pods).
- PDB without HPA — PDB alone does not scale. Pair with HPA so disruptions do not reduce capacity below minimum.
- Privileged containers —
privileged: true grants host-level access. Use securityContext.runAsNonRoot: true and drop all capabilities.
- Hardcoded image tags —
:latest in production is non-reproducible. Use digest or semver tags.
Quality Checklist
[ ] All containers have resource requests AND limits
[ ] Liveness and readiness probes defined
[ ] SecurityContext sets runAsNonRoot: true
[ ] NetworkPolicy restricts ingress/egress
[ ] PodDisruptionBudget defined for stateless workloads
[ ] HPA configured with appropriate min/max replicas
[ ] TopologySpreadConstraints for multi-zone resilience
[ ] Image tags pinned (no :latest in prod)
[ ] Labels follow app.kubernetes.io conventions
[ ] Secrets mounted as volumes, not environment variables
[ ] Helm chart passes `helm lint` and `helm template` validation
[ ] Kustomize overlays tested for dev, staging, and prod
1---2name: kubernetes-manifest-generator3description: Kubernetes manifest and Helm chart generator for production workloads. Activate on: K8s config, Deployment YAML, HPA autoscaling, PodDisruptionBudget, Ingress rules, NetworkPolicy, Helm chart, Kustomize. NOT for: Docker image building (use docker-multi-stage-optimizer), IaC provisioning of clusters (use terraform-module-builder), CI/CD pipeline config (use github-actions-pipeline-builder).4license: Apache-2.05---67# Kubernetes Manifest Generator89Expert in generating production-grade Kubernetes manifests, Helm charts, and Kustomize overlays with security and reliability built in.1011## Activation Triggers1213**Activate on:** "Kubernetes manifest", "K8s YAML", "Helm chart", "HPA", "PodDisruptionBudget", "Ingress", "NetworkPolicy", "Kustomize", "deployment config", "service mesh", "resource limits"1415**NOT for:** Docker image building → `docker-multi-stage-optimizer` | Cluster provisioning → `terraform-module-builder` | CI/CD → `github-actions-pipeline-builder`1617## Quick Start18191. **Define the workload** — Deployment, StatefulSet, or Job based on use case202. **Set resource requests/limits** — always specify both CPU and memory213. **Add reliability primitives** — HPA, PDB, health probes, topology spread224. **Secure the workload** — NetworkPolicy, SecurityContext, RBAC235. **Package for environments** — Helm chart or Kustomize overlays for dev/staging/prod2425## Core Capabilities2627| Domain | Technologies |28|--------|-------------|29| **Workloads** | Deployment, StatefulSet, DaemonSet, Job, CronJob |30| **Autoscaling** | HPA (CPU/memory/custom), VPA, KEDA event-driven |31| **Networking** | Ingress (nginx/traefik), Gateway API, NetworkPolicy, Service Mesh |32| **Reliability** | PDB, TopologySpreadConstraints, PriorityClasses, Pod Anti-Affinity |33| **Packaging** | Helm 3, Kustomize, Timoni (CUE-based) |3435## Architecture Patterns3637### Production Deployment Template3839```yaml40apiVersion: apps/v141kind: Deployment42metadata:43 name: {{ .name }}44 labels:45 app.kubernetes.io/name: {{ .name }}46 app.kubernetes.io/version: {{ .version }}47spec:48 replicas: 349 strategy:50 rollingUpdate:51 maxSurge: 152 maxUnavailable: 0 # Zero-downtime deploys53 selector:54 matchLabels:55 app.kubernetes.io/name: {{ .name }}56 template:57 spec:58 securityContext:59 runAsNonRoot: true60 seccompProfile:61 type: RuntimeDefault62 containers:63 - name: {{ .name }}64 image: {{ .image }}65 resources:66 requests:67 cpu: 100m68 memory: 128Mi69 limits:70 cpu: 500m71 memory: 512Mi72 livenessProbe:73 httpGet: { path: /healthz, port: 8080 }74 initialDelaySeconds: 1075 readinessProbe:76 httpGet: { path: /readyz, port: 8080 }77 initialDelaySeconds: 578 topologySpreadConstraints:79 - maxSkew: 180 topologyKey: topology.kubernetes.io/zone81 whenUnsatisfiable: DoNotSchedule82```8384### HPA + PDB Pairing8586```87HPA ensures enough pods exist for load:88 minReplicas: 3 → maxReplicas: 2089 ├─ CPU target: 70%90 └─ Custom metric: requests_per_second target 10009192PDB ensures enough pods survive disruptions:93 minAvailable: 2 (or maxUnavailable: 1)94 └─ Guarantees service during node drains, upgrades95```9697### Gateway API (replaces Ingress, K8s 1.31+)9899```yaml100apiVersion: gateway.networking.k8s.io/v1101kind: HTTPRoute102metadata:103 name: api-routes104spec:105 parentRefs:106 - name: main-gateway107 rules:108 - matches:109 - path: { type: PathPrefix, value: /api/v1 }110 backendRefs:111 - name: api-service112 port: 8080113 weight: 90114 - name: api-service-canary115 port: 8080116 weight: 10 # 10% canary traffic117```118119## Anti-Patterns1201211. **No resource limits** — pods consume unbounded resources and starve neighbors. Always set both requests and limits.1222. **Missing health probes** — K8s cannot detect unhealthy pods. Define both liveness (restart stuck pods) and readiness (stop routing to unready pods).1233. **PDB without HPA** — PDB alone does not scale. Pair with HPA so disruptions do not reduce capacity below minimum.1244. **Privileged containers** — `privileged: true` grants host-level access. Use `securityContext.runAsNonRoot: true` and drop all capabilities.1255. **Hardcoded image tags** — `:latest` in production is non-reproducible. Use digest or semver tags.126127## Quality Checklist128129```130[ ] All containers have resource requests AND limits131[ ] Liveness and readiness probes defined132[ ] SecurityContext sets runAsNonRoot: true133[ ] NetworkPolicy restricts ingress/egress134[ ] PodDisruptionBudget defined for stateless workloads135[ ] HPA configured with appropriate min/max replicas136[ ] TopologySpreadConstraints for multi-zone resilience137[ ] Image tags pinned (no :latest in prod)138[ ] Labels follow app.kubernetes.io conventions139[ ] Secrets mounted as volumes, not environment variables140[ ] Helm chart passes `helm lint` and `helm template` validation141[ ] Kustomize overlays tested for dev, staging, and prod142```