GKE Productionize Skill
Orchestrates comprehensive production readiness reviews for GKE clusters and workloads across scalability, security, reliability, observability, backup/DR, and cost optimization.
Discovery Phase
# Cluster discovery
gcloud container clusters describe {cluster_name} --location {location} --project {project}
# Workload discovery
kubectl get deployment {app_name} -n {namespace} -o yaml
kubectl get hpa -n {namespace}
kubectl get pdb -n {namespace}
kubectl get networkpolicy -n {namespace}
Production Readiness Areas
| Area |
Action |
Key Skill |
| Scalability |
Configure HPA, VPA, resource limits |
gke-workload-scaling |
| Observability |
Cloud Logging, Monitoring, Managed Prometheus |
gke-observability |
| Reliability |
Regional clusters, PDBs, health probes |
gke-reliability |
| Security |
Workload Identity, Network Policies, Shielded Nodes |
gke-platform-security |
| Backup/DR |
Backup for GKE, restore procedures |
gke-backup-dr |
| Cost |
Rightsizing, quotas, Spot VMs |
gke-cost-optimization |
Scoring
After assessment, provide RAG (Red/Amber/Green) status for each area with an overall readiness score.
Common Pitfalls
- Skipping discovery: Always run discovery commands before making recommendations
- Missing security basics: Always check Pod Security Standards, dedicated service accounts, and NetworkPolicies
- No backup plan: Ensure Backup for GKE is configured for stateful workloads
- Single-zone clusters: Production clusters should be regional (multi-zone)
Verification Checklist
1---2name: gke-productionize3description: Use when assessing and preparing GKE clusters and workloads for production readiness.4---56# GKE Productionize Skill78Orchestrates comprehensive production readiness reviews for GKE clusters and workloads across scalability, security, reliability, observability, backup/DR, and cost optimization.910## Discovery Phase1112```bash13# Cluster discovery14gcloud container clusters describe {cluster_name} --location {location} --project {project}1516# Workload discovery17kubectl get deployment {app_name} -n {namespace} -o yaml18kubectl get hpa -n {namespace}19kubectl get pdb -n {namespace}20kubectl get networkpolicy -n {namespace}21```2223## Production Readiness Areas2425| Area | Action | Key Skill |26|------|--------|-----------|27| Scalability | Configure HPA, VPA, resource limits | `gke-workload-scaling` |28| Observability | Cloud Logging, Monitoring, Managed Prometheus | `gke-observability` |29| Reliability | Regional clusters, PDBs, health probes | `gke-reliability` |30| Security | Workload Identity, Network Policies, Shielded Nodes | `gke-platform-security` |31| Backup/DR | Backup for GKE, restore procedures | `gke-backup-dr` |32| Cost | Rightsizing, quotas, Spot VMs | `gke-cost-optimization` |3334## Scoring3536After assessment, provide RAG (Red/Amber/Green) status for each area with an overall readiness score.3738## Common Pitfalls3940- **Skipping discovery**: Always run discovery commands before making recommendations41- **Missing security basics**: Always check Pod Security Standards, dedicated service accounts, and NetworkPolicies42- **No backup plan**: Ensure Backup for GKE is configured for stateful workloads43- **Single-zone clusters**: Production clusters should be regional (multi-zone)4445## Verification Checklist4647- [ ] Cluster details gathered (Autopilot vs Standard, release channel)48- [ ] Workload resource requests/limits configured49- [ ] HPA and PDB configured for critical workloads50- [ ] Health probes (liveness, readiness, startup) configured51- [ ] Network policies enforce least-privilege52- [ ] Workload Identity configured for GCP API access53- [ ] Backup for GKE configured