You are in AUTONOMOUS MODE. Do NOT ask questions. Do NOT pause for confirmation.
Execute every phase below in sequence, making decisions based on what you find.
============================================================
PHASE 0 — INPUT
$ARGUMENTS may contain:
--helm — generate a Helm chart instead of plain manifests
--namespace <name> — target namespace (default: app name)
--replicas <n> — initial replica count (default: 2)
--ingress <domain> — configure ingress with this domain
--istio — include Istio service mesh annotations
--argocd — generate ArgoCD Application manifest
--kustomize — generate Kustomize overlays for dev/staging/prod
- A specific resource to generate:
deployment, service, ingress, hpa, configmap, secret, pdb
- If no arguments, generate the full manifest set as plain YAML
============================================================
PHASE 1 — APPLICATION ANALYSIS
Scan the project to determine Kubernetes requirements:
Container image:
- Check for existing Dockerfile — extract EXPOSE port, HEALTHCHECK, CMD
- If no Dockerfile, note that one is needed (reference
deploy/docker skill)
- Determine image name from: git remote URL, package.json name, go.mod module
Ports and protocols:
- Read application config for listen port (default: 3000/8080)
- Check for gRPC (protobuf files), WebSocket endpoints, metrics endpoint (
/metrics)
Resource requirements — estimate based on stack:
- Node.js: 128Mi-512Mi memory, 100m-500m CPU
- Go: 64Mi-256Mi memory, 50m-250m CPU
- Java/Spring: 512Mi-1Gi memory, 250m-1000m CPU
- Python: 128Mi-512Mi memory, 100m-500m CPU
Dependencies:
- Database: detected from Prisma, SQLAlchemy, GORM, etc.
- Cache: Redis/Memcached references
- Message queues: RabbitMQ, Kafka, NATS
- External services: API calls, third-party integrations
Health endpoints:
- Check for
/health, /healthz, /ready, /readyz, /live, /livez
- If none found, note to create them
Environment variables:
- Scan for
process.env., os.Getenv, os.environ references
- Categorize as: config (ConfigMap) vs secrets (Secret)
============================================================
PHASE 2 — GENERATE NAMESPACE AND RBAC
Create k8s/namespace.yml with standard Kubernetes labels:
app.kubernetes.io/name
app.kubernetes.io/managed-by: skill-deploy-k8s
Create k8s/serviceaccount.yml with matching labels.
============================================================
PHASE 3 — GENERATE CORE MANIFESTS
Create all manifests in k8s/ directory (or helm/{app-name}/templates/ if --helm).
Deployment (k8s/deployment.yml):
apiVersion: apps/v1
- Minimum 2 replicas for HA
- Rolling update strategy:
maxSurge: 1, maxUnavailable: 0
- Pod anti-affinity: prefer spreading across nodes
- Resource requests AND limits (always set both)
- Liveness probe: HTTP GET on health endpoint,
initialDelaySeconds: 15, periodSeconds: 10
- Readiness probe: HTTP GET on ready endpoint,
initialDelaySeconds: 5, periodSeconds: 5
- Startup probe (for slow-starting apps like Java):
failureThreshold: 30, periodSeconds: 10
terminationGracePeriodSeconds: 30
- Security context:
runAsNonRoot: true, runAsUser: 1001, fsGroup: 1001, seccompProfile: RuntimeDefault, allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities.drop: ["ALL"]
- Environment from ConfigMap and Secret refs
- Image pull policy:
IfNotPresent for tagged, Always for latest
Service (k8s/service.yml):
type: ClusterIP (default — use Ingress for external access)
- Target port matching container port
- Named port for service mesh compatibility
Ingress (k8s/ingress.yml, if domain provided):
networking.k8s.io/v1
- TLS with cert-manager annotation:
cert-manager.io/cluster-issuer: letsencrypt-prod
- nginx SSL redirect:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
- Path-based routing (
/ -> service)
HPA (k8s/hpa.yml):
autoscaling/v2
- Min replicas: 2, Max replicas: 10
- CPU target: 70%, Memory target: 80%
- Scale-down stabilization: 300s (prevent flapping)
- Scale-up stabilization: 60s
- Scale-down policy: max 25% reduction per 60s
PodDisruptionBudget (k8s/pdb.yml):
minAvailable: 1 for small replica counts
ConfigMap (k8s/configmap.yml):
- Non-sensitive configuration values extracted from env analysis
Secret (k8s/secret.yml):
- Placeholder secret with
stringData (not base64 in source)
- Clearly marked as "REPLACE BEFORE APPLYING"
NetworkPolicy (k8s/networkpolicy.yml):
- Default deny ingress
- Allow ingress only from ingress controller namespace
- Allow egress to database/cache services and DNS (kube-dns port 53)
============================================================
PHASE 4 — HELM CHART (if --helm)
Generate Helm chart structure under helm/{app-name}/:
Chart.yaml, values.yaml, values-dev.yaml, values-staging.yaml, values-prod.yaml
templates/: deployment, service, ingress, hpa, pdb, configmap, secret, serviceaccount, networkpolicy, _helpers.tpl, NOTES.txt
values.yaml — parameterize all environment-specific values:
image.repository, image.tag, image.pullPolicy
replicaCount, resources.requests, resources.limits
ingress.enabled, ingress.hosts, ingress.tls
autoscaling.enabled, autoscaling.minReplicas, autoscaling.maxReplicas
env as key-value map
_helpers.tpl — standard helper templates: fullname, name, chart, labels, selectorLabels
============================================================
PHASE 5 — KUSTOMIZE (if --kustomize)
Generate Kustomize structure under k8s/:
base/ with kustomization.yaml and all core manifests
overlays/dev/ — 1 replica, lower resources, debug logging
overlays/staging/ — 2 replicas, production-like resources, info logging
overlays/prod/ — 3+ replicas, full resources, warn logging, PDB enabled
============================================================
PHASE 6 — ISTIO / SERVICE MESH (if --istio)
- Pod annotation:
sidecar.istio.io/inject: "true"
- Namespace label:
istio-injection: enabled
- Generate
VirtualService for traffic routing
- Generate
DestinationRule for connection pool settings
- Generate
PeerAuthentication for mTLS (STRICT mode)
============================================================
PHASE 7 — ARGOCD (if --argocd)
Generate argocd/application.yml:
- Source from git remote with
targetRevision: HEAD
- Path to k8s/ or helm/ directory
- Sync policy: automated with prune and self-heal enabled
============================================================
SELF-HEALING VALIDATION (max 2 iterations)
After completing deployment/infrastructure changes, validate:
- Verify all generated files are syntactically valid (YAML, JSON, HCL, Dockerfile).
- Run validation commands if available (terraform validate, docker build --check, kubectl dry-run).
- Verify no secrets, credentials, or sensitive values are hardcoded.
- If validation fails, diagnose and fix the specific syntax or config error.
- Repeat up to 2 iterations.
IF STILL FAILING after 2 iterations:
- Document what failed and the exact error
- Include partial output if available
============================================================
OUTPUT
## Kubernetes Manifests Generated
### Files Created
{list all generated files with one-line descriptions}
### Resource Summary
| Resource | Name | Key Settings |
|----------|------|--------------|
| Namespace | {ns} | -- |
| Deployment | {name} | {replicas} replicas, {memory} memory |
| Service | {name} | ClusterIP, port {port} |
| Ingress | {name} | {domain}, TLS enabled |
| HPA | {name} | {min}-{max} replicas |
| PDB | {name} | minAvailable: 1 |
### Apply Commands
kubectl apply -f k8s/namespace.yml
kubectl apply -f k8s/
### Pre-Apply Checklist
- [ ] Replace placeholder secrets in k8s/secret.yml
- [ ] Verify container image is pushed to registry
- [ ] Ensure namespace exists in target cluster
- [ ] Configure cert-manager ClusterIssuer if using TLS
- [ ] Review resource limits for your workload
============================================================
NEXT STEPS
- Build and push the container image (run
deploy/docker if needed)
- Replace placeholder secrets with real values (or use external secrets operator)
- Apply manifests to a dev cluster first:
kubectl apply -f k8s/ -n {namespace}
- Verify pods are running:
kubectl get pods -n {namespace}
- Check probes:
kubectl describe pod -n {namespace}
- Consider GitOps with ArgoCD or Flux for automated deployments (use
--argocd)
============================================================
SELF-EVOLUTION TELEMETRY
After producing output, record execution metadata for the /evolve pipeline.
Check if a project memory directory exists:
- Look for the project path in
~/.claude/projects/
- If found, append to
skill-telemetry.md in that memory directory
Entry format:
### /k8s — {{YYYY-MM-DD}}
- Outcome: {{SUCCESS | PARTIAL | FAILED}}
- Self-healed: {{yes — what was healed | no}}
- Iterations used: {{N}} / {{N max}}
- Bottleneck: {{phase that struggled or "none"}}
- Suggestion: {{one-line improvement idea for /evolve, or "none"}}
Only log if the memory directory exists. Skip silently if not found.
Keep entries concise — /evolve will parse these for skill improvement signals.
============================================================
DO NOT
- Do NOT use
apiVersion: extensions/v1beta1 — use current stable APIs
- Do NOT set resource limits without requests (always set both)
- Do NOT use
latest tag in deployment manifests — use specific tags or SHA digests
- Do NOT store real secrets in YAML files committed to git
- Do NOT set
replicas in Deployment when HPA is enabled (HPA manages replicas)
- Do NOT use
hostNetwork: true or hostPort without explicit justification
- Do NOT use
privileged: true in security context
- Do NOT skip liveness/readiness probes — they are required for production
- Do NOT use
LoadBalancer service type without considering cost — prefer ClusterIP + Ingress
- Do NOT overwrite existing manifests without reading them first
- Do NOT generate manifests for services not detected in the project
1---2name: k8s3description: Generates production-grade Kubernetes manifests including Deployments with probes and security contexts, Services, Ingress with TLS, HPA, PDB, NetworkPolicy, ConfigMaps, and Secrets, with optional Helm charts, Kustomize overlays, Istio mesh, and ArgoCD GitOps.4---56You are in AUTONOMOUS MODE. Do NOT ask questions. Do NOT pause for confirmation.7Execute every phase below in sequence, making decisions based on what you find.89============================================================10PHASE 0 — INPUT11============================================================1213$ARGUMENTS may contain:14- `--helm` — generate a Helm chart instead of plain manifests15- `--namespace <name>` — target namespace (default: app name)16- `--replicas <n>` — initial replica count (default: 2)17- `--ingress <domain>` — configure ingress with this domain18- `--istio` — include Istio service mesh annotations19- `--argocd` — generate ArgoCD Application manifest20- `--kustomize` — generate Kustomize overlays for dev/staging/prod21- A specific resource to generate: `deployment`, `service`, `ingress`, `hpa`, `configmap`, `secret`, `pdb`22- If no arguments, generate the full manifest set as plain YAML2324============================================================25PHASE 1 — APPLICATION ANALYSIS26============================================================2728Scan the project to determine Kubernetes requirements:2930**Container image**:31- Check for existing Dockerfile — extract EXPOSE port, HEALTHCHECK, CMD32- If no Dockerfile, note that one is needed (reference `deploy/docker` skill)33- Determine image name from: git remote URL, package.json name, go.mod module3435**Ports and protocols**:36- Read application config for listen port (default: 3000/8080)37- Check for gRPC (protobuf files), WebSocket endpoints, metrics endpoint (`/metrics`)3839**Resource requirements** — estimate based on stack:40- Node.js: 128Mi-512Mi memory, 100m-500m CPU41- Go: 64Mi-256Mi memory, 50m-250m CPU42- Java/Spring: 512Mi-1Gi memory, 250m-1000m CPU43- Python: 128Mi-512Mi memory, 100m-500m CPU4445**Dependencies**:46- Database: detected from Prisma, SQLAlchemy, GORM, etc.47- Cache: Redis/Memcached references48- Message queues: RabbitMQ, Kafka, NATS49- External services: API calls, third-party integrations5051**Health endpoints**:52- Check for `/health`, `/healthz`, `/ready`, `/readyz`, `/live`, `/livez`53- If none found, note to create them5455**Environment variables**:56- Scan for `process.env.`, `os.Getenv`, `os.environ` references57- Categorize as: config (ConfigMap) vs secrets (Secret)5859============================================================60PHASE 2 — GENERATE NAMESPACE AND RBAC61============================================================6263Create `k8s/namespace.yml` with standard Kubernetes labels:64- `app.kubernetes.io/name`65- `app.kubernetes.io/managed-by: skill-deploy-k8s`6667Create `k8s/serviceaccount.yml` with matching labels.6869============================================================70PHASE 3 — GENERATE CORE MANIFESTS71============================================================7273Create all manifests in `k8s/` directory (or `helm/{app-name}/templates/` if `--helm`).7475**Deployment** (`k8s/deployment.yml`):76- `apiVersion: apps/v1`77- Minimum 2 replicas for HA78- Rolling update strategy: `maxSurge: 1`, `maxUnavailable: 0`79- Pod anti-affinity: prefer spreading across nodes80- Resource requests AND limits (always set both)81- Liveness probe: HTTP GET on health endpoint, `initialDelaySeconds: 15`, `periodSeconds: 10`82- Readiness probe: HTTP GET on ready endpoint, `initialDelaySeconds: 5`, `periodSeconds: 5`83- Startup probe (for slow-starting apps like Java): `failureThreshold: 30`, `periodSeconds: 10`84- `terminationGracePeriodSeconds: 30`85- Security context: `runAsNonRoot: true`, `runAsUser: 1001`, `fsGroup: 1001`, `seccompProfile: RuntimeDefault`, `allowPrivilegeEscalation: false`, `readOnlyRootFilesystem: true`, `capabilities.drop: ["ALL"]`86- Environment from ConfigMap and Secret refs87- Image pull policy: `IfNotPresent` for tagged, `Always` for `latest`8889**Service** (`k8s/service.yml`):90- `type: ClusterIP` (default — use Ingress for external access)91- Target port matching container port92- Named port for service mesh compatibility9394**Ingress** (`k8s/ingress.yml`, if domain provided):95- `networking.k8s.io/v1`96- TLS with cert-manager annotation: `cert-manager.io/cluster-issuer: letsencrypt-prod`97- nginx SSL redirect: `nginx.ingress.kubernetes.io/ssl-redirect: "true"`98- Path-based routing (`/` -> service)99100**HPA** (`k8s/hpa.yml`):101- `autoscaling/v2`102- Min replicas: 2, Max replicas: 10103- CPU target: 70%, Memory target: 80%104- Scale-down stabilization: 300s (prevent flapping)105- Scale-up stabilization: 60s106- Scale-down policy: max 25% reduction per 60s107108**PodDisruptionBudget** (`k8s/pdb.yml`):109- `minAvailable: 1` for small replica counts110111**ConfigMap** (`k8s/configmap.yml`):112- Non-sensitive configuration values extracted from env analysis113114**Secret** (`k8s/secret.yml`):115- Placeholder secret with `stringData` (not base64 in source)116- Clearly marked as "REPLACE BEFORE APPLYING"117118**NetworkPolicy** (`k8s/networkpolicy.yml`):119- Default deny ingress120- Allow ingress only from ingress controller namespace121- Allow egress to database/cache services and DNS (kube-dns port 53)122123============================================================124PHASE 4 — HELM CHART (if --helm)125============================================================126127Generate Helm chart structure under `helm/{app-name}/`:128- `Chart.yaml`, `values.yaml`, `values-dev.yaml`, `values-staging.yaml`, `values-prod.yaml`129- `templates/`: deployment, service, ingress, hpa, pdb, configmap, secret, serviceaccount, networkpolicy, `_helpers.tpl`, `NOTES.txt`130131**values.yaml** — parameterize all environment-specific values:132- `image.repository`, `image.tag`, `image.pullPolicy`133- `replicaCount`, `resources.requests`, `resources.limits`134- `ingress.enabled`, `ingress.hosts`, `ingress.tls`135- `autoscaling.enabled`, `autoscaling.minReplicas`, `autoscaling.maxReplicas`136- `env` as key-value map137138**_helpers.tpl** — standard helper templates: `fullname`, `name`, `chart`, `labels`, `selectorLabels`139140============================================================141PHASE 5 — KUSTOMIZE (if --kustomize)142============================================================143144Generate Kustomize structure under `k8s/`:145- `base/` with `kustomization.yaml` and all core manifests146- `overlays/dev/` — 1 replica, lower resources, debug logging147- `overlays/staging/` — 2 replicas, production-like resources, info logging148- `overlays/prod/` — 3+ replicas, full resources, warn logging, PDB enabled149150============================================================151PHASE 6 — ISTIO / SERVICE MESH (if --istio)152============================================================153154- Pod annotation: `sidecar.istio.io/inject: "true"`155- Namespace label: `istio-injection: enabled`156- Generate `VirtualService` for traffic routing157- Generate `DestinationRule` for connection pool settings158- Generate `PeerAuthentication` for mTLS (STRICT mode)159160============================================================161PHASE 7 — ARGOCD (if --argocd)162============================================================163164Generate `argocd/application.yml`:165- Source from git remote with `targetRevision: HEAD`166- Path to k8s/ or helm/ directory167- Sync policy: automated with prune and self-heal enabled168169170============================================================171SELF-HEALING VALIDATION (max 2 iterations)172============================================================173174After completing deployment/infrastructure changes, validate:1751761. Verify all generated files are syntactically valid (YAML, JSON, HCL, Dockerfile).1772. Run validation commands if available (terraform validate, docker build --check, kubectl dry-run).1783. Verify no secrets, credentials, or sensitive values are hardcoded.1794. If validation fails, diagnose and fix the specific syntax or config error.1805. Repeat up to 2 iterations.181182IF STILL FAILING after 2 iterations:183- Document what failed and the exact error184- Include partial output if available185186============================================================187OUTPUT188============================================================189190```191## Kubernetes Manifests Generated192193### Files Created194{list all generated files with one-line descriptions}195196### Resource Summary197| Resource | Name | Key Settings |198|----------|------|--------------|199| Namespace | {ns} | -- |200| Deployment | {name} | {replicas} replicas, {memory} memory |201| Service | {name} | ClusterIP, port {port} |202| Ingress | {name} | {domain}, TLS enabled |203| HPA | {name} | {min}-{max} replicas |204| PDB | {name} | minAvailable: 1 |205206### Apply Commands207kubectl apply -f k8s/namespace.yml208kubectl apply -f k8s/209210### Pre-Apply Checklist211- [ ] Replace placeholder secrets in k8s/secret.yml212- [ ] Verify container image is pushed to registry213- [ ] Ensure namespace exists in target cluster214- [ ] Configure cert-manager ClusterIssuer if using TLS215- [ ] Review resource limits for your workload216```217218============================================================219NEXT STEPS220============================================================2212221. Build and push the container image (run `deploy/docker` if needed)2232. Replace placeholder secrets with real values (or use external secrets operator)2243. Apply manifests to a dev cluster first: `kubectl apply -f k8s/ -n {namespace}`2254. Verify pods are running: `kubectl get pods -n {namespace}`2265. Check probes: `kubectl describe pod -n {namespace}`2276. Consider GitOps with ArgoCD or Flux for automated deployments (use `--argocd`)228229230============================================================231SELF-EVOLUTION TELEMETRY232============================================================233234After producing output, record execution metadata for the /evolve pipeline.235236Check if a project memory directory exists:237- Look for the project path in `~/.claude/projects/`238- If found, append to `skill-telemetry.md` in that memory directory239240Entry format:241```242### /k8s — {{YYYY-MM-DD}}243- Outcome: {{SUCCESS | PARTIAL | FAILED}}244- Self-healed: {{yes — what was healed | no}}245- Iterations used: {{N}} / {{N max}}246- Bottleneck: {{phase that struggled or "none"}}247- Suggestion: {{one-line improvement idea for /evolve, or "none"}}248```249250Only log if the memory directory exists. Skip silently if not found.251Keep entries concise — /evolve will parse these for skill improvement signals.252253============================================================254DO NOT255============================================================256257- Do NOT use `apiVersion: extensions/v1beta1` — use current stable APIs258- Do NOT set resource limits without requests (always set both)259- Do NOT use `latest` tag in deployment manifests — use specific tags or SHA digests260- Do NOT store real secrets in YAML files committed to git261- Do NOT set `replicas` in Deployment when HPA is enabled (HPA manages replicas)262- Do NOT use `hostNetwork: true` or `hostPort` without explicit justification263- Do NOT use `privileged: true` in security context264- Do NOT skip liveness/readiness probes — they are required for production265- Do NOT use `LoadBalancer` service type without considering cost — prefer `ClusterIP` + Ingress266- Do NOT overwrite existing manifests without reading them first267- Do NOT generate manifests for services not detected in the project