kubernetes-manifest
minagayid/Agents/skills/library/kubernetes-manifest/SKILL.md
Write production-ready Kubernetes manifests (Deployment, Service, probes, resources, security). Use when the user asks to write or review K8s YAML, deploy to Kubernetes, or fix a manifest.
Skill1 starsChanged 3 months ago
What's in it
- Kubernetes Manifest
- Essentials for a Deployment
- Skeleton
- Guidelines
---
name: kubernetes-manifest
description: Write production-ready Kubernetes manifests (Deployment, Service, probes, resources, security). Use when the user asks to write or review K8s YAML, deploy to Kubernetes, or fix a manifest.
---
# Kubernetes Manifest
Write manifests that are safe, observable, and production-ready.
## Essentials for a Deployment
- **Resource requests & limits** on every container (CPU/memory) — required for scheduling and stability.
- **Liveness, readiness, and startup probes** — don't route traffic before ready; restart when wedged.
- **Security context** — `runAsNonRoot`, drop capabilities, `readOnlyRootFilesystem`, no privilege escalation.
- **Config & secrets** via `ConfigMap`/`Secret` (or a secrets manager) — never bake into the image.
- **Labels** (`app.kubernetes.io/*`) and a matching `Service` selector.
- **Rollout strategy** (`RollingUpdate` with sane `maxUnavailable`/`maxSurge`) and replica count.
- **Pod disruption budget** + anti-affinity for HA workloads; `HorizontalPodAutoscaler` if load varies.
- Pin image tags to digests or immutable versions (never `:latest` in prod).
## Skeleton
```yaml
apiVersion: apps/v1
kind: Deployment
metadata: { name: web, labels: { app.kubernetes.io/name: web } }
spec:
replicas: 3
selector: { matchLabels: { app.kubernetes.io/name: web } }
template:
metadata: { labels: { app.kubernetes.io/name: web } }
spec:
securityContext: { runAsNonRoot: true }
containers:
- name: web
image: registry/web:1.4.0
ports: [{ containerPort: 8080 }]
resources:
requests: { cpu: 100m, memory: 128Mi }
limits: { cpu: 500m, memory: 256Mi }
readinessProbe: { httpGet: { path: /healthz, port: 8080 }, initialDelaySeconds: 5 }
livenessProbe: { httpGet: { path: /healthz, port: 8080 }, initialDelaySeconds: 10 }
```
## Guidelines
- Validate with `kubectl apply --dry-run=server` / `kubeconform`; lint with `kube-linter`.
- Keep environment differences in overlays (Kustomize) or values (Helm), not copy-pasted YAML.
More agent context in minagayid/Agents
25 other files this repository gives its agents.
Skill
- agent-project-scaffoldskills/agent-project-scaffold/SKILL.md
- accessibility-auditskills/library/accessibility-audit/SKILL.md
- changelog-keeperskills/library/changelog-keeper/SKILL.md
- code-review-checklistskills/library/code-review-checklist/SKILL.md
- conventional-commitsskills/library/conventional-commits/SKILL.md
- data-cleaningskills/library/data-cleaning/SKILL.md
- debugging-methodologyskills/library/debugging-methodology/SKILL.md
- dependency-auditskills/library/dependency-audit/SKILL.md
- dockerfile-authorskills/library/dockerfile-author/SKILL.md
- exploratory-data-analysisskills/library/exploratory-data-analysis/SKILL.md
- github-actions-ciskills/library/github-actions-ci/SKILL.md
- incident-postmortemskills/library/incident-postmortem/SKILL.md
- pr-descriptionskills/library/pr-description/SKILL.md
- prompt-engineeringskills/library/prompt-engineering/SKILL.md
- react-componentskills/library/react-component/SKILL.md
- readme-generatorskills/library/readme-generator/SKILL.md
- refactoringskills/library/refactoring/SKILL.md
- rest-api-designerskills/library/rest-api-designer/SKILL.md
- secure-coding-reviewskills/library/secure-coding-review/SKILL.md
- sql-optimizerskills/library/sql-optimizer/SKILL.md
- technical-writingskills/library/technical-writing/SKILL.md
- terraform-moduleskills/library/terraform-module/SKILL.md
- threat-modelskills/library/threat-model/SKILL.md
- unit-test-writerskills/library/unit-test-writer/SKILL.md
- web-performanceskills/library/web-performance/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

