{"slug":"infra-containers-kubernetes","title":"infra-containers-kubernetes","summary":"Kubernetes manifests, Helm charts, Kustomize overlays, and resource patterns","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-29T15:28:07.992224Z","repo":{"url":"https://github.com/agents-inc/skills","stars":24,"forks":8,"license":"MIT","updatedAt":"2026-09-07T17:50:55Z"},"bodyHtml":"<hr>\n<h2>name: infra-containers-kubernetes\ndescription: Kubernetes manifests, Helm charts, Kustomize overlays, and resource patterns</h2>\n<h1>Kubernetes Patterns</h1>\n<blockquote>\n<p><strong>Quick Guide:</strong> Declarative YAML manifests for Kubernetes workloads. Use <code>apps/v1</code> Deployments with resource requests/limits, health probes, and Pod Security Standards (restricted profile). Helm for templated multi-environment releases. Kustomize for patch-based overlays without templating. Always set <code>securityContext</code> (runAsNonRoot, drop ALL capabilities, readOnlyRootFilesystem), resource requests/limits on every container, and liveness/readiness probes on every pod.</p>\n</blockquote>\n<hr>\n<p>&lt;critical_requirements&gt;</p>\n<h2>CRITICAL: Before Using This Skill</h2>\n<blockquote>\n<p><strong>All code must follow project conventions in CLAUDE.md</strong> (kebab-case, named exports, import ordering, <code>import type</code>, named constants)</p>\n</blockquote>\n<p><strong>(You MUST set resource requests AND limits on every container -- pods without requests are unschedulable under resource pressure and pods without limits can OOM-kill neighbors)</strong></p>\n<p><strong>(You MUST set securityContext with runAsNonRoot: true, allowPrivilegeEscalation: false, drop ALL capabilities, and readOnlyRootFilesystem: true on every container)</strong></p>\n<p><strong>(You MUST define both liveness and readiness probes -- without readiness probes, traffic reaches unready pods; without liveness probes, hung processes are never restarted)</strong></p>\n<p><strong>(You MUST use the current stable apiVersion for each resource -- apps/v1 for Deployments, networking.k8s.io/v1 for Ingress, autoscaling/v2 for HPA, policy/v1 for PDB)</strong></p>\n<p>&lt;/critical_requirements&gt;</p>\n<hr>\n<h2>Examples</h2>\n<ul>\n<li><a href=\"examples/core.md\">Core Manifests</a> - Deployments, Services, Ingress, ConfigMaps, Secrets, Namespaces</li>\n<li><a href=\"examples/helm.md\">Helm Charts</a> - Chart structure, values.yaml, templates, helpers, dependencies</li>\n<li><a href=\"examples/operations.md\">Operations</a> - HPA scaling, RBAC, health checks, resource limits, PDB, NetworkPolicy</li>\n<li><a href=\"reference.md\">Quick Reference</a> - API versions, kubectl commands, label conventions, decision frameworks</li>\n</ul>\n<hr>\n<p><strong>Auto-detection:</strong> Kubernetes, kubectl, k8s, Deployment, Service, Ingress, ConfigMap, Secret, HPA, HorizontalPodAutoscaler, Helm, helm chart, Kustomize, kustomization, RBAC, Role, ClusterRole, PodDisruptionBudget, NetworkPolicy, Pod, StatefulSet, DaemonSet, CronJob, Job, PersistentVolumeClaim, apiVersion, kind, metadata, spec</p>\n<p><strong>When to use:</strong></p>\n<ul>\n<li>Writing Kubernetes Deployment, Service, Ingress, or other resource manifests</li>\n<li>Creating Helm charts for templated multi-environment releases</li>\n<li>Building Kustomize overlays for environment-specific patches</li>\n<li>Configuring RBAC roles and bindings for least-privilege access</li>\n<li>Setting up HPA autoscaling, PDB, or resource limits</li>\n<li>Defining health checks (liveness, readiness, startup probes)</li>\n<li>Managing ConfigMaps, Secrets, and environment configuration</li>\n<li>Writing NetworkPolicy for pod-to-pod traffic control</li>\n</ul>\n<p><strong>When NOT to use:</strong></p>\n<ul>\n<li>Container image building (use a containerization skill)</li>\n<li>CI/CD pipeline definitions (use a CI/CD skill)</li>\n<li>Infrastructure provisioning (use an IaC tool)</li>\n<li>Service mesh configuration beyond basic Kubernetes resources</li>\n<li>Managed Kubernetes cluster setup (cloud provider control plane configuration)</li>\n</ul>\n<p><strong>Key patterns covered:</strong></p>\n<ul>\n<li>Deployment with security context, resource limits, and probes</li>\n<li>Service types (ClusterIP, NodePort, LoadBalancer, Headless)</li>\n<li>Ingress with TLS and path routing (networking.k8s.io/v1)</li>\n<li>ConfigMap and Secret management (envFrom, volume mounts)</li>\n<li>HPA autoscaling (autoscaling/v2 metrics array)</li>\n<li>RBAC (Role, ClusterRole, RoleBinding, ServiceAccount)</li>\n<li>Pod Security Standards (restricted profile)</li>\n<li>Helm chart structure, values, templates, and helpers</li>\n<li>Kustomize base/overlay pattern with strategic merge patches</li>\n<li>PodDisruptionBudget for safe rollouts</li>\n<li>NetworkPolicy for pod traffic isolation</li>\n</ul>\n<hr>\n\n<hr>\n\n<hr>\n<p>&lt;decision_framework&gt;</p>\n<h2>Decision Framework</h2>\n<h3>Helm vs Kustomize</h3>\n<pre><code>Do you distribute charts to external teams?\n  +-- YES --&gt; Helm (package management, versioned releases)\n  +-- NO  --&gt; Do you need Go templating / conditionals?\n      +-- YES --&gt; Helm (parameterized templates)\n      +-- NO  --&gt; Do you prefer plain YAML with patches?\n          +-- YES --&gt; Kustomize (built into kubectl, no templating)\n          +-- NO  --&gt; Either works. Choose team familiarity.\n</code></pre>\n<h3>Workload Type Selection</h3>\n<pre><code>What is the workload?\n  +-- Stateless HTTP/API server? --&gt; Deployment\n  +-- Needs stable network identity / ordered startup? --&gt; StatefulSet\n  +-- Must run on every node (logging, monitoring)? --&gt; DaemonSet\n  +-- One-time batch job? --&gt; Job\n  +-- Scheduled recurring job? --&gt; CronJob\n</code></pre>\n<h3>Service Type Selection</h3>\n<pre><code>Who needs to reach this service?\n  +-- Other pods in the cluster? --&gt; ClusterIP (default)\n  +-- External traffic via HTTP/HTTPS? --&gt; ClusterIP + Ingress\n  +-- External TCP/UDP without Ingress? --&gt; LoadBalancer\n  +-- Direct node access (dev/test)? --&gt; NodePort\n  +-- StatefulSet pod discovery? --&gt; Headless (clusterIP: None)\n</code></pre>\n<h3>Resource Requests vs Limits</h3>\n<pre><code>What QoS class do you need?\n  +-- Guaranteed (critical workloads) --&gt; requests == limits\n  +-- Burstable (typical workloads) --&gt; requests &lt; limits\n  +-- BestEffort (batch, non-critical) --&gt; no requests/limits (NOT recommended for production)\n</code></pre>\n<p>&lt;/decision_framework&gt;</p>\n<hr>\n<p>&lt;red_flags&gt;</p>\n<h2>RED FLAGS</h2>\n<p><strong>High Priority Issues:</strong></p>\n<ul>\n<li>Missing <code>resources.requests</code> and <code>resources.limits</code> on containers -- unschedulable under pressure, can OOM-kill neighbors</li>\n<li>Running as root (no <code>securityContext.runAsNonRoot: true</code>) -- container escape gives host root access</li>\n<li>Using <code>:latest</code> image tag -- non-deterministic deployments, impossible to roll back to known version</li>\n<li>Missing liveness/readiness probes -- hung processes never restart, traffic hits unready pods</li>\n<li>Using deprecated apiVersions (<code>extensions/v1beta1</code>, <code>autoscaling/v2beta2</code>) -- will fail on modern clusters</li>\n<li>Wildcard RBAC rules (<code>verbs: [\"*\"]</code>, <code>resources: [\"*\"]</code>) -- violates least privilege, security risk</li>\n<li>Storing actual secrets in manifests committed to Git -- use sealed secrets or external secret operators</li>\n</ul>\n<p><strong>Medium Priority Issues:</strong></p>\n<ul>\n<li><code>automountServiceAccountToken</code> not set to false -- every pod gets a token that can access the API server</li>\n<li>No <code>PodDisruptionBudget</code> -- cluster upgrades or node drains can terminate all replicas simultaneously</li>\n<li>No <code>NetworkPolicy</code> -- all pods can communicate with all other pods by default</li>\n<li>Using <code>spec.targetCPUUtilizationPercentage</code> in HPA -- deprecated in <code>autoscaling/v2</code>, use <code>metrics</code> array</li>\n<li>Missing <code>revisionHistoryLimit</code> on Deployments -- unlimited old ReplicaSets consume etcd storage</li>\n<li>ConfigMap/Secret changes not triggering rollout -- pods keep stale config until manually restarted</li>\n</ul>\n<p><strong>Gotchas &amp; Edge Cases:</strong></p>\n<ul>\n<li><code>readOnlyRootFilesystem: true</code> breaks apps that write to <code>/tmp</code> -- add an <code>emptyDir</code> volume mount for <code>/tmp</code></li>\n<li><code>requests.memory</code> too low causes OOMKill; <code>limits.cpu</code> too low causes CPU throttling (latency spikes, not kills)</li>\n<li>Ingress <code>pathType: Prefix</code> matches <code>/api</code> AND <code>/api-docs</code> -- use <code>pathType: Exact</code> for precise matching or add trailing <code>/</code></li>\n<li>Secrets are base64-encoded, NOT encrypted -- anyone with RBAC read access to secrets can decode them</li>\n<li>HPA and manual <code>replicas</code> in Deployment conflict -- remove <code>spec.replicas</code> from manifests when HPA is active</li>\n<li><code>kubectl apply</code> vs <code>kubectl create</code> -- apply is declarative and idempotent; create fails if resource exists</li>\n<li>Kustomize <code>commonLabels</code> adds labels to selectors too -- changing them on existing Deployments breaks selector immutability</li>\n<li>Helm <code>lookup</code> function doesn't work during <code>helm template</code> (no cluster access) -- only works during <code>helm install/upgrade</code></li>\n<li>Pod Security Admission enforces at namespace level via labels -- pods in unlabeled namespaces get the default (usually privileged)</li>\n</ul>\n<p>&lt;/red_flags&gt;</p>\n<hr>\n<p>&lt;critical_reminders&gt;</p>\n<h2>CRITICAL REMINDERS</h2>\n<blockquote>\n<p><strong>All code must follow project conventions in CLAUDE.md</strong> (kebab-case, named exports, import ordering, <code>import type</code>, named constants)</p>\n</blockquote>\n<p><strong>(You MUST set resource requests AND limits on every container -- pods without requests are unschedulable under resource pressure and pods without limits can OOM-kill neighbors)</strong></p>\n<p><strong>(You MUST set securityContext with runAsNonRoot: true, allowPrivilegeEscalation: false, drop ALL capabilities, and readOnlyRootFilesystem: true on every container)</strong></p>\n<p><strong>(You MUST define both liveness and readiness probes -- without readiness probes, traffic reaches unready pods; without liveness probes, hung processes are never restarted)</strong></p>\n<p><strong>(You MUST use the current stable apiVersion for each resource -- apps/v1 for Deployments, networking.k8s.io/v1 for Ingress, autoscaling/v2 for HPA, policy/v1 for PDB)</strong></p>\n<p><strong>Failure to follow these rules will produce insecure pods with root access, unschedulable workloads, unmonitored health, and manifests that fail on modern clusters.</strong></p>\n<p>&lt;/critical_reminders&gt;</p>\n","files":[{"path":"examples/core.md","sizeBytes":10659,"isText":true},{"path":"examples/helm.md","sizeBytes":10736,"isText":true},{"path":"examples/operations.md","sizeBytes":11214,"isText":true},{"path":"reference.md","sizeBytes":7606,"isText":true},{"path":"SKILL.md","sizeBytes":18811,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-29T15:30:17.057148Z","sha256":"83868038C5BEABF5E3ED464F47182FBE74CEC1EA1E5EC9676D93F5FB2AB03AE2","sizeBytes":19255},"review":null,"source":{"repositoryUrl":"https://github.com/agents-inc/skills","path":"dist/plugins/infra-containers-kubernetes/skills/infra-containers-kubernetes","license":"MIT","commit":"3a51ef571e996b18294bf776d53dbdad26de0617","subtreeSha":"A15D68D8FF2E0635ACC8A488AEAA2B44FCFA19A69198B8406FBF741384423334","lastSyncedAt":"2026-09-29T15:27:48.914434Z"},"reviewedAt":"2026-09-29T15:35:07.120854Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/agents-inc/skills/tree/main/dist/plugins/infra-containers-kubernetes/skills/infra-containers-kubernetes"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install agents-inc-skills@llmmart"},{"target":"git","command":"git clone https://github.com/agents-inc/skills.git"}]}