
Kubernetes Deployment Helper
Generate and audit production-ready Kubernetes manifests with security and reliability best pract...
What You Can Do
You can generate complete, production-ready Kubernetes manifests from application requirements or audit existing YAML configurations for security vulnerabilities, resource efficiency, and reliability gaps. The skill applies industry best practices including CPU/memory limits, liveness and readiness probes, graceful rollout strategies, and least-privilege RBAC policies—eliminating common deployment pitfalls and accelerating your path to secure, scalable containerized applications.
Features
Creates YAML with replicas, rolling update strategy, and pod disruption budgets configured for zero-downtime deployments
Generates liveness and readiness probes (HTTP, TCP, exec) tailored to your application startup time and health endpoints
Automatically sets CPU/memory requests and limits based on application tier to prevent cluster overallocation and eviction
Creates ServiceAccounts, Roles, and RoleBindings implementing least-privilege access control for your workloads
Generates ClusterIP, NodePort, and LoadBalancer Services plus Ingress rules with TLS configuration
Structures environment variables and configuration files for safe, auditable configuration management
Reviews existing YAML for missing resource limits, probe gaps, RBAC violations, and production readiness issues with specific remediation steps
Recommends maxSurge, maxUnavailable, and minReadySeconds settings based on your availability requirements
Example Output
Example 1: Generate Deployment with Health Checks
Input: Node.js API running on port 3000 with /health endpoint
Output:
apiVersion: apps/v1
kind: Deployment
metadata:
name: api-service
namespace: production
spec:
replicas: 3
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
template:
spec:
containers:
- name: api
image: myrepo/api:v1.2.0
ports:
- containerPort: 3000
livenessProbe:
httpGet:
path: /health
port: 3000
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
httpGet:
path: /ready
port: 3000
initialDelaySeconds: 5
periodSeconds: 5
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
Example 2: Audit Existing Manifest
Input: User pastes production Deployment without resource limits
Output: ✗ Missing resource requests/limits — Pod may be evicted. Add requests: {cpu: 100m, memory: 256Mi} and limits: {cpu: 500m, memory: 512Mi} ✗ No liveness probe — Container restarts will be delayed. Add httpGet probe to /health endpoint with initialDelaySeconds: 30 ✓ RBAC: ServiceAccount configured — Least-privilege access enforced ✓ Rolling update strategy — maxUnavailable: 0 ensures zero-downtime deployments
What's Included
- SKILL.md instruction file with activation triggers and usage guidelines:
- Deployment manifest template with rolling updates and probe configurations:
- Service and Ingress template for both internal and external traffic routing:
- RBAC policy template with ServiceAccount, Role, and RoleBinding examples:
- Manifest audit checklist for reviewing security, performance, and reliability (resource limits, probes, RBAC, image policy, PDB):
- Health probe configuration guide with recommended initialDelaySeconds and periodSeconds for common application types:
Who It's For
- DevOps/SRE Engineers — generating and auditing Kubernetes manifests at scale across environments
- Platform Engineers — establishing baseline manifest templates and governance policies
- Software Engineers — transitioning applications to Kubernetes with production-ready configurations
- Cloud Architects — reviewing deployment patterns for security, cost, and reliability alignment
- Site Reliability Engineers — hardening existing Kubernetes deployments against operational risks
Best For
- Creating production Deployments from container images with zero-downtime rollout requirements
- Implementing health checks and graceful shutdown behavior for stateless microservices
- Auditing existing manifests for missing resource limits, RBAC violations, and probe gaps
- Configuring multi-tier applications with Services, Ingress, and ConfigMaps in a single coherent manifest set
- Establishing RBAC policies that enforce least-privilege access for CI/CD and application workloads







