| name | kubernetes-operator |
| description | > Use when this capability is needed. |
When to activate
Writing K8s manifests, debugging pod issues, setting up Helm charts, RBAC configuration.
When NOT to activate
- Pure Docker without K8s (use docker-specialist)
- CI/CD pipeline (use devops-orchestrator)
Minimal production Deployment
PASS: Complete deployment with all safety features
apiVersion: apps/v1
kind: Deployment
metadata:
name: myapp
namespace: production
labels: { app: myapp }
spec:
replicas: 3
selector:
matchLabels: { app: myapp }
template:
metadata:
labels: { app: myapp }
spec:
containers:
- name: myapp
image: myapp:1.2.3
ports: [{ containerPort: 3000 }]
resources:
requests: { cpu: "100m", memory: "128Mi" }
limits: { cpu: "500m", memory: "512Mi" }
livenessProbe:
httpGet: { path: /health, port: 3000 }
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
httpGet: { path: /ready, port: 3000 }
initialDelaySeconds: 5
periodSeconds: 5
env:
- name: DATABASE_URL
valueFrom:
secretKeyRef: { name: myapp-secrets, key: database-url }
securityContext:
runAsNonRoot: true
runAsUser: 1000
readOnlyRootFilesystem: true
FAIL: Dangerous defaults
image: myapp:latest
Pod crash debugging
kubectl logs <pod> --previous
kubectl describe pod <pod>
kubectl get events --sort-by='.lastTimestamp' | head -20
kubectl describe pod <pod>
kubectl top pods
kubectl describe pod <pod> | grep -A5 "OOM"
kubectl describe pod <pod>
kubectl get nodes -o wide
Namespace isolation (RBAC template)
apiVersion: v1
kind: ServiceAccount
metadata: { name: myapp, namespace: production }
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata: { name: myapp-role, namespace: production }
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata: { name: myapp-binding, namespace: production }
subjects: [{ kind: ServiceAccount, name: myapp, namespace: production }]
roleRef: { kind: Role, name: myapp-role, apiGroup: rbac.authorization.k8s.io }
Resource sizing guide
| App Type | CPU Request | CPU Limit | Mem Request | Mem Limit |
|---|
| Node.js API | 100m | 500m | 128Mi | 512Mi |
| Python API | 100m | 500m | 256Mi | 1Gi |
| Database (Postgres) | 250m | 1000m | 512Mi | 2Gi |
| Redis | 100m | 500m | 128Mi | 512Mi |
Verification
Source: Abhiram1106/omnix — distributed by TomeVault.