Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/tomevault-io/skills-registry --skill kubernetes-operator명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | kubernetes-operator |
| description | > Use when this capability is needed. |
Writing K8s manifests, debugging pod issues, setting up Helm charts, RBAC configuration.
PASS: Complete deployment with all safety features
apiVersion: apps/v1
kind: Deployment
metadata:
name: myapp
namespace: production
labels: { app: myapp }
spec:
replicas: 3
selector:
matchLabels: { app: myapp }
template:
metadata:
labels: { app: myapp }
spec:
containers:
- name: myapp
image: myapp:1.2.3 # NEVER use :latest in production
ports: [{ containerPort: 3000 }]
resources:
requests: { cpu: "100m", memory: "128Mi" }
limits: { cpu: "500m", memory: "512Mi" } # prevent OOMKilled
livenessProbe:
httpGet: { path: /health, port: 3000 }
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
httpGet: { path: /ready, port: 3000 }
initialDelaySeconds: 5
periodSeconds: 5
env:
- name: DATABASE_URL
valueFrom:
secretKeyRef: { name: myapp-secrets, key: database-url }
securityContext:
runAsNonRoot: true
runAsUser: 1000
readOnlyRootFilesystem: true
FAIL: Dangerous defaults
image: myapp:latest # No pinned version
# No resources (can OOM and crash cluster)
# No probes (Kubernetes can't detect unhealthy pods)
# No securityContext (runs as root)
# CrashLoopBackOff
kubectl logs <pod> --previous # logs before crash
kubectl describe pod <pod> # events section
kubectl get events --sort-by='.lastTimestamp' | head -20
# ImagePullBackOff
kubectl describe pod <pod> # look for image pull error
# Fix: check image name/tag, check registry credentials
# OOMKilled
kubectl top pods # check memory usage
kubectl describe pod <pod> | grep -A5 "OOM"
# Fix: increase memory limit, fix memory leak
# Pending pod (not scheduled)
kubectl describe pod <pod> # look for "Insufficient" in events
kubectl get nodes -o wide # check node capacity
apiVersion: v1
kind: ServiceAccount
metadata: { name: myapp, namespace: production }
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata: { name: myapp-role, namespace: production }
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata: { name: myapp-binding, namespace: production }
subjects: [{ kind: ServiceAccount, name: myapp, namespace: production }]
roleRef: { kind: Role, name: myapp-role, apiGroup: rbac.authorization.k8s.io }
| App Type | CPU Request | CPU Limit | Mem Request | Mem Limit |
|---|---|---|---|---|
| Node.js API | 100m | 500m | 128Mi | 512Mi |
| Python API | 100m | 500m | 256Mi | 1Gi |
| Database (Postgres) | 250m | 1000m | 512Mi | 2Gi |
| Redis | 100m | 500m | 128Mi | 512Mi |
Source: Abhiram1106/omnix — distributed by TomeVault.