Skip to content
Back to skills

K8s Manifest

ASecurity

Write Kubernetes Deployment, Service, and Ingress manifests with sane defaults

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsgokubernetesbackendsecurity

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill k8s-manifest --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of K8s Manifest?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for K8s Manifest
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-k8s-manifest/badge)](https://www.skillsdirectory.com/skills/black141312-k8s-manifest)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: k8s-manifest
description: Write Kubernetes Deployment, Service, and Ingress manifests with sane defaults
category: cloud
---

# K8s Manifest

Use this to stand up a stateless workload on Kubernetes — a Deployment fronted by a Service and exposed via an Ingress — without missing the production-critical fields people forget.

1. Write the `Deployment` with explicit `replicas`, matching `selector`/`template` labels, and a pinned image tag (never `:latest`).
2. Set `resources.requests` and `resources.limits` for cpu and memory on every container.
3. Add `livenessProbe` and `readinessProbe` (HTTP or exec) so rollouts and restarts behave.
4. Write the `Service` (usually `ClusterIP`) selecting the same pod labels and naming the target port.
5. Write the `Ingress` with host rules, a `pathType`, the backend Service, and TLS referencing a cert Secret.
6. Validate with `kubectl apply --dry-run=server -f .` (or `kubeval`) and `kubectl diff` before applying.

## Rules
- Always run as non-root: set `securityContext` with `runAsNonRoot: true`, drop capabilities, and `readOnlyRootFilesystem` where possible.
- Keep config in `ConfigMap`/`Secret` and inject via `envFrom`/`valueFrom` — no secrets baked into manifests or images.
- Label consistently (`app`, `app.kubernetes.io/name`, `version`) so selectors and tooling work.
- Set a `Namespace` explicitly or via kustomize; don't rely on `default`.
- Prefer a rolling `strategy` with `maxUnavailable`/`maxSurge` tuned for your replica count.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…