Use when kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments. Only for Kubernetes — not for Docker Compose or other orchestrators. Triggers on \"kubernetes-patterns\", \"kubernetes patterns\", \"patterns\".
Installs into .claude/skills of the current project.
Are you the author of Kubernetes Patterns?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/majinmagros-kubernetes-patterns)
---
name: kubernetes-patterns
description: "Use when kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments. Only for Kubernetes — not for Docker Compose or other orchestrators. Triggers on \"kubernetes-patterns\", \"kubernetes patterns\", \"patterns\"."
metadata:
origin: ECC
---
# Kubernetes Patterns
Production-grade Kubernetes patterns for deploying, managing, and debugging workloads reliably.
## When to Activate
- Writing Kubernetes manifests (Deployments, Services, Ingress, Jobs)
- Configuring resource requests/limits, liveness/readiness probes
- Setting up RBAC, namespaces, or ServiceAccounts
- Managing configuration and secrets in K8s
- Debugging CrashLoopBackOff, OOMKilled, pending pods, or image pull errors
- Configuring HPA (Horizontal Pod Autoscaler) or PodDisruptionBudgets
- Reviewing K8s YAML for security or correctness
## When to Use
> Same as **When to Activate** above. This alias satisfies repo skill-format conventions. Use this skill any time you are writing, reviewing, or debugging Kubernetes YAML and workloads.
## When NOT to Use
- Plain Docker/Compose (use `docker-patterns`)
- CI/CD pipelines (use `deployment-patterns`)
- App-level security review (use `security-review`)
## How It Works
This skill provides **copy-pasteable, production-grade YAML patterns** and **kubectl debugging commands** organized by task:
1. **Deployment template** — A fully configured production `Deployment` with security context, rolling update strategy, all three probe types, resource limits, and environment injection from ConfigMap/Secret.
2. **Probes** — Decision table for startup vs liveness vs readiness, with correct `failureThreshold × periodSeconds` math.
3. **Services & Ingress** — ClusterIP, LoadBalancer, and TLS Ingress patterns with cert-manager annotations.
4. **ConfigMaps & Secrets** — `envFrom`, file-mount, and external secrets guidance.
5. **Resource management** — Requests vs limits rules of thumb by workload type (web API, JVM, worker, sidecar).
6. **RBAC** — Least-privilege ServiceAccount → Role → RoleBinding chain.
7. **HPA & PDB** — Autoscaling and node-drain safety configurations.
8. **Jobs & CronJobs** — One-off and scheduled workload patterns with correct `restartPolicy`.
9. **kubectl cheatsheet** — Logs, exec, rollback, port-forward, dry-run, and common error diagnosis commands.
10. **Anti-patterns & checklist** — What NOT to do, and a security/reliability/observability checklist.
## Examples
| Task | Jump to |
|------|---------|
| Full production Deployment YAML | `references/workloads.md` |
| Probe configuration | `references/probes-services.md` |
| RBAC least-privilege setup | `references/rbac-autoscaling.md` |
| Debug a CrashLoopBackOff | `references/debugging-antipatterns.md` |
| Autoscaling | `references/rbac-autoscaling.md` |
## Example
```yaml
# The 3 probes, correctly combined
startupProbe:
httpGet: { path: /ready, port: 8080 }
failureThreshold: 30
periodSeconds: 2
livenessProbe: