Back to skills
SKILL.md
K8s Platform Ops
ASecurityOperate a safe multi-tenant cluster: namespace-per-tenant with scoped RBAC (no workload cluster-admin), default-deny NetworkPolicies, resource quotas/LimitRanges, policy admission control, and tested PDB-respecting upgrades.
- 7 stars
- 0 votes
- 0 copies
- 0 views
- Added September 23, 2026
Works with
Security analysis
100/100npx -y skills add mcorbett51090/RavenClaude --skill k8s-platform-ops --agent claude-codeAre you the author of K8s Platform Ops?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/mcorbett51090-k8s-platform-ops)---
name: k8s-platform-ops
description: "Operate a safe multi-tenant cluster: namespace-per-tenant with scoped RBAC (no workload cluster-admin), default-deny NetworkPolicies, resource quotas/LimitRanges, policy admission control, and tested PDB-respecting upgrades."
---
# Kubernetes Platform Ops
## Tenancy
Namespace per team/app; RBAC scoped to it. **No** workload gets cluster-admin.
## Network
**Default-deny** pod-to-pod, then allow required flows. (Pairs with mesh mTLS.)
## Fairness
ResourceQuota + LimitRange per namespace so no tenant starves the cluster.
## Enforcement
Admission **policy-as-code** rejects privileged pods, missing limits, `:latest`. Preventive > detective.
## Upgrades
Deprecated-API audit -> non-prod test -> drain respecting **PDBs** -> stay within version-skew -> rollback posture.
Attribution
Comments
Loading comments…