hermes

Write Kubernetes manifests

Writes production-ready Kubernetes manifests for a service with probes, resource requests, a disruption budget and a restricted security context. Use when deploying a service to a cluster.

context

Most Kubernetes outages caused by manifests come from a short list: liveness probes that check a database and restart every pod when it blips, no readiness probe so traffic hits pods that are still starting, missing memory requests so the scheduler overpacks nodes, a disruption budget that blocks every node drain, all replicas on one node or zone, and containers running as root with a writable filesystem. These manifests should survive a node drain, a zone loss and a security review.

task

Write Kubernetes manifests for this service, for the environment, packaged as :

  1. If the description lacks the image, the listening port or whether the service holds state, ask for them and stop. Everything else you may default; record each default under Assumptions.
  2. A stateless service gets a Deployment; one that owns disk state gets a StatefulSet. Say which and why.
  3. Deployment: rolling update with maxUnavailable: 0 and a small maxSurge; replicas of at least 3 in prod, 2 in staging, 1 in dev; topology spread constraints across zones and nodes; a dedicated ServiceAccount with automountServiceAccountToken: false unless the app calls the API server.
  4. Probes with distinct jobs: a startup probe for slow boots, a readiness probe that reflects ability to serve, and a liveness probe that checks only the process itself, never downstream dependencies.
  5. Resources: CPU and memory requests sized from the description; a memory limit equal to the memory request; no CPU limit unless the user asks for one (explain the throttling trade-off).
  6. Security context: runAsNonRoot, a numeric non-zero UID, readOnlyRootFilesystem (with an emptyDir for any scratch path), allowPrivilegeEscalation: false, all capabilities dropped, seccompProfile: RuntimeDefault. Label the namespace for the restricted Pod Security Standard.
  7. Graceful shutdown: a terminationGracePeriodSeconds and a short preStop sleep so endpoints are removed before the process stops.
  8. Also write: a Service, a PodDisruptionBudget (maxUnavailable: 1; omit it when replicas are 1, because it would block drains), a HorizontalPodAutoscaler for prod, and a NetworkPolicy that denies ingress except from the callers described. When an HPA manages the Deployment, leave spec.replicas out of the Deployment and set the floor in the HPA's minReplicas, so each apply does not reset the autoscaler.
  9. Config comes from a ConfigMap; secrets are referenced by name from a Secret or external secret store, never written with values.
  10. Packaging: plain is one multi-document YAML file; kustomize is a base plus an overlay per environment; helm is a chart with values.yaml, templates and per-environment values files.
constraints
  • Use stable API versions only (apps/v1, policy/v1, autoscaling/v2, networking.k8s.io/v1).
  • Pin the image by digest or an immutable version tag, never latest.
  • Do not invent hostnames, registry paths or secret names; use clearly marked placeholders such as REPLACE_ME_REGISTRY and list them under Assumptions.
  • Do only what was asked. If you notice something else worth changing, mention it in one line at the end instead of changing it.
  • Keep the change as small as it can be while still being correct.
output format

Assumptions

Bullets: every default and placeholder.

Manifests

One fenced yaml block per file, headed by its path.

Why these values

A table: setting, value, reason. Cover replicas, probes, requests and limits, the disruption budget and the security context.

Verify

Commands: kubectl apply --dry-run=server, a schema check such as kubeconform, and how to confirm the rollout and a node drain behave as intended.

1 required value still a placeholder; the assistant will ask for it.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Software engineering
category
DevOps
level
Intermediate
made for
DevOps / platform engineer, Site reliability engineer, Backend engineer
risk
read-only
version
v1.0.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install write-kubernetes-manifests --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill write-kubernetes-manifests -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the software-engineering plugin
claude plugin install hodios-software-engineering@hodios

The plugin brings every entry in this domain at once.

pairs well with

All of DevOps
PromptDevOps

Review a Dockerfile

Reviews a Dockerfile for security, image size, build cache use and runtime correctness, and returns ranked findings with a corrected file. Use before shipping an image, or when one is too big.

review-dockerfile
PromptDevOps

Design a deployment strategy

Chooses and specifies a deployment strategy (rolling, blue-green, canary or feature-flagged) with health gates, automated rollback triggers and database-change ordering. Use when deploys feel risky.

design-deployment-strategy
PromptDevOps

Review an infrastructure plan before apply

Reviews a Terraform, OpenTofu or other IaC plan for destructive changes, security exposure, cost surprises and changes outside the stated intent. Use before running apply, especially in production.

review-iac-plan
PromptDevOps

Write a Docker Compose dev environment

Writes a Docker Compose local development setup that mirrors production dependencies, with health checks, named volumes, seed data, env files and a one-command start. Use when onboarding developers.

write-docker-compose
PromptDevOps

Write a GitHub Actions workflow

Writes a secure, cached and least-privilege GitHub Actions workflow that fits the repository's real build and test commands. Use when adding CI, a release job or a scheduled task.

write-github-actions-workflow
PromptDevOps

Automate mobile app signing

Sets up iOS provisioning and Android keystore signing in CI with certificate and profile management, secret storage, build numbers, test-track uploads and recovery from expired certificates.

automate-mobile-app-signing