Write Kubernetes manifests
Writes production-ready Kubernetes manifests for a service with probes, resource requests, a disruption budget and a restricted security context. Use when deploying a service to a cluster.
Most Kubernetes outages caused by manifests come from a short list: liveness probes that check a database and restart every pod when it blips, no readiness probe so traffic hits pods that are still starting, missing memory requests so the scheduler overpacks nodes, a disruption budget that blocks every node drain, all replicas on one node or zone, and containers running as root with a writable filesystem. These manifests should survive a node drain, a zone loss and a security review.
Write Kubernetes manifests for this service, for the environment, packaged as :
- If the description lacks the image, the listening port or whether the service holds state, ask for them and stop. Everything else you may default; record each default under Assumptions.
- A stateless service gets a Deployment; one that owns disk state gets a StatefulSet. Say which and why.
- Deployment: rolling update with
maxUnavailable: 0and a smallmaxSurge; replicas of at least 3 in prod, 2 in staging, 1 in dev; topology spread constraints across zones and nodes; a dedicated ServiceAccount withautomountServiceAccountToken: falseunless the app calls the API server. - Probes with distinct jobs: a startup probe for slow boots, a readiness probe that reflects ability to serve, and a liveness probe that checks only the process itself, never downstream dependencies.
- Resources: CPU and memory requests sized from the description; a memory limit equal to the memory request; no CPU limit unless the user asks for one (explain the throttling trade-off).
- Security context:
runAsNonRoot, a numeric non-zero UID,readOnlyRootFilesystem(with anemptyDirfor any scratch path),allowPrivilegeEscalation: false, all capabilities dropped,seccompProfile: RuntimeDefault. Label the namespace for therestrictedPod Security Standard. - Graceful shutdown: a
terminationGracePeriodSecondsand a shortpreStopsleep so endpoints are removed before the process stops. - Also write: a Service, a PodDisruptionBudget (
maxUnavailable: 1; omit it when replicas are 1, because it would block drains), a HorizontalPodAutoscaler for prod, and a NetworkPolicy that denies ingress except from the callers described. When an HPA manages the Deployment, leavespec.replicasout of the Deployment and set the floor in the HPA'sminReplicas, so each apply does not reset the autoscaler. - Config comes from a ConfigMap; secrets are referenced by name from a Secret or external secret store, never written with values.
- Packaging:
plainis one multi-document YAML file;kustomizeis a base plus an overlay per environment;helmis a chart withvalues.yaml, templates and per-environment values files.
- Use stable API versions only (
apps/v1,policy/v1,autoscaling/v2,networking.k8s.io/v1). - Pin the image by digest or an immutable version tag, never
latest. - Do not invent hostnames, registry paths or secret names; use clearly marked placeholders such as
REPLACE_ME_REGISTRYand list them under Assumptions. - Do only what was asked. If you notice something else worth changing, mention it in one line at the end instead of changing it.
- Keep the change as small as it can be while still being correct.
Assumptions
Bullets: every default and placeholder.
Manifests
One fenced yaml block per file, headed by its path.
Why these values
A table: setting, value, reason. Cover replicas, probes, requests and limits, the disruption budget and the security context.
Verify
Commands: kubectl apply --dry-run=server, a schema check such as kubeconform, and how to confirm the rollout and a node drain behave as intended.
1 required value still a placeholder; the assistant will ask for it.
details
- kind
- Prompt: a task you run by name to get one finished thing back
- domain
- Software engineering
- category
- DevOps
- level
- Intermediate
- made for
- DevOps / platform engineer, Site reliability engineer, Backend engineer
- risk
- read-only
- version
- v1.0.0 · incubating
- reviewed
- 2026-10-02
- works in
- Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai
use in
npx @hermes-hq/hodios install write-kubernetes-manifests --target claude-codenpx skills add hermes-hq/hodios-dist --skill write-kubernetes-manifests -a claude-codeclaude plugin marketplace add hermes-hq/hodios-distclaude plugin install hodios-software-engineering@hodiosThe plugin brings every entry in this domain at once.
pairs well with
All of DevOpsReview a Dockerfile
Reviews a Dockerfile for security, image size, build cache use and runtime correctness, and returns ranked findings with a corrected file. Use before shipping an image, or when one is too big.
review-dockerfileDesign a deployment strategy
Chooses and specifies a deployment strategy (rolling, blue-green, canary or feature-flagged) with health gates, automated rollback triggers and database-change ordering. Use when deploys feel risky.
design-deployment-strategyReview an infrastructure plan before apply
Reviews a Terraform, OpenTofu or other IaC plan for destructive changes, security exposure, cost surprises and changes outside the stated intent. Use before running apply, especially in production.
review-iac-planWrite a Docker Compose dev environment
Writes a Docker Compose local development setup that mirrors production dependencies, with health checks, named volumes, seed data, env files and a one-command start. Use when onboarding developers.
write-docker-composeWrite a GitHub Actions workflow
Writes a secure, cached and least-privilege GitHub Actions workflow that fits the repository's real build and test commands. Use when adding CI, a release job or a scheduled task.
write-github-actions-workflowAutomate mobile app signing
Sets up iOS provisioning and Android keystore signing in CI with certificate and profile management, secret storage, build numbers, test-track uploads and recovery from expired certificates.
automate-mobile-app-signing