role-devops:kubernetes-expert
Deep Kubernetes expertise covering workload management, Gateway API, Cilium eBPF networking, Kyverno/OPA policy enforcement, KEDA event-driven autoscaling, Karpenter node provisioning, Helm advanced patterns, Kustomize, Operator pattern, CRDs, multi-cluster management, local development clusters,...
SKILL.md
Full skill instructions
Kubernetes Expert
When to use
- Designing or reviewing Kubernetes workload configuration (Deployments, StatefulSets, DaemonSets, Jobs)
- Setting up cluster networking, NetworkPolicies, or migrating from Ingress to Gateway API
- Configuring autoscaling with HPA, VPA, KEDA, Cluster Autoscaler, or Karpenter
- Writing Helm charts, Kustomize overlays, or Kubernetes Operators
- Multi-cluster strategy, local development environments, or Crossplane infrastructure
Core principles
- Resources are mandatory — requests and limits on every container, every time
- Default-deny networking — NetworkPolicies with default-deny ingress per namespace
- Gateway API over Ingress — for all new ingress implementations
- Policy at admission — Kyverno or OPA Gatekeeper, never after-the-fact auditing
- Autoscaling is layered — KEDA for event-driven zero-scale, Karpenter for optimal nodes
Reference Files
references/workloads.md— Deployment/StatefulSet/DaemonSet/Job patterns, resource quotas, LimitRanges, PodDisruptionBudgets, topology spread constraints, node affinity and taintsreferences/networking-gateway.md— ClusterIP/NodePort/LoadBalancer/Headless services, Gateway API (GatewayClass, Gateway, HTTPRoute), canary routing, namespace managementreferences/cilium-policy.md— Cilium eBPF core concepts, CiliumNetworkPolicy L7 rules, Hubble observability, service mesh, Calico, Flannel, Kyverno admission policies, OPA Gatekeeper Regoreferences/autoscaling.md— HPA behavior and stabilization, VPA modes, KEDA ScaledObject/ScaledJob with Kafka/Redis/SQS triggers, Cluster Autoscaler, Karpenter NodePool with spot consolidationreferences/helm-kustomize-ops.md— OCI registries, Helm hooks, library charts, SOPS integration, Kustomize patches and components, kubebuilder/Operator SDK/kopf, CRD design, Cluster API, vCluster, local clusters (kind/k3d), Crossplane composite resources
Best Practices Checklist
- Resource requests and limits on every container
- Liveness, readiness, and startup probes configured correctly
- PodDisruptionBudgets for critical services
- NetworkPolicies with default-deny ingress per namespace
- RBAC with dedicated ServiceAccounts, no wildcard permissions
- Namespaces with ResourceQuotas and LimitRanges
- Topology spread constraints for zone and node distribution
- Helm or Kustomize for manifest management, never raw kubectl apply
- Karpenter or Cluster Autoscaler for dynamic node scaling
- KEDA for event-driven workloads that should scale to zero
- Gateway API (not Ingress) for new ingress implementations
- Kyverno or OPA Gatekeeper policies enforced at admission
- Cilium for eBPF-powered networking and observability
- Crossplane for self-service infrastructure provisioning
- Cluster upgrades tested in staging with Cluster API or managed upgrade tools
