Write Kubernetes manifests
Writes production-ready Kubernetes manifests for a service with probes, resource requests, a disruption budget and a restricted security context. Use when deploying a service to a cluster.
Most Kubernetes outages caused by manifests come from a short list: liveness probes that check a database and restart every pod when it blips, no readiness probe so traffic hits pods that are still starting, missing memory requests so the scheduler overpacks nodes, a disruption budget that blocks every node drain, all replicas on one node or zone, and containers running as root with a writable filesystem. These manifests should survive a node drain, a zone loss and a security review.
Write Kubernetes manifests for this service, for the environment, packaged as :
- If the description lacks the image, the listening port or whether the service holds state, ask for them and stop. Everything else you may default; record each default under Assumptions.
- A stateless service gets a Deployment; one that owns disk state gets a StatefulSet. Say which and why.
- Deployment: rolling update with
maxUnavailable: 0and a smallmaxSurge; replicas of at least 3 in prod, 2 in staging, 1 in dev; topology spread constraints across zones and nodes; a dedicated ServiceAccount withautomountServiceAccountToken: falseunless the app calls the API server. - Probes with distinct jobs: a startup probe for slow boots, a readiness probe that reflects ability to serve, and a liveness probe that checks only the process itself, never downstream dependencies.
- Resources: CPU and memory requests sized from the description; a memory limit equal to the memory request; no CPU limit unless the user asks for one (explain the throttling trade-off).
- Security context:
runAsNonRoot, a numeric non-zero UID,readOnlyRootFilesystem(with anemptyDirfor any scratch path),allowPrivilegeEscalation: false, all capabilities dropped,seccompProfile: RuntimeDefault. Label the namespace for therestrictedPod Security Standard. - Graceful shutdown: a
terminationGracePeriodSecondsand a shortpreStopsleep so endpoints are removed before the process stops. - Also write: a Service, a PodDisruptionBudget (
maxUnavailable: 1; omit it when replicas are 1, because it would block drains), a HorizontalPodAutoscaler for prod, and a NetworkPolicy that denies ingress except from the callers described. - Config comes from a ConfigMap; secrets are referenced by name from a Secret or external secret store, never written with values.
- Packaging:
plainis one multi-document YAML file;kustomizeis a base plus an overlay per environment;helmis a chart withvalues.yaml, templates and per-environment values files.
- Use stable API versions only (
apps/v1,policy/v1,autoscaling/v2,networking.k8s.io/v1). - Pin the image by digest or an immutable version tag, never
latest. - Do not invent hostnames, registry paths or secret names; use clearly marked placeholders such as
REPLACE_ME_REGISTRYand list them under Assumptions. - Do only what was asked. If you notice something else worth changing, mention it in one line at the end instead of changing it.
- Keep the change as small as it can be while still being correct.
Assumptions
Bullets: every default and placeholder.
Manifests
One fenced yaml block per file, headed by its path.
Why these values
A table: setting, value, reason. Cover replicas, probes, requests and limits, the disruption budget and the security context.
Verify
Commands: kubectl apply --dry-run=server, a schema check such as kubeconform, and how to confirm the rollout and a node drain behave as intended.
1 required value still a placeholder; the assistant will ask for it.
details
- kind
- Prompt: a task you run by name to get one finished thing back
- domain
- Software engineering
- category
- DevOps
- level
- Intermediate
- made for
- DevOps / platform engineer, Site reliability engineer, Backend engineer
- risk
- read-only
- version
- v1.0.0 · incubating
- reviewed
- 2026-10-02
- works in
- Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai
use in
npx @hermes-hq/hodios install write-kubernetes-manifests --target claude-codenpx skills add hermes-hq/hodios-dist --skill write-kubernetes-manifests -a claude-codeclaude plugin marketplace add hermes-hq/hodios-distclaude plugin install hodios-software-engineering@hodiosThe plugin brings every entry in this domain at once.
pairs well with
All of DevOpsSlim down a container image
Rewrites a Dockerfile for a smaller, faster, safer image with multi-stage builds, cache-friendly layers, pinned bases and a non-root user. Use when images are large, slow or flagged by scanners.
slim-container-imageDesign a deployment strategy
Chooses and specifies a deployment strategy (rolling, blue-green, canary or feature-flagged) with health gates, automated rollback triggers and database-change ordering. Use when deploys feel risky.
design-deployment-strategyReview a Dockerfile
Reviews a Dockerfile for security, image size, build cache use and runtime correctness, and returns ranked findings with a corrected file. Use before shipping a new or changed container image.
review-dockerfileReview an infrastructure plan before apply
Reviews a Terraform, OpenTofu or other IaC plan for destructive changes, security exposure, cost surprises and changes outside the stated intent. Use before running apply, especially in production.
review-iac-planWrite a Docker Compose dev environment
Writes a Docker Compose local development setup that mirrors production dependencies, with health checks, named volumes, seed data, env files and a one-command start. Use when onboarding developers.
write-docker-composeWrite a GitHub Actions workflow
Writes a secure, cached and least-privilege GitHub Actions workflow that fits the repository's real build and test commands. Use when adding CI, a release job or a scheduled task.
write-github-actions-workflow