Creating Kubernetes DeploymentsSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Template files for kubernetes-deployment-creator skill
Core Templates
- [x] deployment_template.yaml: Kubernetes Deployment with resource limits, probes, and rolling updates
- [x] service_template.yaml: Service types (ClusterIP, NodePort, LoadBalancer) with ports configuration
- [x] ingress_template.yaml: Ingress with TLS, annotations, and path-based routing
Scaling & Availability
- [x] hpa_template.yaml: HorizontalPodAutoscaler with CPU/memory metrics
- [x] pdb_template.yaml: PodDisruptionBudget for voluntary disruption protection
- [x] statefulset_template.yaml: StatefulSet for databases and stateful workloads
Configuration
- [x] configmap_template.yaml: ConfigMap for non-sensitive configuration
- [x] secret_template.yaml: Secret for credentials and sensitive data
Security
- [x] networkpolicy_template.yaml: NetworkPolicy for ingress/egress traffic control
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: creating-kubernetes-deployments description: 'Deploy applications to Kubernetes with production-ready manifests. Supports Deployments, Services, Ingress, HPA, ConfigMaps, Secrets, StatefulSets, and NetworkPolicies. Includes health checks, resource limits, auto-scaling, and TLS termination. Use when working with creating kubernetes deployments. Trigger with ''creating'', ''kubernetes'', ''deployments''. ' allowed-tools: Read, Write, Edit, Grep, Glob, Bash(kubectl:*) version: 1.28.0 author: Jeremy Longshore <[email protected]> license: MIT tags: - devops - deployment - kubernetes - scaling compatibility: Designed for Claude Code --- # Creating Kubernetes Deployments Generate production-ready Kubernetes manifests with health checks, resource limits, and security best practices. ## Quick Start ### Basic Deployment + Service ```yaml # deployment.yaml apiVersion: apps/v1 kind: Deployment metadata: name: my-api labels: app: my-api spec: replicas: 3 selector: matchLabels: app: my-api strategy: type: RollingUpdate rollingUpdate: maxSurge: 25% maxUnavailable: 25% template: metadata: labels: app: my-api spec: containers: - name: my-api image: my-registry/my-api:v1.0.0 ports: - containerPort: 8080 # 8080: HTTP proxy port resources: requests: cpu: 100m memory: 256Mi limits: cpu: 500m memory: 512Mi livenessProbe: httpGet: path: /healthz port: 8080 # HTTP proxy port initialDelaySeconds: 30 periodSeconds: 10 readinessProbe: httpGet: path: /readyz port: 8080 # HTTP proxy port initialDelaySeconds: 5 periodSeconds: 5 --- apiVersion: v1 kind: Service metadata: name: my-api spec: type: ClusterIP selector: app: my-api ports: - port: 80 targetPort: 8080 # HTTP proxy port ``` ## Deployment Strategies | Strategy | Use Case | Configuration | |----------|----------|---------------| | RollingUpdate | Zero-downtime updates | `maxSurge: 25%`, `maxUnavailable: 25%` | | Recreate | Stateful apps, incompatible versions | `type: Recreate` | | Blue-Green | Instant rollback | Two deployments, switch Service selector | | Canary | Gradual rollout | Multiple deployments with weighted traffic | ### Blue-Green Deployment ```yaml # Blue deployment (current production) apiVersion: apps/v1 kind: Deployment metadata: name: my-api-blue labels: app: my-api version: blue spec: replicas: 3 selector: matchLabels: app: my-api version: blue template: metadata: labels: app: my-api version: blue spec: containers: - name: my-api image: my-registry/my-api:v1.0.0 --- # Service points to blue apiVersion: v1 kind: Service metadata: name: my-api spec: selector: app: my-api version: blue # Switch to 'green' for deployment ports: - port: 80 targetPort: 8080 # 8080: HTTP proxy port ``` ## Service Types | Type | Use Case | Access | |------|----------|--------| | ClusterIP | Internal services | `my-api.namespace.svc.cluster.local` | | NodePort | Development, debugging | `<NodeIP>:<NodePort>` | | LoadBalancer | External traffic (cloud) | Cloud provider LB IP | | ExternalName | External service proxy | DNS CNAME | ## Ingress with TLS ```yaml apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my-api-ingress annotations: cert-manager.io/cluster-issuer: letsencrypt-prod nginx.ingress.kubernetes.io/ssl-redirect: "true" spec: ingressClassName: nginx tls: - hosts: - api.example.com secretName: api-tls-secret rules: - host: api.example.com http: paths: - path: / pathType: Prefix backend: service: name: my-api port: number: 80 ``` ## Resource Limits **Always set resource requests and limits:** ```yaml resources: requests: # Guaranteed resources cpu: 100m # 0.1 CPU core memory: 256Mi limits: # Maximum allowed cpu: 500m # 0.5 CPU core memory: 512Mi ``` | Workload Type | CPU Request | Memory Request | CPU Limit | Memory Limit | |---------------|-------------|----------------|-----------|--------------| | Web API | 100m-500m | 256Mi-512Mi | 500m-1000m | 512Mi-1Gi | | Worker | 250m-1000m | 512Mi-1Gi | 1000m-2000m | 1Gi-2Gi | | Database | 500m-2000m | 1Gi-4Gi | 2000m-4000m | 4Gi-8Gi | ## Health Checks ### Liveness Probe (Is container running?) ```yaml livenessProbe: httpGet: path: /healthz port: 8080 # 8080: HTTP proxy port initialDelaySeconds: 30 # Wait for app startup periodSeconds: 10 # Check every 10s timeoutSeconds: 5 # Timeout per check failureThreshold: 3 # Restart after 3 failures ``` ### Readiness Probe (Ready for traffic?) ```yaml readinessProbe: httpGet: path: /readyz port: 8080 # 8080: HTTP proxy port initialDelaySeconds: 5 # Quick check after start periodSeconds: 5 # Check every 5s successThreshold: 1 # 1 success = ready failureThreshold: 3 # Remove from LB after 3 failures ``` ### Startup Probe (Slow-starting apps) ```yaml startupProbe: httpGet: path: /healthz port: 8080 # 8080: HTTP proxy port initialDelaySeconds: 0 periodSeconds: 10 failureThreshold: 30 # Allow 5 minutes to start (30 * 10s) ``` ## Horizontal Pod Autoscaler ```yaml apiVersion: autoscaling/v2 kind: HorizontalPodAutoscaler metadata: name: my-api-hpa spec: scaleTargetRef: apiVersion: apps/v1 kind: Deployment name: my-api minReplicas: 2 maxReplicas: 10 metrics: - type: Resource resource: name: cpu target: type: Utilization averageUtilization: 70 - type: Resource resource: name: memory
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
| secrets access | Credential theft |
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__creating-kubernetes-deployments.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Creating Kubernetes Deployments skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Creating Kubernetes Deployments safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Creating Kubernetes Deployments access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Creating Kubernetes Deployments work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.