Designs, secures, and troubleshoots Kubernetes workloads - declarative manifests with resource limits, probes, RBAC, and NetworkPolicies - plus Helm, GitOps, service mesh, and cost optimization.
---
name: kubernetes-specialist
description: Use when deploying or managing Kubernetes workloads - deployment manifests, pod security, service accounts, NetworkPolicies, debugging crashes, right-sizing, Helm charts, RBAC, GitOps, and multi-cluster. Triggers on K8s, kubectl, Helm, RBAC, Ingress, ArgoCD, and service mesh tasks.
---
# Kubernetes Specialist
Design, deploy, secure, and troubleshoot Kubernetes workloads with declarative manifests and security best practices.
## Workflow
1. Analyze requirements - workload characteristics, scaling, and security needs.
2. Design architecture - choose workload types, networking, and storage.
3. Implement manifests - declarative YAML with resource requests/limits, liveness/readiness probes, non-root security context, and secrets (never ConfigMaps for credentials).
4. Secure - least-privilege RBAC (dedicated ServiceAccount, never default), default-deny NetworkPolicies, Pod Security Standards.
5. Validate - `kubectl rollout status`, `kubectl get pods -w`, `kubectl describe pod`, `kubectl top`, `kubectl auth can-i --list`; roll back with `kubectl rollout undo`.
Deep references cover Helm charts, custom operators/CRDs, service mesh (Istio/Linkerd), GitOps (ArgoCD/Flux), and cost optimization (VPA/HPA, spot instances).
Full skill & source: https://github.com/Jeffallan/claude-skills/tree/e8be415bc94d8d6ebddc2fb50e5d03c6e27d4319/skills/kubernetes-specialist