SkillByAIOpen interactive version →

Lesson 21 / 25

Kustomize Overlays

One base, many environments.

Patch without templates

Kustomize (built into kubectl) composes plain YAML: a base with the common manifests and overlays per environment that set a namespace, add labels, change image tags, patch replica counts and generate ConfigMaps and Secrets. There is no templating language; overlays describe differences. Build with kubectl kustomize dir to see the result, or apply with kubectl apply -k dir.

The prod overlay's kustomization.yaml

The base contains a plain Deployment (2 replicas, image tag 1.4.0) and Service.

resources:
- ../../base
namespace: shop-prod
labels:
- pairs:
    env: prod
images:
- name: ghcr.io/example/web
  newTag: 1.5.2
patches:
- target:
    kind: Deployment
    name: web
  patch: |-
    - op: replace
      path: /spec/replicas
      value: 4

Building the prod overlay, run

I ran this with kubectl 1.37.0 using --dry-run=client (or kubectl kustomize), which generates manifests locally without a cluster; nothing was applied to a live cluster. The overlay sets namespace shop-prod, adds the env: prod label, changes the image tag to 1.5.2 and patches replicas from 2 to 4, without editing the base files.

kubectl kustomize kz/overlays/prod

Output:

apiVersion: v1
kind: Service
metadata:
  labels:
    env: prod
  name: web
  namespace: shop-prod
spec:
  ports:
  - port: 80
    targetPort: 8080
  selector:
    app: web
---
apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    env: prod
  name: web
  namespace: shop-prod
spec:
  replicas: 4
  selector:
    matchLabels:
      app: web
  template:
    metadata:
      labels:
        app: web
    spec:
      containers:
      - image: ghcr.io/example/web:1.5.2
        name: web
        ports:
        - containerPort: 8080

Quick check: How does Kustomize customise manifests per environment?

  • It edits files in place
  • Overlays patch a shared base without a templating language
  • It uses Go templates
  • It requires a separate server
Answer

Overlays patch a shared base without a templating language — Base plus overlays.