Lesson 25 / 25
A Kubernetes Production Checklist
Review every workload before launch.
Questions to ask
Are images pinned and scanned? Are there at least two replicas spread across nodes or zones, with a PDB? Are requests set from real usage and memory limits sensible? Are startup, readiness and liveness probes configured correctly? Does the app handle SIGTERM gracefully? Is configuration in ConfigMaps and are secrets protected (not plain in git)? Does the container run as non-root with a hardened securityContext? Are NetworkPolicies and least-privilege RBAC in place? Is autoscaling configured on the real bottleneck? Are manifests linted in CI and managed through git?
The checklist
Use it in reviews.
[ ] image pinned (version or digest) and scanned
[ ] >= 2 replicas; topology spread; PodDisruptionBudget
[ ] requests from real usage; memory limits with headroom
[ ] startup / readiness / liveness probes, liveness kept local
[ ] graceful shutdown (SIGTERM, preStop, grace period)
[ ] ConfigMaps for config; secrets from a secret manager, not git
[ ] securityContext: non-root, read-only root fs, no privilege escalation
[ ] NetworkPolicy default-deny + explicit allows; least-privilege RBAC
[ ] HPA on the right metric; cluster autoscaler for capacity
[ ] manifests in git, linted in CI, admission policies enforcedPractise with a local cluster
Tools like kind, k3d or minikube run a small cluster on a laptop, which is the safest place to try every manifest in this course.
Quick check: Which item belongs on a Kubernetes production checklist?
- Run a single replica for simplicity
- Use the latest image tag
- Containers run as non-root with a hardened securityContext
- Store Secret manifests in git as plain base64
Answer
Containers run as non-root with a hardened securityContext — Secure, resilient, observable defaults.