{"product_id":"kubernetes-auto-scaling-configuration","title":"Kubernetes Auto-Scaling Configuration","description":"\u003ch3\u003eKubernetes Auto-Scaling Configuration\u003c\/h3\u003e\n\u003cp\u003eDeploying to Kubernetes without a structured pipeline means someone is running \u003ccode\u003ekubectl apply\u003c\/code\u003e from their laptop with a kubeconfig that has cluster-admin privileges. I have seen this at three different enterprises before I helped them fix it. At one energy sector client, a developer accidentally applied a staging manifest to production because their kubeconfig context was wrong. The service mesh routed 100% of traffic to an unconfigured pod for 22 minutes. This template makes that class of error structurally impossible.\u003c\/p\u003e\n\n\u003cp\u003eThis pipeline implements GitOps-aligned Kubernetes deployment via GitHub Actions. Every manifest change is version-controlled, reviewed, scanned, and promoted through environments with gates — not \u003ccode\u003ekubectl\u003c\/code\u003e commands typed into terminals.\u003c\/p\u003e\n\n\u003ch3\u003ePipeline Stages\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003emanifest-lint\u003c\/strong\u003e — \u003ccode\u003einstrumenta\/kubeval@v0.16.1\u003c\/code\u003e validates manifests against Kubernetes OpenAPI schemas. Catches invalid field names, wrong API versions, and missing required fields before anything touches a cluster.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003epolicy-check\u003c\/strong\u003e — \u003ccode\u003ebridgecrewio\/checkov-action@v12\u003c\/code\u003e enforces security policies: no privileged containers, no host network access, resource limits required, no \u003ccode\u003elatest\u003c\/code\u003e image tags, read-only root filesystem.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ebuild-and-scan\u003c\/strong\u003e — Builds the container image, scans with Trivy, signs with Cosign. The image digest (not tag) is injected into the Kubernetes manifests via \u003ccode\u003ekustomize edit set image\u003c\/code\u003e.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003edeploy-dev\u003c\/strong\u003e — \u003ccode\u003eazure\/k8s-deploy@v5\u003c\/code\u003e or \u003ccode\u003eaws-actions\/amazon-eks-kubectl@v1\u003c\/code\u003e applies to the dev cluster. Uses namespace isolation. Runs a post-deploy health check: \u003ccode\u003ekubectl rollout status deployment\/app --timeout=300s\u003c\/code\u003e.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eintegration-test\u003c\/strong\u003e — Port-forwards the service and runs the integration test suite against the deployed pods. Tests service mesh routing, database connectivity, and external API mocks.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003edeploy-staging\u003c\/strong\u003e — Promotion via environment protection rules. Kustomize overlay patches the replica count, resource limits, and ingress hostname for staging. Same manifests, different configuration.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003edeploy-prod\u003c\/strong\u003e — Canary deployment: 10% traffic shift, 5-minute bake time, automated metric check (error rate \u0026lt; 0.1%, p99 latency \u0026lt; 500ms), then full rollout. Manual approval gate with two required reviewers.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003erollback-on-failure\u003c\/strong\u003e — If the canary metrics breach thresholds, the pipeline runs \u003ccode\u003ekubectl rollout undo\u003c\/code\u003e and opens an incident issue with the deployment SHA, metric values, and pod logs attached.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eSecurity Gates\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCheckov\/OPA\u003c\/strong\u003e — Enforces pod security standards. No containers run as root. All images must come from approved registries. NetworkPolicies must exist for every namespace.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eImage digest pinning\u003c\/strong\u003e — Manifests reference images by SHA256 digest, not mutable tags. Prevents supply chain attacks where a tag is overwritten with a compromised image.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRBAC-scoped service accounts\u003c\/strong\u003e — The GitHub Actions deployer service account has namespace-scoped permissions only. Cannot modify cluster-level resources, RBAC, or other namespaces.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAdmission controller integration\u003c\/strong\u003e — Cosign image signatures are verified by Kyverno or OPA Gatekeeper at admission time. Unsigned images are rejected by the cluster.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eEnvironment Matrix\u003c\/h3\u003e\n\u003cp\u003eDev namespace auto-deploys on PR merge. Staging requires a release candidate tag and one approval. Production requires two approvals, passing staging integration tests, and a canary deployment window. Each environment runs in a separate cluster (or namespace with NetworkPolicy isolation) with distinct IAM roles and Secrets Manager paths.\u003c\/p\u003e\n\n\u003ch3\u003eTop 3 Failures\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eImagePullBackOff from ECR token expiry\u003c\/strong\u003e — EKS nodes cache ECR credentials for 12 hours. Long-running nodes with expired tokens cannot pull new images. Fix: ensure \u003ccode\u003eamazon-k8s-cni\u003c\/code\u003e and ECR credential helper are updated, or use \u003ccode\u003eimagePullSecrets\u003c\/code\u003e with a CronJob that refreshes the token.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eResource quota exceeded in namespace\u003c\/strong\u003e — The deployment specifies resource requests that exceed the namespace ResourceQuota. Fix: right-size resource requests based on actual usage metrics from Prometheus, and set the quota 20% above the expected peak.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eKustomize overlay merge conflicts\u003c\/strong\u003e — Two PRs modify the same Kustomize patch file. The merge produces invalid YAML that passes GitHub merge checks but fails \u003ccode\u003ekustomize build\u003c\/code\u003e. Fix: add a \u003ccode\u003ekustomize build\u003c\/code\u003e step in the PR check pipeline that validates the merged output.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"Citadel Cloud Management","offers":[{"title":"Default Title","offer_id":54890412736803,"sku":"CCM-DEV-036","price":35.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0979\/8539\/7027\/files\/citadel-devops-product_92815045-93de-48d0-b3b6-31c86c5f9ab5.jpg?v=1775138134","url":"https:\/\/citadel-cloud-management.myshopify.com\/products\/kubernetes-auto-scaling-configuration","provider":"Citadel Cloud Management","version":"1.0","type":"link"}