k8s-workload-packaging-and-manifest
Kubernetes Workload Packaging and Manifest
When to use
Invoke when shipping a workload to Kubernetes for the first time, materially changing a workload's manifest set, or hardening inherited manifests for production-readiness authoring. This skill owns the authoring of the manifest slice; the k8s-deploy-manifest-review omnibus remains the holistic cross-archetype review pass.
Do not use for: NetworkPolicy / ServiceAccount / RBAC depth (use k8s-network-and-identity-policy); HPA/VPA/KEDA tuning, PDB sizing, anti-affinity, topology spread, graceful shutdown (use k8s-scaling-and-resilience-topology); metrics/log/trace wiring and ServiceMonitor (use k8s-observability-and-operations-readiness); image hardening, signing, SBOM, admission control (use k8s-supply-chain-and-image-hardening); cluster provisioning, node pools, control-plane topology (out of Family G — owned by the cloud platform stack and Terraform).
Inputs
Required:
- A container image reference (registry + tag, digest-pinnable) or the source to package via a language sub-skill.
- Approved
infrastructure-platform.md, or explicit confirmation it is intentionally deferred.
Optional: