Q: Your pipeline deploys to Kubernetes using `kubectl apply -f manifests/`. A colleague points out that no one validates the YAML before it hits the cluster โ a typo in a resource limit field goes undetected until the pod fails to schedule. How do you add static validation to the pipeline?
Add a dedicated manifest validation stage before any kubectl apply:
#CI/CD #๐ Supply Chain Security & Advanced CI/CD #L3 #DevOps #Automation #Pipelines
๐๏ธ Candidate Opening & Architectural Context
""During a high-stakes release, we hit a similar deployment challenge and resolved it with automated safeguards. The interviewer is testing: Kubernetes manifest validation, kubeconform, OPA/Conftest policy gates.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
๐ ๏ธ Production Runbook & Step-by-Step Resolution
1๏ธโฃ
Initial Diagnostics & Root Cause Analysis
Add a dedicated manifest validation stage before any kubectl apply:
- Schema validation with
kubeconform: - Policy validation with
conftest(OPA): - Dry-run against a real cluster:
kubectl apply --dry-run=server -f manifests/sends the manifest to the API server for server-side validation without creating any resources. This catches admission webhook rejections too.
2๏ธโฃ
Remediation & Permanent Safeguards
This validates every field against the official Kubernetes OpenAPI schema. A wrong resource.limits.memory: "512Mi" (note the wrong field path) fails immediately. Write Rego policies enforcing your standards: Run: conftest test manifests/. This catches policy violations the schema alone can't catch.
kubeconform -strict -kubernetes-version 1.30.0 manifests/
๐ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Schema validation with kubeconform:."
โก 60-Second Elevator Pitch Talking Points
- Schema validation with kubeconform:
- Policy validation with conftest (OPA):
- Dry-run against a real cluster: kubectl apply --dry-run=server -f manifests/ sends the manifest t...
Advertisement