Concept and mechanism
An image should contain what the application needs at runtime. In a multi-stage build, one stage can compile while another receives only the artifact and runtime dependencies. Deleting tools in a later layer does not remove data from earlier layers. To reproduce a release, record its approved digest: a tag can change content. The digest identifies the artifact but does not prove it was tested or is secure. Approval evidence, configuration, and dependencies should accompany promotion between environments.
Guided application
Choose a Deployment for an ongoing service and a Job for work that finishes. A CronJob adds scheduling, with decisions about concurrency and missed runs. In a reconciliation batch, Forbid can prevent overlapping Jobs from the same CronJob but does not guarantee each posting happens only once. The application should recognize repeated work and retain enough state to reconcile results after retries. Before production handover, define how to observe success, failure, delay, and partial effects, including who decides to reprocess a file.
A batch scheduled every five minutes takes eight. Discuss Forbid, per-file identifier idempotency, and an alert when execution misses the business window.
Common pitfalls
Treating latest as approval; confusing a Job with exactly-once execution; using Replace without handling already-produced effects.
Related topics: Init containers, sharing, and persistence · Deployments and recovery
The artifact needs an identity and the work needs an explicit lifecycle.
Reference: Multi-stage container builds · CKAD Kubernetes v1.35