← Kubernetes: operate workloads and recover services
08 / 8 · 60 MIN

Kustomize overlays and manifest review

Compare final environment configurations, follow generated references and distinguish local generation from cluster acceptance and execution.

Review output matching the destination

A shared base reduces duplication, but overlays can change names, namespace, replicas, images and resources. The original lab generates staging with two replicas and production with four. Analyze intended final output while preserving its connection to input revision and tool version. The directory name alone does not select the context of a future application. Confirm operational scope separately. Using the staging manifest to approve production capacity ignores changes that may determine whether the change can proceed during its window with adequate availability and resource headroom.

Observe effective patch semantics

The exercise’s strategic patch adds resources to container api. Output retains metrics and api’s earlier ports. The container list has name-based merge semantics, but not every list and patch behaves that way. Another input tries removing containers/99 through JSON patch and generation fails. Do not promote an old file merely because it still exists in the directory. Connect successful generation, input revision and artifact identity. An error should stop an output that does not correspond to the current change from moving into the next stage.

Follow the ConfigMap to its consumer

Changing MODE=batch to MODE=validated makes the generator produce another hashed name and update the Deployment envFrom reference. The lab confirms that match in output. In a variant with hashing disabled on the effective generator, data changes while the template retains the same rules reference. This helps explain why updating a ConfigMap does not guarantee renewal of processes using environment variables. Review where the option applies and the output actually generated. Acceptance should confirm application-consumed values while preserving availability through any replacement needed to deliver the new configuration.

Labels and namespaces have different effects

The staging overlay adds environment to the template while preserving selector app=ledger. Another overlay includes environment=blue in selectors and output changes. If the apps/v1 Deployment already exists, that update encounters an immutable field. Distinguish identification requirements from selection changes; the solution may preserve selectors or require a deliberate transition. Setting metadata.namespace also does not automatically create the namespace or permissions. Generation needs subsequent review of destination existence, authorization and state. None of these server checks was executed in the local lab, which only produced and compared configuration objects.

Interpret the nine actual renders

The lab executed kubectl 1.37.1 with Kustomize 5.8.1 over eleven original input files. Nine renders include a repeat of the production overlay and one expected invalid-patch rejection. Eight observation groups record environments, images, merge, ConfigMaps, disabled hashing, labels, rejection and repeatability. The image digest made of letter a characters is synthetic and was not queried from a registry. Equal outputs demonstrate repeatability in this experiment rather than universal compatibility. Execution used generated empty configuration for the exercise without consulting real credentials or clusters.

Evidence workshop from generation to production

Prepare a three-stage review. First compare output with intent: resource, name, namespace, template, configuration reference and image. Then, in an authorized environment, validate server acceptance and applicable policies. Finally observe reconciliation and functional outcome with service owners. Neither local generation nor server dry-run itself executes the workload and establishes its behavior. During handover use: “The manifests were generated locally; admission and workload behavior remain unverified.” Keep that difference visible in readiness decisions and preserve a clear link from the reviewed artifact to the eventual operational result.

IN PRACTICE

Actual observation: rules-b69md2f576 changes to rules-f8k6bd2264 and envFrom follows the name. With hashing disabled, rules retains its name and the template stays equal despite changed data.

Common pitfalls

Applying old output after failure; assuming every list is replaced; changing selectors without assessing existing state; treating synthetic digest as an existing image; declaring consumption after generating configuration.

Related topics: Workloads and desired state · Resources and scheduling · Configuration and data

Take this idea with you

Final configuration needs its own review. Preserve identity and references, confirm destination and separate local generation from server acceptance and functional outcome.

Create account

Reference: Declarative Management Using Kustomize · Kubernetes v1.37 concepts; current official documentation consulted 2026-09-30; cluster versions and plugin capabilities must be confirmed

Kubernetes® is a registered trademark of The Linux Foundation. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by The Linux Foundation. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.