Project challenges / verified progress
Beacon: ship it without fear

The engineering notebook

Shape manifests per place

How can the same Kubernetes manifests fit dev, staging and production?

Loading statusStage 6 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Let Git drive the cluster

Step 01 of 06

Learn the concept

Copying a Kubernetes directory for every environment feels simple until the third security patch. Kustomize keeps the shared base in one place and records only the differences per environment.

ONE BASE THREE OVERLAYSBaseshared manifestsDev1 replica, fastkindStageprod-like configapprovalProdmore replicasstable
The base is the shared manifest set, not an environment. Each overlay records the smallest useful difference so review focuses on what actually changes.
Step 01

The ideas this is made of

A base is the part you hate to patch three times

The Deployment, Service, labels and probes usually mean the same thing everywhere. Put that in a base. When a port changes or a label is fixed, the repair lands once.

Overlays are small, reviewable differences

An overlay references the base and adds patches, image substitutions, labels or generated config. The review should make the environment difference obvious: production has more replicas; dev has debug logging.

Patch type depends on precision

Strategic merge patches look like partial Kubernetes objects and merge by fields such as container name. JSON 6902 patches name exact operations and paths. One is readable for common edits; the other is surgical.

Generated ConfigMaps force rollouts

Kustomize appends a content hash to generated ConfigMaps. When the config changes, the name changes, the Deployment reference changes, and Kubernetes rolls Pods. Without that, config can change while old Pods keep running.

One menu, three branches
base: burger, fries, tea
dev: staff discount
stage: supplier trial
prod: weekend price
rule: recipe changes once

The burger recipe does not get copied for every branch. Local differences sit in overlays, so a recipe fix is not patched three times.

Kustomize and Helm are honest alternatives

ToolBest atTrade-off

Kustomize

Patch existing YAML

Less logic

Helm

Reusable app packages

Templates hide output

Raw YAML

Tiny demos

Copy drift

Jsonnet/CUE

Generated systems

Higher language cost

What these are called on the job

  • Base — Reusable Kustomize directory containing shared resources.

  • Overlay — Environment directory that includes a base and applies differences.

  • Strategic merge — Kubernetes-aware patch style that merges object fragments by known keys.

  • JSON 6902 — Patch style with explicit add, remove and replace operations at JSON paths.