Step 01 of 06
Learn the concept
Copying a Kubernetes directory for every environment feels simple until the third security patch. Kustomize keeps the shared base in one place and records only the differences per environment.
The ideas this is made of
A base is the part you hate to patch three times
The Deployment, Service, labels and probes usually mean the same thing everywhere. Put that in a base. When a port changes or a label is fixed, the repair lands once.
Overlays are small, reviewable differences
An overlay references the base and adds patches, image substitutions, labels or generated config. The review should make the environment difference obvious: production has more replicas; dev has debug logging.
Patch type depends on precision
Strategic merge patches look like partial Kubernetes objects and merge by fields such as container name. JSON 6902 patches name exact operations and paths. One is readable for common edits; the other is surgical.
Generated ConfigMaps force rollouts
Kustomize appends a content hash to generated ConfigMaps. When the config changes, the name changes, the Deployment reference changes, and Kubernetes rolls Pods. Without that, config can change while old Pods keep running.
base: burger, fries, tea
dev: staff discount
stage: supplier trial
prod: weekend price
rule: recipe changes onceThe burger recipe does not get copied for every branch. Local differences sit in overlays, so a recipe fix is not patched three times.
Kustomize and Helm are honest alternatives
| Tool | Best at | Trade-off |
|---|---|---|
Kustomize | Patch existing YAML | Less logic |
Helm | Reusable app packages | Templates hide output |
Raw YAML | Tiny demos | Copy drift |
Jsonnet/CUE | Generated systems | Higher language cost |
What these are called on the job
Base — Reusable Kustomize directory containing shared resources.
Overlay — Environment directory that includes a base and applies differences.
Strategic merge — Kubernetes-aware patch style that merges object fragments by known keys.
JSON 6902 — Patch style with explicit add, remove and replace operations at JSON paths.
