Kubernetes is a contract, not a destination. Pick a managed control plane, define your golden-path manifests, and stop there until a real need pushes you further. Most of the pain teams attribute to Kubernetes is self-inflicted — bespoke clusters, hand-rolled ingress, a service mesh installed on day one because a conference talk made it look fun.
The golden-path baseline
- Managed control plane (EKS, GKE, AKS). Do not run your own.
- One Deployment template, one Service template, one Ingress template. Variants live in values files.
- Sensible resource requests on every workload. No requests, no priority.
- Liveness and readiness probes that mean different things. Most teams conflate them.
- Alerting that pages on user-visible symptoms, not internal noise.
What you do not need on day one
Service mesh. Custom operators. A multi-cluster federation story. GitOps with three layers of abstraction. Add complexity only when a concrete problem demands it, and document the problem in the same commit that introduces the solution.
Md Arifur Rahman is a Senior Software Engineer, Systems Architect, and Cyber Security professional with 8+ years building production-grade platforms across fintech, government, and enterprise SaaS.
