Operate a safe multi-tenant cluster: namespace-per-tenant with scoped RBAC (no workload cluster-admin), default-deny NetworkPolicies, resource quotas/LimitRanges, policy admission control, and tested PDB-respecting upgrades.
Scanned 9/23/2026
npx -y skills add mcorbett51090/RavenClaude --skill k8s-platform-ops --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of K8s Platform Ops?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mcorbett51090-k8s-platform-ops)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: k8s-platform-ops
description: "Operate a safe multi-tenant cluster: namespace-per-tenant with scoped RBAC (no workload cluster-admin), default-deny NetworkPolicies, resource quotas/LimitRanges, policy admission control, and tested PDB-respecting upgrades."
---
# Kubernetes Platform Ops
## Tenancy
Namespace per team/app; RBAC scoped to it. **No** workload gets cluster-admin.
## Network
**Default-deny** pod-to-pod, then allow required flows. (Pairs with mesh mTLS.)
## Fairness
ResourceQuota + LimitRange per namespace so no tenant starves the cluster.
## Enforcement
Admission **policy-as-code** rejects privileged pods, missing limits, `:latest`. Preventive > detective.
## Upgrades
Deprecated-API audit -> non-prod test -> drain respecting **PDBs** -> stay within version-skew -> rollback posture.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!