TT Lab
Get started
Learn Learning paths Courses

Production Backend API Capstone

Parse the Deployment Declaration Too, and Check What It Means at Runtime

Continue in TT Lab

One-line summary

A safe deployment declares, as structured objects, a digest-pinned image, non-root execution, no privilege escalation, a read-only root filesystem, resource requests and limits, readiness and liveness probes with different meanings, and Secret references.

Why string search is dangerous

Even if you write runAsNonRoot: true in a comment, Kubernetes receives no security setting at all. YAML with broken indentation or a wrong nesting path can still contain all the strings. In this lab you write deployment.yaml in JSON format, a strict subset of YAML 1.2. The Python standard library parses the real object and checks the values under spec.template.spec.containers, so there is no extra internet dependency.

Pin the image with a sha256 digest, not a mutable tag. The Pod security context has runAsNonRoot and RuntimeDefault seccomp, and the container security context has allowPrivilegeEscalation: false and readOnlyRootFilesystem: true. Set both CPU and memory requests and limits, and separate /readyz from /healthz. A readiness failure removes the Pod from new traffic, and a liveness failure triggers a process restart.

How to inject secrets in practice

If you write the DATABASE_URL value directly in the manifest, credentials remain in Git history and on review screens. Reference only the name and key with valueFrom.secretKeyRef, and let the deployment system supply the actual secret. The Dockerfile pins a Python 3.12 base image by digest and runs with a numeric UID. CMD explicitly makes the server start on port 8080 on all interfaces.

Practical judgment criteria

Parsing successfully is only the first step. Structurally check that the selector matches the Pod labels, that each container has a single responsibility, the probe paths, the resource values, and the form of the Secret reference. In a real cluster you add a policy engine and server-side dry-run. The capstone check verifies the core structure that is hard to tamper with even in an offline session with no cluster, and the last module organizes these choices and the lessons from failures into evidence that makes you hireable.