Files
nexus/sreweekly/articles/462/07-kubernetes-best-practices-i-wish-i-had-known-before.html
2026-09-12 17:23:01 +08:00

181 lines
191 KiB
HTML
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html><html lang="en-US" prefix="og: http://ogp.me/ns#"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"><meta name="viewport" content="width=device-width,initial-scale=1,maximum-scale=5"><script>var segmentWriteKey="UK90Ofwacetj5VCPJ7cUgkbNcKLSHO3u",snippetName="C8Y429BDEy/06ujkUhzfL.min.js";window.growthbook_sdk_key="sdk-psPofGr6jFV2ja9O",window.growthbook_decrypt_key="9NsAVMNWaDS+Oky3rhLQ+A==",window.growthbook_dev_mode=!1</script><link rel="preconnect" href="https://cdn.segment.com" crossorigin><link rel="preconnect" href="https://cdn.growthbook.io" crossorigin><link rel="preconnect" href="https://cdn.cr-relay.com" crossorigin><link rel="preconnect" href="https://bzrcdn.openai.com" crossorigin><link rel="preload" href="/fonts/monaspace-neon-regular.woff2" as="font" type="font/woff2" crossorigin><link rel="preload" href="/fonts/inter-regular.woff2" as="font" type="font/woff2" crossorigin><link rel="preload" href="/fonts/inter-semibold.woff2" as="font" type="font/woff2" crossorigin><link rel="llms-txt" href="/llms.txt"><script src="/js/bundle.6c1f5611.js" defer></script><script src="/js/algolia.0829731d.js" defer></script><link rel="stylesheet" href="/css/bundle.push-cbf96af2.css"><meta name="google-site-verification" content="N-ezSTIu4P3bSc4TqidV4wWCkMzFiMN269ZgDYArGkk"><script type="application/ld+json">{"@context":"https://schema.org","@graph":[{"@id":"#breadcrumb","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","item":"https://www.pulumi.com","name":"Home","position":1},{"@type":"ListItem","item":"https://www.pulumi.com/blog/","name":"Blog","position":2},{"@type":"ListItem","name":"Kubernetes Best Practices I Wish I Had Known Before","position":3}]},{"@id":"#main-content","@type":"BlogPosting","articleSection":"Best Practices","author":[{"@id":"https://www.pulumi.com/authors/engin-diri/#person","@type":"Person","affiliation":{"@id":"https://www.pulumi.com/#organization","@type":"Organization","name":"Pulumi"},"image":"https://www.pulumi.com/images/team/engin-diri.jpg","jobTitle":"Principal Solutions Architect","knowsAbout":["Infrastructure as Code","Cloud Computing","DevOps"],"name":"Engin Diri","sameAs":["https://github.com/dirien","https://x.com/_ediri"],"url":"https://www.pulumi.com/blog/author/engin-diri/","worksFor":{"@id":"https://www.pulumi.com/#organization","@type":"Organization","name":"Pulumi"}}],"dateModified":"2026-08-17T13:35:37-05:00","datePublished":"2025-01-20T00:00:00Z","description":"Kubernetes best practices for 2026: resource limits, RBAC, NetworkPolicy, autoscaling, GitOps, policy-as-code, SBOM, and FinOps — with anti-patterns and fixes.\n","headline":"Kubernetes Best Practices I Wish I Had Known Before","image":"https://www.pulumi.com/images/generated/blog/kubernetes-best-practices-i-wish-i-had-known-before/index.png","inLanguage":"en-US","isPartOf":{"@id":"https://www.pulumi.com/#website"},"keywords":"kubernetes, best-practices, devops","mainEntityOfPage":{"@id":"https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/#webpage"},"publisher":{"@id":"https://www.pulumi.com/#organization"},"speakable":{"@type":"SpeakableSpecification","cssSelector":["article h1","article \u003e section:first-of-type \u003e p:first-of-type"]},"timeRequired":"PT17M","url":"https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/","wordCount":3451},{"@id":"#faq","@type":"FAQPage","breadcrumb":{"@id":"#breadcrumb"},"dateModified":"2026-08-17T13:35:37-05:00","datePublished":"2025-01-20T00:00:00Z","description":"Kubernetes best practices for 2026: resource limits, RBAC, NetworkPolicy, autoscaling, GitOps, policy-as-code, SBOM, and FinOps — with anti-patterns and fixes.\n","inLanguage":"en-US","mainEntity":[{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Kubernetes best practices are the operational patterns that keep workloads available, secure, observable, and cost-efficient on a Kubernetes cluster. They span four areas: workload configuration (resources, probes, images), security (RBAC, NetworkPolicy, Pod Security, secrets, supply chain), delivery (GitOps, policy-as-code, IaC), and platform operations (autoscaling, monitoring, upgrades, FinOps). The rest of this post explains each one with a copy-pasteable rule, a definition of the underlying Kubernetes object, and a common anti-pattern to avoid."},"name":"What are Kubernetes best practices?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What are resource requests and limits? A resource request is the minimum CPU and memory the kube-scheduler guarantees a container; a resource limit is the maximum the kubelet allows it to consume before throttling CPU or OOMKilling memory. Pods without requests are scheduled blind, so a noisy neighbor can evict your workload at any time. The rule: every container in production sets a request for both CPU and memory, and a memory limit. CPU limits are optional and frequently counter-productive — they cause throttling spikes that look like outages. Start at 100–200m CPU and 128–512Mi memory for a typical web service. Tune from real data using Vertical Pod Autoscaler with updateMode: Off (recommendation-only) or Prometheus histograms. Use a per-namespace LimitRange so teams cannot ship a container with no requests at all."},"name":"1. How do you set Kubernetes resource requests and limits?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is a Kubernetes namespace? A namespace is a logical partition of cluster resources. It scopes object names, RBAC bindings, NetworkPolicies, and quotas — but does not provide hard isolation by itself. The rule: never deploy production workloads to default. Map namespaces to ownership boundaries — usually one per team, environment, or tenant — and pair every namespace with three things: A ResourceQuota to cap aggregate CPU, memory, and object counts. A LimitRange to enforce per-container defaults. A RoleBinding that grants only the permissions that team needs. This is the smallest unit that gives you predictable cost, blast-radius containment, and an RBAC perimeter."},"name":"2. How should you structure Kubernetes namespaces?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is a Pod? A Pod is the smallest deployable unit in Kubernetes — one or more containers that share a network namespace, IPC, and storage volumes, and that are scheduled and scaled as a single unit. The rule: one container per Pod by default. Add a second container only when it must share the Pod’s network or volumes — for example, a service-mesh sidecar (Istio/Linkerd), a logging shipper, or an init container that prepares state before the main process starts. Multi-container Pods couple lifecycles and scaling, so reach for them deliberately, not by default."},"name":"3. Should you run multiple containers in one Pod?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"The rule: never copy-paste raw YAML across services. Pick one of these: Helm — Go-templated charts; the de-facto distribution format for off-the-shelf software (Prometheus, cert-manager, Argo CD). Kustomize — overlay-based, no templating; ships in kubectl. Best for “same app, different environment” diffs. Pulumi — real programming languages (TypeScript, Python, Go, Java, .NET) for Kubernetes plus the cloud resources around it (EKS, GKE, AKS, DNS, IAM). Type checking, tests, and the Pulumi Kubernetes Operator for GitOps-style reconciliation. If you are already managing cloud infrastructure with code, extending the same Pulumi program to Kubernetes is the smallest cognitive jump — the cluster, its IAM, its DNS, and its workloads live in one stack and one review."},"name":"4. Should you use Helm, Kustomize, or Pulumi for Kubernetes manifests?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is the Gateway API? The Gateway API is the successor to the legacy Ingress resource. It splits responsibility between infrastructure (GatewayClass, Gateway) and application (HTTPRoute, GRPCRoute, TLSRoute) teams, and it is the SIG-Network direction for north-south traffic. The rule: new clusters should standardize on the Gateway API. The widely deployed ingress-nginx controller retired in March 2026, and remaining deployments should migrate to Envoy Gateway, Istio, Linkerd Gateway, or Kgateway. Terminate TLS at the gateway and automate certificates with cert-manager. Use path-based and host-based routing instead of one gateway per service. Protect every gateway with a WAF (managed cloud WAF or Coraza on Envoy). ingress-nginx is retiring in March 2026. Here is a guide on How to Move to the Gateway API: post ingress-nginx Retirement."},"name":"5. How should you handle ingress and networking on Kubernetes in 2026?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Probes tell the kubelet whether to restart a container, route traffic to it, or wait for it. Configure them per workload: Liveness probe — restarts a hung container. Use sparingly; a bad liveness probe is a self-inflicted DoS. Readiness probe — gates traffic from Services and Gateway routes. Use for every network-facing workload. Startup probe — gives slow-booting apps (JVM, ML models) time to come up before liveness checks begin. Use whenever cold-start exceeds 10 seconds. See the upstream guide for HTTP, TCP, and exec probe syntax. Tune failureThreshold, periodSeconds, and timeoutSeconds based on real latency, not defaults."},"name":"6. What's the difference between liveness, readiness, and startup probes?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Cluster security is layered: identity, workload posture, network, and secrets. Get all four right."},"name":"7. How do you secure a Kubernetes cluster?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"RBAC (Role-Based Access Control) is the Kubernetes authorization model that maps subjects (users, groups, ServiceAccounts) to verbs (get, list, create, delete) on resources, scoped to a namespace (Role) or the whole cluster (ClusterRole). Grant least privilege — never bind humans or workloads to cluster-admin. Prefer per-namespace Role + RoleBinding over ClusterRoleBinding. Audit with kubectl auth can-i --as=... and tools like rbac-lookup."},"name":"What is RBAC in Kubernetes?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Pod Security Admission is the built-in admission controller that enforces the three Pod Security Standards (privileged, baseline, restricted) at the namespace level. Label every namespace pod-security.kubernetes.io/enforce=restricted by default. Drop NET_RAW and all capabilities; run as non-root with a read-only root filesystem. Use seccompProfile: RuntimeDefault and a tight securityContext for every container."},"name":"What is Pod Security Admission?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"A NetworkPolicy is a Kubernetes object that defines allowed ingress and egress traffic for selected Pods at the IP/port level. Without one, every Pod can reach every other Pod by default. Apply a default-deny ingress and egress policy in every namespace. Allow only the flows your service actually needs (DNS, the database, the upstream API). For richer L7 controls (mTLS, JWT auth), layer a service mesh on top."},"name":"What is a NetworkPolicy?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Built-in Secret objects are base64-encoded, not encrypted. Treat them as a transport, not as storage. Store the source of truth in Pulumi ESC, HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, or Azure Key Vault. Project secrets into Pods with the External Secrets Operator or the Secret Store CSI Driver. Enable etcd encryption-at-rest with a KMS provider so leaked etcd snapshots stay opaque. Rotate automatically; never commit secrets to Git, even encrypted."},"name":"How should you manage Kubernetes secrets?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Observability rests on the three pillars: metrics, logs, and traces. The 2026 default stack is OpenTelemetry-first. Metrics — Prometheus (or a Prometheus-compatible TSDB like Mimir, Thanos, VictoriaMetrics) plus Grafana dashboards. Logs — Fluent Bit or the OpenTelemetry Collector shipping structured JSON to Loki, Elastic/OpenSearch, or a managed service. Never depend on kubectl logs for incidents — Pods are ephemeral. Traces — OpenTelemetry SDKs in your apps emitting to Tempo, Jaeger, or a vendor backend. Correlate trace IDs with logs. Alerts — page on SLO burn rate, not on every crashed Pod. Burn-rate alerting catches real user impact without firing on every restart."},"name":"8. How do you set up Kubernetes observability?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is GitOps? GitOps is a deployment model where the desired cluster state lives in a Git repository and a controller continuously reconciles the live cluster to match. Changes happen through pull requests, not kubectl apply. The rule: every cluster has a controller — Argo CD, Flux, or the Pulumi Kubernetes Operator — that owns reconciliation. Humans never kubectl apply to production. Use app-of-apps (Argo) or Kustomization trees (Flux) to bootstrap whole clusters from a single root. Keep manifests, Helm values, and Pulumi stack references in Git, with environment promotion via PR. Combine GitOps with Pulumi Deployments so cloud infrastructure (VPCs, EKS clusters, IAM, DNS) and the workloads on top promote through the same review pipeline. See improving GitOps with the Pulumi Operator for a worked example. Configure automated rollback on health-check failure, and drift detection alerts when someone edits live state."},"name":"9. How do you automate Kubernetes deployments with GitOps?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Kubernetes ships a minor release roughly every four months and supports each one for about 14 months. Treat upgrades as routine maintenance, not a project. Stay within two minor versions of upstream — older versions miss CVE patches. Test upgrades in a non-prod cluster, run a conformance test, then promote. Back up etcd before control-plane changes; managed services (EKS, GKE, AKS) handle most of this for you. Upgrade add-ons (CNI, CSI, Gateway controller, cert-manager, metrics-server) on the same cadence — pin versions in code so the upgrade is auditable. Watch the Kubernetes deprecation guide and run pluto or kubent to find deprecated APIs before they break."},"name":"10. How often should you upgrade Kubernetes?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Labels and annotations are the metadata layer that everything — Services, NetworkPolicies, monitoring, cost tools, GitOps — keys off of. Consistency matters more than cleverness. Adopt the recommended labels: app.kubernetes.io/name, app.kubernetes.io/instance, app.kubernetes.io/version, app.kubernetes.io/component, app.kubernetes.io/part-of, app.kubernetes.io/managed-by. Add organization-specific labels for owner, cost-center, environment, and SLO tier — your FinOps and on-call processes will need them. Reserve annotations for non-identifying metadata: build SHA, change-ticket, last-deployed timestamp, ingress controller hints. Provision your clusters, their cloud resources, and the workloads on them from one Pulumi program, and use stacks to promote changes from dev to production."},"name":"11. How should you label and annotate Kubernetes resources?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"The rule: production is its own cluster. Dev and staging can share — sometimes. Mixing prod with anything else couples blast radius, upgrade cadence, and quotas. Separate clusters per environment is the safe default. With managed control planes (EKS, GKE, AKS) the cost is small. Virtual clusters with vCluster give each team a Kubernetes API of their own without the operational cost of a real cluster. Namespace-only segregation can work for dev/staging if you enforce strict NetworkPolicy, RBAC, and ResourceQuota boundaries. Provision all of them from the same Pulumi program with different stacks — dev, staging, prod — so promotion is a config change, not a copy."},"name":"12. How should you separate Kubernetes environments?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Start from a distroless (gcr.io/distroless) or chainguard/static base. Alpine is fine if you accept musl. Build with multi-stage Dockerfiles so build tools never ship in the final image. Pin the base image by digest (@sha256:...), not by tag — latest and 1.21 move under you. Scan every image with Trivy, Grype, or your registry’s built-in scanner. Block builds on Critical/High CVEs. Smaller images mean faster pulls, faster autoscaling, and a smaller attack surface."},"name":"13. How do you optimize Kubernetes container images?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Centralize to Loki, Elastic/OpenSearch, or a managed service via Fluent Bit or the OpenTelemetry Collector running as a DaemonSet. Structure logs as JSON with consistent field names (trace_id, span_id, service, level). Retain by tier — 7 days hot, 30–90 days warm, archive to object storage for compliance. Redact secrets and PII at the collector, not after the fact."},"name":"14. What's a reliable Kubernetes logging strategy?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is the Horizontal Pod Autoscaler? The HPA scales the replica count of a Deployment or StatefulSet up and down based on CPU, memory, or custom/external metrics. What is the Vertical Pod Autoscaler? The VPA adjusts a Pod’s CPU and memory requests over time based on observed usage. Run it with updateMode: Off (recommendation-only) in production and apply the recommendations through your IaC tool. What are Cluster Autoscaler and Karpenter? Cluster Autoscaler adds and removes nodes to match Pod demand. Karpenter is a faster, group-less node provisioner now widely used on EKS and gaining traction on other clouds. The rule: every production workload has an HPA. Every cluster has a node-level autoscaler. Set sensible min/max replicas, define a PodDisruptionBudget, and gate scale-down behavior so traffic spikes don’t pile up at restart time. Pair with KEDA for event-driven scaling (queues, Kafka lag, scheduled scale)."},"name":"15. How should you autoscale workloads on Kubernetes?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is policy-as-code? Policy-as-code expresses governance rules — security baselines, tagging, region restrictions, cost guardrails — as code that runs in CI and at admission time, blocking non-compliant changes before they reach the cluster. The rule: every change goes through at least one policy engine. Pre-deploy — validate Pulumi or Helm output with Pulumi CrossGuard or Conftest in CI. Admission-time — install OPA Gatekeeper or Kyverno and require, for example, signed images, a team label, and a non-root securityContext on every Pod. Continuous — scan running clusters with Pulumi Insights or kubescape for drift from policy. See the benefits of policy-as-code and enforcing policy-as-code on discovered resources for end-to-end examples."},"name":"16. How do you enforce policy-as-code on Kubernetes?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"What is an SBOM? A Software Bill of Materials is a machine-readable inventory of every component in a container image — packages, versions, licenses, hashes — typically in SPDX or CycloneDX format. The rule: every image you run in production has a verified SBOM and a verified signature. Generate SBOMs at build time with Syft or docker sbom. Sign images and SBOMs with Sigstore/cosign keylessly via GitHub OIDC. Verify signatures at admission with Kyverno or Connaisseur. Generate provenance attestations (SLSA) so you can prove which build pipeline produced a given image. Pin base images by digest and rebuild on a cadence so CVE patches actually land. This is what regulators and customers ask for in 2026 — Executive Order 14028, the EU Cyber Resilience Act, and most enterprise procurement checklists all require it."},"name":"17. How do you secure the Kubernetes software supply chain?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"The rule: Kubernetes cost is a labeling and right-sizing problem before it is a discount problem. Right-size with VPA recommendations, Goldilocks, or your APM’s recommendation engine. Most workloads request more CPU than they actually use; right-sizing is usually the largest single saving. Schedule non-prod clusters off overnight and on weekends. Spot/preemptible nodes for fault-tolerant workloads; use Karpenter’s consolidation to compact bin-packing. Show back / charge back by namespace and label using OpenCost or Kubecost. Without per-team attribution, no team owns cost. Provision the underlying cluster with IaC — see Pulumi for Kubernetes — so node types, autoscaling limits, and reserved capacity are reviewable artifacts. Pulumi’s hidden-cost analysis walks through where the money actually goes."},"name":"18. How do you manage Kubernetes cost (FinOps)?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"The old “cattle, not pets” adage applies more strictly to Kubernetes than to VMs. Manual edits to a live cluster will be reconciled away, drift between environments, or vanish on the next Pod restart. Fix problems in code — YAML, Helm chart, or Pulumi program — and let the controller redeploy. If you can’t redeploy a cluster from Git in under an hour, you have a pet. Use ephemeral preview environments for PRs; use blue/green or progressive delivery (Argo Rollouts, Flagger) for production cutovers."},"name":"19. Why should you treat Kubernetes clusters as cattle, not pets?"},{"@type":"Question","acceptedAnswer":{"@type":"Answer","text":"Native YAML scales until your team doesn’t. Once you have more than a handful of services, dependencies between cloud resources and Kubernetes objects, or more than one cluster, infrastructure as code in a real programming language wins on every axis. Real languages — TypeScript, Python, Go, Java, .NET — for type-safe, testable Kubernetes infrastructure. Loops, conditionals, and unit tests instead of templating. One stack, full topology — manage the cloud (EKS/GKE/AKS, VPC, IAM, DNS) and the workloads in it together. See easily create and manage AWS EKS clusters with Pulumi. Reusable components — abstract platform patterns into Pulumi packages other teams import instead of copy-pasting. GitOps reconciliation — the Pulumi Kubernetes Operator reconciles a cluster to a Pulumi stack on every Git push. Policy-as-code built in — CrossGuard blocks non-compliant changes before pulumi up. Secrets done right — Pulumi ESC federates secrets and configuration across stacks, environments, and Kubernetes clusters. For a deeper comparison of hand-written YAML, Terraform, and Pulumi for Kubernetes, see YAML, Terraform, Pulumi: what’s the smart choice for deployment automation with Kubernetes, and the beyond YAML write-up on where Kubernetes automation is heading in 2026. See how Pulumi helps you manage Kubernetes Services and Deployments with code instead of YAML—bringing structure, reuse, and type safety to your configs. By adopting Pulumi, you can avoid the complexity of juggling endless YAML files and gain a more streamlined, maintainable workflow for your Kubernetes infrastructure."},"name":"20. Why use Pulumi to manage Kubernetes?"}],"name":"Kubernetes Best Practices I Wish I Had Known Before","publisher":{"@id":"https://www.pulumi.com/#organization"},"url":"https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/"},{"@id":"https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/#webpage","@type":"WebPage","breadcrumb":{"@id":"#breadcrumb"},"dateModified":"2026-08-17T13:35:37-05:00","datePublished":"2025-01-20T00:00:00Z","description":"Kubernetes best practices for 2026: resource limits, RBAC, NetworkPolicy, autoscaling, GitOps, policy-as-code, SBOM, and FinOps — with anti-patterns and fixes.\n","headline":"Kubernetes Best Practices I Wish I Had Known Before","inLanguage":"en-US","isPartOf":{"@id":"https://www.pulumi.com/#website"},"mainEntity":{"@id":"#main-content"},"mentions":[{"@id":"https://en.wikipedia.org/wiki/Kubernetes","@type":"SoftwareApplication","alternateName":"K8s","name":"Kubernetes","sameAs":"https://www.wikidata.org/wiki/Q22661306"},{"@id":"https://en.wikipedia.org/wiki/Docker_(software)","@type":"SoftwareApplication","name":"Docker","sameAs":"https://www.wikidata.org/wiki/Q15206305"},{"@id":"https://en.wikipedia.org/wiki/Terraform_(software)","@type":"SoftwareApplication","name":"Terraform","sameAs":"https://www.wikidata.org/wiki/Q30273653"},{"@id":"https://en.wikipedia.org/wiki/TypeScript","@type":"ComputerLanguage","name":"TypeScript","sameAs":"https://www.wikidata.org/wiki/Q978185"},{"@id":"https://en.wikipedia.org/wiki/Python_(programming_language)","@type":"ComputerLanguage","name":"Python","sameAs":"https://www.wikidata.org/wiki/Q28865"},{"@id":"https://en.wikipedia.org/wiki/YAML","@type":"ComputerLanguage","name":"YAML","sameAs":"https://www.wikidata.org/wiki/Q281876"}],"name":"Kubernetes Best Practices I Wish I Had Known Before","url":"https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/"},{"@id":"https://www.pulumi.com/#organization","@type":["Organization","Corporation"],"alternateName":"Pulumi","description":"Pulumi enables cloud infrastructure teams to define, deploy, and manage cloud resources using familiar programming languages.","foundingDate":"2017","logo":{"@type":"ImageObject","height":299,"url":"https://brand.pulumi.com/media/images/logos/horizontal-1200w.png","width":1200},"name":"Pulumi Corporation","sameAs":["https://github.com/pulumi","https://twitter.com/PulumiCorp","https://x.com/PulumiCorp","https://www.linkedin.com/company/pulumi","https://www.youtube.com/channel/UC2Dhyn4Ev52YSbcpfnfP0Mw","https://www.wikidata.org/wiki/Q122864080","https://en.wikipedia.org/wiki/Pulumi","https://www.crunchbase.com/organization/pulumi-corporation"],"url":"https://www.pulumi.com"},{"@id":"https://www.pulumi.com/#website","@type":"WebSite","alternateName":"Pulumi IaC Platform","description":"Infrastructure as Code platform with AI. Deploy to any cloud using TypeScript, Python, Go, C#, Java, or YAML.","inLanguage":"en-US","name":"Pulumi","publisher":{"@id":"https://www.pulumi.com/#organization"},"url":"https://www.pulumi.com"},{"@id":"https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/#video","@type":"VideoObject","contentUrl":"https://www.youtube.com/watch?v=2P8JLgAc5QI","description":"Kubernetes best practices for 2026: resource limits, RBAC, NetworkPolicy, autoscaling, GitOps, policy-as-code, SBOM, and FinOps — with anti-patterns and fixes.\n","embedUrl":"https://www.youtube.com/embed/2P8JLgAc5QI","name":"Kubernetes Best Practices I Wish I Had Known Before","publisher":{"@id":"https://www.pulumi.com/#organization"},"thumbnailUrl":"https://img.youtube.com/vi/2P8JLgAc5QI/maxresdefault.jpg","uploadDate":"2025-01-20T00:00:00Z"}]}</script><meta property="og:image" content="https://www.pulumi.com/images/generated/blog/kubernetes-best-practices-i-wish-i-had-known-before/index.png"><meta property="og:type" content="article"><meta property="og:url" content="https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/"><meta property="og:site_name" content="pulumi"><meta name="twitter:image" content="https://www.pulumi.com/images/generated/blog/kubernetes-best-practices-i-wish-i-had-known-before/index.png"><meta name="twitter:card" content="summary_large_image"><meta name="twitter:site" content="@PulumiCorp"><meta property="article:author" content="Engin Diri"><meta name="author" content="Engin Diri"><meta property="article:published_time" content="2025-01-20T00:00:00Z"><meta property="article:modified_time" content="2026-08-17T13:35:37-05:00"><meta property="og:title" content="Kubernetes Best Practices I Wish I Had Known Before"><meta name="description" content="Kubernetes best practices for 2026: resource limits, RBAC, NetworkPolicy, autoscaling, GitOps, policy-as-code, SBOM, and FinOps — with anti-patterns and fixes.
"><meta property="og:description" content="Kubernetes best practices for 2026: resource limits, RBAC, NetworkPolicy, autoscaling, GitOps, policy-as-code, SBOM, and FinOps — with anti-patterns and fixes.
"><title>Kubernetes Best Practices I Wish I Had Known Before | Pulumi Blog</title><link rel="icon" type="image/x-icon" href="/images/favicon.ico"><link rel="canonical" href="https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/"><link rel="alternate" type="application/rss+xml" href="https://www.pulumi.com/blog/rss.xml" title="Pulumi Blog"><script>userAgentBlocklist=["Mozilla/5.0 (compatible; SiteAuditBot/0.97; +http://www.semrush.com/bot.html)","Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"],!function(){var n,s,t="analytics",e=window[t]=window[t]||[];if(!e.initialize)if(e.invoked)window.console&&console.error&&console.error("Segment snippet included twice.");else if(userAgentBlocklist.includes(navigator.userAgent))console.log("Segment snippet not loaded for user agent: "+navigator.userAgent);else{e.invoked=!0,e.methods=["trackSubmit","trackClick","trackLink","trackForm","pageview","identify","reset","group","track","ready","alias","debug","page","screen","once","off","on","addSourceMiddleware","addIntegrationMiddleware","setAnonymousId","addDestinationMiddleware","register"],e.factory=function(n){return function(){if(window[t].initialized)return window[t][n].apply(window[t],arguments);var o,s=Array.prototype.slice.call(arguments);return["track","screen","alias","group","page","identify"].indexOf(n)>-1&&(o=document.querySelector("link[rel='canonical']"),s.push({__t:"bpc",c:o&&o.getAttribute("href")||0[0],p:location.pathname,u:location.href,s:location.search,t:document.title,r:document.referrer})),s.unshift(n),e.push(s),e}};for(n=0;n<e.methods.length;n++)s=e.methods[n],e[s]=e.factory(s);e.load=function(n,s){var i,o=document.createElement("script");o.type="text/javascript",o.async=!0,o.setAttribute("data-global-segment-analytics-key",t),o.src="https://evs.analytics.pulumi.com/"+snippetName,i=document.getElementsByTagName("script")[0],i.parentNode.insertBefore(o,i),e._loadOptions=s},e._writeKey=segmentWriteKey,e._cdn="https://evs.analytics.pulumi.com",e.SNIPPET_VERSION="5.2.0",e.page()}}()</script><script>window.consentManagerConfig={writeKey:segmentWriteKey,cdnHost:"evs.analytics.pulumi.com",container:"#segment-consent-manager",privacyPolicyUrl:"/privacy/",bannerText:"We use cookies (and other similar technologies) to collect data to improve your experience on our site. By using our website, youʼre agreeing to the collection of data as described in our",preferencesDialogTitle:"Website Data Collection Preferences",preferencesDialogContent:"We use data collected by cookies and JavaScript libraries to improve your browsing experience, analyze site traffic, deliver personalized advertisements, and increase the overall performance of our site.",cancelDialogTitle:"Are you sure you want to cancel?",cancelDialogContent:"Your preferences have not been saved. By continuing to use our website, you are agreeing to our Website Data Collection Policy."}</script><script>window.addEventListener("load",function(){var e=document.createElement("script");e.src="/js/consent-manager.9f70d491.js",document.body.appendChild(e)})</script><meta name="facebook-domain-verification" content="phlf6qes2bxa9ufzk8zt2es0qivg8j"><script>window.addEventListener("load",function(){if(typeof window.signals!="undefined")return;var e=document.createElement("script");e.src="https://cdn.cr-relay.com/v1/site/a725b5ba-75f1-44dc-b250-11023fc10b9d/signals.js",e.async=!0,window.signals=Object.assign([],["page","identify","form"].reduce(function(e,t){return e[t]=function(){return signals.push([t,arguments]),signals},e},{})),document.head.appendChild(e)})</script><script>window.addEventListener("load",function(){function e(){!function(e,t,n,s){if(e.oaiq)return;var o,a,i=function(){i.q.push(arguments)};i.q=[],e.oaiq=i,o=t.createElement(n),o.async=1,o.src=s,a=t.getElementsByTagName(n)[0],a.parentNode.insertBefore(o,a)}(window,document,"script","https://bzrcdn.openai.com/sdk/oaiq.min.js"),oaiq("init",{pixelId:"7KRuATZtZE3j5BSAZErZAb",debug:!1})}window.analytics&&typeof window.analytics.ready=="function"&&window.analytics.ready(e)})</script><script async defer src="/js/anchor-js.min.js"></script><script>window.addEventListener("load",function(){anchors&&anchors.add(".blog-post-content :is(h1, h2, h3, h4, h5, h6):not(.no-anchor)")})</script><meta http-equiv="last-modified" content="2026-04-30T00:00:00Z"><script>try{var c=document.cookie.split("; ").find(function(e){return e.indexOf("pulumi_web_user_info=")===0}),v=c?JSON.parse(decodeURIComponent(c.slice(c.indexOf("=")+1)).slice(2)):null;v&&v.userId&&document.documentElement.classList.add("is-signed-in")}catch{}</script></head><body class="section-blog antialiased min-h-screen flex flex-col"><a href="#main" class="btn btn-outline fixed left-2 top-2.5 z-[100] -translate-y-16 no-underline focus:translate-y-0">Skip to main content</a>
<pulumi-root></pulumi-root><script>(function(){try{var e,t,s,o,i=["blog-pulumi-neo-security-2026-08-Nx9vQ7"],n=[];try{s=JSON.parse(localStorage.getItem("announcement-banner")||"{}"),Array.isArray(s.dismissed)&&(n=s.dismissed)}catch{}if(e=i.filter(function(e){return n.indexOf(e)<0}),e.length===0)return;o=e[Math.floor(Math.random()*e.length)],t=document.createElement("style"),t.id="announcement-banner-reveal",t.textContent='#announcement-banner{display:block!important}#announcement-banner .announcement[data-announcement-id="'+o+'"]{display:flex!important}',document.head.appendChild(t),document.documentElement.setAttribute("data-announcement-chosen",o)}catch{}})()</script><div id="announcement-banner" class="hidden w-full bg-violet-950 text-white group text-sm" data-announcement-banner role="region" aria-label="Site announcement"><div class="announcement hidden h-10 items-center gap-3 px-4 md:px-6" data-announcement-id="blog-pulumi-neo-security-2026-08-Nx9vQ7"><div class="flex flex-1 min-w-0 items-center gap-3"><a href="/blog/pulumi-neo-security/" tabindex="-1" class="contents text-white group-hover:text-white/90 hover:no-underline"><svg class="ph-icon ph-icon--fill size-5 shrink-0 text-violet-300" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-shield-check-fill"/></svg><div class="min-w-0 overflow-hidden whitespace-nowrap" data-announcement-marquee><span class="inline-block" data-announcement-content><span class="announcement-text inline-block"><strong>Identify weaknesses before attackers do.</strong> Neo Security finds and fixes exploitable flaws in your infrastructure. Now in research preview.</span></span></div></a><a href="/blog/pulumi-neo-security/" class="shrink-0 inline-flex items-center rounded-md border border-white/20 px-2 py-0.5 text-xs font-medium text-white hover:bg-white/10 hover:no-underline">Read the blog</a></div><button type="button" aria-label="Dismiss announcement" class="shrink-0 inline-flex h-6 w-6 items-center justify-center rounded text-white hover:bg-white/10" data-announcement-dismiss>
<svg class="ph-icon ph-icon--regular size-3" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-x-regular"/></svg></button></div></div><header class="sticky top-0 z-40 w-full border-b border-gray-200 bg-white"><div class="flex h-16 items-center justify-between gap-2 px-4 md:px-6"><a href="/" data-track="header-pulumi-logo" data-logo-brand-menu class="flex shrink-0 items-center rounded-md transition-opacity hover:opacity-80 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:ring-offset-4 focus-visible:outline-1 focus-visible:outline-transparent" aria-label="Pulumi home"><img class="docs-logo-light h-7 w-auto" src="/fingerprinted/logos/brand/logo-on-white.325f59b356d06fbea052c320e4d50d5b40a392616680cd6c72a0e807869f4bba.svg" alt="Pulumi logo" width="112" height="28" loading="eager" decoding="async">
<img class="docs-logo-dark h-7 w-auto" src="/fingerprinted/logos/brand/logo-on-black.cc9e57571fcea31f6ed8dfbdb619a59755570083e72a35ed490569a3dcb83ac6.svg" alt="Pulumi logo" width="112" height="28" loading="eager" decoding="async"></a><nav data-nav-root class="hidden nav-desktop:flex relative self-stretch items-center" aria-label="Primary"><ul class="flex items-center gap-0"><li><button type="button" data-nav-trigger-button data-nav-index="0" aria-expanded="false" aria-haspopup="menu" aria-controls="nav-desktop-popup" class="btn btn-ghost-nav group/trigger inline-flex items-center justify-center px-4">
Product
<svg class="ph-icon ph-icon--bold text-gray-500 group-hover/trigger:text-violet-500 [[data-open=true]_&]:text-violet-300 relative top-px size-3 transition duration-300 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button></li><li><button type="button" data-nav-trigger-button data-nav-index="1" aria-expanded="false" aria-haspopup="menu" aria-controls="nav-desktop-popup" class="btn btn-ghost-nav group/trigger inline-flex items-center justify-center px-4">
For engineers
<svg class="ph-icon ph-icon--bold text-gray-500 group-hover/trigger:text-violet-500 [[data-open=true]_&]:text-violet-300 relative top-px size-3 transition duration-300 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button></li><li><button type="button" data-nav-trigger-button data-nav-index="2" aria-expanded="false" aria-haspopup="menu" aria-controls="nav-desktop-popup" class="btn btn-ghost-nav group/trigger inline-flex items-center justify-center px-4">
For enterprises
<svg class="ph-icon ph-icon--bold text-gray-500 group-hover/trigger:text-violet-500 [[data-open=true]_&]:text-violet-300 relative top-px size-3 transition duration-300 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button></li><li><a href="/docs/" data-track="header-docs" class="btn btn-ghost-nav inline-flex items-center justify-center">Docs</a></li><li><a href="/registry/" data-track="header-registry" class="btn btn-ghost-nav inline-flex items-center justify-center">Registry</a></li><li><a href="/blog/" data-track="header-blog" class="btn btn-ghost-nav inline-flex items-center justify-center">Blog</a></li><li><a href="/pricing/" data-track="header-pricing" class="btn btn-ghost-nav inline-flex items-center justify-center">Pricing</a></li><li><button type="button" data-nav-trigger-button data-nav-index="3" aria-expanded="false" aria-haspopup="menu" aria-controls="nav-desktop-popup" class="btn btn-ghost-nav group/trigger inline-flex items-center justify-center px-4">
Company
<svg class="ph-icon ph-icon--bold text-gray-500 group-hover/trigger:text-violet-500 [[data-open=true]_&]:text-violet-300 relative top-px size-3 transition duration-300 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button></li></ul><div data-nav-popup id="nav-desktop-popup" class="card absolute z-50 bg-white text-gray-950 shadow" style="display:none;top:calc(100% - .5rem);left:0;opacity:0;transform:scale(.95);transform-origin:top left;transition:none"><div data-nav-viewport style="position:relative;overflow:hidden;width:100%;height:100%"><div data-nav-content="0" style="position:absolute;top:0;left:0;opacity:0;transform:translateX(0);will-change:opacity,transform"><div class="grid gap-x-6 gap-y-4 p-2 w-[640px] grid-cols-2"><div class="flex flex-col gap-1 col-span-full"><span class="px-3 pt-2 font-mono text-xs uppercase tracking-wide text-gray-600">Core product</span><ul class="grid gap-x-6 gap-y-0.5 grid-cols-2"><li><a href="/product/" data-track="header-product-platform" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-cloud-arrow-up-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Platform overview</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Everything platform engineering teams need to build, secure, and scale cloud infrastructure</span></span></a></li><li><a href="/product/infrastructure-as-code/" data-track="header-product-iac" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-iac-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Infrastructure as code</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">IaC for any cloud, in any language — Node.js, Python, Go, .NET, Java, and YAML</span></span></a></li></ul></div><div class="flex flex-col gap-1 col-span-full"><span class="px-3 pt-2 font-mono text-xs uppercase tracking-wide text-gray-600">Key capabilities</span><ul class="grid gap-x-6 gap-y-0.5 grid-cols-2"><li><a href="/product/neo/" data-track="header-product-neo" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--fill size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-neo-fill"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">AI infrastructure agent</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Meet Neo, our AI-powered infrastructure engineering agent</span></span></a></li><li><a href="/product/secrets-management/" data-track="header-product-secrets" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-secrets-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Secrets & configuration</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Environments, secrets, and configuration management</span></span></a></li><li><a href="/product/discovery-governance/" data-track="header-product-insights" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-insights-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Discovery & governance</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Asset management, compliance remediation, and AI insights over the cloud</span></span></a></li><li><a href="/product/internal-developer-platforms/" data-track="header-product-idp" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-idp-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Internal developer platform</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">The fastest, most secure way to deliver cloud infrastructure</span></span></a></li></ul></div></div></div><div data-nav-content="1" style="position:absolute;top:0;left:0;opacity:0;transform:translateX(0);will-change:opacity,transform"><div class="grid gap-x-6 gap-y-4 p-2 w-[640px] grid-cols-2"><div class="flex flex-col gap-1 col-span-full"><ul class="grid gap-x-6 gap-y-0.5 grid-cols-2"><li><a href="/docs/get-started/" data-track="header-engineers-get-started" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-rocket-launch-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Get started</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Install Pulumi and deploy your first project in minutes</span></span></a></li><li><a href="/docs/" data-track="header-engineers-docs" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-book-open-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Documentation</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Complete guides and API references</span></span></a></li><li><a href="/registry/" data-track="header-engineers-registry" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-package-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Registry</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Browse hundreds of cloud providers and packages</span></span></a></li><li><a href="/dev/" data-track="header-engineers-learn" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-compass-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Dev Center</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Tutorials, templates, examples, and more</span></span></a></li><li><a href="/events#upcoming" data-track="header-engineers-events" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-calendar-blank-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Events and workshops</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Live sessions and workshops</span></span></a></li><li><a href="/community/" data-track="header-engineers-community" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-users-three-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Community</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Join 10k+ developers on Slack</span></span></a></li><li><a href="/testimonials/" data-track="header-engineers-testimonials" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-heart-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Engineers love Pulumi</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Hear from engineers why they love us</span></span></a></li><li><a href="/releases/" data-track="header-engineers-releases" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-megaphone-simple-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Releases</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Major platform updates from the team</span></span></a></li></ul></div></div></div><div data-nav-content="2" style="position:absolute;top:0;left:0;opacity:0;transform:translateX(0);will-change:opacity,transform"><div class="grid gap-x-6 gap-y-4 p-2 w-[320px] grid-cols-1"><div class="flex flex-col gap-1"><ul class="grid gap-x-6 gap-y-0.5 grid-cols-1"><li><a href="/enterprise/" data-track="header-enterprise-solutions" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-buildings-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Enterprise solutions</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Security, compliance, and support for teams</span></span></a></li><li><a href="/case-studies/" data-track="header-enterprise-case-studies" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-article-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Case studies</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">How Snowflake, Mercedes-Benz, and others use Pulumi</span></span></a></li><li><a href="/request-a-demo/" data-track="header-enterprise-demo" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-chalkboard-teacher-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Request a demo</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">See how Pulumi can help your team</span></span></a></li><li><a href="/proserv/" data-track="header-enterprise-proserv" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-briefcase-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Professional services</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Get expert help with your implementation</span></span></a></li><li><a href="/contact/" data-track="header-enterprise-contact" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-chat-circle-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Contact sales</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Talk to our team about your needs</span></span></a></li></ul></div></div></div><div data-nav-content="3" style="position:absolute;top:0;left:0;opacity:0;transform:translateX(0);will-change:opacity,transform"><div class="grid gap-x-6 gap-y-4 p-2 w-[320px] grid-cols-1"><div class="flex flex-col gap-1"><ul class="grid gap-x-6 gap-y-0.5 grid-cols-1"><li><a href="/about/" data-track="header-company-about" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-quotes-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">About us</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Our purpose and values</span></span></a></li><li><a href="/careers/" data-track="header-company-careers" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-briefcase-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Careers</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Come work for Pulumi</span></span></a></li><li><a href="/about/newsroom/" data-track="header-company-newsroom" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-newspaper-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Newsroom</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Pulumi in the news</span></span></a></li><li><a href="/awards/" data-track="header-company-awards" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-trophy-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Awards</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Recognition from press and analysts</span></span></a></li></ul></div></div></div></div></div></nav><div class="flex items-center gap-2"><a href="https://github.com/pulumi/pulumi" target="_blank" rel="noopener" data-track="header-github-stars" class="btn btn-ghost-nav px-2.5 gap-1.5 hidden nav-desktop:inline-flex" aria-label="Star pulumi/pulumi on GitHub — 25669 stars"><svg class="ph-icon size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-github"/></svg>
<span>25.7K</span></a>
<a href="/contact/" data-track="header-contact" class="hidden nav-desktop:inline-flex btn btn-outline">Contact us
</a><a href="https://app.pulumi.com/signin" data-track="header-console" data-nav-loggedout class="hidden nav-desktop:inline-flex btn btn-outline">Sign in
</a><a href="https://app.pulumi.com" data-track="header-dashboard" data-nav-dashboard class="hidden nav-desktop:inline-flex btn btn-primary">Dashboard
</a><a href="https://app.pulumi.com/signup" data-track="header-signup" data-role="cta-get-started" data-nav-loggedout class="hidden nav-desktop:inline-flex btn btn-primary">Get started</a><div class="flex gap-2 nav-desktop:hidden"><div class="max-sm:hidden flex gap-2"><a href="https://github.com/pulumi/pulumi" target="_blank" rel="noopener" data-track="header-github-stars-mobile" class="btn btn-ghost-nav px-2.5 gap-1.5 inline-flex" aria-label="Star pulumi/pulumi on GitHub — 25669 stars"><svg class="ph-icon size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-github"/></svg>
<span>25.7K</span></a>
<a href="/contact/" data-track="header-contact" class="btn btn-outline">Contact us
</a><a href="https://app.pulumi.com/signin" data-track="header-console" data-nav-loggedout class="btn btn-outline">Sign in
</a><a href="https://app.pulumi.com" data-track="header-dashboard" data-nav-dashboard class="btn btn-primary">Dashboard
</a><a href="https://app.pulumi.com/signup" data-track="header-signup-mobile" data-role="cta-get-started" data-nav-loggedout class="btn btn-primary">Get started</a></div><button type="button" data-nav-sheet-trigger aria-label="Open navigation" aria-expanded="false" aria-controls="nav-mobile-sheet" class="btn btn-outline btn-icon">
<svg class="ph-icon ph-icon--bold size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-list-bold"/></svg></button></div></div></div></header><div data-nav-sheet-overlay data-state="closed" class="fixed inset-0 z-50 bg-black/10 opacity-0 pointer-events-none transition-opacity duration-150
data-[state=open]:opacity-100 data-[state=open]:pointer-events-auto
supports-[backdrop-filter]:backdrop-blur-xs"></div><aside data-nav-sheet data-state="closed" data-side="right" id="nav-mobile-sheet" role="dialog" aria-modal="true" aria-labelledby="nav-mobile-sheet-title" class="fixed inset-y-0 right-0 z-50 flex w-3/4 flex-col gap-0 border-l border-gray-100 bg-white text-gray-950 shadow-lg opacity-0 pointer-events-none translate-x-[2.5rem] transition duration-200 ease-in-out p-0 sm:max-w-md
data-[state=open]:translate-x-0 data-[state=open]:opacity-100 data-[state=open]:pointer-events-auto"><div class="flex flex-col gap-1.5 p-4"><h2 id="nav-mobile-sheet-title" class="sr-only">Navigation</h2><button type="button" data-nav-sheet-close aria-label="Close navigation" class="btn btn-ghost btn-icon-sm absolute top-4 right-4">
<svg class="ph-icon ph-icon--bold size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-x-bold"/></svg></button></div><nav class="flex flex-1 flex-col overflow-y-auto px-3 py-2"><div data-nav-collapsible class="border-b border-gray-100"><button type="button" data-nav-collapsible-trigger aria-expanded="false" aria-controls="nav-mobile-panel-product" class="group flex w-full items-center justify-between rounded-md px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">
Product
<svg class="ph-icon ph-icon--bold size-4 transition-transform duration-200 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button><div data-nav-collapsible-panel data-state="closed" inert id="nav-mobile-panel-product" class="overflow-hidden max-h-0 opacity-0 transition-all duration-200
data-[state=open]:max-h-[2000px] data-[state=open]:opacity-100"><div class="flex flex-col gap-3 pb-3"><div class="flex flex-col gap-1"><span class="px-3 pt-2 font-mono text-xs uppercase tracking-wide text-gray-600">Core product</span><ul class="flex flex-col gap-0.5"><li><a href="/product/" data-nav-sheet-close data-track="header-product-platform" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-cloud-arrow-up-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Platform overview</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Everything platform engineering teams need to build, secure, and scale cloud infrastructure</span></span></a></li><li><a href="/product/infrastructure-as-code/" data-nav-sheet-close data-track="header-product-iac" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-iac-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Infrastructure as code</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">IaC for any cloud, in any language — Node.js, Python, Go, .NET, Java, and YAML</span></span></a></li></ul></div><div class="flex flex-col gap-1"><span class="px-3 pt-2 font-mono text-xs uppercase tracking-wide text-gray-600">Key capabilities</span><ul class="flex flex-col gap-0.5"><li><a href="/product/neo/" data-nav-sheet-close data-track="header-product-neo" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--fill size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-neo-fill"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">AI infrastructure agent</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Meet Neo, our AI-powered infrastructure engineering agent</span></span></a></li><li><a href="/product/secrets-management/" data-nav-sheet-close data-track="header-product-secrets" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-secrets-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Secrets & configuration</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Environments, secrets, and configuration management</span></span></a></li><li><a href="/product/discovery-governance/" data-nav-sheet-close data-track="header-product-insights" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-insights-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Discovery & governance</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Asset management, compliance remediation, and AI insights over the cloud</span></span></a></li><li><a href="/product/internal-developer-platforms/" data-nav-sheet-close data-track="header-product-idp" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#c-pulumi-idp-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Internal developer platform</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">The fastest, most secure way to deliver cloud infrastructure</span></span></a></li></ul></div></div></div></div><div data-nav-collapsible class="border-b border-gray-100"><button type="button" data-nav-collapsible-trigger aria-expanded="false" aria-controls="nav-mobile-panel-for-engineers" class="group flex w-full items-center justify-between rounded-md px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">
For engineers
<svg class="ph-icon ph-icon--bold size-4 transition-transform duration-200 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button><div data-nav-collapsible-panel data-state="closed" inert id="nav-mobile-panel-for-engineers" class="overflow-hidden max-h-0 opacity-0 transition-all duration-200
data-[state=open]:max-h-[2000px] data-[state=open]:opacity-100"><div class="flex flex-col gap-3 pb-3"><div class="flex flex-col gap-1"><ul class="flex flex-col gap-0.5"><li><a href="/docs/get-started/" data-nav-sheet-close data-track="header-engineers-get-started" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-rocket-launch-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Get started</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Install Pulumi and deploy your first project in minutes</span></span></a></li><li><a href="/docs/" data-nav-sheet-close data-track="header-engineers-docs" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-book-open-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Documentation</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Complete guides and API references</span></span></a></li><li><a href="/registry/" data-nav-sheet-close data-track="header-engineers-registry" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-package-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Registry</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Browse hundreds of cloud providers and packages</span></span></a></li><li><a href="/dev/" data-nav-sheet-close data-track="header-engineers-learn" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-compass-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Dev Center</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Tutorials, templates, examples, and more</span></span></a></li><li><a href="/events#upcoming" data-nav-sheet-close data-track="header-engineers-events" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-calendar-blank-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Events and workshops</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Live sessions and workshops</span></span></a></li><li><a href="/community/" data-nav-sheet-close data-track="header-engineers-community" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-users-three-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Community</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Join 10k+ developers on Slack</span></span></a></li><li><a href="/testimonials/" data-nav-sheet-close data-track="header-engineers-testimonials" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-heart-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Engineers love Pulumi</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Hear from engineers why they love us</span></span></a></li><li><a href="/releases/" data-nav-sheet-close data-track="header-engineers-releases" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-megaphone-simple-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Releases</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Major platform updates from the team</span></span></a></li></ul></div></div></div></div><div data-nav-collapsible class="border-b border-gray-100"><button type="button" data-nav-collapsible-trigger aria-expanded="false" aria-controls="nav-mobile-panel-for-enterprises" class="group flex w-full items-center justify-between rounded-md px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">
For enterprises
<svg class="ph-icon ph-icon--bold size-4 transition-transform duration-200 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button><div data-nav-collapsible-panel data-state="closed" inert id="nav-mobile-panel-for-enterprises" class="overflow-hidden max-h-0 opacity-0 transition-all duration-200
data-[state=open]:max-h-[2000px] data-[state=open]:opacity-100"><div class="flex flex-col gap-3 pb-3"><div class="flex flex-col gap-1"><ul class="flex flex-col gap-0.5"><li><a href="/enterprise/" data-nav-sheet-close data-track="header-enterprise-solutions" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-buildings-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Enterprise solutions</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Security, compliance, and support for teams</span></span></a></li><li><a href="/case-studies/" data-nav-sheet-close data-track="header-enterprise-case-studies" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-article-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Case studies</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">How Snowflake, Mercedes-Benz, and others use Pulumi</span></span></a></li><li><a href="/request-a-demo/" data-nav-sheet-close data-track="header-enterprise-demo" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-chalkboard-teacher-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Request a demo</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">See how Pulumi can help your team</span></span></a></li><li><a href="/proserv/" data-nav-sheet-close data-track="header-enterprise-proserv" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-briefcase-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Professional services</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Get expert help with your implementation</span></span></a></li><li><a href="/contact/" data-nav-sheet-close data-track="header-enterprise-contact" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-chat-circle-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Contact sales</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Talk to our team about your needs</span></span></a></li></ul></div></div></div></div><a href="/docs/" data-nav-sheet-close data-track="header-docs" class="block rounded-md border-b border-gray-100 px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">Docs
</a><a href="/registry/" data-nav-sheet-close data-track="header-registry" class="block rounded-md border-b border-gray-100 px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">Registry
</a><a href="/blog/" data-nav-sheet-close data-track="header-blog" class="block rounded-md border-b border-gray-100 px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">Blog
</a><a href="/pricing/" data-nav-sheet-close data-track="header-pricing" class="block rounded-md border-b border-gray-100 px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">Pricing</a><div data-nav-collapsible class="border-b border-gray-100"><button type="button" data-nav-collapsible-trigger aria-expanded="false" aria-controls="nav-mobile-panel-company" class="group flex w-full items-center justify-between rounded-md px-3 py-4 text-base font-semibold text-gray-950 outline-none transition-colors hover:text-violet-700 focus-visible:text-violet-700 focus-visible:ring-3 focus-visible:ring-violet-400/50 focus-visible:outline-1">
Company
<svg class="ph-icon ph-icon--bold size-4 transition-transform duration-200 [[data-open=true]_&]:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-bold"/></svg></button><div data-nav-collapsible-panel data-state="closed" inert id="nav-mobile-panel-company" class="overflow-hidden max-h-0 opacity-0 transition-all duration-200
data-[state=open]:max-h-[2000px] data-[state=open]:opacity-100"><div class="flex flex-col gap-3 pb-3"><div class="flex flex-col gap-1"><ul class="flex flex-col gap-0.5"><li><a href="/about/" data-nav-sheet-close data-track="header-company-about" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-quotes-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">About us</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Our purpose and values</span></span></a></li><li><a href="/careers/" data-nav-sheet-close data-track="header-company-careers" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-briefcase-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Careers</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Come work for Pulumi</span></span></a></li><li><a href="/about/newsroom/" data-nav-sheet-close data-track="header-company-newsroom" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-newspaper-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Newsroom</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Pulumi in the news</span></span></a></li><li><a href="/awards/" data-nav-sheet-close data-track="header-company-awards" class="group flex flex-row items-start gap-3 rounded-md p-3 outline-none transition-all hover:bg-violet-50 focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span aria-hidden="true" class="mt-0.5 flex size-8 shrink-0 items-center justify-center rounded-md border group-hover:border-violet-200 border-gray-200 group-hover text-violet-700"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-trophy-regular"/></svg>
</span><span class="flex min-w-0 flex-col gap-0.5"><span class="text-sm font-semibold text-gray-950 group-hover:text-violet-primary">Awards</span>
<span class="text-xs text-gray-600 group-hover:text-gray-800">Recognition from press and analysts</span></span></a></li></ul></div></div></div></div></nav><div class="flex flex-col gap-2 border-t border-gray-100 p-4"><a href="https://github.com/pulumi/pulumi" target="_blank" rel="noopener" data-track="header-github-stars-sheet" class="btn btn-ghost-nav px-2.5 gap-1.5 inline-flex justify-center" aria-label="Star pulumi/pulumi on GitHub — 25669 stars"><svg class="ph-icon size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-github"/></svg>
<span>25.7K</span></a>
<a href="/contact/" data-track="header-contact" class="btn btn-outline">Contact us
</a><a href="https://app.pulumi.com/signin" data-track="header-console" data-nav-loggedout class="btn btn-outline">Sign in
</a><a href="https://app.pulumi.com" data-track="header-dashboard" data-nav-dashboard class="btn btn-primary">Dashboard
</a><a href="https://app.pulumi.com/signup" data-track="header-signup-mobile" data-role="cta-get-started" data-nav-loggedout class="btn btn-primary">Get started</a></div></aside><div data-brand-menu role="menu" aria-label="Pulumi logo options" hidden class="card fixed z-50 min-w-[220px] bg-white p-2 text-gray-950 shadow"><ul class="flex flex-col gap-0.5"><li role="none"><button type="button" role="menuitem" data-brand-menu-copy class="flex w-full items-center justify-between gap-3 rounded-md px-3 py-2 text-left text-sm font-normal text-gray-950 outline-none transition-colors hover:bg-violet-50 hover:text-violet-primary focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50">
<span data-brand-menu-copy-label>Copy logo SVG</span></button></li><li role="none"><a role="menuitem" data-brand-menu-close href="/logos/brand/pulumi_mark_on_light.svg" download="pulumi-logo-mark-color.svg" class="flex w-full items-center justify-between gap-3 rounded-md px-3 py-2 text-left text-sm font-normal text-gray-950 outline-none transition-colors hover:bg-violet-50 hover:text-violet-primary focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50">Download mark</a></li><li role="none"><a role="menuitem" data-brand-menu-close href="https://brand.pulumi.com/identity/logo/#get-the-logo" target="_blank" rel="noopener" class="flex w-full items-center justify-between gap-3 rounded-md px-3 py-2 text-left text-sm font-normal text-gray-950 outline-none transition-colors hover:bg-violet-50 hover:text-violet-primary focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span>Get other variants</span><svg class="ph-icon ph-icon--regular size-3.5 shrink-0 text-gray-400" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-arrow-square-out-regular"/></svg></a></li><li role="none"><a role="menuitem" data-brand-menu-close href="https://brand.pulumi.com" target="_blank" rel="noopener" class="flex w-full items-center justify-between gap-3 rounded-md px-3 py-2 text-left text-sm font-normal text-gray-950 outline-none transition-colors hover:bg-violet-50 hover:text-violet-primary focus-visible:bg-violet-50 focus-visible:ring-3 focus-visible:ring-violet-400/50"><span>Read brand guide</span><svg class="ph-icon ph-icon--regular size-3.5 shrink-0 text-gray-400" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-arrow-square-out-regular"/></svg></a></li></ul></div><script src="/js/header-nav.a99ba15a.js" defer></script><main id="main" tabindex="-1" class="focus:outline-none flex-1"><div class="blog-header border-b border-gray-200"><div class="container mx-auto flex flex-nowrap items-center justify-between gap-4 px-4 py-6 lg:h-26 lg:py-0"><div class="flex min-w-0 items-center gap-3 lg:gap-4"><div class="heading-2 m-0! flex min-w-0 items-center gap-2"><a href="/blog/" class="shrink-0 text-service-black transition-colors hover:text-violet-primary">Blog</a></div></div><div class="flex shrink-0 items-center"><div class="hidden items-center xl:flex mr-4"><pulumi-hubspot-form form-id="027b4c6d-9b73-4ad8-b149-3c8b07fff608" class="newsletter newsletter-inline newsletter-header newsletter-btn-outline"></pulumi-hubspot-form></div><div><div id="search" data-app-id="P6KICOKU8E" data-search-key="9ac9f1177f81bc8cb5f6cf30485e62db" data-facets="Blog" data-index="production"></div></div><a href="/blog/rss.xml" target="_blank" rel="noopener" aria-label="Pulumi Blog RSS feed" data-track="blog-rss" class="btn btn-icon btn-ghost shrink-0"><svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-rss-regular"/></svg></a></div></div></div><div data-post-progress aria-hidden="true" style="transform:scaleX(0)" class="fixed inset-x-0 top-16 z-30 h-[3px] origin-left bg-violet-primary"></div><div class="mx-auto max-w-[1220px] px-4 py-8 lg:py-10"><header class="grid grid-cols-1 items-center gap-8"><div class="order-2 flex flex-col items-start gap-5 lg:order-1"><a href="/blog/category/best-practices/" data-track="blog-category-best-practices" class="relative z-10 badge badge-outline">Best Practices</a><h1 class="heading-xl m-0!">Kubernetes Best Practices I Wish I Had Known Before</h1><div class="body-sm flex flex-wrap items-center gap-1.5"><time datetime="2025-01-20">Jan 20, 2025</time>
<span aria-hidden="true" class="text-gray-500">•</span><span>Updated Apr 30, 2026</span>
<span aria-hidden="true" class="text-gray-500">•</span><span class="whitespace-nowrap">17 min read</span></div><div class="flex flex-wrap items-center gap-x-6 gap-y-3"><span class="flex items-center gap-2"><a href="/community/team/engin-diri/" data-track="blog-author-engin-diri" class="flex items-center gap-2"><img src="/images/team/engin-diri.jpg" alt="Engin Diri" class="size-8 rounded-full bg-violet-200 object-cover border border-gray-100" loading="lazy" decoding="async">
<span class="body-sm text-service-black transition-colors hover:text-violet-primary">Engin Diri</span></a></span></div></div></header><hr class="my-8 border-gray-200 lg:my-10"><div class="lg:flex lg:gap-12"><div class="min-w-0 lg:flex-1"><div class="mb-8 empty:hidden md:hidden"><details class="group border-b py-3 -mt-8"><summary class="flex cursor-pointer list-none items-center justify-between gap-4 marker:hidden [&::-webkit-details-marker]:hidden"><span class="font-overline-sm text-service-black">In this post</span>
<svg class="ph-icon ph-icon--regular size-4 shrink-0 text-gray-500 transition-transform group-open:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-regular"/></svg></summary><ul class="m-0 mt-4 flex list-none flex-col gap-3 p-0"><li class="m-0 leading-snug"><a href="#tldr-20-kubernetes-best-practices-for-2026" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">TL;DR: 20 Kubernetes best practices for 2026</a></li><li class="m-0 leading-snug"><a href="#what-are-kubernetes-best-practices" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">What are Kubernetes best practices?</a></li><li class="m-0 leading-snug"><a href="#common-kubernetes-anti-patterns-vs-the-correct-approach" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">Common Kubernetes anti-patterns vs. the correct approach</a></li><li class="m-0 leading-snug"><a href="#1-how-do-you-set-kubernetes-resource-requests-and-limits" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">1. How do you set Kubernetes resource requests and limits?</a></li><li class="m-0 leading-snug"><a href="#2-how-should-you-structure-kubernetes-namespaces" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">2. How should you structure Kubernetes namespaces?</a></li><li class="m-0 leading-snug"><a href="#3-should-you-run-multiple-containers-in-one-pod" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">3. Should you run multiple containers in one Pod?</a></li><li class="m-0 leading-snug"><a href="#4-should-you-use-helm-kustomize-or-pulumi-for-kubernetes-manifests" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">4. Should you use Helm, Kustomize, or Pulumi for Kubernetes manifests?</a></li><li class="m-0 leading-snug"><a href="#5-how-should-you-handle-ingress-and-networking-on-kubernetes-in-2026" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">5. How should you handle ingress and networking on Kubernetes in 2026?</a></li><li class="m-0 leading-snug"><a href="#6-whats-the-difference-between-liveness-readiness-and-startup-probes" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">6. What&rsquo;s the difference between liveness, readiness, and startup probes?</a></li><li class="m-0 leading-snug"><a href="#7-how-do-you-secure-a-kubernetes-cluster" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">7. How do you secure a Kubernetes cluster?</a></li><li class="m-0 leading-snug"><a href="#8-how-do-you-set-up-kubernetes-observability" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">8. How do you set up Kubernetes observability?</a></li><li class="m-0 leading-snug"><a href="#9-how-do-you-automate-kubernetes-deployments-with-gitops" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">9. How do you automate Kubernetes deployments with GitOps?</a></li><li class="m-0 leading-snug"><a href="#10-how-often-should-you-upgrade-kubernetes" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">10. How often should you upgrade Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#11-how-should-you-label-and-annotate-kubernetes-resources" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">11. How should you label and annotate Kubernetes resources?</a></li><li class="m-0 leading-snug"><a href="#12-how-should-you-separate-kubernetes-environments" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">12. How should you separate Kubernetes environments?</a></li><li class="m-0 leading-snug"><a href="#13-how-do-you-optimize-kubernetes-container-images" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">13. How do you optimize Kubernetes container images?</a></li><li class="m-0 leading-snug"><a href="#14-whats-a-reliable-kubernetes-logging-strategy" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">14. What&rsquo;s a reliable Kubernetes logging strategy?</a></li><li class="m-0 leading-snug"><a href="#15-how-should-you-autoscale-workloads-on-kubernetes" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">15. How should you autoscale workloads on Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#16-how-do-you-enforce-policy-as-code-on-kubernetes" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">16. How do you enforce policy-as-code on Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#17-how-do-you-secure-the-kubernetes-software-supply-chain" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">17. How do you secure the Kubernetes software supply chain?</a></li><li class="m-0 leading-snug"><a href="#18-how-do-you-manage-kubernetes-cost-finops" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">18. How do you manage Kubernetes cost (FinOps)?</a></li><li class="m-0 leading-snug"><a href="#19-why-should-you-treat-kubernetes-clusters-as-cattle-not-pets" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">19. Why should you treat Kubernetes clusters as cattle, not pets?</a></li><li class="m-0 leading-snug"><a href="#20-why-use-pulumi-to-manage-kubernetes" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">20. Why use Pulumi to manage Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#final-thoughts" data-track="blog-toc" class="block font-semibold text-service-black transition-colors hover:text-violet-primary">Final thoughts</a></li></ul></details></div><section class="blog-post-content max-w-3xl"><p><strong>Kubernetes best practices</strong> are the production-tested rules that keep clusters reliable, secure, and affordable: set resource requests and limits on every container, isolate workloads with namespaces and NetworkPolicies, enforce least-privilege RBAC, automate health checks, ship via GitOps, validate every change with policy-as-code, generate an SBOM for every image, and manage Kubernetes itself with infrastructure as code instead of hand-rolled YAML. The 20 practices below cover what production teams actually do in 2026 — not what tutorials suggest.</p><h2 id="tldr-20-kubernetes-best-practices-for-2026">TL;DR: 20 Kubernetes best practices for 2026</h2><ol><li>Set resource <strong>requests and limits</strong> on every container.</li><li>Use <strong>namespaces</strong> plus <strong>ResourceQuota</strong> and <strong>LimitRange</strong> for isolation.</li><li>Run <strong>one container per Pod</strong> unless you genuinely need a sidecar.</li><li>Manage manifests with <strong>Helm, Kustomize, or Pulumi</strong> — never raw copies.</li><li>Use the <strong>Gateway API</strong> (ingress-nginx is retired) for north-south traffic.</li><li>Configure <strong>liveness, readiness, and startup probes</strong> for every workload.</li><li>Enforce <strong>RBAC</strong> with the principle of least privilege from day one.</li><li>Apply <strong>Pod Security Admission</strong> at the <code>restricted</code> level by default.</li><li>Lock down east-west traffic with <strong>NetworkPolicy</strong> (default-deny).</li><li>Store secrets in an <strong>external secret manager</strong> (Pulumi ESC, Vault, AWS Secrets Manager) — not as plain Kubernetes Secrets.</li><li>Autoscale with <strong>HPA, VPA, and Cluster Autoscaler / Karpenter</strong>.</li><li>Monitor with <strong>Prometheus, Grafana, and OpenTelemetry</strong>; alert before users do.</li><li>Deploy with <strong>GitOps</strong> (Argo CD or Flux) — Git is the only source of truth.</li><li>Gate every change with <strong>policy-as-code</strong> (Pulumi CrossGuard, OPA/Gatekeeper, Kyverno).</li><li>Generate and verify an <strong>SBOM</strong> for every image; sign with <strong>Sigstore/cosign</strong>.</li><li>Manage cost with <strong>FinOps</strong> practices: right-size, schedule, and chargeback by namespace.</li><li>Keep clusters and add-ons <strong>patched</strong> on a documented cadence.</li><li>Use <strong>labels and annotations</strong> consistently for ownership, cost, and SLO tracking.</li><li>Separate <strong>dev, staging, and prod</strong> clusters — or virtualize with vCluster.</li><li>Treat clusters as <strong>cattle, not pets</strong>: rebuild from code, never edit live.</li></ol><blockquote><p><strong>Last updated April 30, 2026</strong> — added GitOps, policy-as-code, SBOM/supply-chain, autoscaling, NetworkPolicy, and FinOps sections; added an anti-pattern table; restructured headings around the questions teams actually ask.</p></blockquote><div class="note note-info"><div class="icon-and-line"><svg class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-info-fill"/></svg><div class="line"></div></div><div class="content"><p>Going to <a href="https://www.pulumi.com/kubecon/">KubeCon Europe 2026</a>? Tame Kubernetes complexity with code.</p><p>Pulumi demos, platform engineering talks, AI-powered Neo in action, and yes, free plushies. <a href="https://www.pulumi.com/kubecon/">Booth 784</a>.</p></div></div><figure><img src="/blog/kubernetes-best-practices-i-wish-i-had-known-before/img.png" alt="The 'Kubernetes is easy'-iceberg meme is a classic example of how Kubernetes can be deceivingly complex" width="100%"><figcaption><p>The &lsquo;Kubernetes is easy&rsquo;-iceberg meme is a classic example of how Kubernetes can be deceivingly complex</p></figcaption></figure><h2 id="what-are-kubernetes-best-practices">What are Kubernetes best practices?</h2><p>Kubernetes best practices are the operational patterns that keep workloads available, secure, observable, and cost-efficient on a Kubernetes cluster. They span four areas: <strong>workload configuration</strong> (resources, probes, images), <strong>security</strong> (RBAC, NetworkPolicy, Pod Security, secrets, supply chain), <strong>delivery</strong> (GitOps, policy-as-code, IaC), and <strong>platform operations</strong> (autoscaling, monitoring, upgrades, FinOps). The rest of this post explains each one with a copy-pasteable rule, a definition of the underlying Kubernetes object, and a common anti-pattern to avoid.</p><h2 id="common-kubernetes-anti-patterns-vs-the-correct-approach">Common Kubernetes anti-patterns vs. the correct approach</h2><div class="table-wrapper table-responsive"><table><thead><tr><th>Common mistake</th><th>What goes wrong</th><th>Correct approach</th></tr></thead><tbody><tr><td data-label="Common mistake">No resource requests or limits</td><td data-label="What goes wrong">Noisy-neighbor evictions, OOMKills, unschedulable Pods</td><td data-label="Correct approach">Set requests for <strong>every</strong> container; use VPA recommendations to tune</td></tr><tr><td data-label="Common mistake">Everything in the <code>default</code> namespace</td><td data-label="What goes wrong">No isolation, no quota, no RBAC boundary</td><td data-label="Correct approach">One namespace per team or environment + ResourceQuota + RBAC</td></tr><tr><td data-label="Common mistake"><code>cluster-admin</code> for service accounts</td><td data-label="What goes wrong">Full-cluster blast radius on compromise</td><td data-label="Correct approach">Per-namespace Role + RoleBinding (least privilege)</td></tr><tr><td data-label="Common mistake">Plain Kubernetes <code>Secret</code> objects</td><td data-label="What goes wrong">Base64 ≠ encryption; secrets leak via etcd, kubectl, audit logs</td><td data-label="Correct approach">External Secrets Operator + <a href="/docs/esc/">Pulumi ESC</a>, Vault, or AWS Secrets Manager</td></tr><tr><td data-label="Common mistake">Open east-west traffic</td><td data-label="What goes wrong">One compromised Pod can reach every service</td><td data-label="Correct approach">Default-deny NetworkPolicy; allow only required flows</td></tr><tr><td data-label="Common mistake"><code>kubectl apply -f</code> from a laptop</td><td data-label="What goes wrong">No history, no review, no rollback</td><td data-label="Correct approach">GitOps with Argo CD or Flux; Git is the source of truth</td></tr><tr><td data-label="Common mistake">Manual <code>latest</code> image tags</td><td data-label="What goes wrong">Non-reproducible deploys, supply-chain risk</td><td data-label="Correct approach">Pinned digests (<code>@sha256:...</code>) with cosign verification</td></tr><tr><td data-label="Common mistake">Ingress-nginx in 2026</td><td data-label="What goes wrong">Project retired March 2026 — no security fixes</td><td data-label="Correct approach">Migrate to the Gateway API (Envoy Gateway, Istio, Kgateway)</td></tr><tr><td data-label="Common mistake">Hand-rolled YAML in dozens of repos</td><td data-label="What goes wrong">Drift, copy-paste bugs, no testing</td><td data-label="Correct approach"><a href="/docs/iac/get-started/kubernetes/">Pulumi</a>, Helm, or Kustomize with reviews</td></tr><tr><td data-label="Common mistake">One shared <code>prod</code> cluster for everything</td><td data-label="What goes wrong">Blast radius spans every team</td><td data-label="Correct approach">Separate clusters or <a href="https://www.vcluster.com/">vCluster</a> virtual clusters</td></tr></tbody></table></div><h2 id="1-how-do-you-set-kubernetes-resource-requests-and-limits">1. How do you set Kubernetes resource requests and limits?</h2><p><strong>What are resource requests and limits?</strong> A resource <em>request</em> is the minimum CPU and memory the kube-scheduler guarantees a container; a resource <em>limit</em> is the maximum the kubelet allows it to consume before throttling CPU or OOMKilling memory. Pods without requests are scheduled blind, so a noisy neighbor can evict your workload at any time.</p><p><strong>The rule:</strong> every container in production sets a request for both CPU and memory, and a memory limit. CPU limits are optional and frequently counter-productive — they cause throttling spikes that look like outages.</p><ul><li>Start at <strong>100–200m CPU and 128–512Mi memory</strong> for a typical web service.</li><li>Tune from real data using <strong>Vertical Pod Autoscaler</strong> with <code>updateMode: Off</code> (recommendation-only) or Prometheus histograms.</li><li>Use a per-namespace <code>LimitRange</code> so teams cannot ship a container with no requests at all.</li></ul><h2 id="2-how-should-you-structure-kubernetes-namespaces">2. How should you structure Kubernetes namespaces?</h2><p><strong>What is a Kubernetes namespace?</strong> A namespace is a logical partition of cluster resources. It scopes object names, RBAC bindings, NetworkPolicies, and quotas — but does not provide hard isolation by itself.</p><p><strong>The rule:</strong> never deploy production workloads to <code>default</code>. Map namespaces to ownership boundaries — usually one per team, environment, or tenant — and pair every namespace with three things:</p><ul><li>A <strong><code>ResourceQuota</code></strong> to cap aggregate CPU, memory, and object counts.</li><li>A <strong><code>LimitRange</code></strong> to enforce per-container defaults.</li><li>A <strong><code>RoleBinding</code></strong> that grants only the permissions that team needs.</li></ul><p>This is the smallest unit that gives you predictable cost, blast-radius containment, and an RBAC perimeter.</p><h2 id="3-should-you-run-multiple-containers-in-one-pod">3. Should you run multiple containers in one Pod?</h2><p><strong>What is a Pod?</strong> A Pod is the smallest deployable unit in Kubernetes — one or more containers that share a network namespace, IPC, and storage volumes, and that are scheduled and scaled as a single unit.</p><p><strong>The rule:</strong> one container per Pod by default. Add a second container only when it must share the Pod&rsquo;s network or volumes — for example, a service-mesh sidecar (Istio/Linkerd), a logging shipper, or an <a href="https://kubernetes.io/docs/concepts/workloads/pods/init-containers/">init container</a> that prepares state before the main process starts. Multi-container Pods couple lifecycles and scaling, so reach for them deliberately, not by default.</p><div class="note note-tip"><div class="icon-and-line"><svg class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-lightbulb-fill"/></svg><div class="line"></div></div><div class="content"><p><strong>You might also like:</strong></p><ul><li><a href="https://www.pulumi.com/blog/master-kubernetes-secrets-with-pulumi-esc-secrets-store-csi-driver/">Master Kubernetes Secrets with Pulumi ESC + Secrets Store CSI Driver</a></li><li><a href="https://www.pulumi.com/blog/aws-eks-auto-mode/">Getting Started with Amazon EKS Auto Mode in Pulumi</a></li><li><a href="https://www.pulumi.com/blog/why-every-platform-engineer-should-care-about-kubernetes-operators/">Why Every Platform Engineer Should Care About Kubernetes Operators</a></li></ul></div></div><h2 id="4-should-you-use-helm-kustomize-or-pulumi-for-kubernetes-manifests">4. Should you use Helm, Kustomize, or Pulumi for Kubernetes manifests?</h2><p><strong>The rule:</strong> never copy-paste raw YAML across services. Pick one of these:</p><ul><li><strong><a href="https://helm.sh/">Helm</a></strong> — Go-templated charts; the de-facto distribution format for off-the-shelf software (Prometheus, cert-manager, Argo CD).</li><li><strong><a href="https://kustomize.io/">Kustomize</a></strong> — overlay-based, no templating; ships in <code>kubectl</code>. Best for &ldquo;same app, different environment&rdquo; diffs.</li><li><strong><a href="/docs/iac/get-started/kubernetes/">Pulumi</a></strong> — real programming languages (TypeScript, Python, Go, Java, .NET) for Kubernetes plus the cloud resources around it (EKS, GKE, AKS, DNS, IAM). Type checking, tests, and the Pulumi <a href="/docs/integrations/clouds/kubernetes/pulumi-kubernetes-operator/">Kubernetes Operator</a> for GitOps-style reconciliation.</li></ul><p>If you are already managing cloud infrastructure with code, extending the same Pulumi program to Kubernetes is the smallest cognitive jump — the cluster, its IAM, its DNS, and its workloads live in one stack and one review.</p><h2 id="5-how-should-you-handle-ingress-and-networking-on-kubernetes-in-2026">5. How should you handle ingress and networking on Kubernetes in 2026?</h2><p><strong>What is the Gateway API?</strong> The <a href="https://gateway-api.sigs.k8s.io/">Gateway API</a> is the successor to the legacy <code>Ingress</code> resource. It splits responsibility between infrastructure (<code>GatewayClass</code>, <code>Gateway</code>) and application (<code>HTTPRoute</code>, <code>GRPCRoute</code>, <code>TLSRoute</code>) teams, and it is the SIG-Network direction for north-south traffic.</p><p><strong>The rule:</strong> new clusters should standardize on the Gateway API. The widely deployed <code>ingress-nginx</code> controller <a href="https://www.pulumi.com/blog/ingress-nginx-to-gateway-api-kgateway/">retired in March 2026</a>, and remaining deployments should migrate to Envoy Gateway, Istio, Linkerd Gateway, or Kgateway.</p><ul><li>Terminate TLS at the gateway and automate certificates with <a href="https://cert-manager.io/">cert-manager</a>.</li><li>Use <strong>path-based and host-based routing</strong> instead of one gateway per service.</li><li>Protect every gateway with a WAF (managed cloud WAF or <a href="https://coraza.io/">Coraza</a> on Envoy).</li></ul><div style="display:flex;align-items:center;justify-content:center;height:100%"><img src="img_1.png" alt="A meme featuring two side-by-side images of Mr. Incredible. The left side shows a normal, happy face labeled “I’M LEARNING KUBERNETES”, while the right side is a dark, distorted version of his face with the same caption, humorously implying the increasing complexity and challenges of learning Kubernetes." style="width:80%;height:100%"></div><div class="note note-info"><div class="icon-and-line"><svg class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-info-fill"/></svg><div class="line"></div></div><div class="content"><p>ingress-nginx is retiring in March 2026.</p><p>Here is a guide on <a href="https://www.pulumi.com/blog/ingress-nginx-to-gateway-api-kgateway/">How to Move to the Gateway API: post ingress-nginx Retirement</a>.</p></div></div><h2 id="6-whats-the-difference-between-liveness-readiness-and-startup-probes">6. What&rsquo;s the difference between liveness, readiness, and startup probes?</h2><p>Probes tell the kubelet whether to restart a container, route traffic to it, or wait for it. Configure them per workload:</p><ul><li><strong>Liveness probe</strong> — restarts a hung container. Use sparingly; a bad liveness probe is a self-inflicted DoS.</li><li><strong>Readiness probe</strong> — gates traffic from Services and Gateway routes. Use for <em>every</em> network-facing workload.</li><li><strong>Startup probe</strong> — gives slow-booting apps (JVM, ML models) time to come up before liveness checks begin. Use whenever cold-start exceeds 10 seconds.</li></ul><p>See <a href="https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/">the upstream guide</a> for HTTP, TCP, and exec probe syntax. Tune <code>failureThreshold</code>, <code>periodSeconds</code>, and <code>timeoutSeconds</code> based on real latency, not defaults.</p><h2 id="7-how-do-you-secure-a-kubernetes-cluster">7. How do you secure a Kubernetes cluster?</h2><p>Cluster security is layered: identity, workload posture, network, and secrets. Get all four right.</p><h3 id="what-is-rbac-in-kubernetes">What is RBAC in Kubernetes?</h3><p><strong>RBAC (Role-Based Access Control)</strong> is the Kubernetes authorization model that maps subjects (users, groups, ServiceAccounts) to verbs (<code>get</code>, <code>list</code>, <code>create</code>, <code>delete</code>) on resources, scoped to a namespace (<code>Role</code>) or the whole cluster (<code>ClusterRole</code>).</p><ul><li>Grant <strong>least privilege</strong> — never bind humans or workloads to <code>cluster-admin</code>.</li><li>Prefer per-namespace <code>Role</code> + <code>RoleBinding</code> over <code>ClusterRoleBinding</code>.</li><li>Audit with <code>kubectl auth can-i --as=...</code> and tools like <a href="https://github.com/FairwindsOps/rbac-lookup"><code>rbac-lookup</code></a>.</li></ul><h3 id="what-is-pod-security-admission">What is Pod Security Admission?</h3><p><a href="https://kubernetes.io/docs/concepts/security/pod-security-admission/">Pod Security Admission</a> is the built-in admission controller that enforces the three Pod Security Standards (<code>privileged</code>, <code>baseline</code>, <code>restricted</code>) at the namespace level.</p><ul><li>Label every namespace <code>pod-security.kubernetes.io/enforce=restricted</code> by default.</li><li>Drop <code>NET_RAW</code> and all capabilities; run as non-root with a read-only root filesystem.</li><li>Use <code>seccompProfile: RuntimeDefault</code> and a tight <code>securityContext</code> for every container.</li></ul><h3 id="what-is-a-networkpolicy">What is a NetworkPolicy?</h3><p>A <strong>NetworkPolicy</strong> is a Kubernetes object that defines allowed ingress and egress traffic for selected Pods at the IP/port level. Without one, every Pod can reach every other Pod by default.</p><ul><li>Apply a <strong>default-deny</strong> ingress and egress policy in every namespace.</li><li>Allow only the flows your service actually needs (DNS, the database, the upstream API).</li><li>For richer L7 controls (mTLS, JWT auth), layer a service mesh on top.</li></ul><h3 id="how-should-you-manage-kubernetes-secrets">How should you manage Kubernetes secrets?</h3><p><strong>Built-in <code>Secret</code> objects are base64-encoded, not encrypted.</strong> Treat them as a transport, not as storage.</p><ul><li>Store the source of truth in <a href="/docs/esc/">Pulumi ESC</a>, <a href="https://www.vaultproject.io/">HashiCorp Vault</a>, <a href="https://aws.amazon.com/secrets-manager/">AWS Secrets Manager</a>, GCP Secret Manager, or Azure Key Vault.</li><li>Project secrets into Pods with the <a href="/docs/esc/integrations/kubernetes/external-secrets-operator/">External Secrets Operator</a> or the <a href="/docs/esc/integrations/kubernetes/secret-store-csi-driver/">Secret Store CSI Driver</a>.</li><li>Enable <strong>etcd encryption-at-rest</strong> with a KMS provider so leaked etcd snapshots stay opaque.</li><li>Rotate automatically; never commit secrets to Git, even encrypted.</li></ul><h2 id="8-how-do-you-set-up-kubernetes-observability">8. How do you set up Kubernetes observability?</h2><p>Observability rests on the three pillars: metrics, logs, and traces. The 2026 default stack is OpenTelemetry-first.</p><ul><li><strong>Metrics</strong> — <a href="https://github.com/prometheus-operator/kube-prometheus">Prometheus</a> (or a Prometheus-compatible TSDB like Mimir, Thanos, VictoriaMetrics) plus Grafana dashboards.</li><li><strong>Logs</strong> — Fluent Bit or the OpenTelemetry Collector shipping structured JSON to Loki, Elastic/OpenSearch, or a managed service. Never depend on <code>kubectl logs</code> for incidents — Pods are ephemeral.</li><li><strong>Traces</strong> — OpenTelemetry SDKs in your apps emitting to Tempo, Jaeger, or a vendor backend. Correlate trace IDs with logs.</li><li><strong>Alerts</strong> — page on <strong>SLO burn rate</strong>, not on every crashed Pod. Burn-rate alerting catches real user impact without firing on every restart.</li></ul><h2 id="9-how-do-you-automate-kubernetes-deployments-with-gitops">9. How do you automate Kubernetes deployments with GitOps?</h2><p><strong>What is GitOps?</strong> <a href="https://opengitops.dev/">GitOps</a> is a deployment model where the desired cluster state lives in a Git repository and a controller continuously reconciles the live cluster to match. Changes happen through pull requests, not <code>kubectl apply</code>.</p><p><strong>The rule:</strong> every cluster has a controller — <a href="https://argoproj.github.io/cd/">Argo CD</a>, <a href="https://fluxcd.io/">Flux</a>, or the <a href="/docs/integrations/clouds/kubernetes/pulumi-kubernetes-operator/">Pulumi Kubernetes Operator</a> — that owns reconciliation. Humans never <code>kubectl apply</code> to production.</p><ul><li>Use <strong>app-of-apps</strong> (Argo) or <strong>Kustomization trees</strong> (Flux) to bootstrap whole clusters from a single root.</li><li>Keep manifests, Helm values, and Pulumi stack references in Git, with environment promotion via PR.</li><li>Combine GitOps with <a href="/docs/deployments/concepts/">Pulumi Deployments</a> so cloud infrastructure (VPCs, EKS clusters, IAM, DNS) and the workloads on top promote through the same review pipeline. See <a href="/blog/improving-gitops-with-pulumi-operator/">improving GitOps with the Pulumi Operator</a> for a worked example.</li><li>Configure <strong>automated rollback</strong> on health-check failure, and <strong>drift detection</strong> alerts when someone edits live state.</li></ul><h2 id="10-how-often-should-you-upgrade-kubernetes">10. How often should you upgrade Kubernetes?</h2><p>Kubernetes ships a minor release roughly <a href="https://kubernetes.io/releases/release/">every four months</a> and supports each one for about 14 months. Treat upgrades as routine maintenance, not a project.</p><ul><li>Stay within <strong>two minor versions</strong> of upstream — older versions miss CVE patches.</li><li>Test upgrades in a non-prod cluster, run a <a href="https://github.com/cncf/k8s-conformance">conformance test</a>, then promote.</li><li>Back up etcd before control-plane changes; managed services (EKS, GKE, AKS) handle most of this for you.</li><li>Upgrade add-ons (CNI, CSI, Gateway controller, cert-manager, metrics-server) on the same cadence — pin versions in code so the upgrade is auditable.</li><li>Watch the <a href="https://kubernetes.io/docs/reference/using-api/deprecation-guide/">Kubernetes deprecation guide</a> and run <a href="https://github.com/FairwindsOps/pluto"><code>pluto</code></a> or <code>kubent</code> to find deprecated APIs before they break.</li></ul><h2 id="11-how-should-you-label-and-annotate-kubernetes-resources">11. How should you label and annotate Kubernetes resources?</h2><p>Labels and annotations are the metadata layer that everything — Services, NetworkPolicies, monitoring, cost tools, GitOps — keys off of. Consistency matters more than cleverness.</p><ul><li>Adopt the <a href="https://kubernetes.io/docs/concepts/overview/working-with-objects/common-labels/">recommended labels</a>: <code>app.kubernetes.io/name</code>, <code>app.kubernetes.io/instance</code>, <code>app.kubernetes.io/version</code>, <code>app.kubernetes.io/component</code>, <code>app.kubernetes.io/part-of</code>, <code>app.kubernetes.io/managed-by</code>.</li><li>Add organization-specific labels for <strong>owner</strong>, <strong>cost-center</strong>, <strong>environment</strong>, and <strong>SLO tier</strong> — your FinOps and on-call processes will need them.</li><li>Reserve <a href="https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/">annotations</a> for non-identifying metadata: build SHA, change-ticket, last-deployed timestamp, ingress controller hints.</li></ul><div class="rounded-lg bg-violet-50 p-6 my-8"><p class="heading-4 m-0 mb-3 flex items-center gap-1.5">Manage Kubernetes with code</p><div class="body-base m-0 text-gray-950">Provision your clusters, their cloud resources, and the workloads on them from one Pulumi program, and use stacks to promote changes from dev to production.</div><a href="https://app.pulumi.com/signup" data-track="blog-body-cta" class="btn btn-primary mt-4">Get started
<svg class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-arrow-right-regular"/></svg></a></div><h2 id="12-how-should-you-separate-kubernetes-environments">12. How should you separate Kubernetes environments?</h2><p><strong>The rule:</strong> production is its own cluster. Dev and staging can share — sometimes. Mixing prod with anything else couples blast radius, upgrade cadence, and quotas.</p><ul><li><strong>Separate clusters per environment</strong> is the safe default. With managed control planes (EKS, GKE, AKS) the cost is small.</li><li><strong>Virtual clusters</strong> with <a href="https://www.vcluster.com/">vCluster</a> give each team a Kubernetes API of their own without the operational cost of a real cluster.</li><li><strong>Namespace-only segregation</strong> can work for dev/staging if you enforce strict NetworkPolicy, RBAC, and ResourceQuota boundaries.</li><li>Provision all of them from the same <a href="/docs/iac/get-started/kubernetes/">Pulumi</a> program with different stacks — <code>dev</code>, <code>staging</code>, <code>prod</code> — so promotion is a config change, not a copy.</li></ul><h2 id="13-how-do-you-optimize-kubernetes-container-images">13. How do you optimize Kubernetes container images?</h2><ul><li>Start from a <strong>distroless</strong> (<a href="https://github.com/GoogleContainerTools/distroless">gcr.io/distroless</a>) or <code>chainguard/static</code> base. Alpine is fine if you accept musl.</li><li>Build with <strong>multi-stage Dockerfiles</strong> so build tools never ship in the final image.</li><li>Pin the base image <strong>by digest</strong> (<code>@sha256:...</code>), not by tag — <code>latest</code> and <code>1.21</code> move under you.</li><li>Scan every image with <strong><a href="https://trivy.dev/latest/">Trivy</a></strong>, <a href="https://github.com/anchore/grype">Grype</a>, or your registry&rsquo;s built-in scanner. Block builds on <code>Critical</code>/<code>High</code> CVEs.</li><li>Smaller images mean faster pulls, faster autoscaling, and a smaller attack surface.</li></ul><h2 id="14-whats-a-reliable-kubernetes-logging-strategy">14. What&rsquo;s a reliable Kubernetes logging strategy?</h2><ul><li><strong>Centralize</strong> to Loki, Elastic/OpenSearch, or a managed service via Fluent Bit or the OpenTelemetry Collector running as a DaemonSet.</li><li><strong>Structure</strong> logs as JSON with consistent field names (<code>trace_id</code>, <code>span_id</code>, <code>service</code>, <code>level</code>).</li><li><strong>Retain</strong> by tier — 7 days hot, 30–90 days warm, archive to object storage for compliance.</li><li><strong>Redact</strong> secrets and PII at the collector, not after the fact.</li></ul><div class="note note-tip"><div class="icon-and-line"><svg class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-lightbulb-fill"/></svg><div class="line"></div></div><div class="content"><p><strong>You might also like:</strong></p><ul><li><a href="https://www.pulumi.com/blog/master-kubernetes-secrets-with-pulumi-esc-secrets-store-csi-driver/">Master Kubernetes Secrets with Pulumi ESC + Secrets Store CSI Driver</a></li><li><a href="https://www.pulumi.com/blog/aws-eks-auto-mode/">Getting Started with Amazon EKS Auto Mode in Pulumi</a></li><li><a href="https://www.pulumi.com/blog/why-every-platform-engineer-should-care-about-kubernetes-operators/">Why Every Platform Engineer Should Care About Kubernetes Operators</a></li></ul></div></div><h2 id="15-how-should-you-autoscale-workloads-on-kubernetes">15. How should you autoscale workloads on Kubernetes?</h2><p><strong>What is the Horizontal Pod Autoscaler?</strong> The <strong>HPA</strong> scales the replica count of a Deployment or StatefulSet up and down based on CPU, memory, or custom/external metrics.</p><p><strong>What is the Vertical Pod Autoscaler?</strong> The <strong>VPA</strong> adjusts a Pod&rsquo;s CPU and memory <em>requests</em> over time based on observed usage. Run it with <code>updateMode: Off</code> (recommendation-only) in production and apply the recommendations through your IaC tool.</p><p><strong>What are Cluster Autoscaler and Karpenter?</strong> <strong>Cluster Autoscaler</strong> adds and removes nodes to match Pod demand. <strong><a href="https://karpenter.sh/">Karpenter</a></strong> is a faster, group-less node provisioner now widely used on EKS and gaining traction on other clouds.</p><p><strong>The rule:</strong> every production workload has an HPA. Every cluster has a node-level autoscaler. Set sensible <code>min</code>/<code>max</code> replicas, define a <code>PodDisruptionBudget</code>, and gate scale-down behavior so traffic spikes don&rsquo;t pile up at restart time. Pair with <strong>KEDA</strong> for event-driven scaling (queues, Kafka lag, scheduled scale).</p><h2 id="16-how-do-you-enforce-policy-as-code-on-kubernetes">16. How do you enforce policy-as-code on Kubernetes?</h2><p><strong>What is policy-as-code?</strong> Policy-as-code expresses governance rules — security baselines, tagging, region restrictions, cost guardrails — as code that runs in CI and at admission time, blocking non-compliant changes before they reach the cluster.</p><p><strong>The rule:</strong> every change goes through at least one policy engine.</p><ul><li><strong>Pre-deploy</strong> — validate Pulumi or Helm output with <a href="/docs/insights/policy/">Pulumi CrossGuard</a> or <a href="https://www.conftest.dev/">Conftest</a> in CI.</li><li><strong>Admission-time</strong> — install <a href="https://open-policy-agent.github.io/gatekeeper/">OPA Gatekeeper</a> or <a href="https://kyverno.io/">Kyverno</a> and require, for example, signed images, a <code>team</code> label, and a non-root <code>securityContext</code> on every Pod.</li><li><strong>Continuous</strong> — scan running clusters with <a href="/docs/insights/policy/">Pulumi Insights</a> or <code>kubescape</code> for drift from policy.</li></ul><p>See <a href="/blog/benefits-of-policy-as-code/">the benefits of policy-as-code</a> and <a href="/blog/enforcing-policy-as-code-on-discovered-resources-with-pulumi/">enforcing policy-as-code on discovered resources</a> for end-to-end examples.</p><h2 id="17-how-do-you-secure-the-kubernetes-software-supply-chain">17. How do you secure the Kubernetes software supply chain?</h2><p><strong>What is an SBOM?</strong> A <strong>Software Bill of Materials</strong> is a machine-readable inventory of every component in a container image — packages, versions, licenses, hashes — typically in <a href="https://spdx.dev/">SPDX</a> or <a href="https://cyclonedx.org/">CycloneDX</a> format.</p><p><strong>The rule:</strong> every image you run in production has a verified SBOM and a verified signature.</p><ul><li>Generate SBOMs at build time with <a href="https://github.com/anchore/syft">Syft</a> or <code>docker sbom</code>.</li><li>Sign images and SBOMs with <a href="https://www.sigstore.dev/">Sigstore/cosign</a> keylessly via GitHub OIDC.</li><li>Verify signatures at admission with <a href="https://kyverno.io/policies/?policytypes=Cosign">Kyverno</a> or <a href="https://github.com/sse-secure-systems/connaisseur">Connaisseur</a>.</li><li>Generate <strong>provenance attestations</strong> (<a href="https://slsa.dev/">SLSA</a>) so you can prove which build pipeline produced a given image.</li><li>Pin base images by digest and rebuild on a cadence so CVE patches actually land.</li></ul><p>This is what regulators and customers ask for in 2026 — Executive Order 14028, the EU Cyber Resilience Act, and most enterprise procurement checklists all require it.</p><h2 id="18-how-do-you-manage-kubernetes-cost-finops">18. How do you manage Kubernetes cost (FinOps)?</h2><p><strong>The rule:</strong> Kubernetes cost is a labeling and right-sizing problem before it is a discount problem.</p><ul><li><strong>Right-size</strong> with VPA recommendations, <a href="https://github.com/FairwindsOps/goldilocks">Goldilocks</a>, or your APM&rsquo;s recommendation engine. Most workloads request more CPU than they actually use; right-sizing is usually the largest single saving.</li><li><strong>Schedule</strong> non-prod clusters off overnight and on weekends.</li><li><strong>Spot/preemptible nodes</strong> for fault-tolerant workloads; use Karpenter&rsquo;s consolidation to compact bin-packing.</li><li><strong>Show back / charge back</strong> by namespace and label using <a href="https://www.opencost.io/">OpenCost</a> or <a href="https://www.kubecost.io/">Kubecost</a>. Without per-team attribution, no team owns cost.</li><li><strong>Provision the underlying cluster with IaC</strong> — see <a href="/docs/iac/get-started/kubernetes/">Pulumi for Kubernetes</a> — so node types, autoscaling limits, and reserved capacity are reviewable artifacts. Pulumi&rsquo;s <a href="/blog/hidden-costs-of-infrastructure-management/">hidden-cost analysis</a> walks through where the money actually goes.</li></ul><h2 id="19-why-should-you-treat-kubernetes-clusters-as-cattle-not-pets">19. Why should you treat Kubernetes clusters as cattle, not pets?</h2><p>The old &ldquo;cattle, not pets&rdquo; adage applies more strictly to Kubernetes than to VMs. Manual edits to a live cluster will be reconciled away, drift between environments, or vanish on the next Pod restart.</p><ul><li>Fix problems in code — YAML, Helm chart, or <a href="/docs/iac/get-started/kubernetes/">Pulumi program</a> — and let the controller redeploy.</li><li>If you can&rsquo;t redeploy a cluster from Git in under an hour, you have a pet.</li><li>Use ephemeral preview environments for PRs; use blue/green or progressive delivery (Argo Rollouts, Flagger) for production cutovers.</li></ul><h2 id="20-why-use-pulumi-to-manage-kubernetes">20. Why use Pulumi to manage Kubernetes?</h2><p>Native YAML scales until your team doesn&rsquo;t. Once you have more than a handful of services, dependencies between cloud resources and Kubernetes objects, or more than one cluster, <strong>infrastructure as code in a real programming language</strong> wins on every axis.</p><ul><li><strong>Real languages</strong> — TypeScript, Python, Go, Java, .NET — for <a href="/docs/iac/languages-sdks/">type-safe, testable Kubernetes infrastructure</a>. Loops, conditionals, and unit tests instead of templating.</li><li><strong>One stack, full topology</strong> — manage the cloud (EKS/GKE/AKS, VPC, IAM, DNS) and the workloads in it together. See <a href="/blog/easily-create-and-manage-aws-eks-kubernetes-clusters-with-pulumi/">easily create and manage AWS EKS clusters with Pulumi</a>.</li><li><strong>Reusable components</strong> — abstract platform patterns into <a href="/docs/iac/concepts/packages/">Pulumi packages</a> other teams <code>import</code> instead of copy-pasting.</li><li><strong>GitOps reconciliation</strong> — the <a href="/docs/integrations/clouds/kubernetes/pulumi-kubernetes-operator/">Pulumi Kubernetes Operator</a> reconciles a cluster to a Pulumi stack on every Git push.</li><li><strong>Policy-as-code</strong> built in — <a href="/docs/insights/policy/">CrossGuard</a> blocks non-compliant changes before <code>pulumi up</code>.</li><li><strong>Secrets done right</strong> — <a href="/docs/esc/">Pulumi ESC</a> federates secrets and configuration across stacks, environments, and Kubernetes clusters.</li></ul><p>For a deeper comparison of hand-written YAML, Terraform, and Pulumi for Kubernetes, see <a href="/blog/yaml-terraform-pulumi-whats-the-smart-choice-for-deployment-automation-with-kubernetes/">YAML, Terraform, Pulumi: what&rsquo;s the smart choice for deployment automation with Kubernetes</a>, and the <a href="/blog/beyond-yaml-kubernetes-2026-automation-era/">beyond YAML</a> write-up on where Kubernetes automation is heading in 2026.</p><div style="position:relative;padding-bottom:56.25%;height:0;overflow:hidden"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/2P8JLgAc5QI?autoplay=0&amp;controls=1&amp;end=0&amp;loop=0&amp;mute=0&amp;start=0" style="position:absolute;top:0;left:0;width:100%;height:100%;border:0" title="YouTube video"></iframe></div><figcaption><center><i>See how Pulumi helps you manage Kubernetes Services and Deployments with code instead of YAML—bringing structure, reuse, and type safety to your configs.</i></center></figcaption><p>By adopting Pulumi, you can avoid the complexity of juggling endless YAML files and gain a more streamlined, maintainable workflow for your Kubernetes infrastructure.</p><h2 id="final-thoughts">Final thoughts</h2><div style="display:flex;align-items:center;justify-content:center;height:100%"><img src="img_2.png" alt="A meme featuring a man slamming a card on a table, labeled “ME”, using “KUBERNETES” to solve “ANY PROBLEM TO SOLVE”, humorously depicting overuse of Kubernetes." style="width:60%;height:100%"></div><p>Kubernetes rewards discipline. The 20 practices above — resource hygiene, namespaced isolation, RBAC, NetworkPolicy, Pod Security, external secrets, probes, the Gateway API, observability, GitOps, policy-as-code, signed images and SBOMs, autoscaling, FinOps, multi-cluster strategy, and IaC — are the dial settings that separate clusters that page their owners every week from clusters that don&rsquo;t.</p><p>Pick the three weakest spots in your environment and fix those first. Then promote the fixes through code, not through <code>kubectl</code>.</p><p>Want to learn how to put these practices into action? Meet us at <a href="https://www.pulumi.com/kubecon/">KubeCon Europe 2026 (Booth 784)</a> or register for our upcoming <a href="https://www.pulumi.com/events/from-zero-to-production-in-kubernetes/">Zero to Production in Kubernetes</a> workshop.</p><a href="/docs/get-started/" class="btn btn-primary">Try Pulumi for Free</a></section><div class="mt-8 flex flex-wrap items-center gap-2 border-t border-gray-200 pt-8"><span class="body-sm font-semibold text-service-black">Tagged as:</span>
<a href="/blog/tag/kubernetes/" data-track="blog-tag-kubernetes" class="relative z-10 badge badge-secondary">kubernetes</a>
<a href="/blog/tag/best-practices/" data-track="blog-tag-best-practices" class="relative z-10 badge badge-secondary">best-practices</a>
<a href="/blog/tag/devops/" data-track="blog-tag-devops" class="relative z-10 badge badge-secondary">devops</a></div><details class="group mt-8 border-t border-gray-200 pt-8"><summary class="flex cursor-pointer list-none items-center justify-between gap-4 text-sm font-semibold marker:hidden [&::-webkit-details-marker]:hidden hover:text-service-black"><span>Archived feature image</span>
<svg class="ph-icon ph-icon--regular size-4 shrink-0 transition-transform group-open:rotate-180" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-down-regular"/></svg></summary><img class="mt-4 rounded-lg border border-gray-200" src="/blog/kubernetes-best-practices-i-wish-i-had-known-before/meta-legacy_hu_f2bac396cdade4c6.webp" srcset="/blog/kubernetes-best-practices-i-wish-i-had-known-before/meta-legacy_hu_f2bac396cdade4c6.webp 1x, /blog/kubernetes-best-practices-i-wish-i-had-known-before/meta-legacy_hu_735c6b23403d2fcd.webp 2x" width="960" height="480" loading="lazy" decoding="async" alt="Original feature image for this post"></details><nav aria-label="Previous and next posts" class="mt-12 grid grid-cols-1 gap-4 sm:grid-cols-2"><a href="/blog/autonaming-configuration/" data-track="blog-prev-post" class="group flex min-w-0 flex-col items-start gap-2 rounded-lg border border-gray-300 bg-white p-5 transition-colors hover:border-gray-500 hover:bg-gray-100"><span class="font-overline-sm flex items-center gap-1 text-service-black"><svg class="ph-icon ph-icon--bold size-3" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-left-bold"/></svg>Previous</span>
<span class="heading-4 m-0 w-full truncate text-service-black transition-colors group-hover:text-violet-primary">Introducing Customizable Resource Auto-naming in Pulumi</span>
</a><a href="/blog/run-deepseek-on-aws-ec2-using-pulumi/" data-track="blog-next-post" class="group flex min-w-0 flex-col items-end gap-2 rounded-lg border border-gray-300 bg-white p-5 text-right transition-colors hover:border-gray-500 hover:bg-gray-100 sm:col-start-2"><span class="font-overline-sm flex items-center gap-1 text-service-black">Next<svg class="ph-icon ph-icon--bold size-3" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-caret-right-bold"/></svg></span>
<span class="heading-4 m-0 w-full truncate text-service-black transition-colors group-hover:text-violet-primary">Run Open-Source LLMs on AWS EC2 with Ollama and Pulumi</span></a></nav><section class="newsletter-input mt-12"><div class="rounded-lg bg-violet-50 px-6 py-8 text-center"><h4 class="mb-4">Subscribe to the Pulumi Monthly Newsletter</h4><div class="inline-block"><pulumi-hubspot-form form-id="6d45d68a-4244-4f23-bbec-941f8ccb2b44" class="newsletter newsletter-blog"></pulumi-hubspot-form></div></div></section></div><aside class="mt-10 lg:mt-0 lg:w-[19rem] lg:shrink-0"><div class="flex flex-col gap-8 lg:sticky lg:top-24"><div class="hidden md:block md:empty:hidden"><nav data-blog-toc aria-label="Table of contents"><p class="font-overline-sm mb-4 text-service-black">In this post</p><ul class="m-0 flex list-none flex-col gap-2 p-0"><li class="m-0 leading-snug"><a href="#tldr-20-kubernetes-best-practices-for-2026" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">TL;DR: 20 Kubernetes best practices for 2026</a></li><li class="m-0 leading-snug"><a href="#what-are-kubernetes-best-practices" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">What are Kubernetes best practices?</a></li><li class="m-0 leading-snug"><a href="#common-kubernetes-anti-patterns-vs-the-correct-approach" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">Common Kubernetes anti-patterns vs. the correct approach</a></li><li class="m-0 leading-snug"><a href="#1-how-do-you-set-kubernetes-resource-requests-and-limits" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">1. How do you set Kubernetes resource requests and limits?</a></li><li class="m-0 leading-snug"><a href="#2-how-should-you-structure-kubernetes-namespaces" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">2. How should you structure Kubernetes namespaces?</a></li><li class="m-0 leading-snug"><a href="#3-should-you-run-multiple-containers-in-one-pod" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">3. Should you run multiple containers in one Pod?</a></li><li class="m-0 leading-snug"><a href="#4-should-you-use-helm-kustomize-or-pulumi-for-kubernetes-manifests" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">4. Should you use Helm, Kustomize, or Pulumi for Kubernetes manifests?</a></li><li class="m-0 leading-snug"><a href="#5-how-should-you-handle-ingress-and-networking-on-kubernetes-in-2026" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">5. How should you handle ingress and networking on Kubernetes in 2026?</a></li><li class="m-0 leading-snug"><a href="#6-whats-the-difference-between-liveness-readiness-and-startup-probes" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">6. What&rsquo;s the difference between liveness, readiness, and startup probes?</a></li><li class="m-0 leading-snug"><a href="#7-how-do-you-secure-a-kubernetes-cluster" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">7. How do you secure a Kubernetes cluster?</a></li><li class="m-0 leading-snug"><a href="#8-how-do-you-set-up-kubernetes-observability" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">8. How do you set up Kubernetes observability?</a></li><li class="m-0 leading-snug"><a href="#9-how-do-you-automate-kubernetes-deployments-with-gitops" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">9. How do you automate Kubernetes deployments with GitOps?</a></li><li class="m-0 leading-snug"><a href="#10-how-often-should-you-upgrade-kubernetes" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">10. How often should you upgrade Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#11-how-should-you-label-and-annotate-kubernetes-resources" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">11. How should you label and annotate Kubernetes resources?</a></li><li class="m-0 leading-snug"><a href="#12-how-should-you-separate-kubernetes-environments" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">12. How should you separate Kubernetes environments?</a></li><li class="m-0 leading-snug"><a href="#13-how-do-you-optimize-kubernetes-container-images" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">13. How do you optimize Kubernetes container images?</a></li><li class="m-0 leading-snug"><a href="#14-whats-a-reliable-kubernetes-logging-strategy" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">14. What&rsquo;s a reliable Kubernetes logging strategy?</a></li><li class="m-0 leading-snug"><a href="#15-how-should-you-autoscale-workloads-on-kubernetes" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">15. How should you autoscale workloads on Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#16-how-do-you-enforce-policy-as-code-on-kubernetes" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">16. How do you enforce policy-as-code on Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#17-how-do-you-secure-the-kubernetes-software-supply-chain" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">17. How do you secure the Kubernetes software supply chain?</a></li><li class="m-0 leading-snug"><a href="#18-how-do-you-manage-kubernetes-cost-finops" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">18. How do you manage Kubernetes cost (FinOps)?</a></li><li class="m-0 leading-snug"><a href="#19-why-should-you-treat-kubernetes-clusters-as-cattle-not-pets" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">19. Why should you treat Kubernetes clusters as cattle, not pets?</a></li><li class="m-0 leading-snug"><a href="#20-why-use-pulumi-to-manage-kubernetes" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">20. Why use Pulumi to manage Kubernetes?</a></li><li class="m-0 leading-snug"><a href="#final-thoughts" data-track="blog-toc" class="body-sm block font-semibold text-service-black transition-colors hover:text-violet-primary">Final thoughts</a></li></ul></nav></div><div><p class="font-overline-sm mb-4 text-service-black">Share</p><ul class="m-0 flex list-none items-center gap-3 p-0"><li class="m-0"><button type="button" data-copy-link data-url="https://www.pulumi.com/blog/kubernetes-best-practices-i-wish-i-had-known-before/" aria-label="Copy link" data-track="blog-share-copy-link" class="block cursor-pointer text-gray-500 transition-colors hover:text-violet-primary">
<span data-copy-link-idle><svg class="ph-icon ph-icon--regular text-lg" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-link-regular"/></svg></span>
<span data-copy-link-done hidden class="text-green-500"><svg class="ph-icon ph-icon--regular text-lg" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-check-regular"/></svg></span></button></li><li class="m-0"><a href="https://www.linkedin.com/feed/?shareActive=true&text=Kubernetes%20Best%20Practices%20I%20Wish%20I%20Had%20Known%20Before%20https%3a%2f%2fwww.pulumi.com%2fblog%2fkubernetes-best-practices-i-wish-i-had-known-before%2f" target="_blank" rel="noopener" aria-label="Share on LinkedIn" data-track="blog-share-linkedin" class="text-gray-500 transition-colors hover:text-violet-primary"><svg class="ph-icon text-lg" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-linkedin"/></svg></a></li><li class="m-0"><a href="https://www.reddit.com/submit?url=https%3a%2f%2fwww.pulumi.com%2fblog%2fkubernetes-best-practices-i-wish-i-had-known-before%2f&title=Kubernetes%20Best%20Practices%20I%20Wish%20I%20Had%20Known%20Before" target="_blank" rel="noopener" aria-label="Share on Reddit" data-track="blog-share-reddit" class="text-gray-500 transition-colors hover:text-violet-primary"><svg class="ph-icon text-lg" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-reddit"/></svg></a></li><li class="m-0"><a href="https://x.com/intent/post?text=Kubernetes%20Best%20Practices%20I%20Wish%20I%20Had%20Known%20Before&url=https%3a%2f%2fwww.pulumi.com%2fblog%2fkubernetes-best-practices-i-wish-i-had-known-before%2f" target="_blank" rel="noopener" aria-label="Share on X" data-track="blog-share-x" class="text-gray-500 transition-colors hover:text-violet-primary"><svg class="ph-icon text-base" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-x"/></svg></a></li><li class="m-0"><a href="https://news.ycombinator.com/submitlink?u=https%3a%2f%2fwww.pulumi.com%2fblog%2fkubernetes-best-practices-i-wish-i-had-known-before%2f&t=Kubernetes%20Best%20Practices%20I%20Wish%20I%20Had%20Known%20Before" target="_blank" rel="noopener" aria-label="Share on Hacker News" data-track="blog-share-hackernews" class="text-gray-500 transition-colors hover:text-violet-primary"><svg class="ph-icon text-lg" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-hackernews"/></svg></a></li></ul></div><div class="rounded-lg bg-violet-50 p-4 pb-2"><p class="font-overline-sm m-0 mb-4 flex items-center gap-1.5 text-violet-primary"><svg class="ph-icon size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-pulumi"/></svg>Program the Cloud</p><p class="body-sm m-0">Create, deploy, and manage cloud infrastructure using your favorite language.</p><a href="/docs/get-started/" data-track="sidebar" class="btn btn-ghost-primary mt-2 -ml-2.5 hover:bg-violet-100">Get started
<svg class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-arrow-right-regular"/></svg></a></div></div></aside></div></div><section class="border-t border-gray-200"><div class="mx-auto max-w-[1220px] px-4 py-10 lg:py-12"><p class="font-overline m-0! mb-6 text-service-black">Related posts</p><div class="flex flex-col"><article data-post-row data-category="best-practices" class="group relative border-b border-gray-200 last:border-0"><div data-row-compact class="flex flex-col md:flex-row items-start md:items-center gap-2 md:gap-4 py-6"><h4 class="m-0! min-w-0 flex-1 md:truncate"><a href="/blog/gitops-best-practices-i-wish-i-had-known-before/" data-track="blog-row-gitops-best-practices-i-wish-i-had-known-before" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">GitOps Best Practices I Wish I Had Known Before</a></h4><div class="flex shrink-0 items-center gap-2"><span class="hidden md:inline-flex"><span class="badge badge-outline">Best Practices</span></span>
<span class="w-32 mx-auto hidden md:inline-flex justify-center"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/engin-diri.jpg" alt="Engin Diri" title="Engin Diri" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span></span>
</span><time class="body-sm whitespace-nowrap text-service-black md:w-28 md:text-right" datetime="2026-02-19">Feb 19, 2026</time></div></div><div data-row-card class="hidden items-center gap-4 py-6 md:gap-8"><div class="flex min-w-0 flex-1 flex-col items-start gap-2"><span class="badge badge-outline">Best Practices</span><h3 class="heading-4 mt-1 mb-0!"><a href="/blog/gitops-best-practices-i-wish-i-had-known-before/" data-track="blog-card-gitops-best-practices-i-wish-i-had-known-before" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">GitOps Best Practices I Wish I Had Known Before</a></h3><p class="m-0! body-sm text-service-black line-clamp-2">Essential GitOps best practices from production experience. Avoid common pitfalls, bridge IaC with GitOps, and streamline Kubernetes deployments.</p><div class="mt-1"><div class="flex flex-wrap items-center gap-x-2 gap-y-1 body-sm"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/engin-diri.jpg" alt="Engin Diri" title="Engin Diri" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span><span class="body-sm text-service-black whitespace-nowrap">Engin Diri</span></span>
<span class="text-gray-500" aria-hidden="true">•</span><time class="text-service-black whitespace-nowrap" datetime="2026-02-19">Feb 19, 2026</time></div></div></div><div class="flex size-20 sm:size-28 lg:size-36 shrink-0 items-center justify-center overflow-hidden rounded-lg bg-violet-950"><img class="h-full w-auto max-w-none" src="/blog/gitops-best-practices-i-wish-i-had-known-before/feature_hu_fc49c82c4e3b23e8.webp" srcset="/blog/gitops-best-practices-i-wish-i-had-known-before/feature_hu_fc49c82c4e3b23e8.webp 1x, /blog/gitops-best-practices-i-wish-i-had-known-before/feature_hu_8d1510794f79e174.webp 2x" sizes="288px" width="288" height="192" alt="GitOps Best Practices I Wish I Had Known Before" loading="lazy" decoding="async"></div></div></article><article data-post-row data-category="best-practices" class="group relative border-b border-gray-200 last:border-0"><div data-row-compact class="flex flex-col md:flex-row items-start md:items-center gap-2 md:gap-4 py-6"><h4 class="m-0! min-w-0 flex-1 md:truncate"><a href="/blog/why-every-platform-engineer-should-care-about-kubernetes-operators/" data-track="blog-row-why-every-platform-engineer-should-care-about-kubernetes-operators" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Why Every Platform Engineer Should Care About Kubernetes Operators</a></h4><div class="flex shrink-0 items-center gap-2"><span class="hidden md:inline-flex"><span class="badge badge-outline">Best Practices</span></span>
<span class="w-32 mx-auto hidden md:inline-flex justify-center"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/engin-diri.jpg" alt="Engin Diri" title="Engin Diri" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span></span>
</span><time class="body-sm whitespace-nowrap text-service-black md:w-28 md:text-right" datetime="2024-12-10">Dec 10, 2024</time></div></div><div data-row-card class="hidden items-center gap-4 py-6 md:gap-8"><div class="flex min-w-0 flex-1 flex-col items-start gap-2"><span class="badge badge-outline">Best Practices</span><h3 class="heading-4 mt-1 mb-0!"><a href="/blog/why-every-platform-engineer-should-care-about-kubernetes-operators/" data-track="blog-card-why-every-platform-engineer-should-care-about-kubernetes-operators" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Why Every Platform Engineer Should Care About Kubernetes Operators</a></h3><p class="m-0! body-sm text-service-black line-clamp-2">Highlighting how Kubernetes Operators empower platform engineers to automate and streamline application deployment, management, and scaling on Kubernetes.</p><div class="mt-1"><div class="flex flex-wrap items-center gap-x-2 gap-y-1 body-sm"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/engin-diri.jpg" alt="Engin Diri" title="Engin Diri" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span><span class="body-sm text-service-black whitespace-nowrap">Engin Diri</span></span>
<span class="text-gray-500" aria-hidden="true">•</span><time class="text-service-black whitespace-nowrap" datetime="2024-12-10">Dec 10, 2024</time></div></div></div></div></article><article data-post-row data-category="best-practices" class="group relative border-b border-gray-200 last:border-0"><div data-row-compact class="flex flex-col md:flex-row items-start md:items-center gap-2 md:gap-4 py-6"><h4 class="m-0! min-w-0 flex-1 md:truncate"><a href="/blog/iac-best-practices-applying-stack-references/" data-track="blog-row-iac-best-practices-applying-stack-references" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">IaC Best Practices: Applying Stack References</a></h4><div class="flex shrink-0 items-center gap-2"><span class="hidden md:inline-flex"><span class="badge badge-outline">Best Practices</span></span>
<span class="w-32 mx-auto hidden md:inline-flex justify-center"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/scott-lowe.jpg" alt="Scott Lowe" title="Scott Lowe" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span></span>
</span><time class="body-sm whitespace-nowrap text-service-black md:w-28 md:text-right" datetime="2023-03-31">Mar 31, 2023</time></div></div><div data-row-card class="hidden items-center gap-4 py-6 md:gap-8"><div class="flex min-w-0 flex-1 flex-col items-start gap-2"><span class="badge badge-outline">Best Practices</span><h3 class="heading-4 mt-1 mb-0!"><a href="/blog/iac-best-practices-applying-stack-references/" data-track="blog-card-iac-best-practices-applying-stack-references" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">IaC Best Practices: Applying Stack References</a></h3><p class="m-0! body-sm text-service-black line-clamp-2">Learn how to apply Pulumi stack references to share data across projects. Improve modularity and maintainability with best practices for stack dependencies.</p><div class="mt-1"><div class="flex flex-wrap items-center gap-x-2 gap-y-1 body-sm"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/scott-lowe.jpg" alt="Scott Lowe" title="Scott Lowe" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span><span class="body-sm text-service-black whitespace-nowrap">Scott Lowe</span></span>
<span class="text-gray-500" aria-hidden="true">•</span><time class="text-service-black whitespace-nowrap" datetime="2023-03-31">Mar 31, 2023</time></div></div></div><div class="flex size-20 sm:size-28 lg:size-36 shrink-0 items-center justify-center overflow-hidden rounded-lg bg-violet-950"><img class="h-full w-auto max-w-none" src="/blog/iac-best-practices-applying-stack-references/feature_hu_d27216aef57358bf.webp" srcset="/blog/iac-best-practices-applying-stack-references/feature_hu_d27216aef57358bf.webp 1x, /blog/iac-best-practices-applying-stack-references/feature_hu_e6a18ed50ede11b3.webp 2x" sizes="288px" width="288" height="192" alt="IaC Best Practices: Applying Stack References" loading="lazy" decoding="async"></div></div></article><article data-post-row data-category="general" class="group relative border-b border-gray-200 last:border-0"><div data-row-compact class="flex flex-col md:flex-row items-start md:items-center gap-2 md:gap-4 py-6"><h4 class="m-0! min-w-0 flex-1 md:truncate"><a href="/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/" data-track="blog-row-future-of-the-cloud-10-trends-shaping-2026-and-beyond" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Future of the Cloud: 10 Trends Shaping 2026 and Beyond</a></h4><div class="flex shrink-0 items-center gap-2"><span class="hidden md:inline-flex"><span class="badge badge-outline">General</span></span>
<span class="w-32 mx-auto hidden md:inline-flex justify-center"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/sara-huddleston.jpg" alt="Sara Huddleston" title="Sara Huddleston" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span></span>
</span><time class="body-sm whitespace-nowrap text-service-black md:w-28 md:text-right" datetime="2025-12-04">Dec 4, 2025</time></div></div><div data-row-card class="hidden items-center gap-4 py-6 md:gap-8"><div class="flex min-w-0 flex-1 flex-col items-start gap-2"><span class="badge badge-outline">General</span><h3 class="heading-4 mt-1 mb-0!"><a href="/blog/future-cloud-infrastructure-10-trends-shaping-2024-and-beyond/" data-track="blog-card-future-of-the-cloud-10-trends-shaping-2026-and-beyond" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Future of the Cloud: 10 Trends Shaping 2026 and Beyond</a></h3><p class="m-0! body-sm text-service-black line-clamp-2">Explore 2026’s top cloud trends, including AI infrastructure, Kubernetes evolution, IaC, DevSecOps, platform engineering, and modern cloud governance.</p><div class="mt-1"><div class="flex flex-wrap items-center gap-x-2 gap-y-1 body-sm"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/sara-huddleston.jpg" alt="Sara Huddleston" title="Sara Huddleston" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span><span class="body-sm text-service-black whitespace-nowrap">Sara Huddleston</span></span>
<span class="text-gray-500" aria-hidden="true">•</span><time class="text-service-black whitespace-nowrap" datetime="2025-12-04">Dec 4, 2025</time></div></div></div></div></article><article data-post-row data-category="general" class="group relative border-b border-gray-200 last:border-0"><div data-row-compact class="flex flex-col md:flex-row items-start md:items-center gap-2 md:gap-4 py-6"><h4 class="m-0! min-w-0 flex-1 md:truncate"><a href="/blog/beyond-yaml-kubernetes-2026-automation-era/" data-track="blog-row-beyond-yaml-in-kubernetes-the-2026-automation-era" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Beyond YAML in Kubernetes: The 2026 Automation Era</a></h4><div class="flex shrink-0 items-center gap-2"><span class="hidden md:inline-flex"><span class="badge badge-outline">General</span></span>
<span class="w-32 mx-auto hidden md:inline-flex justify-center"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/sara-huddleston.jpg" alt="Sara Huddleston" title="Sara Huddleston" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span></span>
</span><time class="body-sm whitespace-nowrap text-service-black md:w-28 md:text-right" datetime="2025-11-12">Nov 12, 2025</time></div></div><div data-row-card class="hidden items-center gap-4 py-6 md:gap-8"><div class="flex min-w-0 flex-1 flex-col items-start gap-2"><span class="badge badge-outline">General</span><h3 class="heading-4 mt-1 mb-0!"><a href="/blog/beyond-yaml-kubernetes-2026-automation-era/" data-track="blog-card-beyond-yaml-in-kubernetes-the-2026-automation-era" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Beyond YAML in Kubernetes: The 2026 Automation Era</a></h3><p class="m-0! body-sm text-service-black line-clamp-2">Discover how AI and automation are shaping Kubernetes in 2026. See Pulumi Neo in action and learn how to simplify multi-cluster operations with code.</p><div class="mt-1"><div class="flex flex-wrap items-center gap-x-2 gap-y-1 body-sm"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/sara-huddleston.jpg" alt="Sara Huddleston" title="Sara Huddleston" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span><span class="body-sm text-service-black whitespace-nowrap">Sara Huddleston</span></span>
<span class="text-gray-500" aria-hidden="true">•</span><time class="text-service-black whitespace-nowrap" datetime="2025-11-12">Nov 12, 2025</time></div></div></div></div></article><article data-post-row data-category="general" class="group relative border-b border-gray-200 last:border-0"><div data-row-compact class="flex flex-col md:flex-row items-start md:items-center gap-2 md:gap-4 py-6"><h4 class="m-0! min-w-0 flex-1 md:truncate"><a href="/blog/best-kubernetes-iac-tools-2026/" data-track="blog-row-best-kubernetes-infrastructure-as-code-tools-in-2026" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Best Kubernetes Infrastructure as Code Tools in 2026</a></h4><div class="flex shrink-0 items-center gap-2"><span class="hidden md:inline-flex"><span class="badge badge-outline">General</span></span>
<span class="w-32 mx-auto hidden md:inline-flex justify-center"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/pulumi-content-team.jpg" alt="Pulumi Content Team" title="Pulumi Content Team" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span></span>
</span><time class="body-sm whitespace-nowrap text-service-black md:w-28 md:text-right" datetime="2026-08-14">Aug 14, 2026</time></div></div><div data-row-card class="hidden items-center gap-4 py-6 md:gap-8"><div class="flex min-w-0 flex-1 flex-col items-start gap-2"><span class="badge badge-outline">General</span><h3 class="heading-4 mt-1 mb-0!"><a href="/blog/best-kubernetes-iac-tools-2026/" data-track="blog-card-best-kubernetes-infrastructure-as-code-tools-in-2026" class="text-service-black transition-colors after:absolute after:inset-0 after:content-[''] group-hover:text-violet-primary">Best Kubernetes Infrastructure as Code Tools in 2026</a></h3><p class="m-0! body-sm text-service-black line-clamp-2">The best Kubernetes IaC tools in 2026: Pulumi, Terraform, Helm, Kustomize, Crossplane, Argo CD, Flux, cdk8s, and kro, compared honestly on fit.</p><div class="mt-1"><div class="flex flex-wrap items-center gap-x-2 gap-y-1 body-sm"><span class="flex items-center gap-2"><span class="flex items-center shrink-0"><img src="/images/team/pulumi-content-team.jpg" alt="Pulumi Content Team" title="Pulumi Content Team" class="size-8 rounded-full object-cover bg-violet-200 ring-1 ring-gray-100 shrink-0" loading="lazy" decoding="async"></span><span class="body-sm text-service-black whitespace-nowrap">Pulumi Content Team</span></span>
<span class="text-gray-500" aria-hidden="true">•</span><time class="text-service-black whitespace-nowrap" datetime="2026-08-14">Aug 14, 2026</time></div></div></div><div class="flex size-20 sm:size-28 lg:size-36 shrink-0 items-center justify-center overflow-hidden rounded-lg bg-violet-950"><img class="h-full w-auto max-w-none" src="/blog/best-kubernetes-iac-tools-2026/feature_hu_9fd69185a34e10ac.webp" srcset="/blog/best-kubernetes-iac-tools-2026/feature_hu_9fd69185a34e10ac.webp 1x, /blog/best-kubernetes-iac-tools-2026/feature_hu_addc0683f0f212fa.webp 2x" sizes="288px" width="288" height="192" alt="Best Kubernetes Infrastructure as Code Tools in 2026" loading="lazy" decoding="async"></div></div></article></div></div></section><dialog data-lightbox aria-label="Expanded view" class="fixed inset-0 m-0 h-full max-h-none w-full max-w-none border-0 bg-transparent p-4 backdrop:bg-service-black/90 md:p-8"><button type="button" data-lightbox-close aria-label="Close" class="absolute right-2 top-2 z-10 inline-flex size-10 items-center justify-center rounded-full border-0 bg-transparent text-white transition-colors hover:bg-white/15 md:right-4 md:top-4">
<svg class="ph-icon ph-icon--regular size-6" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-x-regular"/></svg></button><figure class="m-0 flex h-full w-full flex-col items-center justify-center gap-3"><img data-lightbox-image alt class="max-h-[calc(100%-6rem)] max-w-full rounded-lg shadow-2xl"><video data-lightbox-video controls playsinline class="hidden max-h-[calc(100%-6rem)] max-w-full rounded-lg shadow-2xl"></video><figcaption data-lightbox-caption aria-hidden="true" class="body-sm line-clamp-3 max-w-3xl shrink-0 text-center text-gray-300 empty:hidden"></figcaption></figure><template data-lightbox-badge><span aria-hidden="true" class="pointer-events-none absolute right-3 top-3 inline-flex size-9 items-center justify-center rounded-md bg-service-black/60 text-white opacity-0 transition-opacity group-hover:opacity-100 group-focus-visible:opacity-100"><svg class="ph-icon ph-icon--regular size-5" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#p-magnifying-glass-plus-regular"/></svg></span></template></dialog></main><section class="bg-violet-background text-gray-950"><div class="container mx-auto flex flex-col md:flex-row items-center justify-center gap-5 md:gap-12 px-4 py-7 text-center md:text-left"><h2 class="text-2xl md:text-3xl font-semibold tracking-tight leading-tight mb-0">The infrastructure as code platform for any cloud.</h2><div class="flex gap-2.5 items-center shrink-0"><a class="btn btn-outline btn-xl" href="/contact/" data-track="footer-cta-contact-us">Contact us</a>
<a class="btn btn-primary btn-xl" href="https://app.pulumi.com/signup" data-track="footer-signup">Get started</a></div></div></section><footer class="relative bg-service-black text-white overflow-clip px-6 lg:px-8 pt-12 pb-24 lg:pb-8"><div class="absolute top-0 right-0 pointer-events-none max-w-[50%] opacity-90" aria-hidden="true"><img src="/fingerprinted/images/footer/bg-lines.db941eef4575a29e90d71577c26c8d1247a92ba851a12ab2021cc3150bc26ba9.svg" alt width="421" height="474" loading="lazy" decoding="async" aria-hidden="true"></div><div class="relative z-10 flex flex-col lg:flex-row gap-x-8 gap-y-10 justify-between"><div class="lg:w-56 lg:shrink-0 flex flex-col gap-4"><a href="/" class="inline-block" data-track="footer-logo" aria-label="Pulumi home"><img class="h-[89px] w-[84px]" src="/fingerprinted/logos/brand/pulumi-mark.2ff13df2c355746e06f3f84162d630b2d7a875e6b07a180a9187a50ba7d70db5.svg" alt="Pulumi" width="84" height="89" loading="lazy" decoding="async"></a><h3 class="mt-0 text-2xl font-semibold tracking-tight leading-snug text-white">Open source and free for individuals.</h3><div class="min-h-[28px]"><a href="https://github.com/pulumi/pulumi" target="_blank" rel="noopener" data-track="footer-github-stars" class="items-stretch h-9 shrink-0 rounded-lg border text-sm font-normal whitespace-nowrap outline-none select-none transition-all overflow-hidden focus-visible:ring-3 focus-visible:ring-violet-400/50 border-white/15 text-white hover:border-white/40 hover:bg-white/5 focus-visible:border-violet-400 inline-flex" aria-label="Star pulumi/pulumi on GitHub — 25669 stars"><span class="inline-flex items-center gap-1.5 px-2.5"><svg class="ph-icon size-4" fill="currentColor" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-github"/></svg>
<span>pulumi/pulumi</span>
</span><span aria-hidden="true" style="width:1px;background-color:rgba(255,255,255,.15)"></span>
<span class="inline-flex items-center px-2.5">25.7K</span></a></div></div><div class="grid grid-cols-2 gap-x-8 gap-y-10 sm:grid-cols-3 lg:flex lg:flex-wrap lg:gap-x-16"><nav aria-label="Resources"><h3 class="footer-heading">Resources</h3><ul><li class="mb-2"><a href="/docs/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-documentation">Docs</a></li><li class="mb-2"><a href="/registry/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-apis">Registry</a></li><li class="mb-2"><a href="/dev/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-learn">Dev Center</a></li><li class="mb-2"><a href="/events/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-events">Events</a></li><li class="mb-2"><a href="/releases/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-releases">Releases</a></li><li class="mb-2"><a href="/community/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-community">Community</a></li></ul></nav><nav aria-label="Platform"><h3 class="footer-heading">Platform</h3><ul><li class="mb-2"><a href="/product/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-overview">Overview</a></li><li class="mb-2"><a href="/product/infrastructure-as-code/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-iac">Infrastructure as code</a></li><li class="mb-2"><a href="/product/secrets-management/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-secrets">Secrets & configuration</a></li><li class="mb-2"><a href="/product/discovery-governance/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-insights">Discovery & governance</a></li><li class="mb-2"><a href="/product/neo/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-neo">AI infrastructure agent</a></li><li class="mb-2"><a href="/product/internal-developer-platforms/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-idp">Internal developer platform</a></li><li class="mb-2"><a href="/pricing/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-platform-pricing">Pricing</a></li></ul></nav><nav aria-label="Pulumi for"><h3 class="footer-heading">Pulumi for</h3><ul><li class="mb-2"><a href="/aws/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-aws">AWS</a></li><li class="mb-2"><a href="/azure/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-azure">Microsoft Azure</a></li><li class="mb-2"><a href="/gcp/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-gcp">Google Cloud Platform</a></li><li class="mb-2"><a href="/kubernetes/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-kubernetes">Kubernetes</a></li><li class="mb-2"><a href="/what-is/what-is-infrastructure-as-code/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-what-is-infrastructure-as-code">Infrastructure as code</a></li><li class="mb-2"><a href="/solutions/ai/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-artificial-intelligence">AI/ML workloads</a></li><li class="mb-2"><a href="/case-studies/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-case-studies">Teams like yours</a></li></ul></nav><nav aria-label="Company"><h3 class="footer-heading">Company</h3><ul><li class="mb-2"><a href="/about/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-about-us">About us</a></li><li class="mb-2"><a href="/blog/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-blog">Blog</a></li><li class="mb-2"><a href="/careers/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-careers">Careers</a></li><li class="mb-2"><a href="/about/newsroom/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-newsroom">Newsroom</a></li><li class="mb-2"><a href="/awards/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-awards">Awards</a></li><li class="mb-2"><a href="/security/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-security">Security</a></li><li class="mb-2"><a href="https://brand.pulumi.com/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-brand">Brand</a></li></ul></nav><nav aria-label="Get help"><h3 class="footer-heading">Get help</h3><ul><li class="mb-2"><a href="https://slack.pulumi.com/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-help-slack">Join our Slack</a></li><li class="mb-2"><a href="/support/new/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-support">Customer support</a></li><li class="mb-2"><a href="/proserv/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-professional-services">Professional services</a></li><li class="mb-2"><a href="/request-a-demo/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-help-demo">Request a demo</a></li><li class="mb-2"><a href="/contact/" class="text-sm text-white hover:text-violet-300 hover:underline" data-track="footer-contact-us">Contact us</a></li></ul></nav></div><div class="flex flex-col gap-8 lg:pr-20"><div><h3 class="footer-heading">Connect</h3><ul class="flex gap-4 items-center"><li><a href="https://slack.pulumi.com/" target="_blank" rel="noopener" class="inline-flex items-center justify-center text-white opacity-85 hover:opacity-100 transition-opacity duration-150" data-track="footer-slack" aria-label="Pulumi Slack"><svg class="ph-icon" fill="currentColor" width="24" height="24" style="width:24px;height:24px" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-slack"/></svg></a></li><li><a href="https://github.com/pulumi/" target="_blank" rel="noopener" class="inline-flex items-center justify-center text-white opacity-85 hover:opacity-100 transition-opacity duration-150" data-track="footer-github" aria-label="Pulumi GitHub"><svg class="ph-icon" fill="currentColor" width="24" height="24" style="width:24px;height:24px" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-github"/></svg></a></li><li><a href="https://www.youtube.com/channel/UC2Dhyn4Ev52YSbcpfnfP0Mw" target="_blank" rel="noopener" class="inline-flex items-center justify-center text-white opacity-85 hover:opacity-100 transition-opacity duration-150" data-track="footer-youtube" aria-label="Pulumi YouTube"><svg class="ph-icon" fill="currentColor" width="24" height="24" style="width:24px;height:24px" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-youtube"/></svg></a></li><li><a href="https://x.com/pulumicorp" target="_blank" rel="noopener" class="inline-flex items-center justify-center text-white opacity-85 hover:opacity-100 transition-opacity duration-150" data-track="footer-twitter" aria-label="Pulumi X"><svg class="ph-icon" fill="currentColor" width="24" height="24" style="width:24px;height:24px" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-x"/></svg></a></li><li><a href="https://www.linkedin.com/company/pulumi/" target="_blank" rel="noopener" class="inline-flex items-center justify-center text-white opacity-85 hover:opacity-100 transition-opacity duration-150" data-track="footer-linkedin" aria-label="Pulumi LinkedIn"><svg class="ph-icon" fill="currentColor" width="24" height="24" style="width:24px;height:24px" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-linkedin"/></svg></a></li><li><a href="https://bsky.app/profile/pulumi.com" target="_blank" rel="noopener" class="inline-flex items-center justify-center text-white opacity-85 hover:opacity-100 transition-opacity duration-150" data-track="footer-bluesky" aria-label="Pulumi Bluesky"><svg class="ph-icon" fill="currentColor" width="24" height="24" style="width:24px;height:24px" aria-hidden="true" focusable="false"><use href="/icons/sprite.2cfc50dc64f04f7b5954b97ba2422ad621d10a8effc0d817cc0c25ec709e052a.svg#b-bluesky"/></svg></a></li></ul></div><div><h3 class="footer-heading">Get our newsletter</h3><pulumi-hubspot-form form-id="027b4c6d-9b73-4ad8-b149-3c8b07fff608" class="newsletter newsletter-dark-border newsletter-inline"></pulumi-hubspot-form></div></div></div><div class="mt-24 pt-6 flex flex-col lg:flex-row gap-4 lg:gap-6 items-center justify-between lg:mr-32"><ul class="text-xs flex flex-wrap gap-x-4 gap-y-2 justify-center lg:justify-start items-center"><li><a class="text-white opacity-70 hover:opacity-100 hover:underline cursor-pointer" data-track="footer-legal-privacy-preferences" onclick=window.consentManager&&window.consentManager.openConsentManager()>Your Privacy Preferences</a></li><li><a class="text-white opacity-70 hover:opacity-100 hover:underline" data-track="footer-legal-trademark-usage" href="/trademark/">Trademark Usage</a></li><li><a class="text-white opacity-70 hover:opacity-100 hover:underline" data-track="footer-legal-acceptable-use-policy" href="/acceptable-use/">Acceptable Use Policy</a></li><li><a class="text-white opacity-70 hover:opacity-100 hover:underline" data-track="footer-legal-terms-conditions" href="/terms-and-conditions/">Terms & Conditions</a></li><li><a class="text-white opacity-70 hover:opacity-100 hover:underline" data-track="footer-legal-privacy-policy" href="/privacy/">Privacy Policy</a></li><li><a class="text-white opacity-70 hover:opacity-100 hover:underline" data-track="footer-legal-professional-services-agreement" href="/professional-services-agreement/">Professional Services Agreement</a></li><li><span class="text-xs text-gray-500">&copy; 2026 Pulumi Corp.</span></li></ul><a class="inline-flex items-center gap-1.5 px-2 py-0.5 min-h-[24px] rounded-lg bg-service-black border border-gray-800 text-white text-sm leading-5 whitespace-nowrap hover:border-gray-500 hover:no-underline" href="https://pulumi.statuspage.io/" target="_blank" rel="noopener" data-statuspage data-track="footer-statuspage" aria-label="Pulumi system status"><span class="inline-block w-2 h-2 rounded-full shrink-0" data-statuspage-dot aria-hidden="true"></span>
<span data-statuspage-label>All Systems Operational</span></a></div></footer><div id="segment-consent-manager"></div></body></html>