kubernetes
Kubernetes YAML Examples: Deployments, Services, ConfigMaps
Intermediate
15 minutes
October 2026
CloudOpsGuide Team
Kubernetes YAML Examples: Deployments, Services, ConfigMaps
Collection of essential Kubernetes YAML templates with explanations for common deployment scenarios.
Table of Contents
- Basic Deployment
- Service Configuration
- ConfigMap Usage
- Secret Management
- Ingress Configuration
- Horizontal Pod Autoscaler
- StatefulSet Example
- DaemonSet Example
Basic Deployment
Simple Deployment
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deployment
labels:
app: nginx
spec:
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx:1.25
ports:
- containerPort: 80
resources:
requests:
memory: "64Mi"
cpu: "250m"
limits:
memory: "128Mi"
cpu: "500m"
Key Components:
replicas: Number of pod copiesselector: Matches pods to deploymenttemplate: Pod template specificationresources: CPU and memory limits
Deployment with Environment Variables
apiVersion: apps/v1
kind: Deployment
metadata:
name: app-deployment
spec:
replicas: 2
selector:
matchLabels:
app: myapp
template:
metadata:
labels:
app: myapp
spec:
containers:
- name: myapp
image: myapp:latest
env:
- name: DATABASE_URL
value: "postgresql://db:5432/mydb"
- name: API_KEY
valueFrom:
secretKeyRef:
name: app-secrets
key: api-key
- name: LOG_LEVEL
value: "info"
ports:
- containerPort: 3000
Service Configuration
ClusterIP Service
apiVersion: v1
kind: Service
metadata:
name: nginx-service
spec:
type: ClusterIP
selector:
app: nginx
ports:
- protocol: TCP
port: 80
targetPort: 80
NodePort Service
apiVersion: v1
kind: Service
metadata:
name: nginx-nodeport
spec:
type: NodePort
selector:
app: nginx
ports:
- protocol: TCP
port: 80
targetPort: 80
nodePort: 30080
LoadBalancer Service
apiVersion: v1
kind: Service
metadata:
name: nginx-loadbalancer
spec:
type: LoadBalancer
selector:
app: nginx
ports:
- protocol: TCP
port: 80
targetPort: 80
ConfigMap Usage
ConfigMap from Literal Values
apiVersion: v1
kind: ConfigMap
metadata:
name: app-config
data:
database.host: "postgres"
database.port: "5432"
cache.ttl: "3600"
app.debug: "false"
ConfigMap from File
apiVersion: v1
kind: ConfigMap
metadata:
name: nginx-config
data:
nginx.conf: |
server {
listen 80;
server_name localhost;
location / {
root /usr/share/nginx/html;
index index.html;
}
}
Using ConfigMap in Pod
apiVersion: v1
kind: Pod
metadata:
name: configmap-pod
spec:
containers:
- name: app
image: myapp:latest
envFrom:
- configMapRef:
name: app-config
volumeMounts:
- name: config-volume
mountPath: /etc/config
volumes:
- name: config-volume
configMap:
name: nginx-config
Secret Management
Creating Secret from Literal
kubectl create secret generic db-secret \
--from-literal=username=admin \
--from-literal=password=secret123
Secret YAML
apiVersion: v1
kind: Secret
metadata:
name: db-secret
type: Opaque
data:
username: YWRtaW4= # base64 encoded "admin"
password: c2VjcmV0MTIz # base64 encoded "secret123"
Using Secret in Pod
apiVersion: v1
kind: Pod
metadata:
name: secret-pod
spec:
containers:
- name: app
image: myapp:latest
env:
- name: DB_USERNAME
valueFrom:
secretKeyRef:
name: db-secret
key: username
- name: DB_PASSWORD
valueFrom:
secretKeyRef:
name: db-secret
key: password
Ingress Configuration
Basic Ingress
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: nginx-ingress
annotations:
nginx.ingress.kubernetes.io/rewrite-target: /
spec:
ingressClassName: nginx
rules:
- host: example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: nginx-service
port:
number: 80
Ingress with TLS
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: tls-ingress
annotations:
cert-manager.io/cluster-issuer: "letsencrypt-prod"
spec:
ingressClassName: nginx
tls:
- hosts:
- example.com
secretName: example-tls
rules:
- host: example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: nginx-service
port:
number: 80
Horizontal Pod Autoscaler
HPA Based on CPU
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: nginx-hpa
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: nginx-deployment
minReplicas: 2
maxReplicas: 10
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 50
HPA Based on Memory
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: app-hpa
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: app-deployment
minReplicas: 1
maxReplicas: 5
metrics:
- type: Resource
resource:
name: memory
target:
type: Utilization
averageUtilization: 70
StatefulSet Example
StatefulSet for Database
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: postgres
spec:
serviceName: postgres
replicas: 3
selector:
matchLabels:
app: postgres
template:
metadata:
labels:
app: postgres
spec:
containers:
- name: postgres
image: postgres:15
ports:
- containerPort: 5432
name: postgres
volumeMounts:
- name: postgres-storage
mountPath: /var/lib/postgresql/data
env:
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
name: postgres-secret
key: password
volumeClaimTemplates:
- metadata:
name: postgres-storage
spec:
accessModes: [ "ReadWriteOnce" ]
resources:
requests:
storage: 10Gi
DaemonSet Example
DaemonSet for Monitoring
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: node-exporter
spec:
selector:
matchLabels:
app: node-exporter
template:
metadata:
labels:
app: node-exporter
spec:
hostNetwork: true
containers:
- name: node-exporter
image: prom/node-exporter:latest
ports:
- containerPort: 9100
hostPort: 9100
resources:
requests:
memory: "64Mi"
cpu: "100m"
limits:
memory: "128Mi"
cpu: "200m"
Complete Example: Full Stack Application
Deployment + Service + ConfigMap + Secret
---
# ConfigMap
apiVersion: v1
kind: ConfigMap
metadata:
name: app-config
data:
app.env: "production"
app.port: "3000"
---
# Secret
apiVersion: v1
kind: Secret
metadata:
name: app-secret
type: Opaque
data:
db-password: c2VjcmV0
---
# Deployment
apiVersion: apps/v1
kind: Deployment
metadata:
name: fullstack-app
spec:
replicas: 3
selector:
matchLabels:
app: fullstack
template:
metadata:
labels:
app: fullstack
spec:
containers:
- name: app
image: fullstack:latest
ports:
- containerPort: 3000
envFrom:
- configMapRef:
name: app-config
env:
- name: DB_PASSWORD
valueFrom:
secretKeyRef:
name: app-secret
key: db-password
resources:
requests:
memory: "128Mi"
cpu: "250m"
limits:
memory: "256Mi"
cpu: "500m"
livenessProbe:
httpGet:
path: /health
port: 3000
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
httpGet:
path: /ready
port: 3000
initialDelaySeconds: 5
periodSeconds: 5
---
# Service
apiVersion: v1
kind: Service
metadata:
name: fullstack-service
spec:
type: ClusterIP
selector:
app: fullstack
ports:
- protocol: TCP
port: 80
targetPort: 3000
---
# HPA
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: fullstack-hpa
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: fullstack-app
minReplicas: 3
maxReplicas: 10
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 70
Best Practices
- Always use labels - For identification and selection
- Set resource limits - Prevent resource exhaustion
- Use health checks - For automatic recovery
- Version your images - Avoid
latesttag - Use secrets for sensitive data - Never in ConfigMaps
- Document your YAML - Add comments
- Use kubectl dry-run - Validate before applying
- Use names consistently - Related resources
- Implement RBAC - For security
- Monitor your deployments - Set up alerts
Useful Commands
# Apply YAML file
kubectl apply -f deployment.yaml
# Validate without applying
kubectl apply --dry-run=client -f deployment.yaml
# Get YAML from running resource
kubectl get deployment nginx -o yaml
# Explain resource fields
kubectl explain deployment.spec.template.spec
# Delete resources
kubectl delete -f deployment.yaml
Related Articles
Last Updated: October 2026
Author: CloudOpsGuide Team
Difficulty: Intermediate
Estimated Reading Time: 15 minutes