Skip to content

/k8s-onboard — assess a new cluster (monitoring mode)

Context: $ARGUMENTS

Invoke kubernetes-platform-ops. Document first, change nothing. Sweep in this order, logging every command as read-only:

  1. Nodes & versions — count, roles (single master = SPOF), k8s version + EOL, OS/runtime, pressure
  2. Namespaces and what runs in each
  3. Workloads & images — versions, EOL, floating tags, requests/limits, replicas, PDBs
  4. Network — CNI, ingress class + TLS, LB pools (one announcer?), NetworkPolicies (any?)
  5. Storage — StorageClasses (a default?), PVs + reclaim policy, backups (any?)
  6. GitOps — ArgoCD apps: are they actually reconciling? prune/selfHeal posture
  7. Security — cluster-admin bindings, plaintext secrets, TLS coverage, PSA/Kyverno
  8. Observability — is anything actually alerting? (metrics-server? Prometheus/VM?)

Produce a findings list with severity + evidence for each item. Nothing is “fixed” without observed proof. This mirrors the ChisinauGaz cg-stage onboarding — see docs/CG-Stage/ if present.