Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 25 / 30 · Build with evidence

Render configuration before delivery

Review the exact resulting manifests and keep deployment authority outside the template.

4 min read + practiceWorked exerciseInterview practice

The mechanism

Configuration composition helps reuse a base workload across environments. Kustomize can combine resources and apply targeted customization. The result still needs review as ordinary Kubernetes objects; a small overlay can produce a consequential change to image, namespace, privilege or network exposure.

A delivery workflow should separate source review, rendering, validation, authorization and rollout observation. GitOps is a broader operating pattern involving a reconciler and repository policy; a local Kustomize file alone does not implement it.

For ParcelOps, keep the base synthetic and make environment differences explicit. Avoid embedding credentials in overlays. Pin reviewed image references and preserve the rendered artifact used for validation so the deployed object can be compared with the reviewed intent.

Base + overlay
Rendered objects
Review + validation
Authorized delivery

Worked example

This offline kustomization example references local files only. It does not apply anything. The optional render command uses the locally installed kubectl client; inspect references first so the configuration does not pull remote bases unexpectedly.

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: handbook-lab
resources:
  - deployment.yaml
  - service.yaml
# Optional local rendering: kubectl kustomize .
# No apply command is executed by this handbook.

Practice: predict, inspect, explain

Offline exercise. Compare the rendered namespace, selector, image and security context with the intended design. Then imagine an overlay that changes Service type or adds a privileged container. Explain why a tiny source diff can still require substantial review.

Expected observation: review should follow the resulting object, not only the amount of changed text. Retain source revision, renderer version and rendered output together. Server-side admission and actual rollout remain later validation stages, not claims established by local rendering.

Troubleshooting and trade-offs

If two environments unexpectedly share a namespace or image, inspect overlay composition and rendering order. If a generated resource name changes, verify dependent references. Do not disable validation to make a template render. A delivery reconciler also needs a scoped identity; its access should not automatically equal cluster administration.

Interview practice

Why review rendered manifests?

Composition can hide consequential changes. The rendered objects show the actual configuration that would reach the API.

Does Kustomize itself implement GitOps?

No. It renders configuration. GitOps additionally involves repository policy, a reconciler, identity, drift handling and operational controls.

Completion check

Produce a rendered-object review checklist and separate rendering from deployment evidence.

Sources and version notes

Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.