DevOps & Config Tools

Kubernetes YAML Generator

Describe your app once and get every manifest it needs to run on Kubernetes, ready for kubectl apply: a Namespace, a ConfigMap for settings, a Secret template for credentials, a Deployment with health checks, resource requests and a restricted security context, a Service, an Ingress with HTTPS through cert-manager, a HorizontalPodAutoscaler and a PodDisruptionBudget.

  • Runs in your browser
  • No sign-up
  • Free to use
Start from an example

0 = no autoscaling.

Include

    How to use Kubernetes YAML Generator

    1. Enter the app name, namespace, image and port.
    2. Add settings, secret names and a public host name.
    3. Choose size, autoscaling and extras.
    4. Download app.yaml and run kubectl apply -f app.yaml.

    Kubernetes YAML Generator features

    Whole app

    Namespace, ConfigMap, Secret, Deployment, Service, Ingress, HPA, PDB.

    Health checks

    Readiness and liveness probes on your health path.

    Secure defaults

    Non-root, read-only root, dropped capabilities, seccomp.

    HTTPS

    Ingress with a cert-manager certificate.

    Scaling

    CPU-based autoscaling and disruption budget.

    Valid YAML

    Consistent labels, names and quoting.

    When to use Kubernetes YAML Generator

    • Deploying a first app to a new cluster.
    • Creating a consistent starting point for every service.
    • Learning how Kubernetes objects fit together.
    • Producing manifests to convert into a Helm chart or Kustomize base.

    Kubernetes YAML Generator FAQ

    Which Kubernetes version is needed?

    The manifests use stable APIs: apps/v1, networking.k8s.io/v1, autoscaling/v2 and policy/v1, supported by Kubernetes 1.23 and later.

    Why is there no CPU limit?

    CPU limits throttle an app even when the node has spare CPU. A CPU request reserves capacity, and a memory limit protects the node.

    How do I fill in the Secret?

    The Secret contains REPLACE_ME placeholders. Create the real Secret with kubectl, or use Sealed Secrets, External Secrets or SOPS, and never commit real values.

    What does the PodDisruptionBudget do?

    It keeps at least one pod running during voluntary disruptions such as node upgrades.

    Do I need an ingress controller?

    Yes. An Ingress needs a controller such as ingress-nginx or Traefik, and the TLS certificate needs cert-manager.

    Is anything uploaded?

    No. The manifests are generated in your browser.

    Everything an app needs on Kubernetes

    Running a simple web service on Kubernetes takes several objects that reference each other: a Deployment runs the pods, a Service gives them a stable address, an Ingress routes external traffic, ConfigMaps and Secrets hold configuration, and an autoscaler adjusts the number of replicas. Getting the labels, names and ports consistent across all of them is where most mistakes happen.

    This generator writes them together from one description, so the selector labels, service names and port names always match. Labels follow the recommended app.kubernetes.io scheme, and every object goes into the namespace you choose.

    The Deployment follows current best practice. Readiness probes keep traffic away from pods that are not ready, liveness probes restart stuck ones, and resources reserve CPU and cap memory. The security context runs the container as a non-root user with a read-only root file system, no extra capabilities and the default seccomp profile, with an emptyDir mounted at /tmp for temporary files.

    Configuration is split by sensitivity. Plain settings go into a ConfigMap loaded with envFrom; secret names become a Secret template with placeholders, because real secrets should be created separately and never committed. Both are mounted as environment variables.

    For public apps, the Ingress routes the host name to the Service and requests a TLS certificate from cert-manager. With autoscaling, a HorizontalPodAutoscaler adds replicas when CPU usage passes 70 percent, and a PodDisruptionBudget keeps the app available during node maintenance.

    Other useful tools