Kustomize · Cheat sheet

Kustomize cheat sheet

Kustomize cheat sheet: build/apply, generators, patches, replacements, components, image setters, and migrating deprecated fields.

44 commands·6 sections·Updated ·By SecOpsLog

Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.

Build & apply

Beginner
kubectl kustomize base/
Render a kustomization to stdout (built into kubectl).
kustomize build overlays/prod
Render with the standalone CLI (newer features).
kubectl apply -k overlays/prod
Build and apply in one step.
kubectl delete -k overlays/prodDestructive
Delete everything the overlay renders.Destructive: Deletes everything the overlay renders, including its Namespace and PVCs.
kustomize build overlays/prod | kubectl diff -f -
Preview the change before applying.
kustomize build overlays/prod | kubectl apply --dry-run=server -f -
Check the rendered output against the API server (schema, admission) without changing anything.
kustomize version
Print the CLI version.
kustomize edit add resource deploy.yaml
Append to resources from the CLI (also: add component, add patch).
kustomize edit set namespace prod
Set the namespace field without hand-editing YAML.
kustomize localize overlays/prod vendored
Alpha: copy the kustomization and its remote bases into a local tree for offline, pinned builds (Helm and KRM plugin fields are not localized).
kustomize build --load-restrictor LoadRestrictionsNone overlays/prodCaution
Allow loading files outside the kustomization root (off by default).Caution: The build can read files outside the kustomization root; relocatability is lost.

kustomization.yaml basics

Beginner
resources: [deploy.yaml, svc.yaml]
The base manifests this kustomization includes.
namespace: prod
Set the namespace on every resource.
namePrefix: prod- / nameSuffix: -v2
Prefix/suffix all names (and references).Example output
metadata:
  name: prod-web-v2
commonLabels: { app: web }
Add labels to all resources AND their selectors (deprecated since v5.3.0; use labels).
commonAnnotations: { team: sre }
Annotate every resource.
labels: [{ pairs: {env: prod}, includeSelectors: false }]
Newer, finer-grained label control.
labels: [{ pairs: {team: sre}, includeTemplates: true }]
Label resources and their pod templates while leaving selectors alone.

Generators

Intermediate
configMapGenerator: [{ name: cfg, literals: [LOG=info] }]
Generate a ConfigMap from literals/files.Example output
name: cfg-2g5h8k9t2c   # content hash suffix
configMapGenerator: [{ name: cfg, files: [app.conf] }]
ConfigMap from file contents.
configMapGenerator: [{ name: env, envs: [.env] }]
ConfigMap from a dotenv file.
secretGenerator: [{ name: db, literals: [pass=s3cr3t] }]Exposes secrets
Generate a Secret the same way.Exposes secrets: The literal lives in kustomization.yaml, so it ends up in Git.
configMapGenerator: [{ name: cfg, behavior: merge, literals: [LOG=debug] }]
In an overlay, change keys of a ConfigMap the base generates; its other keys are kept.
generatorOptions: { disableNameSuffixHash: true }
Turn off the content-hash suffix.

Images & replicas

Intermediate
images: [{ name: nginx, newTag: "1.30" }]
Pin an image tag without editing manifests.
images: [{ name: nginx, newName: reg.io/nginx }]
Swap the image name/registry.
images: [{ name: nginx, digest: sha256:... }]
Pin by immutable digest.
replicas: [{ name: web, count: 5 }]
Override replica count per workload.
kustomize edit set image nginx=nginx:1.30
Edit kustomization.yaml from the CLI.

Patches

Intermediate
patches: [{ path: cpu.yaml, target: { kind: Deployment } }]
Patch resources matching a selector.
patchesStrategicMerge: [patch.yaml]
Overlay a partial manifest (deprecated in v5.0.0; use patches).
kustomize edit fix
Rewrite deprecated fields (bases, commonLabels, patchesStrategicMerge, patchesJson6902); commonLabels becomes labels with includeSelectors: true, so selectors stay the same.
kustomize edit fix --vars
Also convert legacy vars to replacements (marked experimental: run it in a clean Git tree and review the diff).
bases: [../base] / vars: [...]
Legacy fields, still read with a deprecation warning: list bases under resources, and use replacements instead of vars.
patches: - target: { kind: Deployment, name: web } patch: |- - op: replace path: /spec/replicas value: 3
An inline JSON 6902 patch: explicit operations for fields and list items a strategic merge cannot express.
target: { labelSelector: "tier=web" }
Aim a patch with a label selector.

Bases, overlays & components

Advanced
resources: [../../base]
An overlay references a base kustomization.
resources: [https://github.com/org/app//deploy?ref=v1.4.0]
Remote base pinned to a tag or commit; an unpinned ref changes under you.
components: [../../components/logging]
Reusable mixins applied across overlays.
apiVersion: kustomize.config.k8s.io/v1alpha1 kind: Component
A component's own kustomization.yaml header; overlays opt in with components:.
replacements: - source: { kind: Service, name: web, fieldPath: metadata.name } targets: - select: { kind: Deployment, name: web } fieldPaths: ["spec.template.spec.containers.[name=app].env.[name=SVC].value"]
Copy the final Service name (after prefixes) into a container env var; quote field paths that contain [name=...].
helmCharts: [{ name: redis, releaseName: cache, valuesInline: {} }]
Inflate a Helm chart through Kustomize; without repo the chart is read from ./charts/redis, and with repo add version to pin it. Needs --enable-helm.
kustomize build --enable-helm overlays/prod
Enable the Helm chart inflator.
buildMetadata: [originAnnotations]
Annotate each output object with the file it came from (debugging overlays).

Primary references

Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.

Go deeper
Hands-on courses for Kustomize