Kustomize · Cheat sheet
Kustomize cheat sheet
Kustomize cheat sheet: build/apply, generators, patches, replacements, components, image setters, and migrating deprecated fields.
Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.
Build & apply
Beginnerkubectl kustomize base/- Render a kustomization to stdout (built into kubectl).
kustomize build overlays/prod- Render with the standalone CLI (newer features).
kubectl apply -k overlays/prod- Build and apply in one step.
kubectl delete -k overlays/prodDestructive- Delete everything the overlay renders.Destructive: Deletes everything the overlay renders, including its Namespace and PVCs.
kustomize build overlays/prod | kubectl diff -f -- Preview the change before applying.
kustomize build overlays/prod | kubectl apply --dry-run=server -f -- Check the rendered output against the API server (schema, admission) without changing anything.
kustomize version- Print the CLI version.
kustomize edit add resource deploy.yaml- Append to resources from the CLI (also: add component, add patch).
kustomize edit set namespace prod- Set the namespace field without hand-editing YAML.
kustomize localize overlays/prod vendored- Alpha: copy the kustomization and its remote bases into a local tree for offline, pinned builds (Helm and KRM plugin fields are not localized).
kustomize build --load-restrictor LoadRestrictionsNone overlays/prodCaution- Allow loading files outside the kustomization root (off by default).Caution: The build can read files outside the kustomization root; relocatability is lost.
kustomization.yaml basics
Beginnerresources: [deploy.yaml, svc.yaml]- The base manifests this kustomization includes.
namespace: prod- Set the namespace on every resource.
namePrefix: prod- / nameSuffix: -v2- Prefix/suffix all names (and references).Example output
metadata: name: prod-web-v2
commonLabels: { app: web }- Add labels to all resources AND their selectors (deprecated since v5.3.0; use labels).
commonAnnotations: { team: sre }- Annotate every resource.
labels: [{ pairs: {env: prod}, includeSelectors: false }]- Newer, finer-grained label control.
labels: [{ pairs: {team: sre}, includeTemplates: true }]- Label resources and their pod templates while leaving selectors alone.
Generators
IntermediateconfigMapGenerator: [{ name: cfg, literals: [LOG=info] }]- Generate a ConfigMap from literals/files.Example output
name: cfg-2g5h8k9t2c # content hash suffix
configMapGenerator: [{ name: cfg, files: [app.conf] }]- ConfigMap from file contents.
configMapGenerator: [{ name: env, envs: [.env] }]- ConfigMap from a dotenv file.
secretGenerator: [{ name: db, literals: [pass=s3cr3t] }]Exposes secrets- Generate a Secret the same way.Exposes secrets: The literal lives in kustomization.yaml, so it ends up in Git.
configMapGenerator: [{ name: cfg, behavior: merge, literals: [LOG=debug] }]- In an overlay, change keys of a ConfigMap the base generates; its other keys are kept.
generatorOptions: { disableNameSuffixHash: true }- Turn off the content-hash suffix.
Images & replicas
Intermediateimages: [{ name: nginx, newTag: "1.30" }]- Pin an image tag without editing manifests.
images: [{ name: nginx, newName: reg.io/nginx }]- Swap the image name/registry.
images: [{ name: nginx, digest: sha256:... }]- Pin by immutable digest.
replicas: [{ name: web, count: 5 }]- Override replica count per workload.
kustomize edit set image nginx=nginx:1.30- Edit kustomization.yaml from the CLI.
Patches
Intermediatepatches: [{ path: cpu.yaml, target: { kind: Deployment } }]- Patch resources matching a selector.
patchesStrategicMerge: [patch.yaml]- Overlay a partial manifest (deprecated in v5.0.0; use patches).
kustomize edit fix- Rewrite deprecated fields (bases, commonLabels, patchesStrategicMerge, patchesJson6902); commonLabels becomes labels with includeSelectors: true, so selectors stay the same.
kustomize edit fix --vars- Also convert legacy vars to replacements (marked experimental: run it in a clean Git tree and review the diff).
bases: [../base] / vars: [...]- Legacy fields, still read with a deprecation warning: list bases under resources, and use replacements instead of vars.
patches: - target: { kind: Deployment, name: web } patch: |- - op: replace path: /spec/replicas value: 3- An inline JSON 6902 patch: explicit operations for fields and list items a strategic merge cannot express.
target: { labelSelector: "tier=web" }- Aim a patch with a label selector.
Bases, overlays & components
Advancedresources: [../../base]- An overlay references a base kustomization.
resources: [https://github.com/org/app//deploy?ref=v1.4.0]- Remote base pinned to a tag or commit; an unpinned ref changes under you.
components: [../../components/logging]- Reusable mixins applied across overlays.
apiVersion: kustomize.config.k8s.io/v1alpha1 kind: Component- A component's own kustomization.yaml header; overlays opt in with components:.
replacements: - source: { kind: Service, name: web, fieldPath: metadata.name } targets: - select: { kind: Deployment, name: web } fieldPaths: ["spec.template.spec.containers.[name=app].env.[name=SVC].value"]- Copy the final Service name (after prefixes) into a container env var; quote field paths that contain [name=...].
helmCharts: [{ name: redis, releaseName: cache, valuesInline: {} }]- Inflate a Helm chart through Kustomize; without repo the chart is read from ./charts/redis, and with repo add version to pin it. Needs --enable-helm.
kustomize build --enable-helm overlays/prod- Enable the Helm chart inflator.
buildMetadata: [originAnnotations]- Annotate each output object with the file it came from (debugging overlays).
Related
- Cheat sheetkubectl cheat sheet
- Cheat sheetHelm cheat sheet
- ComparisonHelm vs Kustomize
- Interview guideKubernetes interview questions
- Cheat sheetArgo CD cheat sheet
- ComparisonArgo CD vs Flux
- CourseKustomize
- CourseFlux
- CourseKubernetes fundamentals
- Field noteDebugging Pending pods: the five usual causes
- Field noteKubernetes liveness, readiness, startup probes done right
- Field noteKubernetes RBAC least privilege: from admin to scoped roles
Primary references
Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.
Go deeper
Hands-on courses for Kustomize