| Creating a cluster securely | Write and maintain a Terraform module, hardening as separate steps | Wizard, secure by default, repeatable |
|---|
| Deploying an application | A chart per app, a workflow per repo, secrets by hand | Service with build, variables encrypted, registry check |
|---|
| Database per service | Instance in the console, CREATE DATABASE via psql, password in the chat | One click on the service page, private instance |
|---|
| Domain and certificate | external-dns, cert-manager, issuer, keeping an eye on rate limits | Enter the host, record and certificate created automatically, warning 14 days ahead |
|---|
| New customer | Script or runbook, known to one person | Pipeline, orderable from the app, rollback included |
|---|
| Customer cancels | Delete and hope someone made a backup first | Dump and archive, then teardown; aborts without a backup |
|---|
| Kubernetes upgrade | Console, read changelogs, check add-ons | Target versions, compatibility, add-on drift in the cockpit |
|---|
| Access and evidence | Hand out and collect kubeconfigs | Roles, mandatory 2FA, audit log |
|---|
| New colleague | Read the wiki, collect credentials, one to two days | Assign a role, grant access to projects |
|---|