SkillVaultskills Browse all 500 skills

Infrastructure · Version 1.6.0 · Reviewed 2026-08-02

Kubernetes Upgrade Planner

Review and harden API deprecation inventory and node-pool sequencing with evidence, explicit trade-offs, and a verification plan.

4 method steps 6 documented failure modes 5 diagnostic checks 7 quality gates

Plans control-plane and node upgrades around API removals, add-on compatibility, workload disruption, skew policy, and rollback constraints.

₹99 one-time

Get this skill archive

What this skill helps you do

  • API deprecation inventory
  • Node-pool sequencing
  • Add-on compatibility review

How Kubernetes Upgrade Planner works

You provide

Current state, consumer inventory, and target state

It inspects

Coexistence and rollback viability for API deprecation inventory

It decides

A node-pool sequencing sequence in reversible increments

You verify

Shadow comparison reports divergence rather than assuming zero

What it checks first

Kubernetes Upgrade Planner plans control-plane and node upgrades around API removals, add-on compatibility, workload disruption, skew policy, and rollback constraints. Use it when the work involves API deprecation inventory, Node-pool sequencing, Add-on compatibility review.

  1. Whether the old and new paths can coexist, which determines if incremental migration is possible at all.
  2. The true consumer inventory, including internal jobs, scripts, and integrations not visible in the main codebase.
  3. Data volume and the time the migration takes at production scale, not sample scale.
  4. Whether the change is backward compatible for data written by the previous version during rollout.
  5. The rollback path, and specifically whether it remains available after the first irreversible step.

Failure modes it recognizes

  • A migration validated on a sample that takes hours on production volume and holds a lock throughout.
  • Dual-write divergence where one write succeeds and the other fails, with no reconciliation.
  • A backfill that races with live writes and overwrites newer values with older ones.
  • Removing the old path before all consumers migrated, discovered by a quarterly batch job weeks later.
  • A schema change that is forward compatible but not backward compatible, blocking rollback.
  • Enum or type widening that older readers cannot parse, breaking during a partial rollout.

Answers it will reject

  • A big-bang cutover with a maintenance window, which concentrates all risk into one unrehearsed moment.
  • Migrating and refactoring simultaneously, which makes failures impossible to attribute.
  • Treating the migration as done at cutover rather than after the old path is removed and verified unused.
  • Skipping the shadow-read comparison because the new implementation "obviously" matches.

Decision rules it applies

  • Use expand-migrate-contract: add the new shape, write both, migrate readers, then remove the old shape.
  • Every increment must be independently verifiable and independently revertible.
  • Keep the old path observable until traffic proves equivalence; remove it only on evidence of zero use.
  • Prefer additive schema changes; a removal is a separate, later, deliberately scheduled change.

Evidence it asks for

  • Run shadow reads comparing old and new outputs, and report the divergence rate rather than assuming zero.
  • Instrument usage of the deprecated path with a caller identifier so removal can be proven safe.
  • Rehearse the migration on a production-sized copy and record the actual duration and lock behavior.

The method inside

  1. Inventory dependencies, compatibility constraints, and current behavior affecting API deprecation inventory.
  2. Create reversible seams for node-pool sequencing before changing the critical path.
  3. Sequence add-on compatibility review into independently verifiable increments with explicit rollback points.
  4. Keep old and new paths observable until equivalence is proven; remove the fallback only after acceptance criteria pass.

Deliverables

  • API deprecation inventory assessment
  • Node-pool sequencing decision and action plan
  • Add-on compatibility review verification checklist

Evidence requirements

  • Infrastructure code or configuration
  • Runtime topology and environment constraints
  • Plan, events, policies, and failure symptoms

Quality gates

  • Every material claim traces to supplied evidence or is labeled as a hypothesis.
  • The response follows the declared deliverable contract.
  • No execution, access, measurement, or verification is invented.
  • Secrets and personal data are redacted rather than repeated.
  • The user receives a concrete independent verification step.
  • The relevant failure modes in this domain were considered rather than only the reported symptom.
  • No listed anti-pattern was recommended as a solution.

Example task

Input

Plan our upgrade from Kubernetes 1.27 to 1.30 with minimal risk across four production clusters.

Expected output

First scan stored and deployed resources for APIs removed in 1.29, then validate CNI, CSI, ingress, and policy add-ons. Upgrade one noncritical cluster, control plane before nodes, and node pools one zone at a time...

Boundaries and compatibility

Ideal for

  • API deprecation inventory: produce a decision or artifact grounded in supplied evidence.
  • Node-pool sequencing: produce a decision or artifact grounded in supplied evidence.
  • Add-on compatibility review: produce a decision or artifact grounded in supplied evidence.

Out of scope

  • Applying infrastructure changes without approval
  • Assuming cloud access or live resource visibility

Agent compatibility

  • GitHub Copilot custom agents
  • Claude Agent Skills / SKILL.md
  • Any instruction-following chat model

Tool policy: Advisory by default. No tools are assumed. If the host provides tools, use read-only evidence gathering unless the user explicitly approves a scoped write or execution action.