Kubernetes & Containers

Kubernetes in Production — The Complete Checklist

Running a cluster isn't enough. This guide details the availability, security, and observability controls that separate a development cluster from a platform truly ready for production.

September 2026

According to the 2026 edition of the CNCF annual survey, 82% of container users now run Kubernetes in production, up from 66% in 2023. But "it runs" and "it's production-ready" remain two different things.

25% of cloud security incidents involve a misconfigured service, according to the IBM X-Force Threat Intelligence Index — not the exploitation of a novel vulnerability.

Availability: the single-replica trap

A service deployed with a single replica has, by definition, zero fault tolerance.

Best practice: at least 3 replicas per critical service, spread across multiple zones, with a PodDisruptionBudget to prevent a node update from taking down too many replicas at once.

Security: RBAC, network, containers

Kubernetes security plays out on three levels: who can act on the cluster (RBAC scoped by namespace), who can talk to whom (explicit NetworkPolicies), and what a compromised container can reach (non-root user, reduced capabilities).

A dashboard or API server exposed without authentication remains one of the most documented misconfigurations.

Key takeaways

  • Every critical service runs with at least 3 replicas spread across multiple zones
  • A PodDisruptionBudget protects each critical workload during node updates
  • RBAC applies least privilege, without broad ClusterRoleBindings
  • NetworkPolicies restrict east-west traffic between namespaces
  • Metrics, logs, and traces are centralized and alerting
  • The persistent volume backup plan has been restored in a test

YOUR GUIDE TO KEEP

Kubernetes in Production — The Complete Checklist

Get the complete guide to explore the topic further and share best practices with your team.

Download the PDF

Free PDF · Direct access

Ready to put it into practice?

Our experts help you move your cloud projects forward.

Go further

Kubernetes Gateway API: Migrating from Nginx IngressKubernetes & Conteneurs

Kubernetes Gateway API: Migrating from Nginx Ingress

The Gateway API became GA in Kubernetes 1.31 and is gradually replacing the Ingress. More expressive, multi-tenant and extensible — here is how to migrate your workloads.

Kubernetes vs Docker Swarm: Which Orchestrator to Choose?Kubernetes & Conteneurs

Kubernetes vs Docker Swarm: Which Orchestrator to Choose?

Docker Swarm is simple, Kubernetes is powerful. In 2025, which should you choose? A pragmatic comparison to help you decide based on your real needs.

BNP ParibasCase Study

BNP Paribas

Keep critical banking services running through technical failures and cyberattacks.