GKE that a small team can actually run
Production Kubernetes on Google Cloud: clusters, GitOps, secrets and monitoring, built so your developers ship instead of babysitting nodes.
Sound familiar?
- The cluster was set up by someone who has since left, and nobody wants to touch it.
- Deploys mean
kubectlfrom a laptop, and rollbacks mean hoping. - Secrets live in environment variables, CI settings and a shared password manager.
- You pay for nodes that sit mostly idle, or pods get evicted at the worst moment.
What you get
Clusters in code
Networking, node pools, autoscaling and Workload Identity, reviewed like any other change.
GitOps with Argo CD
Every change is a pull request, every rollback is a revert.
Secrets without keys
Secret Manager through External Secrets, with no service account keys anywhere.
One Helm chart for every app
Autoscaling, disruption budgets and zone spread by default, so each service does not reinvent them.
Monitoring that matters
Dashboards and alerts that tell you about a problem before your users do.
A runbook
Docs your team can follow at 3 a.m., not just the person who built it.
How it runs
Review
You show me what runs and where it hurts. I look at the real setup, not a slide deck.
Plan
A short written plan: what changes, in what order, and how long it takes.
Build
Small steps you can review and roll back, dev before prod.
Handover
Docs and a runbook so your team can run it, with me on call if you want.
Where I've done this
- Built dev and prod on GKE from scratch for a B2B SaaS startup, then connected a cluster outside Google Cloud for Saudi data residency.
How the keyless part works → - Ran highly available production GKE clusters with autoscaling at InPost, with Istio mTLS and GitOps.