No thanks I'll just write JavaScript
I read everything and I still don’t understand why.
This is in fact how I manage Kubernetes manifests.
I use this package: https://www.npmjs.com/package/kubernetes-models
Then I write normal TypeScript code to create Kubernetes objects/resources.
Then I render it to JSON and feed to kubectl.
The beauty of this solution is that it’s OOP and DRY.
He has a TS script that outputs JSON, which he is using as config.
He might trust his code, but I was highlighting reasons why this is not true everywhere, and indeed the ability to evaluate untrusted code can open up previously unavailable avenues. For example, storing server-side Jsonnet that can be safely evaluated by a multitenant backend.