Here's an example of Vaultwarden running on my K8s cluster:
deployment: bitwarden: {
spec: {
template: {
spec: {
containers: [{
image: "vaultwarden/server:1.32.7"
env: [{
name: "ROCKET_PORT"
value: "8080"
}, {
name: "ADMIN_TOKEN"
valueFrom: secretKeyRef: {
name: "bitwarden-secrets"
key: "ADMIN_TOKEN"
}
}]
volumeMounts: [{
name: "data"
mountPath: "/data"
subPath: "bitwarden"
}]
ports: [{
containerPort: 8080
name: "web"
}]
}]
volumes: [{
name: "data"
persistentVolumeClaim: claimName: "local-pvc"
}]
}
}
}
}
And simpler services are, well, even simpler: deployment: myapp: spec: template: spec: containers: [{
ports: [{
containerPort: 8080
name: "web"
}]
}]
And with Cue, you get strongly typed values for everything, and can add tighter constraints as well. This expands to the relevant YAML resources (Services, Deployments, etc), which then get applied to the cluster. The nice thing of this approach is that the cluster doesn't need to know anything about how you manage your resources.