FuturByte

Hire Kubernetes developers

Kubernetes orchestrates containers across machines, and the most valuable thing a candidate can tell you is when not to use it.

What Kubernetes actually is

Kubernetes is an open-source system for running containers across a cluster of machines, originally from Google and now governed by the Cloud Native Computing Foundation. It schedules workloads onto nodes, restarts what fails, routes traffic, manages configuration and secrets, and scales services against demand. It has become the default answer for running containers at scale, and the default answer at scales where it is not warranted.

Its central idea is declarative reconciliation. You describe the state you want and controllers continuously work to make reality match. That is genuinely powerful and it is also why Kubernetes failures are confusing to newcomers: nothing failed in the sense of throwing an error, something simply has not converged, and understanding why means understanding what each controller is trying to do.

The honest commercial assessment is that Kubernetes solves real problems and creates a substantial operational surface in exchange. Networking, storage, upgrades, access control, resource management and cost all become things somebody owns. For an organisation with many services and several teams, that trade is usually worth it. For three services and four engineers, it frequently is not, and a good Kubernetes engineer will say so.

The part that separates seniors from mid-levels

Resource requests and limits are where most production problems originate, and they are the clearest test of real operating experience. Requests determine scheduling; limits determine throttling and termination. Set memory limits too low and the process is killed under load, producing crashes that look like application bugs. Set them too high and you pay for capacity nobody uses. Set CPU limits carelessly and you throttle a service that had plenty of headroom. Candidates who have tuned these on a real cluster describe them very differently from those who have copied examples.

Networking is the second area and the most commonly misunderstood. Services, ingress, network policies and the cluster's own networking implementation determine what can reach what. Without network policies, every pod can talk to every other pod, which is the default and is rarely what anyone intends. Engineers who have implemented policies in a running cluster know that the hard part is discovering what actually communicates, not writing the rules.

Upgrades are the third and the one that separates people who run clusters from people who use them. Kubernetes releases frequently with a relatively short support window, so an estate must be upgraded continuously rather than occasionally. Each upgrade can remove APIs that workloads depend on. An engineer who has taken a production cluster through several version upgrades without downtime has done something genuinely difficult.

Where Kubernetes is used

The label “Kubernetes developer” covers several jobs that share a technology and little else. These are the settings the work usually turns up in, and the one you are hiring into should shape the whole process, because the judgement each demands is different.

Multi-service platforms

Organisations running many services across several teams, which is the situation Kubernetes was designed for.

Regulated and hybrid environments

Where workloads must run across on-premises and cloud infrastructure with consistent tooling.

Platform engineering

Internal platforms giving product teams a way to deploy without needing cluster expertise themselves.

Machine learning infrastructure

Scheduling training and inference workloads, including access to specialised hardware.

Software vendors

Products shipped to customers who run them in their own clusters, where Kubernetes is the distribution format.

Migration from virtual machines

Consolidating workloads onto shared infrastructure with better utilisation.

If a candidate's experience sits in a different row of that list from the work you have, that is not a reason to reject them, but it is the thing to probe. Ask what would be different about their approach in your setting. Someone who can answer that has transferable judgement. Someone who says it would be much the same has probably not thought about it.

Which Kubernetes versions are still supported

Kubernetes releases several times a year with a comparatively short support window per version, which makes continuous upgrading an operational commitment rather than an occasional project.

The table is generated from public release data rather than written by hand, so it states what is supported today rather than what was true when any given article was published. Of the 8 most recent release lines, 4 are still maintained and 4 have passed their published end-of-life date. That distinction is the practical one when you read a job specification: a requirement written against a line that is now out of support tells you the specification is older than the codebase it describes, and it is worth asking which of the two the new developer will actually work in.

Kubernetes release lines
ReleaseReleasedEnd of lifeStatusLatest patch
1.372026-08-262027-10-28Maintained1.37.1 (2026-09-23)
1.362026-04-222027-06-28Maintained1.36.5 (2026-09-23)
1.352025-12-172027-02-28Maintained1.35.9 (2026-09-23)
1.342025-08-272026-10-27Maintained1.34.12 (2026-09-23)
1.332025-04-232026-06-28End of life1.33.13 (2026-06-11)
1.322024-12-112026-02-28End of life1.32.13 (2026-02-26)
1.312024-08-132025-11-11End of life1.31.14 (2025-11-11)
1.302024-04-172025-07-15End of life1.30.14 (2025-06-17)

Source: endoflife.date public release data, read 2026-09-25.

Two questions follow from this table in an interview. The first is which line the candidate has most recently shipped against, because someone whose last production work was on an unsupported line has not had to deal with the changes since. The second is how they have handled an upgrade. Version migrations are where you see whether a developer reads release notes, writes characterisation tests before changing anything, and knows how to stage a rollout, or whether they upgrade in place on a Friday and hope.

The toolchain around it

Nobody hires for Kubernetes alone. The surrounding tools are where most of the day-to-day work happens, and a gap in any of them costs more time than a gap in the core library. This is the set that turns up most often on real job specifications alongside it.

A managed control plane
EKS, GKE or AKS. Running your own control plane is rarely justified now.
Helm or Kustomize
Packaging and environment-specific configuration of manifests.
Argo CD or Flux
Continuous deployment driven from a repository, which makes cluster state reviewable.
Prometheus and Grafana
Metrics, including the resource usage that drives requests and limits.
An ingress controller
Routing external traffic, with certificate handling.
Network policies
Restricting pod-to-pod communication, which is unrestricted by default.
External Secrets or similar
Pulling credentials from a real secret manager instead of storing them in the cluster.
Cost tooling
Attribution by namespace or team, since a cluster hides who is spending what.

Related skills that frequently appear on the same specification: Go, Microsoft Azure, AWS, DevOps, Terraform.

What to test in an interview

These are the topics that separate candidates in practice. Each one is given with why it discriminates, what a strong answer sounds like, and the response that should make you slow down. None of them requires a whiteboard.

Requests and limits

Where production problems concentrate and where real experience shows.

Debugging a pod that will not start

A concrete diagnostic question that cannot be answered from theory.

Networking and policies

The default is wide open and most clusters stay that way.

Cluster upgrades

Separates cluster operators from cluster users.

Secret handling

Kubernetes secrets are base64-encoded, not encrypted, which surprises people.

When not to use Kubernetes

The single most useful question in this field.

An incident on a cluster

Operational judgement is learned during outages.

Warning signs in a Kubernetes codebase

The fastest way to read a candidate is to ask what they have found wrong in code they inherited. These are the patterns that come up most often, what they cost, and what fixing them looks like. A developer who recognises three or four of these from their own experience is worth more than one who can recite the documentation.

Missing resource requests and limits

No network policies

Secrets treated as encrypted

Latest image tags

Adopting Kubernetes too early

Cluster state changed by hand

What each level can own

Job titles are not comparable between companies, so it is more useful to describe levels by what a person can be left to own without supervision. These are the boundaries we use when we assess a Kubernetes engineer.

Junior
Deploys workloads into an existing cluster using established manifests. Needs review on resources and health checks.
Mid-level
Owns the deployment and operation of services on the cluster, including monitoring and resource tuning.
Senior
Owns cluster architecture, networking, security posture, upgrade strategy and cost attribution. Can diagnose a control-plane-level problem.
Staff
Owns the platform contract with product teams, the multi-cluster strategy, and the judgement about which workloads belong on Kubernetes at all.

How the work is usually scoped

Team shape follows the kind of work, not the headcount you happen to have budget for. These are the shapes that come up most often and the constraint that actually governs each one.

Cluster setup

Migration onto Kubernetes

Cluster upgrade programme

Security hardening

Cost attribution and reduction

Migration work you may actually be hiring for

A large share of Kubernetes work is not new development. It is moving an existing system from one state to another while it stays in service. These are the migrations that come up most often, and each one asks for a different kind of experience from the person you hire.

Virtual machines to Kubernetes

A self-managed control plane to a managed one

Manual manifest application to repository-driven deployment

An unsupported Kubernetes version to current

Migration work rewards a different temperament from greenfield work. The useful question in an interview is not whether someone has done the specific migration you face, but whether they have ever run one incrementally: behind a flag, with both paths live, and with a way back. Developers who have only done big-bang cutovers tend to propose them again.

What a good brief for this role contains

Most of the time lost in hiring a Kubernetes engineer is lost before anyone is interviewed, in the gap between what the brief says and what the team actually needs. These are the points that, for this technology specifically, change who the right candidate is. A brief that answers them can be matched in days. One that does not produces a shortlist that looks reasonable and converts badly.

If you cannot answer some of these yet, that is normal and it is still worth writing down which ones are open. An unknown that is named can be worked around. An unknown that is papered over in a job specification turns into a rejected shortlist and a restart four weeks later.

What the US market pays for this work

Kubernetes work is counted by the US Bureau of Labor Statistics under Network and Computer Systems Administrators. That classification is broader than the technology itself, so treat the figures as the shape of the market a Kubernetes engineer is hired into rather than as a rate card for the skill. Across the United States the Bureau counts 314,340 people in this occupation, with a median annual wage of $99,130.

US annual wages, Network and Computer Systems Administrators, May 2025
US annual wages, Network and Computer Systems Administrators, May 2025$99,130Median$62,640$155,05010th pct90th pctMiddle half $78K to $127K

The spread matters more than the midpoint. The 90th percentile is about 2.5 times the 10th, which is a wide band for a single occupation and tells you that the title on its own carries very little pricing information. Two people described as a Kubernetes engineer can sit at $62,640 and $155,050 in the same national dataset. When a budget is set from a median without asking which end of that range the work actually needs, the hire that follows is usually the wrong one in one direction or the other.

Related classifications are worth reading alongside it, because teams hiring for Kubernetes frequently end up recruiting against these titles too:

US national wages, May 2025
OccupationEmployed25th percentileMedian75th percentile90th percentile
Network and Computer Systems Administrators314,340$78,010$99,130$126,640$155,050
Computer Network Architects179,740$104,620$134,050$168,200$202,680
Software Developers1,687,890$105,210$135,980$171,980$214,670
Computer and Information Systems Managers670,570$138,060$175,140$220,730$297,510

Source: BLS Occupational Employment and Wage Statistics, May 2025. Figures cover all US employers and are not FuturByte rates.

These are employer-side wage figures for people on a US payroll. They exclude employer taxes, benefits, recruitment cost and the months a seat sits empty, all of which are real and none of which appear in a salary line. The useful way to read the table is as the cost of the alternative you are comparing against, not as a number to match.

How US metro markets compare for this role

The same job is priced very differently across the country. Ranked by median annual wage for Network and Computer Systems Administrators, the gap between the highest and lowest of the 28 metro areas covered here is a factor of about 1.7. San Jose sits at the top with a median of $133,360; Pittsburgh sits at the bottom with $80,440. A budget built from a national median will be wrong in both of those markets, in opposite directions.

Median wage for network and computer systems administrators, by US metro area
Median wage for network and computer systems administrators, by US metro areaSan Jose, CA: $133,360San Jose, CASan Jose, CA$133,360San Francisco, CA: $129,680San Francisco, CASan Francisco, CA$129,680Washington, D.C.: $125,430Washington, D.C.Washington, D.C.$125,430Baltimore, MD: $122,950Baltimore, MDBaltimore, MD$122,950New York, NY: $119,390New York, NYNew York, NY$119,390Boston, MA: $116,770Boston, MABoston, MA$116,770Los Angeles, CA: $106,290Los Angeles, CALos Angeles, CA$106,290San Diego, CA: $105,170San Diego, CASan Diego, CA$105,170Denver, CO: $105,090Denver, CODenver, CO$105,090Austin, TX: $104,520Austin, TXAustin, TX$104,520Seattle, WA: $104,440Seattle, WASeattle, WA$104,440Raleigh, NC: $103,380Raleigh, NCRaleigh, NC$103,380Dallas-Fort Worth, TX: $103,260Dallas-Fort Worth, TXDallas-Fort Worth, TX$103,260Chicago, IL: $103,170Chicago, ILChicago, IL$103,170Portland, OR: $102,950Portland, ORPortland, OR$102,950Minneapolis-St. Paul, MN: $102,790Minneapolis-St. Paul, MNMinneapolis-St. Paul, MN$102,790Tampa, FL: $101,560Tampa, FLTampa, FL$101,560Houston, TX: $101,430Houston, TXHouston, TX$101,430Atlanta, GA: $101,000Atlanta, GAAtlanta, GA$101,000Philadelphia, PA: $100,460Philadelphia, PAPhiladelphia, PA$100,460Salt Lake City, UT: $99,110Salt Lake City, UTSalt Lake City, UT$99,110Miami, FL: $97,180Miami, FLMiami, FL$97,180Detroit, MI: $96,400Detroit, MIDetroit, MI$96,400Phoenix, AZ: $93,730Phoenix, AZPhoenix, AZ$93,730Kansas City, MO: $91,980Kansas City, MOKansas City, MO$91,980Orlando, FL: $91,800Orlando, FLOrlando, FL$91,800Charlotte, NC: $89,990Charlotte, NCCharlotte, NC$89,990Pittsburgh, PA: $80,440Pittsburgh, PAPittsburgh, PA$80,440
Network and Computer Systems Administrators by metro area, May 2025, ranked by median wage
Metro areaEmployedMedian wagevs US medianLocation quotient
San Jose, CA2,460$133,360+35%1.07
San Francisco, CA3,910$129,680+31%0.81
Washington, D.C.9,920$125,430+27%1.57
Baltimore, MD4,620$122,950+24%1.69
New York, NY17,690$119,390+20%0.92
Boston, MA6,760$116,770+18%1.24
Los Angeles, CA8,770$106,290+7%0.69
San Diego, CA2,510$105,170+6%0.81
Denver, CO4,670$105,090+6%1.44
Austin, TX5,030$104,520+5%1.92
Seattle, WA5,530$104,440+5%1.31
Raleigh, NC2,730$103,380+4%1.82
Dallas-Fort Worth, TX11,740$103,260+4%1.43
Chicago, IL6,950$103,170+4%0.76
Portland, OR2,820$102,950+4%1.15
Minneapolis-St. Paul, MN3,200$102,790+4%0.81
Tampa, FL4,720$101,560+2%1.61
Houston, TX6,330$101,430+2%0.95
Atlanta, GA6,140$101,000+2%1.05
Philadelphia, PA4,050$100,460+1%0.69
Salt Lake City, UT1,130$99,1100%0.68
Miami, FL6,340$97,180-2%1.11
Detroit, MI3,010$96,400-3%0.78
Phoenix, AZ4,370$93,730-5%0.91
Kansas City, MO2,760$91,980-7%1.25
Orlando, FL4,260$91,800-7%1.49
Charlotte, NC4,180$89,990-9%1.52
Pittsburgh, PA1,570$80,440-19%0.70

Location quotient compares how concentrated this occupation is in the metro against the national average. A value above 1 means the metro has more of this work than its size would predict.

The location quotient column is the more useful one for hiring. A high median tells you what a role costs; a high quotient tells you whether the people exist. Washington, D.C., Baltimore, Austin, Raleigh, Tampa, Charlotte each have a quotient of 1.5 or above, meaning the work is concentrated there well beyond what the size of the local economy would predict. Those are the markets where a search is likely to be quick and competitive at the same time, and where a counter-offer is most likely to take a candidate off the table late in the process.

The opposite case is worth planning for too. In a metro with a low quotient, the total pool is small even when wages look reasonable, so the realistic options are to widen the search radius, accept a longer time to hire, or bring the capability in from outside the local market entirely. That last option is what most teams are weighing when they come to us.

Hiring risks worth naming

Every one of these has produced a bad hire somewhere. They are written down so that the process tests for them deliberately rather than discovering them in month three.

Cluster user presented as cluster operator. Ask whether they have upgraded a production cluster. Deploying into one is a different job from running one.

Enthusiasm over judgement. Ask when they would not use it. Someone with no answer will build something your team cannot sustain.

No security posture. Ask about network policies and secrets. Both defaults are permissive and most clusters never change them.

No cost awareness. Over-provisioned requests are the most common source of cluster waste and are invisible without attribution.

Hiring Kubernetes developers by metro area

Wages for this occupation vary more between US metro areas than most budget models assume. Each page below sets out the published employment and wage figures for that market, how it compares with the national picture, and what the local industry mix means for the kind of Kubernetes engineer who will be available.

Frequently asked questions

Do we need Kubernetes?

Probably not if you run a handful of services with a small team, because a managed container service will do the job with a fraction of the operational surface. It becomes worth it when you have many services, several teams needing to deploy independently, hybrid or multi-cloud requirements, or workloads that genuinely need sophisticated scheduling. The question that settles it is who will operate the cluster at three in the morning.

Should we run our own control plane?

Almost certainly not. Managed control planes from the major cloud providers remove the hardest operational work for a modest cost, and running your own is justified only by specific regulatory or infrastructure constraints. Teams that do it without such a reason spend a great deal of engineering time on something that is available as a product.

Why do our pods keep restarting?

The two most common causes are memory limits set too low, so the process is terminated under load, and health checks that are too aggressive, so a slow-starting service is killed before it is ready. Both present as application instability and neither is an application bug. Checking the previous container's exit reason usually identifies which.

Are Kubernetes secrets secure?

Not by default, and this surprises people regularly. They are base64-encoded rather than encrypted, and anyone with read access to the namespace can read them. Enable encryption at rest, restrict access properly, and for anything genuinely sensitive pull from an external secret manager at runtime rather than storing it in the cluster.

How often do we have to upgrade?

Several times a year, because the support window for each version is short. This is a real ongoing commitment and one of the honest costs of adoption. Estates that fall behind face upgrades that cross multiple versions with removed APIs, which is considerably harder than staying current.

Why is our cluster so expensive?

Usually over-provisioned resource requests, because requests reserve capacity whether or not it is used. A cluster full of workloads requesting far more than they consume pays for idle capacity on every node. Comparing requested against actual usage per workload is typically the single highest-return exercise available on a cluster nobody has reviewed.

Can our developers deploy without learning Kubernetes?

They should be able to, and if they cannot then the platform work is unfinished. The point of platform engineering is to give product teams a simple path to deploy and observe their services without needing cluster expertise. If every deployment requires a specialist, the cluster has become a bottleneck rather than an enabler.

Should stateful workloads run on Kubernetes?

They can, and for databases specifically the honest answer is usually to use a managed service instead. Running a database on Kubernetes means owning storage, backup, failover and upgrades yourself, which is exactly the work a managed database removes. Do it when there is a specific reason, not for architectural symmetry.