Twelve-factor on Kubernetes today
How the factors map to containers, ConfigMaps, Deployments, and where the original text needs updating.
Twelve-factor still pays rent on Kubernetes — if you map intents to primitives deliberately.
Natural fits
| Factor | K8s / cloud expression |
|---|---|
| Config | ConfigMap, Secret, external stores |
| Build/release/run | image digest + GitOps/CD release |
| Processes | Pods as disposable units |
| Concurrency | replicas, separate worker Deployments |
| Port binding | containerPort + Service/Ingress |
| Logs | stdout → node agent / platform logging |
| Disposability | probes, preStop, graceful termination |
| Admin | Jobs, one-off pods with same image |
Still commonly violated
- secrets baked into images or checked into git
- rebuilding different images per environment
- durable state on local disk without PVC/backing service design
- “admin” via kubectl exec into a random prod pod with untracked scripts
- logs only inside containers, never shipped
What the original essay underplays
- service mesh, sidecars, and multi-container pods
- operators and CRDs for complex backing services
- security/admission policy as part of the platform contract
- data migrations and schema compatibility (still your problem)
Use as a review lens
In design review: walk I–XII quickly. Gaps become backlog before they become outages. Complements — does not replace — domain design, SLOs, and threat modeling.