Deployments and Services are portable; the plumbing around them is not.
The left column is stable Kubernetes. The three right columns are what each platform plugs in.
| Concern | |||
|---|---|---|---|
| type: LoadBalancer | Google Cloud load balancer | AWS load balancer through the AWS Load Balancer Controller | MetalLB (layer 2 or BGP) or kube-vip |
| Default StorageClass | Persistent Disk or Hyperdisk CSI | EBS CSI (gp3) | Longhorn, Rook-Ceph or NFS: you install it |
| Gateway or Ingress | GKE Gateway controller | AWS Load Balancer Controller, VPC Lattice | Envoy Gateway, NGINX, Traefik |
| Workload to cloud identity | Workload Identity Federation | IRSA or EKS Pod Identity | OIDC, Vault, SPIFFE: you design it |
| Node scaling | Autopilot or cluster autoscaler | Karpenter, managed node groups, Auto Mode | Rancher or Cluster API machine pools |
| Control-plane upgrade | Release channels, automatic | You trigger it, AWS performs it | You run it: kubeadm, RKE2 upgrade plan |
Keep portable
Deployment, Service, ConfigMap, HPA, NetworkPolicy, PDB, probes and requests are identical everywhere.
Isolate in overlays
Annotations for load balancers, StorageClass names and identity bindings. Use Kustomize overlays or Helm values per platform.
Verify per platform
Product names and defaults evolve quickly. Check the current docs of each provider before committing a design.