shouldiuse.io

Categories

VERDICT

Should I use Kubernetes?

Open-source container orchestration, also known as K8s - kubernetes.io

Depends. Buy Kubernetes if you run many microservices across clouds and have engineers dedicated to operating clusters. Small teams with simple apps should use Docker Compose or a PaaS instead.

Confidence

High. Based on 40+ public sources: official docs, G2, Reddit, Hacker News, and security databases.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityCommunity project; no support-quality evidence found
  • Security posture

Pricing

Free

Self-managed (open source)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Managed (DigitalOcean Basic)$12/mo
Managed (EKS/GKE/AKS)Usage-based

Best for

  • Platform teams running many microservices
  • Multi-cloud and hybrid infrastructure
  • High-scale workloads needing autoscaling
  • Orgs with dedicated DevOps/SRE staff

Not for

  • Solo founders and small startups — heavy overkill
  • Teams without a dedicated ops engineer
  • Simple apps that fit one server
  • Anyone unwilling to learn YAML and cluster ops

Gotchas - check before you buy

high

The software is free; running it is not — nodes, load balancers, egress add up

high

RBAC misconfigurations have enabled real-world attacks; audit permissions early

medium

Some vulnerability classes are effectively unpatchable (CVE-2020-8562); plan compensating controls

medium

Control-plane and node prices differ sharply across EKS, GKE, AKS — compare before committing

Pros and cons

Pros

  • Portable, open-source orchestration that runs on every major cloud
  • Proven at extreme scale by OpenAI, CERN, and Spotify
  • Managed offerings from AWS, Azure, Google, Oracle, and DigitalOcean
  • Community-maintained public CVE feed gives transparent vulnerability tracking
  • Even critics concede it is 'a great tool' at the right scale

Cons

  • Famously steep learning curve; Reddit threads full of complexity complaints
  • Needs dedicated platform engineers to run safely in production
  • Cloud spend easily spirals; called 'a black hole of unpredictable spend'
  • Misconfigurations are a leading cause of real breaches
  • Serious overkill for small teams and simple applications

Sources & method

Analyzed 10/05/2026 - 12 sources - Mature RBAC and active security process, but a steady CVE stream and frequent misconfiguration-driven breaches.

official x2review x4security x3news x3
  • CVE-2025-5187 — privilege escalation, Kubernetes privilege escalation vulnerability tracked in SentinelOne's database.
  • CVE-2020-8562 — unpatchable vulnerability class, Datadog Security Labs documents Kubernetes flaws that cannot be fully patched.
  • CVE-2025-9708, NVD-listed Kubernetes flaw published September 2025.

Key stats

  • Value for money: 2/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 2/5. Free software, costly operations and unpredictable cloud spend
  • Ease of use: 2/5. Reddit consensus: famously steep learning curve
  • Feature depth: 5/5. Scheduling, autoscaling, self-healing, proven at OpenAI scale
  • Support quality. Community project; no support-quality evidence found
  • Security posture: 3/5. Mature RBAC, but steady CVE stream and misconfiguration risk
  • Free Self-hosted cost Open-source; you pay only for infrastructure
  • $12/mo Entry managed price DigitalOcean Basic managed cluster
  • 2014 First release Open-sourced by Google, now CNCF-hosted
  • 10+ Review footprint Dedicated G2, Reddit, and vendor review listings

Pricing

Self-managed (open source)

Free

  • Run control plane yourself
  • Pay only for servers

Managed (DigitalOcean Basic)

$12/mo

  • Basic managed cluster
  • Nodes billed separately

Managed (EKS/GKE/AKS)

Usage-based

  • Hourly control-plane fee
  • Pay per node

Security

Mature RBAC and active security process, but a steady CVE stream and frequent misconfiguration-driven breaches.

  • CVE-2025-5187 — privilege escalationKubernetes privilege escalation vulnerability tracked in SentinelOne's database.10
  • CVE-2020-8562 — unpatchable vulnerability classDatadog Security Labs documents Kubernetes flaws that cannot be fully patched.11
  • CVE-2025-9708NVD-listed Kubernetes flaw published September 2025.

What users say

Users love its scale and ecosystem but consistently warn about steep complexity and unpredictable costs.

“Is it just me, or is Kubernetes supposed to be this frikkin ...”
Reddit, r/kubernetes
“Kubernetes a black hole of unpredictable spend, according ...”
Hacker News
“And it is a great tool.”
The New Stack

Alternatives

Compare Kubernetes with each alternative.

  • Docker Compose

    One-file deployments; plenty for single-server apps

  • Portainer + Docker Swarm

    Simple container management UI for teams not ready for K8s

  • Managed Kubernetes (EKS/GKE/AKS)

    Run K8s without operating control planes yourself

  • Heroku-style PaaS

    Push code, skip cluster upkeep entirely

Companies that use it

  • OpenAI
  • CERN
  • Spotify
  • Ancestry
Full analysis

Based on 40+ public sources: official docs, G2, Reddit, Hacker News, and security databases.

Industry-standard cluster orchestrator: transformative at scale, expensive overkill for small teams.

Methodology

Based on 40+ public sources: official docs, G2, Reddit, Hacker News, and security databases.

Sources

  1. official
  2. review
  3. review
  4. review
  5. review
  6. news
  7. news
  8. official
  9. Official CVE Feedkubernetes.io
    security
  10. security
  11. security
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.