Developer tool
Kubernetes agent skills, page 10
Kubernetes skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 433 | Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 434 | Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 435 | Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 436 | Turns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 437 | Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 438 | Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 439 | Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 440 | Reference knowledge for installing, uninstalling, or creating-and-installing Dynatrace OneAgent across VM/server, Kubernetes (Operator + DynaKube), AWS Lambda (layer + env vars, plus optional fresh… | Dynatrace/ | 163 | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | 10 days ago |
| 441 | A skill your agent uses when planning, running, or learning from chaos engineering experiments. | alirezarezvani/ | 28k | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 442 | A skill your agent uses when building a Kubernetes Operator — custom controllers that reconcile CRD state. | alirezarezvani/ | 28k | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 443 | 443.Slo Architect A skill your agent uses when defining, reviewing, or operating SLOs/SLIs/error budgets. | alirezarezvani/ | 28k | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 444 | Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). | OWASP/ | 188 | — | ~694 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 445 | Configure zero-downtime deployment strategies including blue-green, canary, and rolling deployments. | sickn33/ | 47k | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 2 days ago |
| 446 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | 2 days ago |
| 447 | 447.Kubernetes Ops Deploy, scale, and manage Kubernetes workloads. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 448 | 448.Infra Triage Infrastructure alert triage — dedup via YT search, deep PVE/K8s investigation, auto-escalation for recurring/flapping alerts, control plane deep dive for K8s controller nodes. | papadopouloskyriakos/ | 107 | — | ~714 | Automated safety check: Notes | No licence | 5 days ago |
| 449 | 449.Iac Security Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. | hardw00t/ | 105 | — | ~2.4k | Automated safety check: Pass | No licence | 5 mo ago |
| 450 | Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules… | mukul975/ | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 451 | Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 452 | Installs and runs the kube-bench tool against a Kubernetes cluster as a Job, DaemonSet, or standalone binary, selecting the correct benchmark version and targets (control plane, etcd, kubelet… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 453 | Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 454 | Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 455 | Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. | mukul975/ | 34k | — | ~635 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 456 | Audits container and pod configuration for escape-enabling misconfiguration using the Kubernetes Python client - privileged flags, dangerous capability grants, host path mounts, shared namespaces… | mukul975/ | 34k | — | ~648 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 457 | Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 458 | 458.K3d Environment Set up or reconfigure Bionic's local k3d Kubernetes environment. | bionic-gpt/ | 2.4k | — | ~356 | Automated safety check: Notes | Apache-2.0 | 4 days ago |
| 459 | Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer. | aspectrr/ | 405 | — | ~1.3k | Automated safety check: Pass | MIT | 5 mo ago |
| 460 | Deployment patterns from Kubernetes to serverless and edge functions. | ancoleman/ | 525 | — | ~3.1k | Automated safety check: Pass | MIT | 10 mo ago |
| 461 | Implement GitOps continuous delivery for Kubernetes using ArgoCD or Flux. | ancoleman/ | 525 | — | ~2.9k | Automated safety check: Pass | MIT | 10 mo ago |
| 462 | 462.Managing DNS Manage DNS records, TTL strategies, and DNS-as-code automation for infrastructure. | ancoleman/ | 525 | — | ~3.6k | Automated safety check: Notes | MIT | 10 mo ago |
| 463 | 463.Managing Secrets Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes. | ancoleman/ | 525 | — | ~2.9k | Automated safety check: Pass | MIT | 10 mo ago |
| 464 | Operating production Kubernetes clusters effectively with resource management, advanced scheduling, networking, storage, security hardening, and autoscaling. | ancoleman/ | 525 | — | ~3.6k | Automated safety check: Pass | MIT | 10 mo ago |
| 465 | Design and implement disaster recovery strategies with RTO/RPO planning, database backups, Kubernetes DR, cross-region replication, and chaos engineering testing. | ancoleman/ | 525 | — | ~3.1k | Automated safety check: Pass | MIT | 10 mo ago |
| 466 | 466.Resource Tagging Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation. | ancoleman/ | 525 | — | ~4k | Automated safety check: Pass | MIT | 10 mo ago |
| 467 | 467.Releasing Test A skill your agent uses when 把任何批次的改动发到 Prismer 测试环境(test.docbrew.cn / APPENV=test),或听到「发测试 / 发 test / 上测试环境 / deploy test / 打 ali-k8s-test tag」。涉及 develop 部署、test 迁移通道、runner 节流时必读。 | Prismer-AI/ | 1.6k | — | ~2.9k | Automated safety check: Pass | MIT | 11 days ago |
| 468 | Implements infrastructure as code using Terraform, Kubernetes, and cloud platforms. | davila7/ | 33k | 1 repo | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 469 | 审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持… | xwtro0tk1t-cloud/ | 265 | — | ~2.8k | Automated safety check: Warn | No licence | 5 mo ago |
| 470 | 470.Triage Canary Triage a failed canary ferry run only when invoked by CI with the required CANARY context. | marin-community/ | 3.9k | — | ~751 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 471 | Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication. | aiskillstore/ | 433 | 8 repos | ~2.8k | Automated safety check: Pass | No licence | yesterday |
| 472 | 472.Apple Container Apple's open-source container CLI to build, run, and manage OCI/Linux containers as lightweight per-container VMs on Apple-silicon macOS — no Docker daemon required. | sanjay3290/ | 432 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 473 | 473.Create Pipeline Generate Harness v0 Pipeline YAML for CI/CD workflows and create them via MCP. | harness/ | 115 | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 474 | 474.Argocd Gitops Implement GitOps with ArgoCD for declarative Kubernetes deployments. | sickn33/ | 47k | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 2 days ago |
| 475 | Secure Docker images and container runtime configurations. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~750 | Automated safety check: Pass | MIT | 2 days ago |
| 476 | 476.Helm Charts Create, manage, and deploy Helm charts for Kubernetes package management. | sickn33/ | 47k | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 2 days ago |
| 477 | Implement Kubernetes security contexts, Pod Security Standards, and network policies. | sickn33/ | 47k | 1 repo | ~858 | Automated safety check: Pass | MIT | 2 days ago |
| 478 | Multi-cluster Kubernetes dashboard with AI-powered operations via MCP server and 10+ built-in agent skills | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 479 | 479.Kustomize Customize Kubernetes manifests without templating using Kustomize. | sickn33/ | 47k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 480 | Auto-scale LLM inference clusters on Kubernetes using KEDA, custom GPU metrics, and horizontal pod autoscaling. | sickn33/ | 47k | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |