Agent skill

K8s YAML Generator

by akin-ozer in akin-ozer/cc-devops-skills

Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs.

Apache-2.0Auto-check passedDevOps & Cloud

Install K8s YAML Generator

skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-generator .claude/skills/k8s-yaml-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
k8s-yaml-generator
GitHub stars
320
Token cost
~2.2k tokens
SKILL.md length
876 words
Files
11 (incl. references)
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs.

  • Works in 8 steps: Preflight → Capture Required Inputs → CRD Lookup Workflow (Bounded) → …
  • Tasks that involve Container orchestration
  • SKILL.md covers Trigger Guidance, Execution Model, 1) Preflight and 2) Capture Required Inputs, plus 6 more sections
  • Runs Shell scripts from its folder; calls kubectl and bash

What it does

K8s YAML Generator is an agent skill from akin-ozer/cc-devops-skills. Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `examples/configmap-secret.yaml`, `examples/deployment-service.yaml` and `examples/hpa-pdb.yaml`).

It sits in DevOps & Cloud, covering Container orchestration, Cloud networking and Authorization and RBAC. It works with Kubernetes. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration
  • Tasks that involve Cloud networking
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/k8s-yaml-generator”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Preflight
  2. Capture Required Inputs
  3. CRD Lookup Workflow (Bounded)
  4. YAML Generation Rules
  5. Mandatory Validation and Contingencies
  6. Delivery Contract
  7. Canonical Example Flows
  8. Definition of Done

What it can do on your machine

Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

K8s YAML Generator loads about 2.2k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 876 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from akin-ozer/cc-devops-skills at commit 276af75, republished under its Apache-2.0 licence (© akin-ozer). 876 words, ~2,216 tokens.

Download SKILL.mdSave it as .claude/skills/k8s-yaml-generator/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
k8s-yaml-generator
description
Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs.

Kubernetes YAML Generator

Generate Kubernetes manifests with deterministic steps, bounded CRD research, and mandatory validation for full-resource output.

Trigger Guidance

Use this skill when the user asks to create or update Kubernetes YAML, for example:

  • "Generate a Deployment + Service manifest for my app."
  • "Create an Argo CD Application CRD."
  • "Write a StatefulSet with PVC templates."
  • "Produce production-ready Kubernetes YAML with best practices."

Do not use this skill for validation-only requests. For validation-only work, use k8s-yaml-validator.

Execution Model

Normative keywords:

  • MUST: required
  • SHOULD: default unless user requests otherwise
  • MAY: optional

Deterministic sequence:

  1. Preflight request and path/rendering sanity.
  2. Capture minimum required inputs.
  3. Resolve CRD references (bounded workflow only when CRD/custom API is involved).
  4. Generate YAML with baseline quality checks.
  5. Run mandatory validation (or documented fallback path when tooling is unavailable).
  6. Deliver YAML plus explicit validation report and assumptions.

If one step is blocked by environment constraints, execute that step's fallback and continue.

1) Preflight

Before generation:

  • Confirm whether output is full manifest(s) or snippet-only.
  • Confirm target Kubernetes version when provided.
  • Verify any referenced local file path exists before using it.
  • Normalize resource naming to DNS-1123-compatible names where applicable.

Preflight stop condition:

  • If required core inputs are missing (resource type, workload image for Pod-based resources, or CRD kind/apiVersion), ask for those first.

2) Capture Required Inputs

Collect:

  • Resource types (Deployment, Service, ConfigMap, CRD kind, etc.)
  • apiVersion + kind
  • Namespace/scoping requirements
  • Ports, replicas, images, probes, storage, and secret/config needs
  • Environment assumptions (dev/staging/prod)
  • For CRDs: project name and target CRD version if known

Safe defaults (state explicitly in output):

  • Namespace: default (namespace-scoped resources)
  • Deployment replicas: 2
  • Service type: ClusterIP
  • Image pull policy: IfNotPresent (unless user needs forced pulls)

3) CRD Lookup Workflow (Bounded)

Run this step only for custom APIs outside Kubernetes built-in groups.

3.1 Identify CRD target

Extract:

  • API group, version, kind (for example argoproj.io/v1alpha1, Application)
  • Requested product/version (for example Argo CD v2.9.x)
3.2 Context7 primary path

Use the correct Context7 tools and payloads:

  1. mcp__context7__resolve-library-id
  2. mcp__context7__query-docs

Sample payloads:

text
Tool: mcp__context7__resolve-library-id
libraryName: "argo-cd"
query: "Find Argo CD documentation for Application CRD schema compatibility"
text
Tool: mcp__context7__query-docs
libraryId: "/argoproj/argo-cd/v2.9.0"
query: "Application CRD required spec fields for apiVersion argoproj.io/v1alpha1 with minimal valid example"

Selection rules:

  • Prefer exact project/library name matches.
  • Prefer versioned libraryId when user specifies a version.
  • Otherwise use unversioned ID and note version uncertainty.
3.3 Thresholds and stop conditions

Bound the lookup to prevent unbounded retries:

  • resolve-library-id: max 2 attempts (primary name + one alternate name).
  • query-docs: max 3 focused queries total.
  • Web fallback: max 2 version-specific searches.

Stop early when all are true:

  • Required CRD fields are identified.
  • At least one authoritative example is found.
  • Version compatibility is known or explicitly marked unknown.

Hard stop when budgets are exhausted:

  • Generate only fields verified by sources.
  • Mark remaining fields as Needs confirmation.
  • Report residual risk and request one of:
    • exact CRD docs URL, or
    • cluster introspection output (for example kubectl explain <kind>.spec when available).
3.4 Fallback order

Use this order:

  1. Context7 (resolve-library-id -> query-docs)
  2. Official project docs via web search
  3. Cluster-local introspection (kubectl explain, if cluster access exists)

If none are available, provide a minimal, clearly marked draft and do not claim full CRD correctness.

Show full SKILL.md (380 more words)Show less

4) YAML Generation Rules

Apply these checks:

  • Use explicit, non-deprecated API versions.
  • Include consistent labels (app.kubernetes.io/*) across related resources.
  • Include namespace for namespace-scoped resources.
  • Add resource requests/limits for Pod workloads unless user opts out.
  • Add readiness/liveness probes for long-running services where applicable.
  • Use securityContext to avoid root execution by default.
  • Keep multi-resource ordering dependency-safe (for example ConfigMap before Deployment consumers).

Minimal label baseline:

yaml
labels:
  app.kubernetes.io/name: myapp
  app.kubernetes.io/instance: myapp-prod
  app.kubernetes.io/part-of: myplatform
  app.kubernetes.io/managed-by: codex

5) Mandatory Validation and Contingencies

For full manifest generation, validation is mandatory.

Primary path:

  • Invoke k8s-yaml-validator.
  • Iterate fix -> revalidate until blocking issues are gone.

Required reporting after each validation pass:

  • Validation mode: k8s-yaml-validator | script fallback | manual fallback
  • Syntax: pass/fail
  • Schema: pass/fail/partial
  • CRD check: pass/fail/partial
  • Dry-run: server/client/skipped
  • Blocking issues remaining: yes/no

Contingency A: validator skill unavailable

Run direct commands:

bash
bash devops-skills-plugin/skills/k8s-yaml-validator/scripts/setup_tools.sh
yamllint -c devops-skills-plugin/skills/k8s-yaml-validator/assets/.yamllint <file.yaml>
kubeconform -schema-location default -strict -ignore-missing-schemas -summary <file.yaml>
server_out="$(mktemp)"
client_out="$(mktemp)"
trap 'rm -f "$server_out" "$client_out"' EXIT

if kubectl apply --dry-run=server -f <file.yaml> >"$server_out" 2>&1; then
  echo "server_validation=passed"
elif grep -Eqi "connection refused|no such host|i/o timeout|tls handshake timeout|unable to connect to the server|no configuration has been provided|the server doesn't have a resource type" "$server_out"; then
  echo "server_validation=skipped"
  if kubectl apply --dry-run=client -f <file.yaml> >"$client_out" 2>&1; then
    echo "client_validation=passed"
  else
    echo "client_validation=failed"
    cat "$client_out"
    exit 1
  fi
else
  echo "server_validation=failed"
  cat "$server_out"
  exit 1
fi

Contingency B: local tools partially unavailable

  • Run available checks.
  • Record skipped checks explicitly.
  • Add residual risk for every skipped check.

Contingency C: repeated validation failure

  • Maximum 3 fix/revalidate cycles.
  • If still failing, stop and return:
    • current YAML,
    • exact failing errors,
    • smallest required user decision/input to unblock.

Validation exceptions:

  • Snippet-only or docs-only requests MAY skip full validation, but the output MUST state Validation status: Skipped (reason).

6) Delivery Contract

Final output MUST include:

  1. Generated YAML.
  2. What was generated (resource list, namespace/scoping).
  3. Validation report in the required format.
  4. Assumptions and defaults used.
  5. References used:
    • Context7 IDs/queries used (for CRDs)
    • external docs/searches used
    • items skipped/missing and impact

Suggested next commands:

bash
kubectl apply -f <filename>.yaml
kubectl get <resource-type> <name> -n <namespace>
kubectl describe <resource-type> <name> -n <namespace>

7) Canonical Example Flows

Example A: Built-in resources (Deployment + Service)
  1. Capture app image, ports, replicas, namespace.
  2. Generate Deployment and Service with consistent labels/selectors.
  3. Validate with k8s-yaml-validator.
  4. Return YAML + validation report + assumptions.
Example B: CRD resource (Argo CD Application)
  1. Extract argoproj.io/v1alpha1 + Application.
  2. Run bounded Context7 lookup (resolve-library-id then query-docs).
  3. If needed, perform bounded web fallback.
  4. Generate CRD YAML only with verified fields.
  5. Validate, report any partial verification, and return residual risks.

8) Definition of Done

Execution is complete only when all applicable checks pass:

  • Trigger use case is correct (generation, not validation-only).
  • Required inputs are captured or explicit assumptions are documented.
  • CRD lookup follows bounded thresholds and stop conditions.
  • Tool names and command paths are valid and consistent.
  • Full manifests are validated (or fallback path is documented with residual risk).
  • Final response includes YAML, validation report, assumptions, and references.

© akin-ozer, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in devops-skills-plugin/skills/k8s-yaml-generator of akin-ozer/cc-devops-skills.

  • SKILL.md
  • examples/configmap-secret.yaml
  • examples/deployment-service.yaml
  • examples/hpa-pdb.yaml
  • examples/ingress.yaml
  • examples/rbac-cluster-reader-optional.yaml
  • examples/rbac.yaml
  • examples/statefulset.yaml
  • references/resource_patterns.md
  • references/security_patterns.md
  • tests/test_regression.sh

Open the folder on GitHubat commit 276af75

Compare with similar skills

K8s YAML Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

K8s YAML Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
K8s YAML Generator this skillakin-ozer/cc-devops-skills320—~2.2kAutomated safety check: PassApache-2.0
Kubernetes Patternstimothywarner-org/claude-code224—~4.5kAutomated safety check: PassMIT
Kubernetes InterviewerPrepLabsAI/InterviewMentor112—~3.4kAutomated safety check: PassMIT
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Mirrord Operatormetalbear-co/mirrord5.4k1 repos~4.6kAutomated safety check: PassMIT
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubernetes Patterns

    timothywarner-org/claude-code

    Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments.

    224 GitHub stars~4.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Kubernetes Interviewer

    PrepLabsAI/InterviewMentor

    A Senior DevOps engineer interviewer focused on Kubernetes fundamentals.

    112 GitHub stars~3.4k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Mirrord Operator

    metalbear-co/mirrord

    Help users install and configure the mirrord Operator for team/enterprise environments.

    5.4k GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from akin-ozer/cc-devops-skills

All 30 skills in this repo
  • GitHub Actions Generator

    akin-ozer/cc-devops-skills

    Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

    320 GitHub stars~3.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Helm Generator

    akin-ozer/cc-devops-skills

    Create, scaffold, or generate Helm charts, Chart.yaml, values.yaml, templates, helpers.

    320 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Generator

    akin-ozer/cc-devops-skills

    Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.

    320 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Dockerfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or scan a Dockerfile for security and best practices.

    320 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Actions Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).

    320 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or check Jenkinsfiles and shared libraries.

    320 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about K8s YAML Generator

What does K8s YAML Generator do?

Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs. K8s YAML Generator is an agent skill from akin-ozer/cc-devops-skills. Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs.

When should I use K8s YAML Generator?

K8s YAML Generator fits situations like: tasks that involve Container orchestration; tasks that involve Cloud networking; tasks that involve Authorization and RBAC.

How do I install K8s YAML Generator in Claude Code?

Run `npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-generator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/k8s-yaml-generator in akin-ozer/cc-devops-skills) into .claude/skills/k8s-yaml-generator in your project. Claude Code loads it when a task matches its description.

How do I install K8s YAML Generator in Codex?

Run `npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-generator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/k8s-yaml-generator in akin-ozer/cc-devops-skills) into .agents/skills/k8s-yaml-generator in your project. Codex loads it when a task matches its description.

Can I use K8s YAML Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-yaml-generator, .gemini/skills/k8s-yaml-generator, .github/skills/k8s-yaml-generator and .opencode/skills/k8s-yaml-generator in your project.

What does K8s YAML Generator need to run?

Going by SKILL.md and its folder, K8s YAML Generator needs a shell for the scripts in its folder and the command-line tools its instructions call (kubectl and bash). Our summary lists: A Bash shell.

Does K8s YAML Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is K8s YAML Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does K8s YAML Generator use?

K8s YAML Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does K8s YAML Generator use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.

What are the alternatives to K8s YAML Generator?

Skills that share tags, products or a category with K8s YAML Generator: Kubernetes Patterns (timothywarner-org/claude-code, 224 stars), Kubernetes Interviewer (PrepLabsAI/InterviewMentor, 112 stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars) and Mirrord Operator (metalbear-co/mirrord, 5.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains K8s YAML Generator?

akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 320 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.

Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.