Iac Security
hardw00t/ai-security-arsenal
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.
Validate, lint, audit, or dry-run Kubernetes manifests (Deployment, Service, ConfigMap, CRD).
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-validator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-validator .claude/skills/k8s-yaml-validator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "k8s-yaml-validator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validator into .claude/skills/k8s-yaml-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-yaml-validator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-validator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-validator .agents/skills/k8s-yaml-validator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "k8s-yaml-validator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validator into .agents/skills/k8s-yaml-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-yaml-validator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-validator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-validator .cursor/skills/k8s-yaml-validator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "k8s-yaml-validator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validator into .cursor/skills/k8s-yaml-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-yaml-validator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/akin-ozer/cc-devops-skills.git --path devops-skills-plugin/skills/k8s-yaml-validator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-validator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-validator .gemini/skills/k8s-yaml-validator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "k8s-yaml-validator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validator into .gemini/skills/k8s-yaml-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-yaml-validator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-validatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-validator .github/skills/k8s-yaml-validator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "k8s-yaml-validator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validator into .github/skills/k8s-yaml-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-yaml-validator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install akin-ozer/cc-devops-skills k8s-yaml-validator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/devops-skills-plugin/skills/k8s-yaml-validator .opencode/skills/k8s-yaml-validator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "k8s-yaml-validator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/k8s-yaml-validator into .opencode/skills/k8s-yaml-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "k8s-yaml-validator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
k8s-yaml-validatorValidate, lint, audit, or dry-run Kubernetes manifests (Deployment, Service, ConfigMap, CRD).
K8s YAML Validator is an agent skill from akin-ozer/cc-devops-skills. Validate, lint, audit, or dry-run Kubernetes manifests (Deployment, Service, ConfigMap, CRD).
Its SKILL.md is about 8.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including scripts, reference files and assets (for example `references/k8s_best_practices.md`, `references/validation_workflow.md` and `scripts/count_yaml_documents.py`).
It sits in DevOps & Cloud, covering Container orchestration and Linting and formatting. It works with Kubernetes. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (Python and Shell), which the agent can run.
Shell commands in SKILL.md call:
bashkubectlpython3gitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
raw.githubusercontent.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
K8s YAML Validator loads about 8.3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 28 tokens; SKILL.md has 2,372 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- Do NOT ask for permission to apply fixes.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from akin-ozer/cc-devops-skills at commit 276af75, republished under its Apache-2.0 licence (© akin-ozer). 2,372 words, ~8,250 tokens.
.claude/skills/k8s-yaml-validator/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.This skill provides a comprehensive validation workflow for Kubernetes YAML resources, combining syntax linting, schema validation, cluster dry-run testing, and intelligent CRD documentation lookup. Validate any Kubernetes manifest with confidence before applying it to the cluster.
IMPORTANT: This is a REPORT-ONLY validation tool. Do NOT modify files, do NOT use Edit tool, do NOT use AskUserQuestion to offer fixes. Generate a comprehensive validation report with suggested fixes shown as before/after code blocks, then let the user decide what to do next.
Use this skill when prompts look like:
Invoke this skill when:
This skill is strictly report-only:
Run with explicit paths so commands are repeatable:
REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)"
SKILL_DIR="$REPO_ROOT/devops-skills-plugin/skills/k8s-yaml-validator"
TARGET_FILE="$REPO_ROOT/<relative/path/to/file.yaml>"Path checks:
REPO_ROOT is empty, stop and ask for repository root.SKILL_DIR does not exist, stop and report path mismatch.TARGET_FILE does not exist, stop and ask for the correct file.Follow this sequential validation workflow. Each stage catches different types of issues:
Before running validators, count documents using the bundled script:
python3 "$SKILL_DIR/scripts/count_yaml_documents.py" "$TARGET_FILE"Expected output (example):
{
"file": ".../manifests.yaml",
"documents": 3,
"separators": 2
}Gate rules:
documents >= 3, load references/validation_workflow.md before Stage 1.python3 is unavailable, use fallback:awk 'BEGIN{d=0;seen=0} /^[[:space:]]*---[[:space:]]*$/ {if(seen){d++;seen=0}; next} /^[[:space:]]*#/ {next} NF{seen=1} END{if(seen)d++; print d}' "$TARGET_FILE"and mark the count as estimated in the report.
Before starting validation, verify required tools are installed:
bash "$SKILL_DIR/scripts/setup_tools.sh"Required tools:
If tools are missing, display installation guidance from script output and continue with available tools. Document missing tools and skipped stages in the report.
Validate YAML syntax and formatting using yamllint:
yamllint -c "$SKILL_DIR/assets/.yamllint" "$TARGET_FILE"Common issues caught:
Reporting approach:
Before schema validation, detect if the YAML contains Custom Resource Definitions:
bash "$SKILL_DIR/scripts/detect_crd_wrapper.sh" "$TARGET_FILE"The wrapper script automatically handles Python dependencies by creating a temporary virtual environment if PyYAML is not available.
Resilient Parsing: The script is resilient to syntax errors in individual documents. If a multi-document YAML file has some valid and some invalid documents, the script will:
The script outputs JSON with resource information and parse status:
{
"resources": [
{
"kind": "Certificate",
"apiVersion": "cert-manager.io/v1",
"group": "cert-manager.io",
"version": "v1",
"isCRD": true,
"name": "example-cert"
}
],
"parseErrors": [
{
"document": 1,
"start_line": 2,
"error_line": 6,
"error": "mapping values are not allowed in this context"
}
],
"summary": {
"totalDocuments": 3,
"parsedSuccessfully": 2,
"parseErrors": 1,
"crdsDetected": 1
}
}For each detected CRD:
Try Context7 MCP first (preferred):
mcp__context7__resolve-library-idlibraryName: CRD project name (example: cert-manager for cert-manager.io)mcp__context7__query-docslibraryId: resolved library ID from previous stepquery: include CRD kind, group, and version (example: Certificate cert-manager.io v1 required fields in spec)Fallback to web.search_query if Context7 fails or returns insufficient details:
Search query pattern:
"<kind>" "<group>" kubernetes CRD "<version>" documentation spec
Example:
"Certificate" "cert-manager.io" kubernetes CRD "v1" documentation specExtract key information:
specSecondary CRD Detection via kubeconform: If detect_crd_wrapper.sh cannot identify CRDs (for example, syntax errors in all documents), but kubeconform still validates a CRD resource, look up docs for that CRD anyway. Parse kubeconform output to identify validated CRDs and perform Context7/web.search_query lookups.
Why this matters: CRDs have custom schemas not available in standard Kubernetes validation tools. Understanding the CRD's spec requirements prevents validation errors and ensures correct resource configuration.
Validate against Kubernetes schemas using kubeconform:
kubeconform \
-schema-location default \
-schema-location 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-strict \
-ignore-missing-schemas \
-summary \
-verbose \
"$TARGET_FILE"Options explained:
-strict: Reject unknown fields (recommended for production - catches typos)-ignore-missing-schemas: Skip validation for CRDs without available schemas-kubernetes-version 1.30.0: Validate against specific K8s versionCommon issues caught:
For CRDs: If kubeconform reports "no schema found", this is expected. Use the documentation from Stage 3 to manually validate the spec fields.
kubeconform line number behavior — two distinct cases:
kubeconform does NOT report file-absolute line numbers. You must translate:
Parse errors (e.g. error converting YAML to JSON: yaml: line N):
N is document-relative (line N within that document's content).file_line = doc_start_line + N - 1doc_start_line comes from the start_line field in detect_crd_wrapper.sh output.yaml: line 5 →
file-absolute line = 4 + 5 − 1 = line 8 (matches yamllint output).Schema validation errors (e.g. got string, want integer):
at '/spec/template/spec/containers/0/ports/0/containerPort': got string, want integercontainerPort) within
the relevant document section, using file-absolute line numbers from the surrounding context.Always present line numbers as file-absolute in the validation report even when translating from kubeconform's document-relative output.
IMPORTANT: Always try server-side dry-run first. Server-side validation catches more issues than client-side because it runs through admission controllers and webhooks.
Decision Tree:
1. Try server-side dry-run first:
kubectl apply --dry-run=server -f "$TARGET_FILE"
└─ If SUCCESS → Use results, continue to Stage 6
└─ If FAILS with connection error (e.g., "connection refused",
"unable to connect", "no configuration"):
│
├─ 2. Attempt client-side dry-run (parse-only fallback):
│ kubectl apply --dry-run=client --validate=false -f "$TARGET_FILE"
│
│ ├─ If SUCCESS:
│ │ Document in report: "Server-side validation skipped (no cluster access); client fallback ran in parse-only mode"
│ │
│ └─ If FAILS with discovery/openapi error (e.g., "unable to recognize",
│ "failed to download openapi", "couldn't get current server API group list"):
│ Document in report: "Dry-run skipped (cluster discovery unavailable)"
│ Continue to Stage 6
│
└─ If FAILS with validation error (e.g., "admission webhook denied",
"resource quota exceeded", "invalid value"):
└─ Record the error, continue to Stage 6
└─ If FAILS with parse error (e.g., "error converting YAML to JSON",
"yaml: line X: mapping values are not allowed"):
└─ Record the error, skip client-side dry-run (same error will occur)
Document in report: "Dry-run blocked by YAML syntax errors - fix syntax first"
Continue to Stage 6Note: Parse errors from earlier stages (yamllint, kubeconform) will also cause dry-run to fail. Do NOT attempt client-side dry-run as a fallback for parse errors - it will produce the same error. Parse errors must be fixed before dry-run validation can proceed.
Server-side dry-run catches:
Client-side dry-run with --validate=false catches (fallback, when command succeeds):
kubectl can process and submit the manifest shape in client mode--validate=false disables schema/type/required-field validation and still does NOT catch admission controller or policy issues.Document in your report which mode was used:
--validate=false: "Limited parse-only validation (no cluster access) - schema and admission policies not checked"For updates to existing resources:
kubectl diff -f "$TARGET_FILE"This shows what would change, helping catch unintended modifications.
After completing all validation stages, generate a comprehensive report. This is a REPORT-ONLY stage.
NEVER do any of the following:
ALWAYS do the following:
Summarize all issues found across all stages in a table format:
| Severity | Stage | Location | Issue | Suggested Fix |
|----------|-------|----------|-------|---------------|
| Error | Syntax | file.yaml:5 | Indentation error | Use 2 spaces |
| Error | Schema | file.yaml:21 | Wrong type | Change to integer |
| Warning | Best Practice | file.yaml:30 | Missing labels | Add app label |Categorize by severity:
Show before/after code blocks for each issue:
For every issue, display explicit before/after YAML snippets showing the suggested fix:
**Issue 1: deployment.yaml:21 - Wrong field type (Error)**
Current:
```yaml
- containerPort: "80"Suggested Fix:
- containerPort: 80Why: containerPort must be an integer, not a string. Kubernetes will reject string values. Reference: See k8s_best_practices.md "Invalid Values" section.
Provide validation summary:
## Validation Report Summary
File: deployment.yaml
Resources Analyzed: 3 (Deployment, Service, Certificate)
| Stage | Status | Issues Found |
|-------|--------|--------------|
| YAML Syntax | ❌ Failed | 2 errors |
| CRD Detection | ✅ Passed | 1 CRD detected (Certificate) |
| Schema Validation | ❌ Failed | 1 error |
| Dry-Run | ❌ Failed | 1 error |
Total Issues: 4 errors, 2 warnings
## Detailed Findings
[List each issue with before/after code blocks as shown above]
## Next Steps
1. Fix the 4 errors listed above (deployment will fail without these)
2. Consider addressing the 2 warnings for best practices
3. Re-run validation after fixes to confirm resolutionDo NOT modify files - this is a reporting tool only
Use this table to keep stage decisions deterministic:
| Stage | Required | Command | Pass/Fail Criteria | Fallback |
|---|---|---|---|---|
| 0 Resource Count | Yes | python3 "$SKILL_DIR/scripts/count_yaml_documents.py" "$TARGET_FILE" | Pass when count output is produced and documents is recorded. | Use AWK estimator and mark estimated. |
| 1 Tool Check | Yes | bash "$SKILL_DIR/scripts/setup_tools.sh" | Pass when command runs and tool availability is known. | Continue with available tools and log skips. |
| 2 YAML Syntax | If yamllint available | yamllint -c "$SKILL_DIR/assets/.yamllint" "$TARGET_FILE" | Pass on exit code 0; fail on lint errors. | Skip with explicit reason if missing binary. |
| 3 CRD Detection | If python3 available | bash "$SKILL_DIR/scripts/detect_crd_wrapper.sh" "$TARGET_FILE" | Pass when JSON output includes summary. | Skip CRD extraction and rely on kubeconform clues. |
| 4 Schema | If kubeconform available | kubeconform command from Stage 4 | Pass when kubeconform reports valid resources. | Skip and record as coverage gap if missing binary. |
| 5 Dry-Run | If kubectl available | kubectl apply --dry-run=server -f "$TARGET_FILE" | Pass on successful server dry-run. | Attempt parse-only client fallback with --dry-run=client --validate=false; if discovery still fails, mark stage skipped. |
| 6 Report | Yes | Report generation | Pass when summary + per-issue snippets + next steps are provided. | No fallback; this stage is mandatory. |
| Constraint | Action | Report Language |
|---|---|---|
python3 unavailable | Skip count_yaml_documents.py and CRD parser scripts. Use AWK count only. | Python runtime unavailable; CRD parser skipped, resource count is estimated. |
yamllint unavailable | Skip Stage 2; continue with schema/dry-run stages if available. | YAML lint skipped because yamllint is not installed. |
kubeconform unavailable | Skip Stage 4; run lint and dry-run only. | Schema validation skipped because kubeconform is not installed. |
kubectl unavailable | Skip Stage 5 entirely. | Dry-run skipped because kubectl is not installed. |
| No cluster connectivity | Run server-side first, then attempt parse-only client fallback with --dry-run=client --validate=false; if it still fails, skip dry-run and continue. | Server-side dry-run unavailable due cluster access; parse-only client-side dry-run attempted (schema checks disabled). |
| Client dry-run still requires discovery | Treat dry-run as unavailable and rely on lint + schema stages. | Dry-run skipped (cluster discovery unavailable); lint and schema results used. |
| External docs unavailable | Continue local validation and state documentation gap. | CRD documentation lookup deferred due tooling/network limitation. |
For detailed Kubernetes YAML best practices, load the reference:
Read "$SKILL_DIR/references/k8s_best_practices.md"This reference includes:
When to load (ALWAYS load in these cases):
For in-depth workflow details and error handling strategies, load the reference:
Read "$SKILL_DIR/references/validation_workflow.md"This reference includes:
When to load (ALWAYS load in these cases):
When a YAML file contains multiple resources (separated by ---):
When a multi-document YAML file has some valid and some invalid documents:
Expected behavior:
detect_crd.py) will parse valid documents and skip invalid onesExample scenario: A file with 3 documents where document 1 has a syntax error:
Expected output:
In your report:
| Document | Resource | Parsing | Validation |
|----------|----------|---------|------------|
| 1 | Deployment | ❌ Syntax error (line 8) | Skipped |
| 2 | Service | ✅ Parsed | ✅ Valid |
| 3 | Certificate | ✅ Parsed | ✅ Valid |Line Number Reference Style:
This ensures users get maximum validation feedback even when some documents have issues.
bash "$SKILL_DIR/scripts/setup_tools.sh" to check availability--dry-run=client --validate=false--validate=false disables schema/type/required-field checks)kubectl get crd <crd-name>.group -o yaml
kubectl explain <kind>When presenting validation results:
Be clear and concise about what was found
Explain why issues matter (e.g., "This will cause pod creation to fail")
Provide context from best practices when relevant
Group related issues (e.g., all missing label issues together)
Use file:line references for all issues
Show fix complexity - Include a complexity indicator in the issue header:
Example format in issue header:
**Issue 1: deployment.yaml:8 - Wrong indentation (Error) [Simple]**
**Issue 2: deployment.yaml:15-25 - Missing security context (Warning) [Medium]**
**Issue 3: deployment.yaml - Selector mismatch with Service (Error) [Complex]**Always provide a comprehensive report including:
NEVER offer to apply fixes - this is strictly a reporting tool
For improved validation speed, some stages can be executed in parallel:
Can run in parallel (no dependencies):
yamllint (Stage 2) and detect_crd_wrapper.sh (Stage 3) can run simultaneouslyExample parallel execution:
# Run these in parallel (using & and wait, or parallel tool calls):
yamllint -c "$SKILL_DIR/assets/.yamllint" "$TARGET_FILE"
bash "$SKILL_DIR/scripts/detect_crd_wrapper.sh" "$TARGET_FILE"Must run sequentially:
When to parallelize:
Always consider Kubernetes version compatibility:
extensions/v1beta1 → apps/v1)kubectl api-versions to list available API versions in the clusterThe test/ directory contains example files to exercise all validation paths. Use these to verify skill behavior.
| Test File | Purpose | Expected Behavior |
|---|---|---|
deployment-test.yaml | Valid standard K8s resource | All stages pass, no errors |
certificate-crd-test.yaml | Valid CRD resource | CRD detected, Context7 lookup performed, no errors |
comprehensive-test.yaml | Multi-resource with intentional YAML syntax error | Syntax error detected, partial parsing works, CRD found |
schema-errors-test.yaml | Valid YAML with intentional schema type errors | yamllint passes; kubeconform fails with 2 JSON-path errors (replicas, containerPort) |
deployment-test.yamlcd "$SKILL_DIR"
python3 scripts/count_yaml_documents.py test/deployment-test.yaml
yamllint -c assets/.yamllint test/deployment-test.yaml
bash scripts/detect_crd_wrapper.sh test/deployment-test.yaml
kubeconform \
-schema-location default \
-schema-location 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-strict -ignore-missing-schemas -summary -verbose \
test/deployment-test.yaml
kubectl apply --dry-run=server -f test/deployment-test.yamlcertificate-crd-test.yamlmcp__context7__resolve-library-id and mcp__context7__query-docs usedcd "$SKILL_DIR"
python3 scripts/count_yaml_documents.py test/certificate-crd-test.yaml
bash scripts/detect_crd_wrapper.sh test/certificate-crd-test.yaml
kubeconform \
-schema-location default \
-schema-location 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-strict -ignore-missing-schemas -summary -verbose \
test/certificate-crd-test.yamlcomprehensive-test.yamlcd "$SKILL_DIR"
python3 scripts/count_yaml_documents.py test/comprehensive-test.yaml
yamllint -c assets/.yamllint test/comprehensive-test.yaml
bash scripts/detect_crd_wrapper.sh test/comprehensive-test.yaml
kubeconform \
-schema-location default \
-schema-location 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-strict -ignore-missing-schemas -summary -verbose \
test/comprehensive-test.yaml
kubectl apply --dry-run=server -f test/comprehensive-test.yamlcomprehensive-test.yaml (has 3 resources, 1 with syntax error)cd "$SKILL_DIR"
python3 scripts/count_yaml_documents.py test/comprehensive-test.yaml
bash scripts/detect_crd_wrapper.sh test/comprehensive-test.yamlschema-errors-test.yamlcd "$SKILL_DIR"
python3 scripts/count_yaml_documents.py test/schema-errors-test.yaml
yamllint -c assets/.yamllint test/schema-errors-test.yaml
bash scripts/detect_crd_wrapper.sh test/schema-errors-test.yaml
kubeconform \
-schema-location default \
-schema-location 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-strict -ignore-missing-schemas -summary -verbose \
test/schema-errors-test.yamlcd "$SKILL_DIR"
KUBECONFIG=/tmp/nonexistent-kubeconfig kubectl apply --dry-run=server -f test/deployment-test.yaml
KUBECONFIG=/tmp/nonexistent-kubeconfig kubectl apply --dry-run=client --validate=false -f test/deployment-test.yamlcd "$SKILL_DIR"
PATH="/usr/bin:/bin" bash scripts/setup_tools.shWhen adding test files:
<scenario>-test.yamlFor any validation, the report should include:
Validation is complete only when all conditions are true:
count_yaml_documents.py (or documented AWK fallback).mcp__context7__resolve-library-id + mcp__context7__query-docs, with web.search_query fallback only when needed.detect_crd_wrapper.sh
bash "$SKILL_DIR/scripts/detect_crd_wrapper.sh" "$TARGET_FILE"detect_crd.py
python3 "$SKILL_DIR/scripts/detect_crd.py" "$TARGET_FILE"count_yaml_documents.py
python3 "$SKILL_DIR/scripts/count_yaml_documents.py" "$TARGET_FILE"setup_tools.sh
bash "$SKILL_DIR/scripts/setup_tools.sh"k8s_best_practices.md
validation_workflow.md
.yamllint
yamllint -c "$SKILL_DIR/assets/.yamllint" "$TARGET_FILE"© akin-ozer, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (scripts, references, assets) in devops-skills-plugin/skills/k8s-yaml-validator of akin-ozer/cc-devops-skills.
Open the folder on GitHubat commit 276af75
K8s YAML Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| K8s YAML Validator this skillakin-ozer/cc-devops-skills | 320 | — | ~8.3k | Automated safety check: Warn | Apache-2.0 | |
| Iac Securityhardw00t/ai-security-arsenal | 105 | — | ~2.4k | Automated safety check: Pass | None | |
| Kubeshark Installerkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | |
| KubeSphere Multi-Tenant Managementkubesphere/kubesphere | 17k | — | ~3.1k | Automated safety check: Pass | Custom licence | |
| Sim Helmsimstudioai/sim | 30k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Helm Chart ScaffoldingCybereason-Public/owLSM | 280 | 13 repos | ~381 | Automated safety check: Pass | GPL-2.0 |
hardw00t/ai-security-arsenal
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
kubesphere/kubesphere
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
simstudioai/sim
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
Cybereason-Public/owLSM
Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
akin-ozer/cc-devops-skills
Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.
akin-ozer/cc-devops-skills
Create, scaffold, or generate Helm charts, Chart.yaml, values.yaml, templates, helpers.
akin-ozer/cc-devops-skills
Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.
akin-ozer/cc-devops-skills
Validate, lint, audit, or scan a Dockerfile for security and best practices.
akin-ozer/cc-devops-skills
Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).
akin-ozer/cc-devops-skills
Validate, lint, audit, or check Jenkinsfiles and shared libraries.
Works with
Categories
Validate, lint, audit, or dry-run Kubernetes manifests (Deployment, Service, ConfigMap, CRD). K8s YAML Validator is an agent skill from akin-ozer/cc-devops-skills. Validate, lint, audit, or dry-run Kubernetes manifests (Deployment, Service, ConfigMap, CRD).
K8s YAML Validator fits situations like: tasks that involve Container orchestration; tasks that involve Linting and formatting.
Run `npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/k8s-yaml-validator in akin-ozer/cc-devops-skills) into .claude/skills/k8s-yaml-validator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/k8s-yaml-validator in akin-ozer/cc-devops-skills) into .agents/skills/k8s-yaml-validator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill k8s-yaml-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-yaml-validator, .gemini/skills/k8s-yaml-validator, .github/skills/k8s-yaml-validator and .opencode/skills/k8s-yaml-validator in your project.
Going by SKILL.md and its folder, K8s YAML Validator needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (bash, kubectl, python3 and git). Our summary lists: Python 3; A Bash shell.
SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
K8s YAML Validator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.3k tokens (SKILL.md is roughly 33k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with K8s YAML Validator: Iac Security (hardw00t/ai-security-arsenal, 105 stars), Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars) and Sim Helm (simstudioai/sim, 30k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 320 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.
Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.