Agent skill

K8s Service Path

by automateyournetwork in automateyournetwork/netclaw

Trace the Kubernetes service path — Service to selector to pods to EndpointSlices to readiness, plus Ingress routing.

Apache-2.0Auto-check passedDevOps & Cloud

Install K8s Service Path

skills CLI
$ npx skills add automateyournetwork/netclaw --skill k8s-service-path -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw k8s-service-path --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/k8s-service-path .claude/skills/k8s-service-path && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
k8s-service-path
GitHub stars
676
Token cost
~919 tokens
SKILL.md length
371 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Trace the Kubernetes service path — Service to selector to pods to EndpointSlices to readiness, plus Ingress routing.

  • Works in 5 steps: State which links you checked and which… → "No endpoints" is a symptom — name the… → Separate ready from not-ready. → …
  • A service is getting no traffic
  • SKILL.md covers Server, The path, and the rule about it, Walking it and Diagnoses that look identical…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

K8s Service Path is an agent skill from automateyournetwork/netclaw. Trace the Kubernetes service path — Service to selector to pods to EndpointSlices to readiness, plus Ingress routing. Use when a service is getting no traffic, an ingress is not routing, or someone asks why a workload is unreachable inside a cluster.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration and Cloud networking. It works with Kubernetes. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • A service is getting no traffic
  • An ingress is not routing
  • Someone asks why a workload is unreachable inside a cluster

Example prompts

  • “/k8s-service-path”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. State which links you checked and which you did not.
  2. "No endpoints" is a symptom — name the cause.
  3. Separate ready from not-ready.
  4. Call out an Ingress backend that does not exist.
  5. Show selectors and scope. Read-only.

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

K8s Service Path loads about 919 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 371 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~919

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 371 words, ~919 tokens.

Download SKILL.mdSave it as .claude/skills/k8s-service-path/SKILL.md (or your agent's skills folder).
name
k8s-service-path
description
Trace the Kubernetes service path — Service to selector to pods to EndpointSlices to readiness, plus Ingress routing. Use when a service is getting no traffic, an ingress is not routing, or someone asks why a workload is unreachable inside a cluster.
version
1.0.0
license
Apache-2.0
tags
kubernetes, k8s, service, ingress, endpoints, endpointslice, troubleshooting
user-invocable
true

Kubernetes Service Path Tracing

Server

k8s-mcp — vendored third-party, read-only, 7 tools. See k8s-network-policy for the shared preflight and the empty-result cautions, which apply here identically.

The path, and the rule about it

Ingress → Service → selector → Pods → EndpointSlice → readiness

Mark every link checked or not checked. A partial trace presented as complete is the failure mode of this skill — "the service is fine" after checking two of five links is worse than saying nothing, because it sends the next person somewhere else.

Walking it

jsonc
resources_list({"apiVersion":"networking.k8s.io/v1","kind":"Ingress"})
resources_get ({"apiVersion":"v1","kind":"Service","namespace":"app1","name":"web"})
pods_list_in_namespace({"namespace":"app1"})            // then match against the Service selector
resources_list({"apiVersion":"discovery.k8s.io/v1","kind":"EndpointSlice","namespace":"app1"})

Diagnoses that look identical and are not

SymptomActual causeHow to say it
No endpointsSelector matches no pods"The Service selector app=web matches no pods" — the selector is wrong or the pods are gone
No endpointsPods exist but none are ready"3 pods match but none are Ready" — a readiness-probe problem, not a wiring problem
No endpointsPods ready, port mismatch"Pods are ready but no container exposes the target port"
Traffic blockedA NetworkPolicy denies ithand off to k8s-network-policy — this skill does not evaluate policy
Ingress not routingBackend names a non-existent Service"Ingress web routes to Service web-v2, which does not exist" — call this out loudly, it is a common and silent misconfiguration

"No endpoints" is a symptom, never a diagnosis. Always name which of these it is.

Show full SKILL.md (160 more words)Show less

Ready is not the same as existing

An EndpointSlice lists both ready and not-ready addresses. A Service with five not-ready endpoints has zero serving capacity but is not empty. Report the two counts separately — collapsing them hides an outage.

Empty results

Everything in k8s-network-policy's six-cause table applies. In particular:

  • A Service in a non-existent namespace returns nothing, not a 404.
  • A typo'd selector returns zero pods with HTTP 200 — show the selector.
  • Without confirmed cluster-wide scope, a cross-namespace Ingress trace may be silently incomplete.

Boundaries

Want to…Use
Whether traffic is permittedk8s-network-policy — this traces wiring, not policy
Whether packets actually flowedkubeshark-traffic
Latency / error ratesprometheus, grafana
Pod inventory and statusk8s-workload-inventory
Change anythingnothing here. Read-only

Rules

  1. State which links you checked and which you did not.
  2. "No endpoints" is a symptom — name the cause.
  3. Separate ready from not-ready.
  4. Call out an Ingress backend that does not exist.
  5. Show selectors and scope. Read-only.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/k8s-service-path of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

K8s Service Path next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

K8s Service Path compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
K8s Service Path this skillautomateyournetwork/netclaw676—~919Automated safety check: PassApache-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
NGINX Ingress Policy CRD Guidenginx/kubernetes-ingress5.1k—~2kAutomated safety check: PassApache-2.0
Aks Deployment Skilltimothywarner/chatgptclass143—~916Automated safety check: PassCustom licence

Similar skills

  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Aks Deployment Skill

    timothywarner/chatgptclass

    Deploy and operate workloads on Azure Kubernetes Service (AKS) the safe way.

    143 GitHub stars~916 tokensUpdated 21 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere Gateway Management

    kubesphere/kubesphere

    Installs, uninstalls, checks and troubleshoots the KubeSphere Gateway extension built on ingress-nginx, including gateways stuck in bad states and Helm or pod failures.

    17k GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about K8s Service Path

What does K8s Service Path do?

Trace the Kubernetes service path — Service to selector to pods to EndpointSlices to readiness, plus Ingress routing. K8s Service Path is an agent skill from automateyournetwork/netclaw. Trace the Kubernetes service path — Service to selector to pods to EndpointSlices to readiness, plus Ingress routing.

When should I use K8s Service Path?

K8s Service Path fits situations like: A service is getting no traffic; an ingress is not routing; someone asks why a workload is unreachable inside a cluster.

How do I install K8s Service Path in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill k8s-service-path -a claude-code`. Or copy the skill folder (workspace/skills/k8s-service-path in automateyournetwork/netclaw) into .claude/skills/k8s-service-path in your project. Claude Code loads it when a task matches its description.

How do I install K8s Service Path in Codex?

Run `npx skills add automateyournetwork/netclaw --skill k8s-service-path -a codex`. Or copy the skill folder (workspace/skills/k8s-service-path in automateyournetwork/netclaw) into .agents/skills/k8s-service-path in your project. Codex loads it when a task matches its description.

Can I use K8s Service Path in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill k8s-service-path -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-service-path, .gemini/skills/k8s-service-path, .github/skills/k8s-service-path and .opencode/skills/k8s-service-path in your project.

What does K8s Service Path need to run?

SKILL.md names no scripts, command-line tools or credentials: K8s Service Path is instructions for the agent only.

Does K8s Service Path access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is K8s Service Path safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does K8s Service Path use?

K8s Service Path is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does K8s Service Path use?

About 919 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to K8s Service Path?

Skills that share tags, products or a category with K8s Service Path: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars) and NGINX Ingress Policy CRD Guide (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains K8s Service Path?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.