Official agent skill

Eks Recon

by aws-samples in aws-samples/appmod-blueprints

EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.

OfficialMIT-0Auto-check: warningsDevOps & Cloud

Install Eks Recon

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/appmod-blueprints eks-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-recon .claude/skills/eks-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eks-recon
GitHub stars
113
Token cost
~4.7k tokens
SKILL.md length
1,607 words
Files
20 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT-0

At a glance

EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.

  • Works in 4 steps: Gather Prerequisites → Check MCP Availability → Run Selected Modules → …
  • Someone asks about their EKS cluster
  • SKILL.md covers When to Use This Skill, Prerequisites, Reconnaissance Modes and Modules and Reference Loading, plus 4 more sections
  • Calls aws, kubectl and helm

What it does

Eks Recon is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. EKS cluster reconnaissance and environment discovery. Detects compute strategy (Karpenter, MNG, Auto Mode, Fargate), IaC tooling (Terraform, CloudFormation, CDK, eksctl), CI/CD pipelines (GitHub Actions, GitLab, ArgoCD, Flux), add-on inventory, networking, security posture, and observability. Use this skill whenever someone asks about their EKS cluster, wants to understand their setup, is planning an upgrade or migration, needs cluster context for any reason, asks what version am I running, mentions wanting to…

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `agents/addons-recon.md`, `agents/cicd-recon.md` and `agents/compute-recon.md`).

It sits in DevOps & Cloud, covering Infrastructure as code, CI/CD and Container orchestration. It works with Argo CD, AWS CloudFormation, GitHub Actions and GitLab. The licence is MIT-0.

When your agent uses it

  • Someone asks about their EKS cluster
  • Wants to understand their setup
  • Is planning an upgrade
  • Needs cluster context for any reason

Example prompts

  • “/eks-recon”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather Prerequisites
  2. Check MCP Availability
  3. Run Selected Modules
  4. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 723cdc0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • kubectl
    • helm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, kubectl and helm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eks Recon loads about 4.7k tokens when it runs, and up to ~32k if it reads all its reference files. Until then it costs about 236 tokens; SKILL.md has 1,607 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~236
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~32k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:209
    ables. AWS credentials can come from `~/.aws/credentials`, `~/.aws/config`, instance metadata, or ECS task roles — none

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/appmod-blueprints at commit 723cdc0, republished under its MIT-0 licence (© aws-samples). 1,607 words, ~4,715 tokens.

Download SKILL.mdSave it as .claude/skills/eks-recon/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.
name
eks-recon
description
EKS cluster reconnaissance and environment discovery. Detects compute strategy (Karpenter, MNG, Auto Mode, Fargate), IaC tooling (Terraform, CloudFormation, CDK, eksctl), CI/CD pipelines (GitHub Actions, GitLab, ArgoCD, Flux), add-on inventory, networking, security posture, and observability. Use this skill whenever someone asks about their EKS cluster, wants to understand their setup, is planning an upgrade or migration, needs cluster context for any reason, asks what version am I running, mentions wanting to review or document their cluster, or is about to make any EKS-related decision - even if they don't explicitly say reconnaissance or discovery. When in doubt about cluster state, run recon first. Skip for upgrade readiness scoring or deprecated API checks (eks-upgrade-check), operational audits with GREEN/AMBER/RED ratings (eks-operation-review), and architecture design documents or Mermaid diagrams (eks-design).

EKS Reconnaissance

Discover everything about an EKS cluster environment. Run this skill to gather comprehensive cluster context before making any decisions, changes, or recommendations.

When to Use This Skill

Run this skill when the user:

  • Asks about their EKS cluster ("what's my cluster running?", "tell me about my setup")
  • Plans an upgrade, migration, or architecture change
  • Needs cluster context before any EKS-related decision
  • Wants to document or review their cluster state
  • Asks questions like "what version am I on?" or "am I using Karpenter?"
  • Is about to modify their cluster (recon first to understand current state)

Also trigger this skill when:

  • User mentions an EKS cluster name and seems to need context
  • Another workflow needs cluster information as input
  • You need to understand the cluster before giving recommendations

Do NOT use this skill for:

  • Upgrade readiness scoring or deprecated API checks — questions like "score my upgrade readiness", "are there deprecated APIs blocking my upgrade", "can I safely upgrade to 1.33", "readiness score", or "breaking changes that would block a version bump" belong to eks-upgrade-check. Recon discovers what version you're on; it does NOT assess whether you're ready to move to the next version.
  • Operational audits with maturity ratings — questions like "run an operational excellence audit", "rate each area GREEN/AMBER/RED", or "audit my cluster's operational posture" belong to eks-operation-review. Recon inventories what exists; it does NOT score operational maturity or produce rated assessments.
  • Architecture design documents or Mermaid diagrams — questions like "create a security architecture document", "generate Mermaid diagrams for our EKS cluster", or "design document" belong to eks-design. Recon discovers current state; it does NOT produce design artifacts or architectural diagrams.
  • Creating or modifying cluster resources (this is read-only)
  • Troubleshooting specific issues (use eks-best-practices)
  • Learning about EKS concepts (use eks-best-practices)

Prerequisites

MCP Server (Preferred)

This skill works best with the EKS MCP Server configured. Check if MCP tools are available:

If tools like `list_eks_resources`, `describe_eks_resource`, `list_k8s_resources` are available:
  -> MCP Mode: Use MCP tools (pre-authorized, richer output)
  
If MCP tools are NOT available:
  -> CLI Mode: Fall back to AWS CLI + kubectl (requires explicit permission)

MCP Mode benefits:

  • Pre-authorized read-only operations (no permission prompts)
  • Richer output with better formatting
  • Single tool call instead of piped commands

CLI Mode limitations:

  • Requires user permission for each command
  • May need kubeconfig setup
  • Some detection patterns are less reliable
Required for CLI Mode
ToolRequired For
aws CLICluster-level detection (describe-cluster, list-nodegroups, list-addons)
kubectlK8s resource detection (deployments, CRDs, service accounts)
helmHelm release inventory (optional)
MCP Troubleshooting

401 Unauthorized on K8s API calls (list_k8s_resources, read_k8s_resource):

The MCP server can access EKS APIs (clusters, nodegroups, addons) but may lack Kubernetes API access. This happens when the MCP server's IAM role doesn't have an EKS access entry.

Solutions (choose one):

  1. Grant MCP access: Create an EKS access entry for the MCP server's IAM role.

    Surface these commands to the user — do NOT execute them. These are persistent IAM writes and violate the read-only contract of this skill.

    bash
    aws eks create-access-entry \
      --cluster-name <cluster> \
      --region <region> \
      --principal-arn <mcp-server-role-arn> \
      --type STANDARD
    aws eks associate-access-policy \
      --cluster-name <cluster> \
      --region <region> \
      --principal-arn <mcp-server-role-arn> \
      --policy-arn arn:aws:eks::aws:cluster-access-policy/AmazonEKSViewPolicy \
      --access-scope type=cluster

    If the user confirms and has permission, they can run these themselves out-of-band.

  2. Fall back to kubectl: If user has local kubectl access, use CLI commands instead:

    "MCP K8s access returned 401. I'll use kubectl instead if you have it configured locally."

Empty results from EKS API calls:

  • Verify cluster name and region are correct
  • Check if the cluster exists: aws eks list-clusters --region <region>

Reconnaissance Modes

ModeWhen to UseWhat Happens
Full ReconFirst engagement with clusterRuns all modules, generates complete report
Selective ReconKnow what you needRun specific modules (e.g., compute + iac)
Targeted QueryQuick answer"Is this cluster using Karpenter?"
How to Invoke

Full reconnaissance:

"Run EKS reconnaissance on cluster my-cluster in us-west-2"

Selective reconnaissance:

"Run EKS recon but only check compute and IaC"

Targeted query:

"What IaC tool manages cluster my-cluster?"


Modules and Reference Loading

Load only the references needed for the user's request — this keeps context focused. references/cluster-basics.md is always loaded first by every module; it provides the shared cluster context all other modules depend on. For targeted queries, load only the matching row(s); for full recon, load all references in parallel. When uncertain, ask the user or default to full recon.

ModuleIntent / when to useReference fileAgent file
Cluster BasicsAlways loaded first by every module (name, region, version, platform version, endpoint)cluster-basics.md—
ComputeKarpenter, nodes, scaling, Auto Mode, node groups, Fargate, self-managedcompute.mdcompute-recon.md
NetworkingVPC, ingress, CNI, service mesh, load balancer, connectivitynetworking.mdnetworking-recon.md
SecurityIAM, IRSA, Pod Identity, RBAC, policies, encryption, secrets, webhookssecurity.mdsecurity-recon.md
Add-onsEKS-managed add-ons, Helm releases, plugins, "what's installed?"addons.mdaddons-recon.md
ObservabilityLogging, metrics, monitoring, Container Insights, Prometheusobservability.mdobservability-recon.md
WorkloadsDeployments, pods, services, ingresses, "what's running?"workloads.mdworkloads-recon.md
StoragePVCs, EBS, EFS, StorageClasses, CSI drivers, volumes, snapshotsstorage.mdstorage-recon.md
IaCTerraform, CloudFormation, CDK, eksctl, Pulumi, "how is it managed?"iac.mdiac-recon.md
CI/CDGitHub Actions, GitLab CI, Jenkins, ArgoCD, Flux, GitOps, pipelinescicd.mdcicd-recon.md

Quick Detection Reference

MCP Commands (Preferred)
DetectionMCP Tool
Cluster infodescribe_eks_resource(resource_type="cluster", cluster_name="<name>")
Node groupslist_eks_resources(resource_type="nodegroup", cluster_name="<name>")
EKS add-onslist_eks_resources(resource_type="addon", cluster_name="<name>")
Karpenterlist_k8s_resources(cluster_name="<name>", kind="NodePool", api_version="karpenter.sh/v1")
Deploymentslist_k8s_resources(cluster_name="<name>", kind="Deployment", api_version="apps/v1")
VPC configget_eks_vpc_config(cluster_name="<name>")
Insightsget_eks_insights(cluster_name="<name>")
CLI Fallbacks
DetectionCLI Command
Cluster infoaws eks describe-cluster --name <name> --region <region>
Node groupsaws eks list-nodegroups --cluster-name <name> --region <region>
EKS add-onsaws eks list-addons --cluster-name <name> --region <region>
Fargate profilesaws eks list-fargate-profiles --cluster-name <name> --region <region>
Auto Modeaws eks describe-cluster --name <name> --region <region> --query 'cluster.computeConfig'
Karpenterkubectl get nodepools.karpenter.sh 2>/dev/null
Helm releaseshelm list -A

Running Reconnaissance

IMPORTANT: Load Reference Files

Before running each module, you MUST read its reference file (e.g., references/compute.md). References contain:

  • Detection order and rationale (why check Auto Mode before Karpenter)
  • Edge cases and how to handle them
  • CLI fallback commands when MCP fails
  • Output schema for structured reporting

Skipping references produces shallow results. The main skill provides orchestration; the references provide detection intelligence.

Show full SKILL.md (682 more words)Show less
Step 1: Gather Prerequisites
Required:
- Cluster name (or auto-discover — see below)
- AWS region (or detect from context/kubeconfig/CLI)

Optional:
- Specific modules to run (default: all)
- Output file path (default: .eks-recon-report.yaml)

Auto-discovery when cluster name is not explicit:

When the user says "my cluster", "current cluster", or does not name a specific cluster, discover it:

  1. kubectl config current-context — if set, extract cluster name from the context ARN
  2. If no kubeconfig context, try AWS CLI directly (credentials may come from ~/.aws/ config files, instance profile, or env vars — don't assume env vars are the only source):
    bash
    aws sts get-caller-identity  # verify we have working AWS access
    aws eks list-clusters --region ${AWS_DEFAULT_REGION:-us-west-2}
  3. If exactly one cluster is found, use it. If multiple clusters across regions, try common regions (us-west-2, us-east-1, the region in any ARN visible in kubeconfig).
  4. Only ask the user to specify a cluster if discovery yields multiple candidates and the prompt is ambiguous.

IMPORTANT: Never give up after checking only environment variables. AWS credentials can come from ~/.aws/credentials, ~/.aws/config, instance metadata, or ECS task roles — none of which appear in env | grep AWS_. Always try aws sts get-caller-identity before concluding credentials are unavailable.

Step 2: Check MCP Availability

If MCP tools are available, use them. Otherwise, inform the user:

"EKS MCP Server not detected. I'll use CLI commands instead, which will require your permission for each command. For a smoother experience, consider setting up the EKS MCP Server."

Step 3: Run Selected Modules

Determine which modules to run based on user intent (see Modules and Reference Loading).

For each selected module:

  1. Load the reference file (e.g., references/compute.md) - REQUIRED
    • For targeted queries: load only the required reference(s) per decision matrix
    • For full recon: load all references in parallel
  2. Run detection commands following the reference's guidance:
    • Try MCP tool first
    • If MCP returns error (401, empty), fall back to CLI from reference
    • If CLI unavailable, note the limitation in report
  3. Collect output into report section using the reference's output schema
Step 4: Generate Report

Write report to .eks-recon-report.yaml and present summary:

yaml
# EKS Reconnaissance Report
# Generated: 2026-04-22T14:30:00Z
# Cluster: my-cluster
# Region: us-west-2
# Modules: cluster-basics, compute, iac, cicd, addons

cluster:
  name: my-cluster
  region: us-west-2
  version: "1.31"
  platform_version: eks.5
  endpoint: https://<cluster-id>.gr7.us-west-2.eks.amazonaws.com
  arn: arn:aws:eks:us-west-2:<account-id>:cluster/my-cluster
  status: ACTIVE
  created_at: "2024-09-10T12:00:00Z"

compute:
  strategy: Karpenter
  auto_mode:
    enabled: false
  karpenter:
    detected: true
    version: "1.0.5"
    nodepools: 2
    nodepool_names: [default, gpu]
  mng:
    detected: true
    count: 1
    groups:
      - name: system
        status: ACTIVE
        instance_types: [m6i.large]
        desired_size: 2
  fargate:
    detected: false
    profiles: 0
  self_managed:
    detected: false
    node_count: 0

iac:
  tool: Terraform
  confidence: high
  evidence:
    type: workspace_files
    details: "./infrastructure/eks/main.tf contains aws_eks_cluster"

cicd:
  workspace:
    github_actions:
      detected: true
      workflows: [.github/workflows/deploy.yml]
    gitlab_ci:
      detected: false
    jenkins:
      detected: false
      jenkinsfile: false
    other: null
  gitops:
    argocd:
      detected: true
      namespace: argocd
      applications: 12
      app_projects: 3
    flux:
      detected: false
      namespace: null
      kustomizations: 0
      helm_releases: 0
      git_repositories: 0

addons:
  eks_managed:
    count: 2
    list:
      - name: vpc-cni
        version: v1.18.1-eksbuild.1
        status: ACTIVE
        configuration: null
      - name: coredns
        version: v1.11.1-eksbuild.8
        status: ACTIVE
        configuration: null
  helm_releases:
    count: 1
    list:
      - name: karpenter
        namespace: kube-system
        chart: karpenter
        version: 1.0.5
        status: deployed

Subagent Mode

When running full reconnaissance, delegate each module to a specialized subagent. This keeps each module's context isolated and enables true parallel execution.

When to Use Subagents
ScenarioModeReason
Any recon (1+ modules)USE subagentsIsolated context, cleaner main conversation
No Agent tool availableInlineSubagents not supported

IMPORTANT: If the Agent tool is available, you MUST use subagent mode for ALL reconnaissance — even single-module targeted queries. Subagents keep detection context isolated from the main conversation. Do not fall back to inline mode just because "it's only one module" or "MCP tools work" — always delegate to subagents.

Subagent Files

Each module has a corresponding subagent prompt in agents/:

SubagentFilePurpose
Computeagents/compute-recon.mdDetect compute strategy
Networkingagents/networking-recon.mdDetect network config
Securityagents/security-recon.mdDetect security posture, secrets, webhooks
Add-onsagents/addons-recon.mdDetect installed components
Observabilityagents/observability-recon.mdDetect monitoring/logging
Storageagents/storage-recon.mdDetect CSI, StorageClasses, PVCs
Workloadsagents/workloads-recon.mdDetect running workloads
IaCagents/iac-recon.mdDetect IaC tooling
CI/CDagents/cicd-recon.mdDetect deployment pipelines
Orchestration Steps

Step 1: Check subagent availability

If Agent tool is available:
  → MUST use subagent mode for ALL recon (full or targeted)
  → Even single-module queries use subagents to isolate context
Else:
  → Use inline mode (load references directly)

Step 2: Spawn module subagents in parallel

Spawn ALL module subagents in a SINGLE message for parallel execution:

Agent(
  description: "EKS compute recon",
  prompt: "Recon compute for cluster {cluster_name} in {region}. 
           Read agents/compute-recon.md and references/compute.md.
           Return YAML output only.",
  subagent_type: "general-purpose"
)

Agent(
  description: "EKS networking recon",
  prompt: "Recon networking for cluster {cluster_name} in {region}.
           Read agents/networking-recon.md and references/networking.md.
           Return YAML output only.",
  subagent_type: "general-purpose"
)

... (spawn all 9 in parallel)

Step 3: Aggregate results

When all subagents complete:

  1. Collect each subagent's YAML output
  2. Merge into single report structure, applying these normalization rules:
    • Every subagent emits its own top-level cluster: block. Merge into a single top-level cluster: by deduplicating exact-match blocks (all subagents report the same cluster); if any field mismatches across subagents, flag it rather than silently picking one.
    • Module outputs are already in their canonical agent-defined shapes. Preserve them verbatim under the matching top-level key: compute:, iac:, cicd:, addons:, networking:, observability:, security:, storage:, workloads:. Do not reshape, flatten, or rename keys.
    • If a subagent fails to respond or errors out, set its key to unavailable: true with a short reason: string; do not omit the key.
  3. Add cross-module insights (e.g., "Karpenter detected but no IRSA for controller")
  4. Generate recommendations based on combined findings
  5. Write final report to .eks-recon-report.yaml
  6. Present summary to user

Integration with Other Workflows

Upgrade Workflow

The upgrade workflow can invoke eks-recon to gather Phase 1 context:

1. Run eks-recon modules: cluster-basics, compute, iac, addons
2. Extract:
   - cluster.version -> Current version
   - compute.strategy -> Determines upgrade approach
   - iac.tool -> Terraform vs CLI upgrade path
   - addons -> Compatibility matrix input
Design Workflow

The design workflow can use eks-recon for existing clusters:

1. Run eks-recon modules: all
2. Pre-populate questionnaire from detected values
3. Ask user: "I detected Karpenter + Terraform + ArgoCD. Correct?"
4. Only ask questions for undetected values

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 19 other files (references) in .kiro/skills/eks-recon of aws-samples/appmod-blueprints.

  • SKILL.md
  • agents/addons-recon.md
  • agents/cicd-recon.md
  • agents/compute-recon.md
  • agents/iac-recon.md
  • agents/networking-recon.md
  • agents/observability-recon.md
  • agents/security-recon.md
  • agents/storage-recon.md
  • agents/workloads-recon.md
  • references/addons.md
  • references/cicd.md
  • references/cluster-basics.md
  • references/compute.md
  • references/iac.md
  • references/networking.md
  • references/observability.md
  • references/security.md
  • references/storage.md
  • … and 1 more

Open the folder on GitHubat commit 723cdc0

Compare with similar skills

Eks Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eks Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eks Recon this skillaws-samples/appmod-blueprints113—~4.7kAutomated safety check: WarnMIT-0
Devops Automatorcuriositech/some_claude_skills243—~1.8kAutomated safety check: PassMIT
Infrastructure Devops Devops Engineerchendongqi/OPB-Skills125—~1.4kAutomated safety check: PassNone
Tirith PoliciesStackGuardian/tirith167—~1.8kAutomated safety check: PassApache-2.0
Devops InfrastructureCloudAI-X/claude-workflow-v21.4k—~2.7kAutomated safety check: NotesMIT
Cloud Devopsdavila7/claude-code-templates32k4 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Devops Automator

    curiositech/some_claude_skills

    Expert DevOps engineer for CI/CD, IaC, Kubernetes, and deployment automation.

    243 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • DevOps助手 - 专业的DevOps实践与自动化专家。适用场景: (1) CI/CD流水线设计与实现 (2) 部署策略与发布管理 (3) 基础设施即代码(IaC) (4) 容器化与Kubernetes部署 (5) 监控告警与可观测性 (6) DevOps工具链选型 (7) DevOps文化与实践推广 触发关键词:DevOps、CI/CD、持续集成、持续部署、Jenkins、GitLab…

    125 GitHub stars~1.4k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Tirith Policies

    StackGuardian/tirith

    Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…

    167 GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops Infrastructure

    CloudAI-X/claude-workflow-v2

    Guides Docker, CI/CD pipelines, deployment strategies, infrastructure as code, and observability setup.

    1.4k GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    32k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Devops Iac Engineer

    davila7/claude-code-templates

    Implements infrastructure as code using Terraform, Kubernetes, and cloud platforms.

    32k GitHub starsUsed in 1 repo~1.6k tokens
    DevOps & CloudAuto-check passed

More from aws-samples/appmod-blueprints

All 9 skills in this repo
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    113 GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Troubleshoot Platform

    aws-samples/appmod-blueprints

    Official

    Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.

    113 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Troubleshoot Kro

    aws-samples/appmod-blueprints

    Official

    Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

    113 GitHub stars~986 tokensUpdated yesterday
    Auto-check passed
  • Eks Upgrade Check

    aws-samples/appmod-blueprints

    Official

    Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…

    113 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check: warnings
  • Eks Platform Engineering

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…

    113 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Eks Recon

What does Eks Recon do?

EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints. Eks Recon is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. EKS cluster reconnaissance and environment discovery.

When should I use Eks Recon?

Eks Recon fits situations like: someone asks about their EKS cluster; wants to understand their setup; is planning an upgrade; needs cluster context for any reason.

How do I install Eks Recon in Claude Code?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-recon -a claude-code`. Or copy the skill folder (.kiro/skills/eks-recon in aws-samples/appmod-blueprints) into .claude/skills/eks-recon in your project. Claude Code loads it when a task matches its description.

How do I install Eks Recon in Codex?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-recon -a codex`. Or copy the skill folder (.kiro/skills/eks-recon in aws-samples/appmod-blueprints) into .agents/skills/eks-recon in your project. Codex loads it when a task matches its description.

Can I use Eks Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-recon, .gemini/skills/eks-recon, .github/skills/eks-recon and .opencode/skills/eks-recon in your project.

What does Eks Recon need to run?

Going by SKILL.md and its folder, Eks Recon needs the command-line tools its instructions call (aws, kubectl and helm).

Does Eks Recon access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Eks Recon safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Eks Recon use?

Eks Recon is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eks Recon use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 27k tokens, read only when the agent opens those files.

What are the alternatives to Eks Recon?

Skills that share tags, products or a category with Eks Recon: Devops Automator (curiositech/some_claude_skills, 243 stars), Infrastructure Devops Devops Engineer (chendongqi/OPB-Skills, 125 stars), Tirith Policies (StackGuardian/tirith, 167 stars) and Devops Infrastructure (CloudAI-X/claude-workflow-v2, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eks Recon?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.

Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.