Devops Automator
curiositech/some_claude_skills
Expert DevOps engineer for CI/CD, IaC, Kubernetes, and deployment automation.
EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-recon --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-recon .claude/skills/eks-recon && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "eks-recon" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-recon into .claude/skills/eks-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-recon", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-reconType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-recon --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.kiro/skills/eks-recon .agents/skills/eks-recon && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "eks-recon" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-recon into .agents/skills/eks-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-recon", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-recon --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.kiro/skills/eks-recon .cursor/skills/eks-recon && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "eks-recon" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-recon into .cursor/skills/eks-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-recon", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws-samples/appmod-blueprints.git --path .kiro/skills/eks-recon--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-recon --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.kiro/skills/eks-recon .gemini/skills/eks-recon && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "eks-recon" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-recon into .gemini/skills/eks-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-recon", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws-samples/appmod-blueprints eks-reconInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .github/skills && cp -r skills-src/.kiro/skills/eks-recon .github/skills/eks-recon && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "eks-recon" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-recon into .github/skills/eks-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-recon", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws-samples/appmod-blueprints --skill eks-recon -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-recon --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.kiro/skills/eks-recon .opencode/skills/eks-recon && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "eks-recon" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-recon into .opencode/skills/eks-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-recon", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
eks-reconEKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.
Eks Recon is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. EKS cluster reconnaissance and environment discovery. Detects compute strategy (Karpenter, MNG, Auto Mode, Fargate), IaC tooling (Terraform, CloudFormation, CDK, eksctl), CI/CD pipelines (GitHub Actions, GitLab, ArgoCD, Flux), add-on inventory, networking, security posture, and observability. Use this skill whenever someone asks about their EKS cluster, wants to understand their setup, is planning an upgrade or migration, needs cluster context for any reason, asks what version am I running, mentions wanting to…
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `agents/addons-recon.md`, `agents/cicd-recon.md` and `agents/compute-recon.md`).
It sits in DevOps & Cloud, covering Infrastructure as code, CI/CD and Container orchestration. It works with Argo CD, AWS CloudFormation, GitHub Actions and GitLab. The licence is MIT-0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 723cdc0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awskubectlhelmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, kubectl and helm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Eks Recon loads about 4.7k tokens when it runs, and up to ~32k if it reads all its reference files. Until then it costs about 236 tokens; SKILL.md has 1,607 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
ables. AWS credentials can come from `~/.aws/credentials`, `~/.aws/config`, instance metadata, or ECS task roles — noneAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws-samples/appmod-blueprints at commit 723cdc0, republished under its MIT-0 licence (© aws-samples). 1,607 words, ~4,715 tokens.
.claude/skills/eks-recon/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.Discover everything about an EKS cluster environment. Run this skill to gather comprehensive cluster context before making any decisions, changes, or recommendations.
Run this skill when the user:
Also trigger this skill when:
Do NOT use this skill for:
eks-upgrade-check. Recon discovers what version you're on; it does NOT assess whether you're ready to move to the next version.eks-operation-review. Recon inventories what exists; it does NOT score operational maturity or produce rated assessments.eks-design. Recon discovers current state; it does NOT produce design artifacts or architectural diagrams.eks-best-practices)eks-best-practices)This skill works best with the EKS MCP Server configured. Check if MCP tools are available:
If tools like `list_eks_resources`, `describe_eks_resource`, `list_k8s_resources` are available:
-> MCP Mode: Use MCP tools (pre-authorized, richer output)
If MCP tools are NOT available:
-> CLI Mode: Fall back to AWS CLI + kubectl (requires explicit permission)MCP Mode benefits:
CLI Mode limitations:
| Tool | Required For |
|---|---|
aws CLI | Cluster-level detection (describe-cluster, list-nodegroups, list-addons) |
kubectl | K8s resource detection (deployments, CRDs, service accounts) |
helm | Helm release inventory (optional) |
401 Unauthorized on K8s API calls (list_k8s_resources, read_k8s_resource):
The MCP server can access EKS APIs (clusters, nodegroups, addons) but may lack Kubernetes API access. This happens when the MCP server's IAM role doesn't have an EKS access entry.
Solutions (choose one):
Grant MCP access: Create an EKS access entry for the MCP server's IAM role.
Surface these commands to the user — do NOT execute them. These are persistent IAM writes and violate the read-only contract of this skill.
aws eks create-access-entry \
--cluster-name <cluster> \
--region <region> \
--principal-arn <mcp-server-role-arn> \
--type STANDARD
aws eks associate-access-policy \
--cluster-name <cluster> \
--region <region> \
--principal-arn <mcp-server-role-arn> \
--policy-arn arn:aws:eks::aws:cluster-access-policy/AmazonEKSViewPolicy \
--access-scope type=clusterIf the user confirms and has permission, they can run these themselves out-of-band.
Fall back to kubectl: If user has local kubectl access, use CLI commands instead:
"MCP K8s access returned 401. I'll use kubectl instead if you have it configured locally."
Empty results from EKS API calls:
aws eks list-clusters --region <region>| Mode | When to Use | What Happens |
|---|---|---|
| Full Recon | First engagement with cluster | Runs all modules, generates complete report |
| Selective Recon | Know what you need | Run specific modules (e.g., compute + iac) |
| Targeted Query | Quick answer | "Is this cluster using Karpenter?" |
Full reconnaissance:
"Run EKS reconnaissance on cluster
my-clusterinus-west-2"
Selective reconnaissance:
"Run EKS recon but only check compute and IaC"
Targeted query:
"What IaC tool manages cluster
my-cluster?"
Load only the references needed for the user's request — this keeps context focused. references/cluster-basics.md is always loaded first by every module; it provides the shared cluster context all other modules depend on. For targeted queries, load only the matching row(s); for full recon, load all references in parallel. When uncertain, ask the user or default to full recon.
| Module | Intent / when to use | Reference file | Agent file |
|---|---|---|---|
| Cluster Basics | Always loaded first by every module (name, region, version, platform version, endpoint) | cluster-basics.md | — |
| Compute | Karpenter, nodes, scaling, Auto Mode, node groups, Fargate, self-managed | compute.md | compute-recon.md |
| Networking | VPC, ingress, CNI, service mesh, load balancer, connectivity | networking.md | networking-recon.md |
| Security | IAM, IRSA, Pod Identity, RBAC, policies, encryption, secrets, webhooks | security.md | security-recon.md |
| Add-ons | EKS-managed add-ons, Helm releases, plugins, "what's installed?" | addons.md | addons-recon.md |
| Observability | Logging, metrics, monitoring, Container Insights, Prometheus | observability.md | observability-recon.md |
| Workloads | Deployments, pods, services, ingresses, "what's running?" | workloads.md | workloads-recon.md |
| Storage | PVCs, EBS, EFS, StorageClasses, CSI drivers, volumes, snapshots | storage.md | storage-recon.md |
| IaC | Terraform, CloudFormation, CDK, eksctl, Pulumi, "how is it managed?" | iac.md | iac-recon.md |
| CI/CD | GitHub Actions, GitLab CI, Jenkins, ArgoCD, Flux, GitOps, pipelines | cicd.md | cicd-recon.md |
| Detection | MCP Tool |
|---|---|
| Cluster info | describe_eks_resource(resource_type="cluster", cluster_name="<name>") |
| Node groups | list_eks_resources(resource_type="nodegroup", cluster_name="<name>") |
| EKS add-ons | list_eks_resources(resource_type="addon", cluster_name="<name>") |
| Karpenter | list_k8s_resources(cluster_name="<name>", kind="NodePool", api_version="karpenter.sh/v1") |
| Deployments | list_k8s_resources(cluster_name="<name>", kind="Deployment", api_version="apps/v1") |
| VPC config | get_eks_vpc_config(cluster_name="<name>") |
| Insights | get_eks_insights(cluster_name="<name>") |
| Detection | CLI Command |
|---|---|
| Cluster info | aws eks describe-cluster --name <name> --region <region> |
| Node groups | aws eks list-nodegroups --cluster-name <name> --region <region> |
| EKS add-ons | aws eks list-addons --cluster-name <name> --region <region> |
| Fargate profiles | aws eks list-fargate-profiles --cluster-name <name> --region <region> |
| Auto Mode | aws eks describe-cluster --name <name> --region <region> --query 'cluster.computeConfig' |
| Karpenter | kubectl get nodepools.karpenter.sh 2>/dev/null |
| Helm releases | helm list -A |
IMPORTANT: Load Reference Files
Before running each module, you MUST read its reference file (e.g.,
references/compute.md). References contain:
- Detection order and rationale (why check Auto Mode before Karpenter)
- Edge cases and how to handle them
- CLI fallback commands when MCP fails
- Output schema for structured reporting
Skipping references produces shallow results. The main skill provides orchestration; the references provide detection intelligence.
Required:
- Cluster name (or auto-discover — see below)
- AWS region (or detect from context/kubeconfig/CLI)
Optional:
- Specific modules to run (default: all)
- Output file path (default: .eks-recon-report.yaml)Auto-discovery when cluster name is not explicit:
When the user says "my cluster", "current cluster", or does not name a specific cluster, discover it:
kubectl config current-context — if set, extract cluster name from the context ARN~/.aws/ config files, instance profile, or env vars — don't assume env vars are the only source):aws sts get-caller-identity # verify we have working AWS access
aws eks list-clusters --region ${AWS_DEFAULT_REGION:-us-west-2}IMPORTANT: Never give up after checking only environment variables. AWS credentials can come from ~/.aws/credentials, ~/.aws/config, instance metadata, or ECS task roles — none of which appear in env | grep AWS_. Always try aws sts get-caller-identity before concluding credentials are unavailable.
If MCP tools are available, use them. Otherwise, inform the user:
"EKS MCP Server not detected. I'll use CLI commands instead, which will require your permission for each command. For a smoother experience, consider setting up the EKS MCP Server."
Determine which modules to run based on user intent (see Modules and Reference Loading).
For each selected module:
references/compute.md) - REQUIREDWrite report to .eks-recon-report.yaml and present summary:
# EKS Reconnaissance Report
# Generated: 2026-04-22T14:30:00Z
# Cluster: my-cluster
# Region: us-west-2
# Modules: cluster-basics, compute, iac, cicd, addons
cluster:
name: my-cluster
region: us-west-2
version: "1.31"
platform_version: eks.5
endpoint: https://<cluster-id>.gr7.us-west-2.eks.amazonaws.com
arn: arn:aws:eks:us-west-2:<account-id>:cluster/my-cluster
status: ACTIVE
created_at: "2024-09-10T12:00:00Z"
compute:
strategy: Karpenter
auto_mode:
enabled: false
karpenter:
detected: true
version: "1.0.5"
nodepools: 2
nodepool_names: [default, gpu]
mng:
detected: true
count: 1
groups:
- name: system
status: ACTIVE
instance_types: [m6i.large]
desired_size: 2
fargate:
detected: false
profiles: 0
self_managed:
detected: false
node_count: 0
iac:
tool: Terraform
confidence: high
evidence:
type: workspace_files
details: "./infrastructure/eks/main.tf contains aws_eks_cluster"
cicd:
workspace:
github_actions:
detected: true
workflows: [.github/workflows/deploy.yml]
gitlab_ci:
detected: false
jenkins:
detected: false
jenkinsfile: false
other: null
gitops:
argocd:
detected: true
namespace: argocd
applications: 12
app_projects: 3
flux:
detected: false
namespace: null
kustomizations: 0
helm_releases: 0
git_repositories: 0
addons:
eks_managed:
count: 2
list:
- name: vpc-cni
version: v1.18.1-eksbuild.1
status: ACTIVE
configuration: null
- name: coredns
version: v1.11.1-eksbuild.8
status: ACTIVE
configuration: null
helm_releases:
count: 1
list:
- name: karpenter
namespace: kube-system
chart: karpenter
version: 1.0.5
status: deployedWhen running full reconnaissance, delegate each module to a specialized subagent. This keeps each module's context isolated and enables true parallel execution.
| Scenario | Mode | Reason |
|---|---|---|
| Any recon (1+ modules) | USE subagents | Isolated context, cleaner main conversation |
| No Agent tool available | Inline | Subagents not supported |
IMPORTANT: If the Agent tool is available, you MUST use subagent mode for ALL reconnaissance — even single-module targeted queries. Subagents keep detection context isolated from the main conversation. Do not fall back to inline mode just because "it's only one module" or "MCP tools work" — always delegate to subagents.
Each module has a corresponding subagent prompt in agents/:
| Subagent | File | Purpose |
|---|---|---|
| Compute | agents/compute-recon.md | Detect compute strategy |
| Networking | agents/networking-recon.md | Detect network config |
| Security | agents/security-recon.md | Detect security posture, secrets, webhooks |
| Add-ons | agents/addons-recon.md | Detect installed components |
| Observability | agents/observability-recon.md | Detect monitoring/logging |
| Storage | agents/storage-recon.md | Detect CSI, StorageClasses, PVCs |
| Workloads | agents/workloads-recon.md | Detect running workloads |
| IaC | agents/iac-recon.md | Detect IaC tooling |
| CI/CD | agents/cicd-recon.md | Detect deployment pipelines |
Step 1: Check subagent availability
If Agent tool is available:
→ MUST use subagent mode for ALL recon (full or targeted)
→ Even single-module queries use subagents to isolate context
Else:
→ Use inline mode (load references directly)Step 2: Spawn module subagents in parallel
Spawn ALL module subagents in a SINGLE message for parallel execution:
Agent(
description: "EKS compute recon",
prompt: "Recon compute for cluster {cluster_name} in {region}.
Read agents/compute-recon.md and references/compute.md.
Return YAML output only.",
subagent_type: "general-purpose"
)
Agent(
description: "EKS networking recon",
prompt: "Recon networking for cluster {cluster_name} in {region}.
Read agents/networking-recon.md and references/networking.md.
Return YAML output only.",
subagent_type: "general-purpose"
)
... (spawn all 9 in parallel)Step 3: Aggregate results
When all subagents complete:
cluster: block. Merge into a single top-level cluster: by deduplicating exact-match blocks (all subagents report the same cluster); if any field mismatches across subagents, flag it rather than silently picking one.compute:, iac:, cicd:, addons:, networking:, observability:, security:, storage:, workloads:. Do not reshape, flatten, or rename keys.unavailable: true with a short reason: string; do not omit the key..eks-recon-report.yamlThe upgrade workflow can invoke eks-recon to gather Phase 1 context:
1. Run eks-recon modules: cluster-basics, compute, iac, addons
2. Extract:
- cluster.version -> Current version
- compute.strategy -> Determines upgrade approach
- iac.tool -> Terraform vs CLI upgrade path
- addons -> Compatibility matrix inputThe design workflow can use eks-recon for existing clusters:
1. Run eks-recon modules: all
2. Pre-populate questionnaire from detected values
3. Ask user: "I detected Karpenter + Terraform + ArgoCD. Correct?"
4. Only ask questions for undetected values© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 19 other files (references) in .kiro/skills/eks-recon of aws-samples/appmod-blueprints.
Open the folder on GitHubat commit 723cdc0
Eks Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Eks Recon this skillaws-samples/appmod-blueprints | 113 | — | ~4.7k | Automated safety check: Warn | MIT-0 | |
| Devops Automatorcuriositech/some_claude_skills | 243 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Infrastructure Devops Devops Engineerchendongqi/OPB-Skills | 125 | — | ~1.4k | Automated safety check: Pass | None | |
| Tirith PoliciesStackGuardian/tirith | 167 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Devops InfrastructureCloudAI-X/claude-workflow-v2 | 1.4k | — | ~2.7k | Automated safety check: Notes | MIT | |
| Cloud Devopsdavila7/claude-code-templates | 32k | 4 repos | ~1.4k | Automated safety check: Pass | MIT |
curiositech/some_claude_skills
Expert DevOps engineer for CI/CD, IaC, Kubernetes, and deployment automation.
chendongqi/OPB-Skills
DevOps助手 - 专业的DevOps实践与自动化专家。适用场景: (1) CI/CD流水线设计与实现 (2) 部署策略与发布管理 (3) 基础设施即代码(IaC) (4) 容器化与Kubernetes部署 (5) 监控告警与可观测性 (6) DevOps工具链选型 (7) DevOps文化与实践推广 触发关键词:DevOps、CI/CD、持续集成、持续部署、Jenkins、GitLab…
StackGuardian/tirith
Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…
CloudAI-X/claude-workflow-v2
Guides Docker, CI/CD pipelines, deployment strategies, infrastructure as code, and observability setup.
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
davila7/claude-code-templates
Implements infrastructure as code using Terraform, Kubernetes, and cloud platforms.
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
aws-samples/appmod-blueprints
Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.
aws-samples/appmod-blueprints
Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.
aws-samples/appmod-blueprints
Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…
aws-samples/appmod-blueprints
A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
Categories
EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints. Eks Recon is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. EKS cluster reconnaissance and environment discovery.
Eks Recon fits situations like: someone asks about their EKS cluster; wants to understand their setup; is planning an upgrade; needs cluster context for any reason.
Run `npx skills add aws-samples/appmod-blueprints --skill eks-recon -a claude-code`. Or copy the skill folder (.kiro/skills/eks-recon in aws-samples/appmod-blueprints) into .claude/skills/eks-recon in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws-samples/appmod-blueprints --skill eks-recon -a codex`. Or copy the skill folder (.kiro/skills/eks-recon in aws-samples/appmod-blueprints) into .agents/skills/eks-recon in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-recon, .gemini/skills/eks-recon, .github/skills/eks-recon and .opencode/skills/eks-recon in your project.
Going by SKILL.md and its folder, Eks Recon needs the command-line tools its instructions call (aws, kubectl and helm).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Eks Recon is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 27k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Eks Recon: Devops Automator (curiositech/some_claude_skills, 243 stars), Infrastructure Devops Devops Engineer (chendongqi/OPB-Skills, 125 stars), Tirith Policies (StackGuardian/tirith, 167 stars) and Devops Infrastructure (CloudAI-X/claude-workflow-v2, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.
Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.