Official agent skill

Eks Upgrade Check

by aws-samples in aws-samples/appmod-blueprints

Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…

OfficialMITAuto-check: warningsDevOps & Cloud

Install Eks Upgrade Check

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .claude/skills/eks-upgrade-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eks-upgrade-check
GitHub stars
113
Token cost
~2.4k tokens
SKILL.md length
1,106 words
Files
14 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…

  • Works in 2 steps: Pre-flight → Calculate Score & Generate Report
  • Someone asks can I upgrade my cluster?
  • SKILL.md covers Overview, What Gets Assessed, Readiness Score and Prerequisites, plus 4 more sections
  • Runs Python scripts from its folder; calls aws and python3

What it does

Eks Upgrade Check is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade plan), calculate a 0-100 readiness score with a hard-blocker override, and generate a markdown/HTML report with prioritized remediation. Use this skill whenever someone asks "can I upgrade my cluster?", "is my cluster ready for 1.32?", "are we good to go to 1.33?", "what is blocking my upgrade?", or "should we move to…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including reference files (for example `UPSTREAM.md`, `data/oss_addon_registry.json` and `references/addon-compatibility.md`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Amazon Web Services, Model Context Protocol and Kubernetes. The licence is MIT.

When your agent uses it

  • Someone asks can I upgrade my cluster?
  • Is my cluster ready for 1.32?
  • Are we good to go to 1.33?
  • What is blocking my upgrade?

Example prompts

  • “can I upgrade my cluster?”
  • “is my cluster ready for 1.32?”
  • “are we good to go to 1.33?”
  • “/eks-upgrade-check”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, WebFetch, WebSearch

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Pre-flight
  2. Calculate Score & Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 723cdc0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • WebFetch
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eks Upgrade Check loads about 2.4k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 169 tokens; SKILL.md has 1,106 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~169
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~20k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:57
    ls configured** — `aws configure` or `~/.aws/credentials` with EKS access
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, WebFetch, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/appmod-blueprints at commit 723cdc0, republished under its MIT licence (© aws-samples). 1,106 words, ~2,396 tokens.

Download SKILL.mdSave it as .claude/skills/eks-upgrade-check/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
eks-upgrade-check
description
Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade plan), calculate a 0-100 readiness score with a hard-blocker override, and generate a markdown/HTML report with prioritized remediation. Use this skill whenever someone asks "can I upgrade my cluster?", "is my cluster ready for 1.32?", "are we good to go to 1.33?", "what is blocking my upgrade?", or "should we move to the next version?" — even if they do not say "readiness" or "score". Falls back to AWS CLI and kubectl when the EKS MCP server is unavailable.
allowed-tools
Bash, Read, Write, Grep, Glob, WebFetch, WebSearch

EKS Upgrade Readiness Skill

Overview

This skill assesses your live EKS cluster's readiness for a Kubernetes version upgrade. It connects to your cluster via AWS CLI and kubectl, runs automated checks across 8 assessment areas, calculates a readiness score (0-100%), and produces a detailed report with prioritized remediation steps and pre-filled AWS CLI commands.

This skill is laser-focused on upgrade safety — answering the question: "Is it safe to upgrade this cluster to the next version?"

What Gets Assessed

#SectionKey Checks
01Version ValidationUpgrade path validity, version skew policy, support status
02Breaking ChangesVersion-specific API removals, behavioral changes, resource impact
03Deprecated API DetectionLive scan of cluster resources for deprecated/removed APIs
04Add-on CompatibilityCore add-on versions, OSS add-on matrix, Karpenter compatibility
05Node ReadinessNode version skew, AL2→AL2023 migration, AMI compatibility
06Workload RisksSingle replicas, missing PDBs, health probes, resource requests
07AWS Upgrade InsightsOfficial EKS pre-upgrade checks and recommendations
08Upgrade PlanPre-filled CLI commands, step-by-step upgrade sequence

Readiness Score

The skill calculates a weighted readiness score:

CategoryMax DeductionRationale
Breaking Changes25 ptsHighest risk — can break apps
Deprecated APIs20 ptsActionable, fixable pre-upgrade
Node Readiness (skew + subnet IPs)20 ptsCan block upgrade entirely
Unsupported Version15 ptsNo security patches, urgent upgrade needed
Add-on Compatibility15 ptsCritical > optional add-ons
Karpenter10 ptsOnly if installed
Workload Risks10 ptsBest-practice, not blockers
AWS Upgrade Insights10 ptsOfficial AWS checks
AL2 Nodes / Behavioral10 ptsInformational

Hard Blocker Override: If any hard blocker is detected (e.g., incompatible Karpenter, critical add-on DEGRADED, subnet IPs < 5, cluster not ACTIVE), the score is capped at ≤ 59% (NOT READY) regardless of other findings. See references/report-generation.md for the full list.

Score Interpretation:

  • 90-100: READY — Safe to proceed
  • 80-89: GOOD — Minor issues, can proceed with caution
  • 70-79: FAIR — Several issues need attention first
  • 60-69: RISKY — Significant issues, not recommended yet
  • 0-59: NOT READY — Critical blockers, must resolve first

Prerequisites

  1. AWS credentials configured — aws configure or ~/.aws/credentials with EKS access
  2. kubectl access to the target cluster (for Kubernetes API queries)
  3. Required AWS Permissions:
    • eks:DescribeCluster, eks:ListClusters, eks:ListNodegroups, eks:DescribeNodegroup
    • eks:ListAddons, eks:DescribeAddon, eks:ListInsights, eks:DescribeInsight
    • ec2:DescribeSubnets
    • iam:GetRole, iam:ListAttachedRolePolicies, iam:ListRolePolicies, iam:GetRolePolicy
MCP Server Setup

This skill works without any MCP server — it falls back to AWS CLI and kubectl commands. That fallback path is the default in apex.

For richer EKS operations (live cluster reads, upgrade insights, K8s resource introspection), enable the EKS MCP server via the apex eks-mcp-server skill — it walks you through both AWS-hosted and self-hosted setup options. Once configured, this skill will prefer MCP tools over CLI for EKS operations.

Note: Apex does NOT ship a project-root .mcp.json. MCP setup is opt-in and user-driven through the eks-mcp-server skill.

Configuration

The skill uses your existing AWS credentials. No additional configuration needed if aws eks list-clusters works from your terminal.

To use a specific profile or region, set environment variables:

bash
export AWS_PROFILE=your-profile-name
export AWS_REGION=your-region
Getting Started

Invoke the skill: /eks-upgrade-check

Or simply ask: "Run an EKS upgrade readiness assessment"

The skill will discover your clusters, ask which one to assess and what target version, then run the full assessment.


Assessment Workflow

Show full SKILL.md (584 more words)Show less
Step 0: Pre-flight

Action 1 — List clusters (test connectivity & discover clusters)

Run aws eks list-clusters to discover available clusters.

  • ✅ Success → Show the cluster list. Ask which cluster to assess. If only one cluster, confirm it.
  • ❌ Failure → STOP. Do NOT retry more than once. Show:

Cannot access EKS clusters. Try these steps:

  1. Check that AWS credentials are configured: aws sts get-caller-identity
  2. Check your region: aws eks list-clusters --region <region>
  3. Check that MCP servers are enabled in Claude Code

Wait for the user to resolve the issue.

Action 2 — Describe the selected cluster

Run aws eks describe-cluster --name <cluster> and show: cluster name, Kubernetes version, platform version, region, status, account ID.

Action 2b — Validate cluster status

Check the status field from the cluster description. If status is NOT ACTIVE:

  • CREATING/UPDATING/DELETING → STOP. Show: "Cluster is currently in <status> state. The EKS API will reject an upgrade request. Wait for the operation to complete, then re-run this assessment."
  • FAILED → STOP. Show: "Cluster is in FAILED state. This is a hard blocker — the cluster must be recovered before an upgrade can be attempted. Contact AWS Support if the cluster is stuck in FAILED."

Do NOT proceed with the assessment if cluster status is not ACTIVE. This is a hard blocker (see report-generation.md).

Action 3 — Validate permissions

After describing the cluster, verify key permissions by attempting:

  1. aws eks list-nodegroups --cluster-name <cluster>
  2. aws eks list-addons --cluster-name <cluster>
  3. aws eks list-insights --cluster-name <cluster>

If any fail with AccessDenied, show the user exactly which permission is missing and list the required IAM actions. Do NOT proceed until permissions are confirmed.

Action 4 — Determine target version

Ask: "Your cluster is on v[current]. The next version is v[current+1]. Shall I assess upgrade readiness to v[current+1]?"

If the user specifies a version more than 1 minor version ahead, explain that EKS requires one-version-at-a-time upgrades and show the required path (e.g., 1.29 → 1.30 → 1.31 → 1.32). Offer to assess the first hop.

Action 5 — Confirm and proceed

Steps 1-8: Run Assessment

Read each steering file in order from ${CLAUDE_SKILL_DIR}/references/. For each section:

  1. Read the steering file
  2. Execute the checks described in it using AWS CLI and kubectl commands
  3. Collect findings with severity ratings

Steering file loading guide:

User RequestSteering File(s)
Full upgrade assessmentALL files in order
Version / upgrade pathreferences/version-validation.md
Breaking changes / API removalsreferences/breaking-changes.md
Deprecated APIsreferences/deprecated-apis.md
Add-on compatibility / Karpenterreferences/addon-compatibility.md
Node readiness / AL2 / AMIreferences/node-readiness.md
Workload risks / PDB / probesreferences/workload-risks.md
AWS Insightsreferences/upgrade-insights.md
Generate reportreferences/report-generation.md
Step 9: Calculate Score & Generate Report

Read ${CLAUDE_SKILL_DIR}/references/report-generation.md and produce the report.


Tool Usage Rules

  1. Do NOT call any tools when this skill is first activated. Wait for the user to ask.
  2. Do NOT hardcode or guess cluster names. Always discover by listing first.
  3. Do NOT retry a failed command more than once.
  4. Always read the relevant steering file before executing checks for that section.
  5. Use aws CLI and kubectl for cluster queries. If MCP servers are available, prefer them for EKS operations.

Data Files

  • OSS Add-on Registry: ${CLAUDE_SKILL_DIR}/data/oss_addon_registry.json — identifiers and authoritative upstream URLs for common OSS add-ons. This file does NOT contain compatibility data. Compatibility is always verified live via the registry's compatibility_url and releases_url fields. If an add-on is not in the registry or the upstream source is unreachable, report UNKNOWN — never guess.
  • HTML Converter: ${CLAUDE_SKILL_DIR}/tools/md_to_html.py — converts markdown reports to HTML

Report Output

  • Markdown: EKS-Upgrade-Assessment-<cluster>-<version>-<YYYY-MM-DD>-<HHMM>.md
  • HTML: Run python3 ${CLAUDE_SKILL_DIR}/tools/md_to_html.py <report>.md to convert

Do NOT generate HTML manually. Always use the conversion script.

© aws-samples, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references) in .kiro/skills/eks-upgrade-check of aws-samples/appmod-blueprints.

  • SKILL.md
  • .vendor-sha
  • LICENSE
  • UPSTREAM.md
  • data/oss_addon_registry.json
  • references/addon-compatibility.md
  • references/breaking-changes.md
  • references/deprecated-apis.md
  • references/node-readiness.md
  • references/report-generation.md
  • references/upgrade-insights.md
  • references/version-validation.md
  • references/workload-risks.md
  • tools/md_to_html.py

Open the folder on GitHubat commit 723cdc0

Compare with similar skills

Eks Upgrade Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eks Upgrade Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eks Upgrade Check this skillaws-samples/appmod-blueprints113—~2.4kAutomated safety check: WarnMIT
Ksaildevantler-tech/ksail166—~1.1kAutomated safety check: PassCustom licence
AWS Containersaws/agent-toolkit-for-aws2.8k—~1.7kAutomated safety check: PassApache-2.0
Create Connectorharness/harness-skills115—~2kAutomated safety check: PassApache-2.0
K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox4.2k—~1.3kAutomated safety check: PassApache-2.0
Fieldflow CLIguillaumegay13/fieldflow110—~872Automated safety check: PassMIT

Similar skills

  • Ksail

    devantler-tech/ksail

    Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.

    166 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Containers

    aws/agent-toolkit-for-aws

    Official

    Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).

    2.8k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Create Connector

    harness/harness-skills

    Generate Harness Connector YAML for integrations and create/test via MCP.

    115 GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • K8s Agent Sandbox MCP

    kubernetes-sigs/agent-sandbox

    Official

    An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.

    4.2k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Fieldflow CLI

    guillaumegay13/fieldflow

    Use FieldFlow to inspect and reduce noisy JSON CLI output before it reaches model context.

    110 GitHub stars~872 tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Kubestellar Console

    sickn33/agentic-awesome-skills

    Multi-cluster Kubernetes dashboard with AI-powered operations via MCP server and 10+ built-in agent skills

    47k GitHub starsUsed in 1 repo~1.2k tokens
    DevOps & CloudAuto-check passed

More from aws-samples/appmod-blueprints

All 9 skills in this repo
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    113 GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Troubleshoot Platform

    aws-samples/appmod-blueprints

    Official

    Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.

    113 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Eks Recon

    aws-samples/appmod-blueprints

    Official

    EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.

    113 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check: warnings
  • Troubleshoot Kro

    aws-samples/appmod-blueprints

    Official

    Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

    113 GitHub stars~986 tokensUpdated yesterday
    Auto-check passed
  • Eks Platform Engineering

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…

    113 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed

Questions about Eks Upgrade Check

What does Eks Upgrade Check do?

Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…. Eks Upgrade Check is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade plan), calculate a 0-100 readiness score with a hard-blocker override, and generate a markdown/HTML report with prioritized remediation.

When should I use Eks Upgrade Check?

Eks Upgrade Check fits situations like: someone asks can I upgrade my cluster?; is my cluster ready for 1.32?; are we good to go to 1.33?; what is blocking my upgrade?.

How do I install Eks Upgrade Check in Claude Code?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a claude-code`. Or copy the skill folder (.kiro/skills/eks-upgrade-check in aws-samples/appmod-blueprints) into .claude/skills/eks-upgrade-check in your project. Claude Code loads it when a task matches its description.

How do I install Eks Upgrade Check in Codex?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a codex`. Or copy the skill folder (.kiro/skills/eks-upgrade-check in aws-samples/appmod-blueprints) into .agents/skills/eks-upgrade-check in your project. Codex loads it when a task matches its description.

Can I use Eks Upgrade Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-upgrade-check, .gemini/skills/eks-upgrade-check, .github/skills/eks-upgrade-check and .opencode/skills/eks-upgrade-check in your project.

What does Eks Upgrade Check need to run?

Going by SKILL.md and its folder, Eks Upgrade Check needs Python for the scripts in its folder and the command-line tools its instructions call (aws and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebFetch, WebSearch.

Does Eks Upgrade Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Eks Upgrade Check safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Eks Upgrade Check use?

Eks Upgrade Check is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eks Upgrade Check use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Eks Upgrade Check?

Skills that share tags, products or a category with Eks Upgrade Check: Ksail (devantler-tech/ksail, 166 stars), AWS Containers (aws/agent-toolkit-for-aws, 2.8k stars), Create Connector (harness/harness-skills, 115 stars) and K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eks Upgrade Check?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.

Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.