Ksail
devantler-tech/ksail
Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.
Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .claude/skills/eks-upgrade-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "eks-upgrade-check" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-check into .claude/skills/eks-upgrade-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-upgrade-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .agents/skills/eks-upgrade-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "eks-upgrade-check" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-check into .agents/skills/eks-upgrade-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-upgrade-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .cursor/skills/eks-upgrade-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "eks-upgrade-check" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-check into .cursor/skills/eks-upgrade-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-upgrade-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws-samples/appmod-blueprints.git --path .kiro/skills/eks-upgrade-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .gemini/skills/eks-upgrade-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "eks-upgrade-check" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-check into .gemini/skills/eks-upgrade-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-upgrade-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .github/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .github/skills/eks-upgrade-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "eks-upgrade-check" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-check into .github/skills/eks-upgrade-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-upgrade-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-upgrade-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.kiro/skills/eks-upgrade-check .opencode/skills/eks-upgrade-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "eks-upgrade-check" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-upgrade-check into .opencode/skills/eks-upgrade-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-upgrade-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
eks-upgrade-checkAssess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…
Eks Upgrade Check is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade plan), calculate a 0-100 readiness score with a hard-blocker override, and generate a markdown/HTML report with prioritized remediation. Use this skill whenever someone asks "can I upgrade my cluster?", "is my cluster ready for 1.32?", "are we good to go to 1.33?", "what is blocking my upgrade?", or "should we move to…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including reference files (for example `UPSTREAM.md`, `data/oss_addon_registry.json` and `references/addon-compatibility.md`).
It sits in DevOps & Cloud, covering Container orchestration. It works with Amazon Web Services, Model Context Protocol and Kubernetes. The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 723cdc0. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteGrepGlobWebFetchWebSearchFrom allowed-tools in the SKILL.md frontmatter.
Ships script files (Python), which the agent can run.
Shell commands in SKILL.md call:
awspython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Eks Upgrade Check loads about 2.4k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 169 tokens; SKILL.md has 1,106 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
ls configured** — `aws configure` or `~/.aws/credentials` with EKS accessallowed-tools: Bash, Read, Write, Grep, Glob, WebFetch, WebSearchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws-samples/appmod-blueprints at commit 723cdc0, republished under its MIT licence (© aws-samples). 1,106 words, ~2,396 tokens.
.claude/skills/eks-upgrade-check/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.This skill assesses your live EKS cluster's readiness for a Kubernetes version upgrade. It connects to your cluster via AWS CLI and kubectl, runs automated checks across 8 assessment areas, calculates a readiness score (0-100%), and produces a detailed report with prioritized remediation steps and pre-filled AWS CLI commands.
This skill is laser-focused on upgrade safety — answering the question: "Is it safe to upgrade this cluster to the next version?"
| # | Section | Key Checks |
|---|---|---|
| 01 | Version Validation | Upgrade path validity, version skew policy, support status |
| 02 | Breaking Changes | Version-specific API removals, behavioral changes, resource impact |
| 03 | Deprecated API Detection | Live scan of cluster resources for deprecated/removed APIs |
| 04 | Add-on Compatibility | Core add-on versions, OSS add-on matrix, Karpenter compatibility |
| 05 | Node Readiness | Node version skew, AL2→AL2023 migration, AMI compatibility |
| 06 | Workload Risks | Single replicas, missing PDBs, health probes, resource requests |
| 07 | AWS Upgrade Insights | Official EKS pre-upgrade checks and recommendations |
| 08 | Upgrade Plan | Pre-filled CLI commands, step-by-step upgrade sequence |
The skill calculates a weighted readiness score:
| Category | Max Deduction | Rationale |
|---|---|---|
| Breaking Changes | 25 pts | Highest risk — can break apps |
| Deprecated APIs | 20 pts | Actionable, fixable pre-upgrade |
| Node Readiness (skew + subnet IPs) | 20 pts | Can block upgrade entirely |
| Unsupported Version | 15 pts | No security patches, urgent upgrade needed |
| Add-on Compatibility | 15 pts | Critical > optional add-ons |
| Karpenter | 10 pts | Only if installed |
| Workload Risks | 10 pts | Best-practice, not blockers |
| AWS Upgrade Insights | 10 pts | Official AWS checks |
| AL2 Nodes / Behavioral | 10 pts | Informational |
Hard Blocker Override: If any hard blocker is detected (e.g., incompatible Karpenter, critical
add-on DEGRADED, subnet IPs < 5, cluster not ACTIVE), the score is capped at ≤ 59% (NOT READY)
regardless of other findings. See references/report-generation.md for the full list.
Score Interpretation:
aws configure or ~/.aws/credentials with EKS accesseks:DescribeCluster, eks:ListClusters, eks:ListNodegroups, eks:DescribeNodegroupeks:ListAddons, eks:DescribeAddon, eks:ListInsights, eks:DescribeInsightec2:DescribeSubnetsiam:GetRole, iam:ListAttachedRolePolicies, iam:ListRolePolicies, iam:GetRolePolicyThis skill works without any MCP server — it falls back to AWS CLI and kubectl commands. That fallback path is the default in apex.
For richer EKS operations (live cluster reads, upgrade insights, K8s resource introspection), enable the EKS MCP server via the apex eks-mcp-server skill — it walks you through both AWS-hosted and self-hosted setup options. Once configured, this skill will prefer MCP tools over CLI for EKS operations.
Note: Apex does NOT ship a project-root .mcp.json. MCP setup is opt-in and user-driven through the eks-mcp-server skill.
The skill uses your existing AWS credentials. No additional configuration needed if aws eks list-clusters works from your terminal.
To use a specific profile or region, set environment variables:
export AWS_PROFILE=your-profile-name
export AWS_REGION=your-regionInvoke the skill: /eks-upgrade-check
Or simply ask: "Run an EKS upgrade readiness assessment"
The skill will discover your clusters, ask which one to assess and what target version, then run the full assessment.
Action 1 — List clusters (test connectivity & discover clusters)
Run aws eks list-clusters to discover available clusters.
Cannot access EKS clusters. Try these steps:
- Check that AWS credentials are configured:
aws sts get-caller-identity- Check your region:
aws eks list-clusters --region <region>- Check that MCP servers are enabled in Claude Code
Wait for the user to resolve the issue.
Action 2 — Describe the selected cluster
Run aws eks describe-cluster --name <cluster> and show: cluster name, Kubernetes version, platform version, region, status, account ID.
Action 2b — Validate cluster status
Check the status field from the cluster description. If status is NOT ACTIVE:
<status> state. The EKS API will reject an upgrade request. Wait for the operation to complete, then re-run this assessment."Do NOT proceed with the assessment if cluster status is not ACTIVE. This is a hard blocker (see report-generation.md).
Action 3 — Validate permissions
After describing the cluster, verify key permissions by attempting:
aws eks list-nodegroups --cluster-name <cluster>aws eks list-addons --cluster-name <cluster>aws eks list-insights --cluster-name <cluster>If any fail with AccessDenied, show the user exactly which permission is missing and list the required IAM actions. Do NOT proceed until permissions are confirmed.
Action 4 — Determine target version
Ask: "Your cluster is on v[current]. The next version is v[current+1]. Shall I assess upgrade readiness to v[current+1]?"
If the user specifies a version more than 1 minor version ahead, explain that EKS requires one-version-at-a-time upgrades and show the required path (e.g., 1.29 → 1.30 → 1.31 → 1.32). Offer to assess the first hop.
Action 5 — Confirm and proceed
Read each steering file in order from ${CLAUDE_SKILL_DIR}/references/. For each section:
Steering file loading guide:
| User Request | Steering File(s) |
|---|---|
| Full upgrade assessment | ALL files in order |
| Version / upgrade path | references/version-validation.md |
| Breaking changes / API removals | references/breaking-changes.md |
| Deprecated APIs | references/deprecated-apis.md |
| Add-on compatibility / Karpenter | references/addon-compatibility.md |
| Node readiness / AL2 / AMI | references/node-readiness.md |
| Workload risks / PDB / probes | references/workload-risks.md |
| AWS Insights | references/upgrade-insights.md |
| Generate report | references/report-generation.md |
Read ${CLAUDE_SKILL_DIR}/references/report-generation.md and produce the report.
aws CLI and kubectl for cluster queries. If MCP servers are available, prefer them for EKS operations.${CLAUDE_SKILL_DIR}/data/oss_addon_registry.json — identifiers and authoritative upstream URLs for common OSS add-ons. This file does NOT contain compatibility data. Compatibility is always verified live via the registry's compatibility_url and releases_url fields. If an add-on is not in the registry or the upstream source is unreachable, report UNKNOWN — never guess.${CLAUDE_SKILL_DIR}/tools/md_to_html.py — converts markdown reports to HTMLEKS-Upgrade-Assessment-<cluster>-<version>-<YYYY-MM-DD>-<HHMM>.mdpython3 ${CLAUDE_SKILL_DIR}/tools/md_to_html.py <report>.md to convertDo NOT generate HTML manually. Always use the conversion script.
© aws-samples, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (references) in .kiro/skills/eks-upgrade-check of aws-samples/appmod-blueprints.
Open the folder on GitHubat commit 723cdc0
Eks Upgrade Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Eks Upgrade Check this skillaws-samples/appmod-blueprints | 113 | — | ~2.4k | Automated safety check: Warn | MIT | |
| Ksaildevantler-tech/ksail | 166 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| AWS Containersaws/agent-toolkit-for-aws | 2.8k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Create Connectorharness/harness-skills | 115 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox | 4.2k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Fieldflow CLIguillaumegay13/fieldflow | 110 | — | ~872 | Automated safety check: Pass | MIT |
devantler-tech/ksail
Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.
aws/agent-toolkit-for-aws
Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).
harness/harness-skills
Generate Harness Connector YAML for integrations and create/test via MCP.
kubernetes-sigs/agent-sandbox
An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.
guillaumegay13/fieldflow
Use FieldFlow to inspect and reduce noisy JSON CLI output before it reaches model context.
sickn33/agentic-awesome-skills
Multi-cluster Kubernetes dashboard with AI-powered operations via MCP server and 10+ built-in agent skills
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
aws-samples/appmod-blueprints
Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.
aws-samples/appmod-blueprints
EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.
aws-samples/appmod-blueprints
Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.
aws-samples/appmod-blueprints
A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
Categories
Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…. Eks Upgrade Check is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade plan), calculate a 0-100 readiness score with a hard-blocker override, and generate a markdown/HTML report with prioritized remediation.
Eks Upgrade Check fits situations like: someone asks can I upgrade my cluster?; is my cluster ready for 1.32?; are we good to go to 1.33?; what is blocking my upgrade?.
Run `npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a claude-code`. Or copy the skill folder (.kiro/skills/eks-upgrade-check in aws-samples/appmod-blueprints) into .claude/skills/eks-upgrade-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a codex`. Or copy the skill folder (.kiro/skills/eks-upgrade-check in aws-samples/appmod-blueprints) into .agents/skills/eks-upgrade-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-upgrade-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-upgrade-check, .gemini/skills/eks-upgrade-check, .github/skills/eks-upgrade-check and .opencode/skills/eks-upgrade-check in your project.
Going by SKILL.md and its folder, Eks Upgrade Check needs Python for the scripts in its folder and the command-line tools its instructions call (aws and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebFetch, WebSearch.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Eks Upgrade Check is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Eks Upgrade Check: Ksail (devantler-tech/ksail, 166 stars), AWS Containers (aws/agent-toolkit-for-aws, 2.8k stars), Create Connector (harness/harness-skills, 115 stars) and K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.
Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.