Official agent skill

Troubleshoot Kro

by aws-samples in aws-samples/appmod-blueprints

Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

OfficialMIT-0Auto-check passedDevOps & Cloud

Install Troubleshoot Kro

skills CLI
$ npx skills add aws-samples/appmod-blueprints --skill troubleshoot-kro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/appmod-blueprints troubleshoot-kro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/troubleshoot-kro .claude/skills/troubleshoot-kro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
troubleshoot-kro
GitHub stars
115
Token cost
~986 tokens
SKILL.md length
309 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT-0

At a glance

Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

  • Works in 6 steps: Check Instance Status → Identify ACK Resources → Diagnose Common Failures → …
  • A Kro instance is stuck INPROGRESS
  • SKILL.md covers Overview, Parameters and Workflow
  • Calls kubectl and aws

What it does

Troubleshoot Kro is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts. Use when a Kro instance is stuck INPROGRESS, ACK resources fail to sync, or RGD dependency chains are broken. Do NOT use for general platform troubleshooting — use troubleshoot-platform instead.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Amazon Web Services and Kubernetes. The licence is MIT-0.

When your agent uses it

  • A Kro instance is stuck INPROGRESS
  • ACK resources fail to sync
  • RGD dependency chains are broken
  • General platform troubleshooting — use troubleshoot-platform instead

Example prompts

  • “/troubleshoot-kro”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Check Instance Status
  2. Identify ACK Resources
  3. Diagnose Common Failures
  4. Fix IAM Trust Policy Issues
  5. Clean Up Conflicting Resources
  6. Force Reconciliation

What it can do on your machine

Read from SKILL.md and the folder at commit 42ea29c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl and aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Troubleshoot Kro loads about 986 tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~986

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/appmod-blueprints at commit 42ea29c, republished under its MIT-0 licence (© aws-samples). 309 words, ~986 tokens.

Download SKILL.mdSave it as .claude/skills/troubleshoot-kro/SKILL.md (or your agent's skills folder).
name
troubleshoot-kro
description
Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts. Use when a Kro instance is stuck IN_PROGRESS, ACK resources fail to sync, or RGD dependency chains are broken. Do NOT use for general platform troubleshooting — use troubleshoot-platform instead.

Troubleshoot KRO

Overview

Systematic troubleshooting for Kro ResourceGraphDefinitions that create ACK-managed AWS resources. Focuses on dependency chains, IAM authentication, and resource conflict resolution.

Parameters

  • rgd_name (required): ResourceGraphDefinition name (e.g., cicdpipeline.kro.run)
  • instance_name (required): Instance name (e.g., rust-cicd-pipeline)
  • namespace (required): Kubernetes namespace

Workflow

1. Check Instance Status

Identify which resource in the dependency chain is blocking.

bash
kubectl get <kind> <name> -n <namespace> -o jsonpath='{.status.conditions[?(@.type=="Ready")].message}'

Constraints:

  • You MUST check the topological order first to understand creation sequence: kubectl get resourcegraphdefinition <name> -o jsonpath='{.status.topologicalOrder}'
  • You MUST check resources in topological order because if an early resource fails, all dependents are blocked
2. Identify ACK Resources
bash
kubectl get resourcegraphdefinition <name> -o yaml | grep -E "apiVersion: (ecr|iam|eks|s3|dynamodb).services.k8s.aws"

Check each ACK resource status:

bash
kubectl describe <ack-resource-type> <name> -n <namespace> | tail -30
3. Diagnose Common Failures

ACK resource status conditions:

ConditionMeaning
ACK.IAMRoleSelectedIAMRoleSelector found and role selected
ACK.ResourceSyncedSuccessfully synced with AWS
ReadyResource ready for use
ACK.TerminalUnrecoverable error (usually resource already exists)
ACK.RecoverableTemporary error (usually IAM permission issue)

Common errors:

ErrorCauseFix
AccessDenied: sts:TagSessionTrust policy missing EKS Capability roleUpdate Terraform workload role trust policy
EntityAlreadyExistsResource from previous deploymentDelete AWS resource, then K8s resource
Resource not managed by ACKResource exists but wasn't created by ACKDelete AWS resource or adopt it
4. Fix IAM Trust Policy Issues

ACK controllers running as EKS Capabilities use <prefix>-<cluster-name>-ack-capability-role.

bash
# Check trust policy
aws iam get-role --role-name <workload-role> --query 'Role.AssumeRolePolicyDocument'

Constraints:

  • You MUST verify the capability role is in the Principal.AWS list
  • You MUST update trust policies through Terraform, not manual AWS CLI because manual changes drift
5. Clean Up Conflicting Resources

When ACK reports "Resource already exists":

bash
# 1. Find the AWS resource
aws ecr describe-repositories --repository-names <name>
aws iam get-policy --policy-arn <arn>

# 2. Delete from AWS first
aws ecr delete-repository --repository-name <name> --force
aws iam delete-policy --policy-arn <arn>

# 3. Delete K8s resource to force recreation
kubectl delete <ack-resource-type> <name> -n <namespace>

Constraints:

  • You MUST NOT delete AWS or Kubernetes resources without explicit user confirmation because these may be production resources
  • You MUST delete the AWS resource before the K8s resource because ACK will try to recreate it immediately
6. Force Reconciliation
bash
kubectl annotate <kind> <name> -n <namespace> kro.run/reconcile="$(date +%s)" --overwrite

Kro will re-evaluate the entire resource graph and create missing resources.

Constraints:

  • You SHOULD wait at least 60 seconds after cleanup before forcing reconciliation because ACK needs time to process deletions

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .kiro/skills/troubleshoot-kro of aws-samples/appmod-blueprints.

Open the folder on GitHubat commit 42ea29c

Compare with similar skills

Troubleshoot Kro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Troubleshoot Kro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Troubleshoot Kro this skillaws-samples/appmod-blueprints115—~986Automated safety check: PassMIT-0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Install Boltmcpboltmcp/boltmcp371—~2.3kAutomated safety check: PassNone
Provider Bug Reviewmondoohq/mql412—~2.9kAutomated safety check: PassCustom licence
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills1.1k—~2kAutomated safety check: PassMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Install Boltmcp

    boltmcp/boltmcp

    A skill your agent uses when asked to help install or uninstall BoltMCP

    371 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    412 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed

More from aws-samples/appmod-blueprints

All 9 skills in this repo
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    115 GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Troubleshoot Platform

    aws-samples/appmod-blueprints

    Official

    Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.

    115 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Eks Recon

    aws-samples/appmod-blueprints

    Official

    EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.

    115 GitHub stars~4.7k tokensUpdated today
    Auto-check: warnings
  • Eks Upgrade Check

    aws-samples/appmod-blueprints

    Official

    Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…

    115 GitHub stars~2.4k tokensUpdated today
    Auto-check: warnings
  • Eks Platform Engineering

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…

    115 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Troubleshoot Kro

What does Troubleshoot Kro do?

Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts. Troubleshoot Kro is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

When should I use Troubleshoot Kro?

Troubleshoot Kro fits situations like: A Kro instance is stuck INPROGRESS; ACK resources fail to sync; RGD dependency chains are broken; general platform troubleshooting — use troubleshoot-platform instead.

How do I install Troubleshoot Kro in Claude Code?

Run `npx skills add aws-samples/appmod-blueprints --skill troubleshoot-kro -a claude-code`. Or copy the skill folder (.kiro/skills/troubleshoot-kro in aws-samples/appmod-blueprints) into .claude/skills/troubleshoot-kro in your project. Claude Code loads it when a task matches its description.

How do I install Troubleshoot Kro in Codex?

Run `npx skills add aws-samples/appmod-blueprints --skill troubleshoot-kro -a codex`. Or copy the skill folder (.kiro/skills/troubleshoot-kro in aws-samples/appmod-blueprints) into .agents/skills/troubleshoot-kro in your project. Codex loads it when a task matches its description.

Can I use Troubleshoot Kro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill troubleshoot-kro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/troubleshoot-kro, .gemini/skills/troubleshoot-kro, .github/skills/troubleshoot-kro and .opencode/skills/troubleshoot-kro in your project.

What does Troubleshoot Kro need to run?

Going by SKILL.md and its folder, Troubleshoot Kro needs the command-line tools its instructions call (kubectl and aws).

Does Troubleshoot Kro access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Troubleshoot Kro safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Troubleshoot Kro use?

Troubleshoot Kro is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Troubleshoot Kro use?

About 986 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Troubleshoot Kro?

Skills that share tags, products or a category with Troubleshoot Kro: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Install Boltmcp (boltmcp/boltmcp, 371 stars), Provider Bug Review (mondoohq/mql, 412 stars) and Kcli Cluster Deployment (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Troubleshoot Kro?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 115 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 8, 2026.

Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.