Kelos
kelos-dev/kelos
Install and configure Kelos; author, document, inspect, troubleshoot, and operate its Kubernetes custom resources and CRD schemas in the kelos.dev API group using manifests, kubectl, or the kelos CLI.
Native Kubernetes components (experimental): render/plan/diff/apply/deploy/delete/validate via Kubernetes Go SDK server-side apply, components.kubernetes, kubectl/kustomize providers…
$ npx skills add cloudposse/atmos --skill atmos-kubernetes -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cloudposse/atmos atmos-kubernetes --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-kubernetes .claude/skills/atmos-kubernetes && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "atmos-kubernetes" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetes into .claude/skills/atmos-kubernetes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-kubernetes", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cloudposse/atmos --skill atmos-kubernetes -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cloudposse/atmos atmos-kubernetes --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agent-skills/skills/atmos-kubernetes .agents/skills/atmos-kubernetes && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "atmos-kubernetes" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetes into .agents/skills/atmos-kubernetes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-kubernetes", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudposse/atmos --skill atmos-kubernetes -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cloudposse/atmos atmos-kubernetes --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agent-skills/skills/atmos-kubernetes .cursor/skills/atmos-kubernetes && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "atmos-kubernetes" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetes into .cursor/skills/atmos-kubernetes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-kubernetes", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cloudposse/atmos.git --path agent-skills/skills/atmos-kubernetes--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cloudposse/atmos --skill atmos-kubernetes -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cloudposse/atmos atmos-kubernetes --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agent-skills/skills/atmos-kubernetes .gemini/skills/atmos-kubernetes && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "atmos-kubernetes" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetes into .gemini/skills/atmos-kubernetes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-kubernetes", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cloudposse/atmos atmos-kubernetesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cloudposse/atmos --skill atmos-kubernetes -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .github/skills && cp -r skills-src/agent-skills/skills/atmos-kubernetes .github/skills/atmos-kubernetes && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "atmos-kubernetes" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetes into .github/skills/atmos-kubernetes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-kubernetes", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudposse/atmos --skill atmos-kubernetes -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cloudposse/atmos atmos-kubernetes --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agent-skills/skills/atmos-kubernetes .opencode/skills/atmos-kubernetes && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "atmos-kubernetes" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-kubernetes into .opencode/skills/atmos-kubernetes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-kubernetes", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
atmos-kubernetesNative Kubernetes components (experimental): render/plan/diff/apply/deploy/delete/validate via Kubernetes Go SDK server-side apply, components.kubernetes, kubectl/kustomize providers…
Atmos Kubernetes is an agent skill from cloudposse/atmos. Native Kubernetes components (experimental): render/plan/diff/apply/deploy/delete/validate via Kubernetes Go SDK server-side apply, components.kubernetes, kubectl/kustomize providers, paths/manifests, provision targets (cluster vs. GitOps repo), and auth
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes and Git. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 36726ae. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Atmos Kubernetes loads about 2.8k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 928 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cloudposse/atmos at commit 36726ae, republished under its Apache-2.0 licence (© cloudposse). 928 words, ~2,754 tokens.
.claude/skills/atmos-kubernetes/SKILL.md (or your agent's skills folder).Use this skill for the native Kubernetes component type (components.kubernetes). It manages
plain YAML/JSON manifests and Kustomize overlays through the Kubernetes Go SDK with server-side
apply. No kubectl or kustomize binary is required. This is distinct from Helm chart deployment —
see atmos-helm for charts, or atmos-helmfile
for Helmfile-based releases.
This feature is experimental. kubectl/kustomize names describe manifest-processing
behavior, not the CLI binaries.
| Need | Load |
|---|---|
| Helm charts (native, Helm Go SDK) | atmos-helm |
| Helmfile-based Kubernetes deployments | atmos-helmfile |
Component dependency ordering for --all/--affected | atmos-components |
GitOps delivery targets (provision.targets, kind: git) | atmos-git |
| EKS kubeconfig / cluster authentication | atmos-aws-eks, atmos-auth |
| Lifecycle hooks around component operations | atmos-hooks |
| Native CI job summaries | atmos-ci |
| Local Kubernetes emulator (k3s) | atmos-emulator |
Define Kubernetes objects under components.kubernetes in stack manifests:
components:
kubernetes:
argocd:
provider: kustomize
paths:
- overlays/{{ .vars.cluster }}
vars:
namespace: argocd
cluster: dev
env:
KUBECONFIG: /tmp/kubeconfig
manifests:
- apiVersion: v1
kind: Namespace
metadata:
name: "{{ .vars.namespace }}"
provision:
default: cluster
targets:
cluster:
kind: kubernetes
deployment-repo:
kind: git
repository: deployments
path: "clusters/{{ .vars.cluster }}/argocd"Kubernetes components use the same stack sections as other component types — vars, env, auth,
metadata, settings, dependencies, hooks, generate, source/provision, inheritance, and
overrides. Kubernetes components do not support command — provider names describe manifest
behavior, and Atmos never shells out to kubectl/kustomize.
| Field | Purpose |
|---|---|
provider | kubectl (plain YAML/JSON) or kustomize (Kustomize overlays). Defaults to atmos.yaml components.kubernetes.provider (default kubectl). |
paths | Files or directories relative to the component directory. Directories are walked recursively for .yaml/.yml/.json. With provider: kustomize, a directory containing a Kustomize file is rendered as a Kustomize root. |
manifests | Inline Kubernetes objects (or YAML strings), merged with objects loaded from paths. |
render | Default output for atmos kubernetes render (output.path, output.split). |
provision | Delivery targets for apply/deploy — the cluster (default) or an external target such as a Git deployment repository. |
| Provider | Behavior |
|---|---|
kubectl | Loads plain YAML/JSON manifests from files, directories, and inline manifests. |
kustomize | Renders Kustomize directories via the Kustomize Go API, then passes objects to the same Kubernetes clients. |
Both providers are Go-SDK-based; neither requires the matching CLI binary installed.
| Command | Purpose |
|---|---|
atmos kubernetes render <component> -s <stack> | Resolve stack config, run generation, load manifests, render provider inputs, write final YAML. Does not contact the API server. |
atmos kubernetes validate <component> -s <stack> | Offline structural checks by default (apiVersion/kind present, metadata.name valid DNS-1123, resolvable GVK); --server adds a live server-side dry-run apply. Reports every invalid object, not just the first. |
atmos kubernetes diff <component> -s <stack> | Server-side dry-run apply against the live object, normalizes volatile metadata, reports created/changed/no-change per object with a unified diff. plan is an alias. |
atmos kubernetes apply <component> -s <stack> | Resolves each object GVK→GVR via discovery/RESTMapper, applies via the dynamic client with server-side apply, or delivers to a --target provision target. |
atmos kubernetes deploy <component> -s <stack> | Alias for apply; use when automation language should read as an application deployment rather than an API operation. |
atmos kubernetes delete <component> -s <stack> | Deletes the rendered objects from the cluster. |
All operation commands accept --all, --affected (with --base/--ref/--sha/--repo-path/
--clone-target-ref/--ssh-key/--ssh-key-password), and --include-dependents, matching
atmos describe affected semantics. --all/--affected are mutually exclusive with a positional
component argument. kubernetes aliases to k8s.
render writes multi-document YAML to stdout by default. --output <file> writes a single file;
--output-dir <dir> (with optional --split) writes one file per object (or manifest.yaml without
--split). These flags only work rendering a single component — set component-level render.output
for --all/--affected runs.
Runs the same offline structural checks automatically before apply/deploy, so malformed manifests
are rejected before anything reaches the cluster or a provision target. --server additionally
requires a reachable cluster/kubeconfig and surfaces schema errors and missing CRDs authoritatively.
atmos kubernetes diff does not shell out to kubectl diff. Secret objects are omitted from
diff output and CI summaries.
By default apply/deploy applies to the cluster (kind: kubernetes). A component can instead
publish rendered manifests to a Git deployment repository reconciled by Argo CD/Flux (kind: git):
git:
repositories:
deployments:
uri: https://github.com/acme/deployments.git
branch: main
components:
kubernetes:
argocd:
provision:
default: cluster # used when --target is omitted
targets:
cluster:
kind: kubernetes
deployment-repo:
kind: git
repository: deployments # references git.repositories.<name>
path: "clusters/{{ .vars.cluster }}/argocd"
auth:
identity: platform-admin # optional; else the repository default
commit:
message: "Render {{ .vars.app_name }} for {{ .vars.stage }}"
signing: auto # auto | always | neveratmos kubernetes deploy argocd -s plat-ue2-dev --target=deployment-repoThe git target clones (or fast-forwards), replaces the managed path with the rendered manifests,
commits with provenance trailers (Atmos-Stack, Atmos-Component), and pushes. Re-delivering
identical manifests is a clean no-op. Credentials come from Atmos Auth (GitHub STS) — never written
into the manifests. Pull-request publishing is not yet supported. See
atmos-git for the underlying mechanics.
Kubernetes operations use whatever kubeconfig/client configuration is visible to the Kubernetes Go client; Atmos Auth prepares that environment before the SDK client is created.
Local/ambient clusters:
auth:
identities:
local-k3s:
kind: ambient
components:
kubernetes:
app:
env:
KUBECONFIG: /path/to/kubeconfigEKS clusters — chain an aws/eks integration off an AWS identity to resolve the cluster and write
kubeconfig before the Kubernetes command runs:
auth:
identities:
platform-admin:
kind: aws
integrations:
prod/eks:
kind: aws/eks
via:
identity: platform-admin
spec:
cluster:
name: acme-prod-eks
region: us-east-1
kubeconfig:
path: /tmp/acme-prod-kubeconfig
update: replaceSee atmos-aws-eks for the full aws/eks integration contract.
components:
kubernetes:
base_path: components/kubernetes # default: components/kubernetes
provider: kubectl # default provider: kubectl | kustomize
auto_generate_files: false # render component `generate:` before operationsWhen ci.enabled: true and Atmos runs in a supported CI provider (e.g. GitHub Actions), Kubernetes
commands write a compact Markdown job summary ($GITHUB_STEP_SUMMARY) — summaries only (no
$GITHUB_OUTPUT, commit statuses, PR comments, or artifacts):
| Command | Summary content |
|---|---|
render | Rendered objects. |
plan/diff | Created/changed/no-change counts, plus a collapsible Kubernetes Diff block (per-object unified diff; Secret objects omitted). |
apply/deploy | Applied or delivered objects. |
delete | Deleted and not-found objects. |
validate | Valid and invalid objects. |
Dotted lifecycle events: before/after × kubernetes.{render,plan,diff,apply,deploy,delete,validate}.
plan normalizes to the diff lifecycle and deploy normalizes to the apply lifecycle for hook
matching, so hooks written for either spelling match the equivalent operation.
components:
kubernetes:
argocd:
hooks:
notify:
events:
- after.kubernetes.apply
command: echo "applied argocd"validate (offline by default) before wiring --server dry-run checks that need a reachable
cluster — it catches structural errors (bad apiVersion/kind, invalid metadata.name) for free.dependencies.components so --all/--affected apply objects across components in the right
order.provision.targets with kind: git for GitOps delivery instead of ad hoc scripts that render
and commit manifests manually.kustomize provider when component paths are Kustomize roots; use kubectl provider for
plain manifest files/directories — both avoid needing the matching CLI binary installed.Secret objects never appear in diff output or CI summaries — don't rely on diff/CI logs
to review secret contents.© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agent-skills/skills/atmos-kubernetes of cloudposse/atmos.
Open the folder on GitHubat commit 36726ae
Atmos Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Atmos Kubernetes this skillcloudposse/atmos | 1.4k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Keloskelos-dev/kelos | 336 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| GitOps with ArgoCD and Fluxwshobson/agents | 40k | 12 repos | ~1.5k | Automated safety check: Pass | MIT | |
| HypaHypabolic/Hypa | 208 | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| Tokf Runmpecan/tokf | 199 | — | ~571 | Automated safety check: Pass | MIT | |
| Argocd GitopsBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2.4k | Automated safety check: Pass | MIT |
kelos-dev/kelos
Install and configure Kelos; author, document, inspect, troubleshoot, and operate its Kubernetes custom resources and CRD schemas in the kelos.dev API group using manifests, kubectl, or the kelos CLI.
wshobson/agents
Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.
Hypabolic/Hypa
Context-optimized command runtime. An agent skill from Hypabolic/Hypa.
mpecan/tokf
Compress verbose CLI output with tokf before returning results.
BagelHole/DevOps-Security-Agent-Skills
Implement GitOps with ArgoCD for declarative Kubernetes deployments.
grafana/skills
Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo /…
cloudposse/atmos
A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…
cloudposse/atmos
Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.
cloudposse/atmos
Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.
cloudposse/atmos
Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…
cloudposse/atmos
Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…
cloudposse/atmos
Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…
Works with
Categories
Native Kubernetes components (experimental): render/plan/diff/apply/deploy/delete/validate via Kubernetes Go SDK server-side apply, components.kubernetes, kubectl/kustomize providers…. Atmos Kubernetes is an agent skill from cloudposse/atmos.kubernetes, kubectl/kustomize providers, paths/manifests, provision targets (cluster vs.
Atmos Kubernetes fits situations like: tasks that involve Container orchestration.
Run `npx skills add cloudposse/atmos --skill atmos-kubernetes -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-kubernetes in cloudposse/atmos) into .claude/skills/atmos-kubernetes in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cloudposse/atmos --skill atmos-kubernetes -a codex`. Or copy the skill folder (agent-skills/skills/atmos-kubernetes in cloudposse/atmos) into .agents/skills/atmos-kubernetes in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-kubernetes, .gemini/skills/atmos-kubernetes, .github/skills/atmos-kubernetes and .opencode/skills/atmos-kubernetes in your project.
Going by SKILL.md and its folder, Atmos Kubernetes needs the command-line tools its instructions call (kubectl).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Atmos Kubernetes is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Atmos Kubernetes: Kelos (kelos-dev/kelos, 336 stars), GitOps with ArgoCD and Flux (wshobson/agents, 40k stars), Hypa (Hypabolic/Hypa, 208 stars) and Tokf Run (mpecan/tokf, 199 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,396 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 8, 2026.
Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.