Kubeshark Installer
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
Agent skill
Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packet --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .claude/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "collecting-cockroachdb-operator-escalation-packet" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet into .claude/skills/collecting-cockroachdb-operator-escalation-packet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "collecting-cockroachdb-operator-escalation-packet", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packetType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packet --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .agents/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "collecting-cockroachdb-operator-escalation-packet" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet into .agents/skills/collecting-cockroachdb-operator-escalation-packet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "collecting-cockroachdb-operator-escalation-packet", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packet --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .cursor/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "collecting-cockroachdb-operator-escalation-packet" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet into .cursor/skills/collecting-cockroachdb-operator-escalation-packet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "collecting-cockroachdb-operator-escalation-packet", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cockroachdb/helm-charts.git --path skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packet --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .gemini/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "collecting-cockroachdb-operator-escalation-packet" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet into .gemini/skills/collecting-cockroachdb-operator-escalation-packet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "collecting-cockroachdb-operator-escalation-packet", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packetInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .github/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "collecting-cockroachdb-operator-escalation-packet" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet into .github/skills/collecting-cockroachdb-operator-escalation-packet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "collecting-cockroachdb-operator-escalation-packet", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cockroachdb/helm-charts collecting-cockroachdb-operator-escalation-packet --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet .opencode/skills/collecting-cockroachdb-operator-escalation-packet && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "collecting-cockroachdb-operator-escalation-packet" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet into .opencode/skills/collecting-cockroachdb-operator-escalation-packet/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "collecting-cockroachdb-operator-escalation-packet", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
collecting-cockroachdb-operator-escalation-packetCollects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…
Collecting Cockroachdb Operator Escalation Packet is an agent skill from cockroachdb/helm-charts. Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps, metrics, and a customer action timeline. Use when general diagnosis cannot resolve an operator-managed CockroachDB Helm issue or before restarting a stuck operator.
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and…
It sits in DevOps & Cloud, covering Container orchestration and Async programming. It works with Kubernetes. The repository describes itself as: Helm charts for cockroachdb. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 26e44ff. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectljqcurlhelmnodeopensslFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl, curl and helm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and CockroachDB namespace; pprof and metrics collection require port-forward access to the operator Deployment.
From compatibility in the SKILL.md frontmatter.
Collecting Cockroachdb Operator Escalation Packet loads about 5.1k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 876 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cockroachdb/helm-charts at commit 26e44ff, republished under its Apache-2.0 licence (© cockroachdb). 876 words, ~5,114 tokens.
.claude/skills/collecting-cockroachdb-operator-escalation-packet/SKILL.md (or your agent's skills folder).Collects the artifacts needed for TSC/TSE or operator-team escalation. Use this after basic diagnosis identifies an unresolved operator, Kubernetes, migration, upgrade, scale, DNS, PVC, or certificate issue. Keep collection read-only unless the customer explicitly approves a mitigation.
CrdbNode, PVC, Secret, service, version checker job, or StatefulSet resources while collecting data.CrdbCluster.status.cockroach init on an existing cluster.OPERATOR_NAMESPACE, CRDB_NAMESPACE, CRDBCLUSTER, and the CRDB_*_PATH exports set in Step 1; opening a new shell drops those variables and downstream jq/kubectl calls will read from the wrong object or emit empty artifacts.CrdbCluster object name from a Helm release, service name, or CockroachDB image/version string. List CrdbCluster objects and use the exact metadata.name.CrdbCluster fields, save the live CRD YAML and derive field paths from the served CRD schema for the object's apiVersion.kubectl exec shells, kubectl debug, port-forwards, pprof/metrics collection, or commands that use external images in production unless the user approves them. If impact or policy is unclear, involve TSE or the operator team first.helm upgrade as part of packet collection.CrdbCluster.metadata.nameAsk the customer to gather outputs into a single directory:
mkdir -p crdb-operator-escalationUse clear filenames, for example operator-logs.txt, crdbcluster.yaml, events.txt, goroutine_dump.txt, and metrics_dump.txt.
export OPERATOR_NAMESPACE="<operator-namespace>"
export OPERATOR_RELEASE="<operator-release>"
export CRDB_NAMESPACE="<cockroachdb-namespace>"
export CRDB_HELM_RELEASE="<cockroachdb-release>"
kubectl config current-context > crdb-operator-escalation/kube-context.txt
kubectl version --short > crdb-operator-escalation/kubernetes-version.txt
helm -n "$OPERATOR_NAMESPACE" status "$OPERATOR_RELEASE" > crdb-operator-escalation/operator-helm-status.txt 2>&1 || true
helm -n "$OPERATOR_NAMESPACE" history "$OPERATOR_RELEASE" > crdb-operator-escalation/operator-helm-history.txt 2>&1 || true
helm -n "$CRDB_NAMESPACE" status "$CRDB_HELM_RELEASE" > crdb-operator-escalation/crdb-helm-status.txt 2>&1 || true
helm -n "$CRDB_NAMESPACE" history "$CRDB_HELM_RELEASE" > crdb-operator-escalation/crdb-helm-history.txt 2>&1 || true
kubectl -n "$OPERATOR_NAMESPACE" get deploy cockroach-operator -o jsonpath='{.spec.template.spec.containers[0].image}{"\n"}' > crdb-operator-escalation/operator-image.txt
kubectl get crd crdbclusters.crdb.cockroachlabs.com crdbnodes.crdb.cockroachlabs.com -o wide > crdb-operator-escalation/crds.txt
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o yaml > crdb-operator-escalation/crdbclusters-crd.yaml
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o json > crdb-operator-escalation/crdbclusters-crd.json
kubectl get crd crdbnodes.crdb.cockroachlabs.com -o yaml > crdb-operator-escalation/crdbnodes-crd.yaml
kubectl -n "$CRDB_NAMESPACE" get crdbcluster -o json | jq -r '
.items[]
| [.metadata.name, .apiVersion, (.metadata.labels["app.kubernetes.io/instance"] // ""), (.metadata.generation | tostring)]
| @tsv
' > crdb-operator-escalation/crdbcluster-candidates.tsvInspect crdbcluster-candidates.tsv. If it is empty, stop object-specific packet collection and report that no live CrdbCluster exists in the namespace. You may collect CrdbNode owner references and labels as teardown evidence, but do not treat those values as a replacement for a discovered CrdbCluster. If more than one CrdbCluster exists in the namespace, select the target by metadata.name; do not use a CockroachDB version or image tag as the object name.
export CRDBCLUSTER="<metadata.name-from-crdbcluster-candidates.tsv>"
test -n "$CRDBCLUSTER"
kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o yaml > crdb-operator-escalation/crdbcluster.yaml
kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o json > crdb-operator-escalation/crdbcluster.json
export CRDBCLUSTER_API_VERSION="$(jq -r '.apiVersion | split("/")[-1]' crdb-operator-escalation/crdbcluster.json)"
export CRDBCLUSTER_SCHEMA_JSON=crdb-operator-escalation/crdbcluster-schema.json
jq -e --arg version "$CRDBCLUSTER_API_VERSION" '
.spec.versions[] | select(.name == $version) | .schema.openAPIV3Schema
' crdb-operator-escalation/crdbclusters-crd.json > "$CRDBCLUSTER_SCHEMA_JSON"
crdb_schema_has() {
jq -e --arg path "$1" '
def has_schema_path($schema; $parts):
if ($parts | length) == 0 then true
elif (($schema.properties? // {}) | has($parts[0])) then
has_schema_path($schema.properties[$parts[0]]; $parts[1:])
else false
end;
has_schema_path(.; $path | split("."))
' "$CRDBCLUSTER_SCHEMA_JSON" >/dev/null
}
crdb_first_schema_path() {
for schema_path in "$@"; do
if crdb_schema_has "$schema_path"; then
printf '%s\n' "$schema_path"
return 0
fi
done
printf '\n'
}
export CRDB_MODE_PATH="$(crdb_first_schema_path spec.mode)"
export CRDB_REGIONS_PATH="$(crdb_first_schema_path spec.regions)"
export CRDB_DESIRED_IMAGE_PATH="$(crdb_first_schema_path spec.template.spec.image spec.image.name spec.image)"
export CRDB_OBSERVED_GENERATION_PATH="$(crdb_first_schema_path status.observedGeneration)"
export CRDB_RECONCILED_PATH="$(crdb_first_schema_path status.reconciled)"
export CRDB_READY_NODES_PATH="$(crdb_first_schema_path status.readyNodes)"
export CRDB_STATUS_IMAGE_PATH="$(crdb_first_schema_path status.image status.crdbcontainerimage)"
export CRDB_STATUS_VERSION_PATH="$(crdb_first_schema_path status.version)"
export CRDB_ACTIONS_PATH="$(crdb_first_schema_path status.actions status.operatorActions)"
export CRDB_CONDITIONS_PATH="$(crdb_first_schema_path status.conditions)"
printf '%s\n' \
"apiVersion=$CRDBCLUSTER_API_VERSION" \
"mode=$CRDB_MODE_PATH" \
"regions=$CRDB_REGIONS_PATH" \
"desiredImage=$CRDB_DESIRED_IMAGE_PATH" \
"observedGeneration=$CRDB_OBSERVED_GENERATION_PATH" \
"reconciled=$CRDB_RECONCILED_PATH" \
"readyNodes=$CRDB_READY_NODES_PATH" \
"statusImage=$CRDB_STATUS_IMAGE_PATH" \
"statusVersion=$CRDB_STATUS_VERSION_PATH" \
"actions=$CRDB_ACTIONS_PATH" \
"conditions=$CRDB_CONDITIONS_PATH" \
> crdb-operator-escalation/crdbcluster-schema-paths.txtGet the CockroachDB version from a Ready pod:
kubectl -n "$CRDB_NAMESPACE" exec <ready-crdb-pod> -c cockroachdb -- \
/cockroach/cockroach version > crdb-operator-escalation/crdb-version.txt 2>&1kubectl -n "$OPERATOR_NAMESPACE" get deploy,pod,svc,endpoints -o wide > crdb-operator-escalation/operator-resources.txt
kubectl -n "$OPERATOR_NAMESPACE" describe deploy cockroach-operator > crdb-operator-escalation/operator-deploy-describe.txt
kubectl -n "$OPERATOR_NAMESPACE" describe pods -l app=cockroach-operator > crdb-operator-escalation/operator-pods-describe.txt
kubectl -n "$OPERATOR_NAMESPACE" get deploy cockroach-operator -o yaml > crdb-operator-escalation/operator-deploy.yaml
kubectl -n "$CRDB_NAMESPACE" describe crdbcluster "$CRDBCLUSTER" > crdb-operator-escalation/crdbcluster-describe.txt
kubectl -n "$CRDB_NAMESPACE" get crdbnodes -o yaml > crdb-operator-escalation/crdbnodes.yaml
kubectl -n "$CRDB_NAMESPACE" describe crdbnodes > crdb-operator-escalation/crdbnodes-describe.txt
kubectl -n "$CRDB_NAMESPACE" get pod,svc,endpoints,pvc,pdb -o wide > crdb-operator-escalation/crdb-resources-wide.txt
kubectl -n "$CRDB_NAMESPACE" describe pods -l app.kubernetes.io/name=cockroachdb > crdb-operator-escalation/crdb-pods-describe.txt
kubectl -n "$CRDB_NAMESPACE" describe pvc > crdb-operator-escalation/pvc-describe.txt
kubectl -n "$CRDB_NAMESPACE" describe pdb > crdb-operator-escalation/pdb-describe.txt
kubectl -n "$CRDB_NAMESPACE" get events --sort-by=.lastTimestamp > crdb-operator-escalation/events.txtSummarize key cluster status:
jq \
--arg modePath "$CRDB_MODE_PATH" \
--arg regionsPath "$CRDB_REGIONS_PATH" \
--arg desiredImagePath "$CRDB_DESIRED_IMAGE_PATH" \
--arg observedGenerationPath "$CRDB_OBSERVED_GENERATION_PATH" \
--arg reconciledPath "$CRDB_RECONCILED_PATH" \
--arg readyNodesPath "$CRDB_READY_NODES_PATH" \
--arg statusImagePath "$CRDB_STATUS_IMAGE_PATH" \
--arg statusVersionPath "$CRDB_STATUS_VERSION_PATH" \
--arg actionsPath "$CRDB_ACTIONS_PATH" \
--arg conditionsPath "$CRDB_CONDITIONS_PATH" \
'
def value($path): if $path == "" then null else getpath($path | split(".")) end;
{
apiVersion,
name: .metadata.name,
schemaPaths: {
mode: $modePath,
regions: $regionsPath,
desiredImage: $desiredImagePath,
observedGeneration: $observedGenerationPath,
reconciled: $reconciledPath,
readyNodes: $readyNodesPath,
statusImage: $statusImagePath,
statusVersion: $statusVersionPath,
actions: $actionsPath,
conditions: $conditionsPath
},
mode: value($modePath),
nodes: (value($regionsPath) // [] | map(.nodes)),
regions: value($regionsPath),
desiredImage: value($desiredImagePath),
generation: .metadata.generation,
observedGeneration: value($observedGenerationPath),
reconciled: value($reconciledPath),
readyNodes: value($readyNodesPath),
statusImage: value($statusImagePath),
statusVersion: value($statusVersionPath),
actions: value($actionsPath),
conditions: value($conditionsPath),
labels: .metadata.labels,
annotations: .metadata.annotations
}' crdb-operator-escalation/crdbcluster.json > crdb-operator-escalation/crdbcluster-summary.json
kubectl -n "$CRDB_NAMESPACE" get crdbnodes \
-o 'custom-columns=NAME:.metadata.name,GENERATION:.metadata.generation,OBSERVED:.status.observedGeneration,DECOMMISSION:.status.decommission,REVISION:.metadata.annotations.crdb\.cockroachlabs\.com/clusterNodeRevision,NODE_ID:.status.nodeID' \
> crdb-operator-escalation/crdbnodes-summary.txtCollect full recent logs, not filtered snippets:
kubectl -n "$OPERATOR_NAMESPACE" logs -l app=cockroach-operator --tail=500 > crdb-operator-escalation/operator-logs.txt 2>&1
kubectl -n "$OPERATOR_NAMESPACE" logs -l app=cockroach-operator --previous --tail=500 > crdb-operator-escalation/operator-previous-logs.txt 2>&1 || trueFor each CockroachDB pod:
kubectl -n "$CRDB_NAMESPACE" logs <crdb-pod> -c cockroachdb --tail=500 > crdb-operator-escalation/<crdb-pod>-cockroachdb.log 2>&1
kubectl -n "$CRDB_NAMESPACE" logs <crdb-pod> -c cockroachdb --previous --tail=500 > crdb-operator-escalation/<crdb-pod>-cockroachdb-previous.log 2>&1 || true
kubectl -n "$CRDB_NAMESPACE" logs <crdb-pod> -c cert-reloader --tail=100 > crdb-operator-escalation/<crdb-pod>-cert-reloader.log 2>&1 || truejq \
--arg desiredImagePath "$CRDB_DESIRED_IMAGE_PATH" \
--arg statusImagePath "$CRDB_STATUS_IMAGE_PATH" \
--arg statusVersionPath "$CRDB_STATUS_VERSION_PATH" \
--arg actionsPath "$CRDB_ACTIONS_PATH" \
--arg conditionsPath "$CRDB_CONDITIONS_PATH" \
'
def value($path): if $path == "" then null else getpath($path | split(".")) end;
{
apiVersion,
name: .metadata.name,
desiredImagePath: $desiredImagePath,
desiredImage: value($desiredImagePath),
statusImagePath: $statusImagePath,
statusImage: value($statusImagePath),
statusVersionPath: $statusVersionPath,
statusVersion: value($statusVersionPath),
actionsPath: $actionsPath,
actions: value($actionsPath),
conditionsPath: $conditionsPath,
conditions: value($conditionsPath),
annotations: .metadata.annotations,
}' crdb-operator-escalation/crdbcluster.json > crdb-operator-escalation/upgrade-status.json
kubectl -n "$CRDB_NAMESPACE" get jobs -o wide > crdb-operator-escalation/jobs.txt
kubectl -n "$CRDB_NAMESPACE" get pods -o 'custom-columns=NAME:.metadata.name,IMAGE:.spec.containers[0].image,PHASE:.status.phase' > crdb-operator-escalation/pod-images.txt
kubectl -n "$CRDB_NAMESPACE" describe job <version-checker-job> > crdb-operator-escalation/version-checker-job.txt 2>&1 || true
kubectl -n "$CRDB_NAMESPACE" logs -l job-name=<version-checker-job> > crdb-operator-escalation/version-checker-logs.txt 2>&1 || trueInclude current and target CRDB image and whether any version checker job or pod was deleted.
kubectl -n "$CRDB_NAMESPACE" exec <ready-crdb-pod> -c cockroachdb -- \
/cockroach/cockroach node status --decommission > crdb-operator-escalation/node-decommission-status.txt 2>&1
kubectl -n "$CRDB_NAMESPACE" get crdbnodes -o json | jq '[.items[] | select(.status.decommission != null and .status.decommission != "")] | {count: length, nodes: [.[] | {name: .metadata.name, decommission: .status.decommission}]}' \
> crdb-operator-escalation/decommissioning-crdbnodes.jsonInclude original and target node count, whether multiple nodes changed at once, and whether manual drain/decommission was attempted.
Capture whether machines, Kubernetes nodes, disks, storage classes, topology spread constraints, or node labels changed:
kubectl get nodes -L topology.kubernetes.io/region,topology.kubernetes.io/zone > crdb-operator-escalation/nodes-locality.txt
kubectl get storageclass > crdb-operator-escalation/storageclasses.txt
kubectl -n "$CRDB_NAMESPACE" get pvc -o wide > crdb-operator-escalation/pvc-wide.txtkubectl -n "$CRDB_NAMESPACE" get secret,configmap | grep -E 'ca|node|client|tls|cert' > crdb-operator-escalation/cert-resources.txt || true
kubectl -n "$CRDB_NAMESPACE" get certificate,issuer,clusterissuer -o wide > crdb-operator-escalation/cert-manager-resources.txt 2>&1 || true
kubectl -n "$CRDB_NAMESPACE" get secret <node-tls-secret> -o jsonpath='{.data.tls\.crt}' | base64 -d | \
openssl x509 -noout -dates -subject -issuer -ext subjectAltName > crdb-operator-escalation/node-cert-metadata.txtDo not collect private key values.
Use debugging-cockroachdb-operator-migrations and attach its migration state output. Include source StatefulSet or v1alpha1 CrdbCluster, migration labels, migration phase, source ownerReferences, and migration controller logs.
Collect these when the operator is running but not reconciling, logs/status do not explain why, or a worker may be blocked. In production or restricted environments, confirm with the customer, TSE, or the operator team before opening port-forwards.
In one terminal:
kubectl -n "$OPERATOR_NAMESPACE" port-forward deployment/cockroach-operator 7080:7080In another terminal:
curl -s 'http://localhost:7080/debug/pprof/goroutine?debug=2' > crdb-operator-escalation/goroutine_dump.txt
curl -s 'http://localhost:7080/debug/pprof/goroutine?debug=1' > crdb-operator-escalation/goroutine_summary.txt
curl -s 'http://localhost:7080/debug/pprof/heap' > crdb-operator-escalation/heap.prof
curl -s 'http://localhost:7080/debug/pprof/profile?seconds=30' > crdb-operator-escalation/cpu.prof
curl -s 'http://localhost:7080/debug/pprof/mutex' > crdb-operator-escalation/mutex.profMetrics:
kubectl -n "$OPERATOR_NAMESPACE" port-forward deployment/cockroach-operator 8080:8080
curl -s http://localhost:8080/metrics > crdb-operator-escalation/metrics_dump.txt
grep 'controller_runtime_reconcile_total' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/reconcile-total.txt || true
grep 'controller_runtime_reconcile_errors_total' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/reconcile-errors.txt || true
grep 'workqueue_depth' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/workqueue-depth.txt || true
grep 'workqueue_longest_running_processor_seconds' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/workqueue-longest-running.txt || true
grep 'workqueue_unfinished_work_seconds' crdb-operator-escalation/metrics_dump.txt > crdb-operator-escalation/workqueue-unfinished.txt || trueWhat TSC should inspect:
processNextWorkItem followed by Reconcile and a long-running call in goroutine_dump.txtkube.(*Ctl).Exec, cockroach init, HTTP calls, or mutex waits with long durationsworkqueue_longest_running_processor_secondsworkqueue_depthCreate crdb-operator-escalation/timeline.md with:
Return a concise summary with:
CrdbCluster mode, generation, observedGeneration, image, version, actions, and conditions© cockroachdb, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet of cockroachdb/helm-charts.
Open the folder on GitHubat commit 26e44ff
Collecting Cockroachdb Operator Escalation Packet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Collecting Cockroachdb Operator Escalation Packet this skillcockroachdb/helm-charts | 105 | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Kubeshark Installerkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | |
| KubeSphere Multi-Tenant Managementkubesphere/kubesphere | 17k | — | ~3.1k | Automated safety check: Pass | Custom licence | |
| Sim Helmsimstudioai/sim | 30k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Helm Chart ScaffoldingCybereason-Public/owLSM | 280 | 13 repos | ~381 | Automated safety check: Pass | GPL-2.0 | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
kubesphere/kubesphere
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
simstudioai/sim
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
Cybereason-Public/owLSM
Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
kubesphere/kubesphere
Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.
cockroachdb/helm-charts
Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.
cockroachdb/helm-charts
Debugs CockroachDB Operator migration scenarios, including Helm StatefulSet to v1beta1 CrdbNode migration and public operator v1alpha1 to v1beta1 migration.
cockroachdb/helm-charts
Guides customer-facing installation of CockroachDB on Kubernetes using the CockroachDB split Helm charts and operator-managed v1beta1 resources.
cockroachdb/helm-charts
Diagnoses failed or unhealthy CockroachDB Helm chart deployments by checking Helm release state, operator health, CrdbCluster and CrdbNode status, pod readiness, RBAC, webhooks, TLS, upgrades…
cockroachdb/helm-charts
Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.
Works with
Categories
Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…. Collecting Cockroachdb Operator Escalation Packet is an agent skill from cockroachdb/helm-charts. Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps, metrics, and a customer action timeline.
Collecting Cockroachdb Operator Escalation Packet fits situations like: general diagnosis cannot resolve an operator-managed CockroachDB Helm issue; before restarting a stuck operator.
Run `npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a claude-code`. Or copy the skill folder (skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet in cockroachdb/helm-charts) into .claude/skills/collecting-cockroachdb-operator-escalation-packet in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a codex`. Or copy the skill folder (skills/cockroachdb-observability-and-diagnostics/collecting-cockroachdb-operator-escalation-packet in cockroachdb/helm-charts) into .agents/skills/collecting-cockroachdb-operator-escalation-packet in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cockroachdb/helm-charts --skill collecting-cockroachdb-operator-escalation-packet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/collecting-cockroachdb-operator-escalation-packet, .gemini/skills/collecting-cockroachdb-operator-escalation-packet, .github/skills/collecting-cockroachdb-operator-escalation-packet and .opencode/skills/collecting-cockroachdb-operator-escalation-packet in your project.
Going by SKILL.md and its folder, Collecting Cockroachdb Operator Escalation Packet needs the command-line tools its instructions call (kubectl, jq, curl, helm, node and openssl). Compatibility (from SKILL.md): CockroachDB Helm v2 charts and operator-managed crdb.cockroachlabs.com/v1beta1 resources. Requires Kubernetes read access to the operator namespace and CockroachDB namespace; pprof and metrics collection require port-forward access to the operator Deployment..
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Collecting Cockroachdb Operator Escalation Packet is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Collecting Cockroachdb Operator Escalation Packet: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cockroachdb (a GitHub organization) maintains it in cockroachdb/helm-charts, which has 105 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 1, 2026.
Source: cockroachdb/helm-charts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.