Agent skill

Configuring Cockroachdb Helm Tls

by cockroachdb in cockroachdb/helm-charts

Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.

Apache-2.0Auto-check passedDevOps & Cloud

Install Configuring Cockroachdb Helm Tls

skills CLI
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .claude/skills/configuring-cockroachdb-helm-tls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuring-cockroachdb-helm-tls
GitHub stars
105
Token cost
~3.8k tokens
SKILL.md length
1,007 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.

  • A customer needs secure CockroachDB Helm values
  • SKILL.md covers When to Use This Skill, Safety Considerations, Execution Discipline and Step 1: Choose the TLS Mode, plus 8 more sections
  • Calls kubectl, jq and openssl
  • Certificate secret mapping

What it does

Configuring Cockroachdb Helm Tls is an agent skill from cockroachdb/helm-charts. Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes. Use when a customer needs secure CockroachDB Helm values, certificate secret mapping, cert-manager integration, or TLS install troubleshooting before deploying the chart.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial…

It sits in DevOps & Cloud, covering Container orchestration. It works with Helm. The repository describes itself as: Helm charts for cockroachdb. The licence is Apache-2.0.

When your agent uses it

  • A customer needs secure CockroachDB Helm values
  • Certificate secret mapping
  • Cert-manager integration
  • TLS install troubleshooting before deploying the chart

Example prompts

  • “Use the configuring-cockroachdb-helm-tls skill to select and validates TLS settings for CockroachDB Helm chart deployments, including self-signer…”
  • “/configuring-cockroachdb-helm-tls”

Requirements

  • Compatibility (from SKILL.md): CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial cluster creation.

What it can do on your machine

Read from SKILL.md and the folder at commit 26e44ff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • jq
    • openssl
    • helm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cockroachlabs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial cluster creation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Configuring Cockroachdb Helm Tls loads about 3.8k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 1,007 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cockroachdb/helm-charts at commit 26e44ff, republished under its Apache-2.0 licence (© cockroachdb). 1,007 words, ~3,765 tokens.

Download SKILL.mdSave it as .claude/skills/configuring-cockroachdb-helm-tls/SKILL.md (or your agent's skills folder).
name
configuring-cockroachdb-helm-tls
description
Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes. Use when a customer needs secure CockroachDB Helm values, certificate secret mapping, cert-manager integration, or TLS install troubleshooting before deploying the chart.
compatibility
CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial cluster creation.
metadata.author
cockroachdb
metadata.version
1.1

Configuring CockroachDB Helm TLS

Guides TLS configuration for operator-managed CockroachDB clusters installed with the Helm v2 charts. The operator API receives externalCertificates; the Helm chart is responsible for translating self-signer, cert-manager, or external certificate values into the CrdbCluster spec.

When to Use This Skill

  • A customer asks which TLS mode to use with CockroachDB Helm charts
  • A values file needs a secure cockroachdb.tls block
  • The install fails with chart TLS validation errors
  • The customer already has cert-manager or externally generated certificates
  • The customer needs to understand which Secrets and ConfigMaps the chart expects

Safety Considerations

  • Do not change cockroachdb.tls.enabled on a running cluster.
  • Enable exactly one of selfSigner.enabled, certManager.enabled, or externalCertificates.enabled when cockroachdb.tls.enabled=true.
  • Disable all three certificate providers when cockroachdb.tls.enabled=false.
  • For production, confirm the certificate rotation owner before install. Self-signer can rotate node/client certs, but a customer-provided CA remains the customer's responsibility.
  • Do not print private key contents. Only reference Secret names and required keys.
  • For certificate rotation or trust failures on a running operator-managed cluster, collect certificate metadata and cert-reloader logs before changing Secrets, ConfigMaps, or cert-manager resources.

Execution Discipline

  • Execute one step at a time and inspect the output before moving on. Certificate mode, Secret names, and issuer state determine which later checks are relevant.
  • Run every step in the same shell session. Certificate discovery relies on CRDB_NAMESPACE, CRDB_TLS_DIR, and the CRDB_CERTIFICATES_PATH export set alongside the CRD schema helper; a fresh shell drops them and later jq/kubectl calls will produce empty output.
  • For an installed cluster, never infer a CrdbCluster object name from the Helm release or CockroachDB image/version. List CrdbCluster objects and use the exact metadata.name.
  • Before reading certificate references from a CrdbCluster, save the live CRD YAML and derive the certificate field path from the served CRD schema for the object's apiVersion.
  • Do not change TLS mode, replace Secrets, patch cert-manager resources, run debug containers, or perform Helm upgrades unless the user explicitly approves the action for the target cluster.
  • Never print private key data. Use metadata checks for expiry, issuer, subject, SANs, and required key presence.
  • In production or when certificate ownership is unclear, involve TSE or the operator team before rotation, regeneration, debug containers, or restart actions.

Step 1: Choose the TLS Mode

ModeUse WhenRequired Inputs
Self-signerFastest secure install, dev/test, or customer accepts chart-managed cert generationOptional CA Secret if customer provides CA
Cert-managerCustomer already runs cert-manager and wants Kubernetes-native renewalIssuer or ClusterIssuer, CA ConfigMap, node Secret, root client Secret
External certificatesCustomer PKI owns all certificates and rotationCA ConfigMap, node Secret, HTTP Secret, root SQL client Secret
InsecureNon-production test onlyExplicit user confirmation

If the user is unsure, default to self-signer for a first secure non-production deployment and recommend cert-manager or external certificates for production environments with existing PKI.

Self-Signer Values

Chart-managed CA, node certs, and root client certs:

yaml
cockroachdb:
  tls:
    enabled: true
    selfSigner:
      enabled: true
      rotateCerts: true
    certManager:
      enabled: false
    externalCertificates:
      enabled: false

Customer-provided CA with chart-generated node and client certs:

yaml
cockroachdb:
  tls:
    enabled: true
    selfSigner:
      enabled: true
      caProvided: true
      caSecret: custom-ca-secret
      rotateCerts: true
    certManager:
      enabled: false
    externalCertificates:
      enabled: false

The CA Secret must contain ca.crt and ca.key in the CockroachDB namespace before install.

Validate:

bash
kubectl -n <namespace> get secret custom-ca-secret
helm template crdb ./cockroachdb-operator/charts/cockroachdb -n <namespace> -f values.yaml >/tmp/crdb-rendered.yaml

Cert-Manager Values

Use cert-manager when an Issuer or ClusterIssuer can issue CockroachDB node and root client certificates.

yaml
cockroachdb:
  tls:
    enabled: true
    selfSigner:
      enabled: false
    certManager:
      enabled: true
      caConfigMap: cockroachdb-ca
      nodeSecret: cockroachdb-node
      clientRootSecret: cockroachdb-root
      issuer:
        group: cert-manager.io
        kind: Issuer
        name: cockroachdb
    externalCertificates:
      enabled: false

Preflight:

bash
kubectl -n <namespace> get issuer cockroachdb
kubectl -n <namespace> get configmap cockroachdb-ca || true
kubectl -n <namespace> get secret cockroachdb-node cockroachdb-root || true
kubectl get crd certificates.cert-manager.io issuers.cert-manager.io

If cert-manager stores CA material in a Secret but the chart needs a ConfigMap, configure trust-manager or another approved process to publish ca.crt into the namespace.

External Certificate Values

Use external certificates when the customer has already generated Kubernetes resources with the names the operator expects:

yaml
cockroachdb:
  tls:
    enabled: true
    selfSigner:
      enabled: false
    certManager:
      enabled: false
    externalCertificates:
      enabled: true
      certificates:
        caConfigMapName: cockroachdb-ca
        nodeSecretName: cockroachdb-node
        httpSecretName: cockroachdb-node
        rootSqlClientSecretName: cockroachdb-root

Expected data keys:

ResourceRequired Keys
CA ConfigMapca.crt
Node TLS Secrettls.crt, tls.key
HTTP TLS Secrettls.crt, tls.key
Root SQL client Secrettls.crt, tls.key or chart-compatible root client cert keys

Validate names and keys without printing secret values:

bash
kubectl -n <namespace> get configmap cockroachdb-ca -o jsonpath='{.data.ca\.crt}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-node -o jsonpath='{.data.tls\.crt}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-node -o jsonpath='{.data.tls\.key}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-root -o jsonpath='{.data.tls\.crt}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-root -o jsonpath='{.data.tls\.key}' >/dev/null
Show full SKILL.md (408 more words)Show less

Insecure Non-Production Values

Only use for local testing or temporary non-production validation:

yaml
cockroachdb:
  tls:
    enabled: false
    selfSigner:
      enabled: false
    certManager:
      enabled: false
    externalCertificates:
      enabled: false

State clearly that insecure mode has no TLS or authentication protections and is not suitable for production.

Post-Install Verification

bash
export CRDB_NAMESPACE="<namespace>"
export CRDB_TLS_DIR="${CRDB_TLS_DIR:-$(mktemp -d)}"

kubectl get crd crdbclusters.crdb.cockroachlabs.com -o yaml > "$CRDB_TLS_DIR/crdbclusters-crd.yaml"
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o json > "$CRDB_TLS_DIR/crdbclusters-crd.json"
kubectl -n "$CRDB_NAMESPACE" get crdbcluster -o json | jq -r '
  .items[]
  | [.metadata.name, .apiVersion, (.metadata.labels["app.kubernetes.io/instance"] // ""), (.metadata.generation | tostring)]
  | @tsv
'

If no CrdbCluster rows are returned, stop the object-specific TLS validation and report that no live CrdbCluster exists in the namespace. You may collect CrdbNode owner references and labels as teardown evidence, but do not treat those values as a replacement for a discovered CrdbCluster.

If multiple CrdbCluster rows are returned, choose the target by metadata.name; do not use the Helm release or CockroachDB version as a substitute.

bash
export CRDBCLUSTER="<metadata.name-from-crdbcluster-list>"
test -n "$CRDBCLUSTER"

kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o yaml > "$CRDB_TLS_DIR/crdbcluster.yaml"
kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o json > "$CRDB_TLS_DIR/crdbcluster.json"

export CRDBCLUSTER_API_VERSION="$(jq -r '.apiVersion | split("/")[-1]' "$CRDB_TLS_DIR/crdbcluster.json")"
export CRDBCLUSTER_SCHEMA_JSON="$CRDB_TLS_DIR/crdbcluster-schema.json"
jq -e --arg version "$CRDBCLUSTER_API_VERSION" '
  .spec.versions[] | select(.name == $version) | .schema.openAPIV3Schema
' "$CRDB_TLS_DIR/crdbclusters-crd.json" > "$CRDBCLUSTER_SCHEMA_JSON"

crdb_schema_has() {
  jq -e --arg path "$1" '
    def has_schema_path($schema; $parts):
      if ($parts | length) == 0 then true
      elif (($schema.properties? // {}) | has($parts[0])) then
        has_schema_path($schema.properties[$parts[0]]; $parts[1:])
      else false
      end;
    has_schema_path(.; $path | split("."))
  ' "$CRDBCLUSTER_SCHEMA_JSON" >/dev/null
}

crdb_first_schema_path() {
  for schema_path in "$@"; do
    if crdb_schema_has "$schema_path"; then
      printf '%s\n' "$schema_path"
      return 0
    fi
  done
  printf '\n'
}

export CRDB_CERTIFICATES_PATH="$(crdb_first_schema_path spec.template.spec.certificates spec.certificates)"

jq --arg certificatesPath "$CRDB_CERTIFICATES_PATH" '
  def value($path): if $path == "" then null else getpath($path | split(".")) end;
  {apiVersion, name: .metadata.name, certificatesPath: $certificatesPath, certificates: value($certificatesPath)}
' "$CRDB_TLS_DIR/crdbcluster.json"

kubectl -n "$CRDB_NAMESPACE" get secret,configmap | grep -E 'cockroach|crdb'
kubectl -n "$CRDB_NAMESPACE" get pods

For self-signer, confirm the self-signer job ran and the generated CA, node, and client resources exist. For cert-manager, confirm Certificate resources are Ready. For external certificates, confirm the CrdbCluster references the expected names.

Certificate Debugging and Rotation Evidence

Use this section when pods report x509 errors, certificate rotation is not reflected in pods, the cert-reloader sidecar fails, or TSC asks for certificate evidence. Collect metadata only; do not print private keys.

bash
jq --arg certificatesPath "$CRDB_CERTIFICATES_PATH" '
  def value($path): if $path == "" then null else getpath($path | split(".")) end;
  {apiVersion, name: .metadata.name, certificatesPath: $certificatesPath, certificates: value($certificatesPath)}
' "$CRDB_TLS_DIR/crdbcluster.json"
kubectl -n "$CRDB_NAMESPACE" get secret,configmap | grep -E 'ca|node|client|tls|cert|cockroach|crdb'
kubectl -n "$CRDB_NAMESPACE" get pod <pod-name> -o jsonpath='{.spec.containers[*].name}{"\n"}'
kubectl -n "$CRDB_NAMESPACE" logs <pod-name> -c cert-reloader --tail=100

Inspect the node certificate:

bash
kubectl -n <namespace> get secret <node-tls-secret> -o jsonpath='{.data.tls\.crt}' | base64 -d | \
  openssl x509 -noout -dates -subject -issuer -ext subjectAltName

Inspect cert-manager resources, if cert-manager is used:

bash
kubectl -n <namespace> get certificate,issuer -o wide
kubectl get clusterissuer -o wide 2>/dev/null || true
kubectl -n <namespace> describe certificate <certificate-name>
kubectl -n <namespace> describe issuer <issuer-name>

If the CockroachDB image does not include network or OpenSSL tooling, use an approved debug image according to the customer's policy. In air-gapped environments, mirror the approved image into the customer's registry and use that registry path instead of pulling a public image directly.

bash
kubectl -n <namespace> debug <pod-name> --image=<approved-network-debug-image> --target=cockroachdb -it -- \
  openssl s_client -connect <pod-ip>:26257 \
    -CAfile /cockroach/cockroach-certs/ca.crt \
    -cert /cockroach/cockroach-certs/node.crt \
    -key /cockroach/cockroach-certs/node.key

For full in-pod certificate metadata:

bash
kubectl -n <namespace> debug <pod-name> --image=<approved-network-debug-image> --target=cockroachdb -it -- bash -c '
for DIR in /cockroach/cockroach-certs /certs /cockroach-certs; do
  if [ -d "$DIR" ]; then
    echo "=== Cert directory: $DIR ==="
    ls -la "$DIR" 2>/dev/null
    for CERT in "$DIR"/*.crt; do
      if [ -f "$CERT" ]; then
        echo "--- $CERT ---"
        openssl x509 -in "$CERT" -noout -subject -issuer -dates -ext subjectAltName 2>&1
      fi
    done
  fi
done'

Escalate with collecting-cockroachdb-operator-escalation-packet if certificates look correct but pods still cannot join, rotate, or become Ready.

Common TLS Failures

SymptomLikely CauseAction
Exactly one of selfSigner, certManager or externalCertificates must be enabled when TLS is onMultiple or zero providers enabledSet exactly one provider true
selfSigner, certManager and externalCertificates must all be disabled when TLS is offProvider enabled while TLS disabledDisable all providers or enable TLS
caProvided with empty caSecretCustomer CA mode missing Secret nameSet cockroachdb.tls.selfSigner.caSecret
Pods fail with certificate trust errorsCA and issued certs do not matchVerify CA ConfigMap/Secret and regenerate certs from the same CA
Cert rotation does not take effectcert-reloader sidecar issue, stale mounted Secret, or cert-manager failureCheck cert-reloader logs, cert-manager Certificate status, and node cert expiry/SAN metadata
Pods fail after migration with TLS errorsMigrated cert resources or CA names do not match operator referencesUse the migration debugging skill and verify the CrdbCluster certificate references

References

© cockroachdb, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls of cockroachdb/helm-charts.

Open the folder on GitHubat commit 26e44ff

Compare with similar skills

Configuring Cockroachdb Helm Tls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuring Cockroachdb Helm Tls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuring Cockroachdb Helm Tls this skillcockroachdb/helm-charts105—~3.8kAutomated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 25 days ago
    DevOps & CloudAuto-check passed

More from cockroachdb/helm-charts

  • Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…

    105 GitHub stars~5.1k tokensUpdated 7 days ago
    Auto-check passed
  • Debugs CockroachDB Operator migration scenarios, including Helm StatefulSet to v1beta1 CrdbNode migration and public operator v1alpha1 to v1beta1 migration.

    105 GitHub stars~3.6k tokensUpdated 7 days ago
    Auto-check passed
  • Installing Cockroachdb With Helm

    cockroachdb/helm-charts

    Guides customer-facing installation of CockroachDB on Kubernetes using the CockroachDB split Helm charts and operator-managed v1beta1 resources.

    105 GitHub stars~3.4k tokensUpdated 7 days ago
    Auto-check passed
  • Diagnoses failed or unhealthy CockroachDB Helm chart deployments by checking Helm release state, operator health, CrdbCluster and CrdbNode status, pod readiness, RBAC, webhooks, TLS, upgrades…

    105 GitHub stars~6.8k tokensUpdated 7 days ago
    Auto-check passed
  • Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.

    105 GitHub stars~2k tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Configuring Cockroachdb Helm Tls

What does Configuring Cockroachdb Helm Tls do?

Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes. Configuring Cockroachdb Helm Tls is an agent skill from cockroachdb/helm-charts. Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.

When should I use Configuring Cockroachdb Helm Tls?

Configuring Cockroachdb Helm Tls fits situations like: A customer needs secure CockroachDB Helm values; certificate secret mapping; cert-manager integration; TLS install troubleshooting before deploying the chart.

How do I install Configuring Cockroachdb Helm Tls in Claude Code?

Run `npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a claude-code`. Or copy the skill folder (skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls in cockroachdb/helm-charts) into .claude/skills/configuring-cockroachdb-helm-tls in your project. Claude Code loads it when a task matches its description.

How do I install Configuring Cockroachdb Helm Tls in Codex?

Run `npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a codex`. Or copy the skill folder (skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls in cockroachdb/helm-charts) into .agents/skills/configuring-cockroachdb-helm-tls in your project. Codex loads it when a task matches its description.

Can I use Configuring Cockroachdb Helm Tls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuring-cockroachdb-helm-tls, .gemini/skills/configuring-cockroachdb-helm-tls, .github/skills/configuring-cockroachdb-helm-tls and .opencode/skills/configuring-cockroachdb-helm-tls in your project.

What does Configuring Cockroachdb Helm Tls need to run?

Going by SKILL.md and its folder, Configuring Cockroachdb Helm Tls needs the command-line tools its instructions call (kubectl, jq, openssl, helm and node). Compatibility (from SKILL.md): CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial cluster creation..

Does Configuring Cockroachdb Helm Tls access the network?

SKILL.md names 1 domain. As links in the text: cockroachlabs.com. This is read from the text; nothing was executed.

Is Configuring Cockroachdb Helm Tls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuring Cockroachdb Helm Tls use?

Configuring Cockroachdb Helm Tls is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuring Cockroachdb Helm Tls use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuring Cockroachdb Helm Tls?

Skills that share tags, products or a category with Configuring Cockroachdb Helm Tls: Kubeshark Installer (kubeshark/kubeshark, 12k stars), Sim Helm (simstudioai/sim, 30k stars), Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuring Cockroachdb Helm Tls?

cockroachdb (a GitHub organization) maintains it in cockroachdb/helm-charts, which has 105 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 1, 2026.

Source: cockroachdb/helm-charts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.