Kubeshark Installer
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tls --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .claude/skills/configuring-cockroachdb-helm-tls && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuring-cockroachdb-helm-tls" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls into .claude/skills/configuring-cockroachdb-helm-tls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-cockroachdb-helm-tls", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tlsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tls --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .agents/skills/configuring-cockroachdb-helm-tls && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuring-cockroachdb-helm-tls" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls into .agents/skills/configuring-cockroachdb-helm-tls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-cockroachdb-helm-tls", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tls --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .cursor/skills/configuring-cockroachdb-helm-tls && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuring-cockroachdb-helm-tls" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls into .cursor/skills/configuring-cockroachdb-helm-tls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-cockroachdb-helm-tls", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cockroachdb/helm-charts.git --path skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tls --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .gemini/skills/configuring-cockroachdb-helm-tls && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuring-cockroachdb-helm-tls" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls into .gemini/skills/configuring-cockroachdb-helm-tls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-cockroachdb-helm-tls", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tlsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .github/skills/configuring-cockroachdb-helm-tls && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuring-cockroachdb-helm-tls" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls into .github/skills/configuring-cockroachdb-helm-tls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-cockroachdb-helm-tls", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cockroachdb/helm-charts configuring-cockroachdb-helm-tls --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls .opencode/skills/configuring-cockroachdb-helm-tls && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuring-cockroachdb-helm-tls" agent skill from https://github.com/cockroachdb/helm-charts/tree/master/skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls into .opencode/skills/configuring-cockroachdb-helm-tls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-cockroachdb-helm-tls", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuring-cockroachdb-helm-tlsSelects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.
Configuring Cockroachdb Helm Tls is an agent skill from cockroachdb/helm-charts. Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes. Use when a customer needs secure CockroachDB Helm values, certificate secret mapping, cert-manager integration, or TLS install troubleshooting before deploying the chart.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial…
It sits in DevOps & Cloud, covering Container orchestration. It works with Helm. The repository describes itself as: Helm charts for cockroachdb. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 26e44ff. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectljqopensslhelmnodeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cockroachlabs.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial cluster creation.
From compatibility in the SKILL.md frontmatter.
Configuring Cockroachdb Helm Tls loads about 3.8k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 1,007 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cockroachdb/helm-charts at commit 26e44ff, republished under its Apache-2.0 licence (© cockroachdb). 1,007 words, ~3,765 tokens.
.claude/skills/configuring-cockroachdb-helm-tls/SKILL.md (or your agent's skills folder).Guides TLS configuration for operator-managed CockroachDB clusters installed with the Helm v2 charts. The operator API receives externalCertificates; the Helm chart is responsible for translating self-signer, cert-manager, or external certificate values into the CrdbCluster spec.
cockroachdb.tls blockcockroachdb.tls.enabled on a running cluster.selfSigner.enabled, certManager.enabled, or externalCertificates.enabled when cockroachdb.tls.enabled=true.cockroachdb.tls.enabled=false.CRDB_NAMESPACE, CRDB_TLS_DIR, and the CRDB_CERTIFICATES_PATH export set alongside the CRD schema helper; a fresh shell drops them and later jq/kubectl calls will produce empty output.CrdbCluster object name from the Helm release or CockroachDB image/version. List CrdbCluster objects and use the exact metadata.name.CrdbCluster, save the live CRD YAML and derive the certificate field path from the served CRD schema for the object's apiVersion.| Mode | Use When | Required Inputs |
|---|---|---|
| Self-signer | Fastest secure install, dev/test, or customer accepts chart-managed cert generation | Optional CA Secret if customer provides CA |
| Cert-manager | Customer already runs cert-manager and wants Kubernetes-native renewal | Issuer or ClusterIssuer, CA ConfigMap, node Secret, root client Secret |
| External certificates | Customer PKI owns all certificates and rotation | CA ConfigMap, node Secret, HTTP Secret, root SQL client Secret |
| Insecure | Non-production test only | Explicit user confirmation |
If the user is unsure, default to self-signer for a first secure non-production deployment and recommend cert-manager or external certificates for production environments with existing PKI.
Chart-managed CA, node certs, and root client certs:
cockroachdb:
tls:
enabled: true
selfSigner:
enabled: true
rotateCerts: true
certManager:
enabled: false
externalCertificates:
enabled: falseCustomer-provided CA with chart-generated node and client certs:
cockroachdb:
tls:
enabled: true
selfSigner:
enabled: true
caProvided: true
caSecret: custom-ca-secret
rotateCerts: true
certManager:
enabled: false
externalCertificates:
enabled: falseThe CA Secret must contain ca.crt and ca.key in the CockroachDB namespace before install.
Validate:
kubectl -n <namespace> get secret custom-ca-secret
helm template crdb ./cockroachdb-operator/charts/cockroachdb -n <namespace> -f values.yaml >/tmp/crdb-rendered.yamlUse cert-manager when an Issuer or ClusterIssuer can issue CockroachDB node and root client certificates.
cockroachdb:
tls:
enabled: true
selfSigner:
enabled: false
certManager:
enabled: true
caConfigMap: cockroachdb-ca
nodeSecret: cockroachdb-node
clientRootSecret: cockroachdb-root
issuer:
group: cert-manager.io
kind: Issuer
name: cockroachdb
externalCertificates:
enabled: falsePreflight:
kubectl -n <namespace> get issuer cockroachdb
kubectl -n <namespace> get configmap cockroachdb-ca || true
kubectl -n <namespace> get secret cockroachdb-node cockroachdb-root || true
kubectl get crd certificates.cert-manager.io issuers.cert-manager.ioIf cert-manager stores CA material in a Secret but the chart needs a ConfigMap, configure trust-manager or another approved process to publish ca.crt into the namespace.
Use external certificates when the customer has already generated Kubernetes resources with the names the operator expects:
cockroachdb:
tls:
enabled: true
selfSigner:
enabled: false
certManager:
enabled: false
externalCertificates:
enabled: true
certificates:
caConfigMapName: cockroachdb-ca
nodeSecretName: cockroachdb-node
httpSecretName: cockroachdb-node
rootSqlClientSecretName: cockroachdb-rootExpected data keys:
| Resource | Required Keys |
|---|---|
| CA ConfigMap | ca.crt |
| Node TLS Secret | tls.crt, tls.key |
| HTTP TLS Secret | tls.crt, tls.key |
| Root SQL client Secret | tls.crt, tls.key or chart-compatible root client cert keys |
Validate names and keys without printing secret values:
kubectl -n <namespace> get configmap cockroachdb-ca -o jsonpath='{.data.ca\.crt}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-node -o jsonpath='{.data.tls\.crt}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-node -o jsonpath='{.data.tls\.key}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-root -o jsonpath='{.data.tls\.crt}' >/dev/null
kubectl -n <namespace> get secret cockroachdb-root -o jsonpath='{.data.tls\.key}' >/dev/nullOnly use for local testing or temporary non-production validation:
cockroachdb:
tls:
enabled: false
selfSigner:
enabled: false
certManager:
enabled: false
externalCertificates:
enabled: falseState clearly that insecure mode has no TLS or authentication protections and is not suitable for production.
export CRDB_NAMESPACE="<namespace>"
export CRDB_TLS_DIR="${CRDB_TLS_DIR:-$(mktemp -d)}"
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o yaml > "$CRDB_TLS_DIR/crdbclusters-crd.yaml"
kubectl get crd crdbclusters.crdb.cockroachlabs.com -o json > "$CRDB_TLS_DIR/crdbclusters-crd.json"
kubectl -n "$CRDB_NAMESPACE" get crdbcluster -o json | jq -r '
.items[]
| [.metadata.name, .apiVersion, (.metadata.labels["app.kubernetes.io/instance"] // ""), (.metadata.generation | tostring)]
| @tsv
'If no CrdbCluster rows are returned, stop the object-specific TLS validation and report that no live CrdbCluster exists in the namespace. You may collect CrdbNode owner references and labels as teardown evidence, but do not treat those values as a replacement for a discovered CrdbCluster.
If multiple CrdbCluster rows are returned, choose the target by metadata.name; do not use the Helm release or CockroachDB version as a substitute.
export CRDBCLUSTER="<metadata.name-from-crdbcluster-list>"
test -n "$CRDBCLUSTER"
kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o yaml > "$CRDB_TLS_DIR/crdbcluster.yaml"
kubectl -n "$CRDB_NAMESPACE" get crdbcluster "$CRDBCLUSTER" -o json > "$CRDB_TLS_DIR/crdbcluster.json"
export CRDBCLUSTER_API_VERSION="$(jq -r '.apiVersion | split("/")[-1]' "$CRDB_TLS_DIR/crdbcluster.json")"
export CRDBCLUSTER_SCHEMA_JSON="$CRDB_TLS_DIR/crdbcluster-schema.json"
jq -e --arg version "$CRDBCLUSTER_API_VERSION" '
.spec.versions[] | select(.name == $version) | .schema.openAPIV3Schema
' "$CRDB_TLS_DIR/crdbclusters-crd.json" > "$CRDBCLUSTER_SCHEMA_JSON"
crdb_schema_has() {
jq -e --arg path "$1" '
def has_schema_path($schema; $parts):
if ($parts | length) == 0 then true
elif (($schema.properties? // {}) | has($parts[0])) then
has_schema_path($schema.properties[$parts[0]]; $parts[1:])
else false
end;
has_schema_path(.; $path | split("."))
' "$CRDBCLUSTER_SCHEMA_JSON" >/dev/null
}
crdb_first_schema_path() {
for schema_path in "$@"; do
if crdb_schema_has "$schema_path"; then
printf '%s\n' "$schema_path"
return 0
fi
done
printf '\n'
}
export CRDB_CERTIFICATES_PATH="$(crdb_first_schema_path spec.template.spec.certificates spec.certificates)"
jq --arg certificatesPath "$CRDB_CERTIFICATES_PATH" '
def value($path): if $path == "" then null else getpath($path | split(".")) end;
{apiVersion, name: .metadata.name, certificatesPath: $certificatesPath, certificates: value($certificatesPath)}
' "$CRDB_TLS_DIR/crdbcluster.json"
kubectl -n "$CRDB_NAMESPACE" get secret,configmap | grep -E 'cockroach|crdb'
kubectl -n "$CRDB_NAMESPACE" get podsFor self-signer, confirm the self-signer job ran and the generated CA, node, and client resources exist. For cert-manager, confirm Certificate resources are Ready. For external certificates, confirm the CrdbCluster references the expected names.
Use this section when pods report x509 errors, certificate rotation is not reflected in pods, the cert-reloader sidecar fails, or TSC asks for certificate evidence. Collect metadata only; do not print private keys.
jq --arg certificatesPath "$CRDB_CERTIFICATES_PATH" '
def value($path): if $path == "" then null else getpath($path | split(".")) end;
{apiVersion, name: .metadata.name, certificatesPath: $certificatesPath, certificates: value($certificatesPath)}
' "$CRDB_TLS_DIR/crdbcluster.json"
kubectl -n "$CRDB_NAMESPACE" get secret,configmap | grep -E 'ca|node|client|tls|cert|cockroach|crdb'
kubectl -n "$CRDB_NAMESPACE" get pod <pod-name> -o jsonpath='{.spec.containers[*].name}{"\n"}'
kubectl -n "$CRDB_NAMESPACE" logs <pod-name> -c cert-reloader --tail=100Inspect the node certificate:
kubectl -n <namespace> get secret <node-tls-secret> -o jsonpath='{.data.tls\.crt}' | base64 -d | \
openssl x509 -noout -dates -subject -issuer -ext subjectAltNameInspect cert-manager resources, if cert-manager is used:
kubectl -n <namespace> get certificate,issuer -o wide
kubectl get clusterissuer -o wide 2>/dev/null || true
kubectl -n <namespace> describe certificate <certificate-name>
kubectl -n <namespace> describe issuer <issuer-name>If the CockroachDB image does not include network or OpenSSL tooling, use an approved debug image according to the customer's policy. In air-gapped environments, mirror the approved image into the customer's registry and use that registry path instead of pulling a public image directly.
kubectl -n <namespace> debug <pod-name> --image=<approved-network-debug-image> --target=cockroachdb -it -- \
openssl s_client -connect <pod-ip>:26257 \
-CAfile /cockroach/cockroach-certs/ca.crt \
-cert /cockroach/cockroach-certs/node.crt \
-key /cockroach/cockroach-certs/node.keyFor full in-pod certificate metadata:
kubectl -n <namespace> debug <pod-name> --image=<approved-network-debug-image> --target=cockroachdb -it -- bash -c '
for DIR in /cockroach/cockroach-certs /certs /cockroach-certs; do
if [ -d "$DIR" ]; then
echo "=== Cert directory: $DIR ==="
ls -la "$DIR" 2>/dev/null
for CERT in "$DIR"/*.crt; do
if [ -f "$CERT" ]; then
echo "--- $CERT ---"
openssl x509 -in "$CERT" -noout -subject -issuer -dates -ext subjectAltName 2>&1
fi
done
fi
done'Escalate with collecting-cockroachdb-operator-escalation-packet if certificates look correct but pods still cannot join, rotate, or become Ready.
| Symptom | Likely Cause | Action |
|---|---|---|
Exactly one of selfSigner, certManager or externalCertificates must be enabled when TLS is on | Multiple or zero providers enabled | Set exactly one provider true |
selfSigner, certManager and externalCertificates must all be disabled when TLS is off | Provider enabled while TLS disabled | Disable all providers or enable TLS |
caProvided with empty caSecret | Customer CA mode missing Secret name | Set cockroachdb.tls.selfSigner.caSecret |
| Pods fail with certificate trust errors | CA and issued certs do not match | Verify CA ConfigMap/Secret and regenerate certs from the same CA |
| Cert rotation does not take effect | cert-reloader sidecar issue, stale mounted Secret, or cert-manager failure | Check cert-reloader logs, cert-manager Certificate status, and node cert expiry/SAN metadata |
| Pods fail after migration with TLS errors | Migrated cert resources or CA names do not match operator references | Use the migration debugging skill and verify the CrdbCluster certificate references |
© cockroachdb, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls of cockroachdb/helm-charts.
Open the folder on GitHubat commit 26e44ff
Configuring Cockroachdb Helm Tls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuring Cockroachdb Helm Tls this skillcockroachdb/helm-charts | 105 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Kubeshark Installerkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | |
| Sim Helmsimstudioai/sim | 30k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Helm Chart ScaffoldingCybereason-Public/owLSM | 280 | 13 repos | ~381 | Automated safety check: Pass | GPL-2.0 | |
| NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress | 5.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes SpecialistJeffallan/claude-skills | 12k | 1 repos | ~2.1k | Automated safety check: Pass | MIT |
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
simstudioai/sim
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
Cybereason-Public/owLSM
Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
Jeffallan/claude-skills
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
LukasNiessen/kubernetes-skill
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
cockroachdb/helm-charts
Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…
cockroachdb/helm-charts
Debugs CockroachDB Operator migration scenarios, including Helm StatefulSet to v1beta1 CrdbNode migration and public operator v1alpha1 to v1beta1 migration.
cockroachdb/helm-charts
Guides customer-facing installation of CockroachDB on Kubernetes using the CockroachDB split Helm charts and operator-managed v1beta1 resources.
cockroachdb/helm-charts
Diagnoses failed or unhealthy CockroachDB Helm chart deployments by checking Helm release state, operator health, CrdbCluster and CrdbNode status, pod readiness, RBAC, webhooks, TLS, upgrades…
cockroachdb/helm-charts
Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.
Works with
Categories
Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes. Configuring Cockroachdb Helm Tls is an agent skill from cockroachdb/helm-charts. Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.
Configuring Cockroachdb Helm Tls fits situations like: A customer needs secure CockroachDB Helm values; certificate secret mapping; cert-manager integration; TLS install troubleshooting before deploying the chart.
Run `npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a claude-code`. Or copy the skill folder (skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls in cockroachdb/helm-charts) into .claude/skills/configuring-cockroachdb-helm-tls in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a codex`. Or copy the skill folder (skills/cockroachdb-operations-and-lifecycle/configuring-cockroachdb-helm-tls in cockroachdb/helm-charts) into .agents/skills/configuring-cockroachdb-helm-tls in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cockroachdb/helm-charts --skill configuring-cockroachdb-helm-tls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuring-cockroachdb-helm-tls, .gemini/skills/configuring-cockroachdb-helm-tls, .github/skills/configuring-cockroachdb-helm-tls and .opencode/skills/configuring-cockroachdb-helm-tls in your project.
Going by SKILL.md and its folder, Configuring Cockroachdb Helm Tls needs the command-line tools its instructions call (kubectl, jq, openssl, helm and node). Compatibility (from SKILL.md): CockroachDB Helm v2 charts. Requires Kubernetes Secret or cert-manager access for externally managed certificates. TLS mode must be chosen before initial cluster creation..
SKILL.md names 1 domain. As links in the text: cockroachlabs.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuring Cockroachdb Helm Tls is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Configuring Cockroachdb Helm Tls: Kubeshark Installer (kubeshark/kubeshark, 12k stars), Sim Helm (simstudioai/sim, 30k stars), Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cockroachdb (a GitHub organization) maintains it in cockroachdb/helm-charts, which has 105 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 1, 2026.
Source: cockroachdb/helm-charts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.