Agent skill

Validating Cockroachdb Helm Multiregion

by cockroachdb in cockroachdb/helm-charts

Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.

Apache-2.0Auto-check passedDevOps & Cloud

Install Validating Cockroachdb Helm Multiregion

skills CLI
$ npx skills add cockroachdb/helm-charts --skill validating-cockroachdb-helm-multiregion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cockroachdb/helm-charts validating-cockroachdb-helm-multiregion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cockroachdb/helm-charts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cockroachdb-onboarding-and-migrations/validating-cockroachdb-helm-multiregion .claude/skills/validating-cockroachdb-helm-multiregion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validating-cockroachdb-helm-multiregion
GitHub stars
105
Token cost
~2k tokens
SKILL.md length
722 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.

  • Works in 5 steps: Validate Node Locality Labels → Validate Values File Completeness → Validate Cross-Region DNS and Network… → …
  • Tasks that involve Container orchestration
  • SKILL.md covers When to Use This Skill, Required Inputs, Safety Considerations and Execution Discipline, plus 7 more sections
  • Calls kubectl and helm

What it does

Validating Cockroachdb Helm Multiregion is an agent skill from cockroachdb/helm-charts. Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments. Use before adding a region, deploying CockroachDB across multiple Kubernetes clusters, checking region DNS domains, or confirming that all regions share certificate and networking assumptions.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CockroachDB Helm v2 charts with crdb.cockroachlabs.com/v1beta1 CrdbCluster resources. Requires access to each Kubernetes context participating in the…

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes and Helm. The repository describes itself as: Helm charts for cockroachdb. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration

Example prompts

  • “Use the validating-cockroachdb-helm-multiregion skill to validate CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed…”
  • “/validating-cockroachdb-helm-multiregion”

Requirements

  • Compatibility (from SKILL.md): CockroachDB Helm v2 charts with crdb.cockroachlabs.com/v1beta1 CrdbCluster resources. Requires access to each Kubernetes context participating in the multi-region deployment.

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Validate Node Locality Labels
  2. Validate Values File Completeness
  3. Validate Cross-Region DNS and Network Paths
  4. Validate Certificate Trust Across Regions
  5. Render Before Applying

What it can do on your machine

Read from SKILL.md and the folder at commit 26e44ff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • helm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cockroachlabs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    CockroachDB Helm v2 charts with crdb.cockroachlabs.com/v1beta1 CrdbCluster resources. Requires access to each Kubernetes context participating in the multi-region deployment.

    From compatibility in the SKILL.md frontmatter.

Context cost

Validating Cockroachdb Helm Multiregion loads about 2k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cockroachdb/helm-charts at commit 26e44ff, republished under its Apache-2.0 licence (© cockroachdb). 722 words, ~2,037 tokens.

Download SKILL.mdSave it as .claude/skills/validating-cockroachdb-helm-multiregion/SKILL.md (or your agent's skills folder).
name
validating-cockroachdb-helm-multiregion
description
Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments. Use before adding a region, deploying CockroachDB across multiple Kubernetes clusters, checking region DNS domains, or confirming that all regions share certificate and networking assumptions.
compatibility
CockroachDB Helm v2 charts with crdb.cockroachlabs.com/v1beta1 CrdbCluster resources. Requires access to each Kubernetes context participating in the multi-region deployment.
metadata.author
cockroachdb
metadata.version
1.1

Validating CockroachDB Helm Multi-Region

Validates the high-risk prerequisites for multi-region CockroachDB deployments managed by the Helm v2 charts and operator. Run this before the first region install and before adding every additional region.

When to Use This Skill

  • A customer is deploying CockroachDB across multiple Kubernetes clusters or regions
  • A new region is being added to an existing Helm-managed CockroachDB cluster
  • An agent needs to validate cockroachdb.crdbCluster.regions before helm install or helm upgrade
  • Cross-region DNS, namespace, or certificate assumptions are unclear

Required Inputs

InputExampleWhy It Matters
Region list in deployment orderus-central1, us-east1Each region values file must include current and previously deployed regions
Kubernetes context per regiongke-prod-us-central1Commands must run against the correct cluster
Namespace per regioncockroachdbUsed in generated join addresses
Cluster domain per regioncluster.gke.gcp-us-east1Other regions connect through this domain
CA/certificate modeself-signer with shared CA, cert-manager, externalMulti-region requires compatible trust across regions

Safety Considerations

  • Do not deploy a new region until cross-region service discovery and network paths are proven.
  • Do not use different CA trust roots across regions.
  • Do not omit previously deployed regions from a new region's values file. The operator uses the full list to compute join addresses.
  • Confirm operator.cloudRegion matches the region reconciled by that operator instance.
  • If an existing multi-region cluster cannot join or reconcile, use the deployment diagnostic skill first and collect the operator escalation packet before restarting the operator.

Execution Discipline

  • Execute one step at a time and inspect the output before moving on. Region inventory, DNS results, network results, and certificate state determine which later checks are relevant.
  • Do not infer cross-region service names from the Helm release alone. List Services in the peer namespace and use the actual DNS service name that CockroachDB pods are expected to join.
  • Do not create debug pods, run interactive shells, use external diagnostic images, or perform Helm upgrades unless the user explicitly approves them for each participating cluster.
  • In air-gapped or private-registry environments, use customer-approved diagnostic images mirrored into the customer's registry.
  • In production or when cross-region networking, certificate trust, or locality is unclear, involve TSE or the operator team before adding regions or changing chart values.

Step 1: Validate Node Locality Labels

For each Kubernetes context:

bash
kubectl --context <context> get nodes \
  -L topology.kubernetes.io/region,topology.kubernetes.io/zone

Expected:

  • Every schedulable node has the correct topology.kubernetes.io/region.
  • Nodes are spread across expected zones where zone failure survival is expected.
  • cockroachdb.crdbCluster.regions[].code matches the node region label for that cluster.
Show full SKILL.md (322 more words)Show less

Step 2: Validate Values File Completeness

Each region's values file must include all already deployed regions plus the current region.

Example for deploying us-east1 after us-central1:

yaml
cockroachdb:
  clusterDomain: cluster.gke.gcp-us-east1
  crdbCluster:
    regions:
      - code: us-central1
        nodes: 3
        cloudProvider: gcp
        domain: cluster.gke.gcp-us-central1
        namespace: cockroachdb
      - code: us-east1
        nodes: 3
        cloudProvider: gcp
        domain: cluster.gke.gcp-us-east1
        namespace: cockroachdb

Checklist:

  • cockroachdb.clusterDomain equals the current region's domain.
  • Every previous region appears under cockroachdb.crdbCluster.regions.
  • Every non-local region has domain and namespace set.
  • nodes matches the intended node count in each region.
  • cloudProvider is one of gcp, aws, azure, k3d, or empty for other environments.

Step 3: Validate Cross-Region DNS and Network Paths

From a temporary debugging pod in each region, verify that peer region service names resolve and connect. First discover the peer service name; do not assume it is identical to the Helm release.

bash
kubectl --context <peer-context> -n <peer-namespace> get service,endpoints -o wide
export PEER_SERVICE="<actual-peer-sql-or-public-service-name-from-output>"
test -n "$PEER_SERVICE"
bash
kubectl --context <context> -n <namespace> run crdb-dns-check \
  --rm -it --restart=Never --image=busybox:1.36 -- sh

Inside the pod:

sh
nslookup <peer-service-name>.<peer-namespace>.svc.<peer-domain>
nc -vz <peer-service-name>.<peer-namespace>.svc.<peer-domain> 26258

If nc is unavailable, use an approved network diagnostic image or cloud-native connectivity test. Do not proceed until DNS and TCP connectivity are proven in both directions.

Step 4: Validate Certificate Trust Across Regions

Use configuring-cockroachdb-helm-tls for the selected TLS mode, then apply these multi-region checks:

  • Self-signer with generated CA is appropriate only if the same CA trust material is shared across regions.
  • Self-signer with customer-provided CA requires the same CA Secret in every region namespace.
  • Cert-manager requires issuer configuration that produces certificates trusted by the same CA ConfigMap in every region.
  • External certificate mode requires all node, HTTP, and root client certificates to chain to the same CA trust root.

Check CA presence without printing contents:

bash
kubectl --context <context> -n <namespace> get configmap <ca-configmap> -o jsonpath='{.data.ca\.crt}' >/dev/null
kubectl --context <context> -n <namespace> get secret <ca-secret> >/dev/null

Step 5: Render Before Applying

Use helm template before installing or upgrading each region:

bash
helm template <release-name> cockroachdb-v2/cockroachdb-chart \
  --version <cockroachdb-chart-version> \
  --namespace <namespace> \
  -f values-<region>.yaml > rendered-<region>.yaml

grep -n "regions:" -A30 rendered-<region>.yaml
grep -n "clusterDomain:" -A3 values-<region>.yaml

Confirm the rendered CrdbCluster contains the expected region list and certificate references.

Outputs

Return a preflight report:

  • Region inventory and deployment order
  • Per-context node labels and zone spread
  • Per-region clusterDomain, namespace, and regions completeness
  • Cross-region DNS/TCP results
  • Certificate trust validation result
  • A clear go/no-go recommendation before Helm install or upgrade

References

© cockroachdb, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cockroachdb-onboarding-and-migrations/validating-cockroachdb-helm-multiregion of cockroachdb/helm-charts.

Open the folder on GitHubat commit 26e44ff

Compare with similar skills

Validating Cockroachdb Helm Multiregion next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validating Cockroachdb Helm Multiregion compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validating Cockroachdb Helm Multiregion this skillcockroachdb/helm-charts105—~2kAutomated safety check: PassApache-2.0
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28012 repos~381Automated safety check: PassGPL-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
KubeShark for KubernetesLukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT

Similar skills

  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 12 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 24 days ago
    DevOps & CloudAuto-check passed
  • Nim Operator Install

    NVIDIA/k8s-nim-operator

    Official

    Install NVIDIA NIM Operator on Kubernetes with prerequisite checks, optional NVIDIA GPU Operator dependency installation, public or local Helm chart selection, optional Dynamo support, and optional…

    159 GitHub stars~4.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from cockroachdb/helm-charts

  • Collects a complete CockroachDB Operator escalation packet for TSC/TSE or operator-team handoff, including Helm state, Kubernetes resources, logs, operation-specific evidence, pprof goroutine dumps…

    105 GitHub stars~5.1k tokensUpdated 6 days ago
    Auto-check passed
  • Configuring Cockroachdb Helm Tls

    cockroachdb/helm-charts

    Selects and validates TLS settings for CockroachDB Helm chart deployments, including self-signer, cert-manager, and external certificate modes.

    105 GitHub stars~3.8k tokensUpdated 6 days ago
    Auto-check passed
  • Debugs CockroachDB Operator migration scenarios, including Helm StatefulSet to v1beta1 CrdbNode migration and public operator v1alpha1 to v1beta1 migration.

    105 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check passed
  • Installing Cockroachdb With Helm

    cockroachdb/helm-charts

    Guides customer-facing installation of CockroachDB on Kubernetes using the CockroachDB split Helm charts and operator-managed v1beta1 resources.

    105 GitHub stars~3.4k tokensUpdated 6 days ago
    Auto-check passed
  • Diagnoses failed or unhealthy CockroachDB Helm chart deployments by checking Helm release state, operator health, CrdbCluster and CrdbNode status, pod readiness, RBAC, webhooks, TLS, upgrades…

    105 GitHub stars~6.8k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Validating Cockroachdb Helm Multiregion

What does Validating Cockroachdb Helm Multiregion do?

Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments. Validating Cockroachdb Helm Multiregion is an agent skill from cockroachdb/helm-charts. Validates CockroachDB Helm chart values and Kubernetes prerequisites for operator-managed multi-region deployments.

When should I use Validating Cockroachdb Helm Multiregion?

Validating Cockroachdb Helm Multiregion fits situations like: tasks that involve Container orchestration.

How do I install Validating Cockroachdb Helm Multiregion in Claude Code?

Run `npx skills add cockroachdb/helm-charts --skill validating-cockroachdb-helm-multiregion -a claude-code`. Or copy the skill folder (skills/cockroachdb-onboarding-and-migrations/validating-cockroachdb-helm-multiregion in cockroachdb/helm-charts) into .claude/skills/validating-cockroachdb-helm-multiregion in your project. Claude Code loads it when a task matches its description.

How do I install Validating Cockroachdb Helm Multiregion in Codex?

Run `npx skills add cockroachdb/helm-charts --skill validating-cockroachdb-helm-multiregion -a codex`. Or copy the skill folder (skills/cockroachdb-onboarding-and-migrations/validating-cockroachdb-helm-multiregion in cockroachdb/helm-charts) into .agents/skills/validating-cockroachdb-helm-multiregion in your project. Codex loads it when a task matches its description.

Can I use Validating Cockroachdb Helm Multiregion in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cockroachdb/helm-charts --skill validating-cockroachdb-helm-multiregion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validating-cockroachdb-helm-multiregion, .gemini/skills/validating-cockroachdb-helm-multiregion, .github/skills/validating-cockroachdb-helm-multiregion and .opencode/skills/validating-cockroachdb-helm-multiregion in your project.

What does Validating Cockroachdb Helm Multiregion need to run?

Going by SKILL.md and its folder, Validating Cockroachdb Helm Multiregion needs the command-line tools its instructions call (kubectl and helm). Compatibility (from SKILL.md): CockroachDB Helm v2 charts with crdb.cockroachlabs.com/v1beta1 CrdbCluster resources. Requires access to each Kubernetes context participating in the multi-region deployment..

Does Validating Cockroachdb Helm Multiregion access the network?

SKILL.md names 1 domain. As links in the text: cockroachlabs.com. This is read from the text; nothing was executed.

Is Validating Cockroachdb Helm Multiregion safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validating Cockroachdb Helm Multiregion use?

Validating Cockroachdb Helm Multiregion is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validating Cockroachdb Helm Multiregion use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validating Cockroachdb Helm Multiregion?

Skills that share tags, products or a category with Validating Cockroachdb Helm Multiregion: Sim Helm (simstudioai/sim, 30k stars), Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars), NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars) and Kubernetes Specialist (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validating Cockroachdb Helm Multiregion?

cockroachdb (a GitHub organization) maintains it in cockroachdb/helm-charts, which has 105 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 1, 2026.

Source: cockroachdb/helm-charts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.