Kubeshark KFL2 Filter Reference
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses.
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edge --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .claude/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fastly-wildcard-subdomain-compute-edge" agent skill from https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edge into .claude/skills/fastly-wildcard-subdomain-compute-edge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fastly-wildcard-subdomain-compute-edge", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edgeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edge --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .agents/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fastly-wildcard-subdomain-compute-edge" agent skill from https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edge into .agents/skills/fastly-wildcard-subdomain-compute-edge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fastly-wildcard-subdomain-compute-edge", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edge --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .cursor/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fastly-wildcard-subdomain-compute-edge" agent skill from https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edge into .cursor/skills/fastly-wildcard-subdomain-compute-edge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fastly-wildcard-subdomain-compute-edge", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/divinevideo/divine-mobile.git --path .agents/skills/fastly-wildcard-subdomain-compute-edge--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edge --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .gemini/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fastly-wildcard-subdomain-compute-edge" agent skill from https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edge into .gemini/skills/fastly-wildcard-subdomain-compute-edge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fastly-wildcard-subdomain-compute-edge", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edgeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .github/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fastly-wildcard-subdomain-compute-edge" agent skill from https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edge into .github/skills/fastly-wildcard-subdomain-compute-edge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fastly-wildcard-subdomain-compute-edge", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edge --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .opencode/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fastly-wildcard-subdomain-compute-edge" agent skill from https://github.com/divinevideo/divine-mobile/tree/main/.agents/skills/fastly-wildcard-subdomain-compute-edge into .opencode/skills/fastly-wildcard-subdomain-compute-edge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fastly-wildcard-subdomain-compute-edge", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fastly-wildcard-subdomain-compute-edgeFix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses.
Fastly Wildcard Subdomain Compute Edge is an agent skill from divinevideo/divine-mobile. Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses. Use when: (1) TLS subscription "issued" but edge serves default certificate (CN=j.sni-644-default), (2) Fastly domain-v1 create succeeds but subdomain returns 500, (3) Static publisher/PublisherServer returns empty content for subdomain requests, (4) DNS wildcard CNAME resolves to wrong target. Covers TLS configuration SNI endpoint selection (x.sni vs j.sni vs w.sni), DNS…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The licence is MPL-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c3d6f7e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqopensslFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.fastly.comAlso links to:
fastly.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FASTLY_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fastly Wildcard Subdomain Compute Edge loads about 2.1k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 436 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from divinevideo/divine-mobile at commit c3d6f7e, republished under its MPL-2.0 licence (© divinevideo). 436 words, ~2,133 tokens.
.claude/skills/fastly-wildcard-subdomain-compute-edge/SKILL.md (or your agent's skills folder).Wildcard subdomains (*.example.com) don't work on Fastly Compute@Edge services even after:
fastly domain-v1 createSymptoms include:
Wrong SNI endpoint: TLS certificate is "issued" but edge serves default certificate
(CN=j.sni-644-default.ssl.fastly.net instead of your domain).
CRITICAL: The TLS configuration name tells you which SNI endpoint to use:
x.sni.global.fastly.net.w.sni.global.fastly.net.j.sni.global.fastly.net.Check your TLS configuration:
FASTLY_KEY=$(fastly profile token) && curl -s -H "Fastly-Key: $FASTLY_KEY" \
"https://api.fastly.com/tls/configurations" | jq '.data[] | {id: .id, name: .attributes.name}'Verify by connecting directly to the correct endpoint:
echo | openssl s_client -servername subdomain.yourdomain.com \
-connect x.sni.global.fastly.net:443 2>/dev/null | openssl x509 -noout -subjectDNS trailing dot issue: CNAME records resolve to target.com.yourdomain.com instead
of target.com because the DNS provider appends the zone name without a trailing dot.
Check with: dig @ns-server *.yourdomain.com CNAME +short
Bad: x.sni.global.fastly.net.yourdomain.com.
Good: x.sni.global.fastly.net.
Domain not activated: Fastly domain-v1 shows "activated": false, "verified": false
even after DNS is set up.
Check with:
curl -s -H "Fastly-Key: $(fastly profile token)" \
"https://api.fastly.com/domain-management/v1/domains/DOMAIN_ID" | jqPublisherServer returns empty for subdomains: The @fastly/compute-js-static-publish
PublisherServer returns null/empty responses when the request hostname is a subdomain,
even though it works for the apex domain and edgecompute.app URL.
Wildcard CNAME with trailing dot (check your TLS config for correct SNI endpoint):
Name: *
Type: CNAME
Value: x.sni.global.fastly.net. <- Use endpoint from your TLS config name (x.sni, w.sni, or j.sni)ACME challenge CNAME with trailing dot (for TLS validation):
Name: _acme-challenge
Type: CNAME
Value: CHALLENGE_VALUE.fastly-validations.com. <- MUST include trailing dotAlternative: Use A records instead of CNAME (avoids trailing dot issues):
Name: *
Type: A
Values: 151.101.1.242, 151.101.65.242, 151.101.129.242, 151.101.193.242If domain shows activated: false even after DNS is correct:
# 1. Delete TLS subscription first (if exists)
fastly tls-subscription delete --id SUBSCRIPTION_ID --force
# 2. Delete the domain
fastly domain-v1 delete --domain-id DOMAIN_ID
# 3. Recreate domain
fastly domain-v1 create --fqdn "*.yourdomain.com" --service-id SERVICE_ID
# 4. Create new TLS subscription
fastly tls-subscription create --domain "*.yourdomain.com"
# 5. Wait 1-5 minutes for verification and TLS issuanceThe PublisherServer from @fastly/compute-js-static-publish doesn't serve content for
subdomain hostnames. You must read from the KV store directly:
if (subdomain) {
// Open the content KV store
const contentStore = new KVStore('your-content-store-name');
// Read the index file - NOTE: collection name might be 'undefined' not 'default'
const indexEntry = await contentStore.get('default_index_undefined');
const indexData = await indexEntry.json();
// Get the index.html entry - structure is { '/path': { key: 'sha256:HASH', ... } }
const indexHtmlInfo = indexData['/index.html'];
// Read the actual content
const contentHash = indexHtmlInfo.key.replace('sha256:', '');
const contentKey = `default_files_sha256_${contentHash}`;
const htmlEntry = await contentStore.get(contentKey);
const html = await htmlEntry.text();
// Inject subdomain-specific data and return
const modifiedHtml = html.replace('<head>', `<head><script>window.SUBDOMAIN_DATA = {...}</script>`);
return new Response(modifiedHtml, {
headers: { 'Content-Type': 'text/html; charset=utf-8' }
});
}The static publisher uses these KV key formats:
${publishId}_index_${collectionName} (e.g., default_index_undefined)${publishId}_settings_${collectionName}${publishId}_files_sha256_${hash}To discover your actual key names:
curl -s -H "Fastly-Key: $(fastly profile token)" \
"https://api.fastly.com/resources/stores/kv/STORE_ID/keys?limit=50" | jq '.data[]' | grep index# 1. Verify DNS is correct
dig @8.8.8.8 subdomain.yourdomain.com A +short
# Should return Fastly IPs
# 2. Verify domain is activated
curl -s -H "Fastly-Key: $(fastly profile token)" \
"https://api.fastly.com/domain-management/v1/domains/DOMAIN_ID" | jq '{activated, verified}'
# Both should be true
# 3. Verify TLS is issued
fastly tls-subscription list | grep yourdomain
# State should be "issued"
# 4. Test the subdomain
curl -sI "https://subdomain.yourdomain.com"
# Should return 200 with contentComplete fix for *.divine.space subdomain routing:
// In Compute@Edge handler
if (subdomain && namesStore) {
const entry = await namesStore.get(`name:${subdomain}`);
const contentStore = new KVStore('divine-space-content');
const indexEntry = await contentStore.get('default_index_undefined');
const indexData = await indexEntry.json();
const indexHtmlInfo = indexData['/index.html'];
const contentHash = indexHtmlInfo.key.replace('sha256:', '');
const htmlEntry = await contentStore.get(`default_files_sha256_${contentHash}`);
const html = await htmlEntry.text();
if (entry) {
const data = await entry.json();
const injectedHtml = html.replace('<head>', `<head>
<script>window.__DIVINE_SPACE_USER__ = {
subdomain: "${subdomain}",
pubkey: "${data.pubkey}"
};</script>`);
return new Response(injectedHtml, {
headers: { 'Content-Type': 'text/html; charset=utf-8' }
});
}
}collectionName in KV keys is often undefined (literal string) rather than
default due to how the static publisher is configured. Always check actual keys.fastly purge --all after changes.© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/fastly-wildcard-subdomain-compute-edge of divinevideo/divine-mobile.
Open the folder on GitHubat commit c3d6f7e
Fastly Wildcard Subdomain Compute Edge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fastly Wildcard Subdomain Compute Edge this skilldivinevideo/divine-mobile | 266 | — | ~2.1k | Automated safety check: Pass | MPL-2.0 | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Nginx To Higress Migrationhigress-group/higress | 9.5k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Rustpgdogdev/pgdog | 5.6k | — | ~1.9k | Automated safety check: Notes | AGPL-3.0 | |
| Bfe Rd Workflowbfenetworks/bfe | 6.3k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress | 5.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
higress-group/higress
Migrate from ingress-nginx to Higress in Kubernetes environments.
pgdogdev/pgdog
Rust coding best practices for idiomatic, efficient, and maintainable code.
bfenetworks/bfe
引导用户在 bfe 代码库中完成一次完整的功能研发流程,包括需求对齐、文档修改、代码实现、集成测试与回归验证. An agent skill from bfenetworks/bfe.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
divinevideo/divine-mobile
Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".
divinevideo/divine-mobile
Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.
divinevideo/divine-mobile
Fix "Null check operator used on a null value" errors when an object is set to null during an async await.
divinevideo/divine-mobile
Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.
divinevideo/divine-mobile
Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.
divinevideo/divine-mobile
Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).
Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses. Fastly Wildcard Subdomain Compute Edge is an agent skill from divinevideo/divine-mobile. Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses.
Fastly Wildcard Subdomain Compute Edge fits situations like: TLS subscription issued but edge serves default certificate (CN=j.sni-644-default); fastly domain-v1 create succeeds but subdomain returns 500; static publisher/PublisherServer returns empty content for subdomain requests; DNS wildcard CNAME resolves to wrong target.
Run `npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a claude-code`. Or copy the skill folder (.agents/skills/fastly-wildcard-subdomain-compute-edge in divinevideo/divine-mobile) into .claude/skills/fastly-wildcard-subdomain-compute-edge in your project. Claude Code loads it when a task matches its description.
Run `npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a codex`. Or copy the skill folder (.agents/skills/fastly-wildcard-subdomain-compute-edge in divinevideo/divine-mobile) into .agents/skills/fastly-wildcard-subdomain-compute-edge in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fastly-wildcard-subdomain-compute-edge, .gemini/skills/fastly-wildcard-subdomain-compute-edge, .github/skills/fastly-wildcard-subdomain-compute-edge and .opencode/skills/fastly-wildcard-subdomain-compute-edge in your project.
Going by SKILL.md and its folder, Fastly Wildcard Subdomain Compute Edge needs the command-line tools its instructions call (curl, jq and openssl) and credentials named FASTLY_KEY. Our summary lists: A credential in FASTLY_KEY.
SKILL.md names 2 domains. In commands or code: api.fastly.com; the agent is likely to contact it when it follows the instructions. As links in the text: fastly.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fastly Wildcard Subdomain Compute Edge is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fastly Wildcard Subdomain Compute Edge: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Rust (pgdogdev/pgdog, 5.6k stars) and Bfe Rd Workflow (bfenetworks/bfe, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 10, 2026.
Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.