Agent skill

Educates Upgrade Vcluster

by educates in educates/educates-training-platform

Upgrade the vcluster software version (and the Kubernetes versions the virtual cluster provisions) used by the vcluster workshop application in session-manager.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Educates Upgrade Vcluster

skills CLI
$ npx skills add educates/educates-training-platform --skill educates-upgrade-vcluster -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install educates/educates-training-platform educates-upgrade-vcluster --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/educates/educates-training-platform.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/educates-upgrade-vcluster .claude/skills/educates-upgrade-vcluster && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
educates-upgrade-vcluster
GitHub stars
161
Token cost
~2.7k tokens
SKILL.md length
1,035 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Upgrade the vcluster software version (and the Kubernetes versions the virtual cluster provisions) used by the vcluster workshop application in session-manager.

  • Works in 4 steps: installer/charts/educates-training-platfo… → session-manager/handlers/operator_config.… → session-manager/handlers/application_vclu… → …
  • Tasks that involve Container orchestration
  • SKILL.md covers Why this is not a one-line bump, The version-state surface (all…, Release-page artifacts and Keeping vcluster and platform…, plus 3 more sections
  • Calls helm, curl and python3; reaches github.com and charts.loft.sh

What it does

Educates Upgrade Vcluster is an agent skill from educates/educates-training-platform. Upgrade the vcluster software version (and the Kubernetes versions the virtual cluster provisions) used by the vcluster workshop application in session-manager. Invoke when asked to "upgrade vcluster", "bump vcluster", "update vcluster to vX.Y.Z", or "align vcluster kubernetes versions".

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes. The repository describes itself as: A platform for hosting interactive workshop environments in Kubernetes, or on top of a local container runtime. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration

Example prompts

  • “upgrade vcluster”
  • “bump vcluster”
  • “update vcluster to vX.Y.Z”
  • “/educates-upgrade-vcluster”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Edit, Glob, Bash, WebFetch

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. installer/charts/educates-training-platform/charts/session-manager/templates/_helpers.tpl
  2. session-manager/handlers/operator_config.py — the
  3. session-manager/handlers/application_vcluster.py — the operator_config
  4. session-manager/packages/vcluster/vcluster-all-config.yaml — the

What it can do on your machine

Read from SKILL.md and the folder at commit a648c25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Glob
    • Bash
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • helm
    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • charts.loft.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Educates Upgrade Vcluster loads about 2.7k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 1,035 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Edit, Glob, Bash, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from educates/educates-training-platform at commit a648c25, republished under its Apache-2.0 licence (© educates). 1,035 words, ~2,731 tokens.

Download SKILL.mdSave it as .claude/skills/educates-upgrade-vcluster/SKILL.md (or your agent's skills folder).
name
educates-upgrade-vcluster
description
Upgrade the vcluster software version (and the Kubernetes versions the virtual cluster provisions) used by the vcluster workshop application in session-manager. Invoke when asked to "upgrade vcluster", "bump vcluster", "update vcluster to vX.Y.Z", or "align vcluster kubernetes versions".
allowed-tools
Read, Edit, Glob, Bash, WebFetch
argument-hint
[<new-vcluster-version>] (e.g. 0.35.2)

Educates vcluster Upgrade Protocol

Upgrade the vcluster workshop application to the vcluster version in $ARGUMENTS (e.g. 0.35.2). With no argument, find the latest stable release at https://github.com/loft-sh/vcluster/releases and confirm the target with the user before proceeding.

This is a runtime-component change (session-manager/). Confirm the scope with the user before starting if it was not explicitly requested.

Why this is not a one-line bump

Educates does not helm install vcluster at runtime. session-manager (session-manager/handlers/application_vcluster.py) deploys each virtual cluster by applying hand-written host-cluster objects and embeds the vcluster config as a Secret (vc-config-my-vcluster, key config.yaml) mounted into the control-plane pod. The StatefulSet, Services, and RBAC in that file are hand-maintained transcriptions of what the upstream vcluster Helm chart renders. Nothing regenerates them, so a version bump means re-rendering the chart and reconciling those objects by hand, preserving Educates' own customizations. Since vcluster 0.20 the k8s distro runs in-process inside the single syncer container (no separate apiserver/etcd Deployment); an init container stages the Kubernetes binaries from the loftsh-kubernetes image.

vcluster's Helm chart version equals its app/binary version (chart 0.35.2 ships vcluster 0.35.2), unlike the cluster-service charts. There is no separate appVersion to resolve.

The version-state surface (all must move together)

  1. installer/charts/educates-training-platform/charts/session-manager/templates/_helpers.tpl — the imageVersions inventory: loftsh-vcluster (ghcr.io/loft-sh/vcluster-oss:<ver> — Educates uses the OSS variant), the loftsh-kubernetes-v1.NN image set, and vcluster-internal-contour / vcluster-internal-envoy (the Contour/Envoy used only when a workshop enables vcluster ingress). The air-gap image list flows from here automatically via hack/generate-image-list.sh — no separate edit.
  2. session-manager/handlers/operator_config.py — the LOFTSH_KUBERNETES_V1_NN_IMAGE = image_reference(...) constants and LOFTSH_VCLUSTER_IMAGE (the latter is version-agnostic; it resolves through the inventory).
  3. session-manager/handlers/application_vcluster.py — the operator_config imports, the K8S_VERSIONS map, and K8S_DEFAULT_VERSION, plus the embedded StatefulSet / Service / RBAC objects (see reconciliation below).
  4. session-manager/packages/vcluster/vcluster-all-config.yaml — the upstream chart values.yaml, copied verbatim (with comments) for the target tag. session-manager loads it, applies a handful of Educates overrides, and ships it as the config Secret. Update the version pin in its 3-line header.

Release-page artifacts

From https://github.com/loft-sh/vcluster/releases/tag/v<VER>:

  • images-optional.txt — the authoritative list of the OSS vcluster image and every optional Kubernetes version the release supports (ghcr.io/loft-sh/kubernetes:v1.NN.p), plus etcd/coredns variants. This is where the supported k8s set and the exact patch versions come from.
  • images.txt — the default images: the vcluster-pro image, the default k8s version (the newest, not in images-optional.txt), and the default coredns.
  • vcluster-images-v1.NN.txt (per-k8s-version) — the full image set for full air-gap support of that k8s version (etcd, coredns, kine, etc.). Out of scope for a version bump, but note it for the air-gap follow-up.

Together, images.txt (default k8s) + images-optional.txt (optional k8s) define the full supported Kubernetes range for the release.

bash
curl -sSfL https://github.com/loft-sh/vcluster/releases/download/v<VER>/images-optional.txt
curl -sSfL https://github.com/loft-sh/vcluster/releases/download/v<VER>/images.txt

Keeping vcluster and platform Kubernetes versions aligned

The set of Kubernetes versions the vcluster application provisions (K8S_VERSIONS) should match the platform's supported Kubernetes versions (the kubectl / kind set managed by the educates-upgrade-kubernetes skill), as long as vcluster's images-optional.txt (plus the default in images.txt) lists them. K8S_DEFAULT_VERSION should match DefaultKubernetesVersion in client-programs/pkg/constants/kubernetes.go.

When you run this skill:

  1. Read the platform's current set from pkg/constants/kubernetes.go (KubernetesVersionToKindImage, DefaultKubernetesVersion).
  2. Intersect it with what the target vcluster release supports (images.txt + images-optional.txt). If a platform version is not supported by this vcluster release, stop and ask the user how to reconcile (hold vcluster back, or drop that k8s version platform-wide).
  3. If the two sets already match and are supported, align K8S_VERSIONS to them. If they diverge, ask the user for permission to run educates-upgrade-kubernetes to bring the platform set in line (or to accept a deliberate divergence), rather than silently picking one.

The educates-upgrade-kubernetes skill carries the reciprocal reminder.

Show full SKILL.md (520 more words)Show less

Step-by-step

  1. Resolve versions. Read images-optional.txt + images.txt. Confirm the vcluster-oss:<VER> tag and the exact loftsh-kubernetes:v1.NN.p patch tags for the k8s set you will support. Reconcile with the platform set (above).

  2. Update the four version-state files (inventory, constants, handler map + default, values file). Re-copy vcluster-all-config.yaml from https://github.com/loft-sh/vcluster/blob/v<VER>/chart/values.yaml and update its header pin. Fold in any new config sub-trees the new values file introduces.

  3. Render the chart with Educates' effective config and reconcile the embedded objects:

    bash
    helm repo add loft https://charts.loft.sh && helm repo update loft
    # overrides.yaml = the sync toggles application_vcluster.py sets at runtime,
    # because they change the generated RBAC:
    cat > overrides.yaml <<'EOF'
    sync:
      toHost:
        serviceAccounts: { enabled: true }
        ingresses: { enabled: true }
      fromHost:
        storageClasses: { enabled: true }
        ingressClasses: { enabled: true }
    policies:
      resourceQuota: { enabled: false }
      limitRange: { enabled: false }
    EOF
    helm template my-vcluster loft/vcluster --version <VER> -n my-vcluster-vc \
      -f session-manager/packages/vcluster/vcluster-all-config.yaml \
      -f overrides.yaml

    Diff the rendered StatefulSet, Services, ClusterRole, and Role against the embedded dicts. Apply the deltas, but preserve Educates' customizations (do not blindly copy the chart):

    • the k8s_image init container and LOFTSH_VCLUSTER_IMAGE syncer image;
    • parametrized resources (syncer_memory / syncer_storage);
    • storageClassName: None on the data volumeClaimTemplate;
    • the pod securityContext storage-group (CLUSTER_STORAGE_GROUP);
    • the non-root syncer securityContext (runAsUser 12345). vcluster's chart may render this container as root (runAsUser 0); keep non-root and validate at runtime. If the control plane misbehaves after the bump, revisit whether non-root is still supported upstream.
  4. Reconcile RBAC (the load-bearing, error-prone step). The embedded ClusterRole/Roles are Educates-curated, not a verbatim chart copy (they add ingressclasses/storageclasses/ingresses/serviceaccounts grants for Educates' sync toggles). Add whatever the new render newly requires (past bumps added pods/resize, pods/ephemeralcontainers, events.k8s.io events, endpointslices create/delete). The -vc namespace Role is the syncer's sync-target Role (it holds pods/status); the session-namespace Role is intentionally narrower. Mirror every added rule into educates-session-manager:vcluster in installer/charts/educates-training-platform/charts/session-manager/templates/clusterroles.yaml — Kubernetes privilege-escalation prevention means session-manager can only create the per-session Roles if it already holds every permission they grant, so that ClusterRole must stay a superset. Under-granting shows up at runtime as a 403 "attempting to grant RBAC permissions not currently held" when a vcluster session is created.

  5. Release note + docs. Add a Features Changed entry to the current project-docs/release-notes/version-<X.Y.Z>.md (vcluster version + the k8s set change). Review project-docs for anything that names the vcluster or k8s versions. No emdashes.

Verify

bash
python3 -c "import ast; ast.parse(open('session-manager/handlers/application_vcluster.py').read())"
# Re-render and confirm the embedded StatefulSet/Services/RBAC match the chart
# output (modulo the preserved Educates customizations listed above).

The authoritative check is a runtime smoke test: deploy a workshop whose session.applications.vcluster.enabled: true, confirm the control-plane pod reaches Ready, the kubeconfig Secret is copied into the session, and kubectl against the virtual cluster works. Exercise a workshop that syncs services / ingresses so the reconciled RBAC is actually hit.

Post-upgrade checklist

  • _helpers.tpl inventory: loftsh-vcluster (oss) + loftsh-kubernetes-v1.NN set updated (exact patch tags from images-optional.txt / images.txt)
  • operator_config.py constants match the inventory names
  • application_vcluster.py: imports, K8S_VERSIONS, K8S_DEFAULT_VERSION updated
  • K8S_VERSIONS aligned with the platform set (pkg/constants/kubernetes.go), or divergence agreed with the user
  • vcluster-all-config.yaml re-copied from the tag + header pin updated
  • Embedded StatefulSet / Services reconciled against the render, Educates customizations preserved
  • Embedded RBAC reconciled AND mirrored into educates-session-manager:vcluster (clusterroles.yaml)
  • Non-root syncer securityContext kept + flagged for runtime validation
  • Release note added; project-docs reviewed
  • application_vcluster.py parses; chart re-render matches; runtime vcluster workshop smoke-tested
  • Air-gap follow-up noted (per-k8s-version image txt files) if full air-gap is in scope

© educates, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/educates-upgrade-vcluster of educates/educates-training-platform.

Open the folder on GitHubat commit a648c25

Compare with similar skills

Educates Upgrade Vcluster next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Educates Upgrade Vcluster compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Educates Upgrade Vcluster this skilleducates/educates-training-platform161—~2.7kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k1 repos~3.1kAutomated safety check: PassCustom licence
Azure Diagnosticsmicrosoft/azure-skills1.5k1 repos~1.6kAutomated safety check: PassMIT
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0

Similar skills

  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed
  • Azure Diagnostics

    microsoft/azure-skills

    Official

    Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

    1.5k GitHub starsUsed in 1 repo~1.6k tokens
    DevOps & CloudAuto-check passed
  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from educates/educates-training-platform

  • Educates Git Workflow

    educates/educates-training-platform

    Drives the Educates project's Gitflow-based branch and release workflow.

    161 GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check passed
  • Educates Release Notes

    educates/educates-training-platform

    Create release notes for an Educates version. An agent skill from educates/educates-training-platform.

    161 GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check: notes
  • Educates Upgrade Cluster Services

    educates/educates-training-platform

    Upgrade a vendored upstream cluster-service Helm chart the Educates operator installs for EducatesClusterConfig — cert-manager, Contour, Kyverno, or external-dns.

    161 GitHub stars~3.2k tokensUpdated 5 days ago
    Auto-check: notes
  • Educates Upgrade Go

    educates/educates-training-platform

    Upgrade the Go version across the entire educates-training-platform project.

    161 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check: notes
  • Educates Upgrade Kubernetes

    educates/educates-training-platform

    Upgrade Kubernetes version support across the educates-training-platform project.

    161 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check: notes
  • Educates Upgrade Theme Libraries

    educates/educates-training-platform

    Upgrade the vendored third-party frontend libraries bundled into the Educates workshop dashboard theme (Bootstrap, Font Awesome, jQuery, Underscore.js, JSONForm, js-yaml).

    161 GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check: notes

Works with

Categories

Questions about Educates Upgrade Vcluster

What does Educates Upgrade Vcluster do?

Upgrade the vcluster software version (and the Kubernetes versions the virtual cluster provisions) used by the vcluster workshop application in session-manager. Educates Upgrade Vcluster is an agent skill from educates/educates-training-platform. Upgrade the vcluster software version (and the Kubernetes versions the virtual cluster provisions) used by the vcluster workshop application in session-manager.

When should I use Educates Upgrade Vcluster?

Educates Upgrade Vcluster fits situations like: tasks that involve Container orchestration.

How do I install Educates Upgrade Vcluster in Claude Code?

Run `npx skills add educates/educates-training-platform --skill educates-upgrade-vcluster -a claude-code`. Or copy the skill folder (.claude/skills/educates-upgrade-vcluster in educates/educates-training-platform) into .claude/skills/educates-upgrade-vcluster in your project. Claude Code loads it when a task matches its description.

How do I install Educates Upgrade Vcluster in Codex?

Run `npx skills add educates/educates-training-platform --skill educates-upgrade-vcluster -a codex`. Or copy the skill folder (.claude/skills/educates-upgrade-vcluster in educates/educates-training-platform) into .agents/skills/educates-upgrade-vcluster in your project. Codex loads it when a task matches its description.

Can I use Educates Upgrade Vcluster in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add educates/educates-training-platform --skill educates-upgrade-vcluster -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/educates-upgrade-vcluster, .gemini/skills/educates-upgrade-vcluster, .github/skills/educates-upgrade-vcluster and .opencode/skills/educates-upgrade-vcluster in your project.

What does Educates Upgrade Vcluster need to run?

Going by SKILL.md and its folder, Educates Upgrade Vcluster needs the command-line tools its instructions call (helm, curl and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Edit, Glob, Bash, WebFetch.

Does Educates Upgrade Vcluster access the network?

SKILL.md names 2 domains. In commands or code: github.com and charts.loft.sh; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Educates Upgrade Vcluster safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Educates Upgrade Vcluster use?

Educates Upgrade Vcluster is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Educates Upgrade Vcluster use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Educates Upgrade Vcluster?

Skills that share tags, products or a category with Educates Upgrade Vcluster: KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Azure Diagnostics (microsoft/azure-skills, 1.5k stars), Kubeshark Installer (kubeshark/kubeshark, 12k stars) and Sim Helm (simstudioai/sim, 30k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Educates Upgrade Vcluster?

educates (a GitHub organization) maintains it in educates/educates-training-platform, which has 161 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 3, 2026.

Source: educates/educates-training-platform on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.