Product Full-Text Search
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
Diagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation.
$ npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills elasticsearch-cluster-health --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-cluster-health .claude/skills/elasticsearch-cluster-health && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "elasticsearch-cluster-health" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-health into .claude/skills/elasticsearch-cluster-health/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-cluster-health", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-healthType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills elasticsearch-cluster-health --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-cluster-health .agents/skills/elasticsearch-cluster-health && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "elasticsearch-cluster-health" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-health into .agents/skills/elasticsearch-cluster-health/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-cluster-health", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills elasticsearch-cluster-health --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-cluster-health .cursor/skills/elasticsearch-cluster-health && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "elasticsearch-cluster-health" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-health into .cursor/skills/elasticsearch-cluster-health/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-cluster-health", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/elasticsearch/elasticsearch-cluster-health--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills elasticsearch-cluster-health --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-cluster-health .gemini/skills/elasticsearch-cluster-health && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "elasticsearch-cluster-health" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-health into .gemini/skills/elasticsearch-cluster-health/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-cluster-health", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills elasticsearch-cluster-healthInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-cluster-health .github/skills/elasticsearch-cluster-health && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-cluster-health" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-health into .github/skills/elasticsearch-cluster-health/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-cluster-health", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills elasticsearch-cluster-health --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-cluster-health .opencode/skills/elasticsearch-cluster-health && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-cluster-health" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-cluster-health into .opencode/skills/elasticsearch-cluster-health/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-cluster-health", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
elasticsearch-cluster-healthDiagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation.
Elasticsearch Cluster Health is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Diagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation. Use when an operator reports yellow or red status, unassigned shards, allocation failures, or wants read-only triage before deeper investigation. Teaches replica-vs-primary impact, allocation decider classification, and data-loss awareness.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Elasticsearch 8.x or 9.x, self-managed or Elastic Cloud Hosted; not applicable to Elastic Cloud Serverless, where cluster, shard, and allocation APIs are…
It sits in Backend & APIs, covering Search implementation. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Elasticsearch 8.x or 9.x, self-managed or Elastic Cloud Hosted; not applicable to Elastic Cloud Serverless, where cluster, shard, and allocation APIs are managed internally. Requires the `elastic` CLI ≥ 0.2 with `stack es` support.
From compatibility in the SKILL.md frontmatter.
Elasticsearch Cluster Health loads about 3.3k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 1,247 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,247 words, ~3,302 tokens.
.claude/skills/elasticsearch-cluster-health/SKILL.md (or your agent's skills folder).Triage a non-green Elasticsearch cluster read-only: localize the problem, classify the allocation decider, and report the single most likely cause with remediation. Never mutate cluster state — surface findings and let the operator act.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
Read the overall status. Call GET /_cluster/health. The status field is the verdict:
green — every primary and replica is assigned. Report healthy and stop.yellow — every primary is assigned but at least one replica is not. Data remains readable; redundancy is
degraded. This is not data loss.red — at least one primary is unassigned. Data for that shard is unavailable; treat as urgent.Also read unassigned_shards, initializing_shards, and relocating_shards. The decision: continue only when
status is yellow or red. If initializing_shards > 0 and unassigned_shards == 0, the cluster is recovering on its
own — call GET /_cat/recovery to confirm progress, wait, and re-check GET /_cluster/health before escalating.
Data needed: cluster-wide status and shard counters.
Localize the problem to one index. Call GET /_cluster/health?level=indices and pick the index that drives the
cluster-wide status:
unassigned_shards..security, .kibana*, .fleet-*) outranks application indices because the rest of the
stack depends on it.Optionally call GET /_cat/shards/{index}?h=index,shard,prirep,state,unassigned.reason to list every unassigned
shard on that index and see whether failures are primaries (prirep=p) or replicas (prirep=r).
The decision: focus the next steps on exactly one index — the one whose recovery unblocks the cluster.
Data needed: per-index status and unassigned_shards; shard role (primary vs replica) when available.
Separate trigger from root cause. Call POST /_cluster/allocation/explain with no body so Elasticsearch selects
an unassigned shard, or target the worst shard explicitly:
{ "index": "<index>", "shard": <id>, "primary": <true|false> }Read these fields in order:
primary — false means a replica is unassigned (typical yellow); true means a primary is unassigned
(typical red).can_allocate — top-level allocation verdict (no, yes, throttled, no_valid_shard_copy, …).unassigned_info.reason — what triggered reassignment (e.g. NODE_LEFT, INDEX_CREATED). This is not the
root cause when can_allocate is no; it only explains why the shard became unassigned.allocate_explanation — human-readable summary; quote it verbatim in the report.node_allocation_decisions[].deciders[] — per-node decider results. Find deciders with decision: "NO"; the
decider name (e.g. disk_threshold, filter, awareness) is the root cause class.The decision:
primary: false — impact is limited to replica redundancy; no data loss. Continue to step 4 to name
the blocking decider (do not stop at NODE_LEFT).primary: true — data for that shard is missing. Continue to step 4; if can_allocate is
no_valid_shard_copy, treat as potential data loss immediately.Data needed: allocation-explain response for one representative unassigned shard on the chosen index.
Classify the decider. Map the blocking signal to a cause class. Prefer the decider with decision: "NO" over the
unassigned_info.reason trigger.
| Signal | Cause class | Typical remediation (operator applies) |
|---|---|---|
decider: disk_threshold, decision: NO | Disk high/low watermark exceeded | Free disk on the named node, add data-node capacity, or adjust cluster.routing.allocation.disk.watermark.* after confirming usage via GET /_cat/allocation |
decider: filter or decider: awareness, decision: NO | Allocation filtering or zone awareness | Add a node that satisfies index.routing.allocation.* / awareness attributes, or adjust index/cluster allocation settings |
decider: throttling or recovery in progress | Transient recovery | Wait; monitor GET /_cat/recovery and re-check GET /_cluster/health |
can_allocate: no_valid_shard_copy (often with empty node_allocation_decisions) | No surviving shard copy | See step 5 — data loss scenario |
can_allocate: yes but shard still unassigned | Delayed allocation or cluster state catch-up | Check unassigned_info.at delay; wait and re-check |
For disk pressure (common yellow scenario after NODE_LEFT): replicas relocate to remaining nodes; if a survivor is
above the high watermark (cluster.routing.allocation.disk.watermark.high, default 90%), the disk_threshold
decider blocks replica allocation even though primaries stay assigned. The fix is disk capacity or watermark relief —
not deleting the index or forcing an empty primary.
Data needed: decider name, explanation text, and affected node names from node_allocation_decisions.
Recommend remediation — read-only triage ends here. Report the single most likely cause (decider class +
verbatim allocate_explanation) and one primary remediation path. Match urgency to color and shard role.
Yellow / replica unassigned (no data loss):
es-node-2), not merely “a node left”.GET /_cat/allocation.allocate_empty_primary, force-allocating over a healthy primary, or
restarting the entire cluster without evidence.Red / primary unassigned with no_valid_shard_copy (data loss risk):
can_allocate: no_valid_shard_copy).POST /_cluster/reroute with allocate_empty_primary — this creates an empty primary
and permanently loses all documents on that shard. State data loss explicitly; never present this as the first
or casual fix.allocate_empty_primary without the
data-loss warning.Self-healing in progress:
Do not execute reroutes, snapshot restores, or settings changes — surface cause and remediation only.
unassigned_info.reason: NODE_LEFT explains the event; node_allocation_decisions deciders
explain why allocation still fails.primary: false = redundancy gap, not data loss. Red + primary: true = missing
data for that shard.GET /_cat/allocation for disk percentages per node and GET /_cat/recovery for ongoing
recoveries when the decider class is unclear or recovery is in progress.Yellow — disk watermark after node departure. Health shows yellow with unassigned replicas on logs-2025-07.
Allocation explain returns primary: false, unassigned_info.reason: NODE_LEFT, but disk_threshold decider NO on
es-node-2 (“above the high watermark … 90%”). Report: no data loss; root cause is disk pressure on the receiving node;
remediate disk/watermark — not “node left” alone.
Red — primary with no valid copy. Health shows red on orders-2025 with one unassigned shard. Explain returns
primary: true, can_allocate: no_valid_shard_copy, last_allocation_status: no_valid_shard_copy. Report: urgent;
primary data missing; restore node or snapshot; mention allocate_empty_primary only as last resort with explicit data
loss.
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET /_cluster/health | elastic es cluster health |
GET /_cluster/health?level=indices | elastic es cluster health --level indices |
POST /_cluster/allocation/explain | elastic es cluster allocation-explain |
POST /_cluster/allocation/explain (specific shard) | elastic es cluster allocation-explain --index '<index>' --shard <id> --primary true (replica: false) |
GET /_cat/allocation | elastic es cat allocation |
GET /_cat/recovery | elastic es cat recovery |
GET /_cat/shards/{index}?h=index,shard,prirep,state,unassigned.reason | elastic es cat shards --index '<index>' --h index,shard,prirep,state,unassigned.reason |
POST /_cluster/reroute (last-resort empty primary — operator only) | elastic es cluster reroute --commands '<json>' |
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/elasticsearch/elasticsearch-cluster-health of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Elasticsearch Cluster Health next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Elasticsearch Cluster Health this skillelastic/agent-skills | 592 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence | |
| Foundatio Repositoriesexceptionless/Exceptionless | 2.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch Authnaspectrr/deer | 405 | — | ~1.2k | Automated safety check: Notes | MIT | |
| Elasticsearch Authzaspectrr/deer | 405 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Elasticsearch File Ingestaspectrr/deer | 405 | — | ~684 | Automated safety check: Pass | MIT |
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
exceptionless/Exceptionless
Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.
aspectrr/deer
Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.
aspectrr/deer
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.
aspectrr/deer
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
aspectrr/deer
Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Diagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation. Elasticsearch Cluster Health is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Diagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation.
Elasticsearch Cluster Health fits situations like: an operator reports yellow; unassigned shards; allocation failures; wants read-only triage before deeper investigation.
Run `npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-cluster-health in elastic/agent-skills) into .claude/skills/elasticsearch-cluster-health in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-cluster-health in elastic/agent-skills) into .agents/skills/elasticsearch-cluster-health in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-cluster-health -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-cluster-health, .gemini/skills/elasticsearch-cluster-health, .github/skills/elasticsearch-cluster-health and .opencode/skills/elasticsearch-cluster-health in your project.
SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Cluster Health is instructions for the agent only. Compatibility (from SKILL.md): Elasticsearch 8.x or 9.x, self-managed or Elastic Cloud Hosted; not applicable to Elastic Cloud Serverless, where cluster, shard, and allocation APIs are managed internally. Requires the `elastic` CLI ≥ 0.2 with `stack es` support..
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Elasticsearch Cluster Health is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Elasticsearch Cluster Health: Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars), Elasticsearch Authn (aspectrr/deer, 405 stars) and Elasticsearch Authz (aspectrr/deer, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.