Agent skill

Kubernetes

by EliasOulkadi in EliasOulkadi/shokunin

Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…

MITAuto-check: notesDevOps & Cloud

Install Kubernetes

skills CLI
$ npx skills add EliasOulkadi/shokunin --skill kubernetes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EliasOulkadi/shokunin kubernetes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/kubernetes .claude/skills/kubernetes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes
GitHub stars
114
Token cost
~3.3k tokens
SKILL.md length
1,049 words
Files
6 (incl. scripts, references, assets)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…

  • Works in 6 steps: Determine deployment type → Generate manifest → Configure networking → …
  • User asks to write K8s manifests
  • SKILL.md covers Decision Framework, Workflow, Error Handling and Production Checklist, plus 8 more sections
  • Runs Shell scripts from its folder; calls kubectl, helm and docker

What it does

Kubernetes is an agent skill from EliasOulkadi/shokunin. Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security Standards, OPA/Kyverno, seccomp, runtime security with Falco/Tetragon), Helm, HPA, PDB, topology spread, and debugging. Use when user asks to write K8s manifests, deploy to a cluster, debug pods, set up Gateway API, configure autoscaling, or harden cluster security. Do NOT use for Dockerfiles (use docker), CI/CD pipeline…

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `assets/deployment-template.yaml`, `references/gateway-api.md` and `references/service-mesh.md`). Compatibility notes: opencode

It sits in DevOps & Cloud, covering Container orchestration, Deployment and Containers. It works with Kubernetes, Docker and Terraform. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.

When your agent uses it

  • User asks to write K8s manifests
  • Deploy to a cluster
  • Set up Gateway API
  • Configure autoscaling

Example prompts

  • “/kubernetes”

Requirements

  • A Bash shell
  • Docker
  • Compatibility (from SKILL.md): opencode
  • Pre-approved tools (allowed-tools): Read, Bash, Write, Grep, Glob

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Determine deployment type
  2. Generate manifest
  3. Configure networking
  4. Add service mesh (if needed)
  5. Configure autoscaling and resilience
  6. Debug issues

What it can do on your machine

Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Write
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl
    • helm
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, helm and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

Kubernetes loads about 3.3k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 148 tokens; SKILL.md has 1,049 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Write, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 1,049 words, ~3,299 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
kubernetes
description
Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security Standards, OPA/Kyverno, seccomp, runtime security with Falco/Tetragon), Helm, HPA, PDB, topology spread, and debugging. Use when user asks to write K8s manifests, deploy to a cluster, debug pods, set up Gateway API, configure autoscaling, or harden cluster security. Do NOT use for Dockerfiles (use docker), CI/CD pipeline design (use ci-cd), or Terraform infrastructure (use terraform).
allowed-tools
Read, Bash, Write, Grep, Glob
compatibility
opencode
license
MIT
metadata.workflow
infrastructure
metadata.audience
devops
metadata.version
3.0.0
metadata.author
shokunin
triggers
k8s, kubernetes, deploy, pod, cluster, helm, kustomize, kubectl, service mesh, istio, linkerd, cilium, gateway api, hpa, network policy, statefulset, daemonset
negatives
Dockerfile, Docker, docker-compose, CI/CD pipeline, Terraform

Kubernetes Architect

Production-grade Kubernetes: deployments, Gateway API, zero-trust networking, service mesh, eBPF observability, and debugging. Follows NSA/CISA hardening guidelines.

Decision Framework

Before deploying to Kubernetes, answer:

  • Does the app need horizontal scaling (3+ replicas)? → Kubernetes
  • Is it a single-instance app with simple needs? → Docker Compose or VPS
  • Is the team already familiar with Kubernetes? → Proceed. If not, consider managed (EKS, GKE, AKS)
  • Does the app need advanced networking (service mesh, ingress routing)? → Kubernetes + Gateway API
  • Is the infrastructure budget tight? → Single-node k3s or Docker Compose for dev
  • Multiple services with different scaling profiles? → Kubernetes (HPA per service)

Workflow

Step 1: Determine deployment type
TypeKindUse case
StatelessDeploymentWeb APIs, workers
StatefulStatefulSetDatabases, queues (use with caution)
BatchJob/CronJobMigrations, periodic tasks
DaemonDaemonSetLogging, monitoring agents

If uncertain, start with a Deployment. See assets/deployment-template.yaml for the full production template.

Step 2: Generate manifest

Use the scaffold script:

bash
scripts/generate-manifest.sh -n api -i myregistry.com/api:1.0.0 -p 3000 -r 3 -o manifests/

This creates: deployment.yaml, service.yaml, hpa.yaml, pdb.yaml with all security contexts, probes, resource requests/limits, and topology spread constraints pre-configured.

If the service expects HTTP traffic, also create a Gateway API HTTPRoute.

Template alternatives: Helm and Kustomize

The scaffold script above generates raw manifests. For more complex deployments, consider:

ToolBest forPattern
Helm (helm create)Packaging reusable apps, versioned releases, templatingvalues.yaml → Go templates → rendered manifests. Use helm lint and helm template for validation.
Kustomize (kubectl kustomize)Environment-specific overlays, patching base manifestsbase/ + overlays/{dev,staging,prod}/ with strategic merge patches. Native in kubectl.
Raw manifestsSimple services, fast iteration, no templating overheadPlain YAML in manifests/. Use with the scaffold script.

Use Helm for distributing apps (charts), Kustomize for environment variants (overlays), and raw manifests for speed. The scaffold script handles the raw manifest path — for Helm/Kustomize, create the chart or overlay manually following the same security constraints.

Step 3: Configure networking
Gateway API (replaces Ingress)
yaml
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: api-gateway
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
  gatewayClassName: istio
  listeners:
    - name: https
      protocol: HTTPS
      port: 443
      hostname: api.example.com
      tls:
        mode: Terminate
        certificateRefs: [{ name: api-tls }]
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: api-route
spec:
  parentRefs: [{ name: api-gateway }]
  hostnames: ["api.example.com"]
  rules:
    - matches:
        - path: { type: PathPrefix, value: /api }
      backendRefs:
        - name: api
          port: 80

See references/gateway-api.md for HTTPRoute, GRPCRoute, TLSRoute, and cross-namespace patterns.

Zero-trust networking
yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata: { name: default-deny-all }
spec:
  podSelector: {}
  policyTypes: [Ingress, Egress]
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata: { name: allow-api-ingress }
spec:
  podSelector: { matchLabels: { app: api } }
  ingress:
    - from:
        - namespaceSelector: { matchLabels: { name: gateway-system } }
      ports: [{ port: 3000 }]

Always start with a default-deny policy. Then add explicit allow rules.

Step 4: Add service mesh (if needed)

See references/service-mesh.md for the complete comparison and setup guide.

Decision matrix:

NeedRecommendation
mTLS + observabilityIstio (full-featured)
Simple mTLS + lightweightLinkerd (low resource overhead)
eBPF-native networking + securityCilium (no sidecar needed)
Step 5: Configure autoscaling and resilience
yaml
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata: { name: api-hpa }
spec:
  scaleTargetRef:
    apiVersion: apps/v1
    kind: Deployment
    name: api
  minReplicas: 3
  maxReplicas: 20
  metrics:
    - type: Resource
      resource:
        name: cpu
        target: { type: Utilization, averageUtilization: 70 }
    - type: Resource
      resource:
        name: memory
        target: { type: Utilization, averageUtilization: 80 }
---
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata: { name: api-pdb }
spec:
  minAvailable: 2
  selector:
    matchLabels: { app: api }
Step 6: Debug issues

See the debugging script:

bash
scripts/debug-pod.sh api-7d8f9c-abc  # describes pod, shows logs, checks events, diagnoses

Common diagnoses the script detects:

SymptomLikely cause
CrashLoopBackOff with OOMKillOut of memory — increase resources.limits.memory
CrashLoopBackOff with ImagePullBackOffWrong image name, tag, or registry credentials
Pending with no nodeInsufficient resources or PVC pending
ImagePullBackOffImage tag doesn't exist, registry unreachable, or imagePullSecrets missing
CreateContainerConfigErrorConfigMap or Secret referenced but not mounted
Running but not readyReadiness probe failing — check /ready endpoint

Error Handling

ScenarioDiagnosisFix
Pod stuck in Pendingkubectl describe pod → eventsCheck node resources, PVC status
Pod crash loopingkubectl logs --previousCheck app errors, OOMKill status
Service unreachablekubectl port-forward svc/api 8080:80Check selector matches pod labels
DNS not resolvingkubectl exec -it dnsutils -- nslookup apiCheck CoreDNS pods and Service entries
TLS cert invalidkubectl describe certificateCheck cert-manager issuer and DNS
PVC stuck in Pendingkubectl describe pvc → no matching PV, storage class wrongCheck StorageClass exists. Verify PV capacity >= PVC request. Check volumeMode matches.
ConfigMap not mountedkubectl describe pod → "MountVolume.SetUp failed"Verify ConfigMap name matches. Use subPath for single-file mounts. Check namespace — ConfigMaps are namespace-scoped.
RBAC deniedkubectl auth can-i <verb> <resource> --as <user> returns noCheck Role/RoleBinding or ClusterRole/ClusterRoleBinding. Verify subjects match service account. Use kubectl auth reconcile -f rbac.yaml to sync.
Show full SKILL.md (446 more words)Show less

Production Checklist

  • Resource requests + limits on every container
  • Liveness + readiness probes
  • Pod Security Standards: restricted enforced
  • NetworkPolicy: default-deny + explicit allow
  • Containers run as non-root
  • Read-only root filesystem
  • Secrets via external provider (Vault, External Secrets, CSI)
  • HPA with CPU + memory metrics
  • PDB >= 1 for critical services
  • Image pinned by digest (not tag)
  • PodDisruptionBudget for HA
  • mTLS between all services
  • Audit logging shipped
  • RBAC: least privilege, no cluster-admin
  • Falco or Tetragon for runtime security
  • Gateway API (not legacy Ingress)

Anti-Patterns

Anti-patternFix
imagePullPolicy: AlwaysPin digest, use IfNotPresent
No resource limitsAlways set requests + limits
Running as rootsecurityContext.runAsNonRoot: true
latest tagPin by digest
Single replicaAlways >= 2 for HA
No probesLiveness + readiness mandatory
Hardcoded config in imageConfigMap + Secret
No NetworkPolicyDefault-deny per namespace
Legacy Ingress resourceMigrate to Gateway API

Review Format (Required)

When reviewing Kubernetes manifests, use Before | After | Why format:

BeforeAfterWhy
image: myapp:latestimage: myapp@sha256:abc...latest is a floating tag. Digest pinning ensures the same image every deploy.
No resources blockresources: { requests: { cpu: "100m", memory: "128Mi" }, limits: { cpu: "500m", memory: "256Mi" } }Without requests, the scheduler can't place pods. Without limits, one pod can starve others.
imagePullPolicy: AlwaysimagePullPolicy: IfNotPresent (with digest tag) or Always (with floating tag only if intentional)Always forces a registry pull on every start, adding latency. Use with digest tags only for rolling updates.
Legacy IngressGateway API Gateway + HTTPRouteIngress is deprecated. Gateway API supports traffic splitting, header matching, and multi-tenancy.

Helm Charts

bash
# Create chart
helm create myapp
# Chart structure: Chart.yaml, values.yaml, templates/deployment.yaml, templates/service.yaml, templates/hpa.yaml

# Install
helm install myapp ./myapp -f values-prod.yaml --namespace production

# Template values: {{ .Values.replicaCount }}, {{ .Values.image.tag }}
# Conditional blocks: {{- if .Values.ingress.enabled }}
# Loops: {{- range .Values.env }}

Kustomize Overlays

yaml
# base/kustomization.yaml
resources: [deployment.yaml, service.yaml]

# overlays/prod/kustomization.yaml
bases: [../../base]
patchesStrategicMerge: [replicas-patch.yaml]
images: [{ name: myapp, newTag: "v1.2.3" }]

Apply: kubectl apply -k overlays/prod/

Pod Hardening (NSA/CISA)

yaml
securityContext:
  runAsNonRoot: true
  runAsUser: 1000
  fsGroup: 1000
containers:
- name: app
  securityContext:
    allowPrivilegeEscalation: false
    readOnlyRootFilesystem: true
    capabilities: { drop: [ALL] }
    seccompProfile: { type: RuntimeDefault }

Rule: every production pod must pass all 6 checks above.

Sources

  • Kubernetes docs (kubernetes.io/docs)
  • Gateway API (gateway-api.sigs.k8s.io)
  • Istio (istio.io), Linkerd (linkerd.io), Cilium (docs.cilium.io)
  • Helm (helm.sh)
  • NSA/CISA Kubernetes Hardening Guide
  • OWASP Kubernetes Security

Hardening Checklist

Before deploying to production:

  • All containers run as non-root (securityContext: { runAsNonRoot: true, readOnlyRootFilesystem: true })
  • Pod Security Standard restricted applied to all namespaces
  • NetworkPolicy default-deny-all with explicit allow rules for each service
  • Image pinned by digest, not tag (image: myapp@sha256:...)
  • Resource requests AND limits set on every container
  • readinessProbe AND livenessProbe configured with different thresholds
  • PodDisruptionBudget set with minAvailable: 1 (or higher for multi-replica services)
  • Secrets stored in external manager (Vault, Sealed Secrets, External Secrets), not plain K8s secrets
  • automountServiceAccountToken: false unless the pod genuinely needs API access
  • allowPrivilegeEscalation: false on all containers
  • TLS enabled on ingress with cert-manager auto-renewal
  • Audit logging enabled on API server and critical namespaces

Checklist

  • Skill loads without errors in the AI agent
  • YAML frontmatter is valid (description, compatibility, audience)
  • Workflow section provides clear step-by-step instructions
  • Error handling section covers common failure modes
  • All referenced files (references/, scripts/, assets/) exist
  • Skill triggers correctly for intended use cases
  • No broken links or missing resources

© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in .pack/skills/kubernetes of EliasOulkadi/shokunin.

  • SKILL.md
  • assets/deployment-template.yaml
  • references/gateway-api.md
  • references/service-mesh.md
  • scripts/debug-pod.sh
  • scripts/generate-manifest.sh

Open the folder on GitHubat commit 4c68e5b

Compare with similar skills

Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubernetes this skillEliasOulkadi/shokunin114—~3.3kAutomated safety check: NotesMIT
Supercheck Infrastructure Deploymentsupercheck-io/supercheck215—~1.4kAutomated safety check: NotesAGPL-3.0
Devops Excellencemajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit292—~2.7kAutomated safety check: PassMIT
Discover Infrarand/cc-polymath181—~783Automated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Supercheck Infrastructure Deployment

    supercheck-io/supercheck

    Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

    215 GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    287 GitHub stars~2.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    292 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Discover Infra

    rand/cc-polymath

    Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC

    181 GitHub stars~783 tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from EliasOulkadi/shokunin

All 49 skills in this repo
  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 6 days ago
    Auto-check: notes
  • Component Forge

    EliasOulkadi/shokunin

    Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…

    114 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check: notes
  • DB Admin

    EliasOulkadi/shokunin

    PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…

    114 GitHub stars~2k tokensUpdated 6 days ago
    Auto-check: notes
  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check: notes
  • Docker

    EliasOulkadi/shokunin

    Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

    114 GitHub stars~3.8k tokensUpdated 6 days ago
    Auto-check: notes
  • Error Handler

    EliasOulkadi/shokunin

    Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…

    114 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check: notes

Categories

Questions about Kubernetes

What does Kubernetes do?

Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…. Kubernetes is an agent skill from EliasOulkadi/shokunin. Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security Standards, OPA/Kyverno, seccomp, runtime security with Falco/Tetragon), Helm, HPA, PDB, topology spread, and debugging.

When should I use Kubernetes?

Kubernetes fits situations like: user asks to write K8s manifests; deploy to a cluster; set up Gateway API; configure autoscaling.

How do I install Kubernetes in Claude Code?

Run `npx skills add EliasOulkadi/shokunin --skill kubernetes -a claude-code`. Or copy the skill folder (.pack/skills/kubernetes in EliasOulkadi/shokunin) into .claude/skills/kubernetes in your project. Claude Code loads it when a task matches its description.

How do I install Kubernetes in Codex?

Run `npx skills add EliasOulkadi/shokunin --skill kubernetes -a codex`. Or copy the skill folder (.pack/skills/kubernetes in EliasOulkadi/shokunin) into .agents/skills/kubernetes in your project. Codex loads it when a task matches its description.

Can I use Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes, .gemini/skills/kubernetes, .github/skills/kubernetes and .opencode/skills/kubernetes in your project.

What does Kubernetes need to run?

Going by SKILL.md and its folder, Kubernetes needs a shell for the scripts in its folder and the command-line tools its instructions call (kubectl, helm and docker). Our summary lists: A Bash shell; Docker. Its frontmatter pre-approves these tools: Read, Bash, Write, Grep, Glob. Compatibility (from SKILL.md): opencode.

Does Kubernetes access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Kubernetes safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Kubernetes use?

Kubernetes is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubernetes use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.3k tokens, read only when the agent opens those files.

What are the alternatives to Kubernetes?

Skills that share tags, products or a category with Kubernetes: Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars), Devops Excellence (majiayu000/spellbook, 287 stars), Devops Deployment (yonatangross/orchestkit, 292 stars) and Discover Infra (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubernetes?

EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.

Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.