Official agent skill

Gke Backup Dr

by google in google/skills

Configures Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows, and CMEK-encrypted backups.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Gke Backup Dr

skills CLI
$ npx skills add google/skills --skill gke-backup-dr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills gke-backup-dr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/gke-backup-dr .claude/skills/gke-backup-dr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gke-backup-dr
GitHub stars
21k
Token cost
~2k tokens
SKILL.md length
671 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows, and CMEK-encrypted backups.

  • Works in 3 steps: Validate the restore in a non-production… → Prefer the safe defaults… → **Always obtain explicit user…
  • Backup policies
  • SKILL.md covers CLI Reference, Restore Safety (CRITICAL), Best Practices and Recent Changes, plus 1 more section
  • Calls gcloud

What it does

Gke Backup Dr is an agent skill from google/skills, published by the product's own GitHub organization. Configures Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows, and CMEK-encrypted backups. Use for backup policies, disaster recovery, or GKE cluster restores. Don't use for database backups.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery. It works with Google Kubernetes Engine. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Backup policies
  • Disaster recovery
  • GKE cluster restores
  • Database backups

Example prompts

  • “Use the gke-backup-dr skill to configure Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows…”
  • “/gke-backup-dr”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Validate the restore in a non-production target cluster first.
  2. Prefer the safe defaults (use-existing-version + fail-on-conflict)
  3. **Always obtain explicit user confirmation before executing a restore into a

What it can do on your machine

Read from SKILL.md and the folder at commit 5120a76. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gke Backup Dr loads about 2k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 671 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 5120a76, republished under its Apache-2.0 licence (© google). 671 words, ~1,989 tokens.

Download SKILL.mdSave it as .claude/skills/gke-backup-dr/SKILL.md (or your agent's skills folder).
name
gke-backup-dr
description
Configures Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows, and CMEK-encrypted backups. Use for backup policies, disaster recovery, or GKE cluster restores. Don't use for database backups.
metadata.version
1.0.0
metadata.category
Storage

GKE Backup & Disaster Recovery

Protects stateful GKE workloads using Backup for GKE. Backup for GKE can capture both Kubernetes resource metadata (manifests, configurations, and secrets) and the underlying persistent volume (PV) data — but volume data and secrets are only captured when the backup plan explicitly enables them (see the flags below).

CLI Reference

bash
# Enable the BackupRestore addon (Slow cluster-level update)
gcloud container clusters update {cluster_name} \
  --update-addons=BackupRestore=ENABLED --location={location} --quiet

# Create Backup Plan
gcloud beta container backup-restore backup-plans create {plan_name} \
  --project={project_id} --location={location} \
  --cluster=projects/{project_id}/locations/{location}/clusters/{cluster_name} \
  --all-namespaces \
  --include-volume-data --include-secrets \
  --backup-retain-days={days} --cron-schedule="{cron}" --quiet

# Trigger Manual Backup
gcloud beta container backup-restore backups create {backup_name} \
  --backup-plan={plan_name} --location={location} --quiet

# Create Restore Plan
gcloud beta container backup-restore restore-plans create {restore_plan_name} \
  --location={location} \
  --cluster=projects/{project_id}/locations/{location}/clusters/{target_cluster_name} \
  --backup-plan=projects/{project_id}/locations/{location}/backupPlans/{source_backup_plan_name} \
  --all-namespaces \
  --cluster-resource-conflict-policy=use-existing-version \
  --namespaced-resource-restore-mode=fail-on-conflict --quiet

# Execute Restore
gcloud beta container backup-restore restores create {restore_name} \
  --restore-plan={restore_plan_name} --location={location} \
  --backup=projects/{project_id}/locations/{location}/backupPlans/{source_backup_plan_name}/backups/{backup_name} \
  --quiet

# Verify Restore Status
gcloud beta container backup-restore restores describe {restore_name} \
  --restore-plan={restore_plan_name} --location={location}

[!WARNING] --include-volume-data and --include-secrets BOTH DEFAULT TO FALSE. If you omit them, the backup plan silently produces config-only backups with no persistent volume snapshots and no Secrets. Always pass both flags explicitly when the goal is full workload protection.

Notes:

  • The backup-restore command group requires the gcloud beta component (gcloud components install beta).
  • --cluster requires the full resource path projects/{project_id}/locations/{location}/clusters/{cluster_name} (or projects/{project_id}/zones/{zone}/clusters/{cluster_name} for zonal clusters), not a bare cluster name.
  • Restore plans require exactly one namespaced-resource scope flag: --all-namespaces, --selected-namespaces={ns1},{ns2}, --excluded-namespaces=..., --selected-applications=..., or --no-namespaces.

Restore Safety (CRITICAL)

A restore writes into a live cluster and, depending on the conflict policy, can overwrite or delete existing resources:

  • --cluster-resource-conflict-policy=use-existing-version keeps existing cluster-scoped resources (safe default); use-backup-version deletes the existing version first — deleting a CRD deletes all of its CRs.
  • --namespaced-resource-restore-mode=fail-on-conflict aborts on any conflict (safe default); merge-skip-on-conflict skips conflicting resources; merge-replace-on-conflict and merge-replace-volume-on-conflict overwrite existing resources or volumes; delete-and-restore deletes entire conflicting namespaces (and all resources in them) before restoring.

Rules:

  1. Validate the restore in a non-production target cluster first.
  2. Prefer the safe defaults (use-existing-version + fail-on-conflict) unless the user explicitly needs to revert live resources.
  3. Always obtain explicit user confirmation before executing a restore into a production cluster, and state which conflict policy is in effect and what it may overwrite or delete.

Best Practices

  1. CMEK Encryption: Encrypt backup plans using Customer-Managed Encryption Keys: --encryption-key=projects/{project_id}/locations/{location}/keyRings/{ring}/cryptoKeys/{key}.
  2. Scope: Prefer backing up specific namespaces rather than the entire cluster: --selected-namespaces={ns1},{ns2} (instead of --all-namespaces).
  3. Application Consistency: Recommend quiescing the database or pausing application writes (e.g. using pre-backup hooks or database-specific tools) prior to backups to ensure data integrity.
  4. CSI Volume Snapshots: Ensure that stateful backups utilize GKE's CSI (Container Storage Interface) driver for volume snapshots to capture persistent volume data.
  5. Service Terminology: Always explicitly refer to the service as Backup for GKE in your response. This distinguishes it from the broader (but complementary) Google Cloud Backup and Disaster Recovery (DR) Service, ## Golden Path Backup Defaults

The recommended production golden path configuration for Backup for GKE:

  • Addon: BackupRestore addon enabled (--update-addons=BackupRestore=ENABLED).
  • Volume Inclusion: --include-volume-data explicitly passed (enabled, since the service default is false).
  • Secret Inclusion: --include-secrets explicitly passed (enabled, since the service default is false).
  • Retention: Defined retention period (e.g. 30 days via --backup-retain-days=30).
  • Encryption: CMEK enabled (--encryption-key=...).
Show full SKILL.md (239 more words)Show less

Recent Changes

  • Cross-project backup and restore (GA): Backup plans can store backups in a different project than the source cluster, and restore plans can target clusters in a third project. Enables centralized backup projects (with immutability/retention managed by a platform team) and cross-project environment seeding without granting access to the source project.
  • Pricing change (effective 2026-03-02): The backup management fee moved from pod-based to NAMESPACE-based pricing — charged per non-system namespace in the most recent successful backup of each plan (system namespaces like kube-system are excluded). Existing committed use discount (CUD) holders keep pod-based management pricing until their commitment ends; everyone else moves to the new model. See https://cloud.google.com/products/backup-for-gke/pricing-changes.
  • Smart Scheduling: RPO-driven backup scheduling as an alternative to fixed cron schedules — pass --target-rpo-minutes={minutes} instead of --cron-schedule when creating the backup plan (optionally with RPO exclusion windows via --exclusion-windows-file).
  • Hyperdisk support: Backup and restore of Hyperdisk ML and Hyperdisk Balanced High Availability volumes is supported on GKE clusters running 1.33.1-gke.1959000 and later (Hyperdisk throughput, extreme, and balanced types are also supported).

Troubleshooting & Common Pitfalls (CRITICAL)

[!IMPORTANT] Slow Operations: Enabling the BackupRestore addon (--update-addons=BackupRestore=ENABLED) triggers a slow Google Cloud control plane cluster update that takes several minutes. * Rule: Do not run a terminal loop waiting for the GKE Backup addon to become active. * Action: Provide the command to enable the addon, explain that the operation will proceed in the background, and immediately proceed to write the backup plan configs. Do not block.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloud/gke-backup-dr of google/skills.

Open the folder on GitHubat commit 5120a76

Compare with similar skills

Gke Backup Dr next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gke Backup Dr compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gke Backup Dr this skillgoogle/skills21k—~2kAutomated safety check: PassApache-2.0
OmniRoute Backup and Sync CLIdiegosouzapw/OmniRoute74k—~948Automated safety check: PassMIT
Pymobiledevice3 Device Operatordoronz88/pymobiledevice32.9k—~1.8kAutomated safety check: NotesGPL-3.0
Myclaw BackupLeoYeAI/openclaw-backup659—~1.8kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1942 repos~814Automated safety check: PassMIT
OmniRoute Database Backupsdiegosouzapw/OmniRoute74k—~395Automated safety check: PassMIT

Similar skills

  • OmniRoute Backup and Sync CLI

    diegosouzapw/OmniRoute

    Backup and restore OmniRoute data from the CLI. Trigger incremental snapshots, sync to cloud storage, manage backup schedules, and restore from archive files.

    74k GitHub stars~948 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pymobiledevice3 Device Operator

    doronz88/pymobiledevice3

    Operate iOS and iPadOS devices with pymobiledevice3, from a local checkout or straight from PyPI via uvx on a fresh workstation.

    2.9k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Myclaw Backup

    LeoYeAI/openclaw-backup

    Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data.

    659 GitHub stars~1.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    194 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • OmniRoute Database Backups

    diegosouzapw/OmniRoute

    Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.

    74k GitHub stars~395 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Temps

    gotempsh/temps

    Manage, deploy, operate, and instrument applications with Temps.

    828 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Gke Backup Dr

What does Gke Backup Dr do?

Configures Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows, and CMEK-encrypted backups. Gke Backup Dr is an agent skill from google/skills, published by the product's own GitHub organization. Configures Backup for GKE: the BackupRestore cluster addon, BackupPlan and RestorePlan resources, restore workflows, and CMEK-encrypted backups.

When should I use Gke Backup Dr?

Gke Backup Dr fits situations like: backup policies; disaster recovery; GKE cluster restores; database backups.

How do I install Gke Backup Dr in Claude Code?

Run `npx skills add google/skills --skill gke-backup-dr -a claude-code`. Or copy the skill folder (skills/cloud/gke-backup-dr in google/skills) into .claude/skills/gke-backup-dr in your project. Claude Code loads it when a task matches its description.

How do I install Gke Backup Dr in Codex?

Run `npx skills add google/skills --skill gke-backup-dr -a codex`. Or copy the skill folder (skills/cloud/gke-backup-dr in google/skills) into .agents/skills/gke-backup-dr in your project. Codex loads it when a task matches its description.

Can I use Gke Backup Dr in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill gke-backup-dr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gke-backup-dr, .gemini/skills/gke-backup-dr, .github/skills/gke-backup-dr and .opencode/skills/gke-backup-dr in your project.

What does Gke Backup Dr need to run?

Going by SKILL.md and its folder, Gke Backup Dr needs the command-line tools its instructions call (gcloud).

Does Gke Backup Dr access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Gke Backup Dr safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gke Backup Dr use?

Gke Backup Dr is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gke Backup Dr use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gke Backup Dr?

Skills that share tags, products or a category with Gke Backup Dr: OmniRoute Backup and Sync CLI (diegosouzapw/OmniRoute, 74k stars), Pymobiledevice3 Device Operator (doronz88/pymobiledevice3, 2.9k stars), Myclaw Backup (LeoYeAI/openclaw-backup, 659 stars) and Devops (nicepkg/auto-company, 194 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gke Backup Dr?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,069 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.