Official agent skill

Gke Basics

by google in google/skills

Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Gke Basics

skills CLI
$ npx skills add google/skills --skill gke-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills gke-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/gke-basics .claude/skills/gke-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gke-basics
GitHub stars
21k
Token cost
~995 tokens
SKILL.md length
364 words
Files
6 (incl. references)
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment.

  • Works in 4 steps: Private Autopilot Clusters → Workload Identity (IAM Binding) → Autopilot Resource Requests → …
  • Creating GKE clusters
  • SKILL.md covers Key Selection Rules: Autopilot…, Critical Gotchas & Best… and Reference Directory
  • Calls gcloud

What it does

Gke Basics is an agent skill from google/skills, published by the product's own GitHub organization. Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment. Use when creating GKE clusters, fetching kubectl credentials, or deciding between Autopilot and Standard modes. Don't use for Workload Identity (use gke-workload-identity), GKE networking (use gke-networking), security hardening (use gke-platform-security or gke-workload-security), or cluster upgrades (use gke-upgrades).

Its SKILL.md is about 1000 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/cli-reference.md`, `references/client-library-usage.md` and `references/core-concepts.md`).

It sits in DevOps & Cloud, covering Container orchestration and Security review. It works with Google Kubernetes Engine and Kubernetes. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Creating GKE clusters
  • Fetching kubectl credentials
  • Deciding between Autopilot and Standard modes
  • Workload Identity (use gke-workload-identity)

Example prompts

  • “Use the gke-basics skill to manage core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment”
  • “/gke-basics”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Private Autopilot Clusters
  2. Workload Identity (IAM Binding)
  3. Autopilot Resource Requests
  4. Cluster Credentials

What it can do on your machine

Read from SKILL.md and the folder at commit 7d97937. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gke Basics loads about 995 tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 364 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~995
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 7d97937, republished under its Apache-2.0 licence (© google). 364 words, ~995 tokens.

Download SKILL.mdSave it as .claude/skills/gke-basics/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
gke-basics
description
Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment. Use when creating GKE clusters, fetching kubectl credentials, or deciding between Autopilot and Standard modes. Don't use for Workload Identity (use gke-workload-identity), GKE networking (use gke-networking), security hardening (use gke-platform-security or gke-workload-security), or cluster upgrades (use gke-upgrades).
metadata.version
1.1.1
metadata.category
Containers

GKE Basics & Critical Gotchas

Routing Note: For Workload Identity KSA/GSA setup, open gke-workload-identity/SKILL.md. For cluster security flags (--database-encryption-key, --security-posture, RBAC, Shielded Nodes, Binary Authorization), open gke-platform-security/SKILL.md. For cluster upgrades or maintenance windows, open gke-upgrades/SKILL.md. For generating Kubernetes YAML manifests (Deployment, StatefulSet, Service, HTTPRoute, PodDisruptionBudget), open gke-manifest-generation/SKILL.md.

Managed Kubernetes platform on Google Cloud. Defaults to Autopilot mode unless Standard is explicitly required.

Key Selection Rules: Autopilot vs. Standard

  • Default to Autopilot for almost all workloads.
  • Use Standard ONLY if:
    • Custom node OS kernel parameters (sysctl) are required.
    • Custom node taints or specific hardware node pools are required.
    • DaemonSets require raw hostPath mounts to the host OS filesystem.
  • When explaining why Standard is required over Autopilot, explicitly cite all matching restrictions (e.g., custom sysctls and custom node taints).
  • For advanced cluster architecture or complex node pool creation planning, refer to gke-cluster-creation.

Critical Gotchas & Best Practices

  1. Private Autopilot Clusters:

    • Use --enable-private-nodes for private node IP addresses.
    • Use --enable-private-endpoint to disable public IP access to the control plane.
    • Restrict control plane access with --enable-master-authorized-networks and --master-authorized-networks=CIDR_BLOCK:
      bash
      gcloud container clusters create-auto CLUSTER_NAME --region=REGION \
        --enable-private-nodes \
        --enable-private-endpoint \
        --enable-master-authorized-networks \
        --master-authorized-networks=CIDR_BLOCK
  2. Workload Identity (IAM Binding):

    • Never mount raw GCP Service Account JSON keys in Pods; open gke-workload-identity/SKILL.md for KSA/GSA setup.
  3. Autopilot Resource Requests:

    • In Autopilot, CPU requests must be specified in increments of 250m (0.25 vCPU). If an unaligned CPU request (e.g., 300m) is requested, round up to the nearest 250m increment (500m / 0.5 vCPU).
    • Resource requests equal limits automatically. Omit limits to allow Autopilot to set defaults matching requests.
  4. Cluster Credentials:

    • Always explicitly specify --region (for regional clusters) or --zone (for zonal clusters) when fetching credentials:
      bash
      gcloud container clusters get-credentials CLUSTER_NAME --region=REGION --quiet
Show full SKILL.md (83 more words)Show less

Reference Directory

  • Core Concepts: Architecture, cluster modes (Autopilot vs Standard), networking, scaling, and security model.

  • CLI Usage & Tool Reference: Tool preference hierarchy (MCP vs gcloud vs kubectl), gcloud container commands, and user preference overrides.

  • Client Libraries: Official Kubernetes and Google Cloud Container client libraries in Python, Go, Node.js, and Java.

  • MCP Usage: Connecting to and using the 23 structured GKE MCP tools for cluster management, K8s resources, and diagnostics.

  • Infrastructure as Code: Terraform examples for google_container_cluster (Autopilot), Kubernetes provider resources, and YAML samples.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/cloud/gke-basics of google/skills.

  • SKILL.md
  • references/cli-reference.md
  • references/client-library-usage.md
  • references/core-concepts.md
  • references/iac-usage.md
  • references/mcp-usage.md

Open the folder on GitHubat commit 7d97937

Compare with similar skills

Gke Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gke Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gke Basics this skillgoogle/skills21k—~995Automated safety check: PassApache-2.0
Devopsnicepkg/auto-company1922 repos~814Automated safety check: PassMIT
KubeShark for KubernetesLukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Aicr Analyzing SnapshotsNVIDIA/aicr439—~3.5kAutomated safety check: PassApache-2.0
GCP Gkesickn33/agentic-awesome-skills47k2 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    192 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 25 days ago
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    A skill your agent uses when analyzing an AICR snapshot YAML file, reviewing cluster state, comparing provider characteristics, extracting GPU/network topology insights, or generating a cluster…

    439 GitHub stars~3.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GCP Gke

    sickn33/agentic-awesome-skills

    Deploy and manage Google Kubernetes Engine clusters. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Performing Kubernetes Cis Benchmark With Kube Bench

    mukul975/Anthropic-Cybersecurity-Skills

    Turns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Gke Basics

What does Gke Basics do?

Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment. Gke Basics is an agent skill from google/skills, published by the product's own GitHub organization. Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment.

When should I use Gke Basics?

Gke Basics fits situations like: creating GKE clusters; fetching kubectl credentials; deciding between Autopilot and Standard modes; workload Identity (use gke-workload-identity).

How do I install Gke Basics in Claude Code?

Run `npx skills add google/skills --skill gke-basics -a claude-code`. Or copy the skill folder (skills/cloud/gke-basics in google/skills) into .claude/skills/gke-basics in your project. Claude Code loads it when a task matches its description.

How do I install Gke Basics in Codex?

Run `npx skills add google/skills --skill gke-basics -a codex`. Or copy the skill folder (skills/cloud/gke-basics in google/skills) into .agents/skills/gke-basics in your project. Codex loads it when a task matches its description.

Can I use Gke Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill gke-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gke-basics, .gemini/skills/gke-basics, .github/skills/gke-basics and .opencode/skills/gke-basics in your project.

What does Gke Basics need to run?

Going by SKILL.md and its folder, Gke Basics needs the command-line tools its instructions call (gcloud). Our summary lists: Node.js.

Does Gke Basics access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gke Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gke Basics use?

Gke Basics is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gke Basics use?

About 995 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.3k tokens, read only when the agent opens those files.

What are the alternatives to Gke Basics?

Skills that share tags, products or a category with Gke Basics: Devops (nicepkg/auto-company, 192 stars), KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars) and Aicr Analyzing Snapshots (NVIDIA/aicr, 439 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gke Basics?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,032 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 8, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.