Official agent skill

Gke Manifest Generation

by google in google/skills

Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Gke Manifest Generation

skills CLI
$ npx skills add google/skills --skill gke-manifest-generation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills gke-manifest-generation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/gke-manifest-generation .claude/skills/gke-manifest-generation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gke-manifest-generation
GitHub stars
21k
Token cost
~3.1k tokens
SKILL.md length
1,300 words
Files
5 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters.

  • Works in 8 steps: Namespace & Resource Isolation → GKE Resource Tuning (Autopilot & Standard) → Container Security Hardening (Pod… → …
  • Modifying GKE deployment manifests
  • SKILL.md covers Core Rules & Verification, Specialty Workloads: GKE…, Tooling & Grounding Guidelines and Reference Examples
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Gke Manifest Generation is an agent skill from google/skills, published by the product's own GitHub organization. Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters. Use when creating or modifying GKE deployment manifests, configuring container security contexts, setting CPU/memory resource limits, defining readiness/liveness/startup probes, mounting secrets and volumes, configuring GKE Gateway API routes, targeting Spot VMs, or deploying AI model inference workloads (vLLM, TGI, Gemma). Don't use for live cluster operations, pod troubleshooting (use…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/ai-inference.md`, `references/basic-workload.md` and `references/gateway-api.md`).

It sits in DevOps & Cloud, covering Container orchestration, Cloud security and LLM inference and serving. It works with Google Kubernetes Engine, Kubernetes and vLLM. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Modifying GKE deployment manifests
  • Configuring container security contexts
  • Setting CPU/memory resource limits
  • Defining readiness/liveness/startup probes

Example prompts

  • “Use the gke-manifest-generation skill to generate and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE…”
  • “/gke-manifest-generation”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Namespace & Resource Isolation
  2. GKE Resource Tuning (Autopilot & Standard)
  3. Container Security Hardening (Pod Security Standards)
  4. Health Checking (Mandatory Probes)
  5. Services & Ingress Routing
  6. Volume Mounts, StorageClasses & subPath Safety
  7. High Availability on GKE
  8. Updates & Server-Side Apply Reconciliations

What it can do on your machine

Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gke Manifest Generation loads about 3.1k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 160 tokens; SKILL.md has 1,300 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~160
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 1,300 words, ~3,092 tokens.

Download SKILL.mdSave it as .claude/skills/gke-manifest-generation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
gke-manifest-generation
description
Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters. Use when creating or modifying GKE deployment manifests, configuring container security contexts, setting CPU/memory resource limits, defining readiness/liveness/startup probes, mounting secrets and volumes, configuring GKE Gateway API routes, targeting Spot VMs, or deploying AI model inference workloads (vLLM, TGI, Gemma). Don't use for live cluster operations, pod troubleshooting (use gke-workload-troubleshooting), or cluster infrastructure provisioning (use gke-cluster-creation).
metadata.version
1.0.0
metadata.category
Containers

GKE Manifest Generation Skill

This skill provides guidelines, tooling integration, and templates to translate natural language descriptions or application code changes into secure, compliant, and cost-effective Kubernetes YAML manifests optimized for both GKE Autopilot and GKE Standard clusters.

Core Rules & Verification

When generating or updating YAML manifests, you must strictly adhere to the following rules:

1. Namespace & Resource Isolation
  • Explicit Namespace: Always declare namespace: {namespace} explicitly in the metadata of every resource (Deployments, Services, ConfigMaps, Secrets, PVCs, Roles, bindings). Map it to the namespace configured in your active SETTINGS.md. Never omit the namespace.
  • Dedicated ServiceAccount: Avoid using the namespace's default ServiceAccount. Always create and reference a dedicated ServiceAccount (e.g., devteam-agent-sa) for each microservice.
2. GKE Resource Tuning (Autopilot & Standard)
  • Resources Requests & Limits: Always specify CPU and Memory requests and limits for all containers.

    • GKE Autopilot: Requests determine pod billing directly; requests and limits must be equal. If they differ, Autopilot will automatically scale requests up to match limits, which can significantly increase costs.
    • GKE Standard: Requests ensure stable scheduling and bin-packing; limits prevent resource starvation/noisy-neighbor issues.
  • Density Defaults: For stateless apps or sidecars on GKE Standard, default to conservative requests (e.g., requests.cpu: "100m" or "200m", requests.memory: "256Mi" or "512Mi") with burstable limits. Use a reasonable overcommit ratio for limits (e.g., 2x to 4x requests, like limits.cpu: "400m" to "800m", and limits.memory: "512Mi" to "1Gi"). Avoid excessive overcommit limits (like limits.cpu: "4" for a 100m request) to prevent severe CPU throttling and latency degradation under heavy scheduling load, particularly in environments without guaranteed node shares.

  • Spot VMs for Staging/Dev: For non-production workloads (e.g., namespaces containing -test, -dev, or -staging), or if the user requests cost optimization, automatically target GKE Spot VMs. This requires injecting both the nodeSelector targeting Spot VMs AND the corresponding toleration to tolerate the Spot VM taint:

    yaml
    nodeSelector:
      cloud.google.com/gke-spot: "true"
    tolerations:
      - key: "cloud.google.com/gke-spot"
        operator: "Equal"
        value: "true"
        effect: "NoSchedule"

    (On GKE Standard, this assumes a Spot node pool is configured).

3. Container Security Hardening (Pod Security Standards)
  • Non-Root Execution: Always configure securityContext at the Pod level (and container level if overriding) to run as a non-root user (e.g., runAsNonRoot: true, runAsUser: 10000, runAsGroup: 10000, fsGroup: 10000). This is strictly enforced on GKE Autopilot and is a critical security baseline for GKE Standard.
  • Minimal Privileges: Always set allowPrivilegeEscalation: false and seccompProfile: {type: RuntimeDefault}.
  • Read-Only Root Filesystem: Set readOnlyRootFilesystem: true to prevent modifications to the container image filesystem.
    • Writable Directory Fallback: If readOnlyRootFilesystem is enabled, mount a local emptyDir volume to /tmp or /var/run/ to allow applications (like Java/Nginx) to write temp files without crashing.
  • Secret Volume Mounting: Prefer mounting Secrets as read-only files (configured in the volumes spec with defaultMode: 0400) instead of mapping them as environment variables, unless the application framework exclusively supports env-var based configuration. This prevents secrets leaking into application logs.
4. Health Checking (Mandatory Probes)
  • Liveness & Readiness Probes: Every Deployment container must define both livenessProbe and readinessProbe.

    • Web/API: Use httpGet probes.
    • TCP Services: Use tcpSocket probes.
    • Databases/Caches: Use command-based exec probes (e.g., exec.command: ["redis-cli", "ping"]).
  • Startup Probes for Slow-Starting Apps: For applications with slow boot times (e.g., Java spring boot, complex Python scripts, LLM model servers), you must also define a startupProbe. When a startupProbe is defined, the liveness and readiness probes are disabled until it succeeds, preventing Kubernetes from prematurely killing the pod during startup:

    yaml
    startupProbe:
      httpGet:
        path: /healthz
        port: 8080
      failureThreshold: 30
      periodSeconds: 10
  • Sensible Defaults: Set initialDelaySeconds: 5 to 15 depending on startup time (e.g., Java requires a longer delay than Go/Nginx).

5. Services & Ingress Routing
  • Internal ClusterIP: Default all internal microservices to type: ClusterIP. Never use type: LoadBalancer or NodePort unless the workload is explicitly intended to be publicly accessible from the internet.
  • Port Naming: Always assign clear, standard names to service and container ports (e.g., name: http-web or name: grpc-api) to enable automatic protocol discovery, tracing, and Web App routing.
  • Prefer Gateway API: When exposing APIs externally, prioritize using GKE Gateway API (Gateway and HTTPRoute resources) over legacy Ingress objects to enable advanced L7 routing and security features (e.g., Cloud Armor).
6. Volume Mounts, StorageClasses & subPath Safety
  • Avoid Directory Overwrites: When mounting a ConfigMap or Secret to an application directory containing other files (like Nginx public directories), always use subPath to overlay only the specific file. Caveat: Note that containers using subPath volume mounts do not receive automatic configuration updates if the underlying ConfigMap or Secret is modified; pods must be restarted manually to pick up changes.
  • StorageClass Selection: Use the correct GKE storage class in PersistentVolumeClaims:
    • CSI Driver Clusters (Autopilot & Modern Standard): Use standard-rwo (default balanced PD) or premium-rwo (SSD PD).
    • Legacy Standard Clusters: Use standard (default PD) or premium (SSD PD) if standard-rwo/premium-rwo are not configured.
    • Database rule: Use SSD storage classes (premium-rwo or premium) only when the prompt explicitly requests high IOPS, low latency, or database storage.
Show full SKILL.md (498 more words)Show less
7. High Availability on GKE
  • Topology Spread: For deployments with >1 replica, use podAntiAffinity or topologySpreadConstraints with topologyKey: "kubernetes.io/hostname" to distribute pods across GKE nodes and availability zones.
  • PodDisruptionBudget: For deployments with >1 replica, declare a PodDisruptionBudget to guarantee minimum replica availability during voluntary GKE node upgrades and maintenance cycles.
8. Updates & Server-Side Apply Reconciliations
  • Stable List Keys: Under Kubernetes Server-Side Apply (SSA), elements in associative lists (like volumes, volume mounts, ports, and container definitions) are matched and merged by their unique identifier keys (typically name). You must keep the name key stable when modifying properties of an existing list item. Renaming the name key will cause SSA to create a brand new entry and leave the old entry intact (orphaned) rather than modifying it.
  • Minimal Diff: Make only the changes requested. Adhere closely to existing labels, annotations, and conventions.

Specialty Workloads: GKE AI/Inference Serving (vLLM, TGI, etc.)

For model serving workloads, prioritize using optimized tooling like GKE Inference Quickstart if available. If generating manually:

  1. GPU Request & Allocation:
    • Always request nvidia.com/gpu in both requests and limits.
    • Add a nodeSelector or node affinity targeting the desired GKE accelerator tag (e.g., cloud.google.com/gke-accelerator: nvidia-l4).
  2. Shared Memory Boost:
    • Model servers require high shared memory (/dev/shm) for inter-process communications. Always declare and mount an emptyDir volume with medium: Memory to /dev/shm.
  3. Weight Loading Optimization:
    • Mount model weight directories (like GCS buckets) using the GKE GCS Fuse CSI driver (csi.storage.gke.io) as readOnly: true for efficient cold-starts.

Tooling & Grounding Guidelines

When generating manifests, you should leverage the following tooling to reduce hallucinations and optimize configurations:

  1. Inference Workloads (GKE Inference Quickstart CLI):

    • Make sure you have the Google Cloud SDK installed.

    • For all AI/LLM inference workloads (e.g. model serving), you must prioritize using the gcloud CLI GKE Inference Quickstart command to generate the optimized manifests instead of writing them manually:

      bash
      gcloud container ai profiles manifests create \
        --model={model_name} \
        --model-server={server_name} \
        --accelerator-type={accelerator_type} \
        --output=manifest \
        --output-path={output_file_path}
    • Constraint: You must include all resources returned by this command (Deployments, Services, PodMonitoring, etc.) without filtering.

  2. Grounding in Official Documentation (Developer Knowledge API):

    • For GKE-specific features, API defaults, manifest examples, or security contexts, you must query Google's developer knowledge base to retrieve official GKE documentation:
      • answer_query: Use this to ask direct questions (e.g., "How to configure GCS Fuse CSI driver in GKE"). This is the preferred tool for general queries.
      • search_documents: Use this to search for relevant GKE guides or examples when you don't have a specific question.
      • get_document: Use this to fetch full document contents when you have a specific document ID.

Reference Examples

For detailed, production-ready manifest templates, consult the following reference guides:

  • Basic Hardened Nginx Workload: Production-ready deployment with dedicated service account, security contexts, probes, anti-affinity, and PodDisruptionBudget.
  • Network Policy: Default-deny ingress network policy and selective ingress allowance for specific apps.
  • AI/LLM Inference Workload: GPU resource allocation, Workload Identity, GCS FUSE CSI driver mounting, /dev/shm shared memory boost, and startup probes.
  • GKE Gateway API Routing: Exposing workloads using GKE L7 Gateway API (Gateway and HTTPRoute resources).

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/cloud/gke-manifest-generation of google/skills.

  • SKILL.md
  • references/ai-inference.md
  • references/basic-workload.md
  • references/gateway-api.md
  • references/network-policy.md

Open the folder on GitHubat commit 4b940dd

Compare with similar skills

Gke Manifest Generation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gke Manifest Generation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gke Manifest Generation this skillgoogle/skills21k—~3.1kAutomated safety check: PassApache-2.0
KubeShark for KubernetesLukasNiessen/kubernetes-skill446—~1.2kAutomated safety check: PassMIT
Vllm Deploy K8svllm-project/vllm-skills102—~2kAutomated safety check: PassApache-2.0
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Eks Best Practicesaws-samples/appmod-blueprints115—~5kAutomated safety check: PassMIT-0
Deploy Controllerai-runway/airunway102—~927Automated safety check: PassApache-2.0

Similar skills

  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    446 GitHub stars~1.2k tokensUpdated 27 days ago
    DevOps & CloudAuto-check passed
  • Vllm Deploy K8s

    vllm-project/vllm-skills

    Deploy vLLM to Kubernetes (K8s) with GPU support, health probes, and OpenAI-compatible API endpoint.

    102 GitHub stars~2k tokensUpdated 6 mo ago
    AI & LLM EngineeringAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    115 GitHub stars~5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Deploy Controller

    ai-runway/airunway

    Interactively build, push or load, and deploy an airunway component (controller or any provider) to the cluster

    102 GitHub stars~927 tokensUpdated 14 days ago
    DevOps & CloudAuto-check passed
  • Model Serving Kubernetes

    sickn33/agentic-awesome-skills

    Deploy ML models on Kubernetes with KServe (formerly KFServing) and NVIDIA Triton Inference Server.

    47k GitHub starsUsed in 1 repo~2.3k tokens
    DevOps & CloudAuto-check passed

More from google/skills

All 150 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated yesterday
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Gke Manifest Generation

What does Gke Manifest Generation do?

Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters. Gke Manifest Generation is an agent skill from google/skills, published by the product's own GitHub organization. Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters.

When should I use Gke Manifest Generation?

Gke Manifest Generation fits situations like: modifying GKE deployment manifests; configuring container security contexts; setting CPU/memory resource limits; defining readiness/liveness/startup probes.

How do I install Gke Manifest Generation in Claude Code?

Run `npx skills add google/skills --skill gke-manifest-generation -a claude-code`. Or copy the skill folder (skills/cloud/gke-manifest-generation in google/skills) into .claude/skills/gke-manifest-generation in your project. Claude Code loads it when a task matches its description.

How do I install Gke Manifest Generation in Codex?

Run `npx skills add google/skills --skill gke-manifest-generation -a codex`. Or copy the skill folder (skills/cloud/gke-manifest-generation in google/skills) into .agents/skills/gke-manifest-generation in your project. Codex loads it when a task matches its description.

Can I use Gke Manifest Generation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill gke-manifest-generation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gke-manifest-generation, .gemini/skills/gke-manifest-generation, .github/skills/gke-manifest-generation and .opencode/skills/gke-manifest-generation in your project.

What does Gke Manifest Generation need to run?

SKILL.md names no scripts, command-line tools or credentials: Gke Manifest Generation is instructions for the agent only. Our summary lists: Python 3.

Does Gke Manifest Generation access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Gke Manifest Generation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gke Manifest Generation use?

Gke Manifest Generation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gke Manifest Generation use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Gke Manifest Generation?

Skills that share tags, products or a category with Gke Manifest Generation: KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 446 stars), Vllm Deploy K8s (vllm-project/vllm-skills, 102 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars) and Eks Best Practices (aws-samples/appmod-blueprints, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gke Manifest Generation?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.