Official agent skill

Gke Networking

by google in google/skills

Plans, configures, and manages core GKE cluster networking. An agent skill from google/skills.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Gke Networking

skills CLI
$ npx skills add google/skills --skill gke-networking -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills gke-networking --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/gke-networking .claude/skills/gke-networking && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gke-networking
GitHub stars
21k
Token cost
~1.5k tokens
SKILL.md length
464 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Plans, configures, and manages core GKE cluster networking. An agent skill from google/skills.

  • Works in 3 steps: DNS endpoint (default):… → Private endpoint: Direct access from… → Authorized networks: Add specific CIDRs to
  • Designing GKE networking layouts
  • SKILL.md covers Golden Path Networking Defaults, Private Cluster Access Patterns, Bring-Your-Own VPC/Subnet and VPC-Native Mode Benefits, plus 3 more sections
  • Calls gcloud

What it does

Gke Networking is an agent skill from google/skills, published by the product's own GitHub organization. Plans, configures, and manages core GKE cluster networking. Covers private clusters, VPC-native configurations, DNS, node egress, Dataplane V2, and IP planning. Use when designing GKE networking layouts, configuring private clusters, setting up Dataplane V2, planning GKE IP ranges, or managing VPC- native cluster modes. Don't use for application ingress, load balancing, or service networking (use gke-service-networking instead).

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking. It works with Google Kubernetes Engine. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Designing GKE networking layouts
  • Configuring private clusters
  • Setting up Dataplane V2
  • Planning GKE IP ranges

Example prompts

  • “/gke-networking”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. DNS endpoint (default): allowExternalTraffic: true enables access via
  2. Private endpoint: Direct access from within the VPC or via Cloud
  3. Authorized networks: Add specific CIDRs to

What it can do on your machine

Read from SKILL.md and the folder at commit 7d97937. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gke Networking loads about 1.5k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 464 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 7d97937, republished under its Apache-2.0 licence (© google). 464 words, ~1,492 tokens.

Download SKILL.mdSave it as .claude/skills/gke-networking/SKILL.md (or your agent's skills folder).
name
gke-networking
description
Plans, configures, and manages core GKE cluster networking. Covers private clusters, VPC-native configurations, DNS, node egress, Dataplane V2, and IP planning. Use when designing GKE networking layouts, configuring private clusters, setting up Dataplane V2, planning GKE IP ranges, or managing VPC- native cluster modes. Don't use for application ingress, load balancing, or service networking (use gke-service-networking instead).
metadata.version
1.0.0
metadata.category
Networking

GKE Networking

This reference covers networking configuration for GKE clusters. The golden path enforces private, VPC-native clusters with Dataplane V2.

MCP Tools: get_cluster, update_cluster, apply_k8s_manifest, get_k8s_resource

Golden Path Networking Defaults

SettingGolden Path ValueDay-0/1Notes
privateClusterConfig.enablePrivateNodestrueDay-0Nodes have no public IPs
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabledtrueDay-0Control plane only reachable via private endpoint or DNS
controlPlaneEndpointsConfig.dnsEndpointConfig.allowExternalTraffictrueDay-0Allows DNS-based access from outside VPC
networkConfig.datapathProviderADVANCED_DATAPATH (Dataplane V2)Day-0eBPF-based, built-in Network Policy
networkConfig.dnsConfig.clusterDnsCLOUD_DNSDay-0Managed DNS, more reliable than kube-dns
networkConfig.enableIntraNodeVisibilitytrueDay-1VPC Flow Logs for intra-node traffic
ipAllocationPolicy.autoIpamConfig.enabledtrueDay-0Automatic IP range management
ipAllocationPolicy.createSubnetworktrueDay-0Auto-create dedicated subnet
defaultMaxPodsConstraint.maxPodsPerNode48Day-0Conservative default; 110 for high density

Private Cluster Access Patterns

The golden path creates a private cluster. Users access it via:

  1. DNS endpoint (default): allowExternalTraffic: true enables access via the cluster's DNS endpoint from outside the VPC. No VPN required.
  2. Private endpoint: Direct access from within the VPC or via Cloud VPN/Interconnect.
  3. Authorized networks: Add specific CIDRs to masterAuthorizedNetworksConfig for IP-based access control.
bash
# Access private cluster via DNS endpoint (golden path default)
gcloud container clusters get-credentials {cluster_name} \
  --region {region} --dns-endpoint \
  --quiet

# Access via private endpoint (from within VPC)
gcloud container clusters get-credentials {cluster_name} \
  --region {region} --internal-ip \
  --quiet

Bring-Your-Own VPC/Subnet

If the customer has existing network infrastructure:

bash
gcloud container clusters create-auto {cluster_name} \
  --region {region} \
  --network {vpc_name} \
  --subnetwork {subnet_name} \
  --cluster-secondary-range-name {pod_range} \
  --services-secondary-range-name {svc_range} \
  --enable-private-nodes \
  --enable-master-authorized-networks \
  --quiet

Day-0 Warning: VPC, subnet, and IP ranges cannot be changed after cluster creation.

VPC-Native Mode Benefits

VPC-native clusters route traffic natively using GCP Alias IP ranges. Key benefits to cover:

  1. Scalability: Traffic routes natively inside the VPC, bypassing the need for custom routes and avoiding custom route limit bottlenecks.
  2. Direct VPC Integration: Direct resource integration across GCP networks without complex bridging or routing tunnels.
  3. Avoiding IP Exhaustion: Supports discontiguous IP ranges and optimizes allocation, reducing the risk of exhausting subnet IP ranges.
Show full SKILL.md (196 more words)Show less

IP Planning

ResourceGolden PathNotes
Pod CIDR/17 (auto)~32K pod IPs; size based on maxPodsPerNode
Service CIDR/20 (auto)~4K service IPs
Node subnetauto-created/20 recommended for growth
Max pods/node48Each node gets a /25 pod range; set to 110
: : : for /24 per node :

Pod CIDR sizing rule of thumb:

  • maxPodsPerNode=48 -> each node uses a /25 (128 IPs) from pod CIDR
  • maxPodsPerNode=110 -> each node uses a /24 (256 IPs) from pod CIDR
  • Larger maxPodsPerNode = fewer nodes fit in a given CIDR

Egress

  • Default: nodes use Cloud NAT for outbound internet access (private nodes have no public IPs) to allow private nodes to reach the internet without public IP exposure.
  • For static egress IPs: configure Cloud NAT with manual IP allocation to maintain a consistent source IP for external allowlists or partner firewalls.
  • For restricted egress: route through a firewall appliance via custom routes to inspect and filter outbound traffic according to organization security policies.

Network Policy

Dataplane V2 (golden path) provides built-in Network Policy enforcement — no additional addon needed. Apply default-deny per namespace, then allow specific flows.

See the gke-workload-security skill for default-deny policy and the gke-multitenancy skill for per-team allow policies.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloud/gke-networking of google/skills.

Open the folder on GitHubat commit 7d97937

Compare with similar skills

Gke Networking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gke Networking compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gke Networking this skillgoogle/skills21k—~1.5kAutomated safety check: PassApache-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0
Bfe Rd Workflowbfenetworks/bfe6.3k—~1.3kAutomated safety check: PassApache-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
NGINX Ingress Policy CRD Guidenginx/kubernetes-ingress5.1k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Bfe Rd Workflow

    bfenetworks/bfe

    引导用户在 bfe 代码库中完成一次完整的功能研发流程,包括需求对齐、文档修改、代码实现、集成测试与回归验证. An agent skill from bfenetworks/bfe.

    6.3k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    192 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Gke Networking

What does Gke Networking do?

Plans, configures, and manages core GKE cluster networking. An agent skill from google/skills. Gke Networking is an agent skill from google/skills, published by the product's own GitHub organization. Plans, configures, and manages core GKE cluster networking.

When should I use Gke Networking?

Gke Networking fits situations like: designing GKE networking layouts; configuring private clusters; setting up Dataplane V2; planning GKE IP ranges.

How do I install Gke Networking in Claude Code?

Run `npx skills add google/skills --skill gke-networking -a claude-code`. Or copy the skill folder (skills/cloud/gke-networking in google/skills) into .claude/skills/gke-networking in your project. Claude Code loads it when a task matches its description.

How do I install Gke Networking in Codex?

Run `npx skills add google/skills --skill gke-networking -a codex`. Or copy the skill folder (skills/cloud/gke-networking in google/skills) into .agents/skills/gke-networking in your project. Codex loads it when a task matches its description.

Can I use Gke Networking in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill gke-networking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gke-networking, .gemini/skills/gke-networking, .github/skills/gke-networking and .opencode/skills/gke-networking in your project.

What does Gke Networking need to run?

Going by SKILL.md and its folder, Gke Networking needs the command-line tools its instructions call (gcloud).

Does Gke Networking access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gke Networking safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gke Networking use?

Gke Networking is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gke Networking use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gke Networking?

Skills that share tags, products or a category with Gke Networking: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Bfe Rd Workflow (bfenetworks/bfe, 6.3k stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gke Networking?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,032 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 8, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.