Kcli Cluster Deployment
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
Plans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters.
$ npx skills add google/skills --skill gke-upgrades -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install google/skills gke-upgrades --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/gke-upgrades .claude/skills/gke-upgrades && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gke-upgrades" agent skill from https://github.com/google/skills/tree/main/skills/cloud/gke-upgrades into .claude/skills/gke-upgrades/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gke-upgrades", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/google/skills/tree/main/skills/cloud/gke-upgradesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add google/skills --skill gke-upgrades -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install google/skills gke-upgrades --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/gke-upgrades .agents/skills/gke-upgrades && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gke-upgrades" agent skill from https://github.com/google/skills/tree/main/skills/cloud/gke-upgrades into .agents/skills/gke-upgrades/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gke-upgrades", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill gke-upgrades -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install google/skills gke-upgrades --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/gke-upgrades .cursor/skills/gke-upgrades && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gke-upgrades" agent skill from https://github.com/google/skills/tree/main/skills/cloud/gke-upgrades into .cursor/skills/gke-upgrades/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gke-upgrades", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/google/skills.git --path skills/cloud/gke-upgrades--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add google/skills --skill gke-upgrades -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install google/skills gke-upgrades --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/gke-upgrades .gemini/skills/gke-upgrades && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gke-upgrades" agent skill from https://github.com/google/skills/tree/main/skills/cloud/gke-upgrades into .gemini/skills/gke-upgrades/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gke-upgrades", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install google/skills gke-upgradesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add google/skills --skill gke-upgrades -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/gke-upgrades .github/skills/gke-upgrades && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gke-upgrades" agent skill from https://github.com/google/skills/tree/main/skills/cloud/gke-upgrades into .github/skills/gke-upgrades/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gke-upgrades", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill gke-upgrades -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install google/skills gke-upgrades --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/gke-upgrades .opencode/skills/gke-upgrades && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gke-upgrades" agent skill from https://github.com/google/skills/tree/main/skills/cloud/gke-upgrades into .opencode/skills/gke-upgrades/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gke-upgrades", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gke-upgradesPlans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters.
Gke Upgrades is an agent skill from google/skills, published by the product's own GitHub organization. Plans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters. Produces upgrade plans, pre/post-upgrade checklists, maintenance runbooks with gcloud commands, release channel strategy, and troubleshooting guides. Handles node pool upgrade strategies (surge, blue-green), version compatibility, PDB management, and workload-specific concerns (stateful, GPU, operators). Use this skill whenever the user mentions GKE upgrades…
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/checklists.md`, `references/runbook-template.md` and `references/troubleshooting.md`).
It sits in DevOps & Cloud, covering Runbooks and postmortems, Deployment and Go-to-market strategy. It works with Google Kubernetes Engine, Kubernetes and Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 7d97937. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlgcloudFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cloud.google.comdocs.cloud.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gke Upgrades loads about 5k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 258 tokens; SKILL.md has 2,425 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from google/skills at commit 7d97937, republished under its Apache-2.0 licence (© google). 2,425 words, ~5,047 tokens.
.claude/skills/gke-upgrades/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Produce clear, actionable documents — upgrade plans, runbooks, or checklists — tailored to the user's environment. Output should be specific to their cluster mode, release channel, version, and workload types rather than generic advice.
Always frame guidance around the auto-upgrade model: auto-upgrade with maintenance windows and exclusions is the preferred control mechanism.
Before producing any upgrade artifact, establish:
If the user provides these upfront, skip straight to the deliverable. If they're vague, fill in reasonable defaults and flag assumptions.
GKE versions follow Kubernetes version terminology: Major.Minor.Patch (e.g., 1.30.1-gke.1187000). A Minor version bump (e.g., 1.29 → 1.30) introduces new features and APIs. A Patch version bump (e.g., 1.30.1 → 1.30.2) introduces security and bug fixes. Ensure the user understands this distinction.
| Channel | Best for | SLA |
|---|---|---|
| Rapid | Dev/test, early feature access | No upgrade stability SLA |
| Regular (default) | Most production | Full SLA |
| Stable | Mission-critical, stability-first | Full SLA |
| Extended | Compliance, EoS enforcement control | Full SLA |
Standard GKE versions are supported for 14 months after they become available in the Regular channel. This means:
terminationGracePeriodSeconds for up to 24 hours; surge upgrades honor it for up to 60 minutes. During node drains, GKE respects PDBs for a maximum of 60 minutes, after which pods are force-deleted (a notification is sent).Configure maintenance windows to control auto-upgrade timing. GKE also supports node pool level maintenance exclusions (in addition to cluster level) to block upgrades for specific workloads.
Exclusion types & Limits:
no_upgrades): Blocks all upgrades (minor, patch, node).no_minor_or_node_upgrades): Blocks minor and node upgrades, but allows control plane patch upgrades (low risk).no_minor_upgrades): Blocks minor upgrades, but allows control plane patches and node upgrades.Important Exclusion Rules (MUST follow when recommending exclusions and MUST include in the final text response):
--add-maintenance-exclusion-until-end-of-support for persistent exclusions.gcloud commands for exclusions, you MUST use the separate flag syntax: --add-maintenance-exclusion-name, --add-maintenance-exclusion-start, --add-maintenance-exclusion-end (or --add-maintenance-exclusion-until-end-of-support), and --add-maintenance-exclusion-scope (do NOT use a single comma-separated --add-maintenance-exclusion flag).GKE reserves the right to override user-defined maintenance windows and exclusions for mandatory operations. These overrides cannot be disabled or blocked.
Common Override Scenarios:
Guidance (MUST follow when overrides are discussed):
When asked to plan an upgrade, produce a structured document covering:
Compatibility Search Rule:
Recommend Surge upgrade as the default and most common strategy, with per-pool settings:
maxSurge (2-3) for speed, maxUnavailable=0 for safety.maxSurge=1, maxUnavailable=0 (conservative).maxSurge=0, maxUnavailable=1 (no surge capacity).maxSurge=20, maxUnavailable=0 (max parallelism).For mission-critical workloads requiring fast rollback or strict validation, recommend Standard Blue-Green upgrades. Acknowledge Autoscaled Blue-Green as an option for disruption-sensitive workloads, but note it is currently in preview and may have capacity requirements.
Upgrade Ordering (User-initiated only): When planning manual upgrades, specify the sequence of node pool upgrades. Recommend upgrading stateless pools first, verifying cluster stability, and then upgrading stateful/GPU pools. For auto-upgrades, GKE automatically manages sequential node pool upgrades.
For standard command sequences and runbook templates, see references/runbook-template.md.
When advising on GPU/TPU upgrades, you MUST cover all of the following:
maxSurge=0, maxUnavailable=1), which releases the reservation of the node being upgraded before provisioning its replacement. Explain that Blue-Green upgrades are not feasible here because they require double (2x) the GPU resources (both quota and reservations) during the transition.uname -r), and driver versions between old (working) and new (non-working) nodes, and deploy a test pod (e.g., vector addition) to verify GPU access. If production is blocked, rolling the node pool back to the previous version is the quickest mitigation.Produce checklists as copyable markdown with checkboxes. See references/checklists.md for the full pre-upgrade and post-upgrade checklist templates. Adapt them to the user's environment.
Stateful Workloads: When stateful workloads (databases) are present, always include checks for PV backup completion and verification of PV reclaim policies (e.g., Retain vs Delete) in the pre-upgrade checklist.
Autopilot Checklists: For Autopilot clusters, ensure the checklists include:
resources.requests on all containers (Autopilot requirement).kubectl commands for API deprecation checks, specifically: kubectl get --raw /metrics | grep apiserver_request_total | grep deprecated to check if any active workloads are using deprecated APIs.terminationGracePeriodSeconds to ensure pods have enough time to shut down gracefully during node recreation.Produce step-by-step runbooks with actual gcloud and kubectl commands. See references/runbook-template.md for the standard command sequences.
Any runbook that relaxes a safety control must restore it in the same runbook. This applies above all to PDBs during a node-pool migration or rollback: back the PDBs up before draining, and make re-applying them a numbered step with its own verification, not a closing remark. A runbook that patches maxUnavailable: 100% to unblock a drain and never reverts it leaves the cluster without disruption protection, and the gap is invisible until the next voluntary eviction. The same rule covers maintenance exclusions, cordons, and autoscaler minNodes overrides added to get through the procedure.
When diagnosing a "stuck" upgrade, consider if it was paused by a maintenance window:
gcloud container clusters update ... --maintenance-window-start ... --maintenance-window-duration ...). Do not suggest re-triggering the manual upgrade or bypassing the window.When a user reports a stuck or failing upgrade, you MUST systematically analyze and address ALL 5 potential causes in your final response. Do not omit checks even if you suspect one is the primary cause:
ALLOWED DISRUPTIONS = 0 using kubectl get pdb -A.Pending due to capacity limits.Stockout / Quota Exhaustion Rule:
ZONE_RESOURCE_POOL_EXHAUSTED (stockout) or QUOTA_EXCEEDED for Compute Engine resources:maxSurge=0 (rolling in-place) to bypass quota limits.QUOTA_EXCEEDED, suggest requesting a quota increase from Google Cloud.Refer to references/troubleshooting.md for the exact diagnostic commands and fix procedures for each step.
© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/cloud/gke-upgrades of google/skills.
Open the folder on GitHubat commit 7d97937
Gke Upgrades next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gke Upgrades this skillgoogle/skills | 21k | — | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Kcli Cluster Deploymentkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Devopsnicepkg/auto-company | 192 | 2 repos | ~814 | Automated safety check: Pass | MIT | |
| KubeShark for KubernetesLukasNiessen/kubernetes-skill | 444 | — | ~1.2k | Automated safety check: Pass | MIT | |
| GCP Gkesickn33/agentic-awesome-skills | 47k | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Apex Azure Cloud Migratejonathan-vella/apex | 217 | — | ~1.2k | Automated safety check: Pass | MIT |
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
nicepkg/auto-company
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).
LukasNiessen/kubernetes-skill
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
sickn33/agentic-awesome-skills
Deploy and manage Google Kubernetes Engine clusters. An agent skill from sickn33/agentic-awesome-skills.
jonathan-vella/apex
WORKFLOW SKILL — Assess and migrate cross-cloud workloads to Azure: assessments and code conversion from AWS, GCP, Heroku, Kubernetes or Spring.
Dynatrace/dynatrace-for-ai
GCP cloud resources including Compute Engine, GKE, Cloud Run, Pub/Sub, VPC networking, DNS, IAM, Secret Manager, and monitoring.
google/skills
Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
google/skills
Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.
google/skills
Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.
google/skills
Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.
google/skills
Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.
Categories
Plans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters. Gke Upgrades is an agent skill from google/skills, published by the product's own GitHub organization. Plans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters.
Gke Upgrades fits situations like: the user mentions GKE upgrades; Kubernetes version bumps; Node pool maintenance; cluster version management.
Run `npx skills add google/skills --skill gke-upgrades -a claude-code`. Or copy the skill folder (skills/cloud/gke-upgrades in google/skills) into .claude/skills/gke-upgrades in your project. Claude Code loads it when a task matches its description.
Run `npx skills add google/skills --skill gke-upgrades -a codex`. Or copy the skill folder (skills/cloud/gke-upgrades in google/skills) into .agents/skills/gke-upgrades in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill gke-upgrades -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gke-upgrades, .gemini/skills/gke-upgrades, .github/skills/gke-upgrades and .opencode/skills/gke-upgrades in your project.
Going by SKILL.md and its folder, Gke Upgrades needs the command-line tools its instructions call (kubectl and gcloud).
SKILL.md names 2 domains. As links in the text: cloud.google.com and docs.cloud.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gke Upgrades is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Gke Upgrades: Kcli Cluster Deployment (karmab/kcli, 653 stars), Devops (nicepkg/auto-company, 192 stars), KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars) and GCP Gke (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,032 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 8, 2026.
Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.