Sandbox build executor for Sealos deploys: build a container image from source with an in-cluster Kaniko Job and push it to GHCR, for environments without a Docker daemon (Brain managed Devbox…

Apache-2.0Auto-check passedDevOps & Cloud

Install K8s Kaniko Job

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill k8s-kaniko-job -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins k8s-kaniko-job --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/labring/sealos-skills/plugins/sealos/skills/k8s-kaniko-job .claude/skills/k8s-kaniko-job && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
k8s-kaniko-job
GitHub stars
1.3k
Token cost
~1.2k tokens
SKILL.md length
471 words
Files
3 (incl. scripts)
Skills in repo
716
Repo updated
First seen
Licence
Apache-2.0

At a glance

Sandbox build executor for Sealos deploys: build a container image from source with an in-cluster Kaniko Job and push it to GHCR, for environments without a Docker daemon (Brain managed Devbox…

  • Tasks that involve Containers
  • SKILL.md covers How it works, Preconditions, Reading the result and Failure triage
  • Runs Python scripts from its folder; calls kubectl and python3; needs GITHUB_TOKEN and SEALOS_DEVBOX_JWT_SECRET
  • Tasks that involve Container orchestration

What it does

K8s Kaniko Job is an agent skill from hashgraph-online/awesome-codex-plugins. Sandbox build executor for Sealos deploys: build a container image from source with an in-cluster Kaniko Job and push it to GHCR, for environments without a Docker daemon (Brain managed Devbox sandboxes). Use only when a managed deploy (SEALAIDEPLOYMODE=managed) needs an image built from project source; local interactive deploys build with docker buildx instead (see the use-sealos skill).

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/kaniko-build.py` and `scripts/test_kaniko_build.py`).

It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Kubernetes and Docker. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Container orchestration

Example prompts

  • “/k8s-kaniko-job”

Requirements

  • Python 3
  • Docker
  • A credential in SEALOS_DEVBOX_JWT_SECRET
  • A credential in GITHUB_TOKEN
  • Pre-approved tools (allowed-tools): Bash(kubectl:*), Bash(python3:*), Bash(tar:*), Bash(curl:*), Bash(bash:*)

What it can do on your machine

Read from SKILL.md and the folder at commit 3e1456a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(kubectl:*)
    • Bash(python3:*)
    • Bash(tar:*)
    • Bash(curl:*)
    • Bash(bash:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • SEALOS_DEVBOX_JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

K8s Kaniko Job loads about 1.2k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 471 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 3e1456a, republished under its Apache-2.0 licence (© hashgraph-online). 471 words, ~1,220 tokens.

Download SKILL.mdSave it as .claude/skills/k8s-kaniko-job/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
k8s-kaniko-job
description
Sandbox build executor for Sealos deploys: build a container image from source with an in-cluster Kaniko Job and push it to GHCR, for environments without a Docker daemon (Brain managed Devbox sandboxes). Use only when a managed deploy (SEALAI_DEPLOY_MODE=managed) needs an image built from project source; local interactive deploys build with docker buildx instead (see the use-sealos skill).
allowed-tools
Bash(kubectl:*), Bash(python3:*), Bash(tar:*), Bash(curl:*), Bash(bash:*)

K8s Kaniko Job

Builds linux/amd64 images inside the Kubernetes namespace when no Docker daemon exists. One script owns the whole flow — do not hand-roll Jobs or Secrets around it:

bash
python3 scripts/kaniko-build.py --image ghcr.io/<owner>/<repo>:<tag> \
  [--context <dir>] [--dockerfile <path-relative-to-context>] \
  [--build-arg KEY=value ...]

Resolve scripts/ against this skill's directory. Run the script from the project workspace so it finds .sealos/build-runtime.json.

How it works

text
tar the context (excludes .git/.sealos/.versitygw-*)
  → DevBox-local VersityGW S3 store (POSIX dir, served on port 1319)
  → Kaniko Job in the current namespace pulls s3://... via the
    Job-reachable endpoint from .sealos/build-runtime.json
  → pushes the tagged image to ghcr.io with a build-only registry Secret
  → digest captured from the pod termination message

Everything is resolved automatically, in order: CLI flags → .sealos/build-runtime.json (written by the control plane: Job-reachable s3Endpoint, S3 secretKeyRef, build deadline) → DevBox runtime env (KANIKO_CONTEXT_POSIX_DIR, S3_ENDPOINT, SEALOS_DEVBOX_JWT_SECRET, ...) → defaults. The Job runs with backoffLimit: 0, an active deadline capped at 1800s, ttlSecondsAfterFinished: 3600, and the current ServiceAccount.

Preconditions

  • kubectl pointed at the sandbox namespace (injected kubeconfig; the script never selects a region, workspace, or other namespace).
  • GITHUB_TOKEN with the write:packages scope. The target image owner must equal the token's login, lowercased: ghcr.io/<login>/<repo>:<tag>. Tag with the commit SHA or a timestamp, never latest.
  • Namespace permissions to create Jobs/Secrets and read Pods/logs.
  • A Dockerfile inside the context (write one first if missing — rules in ../use-sealos/references/build.md §1; the buildx/registry sections of that file do not apply here).

Reading the result

On success stdout is JSON with digest and image_ref (ghcr.io/<owner>/<repo>@sha256:...). Prefer image_ref in deployment manifests — the digest pin survives tag mutation. If digest is null (rare: termination message lost), fall back to the tag reference in image.

pull reports downstream pull behavior:

  • anonymous — the package is public; no pull secret needed.

  • private — GHCR packages are private by default. Create a pull secret in the namespace and reference it from the workload (imagePullSecrets: [{name: <app>-pull}], fixed literal name):

    bash
    kubectl create secret docker-registry <app>-pull \
      --docker-server=ghcr.io --docker-username=<login> \
      --docker-password="$GITHUB_TOKEN" \
      --dry-run=client -o yaml | kubectl apply -f -
  • indeterminate — verify by watching the first pod pull, and add the pull secret if it hits ErrImagePull.

Show full SKILL.md (203 more words)Show less

Failure triage

The script reports the Job and namespace on failure without echoing raw Pod logs or Kubernetes error text, which may contain credentials. Inspect the named Job and Pods directly, then summarize only redacted findings.

SymptomCause → fix
Job pod ImagePullBackOff on the executor imagecluster cannot pull gcr.io/kaniko-project/executor → report; there is no local fallback
Kaniko log: error uploading context / S3 connection refusedthe Job cannot reach the VersityGW endpoint → check .sealos/build-runtime.json.s3Endpoint; never point the Job at 127.0.0.1
Kaniko log: 401/403 on pushtoken scope or owner mismatch → the script validates both before creating the Job; inspect the token and image owner privately
Dockerfile build errorfix the Dockerfile in the workspace and rerun; each run creates a fresh Job
Job deadline exceededbuild too slow → trim the context (.dockerignore), use smaller base images

Build-only Secrets (use-sealos-ghcr-auth-*) are namespace-local with no TTL; the Job itself is garbage-collected after an hour. Leave cleanup to sandbox teardown unless the user asks.

Never print GITHUB_TOKEN, S3 credentials, or Secret payloads. Never pass secrets through --build-arg — build args are visible in the Job spec. --render-only prints a synthetic, redacted Job manifest for structural inspection; it does not reveal values from the runtime contract or build args.

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in plugins/labring/sealos-skills/plugins/sealos/skills/k8s-kaniko-job of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • scripts/kaniko-build.py
  • scripts/test_kaniko_build.py

Open the folder on GitHubat commit 3e1456a

Compare with similar skills

K8s Kaniko Job next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

K8s Kaniko Job compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
K8s Kaniko Job this skillhashgraph-online/awesome-codex-plugins1.3k—~1.2kAutomated safety check: PassApache-2.0
LangBot Deployment Guidelangbot-app/LangBot18k—~1.5kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell16k—~4.9kAutomated safety check: PassApache-2.0
Devopsnicepkg/auto-company1952 repos~814Automated safety check: PassMIT
Debug Openshell ClusterNVIDIA/OpenShell16k—~20kAutomated safety check: NotesApache-2.0
Deepseek Harness Dockerrunzhliu/deepseek-harness-docker110—~2.7kAutomated safety check: NotesMIT

Similar skills

  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    195 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    16k GitHub stars~20k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Deepseek Harness Docker

    runzhliu/deepseek-harness-docker

    Deploy, configure, verify, upgrade, and troubleshoot DeepSeek Harness with the community Docker, Docker Compose, rootless Podman, and Helm runtime, including the built-in Chromium/noVNC browser…

    110 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Cleanup

    ericboy0224/learn-docker-and-k8s

    Clean up Docker resources created by the Learn Docker & K8s game.

    491 GitHub stars~454 tokensUpdated 6 mo ago
    DevOps & CloudAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 715 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Categories

Questions about K8s Kaniko Job

What does K8s Kaniko Job do?

Sandbox build executor for Sealos deploys: build a container image from source with an in-cluster Kaniko Job and push it to GHCR, for environments without a Docker daemon (Brain managed Devbox…. K8s Kaniko Job is an agent skill from hashgraph-online/awesome-codex-plugins. Sandbox build executor for Sealos deploys: build a container image from source with an in-cluster Kaniko Job and push it to GHCR, for environments without a Docker daemon (Brain managed Devbox sandboxes).

When should I use K8s Kaniko Job?

K8s Kaniko Job fits situations like: tasks that involve Containers; tasks that involve Container orchestration.

How do I install K8s Kaniko Job in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill k8s-kaniko-job -a claude-code`. Or copy the skill folder (plugins/labring/sealos-skills/plugins/sealos/skills/k8s-kaniko-job in hashgraph-online/awesome-codex-plugins) into .claude/skills/k8s-kaniko-job in your project. Claude Code loads it when a task matches its description.

How do I install K8s Kaniko Job in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill k8s-kaniko-job -a codex`. Or copy the skill folder (plugins/labring/sealos-skills/plugins/sealos/skills/k8s-kaniko-job in hashgraph-online/awesome-codex-plugins) into .agents/skills/k8s-kaniko-job in your project. Codex loads it when a task matches its description.

Can I use K8s Kaniko Job in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill k8s-kaniko-job -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-kaniko-job, .gemini/skills/k8s-kaniko-job, .github/skills/k8s-kaniko-job and .opencode/skills/k8s-kaniko-job in your project.

What does K8s Kaniko Job need to run?

Going by SKILL.md and its folder, K8s Kaniko Job needs Python for the scripts in its folder, the command-line tools its instructions call (kubectl and python3) and credentials named GITHUB_TOKEN and SEALOS_DEVBOX_JWT_SECRET. Our summary lists: Python 3; Docker; A credential in SEALOS_DEVBOX_JWT_SECRET; A credential in GITHUB_TOKEN. Its frontmatter pre-approves these tools: Bash(kubectl:*), Bash(python3:*), Bash(tar:*), Bash(curl:*), Bash(bash:*).

Does K8s Kaniko Job access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is K8s Kaniko Job safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does K8s Kaniko Job use?

K8s Kaniko Job is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does K8s Kaniko Job use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to K8s Kaniko Job?

Skills that share tags, products or a category with K8s Kaniko Job: LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Build Openshell Mxc Windows (NVIDIA/OpenShell, 16k stars), Devops (nicepkg/auto-company, 195 stars) and Debug Openshell Cluster (NVIDIA/OpenShell, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains K8s Kaniko Job?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,267 GitHub stars. The repository holds 716 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.