Agent skill

Higress Update Envoy Gateway

by higress-group in higress-group/higress

Update Higress Envoy binary and gateway image dependencies for e2e validation.

Apache-2.0Auto-check passedTesting & QA

Install Higress Update Envoy Gateway

skills CLI
$ npx skills add higress-group/higress --skill higress-update-envoy-gateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install higress-group/higress higress-update-envoy-gateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/higress-group/higress.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/higress-update-envoy-gateway .claude/skills/higress-update-envoy-gateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
higress-update-envoy-gateway
GitHub stars
9.5k
Token cost
~1.2k tokens
SKILL.md length
400 words
Files
2
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Update Higress Envoy binary and gateway image dependencies for e2e validation.

  • Works in 8 steps: Verify context → Build Envoy packages from the current… → Publish Envoy package release in… → …
  • Codex needs to build Envoy packages from the current Higress branch
  • SKILL.md covers Core Workflow and Practical Notes
  • Calls make, docker and git

What it does

Higress Update Envoy Gateway is an agent skill from higress-group/higress. Update Higress Envoy binary and gateway image dependencies for e2e validation. Use when Codex needs to build Envoy packages from the current Higress branch, upload those packages to higress-group/proxy releases, update Makefile.core.mk ENVOYPACKAGEURLPATTERN and ENVOYLATESTIMAGETAG, run make build-gateway-local, retag the generated proxy/proxyv2 image as gateway, push the gateway image, or prepare a signed-off PR that lets Higress e2e tests consume a new Envoy build.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Testing & QA, covering End-to-end testing. The repository describes itself as: 🤖 AI Gateway | AI Native API Gateway. The licence is Apache-2.0.

When your agent uses it

  • Codex needs to build Envoy packages from the current Higress branch
  • Upload those packages to higress-group/proxy releases
  • Update Makefile.core.mk ENVOYPACKAGEURLPATTERN and ENVOYLATESTIMAGETAG
  • Run make build-gateway-local

Example prompts

  • “/higress-update-envoy-gateway”

Requirements

  • Docker

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Verify context
  2. Build Envoy packages from the current branch
  3. Publish Envoy package release in higress-group/proxy
  4. Update Higress Makefile dependencies
  5. Build the local gateway image
  6. Retag proxy image as gateway
  7. Push the gateway image when requested
  8. Commit and push Makefile changes

What it can do on your machine

Read from SKILL.md and the folder at commit c74d7e2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • docker
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Higress Update Envoy Gateway loads about 1.2k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from higress-group/higress at commit c74d7e2, republished under its Apache-2.0 licence (© higress-group). 400 words, ~1,189 tokens.

Download SKILL.mdSave it as .claude/skills/higress-update-envoy-gateway/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
higress-update-envoy-gateway
description
Update Higress Envoy binary and gateway image dependencies for e2e validation. Use when Codex needs to build Envoy packages from the current Higress branch, upload those packages to higress-group/proxy releases, update Makefile.core.mk ENVOY_PACKAGE_URL_PATTERN and ENVOY_LATEST_IMAGE_TAG, run make build-gateway-local, retag the generated proxy/proxyv2 image as gateway, push the gateway image, or prepare a signed-off PR that lets Higress e2e tests consume a new Envoy build.

Higress Envoy Gateway Dependency Update

Core Workflow

Run from the Higress repo root unless a step explicitly says otherwise.

  1. Verify context:

    • Check git status --short --branch.
    • Do not remove unrelated user changes or generated artifacts.
    • Use gh for GitHub release/PR checks and always pass --repo for non-current repos.
  2. Build Envoy packages from the current branch:

    bash
    git submodule update --init
    make build-envoy

    Expected artifacts land in external/package/, typically:

    • envoy-alpha-<proxy-sha>.tar.gz
    • envoy-symbol-<proxy-sha>.tar.gz
    • matching .sha256 and .dwp files
  3. Publish Envoy package release in higress-group/proxy:

    • Create a new release tag by incrementing the requested RC/test tag, for example v2.2.4-rc.2-test-cpp-host.
    • Match the reference release asset names, even if local filenames include SHAs:
      • local envoy-alpha-<sha>.tar.gz uploads as envoy-amd64.tar.gz
      • local envoy-symbol-<sha>.tar.gz uploads as envoy-symbol-amd64.tar.gz
    • Use temporary renamed copies rather than renaming source artifacts:
      bash
      cp external/package/envoy-alpha-<sha>.tar.gz /tmp/envoy-amd64.tar.gz
      cp external/package/envoy-symbol-<sha>.tar.gz /tmp/envoy-symbol-amd64.tar.gz
      gh release create <release-tag> /tmp/envoy-amd64.tar.gz /tmp/envoy-symbol-amd64.tar.gz \
        --repo higress-group/proxy --target <target-branch> --title <release-tag> --generate-notes
      gh release view <release-tag> --repo higress-group/proxy --json tagName,targetCommitish,assets,url
    • If following an existing reference release, inspect it first with gh release view.
  4. Update Higress Makefile dependencies:

    • In Makefile.core.mk, set:
      make
      export ENVOY_PACKAGE_URL_PATTERN?=https://github.com/higress-group/proxy/releases/download/<release-tag>/envoy-symbol-ARCH.tar.gz
    • After building and pushing the gateway image, set:
      make
      ENVOY_LATEST_IMAGE_TAG ?= <gateway-image-tag>
  5. Build the local gateway image:

    bash
    make build-gateway-local

    Watch the log to confirm Envoy downloads from the new release URL. The build target may emit an image under a proxy-style repository/name, commonly:

    • higress-registry.cn-hangzhou.cr.aliyuncs.com/higress/proxyv2:<tag>
  6. Retag proxy image as gateway:

    bash
    docker tag higress-registry.cn-hangzhou.cr.aliyuncs.com/higress/proxyv2:<tag> \
      higress-registry.cn-hangzhou.cr.aliyuncs.com/higress/gateway:<tag>
    docker images --format '{{.Repository}}:{{.Tag}} {{.ID}} {{.CreatedSince}}' \
      higress-registry.cn-hangzhou.cr.aliyuncs.com/higress/gateway

    Verify the gateway:<tag> and proxyv2:<tag> image IDs match.

  7. Push the gateway image when requested:

    bash
    docker push higress-registry.cn-hangzhou.cr.aliyuncs.com/higress/gateway:<tag>

    Record the pushed digest in the final response.

  8. Commit and push Makefile changes:

    • Commit only intended tracked files. Do not add plugins/golang-filter/golang-filter_amd64.so or other build outputs unless explicitly requested.
    • Use DCO sign-off:
      bash
      git add Makefile.core.mk
      git commit -s -m "Update gateway envoy dependencies"
      git push origin <branch>
    • If DCO fails after a previous unsigned commit:
      bash
      git commit --amend --no-edit --signoff
      git push --force-with-lease origin <branch>
      gh pr checks <pr-number> --repo higress-group/higress
Show full SKILL.md (89 more words)Show less

Practical Notes

  • make build-gateway-local may need Docker daemon access, network access, and write access to repo/submodule state.
  • If sandboxed commands fail with read-only filesystem errors, Docker socket permission errors, or network failures, rerun the same important command with elevated permissions and a concrete justification.
  • The default local gateway tag usually comes from the current Git revision shown in the build log as TAG=<sha>.
  • For e2e validation, the point of this workflow is to make install-dev, install-dev-wasmplugin, and local image update targets use the newly pushed gateway image through ENVOY_LATEST_IMAGE_TAG.

© higress-group, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/higress-update-envoy-gateway of higress-group/higress.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit c74d7e2

Compare with similar skills

Higress Update Envoy Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Higress Update Envoy Gateway compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Higress Update Envoy Gateway this skillhigress-group/higress9.5k—~1.2kAutomated safety check: PassApache-2.0
Web Application Testinganthropics/skills180k51 repos~966Automated safety check: PassApache-2.0
TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph11211 repos~2.4kAutomated safety check: PassNone
Uloop Replay Inputkurotu/VRCQuestTools3733 repos~615Automated safety check: PassMIT
Ui4 Convert Testspayloadcms/payload45k—~3.5kAutomated safety check: PassMIT
E2Estackia/rtp2httpd2.2k—~517Automated safety check: PassGPL-2.0

Similar skills

  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed
  • TDD Workflow

    hellangleZ/burn-in-cceverywhere-ralph

    A skill your agent uses when writing new features, fixing bugs, or refactoring code.

    112 GitHub starsUsed in 11 repos~2.4k tokens
    Testing & QAAuto-check passed
  • Uloop Replay Input

    kurotu/VRCQuestTools

    Replay recorded PlayMode keyboard and mouse input. An agent skill from kurotu/VRCQuestTools.

    373 GitHub starsUsed in 3 repos~615 tokens
    Testing & QAAuto-check passed
  • Ui4 Convert Tests

    payloadcms/payload

    A skill your agent uses when UI changes are complete and e2e tests need updating.

    45k GitHub stars~3.5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • E2E

    stackia/rtp2httpd

    Write, run, review, or debug rtp2httpd E2E tests and their harness in e2e/ and scripts/run-e2e.sh.

    2.2k GitHub stars~517 tokensUpdated 9 days ago
    Testing & QAAuto-check passed
  • Moav E2E

    MotherofallVPNs/MoaV

    Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS.

    449 GitHub stars~1.9k tokensUpdated 4 days ago
    Testing & QAAuto-check: notes

More from higress-group/higress

All 11 skills in this repo
  • Higress Openclaw Integration

    higress-group/higress

    Deploy and configure Higress AI Gateway for OpenClaw integration.

    9.5k GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 3 days ago
    Auto-check passed
  • Agent Session Monitor

    higress-group/higress

    Real-time agent conversation monitoring - monitors Higress access logs, aggregates conversations by session, tracks token usage.

    9.5k GitHub stars~3.3k tokensUpdated 3 days ago
    Auto-check passed
  • Higress Wasm Go Plugin

    higress-group/higress

    Develop Higress WASM plugins using Go 1.24+. An agent skill from higress-group/higress.

    9.5k GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • Higress Auto Router

    higress-group/higress

    Configure automatic model routing using the get-ai-gateway.sh CLI tool for Higress AI Gateway.

    9.5k GitHub stars~954 tokensUpdated 3 days ago
    Auto-check passed
  • Higress Daily Report

    higress-group/higress

    生成 Higress 项目每日报告,追踪 issue/PR 动态,沉淀问题处理经验,驱动社区问题闭环。用于生成日报、跟进 issue、记录解决方案。

    9.5k GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Higress Update Envoy Gateway

What does Higress Update Envoy Gateway do?

Update Higress Envoy binary and gateway image dependencies for e2e validation. Higress Update Envoy Gateway is an agent skill from higress-group/higress. Update Higress Envoy binary and gateway image dependencies for e2e validation.

When should I use Higress Update Envoy Gateway?

Higress Update Envoy Gateway fits situations like: Codex needs to build Envoy packages from the current Higress branch; upload those packages to higress-group/proxy releases; update Makefile.core.mk ENVOYPACKAGEURLPATTERN and ENVOYLATESTIMAGETAG; run make build-gateway-local.

How do I install Higress Update Envoy Gateway in Claude Code?

Run `npx skills add higress-group/higress --skill higress-update-envoy-gateway -a claude-code`. Or copy the skill folder (.agents/skills/higress-update-envoy-gateway in higress-group/higress) into .claude/skills/higress-update-envoy-gateway in your project. Claude Code loads it when a task matches its description.

How do I install Higress Update Envoy Gateway in Codex?

Run `npx skills add higress-group/higress --skill higress-update-envoy-gateway -a codex`. Or copy the skill folder (.agents/skills/higress-update-envoy-gateway in higress-group/higress) into .agents/skills/higress-update-envoy-gateway in your project. Codex loads it when a task matches its description.

Can I use Higress Update Envoy Gateway in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add higress-group/higress --skill higress-update-envoy-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/higress-update-envoy-gateway, .gemini/skills/higress-update-envoy-gateway, .github/skills/higress-update-envoy-gateway and .opencode/skills/higress-update-envoy-gateway in your project.

What does Higress Update Envoy Gateway need to run?

Going by SKILL.md and its folder, Higress Update Envoy Gateway needs the command-line tools its instructions call (make, docker, git and gh). Our summary lists: Docker.

Does Higress Update Envoy Gateway access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Higress Update Envoy Gateway safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Higress Update Envoy Gateway use?

Higress Update Envoy Gateway is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Higress Update Envoy Gateway use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Higress Update Envoy Gateway?

Skills that share tags, products or a category with Higress Update Envoy Gateway: Web Application Testing (anthropics/skills, 180k stars), TDD Workflow (hellangleZ/burn-in-cceverywhere-ralph, 112 stars), Uloop Replay Input (kurotu/VRCQuestTools, 373 stars) and Ui4 Convert Tests (payloadcms/payload, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Higress Update Envoy Gateway?

higress-group (a GitHub organization) maintains it in higress-group/higress, which has 9,516 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: higress-group/higress on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.