KubeSphere Multi-Tenant Management
kubesphere/kubesphere
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/.
$ npx skills add home-operations/kopiur --skill documentation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install home-operations/kopiur documentation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/home-operations/kopiur.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/documentation .claude/skills/documentation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "documentation" agent skill from https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentation into .claude/skills/documentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "documentation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add home-operations/kopiur --skill documentation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install home-operations/kopiur documentation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/home-operations/kopiur.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/documentation .agents/skills/documentation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "documentation" agent skill from https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentation into .agents/skills/documentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "documentation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add home-operations/kopiur --skill documentation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install home-operations/kopiur documentation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/home-operations/kopiur.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/documentation .cursor/skills/documentation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "documentation" agent skill from https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentation into .cursor/skills/documentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "documentation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/home-operations/kopiur.git --path .claude/skills/documentation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add home-operations/kopiur --skill documentation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install home-operations/kopiur documentation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/home-operations/kopiur.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/documentation .gemini/skills/documentation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "documentation" agent skill from https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentation into .gemini/skills/documentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "documentation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install home-operations/kopiur documentationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add home-operations/kopiur --skill documentation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/home-operations/kopiur.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/documentation .github/skills/documentation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "documentation" agent skill from https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentation into .github/skills/documentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "documentation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add home-operations/kopiur --skill documentation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install home-operations/kopiur documentation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/home-operations/kopiur.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/documentation .opencode/skills/documentation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "documentation" agent skill from https://github.com/home-operations/kopiur/tree/main/.claude/skills/documentation into .opencode/skills/documentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "documentation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
documentationHow Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/.
Documentation is an agent skill from home-operations/kopiur. How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/. Use when adding or editing any doc page, writing or changing an example manifest, or whenever you change operator behavior that affects how someone deploys, uses, or configures Kopiur (CRD fields, defaults, Helm values, RBAC, reconciler UX, kopia/mover invocation). Encodes the painfully-clear-for-three-audiences rule, the…
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration and Authorization and RBAC. It works with Kubernetes. The repository describes itself as: A Kopia-native Kubernetes backup operator written in Rust. The licence is AGPL-3.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 379efb7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
misekubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
KOPIA_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Documentation loads about 2.5k tokens when it runs. Until then it costs about 157 tokens; SKILL.md has 737 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from home-operations/kopiur at commit 379efb7, republished under its AGPL-3.0 licence (© home-operations). 737 words, ~2,539 tokens.
.claude/skills/documentation/SKILL.md (or your agent's skills folder).Kopiur's docs are an MkDocs Material site whose source IS the docs/ tree
(mkdocs.yml sets docs_dir: docs). Page order and grouping live in the nav:
block of mkdocs.yml — there is no SUMMARY.md; a docs/*.md left out of nav:
still builds but is unlinked (and --strict warns). Example manifests live in
deploy/examples/ and are pulled into the prose at build time (pymdownx
snippets); they are never copy-pasted into .md files. mise run docs builds
the site with mkdocs build --strict — a broken cross-link or a missing nav file
fails the build, so it doubles as our doc lint.
The MkDocs + Material + pymdown-extensions toolchain is pinned in pyproject.toml
/ uv.lock and run via uv (mise installs uv). Material bundles mermaid.js and the
admonition styling, so there are no preprocessor binaries or committed assets.
Every user-facing page must let a reader who has never seen Kopiur succeed at all three of:
kubectl apply, scope,
prerequisites). No "obviously you'd…" steps left implicit.SnapshotPolicy) from the invocation (Snapshot) from the schedule
(SnapshotSchedule); say which one does what before showing fields.When in doubt, over-explain the "why", and prefer a worked example over a prose
description. Use Material admonitions for the gotchas — alpha API,
webhook-enforced constraints, version prerequisites. This repo uses the pymdownx
blocks form (/// note | Title … ///), NOT the classic !!! note form:
the classic admonition extension is not even registered (mkdocs.yml wires up
pymdownx.blocks.admonition), because the pre-commit oxfmt pass strips the
4-space body indentation !!! requires and silently breaks every such block. The
blocks body stays at column 0 and the block is closed with a /// line:
/// warning | Lose the password, lose the backups
The `KOPIA_PASSWORD` encrypts the repository. If you lose it, the backups are
unrecoverable — kopia cannot decrypt without it.
///Keep a blank line before the closing /// (so oxfmt doesn't fold it into a
preceding list item). The title is bare text after | — not quoted. Registered
types are the canonical Material set: note, abstract, info, tip,
success, question, warning, failure, danger, bug, example, quote
— important is not one; use warning for a webhook-enforced constraint.
Reach for an example for any non-trivial capability. The example set must form a ladder: the lowest-numbered examples are the canonical first run with the fewest moving parts; later ones layer in complexity (cluster scope, selectors, GitOps deploy-or-restore, discovered snapshots, fine-grained maintenance). Add new examples at the complexity tier they belong to, not just at the end.
deploy/examples/, never inlineDocs include manifests with a pymdownx snippet marker so prose and apply-ready
files cannot drift. The snippet path is repo-root-relative (snippets base_path
is the repo root):
## Example 09 — <what it demonstrates>
<1–3 sentences: what this shows and when you'd reach for it.>
```yaml
--8<-- "deploy/examples/09-<kebab-name>.yaml"
```
**Never** paste a literal multi-line manifest into a `.md` file. If you're about
to, stop and make it a file under `deploy/examples/` instead. (Short inline
`console`/`kubectl` snippets that aren't manifests are fine.)
### Example manifest conventions (match the existing files)
- Filename `NN-kebab-name.yaml`, `NN` zero-padded and ordered by complexity.
- A top-of-file comment block: what it demonstrates, the CRD type/field it maps
to (verified against `crates/api`), and any caveats on field shapes.
- `REPLACE_ME` for secrets the user must supply; a real-looking but obviously-
placeholder value otherwise.
- Inline comments on every non-obvious field — especially the "common values"
above and any default being made explicit for teaching.
- Backends are **externally tagged** (`backend.s3`, not `backend: { kind: S3 }`)
— see [[kopiur-design]]. Apply-ready and self-contained (Secret + CRs in one
file) so `kubectl apply -f` just works after filling in `REPLACE_ME`.
### Adding an example: which of the two homes it belongs to
There are **two** conventions, and the number tells you which:
**01–20 — the `docs/examples.md` ladder.** A three-touch change:
1. Create `deploy/examples/NN-name.yaml`.
2. Add a `## Example NN — …` section in `docs/examples.md` with the
`--8<-- "deploy/examples/NN-name.yaml"` snippet inside a `yaml` fence.
3. Add a row to the table at the top of `docs/examples.md`.
**21+ — capability-page inclusion.** The ladder is a *tutorial* sequence and
stops at 20 deliberately; everything after it is a per-capability example that
belongs beside the prose explaining that capability, not at the end of a
tutorial. So a two-touch change:
1. Create `deploy/examples/NN-name.yaml`, usually with
`# --8<-- [start:…]` / `[end:…]` section markers so the page can pull just
the CR that teaches the point.
2. Snippet-include it from the capability page that documents the field
(`docs/replication.md` for 19's replication CR, `docs/repositories.md` for
the `spec.seed` examples, `docs/backends/s3.md` for 38, …).
**Do not** add a `docs/examples.md` row/section for a 21+ example — that is
how the same manifest ends up documented twice and the two copies drift.
Either way the file must be reachable from *some* page: an example nothing
includes is an orphan, and nothing in the build catches it.
**Scenario bundles** are a third home: `deploy/examples/scenarios/NN-name.yaml`,
one per `docs/scenarios/*.md` page, pulled by that page (whole-file or by
section) and listed in the scenarios index table. They are typed-checked by
`crates/api/tests/examples_match_crd_shapes.rs` like everything else.
A new top-level **page** (not an example) also needs an entry in the `nav:` of
`mkdocs.yml`, or it builds unlinked (and `--strict` warns). A new **scenario**
page additionally needs its row in `docs/scenarios/index.md`.
## Docs change in the same PR as the behavior
**Whenever you change logic that affects how someone deploys, uses, or configures
Kopiur, update the docs in the same change.** This is not a follow-up task.
Triggers that REQUIRE a docs/examples update:
| You changed… | Update… |
|---|---|
| A CRD field / shape / default in `crates/api` | the relevant `docs/*.md` prose **and** any example manifest that uses it |
| A Helm value or install scope (`deploy/helm`) | `docs/install.md` |
| RBAC / SA / mover behavior | `docs/movers.md` |
| Maintenance defaults or projection | `docs/maintenance.md` |
| A webhook-enforced constraint | the affected page (state it as a `/// warning` admonition) + the example that would otherwise violate it |
| A reconciler UX change (status, print columns, phases) | wherever that surface is described |
Field shapes shown in docs/examples must be the real ones — the manifests are
apply-ready, so a wrong field is a user-facing bug, not a typo.
## Verify before claiming done
```bash
mise run docs # mkdocs build --strict (broken link / missing nav file = build fail)The build also expands every snippet — a renamed/missing example file fails here
(snippets check_paths is on). --strict additionally validates heading anchors,
so a deep-link to a #section that no longer exists fails too. Don't claim a docs
change is done without a green mise run docs. For a fast inner loop without the
rustdoc nesting, use mise run docs-serve (live-reload mkdocs serve). If you
added/changed a manifest, the field shapes should be the same ones the tests in
crates/api accept (see [[kopiur-design]] for the from_yaml parse path); a
manifest that wouldn't survive admission is wrong even if the site builds.
.md instead of snippet-including a file → drift.docs/examples.md table
row or the section (or vice-versa) → orphaned file or dead reference.docs/examples.md ladder as well as its
capability page → the same manifest documented twice, and the copies drift.nav: in mkdocs.yml → builds unlinked.!!! note form (4-space-indented body)
instead of the /// note | Title … /// blocks form → the title renders as
literal text and the indented body becomes a code block (it does not error —
eyeball the rendered page or grep the built HTML for class="admonition).© home-operations, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/documentation of home-operations/kopiur.
Open the folder on GitHubat commit 379efb7
Documentation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Documentation this skillhome-operations/kopiur | 113 | — | ~2.5k | Automated safety check: Pass | AGPL-3.0 | |
| KubeSphere Multi-Tenant Managementkubesphere/kubesphere | 17k | 1 repos | ~3.1k | Automated safety check: Pass | Custom licence | |
| Kubernetes SpecialistJeffallan/claude-skills | 12k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Kubernetes Patternstimothywarner-org/claude-code | 224 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Azure Bastion Jitvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Kubernetes Patternsaffaan-m/ECC | 275k | 1 repos | ~5k | Automated safety check: Pass | MIT |
kubesphere/kubesphere
Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.
Jeffallan/claude-skills
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
timothywarner-org/claude-code
Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
affaan-m/ECC
Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments.
mukul975/Anthropic-Cybersecurity-Skills
Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation.
home-operations/kopiur
How Kopiur does strongly-typed, actionable error handling and end-to-end testing.
home-operations/kopiur
Design norms and locked decisions for the Kopiur Kopia-native Kubernetes backup operator (Rust/kube-rs).
Works with
Categories
How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/. Documentation is an agent skill from home-operations/kopiur. How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/.
Documentation fits situations like: editing any doc page; changing an example manifest; whenever you change operator behavior that affects how someone deploys; configures Kopiur (CRD fields.
Run `npx skills add home-operations/kopiur --skill documentation -a claude-code`. Or copy the skill folder (.claude/skills/documentation in home-operations/kopiur) into .claude/skills/documentation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add home-operations/kopiur --skill documentation -a codex`. Or copy the skill folder (.claude/skills/documentation in home-operations/kopiur) into .agents/skills/documentation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add home-operations/kopiur --skill documentation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/documentation, .gemini/skills/documentation, .github/skills/documentation and .opencode/skills/documentation in your project.
Going by SKILL.md and its folder, Documentation needs the command-line tools its instructions call (mise and kubectl) and credentials named KOPIA_PASSWORD.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Documentation is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Documentation: KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Kubernetes Specialist (Jeffallan/claude-skills, 12k stars), Kubernetes Patterns (timothywarner-org/claude-code, 224 stars) and Azure Bastion Jit (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
home-operations (a GitHub organization) maintains it in home-operations/kopiur, which has 113 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.
Source: home-operations/kopiur on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.