Agent skill

Kc Entrypoint Change

by imran31415 in imran31415/kube-coder

Safely edit the workspace pod's boot scripts (start.sh, the entrypoint/ssh-server configmaps) in kube-coder.

MITAuto-check: notesDevOps & Cloud

Install Kc Entrypoint Change

skills CLI
$ npx skills add imran31415/kube-coder --skill kc-entrypoint-change -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install imran31415/kube-coder kc-entrypoint-change --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/imran31415/kube-coder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/kc-entrypoint-change .claude/skills/kc-entrypoint-change && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kc-entrypoint-change
GitHub stars
388
Token cost
~1.3k tokens
SKILL.md length
464 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Safely edit the workspace pod's boot scripts (start.sh, the entrypoint/ssh-server configmaps) in kube-coder.

  • Changing anything that runs at pod start — credential wiring
  • SKILL.md covers Where boot logic lives, Footgun 1 — the two-home…, Footgun 2 — tpl runs Go… and Footgun 3 — configmap YAML…, plus 4 more sections
  • Calls helm and bash
  • Tmux/ttyd config

What it does

Kc Entrypoint Change is an agent skill from imran31415/kube-coder. Safely edit the workspace pod's boot scripts (start.sh, the entrypoint/ssh-server configmaps) in kube-coder. Use when changing anything that runs at pod start — credential wiring, service launch, tmux/ttyd config, symlinks — where the two-home layout and Helm templating have non-obvious footguns.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with tmux. The repository describes itself as: helm chart for a isolated dev coding environment pod in kubernetes. The licence is MIT.

When your agent uses it

  • Changing anything that runs at pod start — credential wiring
  • Tmux/ttyd config
  • Symlinks — where the two-home layout and Helm templating have non-obvious footguns

Example prompts

  • “/kc-entrypoint-change”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Edit, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit fc0b886. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • helm
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use helm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kc Entrypoint Change loads about 1.3k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 464 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Edit, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from imran31415/kube-coder at commit fc0b886, republished under its MIT licence (© imran31415). 464 words, ~1,253 tokens.

Download SKILL.mdSave it as .claude/skills/kc-entrypoint-change/SKILL.md (or your agent's skills folder).
name
kc-entrypoint-change
description
Safely edit the workspace pod's boot scripts (start.sh, the entrypoint/ssh-server configmaps) in kube-coder. Use when changing anything that runs at pod start — credential wiring, service launch, tmux/ttyd config, symlinks — where the two-home layout and Helm templating have non-obvious footguns.
allowed-tools
Bash, Read, Edit, Grep
user-invocable
true
argument-hint
[what you want the boot script to do]

Editing kube-coder boot scripts safely

Changes to the pod entrypoint affect every workspace on next restart, and a mistake can break boot for everyone. This skill captures the gotchas and the validation loop.

Where boot logic lives

  • charts/workspace/start.sh — the main IDE container entrypoint. Shipped into a ConfigMap via {{ tpl (.Files.Get "start.sh") . | indent 4 }} in templates/workspace-entrypoint-configmap.yaml, and run as command: ["/bin/bash","-l","/workspace-entrypoint/start.sh"].
  • charts/workspace/templates/ssh-server-configmap.yaml — the SSH sidecar entrypoint (data.entrypoint.sh), gated by {{- if .Values.ssh.enabled }}.
  • charts/workspace/templates/terminal-entry-configmap.yaml — the per-ttyd connection script (tmux attach / DEC-mode resets).

Prefer editing start.sh as a real file; the configmaps are YAML block scalars.

Footgun 1 — the two-home layout (MOST IMPORTANT)

There are two home directories:

  • /home/dev — the persistent PVC. Survives restarts.
  • /home/ubuntu — ephemeral. Wiped on every pod restart.

start.sh and the interactive terminals (ttyd, code-server, SSH) run with HOME=/home/ubuntu. That's why /home/ubuntu/.ssh is a symlink but /home/dev/.ssh doesn't exist. Anything a tool writes under $HOME is lost on restart unless it's redirected onto /home/dev.

The established pattern to persist something is: keep the real data under /home/dev/... (secrets go in /home/dev/.credentials/), and symlink the ephemeral $HOME path to it. See the persist_cred helper and the for HOME_DIR in /home/ubuntu loops in start.sh, and the mirrored block in ssh-server-configmap.yaml (the sidecar has its own ephemeral /home/ubuntu, so it needs the symlinks independently).

When persisting a new credential/config: migrate any pre-existing login onto the PVC once with cp -an (archive + no-clobber, so a real PVC login is never overwritten by a stale ephemeral copy), then replace with a symlink. Make it idempotent — guard with [ -L "$link" ] so re-runs don't nest symlinks.

Show full SKILL.md (206 more words)Show less

Footgun 2 — tpl runs Go templating over start.sh

Because the configmap uses {{ tpl (.Files.Get "start.sh") . }}, any literal {{ ... }} in start.sh is interpreted by Helm. Plain shell ($VAR, $(cmd), backticks) is fine, but never introduce {{/}} unless you mean a template action. After editing, always render (below) to catch this.

Footgun 3 — configmap YAML indentation

The sidecar script is a data.entrypoint.sh: | block scalar at 4-space indent. Keep added lines at the same indent; a stray dedent silently truncates the script. helm template will surface most of these.

Footgun 4 — two ttyd launch sites

start.sh launches ttyd once at boot and relaunches it in the watchdog loop. If you change ttyd flags, change both occurrences (grep for ttyd).

Footgun 5 — overwrite-on-boot files

CLAUDE.md/claude-md.txt, ~/.tmux.conf, and the OpenCode config are rewritten every boot so chart edits propagate. Don't add logic that "preserves existing" for these — it defeats the design. User notes belong in the persistent-memory subsystem, not these files.

Validation loop (always run before pushing)

bash
# 1. Shell syntax — a broken start.sh breaks boot for every workspace.
bash -n charts/workspace/start.sh

# 2. Render through Helm (catches tpl + YAML indent errors, proves it ships).
export PATH="$HOME/.local/bin:$PATH"
helm template test-ws charts/workspace/ -f charts/workspace/tests/test-values.yaml >/tmp/r.yaml
grep -n "<a string from your change>" /tmp/r.yaml    # confirm it rendered
# sidecar is gated — render it with ssh on:
helm template test-ws charts/workspace/ -f charts/workspace/tests/test-values.yaml \
  --set ssh.enabled=true >/tmp/r-ssh.yaml

# 3. If you can, unit-execute the logic in a sandbox against fake /home dirs
#    (extract the function, rebind paths to /tmp, stub chown) to prove
#    fresh / migrate / no-clobber / idempotent behavior.

Add a regression test

Boot-script behavior is covered by helm-unittest files in charts/workspace/tests/*_test.yaml. Add matchRegex assertions on data["start.sh"] (and data["entrypoint.sh"] for the sidecar, with set: {ssh.enabled: true}) so your change can't silently regress. Model it on credential_persist_test.yaml or browser_gate_test.yaml. Then:

bash
helm unittest charts/workspace/

Finish by running kc-preflight, then kc-ship-pr.

© imran31415, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/kc-entrypoint-change of imran31415/kube-coder.

Open the folder on GitHubat commit fc0b886

Compare with similar skills

Kc Entrypoint Change next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kc Entrypoint Change compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kc Entrypoint Change this skillimran31415/kube-coder388—~1.3kAutomated safety check: NotesMIT
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from imran31415/kube-coder

All 8 skills in this repo
  • Kc Issue

    imran31415/kube-coder

    Spin up an isolated agent to work a GitHub issue of kube-coder or any other repo checked out in the workspace.

    388 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check: notes
  • Kc Screenshot

    imran31415/kube-coder

    Capture desktop + mobile, dark + light screenshots of the kube-coder dashboard SPA for visual QA of a UI change.

    388 GitHub stars~870 tokensUpdated yesterday
    Auto-check: notes
  • Kc Ship PR

    imran31415/kube-coder

    Commit local changes and open a pull request against kube-coder from inside a workspace pod.

    388 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Remote Task

    imran31415/kube-coder

    Launch a Claude task on a remote kube-coder workspace, check task status, or attach to a running session.

    388 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check: notes
  • Kc Preflight

    imran31415/kube-coder

    Run kube-coder's full CI suite locally before pushing — helm lint + unit tests, server.py tests, dashboard + controller SPA builds + vitest, and shell syntax checks.

    388 GitHub stars~1k tokensUpdated yesterday
    Auto-check: notes
  • Kc Scope PR

    imran31415/kube-coder

    Scope a kube-coder change before you open or update a PR — what the diff actually touches, which tests reach it, what the change made worse, and what is left untested.

    388 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Kc Entrypoint Change

What does Kc Entrypoint Change do?

Safely edit the workspace pod's boot scripts (start.sh, the entrypoint/ssh-server configmaps) in kube-coder. Kc Entrypoint Change is an agent skill from imran31415/kube-coder.sh, the entrypoint/ssh-server configmaps) in kube-coder.

When should I use Kc Entrypoint Change?

Kc Entrypoint Change fits situations like: changing anything that runs at pod start — credential wiring; tmux/ttyd config; symlinks — where the two-home layout and Helm templating have non-obvious footguns.

How do I install Kc Entrypoint Change in Claude Code?

Run `npx skills add imran31415/kube-coder --skill kc-entrypoint-change -a claude-code`. Or copy the skill folder (.claude/skills/kc-entrypoint-change in imran31415/kube-coder) into .claude/skills/kc-entrypoint-change in your project. Claude Code loads it when a task matches its description.

How do I install Kc Entrypoint Change in Codex?

Run `npx skills add imran31415/kube-coder --skill kc-entrypoint-change -a codex`. Or copy the skill folder (.claude/skills/kc-entrypoint-change in imran31415/kube-coder) into .agents/skills/kc-entrypoint-change in your project. Codex loads it when a task matches its description.

Can I use Kc Entrypoint Change in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add imran31415/kube-coder --skill kc-entrypoint-change -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kc-entrypoint-change, .gemini/skills/kc-entrypoint-change, .github/skills/kc-entrypoint-change and .opencode/skills/kc-entrypoint-change in your project.

What does Kc Entrypoint Change need to run?

Going by SKILL.md and its folder, Kc Entrypoint Change needs the command-line tools its instructions call (helm and bash). Its frontmatter pre-approves these tools: Bash, Read, Edit, Grep.

Does Kc Entrypoint Change access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kc Entrypoint Change safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kc Entrypoint Change use?

Kc Entrypoint Change is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kc Entrypoint Change use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kc Entrypoint Change?

Skills that share tags, products or a category with Kc Entrypoint Change: Sim Helm (simstudioai/sim, 30k stars), Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars), Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars) and Nginx To Higress Migration (higress-group/higress, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kc Entrypoint Change?

imran31415 (a GitHub user) maintains it in imran31415/kube-coder, which has 388 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 8, 2026.

Source: imran31415/kube-coder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.