Agent skill

Kubernetes Specialist

by Jeffallan in Jeffallan/claude-skills

Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

MITAuto-check passedDevOps & Cloud

Install Kubernetes Specialist

skills CLI
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Jeffallan/claude-skills kubernetes-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubernetes-specialist .claude/skills/kubernetes-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes-specialist
GitHub stars
12k
Used in
1 other repo
Token cost
~2.1k tokens
SKILL.md length
397 words
Files
12 (incl. references)
Skills in repo
58
Repo updated
First seen
Licence
MIT

At a glance

Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

  • Works in 5 steps: Analyze requirements — Understand… → Design architecture — Choose workload… → Implement manifests — Create declarative… → …
  • Writing Deployment, StatefulSet or CronJob manifests with limits and probes
  • SKILL.md covers When to Use This Skill, Core Workflow, Reference Guide and Constraints, plus 3 more sections
  • Calls kubectl

What it does

The agent analyzes workload and scaling needs, picks workload types, networking and storage, writes declarative YAML with resource limits and health checks, applies RBAC, NetworkPolicies and Pod Security Standards, then validates. Validation uses kubectl rollout status, kubectl get pods -w and kubectl describe pod to confirm health, with kubectl rollout undo as the way back if a rollout goes wrong.

Eleven reference files cover workloads, networking, configuration, storage, Helm charts, troubleshooting, custom operators, service meshes such as Istio and Linkerd, GitOps with ArgoCD and Flux, cost optimization with VPA and HPA tuning, and multi-cluster setups. The rules ask for declarative manifests over imperative commands, requests and limits on every container, liveness and readiness probes, and secrets instead of hardcoded credentials.

When your agent uses it

  • Writing Deployment, StatefulSet or CronJob manifests with limits and probes
  • Locking down a namespace with RBAC and NetworkPolicies
  • Packaging an application as a Helm chart
  • Debugging crashing pods using logs, events and kubectl describe
  • Right-sizing workloads or setting up GitOps delivery

Example prompts

  • “Write a Deployment and Service for the payments API with requests, limits and readiness probes.”
  • “Add NetworkPolicies so only the frontend namespace can reach the database pods.”
  • “Pods in the checkout namespace keep restarting, so work out why from the events and logs.”
  • “Turn these manifests into a Helm chart with separate values files for staging and production.”

Requirements

  • `kubectl` access to a Kubernetes cluster

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Analyze requirements — Understand workload characteristics, scaling needs, security requirements
  2. Design architecture — Choose workload types, networking patterns, storage solutions
  3. Implement manifests — Create declarative YAML with proper resource limits, health checks
  4. Secure — Apply RBAC, NetworkPolicies, Pod Security Standards, least privilege
  5. Validate — Run kubectl rollout status, kubectl get pods -w, and kubectl describe pod to confirm health; roll back with kubectl rollout…

What it can do on your machine

Read from SKILL.md and the folder at commit 1be15d8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • synergetic.solutions
    • jeffallan.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kubernetes Specialist loads about 2.1k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~33k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Jeffallan/claude-skills at commit 1be15d8, republished under its MIT licence (© Jeffallan). 397 words, ~2,084 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes-specialist/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
kubernetes-specialist
description
Use when deploying or managing Kubernetes workloads. Invoke to create deployment manifests, configure pod security policies, set up service accounts, define network isolation rules, debug pod crashes, analyze resource limits, inspect container logs, or right-size workloads. Use for Helm charts, RBAC policies, NetworkPolicies, storage configuration, performance optimization, GitOps pipelines, and multi-cluster management.
license
MIT
metadata.author
https://github.com/Jeffallan
metadata.company
https://synergetic.solutions
metadata.version
1.1.1
metadata.domain
infrastructure
metadata.triggers
Kubernetes, K8s, kubectl, Helm, container orchestration, pod deployment, RBAC, NetworkPolicy, Ingress, StatefulSet, Operator, CRD, CustomResourceDefinition…
metadata.role
specialist
metadata.scope
infrastructure
metadata.output-format
manifests
metadata.related-skills
devops-engineer, cloud-architect, sre-engineer, terraform-engineer, security-reviewer, chaos-engineer

Kubernetes Specialist

When to Use This Skill

  • Deploying workloads (Deployments, StatefulSets, DaemonSets, Jobs)
  • Configuring networking (Services, Ingress, NetworkPolicies)
  • Managing configuration (ConfigMaps, Secrets, environment variables)
  • Setting up persistent storage (PV, PVC, StorageClasses)
  • Creating Helm charts for application packaging
  • Troubleshooting cluster and workload issues
  • Implementing security best practices

Core Workflow

  1. Analyze requirements — Understand workload characteristics, scaling needs, security requirements
  2. Design architecture — Choose workload types, networking patterns, storage solutions
  3. Implement manifests — Create declarative YAML with proper resource limits, health checks
  4. Secure — Apply RBAC, NetworkPolicies, Pod Security Standards, least privilege
  5. Validate — Run kubectl rollout status, kubectl get pods -w, and kubectl describe pod <name> to confirm health; roll back with kubectl rollout undo if needed

Reference Guide

Load detailed guidance based on context:

TopicReferenceLoad When
Workloadsreferences/workloads.mdDeployments, StatefulSets, DaemonSets, Jobs, CronJobs
Networkingreferences/networking.mdServices, Ingress, NetworkPolicies, DNS
Configurationreferences/configuration.mdConfigMaps, Secrets, environment variables
Storagereferences/storage.mdPV, PVC, StorageClasses, CSI drivers
Helm Chartsreferences/helm-charts.mdChart structure, values, templates, hooks, testing, repositories
Troubleshootingreferences/troubleshooting.mdkubectl debug, logs, events, common issues
Custom Operatorsreferences/custom-operators.mdCRD, Operator SDK, controller-runtime, reconciliation
Service Meshreferences/service-mesh.mdIstio, Linkerd, traffic management, mTLS, canary
GitOpsreferences/gitops.mdArgoCD, Flux, progressive delivery, sealed secrets
Cost Optimizationreferences/cost-optimization.mdVPA, HPA tuning, spot instances, quotas, right-sizing
Multi-Clusterreferences/multi-cluster.mdCluster API, federation, cross-cluster networking, DR

Constraints

Show full SKILL.md (181 more words)Show less
MUST DO
  • Use declarative YAML manifests (avoid imperative kubectl commands)
  • Set resource requests and limits on all containers
  • Include liveness and readiness probes
  • Use secrets for sensitive data (never hardcode credentials)
  • Apply least privilege RBAC permissions
  • Implement NetworkPolicies for network segmentation
  • Use namespaces for logical isolation
  • Label resources consistently for organization
  • Document configuration decisions in annotations
MUST NOT DO
  • Deploy to production without resource limits
  • Store secrets in ConfigMaps or as plain environment variables
  • Use default ServiceAccount for application pods
  • Allow unrestricted network access (default allow-all)
  • Run containers as root without justification
  • Skip health checks (liveness/readiness probes)
  • Use latest tag for production images
  • Expose unnecessary ports or services

Common YAML Patterns

Deployment with resource limits, probes, and security context
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-app
  namespace: my-namespace
  labels:
    app: my-app
    version: "1.2.3"
spec:
  replicas: 3
  selector:
    matchLabels:
      app: my-app
  template:
    metadata:
      labels:
        app: my-app
        version: "1.2.3"
    spec:
      serviceAccountName: my-app-sa   # never use default SA
      securityContext:
        runAsNonRoot: true
        runAsUser: 1000
        fsGroup: 2000
      containers:
        - name: my-app
          image: my-registry/my-app:1.2.3   # never use latest
          ports:
            - containerPort: 8080
          resources:
            requests:
              cpu: "100m"
              memory: "128Mi"
            limits:
              cpu: "500m"
              memory: "512Mi"
          livenessProbe:
            httpGet:
              path: /healthz
              port: 8080
            initialDelaySeconds: 15
            periodSeconds: 20
          readinessProbe:
            httpGet:
              path: /ready
              port: 8080
            initialDelaySeconds: 5
            periodSeconds: 10
          securityContext:
            allowPrivilegeEscalation: false
            readOnlyRootFilesystem: true
            capabilities:
              drop: ["ALL"]
          envFrom:
            - secretRef:
                name: my-app-secret   # pull credentials from Secret, not ConfigMap
Minimal RBAC (least privilege)
yaml
apiVersion: v1
kind: ServiceAccount
metadata:
  name: my-app-sa
  namespace: my-namespace
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: my-app-role
  namespace: my-namespace
rules:
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["get", "list"]   # grant only what is needed
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: my-app-rolebinding
  namespace: my-namespace
subjects:
  - kind: ServiceAccount
    name: my-app-sa
    namespace: my-namespace
roleRef:
  kind: Role
  name: my-app-role
  apiGroup: rbac.authorization.k8s.io
NetworkPolicy (default-deny + explicit allow)
yaml
# Deny all ingress and egress by default
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
  namespace: my-namespace
spec:
  podSelector: {}
  policyTypes: ["Ingress", "Egress"]
---
# Allow only specific traffic
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-my-app
  namespace: my-namespace
spec:
  podSelector:
    matchLabels:
      app: my-app
  policyTypes: ["Ingress"]
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: frontend
      ports:
        - protocol: TCP
          port: 8080

Validation Commands

After deploying, verify health and security posture:

bash
# Watch rollout complete
kubectl rollout status deployment/my-app -n my-namespace

# Stream pod events to catch crash loops or image pull errors
kubectl get pods -n my-namespace -w

# Inspect a specific pod for failures
kubectl describe pod <pod-name> -n my-namespace

# Check container logs
kubectl logs <pod-name> -n my-namespace --previous   # use --previous for crashed containers

# Verify resource usage vs. limits
kubectl top pods -n my-namespace

# Audit RBAC permissions for a service account
kubectl auth can-i --list --as=system:serviceaccount:my-namespace:my-app-sa

# Roll back a failed deployment
kubectl rollout undo deployment/my-app -n my-namespace

Output Templates

When implementing Kubernetes resources, provide:

  1. Complete YAML manifests with proper structure
  2. RBAC configuration if needed (ServiceAccount, Role, RoleBinding)
  3. NetworkPolicy for network isolation
  4. Brief explanation of design decisions and security considerations

Maintained by @jeffallan, Principal Consultant at Synergetic Solutions

Documentation

© Jeffallan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references) in skills/kubernetes-specialist of Jeffallan/claude-skills.

  • SKILL.md
  • references/configuration.md
  • references/cost-optimization.md
  • references/custom-operators.md
  • references/gitops.md
  • references/helm-charts.md
  • references/multi-cluster.md
  • references/networking.md
  • references/service-mesh.md
  • references/storage.md
  • references/troubleshooting.md
  • references/workloads.md

Open the folder on GitHubat commit 1be15d8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Jeffallan/claude-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Kubernetes Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubernetes Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubernetes Specialist this skillJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Kubernetes ArchitectCybereason-Public/owLSM2809 repos~2.6kAutomated safety check: PassGPL-2.0
GitOps with ArgoCD and Fluxwshobson/agents40k12 repos~1.5kAutomated safety check: PassMIT
Signozqjoly/GitOps112—~6.1kAutomated safety check: PassWTFPL
Ksaildevantler-tech/ksail165—~1.1kAutomated safety check: PassCustom licence
Argocd GitopsBagelHole/DevOps-Security-Agent-Skills1.2k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 9 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 12 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Signoz

    qjoly/GitOps

    Manage the self-hosted SigNoz observability stack in this GitOps repo.

    112 GitHub stars~6.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Ksail

    devantler-tech/ksail

    Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.

    165 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Argocd Gitops

    BagelHole/DevOps-Security-Agent-Skills

    Implement GitOps with ArgoCD for declarative Kubernetes deployments.

    1.2k GitHub stars~2.4k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Deploying Applications

    ancoleman/ai-design-components

    Deployment patterns from Kubernetes to serverless and edge functions.

    525 GitHub stars~3.1k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed

More from Jeffallan/claude-skills

All 58 skills in this repo
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Pandas Pro

    Jeffallan/claude-skills

    Handles pandas DataFrame work: cleaning, merging, groupby aggregation, pivots, time-series resampling and memory tuning, with checks on dtypes, shapes and nulls.

    12k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Apache Spark Engineer

    Jeffallan/claude-skills

    Guides writing and tuning Apache Spark jobs: DataFrame and RDD code, Spark SQL, partitioning, caching, shuffle tuning and structured streaming.

    12k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • TypeScript Pro

    Jeffallan/claude-skills

    Designs advanced TypeScript types: generics, conditional and mapped types, branded types, discriminated unions and type guards, with tsc checks and tRPC type safety.

    12k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Categories

Questions about Kubernetes Specialist

What does Kubernetes Specialist do?

Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps. The agent analyzes workload and scaling needs, picks workload types, networking and storage, writes declarative YAML with resource limits and health checks, applies RBAC, NetworkPolicies and Pod Security Standards, then validates. Validation uses kubectl rollout status, kubectl get pods -w and kubectl describe pod to confirm health, with kubectl rollout undo as the way back if a rollout goes wrong.

When should I use Kubernetes Specialist?

Kubernetes Specialist fits situations like: writing Deployment, StatefulSet or CronJob manifests with limits and probes; locking down a namespace with RBAC and NetworkPolicies; packaging an application as a Helm chart; debugging crashing pods using logs, events and kubectl describe.

How do I install Kubernetes Specialist in Claude Code?

Run `npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a claude-code`. Or copy the skill folder (skills/kubernetes-specialist in Jeffallan/claude-skills) into .claude/skills/kubernetes-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Kubernetes Specialist in Codex?

Run `npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a codex`. Or copy the skill folder (skills/kubernetes-specialist in Jeffallan/claude-skills) into .agents/skills/kubernetes-specialist in your project. Codex loads it when a task matches its description.

Can I use Kubernetes Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes-specialist, .gemini/skills/kubernetes-specialist, .github/skills/kubernetes-specialist and .opencode/skills/kubernetes-specialist in your project.

What does Kubernetes Specialist need to run?

Going by SKILL.md and its folder, Kubernetes Specialist needs the command-line tools its instructions call (kubectl). Our summary lists: `kubectl` access to a Kubernetes cluster.

Does Kubernetes Specialist access the network?

SKILL.md names 3 domains. As links in the text: github.com, synergetic.solutions and jeffallan.github.io. This is read from the text; nothing was executed.

Is Kubernetes Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kubernetes Specialist use?

Kubernetes Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubernetes Specialist use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.

What are the alternatives to Kubernetes Specialist?

Skills that share tags, products or a category with Kubernetes Specialist: Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), GitOps with ArgoCD and Flux (wshobson/agents, 40k stars), Signoz (qjoly/GitOps, 112 stars) and Ksail (devantler-tech/ksail, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubernetes Specialist?

Jeffallan (a GitHub user) maintains it in Jeffallan/claude-skills, which has 11,802 GitHub stars. The repository holds 58 skills in this directory. The repository was last updated on October 3, 2026.

Source: Jeffallan/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.