Kubernetes Architect
Cybereason-Public/owLSM
Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Jeffallan/claude-skills kubernetes-specialist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubernetes-specialist .claude/skills/kubernetes-specialist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kubernetes-specialist" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialist into .claude/skills/kubernetes-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-specialist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Jeffallan/claude-skills kubernetes-specialist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kubernetes-specialist .agents/skills/kubernetes-specialist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kubernetes-specialist" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialist into .agents/skills/kubernetes-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-specialist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Jeffallan/claude-skills kubernetes-specialist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kubernetes-specialist .cursor/skills/kubernetes-specialist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kubernetes-specialist" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialist into .cursor/skills/kubernetes-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-specialist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Jeffallan/claude-skills.git --path skills/kubernetes-specialist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Jeffallan/claude-skills kubernetes-specialist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kubernetes-specialist .gemini/skills/kubernetes-specialist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kubernetes-specialist" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialist into .gemini/skills/kubernetes-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-specialist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Jeffallan/claude-skills kubernetes-specialistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kubernetes-specialist .github/skills/kubernetes-specialist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kubernetes-specialist" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialist into .github/skills/kubernetes-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-specialist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Jeffallan/claude-skills kubernetes-specialist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kubernetes-specialist .opencode/skills/kubernetes-specialist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kubernetes-specialist" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/kubernetes-specialist into .opencode/skills/kubernetes-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-specialist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kubernetes-specialistCreates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
The agent analyzes workload and scaling needs, picks workload types, networking and storage, writes declarative YAML with resource limits and health checks, applies RBAC, NetworkPolicies and Pod Security Standards, then validates. Validation uses kubectl rollout status, kubectl get pods -w and kubectl describe pod to confirm health, with kubectl rollout undo as the way back if a rollout goes wrong.
Eleven reference files cover workloads, networking, configuration, storage, Helm charts, troubleshooting, custom operators, service meshes such as Istio and Linkerd, GitOps with ArgoCD and Flux, cost optimization with VPA and HPA tuning, and multi-cluster setups. The rules ask for declarative manifests over imperative commands, requests and limits on every container, liveness and readiness probes, and secrets instead of hardcoded credentials.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1be15d8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comsynergetic.solutionsjeffallan.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kubernetes Specialist loads about 2.1k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 397 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Jeffallan/claude-skills at commit 1be15d8, republished under its MIT licence (© Jeffallan). 397 words, ~2,084 tokens.
.claude/skills/kubernetes-specialist/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.kubectl rollout status, kubectl get pods -w, and kubectl describe pod <name> to confirm health; roll back with kubectl rollout undo if neededLoad detailed guidance based on context:
| Topic | Reference | Load When |
|---|---|---|
| Workloads | references/workloads.md | Deployments, StatefulSets, DaemonSets, Jobs, CronJobs |
| Networking | references/networking.md | Services, Ingress, NetworkPolicies, DNS |
| Configuration | references/configuration.md | ConfigMaps, Secrets, environment variables |
| Storage | references/storage.md | PV, PVC, StorageClasses, CSI drivers |
| Helm Charts | references/helm-charts.md | Chart structure, values, templates, hooks, testing, repositories |
| Troubleshooting | references/troubleshooting.md | kubectl debug, logs, events, common issues |
| Custom Operators | references/custom-operators.md | CRD, Operator SDK, controller-runtime, reconciliation |
| Service Mesh | references/service-mesh.md | Istio, Linkerd, traffic management, mTLS, canary |
| GitOps | references/gitops.md | ArgoCD, Flux, progressive delivery, sealed secrets |
| Cost Optimization | references/cost-optimization.md | VPA, HPA tuning, spot instances, quotas, right-sizing |
| Multi-Cluster | references/multi-cluster.md | Cluster API, federation, cross-cluster networking, DR |
apiVersion: apps/v1
kind: Deployment
metadata:
name: my-app
namespace: my-namespace
labels:
app: my-app
version: "1.2.3"
spec:
replicas: 3
selector:
matchLabels:
app: my-app
template:
metadata:
labels:
app: my-app
version: "1.2.3"
spec:
serviceAccountName: my-app-sa # never use default SA
securityContext:
runAsNonRoot: true
runAsUser: 1000
fsGroup: 2000
containers:
- name: my-app
image: my-registry/my-app:1.2.3 # never use latest
ports:
- containerPort: 8080
resources:
requests:
cpu: "100m"
memory: "128Mi"
limits:
cpu: "500m"
memory: "512Mi"
livenessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 15
periodSeconds: 20
readinessProbe:
httpGet:
path: /ready
port: 8080
initialDelaySeconds: 5
periodSeconds: 10
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
envFrom:
- secretRef:
name: my-app-secret # pull credentials from Secret, not ConfigMapapiVersion: v1
kind: ServiceAccount
metadata:
name: my-app-sa
namespace: my-namespace
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: my-app-role
namespace: my-namespace
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list"] # grant only what is needed
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: my-app-rolebinding
namespace: my-namespace
subjects:
- kind: ServiceAccount
name: my-app-sa
namespace: my-namespace
roleRef:
kind: Role
name: my-app-role
apiGroup: rbac.authorization.k8s.io# Deny all ingress and egress by default
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-all
namespace: my-namespace
spec:
podSelector: {}
policyTypes: ["Ingress", "Egress"]
---
# Allow only specific traffic
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-my-app
namespace: my-namespace
spec:
podSelector:
matchLabels:
app: my-app
policyTypes: ["Ingress"]
ingress:
- from:
- podSelector:
matchLabels:
app: frontend
ports:
- protocol: TCP
port: 8080After deploying, verify health and security posture:
# Watch rollout complete
kubectl rollout status deployment/my-app -n my-namespace
# Stream pod events to catch crash loops or image pull errors
kubectl get pods -n my-namespace -w
# Inspect a specific pod for failures
kubectl describe pod <pod-name> -n my-namespace
# Check container logs
kubectl logs <pod-name> -n my-namespace --previous # use --previous for crashed containers
# Verify resource usage vs. limits
kubectl top pods -n my-namespace
# Audit RBAC permissions for a service account
kubectl auth can-i --list --as=system:serviceaccount:my-namespace:my-app-sa
# Roll back a failed deployment
kubectl rollout undo deployment/my-app -n my-namespaceWhen implementing Kubernetes resources, provide:
Maintained by @jeffallan, Principal Consultant at Synergetic Solutions
© Jeffallan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (references) in skills/kubernetes-specialist of Jeffallan/claude-skills.
Open the folder on GitHubat commit 1be15d8
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Jeffallan/claude-skills, which our catalogue first saw on October 7, 2026.
Kubernetes Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kubernetes Specialist this skillJeffallan/claude-skills | 12k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Kubernetes ArchitectCybereason-Public/owLSM | 280 | 9 repos | ~2.6k | Automated safety check: Pass | GPL-2.0 | |
| GitOps with ArgoCD and Fluxwshobson/agents | 40k | 12 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Signozqjoly/GitOps | 112 | — | ~6.1k | Automated safety check: Pass | WTFPL | |
| Ksaildevantler-tech/ksail | 165 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Argocd GitopsBagelHole/DevOps-Security-Agent-Skills | 1.2k | — | ~2.4k | Automated safety check: Pass | MIT |
Cybereason-Public/owLSM
Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.
wshobson/agents
Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.
qjoly/GitOps
Manage the self-hosted SigNoz observability stack in this GitOps repo.
devantler-tech/ksail
Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.
BagelHole/DevOps-Security-Agent-Skills
Implement GitOps with ArgoCD for declarative Kubernetes deployments.
ancoleman/ai-design-components
Deployment patterns from Kubernetes to serverless and edge functions.
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
Jeffallan/claude-skills
Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.
Jeffallan/claude-skills
Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.
Jeffallan/claude-skills
Handles pandas DataFrame work: cleaning, merging, groupby aggregation, pivots, time-series resampling and memory tuning, with checks on dtypes, shapes and nulls.
Jeffallan/claude-skills
Guides writing and tuning Apache Spark jobs: DataFrame and RDD code, Spark SQL, partitioning, caching, shuffle tuning and structured streaming.
Jeffallan/claude-skills
Designs advanced TypeScript types: generics, conditional and mapped types, branded types, discriminated unions and type guards, with tsc checks and tRPC type safety.
Works with
Categories
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps. The agent analyzes workload and scaling needs, picks workload types, networking and storage, writes declarative YAML with resource limits and health checks, applies RBAC, NetworkPolicies and Pod Security Standards, then validates. Validation uses kubectl rollout status, kubectl get pods -w and kubectl describe pod to confirm health, with kubectl rollout undo as the way back if a rollout goes wrong.
Kubernetes Specialist fits situations like: writing Deployment, StatefulSet or CronJob manifests with limits and probes; locking down a namespace with RBAC and NetworkPolicies; packaging an application as a Helm chart; debugging crashing pods using logs, events and kubectl describe.
Run `npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a claude-code`. Or copy the skill folder (skills/kubernetes-specialist in Jeffallan/claude-skills) into .claude/skills/kubernetes-specialist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a codex`. Or copy the skill folder (skills/kubernetes-specialist in Jeffallan/claude-skills) into .agents/skills/kubernetes-specialist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jeffallan/claude-skills --skill kubernetes-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes-specialist, .gemini/skills/kubernetes-specialist, .github/skills/kubernetes-specialist and .opencode/skills/kubernetes-specialist in your project.
Going by SKILL.md and its folder, Kubernetes Specialist needs the command-line tools its instructions call (kubectl). Our summary lists: `kubectl` access to a Kubernetes cluster.
SKILL.md names 3 domains. As links in the text: github.com, synergetic.solutions and jeffallan.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kubernetes Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Kubernetes Specialist: Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), GitOps with ArgoCD and Flux (wshobson/agents, 40k stars), Signoz (qjoly/GitOps, 112 stars) and Ksail (devantler-tech/ksail, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Jeffallan (a GitHub user) maintains it in Jeffallan/claude-skills, which has 11,802 GitHub stars. The repository holds 58 skills in this directory. The repository was last updated on October 3, 2026.
Source: Jeffallan/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.