Agent skill

Kcli Configuration

by karmab in karmab/kcli

Guides kcli configuration and provider setup. An agent skill from karmab/kcli.

Apache-2.0Auto-check: warningsDevOps & Cloud

Install Kcli Configuration

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add karmab/kcli --skill kcli-configuration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install karmab/kcli kcli-configuration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/karmab/kcli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kcli-configuration .claude/skills/kcli-configuration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kcli-configuration
GitHub stars
653
Token cost
~1.5k tokens
SKILL.md length
143 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides kcli configuration and provider setup. An agent skill from karmab/kcli.

  • Setting up ~/.kcli/config.yml
  • SKILL.md covers Configuration Files Location, Basic config.yml Structure, Provider Types and KVM/Libvirt Configuration, plus 12 more sections
  • Needs GOOGLE_APPLICATION_CREDENTIALS and AWS_ACCESS_KEY_ID
  • Configuring providers (KVM

What it does

Kcli Configuration is an agent skill from karmab/kcli. Guides kcli configuration and provider setup. Use when setting up ~/.kcli/config.yml, configuring providers (KVM, AWS, GCP, Azure, etc.), or managing profiles.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Amazon Web Services, Microsoft Azure, Google Cloud and Kubernetes. The repository describes itself as: Management tool for virtualization and kubernetes platforms. The licence is Apache-2.0.

When your agent uses it

  • Setting up ~/.kcli/config.yml
  • Configuring providers (KVM
  • Managing profiles

Example prompts

  • “Use the kcli-configuration skill to guide kcli configuration and provider setup. An agent skill from karmab/kcli”
  • “/kcli-configuration”

Requirements

  • A credential in AWS_SECRET_ACCESS_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 30a28e3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GOOGLE_APPLICATION_CREDENTIALS
    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kcli Configuration loads about 1.5k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 143 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:14
    ├── id_rsa / id_rsa.pub  # SSH keys for VM access
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:15
    ├── id_ed25519           # Alternative SSH key
  • NoteRuns commands with sudoSKILL.md:282
    sudo systemctl status libvirtd
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:291
    ssh-keygen -t rsa -N '' -f ~/.kcli/id_rsa
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:294
    ssh-keygen -t ed25519 -N '' -f ~/.kcli/id_ed25519

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from karmab/kcli at commit 30a28e3, republished under its Apache-2.0 licence (© karmab). 143 words, ~1,522 tokens.

Download SKILL.mdSave it as .claude/skills/kcli-configuration/SKILL.md (or your agent's skills folder).
name
kcli-configuration
description
Guides kcli configuration and provider setup. Use when setting up ~/.kcli/config.yml, configuring providers (KVM, AWS, GCP, Azure, etc.), or managing profiles.

kcli Configuration

Configuration Files Location

~/.kcli/
├── config.yml           # Main configuration (clients/providers)
├── profiles.yml         # VM profiles (optional, can be in config.yml)
├── id_rsa / id_rsa.pub  # SSH keys for VM access
├── id_ed25519           # Alternative SSH key
└── clusters/            # Cluster state (created by kcli)

Basic config.yml Structure

yaml
default:
  client: localhost       # Default provider to use
  numcpus: 2
  memory: 512
  pool: default
  nets:
    - default
  disks:
    - size: 10

# Provider definitions
localhost:
  type: kvm
  host: 127.0.0.1

Provider Types

TypeDescriptionRequired Fields
kvmLocal/remote libvirthost
awsAmazon Web Servicesaccess_key_id, access_key_secret, region
gcpGoogle Cloud Platformcredentials, project, zone
azureMicrosoft Azuresubscription_id, credentials (file)
kubevirtVMs on Kubernetescontext, host
openstackOpenStack cloudauth_url, user, password, project
ovirtoVirt/RHVhost, user, password, datacenter
vsphereVMware vSpherehost, user, password, datacenter
proxmoxProxmox VEhost, user, password
hcloudHetzner Cloudtoken
ibmIBM Cloudiam_api_key, region, vpc

KVM/Libvirt Configuration

yaml
# Local libvirt
localhost:
  type: kvm
  host: 127.0.0.1
  pool: default

# Remote libvirt via SSH
remote-kvm:
  type: kvm
  host: 192.168.1.100
  protocol: ssh           # ssh (default), tcp, or tls
  user: root              # SSH user
  pool: default
  # url: qemu+ssh://root@host/system  # Or custom URI

AWS Configuration

yaml
myaws:
  type: aws
  access_key_id: AKIAIOSFODNN7EXAMPLE
  access_key_secret: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
  region: us-east-1
  keypair: mykey          # EC2 key pair name

GCP Configuration

yaml
mygcp:
  type: gcp
  credentials: ~/service-account.json   # Service account JSON
  project: my-project-id
  zone: us-central1-a
  region: us-central1     # Optional, derived from zone

Azure Configuration

yaml
myazure:
  type: azure
  subscription_id: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
  credentials: ~/.azure/credentials.json
  # Or use environment: AZURE_AUTH_LOCATION
  location: eastus
  resource_group: my-rg   # Optional, created if needed

KubeVirt Configuration

yaml
mykubevirt:
  type: kubevirt
  context: my-k8s-context   # kubectl context
  host: api.cluster.local   # API server for SSH tunneling
  pool: my-storageclass     # StorageClass name
  multus: true              # Use Multus CNI
  cdi: true                 # Use CDI for images

OpenStack Configuration

yaml
myopenstack:
  type: openstack
  auth_url: https://openstack:5000/v3
  user: admin
  password: secret
  project: myproject
  domain: Default

oVirt/RHV Configuration

yaml
myovirt:
  type: ovirt
  host: ovirt-engine.local
  user: admin@internal
  password: secret
  datacenter: Default
  cluster: Default
  pool: DataDomain
  ca_file: ~/ovirt.pem      # Engine CA certificate

Default Section Options

yaml
default:
  # Client selection
  client: localhost

  # Compute
  numcpus: 2
  memory: 512               # MB
  cpumodel: host-model
  nested: true              # Nested virtualization

  # Storage
  pool: default
  disks:
    - size: 10
  diskinterface: virtio
  diskthin: true

  # Network
  nets:
    - default
  reservedns: false
  reservehost: false
  reserveip: false

  # OS/Cloud-init
  cloudinit: true
  keys: []                  # SSH public keys
  cmds: []                  # Post-boot commands
  files: []                 # Files to inject

  # Access
  tunnel: false             # SSH tunneling for console
  insecure: false           # Ignore SSH host keys
  enableroot: true          # Allow root SSH

  # Metadata
  storemetadata: false
  planview: false

Profiles (profiles.yml or in config.yml)

yaml
# In ~/.kcli/profiles.yml or config.yml profiles section
small:
  numcpus: 1
  memory: 1024
  disks:
    - size: 10

medium:
  numcpus: 2
  memory: 2048
  disks:
    - size: 20

large:
  numcpus: 4
  memory: 4096
  disks:
    - size: 40
    - size: 100

webserver:
  image: centos9stream
  numcpus: 2
  memory: 4096
  nets:
    - default
  cmds:
    - dnf -y install nginx
    - systemctl enable --now nginx
  base: medium              # Inherit from another profile

Multiple Clients

yaml
default:
  client: local-kvm         # Default client

local-kvm:
  type: kvm
  host: 127.0.0.1

remote-kvm:
  type: kvm
  host: 192.168.1.100

myaws:
  type: aws
  access_key_id: ...
  access_key_secret: ...
  region: us-east-1

Switch clients:

bash
kcli switch local-kvm       # Change default
kcli -C myaws list vm       # Use specific client

Validation Commands

bash
# List configured clients
kcli list client

# Check client connectivity
kcli list host

# Info about current client
kcli info host

# Switch default client
kcli switch <client>

# Test with specific client
kcli -C <client> list vm

Environment Variables

Some values can come from environment:

  • GOOGLE_APPLICATION_CREDENTIALS - GCP credentials path
  • AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY - AWS credentials
  • AZURE_AUTH_LOCATION - Azure credentials path
  • OS_* - OpenStack credentials (standard OS_ vars)

Troubleshooting

Connection refused (KVM):

bash
# Check libvirt is running
sudo systemctl status libvirtd

# Test virsh connection
virsh -c qemu:///system list

SSH key issues:

bash
# Generate kcli SSH key
ssh-keygen -t rsa -N '' -f ~/.kcli/id_rsa

# Or use ed25519
ssh-keygen -t ed25519 -N '' -f ~/.kcli/id_ed25519

Debug mode:

bash
kcli -d list vm             # Shows provider connection details

© karmab, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/kcli-configuration of karmab/kcli.

Open the folder on GitHubat commit 30a28e3

Compare with similar skills

Kcli Configuration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kcli Configuration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kcli Configuration this skillkarmab/kcli653—~1.5kAutomated safety check: WarnApache-2.0
Provider Bug Reviewmondoohq/mql411—~2.9kAutomated safety check: PassCustom licence
Extend Discovery Typerunwhen-contrib/runwhen-local163—~1.7kAutomated safety check: PassApache-2.0
Multi Cloud ArchitectureHermeticOrmus/LibreUIUX-Claude-Code11110 repos~1.2kAutomated safety check: PassMIT
Staged Discoverymondoohq/mql411—~2.9kAutomated safety check: PassCustom licence
Azure Arcvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT

Similar skills

  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    411 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Extend Discovery Type

    runwhen-contrib/runwhen-local

    Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).

    163 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Multi Cloud Architecture

    HermeticOrmus/LibreUIUX-Claude-Code

    Design multi-cloud architectures using a decision framework to select and integrate services across AWS, Azure, and GCP.

    111 GitHub starsUsed in 10 repos~1.2k tokens
    DevOps & CloudAuto-check passed
  • Staged Discovery

    mondoohq/mql

    Add staged discovery support to a provider. An agent skill from mondoohq/mql.

    411 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…

    411 GitHub stars~7.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from karmab/kcli

All 8 skills in this repo
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Kcli

    karmab/kcli

    Comprehensive guide for kcli usage. An agent skill from karmab/kcli.

    653 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: warnings
  • Guides creation of kcli plan files for deploying VMs, networks, and infrastructure.

    653 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Guides implementation of new virtualization providers for kcli.

    653 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Kcli Ksushy

    karmab/kcli

    Guides interaction with kcli VMs via ksushy (Redfish emulator).

    653 GitHub stars~1k tokensUpdated yesterday
    Auto-check: warnings
  • Kcli Testing

    karmab/kcli

    Guides testing and code quality for kcli. An agent skill from karmab/kcli.

    653 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check: warnings

Categories

Questions about Kcli Configuration

What does Kcli Configuration do?

Guides kcli configuration and provider setup. An agent skill from karmab/kcli. Kcli Configuration is an agent skill from karmab/kcli. Guides kcli configuration and provider setup.

When should I use Kcli Configuration?

Kcli Configuration fits situations like: setting up ~/.kcli/config.yml; configuring providers (KVM; managing profiles.

How do I install Kcli Configuration in Claude Code?

Run `npx skills add karmab/kcli --skill kcli-configuration -a claude-code`. Or copy the skill folder (skills/kcli-configuration in karmab/kcli) into .claude/skills/kcli-configuration in your project. Claude Code loads it when a task matches its description.

How do I install Kcli Configuration in Codex?

Run `npx skills add karmab/kcli --skill kcli-configuration -a codex`. Or copy the skill folder (skills/kcli-configuration in karmab/kcli) into .agents/skills/kcli-configuration in your project. Codex loads it when a task matches its description.

Can I use Kcli Configuration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add karmab/kcli --skill kcli-configuration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kcli-configuration, .gemini/skills/kcli-configuration, .github/skills/kcli-configuration and .opencode/skills/kcli-configuration in your project.

What does Kcli Configuration need to run?

Going by SKILL.md and its folder, Kcli Configuration needs credentials named GOOGLE_APPLICATION_CREDENTIALS, AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. Our summary lists: A credential in AWS_SECRET_ACCESS_KEY.

Does Kcli Configuration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kcli Configuration safe to install?

Our automated static check of SKILL.md flagged 4 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Kcli Configuration use?

Kcli Configuration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kcli Configuration use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kcli Configuration?

Skills that share tags, products or a category with Kcli Configuration: Provider Bug Review (mondoohq/mql, 411 stars), Extend Discovery Type (runwhen-contrib/runwhen-local, 163 stars), Multi Cloud Architecture (HermeticOrmus/LibreUIUX-Claude-Code, 111 stars) and Staged Discovery (mondoohq/mql, 411 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kcli Configuration?

karmab (a GitHub user) maintains it in karmab/kcli, which has 653 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: karmab/kcli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.