Official agent skill

Build Images

by kubernetes-sigs in kubernetes-sigs/cloud-provider-azure

Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Build Images

skills CLI
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill build-images -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubernetes-sigs/cloud-provider-azure build-images --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/build-images .claude/skills/build-images && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
build-images
GitHub stars
294
Token cost
~1.7k tokens
SKILL.md length
695 words
Files
3 (incl. scripts)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

  • The user wants to build CCM
  • SKILL.md covers Workflow, Image Aliases, Flags and Transient Runtime Retries, plus 1 more section
  • Runs Python scripts from its folder; calls python3 and make
  • Health-probe-proxy

What it does

Build Images is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries. Use when the user wants to build CCM, CNM, health-probe-proxy, CCM e2e, or root CCM/CNM aggregate images, or mentions build-ccm-image, build-node-image-linux, build images, image registry, or image tag.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/build_image.py` and `scripts/test_build_image.py`).

It sits in DevOps & Cloud, covering Containers and End-to-end testing. It works with Microsoft Azure, Kubernetes, Linux and Docker. The repository describes itself as: Cloud provider for Azure. The licence is Apache-2.0.

When your agent uses it

  • The user wants to build CCM
  • Health-probe-proxy
  • Root CCM/CNM aggregate images
  • Mentions build-ccm-image

Example prompts

  • “/build-images”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 0201852. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Build Images loads about 1.7k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 695 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from kubernetes-sigs/cloud-provider-azure at commit 0201852, republished under its Apache-2.0 licence (© kubernetes-sigs). 695 words, ~1,724 tokens.

Download SKILL.mdSave it as .claude/skills/build-images/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
build-images
description
Build cloud-provider-azure container images through the repo Makefile with explicit IMAGE_TAG and IMAGE_REGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries. Use when the user wants to build CCM, CNM, health-probe-proxy, CCM e2e, or root CCM/CNM aggregate images, or mentions build-ccm-image, build-node-image-linux, build images, image registry, or image tag.

Build Images

Workflow

Use this skill to build cloud-provider-azure images from the repository Makefiles. Ask for IMAGE_TAG and IMAGE_REGISTRY when either value is missing.

Replace <SKILL_DIR> with the path to this skill directory.

Dry-run the default CCM command:

bash
python3 <SKILL_DIR>/scripts/build_image.py \
  --image ccm \
  --tag <tag> \
  --registry <registry> \
  --dry-run

Build the default CCM image:

bash
python3 <SKILL_DIR>/scripts/build_image.py \
  --image ccm \
  --tag <tag> \
  --registry <registry>

The default CCM command is:

bash
IMAGE_TAG=<tag> IMAGE_REGISTRY=<registry> MS_GO_NOSYSTEMCRYPTO=1 ENABLE_GIT_COMMAND=false make build-ccm-image

Image Aliases

Pass one of these values to --image:

AliasMake targetDirectory
ccmbuild-ccm-imagerepo root
ccm-allbuild-all-ccm-imagesrepo root
cnm, cnm-linuxbuild-node-image-linuxrepo root
cnm-windowsbuild-node-image-windowsrepo root
cnm-windows-hpcbuild-node-image-windows-hpcrepo root
cnm-allbuild-all-node-imagesrepo root
ccm-e2ebuild-ccm-e2e-test-imagerepo root
hppbuild-health-probe-proxy-imagehealth-probe-proxy/
hpp-windowsbuild-health-probe-proxy-image-windowshealth-probe-proxy/
allimagerepo root

all maps to the root make image target. It builds the root CCM/CNM aggregate only; it does not build hpp, hpp-windows, or ccm-e2e.

cnm-all maps to the raw root build-all-node-images aggregate. Because that aggregate includes Windows image targets with host-side Go builds, the helper does not default MS_GO_NOSYSTEMCRYPTO for cnm-all.

The helper invokes health-probe-proxy builds with make -B so each hpp or hpp-windows image rebuilds its host binary before invoking Buildx. This prevents a binary left by an earlier branch or remediation cycle from being reused in a verification image, including when the target checkout has an older Makefile.

Do not use this skill for acr-credential-provider images. This repo exposes the acr-credential-provider as a binary build, not an image build target.

Flags

The helper always sets IMAGE_TAG, IMAGE_REGISTRY, and ENABLE_GIT_COMMAND=false unless a default is explicitly removed with --unset.

The ccm, ccm-all, cnm, and cnm-linux aliases set MS_GO_NOSYSTEMCRYPTO=1 for non-FIPS development images. Their Dockerfiles use Microsoft Go, where starting with version 1.27, systemcrypto is no longer configured through GOEXPERIMENT; this setting disables system crypto. For other aliases, pass the setting explicitly only when FIPS compliance is not required:

bash
python3 <SKILL_DIR>/scripts/build_image.py \
  --image hpp \
  --tag <tag> \
  --registry <registry> \
  --set MS_GO_NOSYSTEMCRYPTO=1

Use repeated --set KEY=VALUE arguments to add or override make variables:

bash
python3 <SKILL_DIR>/scripts/build_image.py \
  --image cnm \
  --tag <tag> \
  --registry <registry> \
  --set ARCH=arm64 \
  --set BUILDX_EXTRA_FLAGS=--no-cache

Use repeated --unset KEY arguments to remove default flags:

bash
python3 <SKILL_DIR>/scripts/build_image.py \
  --image ccm \
  --tag <tag> \
  --registry <registry> \
  --unset MS_GO_NOSYSTEMCRYPTO \
  --unset ENABLE_GIT_COMMAND

IMAGE_TAG and IMAGE_REGISTRY are required inputs and cannot be unset. They also cannot be overridden with --set; use --tag and --registry. Passing the same key to both --set and --unset is rejected.

For a deterministic local Linux amd64 verification build, explicitly set ARCH=amd64 and OUTPUT_TYPE=docker, then unset inherited OUTPUT_FLAG and BUILDX_EXTRA_FLAGS. This prevents caller environment from selecting another architecture, registry output, or push-oriented Buildx flags.

Use --repo when the target checkout differs from the checkout containing the skill. This is required when a caller snapshots the skill before switching the target worktree to another branch.

Make control variables that can override command-line or environment values are reserved. Do not pass MAKEFLAGS, MFLAGS, GNUMAKEFLAGS, MAKEOVERRIDES, or MAKEFILES with --set; the helper rejects those keys and removes inherited values before running make.

Show full SKILL.md (258 more words)Show less

Transient Runtime Retries

Use --retry-transient-runtime-errors only when the caller wants the helper to retry one recognized transient runtime failure. This option requires an explicit --set CONTAINER_CLI=<path-to-docker-or-podman> so classification and the retry use the same selected runtime:

bash
python3 <SKILL_DIR>/scripts/build_image.py \
  --image ccm \
  --tag <tag> \
  --registry <registry> \
  --set CONTAINER_CLI=/absolute/path/to/podman \
  --retry-transient-runtime-errors

The helper streams build output while retaining only the last 50 stderr lines for classification. It waits five seconds, then retries the identical working directory, command, and environment once in these cases:

  • Docker Buildx setup failed because concurrent builder creation raced.
  • Podman failed during registry access or image transfer with a temporary DNS error, connection timeout or reset, TLS handshake timeout, or registry HTTP 429 or 5xx response. Before retrying, the helper requires the same Podman executable's info check to succeed within ten seconds.

The helper does not retry authentication or authorization, missing manifests or digests, disk-capacity, compilation, Dockerfile or Makefile, builder-configuration, interruption, or unclassified failures. A failed retry is returned directly; there is no third attempt. --dry-run never builds, checks runtime health, sleeps, or includes the retry option in the resolved Make command.

Validation

Use --dry-run when the user asks for the command, when checking flag changes, or before running an expensive build. The script prints the resolved working directory and shell-quoted command. When the helper removes a default or sanitizes inherited managed environment, dry-runs show that as env -u KEY. Without --dry-run, it prints the same resolved working directory and command. The default path runs make once via subprocess.run without shell=True; the opt-in retry path streams stderr via subprocess.Popen without shell=True so it can classify and replay bounded failure evidence.

© kubernetes-sigs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/build-images of kubernetes-sigs/cloud-provider-azure.

  • SKILL.md
  • scripts/build_image.py
  • scripts/test_build_image.py

Open the folder on GitHubat commit 0201852

Compare with similar skills

Build Images next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Build Images compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Build Images this skillkubernetes-sigs/cloud-provider-azure294—~1.7kAutomated safety check: PassApache-2.0
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Devsydevsy-org/devsy113—~1.7kAutomated safety check: PassMPL-2.0
Image Managementdotnet/dotnet-docker4.9k—~1.1kAutomated safety check: PassMIT
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    113 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Image Management

    dotnet/dotnet-docker

    Official

    Manages .NET Docker images including adding images for new .NET versions, new Linux distros (Alpine, Ubuntu, Azure Linux), and new Windows versions.

    4.9k GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Aspire Deployment

    CommunityToolkit/Aspire

    WORKFLOW SKILL — Deploy Aspire apps from AppHost models to Docker Compose, Kubernetes, Azure, AWS, or preview Radius.

    627 GitHub stars~4.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes

More from kubernetes-sigs/cloud-provider-azure

All 12 skills in this repo
  • Run E2E Test

    kubernetes-sigs/cloud-provider-azure

    Official

    Parse a Go e2e test from tests/e2e/, translate each step to kubectl and az CLI commands, and interactively replay the test against a live cluster.

    294 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check passed
  • Cherry Pick PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Cherry-pick a merged pull request onto a release branch with Prow-style branch naming, manual conflict resolution, targeted validation, and GitHub PR creation.

    294 GitHub stars~636 tokensUpdated 2 days ago
    Auto-check passed
  • Create Release Note Doc PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Generate or update the documentation-site release note for a given tag, commit it on a branch, push it to a writable remote, and open a GitHub PR to the docs branch.

    294 GitHub stars~768 tokensUpdated 2 days ago
    Auto-check passed
  • Create Release Tags

    kubernetes-sigs/cloud-provider-azure

    Official

    Create and optionally push the next Kubernetes-style release tag (vX.Y.Z) from a release-X.Y branch by resolving the remote branch tip, computing the next patch tag, and tagging the commit directly…

    294 GitHub stars~574 tokensUpdated 2 days ago
    Auto-check passed
  • Cve Remediator V2

    kubernetes-sigs/cloud-provider-azure

    Official

    Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

    294 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Debug E2E Pipeline

    kubernetes-sigs/cloud-provider-azure

    Official

    Fetch and analyze Prow e2e pipeline failures for cloud-provider-azure.

    294 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed

Questions about Build Images

What does Build Images do?

Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries. Build Images is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

When should I use Build Images?

Build Images fits situations like: the user wants to build CCM; health-probe-proxy; root CCM/CNM aggregate images; mentions build-ccm-image.

How do I install Build Images in Claude Code?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill build-images -a claude-code`. Or copy the skill folder (.agents/skills/build-images in kubernetes-sigs/cloud-provider-azure) into .claude/skills/build-images in your project. Claude Code loads it when a task matches its description.

How do I install Build Images in Codex?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill build-images -a codex`. Or copy the skill folder (.agents/skills/build-images in kubernetes-sigs/cloud-provider-azure) into .agents/skills/build-images in your project. Codex loads it when a task matches its description.

Can I use Build Images in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubernetes-sigs/cloud-provider-azure --skill build-images -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/build-images, .gemini/skills/build-images, .github/skills/build-images and .opencode/skills/build-images in your project.

What does Build Images need to run?

Going by SKILL.md and its folder, Build Images needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and make). Our summary lists: Python 3; Docker.

Does Build Images access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Build Images safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Build Images use?

Build Images is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Build Images use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Build Images?

Skills that share tags, products or a category with Build Images: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars), Devsy (devsy-org/devsy, 113 stars) and Image Management (dotnet/dotnet-docker, 4.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Build Images?

kubernetes-sigs (a GitHub organization, an official publisher) maintains it in kubernetes-sigs/cloud-provider-azure, which has 294 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.

Source: kubernetes-sigs/cloud-provider-azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.