Official agent skill

K8s API Conventions

by kubernetes-sigs in kubernetes-sigs/agent-sandbox

Guides the agent to follow Kubernetes API conventions for OSS standards.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install K8s API Conventions

skills CLI
$ npx skills add kubernetes-sigs/agent-sandbox --skill k8s-api-conventions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubernetes-sigs/agent-sandbox k8s-api-conventions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubernetes-sigs/agent-sandbox.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/k8s-api-conventions .claude/skills/k8s-api-conventions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
k8s-api-conventions
GitHub stars
4.2k
Token cost
~1.4k tokens
SKILL.md length
722 words
Files
2 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides the agent to follow Kubernetes API conventions for OSS standards.

  • Works in 3 steps: CRDs as First-Class APIs: Adhere to the… → Primary Guidelines: Rely on the… → Deep-Dive Reference: If you encounter…
  • Tasks that involve Container orchestration
  • SKILL.md covers Purpose, Instructions and References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

K8s API Conventions is an agent skill from kubernetes-sigs/agent-sandbox, published by the product's own GitHub organization. Guides the agent to follow Kubernetes API conventions for OSS standards.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/api-conventions.md`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes. The repository describes itself as: agent-sandbox enables easy management of isolated, stateful, singleton workloads, ideal for use cases like AI agent runtimes and reinforcement learning (RL). The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration

Example prompts

  • “Use the k8s-api-conventions skill to guide the agent to follow Kubernetes API conventions for OSS standards”
  • “/k8s-api-conventions”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. CRDs as First-Class APIs: Adhere to the guidelines in the official Kubernetes API conventions. CRDs must follow the same conventions…
  2. Primary Guidelines: Rely on the condensed "Gotchas" below for 90% of standard CRD and API reviews. These represent the most common…
  3. Deep-Dive Reference: If you encounter complex architectural ambiguity, custom subresources, or edge cases not covered by the Gotchas…

What it can do on your machine

Read from SKILL.md and the folder at commit b668082. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

K8s API Conventions loads about 1.4k tokens when it runs, and up to ~30k if it reads all its reference files. Until then it costs about 23 tokens; SKILL.md has 722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~30k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kubernetes-sigs/agent-sandbox at commit b668082, republished under its Apache-2.0 licence (© kubernetes-sigs). 722 words, ~1,398 tokens.

Download SKILL.mdSave it as .claude/skills/k8s-api-conventions/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
k8s-api-conventions
description
Guides the agent to follow Kubernetes API conventions for OSS standards.

Kubernetes API Conventions Skill

Purpose

This skill ensures that all Custom Resource Definitions (CRDs) generated or modified in this project follow the established conventions defined by the Kubernetes community.

Instructions

  1. CRDs as First-Class APIs: Adhere to the guidelines in the official Kubernetes API conventions. CRDs must follow the same conventions regarding field naming, types, and structure (Spec/Status separation) as core Kubernetes resources.
  2. Primary Guidelines: Rely on the condensed "Gotchas" below for 90% of standard CRD and API reviews. These represent the most common compliance failures derived from Kubernetes API conventions and community best practices, which automated linters often miss:
    • Label Values: Do NOT use full resource names as label values. Kubernetes enforces a strict 63-character limit on label values, whereas resource names can be up to 253 characters. Using full resource names in labels can lead to asynchronous runtime failures (e.g., a parent resource is successfully created, but the controller continuously fails to create child resources due to label length limits). When resource names must be reflected in labels, implement safe truncation or hashing in the controller logic to ensure values remain under 63 characters.
    • Preview Features: Do NOT use annotations for alpha/preview features. Use new API fields instead, to avoid migration difficulties later.
    • Status Properties: Use conditions instead of phase for tracking state.
    • Mutating Spec: The spec of the primary Custom Resource (CR) being reconciled is user-owned and should not be modified and saved back to the API server by the reconciler. This avoids mutating user intent. Controllers may, however, create and update the spec of secondary or target objects (for example, the HPA controller updating a Deployment's spec.replicas).
    • Zero vs. Unset: Use pointers for fields where it is important to distinguish between a zero value (e.g., 0) and the field being unset.
    • Scalability: Avoid storing unbounded lists of items in the API (etcd has size limits). Consider aggregating or summarizing lists in status.
    • Metrics Cardinality & Normalization: Never introduce high or unbounded cardinality Prometheus labels (e.g., pod names, UIDs, timestamps, raw errors). When deriving label values from dynamic input or errors, apply metrics normalization (an allowlist switch or categorizer) to map strings into a small, fixed enum.
    • Think twice about booleans: Avoid booleans for fields that might evolve to have more states in the future. Use enums or string fields instead.
    • Declarative Field Names: Ensure field names describe the desired state, not an action (e.g., use suspended instead of suspend).
    • Lists over Maps: Do not use maps of subobjects (e.g., ports: {www: {port: 80}}). Use a list of subobjects containing a name field (e.g., ports: [{name: www, port: 80}]). The only exceptions are pure string maps (labels, annotations).
    • Integer & Float Types: Always use explicit int32 or int64 (preferring int32), never ambiguously sized int or unsigned integers (uint). Avoid floating-point types entirely in spec.
    • Duration & Timestamp Naming: Express durations with a Seconds suffix (e.g., periodSeconds, timeoutSeconds). For timestamps, use somethingTime (e.g., lastTransitionTime), avoiding the word stamp.
    • Allocated Values in Status: If a controller automatically allocates a resource (like a ClusterIP, port number, or storage ID) on behalf of the user, store the resulting allocated value in status, not spec.
    • Breaking Changes: Whenever reviewing or proposing changes that alter existing default runtime behaviors, flag them as breaking changes that require deprecation cycles and migration paths.
    • Controller CLI Flags vs. Declarative CRs: Do NOT use global controller command-line flags to configure tenant workload semantics or operational behaviors; all workload behavior must be configured declaratively via Custom Resources. When global CLI flags exist for platform-level baseline governance, ensure declarative Custom Resource configuration always takes precedence.
    • API Schema Minimization: Do NOT expand CRD schemas with new fields unless strictly necessary. Avoid toggle proliferation (introducing multiple overlapping configuration mechanisms for a single behavior) and establish clear, declarative precedence hierarchies.
    • Controller Logging Discipline: In high-frequency Reconcile loops, reserve logger.Info / V(0) for major state changes and lifecycle milestones (e.g., resource created, claim adopted). Require logger.V(4).Info for routine steady-state checks, cache lookups, or status fall-throughs.
    • Call-Site & Downstream Impact Auditing: When modifying helper predicates, validation functions, or error return criteria, audit all call sites across reconcilers to prevent downstream side effects (e.g., premature queue evictions or cache drops).
  3. Deep-Dive Reference: If you encounter complex architectural ambiguity, custom subresources, or edge cases not covered by the Gotchas above, consult the full upstream specification at references/api-conventions.md.
Show full SKILL.md (4 more words)Show less

© kubernetes-sigs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/k8s-api-conventions of kubernetes-sigs/agent-sandbox.

  • SKILL.md
  • references/api-conventions.md

Open the folder on GitHubat commit b668082

Compare with similar skills

K8s API Conventions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

K8s API Conventions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
K8s API Conventions this skillkubernetes-sigs/agent-sandbox4.2k—~1.4kAutomated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from kubernetes-sigs/agent-sandbox

  • Bump Go Version

    kubernetes-sigs/agent-sandbox

    Official

    Bumps the Go version to the latest release across go.mod, tools.mod, and Dockerfiles.

    4.2k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Fix Flakes

    kubernetes-sigs/agent-sandbox

    Official

    Diagnose and fix flaky tests tracked as open kind/flake issues in kubernetes-sigs/agent-sandbox — reproduce the flake, apply a minimal fix, and open a PR linking the issue.

    4.2k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • K8s Agent Sandbox MCP

    kubernetes-sigs/agent-sandbox

    Official

    An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.

    4.2k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Test Pyramid

    kubernetes-sigs/agent-sandbox

    Official

    Analyze the repo's unit and E2E tests and propose rebalancing toward a test pyramid — which E2E tests (or assertions inside them) can be covered by unit tests, which unit-level gaps genuinely need…

    4.2k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Dev Rules

    kubernetes-sigs/agent-sandbox

    Official

    Enforces project-specific development rules and conventions.

    4.2k GitHub stars~447 tokensUpdated yesterday
    Auto-check passed
  • Triage Issues

    kubernetes-sigs/agent-sandbox

    Official

    Triage open GitHub issues for kubernetes-sigs/agent-sandbox by mapping them to roadmap.md and assigning k8s priority labels + Kanban Priority (P0–P4) on Project

    4.2k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about K8s API Conventions

What does K8s API Conventions do?

Guides the agent to follow Kubernetes API conventions for OSS standards. K8s API Conventions is an agent skill from kubernetes-sigs/agent-sandbox, published by the product's own GitHub organization. Guides the agent to follow Kubernetes API conventions for OSS standards.

When should I use K8s API Conventions?

K8s API Conventions fits situations like: tasks that involve Container orchestration.

How do I install K8s API Conventions in Claude Code?

Run `npx skills add kubernetes-sigs/agent-sandbox --skill k8s-api-conventions -a claude-code`. Or copy the skill folder (.agents/skills/k8s-api-conventions in kubernetes-sigs/agent-sandbox) into .claude/skills/k8s-api-conventions in your project. Claude Code loads it when a task matches its description.

How do I install K8s API Conventions in Codex?

Run `npx skills add kubernetes-sigs/agent-sandbox --skill k8s-api-conventions -a codex`. Or copy the skill folder (.agents/skills/k8s-api-conventions in kubernetes-sigs/agent-sandbox) into .agents/skills/k8s-api-conventions in your project. Codex loads it when a task matches its description.

Can I use K8s API Conventions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubernetes-sigs/agent-sandbox --skill k8s-api-conventions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/k8s-api-conventions, .gemini/skills/k8s-api-conventions, .github/skills/k8s-api-conventions and .opencode/skills/k8s-api-conventions in your project.

What does K8s API Conventions need to run?

SKILL.md names no scripts, command-line tools or credentials: K8s API Conventions is instructions for the agent only.

Does K8s API Conventions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is K8s API Conventions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does K8s API Conventions use?

K8s API Conventions is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does K8s API Conventions use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 29k tokens, read only when the agent opens those files.

What are the alternatives to K8s API Conventions?

Skills that share tags, products or a category with K8s API Conventions: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains K8s API Conventions?

kubernetes-sigs (a GitHub organization, an official publisher) maintains it in kubernetes-sigs/agent-sandbox, which has 4,198 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 9, 2026.

Source: kubernetes-sigs/agent-sandbox on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.