Agent skill

KubeEye Cluster Inspection

by kubesphere in kubesphere/kubesphere

Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.

Custom licenceAuto-check passedDevOps & Cloud

Install KubeEye Cluster Inspection

skills CLI
$ npx skills add kubesphere/kubesphere --skill kubeeye -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubesphere/kubesphere kubeeye --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubeeye .claude/skills/kubeeye && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubeeye
GitHub stars
17k
Token cost
~3.6k tokens
SKILL.md length
582 words
Files
22 (incl. scripts)
Skills in repo
32
Repo updated
First seen
Licence
Custom licence

At a glance

Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.

  • Works in 6 steps: Detect and Select Version → Generate and Apply InstallPlan → Import Rules → …
  • Installing the KubeEye extension on a KubeSphere cluster
  • SKILL.md covers Overview, When to Use, Architecture and Before You Start, plus 4 more sections
  • Runs Shell scripts from its folder; calls kubectl and curl

What it does

KubeEye is a cluster inspection tool installed as a KubeSphere extension through an InstallPlan. It looks for problems in workloads, nodes, configuration and components using OPA and Rego policies, PromQL queries, file integrity checks, kernel parameter checks and systemd health checks. The skill first checks whether the extension version is published and whether an InstallPlan already exists, in which case it upgrades instead.

Four custom resources carry the work: InspectRule defines checks, InspectPlan schedules them as cron or one-shot runs, InspectTask tracks each run and InspectResult stores findings. Rule types covered are OPA, PromQL, FileChange, Sysctl, Systemd, NodeInfo, FileFilter, ServiceConnect and CustomCommand, with sample rule files in the bundle and a `check-status.sh` script.

When your agent uses it

  • Installing the KubeEye extension on a KubeSphere cluster
  • Writing an InspectRule that checks pods, nodes or kernel settings
  • Scheduling recurring or one-time cluster inspections
  • Finding and downloading the report from an inspection run

Example prompts

  • “Install KubeEye on my KubeSphere cluster and confirm the extension is available first.”
  • “Write an InspectRule that flags deployments without resource limits using OPA.”
  • “Create an InspectPlan that runs the node and pod rules every night and show me the latest report.”

Requirements

  • kubectl
  • A KubeSphere cluster with the kubeeye extension published in the marketplace
  • Compatibility (from SKILL.md): Requires kubectl and a KubeSphere cluster with the kubeeye extension published in the marketplace.

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect and Select Version
  2. Generate and Apply InstallPlan
  3. Import Rules
  4. Create InspectPlan
  5. Monitor InspectTask
  6. View InspectResult

What it can do on your machine

Read from SKILL.md and the folder at commit 04a29b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires kubectl and a KubeSphere cluster with the kubeeye extension published in the marketplace.

    From compatibility in the SKILL.md frontmatter.

Context cost

KubeEye Cluster Inspection loads about 3.6k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 582 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 582 words (~3,565 tokens).

“KubeEye is a Kubernetes cluster inspection tool for KubeSphere. It detects issues in workloads, nodes, configurations, and components through OPA/Rego policies, PromQL queries, file integrity checks, kernel parameter validation, and systemd health checks. It is installed as a KubeSphere extension.”

— opening of SKILL.md by kubesphere, Custom licence
name
kubeeye
compatibility
Requires kubectl and a KubeSphere cluster with the kubeeye extension published in the marketplace.

Read the full SKILL.md on GitHub

Files

SKILL.md and 21 other files (scripts) in skills/kubeeye of kubesphere/kubesphere.

  • SKILL.md
  • rules/kubeeye_filechange_inspect.yaml
  • rules/kubeeye_filterrule_inspect.yaml
  • rules/kubeeye_nodeInfo_inspect.yaml
  • rules/kubeeye_opa_cronjob_inspect.yaml
  • rules/kubeeye_opa_daemonset_inspect.yaml
  • rules/kubeeye_opa_deployment_inspect.yaml
  • rules/kubeeye_opa_event_inspect.yaml
  • rules/kubeeye_opa_job_inspect.yaml
  • rules/kubeeye_opa_node_inspect.yaml
  • rules/kubeeye_opa_node_stats_summary_inspect.yaml
  • rules/kubeeye_opa_pod_inspect.yaml
  • rules/kubeeye_opa_pod_state_inspect.yaml
  • rules/kubeeye_opa_statefulset_inspect.yaml
  • rules/kubeeye_promql_inspect.yaml
  • rules/kubeeye_services_connect_inspect.yaml
  • rules/kubeeye_sysctlrule_inspect.yaml
  • rules/kubeeye_systemd_inspect.yaml
  • scripts/check-status.sh
  • … and 3 more

Open the folder on GitHubat commit 04a29b5

Compare with similar skills

KubeEye Cluster Inspection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

KubeEye Cluster Inspection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
KubeEye Cluster Inspection this skillkubesphere/kubesphere17k—~3.6kAutomated safety check: PassCustom licence
Signozqjoly/GitOps112—~6.1kAutomated safety check: PassWTFPL
Grafana Dashboardpando85/kaniop130—~987Automated safety check: PassAGPL-3.0
Alloygrafana/skills279—~1.3kAutomated safety check: PassApache-2.0
Beylagrafana/skills279—~1.1kAutomated safety check: PassApache-2.0
Fleet Managementgrafana/skills279—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Signoz

    qjoly/GitOps

    Manage the self-hosted SigNoz observability stack in this GitOps repo.

    112 GitHub stars~6.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Grafana Dashboard

    pando85/kaniop

    Improve and validate the Kaniop Grafana dashboard against repository metrics and the grigri live cluster.

    130 GitHub stars~987 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Alloy

    grafana/skills

    Official

    Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo /…

    279 GitHub stars~1.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Beyla

    grafana/skills

    Official

    Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart.

    279 GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Fleet Management

    grafana/skills

    Official

    Manage a fleet of Grafana Alloy collectors with Fleet Management — author Alloy pipelines once, target them via attribute matchers (env="production", regex region=~"us-."), push remotely via OpAMP…

    279 GitHub stars~1.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Mimir

    grafana/skills

    Official

    Stand up Grafana Mimir for horizontally scalable, multi-tenant, long-term Prometheus + OTLP metrics storage.

    279 GitHub stars~1.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from kubesphere/kubesphere

All 32 skills in this repo
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    Auto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeSphere NodeGroup Operations

    kubesphere/kubesphere

    Queries, creates, updates, binds and troubleshoots NodeGroup resources in the edgewize nodegroup project through a bundled authenticated API script.

    17k GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • WizTelemetry Platform Service

    kubesphere/kubesphere

    Installs and configures the WizTelemetry Platform Service extension for KubeSphere, the shared API server behind its observability extensions.

    17k GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Runs the lifecycle of FrontendExtension resources in a Kubernetes cluster: create, rebuild, package, publish, unpublish, delete and debug stuck states.

    17k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Forge FI Operations

    kubesphere/kubesphere

    Operates FrontendIntegration resources and the frontend-forge extension with kubectl: create from YAML, update, enable, disable, delete, inspect and troubleshoot builds.

    17k GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about KubeEye Cluster Inspection

What does KubeEye Cluster Inspection do?

Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports. KubeEye is a cluster inspection tool installed as a KubeSphere extension through an InstallPlan. It looks for problems in workloads, nodes, configuration and components using OPA and Rego policies, PromQL queries, file integrity checks, kernel parameter checks and systemd health checks.

When should I use KubeEye Cluster Inspection?

KubeEye Cluster Inspection fits situations like: installing the KubeEye extension on a KubeSphere cluster; writing an InspectRule that checks pods, nodes or kernel settings; scheduling recurring or one-time cluster inspections; finding and downloading the report from an inspection run.

How do I install KubeEye Cluster Inspection in Claude Code?

Run `npx skills add kubesphere/kubesphere --skill kubeeye -a claude-code`. Or copy the skill folder (skills/kubeeye in kubesphere/kubesphere) into .claude/skills/kubeeye in your project. Claude Code loads it when a task matches its description.

How do I install KubeEye Cluster Inspection in Codex?

Run `npx skills add kubesphere/kubesphere --skill kubeeye -a codex`. Or copy the skill folder (skills/kubeeye in kubesphere/kubesphere) into .agents/skills/kubeeye in your project. Codex loads it when a task matches its description.

Can I use KubeEye Cluster Inspection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubesphere/kubesphere --skill kubeeye -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubeeye, .gemini/skills/kubeeye, .github/skills/kubeeye and .opencode/skills/kubeeye in your project.

What does KubeEye Cluster Inspection need to run?

Going by SKILL.md and its folder, KubeEye Cluster Inspection needs a shell for the scripts in its folder and the command-line tools its instructions call (kubectl and curl). Our summary lists: kubectl; A KubeSphere cluster with the kubeeye extension published in the marketplace. Compatibility (from SKILL.md): Requires kubectl and a KubeSphere cluster with the kubeeye extension published in the marketplace..

Does KubeEye Cluster Inspection access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is KubeEye Cluster Inspection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does KubeEye Cluster Inspection use?

KubeEye Cluster Inspection has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does KubeEye Cluster Inspection use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to KubeEye Cluster Inspection?

Skills that share tags, products or a category with KubeEye Cluster Inspection: Signoz (qjoly/GitOps, 112 stars), Grafana Dashboard (pando85/kaniop, 130 stars), Alloy (grafana/skills, 279 stars) and Beyla (grafana/skills, 279 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains KubeEye Cluster Inspection?

kubesphere (a GitHub organization) maintains it in kubesphere/kubesphere, which has 17,060 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on July 15, 2026.

Source: kubesphere/kubesphere on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.