Agent skill

KubeSphere DevOps Credentials

by kubesphere in kubesphere/kubesphere

Covers creating and managing KubeSphere DevOps credentials as typed Kubernetes Secrets that sync to Jenkins, including the API endpoints and a common pitfall.

Custom licenceAuto-check passedDevOps & Cloud

Install KubeSphere DevOps Credentials

skills CLI
$ npx skills add kubesphere/kubesphere --skill kubesphere-devops-credentials -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubesphere/kubesphere kubesphere-devops-credentials --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubesphere-devops-credentials .claude/skills/kubesphere-devops-credentials && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubesphere-devops-credentials
GitHub stars
17k
Token cost
~4.2k tokens
SKILL.md length
526 words
Files
1
Skills in repo
32
Repo updated
First seen
Licence
Custom licence

At a glance

Covers creating and managing KubeSphere DevOps credentials as typed Kubernetes Secrets that sync to Jenkins, including the API endpoints and a common pitfall.

  • Creating Git, kubeconfig or registry credentials in a KubeSphere DevOps project
  • SKILL.md covers Overview, When to Use, Credential Types and Resource Structure, plus 9 more sections
  • Calls curl, kubectl and jq; reaches github.com and kubernetes.default.svc; needs API_TOKEN and GITHUB_TOKEN
  • Fixing a credential stuck at pending sync or missing in Jenkins

What it does

In KubeSphere DevOps a credential is a Kubernetes Secret carrying specific labels and annotations, which is synced to Jenkins for pipeline use. The skill lists the credential types, including SSH keys, basic username and password, secret text and kubeconfig, which is noted as limited to v1.1.x, along with the key names each secret must contain. Typical uses are Git repository access, deployment credentials such as kubeconfig or a registry, external service tokens, troubleshooting access problems and moving credentials between DevOps projects.

The most prominent warning is that the Secret type must start with credential.devops.kubesphere.io, such as the basic-auth, ssh-auth, secret-text or kubeconfig variants. A Secret of type Opaque is ignored by the credential controller, leaving sync status stuck at pending, Jenkins unable to find the credential and pipeline builds failing with a CredentialId could not be found error. REST endpoints under the devops.kubesphere.io v1alpha3 API cover list, create, get, update and delete.

When your agent uses it

  • Creating Git, kubeconfig or registry credentials in a KubeSphere DevOps project
  • Fixing a credential stuck at pending sync or missing in Jenkins
  • Managing credentials through the KubeSphere REST API
  • Migrating credentials between DevOps projects

Example prompts

  • “Create an SSH credential for our Git repository in the payments DevOps project.”
  • “Our pipeline fails with CredentialId could not be found, so check how the credential secret is defined.”
  • “Write the Secret manifest for an API token credential that Jenkins can pick up.”

Requirements

  • A KubeSphere cluster with DevOps enabled
  • Access to the Kubernetes cluster that runs it

What it can do on your machine

Read from SKILL.md and the folder at commit 04a29b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • kubectl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • kubernetes.default.svc

    Also links to:

    • plugins.jenkins.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

KubeSphere DevOps Credentials loads about 4.2k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 526 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 526 words (~4,171 tokens).

“Credentials in KubeSphere DevOps are Kubernetes Secrets with specific labels and annotations. They are synced to Jenkins for use in pipelines. Supported types include SSH keys, username/password, and secret tokens.”

— opening of SKILL.md by kubesphere, Custom licence
name
kubesphere-devops-credentials

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/kubesphere-devops-credentials of kubesphere/kubesphere.

Open the folder on GitHubat commit 04a29b5

Compare with similar skills

KubeSphere DevOps Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

KubeSphere DevOps Credentials compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
KubeSphere DevOps Credentials this skillkubesphere/kubesphere17k—~4.2kAutomated safety check: PassCustom licence
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Secrets GitleaksAgentSecOps/SecOpsAgentKit2192 repos~4.1kAutomated safety check: PassCustom licence
Jenkinsfile Generatorakin-ozer/cc-devops-skills319—~3.7kAutomated safety check: PassApache-2.0
Implementing Secrets Management With Vaultmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Implementing Gitopsancoleman/ai-design-components526—~2.9kAutomated safety check: PassMIT

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Secrets Gitleaks

    AgentSecOps/SecOpsAgentKit

    Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

    219 GitHub starsUsed in 2 repos~4.1k tokens
    DevOps & CloudAuto-check passed
  • Jenkinsfile Generator

    akin-ozer/cc-devops-skills

    Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.

    319 GitHub stars~3.7k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Secrets Management With Vault

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Gitops

    ancoleman/ai-design-components

    Implement GitOps continuous delivery for Kubernetes using ArgoCD or Flux.

    526 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    112 GitHub stars~688 tokensUpdated 22 days ago
    DevOps & CloudAuto-check: warnings

More from kubesphere/kubesphere

All 32 skills in this repo
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeEye Cluster Inspection

    kubesphere/kubesphere

    Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.

    17k GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeSphere NodeGroup Operations

    kubesphere/kubesphere

    Queries, creates, updates, binds and troubleshoots NodeGroup resources in the edgewize nodegroup project through a bundled authenticated API script.

    17k GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • WizTelemetry Platform Service

    kubesphere/kubesphere

    Installs and configures the WizTelemetry Platform Service extension for KubeSphere, the shared API server behind its observability extensions.

    17k GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Runs the lifecycle of FrontendExtension resources in a Kubernetes cluster: create, rebuild, package, publish, unpublish, delete and debug stuck states.

    17k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about KubeSphere DevOps Credentials

What does KubeSphere DevOps Credentials do?

Covers creating and managing KubeSphere DevOps credentials as typed Kubernetes Secrets that sync to Jenkins, including the API endpoints and a common pitfall. In KubeSphere DevOps a credential is a Kubernetes Secret carrying specific labels and annotations, which is synced to Jenkins for pipeline use.x, along with the key names each secret must contain.

When should I use KubeSphere DevOps Credentials?

KubeSphere DevOps Credentials fits situations like: creating Git, kubeconfig or registry credentials in a KubeSphere DevOps project; fixing a credential stuck at pending sync or missing in Jenkins; managing credentials through the KubeSphere REST API; migrating credentials between DevOps projects.

How do I install KubeSphere DevOps Credentials in Claude Code?

Run `npx skills add kubesphere/kubesphere --skill kubesphere-devops-credentials -a claude-code`. Or copy the skill folder (skills/kubesphere-devops-credentials in kubesphere/kubesphere) into .claude/skills/kubesphere-devops-credentials in your project. Claude Code loads it when a task matches its description.

How do I install KubeSphere DevOps Credentials in Codex?

Run `npx skills add kubesphere/kubesphere --skill kubesphere-devops-credentials -a codex`. Or copy the skill folder (skills/kubesphere-devops-credentials in kubesphere/kubesphere) into .agents/skills/kubesphere-devops-credentials in your project. Codex loads it when a task matches its description.

Can I use KubeSphere DevOps Credentials in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubesphere/kubesphere --skill kubesphere-devops-credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubesphere-devops-credentials, .gemini/skills/kubesphere-devops-credentials, .github/skills/kubesphere-devops-credentials and .opencode/skills/kubesphere-devops-credentials in your project.

What does KubeSphere DevOps Credentials need to run?

Going by SKILL.md and its folder, KubeSphere DevOps Credentials needs the command-line tools its instructions call (curl, kubectl and jq) and credentials named API_TOKEN and GITHUB_TOKEN. Our summary lists: A KubeSphere cluster with DevOps enabled; Access to the Kubernetes cluster that runs it.

Does KubeSphere DevOps Credentials access the network?

SKILL.md names 3 domains. In commands or code: github.com and kubernetes.default.svc; the agent is likely to contact these when it follows the instructions. As links in the text: plugins.jenkins.io. This is read from the text; nothing was executed.

Is KubeSphere DevOps Credentials safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does KubeSphere DevOps Credentials use?

KubeSphere DevOps Credentials has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does KubeSphere DevOps Credentials use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to KubeSphere DevOps Credentials?

Skills that share tags, products or a category with KubeSphere DevOps Credentials: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Secrets Gitleaks (AgentSecOps/SecOpsAgentKit, 219 stars), Jenkinsfile Generator (akin-ozer/cc-devops-skills, 319 stars) and Implementing Secrets Management With Vault (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains KubeSphere DevOps Credentials?

kubesphere (a GitHub organization) maintains it in kubesphere/kubesphere, which has 17,059 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on July 15, 2026.

Source: kubesphere/kubesphere on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.