Agent skill

KubeSphere Multi-Tenant Management

by kubesphere in kubesphere/kubesphere

Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

Custom licenceAuto-check passedDevOps & Cloud

Install KubeSphere Multi-Tenant Management

skills CLI
$ npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubesphere/kubesphere kubesphere-multi-tenant-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubesphere/kubesphere.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubesphere-multi-tenant-management .claude/skills/kubesphere-multi-tenant-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubesphere-multi-tenant-management
GitHub stars
17k
Token cost
~3.1k tokens
SKILL.md length
891 words
Files
5 (incl. scripts, references)
Skills in repo
32
Repo updated
First seen
Licence
Custom licence

At a glance

Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

  • Works in 6 steps: Create Workspace → Create Project within Workspace → Create User → …
  • Creating a KubeSphere user with a safe default role
  • SKILL.md covers Security Guidelines, Core Concepts, Step-by-Step Guide and Error Handling, plus 2 more sections
  • Runs Python scripts from its folder; calls python, kubectl and pip

What it does

The skill covers user lifecycle, workspace setup, project creation and role binding in KubeSphere, with a bundled ks_api.py script. It is deliberately limited to creating and querying. The agent must not run kubectl edit or delete, must not delete users, workspaces, projects, roles or bindings through the API, and must not create custom roles. Those actions are left to the KubeSphere Console and its approval workflow.

Permissions default to the lowest level: new users get platform-regular, workspace invitations get the regular role for that workspace, and project invitations get viewer, escalating only when you explicitly ask. The skill explains the model: a workspace is the top-level team or business unit and can span several clusters, a project maps to one namespace, and roles come from three tiers of built-in RBAC. A reference document and an evals file ship with it.

When your agent uses it

  • Creating a KubeSphere user with a safe default role
  • Setting up a workspace and the projects inside it for a team
  • Inviting people to a workspace or project with the right built-in role
  • Looking up who has access to which workspace or project

Example prompts

  • “Create a KubeSphere user for Priya with the default platform role.”
  • “Set up a workspace called payments and add two projects, staging and production.”
  • “Invite Dana to the payments workspace as a regular member and give her viewer access to staging.”
  • “List the projects in the payments workspace and show who can see them.”

Requirements

  • A KubeSphere installation the agent can reach
  • Python, to run scripts/ks_api.py

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Create Workspace
  2. Create Project within Workspace
  3. Create User
  4. Invite User to Workspace/Project
  5. Modify User Permissions
  6. Query Resources

What it can do on your machine

Read from SKILL.md and the folder at commit 04a29b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • kubectl
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.kubesphere.com.cn
    • kubernetes.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

KubeSphere Multi-Tenant Management loads about 3.1k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 891 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 891 words (~3,105 tokens).

“The top-level organizational unit in KubeSphere, representing a team, department, or business unit. A workspace can contain multiple projects and serves as the basic boundary for resource grouping and access control. Workspaces can span multiple clusters, enabling centralized management of…”

— opening of SKILL.md by kubesphere, Custom licence
name
kubesphere-multi-tenant-management

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (scripts, references) in skills/kubesphere-multi-tenant-management of kubesphere/kubesphere.

  • SKILL.md
  • evals/evals.json
  • references/multi-tenancy-architecture.jpeg
  • references/multi-tenancy-in-kubesphere.md
  • scripts/ks_api.py

Open the folder on GitHubat commit 04a29b5

Compare with similar skills

KubeSphere Multi-Tenant Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

KubeSphere Multi-Tenant Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
KubeSphere Multi-Tenant Management this skillkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Azure Bastion Jitvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Analyzing Kubernetes Audit Logsmukul975/Anthropic-Cybersecurity-Skills34k—~654Automated safety check: PassApache-2.0
Mimirgrafana/skills282—~1.2kAutomated safety check: PassApache-2.0
Kubernetesnotque/vexjoy-agent441—~1.5kAutomated safety check: PassMIT
Defending Kubernetestrilwu/secskills157—~2.2kAutomated safety check: PassMIT

Similar skills

  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Analyzing Kubernetes Audit Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules…

    34k GitHub stars~654 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Mimir

    grafana/skills

    Official

    Stand up Grafana Mimir for horizontally scalable, multi-tenant, long-term Prometheus + OTLP metrics storage.

    282 GitHub stars~1.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Kubernetes

    notque/vexjoy-agent

    Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.

    441 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Defending Kubernetes

    trilwu/secskills

    Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

    157 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Castai Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Review CAST AI identity, Kubernetes RBAC, cloud IAM, Kvisor, network, and evidence boundaries against enabled features.

    2.8k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from kubesphere/kubesphere

All 32 skills in this repo
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeEye Cluster Inspection

    kubesphere/kubesphere

    Deploys KubeEye on KubeSphere and writes InspectRule and InspectPlan resources to inspect cluster health, then retrieves the inspection reports.

    17k GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • KubeSphere NodeGroup Operations

    kubesphere/kubesphere

    Queries, creates, updates, binds and troubleshoots NodeGroup resources in the edgewize nodegroup project through a bundled authenticated API script.

    17k GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • WizTelemetry Platform Service

    kubesphere/kubesphere

    Installs and configures the WizTelemetry Platform Service extension for KubeSphere, the shared API server behind its observability extensions.

    17k GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Runs the lifecycle of FrontendExtension resources in a Kubernetes cluster: create, rebuild, package, publish, unpublish, delete and debug stuck states.

    17k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Forge FI Operations

    kubesphere/kubesphere

    Operates FrontendIntegration resources and the frontend-forge extension with kubectl: create from YAML, update, enable, disable, delete, inspect and troubleshoot builds.

    17k GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about KubeSphere Multi-Tenant Management

What does KubeSphere Multi-Tenant Management do?

Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything. py script. It is deliberately limited to creating and querying.

When should I use KubeSphere Multi-Tenant Management?

KubeSphere Multi-Tenant Management fits situations like: creating a KubeSphere user with a safe default role; setting up a workspace and the projects inside it for a team; inviting people to a workspace or project with the right built-in role; looking up who has access to which workspace or project.

How do I install KubeSphere Multi-Tenant Management in Claude Code?

Run `npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a claude-code`. Or copy the skill folder (skills/kubesphere-multi-tenant-management in kubesphere/kubesphere) into .claude/skills/kubesphere-multi-tenant-management in your project. Claude Code loads it when a task matches its description.

How do I install KubeSphere Multi-Tenant Management in Codex?

Run `npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a codex`. Or copy the skill folder (skills/kubesphere-multi-tenant-management in kubesphere/kubesphere) into .agents/skills/kubesphere-multi-tenant-management in your project. Codex loads it when a task matches its description.

Can I use KubeSphere Multi-Tenant Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubesphere-multi-tenant-management, .gemini/skills/kubesphere-multi-tenant-management, .github/skills/kubesphere-multi-tenant-management and .opencode/skills/kubesphere-multi-tenant-management in your project.

What does KubeSphere Multi-Tenant Management need to run?

Going by SKILL.md and its folder, KubeSphere Multi-Tenant Management needs Python for the scripts in its folder and the command-line tools its instructions call (python, kubectl and pip). Our summary lists: A KubeSphere installation the agent can reach; Python, to run scripts/ks_api.py.

Does KubeSphere Multi-Tenant Management access the network?

SKILL.md names 2 domains. As links in the text: docs.kubesphere.com.cn and kubernetes.io. This is read from the text; nothing was executed.

Is KubeSphere Multi-Tenant Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does KubeSphere Multi-Tenant Management use?

KubeSphere Multi-Tenant Management has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does KubeSphere Multi-Tenant Management use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to KubeSphere Multi-Tenant Management?

Skills that share tags, products or a category with KubeSphere Multi-Tenant Management: Azure Bastion Jit (vinayaklatthe/microsoft-security-skills, 175 stars), Analyzing Kubernetes Audit Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mimir (grafana/skills, 282 stars) and Kubernetes (notque/vexjoy-agent, 441 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains KubeSphere Multi-Tenant Management?

kubesphere (a GitHub organization) maintains it in kubesphere/kubesphere, which has 17,056 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on July 15, 2026.

Source: kubesphere/kubesphere on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.