Gke Manifest Generation
google/skills
Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters.
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kubernetes-skill" agent skill from https://github.com/LukasNiessen/kubernetes-skill/tree/main into .claude/skills/kubernetes-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kubernetes-skill" agent skill from https://github.com/LukasNiessen/kubernetes-skill/tree/main into .agents/skills/kubernetes-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kubernetes-skill" agent skill from https://github.com/LukasNiessen/kubernetes-skill/tree/main into .cursor/skills/kubernetes-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kubernetes-skill" agent skill from https://github.com/LukasNiessen/kubernetes-skill/tree/main into .gemini/skills/kubernetes-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kubernetes-skill" agent skill from https://github.com/LukasNiessen/kubernetes-skill/tree/main into .github/skills/kubernetes-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LukasNiessen/kubernetes-skill kubernetes-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kubernetes-skill" agent skill from https://github.com/LukasNiessen/kubernetes-skill/tree/main into .opencode/skills/kubernetes-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubernetes-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kubernetes-skillKeeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
The agent works top to bottom. It first records context: cluster version and distribution, namespace and environment criticality, workload type, deployment method, policy enforcement, cloud provider and CNI, and add-ons such as GitOps, observability, ingress or service mesh, stating assumptions when something is unknown. It then picks one or more failure modes: insecure workload defaults, resource starvation, network exposure, privilege sprawl, fragile rollouts and API drift.
Each failure mode has its own reference file, and the agent loads only those that apply, plus supplemental references for deployment, stateful and job patterns, security hardening, observability, multi-tenancy, storage, Helm, Kustomize and validation. Conditional references load only when a signal appears, for example EKS patterns when AWS, IRSA or Karpenter come up. The aim is to stop models inventing Kubernetes details by tying output to official best practices.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 34f93c1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
KubeShark for Kubernetes loads about 1.2k tokens when it runs, and up to ~52k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 430 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LukasNiessen/kubernetes-skill at commit 34f93c1, republished under its MIT licence (© LukasNiessen). 430 words, ~1,187 tokens.
.claude/skills/kubernetes-skill/SKILL.md (or your agent's skills folder). This skill also uses 86 other files; get the full folder from GitHub.Run this workflow top to bottom.
Record before writing manifests:
If unknown, state assumptions explicitly.
Select one or more based on user intent and risk:
Primary failure-mode references:
references/insecure-workload-defaults.mdreferences/resource-starvation.mdreferences/network-exposure.mdreferences/privilege-sprawl.mdreferences/fragile-rollouts.mdreferences/api-drift.mdSupplemental references (only when needed):
references/deployment-patterns.mdreferences/stateful-patterns.mdreferences/job-patterns.mdreferences/daemonset-operator-patterns.mdreferences/security-hardening.mdreferences/observability.mdreferences/multi-tenancy.mdreferences/storage-and-state.mdreferences/helm-patterns.mdreferences/kustomize-patterns.mdreferences/validation-and-policy.mdreferences/examples-good.mdreferences/examples-bad.mdreferences/do-dont-patterns.mdConditional Reference Retrieval (CRR) references (load only when the signal is detected):
references/conditional/eks-patterns.md for EKS, AWS, IRSA, EKS Pod Identity, AWS Load Balancer Controller, EBS/EFS CSI, Karpenterreferences/conditional/gke-patterns.md for GKE, Autopilot, Workload Identity Federation for GKE, Dataplane V2, GCE Ingress, Config Syncreferences/conditional/aks-patterns.md for AKS, Microsoft Entra Workload ID, Azure CNI, AGIC, Azure Disk/File/Blob CSIreferences/conditional/openshift-patterns.md for OpenShift, OKD, ROSA, ARO, Routes, SCCs, OLM, ocreferences/conditional/gitops-controllers.md for Argo CD, ApplicationSet, Flux, GitOps reconciliation, sync wavesreferences/conditional/observability-stacks.md for Prometheus Operator, ServiceMonitor, PodMonitor, OpenTelemetry, Loki, GrafanaDo not load multiple CRR files unless the task spans multiple detected platforms/tools.
For each fix, include:
When applicable, output:
Always provide validation steps tailored to deployment method and risk tier:
kubectl apply --dry-run=server or kubectl diffkubeconform for schema validation against target cluster versionReturn:
© LukasNiessen, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 86 other files (references, assets) in the repository root of LukasNiessen/kubernetes-skill.
Open the folder on GitHubat commit 34f93c1
KubeShark for Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| KubeShark for Kubernetes this skillLukasNiessen/kubernetes-skill | 446 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Gke Manifest Generationgoogle/skills | 21k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Defender For Containersvinayaklatthe/microsoft-security-skills | 175 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Release Chartzabbix-community/helm-zabbix | 132 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Kcli Cluster Deploymentkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Aks Deployment Skilltimothywarner/chatgptclass | 143 | — | ~916 | Automated safety check: Pass | Custom licence |
google/skills
Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters.
vinayaklatthe/microsoft-security-skills
Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift.
zabbix-community/helm-zabbix
Cut and publish a new release of the Zabbix Helm chart in this repository, following the versioning rules and maintainer release process documented in CONTRIBUTING.md and CLAUDE.md (bump…
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
timothywarner/chatgptclass
Deploy and operate workloads on Azure Kubernetes Service (AKS) the safe way.
google/skills
Runs batch and HPC workloads on GKE, utilizing job queues and parallel processing.
Works with
Categories
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references. The agent works top to bottom. It first records context: cluster version and distribution, namespace and environment criticality, workload type, deployment method, policy enforcement, cloud provider and CNI, and add-ons such as GitOps, observability, ingress or service mesh, stating assumptions when something is unknown.
KubeShark for Kubernetes fits situations like: generating Kubernetes manifests with secure, resource-aware defaults; reviewing manifests or Helm charts for risky settings; migrating manifests off deprecated APIs; working on EKS, GKE, AKS or OpenShift specific configuration.
Run `npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a claude-code`. Or copy the skill folder (the LukasNiessen/kubernetes-skill repository) into .claude/skills/kubernetes-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a codex`. Or copy the skill folder (the LukasNiessen/kubernetes-skill repository) into .agents/skills/kubernetes-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LukasNiessen/kubernetes-skill --skill kubernetes-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes-skill, .gemini/skills/kubernetes-skill, .github/skills/kubernetes-skill and .opencode/skills/kubernetes-skill in your project.
Going by SKILL.md and its folder, KubeShark for Kubernetes needs the command-line tools its instructions call (kubectl).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
KubeShark for Kubernetes is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 51k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with KubeShark for Kubernetes: Gke Manifest Generation (google/skills, 21k stars), Defender For Containers (vinayaklatthe/microsoft-security-skills, 175 stars), Release Chart (zabbix-community/helm-zabbix, 132 stars) and Kcli Cluster Deployment (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LukasNiessen (a GitHub user) maintains it in LukasNiessen/kubernetes-skill, which has 446 GitHub stars. The repository was last updated on September 13, 2026.
Source: LukasNiessen/kubernetes-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.