Agent skill

Kubernetes

by magnus919 in magnus919/agent-skills

Operate, troubleshoot, secure, upgrade, and automate Kubernetes clusters and workloads safely across upstream Kubernetes, k3s, RKE2, MicroK8s, k0s, Talos, OpenShift/OKD, kind, Minikube…

MITAuto-check passedDevOps & Cloud

Install Kubernetes

skills CLI
$ npx skills add magnus919/agent-skills --skill kubernetes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills kubernetes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/kubernetes .claude/skills/kubernetes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes
GitHub stars
115
Token cost
~1.6k tokens
SKILL.md length
624 words
Files
34 (incl. scripts, references)
Skills in repo
131
Repo updated
First seen
Licence
MIT

At a glance

Operate, troubleshoot, secure, upgrade, and automate Kubernetes clusters and workloads safely across upstream Kubernetes, k3s, RKE2, MicroK8s, k0s, Talos, OpenShift/OKD, kind, Minikube…

  • Works in 6 steps: Identify the target: distribution,… → Discover before assuming: query served… → Separate portable Kubernetes behavior… → …
  • A task involves kubectl
  • SKILL.md covers Operating contract, Choose the operating path, First-response discovery and Routing, plus 4 more sections
  • Calls kubectl

What it does

Kubernetes is an agent skill from magnus919/agent-skills. Operate, troubleshoot, secure, upgrade, and automate Kubernetes clusters and workloads safely across upstream Kubernetes, k3s, RKE2, MicroK8s, k0s, Talos, OpenShift/OKD, kind, Minikube, Rancher-managed clusters, EKS, AKS, and GKE. Use when a task involves kubectl, Kubernetes APIs, Pods, Deployments, StatefulSets, Services, Ingress or Gateway API, CRDs, RBAC, NetworkPolicy, storage, scheduling, autoscaling, cluster lifecycle, or the bundled agent-first k8s-cli. Do not use this skill for unrelated requests; route…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 35 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/api-and-versioning.md`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes and Google Kubernetes Engine. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • A task involves kubectl
  • Kubernetes APIs
  • Cluster lifecycle
  • The bundled agent-first k8s-cli

Example prompts

  • “/kubernetes”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify the target: distribution, provider, cluster version, client version, context, namespace, access mode, and whether the cluster is…
  2. Discover before assuming: query served API resources, API versions, CRDs, system workloads, nodes, and distribution markers.
  3. Separate portable Kubernetes behavior from distribution/provider overlays. Load the matching reference before using lifecycle, networking…
  4. For mutations, preview first (k8s-cli ... --dry-run or kubectl diff / server dry-run), state scope, require explicit confirmation for…
  5. Prefer stable APIs and server-side validation. Treat beta/alpha APIs, feature gates, provider defaults, and version numbers as…
  6. Keep evidence bounded and structured. Never dump kubeconfigs, Secret values, tokens, or unbounded logs into chat.

What it can do on your machine

Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kubernetes loads about 1.6k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 624 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 624 words, ~1,583 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes/SKILL.md (or your agent's skills folder). This skill also uses 33 other files; get the full folder from GitHub.
name
kubernetes
description
Operate, troubleshoot, secure, upgrade, and automate Kubernetes clusters and workloads safely across upstream Kubernetes, k3s, RKE2, MicroK8s, k0s, Talos, OpenShift/OKD, kind, Minikube, Rancher-managed clusters, EKS, AKS, and GKE. Use when a task involves kubectl, Kubernetes APIs, Pods, Deployments, StatefulSets, Services, Ingress or Gateway API, CRDs, RBAC, NetworkPolicy, storage, scheduling, autoscaling, cluster lifecycle, or the bundled agent-first k8s-cli. Do not use this skill for unrelated requests; route to the nearest named specialist.

Kubernetes

Use this skill as a decision and routing layer. Do not treat it as a static kubectl cheat sheet.

Operating contract

  1. Identify the target: distribution, provider, cluster version, client version, context, namespace, access mode, and whether the cluster is production.
  2. Discover before assuming: query served API resources, API versions, CRDs, system workloads, nodes, and distribution markers.
  3. Separate portable Kubernetes behavior from distribution/provider overlays. Load the matching reference before using lifecycle, networking, identity, storage, or upgrade instructions.
  4. For mutations, preview first (k8s-cli ... --dry-run or kubectl diff / server dry-run), state scope, require explicit confirmation for destructive actions, then verify conditions, events, rollout, and the external boundary.
  5. Prefer stable APIs and server-side validation. Treat beta/alpha APIs, feature gates, provider defaults, and version numbers as time-sensitive.
  6. Keep evidence bounded and structured. Never dump kubeconfigs, Secret values, tokens, or unbounded logs into chat.

Choose the operating path

SituationFirst moveDo not do
Live cluster operationRun doctor, context, and discover; record context, namespace, distribution, and versionsDo not infer cluster state from configuration or a prior command
No cluster accessProduce a bounded plan and name the missing prerequisiteDo not claim a diagnosis, success, or invented command output
Any mutationRender, diff/server-dry-run, state scope, obtain the required confirmation, then mutate and verify the relevant boundaryDo not treat command exit 0 as operational success
Provider or distribution presentLoad the matching overlay before applying portable guidanceDo not apply upstream instructions unchanged

First-response discovery

sh
scripts/k8s-cli --json doctor
scripts/k8s-cli --json context
scripts/k8s-cli --json discover

If the wrapper is unavailable, use the equivalent native commands from references/cli-reference.md. If kubectl is absent, stop and report the prerequisite rather than inventing cluster state.

Routing

ScenarioLoad
API discovery, SSA, CRDs, or deprecationsreferences/api-and-versioning.md
Workloads, probes, rollouts, jobs, or controllersreferences/workloads-and-rollouts.md
Scheduling, scaling, storage, node disruption, or reliabilityreferences/scheduling-scaling-storage.md and references/nodes-and-reliability.md
Services, DNS, NetworkPolicy, Ingress, or Gateway APIreferences/networking.md
Pod is Running but not serving traffic or is absent from Service endpointsreferences/workloads-and-rollouts.md, references/networking.md, references/troubleshooting.md, and the matching distribution overlay
RBAC, Pod Security, admission, audit, secrets, or policy enginesreferences/security-and-policy.md and references/policy.md
Evidence-first diagnosis or advanced debuggingreferences/troubleshooting.md and references/debugging.md
Backups, upgrades, HA, or observabilityreferences/operations.md, references/backup-restore.md, and references/observability.md
Distribution/provider overlays or version matrixreferences/distributions.md, references/version-skew.md, and references/source-index.md
Native command details or output contractsreferences/cli-reference.md
Mutation safety gatesreferences/safety-gates.md
Show full SKILL.md (245 more words)Show less

Templates and scripts

  • templates/diagnostic-report.md: human-readable incident report
  • templates/cluster-inventory.json: bounded inventory schema
  • templates/upgrade-runbook.md: preflight, change, and verification runbook
  • scripts/k8s-cli: agent-first wrapper around kubectl
  • scripts/test-k8s-cli.sh: deterministic tests using a fake kubectl
  • scripts/gather-cluster-state.sh: bounded diagnostic collection for incident reports
  • scripts/verify-cluster-health.sh: bounded post-operation health verification
  • scripts/refresh-version-matrix.sh: refreshes dated release observations, never silently edits guidance

Version policy

The research baseline was checked 2026-07-11. The Kubernetes project page reported maintained minors 1.36, 1.35, and 1.34. This is not a permanent claim. Refresh references/distributions.md and the source index before asserting current versions or support status.

Verification boundary

ClaimMinimum evidence
Pod is healthyPod conditions, readiness, events, and relevant EndpointSlice or external boundary
Pod is serving trafficReady condition, Service selector, EndpointSlice membership, events, and a bounded Service-level check
Rollout succeededController conditions, resulting Pods, events, and the relevant Service or external check
API/resource is availableServed API discovery, installed CRDs/controller support, and server-side validation
Command succeeded operationallyBounded command result plus the resource condition and user-visible boundary

A component-level command result is evidence about that component only; do not promote it to a cluster or integration claim.

Hard boundaries

  • Never expose Secret data or raw kubeconfig credentials.
  • Never use --force-conflicts, delete, drain, patch, upgrade, or cluster-reset procedures without explaining scope and obtaining the required confirmation.
  • Never call a Pod healthy from Running alone.
  • Never call an integration successful from a component-level test alone.
  • Never apply an upstream procedure to k3s, RKE2, a managed provider, Talos, or OpenShift without loading its overlay.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 33 other files (scripts, references) in kubernetes of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • references/api-and-versioning.md
  • references/backup-restore.md
  • references/cli-reference.md
  • references/debugging.md
  • references/distributions.md
  • references/networking.md
  • references/nodes-and-reliability.md
  • references/observability.md
  • references/operations.md
  • references/policy.md
  • references/safety-gates.md
  • references/scheduling-scaling-storage.md
  • references/security-and-policy.md
  • references/source-index.md
  • references/troubleshooting.md
  • references/version-skew.md
  • … and 15 more

Open the folder on GitHubat commit 22b4723

Compare with similar skills

Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubernetes this skillmagnus919/agent-skills115—~1.6kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1952 repos~814Automated safety check: PassMIT
KubeShark for KubernetesLukasNiessen/kubernetes-skill446—~1.2kAutomated safety check: PassMIT
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Aicr Analyzing SnapshotsNVIDIA/aicr440—~3.5kAutomated safety check: PassApache-2.0
GCP Gkesickn33/agentic-awesome-skills47k2 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    195 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    446 GitHub stars~1.2k tokensUpdated 27 days ago
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    A skill your agent uses when analyzing an AICR snapshot YAML file, reviewing cluster state, comparing provider characteristics, extracting GPU/network topology insights, or generating a cluster…

    440 GitHub stars~3.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GCP Gke

    sickn33/agentic-awesome-skills

    Deploy and manage Google Kubernetes Engine clusters. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Performing Kubernetes Cis Benchmark With Kube Bench

    mukul975/Anthropic-Cybersecurity-Skills

    Turns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from magnus919/agent-skills

All 131 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    115 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    115 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    115 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Kubernetes

What does Kubernetes do?

Operate, troubleshoot, secure, upgrade, and automate Kubernetes clusters and workloads safely across upstream Kubernetes, k3s, RKE2, MicroK8s, k0s, Talos, OpenShift/OKD, kind, Minikube…. Kubernetes is an agent skill from magnus919/agent-skills. Operate, troubleshoot, secure, upgrade, and automate Kubernetes clusters and workloads safely across upstream Kubernetes, k3s, RKE2, MicroK8s, k0s, Talos, OpenShift/OKD, kind, Minikube, Rancher-managed clusters, EKS, AKS, and GKE.

When should I use Kubernetes?

Kubernetes fits situations like: A task involves kubectl; Kubernetes APIs; cluster lifecycle; the bundled agent-first k8s-cli.

How do I install Kubernetes in Claude Code?

Run `npx skills add magnus919/agent-skills --skill kubernetes -a claude-code`. Or copy the skill folder (kubernetes in magnus919/agent-skills) into .claude/skills/kubernetes in your project. Claude Code loads it when a task matches its description.

How do I install Kubernetes in Codex?

Run `npx skills add magnus919/agent-skills --skill kubernetes -a codex`. Or copy the skill folder (kubernetes in magnus919/agent-skills) into .agents/skills/kubernetes in your project. Codex loads it when a task matches its description.

Can I use Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes, .gemini/skills/kubernetes, .github/skills/kubernetes and .opencode/skills/kubernetes in your project.

What does Kubernetes need to run?

Going by SKILL.md and its folder, Kubernetes needs the command-line tools its instructions call (kubectl).

Does Kubernetes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kubernetes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Kubernetes use?

Kubernetes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubernetes use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.1k tokens, read only when the agent opens those files.

What are the alternatives to Kubernetes?

Skills that share tags, products or a category with Kubernetes: Devops (nicepkg/auto-company, 195 stars), KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 446 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars) and Aicr Analyzing Snapshots (NVIDIA/aicr, 440 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubernetes?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.