Deploying Kafka K8s
aiskillstore/marketplace
Deploys Apache Kafka on Kubernetes using the Strimzi operator with KRaft mode.
Helps DevOps engineers configure mirrord Operator's Kafka queue splitting feature end-to-end.
$ npx skills add metalbear-co/mirrord --skill mirrord-kafka -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install metalbear-co/mirrord mirrord-kafka --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/metalbear-co/mirrord.git skills-src && mkdir -p .claude/skills && cp -r skills-src/mirrord/mcp/corpus/skills/mirrord-kafka .claude/skills/mirrord-kafka && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mirrord-kafka" agent skill from https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafka into .claude/skills/mirrord-kafka/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mirrord-kafka", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafkaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add metalbear-co/mirrord --skill mirrord-kafka -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install metalbear-co/mirrord mirrord-kafka --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/metalbear-co/mirrord.git skills-src && mkdir -p .agents/skills && cp -r skills-src/mirrord/mcp/corpus/skills/mirrord-kafka .agents/skills/mirrord-kafka && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mirrord-kafka" agent skill from https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafka into .agents/skills/mirrord-kafka/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mirrord-kafka", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add metalbear-co/mirrord --skill mirrord-kafka -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install metalbear-co/mirrord mirrord-kafka --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/metalbear-co/mirrord.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/mirrord/mcp/corpus/skills/mirrord-kafka .cursor/skills/mirrord-kafka && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mirrord-kafka" agent skill from https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafka into .cursor/skills/mirrord-kafka/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mirrord-kafka", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/metalbear-co/mirrord.git --path mirrord/mcp/corpus/skills/mirrord-kafka--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add metalbear-co/mirrord --skill mirrord-kafka -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install metalbear-co/mirrord mirrord-kafka --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/metalbear-co/mirrord.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/mirrord/mcp/corpus/skills/mirrord-kafka .gemini/skills/mirrord-kafka && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mirrord-kafka" agent skill from https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafka into .gemini/skills/mirrord-kafka/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mirrord-kafka", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install metalbear-co/mirrord mirrord-kafkaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add metalbear-co/mirrord --skill mirrord-kafka -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/metalbear-co/mirrord.git skills-src && mkdir -p .github/skills && cp -r skills-src/mirrord/mcp/corpus/skills/mirrord-kafka .github/skills/mirrord-kafka && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mirrord-kafka" agent skill from https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafka into .github/skills/mirrord-kafka/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mirrord-kafka", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add metalbear-co/mirrord --skill mirrord-kafka -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install metalbear-co/mirrord mirrord-kafka --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/metalbear-co/mirrord.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/mirrord/mcp/corpus/skills/mirrord-kafka .opencode/skills/mirrord-kafka && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mirrord-kafka" agent skill from https://github.com/metalbear-co/mirrord/tree/main/mirrord/mcp/corpus/skills/mirrord-kafka into .opencode/skills/mirrord-kafka/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mirrord-kafka", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mirrord-kafkaHelps DevOps engineers configure mirrord Operator's Kafka queue splitting feature end-to-end.
Mirrord Kafka is an agent skill from metalbear-co/mirrord. Helps DevOps engineers configure mirrord Operator's Kafka queue splitting feature end-to-end. Generates the MirrordSplitConfig and MirrordPropertyList Kubernetes CRD YAMLs (the current resources; MirrordKafkaTopicsConsumer + MirrordKafkaClientConfig are deprecated but still supported), the matching mirrord.json splitqueues section with messagefilter and jqfilter, and Helm value guidance. Use this skill whenever the user mentions Kafka splitting with mirrord, MirrordSplitConfig, MirrordPropertyList…
Its SKILL.md is about 6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/kafka-client-config-crd.md`, `references/kafka-topics-consumer-crd.md` and `references/known-issues.md`).
It sits in Backend & APIs, covering Event-driven systems and Container orchestration. It works with Apache Kafka and Kubernetes. The repository describes itself as: Run any process, on your machine or in an AI agent's environment, as if it were a pod in your Kubernetes cluster: real env vars, DNS, network, traffic. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c8f017a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlhelmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl and helm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mirrord Kafka loads about 6k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 215 tokens; SKILL.md has 2,498 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from metalbear-co/mirrord at commit c8f017a, republished under its MIT licence (© metalbear-co). 2,498 words, ~6,028 tokens.
.claude/skills/mirrord-kafka/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Which CRDs? Kafka splitting is now configured with
MirrordSplitConfig(which queues to split + how the app finds their names) andMirrordPropertyList(the Kafka client connection). These replace the deprecatedMirrordKafkaTopicsConsumer+MirrordKafkaClientConfig, which still work for backward compatibility. Generate the new resources for any new setup. Only produce the deprecated ones if the user explicitly asks or is maintaining an existing deployment. Requires operator 3.170.0+ and CLI 3.221.0+.
IMPORTANT: Follow these security rules for all operations in this skill.
MirrordPropertyList YAML. Reference a Kubernetes Secret with valueFrom.secretKeyRef per property.kubectl create secret generic ... --from-file=... reading values from files (then delete the files). Do not suggest --from-literal for credential values — it exposes secrets in argv/shell history.^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$ and reject shell metacharacters before interpolating into commands.kubectl get / kubectl config calls are read-only and safe. Never run kubectl apply/create/delete or helm install/upgrade on the user's behalf — present generated YAML and cluster-modifying commands for the user to review and run themselves.Guide DevOps engineers through the full setup of mirrord Operator's Kafka queue splitting:
operator.kafkaSplitting (and the Kafka sidecar for Kafka Streams)feature.split_queues section developers use to filter messages (message_filter on headers, jq_filter on record content)Step 1: Load reference files
references/mirrord-split-config-crd.md — MirrordSplitConfig field spec (current)references/mirrord-property-list-crd.md — MirrordPropertyList field spec, auth patterns (current)references/known-issues.md — active bugs, gotchas, and workaroundsreferences/kafka-topics-consumer-crd.md, references/kafka-client-config-crd.md — deprecated CRDs; read only when helping with an existing legacy setupAlways read the relevant CRD reference for any resource you generate.
Step 2: Inspect the cluster (if kubectl is available)
kubectl config current-context
kubectl cluster-info 2>/dev/null | head -5
# Operator present?
kubectl get ns mirrord --no-headers 2>/dev/null
kubectl get deploy mirrord-operator -n mirrord --no-headers 2>/dev/null
# Kafka splitting enabled? (current CRDs)
kubectl get crd mirrordsplitconfigs.queues.mirrord.metalbear.co --no-headers 2>/dev/null
kubectl get crd mirrordpropertylists.mirrord.metalbear.co --no-headers 2>/dev/null
# Existing configs
kubectl get mirrordsplitconfigs --all-namespaces --no-headers 2>/dev/null
kubectl get mirrordpropertylists --all-namespaces --no-headers 2>/dev/null
# Legacy CRDs (only if migrating an existing setup)
kubectl get crd mirrordkafkatopicsconsumers.queues.mirrord.metalbear.co --no-headers 2>/dev/nullIf the operator is missing and the cluster has no mirrord for Teams license, an AI agent can offer the user a seven-day Enterprise trial and, once they agree, start it and install the operator: see the mirrord-operator skill, "Agent-started trial".
Inspect the target workload to extract container names and env vars:
kubectl get deployment/<name> -n <ns> -o yaml 2>/dev/null # or statefulset / rollout
kubectl get svc --all-namespaces --no-headers 2>/dev/null | grep -i kafkaThis auto-discovery reduces the questions you need to ask (bootstrap server from a Kafka service; topic/group-id env vars from the target's pod spec). If kubectl isn't available, ask.
Step 3: Gather remaining context
For MirrordPropertyList:
For MirrordSplitConfig:
MirrordPropertyList name to referenceRemind the user once, early, to enable Kafka splitting:
operator:
kafkaSplitting: true
# For Kafka Streams consumers only:
kafkaSplittingSidecar:
enabled: trueRules:
MirrordSplitConfig) — this is the recommended primary location for a single team's connection config, and it wins if a list of the same name also exists in the operator's namespace. The operator (3.191.0+) also looks up the list in its own namespace as a fallback, so one connection config can be shared across many teams/namespaces — only reach for that when the user explicitly wants shared/cluster-wide credentials. ConfigMap/Secret refs inside the list resolve in whichever namespace the list itself was found in.group.id — mirrord manages the operator's consumer group.INCONSISTENT_GROUP_PROTOCOL: set mirrord.temporary_group_id: "true" (operator 3.195.0+). This is different from the Kafka Streams case below — it's for regular consumers whose client library advertises a custom partition-assignment protocol the operator's librdkafka consumer can't join.PolicyViolation (e.g. Confluent Cloud requires replication factor 3): set mirrord.split_topic.replication_factor (operator 3.191.0+) to a positive number, copy (match the source topic's factor), or -1 (broker default).valueFrom.secretKeyRef for any credential (SASL password, SSL PEMs, key password).mirrord.auth.kind: MSK_IAM + mirrord.auth.aws_region (auto-adds OAUTHBEARER + SASL_SSL).mirrord.client_implementation: java.security.protocol to SASL_SSL when the user mentions SASL without specifying transport, and flag it: "defaulted to SASL_SSL — change to SASL_PLAINTEXT if your broker uses plaintext transport."apiVersion: mirrord.metalbear.co/v1
kind: MirrordPropertyList
metadata:
name: kafka-connection
namespace: <target-namespace>
spec:
properties:
- name: bootstrap.servers
value: <broker-address>
- name: security.protocol
value: PLAINTEXT
# credentials via valueFrom.secretKeyRef, MSK IAM keys, or client_implementation as neededSee references/mirrord-property-list-crd.md for MSK IAM, SSL-via-Secret, Streams, and Java KeyStore credentials (native mirrord.ssl.*.base64 on operator 3.199.0+, JKS→PEM conversion for older operators).
Rules:
spec.targetRef = { apiVersion, kind, name } (Deployment/StatefulSet/Rollout).spec.queues[] needs id, kind: kafka, a clientConfig (the MirrordPropertyList name; or set once via spec.clientConfigs.kafka), and appConfig.topic.appConfig.groupId (standard consumers) or appConfig.appId (Kafka Streams) per queue.spec.restart.timeout (pod readiness wait after a restart), spec.ttl (idle window: keeps the split fully live so a reconnecting session resumes instantly, requires operator 3.194.0+), and spec.drainTimeout (drain window that follows: lets the workload finish the already-forwarded backlog before unpatching). On operators older than 3.194.0, spec.drainTimeout alone controls how long the workload stays patched after the last session.mirrord.temporary_group_id) waits for the workload's rollout to finish — 180 seconds by default, then the session fails. For a slow rollout (many replicas, a long termination grace period, a consumer that stays in the group until its session timeout expires), raise it with mirrord.group_join_timeout (seconds) on the MirrordPropertyList (operator 3.204.0+; older operators reject it as an unknown mirrord. key).apiVersion: queues.mirrord.metalbear.co/v1
kind: MirrordSplitConfig
metadata:
name: <workload>-split
namespace: <target-namespace>
spec:
targetRef:
apiVersion: apps/v1
kind: Deployment
name: <workload-name>
queues:
- id: <topic-id>
kind: kafka
clientConfig: kafka-connection
appConfig:
topic:
- env: <TOPIC_ENV_VAR>
fallback: <topic-name> # optional
containers: [<container>]
groupId:
- env: <GROUP_ID_ENV_VAR>
containers: [<container>]appConfig.topic/groupId/appId sources also support envLike (regex over var names), volume (read the name from a file mounted from a ConfigMap volume instead of an env var — requires operator 3.198.0+; see references/mirrord-split-config-crd.md), podFile (read the name from a file that exists only inside the running pods — e.g. rendered by vault-agent-injector or a secrets-store CSI driver, with no ConfigMap/Secret behind it — requires operator 3.201.0+; see below), valueSelector (a selector over nested keys / .[] for JSON-valued env vars — not a full jq expression, no pipes or functions), and valuePattern (regex to swap an embedded name). See the split-config reference.
podFile source (Vault/CSI-injected names): the operator reads the file by running cat in a running pod of the target, so the target needs at least one running pod when the split starts, and the operator needs get/create on pods/exec in the target namespace (the Helm chart grants this when Kafka splitting is enabled). It then mounts a Secret carrying the substituted content over the file's exact path in the app containers — the same kind of restart env-var injection causes — while the injector's own sidecar keeps rendering the original underneath. podFile.path is the absolute in-container path; podFile.container defaults to a vault-agent sidecar if present, else the pod's first app container (set it explicitly if the default container has no cat, e.g. distroless). If both podFile and an env/envLike/volume source are set on the same entry, the other source wins and podFile is ignored; fallback doesn't apply to it. The referenced file's content is pinned for the split's duration — a value that also rotates (like a credential) keeps reading the value from split start.
Show the developer-facing config referencing the topic IDs. Two filter kinds, and you can combine them:
Filter on Kafka headers (message_filter):
{
"operator": true,
"target": "deployment/<workload>/container/<container>",
"feature": {
"split_queues": {
"<topic-id>": {
"queue_type": "Kafka",
"message_filter": { "<header-name>": "<regex>" }
}
}
}
}All specified headers must match. An empty message_filter: {} with no jq_filter is match-none (the local app gets zero messages).
Composable header filter (filter) — NEW, alternative to message_filter:
{
"operator": true,
"target": "deployment/<workload>/container/<container>",
"feature": {
"split_queues": {
"<topic-id>": {
"queue_type": "Kafka",
"filter": {
"all_of": [
{ "metadata": "^tenant: blue$" },
{ "metadata": "^region: eu-.*$" }
]
}
}
}
}
}filter takes a single { "metadata": "<regex>" }, or an any_of/all_of list of them. Each metadata regex is matched against every header rendered as <name>: <value> — one regex can pin a header by name or match a marker wherever it's propagated. A message_filter of {"tenant": "^blue$"} is equivalent to filter: {"metadata": "^tenant: blue$"}, except message_filter requires the header name to match exactly while a metadata regex sees the whole name: value line. Use either filter or message_filter on an entry, not both. Requires mirrord 3.264.0+ and operator 3.212.0+. A metadata regex can't be verified against a specific header name, so a topic covered by a splitQueues policy rule rejects a lone metadata filter the same way it rejects a lone jq_filter — use message_filter there instead.
Filter on record content (jq_filter) — NEW:
{
"operator": true,
"target": "deployment/<workload>/container/<container>",
"feature": {
"split_queues": {
"<topic-id>": {
"queue_type": "Kafka",
"jq_filter": ".payload | fromjson | .data.merchantId == 2137"
}
}
}
}jq_filter runs a jq program over a JSON doc the operator builds per record: topic, partition, offset, timestamp, key, payload, headers. key/payload/header values are UTF-8 strings (or base64 when not valid UTF-8). A record matches if the program outputs true; a record whose program errors (e.g. fromjson on non-JSON) is treated as not matching and stays on the deployed app's path.
Filter on protobuf payloads (payload_protobuf) — NEW:
{
"operator": true,
"target": "deployment/<workload>/container/<container>",
"feature": {
"split_queues": {
"<topic-id>": {
"queue_type": "Kafka",
"payload_protobuf": {
"schema_file": "schemas/cdc_record.proto",
"message_type": "com.example.cdc.Record"
},
"jq_filter": ".payload_decoded.merchant_id == 2137"
}
}
}
}For topics carrying raw protobuf record values (no JSON envelope, no schema-registry framing) instead of JSON. schema_file points at a local .proto file the CLI compiles itself (resolving imports against the file's directory — add include_directories for extra import roots); message_type is the fully-qualified message type. Users with a pre-compiled schema can set descriptor_base64 (a base64 FileDescriptorSet from protoc --descriptor_set_out --include_imports) instead of schema_file. The decoded message is exposed to jq_filter as payload_decoded (field names as in the schema, enums as their names, 64-bit ints as JSON numbers, default-valued fields included). A record that fails to decode with the given schema is treated as not matching. Like jq_filter, payload_protobuf only works with the default librdkafka client, and does not support schema-registry framing (magic byte + schema id prefix).
Notes to convey:
queue_mode is optional: steal (default, only your local app gets a matched message) or mirror (both your app and the deployed app get a copy).filter/message_filter and a jq_filter are both set, both must match.jq_filter requires operator 3.183.0+, CLI 3.232.0+, and the default librdkafka client — it is not supported with the Java client (Kafka Streams), which fails with a clear error.queue_id per entry — it also accepts payload_protobuf per entry.If the user has the mirrord-config skill, point them there for the full mirrord.json.
MirrordPropertyList (in the target's namespace, or the operator's namespace if sharing) has bootstrap.servers; does not set group.id.MirrordSplitConfig is in the target's namespace with spec.targetRef (apiVersion, kind, name).id, kind: kafka, a clientConfig (or spec.clientConfigs.kafka), and appConfig.topic.appConfig.groupId or appConfig.appId.kind (targetRef) is one of Deployment, StatefulSet, Rollout.clientConfig resolves to a MirrordPropertyList, looked up in the target's namespace first, then the operator's namespace (operator 3.191.0+) — or, as a final legacy fallback, a MirrordKafkaClientConfig of that name in the operator namespace.target matches the MirrordSplitConfig targetRef.jq_filter is only used with librdkafka (not with mirrord.client_implementation: java).payload_protobuf is only used with librdkafka, on queue_type: Kafka, and sets exactly one of schema_file or descriptor_base64 plus message_type.min.insync.replicas / acks workaround.mirrord.ssl.*.base64); offer PEM conversion commands only for older operators.podFile source (operator 3.201.0+) can read them straight from the rendered file.mirrord-tmp-* topics.jq_filter won't work.Present results as:
✅ Validation passed
⚠️ Warning: [description + workaround]
❌ Error: [what's wrong + how to fix]Full setup: brief overview of the 2 resources → MirrordPropertyList YAML → MirrordSplitConfig YAML → example mirrord.json → validation → warnings.
Single resource: YAML → validation → warnings.
Troubleshooting: read references/known-issues.md, use the Quick Symptom Lookup, ask for the operator version (kubectl get deploy mirrord-operator -n mirrord -o jsonpath='{.spec.template.spec.containers[0].image}'), match symptoms, suggest checking operator logs (kubectl logs -n mirrord deployment/mirrord-operator --tail 100).
"Set up Kafka splitting for my deployment" → ask for bootstrap servers, auth, workload name/namespace, topic + group-id env vars → generate MirrordPropertyList + MirrordSplitConfig + mirrord.json example.
"Filter by message body / a field in the payload" → use jq_filter (this is now supported). Confirm operator 3.183.0+/CLI 3.232.0+ and librdkafka (not Streams).
"Our topic carries raw protobuf, not JSON" → use payload_protobuf (schema_file + message_type, or descriptor_base64) alongside jq_filter on the decoded payload_decoded field. librdkafka only, same as jq_filter.
"Our topic/group name comes from a Vault-injected file, not an env var" → use a podFile source on appConfig.topic/groupId/appId (operator 3.201.0+) instead of env/volume.
"We use Kafka Streams" → appConfig.appId + mirrord.client_implementation: java + operator.kafkaSplittingSidecar.enabled: true. Note jq_filter is unavailable with the Java client.
"We use AWS MSK with IAM" → mirrord.auth.kind: MSK_IAM + mirrord.auth.aws_region; annotate the operator SA with the role ARN via sa.roleArn.
"We use JKS for Kafka auth" → put the same ssl.* properties the JVM app already uses on the MirrordPropertyList: base64-encode the store into mirrord.ssl.truststore.base64/mirrord.ssl.keystore.base64 (or point ssl.truststore.location/ssl.keystore.location at a store mounted into the operator pod), via a Secret. Requires operator 3.199.0+ — on older operators, fall back to JKS→PEM conversion and ssl.*.pem via a Secret. See references/mirrord-property-list-crd.md.
"My session fails with INCONSISTENT_GROUP_PROTOCOL" / "We use KafkaJS" → set mirrord.temporary_group_id: "true" on the MirrordPropertyList (operator 3.195.0+). The operator then patches the consumer group to a generated temporary one so it never negotiates a protocol with the app's client. Only reach for the Kafka Streams JVM-proxy setup (appConfig.appId + client_implementation: java) if the workload is an actual Kafka Streams app.
"Splitting fails with a PolicyViolation broker error" / "We use Confluent Cloud" → the managed platform enforces a minimum replication factor for new topics. Set mirrord.split_topic.replication_factor: copy (or a number matching the platform's minimum) on the MirrordPropertyList (operator 3.191.0+).
"My session times out" → check known-issues (single-replica min.insync.replicas, ephemeral topic cleanup), tune spec.restart.timeout, check operator logs.
"Migrate our existing Kafka splitting config" → map MirrordKafkaTopicsConsumer→MirrordSplitConfig and MirrordKafkaClientConfig→MirrordPropertyList (mapping tables in the reference files). You can migrate the topics consumer first — clientConfig falls back to the legacy client config by name.
MirrordKafkaTopicsConsumer/MirrordKafkaClientConfig for a new setup — use MirrordSplitConfig + MirrordPropertyList.group.id — mirrord manages it.MirrordPropertyList to the operator's namespace — the target's namespace is still the recommended default; only use the operator's namespace (operator 3.191.0+) when the user wants to share one connection config across namespaces.appConfig.groupId and appConfig.appId on one queue.jq_filter for Kafka Streams (Java client) sessions — it's librdkafka-only.jq_filter supports it.© metalbear-co, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in mirrord/mcp/corpus/skills/mirrord-kafka of metalbear-co/mirrord.
Open the folder on GitHubat commit c8f017a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in metalbear-co/mirrord, which our catalogue first saw on October 11, 2026.
Mirrord Kafka next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mirrord Kafka this skillmetalbear-co/mirrord | 5.4k | 1 repos | ~6k | Automated safety check: Pass | MIT | |
| Deploying Kafka K8saiskillstore/marketplace | 433 | — | ~1.8k | Automated safety check: Pass | None | |
| Opensourcefaqdigoal/blog | 8.6k | — | ~966 | Automated safety check: Pass | GPL-2.0 | |
| Dt Obs GCPDynatrace/dynatrace-for-ai | 163 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Ak Cloud Deployyaalalabs/agent-kernel | 192 | — | ~14k | Automated safety check: Pass | Apache-2.0 | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 |
aiskillstore/marketplace
Deploys Apache Kafka on Kubernetes using the Strimzi operator with KRaft mode.
digoal/blog
解答与开源产品有关的深度技术问题,输出图文并茂的 Markdown 技术文章。触发条件:用户提出与开源项目(如 PostgreSQL、Redis、Kafka、Kubernetes、ClickHouse、Flink 等)相关的技术问题,并提供源码目录或 URL、deepwiki repo 名称。即使用户只说"帮我解答这个开源问题"或"分析一下这个项目的某个机制",也应使用本…
Dynatrace/dynatrace-for-ai
GCP cloud resources including Compute Engine, GKE, Cloud Run, Pub/Sub, VPC networking, DNS, IAM, Secret Manager, and monitoring.
yaalalabs/agent-kernel
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
pydantic/skills
Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.
metalbear-co/mirrord
Help users install and configure the mirrord Operator for team/enterprise environments.
metalbear-co/mirrord
Helps DevOps engineers configure mirrord Operator's Temporal task queue splitting feature end-to-end.
metalbear-co/mirrord
Help users set up mirrord in CI pipelines for testing against real Kubernetes environments.
metalbear-co/mirrord
Help users chaos test their app with mirrord: inject artificial latency or connection errors into a mirrord session's outgoing traffic via per-session chaos rules managed with the mirrord chaos CLI.
metalbear-co/mirrord
Helps users generate, edit, and validate mirrord.json configuration files for mirrord (MetalBear).
metalbear-co/mirrord
Guide users from zero to their first working mirrord session.
Works with
Categories
Helps DevOps engineers configure mirrord Operator's Kafka queue splitting feature end-to-end. Mirrord Kafka is an agent skill from metalbear-co/mirrord. Helps DevOps engineers configure mirrord Operator's Kafka queue splitting feature end-to-end.
Mirrord Kafka fits situations like: the user mentions Kafka splitting with mirrord; mirrordSplitConfig; mirrordPropertyList; mirrordKafkaClientConfig.
Run `npx skills add metalbear-co/mirrord --skill mirrord-kafka -a claude-code`. Or copy the skill folder (mirrord/mcp/corpus/skills/mirrord-kafka in metalbear-co/mirrord) into .claude/skills/mirrord-kafka in your project. Claude Code loads it when a task matches its description.
Run `npx skills add metalbear-co/mirrord --skill mirrord-kafka -a codex`. Or copy the skill folder (mirrord/mcp/corpus/skills/mirrord-kafka in metalbear-co/mirrord) into .agents/skills/mirrord-kafka in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add metalbear-co/mirrord --skill mirrord-kafka -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mirrord-kafka, .gemini/skills/mirrord-kafka, .github/skills/mirrord-kafka and .opencode/skills/mirrord-kafka in your project.
Going by SKILL.md and its folder, Mirrord Kafka needs the command-line tools its instructions call (kubectl and helm).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mirrord Kafka is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Mirrord Kafka: Deploying Kafka K8s (aiskillstore/marketplace, 433 stars), Opensourcefaq (digoal/blog, 8.6k stars), Dt Obs GCP (Dynatrace/dynatrace-for-ai, 163 stars) and Ak Cloud Deploy (yaalalabs/agent-kernel, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
metalbear-co (a GitHub organization) maintains it in metalbear-co/mirrord, which has 5,362 GitHub stars. The repository was last updated on October 11, 2026.
Source: metalbear-co/mirrord on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.