Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Explains the multi-stage Dockerfile, the 25 image variant combinations, and the Makefile targets for building NGINX Ingress Controller images.
$ npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nginx/kubernetes-ingress nic-docker-images --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/nic-docker-images .claude/skills/nic-docker-images && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nic-docker-images" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-images into .claude/skills/nic-docker-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-docker-images", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-imagesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nginx/kubernetes-ingress nic-docker-images --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/nic-docker-images .agents/skills/nic-docker-images && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nic-docker-images" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-images into .agents/skills/nic-docker-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-docker-images", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nginx/kubernetes-ingress nic-docker-images --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/nic-docker-images .cursor/skills/nic-docker-images && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nic-docker-images" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-images into .cursor/skills/nic-docker-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-docker-images", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nginx/kubernetes-ingress.git --path .github/skills/nic-docker-images--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nginx/kubernetes-ingress nic-docker-images --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/nic-docker-images .gemini/skills/nic-docker-images && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nic-docker-images" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-images into .gemini/skills/nic-docker-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-docker-images", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nginx/kubernetes-ingress nic-docker-imagesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/nic-docker-images .github/skills/nic-docker-images && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nic-docker-images" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-images into .github/skills/nic-docker-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-docker-images", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nginx/kubernetes-ingress nic-docker-images --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/nic-docker-images .opencode/skills/nic-docker-images && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nic-docker-images" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-docker-images into .opencode/skills/nic-docker-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-docker-images", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nic-docker-imagesExplains the multi-stage Dockerfile, the 25 image variant combinations, and the Makefile targets for building NGINX Ingress Controller images.
This skill describes a roughly 1100-line multi-stage Dockerfile where a BUILD_OS argument picks the base-image stage and a TARGET argument picks the final stage, plus supporting images built outside that Dockerfile, such as a UBI dependency image pinned by digest in the Makefile.
make all-images builds 25 variants across three axes: OS family (Debian, Alpine, or UBI), NGINX edition (OSS, Plus, or Plus with WAF/DoS/FIPS add-ons), and NGINX Agent version (v2 or v3), with OSS and plain Plus images shipping agent v3 only while NAP WAF stages exist in matched v2/v3 pairs. NAP variants build amd64 only while OSS and Plus also build arm64.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 29a1a36. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makedockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
NGINX Ingress Controller Image Builder loads about 2.9k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 1,137 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nginx/kubernetes-ingress at commit 29a1a36, republished under its Apache-2.0 licence (© nginx). 1,137 words, ~2,944 tokens.
.claude/skills/nic-docker-images/SKILL.md (or your agent's skills folder).Single build/Dockerfile (~1100 lines), heavily multi-stage. The BUILD_OS arg selects which base image stage is used, and TARGET selects the final stage.
nginx-files (scratch) <- Repo files, signing keys, package repo definitions, scripts
| (rewrites repo hosts + user-agent strings via sed)
OS-specific base stages <- One per variant (debian, alpine, ubi, *-plus, *-nap[-v5][-fips][-agent])
|
FROM ${BUILD_OS} AS common <- Runs common.sh + patch-os.sh, sets permissions
|
TARGET stages (final image) <- local, container, goreleaser, debug, debug-container,
download, aws, patched, and *-prebuilt variantsSupporting images built outside this Dockerfile:
build/dependencies/Dockerfile.ubi10 builds the UBI package image published to ghcr.io/nginx/dependencies/nginx-ubi, consumed via the UBI10_PACKAGES_IMAGE build arg (pinned by digest in the Makefile). Built by build-ubi-dependency.yml on changes to that file, or locally with make ubi10-dependency-image-local (requires rhel_license).build/dependencies/tracking.info.default is copied in as tracking.info to attribute the install to NIC before the Plus licence reporter initialises.make all-images builds 25 variants. Three axes combine:
-agent suffixed stages)| OS | OSS | Plus | Plus+WAF | Plus+WAFv5 | Plus+DoS | Plus+WAF+DoS | Plus+FIPS | Plus+WAF+FIPS | Plus+WAFv5+FIPS |
|---|---|---|---|---|---|---|---|---|---|
| Debian | yes | yes | yes | yes | yes | yes | - | - | - |
| Alpine | yes | yes | - | - | - | - | yes | yes | yes |
| UBI 10 | yes | yes | yes | yes | yes | yes | - | - | - |
Architecture: amd64 + arm64 for OSS and Plus. NAP variants are amd64 only.
AGENT_V3_VERSION).AGENT_V2_VERSION, the -agent suffixed stage pins AGENT_V3_VERSION. For example debian-plus-nap (agent v2) and debian-plus-nap-agent (agent v3)..github/data/matrix-images-nap.json builds both halves of each pair for WAF and WAF+DoS (nap_modules: waf and nap_modules: waf,dos). DoS-only (nap_modules: dos) builds on the standard plus-nap stages (debian-plus-nap and ubi-10-plus-nap), which conditionally install Agent v3 when NAP_MODULES=dos, publishing Agent v3 under standard tags without redundant -agent image variants.debian-image-dos-plus, ubi-image-dos-plus) and the CI matrix use plus-nap (debian-plus-nap, ubi-10-plus-nap) with Agent v3 for DoS-only images.agentv2 / agentv3 pytest markers.All targets call $(DOCKER_CMD) = docker build --platform linux/$(ARCH) --target $(TARGET) -f build/Dockerfile.
| Target | BUILD_OS | NAP_MODULES | Agent |
|---|---|---|---|
debian-image | debian | - | v3 |
alpine-image | alpine | - | v3 |
ubi-image | ubi | - | v3 |
debian-image-plus | debian-plus | - | v3 |
alpine-image-plus | alpine-plus | - | v3 |
alpine-image-plus-fips | alpine-plus-fips | - | v3 |
ubi-image-plus | ubi-10-plus | - | v3 |
alpine-image-nap-plus-fips | alpine-plus-nap-fips | waf | v2 |
alpine-image-nap-plus-fips-agent | alpine-plus-nap-fips-agent | waf | v3 |
alpine-image-nap-v5-plus-fips | alpine-plus-nap-v5-fips | waf | v2 |
alpine-image-nap-v5-plus-fips-agent | alpine-plus-nap-v5-fips-agent | waf | v3 |
debian-image-nap-plus | debian-plus-nap | waf | v2 |
debian-image-nap-plus-agent | debian-plus-nap-agent | waf | v3 |
debian-image-nap-v5-plus | debian-plus-nap-v5 | waf | v2 |
debian-image-nap-v5-plus-agent | debian-plus-nap-v5-agent | waf | v3 |
debian-image-dos-plus | debian-plus-nap | dos | v3 |
debian-image-nap-dos-plus | debian-plus-nap | waf,dos | v2 |
debian-image-nap-dos-plus-agent | debian-plus-nap-agent | waf,dos | v3 |
ubi-image-nap-plus | ubi-10-plus-nap | waf | v2 |
ubi-image-nap-plus-agent | ubi-10-plus-nap-agent | waf | v3 |
ubi-image-nap-v5-plus | ubi-10-plus-nap-v5 | waf | v2 |
ubi-image-nap-v5-plus-agent | ubi-10-plus-nap-v5-agent | waf | v3 |
ubi-image-dos-plus | ubi-10-plus-nap | dos | v3 |
ubi-image-nap-dos-plus | ubi-10-plus-nap | waf,dos | v2 |
ubi-image-nap-dos-plus-agent | ubi-10-plus-nap-agent | waf,dos | v3 |
Other targets: all-images (all 25, prunes the builder cache first), ubi10-dependency-image-local (UBI package image), push (docker push to PREFIX:TAG), patch-os (OS patches an existing image).
Plus images receive $(PLUS_ARGS): --secret id=nginx-repo.crt --secret id=nginx-repo.key plus NGINX_PLUS_VERSION and PLUS_PACKAGE_REPO.
make build accepts only local, container, download, goreleaser, debug and errors on anything else. The remaining stages are selected by CI or by make patch-os directly.
| Target | Use Case |
|---|---|
local | Default -- binary pre-built on host, copied in |
container | Binary built inside Docker (multi-arch capable) |
goreleaser | Binary from GoReleaser dist/ (CI builds) |
debug | Includes delve debugger |
debug-container | Delve build with the binary compiled inside Docker |
download | Extracts binary from a published Docker Hub image (DOWNLOAD_TAG, resolved by hack/docker.sh) |
aws | AWS marketplace variant |
patched | OS patches an existing image (IMAGE_NAME) |
local-prebuilt, goreleaser-prebuilt, aws-prebuilt | Same as their counterparts but layered onto PREBUILT_BASE_IMG instead of rebuilding the OS stage |
| Arg | Purpose | Source of truth |
|---|---|---|
BUILD_OS | Base image stage | Makefile targets + Dockerfile stages |
IC_VERSION | Ingress controller version | .github/data/version.txt |
NGINX_PLUS_VERSION | NGINX Plus version | Makefile |
NGINX_OSS_VERSION | NGINX OSS version | Makefile |
AGENT_V2_VERSION / AGENT_V3_VERSION | nginx-agent version per variant | Makefile |
NAP_MODULES | App Protect modules | Any of waf, dos, or waf,dos |
NAP_WAF_VERSION, NAP_WAF_COMMON_VERSION, NAP_WAF_PLUGIN_VERSION, NAP_WAF_IPI_VERSION | NAP WAF package pins | Makefile |
UBI10_PACKAGES_IMAGE | UBI package image, digest-pinned | Makefile (ghcr.io/nginx/dependencies/nginx-ubi) |
PREBUILT_BASE_IMG | Base for *-prebuilt targets | GCR image ref (set by CI) |
IMAGE_NAME | Image to patch for TARGET=patched | make patch-os / patch-image.yml |
DOWNLOAD_TAG | Published tag for TARGET=download | hack/docker.sh |
OSS_PACKAGE_REPO | Repo host for OSS packages | Makefile / CI inputs (defaults to packages.nginx.org) |
AGENT_PACKAGE_REPO | Repo host for NGINX Agent packages | Makefile / CI inputs (defaults to packages.nginx.org) |
PLUS_PACKAGE_REPO | Repo host for Plus packages | Makefile / CI inputs (defaults to pkgs.nginx.com) |
WAF_PACKAGE_REPO | Repo host for F5 NAP WAF packages | Makefile / CI inputs (defaults to pkgs.nginx.com) |
DOS_PACKAGE_REPO | Repo host for F5 NAP DoS packages | Makefile / CI inputs (defaults to pkgs.nginx.com) |
Do not hard-code IC_VERSION, NGINX_*_VERSION, AGENT_*_VERSION or NAP_WAF_* values in this file or in other docs as they change every release. Always reference the Makefile variables or .github/data/version.txt.
build/scripts/)| Script | Purpose |
|---|---|
common.sh | Sets up directories, copies NGINX templates (v1/v2), sets file permissions (101:0), runs setcap on nginx binaries |
agent.sh | Configures nginx-agent ownership; creates NMS compiler symlinks for NAP v4 |
nap-waf.sh | Creates WAF directories (/etc/nginx/waf/nac-policies, /opt/app_protect/) |
nap-dos.sh | Creates DoS directories (/root/app_protect_dos, /shared/cores) |
ubi-setup.sh | UBI-specific: installs shadow-utils, creates nginx user/group (101:0) |
ubi-clean.sh | UBI-specific: removes build-time packages, cleans dnf cache |
patch-os.sh is not in this repo -- the nginx-files stage fetches it from nginx/k8s-common (files/patch-os.sh). Changes to it must be made in that repository.
Package repo definitions (*.repo, *.sources, 90pkgs-nginx) are likewise fetched in nginx-files from cs.nginx.com and nginx/k8s-common, then rewritten with sed to inject the version, the *_PACKAGE_REPO host override, and the k8s-ic-<IC_VERSION> user-agent used for usage attribution.
setcap cap_net_bind_service for ports 80/443--mount=type=bind, --mount=type=secret, --mount=type=cache--secret mounts, never COPY into layers--secret mounts (required=false) for nginx-repo.crt/nginx-repo.key to authenticate against non-default repo hosts like pkgs-test.nginx.com when running authenticated CI builds.@sha256: digests for reproducibility; some stages intentionally use build-arg/tag-selected bases (for example BUILD_OS, UBI10_PACKAGES_IMAGE, or download/prebuilt images)ghcr.io/nginx/alpine-fips; UBI variants build on redhat/ubi10-minimalnginx-module-otel (OpenTelemetry) and nginx-agent (usage reporting)njs and fips-check modules# renovate: comments--secret mountsarm64 to NAP image matrices -- NAP is amd64 onlyBUILD_OS to select variants, not separate Dockerfilesfoo-nap stage needs a matching foo-nap-agent stage, a Makefile target, an entry in make all-images, and both entries in .github/data/matrix-images-nap.json. DoS-only is the exception -- it builds the standard plus-nap stages with NAP_MODULES=dos, which install Agent v3, and has no -agent twin.common stage unifies all variants -- changes there affect every imagecommon.sh detects Plus via BUILD_OS containing "plus" and creates OIDC directoriespatch-os.sh lives in nginx/k8s-common, not build/scripts/ -- editing it here is impossibleUBI10_PACKAGES_IMAGE is digest-pinned in the Makefile; rebuilding build/dependencies/Dockerfile.ubi10 requires bumping that digest afterwards© nginx, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/nic-docker-images of nginx/kubernetes-ingress.
Open the folder on GitHubat commit 29a1a36
NGINX Ingress Controller Image Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| NGINX Ingress Controller Image Builder this skillnginx/kubernetes-ingress | 5.1k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 16k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Devopsnicepkg/auto-company | 195 | 2 repos | ~814 | Automated safety check: Pass | MIT | |
| .NET Crash Dump Collectiondotnet/skills | 5.6k | 2 repos | ~1.1k | Automated safety check: Pass | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
nicepkg/auto-company
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).
dotnet/skills
Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.
NVIDIA/OpenShell
Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
nginx/kubernetes-ingress
Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.
nginx/kubernetes-ingress
Testing conventions for the NGINX Ingress Controller repo: Go table-driven tests, mandatory snapshot regeneration, Helm tests and Python pytest integration tests.
nginx/kubernetes-ingress
Explains how the NGINX Ingress Controller's GitHub Actions workflows, reusable workflows, build matrices and release pipeline fit together across two repositories.
nginx/kubernetes-ingress
Troubleshooting patterns for the NGINX Ingress Controller: reload failures, custom resources that have no effect, controller panics and snapshot test failures.
Works with
Categories
Explains the multi-stage Dockerfile, the 25 image variant combinations, and the Makefile targets for building NGINX Ingress Controller images. This skill describes a roughly 1100-line multi-stage Dockerfile where a BUILD_OS argument picks the base-image stage and a TARGET argument picks the final stage, plus supporting images built outside that Dockerfile, such as a UBI dependency image pinned by digest in the Makefile.
NGINX Ingress Controller Image Builder fits situations like: adding a new NGINX Ingress Controller image variant; debugging a failed image build; understanding which base image and NGINX edition a Dockerfile stage targets.
Run `npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a claude-code`. Or copy the skill folder (.github/skills/nic-docker-images in nginx/kubernetes-ingress) into .claude/skills/nic-docker-images in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a codex`. Or copy the skill folder (.github/skills/nic-docker-images in nginx/kubernetes-ingress) into .agents/skills/nic-docker-images in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nginx/kubernetes-ingress --skill nic-docker-images -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nic-docker-images, .gemini/skills/nic-docker-images, .github/skills/nic-docker-images and .opencode/skills/nic-docker-images in your project.
Going by SKILL.md and its folder, NGINX Ingress Controller Image Builder needs the command-line tools its instructions call (make and docker).
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
NGINX Ingress Controller Image Builder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with NGINX Ingress Controller Image Builder: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Build Openshell Mxc Windows (NVIDIA/OpenShell, 16k stars) and Devops (nicepkg/auto-company, 195 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nginx (a GitHub organization) maintains it in nginx/kubernetes-ingress, which has 5,081 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.
Source: nginx/kubernetes-ingress on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.