Agent skill

NIC Task Planning

by nginx in nginx/kubernetes-ingress

Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list.

Apache-2.0Auto-check passedDevelopment

Install NIC Task Planning

skills CLI
$ npx skills add nginx/kubernetes-ingress --skill nic-planning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nginx/kubernetes-ingress nic-planning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/nic-planning .claude/skills/nic-planning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nic-planning
GitHub stars
5.1k
Token cost
~1.7k tokens
SKILL.md length
829 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list.

  • Works in 7 steps: Read the requirement — Understand what's… → Write acceptance criteria — Before… → Identify security impact — Does this… → …
  • Starting any non-trivial change in the NGINX Ingress Controller repo
  • SKILL.md covers Before Writing Code, Layer Impact Checklist, Definition of Done and Scope Assessment, plus 2 more sections
  • Calls make, git and go

What it does

The skill sets a seven-step routine for non-trivial work in the NGINX Kubernetes Ingress Controller repo. The agent reads the requirement and any linked issues or specs, writes testable acceptance criteria that include what must be rejected and what must not break, and assesses security impact: new untrusted input needs validation at the trust boundary, credential or secret paths need human review, config generated from user data must pass through containsDangerousChars(), and RBAC changes need security review.

It then maps which layers a change touches, from the data model in types.go through validation, controller, config generation, templates, process management and the Helm chart, and checks the invariants in AGENTS.md: never hand-edit zz_generated.deepcopy.go, update both OSS and Plus templates for shared directives, and give every new CRD field kubebuilder markers, validation, template changes and tests. The plan lists the test surface (unit, negative, snapshot, Helm and integration tests) and the files to change in order. A checklist adds make update-codegen and make update-crds when types.go changes.

When your agent uses it

  • Starting any non-trivial change in the NGINX Ingress Controller repo
  • Turning an issue or spec into a plan before implementing it
  • Working out which layers, templates and tests a new CRD field touches

Example prompts

  • “Plan a change that adds a new CRD field to the ingress controller and list the files in order.”
  • “Read this issue about a new NGINX directive and write acceptance criteria and the test surface.”
  • “What must not break if we change how config is generated from user-supplied strings? Draft the plan.”

Requirements

  • A checkout of the nginx/kubernetes-ingress repository with its AGENTS.md

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read the requirement — Understand what's being asked. Check linked issues, specs, or PRs for full context.
  2. Write acceptance criteria — Before implementing, state what "done" looks like in testable terms. What should work? What should be…
  3. Identify security impact — Does this change
  4. Identify affected layers — Determine which architectural layers are touched
  5. Check invariants — Review the Key Invariants section in AGENTS.md
  6. Identify test surface — What tests need adding or updating?
  7. Produce a plan — State your approach before coding. List files to change in order. Include what this change must NOT break.

What it can do on your machine

Read from SKILL.md and the folder at commit 03e1429. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • git
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • nginx.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

NIC Task Planning loads about 1.7k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 829 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nginx/kubernetes-ingress at commit 03e1429, republished under its Apache-2.0 licence (© nginx). 829 words, ~1,722 tokens.

Download SKILL.mdSave it as .claude/skills/nic-planning/SKILL.md (or your agent's skills folder).
name
nic-planning
description
Task planning and approach strategy for NIC. Use when starting any non-trivial task, reading issues or specs, planning before implementing, or when asked to create a plan for a change.

Planning and Task Approach

Before Writing Code

  1. Read the requirement — Understand what's being asked. Check linked issues, specs, or PRs for full context.
  2. Write acceptance criteria — Before implementing, state what "done" looks like in testable terms. What should work? What should be rejected? What must NOT break?
  3. Identify security impact — Does this change:
    • Accept new external/untrusted input? → Requires input validation at the trust boundary
    • Touch credential or secret paths? → Requires human review
    • Generate config from user data? → Must pass through containsDangerousChars()
    • Change RBAC or access control? → Requires security review
  4. Identify affected layers — Determine which architectural layers are touched:
    • Data Model (pkg/apis/configuration/v1/types.go)
    • Validation (pkg/apis/configuration/validation/)
    • Controller (internal/k8s/)
    • Config Generation (internal/configs/)
    • Templates (internal/configs/version1/ or version2/)
    • Process Management (internal/nginx/)
    • Helm Chart (charts/nginx-ingress/)
  5. Check invariants — Review the Key Invariants section in AGENTS.md:
    • Security: containsDangerousChars() on user strings reaching NGINX config
    • Codegen: Never edit zz_generated.deepcopy.go manually
    • Templates: Update BOTH OSS and Plus variants for shared directives; Plus-only directives go in the Plus template only
    • CRD fields: Every new field needs kubebuilder markers + validation + template + tests
  6. Identify test surface — What tests need adding or updating?
    • Unit tests for validation logic
    • Negative tests for input rejection (security)
    • Snapshot tests for template output
    • Helm tests if chart changes
    • Integration tests if behaviour changes
  7. Produce a plan — State your approach before coding. List files to change in order. Include what this change must NOT break.

Layer Impact Checklist

For any change, ask:

  • Does it accept new external input? → Add validation with containsDangerousChars() or appropriate sanitizer
  • Does it touch types.go? → Run make update-codegen then make update-crds
  • Does it add a template directive? → Update BOTH nginx.ingress.tmpl AND nginx-plus.ingress.tmpl (or v2 equivalents) if the directive is shared; Plus-only directives go in the Plus template alone
  • Does it add a CRD field? → Add kubebuilder markers, validation, template struct, rendering, tests
  • Does it touch Helm values? → Update values.yaml, values.schema.json, and helmunit tests
  • Does it affect config generation? → Add a snapshot fixture that exercises the change, then run make test-update-snaps
  • Does it change telemetry data types? → Run make telemetry-schema
  • Does user-controlled data reach NGINX config? → Verify sanitization path exists and is tested

Definition of Done

Do not report a task as complete until every applicable box is ticked. These are the steps most often skipped.

ConditionRequired actionVerification
Edited any .tmplSnapshot fixture added and regeneratedgit diff -- '**/__snapshots__/**' is non-empty and shows the new directive
Edited a template struct (version1/config.go, version2/http.go, version2/stream.go)Fixture populates the field, snapshots regeneratedSame as above
Edited pkg/apis/**/types.gomake update-codegen && make update-crdsgit status shows regenerated pkg/**, config/crd/bases, deploy/crds*.yaml, docs/crd/
Edited telemetry Data / NICResourceCountsmake telemetry-schemaNo diff on re-run
Added/changed importsgo mod tidygo.mod / go.sum clean
Edited chart templates or valuestestdata + helmunit casecharts/tests/__snapshots__/ diff is non-empty
Added a pytest markerRegistered in pyproject.tomlSuite runs under --strict-markers
Any of the abovemake test then make lintBoth pass

Snapshot rule: regenerating without adding a fixture produces an empty diff, which is a silent failure, not a success. If make test-update-snaps changes nothing after a template edit, you have not tested the feature.

Show full SKILL.md (315 more words)Show less

Scope Assessment

ScopeIndicatorsAction
TrivialTypo, docs, comment fixFix directly, no plan needed
SmallSingle layer, <50 lines, no API changeBrief plan → implement → test
Medium2-3 layers, new field or annotationDetailed plan → implement layer by layer → test each
LargeNew subsystem, new policy type, cross-cuttingWrite plan document → get approval → implement in stages

Common Planning Mistakes

  • Starting implementation before understanding the full scope of affected files
  • Forgetting to update BOTH OSS and Plus templates for a shared directive -- or the inverse, leaking a Plus-only directive into the OSS template
  • Changing types.go without running codegen
  • Adding a VirtualServer feature without checking if Ingress (v1) also needs it
  • Adding Helm values without updating the JSON schema
  • Not checking if the feature already exists as an annotation when adding a CRD field
  • Skipping snapshot regeneration after template changes -- or regenerating without adding a fixture, which silently produces no diff
  • Forgetting make telemetry-schema after touching telemetry data types
  • Assuming a directive exists or behaves a certain way without checking https://nginx.org/en/docs/ -- verify NGINX semantics before wiring a template
  • Not identifying where untrusted input enters — a new CRD field IS user input that reaches NGINX config
  • Skipping negative tests — only testing the happy path leaves injection vectors undiscovered

Ordering Rules for Multi-Layer Changes

When a change spans multiple layers, implement in this order:

  1. Data model — Define types/fields in types.go
  2. Codegen — make update-codegen && make update-crds
  3. Validation — Add validation rules in pkg/apis/configuration/validation/
  4. Config structs — Add fields to template structs in version1/ or version2/
  5. Config generation — Wire the new field into config builders in internal/configs/
  6. Templates — Add NGINX directives to .tmpl files (OSS + Plus)
  7. Controller — Wire into sync handlers if needed
  8. Helm — Update chart values, schema, templates
  9. Tests — Unit, negative, snapshot (fixture + regenerate), helm, integration
  10. Regenerate — make update-codegen, make update-crds, make telemetry-schema, make test-update-snaps, then make test and make lint

© nginx, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/nic-planning of nginx/kubernetes-ingress.

Open the folder on GitHubat commit 03e1429

Compare with similar skills

NIC Task Planning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

NIC Task Planning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
NIC Task Planning this skillnginx/kubernetes-ingress5.1k—~1.7kAutomated safety check: PassApache-2.0
KubeSphere Gateway Managementkubesphere/kubesphere17k—~2.9kAutomated safety check: PassCustom licence
Releasengrok/ngrok-operator272—~2.7kAutomated safety check: PassMIT
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0

Similar skills

  • KubeSphere Gateway Management

    kubesphere/kubesphere

    Installs, uninstalls, checks and troubleshoots the KubeSphere Gateway extension built on ingress-nginx, including gateways stuck in bad states and Helm or pod failures.

    17k GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Release

    ngrok/ngrok-operator

    Automates the ngrok-operator release process: gathers PR data, classifies changes by component (container, Helm chart, CRDs chart), generates changelogs, updates version files, and prepares the…

    272 GitHub stars~2.7k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from nginx/kubernetes-ingress

All 9 skills in this repo
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Explains the multi-stage Dockerfile, the 25 image variant combinations, and the Makefile targets for building NGINX Ingress Controller images.

    5.1k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • NGINX Ingress Controller Structure

    nginx/kubernetes-ingress

    Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.

    5.1k GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • NIC Testing Patterns

    nginx/kubernetes-ingress

    Testing conventions for the NGINX Ingress Controller repo: Go table-driven tests, mandatory snapshot regeneration, Helm tests and Python pytest integration tests.

    5.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • NGINX Ingress CI Pipelines

    nginx/kubernetes-ingress

    Explains how the NGINX Ingress Controller's GitHub Actions workflows, reusable workflows, build matrices and release pipeline fit together across two repositories.

    5.1k GitHub stars~5.1k tokensUpdated today
    Auto-check passed

Questions about NIC Task Planning

What does NIC Task Planning do?

Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list. The skill sets a seven-step routine for non-trivial work in the NGINX Kubernetes Ingress Controller repo. The agent reads the requirement and any linked issues or specs, writes testable acceptance criteria that include what must be rejected and what must not break, and assesses security impact: new untrusted input needs validation at the trust boundary, credential or secret paths need human review, config generated from user data must pass through containsDangerousChars(), and RBAC changes need security review.

When should I use NIC Task Planning?

NIC Task Planning fits situations like: starting any non-trivial change in the NGINX Ingress Controller repo; turning an issue or spec into a plan before implementing it; working out which layers, templates and tests a new CRD field touches.

How do I install NIC Task Planning in Claude Code?

Run `npx skills add nginx/kubernetes-ingress --skill nic-planning -a claude-code`. Or copy the skill folder (.github/skills/nic-planning in nginx/kubernetes-ingress) into .claude/skills/nic-planning in your project. Claude Code loads it when a task matches its description.

How do I install NIC Task Planning in Codex?

Run `npx skills add nginx/kubernetes-ingress --skill nic-planning -a codex`. Or copy the skill folder (.github/skills/nic-planning in nginx/kubernetes-ingress) into .agents/skills/nic-planning in your project. Codex loads it when a task matches its description.

Can I use NIC Task Planning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nginx/kubernetes-ingress --skill nic-planning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nic-planning, .gemini/skills/nic-planning, .github/skills/nic-planning and .opencode/skills/nic-planning in your project.

What does NIC Task Planning need to run?

Going by SKILL.md and its folder, NIC Task Planning needs the command-line tools its instructions call (make, git and go). Our summary lists: A checkout of the nginx/kubernetes-ingress repository with its AGENTS.md.

Does NIC Task Planning access the network?

SKILL.md names 1 domain. As links in the text: nginx.org. This is read from the text; nothing was executed.

Is NIC Task Planning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does NIC Task Planning use?

NIC Task Planning is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does NIC Task Planning use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to NIC Task Planning?

Skills that share tags, products or a category with NIC Task Planning: KubeSphere Gateway Management (kubesphere/kubesphere, 17k stars), Release (ngrok/ngrok-operator, 272 stars), Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars) and Sim Helm (simstudioai/sim, 30k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains NIC Task Planning?

nginx (a GitHub organization) maintains it in nginx/kubernetes-ingress, which has 5,081 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.

Source: nginx/kubernetes-ingress on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.