Go Concurrency
inference-gateway/inference-gateway
Idiomatic Go concurrency - sync primitives, channel semantics, the select statement, and the standard channel patterns (cancellation/done-channel, fan-out/fan-in, pipeline, or-done, context…
Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.
$ npx skills add nginx/kubernetes-ingress --skill nic-structure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nginx/kubernetes-ingress nic-structure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/nic-structure .claude/skills/nic-structure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nic-structure" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structure into .claude/skills/nic-structure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-structure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nginx/kubernetes-ingress --skill nic-structure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nginx/kubernetes-ingress nic-structure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/nic-structure .agents/skills/nic-structure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nic-structure" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structure into .agents/skills/nic-structure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-structure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nginx/kubernetes-ingress --skill nic-structure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nginx/kubernetes-ingress nic-structure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/nic-structure .cursor/skills/nic-structure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nic-structure" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structure into .cursor/skills/nic-structure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-structure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nginx/kubernetes-ingress.git --path .github/skills/nic-structure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nginx/kubernetes-ingress --skill nic-structure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nginx/kubernetes-ingress nic-structure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/nic-structure .gemini/skills/nic-structure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nic-structure" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structure into .gemini/skills/nic-structure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-structure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nginx/kubernetes-ingress nic-structureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nginx/kubernetes-ingress --skill nic-structure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/nic-structure .github/skills/nic-structure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nic-structure" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structure into .github/skills/nic-structure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-structure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nginx/kubernetes-ingress --skill nic-structure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nginx/kubernetes-ingress nic-structure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nginx/kubernetes-ingress.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/nic-structure .opencode/skills/nic-structure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nic-structure" agent skill from https://github.com/nginx/kubernetes-ingress/tree/main/.github/skills/nic-structure into .opencode/skills/nic-structure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nic-structure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nic-structureMaps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.
This skill is a guide to the nginx/kubernetes-ingress codebase for anyone exploring it, tracing data flow, debugging config generation or changing controller logic. It starts with the repository layout, from the main binary entry point to the CRD type definitions, then splits the code into five layers with strict ownership: data model, validation, controller, config generation and process management.
Each layer has stated boundaries. Config generation must not call the Kubernetes API or read the secret store directly, the controller must not render NGINX config text or templates, the data model must not import the controller or config packages, and validation must not trigger reloads or update status. The guide says to identify the right layer before placing a change, because crossing layers causes architectural drift.
A table of generated artifacts lists what must never be edited by hand: deepcopy and client code regenerated with make update-codegen, CRD manifests and docs regenerated with make update-crds, and a chart CRD folder that is only a symlink. It also notes which of these outputs CI diffs and which it does not.
Read from SKILL.md and the folder at commit 06f9917. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
NGINX Ingress Controller Structure loads about 3.8k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 841 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nginx/kubernetes-ingress at commit 06f9917, republished under its Apache-2.0 licence (© nginx). 841 words, ~3,821 tokens.
.claude/skills/nic-structure/SKILL.md (or your agent's skills folder).cmd/nginx-ingress/ Main binary entry point
pkg/apis/configuration/v1/
types.go CRD struct definitions (source of truth)
zz_generated.deepcopy.go Auto-generated DeepCopy (never edit)
pkg/apis/configuration/validation/
policy.go ValidatePolicy entry point
virtualserver.go VirtualServer/VSR validation
pkg/client/ Auto-generated typed clients, informers, listers
internal/k8s/
controller.go Informer setup, sync loop, task dispatch
policy.go syncPolicy handler
handlers.go Event handler factories
configuration.go In-memory resource state
secrets/ Secret store and validation
policies/policy_refs.go Policy reference conversion
internal/configs/
configurator.go Orchestrator: merge config, render, write, reload
virtualserver.go VirtualServer -> version2 config generation
ingress.go Ingress -> version1 config generation
transportserver.go TransportServer -> version2 stream config generation
policy.go generatePolicies() dispatcher + add*Config() methods
annotations.go Annotation constants + parseAnnotations()
config_params.go ConfigParams struct + defaults
configmaps.go ConfigMap -> ConfigParams merge
dos.go DoS protection config generation
common.go Shared config utilities
warnings.go Warning accumulation types
validation_results.go validationResults type (isError + warnings)
commonhelpers/ Shared template helper functions (v1 + v2)
oidc/ OIDC config files (openid_connect.js, oidc_common.conf)
njs/ NJS scripts (apikey_auth.js)
version1/ Ingress template structs + .tmpl files
__snapshots__/ Snapshot golden files
version2/ VirtualServer/TS template structs + .tmpl files
__snapshots__/ Snapshot golden files
internal/nginx/ NGINX process manager, reload, rollback, version detection
internal/metrics/ Prometheus metrics collectors and listeners
internal/telemetry/ Usage telemetry collection and export
internal/certmanager/ cert-manager integration controller
internal/externaldns/ ExternalDNS integration controller
charts/nginx-ingress/ Helm chart (values.yaml, schema, templates)
charts/tests/ Helm snapshot tests (terratest + go-snaps)
tests/suite/ Python integration tests (pytest)
tests/data/ Test YAML manifests by feature
config/crd/bases/ Generated CRD YAML (from controller-gen)
deploy/ Pre-built CRD YAML bundles (crds.yaml, crds-nap-*.yaml)
hack/ update-codegen.sh, verify-codegen.shEach layer has a strict ownership boundary. Identify the correct layer before placing any change.
| Layer | Package(s) | Owns |
|---|---|---|
| Data model | pkg/apis/configuration/v1/ | CRD struct definitions, generated DeepCopy |
| Validation | pkg/apis/configuration/validation/, internal/k8s/validation.go | CRD field validation (kubebuilder markers), Ingress annotation validation |
| Controller | internal/k8s/ | Event handling, in-memory state, secret resolution, sync handlers, status updates |
| Config generation | internal/configs/, version1/, version2/ | Extended resource → NGINX config struct → template render → file write |
| Process management | internal/nginx/ | NGINX process lifecycle, reload, rollback |
Layer crossing rules — violations cause architectural drift:
internal/configs/) must NOT call the k8s API or access SecretStore directly — it receives pre-resolved role-qualified SecretReference via extended resources. Controller-side WAF bundle resolution and the dedicated PLM KubeClientSecretSource are explicit exceptions to the normal extended-resource flow.internal/k8s/) must NOT generate NGINX config text or render templates.types.go) must NOT import internal/configs or internal/k8s.Every entry below is produced by a command. Regenerate and commit the output after changing the source.
| Artifact | Source | Command | Diffed by CI |
|---|---|---|---|
pkg/apis/**/zz_generated.deepcopy.go, pkg/client/** | pkg/apis/**/types.go | make update-codegen | yes (pkg/**) |
config/crd/bases/*.yaml | kubebuilder markers in pkg/apis/** | make update-crds | yes |
deploy/crds.yaml, deploy/crds-nap-*.yaml | config/crd/** via kustomize | make update-crds | no |
docs/crd/*.md | config/crd/bases via hack/generate-crd-docs.go | make update-crds (runs update-crd-docs) | no |
charts/nginx-ingress/crds | symlink to config/crd/bases/ | nothing — never edit | n/a |
internal/telemetry/*_generated.go, data.avdl | Data / NICResourceCounts in internal/telemetry/exporter.go | make telemetry-schema | yes |
internal/configs/version1/__snapshots__/** | version1/*.tmpl + fixtures in template_test.go | make test-update-snaps | via unit-tests |
internal/configs/version2/__snapshots__/** | version2/*.tmpl + fixtures in templates_test.go | make test-update-snaps | via unit-tests |
charts/tests/__snapshots__/** | chart templates + charts/tests/testdata/*.yaml | make test-update-snaps | via unit-tests |
Two traps:
verify-codegen diffs only config/crd/bases after make update-crds. Uncommitted deploy/crds*.yaml or docs/crd/ changes pass CI silently.nic-testing for the required sequence.kubectl apply -f resource.yaml
-> K8s API Server persists resource
-> Informer detects Add/Update/Delete event
[handlers.go: createXxxHandlers()]
-> Event handler enqueues task onto syncQueue
[controller.go: AddSyncQueue()]
-> Controller dispatches task
[controller.go: sync() -> syncVirtualServer() / syncIngress() / syncSecret() / syncPolicy() / ...]
-> Build / update in-memory state, returning []ResourceChange
[configuration.go: AddOrUpdateVirtualServer() / AddOrUpdateIngress()]
Validation (CRD fields): pkg/apis/configuration/validation/
Validation (Ingress annotations): internal/k8s/validation.go
-> Find affected resources (fans out when a secret or policy changes)
[configuration.go: FindResourcesForSecret() / FindResourcesForPolicy()]
-> Resolve secret references <-- controller layer resolves; configurator only consumes paths
[controller.go: createVirtualServerEx() / createIngressEx() and add*SecretRefs() -> secretStore.GetSecret(key, role)]
On a store miss, the resolver reads the namespace informer cache.
Valid file-backed roles are materialized under /etc/nginx/secrets on first successful resolution.
Later secret updates revalidate and rewrite roles that have already been resolved.
-> Build extended resources
[controller.go: createVirtualServerEx() -> VirtualServerEx]
[createIngressEx() -> IngressEx]
[createTransportServerEx() -> TransportServerEx]
-> Configurator generates NGINX config [internal/configs/configurator.go: AddOrUpdateVirtualServer()]
HTTP path: GenerateVirtualServerConfig() [virtualserver.go] -> version2.VirtualServerConfig
generateNginxCfg() [ingress.go] -> version1.IngressNginxConfig
Stream path: generateTransportServerConfig(...) [transportserver.go] -> *version2.TransportServerConfig
Policies: generatePolicies() -> add*Config() -> policiesCfg [policy.go]
OSS vs Plus: Configurator.isPlus flag; Plus-only policies = OIDC, WAF
Template level: nginx.virtualserver.tmpl vs nginx-plus.virtualserver.tmpl
-> Template executor renders NGINX config text
[version1.TemplateExecutor / version2.TemplateExecutorV2;
TransportServer uses ExecuteTransportServerTemplate(...)]
-> NginxManager writes files + reloads NGINX
[internal/nginx/: Manager.CreateConfig() + Manager.Reload()]
-> Update resource status + emit Kubernetes events [happens AFTER reload returns]
[controller.go: updateVirtualServerStatusAndEvents() / updateIngressStatusAndEvents()]
[k8s/status.go: statusUpdater.UpdateVirtualServerStatus()]
Startup optimisation: status updates deferred to pendingVSStatus slices during !isNginxReady;
flushed in background via flushPendingStatusesAsync() after first reload.The secret store (internal/k8s/secrets/) is role-driven. A reference site selects a SecretRole for each secret. Kubernetes Secret.type does not determine validation, materialization, or reload behavior.
Phase 1 — reference-gated caching (syncSecret() and SecretStore.AddOrUpdateSecret()):
syncSecret() finds direct references and Policy references through policySecretIndex. Referenced and special Secrets are cached; unreferenced Secrets are evicted. preSyncSecrets() temporarily primes the store during startup, and the informer-backed resolver loads newly referenced Secrets on demand.
Phase 2 — lazy role resolution (SecretStore.GetSecret()):
For an existing Secret, GetSecret() validates and caches the result by (namespace/name, role). Valid file-backed roles are materialized under /etc/nginx/secrets/ using role-specific filenames. Missing lookups return an error reference with the expected path but are not cached.
Secret roles (internal/k8s/secrets/validation.go):
Kubernetes Secret.type is not used for validation, so any type is accepted. The Opaque type is recommended, or kubernetes.io/tls for TLS secrets. Legacy nginx.org/* and nginx.com/* types remain accepted.
| Role | Required or Recognized Keys | Used for |
|---|---|---|
RoleTLS | tls.crt, tls.key | TLS server certs |
RoleCA | ca.crt; optional ca.crl | CA cert (mTLS / upstream trust) |
RoleJWK | jwk | JWT validation keys |
RoleHtpasswd | htpasswd | HTTP Basic auth |
RoleOIDC | client-secret | OIDC client secret |
RoleAPIKey | Client IDs and credentials | API key auth |
RoleLicense | license.jwt | NGINX Plus license |
RoleWAFBundle | token, or username and password; optional ca.crt | Bundle-fetch credentials |
Special secrets Default-server TLS, wildcard TLS, license, management client certificate, and management trusted CA are selected by configured references. One Secret can satisfy multiple roles; NIC validates and writes every applicable representation and performs the strongest required reload once.
Key invariant: Extended resources carry map[secrets.SecretRefKey]*secrets.SecretReference, keyed by namespaced Secret and role. Standard config generation may consume Path, CRLPath, Error, and role-specific data, but must not inspect Secret.type or call SecretStore.GetSecret().
| Pipeline | Resources | Package | Templates |
|---|---|---|---|
| Version 1 | Ingress | internal/configs/version1/ | nginx.ingress.tmpl, nginx-plus.ingress.tmpl |
| Version 2 | VirtualServer, VSR, TS | internal/configs/version2/ | nginx.virtualserver.tmpl, nginx-plus.virtualserver.tmpl |
IngressNginxConfig with multiple Server blocks per configVirtualServerConfig with single Server block per confignginx.tmpl, nginx-plus.tmpl) produce global nginx.confgeneratePolicies() in internal/configs/policy.goPolicies are mutually exclusive: each Policy CR has exactly ONE non-nil field in PolicySpec.
Types: AccessControl, RateLimit, JWTAuth, ExternalAuth, BasicAuth, IngressMTLS, EgressMTLS, OIDC, WAF, APIKey, Cache, CORS.
Application levels (VirtualServer):
spec.policies -- server-level (all routes unless overridden)route.policies -- route-level (overrides spec-level)subroute.policies -- VirtualServerRoute subroute-levelIngress: Policies referenced via IngressEx.Policies map. Annotations are Ingress-only, never on VS/VSR.
policiesCfg (internal/configs/policy.go): Aggregation struct holding resolved policies per context (Allow/Deny slices, RateLimit, JWTAuth, ExternalAuth, BasicAuth, IngressMTLS, EgressMTLS, OIDC, APIKey, WAF, Cache, CORSHeaders/CORSMap, Context, BundleValidator, ErrorReturn).
version2.VirtualServerConfig: Top-level struct with HTTP-level directives (Maps, LimitReqZones, CacheZones) and a single Server block.
version2.Location: Per-route struct with all policy fields (Allow, Deny, LimitReqs, JWTAuth, Cache, CORSEnabled, AddHeaders).
version1.IngressNginxConfig: Top-level Ingress struct with multiple Server blocks plus Maps, CORSHeaders, LimitReqZones.
ConfigParams (config_params.go): ~125 fields for tunable NGINX params. Flow: defaults -> ConfigMap -> Ingress annotations.
// +kubebuilder:resource:shortName=pol
// +kubebuilder:subresource:status
// +kubebuilder:storageversion
type Policy struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata"`
Spec PolicySpec `json:"spec"`
Status PolicyStatus `json:"status"`
}<CRD>Spec, <CRD>Status. Lists: <CRD>List.vs, vsr, ts, gc, pol. API group: k8s.nginx.org/v1.| Marker | Purpose |
|---|---|
+kubebuilder:validation:Required | Field must be present |
+kubebuilder:validation:Optional | Field is optional |
+kubebuilder:validation:Pattern= `regex` | Regex validation |
+kubebuilder:validation:Minimum=N | Numeric minimum |
+kubebuilder:default=value | Default value |
+kubebuilder:validation:XValidation:rule="CEL" | Cross-field CEL validation |
map[runtime.Object][]string in internal/configs/warnings.goisError bool + warnings []string. When isError = true, policy dispatcher returns ErrorReturn: {Code: 500}field.ErrorList from k8s.io/apimachinery/pkg/util/validation/field© nginx, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/nic-structure of nginx/kubernetes-ingress.
Open the folder on GitHubat commit 06f9917
NGINX Ingress Controller Structure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| NGINX Ingress Controller Structure this skillnginx/kubernetes-ingress | 5.1k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Go Concurrencyinference-gateway/inference-gateway | 214 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Go Spec Reviewerinference-gateway/inference-gateway | 214 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| sfdx-hardis Architecture Guidehardisgroupcom/sfdx-hardis | 401 | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Unblock Dependabot PRkubernetes-sigs/cloud-provider-azure | 294 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Code Graph Mermaid Diagramstrailofbits/skills | 7.4k | 1 repos | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 |
inference-gateway/inference-gateway
Idiomatic Go concurrency - sync primitives, channel semantics, the select statement, and the standard channel patterns (cancellation/done-channel, fan-out/fan-in, pipeline, or-done, context…
inference-gateway/inference-gateway
Review a Go design spec before implementation begins - dispatch a subagent that checks a design doc for completeness, consistency, and idiomatic Go (simplicity, small consumer-defined interfaces…
hardisgroupcom/sfdx-hardis
Explains how the sfdx-hardis Salesforce CLI plugin is built: its TypeScript and Oclif stack, command layout, agent-mode flag and provider classes for git, notifications and AI.
kubernetes-sigs/cloud-provider-azure
Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked…
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
higress-group/higress
Migrate from ingress-nginx to Higress in Kubernetes environments.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
nginx/kubernetes-ingress
Explains how the NGINX Ingress Controller's GitHub Actions workflows, reusable workflows, build matrices and release pipeline fit together across two repositories.
nginx/kubernetes-ingress
Explains the multi-stage Dockerfile, the 25 image variant combinations, and the Makefile targets for building NGINX Ingress Controller images.
nginx/kubernetes-ingress
Testing conventions for the NGINX Ingress Controller repo: Go table-driven tests, mandatory snapshot regeneration, Helm tests and Python pytest integration tests.
nginx/kubernetes-ingress
Troubleshooting patterns for the NGINX Ingress Controller: reload failures, custom resources that have no effect, controller panics and snapshot test failures.
Works with
Categories
Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated. This skill is a guide to the nginx/kubernetes-ingress codebase for anyone exploring it, tracing data flow, debugging config generation or changing controller logic. It starts with the repository layout, from the main binary entry point to the CRD type definitions, then splits the code into five layers with strict ownership: data model, validation, controller, config generation and process management.
NGINX Ingress Controller Structure fits situations like: finding where a change belongs in the ingress controller codebase; tracing how a resource becomes NGINX configuration; debugging config generation or controller sync logic; checking whether a file is generated before editing it.
Run `npx skills add nginx/kubernetes-ingress --skill nic-structure -a claude-code`. Or copy the skill folder (.github/skills/nic-structure in nginx/kubernetes-ingress) into .claude/skills/nic-structure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nginx/kubernetes-ingress --skill nic-structure -a codex`. Or copy the skill folder (.github/skills/nic-structure in nginx/kubernetes-ingress) into .agents/skills/nic-structure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nginx/kubernetes-ingress --skill nic-structure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nic-structure, .gemini/skills/nic-structure, .github/skills/nic-structure and .opencode/skills/nic-structure in your project.
Going by SKILL.md and its folder, NGINX Ingress Controller Structure needs the command-line tools its instructions call (make). Our summary lists: A checkout of the nginx/kubernetes-ingress repository.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
NGINX Ingress Controller Structure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with NGINX Ingress Controller Structure: Go Concurrency (inference-gateway/inference-gateway, 214 stars), Go Spec Reviewer (inference-gateway/inference-gateway, 214 stars), sfdx-hardis Architecture Guide (hardisgroupcom/sfdx-hardis, 401 stars) and Unblock Dependabot PR (kubernetes-sigs/cloud-provider-azure, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nginx (a GitHub organization) maintains it in nginx/kubernetes-ingress, which has 5,082 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 8, 2026.
Source: nginx/kubernetes-ingress on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.