Agent skill

Kubernetes

by notque in notque/vexjoy-agent

Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.

MITAuto-check passedDevOps & Cloud

Install Kubernetes

skills CLI
$ npx skills add notque/vexjoy-agent --skill kubernetes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install notque/vexjoy-agent kubernetes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/infrastructure/kubernetes .claude/skills/kubernetes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes
GitHub stars
435
Token cost
~1.5k tokens
SKILL.md length
429 words
Files
4 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.

  • Works in 3 steps: TRIAGE → DIAGNOSE / RESPOND → VERIFY
  • Tasks that involve Container orchestration
  • SKILL.md covers Domain Selection, Phase 1: TRIAGE, Phase 2: DIAGNOSE / RESPOND and Phase 3: VERIFY, plus 1 more section
  • Calls kubectl

What it does

Kubernetes is an agent skill from notque/vexjoy-agent. Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/cobalt-concurrency-patterns.md`, `references/cobalt-kvm-exporter.md` and `references/cobalt-testing-patterns.md`).

It sits in DevOps & Cloud, covering Container orchestration, Authorization and RBAC and Debugging. It works with Kubernetes. The repository describes itself as: VexJoy AI Agent with Jev Intelligent Routing - /do routes plain-English requests to the right specialist agent and gates the work with reviews, tests, and a learning loop. The licence is MIT.

When your agent uses it

  • Tasks that involve Container orchestration
  • Tasks that involve Authorization and RBAC
  • Tasks that involve Debugging

Example prompts

  • “Use the kubernetes skill to kubernete operations: debugging, security, RBAC, and infrastructure tooling”
  • “/kubernetes”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. TRIAGE
  2. DIAGNOSE / RESPOND
  3. VERIFY

What it can do on your machine

Read from SKILL.md and the folder at commit 5218674. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kubernetes loads about 1.5k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 22 tokens; SKILL.md has 429 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from notque/vexjoy-agent at commit 5218674, republished under its MIT licence (© notque). 429 words, ~1,536 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
kubernetes
description
Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.
user-invocable
false
context
fork
agent
kubernetes-helm-engineer
routing.triggers
kubernetes debug, pod failure, pod crashloop, kubectl logs, OOMKilled, pod pending, kubernetes security, k8s RBAC, RBAC setup, pod security policy, network…
routing.category
kubernetes
routing.pairs_with
assessment, programming, prometheus-grafana-engineer

Kubernetes Skill

Three domains: debugging (pod triage, networking, resources), security (RBAC, pod hardening, network isolation, supply chain), and cobaltcore (KVM exporter, hypervisor metrics). Select by request signal, then follow the phases below.

Always specify -n <namespace> in every kubectl command. Use read-only commands to gather evidence before proposing changes.


Domain Selection

SignalDomain
CrashLoopBackOff, OOMKilled, ImagePullBackOff, PendingDebugging
Service unreachable, DNS failure, port-forwardDebugging (network)
CPU throttling, memory limit, disk pressureDebugging (resources)
RBAC, permissions, roles, ServiceAccountSecurity (access)
Pod hardening, container security, PodSecuritySecurity (pods)
NetworkPolicy, default-deny, namespace isolationSecurity (network)
Image signing, secrets, admission controlSecurity (supply chain)
KVM exporter, cobaltcore, hypervisor metricsCobaltcore

Phase 1: TRIAGE

Debugging Triage Flow

Follow this sequence for every pod or workload issue. Do not skip steps -- many failures are only visible in events and describe output, not in logs.

bash
kubectl get pods -n <namespace> -o wide
kubectl describe pod <pod-name> -n <namespace>
kubectl logs <pod-name> -n <namespace> -c <container-name>
kubectl logs <pod-name> -n <namespace> -c <container-name> --previous
kubectl get events -n <namespace> --sort-by='.lastTimestamp'
kubectl exec -it <pod-name> -n <namespace> -c <container-name> -- /bin/sh

Always check --previous logs for crashed containers before current logs -- restarting destroys them permanently.

Diagnosis routing:

SymptomAction
CrashLoopBackOff, ImagePullBackOff, Pending, FailedSchedulingCheck describe output for events, previous logs, image pull errors
Service unreachable, DNS failureCheck service endpoints, CoreDNS, NetworkPolicy below
CPU throttling, OOMKill, disk pressureCheck resource limits, requests vs actual, node capacity
"no endpoints available for service"Compare svc selector with pod labels

Network debugging:

bash
# Verify service has endpoints
kubectl get endpoints <service-name> -n <namespace>
# DNS lookup from inside cluster
kubectl run dns-debug --rm -it --restart=Never --image=busybox:1.36 -n <namespace> -- \
  nslookup <service-name>.<namespace>.svc.cluster.local
# Check CoreDNS
kubectl get pods -n kube-system -l k8s-app=kube-dns
kubectl logs -n kube-system -l k8s-app=kube-dns --tail=50
# Port-forward for local testing
kubectl port-forward svc/<service-name> -n <namespace> 8080:80
Security Domain Selection

For security requests, provide concrete YAML manifests from the patterns below. Reference-backed specifics, not generic advice.

RBAC patterns: Prefer namespace-scoped Roles over ClusterRoles. Write exact verbs and resources. Create dedicated ServiceAccounts per workload. Set automountServiceAccountToken: false on pods that need no API access.

yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  namespace: app-team
  name: deployment-reader
rules:
  - apiGroups: ["apps"]
    resources: ["deployments"]
    verbs: ["get", "list", "watch"]

Pod security: Enforce PodSecurity labels at namespace level. All containers: runAsNonRoot: true, readOnlyRootFilesystem: true, allowPrivilegeEscalation: false, capabilities: drop: ["ALL"]. Use distroless base images. Pin image digests.

yaml
labels:
  pod-security.kubernetes.io/enforce: restricted
  pod-security.kubernetes.io/warn: restricted

Network policies: Start with default-deny for ingress and egress. Add allow-list rules per service. Always allow DNS egress (UDP/TCP 53).

yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
spec:
  podSelector: {}
  policyTypes: [Ingress, Egress]
Show full SKILL.md (131 more words)Show less
Cobaltcore Domain

Components: KVM Exporter (cobaltcore-dev/kvm-exporter). Load references/cobalt-kvm-exporter.md for architecture, metric catalogs, configuration, and deployment. Pair with go-patterns for code, prometheus-grafana-engineer for metrics.


Phase 2: DIAGNOSE / RESPOND

Debugging: Follow the triage flow. Gather evidence with read-only commands before proposing changes.

Security: Provide copy-paste-ready YAML using the patterns in Phase 1.

Cobaltcore: Use component-specific references for architecture, metrics, concurrency patterns, and testing.


Phase 3: VERIFY

  • Debugging: Confirm the fix resolves the symptom with the same triage commands.
  • Security: Validate against the PodSecurity standards and RBAC least-privilege patterns above.
  • Cobaltcore: Verify against component test patterns in references/cobalt-testing-patterns.md.

Deep References

SignalReferenceContent
KVM exporter architecture, metrics, configreferences/cobalt-kvm-exporter.mdFull component reference (463 lines)
Cobaltcore concurrency, goroutine, semaphorereferences/cobalt-concurrency-patterns.mdGo concurrency patterns (268 lines)
Cobaltcore testing, mock, Kind clusterreferences/cobalt-testing-patterns.mdTesting strategies (271 lines)

© notque, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/infrastructure/kubernetes of notque/vexjoy-agent.

  • SKILL.md
  • references/cobalt-concurrency-patterns.md
  • references/cobalt-kvm-exporter.md
  • references/cobalt-testing-patterns.md

Open the folder on GitHubat commit 5218674

Compare with similar skills

Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubernetes this skillnotque/vexjoy-agent435—~1.5kAutomated safety check: PassMIT
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Azure Bastion Jitvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Analyzing Kubernetes Audit Logsmukul975/Anthropic-Cybersecurity-Skills34k—~654Automated safety check: PassApache-2.0
Defending Kubernetestrilwu/secskills156—~2.2kAutomated safety check: PassMIT
Operate Kubernetes Toolchaincyberful/cyberful134—~898Automated safety check: PassAGPL-3.0

Similar skills

  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Analyzing Kubernetes Audit Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules…

    34k GitHub stars~654 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Defending Kubernetes

    trilwu/secskills

    Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

    156 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

    134 GitHub stars~898 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Mirrord Operator

    aiskillstore/marketplace

    Help users install and configure the mirrord Operator for team/enterprise environments.

    430 GitHub stars~4.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from notque/vexjoy-agent

All 61 skills in this repo
  • Game Asset Generator

    notque/vexjoy-agent

    Deterministic palette/matrix pixel art (not AI). An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2.3k tokensUpdated 4 days ago
    Auto-check: notes
  • PR Workflow

    notque/vexjoy-agent

    Pull request lifecycle: commit, codex review, sync, review, fix, status, cleanup, and PR mining.

    435 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check: notes
  • Architecture Deepening

    notque/vexjoy-agent

    Improve architecture across modules by deepening interfaces.

    435 GitHub stars~3.3k tokensUpdated 4 days ago
    Auto-check: notes
  • Code Quality

    notque/vexjoy-agent

    Code quality: cleanup, linting, formatting, quality gates. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check: notes
  • Codebase Analyzer

    notque/vexjoy-agent

    Statistical rule discovery from Go codebase patterns. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check: notes
  • Comment Quality

    notque/vexjoy-agent

    Review and fix temporal references in code comments. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check: notes

Works with

Questions about Kubernetes

What does Kubernetes do?

Kubernetes operations: debugging, security, RBAC, and infrastructure tooling. Kubernetes is an agent skill from notque/vexjoy-agent. Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.

When should I use Kubernetes?

Kubernetes fits situations like: tasks that involve Container orchestration; tasks that involve Authorization and RBAC; tasks that involve Debugging.

How do I install Kubernetes in Claude Code?

Run `npx skills add notque/vexjoy-agent --skill kubernetes -a claude-code`. Or copy the skill folder (skills/infrastructure/kubernetes in notque/vexjoy-agent) into .claude/skills/kubernetes in your project. Claude Code loads it when a task matches its description.

How do I install Kubernetes in Codex?

Run `npx skills add notque/vexjoy-agent --skill kubernetes -a codex`. Or copy the skill folder (skills/infrastructure/kubernetes in notque/vexjoy-agent) into .agents/skills/kubernetes in your project. Codex loads it when a task matches its description.

Can I use Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add notque/vexjoy-agent --skill kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes, .gemini/skills/kubernetes, .github/skills/kubernetes and .opencode/skills/kubernetes in your project.

What does Kubernetes need to run?

Going by SKILL.md and its folder, Kubernetes needs the command-line tools its instructions call (kubectl).

Does Kubernetes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kubernetes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kubernetes use?

Kubernetes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubernetes use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.2k tokens, read only when the agent opens those files.

What are the alternatives to Kubernetes?

Skills that share tags, products or a category with Kubernetes: KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Azure Bastion Jit (vinayaklatthe/microsoft-security-skills, 175 stars), Analyzing Kubernetes Audit Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Defending Kubernetes (trilwu/secskills, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubernetes?

notque (a GitHub user) maintains it in notque/vexjoy-agent, which has 435 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 3, 2026.

Source: notque/vexjoy-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.