Agent skill

Openshift Node Kernel

by openshift-eng in openshift-eng/ai-helpers

Inspect kernel-level networking configuration on OpenShift/Kubernetes nodes using oc debug

Apache-2.0Auto-check passedDevOps & Cloud

Install Openshift Node Kernel

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill openshift-node-kernel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers openshift-node-kernel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/openshift/skills/openshift-node-kernel .claude/skills/openshift-node-kernel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openshift-node-kernel
GitHub stars
120
Token cost
~876 tokens
SKILL.md length
290 words
Files
6
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

Inspect kernel-level networking configuration on OpenShift/Kubernetes nodes using oc debug

  • Works in 4 steps: Complete output capture: All… → Reliable filtering: Uses single grep -E… → Guaranteed output: The || cat fallback… → …
  • Tasks that involve Container orchestration
  • SKILL.md covers Overview, Commands Provided, Helper Functions and Output Handling
  • Runs Shell scripts from its folder

What it does

Openshift Node Kernel is an agent skill from openshift-eng/ai-helpers. Inspect kernel-level networking configuration on OpenShift/Kubernetes nodes using oc debug

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `kernel-helper.sh`, `node-kernel-conntrack.sh` and `node-kernel-ip.sh`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration

Example prompts

  • “/openshift-node-kernel”

Requirements

  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Complete output capture: All stdout/stderr is captured in a variable
  2. Reliable filtering: Uses single grep -E with multiple patterns for efficiency
  3. Guaranteed output: The || cat fallback ensures output passes through even if no warnings are found
  4. Explicit return: Output is explicitly sent to stdout using printf for reliable data flow

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openshift Node Kernel loads about 876 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 290 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~876

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 290 words, ~876 tokens.

Download SKILL.mdSave it as .claude/skills/openshift-node-kernel/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
openshift-node-kernel
description
Inspect kernel-level networking configuration on OpenShift/Kubernetes nodes using oc debug

OpenShift Node Kernel Inspection Skill

This skill provides utilities for inspecting kernel-level networking configuration on OpenShift/Kubernetes nodes using oc debug.

Overview

The skill enables interaction with kernel networking tools on Kubernetes nodes without requiring SSH access. It uses oc debug to create ephemeral containers with host network access and executes kernel commands in the host's namespace.

Commands Provided

node-kernel-ip

Executes ip commands to inspect routing tables, network devices, and interfaces.

Script: node-kernel-ip.sh

Usage:

bash
./node-kernel-ip.sh <node> <image> --command <cmd> [--options <opts>] [--filter <params>]

Example:

bash
./node-kernel-ip.sh worker-1 registry.redhat.io/rhel9/support-tools --command "route show"
node-kernel-iptables

Executes iptables or ip6tables commands to inspect packet filter rules.

Script: node-kernel-iptables.sh

Usage:

bash
./node-kernel-iptables.sh <node> <image> --command <cmd> [--table <table>] [--filter <params>]

Example:

bash
./node-kernel-iptables.sh worker-1 registry.redhat.io/rhel9/support-tools --command "-L POSTROUTING" --table nat --filter "-nv4"
node-kernel-nft

Executes nft commands to inspect nftables packet filtering and classification rules.

Script: node-kernel-nft.sh

Usage:

bash
./node-kernel-nft.sh <node> <image> --command <cmd> [--family <family>]

Example:

bash
./node-kernel-nft.sh worker-1 registry.redhat.io/rhel9/support-tools --command "list tables" --family inet
node-kernel-conntrack

Executes conntrack commands or reads /proc/net/nf_conntrack to inspect connection tracking entries.

Script: node-kernel-conntrack.sh

Usage:

bash
./node-kernel-conntrack.sh <node> <image> [--command <cmd>] [--filter <params>]

Example:

bash
./node-kernel-conntrack.sh worker-1 registry.redhat.io/rhel9/support-tools --command "-L" --filter "-s 1.2.3.4"

Helper Functions

The kernel-helper.sh script provides shared functions:

  • check_utility_exists: Verifies a utility exists in the debug image
  • execute_kernel_command: Executes commands on a node via oc debug
  • filter_warnings: Removes common oc debug warning messages from output
  • validate_node_exists: Validates node name exists in cluster
  • detect_and_set_kubeconfig: Auto-detects and configures kubeconfig

Output Handling

All commands ensure:

  • stdout contains only the actual command output (routing tables, interface info, etc.)
  • stderr contains warnings, debug messages, and errors
  • Common oc debug warnings are filtered out automatically using improved regex patterns
  • Output is explicitly captured and returned to ensure proper data flow to calling processes
Improvements

The execute_kernel_command() function explicitly captures all output from oc debug and filters warnings before returning results, ensuring:

  1. Complete output capture: All stdout/stderr is captured in a variable
  2. Reliable filtering: Uses single grep -E with multiple patterns for efficiency
  3. Guaranteed output: The || cat fallback ensures output passes through even if no warnings are found
  4. Explicit return: Output is explicitly sent to stdout using printf for reliable data flow

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in plugins/openshift/skills/openshift-node-kernel of openshift-eng/ai-helpers.

  • SKILL.md
  • kernel-helper.sh
  • node-kernel-conntrack.sh
  • node-kernel-ip.sh
  • node-kernel-iptables.sh
  • node-kernel-nft.sh

Open the folder on GitHubat commit a627176

Compare with similar skills

Openshift Node Kernel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openshift Node Kernel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openshift Node Kernel this skillopenshift-eng/ai-helpers120—~876Automated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28012 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 12 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Openshift Node Kernel

What does Openshift Node Kernel do?

Inspect kernel-level networking configuration on OpenShift/Kubernetes nodes using oc debug. Openshift Node Kernel is an agent skill from openshift-eng/ai-helpers.

When should I use Openshift Node Kernel?

Openshift Node Kernel fits situations like: tasks that involve Container orchestration.

How do I install Openshift Node Kernel in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill openshift-node-kernel -a claude-code`. Or copy the skill folder (plugins/openshift/skills/openshift-node-kernel in openshift-eng/ai-helpers) into .claude/skills/openshift-node-kernel in your project. Claude Code loads it when a task matches its description.

How do I install Openshift Node Kernel in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill openshift-node-kernel -a codex`. Or copy the skill folder (plugins/openshift/skills/openshift-node-kernel in openshift-eng/ai-helpers) into .agents/skills/openshift-node-kernel in your project. Codex loads it when a task matches its description.

Can I use Openshift Node Kernel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill openshift-node-kernel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openshift-node-kernel, .gemini/skills/openshift-node-kernel, .github/skills/openshift-node-kernel and .opencode/skills/openshift-node-kernel in your project.

What does Openshift Node Kernel need to run?

Going by SKILL.md and its folder, Openshift Node Kernel needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Openshift Node Kernel access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Openshift Node Kernel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openshift Node Kernel use?

Openshift Node Kernel is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openshift Node Kernel use?

About 876 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openshift Node Kernel?

Skills that share tags, products or a category with Openshift Node Kernel: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openshift Node Kernel?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.