Must Gather Investigation
scylladb/scylla-operator
Investigate failed e2e tests from Ginkgo JSON reports and must-gather artifacts, systematically analyzing logs, events, and resource states to identify root causes.
Kaniop architecture, Rust controller conventions, commands, testing, and repository workflows.
$ npx skills add pando85/kaniop --skill kaniop-development -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pando85/kaniop kaniop-development --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pando85/kaniop.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/kaniop-development .claude/skills/kaniop-development && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kaniop-development" agent skill from https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-development into .claude/skills/kaniop-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kaniop-development", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-developmentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pando85/kaniop --skill kaniop-development -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pando85/kaniop kaniop-development --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pando85/kaniop.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.opencode/skills/kaniop-development .agents/skills/kaniop-development && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kaniop-development" agent skill from https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-development into .agents/skills/kaniop-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kaniop-development", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pando85/kaniop --skill kaniop-development -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pando85/kaniop kaniop-development --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pando85/kaniop.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.opencode/skills/kaniop-development .cursor/skills/kaniop-development && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kaniop-development" agent skill from https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-development into .cursor/skills/kaniop-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kaniop-development", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pando85/kaniop.git --path .opencode/skills/kaniop-development--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pando85/kaniop --skill kaniop-development -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pando85/kaniop kaniop-development --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pando85/kaniop.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.opencode/skills/kaniop-development .gemini/skills/kaniop-development && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kaniop-development" agent skill from https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-development into .gemini/skills/kaniop-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kaniop-development", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pando85/kaniop kaniop-developmentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pando85/kaniop --skill kaniop-development -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pando85/kaniop.git skills-src && mkdir -p .github/skills && cp -r skills-src/.opencode/skills/kaniop-development .github/skills/kaniop-development && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kaniop-development" agent skill from https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-development into .github/skills/kaniop-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kaniop-development", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pando85/kaniop --skill kaniop-development -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pando85/kaniop kaniop-development --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pando85/kaniop.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.opencode/skills/kaniop-development .opencode/skills/kaniop-development && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kaniop-development" agent skill from https://github.com/pando85/kaniop/tree/master/.opencode/skills/kaniop-development into .opencode/skills/kaniop-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kaniop-development", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kaniop-developmentKaniop architecture, Rust controller conventions, commands, testing, and repository workflows.
Kaniop Development is an agent skill from pando85/kaniop. Kaniop architecture, Rust controller conventions, commands, testing, and repository workflows. Use when changing Kaniop source code, tests, CRDs, configuration, or documentation.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Testing & QA, covering Container orchestration and End-to-end testing. It works with Rust and Kubernetes. The repository describes itself as: Kubernetes operator for managing Kanidm. The licence is AGPL-3.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 768ac0b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makekubectlcargohelmghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl, helm and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kaniop Development loads about 3.1k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,181 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from pando85/kaniop at commit 768ac0b, republished under its AGPL-3.0 licence (© pando85). 1,181 words, ~3,107 tokens.
.claude/skills/kaniop-development/SKILL.md (or your agent's skills folder).Detailed project guidance for agents working with code in this repository.
Kaniop is a Kubernetes operator for managing Kanidm identity services. It provides declarative management of Kanidm clusters and identity resources (persons, groups, OAuth2 clients, service accounts) through Kubernetes Custom Resources.
Tech Stack: Rust (edition 2024), Cargo workspace, Kubernetes controller-runtime (kube-rs), Kanidm client SDK, Helm charts, Kind for e2e testing.
# Lint and format check (must pass with zero warnings)
make lint
# Run unit tests (includes lint)
make test
# Build debug binaries (kaniop and kaniop-webhook)
make build
# Build optimized release binaries
make release
# Regenerate CRDs after any CRD spec changes (REQUIRED)
make crdgen
# Regenerate example YAML files (do not hand-edit examples/)
make examples
# Update version across workspace and Helm chart
make update-version# Integration tests (requires Tempo tracing container)
make integration-test
# Create Kind cluster, build images, install operator
make e2e
# Run e2e tests (requires Kind cluster from `make e2e`)
make e2e-test
# Rapid iteration: rebuild operator and reload into Kind cluster
make update-e2e-kaniop
# Clean e2e resources but keep cluster
make clean-e2e
# Delete Kind cluster completely
make delete-kind# After `make e2e` has created the cluster:
RUST_TEST_THREADS=16 cargo test -p kaniop-e2e-tests --features e2e-test <test_name># After `make e2e` has created the cluster:
make e2e-test-shard SHARD=kanidm-core
# Verify shard filters still cover every test (run after adding/removing tests):
make check-e2e-shardsValid shards: kanidm-core, kanidm-ha, kanidm-backup, kanidm-restore, kanidm-restore-hardening, oauth2, resources, misc. Shard filters are defined in the Makefile (E2E_SHARD_FILTER_* / E2E_SHARD_SKIP_*) and consumed by the CI e2e job matrix in .github/workflows/rust.yml.
# Build single-arch local images
make images
# Build and push multi-arch images (amd64, arm64)
make push-imagesBinaries (cmd/):
cmd/operator: Main operator binary with multiple controllerscmd/webhook: Validating admission webhookcmd/crdgen: CRD generator (outputs to charts/kaniop/crds/crds.yaml)cmd/examples: Example YAML generator (outputs to examples/)Libraries (libs/):
libs/operator: Core operator framework (controller runner, metrics, telemetry, Kanidm cluster CRD)libs/person: KanidmPersonAccount controller and reconcilerlibs/group: KanidmGroup controller and reconcilerlibs/oauth2: KanidmOAuth2 controller and reconcilerlibs/service-account: KanidmServiceAccount controller and reconcilerlibs/k8s-util: Kubernetes client utilities, error types, patch helpersTests (tests/):
tests/e2e/: End-to-end tests with feature flag e2e-testtests/integration/: Integration tests with feature flag integration-testImportant: Never use both feature flags together.
Each identity resource follows the same pattern:
crd.rs): Defines the Kubernetes Custom Resourcecontroller.rs): Sets up the kube-rs controller with watchers and reconcilerreconcile.rs): Implements the reconciliation logic using Kanidm client SDKAll controllers:
backoff_reconciler! macroContext trait pattern with IdmClientContext and BackoffContextKanidmClient cached per-clusterlibs/operator/src/controller.rs: Core controller infrastructure
State: Shared state across all controllers (metrics registry, Kanidm client cache)Context trait: Provides access to k8s client, metrics, Kanidm clientcreate_subscriber(): Sets up controller with retry backofflibs/operator/src/kanidm/: Kanidm cluster management
controller.rs: Reconciles Kanidm StatefulSet, Services, PVCscrd.rs: Kanidm cluster CRD definitionreconcile/: Stateful set, service, secret management logiclibs/k8s-util/src/error.rs: Centralized error handling
Error enum for all controller errorsResult<T> type alias used throughoutContext::get_idm_client())chart-testing (context: kind-chart-testing)kaniopRUST_TEST_THREADS=16 for parallel tests, override via E2E_TEST_THREADS)When iterating on code changes with e2e tests:
Initial setup (once per session):
make e2e # Creates Kind cluster, builds images, installs operatorRapid iteration cycle:
# After code changes, rebuild and reload operator into cluster
make update-e2e-kaniop
# Run a specific test
RUST_TEST_THREADS=16 cargo test -p kaniop-e2e-tests --features e2e-test <test_name>
# Or run all e2e tests
make e2e-testCleanup between test runs (if tests fail with "already exists" errors):
# Clean up leftover test resources but keep cluster running
make clean-e2e
# Then re-run tests
make e2e-testDelete specific leftover resources (for targeted cleanup):
kubectl delete kanidmgroup <name> -n default --ignore-not-found=true
kubectl delete kanidmpersonaccount <name> -n default --ignore-not-found=true
kubectl delete kanidmoauth2client <name> -n default --ignore-not-found=true
kubectl delete kanidmserviceaccount <name> -n default --ignore-not-found=true
kubectl delete kanidm <name> -n default --ignore-not-found=trueFull reset (when cluster is in bad state):
make delete-kind && make e2eCommon e2e test failure patterns:
"already exists" errors → Run make clean-e2e to remove leftover resources"admission webhook denied" with duplicate message → Previous test didn't clean up; delete the specific resourceclone, prefer references and iteratorsanyhow::Context for error wrapping, domain-specific error enumscharts/kaniop/values.yaml — add value with YAML doc commentscharts/kaniop/values.schema.json — add matching JSON schema entrycharts/kaniop/templates/charts/kaniop/tests/ — test both default and custom valueshelm unittest charts/kaniop to verifyWhen adding a new operator config via env var:
#[arg(long, default_value = "...", env)] in cmd/operator/src/main.rsOnceLock getter/setter in libs/operator/src/controller/mod.rsmain() after args parsingcrate::controller::function_namelibs/*/src/crd.rsmake crdgen to regenerate charts/kaniop/crds/crds.yamlmake update-versioncmd/examples should always include values for the CRD fields they demonstrate.null, or omitted.cmd/examples/src/*.rs). Comments in Rust code are NOT rendered in the generated YAML output.libs/*/src/crd.rs). CRD doc comments (///) are extracted by the schema generator and rendered in YAML.Some(...) with concrete values, not None, so they appear in generated YAML documentation.make examples after modifying example code or CRD definitions.[workspace.dependencies] in root Cargo.tomltests/e2e/cmd/examples/make examples to regenerate example YAML files after adding/modifying examplesHandle these scenarios gracefully:
make crdgen after CRD changes → version mismatch errorsexamples/ or charts/kaniop/crds/integration-test + e2e-test → compilation error)make lint before committing → CI failuremake lint must pass with zero clippy warningsmake test.pre-commit-config.yamlmake lint and make test locally before pushing.gh pr checks <pr> --watch.make e2e && make e2e-test-shard SHARD=<failing-shard>), fix, push, and repeat until CI is green.VERSION: Image tag version (default: git SHA)CARGO_TARGET: Cross-compilation target (default: x86_64-unknown-linux-gnu)CARGO_RELEASE_PROFILE: Cargo profile for release builds (default: release)E2E_LOGGING_LEVEL: Log filter for e2e tests (default: info,kaniop=debug,kaniop_webhook=debug)E2E_TEST_THREADS: Parallel e2e test threads for make e2e-test (default: 16)E2E_WAIT_TIMEOUT_SECONDS: Timeout for e2e wait conditions (default: 180)E2E_EVENT_TIMEOUT_SECONDS: Timeout for waiting on Kubernetes events (default: 10)E2E_EVENT_POLL_INTERVAL_MILLISECONDS: Poll interval for event checks (default: 1000)KANIDM_DEV_YOLO=1: Required for e2e tests to prevent Kanidm client silent exit with dev profiles© pando85, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .opencode/skills/kaniop-development of pando85/kaniop.
Open the folder on GitHubat commit 768ac0b
Kaniop Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kaniop Development this skillpando85/kaniop | 130 | — | ~3.1k | Automated safety check: Pass | AGPL-3.0 | |
| Must Gather Investigationscylladb/scylla-operator | 401 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Run E2E Testkubernetes-sigs/cloud-provider-azure | 294 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Debug E2E Pipelinekubernetes-sigs/cloud-provider-azure | 294 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Unblock Dependabot PRkubernetes-sigs/cloud-provider-azure | 294 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Kopiur Designhome-operations/kopiur | 113 | — | ~2.4k | Automated safety check: Pass | AGPL-3.0 |
scylladb/scylla-operator
Investigate failed e2e tests from Ginkgo JSON reports and must-gather artifacts, systematically analyzing logs, events, and resource states to identify root causes.
kubernetes-sigs/cloud-provider-azure
Parse a Go e2e test from tests/e2e/, translate each step to kubectl and az CLI commands, and interactively replay the test against a live cluster.
kubernetes-sigs/cloud-provider-azure
Fetch and analyze Prow e2e pipeline failures for cloud-provider-azure.
kubernetes-sigs/cloud-provider-azure
Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked…
home-operations/kopiur
Design norms and locked decisions for the Kopiur Kopia-native Kubernetes backup operator (Rust/kube-rs).
mpecan/tokf
Compress verbose CLI output with tokf before returning results.
pando85/kaniop
Guidelines for documenting reusable patterns discovered during work.
pando85/kaniop
Guidelines for modifying the Helm chart. An agent skill from pando85/kaniop.
pando85/kaniop
Prepare and publish a new release. An agent skill from pando85/kaniop.
pando85/kaniop
Improve and validate the Kaniop Grafana dashboard against repository metrics and the grigri live cluster.
Works with
Categories
Kaniop architecture, Rust controller conventions, commands, testing, and repository workflows. Kaniop Development is an agent skill from pando85/kaniop. Kaniop architecture, Rust controller conventions, commands, testing, and repository workflows.
Kaniop Development fits situations like: changing Kaniop source code; tasks that involve Container orchestration; tasks that involve End-to-end testing.
Run `npx skills add pando85/kaniop --skill kaniop-development -a claude-code`. Or copy the skill folder (.opencode/skills/kaniop-development in pando85/kaniop) into .claude/skills/kaniop-development in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pando85/kaniop --skill kaniop-development -a codex`. Or copy the skill folder (.opencode/skills/kaniop-development in pando85/kaniop) into .agents/skills/kaniop-development in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pando85/kaniop --skill kaniop-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kaniop-development, .gemini/skills/kaniop-development, .github/skills/kaniop-development and .opencode/skills/kaniop-development in your project.
Going by SKILL.md and its folder, Kaniop Development needs the command-line tools its instructions call (make, kubectl, cargo, helm and gh).
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kaniop Development is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kaniop Development: Must Gather Investigation (scylladb/scylla-operator, 401 stars), Run E2E Test (kubernetes-sigs/cloud-provider-azure, 294 stars), Debug E2E Pipeline (kubernetes-sigs/cloud-provider-azure, 294 stars) and Unblock Dependabot PR (kubernetes-sigs/cloud-provider-azure, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pando85 (a GitHub user) maintains it in pando85/kaniop, which has 130 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 7, 2026.
Source: pando85/kaniop on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.