Agent skill

Sim Helm

by simstudioai in simstudioai/sim

Install, upgrade, and operate the Sim Helm chart on Kubernetes.

Apache-2.0Auto-check passedDevOps & Cloud

Install Sim Helm

skills CLI
$ npx skills add simstudioai/sim --skill sim-helm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install simstudioai/sim sim-helm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .claude/skills/sim-helm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sim-helm
GitHub stars
30k
Token cost
~2.2k tokens
SKILL.md length
957 words
Files
5 (incl. references)
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Install, upgrade, and operate the Sim Helm chart on Kubernetes.

  • Works in 5 steps: Capture context → Diagnose → Propose → …
  • Tasks that involve Container orchestration
  • SKILL.md covers Workflow — follow in order, Quick reference — the three…, Quick reference — the four… and Rules of engagement, plus 2 more sections
  • Calls helm, kubectl and openssl; needs BETTER_AUTH_SECRET and ENCRYPTION_KEY

What it does

Sim Helm is an agent skill from simstudioai/sim. Install, upgrade, and operate the Sim Helm chart on Kubernetes. Covers install path selection (inline / existingSecret / External Secrets Operator), required secret generation, the values.yaml mental model (env vs envDefaults vs Secret), and common failure triage. Invoke when a user asks about deploying Sim to a cluster, authoring a Sim values.yaml, debugging a Sim pod that won't start, upgrading a Sim release, or wiring Sim into a secret manager.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/install-paths.md`, `references/secrets.md` and `references/troubleshooting.md`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Helm and Kubernetes. The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Container orchestration

Example prompts

  • “/sim-helm”

Requirements

  • Docker
  • A credential in BETTER_AUTH_SECRET
  • A credential in ENCRYPTION_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Capture context
  2. Diagnose
  3. Propose
  4. Validate before applying
  5. Deliver

What it can do on your machine

Read from SKILL.md and the folder at commit 546d4e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • helm
    • kubectl
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.sim.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET
    • ENCRYPTION_KEY
    • INTERNAL_API_SECRET
    • CRON_SECRET
    • API_ENCRYPTION_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sim Helm loads about 2.2k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 957 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from simstudioai/sim at commit 546d4e7, republished under its Apache-2.0 licence (© simstudioai). 957 words, ~2,181 tokens.

Download SKILL.mdSave it as .claude/skills/sim-helm/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
sim-helm
description
Install, upgrade, and operate the Sim Helm chart on Kubernetes. Covers install path selection (inline / existingSecret / External Secrets Operator), required secret generation, the values.yaml mental model (env vs envDefaults vs Secret), and common failure triage. Invoke when a user asks about deploying Sim to a cluster, authoring a Sim values.yaml, debugging a Sim pod that won't start, upgrading a Sim release, or wiring Sim into a secret manager.
license
Apache-2.0

Sim Helm Chart — Operations Skill

This skill helps an agent deploy and operate the Sim Helm chart at helm/sim/ in the simstudioai/sim repository. Use it when the user is installing, upgrading, troubleshooting, or authoring values for the Sim chart.

The skill is diagnostic-first: capture context, classify the situation, load only the references that apply, then act. Do not dump the README at the user. Do not invent values that are not in their current state.


Workflow — follow in order

1. Capture context

Before recommending anything, ask (or infer from the conversation) all of these. Never skip this step. A wrong assumption here corrupts every downstream step.

QuestionWhy it matters
Cluster: EKS / GKE / AKS / OpenShift / kind / other?Storage class, ingress class, identity provider differ
Secret strategy: inline --set, pre-existing K8s Secret, or External Secrets Operator (ESO)?The chart has three distinct code paths
Postgres: chart-bundled, or external (RDS / Cloud SQL / Azure DB)?Different value blocks (postgresql.* vs externalDatabase.*)
Public-facing? Ingress class? TLS?ingress.enabled, ingress.className, cert-manager wiring
HA? (target replicas)Drives autoscaling.enabled, app.replicaCount, PDB activation
Existing values.yaml the user is editing?Always read it before proposing a diff — never write blind

If the user has a values.yaml, read it. If they don't, ask before writing one.

2. Diagnose

Map the user's request to one of these categories and load the matching reference(s):

SituationReference
User wants to install for the first timereferences/install-paths.md then references/secrets.md
User needs to generate the required secretsreferences/secrets.md
User asks "what does this value do" / wants to author values.yamlreferences/values-model.md
Pod won't start, error message, CrashLoopBackOff, image pull error, ingress not routingreferences/troubleshooting.md
User asks about ESO / Vault / AWS Secrets Manager / Azure Key Vault / GCP Secret Managerreferences/install-paths.md (ESO section)
User asks "is X production-ready" / autoscaling / network policy / security contextRead the README's "Production checklist" section directly — no separate reference

Load only what the situation requires. Loading every reference burns tokens and produces vague answers.

3. Propose

When proposing values changes:

  • Show the minimal diff against the user's current values.yaml. Don't rewrite the file.
  • Name the risk (e.g., "this puts the secret in helm get values output — fine for dev, not for prod").
  • Name the rollback (e.g., "if this breaks, helm rollback sim 1 reverts").
  • Cite the canonical source (helm/sim/values.yaml line numbers, README section, or this skill's reference file).
4. Validate before applying

Always run these before telling the user to helm install / helm upgrade:

bash
# Schema + value validation
helm lint helm/sim --values <user-values>.yaml

# Render full manifest set to catch template errors
helm template sim helm/sim --values <user-values>.yaml > /tmp/render.yaml

# For upgrades, render against the live release first
helm upgrade --dry-run sim helm/sim --values <user-values>.yaml

If lint or template fails, fix the values — do not work around chart validation. The chart's fail statements exist to catch misconfigurations that would otherwise surface as CrashLoopBackOff at runtime.

5. Deliver

Every recommendation should include:

  • The exact command(s) to run
  • A one-line summary of what will change
  • The success signal (e.g., "kubectl rollout status deploy/sim-app returns Ready")
  • The rollback command if something breaks

Quick reference — the three secret modes

ModeWhenCode path
Inline (--set)Dev / kind / dry-run only. Values leak into helm get values.app.env.<KEY>: "..."
Pre-existing SecretGitOps with Sealed Secrets / SOPS, or hand-managed Secrets. Chart references a Secret you create.app.secrets.existingSecret.enabled: true + .name
External Secrets Operator (recommended for prod)Vault, AWS SM, Azure KV, GCP SM. Chart renders an ExternalSecret that ESO syncs.externalSecrets.enabled: true + secretStoreRef + remoteRefs.app.<KEY>

These modes are mutually exclusive for the app Secret. ESO takes precedence over inline. existingSecret takes precedence over inline. The chart fails template rendering when ESO is enabled and a required key (BETTER_AUTH_SECRET, ENCRYPTION_KEY, INTERNAL_API_SECRET, plus CRON_SECRET when cronjobs are enabled) is neither in app.env nor mapped in remoteRefs.app — see references/install-paths.md.


Show full SKILL.md (377 more words)Show less

Quick reference — the four required secrets

KeyGenerate withNotes
BETTER_AUTH_SECRETopenssl rand -hex 32Session signing
ENCRYPTION_KEYopenssl rand -hex 32App-level encryption
INTERNAL_API_SECRETopenssl rand -hex 32Service-to-service auth (app ↔ realtime)
CRON_SECRETopenssl rand -hex 32Required iff cronjobs.enabled=true (default true)

Optional but commonly needed:

KeyGenerate withNotes
API_ENCRYPTION_KEYopenssl rand -hex 32Must be exactly 64 hex chars. Required to encrypt user API keys at rest.
postgresql.auth.passwordopenssl rand -base64 24 | tr -d '/+='Only if using chart-bundled Postgres. Must match ^[a-zA-Z0-9._-]+$ for DATABASE_URL compatibility.

See references/secrets.md for storage patterns and rotation guidance.


Rules of engagement

These are non-negotiable. Violating any of these has burned users in the past.

  1. Never recommend --set for production secrets. They land in helm get values and Helm release history. Direct users to existingSecret or ESO.
  2. Never set image.tag: latest. The chart defaults to Chart.AppVersion for a reason — reproducible rollouts. If the user pinned latest, push back.
  3. Never edit chart templates to work around a fail statement. The validation exists because a misconfiguration would otherwise surface as a runtime CrashLoopBackOff with cryptic env errors.
  4. Never drop automountServiceAccountToken: false unless the workload genuinely needs in-cluster API access (Sim's app/realtime/postgres pods do not).
  5. Never kubectl delete sts without --cascade=orphan on a live Postgres. It deletes the pods (PVCs survive, but the database goes down immediately).
  6. Never tell a user "the chart works on your cluster" without helm lint + helm template against their values. Static reading is not validation.
  7. Always confirm before helm uninstall in a shared namespace. PVCs survive but other namespace resources may not.

When the user is stuck and you can't diagnose

Get logs from every component in parallel. This single block answers ~80% of "it's broken" questions:

bash
kubectl --namespace <ns> get pods,events --sort-by='.lastTimestamp'
kubectl --namespace <ns> logs deploy/sim-app --tail=200
kubectl --namespace <ns> logs deploy/sim-realtime --tail=200
kubectl --namespace <ns> logs sts/sim-postgresql --tail=200
kubectl --namespace <ns> logs deploy/sim-app -c migrations --tail=200 2>/dev/null
kubectl --namespace <ns> describe pod -l app.kubernetes.io/name=sim

Then map the symptom to references/troubleshooting.md.


What this skill does not cover

  • Sim application configuration beyond env vars (provider keys, knowledge base setup, etc.) — that's the Sim app docs at https://docs.sim.ai
  • Kubernetes cluster setup (creating an EKS cluster, installing ingress-nginx, etc.) — that's cloud-provider docs
  • Authoring new chart templates — that's helm/sim/templates/_helpers.tpl and the chart's own contributor docs
  • Running Sim outside Kubernetes (Docker Compose, bare-metal) — see the root README.md

If the user's question falls outside this scope, say so and point them at the right doc.

© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in helm/sim/.claude/skills/sim-helm of simstudioai/sim.

  • SKILL.md
  • references/install-paths.md
  • references/secrets.md
  • references/troubleshooting.md
  • references/values-model.md

Open the folder on GitHubat commit 546d4e7

Compare with similar skills

Sim Helm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sim Helm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sim Helm this skillsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28012 repos~381Automated safety check: PassGPL-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
KubeShark for KubernetesLukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT
Nim Operator InstallNVIDIA/k8s-nim-operator159—~4.7kAutomated safety check: PassApache-2.0

Similar skills

  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 12 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 24 days ago
    DevOps & CloudAuto-check passed
  • Nim Operator Install

    NVIDIA/k8s-nim-operator

    Official

    Install NVIDIA NIM Operator on Kubernetes with prerequisite checks, optional NVIDIA GPU Operator dependency installation, public or local Helm chart selection, optional Dynamo support, and optional…

    159 GitHub stars~4.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Chart Tests

    astronomer/astronomer

    A skill your agent uses when writing, editing, reviewing, or running Helm chart tests for the Astronomer APC repository.

    491 GitHub stars~3.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from simstudioai/sim

All 40 skills in this repo
  • Add Column Type

    simstudioai/sim

    Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.

    30k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Add Enrichment

    simstudioai/sim

    Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Add Managed CLI

    simstudioai/sim

    Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…

    30k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Add Selector

    simstudioai/sim

    Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.

    30k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Babysit

    simstudioai/sim

    Drive a PR to a clean review (Greptile 5/5, zero open threads) — ships if needed, keeps it mergeable against staging, re-triggers both Greptile and cubic, fixes real findings, replies to and…

    30k GitHub stars~2.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Sim Helm

What does Sim Helm do?

Install, upgrade, and operate the Sim Helm chart on Kubernetes. Sim Helm is an agent skill from simstudioai/sim. Install, upgrade, and operate the Sim Helm chart on Kubernetes.

When should I use Sim Helm?

Sim Helm fits situations like: tasks that involve Container orchestration.

How do I install Sim Helm in Claude Code?

Run `npx skills add simstudioai/sim --skill sim-helm -a claude-code`. Or copy the skill folder (helm/sim/.claude/skills/sim-helm in simstudioai/sim) into .claude/skills/sim-helm in your project. Claude Code loads it when a task matches its description.

How do I install Sim Helm in Codex?

Run `npx skills add simstudioai/sim --skill sim-helm -a codex`. Or copy the skill folder (helm/sim/.claude/skills/sim-helm in simstudioai/sim) into .agents/skills/sim-helm in your project. Codex loads it when a task matches its description.

Can I use Sim Helm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill sim-helm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sim-helm, .gemini/skills/sim-helm, .github/skills/sim-helm and .opencode/skills/sim-helm in your project.

What does Sim Helm need to run?

Going by SKILL.md and its folder, Sim Helm needs the command-line tools its instructions call (helm, kubectl and openssl) and credentials named BETTER_AUTH_SECRET, ENCRYPTION_KEY, INTERNAL_API_SECRET and CRON_SECRET. Our summary lists: Docker; A credential in BETTER_AUTH_SECRET; A credential in ENCRYPTION_KEY.

Does Sim Helm access the network?

SKILL.md names 1 domain. As links in the text: docs.sim.ai. This is read from the text; nothing was executed.

Is Sim Helm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sim Helm use?

Sim Helm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sim Helm use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.4k tokens, read only when the agent opens those files.

What are the alternatives to Sim Helm?

Skills that share tags, products or a category with Sim Helm: Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars), NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars), Kubernetes Specialist (Jeffallan/claude-skills, 12k stars) and KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sim Helm?

simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,785 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 7, 2026.

Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.