Helm Chart Scaffolding
Cybereason-Public/owLSM
Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
$ npx skills add simstudioai/sim --skill sim-helm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install simstudioai/sim sim-helm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .claude/skills/sim-helm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sim-helm" agent skill from https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helm into .claude/skills/sim-helm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sim-helm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helmType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add simstudioai/sim --skill sim-helm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install simstudioai/sim sim-helm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .agents/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .agents/skills/sim-helm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sim-helm" agent skill from https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helm into .agents/skills/sim-helm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sim-helm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simstudioai/sim --skill sim-helm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install simstudioai/sim sim-helm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .cursor/skills/sim-helm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sim-helm" agent skill from https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helm into .cursor/skills/sim-helm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sim-helm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/simstudioai/sim.git --path helm/sim/.claude/skills/sim-helm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add simstudioai/sim --skill sim-helm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install simstudioai/sim sim-helm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .gemini/skills/sim-helm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sim-helm" agent skill from https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helm into .gemini/skills/sim-helm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sim-helm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install simstudioai/sim sim-helmInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add simstudioai/sim --skill sim-helm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .github/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .github/skills/sim-helm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sim-helm" agent skill from https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helm into .github/skills/sim-helm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sim-helm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simstudioai/sim --skill sim-helm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install simstudioai/sim sim-helm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/helm/sim/.claude/skills/sim-helm .opencode/skills/sim-helm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sim-helm" agent skill from https://github.com/simstudioai/sim/tree/main/helm/sim/.claude/skills/sim-helm into .opencode/skills/sim-helm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sim-helm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sim-helmInstall, upgrade, and operate the Sim Helm chart on Kubernetes.
Sim Helm is an agent skill from simstudioai/sim. Install, upgrade, and operate the Sim Helm chart on Kubernetes. Covers install path selection (inline / existingSecret / External Secrets Operator), required secret generation, the values.yaml mental model (env vs envDefaults vs Secret), and common failure triage. Invoke when a user asks about deploying Sim to a cluster, authoring a Sim values.yaml, debugging a Sim pod that won't start, upgrading a Sim release, or wiring Sim into a secret manager.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/install-paths.md`, `references/secrets.md` and `references/troubleshooting.md`).
It sits in DevOps & Cloud, covering Container orchestration. It works with Helm and Kubernetes. The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 546d4e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
helmkubectlopensslFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.sim.aiFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BETTER_AUTH_SECRETENCRYPTION_KEYINTERNAL_API_SECRETCRON_SECRETAPI_ENCRYPTION_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sim Helm loads about 2.2k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 957 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from simstudioai/sim at commit 546d4e7, republished under its Apache-2.0 licence (© simstudioai). 957 words, ~2,181 tokens.
.claude/skills/sim-helm/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.This skill helps an agent deploy and operate the Sim Helm chart at helm/sim/ in the simstudioai/sim repository. Use it when the user is installing, upgrading, troubleshooting, or authoring values for the Sim chart.
The skill is diagnostic-first: capture context, classify the situation, load only the references that apply, then act. Do not dump the README at the user. Do not invent values that are not in their current state.
Before recommending anything, ask (or infer from the conversation) all of these. Never skip this step. A wrong assumption here corrupts every downstream step.
| Question | Why it matters |
|---|---|
| Cluster: EKS / GKE / AKS / OpenShift / kind / other? | Storage class, ingress class, identity provider differ |
Secret strategy: inline --set, pre-existing K8s Secret, or External Secrets Operator (ESO)? | The chart has three distinct code paths |
| Postgres: chart-bundled, or external (RDS / Cloud SQL / Azure DB)? | Different value blocks (postgresql.* vs externalDatabase.*) |
| Public-facing? Ingress class? TLS? | ingress.enabled, ingress.className, cert-manager wiring |
| HA? (target replicas) | Drives autoscaling.enabled, app.replicaCount, PDB activation |
| Existing values.yaml the user is editing? | Always read it before proposing a diff — never write blind |
If the user has a values.yaml, read it. If they don't, ask before writing one.
Map the user's request to one of these categories and load the matching reference(s):
| Situation | Reference |
|---|---|
| User wants to install for the first time | references/install-paths.md then references/secrets.md |
| User needs to generate the required secrets | references/secrets.md |
| User asks "what does this value do" / wants to author values.yaml | references/values-model.md |
Pod won't start, error message, CrashLoopBackOff, image pull error, ingress not routing | references/troubleshooting.md |
| User asks about ESO / Vault / AWS Secrets Manager / Azure Key Vault / GCP Secret Manager | references/install-paths.md (ESO section) |
| User asks "is X production-ready" / autoscaling / network policy / security context | Read the README's "Production checklist" section directly — no separate reference |
Load only what the situation requires. Loading every reference burns tokens and produces vague answers.
When proposing values changes:
helm get values output — fine for dev, not for prod").helm rollback sim 1 reverts").helm/sim/values.yaml line numbers, README section, or this skill's reference file).Always run these before telling the user to helm install / helm upgrade:
# Schema + value validation
helm lint helm/sim --values <user-values>.yaml
# Render full manifest set to catch template errors
helm template sim helm/sim --values <user-values>.yaml > /tmp/render.yaml
# For upgrades, render against the live release first
helm upgrade --dry-run sim helm/sim --values <user-values>.yamlIf lint or template fails, fix the values — do not work around chart validation. The chart's fail statements exist to catch misconfigurations that would otherwise surface as CrashLoopBackOff at runtime.
Every recommendation should include:
kubectl rollout status deploy/sim-app returns Ready")| Mode | When | Code path |
|---|---|---|
Inline (--set) | Dev / kind / dry-run only. Values leak into helm get values. | app.env.<KEY>: "..." |
| Pre-existing Secret | GitOps with Sealed Secrets / SOPS, or hand-managed Secrets. Chart references a Secret you create. | app.secrets.existingSecret.enabled: true + .name |
| External Secrets Operator (recommended for prod) | Vault, AWS SM, Azure KV, GCP SM. Chart renders an ExternalSecret that ESO syncs. | externalSecrets.enabled: true + secretStoreRef + remoteRefs.app.<KEY> |
These modes are mutually exclusive for the app Secret. ESO takes precedence over inline. existingSecret takes precedence over inline. The chart fails template rendering when ESO is enabled and a required key (BETTER_AUTH_SECRET, ENCRYPTION_KEY, INTERNAL_API_SECRET, plus CRON_SECRET when cronjobs are enabled) is neither in app.env nor mapped in remoteRefs.app — see references/install-paths.md.
| Key | Generate with | Notes |
|---|---|---|
BETTER_AUTH_SECRET | openssl rand -hex 32 | Session signing |
ENCRYPTION_KEY | openssl rand -hex 32 | App-level encryption |
INTERNAL_API_SECRET | openssl rand -hex 32 | Service-to-service auth (app ↔ realtime) |
CRON_SECRET | openssl rand -hex 32 | Required iff cronjobs.enabled=true (default true) |
Optional but commonly needed:
| Key | Generate with | Notes |
|---|---|---|
API_ENCRYPTION_KEY | openssl rand -hex 32 | Must be exactly 64 hex chars. Required to encrypt user API keys at rest. |
postgresql.auth.password | openssl rand -base64 24 | tr -d '/+=' | Only if using chart-bundled Postgres. Must match ^[a-zA-Z0-9._-]+$ for DATABASE_URL compatibility. |
See references/secrets.md for storage patterns and rotation guidance.
These are non-negotiable. Violating any of these has burned users in the past.
--set for production secrets. They land in helm get values and Helm release history. Direct users to existingSecret or ESO.image.tag: latest. The chart defaults to Chart.AppVersion for a reason — reproducible rollouts. If the user pinned latest, push back.fail statement. The validation exists because a misconfiguration would otherwise surface as a runtime CrashLoopBackOff with cryptic env errors.automountServiceAccountToken: false unless the workload genuinely needs in-cluster API access (Sim's app/realtime/postgres pods do not).kubectl delete sts without --cascade=orphan on a live Postgres. It deletes the pods (PVCs survive, but the database goes down immediately).helm lint + helm template against their values. Static reading is not validation.helm uninstall in a shared namespace. PVCs survive but other namespace resources may not.Get logs from every component in parallel. This single block answers ~80% of "it's broken" questions:
kubectl --namespace <ns> get pods,events --sort-by='.lastTimestamp'
kubectl --namespace <ns> logs deploy/sim-app --tail=200
kubectl --namespace <ns> logs deploy/sim-realtime --tail=200
kubectl --namespace <ns> logs sts/sim-postgresql --tail=200
kubectl --namespace <ns> logs deploy/sim-app -c migrations --tail=200 2>/dev/null
kubectl --namespace <ns> describe pod -l app.kubernetes.io/name=simThen map the symptom to references/troubleshooting.md.
helm/sim/templates/_helpers.tpl and the chart's own contributor docsREADME.mdIf the user's question falls outside this scope, say so and point them at the right doc.
© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in helm/sim/.claude/skills/sim-helm of simstudioai/sim.
Open the folder on GitHubat commit 546d4e7
Sim Helm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sim Helm this skillsimstudioai/sim | 30k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Helm Chart ScaffoldingCybereason-Public/owLSM | 280 | 12 repos | ~381 | Automated safety check: Pass | GPL-2.0 | |
| NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress | 5.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes SpecialistJeffallan/claude-skills | 12k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| KubeShark for KubernetesLukasNiessen/kubernetes-skill | 444 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Nim Operator InstallNVIDIA/k8s-nim-operator | 159 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 |
Cybereason-Public/owLSM
Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
Jeffallan/claude-skills
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
LukasNiessen/kubernetes-skill
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
NVIDIA/k8s-nim-operator
Install NVIDIA NIM Operator on Kubernetes with prerequisite checks, optional NVIDIA GPU Operator dependency installation, public or local Helm chart selection, optional Dynamo support, and optional…
astronomer/astronomer
A skill your agent uses when writing, editing, reviewing, or running Helm chart tests for the Astronomer APC repository.
simstudioai/sim
Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.
simstudioai/sim
Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.
simstudioai/sim
Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
simstudioai/sim
Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…
simstudioai/sim
Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.
simstudioai/sim
Drive a PR to a clean review (Greptile 5/5, zero open threads) — ships if needed, keeps it mergeable against staging, re-triggers both Greptile and cubic, fixes real findings, replies to and…
Works with
Categories
Install, upgrade, and operate the Sim Helm chart on Kubernetes. Sim Helm is an agent skill from simstudioai/sim. Install, upgrade, and operate the Sim Helm chart on Kubernetes.
Sim Helm fits situations like: tasks that involve Container orchestration.
Run `npx skills add simstudioai/sim --skill sim-helm -a claude-code`. Or copy the skill folder (helm/sim/.claude/skills/sim-helm in simstudioai/sim) into .claude/skills/sim-helm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add simstudioai/sim --skill sim-helm -a codex`. Or copy the skill folder (helm/sim/.claude/skills/sim-helm in simstudioai/sim) into .agents/skills/sim-helm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill sim-helm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sim-helm, .gemini/skills/sim-helm, .github/skills/sim-helm and .opencode/skills/sim-helm in your project.
Going by SKILL.md and its folder, Sim Helm needs the command-line tools its instructions call (helm, kubectl and openssl) and credentials named BETTER_AUTH_SECRET, ENCRYPTION_KEY, INTERNAL_API_SECRET and CRON_SECRET. Our summary lists: Docker; A credential in BETTER_AUTH_SECRET; A credential in ENCRYPTION_KEY.
SKILL.md names 1 domain. As links in the text: docs.sim.ai. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sim Helm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sim Helm: Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars), NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars), Kubernetes Specialist (Jeffallan/claude-skills, 12k stars) and KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,785 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 7, 2026.
Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.