Agent skill

Kubernetes Patterns

by vibeeval in vibeeval/vibecosystem

Pod design patterns, sidecar containers, init containers, config management, rolling updates, and resource limits.

MITAuto-check passedDevOps & Cloud

Install Kubernetes Patterns

skills CLI
$ npx skills add vibeeval/vibecosystem --skill kubernetes-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem kubernetes-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kubernetes-patterns .claude/skills/kubernetes-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubernetes-patterns
GitHub stars
531
Token cost
~1.6k tokens
SKILL.md length
145 words
Files
1
Skills in repo
144
Repo updated
First seen
Licence
MIT

At a glance

Pod design patterns, sidecar containers, init containers, config management, rolling updates, and resource limits.

  • Tasks that involve Container orchestration
  • SKILL.md covers Pod Design Patterns, Init Containers, Resource Limits and Requests and ConfigMap and Secrets, plus 5 more sections
  • Needs JWT_SECRET
  • Tasks that involve Design patterns

What it does

Kubernetes Patterns is an agent skill from vibeeval/vibecosystem. Pod design patterns, sidecar containers, init containers, config management, rolling updates, and resource limits.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration and Design patterns. It works with Kubernetes. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Tasks that involve Container orchestration
  • Tasks that involve Design patterns

Example prompts

  • “/kubernetes-patterns”

Requirements

  • A credential in JWT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kubernetes Patterns loads about 1.6k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 145 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 145 words, ~1,560 tokens.

Download SKILL.mdSave it as .claude/skills/kubernetes-patterns/SKILL.md (or your agent's skills folder).
name
kubernetes-patterns
description
Pod design patterns, sidecar containers, init containers, config management, rolling updates, and resource limits.

Kubernetes Patterns

Production-grade Kubernetes deployment and pod design patterns.

Pod Design Patterns

yaml
# Sidecar Pattern: log collector alongside main app
apiVersion: v1
kind: Pod
metadata:
  name: app-with-sidecar
spec:
  containers:
    - name: app
      image: myapp:v1.2.0
      ports:
        - containerPort: 8080
      volumeMounts:
        - name: logs
          mountPath: /var/log/app

    - name: log-collector
      image: fluentd:v1.16
      volumeMounts:
        - name: logs
          mountPath: /var/log/app
          readOnly: true

  volumes:
    - name: logs
      emptyDir: {}

Init Containers

yaml
# Run setup tasks before main container starts
apiVersion: apps/v1
kind: Deployment
metadata:
  name: api-server
spec:
  replicas: 3
  template:
    spec:
      initContainers:
        # Wait for database to be ready
        - name: wait-for-db
          image: busybox:1.36
          command: ['sh', '-c', 'until nc -z postgres-svc 5432; do sleep 2; done']

        # Run database migrations
        - name: run-migrations
          image: myapp:v1.2.0
          command: ['npx', 'prisma', 'migrate', 'deploy']
          envFrom:
            - secretRef:
                name: db-credentials

      containers:
        - name: api
          image: myapp:v1.2.0
          ports:
            - containerPort: 3000

Resource Limits and Requests

yaml
containers:
  - name: api
    image: myapp:v1.2.0
    resources:
      requests:          # Scheduler uses this to place pods
        cpu: 250m        # 0.25 CPU cores
        memory: 256Mi    # 256 MB
      limits:            # OOM kill / CPU throttle beyond this
        cpu: 500m        # 0.5 CPU cores
        memory: 512Mi    # 512 MB

    # Liveness: restart container if health check fails
    livenessProbe:
      httpGet:
        path: /healthz
        port: 3000
      initialDelaySeconds: 15
      periodSeconds: 10
      failureThreshold: 3

    # Readiness: remove from service if not ready (no traffic)
    readinessProbe:
      httpGet:
        path: /ready
        port: 3000
      initialDelaySeconds: 5
      periodSeconds: 5

    # Startup: disable liveness/readiness until app starts
    startupProbe:
      httpGet:
        path: /healthz
        port: 3000
      failureThreshold: 30    # 30 * 10s = 5 min max startup
      periodSeconds: 10

ConfigMap and Secrets

yaml
# ConfigMap for non-sensitive config
apiVersion: v1
kind: ConfigMap
metadata:
  name: app-config
data:
  LOG_LEVEL: "info"
  MAX_CONNECTIONS: "100"
  FEATURE_NEW_UI: "true"

---
# Secret for sensitive data (base64 encoded, use sealed-secrets in prod)
apiVersion: v1
kind: Secret
metadata:
  name: db-credentials
type: Opaque
stringData:        # stringData auto-encodes to base64
  DATABASE_URL: "postgresql://user:pass@postgres:5432/mydb"
  JWT_SECRET: "super-secret-key"

---
# Mount in deployment
spec:
  containers:
    - name: api
      envFrom:
        - configMapRef:
            name: app-config
        - secretRef:
            name: db-credentials

Rolling Update Strategy

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: api-server
spec:
  replicas: 4
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxSurge: 1          # At most 5 pods during update (4+1)
      maxUnavailable: 0    # All 4 must stay available (zero downtime)

  template:
    spec:
      terminationGracePeriodSeconds: 30

      containers:
        - name: api
          image: myapp:v1.2.0
          lifecycle:
            preStop:
              exec:
                # Allow in-flight requests to complete
                command: ["/bin/sh", "-c", "sleep 5"]

Horizontal Pod Autoscaler

yaml
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
  name: api-hpa
spec:
  scaleTargetRef:
    apiVersion: apps/v1
    kind: Deployment
    name: api-server
  minReplicas: 2
  maxReplicas: 20
  metrics:
    - type: Resource
      resource:
        name: cpu
        target:
          type: Utilization
          averageUtilization: 70    # Scale up when CPU > 70%
    - type: Resource
      resource:
        name: memory
        target:
          type: Utilization
          averageUtilization: 80
  behavior:
    scaleDown:
      stabilizationWindowSeconds: 300   # Wait 5 min before scaling down
      policies:
        - type: Percent
          value: 25                     # Max 25% reduction per period
          periodSeconds: 60

Network Policy

yaml
# Only allow traffic from specific namespaces/pods
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: api-network-policy
spec:
  podSelector:
    matchLabels:
      app: api-server
  policyTypes:
    - Ingress
    - Egress
  ingress:
    - from:
        - namespaceSelector:
            matchLabels:
              env: production
        - podSelector:
            matchLabels:
              role: frontend
      ports:
        - port: 3000
  egress:
    - to:
        - podSelector:
            matchLabels:
              app: postgres
      ports:
        - port: 5432

Checklist

  • Resource requests AND limits set for every container
  • Liveness, readiness, and startup probes configured
  • Rolling update with maxUnavailable: 0 for zero-downtime deploys
  • preStop hook with sleep for graceful connection draining
  • Pod Disruption Budget (minAvailable: 50%) for maintenance windows
  • Network policies restrict ingress/egress to required paths only
  • Secrets managed via sealed-secrets or external-secrets, not plain YAML
  • HPA configured with scale-down stabilization window

Anti-Patterns

  • No resource limits: single pod can starve the entire node
  • Liveness probe hitting a heavy endpoint: cascading restarts under load
  • Using latest tag: no rollback capability, unpredictable deployments
  • Storing secrets in ConfigMaps: no encryption at rest
  • Single replica for stateful services: no availability during updates
  • Missing PodDisruptionBudget: node drain kills all pods simultaneously

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/kubernetes-patterns of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Kubernetes Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubernetes Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubernetes Patterns this skillvibeeval/vibecosystem531—~1.6kAutomated safety check: PassMIT
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
Provider Bug Reviewmondoohq/mql411—~2.9kAutomated safety check: PassCustom licence
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider173—~2.6kAutomated safety check: PassCustom licence
Kopiur Designhome-operations/kopiur113—~2.4kAutomated safety check: PassAGPL-3.0
NGINX Ingress Controller Debuggingnginx/kubernetes-ingress5.1k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    411 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    173 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kopiur Design

    home-operations/kopiur

    Design norms and locked decisions for the Kopiur Kopia-native Kubernetes backup operator (Rust/kube-rs).

    113 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • NGINX Ingress Controller Debugging

    nginx/kubernetes-ingress

    Troubleshooting patterns for the NGINX Ingress Controller: reload failures, custom resources that have no effect, controller panics and snapshot test failures.

    5.1k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Release Cut And Demo Roll

    carverauto/serviceradar

    Cut a ServiceRadar release and roll the Kubernetes demo namespace to the resulting published semver image tag through the guarded ArgoCD release branch.

    921 GitHub stars~3.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from vibeeval/vibecosystem

All 144 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Kubernetes Patterns

What does Kubernetes Patterns do?

Pod design patterns, sidecar containers, init containers, config management, rolling updates, and resource limits. Kubernetes Patterns is an agent skill from vibeeval/vibecosystem. Pod design patterns, sidecar containers, init containers, config management, rolling updates, and resource limits.

When should I use Kubernetes Patterns?

Kubernetes Patterns fits situations like: tasks that involve Container orchestration; tasks that involve Design patterns.

How do I install Kubernetes Patterns in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill kubernetes-patterns -a claude-code`. Or copy the skill folder (skills/kubernetes-patterns in vibeeval/vibecosystem) into .claude/skills/kubernetes-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Kubernetes Patterns in Codex?

Run `npx skills add vibeeval/vibecosystem --skill kubernetes-patterns -a codex`. Or copy the skill folder (skills/kubernetes-patterns in vibeeval/vibecosystem) into .agents/skills/kubernetes-patterns in your project. Codex loads it when a task matches its description.

Can I use Kubernetes Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill kubernetes-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubernetes-patterns, .gemini/skills/kubernetes-patterns, .github/skills/kubernetes-patterns and .opencode/skills/kubernetes-patterns in your project.

What does Kubernetes Patterns need to run?

Going by SKILL.md and its folder, Kubernetes Patterns needs credentials named JWT_SECRET. Our summary lists: A credential in JWT_SECRET.

Does Kubernetes Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kubernetes Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kubernetes Patterns use?

Kubernetes Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubernetes Patterns use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kubernetes Patterns?

Skills that share tags, products or a category with Kubernetes Patterns: NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars), Provider Bug Review (mondoohq/mql, 411 stars), Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 173 stars) and Kopiur Design (home-operations/kopiur, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubernetes Patterns?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 144 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.