Eks Best Practices
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
Enterprise-grade systems with microservices, Kubernetes, Terraform, and AI Native methodology.
$ npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ww-w-ai/bkit-claude-code enterprise --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/enterprise .claude/skills/enterprise && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "enterprise" agent skill from https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterprise into .claude/skills/enterprise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enterprise", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterpriseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ww-w-ai/bkit-claude-code enterprise --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/enterprise .agents/skills/enterprise && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "enterprise" agent skill from https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterprise into .agents/skills/enterprise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enterprise", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ww-w-ai/bkit-claude-code enterprise --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/enterprise .cursor/skills/enterprise && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "enterprise" agent skill from https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterprise into .cursor/skills/enterprise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enterprise", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ww-w-ai/bkit-claude-code.git --path skills/enterprise--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ww-w-ai/bkit-claude-code enterprise --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/enterprise .gemini/skills/enterprise && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "enterprise" agent skill from https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterprise into .gemini/skills/enterprise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enterprise", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ww-w-ai/bkit-claude-code enterpriseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/enterprise .github/skills/enterprise && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "enterprise" agent skill from https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterprise into .github/skills/enterprise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enterprise", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ww-w-ai/bkit-claude-code enterprise --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/enterprise .opencode/skills/enterprise && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "enterprise" agent skill from https://github.com/ww-w-ai/bkit-claude-code/tree/main/skills/enterprise into .opencode/skills/enterprise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enterprise", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
enterpriseEnterprise-grade systems with microservices, Kubernetes, Terraform, and AI Native methodology.
Enterprise is an agent skill from ww-w-ai/bkit-claude-code. Enterprise-grade systems with microservices, Kubernetes, Terraform, and AI Native methodology. For multi-feature initiatives spanning a release timeline, combine with /sprint master-plan (v2.1.13) to group features into a single 8-phase sprint container with shared scope/budget and 4 auto-pause triggers (QUALITYGATEFAIL / ITERATIONEXHAUSTED / BUDGETEXCEEDED / PHASETIMEOUT). Triggers: microservices, k8s, terraform, monorepo, AI native
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration, Infrastructure as code and Microservices. It works with Kubernetes and Terraform. The repository describes itself as: bkit Vibecoding Kit - PDCA methodology + Claude Code mastery for AI-native development. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 85b4913. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditGlobGrepBashTaskWebSearchFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
argocdclaudeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
INTERNAL_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Enterprise loads about 3.5k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 479 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Edit, Glob, Grep, Bash, Task, WebSearchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ww-w-ai/bkit-claude-code at commit 85b4913, republished under its Apache-2.0 licence (© ww-w-ai). 479 words, ~3,524 tokens.
.claude/skills/enterprise/SKILL.md (or your agent's skills folder).| Action | Description | Example |
|---|---|---|
init | Project initialization (/init-enterprise feature) | /enterprise init my-platform |
guide | Display development guide | /enterprise guide |
help | MSA/Infrastructure help | /enterprise help |
writeBkitMemory() in lib/pdca/status.js,
which writes .bkit/state/memory.json (the migrated path of .bkit-memory.json).
This holds the project level and the 9-phase pipelineStatus, read by
the pipeline Stop hooks for phases 5, 6 and 9.
It is NOT where the PDCA phase lives — that is .bkit/state/pdca-status.json.Frontend:
- Next.js 14+ (Turborepo monorepo)
- TypeScript
- Tailwind CSS
- TanStack Query
- Zustand
- Sentry Browser SDK (@sentry/nextjs) — Error tracking + Session Replay
Backend:
- Python FastAPI (microservices) — default
- PostgreSQL (schema separation)
- Redis (cache, Pub/Sub)
- RabbitMQ / SQS (message queue)
- Sentry Server SDK (sentry-sdk[fastapi]) — Error tracking + APM
Infrastructure:
- AWS (EKS, RDS, S3, CloudFront)
- Kubernetes (Kustomize)
- Terraform (IaC)
- ArgoCD (GitOps)
- ALB + NGINX Ingress Controller (L7 load balancing)
- CORS: Ingress annotation으로 처리
nginx.ingress.kubernetes.io/enable-cors: "true"
- NLB(L4)는 gRPC/WebSocket 전용 서비스에만 사용
CI/CD:
- GitHub Actions
- Docker
- Semgrep (SAST) + Trivy (Container Scan)
Monitoring & Error Tracking:
- Sentry — Error tracking, grouping, regression detection
- Prometheus + Grafana — Metrics & dashboards
- Loki + Promtail — Log aggregation
- Tempo + OpenTelemetry — Distributed tracing
- Alertmanager → PagerDuty (critical) / Slack (warning)
Self-Healing Pipeline:
- Sentry Webhook → Self-Healing Agent trigger
- 4-Layer Living Context (Scenarios, Invariants, Impact, Incidents)
- Auto-fix (max 5 iterations) → Auto PR → Canary Deploy
- Auto-Rollback on error rate spikeSupported: All Tiers
Enterprise level handles complex requirements including legacy system integration.
| Tier | Usage | Guidance |
|---|---|---|
| Tier 1 | Primary services | New development, core features |
| Tier 2 | System/Cloud | Go (K8s), Rust (performance critical) |
| Tier 3 | Platform native | iOS (Swift), Android (Kotlin), legacy Java |
| Tier 4 | Legacy integration | Migration plan required |
Migration Path:
project/
├── apps/ # Frontend apps (Turborepo)
│ ├── web/ # Main web app
│ ├── admin/ # Admin
│ └── docs/ # Documentation site
│
├── packages/ # Shared packages
│ ├── ui/ # UI components
│ ├── api-client/ # API client
│ └── config/ # Shared config
│
├── services/ # Backend microservices
│ ├── auth/ # Auth service
│ ├── user/ # User service
│ ├── {domain}/ # Domain-specific services
│ └── shared/ # Shared modules
│
├── infra/ # Infrastructure code
│ ├── terraform/
│ │ ├── modules/ # Reusable modules
│ │ └── environments/ # Environment-specific config
│ └── k8s/
│ ├── base/ # Common manifests
│ └── overlays/ # Environment-specific patches
│
├── docs/ # PDCA documents
│ ├── 00-requirement/
│ ├── 01-development/ # Design documents (multiple)
│ ├── 02-scenario/
│ ├── 03-refactoring/
│ └── 04-operation/
│
├── scripts/ # Utility scripts
├── .github/workflows/ # CI/CD
├── docker-compose.yml
├── turbo.json
└── pnpm-workspace.yaml┌─────────────────────────────────────────────────────────┐
│ API Layer │
│ - FastAPI routers │
│ - Request/Response DTOs │
│ - Auth/authz middleware │
├─────────────────────────────────────────────────────────┤
│ Application Layer │
│ - Service classes │
│ - Use Case implementation │
│ - Transaction management │
├─────────────────────────────────────────────────────────┤
│ Domain Layer │
│ - Entity classes (pure Python) │
│ - Repository interfaces (ABC) │
│ - Business rules │
├─────────────────────────────────────────────────────────┤
│ Infrastructure Layer │
│ - Repository implementations (SQLAlchemy) │
│ - External API clients │
│ - Cache, messaging │
│ - Sentry SDK integration (error capture) │
└─────────────────────────────────────────────────────────┘
Dependency direction: Top → Bottom
Domain Layer depends on nothingException 발생 (Frontend/Backend)
↓
Sentry SDK 자동 캡처 (stack trace + breadcrumbs + user context)
↓
Sentry Alert Rule (new issue / regression / spike)
↓
Webhook → Self-Healing Agent trigger
↓
Living Context 4-Layer 로딩
├── Scenario Matrix: 테스트 시나리오
├── Invariants: 불변 조건 (critical = 수정 차단)
├── Impact Map: blast radius 계산
└── Incident Memory: 과거 장애 교훈
↓
Claude Code Fix (max 5 iterations)
↓
4중 검증 (scenarios + invariants + impact + anti-patterns)
↓
Pass → Auto PR → Human Review → Canary Deploy (10%→25%→50%→100%)
Fail → Escalation → PagerDuty + Slack + Auto-Rollback
↓
Post-deploy: Sentry에서 issue resolved 확인 + error_rate 모니터링ALB + NGINX Ingress Controller (기본, 권장)
─────────────────────────────────────
- L7 로드밸런싱 (HTTP/HTTPS/gRPC)
- CORS: Ingress annotation으로 처리 (앱 코드 불필요)
- Path-based routing (/api/auth/*, /api/users/*)
- AWS Certificate Manager (ACM) TLS 연동
- WAF 연동 가능
NLB (특수 케이스만)
─────────────────────────────────────
- L4 로드밸런싱 (TCP/UDP)
- 극도의 저지연 필요 시 (< 1ms)
- WebSocket/gRPC 전용 서비스
- CORS 처리 불가 → 앱단에서 직접 처리 필요# domain/repositories/user_repository.py (interface)
from abc import ABC, abstractmethod
class UserRepository(ABC):
@abstractmethod
async def find_by_id(self, id: str) -> User | None:
pass
@abstractmethod
async def save(self, user: User) -> User:
pass
# infrastructure/repositories/user_repository_impl.py (implementation)
class UserRepositoryImpl(UserRepository):
def __init__(self, db: AsyncSession):
self.db = db
async def find_by_id(self, id: str) -> User | None:
result = await self.db.execute(
select(UserModel).where(UserModel.id == id)
)
return result.scalar_one_or_none()# Synchronous (Internal API)
async def get_user_info(user_id: str) -> dict:
async with httpx.AsyncClient() as client:
response = await client.get(
f"{USER_SERVICE_URL}/internal/users/{user_id}",
headers={"X-Internal-Token": INTERNAL_TOKEN}
)
return response.json()
# Asynchronous (message queue)
await message_queue.publish(
topic="user.created",
message={"user_id": user.id, "email": user.email}
)# modules/eks/main.tf
resource "aws_eks_cluster" "this" {
name = "${var.environment}-${var.project_name}-eks"
role_arn = aws_iam_role.cluster.arn
version = var.kubernetes_version
vpc_config {
subnet_ids = var.subnet_ids
}
tags = merge(var.tags, {
Environment = var.environment
})
}# k8s/base/backend/deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: user-service
spec:
replicas: 2
template:
spec:
containers:
- name: user-service
image: ${ECR_REGISTRY}/user-service:${TAG}
resources:
requests:
cpu: "100m"
memory: "256Mi"
limits:
cpu: "500m"
memory: "512Mi"
livenessProbe:
httpGet:
path: /health
port: 8000| Environment | Infrastructure | Deployment Method |
|---|---|---|
| Local | Docker Compose | Manual |
| Staging | EKS | ArgoCD Auto Sync |
| Production | EKS | ArgoCD Manual Sync |
✅ Allowed
- Retrieve secrets from Secrets Manager
- IAM role-based access
- VPC internal communication
- mTLS (inter-service)
❌ Prohibited
- Hardcoded secrets
- DB in public subnet
- Using root account
- Excessive IAM permissionsPush to feature/*
↓
GitHub Actions (CI)
- Lint
- Test
- Build Docker image
- Push to ECR
↓
PR to staging
↓
ArgoCD Auto Sync (Staging)
↓
PR to main
↓
ArgoCD Manual Sync (Production)1st Priority: Codebase
- scripts/init-db.sql (source of truth for DB schema)
- services/{service}/app/ (each service implementation)
2nd Priority: CLAUDE.md / Convention docs
- services/CLAUDE.md
- frontend/CLAUDE.md
- infra/CLAUDE.md
3rd Priority: docs/ design documents
- For understanding design intent
- If different from code, code is correct| Day | Focus | Output |
|---|---|---|
| 1 | Architecture | Market analysis + System architecture |
| 2-3 | Core | Auth, User + Business services |
| 4-5 | UX | PO feedback → Documentation → Implementation |
| 6-7 | QA | Zero Script QA + bug fixes |
| 8 | Infra | Terraform + GitOps |
| 9-10 | Production | Security review + Deployment |
Mono-repo:
└─ project/
├─ frontend/ ──────┐
├─ services/ ──────┤ AI reads completely
├─ infra/ ─────────┤ Context unified
└─ packages/ ──────┘
✅ AI understands full context
✅ Single source of truth for types
✅ Atomic commits across layers
✅ Consistent patterns enforcedproject/
├── CLAUDE.md # Project-wide context
├── frontend/CLAUDE.md # Frontend conventions
├── services/CLAUDE.md # Backend conventions
└── infra/CLAUDE.md # Infra conventionsRule: Area-specific CLAUDE.md overrides project-level rules
For CTO-level architecture perspectives, activate the enterprise style:
/output-style bkit-enterpriseThis provides:
Enterprise projects support full Agent Teams for parallel PDCA execution:
| Role | Agents | PDCA Phases |
|---|---|---|
| architect | enterprise-expert, infra-architect | Design |
| developer | bkend-expert | Do, Act |
| qa | qa-monitor, gap-detector | Check |
| reviewer | code-analyzer, design-validator | Check, Act |
To enable:
CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1/pdca team {feature}/pdca team statusAll bkit agents automatically remember project context across sessions.
Enterprise agents use project scope memory, ensuring architecture decisions
and infrastructure patterns persist across development sessions.
© ww-w-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/enterprise of ww-w-ai/bkit-claude-code.
Open the folder on GitHubat commit 85b4913
Enterprise next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Enterprise this skillww-w-ai/bkit-claude-code | 601 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Eks Best Practicesaws-samples/appmod-blueprints | 115 | — | ~5k | Automated safety check: Pass | MIT-0 | |
| Asdfjjmartres/opencode | 133 | — | ~2.1k | Automated safety check: Notes | MIT | |
| Supercheck Infrastructure Deploymentsupercheck-io/supercheck | 215 | — | ~1.4k | Automated safety check: Notes | AGPL-3.0 | |
| Cloud Devopsdavila7/claude-code-templates | 33k | 4 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Infrastructuremicrosoft/physical-ai-toolchain | 126 | — | ~1.6k | Automated safety check: Pass | MIT |
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
jjmartres/opencode
A skill your agent uses whenever the user wants to install, configure, or use asdf (asdf-vm), the universal version manager.
supercheck-io/supercheck
Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
microsoft/physical-ai-toolchain
Deploy and manage Azure infrastructure for the Physical AI Toolchain including Terraform IaC, Kubernetes setup, GPU configuration, and network topology
oracle/skills
Oracle Cloud Infrastructure guidance for designing, operating, and troubleshooting OCI services, including OCI Kubernetes Engine (OKE), OCI Internet of Things Platform, OCI Functions deployment and…
ww-w-ai/bkit-claude-code
View audit logs, decision traces, and session history for AI transparency.
ww-w-ai/bkit-claude-code
bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.
ww-w-ai/bkit-claude-code
bkend.ai project tutorials (todo to SaaS) and common error troubleshooting.
ww-w-ai/bkit-claude-code
bkend.ai onboarding — MCP setup, resource hierarchy, tenant/user model, first project.
ww-w-ai/bkit-claude-code
bkend.ai file storage — upload (presigned URL), download (CDN), visibility levels, buckets.
ww-w-ai/bkit-claude-code
bkit plugin help - list available functions including /pdca (9-phase feature cycle), /sprint (8-phase feature container, v2.1.13), /control (Trust L0-L4 + SPRINTAUTORUNSCOPE), /bkit-explore, and 40+…
Works with
Categories
Enterprise-grade systems with microservices, Kubernetes, Terraform, and AI Native methodology. Enterprise is an agent skill from ww-w-ai/bkit-claude-code. Enterprise-grade systems with microservices, Kubernetes, Terraform, and AI Native methodology.
Enterprise fits situations like: (QUALITYGATEFAIL / ITERATIONEXHAUSTED / BUDGETEXCEEDED / PHASETIMEOUT); tasks that involve Container orchestration; tasks that involve Infrastructure as code.
Run `npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a claude-code`. Or copy the skill folder (skills/enterprise in ww-w-ai/bkit-claude-code) into .claude/skills/enterprise in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a codex`. Or copy the skill folder (skills/enterprise in ww-w-ai/bkit-claude-code) into .agents/skills/enterprise in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ww-w-ai/bkit-claude-code --skill enterprise -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enterprise, .gemini/skills/enterprise, .github/skills/enterprise and .opencode/skills/enterprise in your project.
Going by SKILL.md and its folder, Enterprise needs the command-line tools its instructions call (argocd and claude) and credentials named INTERNAL_TOKEN. Our summary lists: Python 3; Docker; A credential in INTERNAL_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash, Task, WebSearch.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Enterprise is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Enterprise: Eks Best Practices (aws-samples/appmod-blueprints, 115 stars), Asdf (jjmartres/opencode, 133 stars), Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars) and Cloud Devops (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ww-w-ai (a GitHub organization) maintains it in ww-w-ai/bkit-claude-code, which has 601 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on September 27, 2026.
Source: ww-w-ai/bkit-claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.