Agent skill

Skipper Architecture

by zalando in zalando/skipper

Skipper architecture reference: routing table lifecycle, request processing pipeline, and package layout

MITAuto-check passedDevOps & Cloud

Install Skipper Architecture

skills CLI
$ npx skills add zalando/skipper --skill skipper-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zalando/skipper skipper-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zalando/skipper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/skipper-architecture .claude/skills/skipper-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skipper-architecture
GitHub stars
3.3k
Token cost
~1.1k tokens
SKILL.md length
389 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Skipper architecture reference: routing table lifecycle, request processing pipeline, and package layout

  • Works in 3 steps: ServeHTTP: creates a skipper proxy… → do: main functionality of the proxy → serve the response by writing…
  • DevOps & Cloud work in your project
  • SKILL.md covers What I do, When to use me and Quick start
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Skipper Architecture is an agent skill from zalando/skipper. Skipper architecture reference: routing table lifecycle, request processing pipeline, and package layout

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: opencode, claude

It sits in DevOps & Cloud. It works with Kubernetes. The repository describes itself as: An HTTP router and reverse proxy for service composition, including use cases like Kubernetes Ingress. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/skipper-architecture”

Requirements

  • Compatibility (from SKILL.md): opencode, claude

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. ServeHTTP: creates a skipper proxy *context, calls p.do(*context, span) and serves the response p.serveResponse(*context) (p is the *Proxy…
  2. do: main functionality of the proxy
  3. serve the response by writing http.Header first and stream the response body.

What it can do on your machine

Read from SKILL.md and the folder at commit fb02285. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode, claude

    From compatibility in the SKILL.md frontmatter.

Context cost

Skipper Architecture loads about 1.1k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 389 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zalando/skipper at commit fb02285, republished under its MIT licence (© zalando). 389 words, ~1,063 tokens.

Download SKILL.mdSave it as .claude/skills/skipper-architecture/SKILL.md (or your agent's skills folder).
name
skipper-architecture
description
Skipper architecture reference: routing table lifecycle, request processing pipeline, and package layout
compatibility
opencode, claude
license
MIT
metadata.audience
maintainers, contributors

What I do

  • focus on skipper architecture

When to use me

when designing a new package, understanding data flow between components, or working on the proxy/routing core — not for routine filter/predicate edits.

Quick start

Architecture
  • Omit the use of internal or generic package directories like pkg.
  • No code comments, that are not godoc style for exported functions, types, variables or constants. Write package doc in doc.go.
  • ./cmd sub-directory contains the main packages
  • ./io and ./net are additions to Go stdlib that should be reused if possible and enhanced if needed.
  • Skipper creates very often a new routing tree, think of every 3s, from different routing sources.
  • Skipper is an http proxy. The core function is in the ./proxy package. net.Listener functionality is outside of the proxy package. The request processing of the proxy starts with the stdlib net/http.Handler interface ServeHTTP(ResponseWriter, *Request), func (p *Proxy) ServeHTTP(w http.ResponseWriter, r *http.Request).
Routing table creation

In routing package there is a DataClient interface.

go
// DataClient instances provide data sources for
// route definitions.
type DataClient interface {
	LoadAll() ([]*eskip.Route, error)
	LoadUpdate() ([]*eskip.Route, []string, error)
}

A DataClient fetches information to create routes. Skipper runs in a loop all dataclients LoadAll and LoadUpdate operations to fetch all routing information every Options.PollTimeout duration to rebuild the routing tree.

On every iteration []*eskip.Route will run through all []routing.PreProcessor.

go
// PreProcessor is an interface for custom pre-processors applying changes
// to the routes before they were created from eskip.Route representation.
type PreProcessor interface {
	Do([]*eskip.Route) []*eskip.Route
}

Then []*eskip.Route are processed to create all predicate and filter instances, which ends in []*routing.Route. After that all []*routing.Route are processed by all []routing.PostProcessors.

go
// PostProcessor is an interface for custom post-processors applying changes
// to the routes after they were created from their data representation and
// before they were passed to the proxy.
type PostProcessor interface {
	Do([]*Route) []*Route
}

The last step is to swap the routing tree routing.Routing.routeTable which is an atomic.Value.

go
type Routing struct {
	routeTable        atomic.Value // of struct routeTable
..

The routeTable struct:

go
type routeTable struct {
	id                 int
	m                  *matcher
	once               sync.Once
	routes             []*Route // only used for closing
	validRoutes        []*eskip.Route
	invalidRoutes      []*eskip.Route
	invalidRouteErrors map[string]string // route ID -> error message
	clients            map[DataClient]struct{}
	created            time.Time
}
Show full SKILL.md (149 more words)Show less
Request Processing

This is hot path code. Everything needs to be efficient!

Starting from ./proxy package func (p *Proxy) ServeHTTP(w http.ResponseWriter, r *http.Request).

We use heavy observability tools to support operations: logging, metrics, OpenTracing/OTel spans and profiling. We conditionally write access logs which can be modified per route and for each status code.

Basic request and response processing:

  1. ServeHTTP: creates a skipper proxy *context, calls p.do(*context, span) and serves the response p.serveResponse(*context) (p is the *Proxy instance)
  2. do: main functionality of the proxy:
    1. route lookup
    2. request filter processing in a loop call all filter.Request(FilterContext)
    3. map to backend
    4. in case of load balancer backend apply load balancer algorithm to select endpoint
    5. send the *http.Request to the endpoint
    6. receive *http.Response
    7. response filter processing in a loop call all filter.Response(FilterContext)
  3. serve the response by writing http.Header first and stream the response body.

© zalando, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/skipper-architecture of zalando/skipper.

Open the folder on GitHubat commit fb02285

Compare with similar skills

Skipper Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skipper Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skipper Architecture this skillzalando/skipper3.3k—~1.1kAutomated safety check: PassMIT
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from zalando/skipper

  • Filter

    zalando/skipper

    Create or modify code in the filters package and all its sub-folders

    3.3k GitHub stars~527 tokensUpdated today
    Auto-check passed
  • Predicate

    zalando/skipper

    Create or modify code in the predicates package and all its sub-folders

    3.3k GitHub stars~453 tokensUpdated today
    Auto-check passed
  • Benchmark

    zalando/skipper

    Create or modify hot-path code or optimizations should be validated by a Go Benchmark

    3.3k GitHub stars~304 tokensUpdated today
    Auto-check passed
  • Go Coding

    zalando/skipper

    Create or modify Go skipper code

    3.3k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Skipper Architecture

What does Skipper Architecture do?

Skipper architecture reference: routing table lifecycle, request processing pipeline, and package layout. Skipper Architecture is an agent skill from zalando/skipper.

When should I use Skipper Architecture?

Skipper Architecture fits situations like: devOps & Cloud work in your project.

How do I install Skipper Architecture in Claude Code?

Run `npx skills add zalando/skipper --skill skipper-architecture -a claude-code`. Or copy the skill folder (.agents/skills/skipper-architecture in zalando/skipper) into .claude/skills/skipper-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Skipper Architecture in Codex?

Run `npx skills add zalando/skipper --skill skipper-architecture -a codex`. Or copy the skill folder (.agents/skills/skipper-architecture in zalando/skipper) into .agents/skills/skipper-architecture in your project. Codex loads it when a task matches its description.

Can I use Skipper Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zalando/skipper --skill skipper-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skipper-architecture, .gemini/skills/skipper-architecture, .github/skills/skipper-architecture and .opencode/skills/skipper-architecture in your project.

What does Skipper Architecture need to run?

SKILL.md names no scripts, command-line tools or credentials: Skipper Architecture is instructions for the agent only. Compatibility (from SKILL.md): opencode, claude.

Does Skipper Architecture access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skipper Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skipper Architecture use?

Skipper Architecture is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skipper Architecture use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skipper Architecture?

Skills that share tags, products or a category with Skipper Architecture: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skipper Architecture?

zalando (a GitHub organization) maintains it in zalando/skipper, which has 3,331 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.

Source: zalando/skipper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.