Topic · DevOps & Cloud
Best container orchestration skills, page 6
Container orchestration skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | 241.Aegisops AI Autonomous DevSecOps & FinOps Guardrails. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | today |
| 242 | Operate GPU-backed Kubernetes clusters for AI inference and training with scheduling, autoscaling, node health, MIG partitioning, and cost controls. | sickn33/ | 47k | 2 repos | ~3.2k | Automated safety check: Pass | MIT | today |
| 243 | Add, configure, or modify GitOps addons on the PEEKS platform. | aws-samples/ | 115 | — | ~1k | Automated safety check: Pass | MIT-0 | yesterday |
| 244 | A skill your agent uses for VSS live metrics, OpenTelemetry traces, pipeline bottlenecks, and metrics-panel troubleshooting. | open-edge-platform/ | 169 | — | ~913 | Automated safety check: Pass | Apache-2.0 | today |
| 245 | 245.Aai Bitbucket Use aai-cli to inspect and manage Bitbucket repositories, pull requests, branches, commits, source files, comments, and pipelines. | aai-labs/ | 109 | — | ~256 | Automated safety check: Pass | Apache-2.0 | today |
| 246 | Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 247 | Writes and tunes Falco rule syntax for container escape detection - conditions, macros, lists, priorities, and output fields - covering host filesystem mounts, sensitive host path access, kernel… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 248 | Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 249 | Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 250 | Implements automated security scanning for Infrastructure as Code using Checkov, tfsec, and KICS to detect misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts, plus… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 251 | Installs Calico as the cluster CNI and writes standard Kubernetes NetworkPolicy under it, covering default-deny baselines, policy ordering and precedence, service-account-based selectors, and… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 252 | Chooses and applies the correct Kubernetes Pod Security Standard (Privileged, Baseline, Restricted) for a workload: what each profile forbids, how to map existing workloads to a profile, which… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 253 | Writes portable upstream Kubernetes NetworkPolicy YAML - default-deny-all, DNS egress, namespace and pod selector rules - that works on any conformant CNI such as Calico or Cilium. | mukul975/ | 34k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 254 | Deploys OPA Gatekeeper via Helm as a Kubernetes admission controller and writes ConstraintTemplates with Rego plus instantiated Constraints to validate, mutate, or deny resource requests at… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 255 | Configures and operates the Kubernetes Pod Security Admission (PSA) controller that enforces Pod Security Standards: namespace enforce/audit/warn labels, cluster-wide defaults via… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 256 | Implements policy-as-code enforcement with Open Policy Agent (OPA) and Gatekeeper for Kubernetes and CI/CD pipelines, covering writing Rego policies, deploying OPA Gatekeeper as a Kubernetes… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 257 | Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 258 | Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 259 | Turns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 260 | Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 261 | Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 262 | Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 263 | Run a live EKS cluster cost efficiency assessment — analyze spending across 6 dimensions (compute efficiency, Spot/Graviton adoption, networking, storage, observability, idle resources), calculate a… | aws-samples/ | 115 | — | ~3.8k | Automated safety check: Warn | MIT-0 | yesterday |
| 264 | Reference knowledge for installing, uninstalling, or creating-and-installing Dynatrace OneAgent across VM/server, Kubernetes (Operator + DynaKube), AWS Lambda (layer + env vars, plus optional fresh… | Dynatrace/ | 162 | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | 8 days ago |
| 265 | A skill your agent uses when building a Kubernetes Operator — custom controllers that reconcile CRD state. | alirezarezvani/ | 28k | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 266 | Security review of Infrastructure-as-Code (Terraform, Kubernetes, CloudFormation). | OWASP/ | 187 | — | ~694 | Automated safety check: Pass | CC-BY-4.0 | 14 days ago |
| 267 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | today |
| 268 | 268.Kubernetes Ops Deploy, scale, and manage Kubernetes workloads. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~2.1k | Automated safety check: Pass | MIT | today |
| 269 | 269.Infra Triage Infrastructure alert triage — dedup via YT search, deep PVE/K8s investigation, auto-escalation for recurring/flapping alerts, control plane deep dive for K8s controller nodes. | papadopouloskyriakos/ | 107 | — | ~714 | Automated safety check: Notes | No licence | 3 days ago |
| 270 | Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules… | mukul975/ | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 271 | Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 272 | Installs and runs the kube-bench tool against a Kubernetes cluster as a Job, DaemonSet, or standalone binary, selecting the correct benchmark version and targets (control plane, etcd, kubelet… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 273 | Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 274 | Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 275 | Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. | mukul975/ | 34k | — | ~635 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 276 | Audits container and pod configuration for escape-enabling misconfiguration using the Kubernetes Python client - privileged flags, dangerous capability grants, host path mounts, shared namespaces… | mukul975/ | 34k | — | ~648 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 277 | Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 278 | 278.Iac Security Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. | hardw00t/ | 104 | — | ~2.4k | Automated safety check: Pass | No licence | 5 mo ago |
| 279 | 279.K3d Environment Set up or reconfigure Bionic's local k3d Kubernetes environment. | bionic-gpt/ | 2.4k | — | ~356 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 280 | Deployment patterns from Kubernetes to serverless and edge functions. | ancoleman/ | 526 | — | ~3.1k | Automated safety check: Pass | MIT | 10 mo ago |
| 281 | Implement GitOps continuous delivery for Kubernetes using ArgoCD or Flux. | ancoleman/ | 526 | — | ~2.9k | Automated safety check: Pass | MIT | 10 mo ago |
| 282 | 282.Managing DNS Manage DNS records, TTL strategies, and DNS-as-code automation for infrastructure. | ancoleman/ | 526 | — | ~3.6k | Automated safety check: Notes | MIT | 10 mo ago |
| 283 | 283.Managing Secrets Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes. | ancoleman/ | 526 | — | ~2.9k | Automated safety check: Pass | MIT | 10 mo ago |
| 284 | Operating production Kubernetes clusters effectively with resource management, advanced scheduling, networking, storage, security hardening, and autoscaling. | ancoleman/ | 526 | — | ~3.6k | Automated safety check: Pass | MIT | 10 mo ago |
| 285 | 285.Resource Tagging Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation. | ancoleman/ | 526 | — | ~4k | Automated safety check: Pass | MIT | 10 mo ago |
| 286 | Design or review infrastructure, deployment, CI/CD, Docker, Kubernetes, health checks, rollback, feature flags, production readiness, and mobile release workflows. | github/ | 40k | 1 repo | ~743 | Automated safety check: Pass | MIT | today |
| 287 | Build, deploy, and test Datadog Agent components (agent, cluster-agent, operator, CSI driver) on a local Kubernetes cluster using the injector-dev CLI. | DataDog/ | 3.8k | — | ~4.4k | Automated safety check: Warn | Apache-2.0 | today |
| 288 | 288.Releasing Test A skill your agent uses when 把任何批次的改动发到 Prismer 测试环境(test.docbrew.cn / APPENV=test),或听到「发测试 / 发 test / 上测试环境 / deploy test / 打 ali-k8s-test tag」。涉及 develop 部署、test 迁移通道、runner 节流时必读。 | Prismer-AI/ | 1.6k | — | ~2.9k | Automated safety check: Pass | MIT | 9 days ago |
Explore related skills
More topics in DevOps & Cloud
- Deployment1,266
- CI/CD978
- Containers729
- Observability631
- Infrastructure as code379
- Monitoring and alerting352
- Secrets management334
- Runbooks and postmortems324
- Incident response302
- Cloud networking227
- Backup and disaster recovery185
- Site reliability engineering150
- Cloud architecture118
- MLOps93
- Cloud cost optimization91
- GitOps88
- Linux administration73
- Platform engineering43
- Chaos engineering24