k8s-aiops
Use this skill whenever the user needs to operate a Kubernetes cluster — list/inspect pods, deployments, statefulsets, daemonsets, replicasets, jobs, cronjobs, services, ingresses, endpoints, configmaps, secrets (names/keys only), PVCs/PVs/storageclasses, nodes, namespaces, and events; read pod logs; describe pods/nodes; pod/node top (metrics); read-only diagnostics / RCA (pod-health, workload-readiness); scale deployments/statefulsets; rollout status/history/undo/pause/resume and set image; delete pods/deployments/jobs; create/delete namespaces; and cordon/uncordon/drain nodes. Works with any kubeconfig-reachable cluster (standard Kubernetes, k3s, EKS, GKE, AKS). Always use this skill for "list k8s pods", "scale deployment", "kubernetes pod logs", "describe pod", "why is my pod crashing", "diagnose pods", "which deployments are unhealthy", "rollout undo", "set image", "top pods", "drain node", "cordon node", "restart deployment", "k3s", or "kubectl"-style tasks when the context is explicitly Kubernetes / a cluster. Do NOT use when the target is not a Kubernetes cluster (hypervisor VM lifecycle, backup products, or cloud-provider consoles are out of scope). Common Kubernetes operations with a built-in governance harness (audit, token budget, undo, risk-tier labels).
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.13.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.13.3release · observed Sep 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:k8s-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:k8s-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/k8s-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-k8s-aiops/snapshot"
Documentation
CLAWHUB
149,600 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: k8s-aiops
slug: k8s-aiops
displayName: "k8s AIops"
summary: "Governed Kubernetes ops — 55 MCP tools with audit, budget, undo, risk-tier audit labels."
license: MIT
homepage: https://github.com/AIops-tools/K8s-AIops
tags: [aiops, mcp, governance, k8s]
description: >
Use this skill whenever the user needs to operate a Kubernetes cluster — list/inspect pods, deployments, statefulsets, daemonsets, replicasets, jobs, cronjobs, services, ingresses, endpoints, configmaps, secrets (names/keys only), PVCs/PVs/storageclasses, nodes, namespaces, and events; read pod logs; describe pods/nodes; pod/node top (metrics); read-only diagnostics / RCA (pod-health, workload-readiness); scale deployments/statefulsets; rollout status/history/undo/pause/resume and set image; delete pods/deployments/jobs; create/delete namespaces; and cordon/uncordon/drain nodes. Works with any kubeconfig-reachable cluster (standard Kubernetes, k3s, EKS, GKE, AKS).
Always use this skill for "list k8s pods", "scale deployment", "kubernetes pod logs", "describe pod", "why is my pod crashing", "diagnose pods", "which deployments are unhealthy", "rollout undo", "set image", "top pods", "drain node", "cordon node", "restart deployment", "k3s", or "kubectl"-style tasks when the context is explicitly Kubernetes / a cluster.
Do NOT use when the target is not a Kubernetes cluster (hypervisor VM lifecycle, backup products, or cloud-provider consoles are out of scope).
Common Kubernetes operations with a built-in governance harness (audit, token budget, undo, risk-tier labels).
installer:
kind: uv
package: k8s-aiops
argument-hint: "[resource name or describe your Kubernetes task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["k8s-aiops","uvx"]},"optional":{"env":["K8S_AIOPS_CONFIG","KUBECONFIG","K8S_AIOPS_HOME"]},"homepage":"https://github.com/AIops-tools/K8s-AIops","emoji":"☸️","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed Kubernetes operations. The governance harness (audit, token/runaway budget, undo, risk-tier labels) is bundled in the package — no external skill-family dependency.
All write operations are audited to a local SQLite DB under ~/.k8s-aiops/ (relocatable via K8S_AIOPS_HOME).
Credentials: k8s-aiops handles NO credentials directly — authentication is delegated to the kubeconfig (KUBECONFIG env or ~/.kube/config), which may hold client certs, bearer tokens, or exec plugins (EKS/GKE/AKS). Underlying credentials are never read, logged, or echoed. The state dir ~/.k8s-aiops should be chmod 700.
Destructive operations (deployment/job/namespace delete, node cordon/drain, rollout undo) require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (budget/runaway guard + audit + a descriptive risk-tier label). Reversible writes record an inverse undo descriptor (scale_deployment/scale_statefulset restore the previous replica count; set_deployment_image_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "k8s-aiops",
"version": "0.13.3",
"publishedAt": 1789452174189
}references/agent-guardrails.md
# Agent guardrails — running k8s-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## Authorization is not this tool's job — decide it where it belongs
Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:
- **The kubeconfig context you connect with.** Bind it to a ServiceAccount or
user whose RBAC grants only `get`/`list`/`watch`, and every write fails at the
apiserver — the only place the permission actually lives. No skill-side flag
can be argued around by a model, but a revoked RBAC verb cannot be. This is
strictly stronger than any in-process switch: it is enforced at the cluster.
- **Your agent's system prompt.** If you want an observe-only session, tell the
model not to call the write tools (they are clearly tagged `[WRITE]`).
What the tool *does* guarantee is that you can always see what happened:
## What the tool enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Log everything you do, over both MCP and the CLI" | Every operation is audited to `~/.k8s-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |
| "Don't invent a value when a field is missing" | A field the apiserver did not return comes back as `null`, never as `""`. An unscheduled pod's `node` is `null`; a pod with no phase yet has `phase: null`; an object with no readable creation timestamp has `age: null`. Absent and empty are distinguishable in the payload. |
| "Tell me if the output was cut off" | The limit-bearing reads return an envelope: `event_list` → `{"events": [...], "returned": N, "limit": L, "truncated": true/false}`, and `undo_list` → `{"undos": [...], "returned": N, "limit": L, "truncated": ...}`. Truncation is **measured** (one extra row is fetched), not guessed from `len(rows) == limit`. |
| "Preserve the ordering / tell me what's most urgent" | `pod_health_rca` and `workload_readiness_rca` findings carry an explicit 1-based `rank`, worst-first, and each finding's `detail` cites the measured signal (the waiting reason, the restart count, the ready/desired ratio). Priority is in the payload, not implied by list position. |
| "Confirm before anything destructive" | Threferences/capabilities.md
# k8s-aiops Capabilities 55 MCP tools (39 read / 16 write). Every tool is wrapped with `@governed_tool` (audit + policy + budget + risk-tier; undo where a clean inverse exists). Returns are high-signal summaries — `_get` / `_describe` tools add detail for a single object. ## Read tools | Tool | Returns | Risk | |------|---------|:----:| | `pod_list` | name, namespace, phase, ready, restarts, node, age | low | | `pod_get` | + host_ip, pod_ip, containers | low | | `pod_describe` | status, conditions, container states + restart counts, recent events | low | | `pod_logs` | trailing log lines (default 100) | low | | `deployment_list` / `deployment_get` | replicas summary / + strategy, images | low | | `rollout_status` | desired/updated/available/unavailable + paused | low | | `rollout_history` | revisions (from replicasets) with images | low | | `statefulset_list` / `statefulset_get` | desired/ready/current / + service, images | low | | `daemonset_list` / `daemonset_get` | desired/ready/available / + images | low | | `replicaset_list` | name, namespace, desired/ready, age | low | | `job_list` / `job_get` | completions, succeeded/failed/active | low | | `cronjob_list` / `cronjob_get` | schedule, suspend, active, last schedule | low | | `service_list` | name, namespace, type, cluster IP, ports | low | | `ingress_list` / `ingress_get` | class, hosts / + path→backend rules | low | | `endpoints_list` | ready addresses + ports | low | | `configmap_list` / `configmap_get` | key count / keys + values | low | | `secret_list` | names, types, key NAMES only (values redacted) | low | | `pvc_list` / `pvc_get` | status, capacity, class / + access modes | low | | `pv_list` | capacity, status, claim, class | low | | `storageclass_list` | provisioner, reclaim policy, default | low | | `node_list` / `node_describe` | status, roles / capacity, allocatable, conditions, taints | low | | `namespace_list` | name, phase, age | low | | `pod_top` / `node_top` | CPU/mem via metrics-server (graceful if absent) | low | | `cluster_info` | server version, node/ready/namespace counts | low | | `api_resources` | available API groups + versions | low | | `event_list` | type, reason, object, namespace, message, age | low | | `pod_health_rca` | worst-first findings: CrashLoopBackOff, image-pull, OOMKilled, unschedulable, high restarts (each cites the reason/count) | low | | `workload_readiness_rca` | worst-first findings: ready<desired, zero-ready outages, stuck rollouts (Deployment/StatefulSet/DaemonSet) | low | | `undo_list` | recorded reversible writes / not-yet-applied undo tokens | low | ## Write tools | Tool | Effect | Risk | Undo | |------|--------|:----:|------| | `scale_deployment` | set replica count | medium | scale back to `previous_replicas` | | `scale_statefulset` | set replica count | medium | scale back to `previous_replicas` | | `rollout_restart_deployment` | patch `restartedAt` annotation | medium | none (pods already rolling) | | `rollout_pause` / `rollout_resume
references/cli-reference.md
# k8s-aiops CLI Reference All commands accept `-t/--target <name>` to select a configured target (a kube context). Namespaced commands accept `-n/--namespace <ns>`; omit it to use the target's default namespace (read lists fall back to all-namespaces). ## Onboarding ```bash k8s-aiops init # interactive wizard: register kube contexts as targets ``` ## Pods ```bash k8s-aiops pod list [-n <ns>] [-t <target>] k8s-aiops pod get <name> [-n <ns>] k8s-aiops pod describe <name> [-n <ns>] # status, container states, events k8s-aiops pod logs <name> [-n <ns>] [--tail N] [-c <container>] k8s-aiops pod delete <name> [-n <ns>] [--dry-run] # destructive: double confirm ``` ## Deployments & Rollouts ```bash k8s-aiops deployment list [-n <ns>] k8s-aiops deployment get <name> [-n <ns>] k8s-aiops deployment scale <name> <replicas> [-n <ns>] k8s-aiops deployment restart <name> [-n <ns>] # rolling restart k8s-aiops deployment delete <name> [-n <ns>] [--dry-run] # HIGH RISK: double confirm k8s-aiops rollout status <name> [-n <ns>] k8s-aiops rollout history <name> [-n <ns>] k8s-aiops rollout pause|resume <name> [-n <ns>] k8s-aiops rollout set-image <name> <container> <image> [-n <ns>] k8s-aiops rollout undo <name> [--to-revision N] [--dry-run] # HIGH RISK: double confirm ``` ## StatefulSets / DaemonSets / Jobs / CronJobs ```bash k8s-aiops statefulset list|get [-n <ns>] k8s-aiops statefulset scale <name> <replicas> [-n <ns>] k8s-aiops daemonset list|get [-n <ns>] k8s-aiops job list|get [-n <ns>] k8s-aiops job delete <name> [-n <ns>] [--dry-run] # destructive: double confirm k8s-aiops cronjob list|get [-n <ns>] ``` ## Services, Ingress, Config, Storage ```bash k8s-aiops service list [-n <ns>] k8s-aiops ingress list|get [-n <ns>] k8s-aiops configmap list|get [-n <ns>] k8s-aiops secret list [-n <ns>] # names + key NAMES only, never values k8s-aiops storage pvc-list|pvc-get [-n <ns>] k8s-aiops storage pv-list|class-list ``` ## Nodes & Metrics ```bash k8s-aiops node list k8s-aiops node describe <name> k8s-aiops node cordon <name> [--dry-run] # destructive: double confirm k8s-aiops node uncordon <name> k8s-aiops node drain <name> [--dry-run] # HIGH RISK: double confirm k8s-aiops top pod|node # requires metrics-server ``` ## Namespaces, Cluster & Events ```bash k8s-aiops namespace list k8s-aiops namespace create <name> k8s-aiops namespace delete <name> [--dry-run] # HIGH RISK: double confirm k8s-aiops cluster-info k8s-aiops api-resources k8s-aiops events [-n <ns>] ``` ## Diagnostics & MCP ```bash k8s-aiops diagnose pod-health [-n <ns>] [-l <selector>] # RCA: crashloop/imagepull/OOM/unschedulable/restarts (read-only) k8s-aiops diagnose workload-readiness [-n <ns>] # RCA: ready<desired / stuck rollouts (read-only) k8s-aiops doctor [--skip-auth] # check config + cluster reachability k8s-aiops mcp # st
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/k8s-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/k8s-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:28:09.610Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-k8s-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-k8s-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T06:28:09.610Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/k8s-aiops",
"sourceUrl": "https://clawhub.ai/zw008/k8s-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:28:09.610Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.13.3",
"href": "https://clawhub.ai/zw008/k8s-aiops",
"sourceUrl": "https://clawhub.ai/zw008/k8s-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T06:02:54.189Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-k8s-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-k8s-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.13.3",
"description": "- Removed the skill description file (skill-card.md). - No user-facing changes to functionality or features. - Documentation is unchanged except for the file removal.",
"href": "https://clawhub.ai/zw008/k8s-aiops",
"sourceUrl": "https://clawhub.ai/zw008/k8s-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T06:02:54.189Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
