vmware-avi
Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context. Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs, service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics, and multi-cluster AKO overview. Always use it for "virtual service", "pool member", "AKO status", "AKO logs", "ingress diagnose", "ssl expiry", "load balancer", "NSX ALB", "AVI controller", "Avi Load Balancer", "AKO sync", or "负载均衡" tasks. Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks. For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.
Rank
62
Safety
84
Downloads
4.9k
Updated
Oct 9, 2026
Version
1.11.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 4.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 4.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.11.0release · observed Sep 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-avi- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-avi` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/vmware-avi before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/snapshot"
Documentation
CLAWHUB
152,450 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: vmware-avi
description: >
Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery
in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context.
Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs,
service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics,
and multi-cluster AKO overview.
Always use it for "virtual service", "pool member", "AKO status", "AKO logs", "ingress diagnose", "ssl expiry", "load balancer", "NSX ALB",
"AVI controller", "Avi Load Balancer", "AKO sync", or "负载均衡" tasks.
Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks.
For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.
installer:
kind: uv
package: vmware-avi
argument-hint: "[vs-name, ako command, or describe your task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---
# VMware AVI
> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** "VMware", "NSX", and "AVI" are trademarks of Broadcom. Source code is publicly auditable at [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI) under the MIT license.
AVI (NSX Advanced Load Balancer) application delivery and AKO Kubernetes operations — 28 MCP tools.
> **Dual mode**: Traditional AVI Controller management + AKO K8s operations in one skill.
> **Family**: [vmware-aiops](https://github.com/vmware-skills/VMware-AIops) (VM lifecycle), [vmware-monitor](https://github.com/vmware-skills/VMware-Monitor) (inventory/health), [vmware-storage](https://github.com/vmware-skills/VMware-Storage) (iSCSI/vSAN), [vmware-vks](https://github.com/vmware-skills/VMware-VKS) (Tanzu Kubernetes), [vmware-nsx](https://github.com/vmware-skills/VMware-NSX) (N_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "vmware-avi",
"version": "1.11.0",
"publishedAt": 1789915951488
}references/agent-guardrails.md
# Operating vmware-avi with a local / small model
Claude-class models drive this skill without special instruction. Smaller and
locally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served
through Goose, Ollama, or OpenShift AI — need explicit operating rules to call
tools reliably.
This page exists because an operator wrote those rules by hand first. The
guardrails below are adapted, with thanks, from the working configuration
[@juanpf-ha](https://github.com/juanpf-ha) developed while running
vmware-monitor and vmware-aria against a production vSphere estate with Llama
3.3 70B FP8 on an on-prem H100
([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The
cross-skill rules are identical across this family; the parts below marked
vmware-avi are specific to this skill.
vmware-avi exposes 28 MCP tools, 6 of which change state. It straddles two
control planes — the AVI Controller and a Kubernetes cluster running AKO — and
most of the trouble a small model gets into here comes from confusing which
side of that boundary an object lives on.
> **Disclaimer**: This is a community-maintained open-source project and is
> **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom
> Inc.** "VMware" and "vSphere" are trademarks of Broadcom.
---
## First: the rules you no longer need to write
Several guardrails from the original configuration are now enforced by the
skill itself. Prompt instructions are advisory — a model can ignore them.
These are structural, so it cannot.
| Guardrail you would otherwise prompt for | Now enforced by |
|---|---|
| "Log every state change you make" | **The `@vmware_tool` decorator.** Every write is recorded to `~/.vmware/audit.db` before the model sees the result, and policy rules are evaluated ahead of execution. |
| "Convert time windows into the units the API expects" | **The ops layer does the conversion.** Analytics duration accepts either an integer of seconds or a shorthand suffix (`30m`, `24h`, `7d`); the model does not have to know the controller wants seconds. |
| "Use the controller's IP, not its hostname" | **The connection layer resolves it.** Some analytics endpoints reject a hostname; the FQDN is resolved to an address before the SDK sees it. |
Note the one guardrail this skill does **not** hand you: vmware-avi's list tools
return bare collections, not the family `{items, returned, limit, total,
truncated, hint}` envelope. Truncation is therefore not self-declaring here, so
the "report every item" and "state the limit you used" rules below carry more
weight than they do in the rest of the family.
---
## The system prompt
Everything below still benefits from being stated explicitly. Copy this into
your agent's instruction block.
```text
## Tool use
- Always call an MCP tool before answering any question about the current AVI
or AKO environment. Never answer from memory or assumption.
- Never describe a tool call, and never output a JSON examplreferences/capabilities.md
# VMware AVI Capabilities All 28 MCP tools exposed by `vmware-avi mcp` (v1.5.15+; legacy entry point: `vmware-avi-mcp`), organized by category. ## Version Compatibility ### AVI Controller (NSX ALB) | Controller Version | Support Level | Notes | |--------------------|--------------|-------| | AVI 30.x | ✅ Full | All 28 tools verified. avisdk `<31.0` upper bound. | | AVI 22.1.x | ✅ Full | All analytics endpoint quirks fixed in v1.5.11 — `vs_analytics` uses POST `/analytics/metrics/collection` with `metric_requests[]`; `pool_list` uses `/virtualservice-inventory` to expose K8S-managed pool groups; SE→VS mapping reconstructed from `vip_summary[].service_engine[]`. | | AVI < 22.1 | ⚠ Untested | avisdk may load but analytics/inventory endpoints differ. Not in CI. | ### VCF (VMware Cloud Foundation) | VCF Version | Bundled AVI / NSX ALB | Support | |-------------|-----------------------|---------| | VCF 9.1 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) | | VCF 9.0 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) | | VCF 5.x | AVI 22.x | ✅ Full | ### Runtime | Requirement | Version | Notes | |-------------|---------|-------| | Python | ≥ 3.11 | `requires-python` bumped from 3.10 to 3.11 in v1.5.19 (regression eval uses `tomllib`). | | avisdk | ≥ 22.1, < 31.0 | Auto-installed. Range chosen so VCF 9.x bundled AVI is covered without forcing a major SDK jump. | | kubernetes (Python) | ≥ 28.0 | Required only for AKO mode. | | kubectl | any recent | Required only for AKO operations. | | helm | ≥ 3.x | Required only for AKO config show/diff/upgrade. | ### MCP Transport | Mode | Status | Recommended | |------|--------|-------------| | `vmware-avi mcp` (CLI subcommand, stdio) | ✅ Full | ✅ v1.5.15+ default — no PyPI re-resolve, works behind corporate TLS proxies. | | `vmware-avi-mcp` (legacy console script, stdio) | ✅ Full | Kept for backward compatibility with pre-1.5.15 configs. | | `python -m vmware_avi.mcp_server` (stdio, via `__main__.py`) | ✅ Full | Docker image `CMD` only — not for end-user CLI install, and no longer used by `smithery.yaml` (which now calls the `vmware-avi mcp` entry point). Added v1.5.22. | | `uvx --from vmware-avi==1.11.0 vmware-avi-mcp` | ⚠ Fallback | Re-resolves PyPI on each launch; fails behind corporate TLS proxies (踩坑 #25). Use `UV_NATIVE_TLS=true` workaround. | ## Automation Level Reference Each operation is classified by autonomy level per the Enterprise Harness Engineering framework: | Level | Meaning | Agent autonomy | Examples in this skill | |:-:|---|---|---| | **L1** | Read-only, raw data | Always auto-run | `vs_list`, `vs_status`, `pool_list`, `pool_members`, `se_list`, `se_health`, `vs_analytics` queries, AKO/AMKO inventory (`ako_status`, `ako_clusters`, `ako_amko_status`) | | **L2** | Read + analysis / recommendation | Always auto-run | traffic distribution analysis, health score correlation, pool member ratio summaries, analytics-driven anomaly detection | | **L3**
references/cli-reference.md
# VMware AVI CLI Reference Complete command reference for the `vmware-avi` CLI (v1.4.0). ## Global Commands | Command | Description | Flags | |---------|-------------|-------| | `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- | | `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- | | `vmware-avi config` | Show current configuration (passwords masked) | -- | ## Virtual Service Commands (`vmware-avi vs`) | Command | Description | Arguments / Flags | |---------|-------------|-------------------| | `vmware-avi vs list` | List all Virtual Services | `--controller <name>` (optional, use a specific controller) | | `vmware-avi vs status <name>` | Show VS status details (VIP, health, pool binding) | `<name>` (required) | | `vmware-avi vs enable <name>` | Enable a Virtual Service | `<name>` (required) | | `vmware-avi vs disable <name>` | Disable a Virtual Service | `<name>` (required). **Double-confirm required.** | ## Pool Member Commands (`vmware-avi pool`) | Command | Description | Arguments / Flags | |---------|-------------|-------------------| | `vmware-avi pool members <pool>` | List pool members and health status | `<pool>` (required) | | `vmware-avi pool enable <pool> <server-ip>` | Enable a pool member (restore traffic) | `<pool>` (required), `<server-ip>` (required) | | `vmware-avi pool disable <pool> <server-ip>` | Disable a pool member (graceful drain) | `<pool>` (required), `<server-ip>` (required). **Double-confirm required.** | ## SSL Certificate Commands (`vmware-avi ssl`) | Command | Description | Arguments / Flags | |---------|-------------|-------------------| | `vmware-avi ssl list` | List all SSL certificates | -- | | `vmware-avi ssl expiry` | Check certificates expiring within N days | `--days <N>` (default: 30) | ## Service Engine Commands (`vmware-avi se`) | Command | Description | Arguments / Flags | |---------|-------------|-------------------| | `vmware-avi se list` | List all Service Engines: name, mgmt IP, operational status, SE group (status from the `serviceengine-inventory` endpoint, config + runtime merged) | -- | | `vmware-avi se health` | Check Service Engine health: per-SE operational status + connected-VS counts (placement map from `virtualservice-inventory`) | -- | ## Analytics Commands | Command | Description | Arguments / Flags | |---------|-------------|-------------------| | `vmware-avi analytics <vs-name>` | Show VS analytics: L4 bandwidth/connections + L7 client transaction latency (`l7_client.avg_client_txn_latency`), response errors, total responses | `<vs-name>` (required) | | `vmware-avi logs <vs-name>` | Show VS request error logs (HTTP status ≥ 400, filter `ge(response_code,400)`) | `<vs-name>` (required), `--since <range>` (default: `1h`, e.g. `30m`, `2h`) | ## AKO Pod Commands (`vmware-avi ako`) | Command | Description | Arguments / Flags | |---------|-------------|-------------------| | `v
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/vmware-avi",
"sourceUrl": "https://clawhub.ai/zw008/skills/vmware-avi",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:44:38.555Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T04:44:38.555Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "4.9K downloads",
"href": "https://clawhub.ai/zw008/vmware-avi",
"sourceUrl": "https://clawhub.ai/zw008/vmware-avi",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:44:38.555Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.11.0",
"href": "https://clawhub.ai/zw008/vmware-avi",
"sourceUrl": "https://clawhub.ai/zw008/vmware-avi",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T14:52:31.488Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.11.0",
"description": "MCP instructions now name the configured targets and how to choose one; a config that cannot be read says so instead of falling silent.",
"href": "https://clawhub.ai/zw008/vmware-avi",
"sourceUrl": "https://clawhub.ai/zw008/vmware-avi",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T14:52:31.488Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
