{"id":"8eeeee4d-c51f-42ed-915c-ee20551941a9","entityType":"agent","slug":"clawhub-kcns008-kubernetes","name":"Kubernetes","canonicalUrl":"https://www.xpersona.co/agent/clawhub-kcns008-kubernetes","canonicalPath":"/agent/clawhub-kcns008-kubernetes","generatedAt":"2026-10-09T14:17:13.925Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when: (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis (3) Creating manifests: Deployments, StatefulSets, Services, Ingress, NetworkPolicies, RBAC (4) Security: audits, Pod Security Standards, RBAC, secrets management, vulnerability scanning (5) GitOps: ArgoCD, Flux, Kustomize, Helm, CI/CD pipelines, progressive delivery (6) OpenShift-specific: SCCs, Routes, Operators, Builds, ImageStreams (7) Multi-cloud: AKS, EKS, GKE, ARO, ROSA operations Skill: Kubernetes Owner: kcns008 Summary: Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when: (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis (3) Creating manifests: Deploymen","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.6K downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn7f82v7f3g1dtvm0gm74q016n7zz73v:kubernetes","sourceUrl":"https://clawhub.ai/kcns008/kubernetes","homepage":"https://clawhub.ai/kcns008/kubernetes","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/kcns008/kubernetes","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":67,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No protocol or capability metadata is available."},"protocols":[],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":0,"capabilityMatrix":{"rows":[],"flattenedTokens":""}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":4554,"packageName":null,"latestVersion":"1.0.0","tractionLabel":"4.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-02-28T17:27:00.947Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T17:27:00.947Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T17:27:00.947Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.0","createdAt":"2026-01-26T14:07:08.875Z","changelog":"Kubernetes Skill 1.0.0 — Initial Release - Covers Kubernetes and OpenShift cluster management including operations, troubleshooting, manifest generation, security, and GitOps workflows. - Includes common commands, templates, and bundled scripts for tasks such as node management, upgrades, backup/restore, and health checks. - Provides ready-to-use manifest templates for Deployments, Services, Ingress, NetworkPolicy, and OpenShift Routes. - Offers security guidance (RBAC, PodSecurity, audits) and outlines GitOps tools (ArgoCD, Flux, Helm, Kustomize). - Supports multi-cloud cluster operations for AKS, EKS, GKE, ARO, and ROSA. - Documents tool and platform versions as of January 2026.","fileCount":8,"zipByteSize":14766}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn7f82v7f3g1dtvm0gm74q016n7zz73v:kubernetes","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":[]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T14:17:13.924Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kcns008-kubernetes/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: Kubernetes\n\nOwner: kcns008\n\nSummary: Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when:\n(1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup\n(2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis\n(3) Creating manifests: Deployments, StatefulSets, Services, Ingress, NetworkPolicies, RBAC\n(4) Security: audits, Pod Security Standards, RBAC, secrets management, vulnerability scanning\n(5) GitOps: ArgoCD, Flux, Kustomize, Helm, CI/CD pipelines, progressive delivery\n(6) OpenShift-specific: SCCs, Routes, Operators, Builds, ImageStreams\n(7) Multi-cloud: AKS, EKS, GKE, ARO, ROSA operations\n\nTags: latest:1.0.0\n\nVersion history:\n\nv1.0.0 | 2026-01-26T14:07:08.875Z | auto\n\nKubernetes Skill 1.0.0 — Initial Release\n\n- Covers Kubernetes and OpenShift cluster management including operations, troubleshooting, manifest generation, security, and GitOps workflows.\n- Includes common commands, templates, and bundled scripts for tasks such as node management, upgrades, backup/restore, and health checks.\n- Provides ready-to-use manifest templates for Deployments, Services, Ingress, NetworkPolicy, and OpenShift Routes.\n- Offers security guidance (RBAC, PodSecurity, audits) and outlines GitOps tools (ArgoCD, Flux, Helm, Kustomize).\n- Supports multi-cloud cluster operations for AKS, EKS, GKE, ARO, and ROSA.\n- Documents tool and platform versions as of January 2026.\n\nArchive index:\n\nArchive v1.0.0: 8 files, 14766 bytes\n\nFiles: scripts/argocd-app-sync.sh (2827b), scripts/cluster-health-check.sh (4996b), scripts/generate-manifest.sh (7754b), scripts/node-maintenance.sh (3025b), scripts/pre-upgrade-check.sh (4668b), scripts/security-audit.sh (5703b), SKILL.md (12225b), _meta.json (129b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: kubernetes\ndescription: |\n  Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when:\n  (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup\n  (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis\n  (3) Creating manifests: Deployments, StatefulSets, Services, Ingress, NetworkPolicies, RBAC\n  (4) Security: audits, Pod Security Standards, RBAC, secrets management, vulnerability scanning\n  (5) GitOps: ArgoCD, Flux, Kustomize, Helm, CI/CD pipelines, progressive delivery\n  (6) OpenShift-specific: SCCs, Routes, Operators, Builds, ImageStreams\n  (7) Multi-cloud: AKS, EKS, GKE, ARO, ROSA operations\nmetadata:\n  author: cluster-skills\n  version: \"1.0.0\"\n---\n\n# Kubernetes & OpenShift Cluster Management\n\nComprehensive skill for Kubernetes and OpenShift clusters covering operations, troubleshooting, manifests, security, and GitOps.\n\n## Current Versions (January 2026)\n\n| Platform | Version | Documentation |\n|----------|---------|---------------|\n| **Kubernetes** | 1.31.x | https://kubernetes.io/docs/ |\n| **OpenShift** | 4.17.x | https://docs.openshift.com/ |\n| **EKS** | 1.31 | https://docs.aws.amazon.com/eks/ |\n| **AKS** | 1.31 | https://learn.microsoft.com/azure/aks/ |\n| **GKE** | 1.31 | https://cloud.google.com/kubernetes-engine/docs |\n\n### Key Tools\n\n| Tool | Version | Purpose |\n|------|---------|---------|\n| **ArgoCD** | v2.13.x | GitOps deployments |\n| **Flux** | v2.4.x | GitOps toolkit |\n| **Kustomize** | v5.5.x | Manifest customization |\n| **Helm** | v3.16.x | Package management |\n| **Velero** | 1.15.x | Backup/restore |\n| **Trivy** | 0.58.x | Security scanning |\n| **Kyverno** | 1.13.x | Policy engine |\n\n## Command Convention\n\n**IMPORTANT**: Use `kubectl` for standard Kubernetes. Use `oc` for OpenShift/ARO.\n\n---\n\n## 1. CLUSTER OPERATIONS\n\n### Node Management\n\n```bash\n# View nodes\nkubectl get nodes -o wide\n\n# Drain node for maintenance\nkubectl drain ${NODE} --ignore-daemonsets --delete-emptydir-data --grace-period=60\n\n# Uncordon after maintenance\nkubectl uncordon ${NODE}\n\n# View node resources\nkubectl top nodes\n```\n\n### Cluster Upgrades\n\n**AKS:**\n```bash\naz aks get-upgrades -g ${RG} -n ${CLUSTER} -o table\naz aks upgrade -g ${RG} -n ${CLUSTER} --kubernetes-version ${VERSION}\n```\n\n**EKS:**\n```bash\naws eks update-cluster-version --name ${CLUSTER} --kubernetes-version ${VERSION}\n```\n\n**GKE:**\n```bash\ngcloud container clusters upgrade ${CLUSTER} --master --cluster-version ${VERSION}\n```\n\n**OpenShift:**\n```bash\noc adm upgrade --to=${VERSION}\noc get clusterversion\n```\n\n### Backup with Velero\n\n```bash\n# Install Velero\nvelero install --provider ${PROVIDER} --bucket ${BUCKET} --secret-file ${CREDS}\n\n# Create backup\nvelero backup create ${BACKUP_NAME} --include-namespaces ${NS}\n\n# Restore\nvelero restore create --from-backup ${BACKUP_NAME}\n```\n\n---\n\n## 2. TROUBLESHOOTING\n\n### Health Assessment\n\nRun the bundled script for comprehensive health check:\n```bash\nbash scripts/cluster-health-check.sh\n```\n\n### Pod Status Interpretation\n\n| Status | Meaning | Action |\n|--------|---------|--------|\n| `Pending` | Scheduling issue | Check resources, nodeSelector, tolerations |\n| `CrashLoopBackOff` | Container crashing | Check logs: `kubectl logs ${POD} --previous` |\n| `ImagePullBackOff` | Image unavailable | Verify image name, registry access |\n| `OOMKilled` | Out of memory | Increase memory limits |\n| `Evicted` | Node pressure | Check node resources |\n\n### Debugging Commands\n\n```bash\n# Pod logs (current and previous)\nkubectl logs ${POD} -c ${CONTAINER} --previous\n\n# Multi-pod logs with stern\nstern ${LABEL_SELECTOR} -n ${NS}\n\n# Exec into pod\nkubectl exec -it ${POD} -- /bin/sh\n\n# Pod events\nkubectl describe pod ${POD} | grep -A 20 Events\n\n# Cluster events (sorted by time)\nkubectl get events -A --sort-by='.lastTimestamp' | tail -50\n```\n\n### Network Troubleshooting\n\n```bash\n# Test DNS\nkubectl run -it --rm debug --image=busybox -- nslookup kubernetes.default\n\n# Test service connectivity\nkubectl run -it --rm debug --image=curlimages/curl -- curl -v http://${SVC}.${NS}:${PORT}\n\n# Check endpoints\nkubectl get endpoints ${SVC}\n```\n\n---\n\n## 3. MANIFEST GENERATION\n\n### Production Deployment Template\n\n```yaml\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n  name: ${APP_NAME}\n  namespace: ${NAMESPACE}\n  labels:\n    app.kubernetes.io/name: ${APP_NAME}\n    app.kubernetes.io/version: \"${VERSION}\"\nspec:\n  replicas: 3\n  strategy:\n    type: RollingUpdate\n    rollingUpdate:\n      maxSurge: 1\n      maxUnavailable: 0\n  selector:\n    matchLabels:\n      app.kubernetes.io/name: ${APP_NAME}\n  template:\n    metadata:\n      labels:\n        app.kubernetes.io/name: ${APP_NAME}\n    spec:\n      serviceAccountName: ${APP_NAME}\n      securityContext:\n        runAsNonRoot: true\n        runAsUser: 1000\n        fsGroup: 1000\n        seccompProfile:\n          type: RuntimeDefault\n      containers:\n        - name: ${APP_NAME}\n          image: ${IMAGE}:${TAG}\n          ports:\n            - name: http\n              containerPort: 8080\n          securityContext:\n            allowPrivilegeEscalation: false\n            readOnlyRootFilesystem: true\n            capabilities:\n              drop: [\"ALL\"]\n          resources:\n            requests:\n              cpu: 100m\n              memory: 128Mi\n            limits:\n              cpu: 500m\n              memory: 512Mi\n          livenessProbe:\n            httpGet:\n              path: /healthz\n              port: http\n            initialDelaySeconds: 10\n            periodSeconds: 10\n          readinessProbe:\n            httpGet:\n              path: /ready\n              port: http\n            initialDelaySeconds: 5\n            periodSeconds: 5\n          volumeMounts:\n            - name: tmp\n              mountPath: /tmp\n      volumes:\n        - name: tmp\n          emptyDir: {}\n      affinity:\n        podAntiAffinity:\n          preferredDuringSchedulingIgnoredDuringExecution:\n            - weight: 100\n              podAffinityTerm:\n                labelSelector:\n                  matchLabels:\n                    app.kubernetes.io/name: ${APP_NAME}\n                topologyKey: kubernetes.io/hostname\n```\n\n### Service & Ingress\n\n```yaml\napiVersion: v1\nkind: Service\nmetadata:\n  name: ${APP_NAME}\nspec:\n  selector:\n    app.kubernetes.io/name: ${APP_NAME}\n  ports:\n    - name: http\n      port: 80\n      targetPort: http\n---\napiVersion: networking.k8s.io/v1\nkind: Ingress\nmetadata:\n  name: ${APP_NAME}\n  annotations:\n    nginx.ingress.kubernetes.io/ssl-redirect: \"true\"\nspec:\n  ingressClassName: nginx\n  tls:\n    - hosts:\n        - ${HOST}\n      secretName: ${APP_NAME}-tls\n  rules:\n    - host: ${HOST}\n      http:\n        paths:\n          - path: /\n            pathType: Prefix\n            backend:\n              service:\n                name: ${APP_NAME}\n                port:\n                  name: http\n```\n\n### OpenShift Route\n\n```yaml\napiVersion: route.openshift.io/v1\nkind: Route\nmetadata:\n  name: ${APP_NAME}\nspec:\n  to:\n    kind: Service\n    name: ${APP_NAME}\n  port:\n    targetPort: http\n  tls:\n    termination: edge\n    insecureEdgeTerminationPolicy: Redirect\n```\n\nUse the bundled script for manifest generation:\n```bash\nbash scripts/generate-manifest.sh deployment myapp production\n```\n\n---\n\n## 4. SECURITY\n\n### Security Audit\n\nRun the bundled script:\n```bash\nbash scripts/security-audit.sh [namespace]\n```\n\n### Pod Security Standards\n\n```yaml\napiVersion: v1\nkind: Namespace\nmetadata:\n  name: ${NAMESPACE}\n  labels:\n    pod-security.kubernetes.io/enforce: restricted\n    pod-security.kubernetes.io/audit: baseline\n    pod-security.kubernetes.io/warn: restricted\n```\n\n### NetworkPolicy (Zero Trust)\n\n```yaml\napiVersion: networking.k8s.io/v1\nkind: NetworkPolicy\nmetadata:\n  name: ${APP_NAME}-policy\nspec:\n  podSelector:\n    matchLabels:\n      app.kubernetes.io/name: ${APP_NAME}\n  policyTypes:\n    - Ingress\n    - Egress\n  ingress:\n    - from:\n        - podSelector:\n            matchLabels:\n              app.kubernetes.io/name: frontend\n      ports:\n        - protocol: TCP\n          port: 8080\n  egress:\n    - to:\n        - podSelector:\n            matchLabels:\n              app.kubernetes.io/name: database\n      ports:\n        - protocol: TCP\n          port: 5432\n    # Allow DNS\n    - to:\n        - namespaceSelector: {}\n          podSelector:\n            matchLabels:\n              k8s-app: kube-dns\n      ports:\n        - protocol: UDP\n          port: 53\n```\n\n### RBAC Best Practices\n\n```yaml\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n  name: ${APP_NAME}\n---\napiVersion: rbac.authorization.k8s.io/v1\nkind: Role\nmetadata:\n  name: ${APP_NAME}-role\nrules:\n  - apiGroups: [\"\"]\n    resources: [\"configmaps\"]\n    verbs: [\"get\", \"list\"]\n---\napiVersion: rbac.authorization.k8s.io/v1\nkind: RoleBinding\nmetadata:\n  name: ${APP_NAME}-binding\nsubjects:\n  - kind: ServiceAccount\n    name: ${APP_NAME}\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: Role\n  name: ${APP_NAME}-role\n```\n\n### Image Scanning\n\n```bash\n# Scan image with Trivy\ntrivy image ${IMAGE}:${TAG}\n\n# Scan with severity filter\ntrivy image --severity HIGH,CRITICAL ${IMAGE}:${TAG}\n\n# Generate SBOM\ntrivy image --format spdx-json -o sbom.json ${IMAGE}:${TAG}\n```\n\n---\n\n## 5. GITOPS\n\n### ArgoCD Application\n\n```yaml\napiVersion: argoproj.io/v1alpha1\nkind: Application\nmetadata:\n  name: ${APP_NAME}\n  namespace: argocd\n  finalizers:\n    - resources-finalizer.argocd.argoproj.io\nspec:\n  project: default\n  source:\n    repoURL: ${GIT_REPO}\n    targetRevision: main\n    path: k8s/overlays/${ENV}\n  destination:\n    server: https://kubernetes.default.svc\n    namespace: ${NAMESPACE}\n  syncPolicy:\n    automated:\n      prune: true\n      selfHeal: true\n    syncOptions:\n      - CreateNamespace=true\n```\n\n### Kustomize Structure\n\n```\nk8s/\n├── base/\n│   ├── kustomization.yaml\n│   ├── deployment.yaml\n│   └── service.yaml\n└── overlays/\n    ├── dev/\n    │   └── kustomization.yaml\n    ├── staging/\n    │   └── kustomization.yaml\n    └── prod/\n        └── kustomization.yaml\n```\n\n**base/kustomization.yaml:**\n```yaml\napiVersion: kustomize.config.k8s.io/v1beta1\nkind: Kustomization\nresources:\n  - deployment.yaml\n  - service.yaml\n```\n\n**overlays/prod/kustomization.yaml:**\n```yaml\napiVersion: kustomize.config.k8s.io/v1beta1\nkind: Kustomization\nresources:\n  - ../../base\nnamePrefix: prod-\nnamespace: production\nreplicas:\n  - name: myapp\n    count: 5\nimages:\n  - name: myregistry/myapp\n    newTag: v1.2.3\n```\n\n### GitHub Actions CI/CD\n\n```yaml\nname: Build and Deploy\non:\n  push:\n    branches: [main]\n\njobs:\n  build:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      \n      - name: Build and push image\n        uses: docker/build-push-action@v5\n        with:\n          push: true\n          tags: ${{ secrets.REGISTRY }}/${{ github.event.repository.name }}:${{ github.sha }}\n      \n      - name: Update Kustomize image\n        run: |\n          cd k8s/overlays/prod\n          kustomize edit set image myapp=${{ secrets.REGISTRY }}/${{ github.event.repository.name }}:${{ github.sha }}\n          \n      - name: Commit and push\n        run: |\n          git config user.name \"github-actions\"\n          git config user.email \"github-actions@github.com\"\n          git add .\n          git commit -m \"Update image to ${{ github.sha }}\"\n          git push\n```\n\nUse the bundled script for ArgoCD sync:\n```bash\nbash scripts/argocd-app-sync.sh ${APP_NAME} --prune\n```\n\n---\n\n## Helper Scripts\n\nThis skill includes automation scripts in the `scripts/` directory:\n\n| Script | Purpose |\n|--------|---------|\n| `cluster-health-check.sh` | Comprehensive cluster health assessment with scoring |\n| `security-audit.sh` | Security posture audit (privileged, root, RBAC, NetworkPolicy) |\n| `node-maintenance.sh` | Safe node drain and maintenance prep |\n| `pre-upgrade-check.sh` | Pre-upgrade validation checklist |\n| `generate-manifest.sh` | Generate production-ready K8s manifests |\n| `argocd-app-sync.sh` | ArgoCD application sync helper |\n\nRun any script:\n```bash\nbash scripts/<script-name>.sh [arguments]\n```\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7f82v7f3g1dtvm0gm74q016n7zz73v\",\n  \"slug\": \"kubernetes\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1769436428875\n}","readmeExcerpt":"Skill: Kubernetes Owner: kcns008 Summary: Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when: (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis (3) Creating manifests: Deploymen","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# View nodes\nkubectl get nodes -o wide\n\n# Drain node for maintenance\nkubectl drain ${NODE} --ignore-daemonsets --delete-emptydir-data --grace-period=60\n\n# Uncordon after maintenance\nkubectl uncordon ${NODE}\n\n# View node resources\nkubectl top nodes"},{"language":"bash","snippet":"az aks get-upgrades -g ${RG} -n ${CLUSTER} -o table\naz aks upgrade -g ${RG} -n ${CLUSTER} --kubernetes-version ${VERSION}"},{"language":"bash","snippet":"aws eks update-cluster-version --name ${CLUSTER} --kubernetes-version ${VERSION}"},{"language":"bash","snippet":"gcloud container clusters upgrade ${CLUSTER} --master --cluster-version ${VERSION}"},{"language":"bash","snippet":"oc adm upgrade --to=${VERSION}\noc get clusterversion"},{"language":"bash","snippet":"# Install Velero\nvelero install --provider ${PROVIDER} --bucket ${BUCKET} --secret-file ${CREDS}\n\n# Create backup\nvelero backup create ${BACKUP_NAME} --include-namespaces ${NS}\n\n# Restore\nvelero restore create --from-backup ${BACKUP_NAME}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: kubernetes\ndescription: |\n  Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when:\n  (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup\n  (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis\n  (3) Creating manifests: Deployments, StatefulSets, Services, Ingress, NetworkPolicies, RBAC\n  (4) Security: audits, Pod Security Standards, RBAC, secrets management, vulnerability scanning\n  (5) GitOps: ArgoCD, Flux, Kustomize, Helm, CI/CD pipelines, progressive delivery\n  (6) OpenShift-specific: SCCs, Routes, Operators, Builds, ImageStreams\n  (7) Multi-cloud: AKS, EKS, GKE, ARO, ROSA operations\nmetadata:\n  author: cluster-skills\n  version: \"1.0.0\"\n---\n\n# Kubernetes & OpenShift Cluster Management\n\nComprehensive skill for Kubernetes and OpenShift clusters covering operations, troubleshooting, manifests, security, and GitOps.\n\n## Current Versions (January 2026)\n\n| Platform | Version | Documentation |\n|----------|---------|---------------|\n| **Kubernetes** | 1.31.x | https://kubernetes.io/docs/ |\n| **OpenShift** | 4.17.x | https://docs.openshift.com/ |\n| **EKS** | 1.31 | https://docs.aws.amazon.com/eks/ |\n| **AKS** | 1.31 | https://learn.microsoft.com/azure/aks/ |\n| **GKE** | 1.31 | https://cloud.google.com/kubernetes-engine/docs |\n\n### Key Tools\n\n| Tool | Version | Purpose |\n|------|---------|---------|\n| **ArgoCD** | v2.13.x | GitOps deployments |\n| **Flux** | v2.4.x | GitOps toolkit |\n| **Kustomize** | v5.5.x | Manifest customization |\n| **Helm** | v3.16.x | Package management |\n| **Velero** | 1.15.x | Backup/restore |\n| **Trivy** | 0.58.x | Security scanning |\n| **Kyverno** | 1.13.x | Policy engine |\n\n## Command Convention\n\n**IMPORTANT**: Use `kubectl` for standard Kubernetes. Use `oc` for OpenShift/ARO.\n\n---\n\n## 1. CLUSTER OPERATIONS\n\n### Node Management\n\n```bash\n# View nodes\nkubectl get nodes -o wide\n\n# Drain node for maintenance\nkubectl drain ${NODE} --ignore-daemonsets --delete-emptydir-data --grace-period=60\n\n# Uncordon after maintenance\nkubectl uncordon ${NODE}\n\n# View node resources\nkubectl top nodes\n```\n\n### Cluster Upgrades\n\n**AKS:**\n```bash\naz aks get-upgrades -g ${RG} -n ${CLUSTER} -o table\naz aks upgrade -g ${RG} -n ${CLUSTER} --kubernetes-version ${VERSION}\n```\n\n**EKS:**\n```bash\naws eks update-cluster-version --name ${CLUSTER} --kubernetes-version ${VERSION}\n```\n\n**GKE:**\n```bash\ngcloud container clusters upgrade ${CLUSTER} --master --cluster-version ${VERSION}\n```\n\n**OpenShift:**\n```bash\noc adm upgrade --to=${VERSION}\noc get clusterversion\n```\n\n### Backup with Velero\n\n```bash\n# Install Velero\nvelero install --provider ${PROVIDER} --bucket ${BUCKET} --secret-file ${CREDS}\n\n# Create backup\nvelero backup create ${BACKUP_NAME} --include-namespaces ${NS}\n\n# Restore\nvelero restore create --from-backup ${BACKUP_NAME}\n```\n\n---\n\n## 2. TROUBLESHOOTING\n\n### Hea"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7f82v7f3g1dtvm0gm74q016n7zz73v\",\n  \"slug\": \"kubernetes\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1769436428875\n}"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when: (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis (3) Creating manifests: Deployments, StatefulSets, Services, Ingress, NetworkPolicies, RBAC (4) Security: audits, Pod Security Standards, RBAC, secrets management, vulnerability scanning (5) GitOps: ArgoCD, Flux, Kustomize, Helm, CI/CD pipelines, progressive delivery (6) OpenShift-specific: SCCs, Routes, Operators, Builds, ImageStreams (7) Multi-cloud: AKS, EKS, GKE, ARO, ROSA operations Skill: Kubernetes Owner: kcns008 Summary: Comprehensive Kubernetes and OpenShift cluster management skill covering operations, troubleshooting, manifest generation, security, and GitOps. Use this skill when: (1) Cluster operations: upgrades, backups, node management, scaling, monitoring setup (2) Troubleshooting: pod failures, networking issues, storage problems, performance analysis (3) Creating manifests: Deploymen","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":740,"uniquenessScore":52,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"agent-directory","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:17:13.925Z","emptyReason":"No close protocol neighbors were found."},"items":[],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[]}}}