{"id":"7a14d825-bf5a-4881-a18d-0611b099a976","entityType":"agent","slug":"clawhub-zw008-vmware-avi","name":"vmware-avi","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-vmware-avi","canonicalPath":"/agent/clawhub-zw008-vmware-avi","generatedAt":"2026-10-09T17:31:33.344Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:44:38.555Z","emptyReason":null},"description":"Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context. Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs, service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics, and multi-cluster AKO overview. Always use it for \"virtual service\", \"pool member\", \"AKO status\", \"AKO logs\", \"ingress diagnose\", \"ssl expiry\", \"load balancer\", \"NSX ALB\", \"AVI controller\", \"Avi Load Balancer\", \"AKO sync\", or \"负载均衡\" tasks. Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks. For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-avi","sourceUrl":"https://clawhub.ai/zw008/vmware-avi","homepage":"https://clawhub.ai/zw008/skills/vmware-avi","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zw008/vmware-avi","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zw008/skills/vmware-avi","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":47,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"vmware-avi technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:44:38.555Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:44:38.555Z","emptyReason":null},"stars":null,"forks":null,"downloads":4854,"packageName":null,"latestVersion":"1.11.0","tractionLabel":"4.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:44:38.554Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T04:44:38.555Z","lastCrawledAt":"2026-10-09T04:44:38.554Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T04:44:38.554Z","lastVerifiedAt":null,"highlights":[{"version":"1.11.0","createdAt":"2026-09-20T14:52:31.488Z","changelog":"MCP instructions now name the configured targets and how to choose one; a config that cannot be read says so instead of falling silent.","fileCount":7,"zipByteSize":25796},{"version":"1.10.0","createdAt":"2026-09-19T03:55:06.166Z","changelog":"Destructive MCP tools preview by default (confirm=False) and state their blast radius; confirm=True refuses on blockers or unreadable measurements. Requires vmware-policy>=1.17.0.","fileCount":7,"zipByteSize":25858},{"version":"1.9.1","createdAt":"2026-09-15T06:00:19.598Z","changelog":"CLI reads are audited under their MCP tool names; every CLI command declares what it reaches (needs vmware-policy 1.15.0)","fileCount":7,"zipByteSize":25000},{"version":"1.9.0","createdAt":"2026-09-12T00:15:10.949Z","changelog":"CLI writes are authorised and audited under their MCP tool names (pool enable/disable now carry pool_member_enable / pool_member_disable), and vs enable/disable audit rows record which direction was taken.","fileCount":7,"zipByteSize":24986},{"version":"1.8.15","createdAt":"2026-08-31T07:24:02.816Z","changelog":"one answer per .env, on every platform","fileCount":7,"zipByteSize":24950},{"version":"1.8.14","createdAt":"2026-08-31T00:34:19.210Z","changelog":"fix: run the suite on a non-UTF-8 machine, and stop one skill answering for another","fileCount":7,"zipByteSize":24887},{"version":"1.8.13","createdAt":"2026-08-30T15:19:00.467Z","changelog":"Second-round fixes from the 2026-08-30 VCF 9.1 re-test; vmware-policy floor raised to 1.11.0 (the engine no longer fails open when rules.yaml cannot be read).","fileCount":7,"zipByteSize":25026},{"version":"1.8.12","createdAt":"2026-08-30T09:35:07.869Z","changelog":"helm output carrying credentials no longer stored in the audit database. Parameter descriptions now reach the MCP JSON schema (0% -> 100% coverage); additionalProperties closed; vmware-policy floor raised to 1.10.0.","fileCount":7,"zipByteSize":24917}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-avi","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-avi` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/vmware-avi before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T17:31:33.340Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-avi/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T04:44:38.555Z","emptyReason":null},"readme":"Skill: vmware-avi\n\nOwner: zw008\n\nSummary: Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context. Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs, service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics, and multi-cluster AKO overview. Always use it for \"virtual service\", \"pool member\", \"AKO status\", \"AKO logs\", \"ingress diagnose\", \"ssl expiry\", \"load balancer\", \"NSX ALB\", \"AVI controller\", \"Avi Load Balancer\", \"AKO sync\", or \"负载均衡\" tasks. Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks. For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.\n\nTags: latest:1.11.0\n\nVersion history:\n\nv1.11.0 | 2026-09-20T14:52:31.488Z | user\n\nMCP instructions now name the configured targets and how to choose one; a config that cannot be read says so instead of falling silent.\n\nv1.10.0 | 2026-09-19T03:55:06.166Z | user\n\nDestructive MCP tools preview by default (confirm=False) and state their blast radius; confirm=True refuses on blockers or unreadable measurements. Requires vmware-policy>=1.17.0.\n\nv1.9.1 | 2026-09-15T06:00:19.598Z | user\n\nCLI reads are audited under their MCP tool names; every CLI command declares what it reaches (needs vmware-policy 1.15.0)\n\nv1.9.0 | 2026-09-12T00:15:10.949Z | user\n\nCLI writes are authorised and audited under their MCP tool names (pool enable/disable now carry pool_member_enable / pool_member_disable), and vs enable/disable audit rows record which direction was taken.\n\nv1.8.15 | 2026-08-31T07:24:02.816Z | user\n\none answer per .env, on every platform\n\nv1.8.14 | 2026-08-31T00:34:19.210Z | user\n\nfix: run the suite on a non-UTF-8 machine, and stop one skill answering for another\n\nv1.8.13 | 2026-08-30T15:19:00.467Z | user\n\nSecond-round fixes from the 2026-08-30 VCF 9.1 re-test; vmware-policy floor raised to 1.11.0 (the engine no longer fails open when rules.yaml cannot be read).\n\nv1.8.12 | 2026-08-30T09:35:07.869Z | user\n\nhelm output carrying credentials no longer stored in the audit database. Parameter descriptions now reach the MCP JSON schema (0% -> 100% coverage); additionalProperties closed; vmware-policy floor raised to 1.10.0.\n\nv1.8.11 | 2026-08-30T07:46:04.449Z | user\n\nPolicy rules were scoped from a different config file than the operations they gated; one resolve_config_path across loader, tools and doctor; server.json starts the MCP server.\n\nv1.8.10 | 2026-08-28T02:53:36.601Z | user\n\nFixes the server's self-reported version and the advertised tool count; adds a Claude Code plugin manifest.\n\nv1.8.9 | 2026-08-01T03:10:28.922Z | user\n\nMoved to vmware-skills GitHub org; MCP Registry namespace → io.github.vmware-skills. Links updated.\n\nv1.8.8 | 2026-07-21T15:45:20.878Z | user\n\nCLI writes now route through the shared guard()+audit_call() core via @guarded, exactly like the MCP tools (HLD I-1/I-8). Requires vmware-policy>=1.8.8.\n\nv1.8.7 | 2026-07-21T11:42:01.982Z | user\n\nRemove read-only switch and approval tiers; read/write authz delegated to RBAC. Plus accumulated fixes since 1.8.5.\n\nv1.8.5 | 2026-07-20T13:06:41.362Z | user\n\nA failure that is returned is now audited as a failure, and certificate/URL detail no longer reaches the agent. Both fixes v1.8.4 announced were incomplete.\n\nv1.8.4 | 2026-07-20T08:27:19.126Z | user\n\nTeaching error messages, domain exceptions no longer redacted on the way to the agent, and tool descriptions that state when to use each tool and what to call next.\n\nv1.8.3 | 2026-07-20T03:49:23.800Z | user\n\nPer-target username can now come from an env var, resolved per access like the password; documented credential variables corrected against what each repo's code actually reads\n\nv1.8.2 | 2026-07-19T18:09:29.378Z | user\n\nMCP server moved into the package namespace — fixes two skills in one environment silently overwriting each other's server; agent-guardrails.md for local/small models now ships in every skill\n\nv1.8.1 | 2026-07-19T11:30:55.768Z | user\n\nRead-only mode now documented on every surface that teaches it (SKILL.md, setup-guide, capabilities) and reported by doctor\n\nv1.8.0 | 2026-07-19T09:48:55.368Z | user\n\nRead-only mode (6 write tools withheld), declared environments; ako_config_diff now previews what ako_config_upgrade applies (--reuse-values) and both accept chart_version\n\nv1.7.5 | 2026-07-13T07:16:56.594Z | user\n\nstyle-only lint cleanup; family version alignment\n\nv1.7.4 | 2026-07-13T04:52:36.468Z | user\n\nFamily version alignment to 1.7.4 (substantive change this cycle is in vmware-monitor: host-check boundary read batching).\n\nv1.7.3 | 2026-07-03T00:48:54.552Z | user\n\nFamily version alignment (v1.7.3)\n\nv1.7.2 | 2026-07-02T14:31:26.065Z | user\n\nEliminate pool/ingress N+1 + honest pagination\n\nv1.7.1 | 2026-07-02T10:52:48.793Z | user\n\nFamily version alignment with v1.7.1 (AIops/Monitor large-inventory scale fix, issue #31).\n\nv1.7.0 | 2026-06-27T01:01:47.640Z | user\n\nguided init wizard (replace plaintext init) + read/write auth teaching\n\nv1.6.1 | 2026-06-24T00:01:16.119Z | user\n\nv1.6.1 .env password b64 obfuscation\n\nv1.6.0 | 2026-06-22T09:17:42.767Z | user\n\nv1.6.0 trust architecture: undo tokens + governance harness (budget/audit/risk-tiers)\n\nv1.5.39 | 2026-06-22T00:42:43.239Z | user\n\nv1.5.39: AIops snapshot-delete async + honest timeout (token-burn fix), Storage browse timeout fix; others version-aligned\n\nv1.5.38 | 2026-06-12T06:59:08.403Z | user\n\nrelease alignment\n\nv1.5.37 | 2026-06-12T01:58:05.122Z | user\n\nbacklog: AKO sync-diff accuracy\n\nv1.5.36 | 2026-06-11T23:21:33.935Z | user\n\nAKO release-blocker fix, honest write results, error translation\n\nv1.5.35 | 2026-06-10T00:44:45.991Z | user\n\nSecurity hardening: safe error handling, TLS/path/permission fixes\n\nv1.5.32 | 2026-06-08T02:47:47.615Z | user\n\nv1.5.32: metric/field corrections + AKO helm OCI + AMKO discovery\n\nv1.5.30 | 2026-06-07T13:23:45.313Z | user\n\nv1.5.30: Glama TDQS tool description quality rewrite\n\nv1.5.29 | 2026-05-29T02:19:36.772Z | user\n\nVersion compatibility table (AVI 22.x, VCF 9.0/9.1); Smithery+Docker deployment section; setup-guide refresh\n\nv1.5.28 | 2026-05-20T10:00:33.080Z | user\n\nFix subclass() arg 1 must be a class in goose/old-mcp environments. v1.5.25-1.5.27 only addressed PEP 604 X|None -> Optional[X] but kept 'from __future__ import annotations'; under mcp 1.10-1.13 FastMCP's issubclass() on string annotations crashed server load. This release removes the future import. CLAUDE.md pitfall #33 updated.\n\nv1.5.27 | 2026-05-20T06:56:51.468Z | user\n\nLoosen Python requirement to >= 3.10 (was >=3.11). v1.5.25/26 PEP 604 fix already enables 3.10 at runtime; this release lifts pip download/install block.\n\nv1.5.26 | 2026-05-20T06:17:06.035Z | user\n\nMCP server Python 3.10 compatibility (踩坑 #33): PEP 604 X|None → Optional[X] in tool signatures; mcp_cmd Python version guard; mcp[cli]>=1.10\n\nv1.5.23 | 2026-05-19T02:58:40.981Z | user\n\nVCF 9.0 / 9.1 compatibility declared. README version-compat tables updated. Added Official Broadcom References (VCF Python SDK, REST APIs, CLI tools).\n\nv1.5.22 | 2026-05-08T23:25:20.818Z | user\n\nv1.5.22 — Smithery onboarding (Dockerfile + smithery.yaml)\n\nv1.5.21 | 2026-05-08T23:20:45.884Z | user\n\nv1.5.21 family alignment + python-multipart 0.0.27\n\nv1.5.20 | 2026-05-08T22:40:07.080Z | user\n\nv1.5.20 family alignment + MCP Registry mcp-name markers\n\nv1.5.19 | 2026-05-06T04:03:22.902Z | user\n\nv1.5.19 — yjs review fixes: NSX CLI subcommand imports (CRITICAL), VKS delete_tkc_cluster ApiClient leak, Harden Twin snapshot_id indexes + LEFT JOIN report, Policy approval gate + singleton lock; py3.11+ requirement; family_smoke recursive subcommand smoke.\n\nv1.5.18 | 2026-05-02T12:11:43.620Z | user\n\nv1.5.18 — family alignment + tooling normalization. Migrated dev deps to [dependency-groups] (PEP 735); added regression eval suite (tests/eval/regression/) catching v1.5.x release blockers.\n\nv1.5.17 | 2026-05-01T11:47:16.157Z | user\n\nv1.5.17 - Family alignment with vmware-pilot v1.5.17 (review_workflow + investigate_alert) and vmware-policy v1.5.17 (L5 pattern matcher). No source changes in this skill.\n\nv1.5.16 | 2026-05-01T03:31:27.647Z | user\n\nv1.5.16 - Enterprise Harness Engineering alignment: 5-level automation taxonomy (L1-L5) in capabilities.md, expert judgment encoded into Common Workflows pre-flight sections, causal-chain investigation protocol shared across aria/monitor/aiops, family version bump.\n\nv1.5.15 | 2026-04-29T18:29:44.724Z | user\n\nv1.5.15: single-command MCP entry point (vmware-avi mcp), verify_ssl default true. Legacy entry point kept for backward compat.\n\nv1.5.14 | 2026-04-21T12:20:39.901Z | user\n\nv1.5.14: code review fixes by @yjs-2026 + Snyk E005 disclaimer\n\nv1.5.12 | 2026-04-17T10:05:20.759Z | user\n\nSecurity & bug fixes from @yjs-2026 code review\n\nv1.5.11 | 2026-04-16T23:40:05.182Z | user\n\n4 AVI 22.x fixes from @timwangbc: analytics POST, error_logs UUID, pool_list inventory, se_health VS count\n\nArchive index:\n\nArchive v1.11.0: 7 files, 25796 bytes\n\nFiles: references/agent-guardrails.md (8702b), references/capabilities.md (13081b), references/cli-reference.md (6579b), references/setup-guide.md (13936b), skill-card.md (2745b), SKILL.md (16577b), _meta.json (130b)\n\nFile v1.11.0:SKILL.md\n\n---\nname: vmware-avi\ndescription: >\n  Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery\n  in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context.\n  Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs,\n  service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics,\n  and multi-cluster AKO overview.\n  Always use it for \"virtual service\", \"pool member\", \"AKO status\", \"AKO logs\", \"ingress diagnose\", \"ssl expiry\", \"load balancer\", \"NSX ALB\",\n  \"AVI controller\", \"Avi Load Balancer\", \"AKO sync\", or \"负载均衡\" tasks.\n  Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks.\n  For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.\ninstaller:\n  kind: uv\n  package: vmware-avi\nargument-hint: \"[vs-name, ako command, or describe your task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"vmware-avi\",\"uvx\"]},\"optional\":{\"env\":[\"VMWARE_AVI_CONFIG\",\"<CONTROLLER>_PASSWORD\",\"<CONTROLLER>_USERNAME\",\"KUBECONFIG\",\"VMWARE_AUDIT_APPROVED_BY\"],\"bins\":[\"vmware-policy\",\"kubectl\",\"helm\"]},\"homepage\":\"https://github.com/vmware-skills/VMware-AVI\",\"emoji\":\"🔀\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.\n  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller \"prod-avi\" → PROD_AVI_PASSWORD).\n  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.\n---\n\n# VMware AVI\n\n> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** \"VMware\", \"NSX\", and \"AVI\" are trademarks of Broadcom. Source code is publicly auditable at [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI) under the MIT license.\n\nAVI (NSX Advanced Load Balancer) application delivery and AKO Kubernetes operations — 28 MCP tools.\n\n> **Dual mode**: Traditional AVI Controller management + AKO K8s operations in one skill.\n> **Family**: [vmware-aiops](https://github.com/vmware-skills/VMware-AIops) (VM lifecycle), [vmware-monitor](https://github.com/vmware-skills/VMware-Monitor) (inventory/health), [vmware-storage](https://github.com/vmware-skills/VMware-Storage) (iSCSI/vSAN), [vmware-vks](https://github.com/vmware-skills/VMware-VKS) (Tanzu Kubernetes), [vmware-nsx](https://github.com/vmware-skills/VMware-NSX) (NSX networking), [vmware-nsx-security](https://github.com/vmware-skills/VMware-NSX-Security) (DFW/firewall), [vmware-aria](https://github.com/vmware-skills/VMware-Aria) (metrics/alerts/capacity), [vmware-harden](https://github.com/vmware-skills/VMware-Harden) (compliance baselines).\n> | [vmware-pilot](../vmware-pilot/SKILL.md) (workflow orchestration) | [vmware-policy](../vmware-policy/SKILL.md) (audit/policy)\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Virtual Service** | list, status, enable/disable | 3 | 2R / 1W |\n| **Pool Member** | pool discovery, member list, enable/disable member (drain/restore traffic) | 4 | 2R / 2W |\n| **SSL Certificate** | list, expiry check | 2 | 2R |\n| **Analytics** | VS metrics overview, request error logs | 2 | 2R |\n| **Service Engine** | list, health check | 2 | 2R |\n| **AKO Pod Ops** | status, logs, restart, version info | 4 | 3R / 1W |\n| **AKO Config** | values.yaml view, Helm diff, Helm upgrade | 3 | 2R / 1W |\n| **Ingress Diagnostics** | annotation validation, VS mapping, error diagnosis (with fix recommendations) | 3 | 3R |\n| **Sync Diagnostics** | K8s-Controller comparison, inconsistency list, force resync | 3 | 2R / 1W |\n| **Multi-cluster** | cross-cluster AKO cluster list, AMKO status | 2 | 2R |\n\n**Total**: 28 tools (22 read + 6 write)\n\n## Quick Install\n\n```bash\nuv tool install vmware-avi==1.11.0\nvmware-avi doctor            # checks Controller connectivity + kubeconfig + avisdk\n```\n\n## When to Use This Skill\n\n- List, enable, or disable virtual services on AVI Controller\n- Add, remove, drain, or restore pool members (maintenance windows, rolling deployments)\n- Check SSL certificate expiry across all virtual services\n- View VS analytics — throughput, latency, error rates, request logs\n- Check service engine status (inventory-based) and per-SE VS placement counts\n- Troubleshoot AKO pods — status, logs, restarts\n- Manage AKO Helm configuration — view, diff, upgrade values.yaml\n- Validate Ingress annotations and diagnose why a VS wasn't created as expected\n- Detect sync drift between K8s resources and AVI Controller objects\n- Get a cross-cluster view of AKO deployments and AMKO status\n\n**Use companion skills for**:\n- VM lifecycle, deployment, guest ops → `vmware-aiops`\n- NSX segments, gateways, NAT → `vmware-nsx`\n- DFW firewall rules, security groups → `vmware-nsx-security`\n- K8s cluster lifecycle (Supervisor, TKC) → `vmware-vks`\n- Read-only vSphere monitoring → `vmware-monitor`\n\n## Related Skills — Skill Routing\n\n| User Intent | Recommended Skill |\n|-------------|------------------|\n| Load balancer, VS, pool, AVI, ALB, AKO | **vmware-avi** ← this skill |\n| VM lifecycle, deployment, guest ops | **vmware-aiops** (`uv tool install vmware-aiops`) |\n| Read-only vSphere monitoring | **vmware-monitor** (`uv tool install vmware-monitor`) |\n| Storage: iSCSI, vSAN, datastores | **vmware-storage** (`uv tool install vmware-storage`) |\n| NSX networking: segments, gateways, NAT | **vmware-nsx** (`uv tool install vmware-nsx-mgmt`) |\n| NSX security: DFW rules, security groups | **vmware-nsx-security** (`uv tool install vmware-nsx-security`) |\n| Tanzu Kubernetes (Supervisor/TKC) | **vmware-vks** (`uv tool install vmware-vks`) |\n| Aria Ops: metrics, alerts, capacity | **vmware-aria** (`uv tool install vmware-aria`) |\n| Multi-step workflows with approval | **vmware-pilot** |\n| Compliance baselines (CIS / 等保 / PCI-DSS), drift detection, LLM remediation advisor | **vmware-harden** (`uv tool install vmware-harden`) |\n| Audit log query | **vmware-policy** (`vmware-audit` CLI) |\n\n## Common Workflows\n\n### Maintenance Window — Drain a Pool Member\n\n**Pre-flight (judgment — affects live traffic)**:\n- Capacity check: pool must have ≥ 2 healthy members. Disabling the only-other-healthy member is a self-DoS. Verify with `pool members my-pool` first.\n- Connection persistence: if VS uses session persistence (cookie/source-IP), existing sessions stay pinned to the disabled member until they expire. \"Drain\" is not instant — 5-30 min depending on persistence TTL.\n- Long-lived connections: WebSocket/streaming sessions can hold for hours. Decide upfront: hard-disconnect (faster, user-visible) or wait (slower, transparent).\n- Observability: enable analytics on the VS BEFORE disabling — you need the baseline to detect degradation.\n\n**Steps**:\n1. `pool members my-pool` → confirm ≥ 2 healthy members and identify session persistence config\n2. `pool disable my-pool <server-ip>` (graceful drain — new connections stop, existing finish)\n3. `analytics my-vs --duration 15m` → watch active connection count to the drained member trend toward zero\n4. Perform maintenance only after active connections = 0 (or you've decided to hard-disconnect)\n5. `pool enable my-pool <server-ip>` → re-enable\n6. **Verify** before declaring success: health monitor passes (typically 30-90 sec) AND new connections are landing on the member (analytics drill-down)\n\n### AKO Ingress Not Creating VS\n\n**Judgment**: this is a layered failure — figure out which layer broke before randomly probing. AKO is a controller; like all K8s controllers, the failure modes are: (a) controller down, (b) controller running but seeing wrong inputs, (c) controller acting but Avi rejecting outputs.\n\n1. `ako status` → controller running, recent reconciles, no panic logs? If not, fix here first\n2. `ako ingress check <namespace>` → required annotations present? Common miss: `kubernetes.io/ingress.class`, `aviinfrasetting.ako.vmware.com/name`\n3. `ako sync status` → drift between K8s state and Avi state. Drift > a few minutes usually means controller error\n4. `ako ingress diagnose <ingress-name>` → AKO's own diagnostic; often pinpoints the issue\n5. If sync drifted: `ako sync diff` → review what's missing on Avi side. **Force resync only after** you understand why drift happened — blind resync masks bugs that will recur\n\n### SSL Certificate Expiry Audit\n\n**Judgment**: cert expiry is the most preventable outage in the LB world. Run this regularly, not reactively. The 30-day window is a minimum — for prod, set 60+ to allow renewal lead time.\n\n1. `ssl expiry --days 60` → catch certs expiring within 60 days, not 30; enterprise renewal cycles take 2-4 weeks\n2. Cross-reference VS mapping (in output) → identify which apps are at risk; some certs may be unused (orphans, candidates for cleanup)\n3. **Decision**: certs marked `unused` (no VS) → propose deletion as part of audit; certs `in_use` → escalate to cert team with VS list and exact expiry date\n4. Schedule a follow-up rescan post-renewal (not just rely on cert team confirming)\n\n## Usage Mode\n\n| Scenario | Recommended | Why |\n|----------|:-----------:|-----|\n| Local/small models (Ollama, Qwen) | **CLI** | ~2K tokens vs ~8K for MCP |\n| Cloud models (Claude, GPT-4o) | Either | MCP gives structured JSON I/O |\n| Automated pipelines | **MCP** | Type-safe parameters, structured output |\n| AKO troubleshooting | **CLI** | Interactive log tailing, Helm diff output |\n\n## MCP Tools (28 — 22 read, 6 write)\n\n| Category | Tools | R/W |\n|----------|-------|:---:|\n| Virtual Service (3) | `vs_list`, `vs_status` | Read |\n| | `vs_toggle` | Write |\n| Pool Member (4) | `pool_list`, `pool_members` | Read |\n| | `pool_member_enable`, `pool_member_disable` | Write |\n| SSL Certificate (2) | `ssl_list`, `ssl_expiry_check` | Read |\n| Analytics (2) | `vs_analytics`, `vs_error_logs` | Read |\n| Service Engine (2) | `se_list`, `se_health` | Read |\n| AKO Pod (4) | `ako_status`, `ako_logs`, `ako_version` | Read |\n| | `ako_restart` | Write |\n| AKO Config (3) | `ako_config_show`, `ako_config_diff` | Read |\n| | `ako_config_upgrade` | Write |\n| Ingress Diagnostics (3) | `ako_ingress_check`, `ako_ingress_map`, `ako_ingress_diagnose` | Read |\n| Sync Diagnostics (3) | `ako_sync_status`, `ako_sync_diff` | Read |\n| | `ako_sync_force` | Write |\n| Multi-cluster (2) | `ako_clusters`, `ako_amko_status` | Read |\n\n**Read/write split**: 22 tools are read-only, 6 modify state, all audit-logged. Five of them (`vs_toggle`, `pool_member_disable`, `ako_restart`, `ako_sync_force`, `ako_config_upgrade`) take `confirm` (default `false`): a bare call returns a `blast_radius` and changes nothing.\n\n## CLI Quick Reference\n\n```bash\n# === Traditional Mode (AVI Controller) ===\nvmware-avi vs list [--controller <name>]\nvmware-avi vs status <vs-name>\nvmware-avi vs enable <vs-name>\nvmware-avi vs disable <vs-name>           # double-confirm\n\nvmware-avi pool members <pool-name>\nvmware-avi pool enable <pool> <server-ip>\nvmware-avi pool disable <pool> <server-ip>  # double-confirm (graceful drain)\n\nvmware-avi ssl list\nvmware-avi ssl expiry [--days 30]\n\nvmware-avi analytics <vs-name>\nvmware-avi logs <vs-name> [--since 1h]\n\nvmware-avi se list\nvmware-avi se health\n\n# === AKO Mode (K8s) ===\nvmware-avi ako status [--context <k8s-context>]\nvmware-avi ako logs [--tail 100] [--since 30m]\nvmware-avi ako restart                    # double-confirm\n\nvmware-avi ako config show\nvmware-avi ako config diff\nvmware-avi ako config upgrade             # double-confirm + --dry-run default\n\nvmware-avi ako ingress check <namespace>\nvmware-avi ako ingress map\nvmware-avi ako ingress diagnose <ingress-name>\n\nvmware-avi ako sync status\nvmware-avi ako sync diff\nvmware-avi ako sync force                 # double-confirm\n\nvmware-avi ako clusters\nvmware-avi ako amko status\n```\n\n> Full CLI reference: see `references/cli-reference.md`\n\n## Troubleshooting\n\n### \"Controller unreachable\" error\n1. Run `vmware-avi doctor` to verify connectivity\n2. Check if the controller address and port are correct in `~/.vmware-avi/config.yaml`\n3. For self-signed certs: set `verify_ssl: false` in config.yaml (lab environments only)\n\n### AKO Pod in CrashLoopBackOff\n1. Check logs → `vmware-avi ako logs --tail 50`\n2. Common causes: wrong controller IP in values.yaml, network policy blocking AKO→Controller, expired credentials\n3. Fix config → `vmware-avi ako config show` to inspect, then `vmware-avi ako config upgrade` with corrected values (release auto-discovered — official installs use `--generate-name`; pulls the official Broadcom OCI chart `oci://projects.packages.broadcom.com/ako/helm-charts/ako`)\n\n### Ingress created but no VS on Controller\n1. Validate annotations → `vmware-avi ako ingress check <namespace>`\n2. Check AKO logs for rejection reason → `vmware-avi ako logs --since 5m`\n3. Run sync diff → `vmware-avi ako sync diff` to see if the object is stuck\n\n### Pool member shows \"down\" after enable\nHealth monitor may still be failing. Check the actual health status on the Controller side — the member is enabled but unhealthy. Fix the backend service first, then the health status will auto-recover.\n\n### SSL expiry check shows 0 certificates\nVerify the controller connection has tenant-level access. Certificates are tenant-scoped in AVI — the configured user may only see certs in their tenant.\n\n### AKO sync force has no effect\nForce resync triggers AKO to re-reconcile all K8s objects. If the drift persists, the issue is likely in the K8s resource definition itself (bad annotation, missing secret). Use `vmware-avi ako ingress diagnose` to pinpoint the root cause.\n\n## Setup\n\n```bash\nuv tool install vmware-avi==1.11.0\nmkdir -p ~/.vmware-avi\nvmware-avi init              # generates config.yaml and .env templates\nchmod 600 ~/.vmware-avi/.env\nvmware-avi doctor            # verify Controller + K8s connectivity\n```\n\n> All tools are automatically audited via vmware-policy. Audit logs: `vmware-audit log --last 20`\n\n**Supported versions**: AVI Controller 22.1.x (analytics endpoint quirks fixed in v1.5.11) and 30.x. VCF 9.0 / 9.1 declared compatible (avisdk `>=22.1,<31.0` covers bundled AVI). Python 3.11+. Full table: `references/capabilities.md` → Version Compatibility.\n\n> Full setup guide, security details, AI platform compatibility, and container/Smithery deployment: see `references/setup-guide.md`\n\n## Audit & Safety\n\nAll operations are automatically audited via vmware-policy (`@vmware_tool` decorator):\n- Every tool call logged to `~/.vmware/audit.db` (SQLite, framework-agnostic)\n- Policy rules enforced via `~/.vmware/rules.yaml` (deny rules, maintenance windows, risk levels)\n- Each controller may declare `environment:` in `config.yaml` (`production` / `staging` / `lab`) as an optional label; an environment-scoped `deny` rule in `~/.vmware/rules.yaml` can match on it to block writes (e.g. freeze `production`). A controller with no label is simply not matched by such a rule. Reads are never affected\n- MCP: `vs_toggle`, `pool_member_disable`, `ako_restart`, `ako_sync_force` and `ako_config_upgrade` preview by default. Without `confirm=true` they return `blast_radius` — the VS or pool with its member counts, the AKO pod and the Ingresses it programs, or the Helm release and the chart it would move to — and change nothing. Show it to the user; do not pass `confirm=true` on your own because they asked earlier. `confirm=true` is refused when a blocker is found (the pool's only enabled member, a terminating AKO pod, a failing `helm upgrade --dry-run`) or a field could not be read. `confirmed` and `dry_run` are deprecated aliases\n- CLI: destructive commands require double confirmation; `vmware-avi ako config upgrade` defaults to `--dry-run`\n- View recent operations: `vmware-audit log --last 20`\n\n## License\n\nMIT — [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI)\n\nFile v1.11.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"vmware-avi\",\n  \"version\": \"1.11.0\",\n  \"publishedAt\": 1789915951488\n}\n\nFile v1.11.0:references/agent-guardrails.md\n\n# Operating vmware-avi with a local / small model\n\nClaude-class models drive this skill without special instruction. Smaller and\nlocally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served\nthrough Goose, Ollama, or OpenShift AI — need explicit operating rules to call\ntools reliably.\n\nThis page exists because an operator wrote those rules by hand first. The\nguardrails below are adapted, with thanks, from the working configuration\n[@juanpf-ha](https://github.com/juanpf-ha) developed while running\nvmware-monitor and vmware-aria against a production vSphere estate with Llama\n3.3 70B FP8 on an on-prem H100\n([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The\ncross-skill rules are identical across this family; the parts below marked\nvmware-avi are specific to this skill.\n\nvmware-avi exposes 28 MCP tools, 6 of which change state. It straddles two\ncontrol planes — the AVI Controller and a Kubernetes cluster running AKO — and\nmost of the trouble a small model gets into here comes from confusing which\nside of that boundary an object lives on.\n\n> **Disclaimer**: This is a community-maintained open-source project and is\n> **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom\n> Inc.** \"VMware\" and \"vSphere\" are trademarks of Broadcom.\n\n---\n\n## First: the rules you no longer need to write\n\nSeveral guardrails from the original configuration are now enforced by the\nskill itself. Prompt instructions are advisory — a model can ignore them.\nThese are structural, so it cannot.\n\n| Guardrail you would otherwise prompt for | Now enforced by |\n|---|---|\n| \"Log every state change you make\" | **The `@vmware_tool` decorator.** Every write is recorded to `~/.vmware/audit.db` before the model sees the result, and policy rules are evaluated ahead of execution. |\n| \"Convert time windows into the units the API expects\" | **The ops layer does the conversion.** Analytics duration accepts either an integer of seconds or a shorthand suffix (`30m`, `24h`, `7d`); the model does not have to know the controller wants seconds. |\n| \"Use the controller's IP, not its hostname\" | **The connection layer resolves it.** Some analytics endpoints reject a hostname; the FQDN is resolved to an address before the SDK sees it. |\n\nNote the one guardrail this skill does **not** hand you: vmware-avi's list tools\nreturn bare collections, not the family `{items, returned, limit, total,\ntruncated, hint}` envelope. Truncation is therefore not self-declaring here, so\nthe \"report every item\" and \"state the limit you used\" rules below carry more\nweight than they do in the rest of the family.\n\n---\n\n## The system prompt\n\nEverything below still benefits from being stated explicitly. Copy this into\nyour agent's instruction block.\n\n```text\n## Tool use\n\n- Always call an MCP tool before answering any question about the current AVI\n  or AKO environment. Never answer from memory or assumption.\n- Never describe a tool call, and never output a JSON example, instead of\n  executing the tool. If you intend to call a tool, call it.\n- If a tool fails, report the actual error text. Do not complete the answer\n  with assumptions about what the result would have been.\n- Use explicit limits and time windows on queries that may return large amounts\n  of data. State the window you used in the answer.\n- Analytics windows accept an integer of seconds or a shorthand suffix such as\n  30m, 24h or 7d. Pick one and say which.\n\n## Skill routing\n\n- vmware-avi: virtual services, pools and pool members, SSL certificates,\n  Service Engines, VS analytics and error logs, AKO pod/config/sync/ingress\n  diagnostics, multi-cluster and AMKO.\n- vmware-nsx: segments, gateways, NAT, routing. The underlay is not this skill.\n- vmware-nsx-security: DFW rules and security groups.\n- vmware-vks: Supervisor and Tanzu Kubernetes cluster lifecycle.\n- vmware-monitor: read-only vCenter inventory, hosts, alarms, events.\n- vmware-aiops: VM lifecycle.\n- vmware-pilot: multi-step workflows that need approval gates.\n\n## Data fidelity\n\n- Never invent virtual services, pools, members, certificates or Service\n  Engines. If a tool did not return it, it does not exist for this answer.\n- Preserve the exact operational state, health-score and enabled/disabled\n  values the tools return. Do not translate, normalise, or prettify them.\n- Report metric values and their units exactly as returned. Do not rescale,\n  average, or recompute a percentage yourself.\n- If a requested field was not returned, show it as \"not available\". Do not\n  infer it from other fields.\n- Preserve the original order and the full set of fields when the user asks\n  for specific ones.\n- These tools return bare lists, not a truncation envelope. If you applied a\n  limit, say so in the answer; never present a limited result as the whole set.\n\n## Analysis discipline\n\n- Separate observed data from interpretation. State which is which.\n- Do not claim a performance, certificate or capacity problem unless the tool\n  output contains explicit supporting evidence.\n- An empty analytics series means no data was recorded for that window — it is\n  not evidence of zero traffic, and not evidence of an outage.\n- Avoid generic recommendations that are not directly supported by the results.\n\n## Two control planes\n\n- Controller-side objects (virtual services, pools, SEs, certificates) and\n  Kubernetes-side objects (AKO pod, Helm values, Ingress) are different things.\n  Name which side you are reporting on.\n- An Ingress with no virtual service is an AKO reconciliation question, not a\n  missing-VS question. Use ako_ingress_check, then ako_logs, then\n  ako_sync_diff — in that order.\n- SSL certificates are tenant-scoped. An empty certificate list may mean the\n  configured user cannot see that tenant, not that no certificates exist.\n\n## Writes in vmware-avi\n\n- vs_toggle takes a virtual service out of service. Call it without confirm\n  first: that returns blast_radius (the VS, its current state, the pools and\n  members behind it) and changes nothing. Show it and wait for the user's\n  decision before calling again with confirm=true.\n- ako_config_upgrade is a Helm release upgrade against a live cluster. Show\n  ako_config_diff first, then the preview (without confirm) of the upgrade.\n- A pool member that reports \"down\" straight after being enabled is failing its\n  health monitor. Report that, do not re-enable it in a loop.\n```\n\n---\n\n## Known failure modes on small models\n\nObserved with Llama 3.3 70B FP8 (Goose, on-prem H100), and useful as a\nchecklist when evaluating any local model against these skills:\n\n| Symptom | Mitigation |\n|---|---|\n| Describes a tool call, or emits a JSON example, instead of executing it | The \"never describe a tool call\" rule above. Also check your harness is not echoing tool schemas into context — models imitate the nearest format they see. |\n| Long tool responses: omits items, or reports \"no data returned\" when data was present | Ask for explicit limits and narrow time windows so responses stay small. This skill has no truncation envelope to check the model's summary against, so verify against the controller when the answer matters. |\n| Adds generic recommendations unsupported by results | The \"analysis discipline\" rules. |\n| Drops requested fields or reorders results | State the required fields and ordering in the request itself, not only in the system prompt. |\n| Multi-tool workflows take 30–50s end to end | Prefer the tools that answer a whole question in one call: `ako_ingress_diagnose` replaces a check/logs/diff sequence, and `ssl_expiry_check` replaces enumerating certificates and comparing dates by hand. |\n| Reads an empty analytics series as an outage | The \"empty series means no data\" rule. Virtual services with no traffic legitimately return nothing for the window. |\n| Passes a bare number where a duration was meant, or invents its own unit | State the window explicitly, in seconds or with a suffix. |\n| Confuses an AKO problem with a Controller problem and reports the wrong root cause | The \"two control planes\" block above. Make the model name the side it is describing. |\n| Reads an empty SSL certificate list as \"no certificates configured\" | Certificates are tenant-scoped. Report it as a visibility result, not an inventory result. |\n\n## Reporting results\n\nLocal-model compatibility is an explicit design constraint for this family, and\nthe evidence base is small. If you evaluate a model against this skill —\nQwen, Mistral, Granite, or anything else — a report of what worked and what did\nnot is genuinely useful:\n[github.com/vmware-skills/VMware-AVI/issues](https://github.com/vmware-skills/VMware-AVI/issues).\n\nFile v1.11.0:references/capabilities.md\n\n# VMware AVI Capabilities\n\nAll 28 MCP tools exposed by `vmware-avi mcp` (v1.5.15+; legacy entry point: `vmware-avi-mcp`), organized by category.\n\n## Version Compatibility\n\n### AVI Controller (NSX ALB)\n\n| Controller Version | Support Level | Notes |\n|--------------------|--------------|-------|\n| AVI 30.x | ✅ Full | All 28 tools verified. avisdk `<31.0` upper bound. |\n| AVI 22.1.x | ✅ Full | All analytics endpoint quirks fixed in v1.5.11 — `vs_analytics` uses POST `/analytics/metrics/collection` with `metric_requests[]`; `pool_list` uses `/virtualservice-inventory` to expose K8S-managed pool groups; SE→VS mapping reconstructed from `vip_summary[].service_engine[]`. |\n| AVI < 22.1 | ⚠ Untested | avisdk may load but analytics/inventory endpoints differ. Not in CI. |\n\n### VCF (VMware Cloud Foundation)\n\n| VCF Version | Bundled AVI / NSX ALB | Support |\n|-------------|-----------------------|---------|\n| VCF 9.1 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) |\n| VCF 9.0 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) |\n| VCF 5.x | AVI 22.x | ✅ Full |\n\n### Runtime\n\n| Requirement | Version | Notes |\n|-------------|---------|-------|\n| Python | ≥ 3.11 | `requires-python` bumped from 3.10 to 3.11 in v1.5.19 (regression eval uses `tomllib`). |\n| avisdk | ≥ 22.1, < 31.0 | Auto-installed. Range chosen so VCF 9.x bundled AVI is covered without forcing a major SDK jump. |\n| kubernetes (Python) | ≥ 28.0 | Required only for AKO mode. |\n| kubectl | any recent | Required only for AKO operations. |\n| helm | ≥ 3.x | Required only for AKO config show/diff/upgrade. |\n\n### MCP Transport\n\n| Mode | Status | Recommended |\n|------|--------|-------------|\n| `vmware-avi mcp` (CLI subcommand, stdio) | ✅ Full | ✅ v1.5.15+ default — no PyPI re-resolve, works behind corporate TLS proxies. |\n| `vmware-avi-mcp` (legacy console script, stdio) | ✅ Full | Kept for backward compatibility with pre-1.5.15 configs. |\n| `python -m vmware_avi.mcp_server` (stdio, via `__main__.py`) | ✅ Full | Docker image `CMD` only — not for end-user CLI install, and no longer used by `smithery.yaml` (which now calls the `vmware-avi mcp` entry point). Added v1.5.22. |\n| `uvx --from vmware-avi==1.11.0 vmware-avi-mcp` | ⚠ Fallback | Re-resolves PyPI on each launch; fails behind corporate TLS proxies (踩坑 #25). Use `UV_NATIVE_TLS=true` workaround. |\n\n## Automation Level Reference\n\nEach operation is classified by autonomy level per the Enterprise Harness Engineering framework:\n\n| Level | Meaning | Agent autonomy | Examples in this skill |\n|:-:|---|---|---|\n| **L1** | Read-only, raw data | Always auto-run | `vs_list`, `vs_status`, `pool_list`, `pool_members`, `se_list`, `se_health`, `vs_analytics` queries, AKO/AMKO inventory (`ako_status`, `ako_clusters`, `ako_amko_status`) |\n| **L2** | Read + analysis / recommendation | Always auto-run | traffic distribution analysis, health score correlation, pool member ratio summaries, analytics-driven anomaly detection |\n| **L3** | Single write — user must approve | Only after explicit confirmation. MCP: `vs_toggle`, `pool_member_disable`, `ako_restart`, `ako_config_upgrade`, `ako_sync_force` return a `blast_radius` preview unless `confirm=true`; CLI: double-confirm + `--dry-run` | `vs_toggle`, `pool_member_enable`/`pool_member_disable`, `ako_restart`, `ako_config_upgrade`, `ako_sync_force` |\n| **L4** | Multi-step plan / apply workflow | Plan generation auto; apply gated by user approval | *(roadmap — VS deployment plans, blue/green pool member rotations)* |\n| **L5** | Auto-remediation from learned pattern | Pattern library only; requires `risk:low` + `reversible:true` + `repeatable:true` | *(roadmap — candidates: stale pool member drain, AKO controller reconnect)* |\n\n> Classification comes from each tool's `[READ]`/`[WRITE]` docstring marker,\n> not from this table — see the README.\n\n**Notes**:\n- L1/L2 tools are always safe for agents to call without confirmation.\n- L3 tools always pass through the `@vmware_tool` decorator: connection check → policy check → audit log. The five gated tools then measure their blast radius; without `confirm=true` they stop there, and with it they refuse on a blocker or an unreadable field.\n- AKO Kubernetes operations affect ingress/service routing — even \"low-risk\" restarts can briefly interrupt traffic; treat as L3 with explicit user approval.\n\n## Traditional Mode — AVI Controller (13 tools)\n\n### Virtual Service (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `vs_list` | List all Virtual Services on the active controller | `controller` (string, optional) | Low | No |\n| `vs_status` | Show detailed status of a single VS (VIP, health score, pool binding, enabled state) | `name` (string, **required**) | Low | No |\n| `vs_toggle` | Enable or disable a Virtual Service. Returns `blast_radius` (VS, uuid, current state, VIPs, pools and member counts); previews unless `confirm=true` | `name` (string, **required**), `enable` (boolean, **required**), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | Medium | Yes (both directions) |\n\n### Pool Member (4)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `pool_list` | Discover pools on the Controller, with VS bindings (uses `/virtualservice-inventory` to include K8S-managed pool groups) | `vs_filter` (string, optional) | Low | No |\n| `pool_members` | List all members of a pool with health status and ratio | `pool` (string, **required**) | Low | No |\n| `pool_member_enable` | Enable a pool member (restore traffic after maintenance) | `pool` (string, **required**), `server` (string, **required**) | Low | No |\n| `pool_member_disable` | Disable a pool member with graceful connection drain. Returns `blast_radius` (pool, member, enabled members before/after); refuses the pool's only enabled member | `pool` (string, **required**), `server` (string, **required**), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | Medium | Yes |\n\n### SSL Certificate (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ssl_list` | List all SSL/TLS certificates on the controller | *(none)* | Low | No |\n| `ssl_expiry_check` | Check certificates expiring within N days, with VS mapping | `days` (integer, default: 30) | Low | No |\n\n### Analytics (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `vs_analytics` | Show VS metrics: L4 bandwidth/connections (`l4_client.avg_bandwidth`, `avg_complete_conns`, `avg_new_established_conns`) + L7 client transaction latency (`l7_client.avg_client_txn_latency`), response errors, total responses | `vs_name` (string, **required**) | Low | No |\n| `vs_error_logs` | Show recent request error logs for a VS (HTTP status ≥ 400, filter `ge(response_code,400)`) | `vs_name` (string, **required**), `since` (string, default: `\"1h\"`) | Low | No |\n\n### Service Engine (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `se_list` | List all Service Engines: name, mgmt IP, operational status, SE group (via `serviceengine-inventory`, config + runtime merged) | *(none)* | Low | No |\n| `se_health` | Check SE health: per-SE operational status + connected-VS counts (placement map from `virtualservice-inventory`) | *(none)* | Low | No |\n\n## AKO Mode — Kubernetes (15 tools)\n\n### AKO Pod Ops (4)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_status` | Check AKO pod status (phase, restart count, readiness) | `context` (string, optional) | Low | No |\n| `ako_logs` | View AKO pod logs (tail mode) | `tail` (integer, default: 100), `since` (string, optional) | Low | No |\n| `ako_restart` | Restart AKO pod by deleting it (its StatefulSet recreates it). Returns `blast_radius` (pod, uid, phase, Ingresses); the delete is pinned to the measured uid | `context` (string, optional), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | High | Yes |\n| `ako_version` | Show AKO container image tag and Helm chart version | `context` (string, optional) | Low | No |\n\n### AKO Config (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_config_show` | Show current AKO Helm values (values.yaml snapshot; release auto-discovered via `helm list` — official installs use `--generate-name`) | *(none)* | Low | No |\n| `ako_config_diff` | Preview the pending Helm change, running the same command `ako_config_upgrade` does (`--reuse-values` included) so the diff describes the actual upgrade rather than the chart's defaults. Chart: `oci://projects.packages.broadcom.com/ako/helm-charts/ako` | `chart_version` (optional — empty resolves to registry latest, which can move between calls) | Low | No |\n| `ako_config_upgrade` | Helm upgrade the discovered AKO release from the official Broadcom OCI chart with `--reuse-values`. Without `confirm=true` returns `blast_radius` (release, chart now → chart to, status) plus the `helm upgrade --dry-run` output | `confirm` (boolean, default `false`), `chart_version` (optional), `dry_run` / `confirmed` (deprecated aliases) | High | Yes |\n\n### Ingress Diagnostics (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_ingress_check` | Validate Ingress annotations against AKO expectations in a namespace | `namespace` (string, **required**) | Low | No |\n| `ako_ingress_map` | Show full Ingress-to-VS mapping across all namespaces | *(none)* | Low | No |\n| `ako_ingress_diagnose` | Diagnose why a specific Ingress has no corresponding VS on the Controller | `name` (string, **required**), `namespace` (string, default: `\"default\"`) | Low | No |\n\n### Sync Diagnostics (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_sync_status` | Check overall K8s-to-Controller sync health | *(none)* | Low | No |\n| `ako_sync_diff` | Show objects present in K8s but missing on Controller, and vice versa | *(none)* | Low | No |\n| `ako_sync_force` | Force AKO to re-reconcile all K8s objects against the Controller (deletes the AKO pod). Returns `blast_radius` like `ako_restart` | `context` (string, optional), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | Medium | Yes |\n\n### Multi-cluster (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_clusters` | List all K8s clusters with AKO deployed | *(none)* | Low | No |\n| `ako_amko_status` | Show AMKO (Avi Multi-cluster Kubernetes Operator) GSLB status | *(none)* | Low | No |\n\n## Risk Level Definitions\n\n| Level | Meaning | Examples |\n|-------|---------|---------|\n| **Low** | Read-only query, no state change | `vs_list`, `ssl_expiry_check`, `ako_logs` |\n| **Medium** | State change affecting traffic flow, but recoverable | `vs_toggle` (disable), `pool_member_disable`, `ako_sync_force` |\n| **High** | Disruptive operation affecting running services or deployments | `ako_restart`, `ako_config_upgrade` |\n\n## Tool Counts by Risk Level\n\nEach tool is counted exactly once, at its default (worst-case) risk level, so the\nthree rows sum to the full tool surface:\n\n| Risk | Count | Tools |\n|------|:-----:|-------|\n| Low | 23 | All 22 read-only tools + `pool_member_enable` (a write, but it only restores traffic) |\n| Medium | 3 | `vs_toggle`, `pool_member_disable`, `ako_sync_force` |\n| High | 2 | `ako_restart`, `ako_config_upgrade` |\n\n**Total: 23 + 3 + 2 = 28.**\n\n> Note: risk is contextual for two tools, but each is listed only once above, at its\n> higher level. `vs_toggle` with `enable=true` is effectively Low risk; with\n> `enable=false` it is Medium (and High against a critical VS), so it is counted as\n> Medium. `ako_config_upgrade` without `confirm=true` is Low risk (preview only); with\n> `confirm=true` it is High, so it is counted as High.\n\n## Audit Coverage\n\nAll 28 tools are wrapped with `@vmware_tool` from vmware-policy, which provides:\n\n- **Pre-execution**: Policy rule check against `~/.vmware/rules.yaml` (deny rules, maintenance windows)\n- **Post-execution**: Audit log entry written to `~/.vmware/audit.db` (SQLite WAL mode)\n- **Input sanitization**: All AVI API response text processed through `_sanitize()` (truncation + control character cleanup)\n\n## Traditional vs AKO Mode Requirements\n\n| Requirement | Traditional Mode | AKO Mode |\n|-------------|:----------------:|:--------:|\n| AVI Controller access | Required | Optional (for sync tools) |\n| avisdk Python package | Required | Not required |\n| kubectl in PATH | Not required | Required |\n| helm in PATH | Not required | Required (for config operations) |\n| kubeconfig | Not required | Required |\n| kubernetes Python package | Not required | Required |\n\nFile v1.11.0:references/cli-reference.md\n\n# VMware AVI CLI Reference\n\nComplete command reference for the `vmware-avi` CLI (v1.4.0).\n\n## Global Commands\n\n| Command | Description | Flags |\n|---------|-------------|-------|\n| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |\n| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |\n| `vmware-avi config` | Show current configuration (passwords masked) | -- |\n\n## Virtual Service Commands (`vmware-avi vs`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi vs list` | List all Virtual Services | `--controller <name>` (optional, use a specific controller) |\n| `vmware-avi vs status <name>` | Show VS status details (VIP, health, pool binding) | `<name>` (required) |\n| `vmware-avi vs enable <name>` | Enable a Virtual Service | `<name>` (required) |\n| `vmware-avi vs disable <name>` | Disable a Virtual Service | `<name>` (required). **Double-confirm required.** |\n\n## Pool Member Commands (`vmware-avi pool`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi pool members <pool>` | List pool members and health status | `<pool>` (required) |\n| `vmware-avi pool enable <pool> <server-ip>` | Enable a pool member (restore traffic) | `<pool>` (required), `<server-ip>` (required) |\n| `vmware-avi pool disable <pool> <server-ip>` | Disable a pool member (graceful drain) | `<pool>` (required), `<server-ip>` (required). **Double-confirm required.** |\n\n## SSL Certificate Commands (`vmware-avi ssl`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ssl list` | List all SSL certificates | -- |\n| `vmware-avi ssl expiry` | Check certificates expiring within N days | `--days <N>` (default: 30) |\n\n## Service Engine Commands (`vmware-avi se`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi se list` | List all Service Engines: name, mgmt IP, operational status, SE group (status from the `serviceengine-inventory` endpoint, config + runtime merged) | -- |\n| `vmware-avi se health` | Check Service Engine health: per-SE operational status + connected-VS counts (placement map from `virtualservice-inventory`) | -- |\n\n## Analytics Commands\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi analytics <vs-name>` | Show VS analytics: L4 bandwidth/connections + L7 client transaction latency (`l7_client.avg_client_txn_latency`), response errors, total responses | `<vs-name>` (required) |\n| `vmware-avi logs <vs-name>` | Show VS request error logs (HTTP status ≥ 400, filter `ge(response_code,400)`) | `<vs-name>` (required), `--since <range>` (default: `1h`, e.g. `30m`, `2h`) |\n\n## AKO Pod Commands (`vmware-avi ako`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako status` | Check AKO pod status (Running, CrashLoopBackOff, etc.) | `--context <k8s-context>` (optional) |\n| `vmware-avi ako logs` | View AKO pod logs | `--tail <N>` (default: 100), `--since <range>` (e.g. `30m`), `--context <k8s-context>` (optional) |\n| `vmware-avi ako restart` | Restart AKO pod by deleting it (its StatefulSet recreates it) | `--context <k8s-context>` (optional). **Double-confirm required.** |\n| `vmware-avi ako version` | Show AKO version info (image tag, Helm chart version) | `--context <k8s-context>` (optional) |\n\n## AKO Config Commands (`vmware-avi ako config-*`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako config-show` | Show current AKO Helm values.yaml (release auto-discovered via `helm list` — official installs use `--generate-name`) | -- |\n| `vmware-avi ako config-diff` | Preview the pending Helm change against `oci://projects.packages.broadcom.com/ako/helm-charts/ako`, using `--reuse-values` so it matches what `config-upgrade` would apply | `--chart-version` (pin the version; default is registry latest) |\n| `vmware-avi ako config-upgrade` | Helm upgrade the discovered AKO release from the official Broadcom OCI chart with `--reuse-values` | `--dry-run` / `--no-dry-run` (default: `--dry-run`). **Double-confirm required for actual apply.** |\n\n## AKO Ingress Commands (`vmware-avi ako ingress-*`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako ingress-check <namespace>` | Validate Ingress annotations in a namespace | `<namespace>` (required) |\n| `vmware-avi ako ingress-map` | Show Ingress to VS mapping across all namespaces | -- |\n| `vmware-avi ako ingress-diagnose <name>` | Diagnose why an Ingress has no corresponding VS | `<name>` (required), `--namespace <ns>` (default: `default`) |\n\n## AKO Sync Commands (`vmware-avi ako sync-*`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako sync-status` | Check K8s-Controller sync status | -- |\n| `vmware-avi ako sync-diff` | Show K8s-Controller inconsistencies (objects in K8s but not on Controller, or vice versa) | -- |\n| `vmware-avi ako sync-force` | Force AKO to re-reconcile all K8s objects | **Double-confirm required.** |\n\n## AKO Multi-cluster Commands (`vmware-avi ako`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako clusters` | List all clusters with AKO deployed | -- |\n| `vmware-avi ako amko-status` | Show AMKO (multi-cluster GSLB) status | -- |\n\n## Destructive Operations Summary\n\nThe following commands require double confirmation before execution:\n\n| Command | Risk | Reason |\n|---------|------|--------|\n| `vs disable` | Medium | Takes a VS offline, impacts client traffic |\n| `pool disable` | Medium | Drains traffic from a pool member |\n| `ako restart` | High | Restarts AKO pod, temporarily pauses K8s-Controller sync |\n| `ako config-upgrade` | High | Modifies AKO Helm release, may change load-balancing behavior |\n| `ako sync-force` | Medium | Forces full re-reconciliation, may cause brief churn |\n\n## Environment Variables\n\n| Variable | Purpose |\n|----------|---------|\n| `VMWARE_AVI_CONFIG` | Override config file path (default: `~/.vmware-avi/config.yaml`) |\n| `<CONTROLLER_NAME>_PASSWORD` | AVI Controller password (e.g. `PROD_AVI_PASSWORD`) |\n\n## Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| `0` | Success |\n| `1` | Failure (connectivity error, missing config, check failed) |\n\nFile v1.11.0:references/setup-guide.md\n\n# VMware AVI Setup Guide\n\nComplete installation, configuration, and AI platform integration guide for the current `vmware-avi` release. Refer to `RELEASE_NOTES.md` in the repository for version-specific changes.\n\n## Prerequisites\n\n| Requirement | Version | Purpose |\n|-------------|---------|---------|\n| Python | >= 3.10 | Runtime |\n| uv | >= 0.4 | Package manager and tool runner |\n| avisdk | >= 22.1 | AVI Controller API (auto-installed) |\n| kubernetes (Python) | >= 28.0 | K8s API client for AKO operations (auto-installed) |\n| kubectl | any recent | Required for AKO pod/ingress/sync operations |\n| helm | >= 3.x | Required for AKO config show/diff/upgrade |\n| vmware-policy | >= 1.0.0 | Audit and policy engine (auto-installed) |\n\n**Optional**: `kubeconfig` file with access to clusters running AKO (only needed for AKO mode).\n\n## Installation\n\n### Standard Install (recommended)\n\n```bash\nuv tool install vmware-avi==1.11.0\n```\n\nThis installs the CLI (`vmware-avi`, with `vmware-avi mcp` subcommand for the MCP server in v1.5.15+), the legacy `vmware-avi-mcp` entry point (for backward compatibility), and all Python dependencies in an isolated environment.\n\n### Development Install\n\n```bash\ngit clone --branch v1.11.0 https://github.com/vmware-skills/VMware-AVI.git\ncd VMware-AVI\nuv pip install -e \".[dev]\"\n```\n\n### Alternative Deployment: Container / Smithery\n\nFor platforms that prefer containerized MCP servers (e.g., Smithery registry, Kubernetes-hosted agents, isolated CI runners), `vmware-avi` ships a `Dockerfile` and `smithery.yaml` at the repository root (added v1.5.22).\n\n#### Docker\n\nBuild and run the MCP server in a container. The image uses `python:3.12-slim` with `uv` for dependency installation and runs `python -m vmware_avi.mcp_server` on stdio (no port exposed — MCP uses stdin/stdout).\n\n```bash\ngit clone --branch v1.11.0 https://github.com/vmware-skills/VMware-AVI.git\ncd VMware-AVI\n\n# Build\ndocker build -t vmware-avi-mcp .\n\n# Run — mount your config directory into the container\ndocker run -i --rm \\\n  -v ~/.vmware-avi:/root/.vmware-avi:ro \\\n  -e VMWARE_AVI_CONFIG=/root/.vmware-avi/config.yaml \\\n  vmware-avi-mcp\n```\n\nThe container's `CMD` is `python -m vmware_avi.mcp_server`, which is wired through `vmware_avi/mcp_server/__main__.py` to the same FastMCP entry point as the CLI subcommand. All 28 tools are available.\n\n#### Smithery\n\n`vmware-avi` is published on the [Smithery](https://smithery.ai) registry. The `smithery.yaml` at the repo root declares:\n\n- `startCommand.type: stdio` — Smithery launches the server over stdio\n- `configSchema.properties.config_path` — optional override for the config file location\n- `commandFunction` — invokes the `vmware-avi mcp` entry point with `VMWARE_AVI_CONFIG` set from the user's Smithery config\n\nUsers can install via the Smithery UI or CLI without managing Python environments locally. Smithery handles the container build and stdio bridge automatically.\n\n#### When to use which deployment\n\n| Deployment | Best For |\n|------------|----------|\n| `uv tool install vmware-avi==1.11.0` + `vmware-avi mcp` | Local developer workstation, single-user CLI + MCP |\n| Docker image | Self-hosted agents, CI runners, isolated environments, multi-user servers |\n| Smithery | Zero-install agent integration, registry-managed discovery, hosted-MCP workflows |\n\n### Verify Installation\n\n```bash\nvmware-avi doctor\n```\n\nThe `doctor` command checks all of the following:\n- Config directory and files exist\n- `.env` file permissions are 600\n- avisdk and kubernetes Python packages installed\n- kubectl and helm binaries in PATH\n- kubeconfig file exists\n- AVI Controller(s) reachable\n- vmware-policy package installed\n\n## AVI Controller Configuration\n\n### Step 1: Generate config templates\n\n```bash\nvmware-avi init\n```\n\nThis creates two files in `~/.vmware-avi/`:\n- `config.yaml` -- connection targets and AKO settings\n- `.env` -- passwords (auto-set to chmod 600)\n\n### Step 2: Edit config.yaml\n\n```yaml\n# ~/.vmware-avi/config.yaml\ncontrollers:\n  - name: prod-avi\n    host: avi-controller.example.com\n    username: admin\n    api_version: \"22.1.4\"\n    tenant: admin\n    port: 443\n    verify_ssl: true\n    environment: production   # scopes policy rules; see the field table below\n\n  - name: staging-avi\n    host: avi-staging.example.com\n    username: admin\n    api_version: \"22.1.4\"\n    tenant: admin\n    verify_ssl: false    # lab/self-signed certs only\n    environment: staging\n\ndefault_controller: prod-avi\n\nako:\n  kubeconfig: ~/.kube/config\n  default_context: \"\"        # empty = use current-context\n  namespace: avi-system\n```\n\n**config.yaml fields**:\n\n| Field | Required | Default | Description |\n|-------|:--------:|---------|-------------|\n| `controllers[].name` | Yes | -- | Unique identifier for this controller |\n| `controllers[].host` | Yes | -- | Controller hostname or IP |\n| `controllers[].username` | No | `admin` | API username |\n| `controllers[].api_version` | No | `22.1.4` | AVI API version string |\n| `controllers[].tenant` | No | `admin` | AVI tenant name |\n| `controllers[].port` | No | `443` | Controller HTTPS port |\n| `controllers[].verify_ssl` | No | `true` | TLS certificate verification |\n| `controllers[].environment` | Optional | -- | Free-form label (`production` / `staging` / `lab`). An environment-scoped `deny` rule in `~/.vmware/rules.yaml` can match on it to block writes (e.g. freeze `production`); a controller with no label is simply not matched by such a rule. Read-only operations are never affected. |\n| `default_controller` | No | first entry | Which controller to use by default |\n| `ako.kubeconfig` | No | `~/.kube/config` | Path to kubeconfig file |\n| `ako.default_context` | No | current-context | K8s context for AKO operations |\n| `ako.namespace` | No | `avi-system` | Namespace where AKO is deployed |\n\n### Step 3: Set passwords in .env\n\n```bash\n# ~/.vmware-avi/.env\nPROD_AVI_PASSWORD=your-secure-password-here\nSTAGING_AVI_PASSWORD=another-password-here\n```\n\nPassword environment variable naming convention: `<CONTROLLER_NAME>_PASSWORD` where the controller name is uppercased and hyphens are replaced with underscores.\n\n| Controller Name | Environment Variable |\n|-----------------|---------------------|\n| `prod-avi` | `PROD_AVI_PASSWORD` |\n| `staging-avi` | `STAGING_AVI_PASSWORD` |\n| `my-lab` | `MY_LAB_PASSWORD` |\n\n### Step 4: Verify connectivity\n\n```bash\nvmware-avi doctor\nvmware-avi vs list          # quick smoke test\n```\n\n## AKO / Kubernetes Configuration\n\nAKO operations require a valid kubeconfig with access to the cluster(s) where AKO is deployed.\n\n### kubeconfig Setup\n\n```bash\nkubectl --context my-cluster get pods -n avi-system   # verify access\nkubectl config get-contexts                            # list all contexts\n```\n\nIf your AKO is deployed in a non-default namespace, update `ako.namespace` in config.yaml. AKO config commands (`config-show`, `config-diff`, `config-upgrade`) require Helm 3.x:\n\n```bash\nhelm repo add ako https://projects.registry.vmware.com/chartrepo/ako\nhelm repo update\n```\n\n### Password obfuscation at rest\n\nOn first load, any plaintext `*_PASSWORD` value in `.env` is automatically\nrewritten to a grep-safe `b64:<encoded>` form and decoded transparently at\nruntime, so a casual `grep` of the file no longer reveals the password. Values\nare read and written through python-dotenv's own parser, so the stored secret\nnever drifts from what you configured (quotes, inline comments, and trailing\nwhitespace are handled correctly).\n\n> **This is obfuscation, not encryption.** Anyone who can read the file can\n> still decode it. For real secrecy at rest, do not store the password in `.env`\n> at all — inject it from a secret manager (HashiCorp Vault, CyberArk, AWS\n> Secrets Manager, or a Kubernetes Secret) into the `*_PASSWORD` environment\n> variable at process start. The code reads the env var either way.\n\n## Security\n\n> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** \"VMware\", \"NSX\", and \"AVI\" are trademarks of Broadcom.\n\n### Password Management\n\n- Passwords are **never** stored in `config.yaml` -- only in `.env`\n- The `.env` file must have `chmod 600` permissions (owner read/write only)\n- `vmware-avi doctor` warns if `.env` permissions are too open\n- Never commit `.env` files to version control\n\n### Audit Logging\n\nAll operations (CLI and MCP) are recorded via vmware-policy:\n\n- **Location**: `~/.vmware/audit.db` (SQLite, WAL mode)\n- **Contents**: timestamp, tool name, parameters, result, user identity\n- **Query**: `vmware-audit log --last 20`\n\n### Policy Rules\n\nOptional deny rules and maintenance windows can be configured in `~/.vmware/rules.yaml` (managed by vmware-policy). Example: block `vs_toggle` disable during business hours.\n\n### Destructive Operation Safety\n\n| Operation | Safety Measures |\n|-----------|----------------|\n| VS disable | CLI: double confirmation prompt. MCP `vs_toggle`: previews `blast_radius` unless `confirm=true` |\n| Pool member disable | CLI: double confirmation prompt (graceful drain). MCP: previews unless `confirm=true`; refuses the pool's only enabled member |\n| AKO restart | CLI: double confirmation prompt. MCP: previews unless `confirm=true`; refuses a terminating pod |\n| AKO config upgrade | CLI: defaults to `--dry-run`; double confirmation for actual apply. MCP: previews (with `helm --dry-run` output) unless `confirm=true`; refuses a failing dry-run |\n| AKO sync force | CLI: double confirmation prompt. MCP: previews unless `confirm=true` |\n\n### Read-Only Operation\n\nTo run the agent read-only, give it a read-only AVI service account (RBAC).\n\n### Data Sanitization\n\nAll text returned from AVI Controller APIs is processed through `_sanitize()`:\n- Truncated to 500 characters maximum\n- C0/C1 control characters stripped\n- Prevents prompt injection via API response content\n\n### TLS Verification\n\n- Enabled by default (`verify_ssl: true`)\n- Set `verify_ssl: false` only for lab environments with self-signed certificates\n- Production deployments should always use valid TLS certificates\n\n## AI Platform Compatibility\n\nvmware-avi supports MCP (Model Context Protocol) integration with the following platforms.\n\n### Claude Code (Claude Desktop / CLI)\n\nAdd to `~/.claude.json` (global) or `.mcp.json` (project-level):\n\n```json\n{\n  \"mcpServers\": {\n    \"vmware-avi\": {\n      \"command\": \"vmware-avi\",\n      \"args\": [\"mcp\"],\n      \"env\": {\n        \"VMWARE_AVI_CONFIG\": \"~/.vmware-avi/config.yaml\"\n      }\n    }\n  }\n}\n```\n\n> v1.5.15+ recommends the single-command form `vmware-avi mcp`. Pre-1.5.15 used\n> `uvx --from vmware-avi vmware-avi-mcp`, which still works but re-resolves from <!-- install-pin: historical -->\n> PyPI on each launch and breaks behind corporate TLS proxies. The legacy\n> `vmware-avi-mcp` entry point is also kept for backward compatibility.\n\n### Cursor\n\nAdd to `.cursor/mcp.json` in your project root:\n\n```json\n{\n  \"mcpServers\": {\n    \"vmware-avi\": {\n      \"command\": \"vmware-avi\",\n      \"args\": [\"mcp\"],\n      \"env\": {\n        \"VMWARE_AVI_CONFIG\": \"~/.vmware-avi/config.yaml\"\n      }\n    }\n  }\n}\n```\n\n### Windsurf / Cline / Qwen / Other MCP-compatible Agents\n\nUse the same JSON block as above, placed in the platform-specific config file:\n\n| Platform | Config File |\n|----------|-------------|\n| Windsurf | `~/.windsurf/mcp.json` |\n| Cline (VS Code) | Cline MCP settings panel |\n| Qwen / other | Any MCP stdio transport config |\n\n### Ollama / Local Models\n\nFor local models with limited context windows, prefer CLI mode over MCP:\n\n```bash\n# CLI produces ~2K tokens vs ~8K for MCP JSON\nvmware-avi vs list\nvmware-avi ako status\n```\n\nIf your Ollama setup supports MCP via a bridge (e.g., `mcp-bridge`), use the same `vmware-avi mcp` command (v1.5.15+).\n\n## Troubleshooting\n\n### \"Config file not found\" on first run\n\n```bash\nvmware-avi init    # generates ~/.vmware-avi/config.yaml and .env\n```\n\n### \"Password not found\" error\n\nThe environment variable name must match `<CONTROLLER_NAME>_PASSWORD` with the controller name uppercased and hyphens replaced by underscores. Check:\n\n```bash\n# If controller name is \"prod-avi\", the variable must be:\nexport PROD_AVI_PASSWORD=yourpassword\n\n# Or set it in ~/.vmware-avi/.env:\necho 'PROD_AVI_PASSWORD=yourpassword' >> ~/.vmware-avi/.env\n```\n\n### \"Controller unreachable\" in doctor\n\n1. Verify the `host` and `port` in config.yaml are correct\n2. Test network connectivity: `curl -k https://avi-controller.example.com/api/cluster`\n3. For self-signed certs, set `verify_ssl: false` in config.yaml\n4. Check if a firewall or VPN is blocking port 443\n\n### MCP server not starting\n\n1. Verify the CLI is on PATH: `which vmware-avi`\n2. Confirm the `mcp` subcommand: `vmware-avi mcp --help` (v1.5.15+)\n3. Check that `~/.vmware-avi/config.yaml` exists (MCP server loads config on startup)\n4. Legacy: `which vmware-avi-mcp` and `vmware-avi-mcp --help` still work\n5. Never use `python -m vmware_avi.mcp_server` — always use `vmware-avi mcp` (v1.5.15+) or the legacy `vmware-avi-mcp` entry point\n\n### `invalid peer certificate: UnknownIssuer` (uvx)\n\nA corporate TLS proxy is intercepting `https://pypi.org` and uv's bundled cert\nstore doesn't trust the proxy CA. Fixes (in order of preference):\n\n1. Use the v1.5.15+ form `vmware-avi mcp` — no PyPI roundtrip needed.\n2. Tell uv to use the system cert store: `export UV_NATIVE_TLS=true` (or pass\n   `--native-tls` to `uvx`).\n3. Point uv at an explicit CA bundle: `export SSL_CERT_FILE=/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem`\n\n### kubectl / helm not found\n\n```bash\n# macOS\nbrew install kubectl helm\n```\n\nFor Linux, see https://kubernetes.io/docs/tasks/tools/ and https://helm.sh/docs/intro/install/.\n\n### AKO namespace not found\n\nUpdate `ako.namespace` in config.yaml to match your deployment (default: `avi-system`).\n\n### Permission denied on .env file\n\n```bash\nchmod 600 ~/.vmware-avi/.env\n```\n\nFile v1.11.0:skill-card.md\n\n## Description:\n\nVMware AVI helps agents inspect and operate AVI/NSX ALB virtual services, pool members, SSL certificates, analytics, service engines, and AKO Kubernetes workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and infrastructure operators use this skill to diagnose and manage VMware AVI/NSX ALB load balancing and AKO Kubernetes application delivery tasks, including virtual service checks, pool member drain or restore, SSL expiry review, analytics, logs, ingress diagnostics, and sync drift analysis.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can inspect and potentially change AVI/NSX ALB and AKO/Kubernetes state.\n\nMitigation: Install it only for intended infrastructure operations, use least-privilege controller and kubeconfig credentials, and review blast-radius previews before approving writes.\n\nRisk: Production controller passwords and kubeconfig access can expose sensitive infrastructure control paths.\n\nMitigation: Prefer a secret manager or runtime environment injection over storing production passwords in local .env files, and keep kubeconfig access scoped to the required clusters.\n\nRisk: Write actions such as virtual service toggles, pool member changes, AKO restarts, sync force, and AKO configuration upgrades can affect live traffic.\n\nMitigation: Use the documented confirmation gates, audit logging, policy rules, and dry-run or preview behavior before applying changes.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/vmware-avi)\n- [Project homepage](https://github.com/vmware-skills/VMware-AVI)\n- [VMware AVI setup guide](references/setup-guide.md)\n- [VMware AVI capabilities](references/capabilities.md)\n- [VMware AVI CLI reference](references/cli-reference.md)\n- [Operating vmware-avi with a local / small model](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown and plain text with inline shell commands, configuration paths, diagnostic summaries, and action recommendations]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include blast-radius previews, audit guidance, and dry-run or confirmation steps for write operations.]\n\n## Skill Version(s):\n\n1.11.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.10.0: 7 files, 25858 bytes\n\nFiles: references/agent-guardrails.md (8702b), references/capabilities.md (13081b), references/cli-reference.md (6579b), references/setup-guide.md (13936b), skill-card.md (2819b), SKILL.md (16577b), _meta.json (130b)\n\nFile v1.10.0:SKILL.md\n\n---\nname: vmware-avi\ndescription: >\n  Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery\n  in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context.\n  Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs,\n  service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics,\n  and multi-cluster AKO overview.\n  Always use it for \"virtual service\", \"pool member\", \"AKO status\", \"AKO logs\", \"ingress diagnose\", \"ssl expiry\", \"load balancer\", \"NSX ALB\",\n  \"AVI controller\", \"Avi Load Balancer\", \"AKO sync\", or \"负载均衡\" tasks.\n  Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks.\n  For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.\ninstaller:\n  kind: uv\n  package: vmware-avi\nargument-hint: \"[vs-name, ako command, or describe your task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"vmware-avi\",\"uvx\"]},\"optional\":{\"env\":[\"VMWARE_AVI_CONFIG\",\"<CONTROLLER>_PASSWORD\",\"<CONTROLLER>_USERNAME\",\"KUBECONFIG\",\"VMWARE_AUDIT_APPROVED_BY\"],\"bins\":[\"vmware-policy\",\"kubectl\",\"helm\"]},\"homepage\":\"https://github.com/vmware-skills/VMware-AVI\",\"emoji\":\"🔀\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.\n  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller \"prod-avi\" → PROD_AVI_PASSWORD).\n  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.\n---\n\n# VMware AVI\n\n> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** \"VMware\", \"NSX\", and \"AVI\" are trademarks of Broadcom. Source code is publicly auditable at [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI) under the MIT license.\n\nAVI (NSX Advanced Load Balancer) application delivery and AKO Kubernetes operations — 28 MCP tools.\n\n> **Dual mode**: Traditional AVI Controller management + AKO K8s operations in one skill.\n> **Family**: [vmware-aiops](https://github.com/vmware-skills/VMware-AIops) (VM lifecycle), [vmware-monitor](https://github.com/vmware-skills/VMware-Monitor) (inventory/health), [vmware-storage](https://github.com/vmware-skills/VMware-Storage) (iSCSI/vSAN), [vmware-vks](https://github.com/vmware-skills/VMware-VKS) (Tanzu Kubernetes), [vmware-nsx](https://github.com/vmware-skills/VMware-NSX) (NSX networking), [vmware-nsx-security](https://github.com/vmware-skills/VMware-NSX-Security) (DFW/firewall), [vmware-aria](https://github.com/vmware-skills/VMware-Aria) (metrics/alerts/capacity), [vmware-harden](https://github.com/vmware-skills/VMware-Harden) (compliance baselines).\n> | [vmware-pilot](../vmware-pilot/SKILL.md) (workflow orchestration) | [vmware-policy](../vmware-policy/SKILL.md) (audit/policy)\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Virtual Service** | list, status, enable/disable | 3 | 2R / 1W |\n| **Pool Member** | pool discovery, member list, enable/disable member (drain/restore traffic) | 4 | 2R / 2W |\n| **SSL Certificate** | list, expiry check | 2 | 2R |\n| **Analytics** | VS metrics overview, request error logs | 2 | 2R |\n| **Service Engine** | list, health check | 2 | 2R |\n| **AKO Pod Ops** | status, logs, restart, version info | 4 | 3R / 1W |\n| **AKO Config** | values.yaml view, Helm diff, Helm upgrade | 3 | 2R / 1W |\n| **Ingress Diagnostics** | annotation validation, VS mapping, error diagnosis (with fix recommendations) | 3 | 3R |\n| **Sync Diagnostics** | K8s-Controller comparison, inconsistency list, force resync | 3 | 2R / 1W |\n| **Multi-cluster** | cross-cluster AKO cluster list, AMKO status | 2 | 2R |\n\n**Total**: 28 tools (22 read + 6 write)\n\n## Quick Install\n\n```bash\nuv tool install vmware-avi==1.10.0\nvmware-avi doctor            # checks Controller connectivity + kubeconfig + avisdk\n```\n\n## When to Use This Skill\n\n- List, enable, or disable virtual services on AVI Controller\n- Add, remove, drain, or restore pool members (maintenance windows, rolling deployments)\n- Check SSL certificate expiry across all virtual services\n- View VS analytics — throughput, latency, error rates, request logs\n- Check service engine status (inventory-based) and per-SE VS placement counts\n- Troubleshoot AKO pods — status, logs, restarts\n- Manage AKO Helm configuration — view, diff, upgrade values.yaml\n- Validate Ingress annotations and diagnose why a VS wasn't created as expected\n- Detect sync drift between K8s resources and AVI Controller objects\n- Get a cross-cluster view of AKO deployments and AMKO status\n\n**Use companion skills for**:\n- VM lifecycle, deployment, guest ops → `vmware-aiops`\n- NSX segments, gateways, NAT → `vmware-nsx`\n- DFW firewall rules, security groups → `vmware-nsx-security`\n- K8s cluster lifecycle (Supervisor, TKC) → `vmware-vks`\n- Read-only vSphere monitoring → `vmware-monitor`\n\n## Related Skills — Skill Routing\n\n| User Intent | Recommended Skill |\n|-------------|------------------|\n| Load balancer, VS, pool, AVI, ALB, AKO | **vmware-avi** ← this skill |\n| VM lifecycle, deployment, guest ops | **vmware-aiops** (`uv tool install vmware-aiops`) |\n| Read-only vSphere monitoring | **vmware-monitor** (`uv tool install vmware-monitor`) |\n| Storage: iSCSI, vSAN, datastores | **vmware-storage** (`uv tool install vmware-storage`) |\n| NSX networking: segments, gateways, NAT | **vmware-nsx** (`uv tool install vmware-nsx-mgmt`) |\n| NSX security: DFW rules, security groups | **vmware-nsx-security** (`uv tool install vmware-nsx-security`) |\n| Tanzu Kubernetes (Supervisor/TKC) | **vmware-vks** (`uv tool install vmware-vks`) |\n| Aria Ops: metrics, alerts, capacity | **vmware-aria** (`uv tool install vmware-aria`) |\n| Multi-step workflows with approval | **vmware-pilot** |\n| Compliance baselines (CIS / 等保 / PCI-DSS), drift detection, LLM remediation advisor | **vmware-harden** (`uv tool install vmware-harden`) |\n| Audit log query | **vmware-policy** (`vmware-audit` CLI) |\n\n## Common Workflows\n\n### Maintenance Window — Drain a Pool Member\n\n**Pre-flight (judgment — affects live traffic)**:\n- Capacity check: pool must have ≥ 2 healthy members. Disabling the only-other-healthy member is a self-DoS. Verify with `pool members my-pool` first.\n- Connection persistence: if VS uses session persistence (cookie/source-IP), existing sessions stay pinned to the disabled member until they expire. \"Drain\" is not instant — 5-30 min depending on persistence TTL.\n- Long-lived connections: WebSocket/streaming sessions can hold for hours. Decide upfront: hard-disconnect (faster, user-visible) or wait (slower, transparent).\n- Observability: enable analytics on the VS BEFORE disabling — you need the baseline to detect degradation.\n\n**Steps**:\n1. `pool members my-pool` → confirm ≥ 2 healthy members and identify session persistence config\n2. `pool disable my-pool <server-ip>` (graceful drain — new connections stop, existing finish)\n3. `analytics my-vs --duration 15m` → watch active connection count to the drained member trend toward zero\n4. Perform maintenance only after active connections = 0 (or you've decided to hard-disconnect)\n5. `pool enable my-pool <server-ip>` → re-enable\n6. **Verify** before declaring success: health monitor passes (typically 30-90 sec) AND new connections are landing on the member (analytics drill-down)\n\n### AKO Ingress Not Creating VS\n\n**Judgment**: this is a layered failure — figure out which layer broke before randomly probing. AKO is a controller; like all K8s controllers, the failure modes are: (a) controller down, (b) controller running but seeing wrong inputs, (c) controller acting but Avi rejecting outputs.\n\n1. `ako status` → controller running, recent reconciles, no panic logs? If not, fix here first\n2. `ako ingress check <namespace>` → required annotations present? Common miss: `kubernetes.io/ingress.class`, `aviinfrasetting.ako.vmware.com/name`\n3. `ako sync status` → drift between K8s state and Avi state. Drift > a few minutes usually means controller error\n4. `ako ingress diagnose <ingress-name>` → AKO's own diagnostic; often pinpoints the issue\n5. If sync drifted: `ako sync diff` → review what's missing on Avi side. **Force resync only after** you understand why drift happened — blind resync masks bugs that will recur\n\n### SSL Certificate Expiry Audit\n\n**Judgment**: cert expiry is the most preventable outage in the LB world. Run this regularly, not reactively. The 30-day window is a minimum — for prod, set 60+ to allow renewal lead time.\n\n1. `ssl expiry --days 60` → catch certs expiring within 60 days, not 30; enterprise renewal cycles take 2-4 weeks\n2. Cross-reference VS mapping (in output) → identify which apps are at risk; some certs may be unused (orphans, candidates for cleanup)\n3. **Decision**: certs marked `unused` (no VS) → propose deletion as part of audit; certs `in_use` → escalate to cert team with VS list and exact expiry date\n4. Schedule a follow-up rescan post-renewal (not just rely on cert team confirming)\n\n## Usage Mode\n\n| Scenario | Recommended | Why |\n|----------|:-----------:|-----|\n| Local/small models (Ollama, Qwen) | **CLI** | ~2K tokens vs ~8K for MCP |\n| Cloud models (Claude, GPT-4o) | Either | MCP gives structured JSON I/O |\n| Automated pipelines | **MCP** | Type-safe parameters, structured output |\n| AKO troubleshooting | **CLI** | Interactive log tailing, Helm diff output |\n\n## MCP Tools (28 — 22 read, 6 write)\n\n| Category | Tools | R/W |\n|----------|-------|:---:|\n| Virtual Service (3) | `vs_list`, `vs_status` | Read |\n| | `vs_toggle` | Write |\n| Pool Member (4) | `pool_list`, `pool_members` | Read |\n| | `pool_member_enable`, `pool_member_disable` | Write |\n| SSL Certificate (2) | `ssl_list`, `ssl_expiry_check` | Read |\n| Analytics (2) | `vs_analytics`, `vs_error_logs` | Read |\n| Service Engine (2) | `se_list`, `se_health` | Read |\n| AKO Pod (4) | `ako_status`, `ako_logs`, `ako_version` | Read |\n| | `ako_restart` | Write |\n| AKO Config (3) | `ako_config_show`, `ako_config_diff` | Read |\n| | `ako_config_upgrade` | Write |\n| Ingress Diagnostics (3) | `ako_ingress_check`, `ako_ingress_map`, `ako_ingress_diagnose` | Read |\n| Sync Diagnostics (3) | `ako_sync_status`, `ako_sync_diff` | Read |\n| | `ako_sync_force` | Write |\n| Multi-cluster (2) | `ako_clusters`, `ako_amko_status` | Read |\n\n**Read/write split**: 22 tools are read-only, 6 modify state, all audit-logged. Five of them (`vs_toggle`, `pool_member_disable`, `ako_restart`, `ako_sync_force`, `ako_config_upgrade`) take `confirm` (default `false`): a bare call returns a `blast_radius` and changes nothing.\n\n## CLI Quick Reference\n\n```bash\n# === Traditional Mode (AVI Controller) ===\nvmware-avi vs list [--controller <name>]\nvmware-avi vs status <vs-name>\nvmware-avi vs enable <vs-name>\nvmware-avi vs disable <vs-name>           # double-confirm\n\nvmware-avi pool members <pool-name>\nvmware-avi pool enable <pool> <server-ip>\nvmware-avi pool disable <pool> <server-ip>  # double-confirm (graceful drain)\n\nvmware-avi ssl list\nvmware-avi ssl expiry [--days 30]\n\nvmware-avi analytics <vs-name>\nvmware-avi logs <vs-name> [--since 1h]\n\nvmware-avi se list\nvmware-avi se health\n\n# === AKO Mode (K8s) ===\nvmware-avi ako status [--context <k8s-context>]\nvmware-avi ako logs [--tail 100] [--since 30m]\nvmware-avi ako restart                    # double-confirm\n\nvmware-avi ako config show\nvmware-avi ako config diff\nvmware-avi ako config upgrade             # double-confirm + --dry-run default\n\nvmware-avi ako ingress check <namespace>\nvmware-avi ako ingress map\nvmware-avi ako ingress diagnose <ingress-name>\n\nvmware-avi ako sync status\nvmware-avi ako sync diff\nvmware-avi ako sync force                 # double-confirm\n\nvmware-avi ako clusters\nvmware-avi ako amko status\n```\n\n> Full CLI reference: see `references/cli-reference.md`\n\n## Troubleshooting\n\n### \"Controller unreachable\" error\n1. Run `vmware-avi doctor` to verify connectivity\n2. Check if the controller address and port are correct in `~/.vmware-avi/config.yaml`\n3. For self-signed certs: set `verify_ssl: false` in config.yaml (lab environments only)\n\n### AKO Pod in CrashLoopBackOff\n1. Check logs → `vmware-avi ako logs --tail 50`\n2. Common causes: wrong controller IP in values.yaml, network policy blocking AKO→Controller, expired credentials\n3. Fix config → `vmware-avi ako config show` to inspect, then `vmware-avi ako config upgrade` with corrected values (release auto-discovered — official installs use `--generate-name`; pulls the official Broadcom OCI chart `oci://projects.packages.broadcom.com/ako/helm-charts/ako`)\n\n### Ingress created but no VS on Controller\n1. Validate annotations → `vmware-avi ako ingress check <namespace>`\n2. Check AKO logs for rejection reason → `vmware-avi ako logs --since 5m`\n3. Run sync diff → `vmware-avi ako sync diff` to see if the object is stuck\n\n### Pool member shows \"down\" after enable\nHealth monitor may still be failing. Check the actual health status on the Controller side — the member is enabled but unhealthy. Fix the backend service first, then the health status will auto-recover.\n\n### SSL expiry check shows 0 certificates\nVerify the controller connection has tenant-level access. Certificates are tenant-scoped in AVI — the configured user may only see certs in their tenant.\n\n### AKO sync force has no effect\nForce resync triggers AKO to re-reconcile all K8s objects. If the drift persists, the issue is likely in the K8s resource definition itself (bad annotation, missing secret). Use `vmware-avi ako ingress diagnose` to pinpoint the root cause.\n\n## Setup\n\n```bash\nuv tool install vmware-avi==1.10.0\nmkdir -p ~/.vmware-avi\nvmware-avi init              # generates config.yaml and .env templates\nchmod 600 ~/.vmware-avi/.env\nvmware-avi doctor            # verify Controller + K8s connectivity\n```\n\n> All tools are automatically audited via vmware-policy. Audit logs: `vmware-audit log --last 20`\n\n**Supported versions**: AVI Controller 22.1.x (analytics endpoint quirks fixed in v1.5.11) and 30.x. VCF 9.0 / 9.1 declared compatible (avisdk `>=22.1,<31.0` covers bundled AVI). Python 3.11+. Full table: `references/capabilities.md` → Version Compatibility.\n\n> Full setup guide, security details, AI platform compatibility, and container/Smithery deployment: see `references/setup-guide.md`\n\n## Audit & Safety\n\nAll operations are automatically audited via vmware-policy (`@vmware_tool` decorator):\n- Every tool call logged to `~/.vmware/audit.db` (SQLite, framework-agnostic)\n- Policy rules enforced via `~/.vmware/rules.yaml` (deny rules, maintenance windows, risk levels)\n- Each controller may declare `environment:` in `config.yaml` (`production` / `staging` / `lab`) as an optional label; an environment-scoped `deny` rule in `~/.vmware/rules.yaml` can match on it to block writes (e.g. freeze `production`). A controller with no label is simply not matched by such a rule. Reads are never affected\n- MCP: `vs_toggle`, `pool_member_disable`, `ako_restart`, `ako_sync_force` and `ako_config_upgrade` preview by default. Without `confirm=true` they return `blast_radius` — the VS or pool with its member counts, the AKO pod and the Ingresses it programs, or the Helm release and the chart it would move to — and change nothing. Show it to the user; do not pass `confirm=true` on your own because they asked earlier. `confirm=true` is refused when a blocker is found (the pool's only enabled member, a terminating AKO pod, a failing `helm upgrade --dry-run`) or a field could not be read. `confirmed` and `dry_run` are deprecated aliases\n- CLI: destructive commands require double confirmation; `vmware-avi ako config upgrade` defaults to `--dry-run`\n- View recent operations: `vmware-audit log --last 20`\n\n## License\n\nMIT — [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI)\n\nFile v1.10.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"vmware-avi\",\n  \"version\": \"1.10.0\",\n  \"publishedAt\": 1789790106166\n}\n\nFile v1.10.0:references/agent-guardrails.md\n\n# Operating vmware-avi with a local / small model\n\nClaude-class models drive this skill without special instruction. Smaller and\nlocally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served\nthrough Goose, Ollama, or OpenShift AI — need explicit operating rules to call\ntools reliably.\n\nThis page exists because an operator wrote those rules by hand first. The\nguardrails below are adapted, with thanks, from the working configuration\n[@juanpf-ha](https://github.com/juanpf-ha) developed while running\nvmware-monitor and vmware-aria against a production vSphere estate with Llama\n3.3 70B FP8 on an on-prem H100\n([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The\ncross-skill rules are identical across this family; the parts below marked\nvmware-avi are specific to this skill.\n\nvmware-avi exposes 28 MCP tools, 6 of which change state. It straddles two\ncontrol planes — the AVI Controller and a Kubernetes cluster running AKO — and\nmost of the trouble a small model gets into here comes from confusing which\nside of that boundary an object lives on.\n\n> **Disclaimer**: This is a community-maintained open-source project and is\n> **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom\n> Inc.** \"VMware\" and \"vSphere\" are trademarks of Broadcom.\n\n---\n\n## First: the rules you no longer need to write\n\nSeveral guardrails from the original configuration are now enforced by the\nskill itself. Prompt instructions are advisory — a model can ignore them.\nThese are structural, so it cannot.\n\n| Guardrail you would otherwise prompt for | Now enforced by |\n|---|---|\n| \"Log every state change you make\" | **The `@vmware_tool` decorator.** Every write is recorded to `~/.vmware/audit.db` before the model sees the result, and policy rules are evaluated ahead of execution. |\n| \"Convert time windows into the units the API expects\" | **The ops layer does the conversion.** Analytics duration accepts either an integer of seconds or a shorthand suffix (`30m`, `24h`, `7d`); the model does not have to know the controller wants seconds. |\n| \"Use the controller's IP, not its hostname\" | **The connection layer resolves it.** Some analytics endpoints reject a hostname; the FQDN is resolved to an address before the SDK sees it. |\n\nNote the one guardrail this skill does **not** hand you: vmware-avi's list tools\nreturn bare collections, not the family `{items, returned, limit, total,\ntruncated, hint}` envelope. Truncation is therefore not self-declaring here, so\nthe \"report every item\" and \"state the limit you used\" rules below carry more\nweight than they do in the rest of the family.\n\n---\n\n## The system prompt\n\nEverything below still benefits from being stated explicitly. Copy this into\nyour agent's instruction block.\n\n```text\n## Tool use\n\n- Always call an MCP tool before answering any question about the current AVI\n  or AKO environment. Never answer from memory or assumption.\n- Never describe a tool call, and never output a JSON example, instead of\n  executing the tool. If you intend to call a tool, call it.\n- If a tool fails, report the actual error text. Do not complete the answer\n  with assumptions about what the result would have been.\n- Use explicit limits and time windows on queries that may return large amounts\n  of data. State the window you used in the answer.\n- Analytics windows accept an integer of seconds or a shorthand suffix such as\n  30m, 24h or 7d. Pick one and say which.\n\n## Skill routing\n\n- vmware-avi: virtual services, pools and pool members, SSL certificates,\n  Service Engines, VS analytics and error logs, AKO pod/config/sync/ingress\n  diagnostics, multi-cluster and AMKO.\n- vmware-nsx: segments, gateways, NAT, routing. The underlay is not this skill.\n- vmware-nsx-security: DFW rules and security groups.\n- vmware-vks: Supervisor and Tanzu Kubernetes cluster lifecycle.\n- vmware-monitor: read-only vCenter inventory, hosts, alarms, events.\n- vmware-aiops: VM lifecycle.\n- vmware-pilot: multi-step workflows that need approval gates.\n\n## Data fidelity\n\n- Never invent virtual services, pools, members, certificates or Service\n  Engines. If a tool did not return it, it does not exist for this answer.\n- Preserve the exact operational state, health-score and enabled/disabled\n  values the tools return. Do not translate, normalise, or prettify them.\n- Report metric values and their units exactly as returned. Do not rescale,\n  average, or recompute a percentage yourself.\n- If a requested field was not returned, show it as \"not available\". Do not\n  infer it from other fields.\n- Preserve the original order and the full set of fields when the user asks\n  for specific ones.\n- These tools return bare lists, not a truncation envelope. If you applied a\n  limit, say so in the answer; never present a limited result as the whole set.\n\n## Analysis discipline\n\n- Separate observed data from interpretation. State which is which.\n- Do not claim a performance, certificate or capacity problem unless the tool\n  output contains explicit supporting evidence.\n- An empty analytics series means no data was recorded for that window — it is\n  not evidence of zero traffic, and not evidence of an outage.\n- Avoid generic recommendations that are not directly supported by the results.\n\n## Two control planes\n\n- Controller-side objects (virtual services, pools, SEs, certificates) and\n  Kubernetes-side objects (AKO pod, Helm values, Ingress) are different things.\n  Name which side you are reporting on.\n- An Ingress with no virtual service is an AKO reconciliation question, not a\n  missing-VS question. Use ako_ingress_check, then ako_logs, then\n  ako_sync_diff — in that order.\n- SSL certificates are tenant-scoped. An empty certificate list may mean the\n  configured user cannot see that tenant, not that no certificates exist.\n\n## Writes in vmware-avi\n\n- vs_toggle takes a virtual service out of service. Call it without confirm\n  first: that returns blast_radius (the VS, its current state, the pools and\n  members behind it) and changes nothing. Show it and wait for the user's\n  decision before calling again with confirm=true.\n- ako_config_upgrade is a Helm release upgrade against a live cluster. Show\n  ako_config_diff first, then the preview (without confirm) of the upgrade.\n- A pool member that reports \"down\" straight after being enabled is failing its\n  health monitor. Report that, do not re-enable it in a loop.\n```\n\n---\n\n## Known failure modes on small models\n\nObserved with Llama 3.3 70B FP8 (Goose, on-prem H100), and useful as a\nchecklist when evaluating any local model against these skills:\n\n| Symptom | Mitigation |\n|---|---|\n| Describes a tool call, or emits a JSON example, instead of executing it | The \"never describe a tool call\" rule above. Also check your harness is not echoing tool schemas into context — models imitate the nearest format they see. |\n| Long tool responses: omits items, or reports \"no data returned\" when data was present | Ask for explicit limits and narrow time windows so responses stay small. This skill has no truncation envelope to check the model's summary against, so verify against the controller when the answer matters. |\n| Adds generic recommendations unsupported by results | The \"analysis discipline\" rules. |\n| Drops requested fields or reorders results | State the required fields and ordering in the request itself, not only in the system prompt. |\n| Multi-tool workflows take 30–50s end to end | Prefer the tools that answer a whole question in one call: `ako_ingress_diagnose` replaces a check/logs/diff sequence, and `ssl_expiry_check` replaces enumerating certificates and comparing dates by hand. |\n| Reads an empty analytics series as an outage | The \"empty series means no data\" rule. Virtual services with no traffic legitimately return nothing for the window. |\n| Passes a bare number where a duration was meant, or invents its own unit | State the window explicitly, in seconds or with a suffix. |\n| Confuses an AKO problem with a Controller problem and reports the wrong root cause | The \"two control planes\" block above. Make the model name the side it is describing. |\n| Reads an empty SSL certificate list as \"no certificates configured\" | Certificates are tenant-scoped. Report it as a visibility result, not an inventory result. |\n\n## Reporting results\n\nLocal-model compatibility is an explicit design constraint for this family, and\nthe evidence base is small. If you evaluate a model against this skill —\nQwen, Mistral, Granite, or anything else — a report of what worked and what did\nnot is genuinely useful:\n[github.com/vmware-skills/VMware-AVI/issues](https://github.com/vmware-skills/VMware-AVI/issues).\n\nFile v1.10.0:references/capabilities.md\n\n# VMware AVI Capabilities\n\nAll 28 MCP tools exposed by `vmware-avi mcp` (v1.5.15+; legacy entry point: `vmware-avi-mcp`), organized by category.\n\n## Version Compatibility\n\n### AVI Controller (NSX ALB)\n\n| Controller Version | Support Level | Notes |\n|--------------------|--------------|-------|\n| AVI 30.x | ✅ Full | All 28 tools verified. avisdk `<31.0` upper bound. |\n| AVI 22.1.x | ✅ Full | All analytics endpoint quirks fixed in v1.5.11 — `vs_analytics` uses POST `/analytics/metrics/collection` with `metric_requests[]`; `pool_list` uses `/virtualservice-inventory` to expose K8S-managed pool groups; SE→VS mapping reconstructed from `vip_summary[].service_engine[]`. |\n| AVI < 22.1 | ⚠ Untested | avisdk may load but analytics/inventory endpoints differ. Not in CI. |\n\n### VCF (VMware Cloud Foundation)\n\n| VCF Version | Bundled AVI / NSX ALB | Support |\n|-------------|-----------------------|---------|\n| VCF 9.1 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) |\n| VCF 9.0 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) |\n| VCF 5.x | AVI 22.x | ✅ Full |\n\n### Runtime\n\n| Requirement | Version | Notes |\n|-------------|---------|-------|\n| Python | ≥ 3.11 | `requires-python` bumped from 3.10 to 3.11 in v1.5.19 (regression eval uses `tomllib`). |\n| avisdk | ≥ 22.1, < 31.0 | Auto-installed. Range chosen so VCF 9.x bundled AVI is covered without forcing a major SDK jump. |\n| kubernetes (Python) | ≥ 28.0 | Required only for AKO mode. |\n| kubectl | any recent | Required only for AKO operations. |\n| helm | ≥ 3.x | Required only for AKO config show/diff/upgrade. |\n\n### MCP Transport\n\n| Mode | Status | Recommended |\n|------|--------|-------------|\n| `vmware-avi mcp` (CLI subcommand, stdio) | ✅ Full | ✅ v1.5.15+ default — no PyPI re-resolve, works behind corporate TLS proxies. |\n| `vmware-avi-mcp` (legacy console script, stdio) | ✅ Full | Kept for backward compatibility with pre-1.5.15 configs. |\n| `python -m vmware_avi.mcp_server` (stdio, via `__main__.py`) | ✅ Full | Docker image `CMD` only — not for end-user CLI install, and no longer used by `smithery.yaml` (which now calls the `vmware-avi mcp` entry point). Added v1.5.22. |\n| `uvx --from vmware-avi==1.10.0 vmware-avi-mcp` | ⚠ Fallback | Re-resolves PyPI on each launch; fails behind corporate TLS proxies (踩坑 #25). Use `UV_NATIVE_TLS=true` workaround. |\n\n## Automation Level Reference\n\nEach operation is classified by autonomy level per the Enterprise Harness Engineering framework:\n\n| Level | Meaning | Agent autonomy | Examples in this skill |\n|:-:|---|---|---|\n| **L1** | Read-only, raw data | Always auto-run | `vs_list`, `vs_status`, `pool_list`, `pool_members`, `se_list`, `se_health`, `vs_analytics` queries, AKO/AMKO inventory (`ako_status`, `ako_clusters`, `ako_amko_status`) |\n| **L2** | Read + analysis / recommendation | Always auto-run | traffic distribution analysis, health score correlation, pool member ratio summaries, analytics-driven anomaly detection |\n| **L3** | Single write — user must approve | Only after explicit confirmation. MCP: `vs_toggle`, `pool_member_disable`, `ako_restart`, `ako_config_upgrade`, `ako_sync_force` return a `blast_radius` preview unless `confirm=true`; CLI: double-confirm + `--dry-run` | `vs_toggle`, `pool_member_enable`/`pool_member_disable`, `ako_restart`, `ako_config_upgrade`, `ako_sync_force` |\n| **L4** | Multi-step plan / apply workflow | Plan generation auto; apply gated by user approval | *(roadmap — VS deployment plans, blue/green pool member rotations)* |\n| **L5** | Auto-remediation from learned pattern | Pattern library only; requires `risk:low` + `reversible:true` + `repeatable:true` | *(roadmap — candidates: stale pool member drain, AKO controller reconnect)* |\n\n> Classification comes from each tool's `[READ]`/`[WRITE]` docstring marker,\n> not from this table — see the README.\n\n**Notes**:\n- L1/L2 tools are always safe for agents to call without confirmation.\n- L3 tools always pass through the `@vmware_tool` decorator: connection check → policy check → audit log. The five gated tools then measure their blast radius; without `confirm=true` they stop there, and with it they refuse on a blocker or an unreadable field.\n- AKO Kubernetes operations affect ingress/service routing — even \"low-risk\" restarts can briefly interrupt traffic; treat as L3 with explicit user approval.\n\n## Traditional Mode — AVI Controller (13 tools)\n\n### Virtual Service (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `vs_list` | List all Virtual Services on the active controller | `controller` (string, optional) | Low | No |\n| `vs_status` | Show detailed status of a single VS (VIP, health score, pool binding, enabled state) | `name` (string, **required**) | Low | No |\n| `vs_toggle` | Enable or disable a Virtual Service. Returns `blast_radius` (VS, uuid, current state, VIPs, pools and member counts); previews unless `confirm=true` | `name` (string, **required**), `enable` (boolean, **required**), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | Medium | Yes (both directions) |\n\n### Pool Member (4)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `pool_list` | Discover pools on the Controller, with VS bindings (uses `/virtualservice-inventory` to include K8S-managed pool groups) | `vs_filter` (string, optional) | Low | No |\n| `pool_members` | List all members of a pool with health status and ratio | `pool` (string, **required**) | Low | No |\n| `pool_member_enable` | Enable a pool member (restore traffic after maintenance) | `pool` (string, **required**), `server` (string, **required**) | Low | No |\n| `pool_member_disable` | Disable a pool member with graceful connection drain. Returns `blast_radius` (pool, member, enabled members before/after); refuses the pool's only enabled member | `pool` (string, **required**), `server` (string, **required**), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | Medium | Yes |\n\n### SSL Certificate (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ssl_list` | List all SSL/TLS certificates on the controller | *(none)* | Low | No |\n| `ssl_expiry_check` | Check certificates expiring within N days, with VS mapping | `days` (integer, default: 30) | Low | No |\n\n### Analytics (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `vs_analytics` | Show VS metrics: L4 bandwidth/connections (`l4_client.avg_bandwidth`, `avg_complete_conns`, `avg_new_established_conns`) + L7 client transaction latency (`l7_client.avg_client_txn_latency`), response errors, total responses | `vs_name` (string, **required**) | Low | No |\n| `vs_error_logs` | Show recent request error logs for a VS (HTTP status ≥ 400, filter `ge(response_code,400)`) | `vs_name` (string, **required**), `since` (string, default: `\"1h\"`) | Low | No |\n\n### Service Engine (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `se_list` | List all Service Engines: name, mgmt IP, operational status, SE group (via `serviceengine-inventory`, config + runtime merged) | *(none)* | Low | No |\n| `se_health` | Check SE health: per-SE operational status + connected-VS counts (placement map from `virtualservice-inventory`) | *(none)* | Low | No |\n\n## AKO Mode — Kubernetes (15 tools)\n\n### AKO Pod Ops (4)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_status` | Check AKO pod status (phase, restart count, readiness) | `context` (string, optional) | Low | No |\n| `ako_logs` | View AKO pod logs (tail mode) | `tail` (integer, default: 100), `since` (string, optional) | Low | No |\n| `ako_restart` | Restart AKO pod by deleting it (its StatefulSet recreates it). Returns `blast_radius` (pod, uid, phase, Ingresses); the delete is pinned to the measured uid | `context` (string, optional), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | High | Yes |\n| `ako_version` | Show AKO container image tag and Helm chart version | `context` (string, optional) | Low | No |\n\n### AKO Config (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_config_show` | Show current AKO Helm values (values.yaml snapshot; release auto-discovered via `helm list` — official installs use `--generate-name`) | *(none)* | Low | No |\n| `ako_config_diff` | Preview the pending Helm change, running the same command `ako_config_upgrade` does (`--reuse-values` included) so the diff describes the actual upgrade rather than the chart's defaults. Chart: `oci://projects.packages.broadcom.com/ako/helm-charts/ako` | `chart_version` (optional — empty resolves to registry latest, which can move between calls) | Low | No |\n| `ako_config_upgrade` | Helm upgrade the discovered AKO release from the official Broadcom OCI chart with `--reuse-values`. Without `confirm=true` returns `blast_radius` (release, chart now → chart to, status) plus the `helm upgrade --dry-run` output | `confirm` (boolean, default `false`), `chart_version` (optional), `dry_run` / `confirmed` (deprecated aliases) | High | Yes |\n\n### Ingress Diagnostics (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_ingress_check` | Validate Ingress annotations against AKO expectations in a namespace | `namespace` (string, **required**) | Low | No |\n| `ako_ingress_map` | Show full Ingress-to-VS mapping across all namespaces | *(none)* | Low | No |\n| `ako_ingress_diagnose` | Diagnose why a specific Ingress has no corresponding VS on the Controller | `name` (string, **required**), `namespace` (string, default: `\"default\"`) | Low | No |\n\n### Sync Diagnostics (3)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_sync_status` | Check overall K8s-to-Controller sync health | *(none)* | Low | No |\n| `ako_sync_diff` | Show objects present in K8s but missing on Controller, and vice versa | *(none)* | Low | No |\n| `ako_sync_force` | Force AKO to re-reconcile all K8s objects against the Controller (deletes the AKO pod). Returns `blast_radius` like `ako_restart` | `context` (string, optional), `confirm` (boolean, default `false`), `confirmed` (deprecated alias) | Medium | Yes |\n\n### Multi-cluster (2)\n\n| Tool | Description | Parameters | Risk | Confirm |\n|------|-------------|------------|:----:|:-------:|\n| `ako_clusters` | List all K8s clusters with AKO deployed | *(none)* | Low | No |\n| `ako_amko_status` | Show AMKO (Avi Multi-cluster Kubernetes Operator) GSLB status | *(none)* | Low | No |\n\n## Risk Level Definitions\n\n| Level | Meaning | Examples |\n|-------|---------|---------|\n| **Low** | Read-only query, no state change | `vs_list`, `ssl_expiry_check`, `ako_logs` |\n| **Medium** | State change affecting traffic flow, but recoverable | `vs_toggle` (disable), `pool_member_disable`, `ako_sync_force` |\n| **High** | Disruptive operation affecting running services or deployments | `ako_restart`, `ako_config_upgrade` |\n\n## Tool Counts by Risk Level\n\nEach tool is counted exactly once, at its default (worst-case) risk level, so the\nthree rows sum to the full tool surface:\n\n| Risk | Count | Tools |\n|------|:-----:|-------|\n| Low | 23 | All 22 read-only tools + `pool_member_enable` (a write, but it only restores traffic) |\n| Medium | 3 | `vs_toggle`, `pool_member_disable`, `ako_sync_force` |\n| High | 2 | `ako_restart`, `ako_config_upgrade` |\n\n**Total: 23 + 3 + 2 = 28.**\n\n> Note: risk is contextual for two tools, but each is listed only once above, at its\n> higher level. `vs_toggle` with `enable=true` is effectively Low risk; with\n> `enable=false` it is Medium (and High against a critical VS), so it is counted as\n> Medium. `ako_config_upgrade` without `confirm=true` is Low risk (preview only); with\n> `confirm=true` it is High, so it is counted as High.\n\n## Audit Coverage\n\nAll 28 tools are wrapped with `@vmware_tool` from vmware-policy, which provides:\n\n- **Pre-execution**: Policy rule check against `~/.vmware/rules.yaml` (deny rules, maintenance windows)\n- **Post-execution**: Audit log entry written to `~/.vmware/audit.db` (SQLite WAL mode)\n- **Input sanitization**: All AVI API response text processed through `_sanitize()` (truncation + control character cleanup)\n\n## Traditional vs AKO Mode Requirements\n\n| Requirement | Traditional Mode | AKO Mode |\n|-------------|:----------------:|:--------:|\n| AVI Controller access | Required | Optional (for sync tools) |\n| avisdk Python package | Required | Not required |\n| kubectl in PATH | Not required | Required |\n| helm in PATH | Not required | Required (for config operations) |\n| kubeconfig | Not required | Required |\n| kubernetes Python package | Not required | Required |\n\nFile v1.10.0:references/cli-reference.md\n\n# VMware AVI CLI Reference\n\nComplete command reference for the `vmware-avi` CLI (v1.4.0).\n\n## Global Commands\n\n| Command | Description | Flags |\n|---------|-------------|-------|\n| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |\n| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |\n| `vmware-avi config` | Show current configuration (passwords masked) | -- |\n\n## Virtual Service Commands (`vmware-avi vs`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi vs list` | List all Virtual Services | `--controller <name>` (optional, use a specific controller) |\n| `vmware-avi vs status <name>` | Show VS status details (VIP, health, pool binding) | `<name>` (required) |\n| `vmware-avi vs enable <name>` | Enable a Virtual Service | `<name>` (required) |\n| `vmware-avi vs disable <name>` | Disable a Virtual Service | `<name>` (required). **Double-confirm required.** |\n\n## Pool Member Commands (`vmware-avi pool`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi pool members <pool>` | List pool members and health status | `<pool>` (required) |\n| `vmware-avi pool enable <pool> <server-ip>` | Enable a pool member (restore traffic) | `<pool>` (required), `<server-ip>` (required) |\n| `vmware-avi pool disable <pool> <server-ip>` | Disable a pool member (graceful drain) | `<pool>` (required), `<server-ip>` (required). **Double-confirm required.** |\n\n## SSL Certificate Commands (`vmware-avi ssl`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ssl list` | List all SSL certificates | -- |\n| `vmware-avi ssl expiry` | Check certificates expiring within N days | `--days <N>` (default: 30) |\n\n## Service Engine Commands (`vmware-avi se`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi se list` | List all Service Engines: name, mgmt IP, operational status, SE group (status from the `serviceengine-inventory` endpoint, config + runtime merged) | -- |\n| `vmware-avi se health` | Check Service Engine health: per-SE operational status + connected-VS counts (placement map from `virtualservice-inventory`) | -- |\n\n## Analytics Commands\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi analytics <vs-name>` | Show VS analytics: L4 bandwidth/connections + L7 client transaction latency (`l7_client.avg_client_txn_latency`), response errors, total responses | `<vs-name>` (required) |\n| `vmware-avi logs <vs-name>` | Show VS request error logs (HTTP status ≥ 400, filter `ge(response_code,400)`) | `<vs-name>` (required), `--since <range>` (default: `1h`, e.g. `30m`, `2h`) |\n\n## AKO Pod Commands (`vmware-avi ako`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako status` | Check AKO pod status (Running, CrashLoopBackOff, etc.) | `--context <k8s-context>` (optional) |\n| `vmware-avi ako logs` | View AKO pod logs | `--tail <N>` (default: 100), `--since <range>` (e.g. `30m`), `--context <k8s-context>` (optional) |\n| `vmware-avi ako restart` | Restart AKO pod by deleting it (its StatefulSet recreates it) | `--context <k8s-context>` (optional). **Double-confirm required.** |\n| `vmware-avi ako version` | Show AKO version info (image tag, Helm chart version) | `--context <k8s-context>` (optional) |\n\n## AKO Config Commands (`vmware-avi ako config-*`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako config-show` | Show current AKO Helm values.yaml (release auto-discovered via `helm list` — official installs use `--generate-name`) | -- |\n| `vmware-avi ako config-diff` | Preview the pending Helm change against `oci://projects.packages.broadcom.com/ako/helm-charts/ako`, using `--reuse-values` so it matches what `config-upgrade` would apply | `--chart-version` (pin the version; default is registry latest) |\n| `vmware-avi ako config-upgrade` | Helm upgrade the discovered AKO release from the official Broadcom OCI chart with `--reuse-values` | `--dry-run` / `--no-dry-run` (default: `--dry-run`). **Double-confirm required for actual apply.** |\n\n## AKO Ingress Commands (`vmware-avi ako ingress-*`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako ingress-check <namespace>` | Validate Ingress annotations in a namespace | `<namespace>` (required) |\n| `vmware-avi ako ingress-map` | Show Ingress to VS mapping across all namespaces | -- |\n| `vmware-avi ako ingress-diagnose <name>` | Diagnose why an Ingress has no corresponding VS | `<name>` (required), `--namespace <ns>` (default: `default`) |\n\n## AKO Sync Commands (`vmware-avi ako sync-*`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako sync-status` | Check K8s-Controller sync status | -- |\n| `vmware-avi ako sync-diff` | Show K8s-Controller inconsistencies (objects in K8s but not on Controller, or vice versa) | -- |\n| `vmware-avi ako sync-force` | Force AKO to re-reconcile all K8s objects | **Double-confirm required.** |\n\n## AKO Multi-cluster Commands (`vmware-avi ako`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ako clusters` | List all clusters with AKO deployed | -- |\n| `vmware-avi ako amko-status` | Show AMKO (multi-cluster GSLB) status | -- |\n\n## Destructive Operations Summary\n\nThe following commands require double confirmation before execution:\n\n| Command | Risk | Reason |\n|---------|------|--------|\n| `vs disable` | Medium | Takes a VS offline, impacts client traffic |\n| `pool disable` | Medium | Drains traffic from a pool member |\n| `ako restart` | High | Restarts AKO pod, temporarily pauses K8s-Controller sync |\n| `ako config-upgrade` | High | Modifies AKO Helm release, may change load-balancing behavior |\n| `ako sync-force` | Medium | Forces full re-reconciliation, may cause brief churn |\n\n## Environment Variables\n\n| Variable | Purpose |\n|----------|---------|\n| `VMWARE_AVI_CONFIG` | Override config file path (default: `~/.vmware-avi/config.yaml`) |\n| `<CONTROLLER_NAME>_PASSWORD` | AVI Controller password (e.g. `PROD_AVI_PASSWORD`) |\n\n## Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| `0` | Success |\n| `1` | Failure (connectivity error, missing config, check failed) |\n\nFile v1.10.0:references/setup-guide.md\n\n# VMware AVI Setup Guide\n\nComplete installation, configuration, and AI platform integration guide for the current `vmware-avi` release. Refer to `RELEASE_NOTES.md` in the repository for version-specific changes.\n\n## Prerequisites\n\n| Requirement | Version | Purpose |\n|-------------|---------|---------|\n| Python | >= 3.10 | Runtime |\n| uv | >= 0.4 | Package manager and tool runner |\n| avisdk | >= 22.1 | AVI Controller API (auto-installed) |\n| kubernetes (Python) | >= 28.0 | K8s API client for AKO operations (auto-installed) |\n| kubectl | any recent | Required for AKO pod/ingress/sync operations |\n| helm | >= 3.x | Required for AKO config show/diff/upgrade |\n| vmware-policy | >= 1.0.0 | Audit and policy engine (auto-installed) |\n\n**Optional**: `kubeconfig` file with access to clusters running AKO (only needed for AKO mode).\n\n## Installation\n\n### Standard Install (recommended)\n\n```bash\nuv tool install vmware-avi==1.10.0\n```\n\nThis installs the CLI (`vmware-avi`, with `vmware-avi mcp` subcommand for the MCP server in v1.5.15+), the legacy `vmware-avi-mcp` entry point (for backward compatibility), and all Python dependencies in an isolated environment.\n\n### Development Install\n\n```bash\ngit clone --branch v1.10.0 https://github.com/vmware-skills/VMware-AVI.git\ncd VMware-AVI\nuv pip install -e \".[dev]\"\n```\n\n### Alternative Deployment: Container / Smithery\n\nFor platforms that prefer containerized MCP servers (e.g., Smithery registry, Kubernetes-hosted agents, isolated CI runners), `vmware-avi` ships a `Dockerfile` and `smithery.yaml` at the repository root (added v1.5.22).\n\n#### Docker\n\nBuild and run the MCP server in a container. The image uses `python:3.12-slim` with `uv` for dependency installation and runs `python -m vmware_avi.mcp_server` on stdio (no port exposed — MCP uses stdin/stdout).\n\n```bash\ngit clone --branch v1.10.0 https://github.com/vmware-skills/VMware-AVI.git\ncd VMware-AVI\n\n# Build\ndocker build -t vmware-avi-mcp .\n\n# Run — mount your config directory into the container\ndocker run -i --rm \\\n  -v ~/.vmware-avi:/root/.vmware-avi:ro \\\n  -e VMWARE_AVI_CONFIG=/root/.vmware-avi/config.yaml \\\n  vmware-avi-mcp\n```\n\nThe container's `CMD` is `python -m vmware_avi.mcp_server`, which is wired through `vmware_avi/mcp_server/__main__.py` to the same FastMCP entry point as the CLI subcommand. All 28 tools are available.\n\n#### Smithery\n\n`vmware-avi` is published on the [Smithery](https://smithery.ai) registry. The `smithery.yaml` at the repo root declares:\n\n- `startCommand.type: stdio` — Smithery launches the server over stdio\n- `configSchema.properties.config_path` — optional override for the config file location\n- `commandFunction` — invokes the `vmware-avi mcp` entry point with `VMWARE_AVI_CONFIG` set from the user's Smithery config\n\nUsers can install via the Smithery UI or CLI without managing Python environments locally. Smithery handles the container build and stdio bridge automatically.\n\n#### When to use which deployment\n\n| Deployment | Best For |\n|------------|----------|\n| `uv tool install vmware-avi==1.10.0` + `vmware-avi mcp` | Local developer workstation, single-user CLI + MCP |\n| Docker image | Self-hosted agents, CI runners, isolated environments, multi-user servers |\n| Smithery | Zero-install agent integration, registry-managed discovery, hosted-MCP workflows |\n\n### Verify Installation\n\n```bash\nvmware-avi doctor\n```\n\nThe `doctor` command checks all of the following:\n- Config directory and files exist\n- `.env` file permissions are 600\n- avisdk and kubernetes Python packages installed\n- kubectl and helm binaries in PATH\n- kubeconfig file exists\n- AVI Controller(s) reachable\n- vmware-policy package installed\n\n## AVI Controller Configuration\n\n### Step 1: Generate config templates\n\n```bash\nvmware-avi init\n```\n\nThis creates two files in `~/.vmware-avi/`:\n- `config.yaml` -- connection targets and AKO settings\n- `.env` -- passwords (auto-set to chmod 600)\n\n### Step 2: Edit config.yaml\n\n```yaml\n# ~/.vmware-avi/config.yaml\ncontrollers:\n  - name: prod-avi\n    host: avi-controller.example.com\n    username: admin\n    api_version: \"22.1.4\"\n    tenant: admin\n    port: 443\n    verify_ssl: true\n    environment: production   # scopes policy rules; see the field table below\n\n  - name: staging-avi\n    host: avi-staging.example.com\n    username: admin\n    api_version: \"22.1.4\"\n    tenant: admin\n    verify_ssl: false    # lab/self-signed certs only\n    environment: staging\n\ndefault_controller: prod-avi\n\nako:\n  kubeconfig: ~/.kube/config\n  default_context: \"\"        # empty = use current-context\n  namespace: avi-system\n```\n\n**config.yaml fields**:\n\n| Field | Required | Default | Description |\n|-------|:--------:|---------|-------------|\n| `controllers[].name` | Yes | -- | Unique identifier for this controller |\n| `controllers[].host` | Yes | -- | Controller hostname or IP |\n| `controllers[].username` | No | `admin` | API username |\n| `controllers[].api_version` | No | `22.1.4` | AVI API version string |\n| `controllers[].tenant` | No | `admin` | AVI tenant name |\n| `controllers[].port` | No | `443` | Controller HTTPS port |\n| `controllers[].verify_ssl` | No | `true` | TLS certificate verification |\n| `controllers[].environment` | Optional | -- | Free-form label (`production` / `staging` / `lab`). An environment-scoped `deny` rule in `~/.vmware/rules.yaml` can match on it to block writes (e.g. freeze `production`); a controller with no label is simply not matched by such a rule. Read-only operations are never affected. |\n| `default_controller` | No | first entry | Which controller to use by default |\n| `ako.kubeconfig` | No | `~/.kube/config` | Path to kubeconfig file |\n| `ako.default_context` | No | current-context | K8s context for AKO operations |\n| `ako.namespace` | No | `avi-system` | Namespace where AKO is deployed |\n\n### Step 3: Set passwords in .env\n\n```bash\n# ~/.vmware-avi/.env\nPROD_AVI_PASSWORD=your-secure-password-here\nSTAGING_AVI_PASSWORD=another-password-here\n```\n\nPassword environment variable naming convention: `<CONTROLLER_NAME>_PASSWORD` where the controller name is uppercased and hyphens are replaced with underscores.\n\n| Controller Name | Environment Variable |\n|-----------------|---------------------|\n| `prod-avi` | `PROD_AVI_PASSWORD` |\n| `staging-avi` | `STAGING_AVI_PASSWORD` |\n| `my-lab` | `MY_LAB_PASSWORD` |\n\n### Step 4: Verify connectivity\n\n```bash\nvmware-avi doctor\nvmware-avi vs list          # quick smoke test\n```\n\n## AKO / Kubernetes Configuration\n\nAKO operations require a valid kubeconfig with access to the cluster(s) where AKO is deployed.\n\n### kubeconfig Setup\n\n```bash\nkubectl --context my-cluster get pods -n avi-system   # verify access\nkubectl config get-contexts                            # list all contexts\n```\n\nIf your AKO is deployed in a non-default namespace, update `ako.namespace` in config.yaml. AKO config commands (`config-show`, `config-diff`, `config-upgrade`) require Helm 3.x:\n\n```bash\nhelm repo add ako https://projects.registry.vmware.com/chartrepo/ako\nhelm repo update\n```\n\n### Password obfuscation at rest\n\nOn first load, any plaintext `*_PASSWORD` value in `.env` is automatically\nrewritten to a grep-safe `b64:<encoded>` form and decoded transparently at\nruntime, so a casual `grep` of the file no longer reveals the password. Values\nare read and written through python-dotenv's own parser, so the stored secret\nnever drifts from what you configured (quotes, inline comments, and trailing\nwhitespace are handled correctly).\n\n> **This is obfuscation, not encryption.** Anyone who can read the file can\n> still decode it. For real secrecy at rest, do not store the password in `.env`\n> at all — inject it from a secret manager (HashiCorp Vault, CyberArk, AWS\n> Secrets Manager, or a Kubernetes Secret) into the `*_PASSWORD` environment\n> variable at process start. The code reads the env var either way.\n\n## Security\n\n> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** \"VMware\", \"NSX\", and \"AVI\" are trademarks of Broadcom.\n\n### Password Management\n\n- Passwords are **never** stored in `config.yaml` -- only in `.env`\n- The `.env` file must have `chmod 600` permissions (owner read/write only)\n- `vmware-avi doctor` warns if `.env` permissions are too open\n- Never commit `.env` files to version control\n\n### Audit Logging\n\nAll operations (CLI and MCP) are recorded via vmware-policy:\n\n- **Location**: `~/.vmware/audit.db` (SQLite, WAL mode)\n- **Contents**: timestamp, tool name, parameters, result, user identity\n- **Query**: `vmware-audit log --last 20`\n\n### Policy Rules\n\nOptional deny rules and maintenance windows can be configured in `~/.vmware/rules.yaml` (managed by vmware-policy). Example: block `vs_toggle` disable during business hours.\n\n### Destructive Operation Safety\n\n| Operation | Safety Measures |\n|-----------|----------------|\n| VS disable | CLI: double confirmation prompt. MCP `vs_toggle`: previews `blast_radius` unless `confirm=true` |\n| Pool member disable | CLI: double confirmation prompt (graceful drain). MCP: previews unless `confirm=true`; refuses the pool's only enabled member |\n| AKO restart | CLI: double confirmation prompt. MCP: previews unless `confirm=true`; refuses a terminating pod |\n| AKO config upgrade | CLI: defaults to `--dry-run`; double confirmation for actual apply. MCP: previews (with `helm --dry-run` output) unless `confirm=true`; refuses a failing dry-run |\n| AKO sync force | CLI: double confirmation prompt. MCP: previews unless `confirm=true` |\n\n### Read-Only Operation\n\nTo run the agent read-only, give it a read-only AVI service account (RBAC).\n\n### Data Sanitization\n\nAll text returned from AVI Controller APIs is processed through `_sanitize()`:\n- Truncated to 500 characters maximum\n- C0/C1 control characters stripped\n- Prevents prompt injection via API response content\n\n### TLS Verification\n\n- Enabled by default (`verify_ssl: true`)\n- Set `verify_ssl: false` only for lab environments with self-signed certificates\n- Production deployments should always use valid TLS certificates\n\n## AI Platform Compatibility\n\nvmware-avi supports MCP (Model Context Protocol) integration with the following platforms.\n\n### Claude Code (Claude Desktop / CLI)\n\nAdd to `~/.claude.json` (global) or `.mcp.json` (project-level):\n\n```json\n{\n  \"mcpServers\": {\n    \"vmware-avi\": {\n      \"command\": \"vmware-avi\",\n      \"args\": [\"mcp\"],\n      \"env\": {\n        \"VMWARE_AVI_CONFIG\": \"~/.vmware-avi/config.yaml\"\n      }\n    }\n  }\n}\n```\n\n> v1.5.15+ recommends the single-command form `vmware-avi mcp`. Pre-1.5.15 used\n> `uvx --from vmware-avi vmware-avi-mcp`, which still works but re-resolves from <!-- install-pin: historical -->\n> PyPI on each launch and breaks behind corporate TLS proxies. The legacy\n> `vmware-avi-mcp` entry point is also kept for backward compatibility.\n\n### Cursor\n\nAdd to `.cursor/mcp.json` in your project root:\n\n```json\n{\n  \"mcpServers\": {\n    \"vmware-avi\": {\n      \"command\": \"vmware-avi\",\n      \"args\": [\"mcp\"],\n      \"env\": {\n        \"VMWARE_AVI_CONFIG\": \"~/.vmware-avi/config.yaml\"\n      }\n    }\n  }\n}\n```\n\n### Windsurf / Cline / Qwen / Other MCP-compatible Agents\n\nUse the same JSON block as above, placed in the platform-specific config file:\n\n| Platform | Config File |\n|----------|-------------|\n| Windsurf | `~/.windsurf/mcp.json` |\n| Cline (VS Code) | Cline MCP settings panel |\n| Qwen / other | Any MCP stdio transport config |\n\n### Ollama / Local Models\n\nFor local models with limited context windows, prefer CLI mode over MCP:\n\n```bash\n# CLI produces ~2K tokens vs ~8K for MCP JSON\nvmware-avi vs list\nvmware-avi ako status\n```\n\nIf your Ollama setup supports MCP via a bridge (e.g., `mcp-bridge`), use the same `vmware-avi mcp` command (v1.5.15+).\n\n## Troubleshooting\n\n### \"Config file not found\" on first run\n\n```bash\nvmware-avi init    # generates ~/.vmware-avi/config.yaml and .env\n```\n\n### \"Password not found\" error\n\nThe environment variable name must match `<CONTROLLER_NAME>_PASSWORD` with the controller name uppercased and hyphens replaced by underscores. Check:\n\n```bash\n# If controller name is \"prod-avi\", the variable must be:\nexport PROD_AVI_PASSWORD=yourpassword\n\n# Or set it in ~/.vmware-avi/.env:\necho 'PROD_AVI_PASSWORD=yourpassword' >> ~/.vmware-avi/.env\n```\n\n### \"Controller unreachable\" in doctor\n\n1. Verify the `host` and `port` in config.yaml are correct\n2. Test network connectivity: `curl -k https://avi-controller.example.com/api/cluster`\n3. For self-signed certs, set `verify_ssl: false` in config.yaml\n4. Check if a firewall or VPN is blocking port 443\n\n### MCP server not starting\n\n1. Verify the CLI is on PATH: `which vmware-avi`\n2. Confirm the `mcp` subcommand: `vmware-avi mcp --help` (v1.5.15+)\n3. Check that `~/.vmware-avi/config.yaml` exists (MCP server loads config on startup)\n4. Legacy: `which vmware-avi-mcp` and `vmware-avi-mcp --help` still work\n5. Never use `python -m vmware_avi.mcp_server` — always use `vmware-avi mcp` (v1.5.15+) or the legacy `vmware-avi-mcp` entry point\n\n### `invalid peer certificate: UnknownIssuer` (uvx)\n\nA corporate TLS proxy is intercepting `https://pypi.org` and uv's bundled cert\nstore doesn't trust the proxy CA. Fixes (in order of preference):\n\n1. Use the v1.5.15+ form `vmware-avi mcp` — no PyPI roundtrip needed.\n2. Tell uv to use the system cert store: `export UV_NATIVE_TLS=true` (or pass\n   `--native-tls` to `uvx`).\n3. Point uv at an explicit CA bundle: `export SSL_CERT_FILE=/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem`\n\n### kubectl / helm not found\n\n```bash\n# macOS\nbrew install kubectl helm\n```\n\nFor Linux, see https://kubernetes.io/docs/tasks/tools/ and https://helm.sh/docs/intro/install/.\n\n### AKO namespace not found\n\nUpdate `ako.namespace` in config.yaml to match your deployment (default: `avi-system`).\n\n### Permission denied on .env file\n\n```bash\nchmod 600 ~/.vmware-avi/.env\n```\n\nFile v1.10.0:skill-card.md\n\n## Description:\n\nVMware AVI helps agents administer NSX Advanced Load Balancer and AKO environments, including virtual services, pool members, SSL expiry, analytics, service engines, ingress diagnostics, Helm configuration, and Kubernetes-to-Controller sync checks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, platform engineers, and operations teams use this skill to inspect and manage VMware AVI Controller and AKO Kubernetes load-balancing resources. It supports troubleshooting, certificate audits, pool member maintenance, ingress diagnostics, service engine health checks, and guarded changes that may affect traffic.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can administer live AVI/NSX ALB and AKO resources, including operations that may affect application traffic.\n\nMitigation: Install it only in environments where that administration is intended, use least-privilege AVI and Kubernetes accounts, and require review of write previews before approval.\n\nRisk: Controller and Kubernetes credentials may be exposed if stored or shared carelessly.\n\nMitigation: Prefer secret-manager or session environment injection, keep `.env` permissions at chmod 600, and avoid committing credentials to source control.\n\nRisk: Destructive or disruptive operations such as virtual service disablement, pool member drain, AKO restart, AKO sync force, or Helm upgrade can interrupt traffic.\n\nMitigation: Use the built-in blast-radius preview or dry-run behavior first, confirm blockers are absent, and approve state-changing commands only after reviewing the affected resources.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/vmware-avi)\n- [Project homepage](https://github.com/vmware-skills/VMware-AVI)\n- [VMware AVI capabilities](references/capabilities.md)\n- [VMware AVI setup guide](references/setup-guide.md)\n- [VMware AVI CLI reference](references/cli-reference.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and operational guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include tool-selection guidance, blast-radius review prompts, diagnostics summaries, and configuration steps.]\n\n## Skill Version(s):\n\n1.10.0 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.1: 7 files, 25000 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11949b), references/cli-reference.md (6579b), references/setup-guide.md (13570b), skill-card.md (2682b), SKILL.md (15916b), _meta.json (129b)\n\nFile v1.9.1:SKILL.md\n\n---\nname: vmware-avi\ndescription: >\n  Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery\n  in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context.\n  Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs,\n  service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics,\n  and multi-cluster AKO overview.\n  Always use it for \"virtual service\", \"pool member\", \"AKO status\", \"AKO logs\", \"ingress diagnose\", \"ssl expiry\", \"load balancer\", \"NSX ALB\",\n  \"AVI controller\", \"Avi Load Balancer\", \"AKO sync\", or \"负载均衡\" tasks.\n  Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks.\n  For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.\ninstaller:\n  kind: uv\n  package: vmware-avi\nargument-hint: \"[vs-name, ako command, or describe your task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"vmware-avi\",\"uvx\"]},\"optional\":{\"env\":[\"VMWARE_AVI_CONFIG\",\"<CONTROLLER>_PASSWORD\",\"<CONTROLLER>_USERNAME\",\"KUBECONFIG\",\"VMWARE_AUDIT_APPROVED_BY\"],\"bins\":[\"vmware-policy\",\"kubectl\",\"helm\"]},\"homepage\":\"https://github.com/vmware-skills/VMware-AVI\",\"emoji\":\"🔀\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.\n  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller \"prod-avi\" → PROD_AVI_PASSWORD).\n  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.\n---\n\n# VMware AVI\n\n> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** \"VMware\", \"NSX\", and \"AVI\" are trademarks of Broadcom. Source code is publicly auditable at [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI) under the MIT license.\n\nAVI (NSX Advanced Load Balancer) application delivery and AKO Kubernetes operations — 28 MCP tools.\n\n> **Dual mode**: Traditional AVI Controller management + AKO K8s operations in one skill.\n> **Family**: [vmware-aiops](https://github.com/vmware-skills/VMware-AIops) (VM lifecycle), [vmware-monitor](https://github.com/vmware-skills/VMware-Monitor) (inventory/health), [vmware-storage](https://github.com/vmware-skills/VMware-Storage) (iSCSI/vSAN), [vmware-vks](https://github.com/vmware-skills/VMware-VKS) (Tanzu Kubernetes), [vmware-nsx](https://github.com/vmware-skills/VMware-NSX) (NSX networking), [vmware-nsx-security](https://github.com/vmware-skills/VMware-NSX-Security) (DFW/firewall), [vmware-aria](https://github.com/vmware-skills/VMware-Aria) (metrics/alerts/capacity), [vmware-harden](https://github.com/vmware-skills/VMware-Harden) (compliance baselines).\n> | [vmware-pilot](../vmware-pilot/SKILL.md) (workflow orchestration) | [vmware-policy](../vmware-policy/SKILL.md) (audit/policy)\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Virtual Service** | list, status, enable/disable | 3 | 2R / 1W |\n| **Pool Member** | pool discovery, member list, enable/disable member (drain/restore traffic) | 4 | 2R / 2W |\n| **SSL Certificate** | list, expiry check | 2 | 2R |\n| **Analytics** | VS metrics overview, request error logs | 2 | 2R |\n| **Service Engine** | list, health check | 2 | 2R |\n| **AKO Pod Ops** | status, logs, restart, version info | 4 | 3R / 1W |\n| **AKO Config** | values.yaml view, Helm diff, Helm upgrade | 3 | 2R / 1W |\n| **Ingress Diagnostics** | annotation validation, VS mapping, error diagnosis (with fix recommendations) | 3 | 3R |\n| **Sync Diagnostics** | K8s-Controller comparison, inconsistency list, force resync | 3 | 2R / 1W |\n| **Multi-cluster** | cross-cluster AKO cluster list, AMKO status | 2 | 2R |\n\n**Total**: 28 tools (22 read + 6 write)\n\n## Quick Install\n\n```bash\nuv tool install vmware-avi==1.9.1\nvmware-avi doctor            # checks Controller connectivity + kubeconfig + avisdk\n```\n\n## When to Use This Skill\n\n- List, enable, or disable virtual services on AVI Controller\n- Add, remove, drain, or restore pool members (maintenance windows, rolling deployments)\n- Check SSL certificate expiry across all virtual services\n- View VS analytics — throughput, latency, error rates, request logs\n- Check service engine status (inventory-based) and per-SE VS placement counts\n- Troubleshoot AKO pods — status, logs, restarts\n- Manage AKO Helm configuration — view, diff, upgrade values.yaml\n- Validate Ingress annotations and diagnose why a VS wasn't created as expected\n- Detect sync drift between K8s resources and AVI Controller objects\n- Get a cross-cluster view of AKO deployments and AMKO status\n\n**Use companion skills for**:\n- VM lifecycle, deployment, guest ops → `vmware-aiops`\n- NSX segments, gateways, NAT → `vmware-nsx`\n- DFW firewall rules, security groups → `vmware-nsx-security`\n- K8s cluster lifecycle (Supervisor, TKC) → `vmware-vks`\n- Read-only vSphere monitoring → `vmware-monitor`\n\n## Related Skills — Skill Routing\n\n| User Intent | Recommended Skill |\n|-------------|------------------|\n| Load balancer, VS, pool, AVI, ALB, AKO | **vmware-avi** ← this skill |\n| VM lifecycle, deployment, guest ops | **vmware-aiops** (`uv tool install vmware-aiops`) |\n| Read-only vSphere monitoring | **vmware-monitor** (`uv tool install vmware-monitor`) |\n| Storage: iSCSI, vSAN, datastores | **vmware-storage** (`uv tool install vmware-storage`) |\n| NSX networking: segments, gateways, NAT | **vmware-nsx** (`uv tool install vmware-nsx-mgmt`) |\n| NSX security: DFW rules, security groups | **vmware-nsx-security** (`uv tool install vmware-nsx-security`) |\n| Tanzu Kubernetes (Supervisor/TKC) | **vmware-vks** (`uv tool install vmware-vks`) |\n| Aria Ops: metrics, alerts, capacity | **vmware-aria** (`uv tool install vmware-aria`) |\n| Multi-step workflows with approval | **vmware-pilot** |\n| Compliance baselines (CIS / 等保 / PCI-DSS), drift detection, LLM remediation advisor | **vmware-harden** (`uv tool install vmware-harden`) |\n| Audit log query | **vmware-policy** (`vmware-audit` CLI) |\n\n## Common Workflows\n\n### Maintenance Window — Drain a Pool Member\n\n**Pre-flight (judgment — affects live traffic)**:\n- Capacity check: pool must have ≥ 2 healthy members. Disabling the only-other-healthy member is a self-DoS. Verify with `pool members my-pool` first.\n- Connection persistence: if VS uses session persistence (cookie/source-IP), existing sessions stay pinned to the disabled member until they expire. \"Drain\" is not instant — 5-30 min depending on persistence TTL.\n- Long-lived connections: WebSocket/streaming sessions can hold for hours. Decide upfront: hard-disconnect (faster, user-visible) or wait (slower, transparent).\n- Observability: enable analytics on the VS BEFORE disabling — you need the baseline to detect degradation.\n\n**Steps**:\n1. `pool members my-pool` → confirm ≥ 2 healthy members and identify session persistence config\n2. `pool disable my-pool <server-ip>` (graceful drain — new connections stop, existing finish)\n3. `analytics my-vs --duration 15m` → watch active connection count to the drained member trend toward zero\n4. Perform maintenance only after active connections = 0 (or you've decided to hard-disconnect)\n5. `pool enable my-pool <server-ip>` → re-enable\n6. **Verify** before declaring success: health monitor passes (typically 30-90 sec) AND new connections are landing on the member (analytics drill-down)\n\n### AKO Ingress Not Creating VS\n\n**Judgment**: this is a layered failure — figure out which layer broke before randomly probing. AKO is a controller; like all K8s controllers, the failure modes are: (a) controller down, (b) controller running but seeing wrong inputs, (c) controller acting but Avi rejecting outputs.\n\n1. `ako status` → controller running, recent reconciles, no panic logs? If not, fix here first\n2. `ako ingress check <namespace>` → required annotations present? Common miss: `kubernetes.io/ingress.class`, `aviinfrasetting.ako.vmware.com/name`\n3. `ako sync status` → drift between K8s state and Avi state. Drift > a few minutes usually means controller error\n4. `ako ingress diagnose <ingress-name>` → AKO's own diagnostic; often pinpoints the issue\n5. If sync drifted: `ako sync diff` → review what's missing on Avi side. **Force resync only after** you understand why drift happened — blind resync masks bugs that will recur\n\n### SSL Certificate Expiry Audit\n\n**Judgment**: cert expiry is the most preventable outage in the LB world. Run this regularly, not reactively. The 30-day window is a minimum — for prod, set 60+ to allow renewal lead time.\n\n1. `ssl expiry --days 60` → catch certs expiring within 60 days, not 30; enterprise renewal cycles take 2-4 weeks\n2. Cross-reference VS mapping (in output) → identify which apps are at risk; some certs may be unused (orphans, candidates for cleanup)\n3. **Decision**: certs marked `unused` (no VS) → propose deletion as part of audit; certs `in_use` → escalate to cert team with VS list and exact expiry date\n4. Schedule a follow-up rescan post-renewal (not just rely on cert team confirming)\n\n## Usage Mode\n\n| Scenario | Recommended | Why |\n|----------|:-----------:|-----|\n| Local/small models (Ollama, Qwen) | **CLI** | ~2K tokens vs ~8K for MCP |\n| Cloud models (Claude, GPT-4o) | Either | MCP gives structured JSON I/O |\n| Automated pipelines | **MCP** | Type-safe parameters, structured output |\n| AKO troubleshooting | **CLI** | Interactive log tailing, Helm diff output |\n\n## MCP Tools (28 — 22 read, 6 write)\n\n| Category | Tools | R/W |\n|----------|-------|:---:|\n| Virtual Service (3) | `vs_list`, `vs_status` | Read |\n| | `vs_toggle` | Write |\n| Pool Member (4) | `pool_list`, `pool_members` | Read |\n| | `pool_member_enable`, `pool_member_disable` | Write |\n| SSL Certificate (2) | `ssl_list`, `ssl_expiry_check` | Read |\n| Analytics (2) | `vs_analytics`, `vs_error_logs` | Read |\n| Service Engine (2) | `se_list`, `se_health` | Read |\n| AKO Pod (4) | `ako_status`, `ako_logs`, `ako_version` | Read |\n| | `ako_restart` | Write |\n| AKO Config (3) | `ako_config_show`, `ako_config_diff` | Read |\n| | `ako_config_upgrade` | Write |\n| Ingress Diagnostics (3) | `ako_ingress_check`, `ako_ingress_map`, `ako_ingress_diagnose` | Read |\n| Sync Diagnostics (3) | `ako_sync_status`, `ako_sync_diff` | Read |\n| | `ako_sync_force` | Write |\n| Multi-cluster (2) | `ako_clusters`, `ako_amko_status` | Read |\n\n**Read/write split**: 22 tools are read-only, 6 modify state. Write tools require double confirmation and are audit-logged.\n\n## CLI Quick Reference\n\n```bash\n# === Traditional Mode (AVI Controller) ===\nvmware-avi vs list [--controller <name>]\nvmware-avi vs status <vs-name>\nvmware-avi vs enable <vs-name>\nvmware-avi vs disable <vs-name>           # double-confirm\n\nvmware-avi pool members <pool-name>\nvmware-avi pool enable <pool> <server-ip>\nvmware-avi pool disable <pool> <server-ip>  # double-confirm (graceful drain)\n\nvmware-avi ssl list\nvmware-avi ssl expiry [--days 30]\n\nvmware-avi analytics <vs-name>\nvmware-avi logs <vs-name> [--since 1h]\n\nvmware-avi se list\nvmware-avi se health\n\n# === AKO Mode (K8s) ===\nvmware-avi ako status [--context <k8s-context>]\nvmware-avi ako logs [--tail 100] [--since 30m]\nvmware-avi ako restart                    # double-confirm\n\nvmware-avi ako config show\nvmware-avi ako config diff\nvmware-avi ako config upgrade             # double-confirm + --dry-run default\n\nvmware-avi ako ingress check <namespace>\nvmware-avi ako ingress map\nvmware-avi ako ingress diagnose <ingress-name>\n\nvmware-avi ako sync status\nvmware-avi ako sync diff\nvmware-avi ako sync force                 # double-confirm\n\nvmware-avi ako clusters\nvmware-avi ako amko status\n```\n\n> Full CLI reference: see `references/cli-reference.md`\n\n## Troubleshooting\n\n### \"Controller unreachable\" error\n1. Run `vmware-avi doctor` to verify connectivity\n2. Check if the controller address and port are correct in `~/.vmware-avi/config.yaml`\n3. For self-signed certs: set `verify_ssl: false` in config.yaml (lab environments only)\n\n### AKO Pod in CrashLoopBackOff\n1. Check logs → `vmware-avi ako logs --tail 50`\n2. Common causes: wrong controller IP in values.yaml, network policy blocking AKO→Controller, expired credentials\n3. Fix config → `vmware-avi ako config show` to inspect, then `vmware-avi ako config upgrade` with corrected values (release auto-discovered — official installs use `--generate-name`; pulls the official Broadcom OCI chart `oci://projects.packages.broadcom.com/ako/helm-charts/ako`)\n\n### Ingress created but no VS on Controller\n1. Validate annotations → `vmware-avi ako ingress check <namespace>`\n2. Check AKO logs for rejection reason → `vmware-avi ako logs --since 5m`\n3. Run sync diff → `vmware-avi ako sync diff` to see if the object is stuck\n\n### Pool member shows \"down\" after enable\nHealth monitor may still be failing. Check the actual health status on the Controller side — the member is enabled but unhealthy. Fix the backend service first, then the health status will auto-recover.\n\n### SSL expiry check shows 0 certificates\nVerify the controller connection has tenant-level access. Certificates are tenant-scoped in AVI — the configured user may only see certs in their tenant.\n\n### AKO sync force has no effect\nForce resync triggers AKO to re-reconcile all K8s objects. If the drift persists, the issue is likely in the K8s resource definition itself (bad annotation, missing secret). Use `vmware-avi ako ingress diagnose` to pinpoint the root cause.\n\n## Setup\n\n```bash\nuv tool install vmware-avi==1.9.1\nmkdir -p ~/.vmware-avi\nvmware-avi init              # generates config.yaml and .env templates\nchmod 600 ~/.vmware-avi/.env\nvmware-avi doctor            # verify Controller + K8s connectivity\n```\n\n> All tools are automatically audited via vmware-policy. Audit logs: `vmware-audit log --last 20`\n\n**Supported versions**: AVI Controller 22.1.x (analytics endpoint quirks fixed in v1.5.11) and 30.x. VCF 9.0 / 9.1 declared compatible (avisdk `>=22.1,<31.0` covers bundled AVI). Python 3.11+. Full table: `references/capabilities.md` → Version Compatibility.\n\n> Full setup guide, security details, AI platform compatibility, and container/Smithery deployment: see `references/setup-guide.md`\n\n## Audit & Safety\n\nAll operations are automatically audited via vmware-policy (`@vmware_tool` decorator):\n- Every tool call logged to `~/.vmware/audit.db` (SQLite, framework-agnostic)\n- Policy rules enforced via `~/.vmware/rules.yaml` (deny rules, maintenance windows, risk levels)\n- Each controller may declare `environment:` in `config.yaml` (`production` / `staging` / `lab`) as an optional label; an environment-scoped `deny` rule in `~/.vmware/rules.yaml` can match on it to block writes (e.g. freeze `production`). A controller with no label is simply not matched by such a rule. Reads are never affected\n- Destructive operations (`vs_toggle` disable, `pool_member_disable`, `ako_restart`, `ako_config_upgrade`, `ako_sync_force`) require double confirmation\n- `ako_config_upgrade` defaults to `--dry-run` mode — user must explicitly confirm to apply\n- View recent operations: `vmware-audit log --last 20`\n\n## License\n\nMIT — [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI)\n\nFile v1.9.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"vmware-avi\",\n  \"version\": \"1.9.1\",\n  \"publishedAt\": 1789452019598\n}\n\nFile v1.9.1:references/agent-guardrails.md\n\n# Operating vmware-avi with a local / small model\n\nClaude-class models drive this skill without special instruction. Smaller and\nlocally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served\nthrough Goose, Ollama, or OpenShift AI — need explicit operating rules to call\ntools reliably.\n\nThis page exists because an operator wrote those rules by hand first. The\nguardrails below are adapted, with thanks, from the working configuration\n[@juanpf-ha](https://github.com/juanpf-ha) developed while running\nvmware-monitor and vmware-aria against a production vSphere estate with Llama\n3.3 70B FP8 on an on-prem H100\n([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The\ncross-skill rules are identical across this family; the parts below marked\nvmware-avi are specific to this skill.\n\nvmware-avi exposes 28 MCP tools, 6 of which change state. It straddles two\ncontrol planes — the AVI Controller and a Kubernetes cluste\n\nArchive v1.9.0: 7 files, 24986 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11949b), references/cli-reference.md (6579b), references/setup-guide.md (13570b), skill-card.md (2684b), SKILL.md (15916b), _meta.json (129b)\n\nArchive v1.8.15: 7 files, 24950 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11942b), references/cli-reference.md (6579b), references/setup-guide.md (13491b), skill-card.md (2661b), SKILL.md (15994b), _meta.json (130b)\n\nArchive v1.8.14: 7 files, 24887 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11942b), references/cli-reference.md (6579b), references/setup-guide.md (13491b), skill-card.md (2643b), SKILL.md (15994b), _meta.json (130b)\n\nArchive v1.8.13: 7 files, 25026 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11942b), references/cli-reference.md (6579b), references/setup-guide.md (13491b), skill-card.md (2847b), SKILL.md (15994b), _meta.json (130b)\n\nArchive v1.8.12: 7 files, 24917 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11942b), references/cli-reference.md (6579b), references/setup-guide.md (13491b), skill-card.md (2635b), SKILL.md (15994b), _meta.json (130b)\n\nArchive v1.8.11: 7 files, 24897 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11942b), references/cli-reference.md (6579b), references/setup-guide.md (13491b), skill-card.md (2604b), SKILL.md (15994b), _meta.json (130b)\n\nArchive v1.8.10: 7 files, 24920 bytes\n\nFiles: references/agent-guardrails.md (8489b), references/capabilities.md (11942b), references/cli-reference.md (6579b), references/setup-guide.md (13491b), skill-card.md (2642b), SKILL.md (15994b), _meta.json (130b)","readmeExcerpt":"Skill: vmware-avi Owner: zw008 Summary: Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context. Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs, service engine health, AKO pod troub","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"uv tool install vmware-avi==1.11.0\nvmware-avi doctor            # checks Controller connectivity + kubeconfig + avisdk"},{"language":"bash","snippet":"# === Traditional Mode (AVI Controller) ===\nvmware-avi vs list [--controller <name>]\nvmware-avi vs status <vs-name>\nvmware-avi vs enable <vs-name>\nvmware-avi vs disable <vs-name>           # double-confirm\n\nvmware-avi pool members <pool-name>\nvmware-avi pool enable <pool> <server-ip>\nvmware-avi pool disable <pool> <server-ip>  # double-confirm (graceful drain)\n\nvmware-avi ssl list\nvmware-avi ssl expiry [--days 30]\n\nvmware-avi analytics <vs-name>\nvmware-avi logs <vs-name> [--since 1h]\n\nvmware-avi se list\nvmware-avi se health\n\n# === AKO Mode (K8s) ===\nvmware-avi ako status [--context <k8s-context>]\nvmware-avi ako logs [--tail 100] [--since 30m]\nvmware-avi ako restart                    # double-confirm\n\nvmware-avi ako config show\nvmware-avi ako config diff\nvmware-avi ako config upgrade             # double-confirm + --dry-run default\n\nvmware-avi ako ingress check <namespace>\nvmware-avi ako ingress map\nvmware-avi ako ingress diagnose <ingress-name>\n\nvmware-avi ako sync status\nvmware-avi ako sync diff\nvmware-avi ako sync force                 # double-confirm\n\nvmware-avi ako clusters\nvmware-avi ako amko status"},{"language":"bash","snippet":"uv tool install vmware-avi==1.11.0\nmkdir -p ~/.vmware-avi\nvmware-avi init              # generates config.yaml and .env templates\nchmod 600 ~/.vmware-avi/.env\nvmware-avi doctor            # verify Controller + K8s connectivity"},{"language":"text","snippet":"## Tool use\n\n- Always call an MCP tool before answering any question about the current AVI\n  or AKO environment. Never answer from memory or assumption.\n- Never describe a tool call, and never output a JSON example, instead of\n  executing the tool. If you intend to call a tool, call it.\n- If a tool fails, report the actual error text. Do not complete the answer\n  with assumptions about what the result would have been.\n- Use explicit limits and time windows on queries that may return large amounts\n  of data. State the window you used in the answer.\n- Analytics windows accept an integer of seconds or a shorthand suffix such as\n  30m, 24h or 7d. Pick one and say which.\n\n## Skill routing\n\n- vmware-avi: virtual services, pools and pool members, SSL certificates,\n  Service Engines, VS analytics and error logs, AKO pod/config/sync/ingress\n  diagnostics, multi-cluster and AMKO.\n- vmware-nsx: segments, gateways, NAT, routing. The underlay is not this skill.\n- vmware-nsx-security: DFW rules and security groups.\n- vmware-vks: Supervisor and Tanzu Kubernetes cluster lifecycle.\n- vmware-monitor: read-only vCenter inventory, hosts, alarms, events.\n- vmware-aiops: VM lifecycle.\n- vmware-pilot: multi-step workflows that need approval gates.\n\n## Data fidelity\n\n- Never invent virtual services, pools, members, certificates or Service\n  Engines. If a tool did not return it, it does not exist for this answer.\n- Preserve the exact operational state, health-score and enabled/disabled\n  values the tools return. Do not translate, normalise, or prettify them.\n- Report metric values and their units exactly as returned. Do not rescale,\n  average, or recompute a percentage yourself.\n- If a requested field was not returned, show it as \"not available\". Do not\n  infer it from other fields.\n- Preserve the original order and the full set of fields when the user asks\n  for specific ones.\n- These tools return bare lists, not a truncation envelope. If you applied a\n  limit, say so in the answer; never "},{"language":"bash","snippet":"uv tool install vmware-avi==1.11.0"},{"language":"bash","snippet":"git clone --branch v1.11.0 https://github.com/vmware-skills/VMware-AVI.git\ncd VMware-AVI\nuv pip install -e \".[dev]\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: vmware-avi\ndescription: >\n  Use this skill whenever the user mentions load balancing, ingress, virtual services, pool members, AVI, NSX ALB, AKO, or application delivery\n  in a VMware/NSX ALB or Tanzu/vSphere Kubernetes context.\n  Directly handles: virtual service listing and enable/disable, pool member drain/enable, SSL certificate expiry checks, analytics and error logs,\n  service engine health, AKO pod troubleshooting, AKO Helm config management, Ingress annotation validation, K8s-to-Controller sync diagnostics,\n  and multi-cluster AKO overview.\n  Always use it for \"virtual service\", \"pool member\", \"AKO status\", \"AKO logs\", \"ingress diagnose\", \"ssl expiry\", \"load balancer\", \"NSX ALB\",\n  \"AVI controller\", \"Avi Load Balancer\", \"AKO sync\", or \"负载均衡\" tasks.\n  Do NOT use to set up or configure nginx/HAProxy/Traefik from scratch — those are not AVI tasks.\n  For VM lifecycle use vmware-aiops, for NSX networking use vmware-nsx, for Kubernetes cluster lifecycle (Supervisor/TKC) use vmware-vks.\ninstaller:\n  kind: uv\n  package: vmware-avi\nargument-hint: \"[vs-name, ako command, or describe your task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"vmware-avi\",\"uvx\"]},\"optional\":{\"env\":[\"VMWARE_AVI_CONFIG\",\"<CONTROLLER>_PASSWORD\",\"<CONTROLLER>_USERNAME\",\"KUBECONFIG\",\"VMWARE_AUDIT_APPROVED_BY\"],\"bins\":[\"vmware-policy\",\"kubectl\",\"helm\"]},\"homepage\":\"https://github.com/vmware-skills/VMware-AVI\",\"emoji\":\"🔀\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.\n  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller \"prod-avi\" → PROD_AVI_PASSWORD).\n  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.\n---\n\n# VMware AVI\n\n> **Disclaimer**: This is a community-maintained open-source project and is **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** \"VMware\", \"NSX\", and \"AVI\" are trademarks of Broadcom. Source code is publicly auditable at [github.com/vmware-skills/VMware-AVI](https://github.com/vmware-skills/VMware-AVI) under the MIT license.\n\nAVI (NSX Advanced Load Balancer) application delivery and AKO Kubernetes operations — 28 MCP tools.\n\n> **Dual mode**: Traditional AVI Controller management + AKO K8s operations in one skill.\n> **Family**: [vmware-aiops](https://github.com/vmware-skills/VMware-AIops) (VM lifecycle), [vmware-monitor](https://github.com/vmware-skills/VMware-Monitor) (inventory/health), [vmware-storage](https://github.com/vmware-skills/VMware-Storage) (iSCSI/vSAN), [vmware-vks](https://github.com/vmware-skills/VMware-VKS) (Tanzu Kubernetes), [vmware-nsx](https://github.com/vmware-skills/VMware-NSX) (N"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"vmware-avi\",\n  \"version\": \"1.11.0\",\n  \"publishedAt\": 1789915951488\n}"},{"path":"references/agent-guardrails.md","content":"# Operating vmware-avi with a local / small model\n\nClaude-class models drive this skill without special instruction. Smaller and\nlocally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served\nthrough Goose, Ollama, or OpenShift AI — need explicit operating rules to call\ntools reliably.\n\nThis page exists because an operator wrote those rules by hand first. The\nguardrails below are adapted, with thanks, from the working configuration\n[@juanpf-ha](https://github.com/juanpf-ha) developed while running\nvmware-monitor and vmware-aria against a production vSphere estate with Llama\n3.3 70B FP8 on an on-prem H100\n([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The\ncross-skill rules are identical across this family; the parts below marked\nvmware-avi are specific to this skill.\n\nvmware-avi exposes 28 MCP tools, 6 of which change state. It straddles two\ncontrol planes — the AVI Controller and a Kubernetes cluster running AKO — and\nmost of the trouble a small model gets into here comes from confusing which\nside of that boundary an object lives on.\n\n> **Disclaimer**: This is a community-maintained open-source project and is\n> **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom\n> Inc.** \"VMware\" and \"vSphere\" are trademarks of Broadcom.\n\n---\n\n## First: the rules you no longer need to write\n\nSeveral guardrails from the original configuration are now enforced by the\nskill itself. Prompt instructions are advisory — a model can ignore them.\nThese are structural, so it cannot.\n\n| Guardrail you would otherwise prompt for | Now enforced by |\n|---|---|\n| \"Log every state change you make\" | **The `@vmware_tool` decorator.** Every write is recorded to `~/.vmware/audit.db` before the model sees the result, and policy rules are evaluated ahead of execution. |\n| \"Convert time windows into the units the API expects\" | **The ops layer does the conversion.** Analytics duration accepts either an integer of seconds or a shorthand suffix (`30m`, `24h`, `7d`); the model does not have to know the controller wants seconds. |\n| \"Use the controller's IP, not its hostname\" | **The connection layer resolves it.** Some analytics endpoints reject a hostname; the FQDN is resolved to an address before the SDK sees it. |\n\nNote the one guardrail this skill does **not** hand you: vmware-avi's list tools\nreturn bare collections, not the family `{items, returned, limit, total,\ntruncated, hint}` envelope. Truncation is therefore not self-declaring here, so\nthe \"report every item\" and \"state the limit you used\" rules below carry more\nweight than they do in the rest of the family.\n\n---\n\n## The system prompt\n\nEverything below still benefits from being stated explicitly. Copy this into\nyour agent's instruction block.\n\n```text\n## Tool use\n\n- Always call an MCP tool before answering any question about the current AVI\n  or AKO environment. Never answer from memory or assumption.\n- Never describe a tool call, and never output a JSON exampl"},{"path":"references/capabilities.md","content":"# VMware AVI Capabilities\n\nAll 28 MCP tools exposed by `vmware-avi mcp` (v1.5.15+; legacy entry point: `vmware-avi-mcp`), organized by category.\n\n## Version Compatibility\n\n### AVI Controller (NSX ALB)\n\n| Controller Version | Support Level | Notes |\n|--------------------|--------------|-------|\n| AVI 30.x | ✅ Full | All 28 tools verified. avisdk `<31.0` upper bound. |\n| AVI 22.1.x | ✅ Full | All analytics endpoint quirks fixed in v1.5.11 — `vs_analytics` uses POST `/analytics/metrics/collection` with `metric_requests[]`; `pool_list` uses `/virtualservice-inventory` to expose K8S-managed pool groups; SE→VS mapping reconstructed from `vip_summary[].service_engine[]`. |\n| AVI < 22.1 | ⚠ Untested | avisdk may load but analytics/inventory endpoints differ. Not in CI. |\n\n### VCF (VMware Cloud Foundation)\n\n| VCF Version | Bundled AVI / NSX ALB | Support |\n|-------------|-----------------------|---------|\n| VCF 9.1 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) |\n| VCF 9.0 | NSX ALB (avisdk >=22.1,<31.0 covers it) | ✅ Full (declared v1.5.23) |\n| VCF 5.x | AVI 22.x | ✅ Full |\n\n### Runtime\n\n| Requirement | Version | Notes |\n|-------------|---------|-------|\n| Python | ≥ 3.11 | `requires-python` bumped from 3.10 to 3.11 in v1.5.19 (regression eval uses `tomllib`). |\n| avisdk | ≥ 22.1, < 31.0 | Auto-installed. Range chosen so VCF 9.x bundled AVI is covered without forcing a major SDK jump. |\n| kubernetes (Python) | ≥ 28.0 | Required only for AKO mode. |\n| kubectl | any recent | Required only for AKO operations. |\n| helm | ≥ 3.x | Required only for AKO config show/diff/upgrade. |\n\n### MCP Transport\n\n| Mode | Status | Recommended |\n|------|--------|-------------|\n| `vmware-avi mcp` (CLI subcommand, stdio) | ✅ Full | ✅ v1.5.15+ default — no PyPI re-resolve, works behind corporate TLS proxies. |\n| `vmware-avi-mcp` (legacy console script, stdio) | ✅ Full | Kept for backward compatibility with pre-1.5.15 configs. |\n| `python -m vmware_avi.mcp_server` (stdio, via `__main__.py`) | ✅ Full | Docker image `CMD` only — not for end-user CLI install, and no longer used by `smithery.yaml` (which now calls the `vmware-avi mcp` entry point). Added v1.5.22. |\n| `uvx --from vmware-avi==1.11.0 vmware-avi-mcp` | ⚠ Fallback | Re-resolves PyPI on each launch; fails behind corporate TLS proxies (踩坑 #25). Use `UV_NATIVE_TLS=true` workaround. |\n\n## Automation Level Reference\n\nEach operation is classified by autonomy level per the Enterprise Harness Engineering framework:\n\n| Level | Meaning | Agent autonomy | Examples in this skill |\n|:-:|---|---|---|\n| **L1** | Read-only, raw data | Always auto-run | `vs_list`, `vs_status`, `pool_list`, `pool_members`, `se_list`, `se_health`, `vs_analytics` queries, AKO/AMKO inventory (`ako_status`, `ako_clusters`, `ako_amko_status`) |\n| **L2** | Read + analysis / recommendation | Always auto-run | traffic distribution analysis, health score correlation, pool member ratio summaries, analytics-driven anomaly detection |\n| **L3** "},{"path":"references/cli-reference.md","content":"# VMware AVI CLI Reference\n\nComplete command reference for the `vmware-avi` CLI (v1.4.0).\n\n## Global Commands\n\n| Command | Description | Flags |\n|---------|-------------|-------|\n| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |\n| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |\n| `vmware-avi config` | Show current configuration (passwords masked) | -- |\n\n## Virtual Service Commands (`vmware-avi vs`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi vs list` | List all Virtual Services | `--controller <name>` (optional, use a specific controller) |\n| `vmware-avi vs status <name>` | Show VS status details (VIP, health, pool binding) | `<name>` (required) |\n| `vmware-avi vs enable <name>` | Enable a Virtual Service | `<name>` (required) |\n| `vmware-avi vs disable <name>` | Disable a Virtual Service | `<name>` (required). **Double-confirm required.** |\n\n## Pool Member Commands (`vmware-avi pool`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi pool members <pool>` | List pool members and health status | `<pool>` (required) |\n| `vmware-avi pool enable <pool> <server-ip>` | Enable a pool member (restore traffic) | `<pool>` (required), `<server-ip>` (required) |\n| `vmware-avi pool disable <pool> <server-ip>` | Disable a pool member (graceful drain) | `<pool>` (required), `<server-ip>` (required). **Double-confirm required.** |\n\n## SSL Certificate Commands (`vmware-avi ssl`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi ssl list` | List all SSL certificates | -- |\n| `vmware-avi ssl expiry` | Check certificates expiring within N days | `--days <N>` (default: 30) |\n\n## Service Engine Commands (`vmware-avi se`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi se list` | List all Service Engines: name, mgmt IP, operational status, SE group (status from the `serviceengine-inventory` endpoint, config + runtime merged) | -- |\n| `vmware-avi se health` | Check Service Engine health: per-SE operational status + connected-VS counts (placement map from `virtualservice-inventory`) | -- |\n\n## Analytics Commands\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `vmware-avi analytics <vs-name>` | Show VS analytics: L4 bandwidth/connections + L7 client transaction latency (`l7_client.avg_client_txn_latency`), response errors, total responses | `<vs-name>` (required) |\n| `vmware-avi logs <vs-name>` | Show VS request error logs (HTTP status ≥ 400, filter `ge(response_code,400)`) | `<vs-name>` (required), `--since <range>` (default: `1h`, e.g. `30m`, `2h`) |\n\n## AKO Pod Commands (`vmware-avi ako`)\n\n| Command | Description | Arguments / Flags |\n|---------|-------------|-------------------|\n| `v"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2239,"uniquenessScore":41,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T04:44:38.555Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T04:44:38.555Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T17:31:33.344Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}