k8s-tool
LOAD THIS SKILL when: working with Kubernetes pods, logs, deployments, resource usage, or running kubectl commands. Contains all k8s-tool commands.
Works with
--- name: k8s-tool description: LOAD THIS SKILL when: working with Kubernetes pods, logs, deployments, resource usage, or running kubectl commands. Contains all k8s-tool commands. license: MIT --- # k8s-tool (Kubernetes) Kubernetes tool — kubectl wrapper with config-driven context resolution and structured commands. Part of [@blogic-cz/agent-tools](https://github.com/blogic-cz/agent-tools). ## How to Run Run via `bun k8s-tool` (requires `@blogic-cz/agent-tools` as a dev dependency). **NEVER run bare `kubectl`** — the credential guard will block it. Auth: existing kubectl context (kubeconfig). Cluster ID from config resolves context automatically. ## Commands ```bash bun k8s-tool kubectl --env test --cmd "get pods -n test-ns" bun k8s-tool kubectl --env prod --cmd "logs <pod> --tail=100" bun k8s-tool kubectl --env test --cmd "describe pod <pod>" bun k8s-tool pods --env test # List pods (structured) bun k8s-tool logs --pod <pod> --env test --tail 50 # Fetch logs bun k8s-tool describe --resource pod --name <pod> --env test bun k8s-tool exec --pod <pod> --exec-cmd "ls -la" --env test bun k8s-tool top --env test # Show resource usage ``` Environment is any string (e.g. `test`, `prod`). Set `defaultEnvironment` in `agent-tools.json5` to skip `--env` on every call. Implicit production access is blocked for safety. ## Safety Boundary - Generic kubectl commands are parsed into arguments and executed without a user-controlled shell. Do not use pipes, chaining, substitution, or shell interpreters. - The configured context, kubeconfig, server, authentication, TLS, and impersonation settings cannot be overridden in `--cmd`. - Only read-only `config` and `auth` subcommands are allowed; `cluster-info dump` is blocked. - Secret reads, raw kubeconfig output, filename/kustomize reads, and `kubectl diff` are blocked. - Pod exec accepts only direct `redis-cli PING/INFO` and `ls` diagnostics; generic exec cannot read file contents. - Use `logs-tool` for confined remote log-file access and filtering. ## Tips - Use `bun k8s-tool commands` for the full machine-readable command/flag tree; `--help` for one subcommand. - Output defaults to **TOON** (token-efficient) — leave it as-is to save tokens. Add `--format json` only when you'll machine-parse the result. - Error responses include `hint`, `nextCommand`, and `retryable` fields — always check them on failure. - Prefer CLI tool over MCP tools — more efficient, doesn't load extra context.
More Deployment & CI/CD skills
azure-enterprise-infra-planner
microsoft/azure-skills
Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.
azure-kubernetes-app-deploy
microsoft/azure-skills
Use when deploying an existing web application or API to an already-running Azure Kubernetes Service cluster. Detects the framework, generates a Dockerfile and Kubernetes manifests, validates against AKS Deployment Safeguards, and deploys with verification. WHEN: deploy app to AKS, deploy to existing AKS cluster, containerize app for Kubernetes, generate K8s manifests for Azure, set up CI/CD for AKS, my AKS deployment is failing safeguard checks, I have a Django/Express/Spring Boot app to run on AKS. DO NOT USE FOR: creating or provisioning an AKS cluster (use azure-kubernetes), assessing migration to AKS Automatic (use azure-kubernetes-automatic-readiness), or deploying to non-AKS targets like Web Apps, Container Apps, or Functions.
finetuning
microsoft/azure-skills
Fine-tune models on Microsoft Foundry using SFT (supervised), DPO (preference), or RFT (reinforcement with graders). Covers dataset preparation, training job submission, deployment, and evaluation. USE FOR: fine-tune, SFT, DPO, RFT, training data, grader, distillation, fine-tuned model, training job, large file upload, calibrate grader, deploy fine-tuned model, evaluate fine-tuned model. DO NOT USE FOR: general model deployment without fine-tuning (use deploy-model), agent creation (use agents), prompt optimization without training (use prompt-optimizer).

