kubernetes-principles
- Repo stars 0
- Author repo skills-registry
Kubernetes Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
Core Checklist
- Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads.
- Use namespace boundaries, least-privilege RBAC, and network policies for isolation.
- Follow Kubernetes Pod Security Standards; default application workloads toward the Restricted profile.
- Run containers as non-root, drop unnecessary capabilities, and avoid host namespaces and privileged containers.
- Store configuration in ConfigMaps and secrets appropriately; do not commit plaintext secrets.
- Validate Helm templates, CRDs, and manifests against schemas and policy before applying.
- Use labels and annotations consistently for ownership, observability, selection, and lifecycle automation.
- Design upgrades and rollbacks before changing stateful workloads, ingress, storage, or networking.
Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
helm lintfor chartshelm template ... | kubeconform -strictor schema validation for rendered manifests- Policy checks with Kyverno, Gatekeeper/OPA, Conftest, or the project's admission policy tooling
Detailed Reference
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful.
<!-- tomevault:4.0:skill_md:2026-05-22 -->Source: asciifylabs/asciify-skills — distributed by TomeVault.
- Fluxly category
- DevOps
- Author-declared agents
- No explicit declaration found; this is not inferred or tested compatibility
- Static check
- 88 / 100 · heuristic scan, not runtime safety proof
- Author / version / license
- @tomevault-io · no license declared
- Fluxly token estimate
- Lean
- Fluxly setup estimate
- Plug-and-play
- External API key
- No requirement detected
- Detected OS requirements
- Unspecified
- Runtime requirements
- Unspecified
- Detected file/system behavior
-
- Read-only
- Detected network behavior
- Local-only
- Install commands
- None (reference only)
Profile is derived at build time from SKILL.md and install vectors. Subject to drift from author intent.
Heads up: 未限定 allowed-tools,默认拥有全部工具权限。
The current SKILL.md does not define a fixed output example. Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. Make the smallest coherent change that satisfies the request while preserving behavior. Treat tests, linting, dependency hygiene, and security review as part of…
Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads. Use namespace boundaries, least-privilege RBAC, and network policies for isolation. Follow Kubernetes Pod Security Standards; default application…
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. helm lint for charts helm template ... | kubeconform -strict or schema validation for rendered manifests
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful. Source: asciifylabs/asciify-skills — distributed by TomeVault. <!-- tomevault:4.0:skillmd:2026-05-22 -->
# Kubernetes Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
## Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
## Core Checklist
- Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads.
- Use namespace boundaries, least-privilege RBAC, and network policies for isolation.
- Follow Kubernetes Pod Security Standards; default application workloads toward the Restricted profile.
- Run containers as non-root, drop unnecessary capabilities, and avoid host namespaces and privileged containers.
- Store configuration in ConfigMaps and secrets appropriately; do not commit plaintext secrets.
- Validate Helm templates, CRDs, and manifests against schemas and policy before applying.
- Use labels and annotations consistently for ownership, observability, selection, and lifecycle automation.
- Design upgrades and rollbacks before changing stateful workloads, ingress, storage, or networking.
## Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
- `helm lint` for charts
- `helm template ... | kubeconform -strict` or schema validation for rendered manifests
… Author text anchors workflow facts; Fluxly only indexes current sections, terms, files, and commands.
sections -> Operating Rules → Core Checklist → Validation → Detailed Reference
terms -> Use this skill as standing guidance for this domain. · - Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. · - Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads. · Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. · - helm lint for charts - helm template ... · --- > Source: [asciifylabs/asciify-skills](https://github.com/asciifylabs/asciify-skills) — distributed by [TomeVault](https://tomevault.io).
files/cmd -> helm lint · helm template ... | kubeconform -strict · Gatekeeper/OPA · references/principles.md · asciifylabs/asciify-skills · github.com/asciifylabs/asciify-skills
body sha256 -> 9c28bd1cca26
Decide Fit First
Design Intent
How To Use It
Boundaries And Review