K8s 助手
- 作者仓库星标 0
- 作者仓库 skills-registry
Kubernetes Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
Core Checklist
- Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads.
- Use namespace boundaries, least-privilege RBAC, and network policies for isolation.
- Follow Kubernetes Pod Security Standards; default application workloads toward the Restricted profile.
- Run containers as non-root, drop unnecessary capabilities, and avoid host namespaces and privileged containers.
- Store configuration in ConfigMaps and secrets appropriately; do not commit plaintext secrets.
- Validate Helm templates, CRDs, and manifests against schemas and policy before applying.
- Use labels and annotations consistently for ownership, observability, selection, and lifecycle automation.
- Design upgrades and rollbacks before changing stateful workloads, ingress, storage, or networking.
Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
helm lintfor chartshelm template ... | kubeconform -strictor schema validation for rendered manifests- Policy checks with Kyverno, Gatekeeper/OPA, Conftest, or the project's admission policy tooling
Detailed Reference
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful.
<!-- tomevault:4.0:skill_md:2026-05-22 -->Source: asciifylabs/asciify-skills — distributed by TomeVault.
- 流狐分类
- 运维部署
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 88 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @tomevault-io · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 即装即用
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- 未声明
- 底层运行要求
- 未声明
- 检测到的文件与系统行为
-
- 只读
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. Make the smallest coherent change that satisfies the request while preserving behavior. Treat tests, linting, dependency hygiene, and security review as part of…
Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads. Use namespace boundaries, least-privilege RBAC, and network policies for isolation. Follow Kubernetes Pod Security Standards; default application…
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. helm lint for charts helm template ... | kubeconform -strict or schema validation for rendered manifests
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful. Source: asciifylabs/asciify-skills — distributed by TomeVault. <!-- tomevault:4.0:skillmd:2026-05-22 -->
# Kubernetes Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
## Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
## Core Checklist
- Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads.
- Use namespace boundaries, least-privilege RBAC, and network policies for isolation.
- Follow Kubernetes Pod Security Standards; default application workloads toward the Restricted profile.
- Run containers as non-root, drop unnecessary capabilities, and avoid host namespaces and privileged containers.
- Store configuration in ConfigMaps and secrets appropriately; do not commit plaintext secrets.
- Validate Helm templates, CRDs, and manifests against schemas and policy before applying.
- Use labels and annotations consistently for ownership, observability, selection, and lifecycle automation.
- Design upgrades and rollbacks before changing stateful workloads, ingress, storage, or networking.
## Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
- `helm lint` for charts
- `helm template ... | kubeconform -strict` or schema validation for rendered manifests
… 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> Operating Rules → Core Checklist → Validation → Detailed Reference
要点 -> Use this skill as standing guidance for this domain. · - Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. · - Set requests, limits, probes, disruption budgets, and rollout strategy deliberately for production workloads. · Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. · - helm lint for charts - helm template ... · --- > Source: [asciifylabs/asciify-skills](https://github.com/asciifylabs/asciify-skills) — distributed by [TomeVault](https://tomevault.io).
文件/命令 -> helm lint · helm template ... | kubeconform -strict · Gatekeeper/OPA · references/principles.md · asciifylabs/asciify-skills · github.com/asciifylabs/asciify-skills
内容 SHA-256 -> 9c28bd1cca26
原文结构
适用与边界
原文中的明确线索
helm lint、helm template ... | kubeconform -strict、Gatekeeper/OPA、references/principles.md、asciifylabs/asciify-skills、github.com/asciifylabs/asciify-skills