用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/notque/vexjoy-agent --skill kubernetes命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Run the full evidence-to-live implementation workflow for large, multi-system, multi-wave, or CPU-delegated 5 Star Booker GM programs.
Classify user requests and route to the correct agent + skill. Primary entry point for all delegated work.
Structured multi-phase workflows: review, debug, refactor (tidy, clean up, untangle messy code without behaviour change), deploy, create, research.
基于 SOC 职业分类
正在显示 SKILL.md
| name | kubernetes |
| description | Kubernetes operations: debugging, security, RBAC, and infrastructure tooling. |
| user-invocable | false |
| context | fork |
| agent | kubernetes-helm-engineer |
| routing | {"triggers":["kubernetes debug","pod failure","pod crashloop","kubectl logs","OOMKilled","pod pending","kubernetes security","k8s RBAC","RBAC setup","pod security policy","network policy","cobalt core","cobaltcore","kvm-exporter","kvm exporter","hypervisor metrics","libvirt exporter","cloud hypervisor"],"category":"kubernetes","pairs_with":["service-health-check","go-patterns","prometheus-grafana-engineer"]} |
Kubernetes debugging, security hardening, and infrastructure tooling. Covers pod triage, RBAC, network policies, and cobaltcore hypervisor components.
| Signal | Reference | Size |
|---|---|---|
| CrashLoopBackOff, OOMKilled, config error, health check, liveness probe, ImagePullBackOff, Pending, FailedScheduling | references/crash-diagnosis.md | ~140 lines |
| service resolution, DNS, CoreDNS, port-forward, NetworkPolicy ingress/egress | references/network-debugging.md | ~50 lines |
| CPU throttling, memory limit, OOMKill, ephemeral storage, DiskPressure, debug container | references/resource-debugging.md | ~100 lines |
| RBAC, Role, RoleBinding, ClusterRole, ServiceAccount, least-privilege | references/rbac-patterns.md | ~60 lines |
| PodSecurity, SecurityContext, runAsNonRoot, readOnlyRootFilesystem, restricted, baseline | references/pod-security.md | ~90 lines |
| NetworkPolicy, default-deny, allow-list, namespace isolation | references/network-policies.md | ~70 lines |
| cosign, Kyverno, OPA, admission controller, Sealed Secrets, External Secrets | references/supply-chain.md | ~120 lines |
| kvm-exporter, metrics, prometheus, libvirt, hypervisor, collector, scrape, steal time, NUMA, cgroups, cloud hypervisor | references/cobalt-kvm-exporter.md | ~800 lines |
| cobaltcore concurrency, goroutine, semaphore, TryLock | references/cobalt-concurrency-patterns.md | ~200 lines |
| cobaltcore testing, mock, moq, Kind cluster | references/cobalt-testing-patterns.md | ~200 lines |
| kubernetes debugging process, triage flow, diagnosis routing | references/kubernetes-debugging.md | ~50 lines |
| kubernetes security process, RBAC + pod security + network hardening | references/kubernetes-security.md | ~50 lines |
| cobaltcore overview, KVM exporter architecture, component identification | references/cobalt-core.md | ~50 lines |
Loading rule. Read the references whose signals match the task before responding.
Determine which Kubernetes domain the request targets:
| Domain | Load references | Action |
|---|---|---|
| Pod failure, CrashLoop, OOM | crash-diagnosis, resource-debugging | Triage flow |
| Network, DNS, service resolution | network-debugging, network-policies | Connectivity diagnosis |
| RBAC, permissions, roles | rbac-patterns | Access control |
| Pod hardening, container security | pod-security | Security posture |
| Image signing, secrets, admission | supply-chain | Supply chain |
| Cobaltcore / KVM exporter | kvm-exporter + cobalt refs | Component-specific |
Always specify -n <namespace> explicitly in every kubectl command.
Gate: Domain identified and relevant references loaded.
For debugging: follow the triage flow — describe, logs, events, exec. Use read-only commands to gather evidence before proposing changes.
For security: provide concrete YAML manifests and specific configurations. Answer with reference-backed specifics, not generic advice.
For cobaltcore: use component-specific reference knowledge for architecture, metrics, configuration, and deployment details.
Gate: Specific, reference-backed diagnosis or response provided.
For debugging: confirm the fix resolves the symptom. For security: validate against the misconfiguration table in supply-chain.md. For cobaltcore: verify against component test patterns.