用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/tomevault-io/skills-registry --skill kubernetes-operator命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
| Use when this capability is needed.
> Use when this capability is needed.
Review architecture and API design for the vfs-s3 project. Use when the user mentions @architect, asks to review an issue's design, discuss module boundaries, API shape, or architectural decisions for vfs-s3. Also trigger when the user wants to create an ADR (Architecture Decision Record) or evaluate a technical approach for the project. Intended for dispatch from Codex automation or Claude routines; GitHub trigger phrase: @vfs-s3-bot please prepare design doc Use when this capability is needed.
基于 SOC 职业分类
正在显示 SKILL.md
| name | kubernetes-operator |
| description | > Use when this capability is needed. |
Writing K8s manifests, debugging pod issues, setting up Helm charts, RBAC configuration.
PASS: Complete deployment with all safety features
apiVersion: apps/v1
kind: Deployment
metadata:
name: myapp
namespace: production
labels: { app: myapp }
spec:
replicas: 3
selector:
matchLabels: { app: myapp }
template:
metadata:
labels: { app: myapp }
spec:
containers:
- name: myapp
image: myapp:1.2.3 # NEVER use :latest in production
ports: [{ containerPort: 3000 }]
resources:
requests: { cpu: "100m", memory: "128Mi" }
limits: { cpu: "500m", memory: "512Mi" } # prevent OOMKilled
livenessProbe:
httpGet: { path: /health, port: 3000 }
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
httpGet: { path: /ready, port: 3000 }
initialDelaySeconds: 5
periodSeconds: 5
env:
- name: DATABASE_URL
valueFrom:
secretKeyRef: { name: myapp-secrets, key: database-url }
securityContext:
runAsNonRoot: true
runAsUser: 1000
readOnlyRootFilesystem: true
FAIL: Dangerous defaults
image: myapp:latest # No pinned version
# No resources (can OOM and crash cluster)
# No probes (Kubernetes can't detect unhealthy pods)
# No securityContext (runs as root)
# CrashLoopBackOff
kubectl logs <pod> --previous # logs before crash
kubectl describe pod <pod> # events section
kubectl get events --sort-by='.lastTimestamp' | head -20
# ImagePullBackOff
kubectl describe pod <pod> # look for image pull error
# Fix: check image name/tag, check registry credentials
# OOMKilled
kubectl top pods # check memory usage
kubectl describe pod <pod> | grep -A5 "OOM"
# Fix: increase memory limit, fix memory leak
# Pending pod (not scheduled)
kubectl describe pod <pod> # look for "Insufficient" in events
kubectl get nodes -o wide # check node capacity
apiVersion: v1
kind: ServiceAccount
metadata: { name: myapp, namespace: production }
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata: { name: myapp-role, namespace: production }
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata: { name: myapp-binding, namespace: production }
subjects: [{ kind: ServiceAccount, name: myapp, namespace: production }]
roleRef: { kind: Role, name: myapp-role, apiGroup: rbac.authorization.k8s.io }
| App Type | CPU Request | CPU Limit | Mem Request | Mem Limit |
|---|---|---|---|---|
| Node.js API | 100m | 500m | 128Mi | 512Mi |
| Python API | 100m | 500m | 256Mi | 1Gi |
| Database (Postgres) | 250m | 1000m | 512Mi | 2Gi |
| Redis | 100m | 500m | 128Mi | 512Mi |
Source: Abhiram1106/omnix — distributed by TomeVault.