Best for
- Building a new Kubernetes Operator (controller for a CRD)
- Reviewing an existing operator for capability-level gaps
- Auditing a CRD spec for status/conditions/finalizer correctness
alirezarezvani/claude-skills/engineering/skills/kubernetes-operator/SKILL.md
Use when building a Kubernetes Operator — custom controllers that reconcile CRD state. Triggers on "build an operator", "CRD design", "reconcile loop", "controller-runtime", "kubebuilder", "operator-sdk", "metacontroller", "KOPF", "operator capability levels", or "custom resource". Ships CRD validator, reconcile-loop linter, and OperatorHub capability auditor (all stdlib Python), 4 references on the operator pattern + CRD design + reconcile patterns + tooling landscape, and a /operator-audit sla
Decision brief
Build operators that reconcile correctly. Most operator bugs are not Kubernetes bugs — they are reconcile-loop bugs: missing finalizers, blocking calls, no requeue on transient errors, status drift, RBAC over-grants. This skill catches them deterministically before they reach a…
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Declared | Source record | Install path and trigger |
| Claude Code | Declared | Source record | Install path and trigger |
| Cursor | Declared | Source record | Install path and trigger |
| Gemini CLI | Declared | Source record | Install path and trigger |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/alirezarezvani/claude-skills --skill "engineering/skills/kubernetes-operator"Inspect the Agent Skill "kubernetes-operator" from https://github.com/alirezarezvani/claude-skills/blob/98180dafc4f0bc9d629bd479fc6107674cfb3cf8/engineering/skills/kubernetes-operator/SKILL.md at commit 98180dafc4f0bc9d629bd479fc6107674cfb3cf8. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
bash SKILL=engineering/kubernetes-operator/skills/kubernetes-operator
Review the “Workflow 1: Bootstrap a new operator (Go + kubebuilder)” section in the pinned source before continuing.
Review the “Workflow 2: Audit an existing operator” section in the pinned source before continuing.
Review the “Workflow 3: Choose a framework” section in the pinned source before continuing.
Building a new Kubernetes Operator (controller for a CRD)
Permission review
The documentation asks the agent to run terminal commands or scripts.
python "$SKILL/scripts/crd_validator.py" --crd config/crd/myapp.yamlThe documentation asks the agent to run terminal commands or scripts.
python "$SKILL/scripts/reconcile_lint.py" --controller controllers/myapp_controller.goEvidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 90/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 24,921 | Source | Repository attention, not individual Skill quality |
| Compatibility | 4 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Build operators that reconcile correctly. Most operator bugs are not Kubernetes bugs — they are reconcile-loop bugs: missing finalizers, blocking calls, no requeue on transient errors, status drift, RBAC over-grants. This skill catches them deterministically before they reach a cluster.
helm-chart-buildersenior-devopscloud-securityobserve(actual) → desired = read(spec) → diff(actual, desired) → act → update(status)
↓
requeue / done
Operators that fail are the ones that:
The 3 tools below catch each of these.
SKILL=engineering/kubernetes-operator/skills/kubernetes-operator
# Validate a CRD design
python "$SKILL/scripts/crd_validator.py" --crd config/crd/myapp.yaml
# Lint a Go reconcile function
python "$SKILL/scripts/reconcile_lint.py" --controller controllers/myapp_controller.go
# Score against OperatorHub Capability Levels (1-5)
python "$SKILL/scripts/operator_capability_audit.py" --operator-dir .
All stdlib-only. Run with --help.
crd_validator.pyValidates a CRD YAML against operator-pattern best practices.
python scripts/crd_validator.py --crd config/crd/myapp.yaml
python scripts/crd_validator.py --crd config/crd/ --format json
Checks:
spec.versions[*].subresources.status is set (status subresource)spec.scope is Namespaced (not Cluster) unless explicitly justifiedspec.versions[*].schema.openAPIV3Schema has type definitions (no x-kubernetes-preserve-unknown-fields: true at top level)served: true AND storage: truemetav1.Conditions)Age and Status/Phasereconcile_lint.pyLints a Go controller reconcile function for anti-patterns.
python scripts/reconcile_lint.py --controller controllers/myapp_controller.go
Checks (regex-based heuristics):
(ctrl.Result, error) shapereturn ctrl.Result{Requeue: true}, err)client.Update() on the spec object is flagged (controllers should update only status)time.Sleep inside reconcile is flagged (use RequeueAfter)defer after a finalizer addIsConditionTrue / SetCondition calls when conditions present in CRDoperator_capability_audit.pyScores an operator against OperatorHub's 5 Capability Levels.
python scripts/operator_capability_audit.py --operator-dir .
Levels:
Reports current level + concrete next steps to advance one level.
Pick a framework based on language and complexity. See references/tooling_landscape.md.
| Framework | Language | Best for | Maintenance |
|---|---|---|---|
| controller-runtime | Go | Production-grade, low-level control | Active (sig-api-machinery) |
| kubebuilder | Go | Standard scaffolding, opinionated | Active (Kubernetes SIGs) |
| operator-sdk | Go / Helm / Ansible | OpenShift / mixed-paradigm teams | Active (Red Hat) |
| metacontroller | Any (webhook-based) | Polyglot teams, avoiding Go | Less active |
| KOPF | Python | Python shops, async-first | Active (community) |
| java-operator-sdk | Java | JVM shops | Active (Red Hat / Java SIG) |
Decision rules:
See references/crd_design.md for full detail. Quick rules:
Ready, Reconciling, Degraded. Each carries a reason and message.v1alpha1 → v1beta1 → v1. Plan a conversion webhook.additionalPrinterColumns for kubectl get. Show Age, Phase, Ready at minimum.See references/reconcile_loop.md for full detail. Quick rules:
ctrl.Result{RequeueAfter: ...} for known transient cases.time.Sleep. No long HTTP calls without context.1. Pick a Group/Version/Kind: e.g., apps.example.com/v1alpha1, kind=MyApp
2. kubebuilder init --domain example.com --repo github.com/org/myapp-operator
3. kubebuilder create api --group apps --version v1alpha1 --kind MyApp
4. Run crd_validator.py on config/crd/bases/apps.example.com_myapps.yaml
→ Fix every WARN before writing controller code
5. Implement the reconcile function (Karpathy principle 2: simplest correct version first)
6. Run reconcile_lint.py on controllers/myapp_controller.go
7. Run operator_capability_audit.py --operator-dir . — confirm L1
8. Test in a kind cluster: kubectl apply -f config/samples/
9. Add status conditions; aim for L2 in the same PR
1. Run operator_capability_audit.py --operator-dir <path>
2. Run crd_validator.py --crd config/crd/
3. Run reconcile_lint.py --controller controllers/
4. Triage findings:
- FAIL → block release; fix before next deploy
- WARN → file an issue; fix in next 30 days
5. Document current capability level in README; commit
6. Plan one capability level advancement per quarter
1. Identify primary language constraint (team skill)
2. Identify deployment target (vanilla k8s vs OpenShift)
3. Identify operator complexity (single CRD vs multi-CRD vs cluster-wide)
4. Cross-reference with references/tooling_landscape.md
5. Build a 1-week proof-of-concept before committing
references/operator_pattern.md — what an operator IS, when to use vs alternativesreferences/crd_design.md — CRD design principles, versioning, conversion webhooksreferences/reconcile_loop.md — reconcile patterns, error handling, idempotencyreferences/tooling_landscape.md — framework comparison + decision tree/operator-audit — Run all 3 tools on an operator repo and produce a markdown report.
assets/crd_template.yaml — CRD with status subresource, conditions, finalizer hint, printer columnsassets/reconcile_skeleton.go — Go controller reconcile function with idempotency, conditions, finalizers, requeue patternstime.Sleep(30 * time.Second) inside reconcile — block other reconciles. Use RequeueAfter.r.Client.Update(ctx, obj) to set status — use r.Status().Update(ctx, obj) instead.x-kubernetes-preserve-unknown-fields: true on spec root — defeats validation.A team using this skill should achieve:
crd_validator.py before mergereconcile_lint.py strict modeFrequently asked questions
Build operators that reconcile correctly. Most operator bugs are not Kubernetes bugs — they are reconcile-loop bugs: missing finalizers, blocking calls, no requeue on transient errors, status drift, RBAC over-grants. This skill catches them deterministically before they reach a…
The source record exposes this install command: npx skills add https://github.com/alirezarezvani/claude-skills --skill "engineering/skills/kubernetes-operator". Inspect the command and pinned source before running it.
The pinned source record declares support for: codex, claude code, cursor, gemini cli.
Static rules flagged exec-script in the source; the page lists the matching lines and excerpts.
Alternatives
alirezarezvani/claude-skills
Use when planning, running, or learning from chaos engineering experiments. Triggers on "chaos experiment", "fault injection", "gameday", "resilience test", "blast radius", "steady state", "abort criteria", "Chaos Toolkit", "Chaos Mesh", "Litmus", "Gremlin", "AWS FIS", or any deliberate failure-injection question. Ships experiment designer, blast-radius calculator, and postmortem generator (all stdlib Python), 4 references on chaos principles + experiment design + attack taxonomy + tooling lands
PramodDutta/qaskills
Simulate aggressive user behavior patterns including rapid clicking, random navigation, form abuse, tab spamming, and unexpected interaction sequences to find UI resilience issues
PramodDutta/qaskills
Verify loading indicators, skeleton screens, and progress bars appear correctly during async operations and disappear on completion or error.
PramodDutta/qaskills
Comprehensive SDET interview preparation covering coding challenges, system design for testing, automation framework design, CI/CD pipeline questions, testing strategy discussions, and behavioral interview patterns for QA engineering roles.