Skip to content
Back to skills

Kubernetes

ASecurity

Operate Kubernetes with kubectl, Helm, k9s, kustomize, and stern.

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentsgobashdockerkubernetesdebugginggitsecuritydocumentation

Works with

  • terminal
  • cli

Security analysis

A100/100

Scanned October 6, 2026

npx -y skills add fmind/dot --skill kubernetes --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Kubernetes?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Kubernetes
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fmind-kubernetes/badge)](https://www.skillsdirectory.com/skills/fmind-kubernetes)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: kubernetes
description: "Operate Kubernetes with kubectl, Helm, k9s, kustomize, and stern."
license: MIT
metadata:
  kind: task
  author: Médéric HURIER (Fmind)
  source: github.com/fmind/dot/tree/main/skills/kubernetes
  created: "2026-09-16"
  updated: "2026-10-05"
---

# Kubernetes Cluster and Workload Operations

Use `kubectl`, `helm`, `k9s`, `kustomize`, and `stern` for Kubernetes cluster inspection, manifest authoring, Helm releases, and log debugging. [docker](../docker/SKILL.md) manages container runtimes and [infra-as-code](../infra-as-code/SKILL.md) provisions managed cloud clusters.

Confirm user authority for cluster mutations and spending, reusing existing authorization. Pin `--context` and `--namespace` (or Helm's `--kube-context`) after resolving the intended cluster.

## Workflow

1. **Verify active context and namespace**: inspect the current cluster context before running any command; never assume terminal defaults point to dev.

   ```bash
   kubectl config get-contexts
   kubectl --context <context> cluster-info
   ```

1. **Lint and validate manifests**: validate schemas against the target cluster's version (kubeconform defaults to `master` schemas) and verify security practices prior to applying manifests.

   ```bash
   kubeconform -strict -summary -kubernetes-version <cluster-version> <file-or-directory>
   trivy config <file-or-directory>
   kustomize build <kustomization-dir> | kubeconform -strict -summary -kubernetes-version <cluster-version> -
   ```

1. **Use a local cluster only when needed**: read [k3d](references/k3d.md) before creating or deleting one; manifest checks often answer the question without it.

1. **Deploy declaratively**: apply configurations using Helm or Kustomize; preview changes before mutating cluster state.

   ```bash
   helm upgrade --install <release-name> <chart-path> --kube-context <context> --namespace <namespace> --dry-run=server --hide-secret
   kubectl --context <context> --namespace <namespace> diff -k <kustomization-dir>
   ```

   A diff exit status of 1 means differences; higher values are errors. Review the preview, then apply within the authorized scope. `kubectl diff` masks Secret data unless `--show-secrets` is passed, but ConfigMaps and rendered chart values are not masked; exclude sensitive values from captured output.

1. **Inspect workloads and bounded logs**: narrow to the relevant workload and time window. Use finite log reads for agents; reserve `k9s` and streaming `stern` for an explicitly interactive investigation. The line limit applies per pod/container, so keep the pod query narrow.

   ```bash
   stern <pod-query> --context <context> -n <namespace> --since 15m --tail 50 --no-follow
   kubectl --context <context> get pods,events -n <namespace>
   ```

## Gotchas

- **Pin the context explicitly**: omitted context flags use mutable kubeconfig defaults. Pass the selected context on each call; change the persistent current context only when that change is requested.
- **Keep Secret payloads out of logs**: avoid running unbounded `kubectl get secret -o yaml`; inspect metadata and annotate keys without printing raw base64 payloads to terminal logs.

## Task guides

<!-- guides:start -->

- [k3d](references/k3d.md): Create, budget, and tear down disposable local k3d clusters for runtime tests.

<!-- guides:end -->

## Documentation

- [Kubernetes Documentation](https://kubernetes.io/docs/) · [Helm Documentation](https://helm.sh/docs/)
- [k9s Terminal UI](https://k9scli.io/) · [Stern Log Tailer](https://github.com/stern/stern)
- Releases: [Kubernetes Releases](https://github.com/kubernetes/kubernetes/releases)
- Companion skills: [docker](../docker/SKILL.md) (container runtimes), [infra-as-code](../infra-as-code/SKILL.md) (provisioning), [incident-response](../incident-response/SKILL.md) (outages).

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…