{
 "id": "kubernetes-helm",
 "kind": "skill",
 "name": "Kubernetes and Helm",
 "description": "Inspect, debug and change Kubernetes clusters and manifests, and write Helm charts, including GitOps (Argo CD) setups.",
 "version": "1.0.0",
 "author": "Hexa Hub",
 "files": {
  "SKILL.md": "---\nname: kubernetes-helm\ndescription: Inspect, debug and change Kubernetes clusters and manifests, and write Helm charts, including GitOps (Argo CD) setups.\ntitle: Kubernetes and Helm\nicon: tabler:ship\ncategory: Containers\ntriggers: kubernetes, k8s, kubectl, helm, chart, pod, deployment, ingress, namespace, argocd, argo, kustomize, crashloopbackoff, imagepullbackoff\nmarkers: kubectl, helm\nrecipes: kubectl.get, kubectl.describe, kubectl.logs, kubectl.diff, kubectl.apply, helm.lint, helm.template, help.kubectl-explain, help.helm\nrelated: docker-compose, gitlab-ci\ncheck: Chart.yaml => helm.lint chart=$dir\n---\n\n# Kubernetes and Helm\n\n## First: which cluster?\nEvery kubectl recipe takes `context`. Ask or check which context is meant; never assume the current one is a test cluster. A context or namespace with `prod` in its name is prod: reading is fine, changes are blocked unless the user unlocked prod.\n\n## Debugging a workload (read-only, no approval)\n1. `kubectl.get` resource `pods`, with `namespace`: look at STATUS and RESTARTS.\n2. `kubectl.describe` the pod: read the **Events** at the bottom first.\n3. `kubectl.logs` for the pod (and `container` if there are several).\n\n| Status | Usual cause | Look at |\n|---|---|---|\n| ImagePullBackOff / ErrImagePull | wrong image name or tag, no pull secret | describe: the pull error text |\n| CrashLoopBackOff | the app exits at start | logs; config, env, missing secret |\n| Pending | no node fits: resources, taints, volume not bound | describe Events: `FailedScheduling` or the PVC |\n| OOMKilled | memory limit too low | describe: Last State; raise the limit |\n| Running but not ready | readiness probe fails | describe: probe; logs |\n\nSay what the evidence shows and what you could not see; do not guess a cause that the events do not support.\n\n**Check or review request**: read the manifest or chart, run `helm.lint` or `kubectl.diff` only if the user wants it compared with the cluster, then answer. Never apply for a review.\n\n## Changing manifests\n1. Find the manifest or chart (`find_code`). If **Argo CD or Flux** manages the app, change the Git repository, not the cluster: a direct apply is reverted on the next sync.\n2. Edit. Look up field names for the cluster's API version with `help.kubectl-explain` (for example `deployment.spec.strategy`); do not invent fields.\n3. For charts: `helm.lint`, then `helm.template` to see the rendered manifests. For plain manifests: `kubectl.diff`.\n4. **Show the user the diff.** Only if asked: `kubectl.apply` (same file, namespace and context as the diff). It always asks.\n\nExample: `run_recipe {\"recipe\":\"kubectl.diff\",\"args\":{\"file\":\"k8s/web.yaml\",\"namespace\":\"shop\",\"context\":\"test-aks\"}}`\n\n## Manifest habits\n- Always set `resources.requests` and `limits`, `readinessProbe` and `livenessProbe`, a non-root `securityContext`, and an explicit `namespace`.\n- Labels and selectors must match (`spec.selector.matchLabels` equals the pod template labels), and a Service selector must match the pod labels: a mismatch shows as a Service with no endpoints.\n- Pin image tags (never `latest`); secrets come from `Secret` objects or an external secret store, never from the manifest in Git.\n- Deployments: set a rollout strategy and `replicas` >= 2 for anything users depend on; use a PodDisruptionBudget.\n\n## Helm\n- Values: defaults in `values.yaml`, environment overrides in `values-<env>.yaml`; read the template to see which values exist.\n- Quote strings that could parse as numbers or booleans; use `{{- ... }}` to control whitespace; `required` for mandatory values; `toYaml | nindent N` for blocks.\n- `helm.template` must succeed and the output must pass `kubectl.diff` before anyone upgrades a release.\n\n## Report\nSay: what you looked at, the finding or the diff, what is still unknown, and whether anything was applied.\n"
 }
}
