ov-layers/skills/k3s-agent/SKILL.md
k3s worker (agent) node — joins an existing k3s-server via pre-shared token. Fully declarative: same ov secrets set once + env K3S_SERVER_URL per agent deploy.
npx skillsauth add overthinkos/overthink-plugins k3s-agentInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Install files | layer.yml, tasks:, service:, secret_requires:, env_requires: |
| Depends on | /ov-layers:k3s |
| Service | k3s-agent.service (system scope, enabled) |
K3S_CLUSTER_TOKEN from the credential store (same secret the
server consumes).K3S_SERVER_URL from deploy.yml env (e.g.,
https://k3s-srv.lan:6443)./etc/rancher/k3s/config.yaml with server: and token:./etc/systemd/system/k3s-agent.service running k3s agent.No join-token handoff, no kubeconfig retrieval — agents only need the server URL (declarative, known at author time) and the pre-shared token (from the credential store).
# overthink.yml (assumes k3s-srv already up; see /ov-layers:k3s-server)
vm:
k3s-ag1:
source: { kind: cloud_image, url: "…" }
disposable: true
ram: 4G
cpus: 2
deployments:
images:
"vm:k3s-ag1":
target: vm
vm_source: k3s-ag1
add_layers: [k3s-agent]
env:
- K3S_SERVER_URL=https://k3s-srv.lan:6443
# K3S_CLUSTER fed in for the agent-joined test below — must
# match the cluster profile name registered by the server.
- K3S_CLUSTER=k3s-srv
ov deploy add vm:k3s-ag1
# agent registers; ov test k8s wait-nodes on server confirms the join.
ov test k8s wait-nodes --cluster k3s-srv --count 2 --timeout 3m
Build-scope:
/etc/rancher/k3s/config.yaml exists, mode 0600./etc/systemd/system/k3s-agent.service exists.Deploy-scope (uses /ov:test-k8s):
k8s: wait-nodes name=${HOSTNAME} — this node reaches Ready on the
server./ov-layers:k3s — Base layer installing the k3s binary (required dep)/ov-layers:k3s-server — Control-plane node this agent joins/ov:test-k8s — Test verb used by the agent-joined checktools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).