infrastructure/skills/k3s/SKILL.md
k3s binary installer (common base for k3s-server and k3s-agent). Use when building images that need the k3s binary but do NOT want a server/agent service started automatically.
npx skillsauth add overthinkos/overthink-plugins k3sInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Install files | charly.yml (binary fetch + symlinks via a run: plan step) |
| Pinned version | v1.31.11+k3s1 (edit K3S_VERSION in charly.yml vars to cut over) |
Downloads the verified-checksum k3s binary (plus sha256sum from the
release manifest), installs it to /usr/local/bin/k3s, and creates
symlinks for kubectl, crictl, ctr (k3s is multi-call). Installs
runtime dependencies (iptables, conntrack, socat, ethtool,
ca-certificates) via the distro package manager — not via the
upstream curl | sh installer. Deliberate, per R9.
No service is started by this candy. Role selection happens in the
dependent candies /charly-infrastructure:k3s-server and /charly-infrastructure:k3s-agent,
which emit systemd units that wrap this binary with the right CLI verb
(k3s server vs k3s agent).
Typically not used directly — compose /charly-infrastructure:k3s-server or
/charly-infrastructure:k3s-agent (both depend on this candy).
# For a bare binary-only image (rare) — a box composes the candy through a
# <box>-candy child node (node-form: every non-scalar field is its own node):
k3s-base:
candy:
base: fedora
k3s-base-candy:
candy:
- k3s
rpm: (Fedora) — conntrack-tools, iptables, ethtool, socat, ca-certificatespac: (Arch) — conntrack-tools, iptables-nft, ethtool, socat, ca-certificatesdeb: (Debian/Ubuntu) — conntrack, iptables, ethtool, socat, ca-certificatesk3s --version matches pinned version./usr/local/bin/k3s is mode 0755./usr/local/bin/kubectl exists as a symlink.package_map handles Debian's conntrack rename)./charly-infrastructure:k3s-server — Control-plane node (depends on this candy)/charly-infrastructure:k3s-agent — Worker node (depends on this candy)/charly-coder:kubernetes-layer — Distro kubectl/helm binaries for the operator, not the clustertools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).