selkies/skills/kde-selkies/SKILL.md
The KDE nested-compositor PRIMITIVE for the selkies streaming desktop — startplasma-wayland nested in pixelflux, de-SDDM, started by a supervisord poll-for-wayland-1 service. MUST be invoked before editing the kde-selkies candy or its kde-selkies-session wrapper.
npx skillsauth add overthinkos/overthink-plugins kde-selkiesInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
kde-selkies is the KDE analogue of the labwc candy: the swappable
nested-compositor primitive that renders a desktop into pixelflux's wayland-1.
It runs a FULL KDE Plasma Wayland session (startplasma-wayland =
kwin_wayland + plasmashell) nested in pixelflux, so selkies streams Plasma.
require: [selkies, kde-shell, pipewire, dbus] — NOT kde-desktop. A pod has
no DRM seat, no SDDM, no graphical.target. So:
kde-selkies-session (priority 12, scope: user,
%(ENV_HOME)s exec — resolves for both supervisord pods AND systemd-user
targets via service_render.go). No after: graphical-session.target —
the wrapper's poll-for-/tmp/wayland-1 IS the ordering primitive (identical to
labwc-wrapper).kde-selkies-session waits for pixelflux's wayland-1, sets
WAYLAND_DISPLAY=wayland-1 (so kwin renders INTO pixelflux), then
exec dbus-run-session startplasma-wayland. kwin creates wayland-0 for
Plasma's own clients.[program:chrome] service in the shared selkies-core candy
(/charly-selkies:selkies-core "Chrome supervision", restart: always) owns it for
both selkies flavors — chrome-wrapper self-polls for the wayland-0 client
socket kwin publishes, so it needs no per-flavor handoff and supervisord
relaunches Chrome if it self-exits during the startup-race. Chrome works headless
under KDE.This headless-no-seat path is exercised by the check-selkies-kde-pod bed:
kde-selkies-session RUNNING ≥20s, https://:3000/ → 200, Chrome CDP
/json/version → 200, plus the deploy-scope wl KWin checks this candy ships.
kde-selkies sets NO SELKIES_ENCODER — pixelflux auto-detects at runtime
(VAAPI on an AMD/Intel renderD via libva-native; NVENC from the cuda-arch-builder
pixelflux on the *-nvidia box; x264 otherwise). So ONE kde-selkies candy
streams on every GPU config. The encoder identity is asserted per-box in the
GPU check beds, not here.
/charly-selkies:labwc — the other nested-compositor primitive (the labwc seam)./charly-selkies:kde-shell — the SDDM-free Plasma session packages kde-selkies requires./charly-selkies:selkies-kde-desktop — the flavor metalayer composing this./charly-distros:cachyos — CachyOS/Arch base where the KDE Plasma stack lives.tools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).