coder/skills/kubernetes-layer/SKILL.md
Kubernetes client tools: kubectl and Helm package manager. Use when working with Kubernetes, kubectl, or Helm charts.
npx skillsauth add overthinkos/overthink-plugins kubernetes-layerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Install files | charly.yml, task: |
RPM: kubernetes-client, helm
rpm: (Fedora), pac: (Arch — kubectl + helm from extra), deb: — adds two upstream apt repos: https://pkgs.k8s.io/core:/stable:/v1.30/deb/ for kubectl and https://baltocdn.com/helm/stable/debian/all for helm. Both use signed-by GPG keys. The flat-repo pkgs.k8s.io URL ends in / — supported by build.yml's deb install template (the trailing-slash suite special case added during Phase 3).
# charly.yml
my-devops:
candy:
- kubernetes
/charly-coder:docker-ce — common companion for local container builds/charly-coder:devops-tools — provides kubectx/kubens and cloud CLIs/charly-coder:dev-tools — typically paired in DevOps boxes/charly-build:build — installs kubectl and helm RPMs during image build/charly-core:shell — run kubectl/helm interactively against external clustersUse when the user asks about:
kubernetes candy/charly-image:layer — candy authoring reference (charly.yml schema, task verbs, service declarations)/charly-eval:eval — declarative testing (eval: block, charly eval box, charly eval live)tools
OpenCharly CLI (charly) binary installed into container/VM images for in-container use. Use when working with charly binary deployment inside containers, native D-Bus support, or the full charly toolchain (charly binary + virtualization + gocryptfs + socat).
development
Operator CachyOS workstation profile — a kind:local template + target:local deploy that installs the full dev stack (30 candies) onto a CachyOS host via ShellExecutor. Lives in the overthinkos/cachyos submodule. MUST be invoked before editing or applying the charly-cachyos workstation profile.
tools
Fedora box with the full charly toolchain using shared candies. Rootless-first — runs as uid=1000 with passwordless sudo (no root, no cap_add: ALL). Same candy list as charly-arch. Includes NVIDIA GPU runtime. MUST be invoked before building, deploying, configuring, or troubleshooting the charly-fedora box.
tools
Arch Linux box with the full charly toolchain. Rootless-first — runs as uid=1000 with passwordless sudo (no root, no cap_add: ALL). Composes /charly-coder:charly-mcp so the box is reachable as an MCP gateway on port 18765. NVIDIA GPU runtime composed in. MUST be invoked before building, deploying, configuring, or troubleshooting the charly-arch box.