跳到主要内容
知仓学习社ZHICANG

kubernetes

Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.

执行命令联网无严重或高危命中notque/vexjoy-agent

它会碰到什么

扫了多少14 个文本文件,66 KB
它会碰到什么执行命令联网
命中总数2 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Kubernetes Skill

Kubernetes debugging, security hardening, and infrastructure tooling. Covers pod triage, RBAC, network policies, and cobaltcore hypervisor components.

Reference Loading Table

| Signal | Reference | Size |

|--------|-----------|------|

| CrashLoopBackOff, OOMKilled, config error, health check, liveness probe, ImagePullBackOff, Pending, FailedScheduling | references/crash-diagnosis.md | ~140 lines |

| service resolution, DNS, CoreDNS, port-forward, NetworkPolicy ingress/egress | references/network-debugging.md | ~50 lines |

| CPU throttling, memory limit, OOMKill, ephemeral storage, DiskPressure, debug container | references/resource-debugging.md | ~100 lines |

| RBAC, Role, RoleBinding, ClusterRole, ServiceAccount, least-privilege | references/rbac-patterns.md | ~60 lines |

| PodSecurity, SecurityContext, runAsNonRoot, readOnlyRootFilesystem, restricted, baseline | references/pod-security.md | ~90 lines |

| NetworkPolicy, default-deny, allow-list, namespace isolation | references/network-policies.md | ~70 lines |

| cosign, Kyverno, OPA, admission controller, Sealed Secrets, External Secrets | references/supply-chain.md | ~120 lines |

| kvm-exporter, metrics, prometheus, libvirt, hypervisor, collector, scrape, steal time, NUMA, cgroups, cloud hypervisor | references/cobalt-kvm-exporter.md | ~800 lines |

| cobaltcore concurrency, goroutine, semaphore, TryLock | references/cobalt-concurrency-patterns.md | ~200 lines |

| cobaltcore testing, mock, moq, Kind cluster | references/cobalt-testing-patterns.md | ~200 lines |

| kubernetes debugging process, triage flow, diagnosis routing | references/kubernetes-debugging.md | ~50 lines |

| kubernetes security process, RBAC + pod security + network hardening | references/kubernetes-security.md | ~50 lines |

| cobaltcore overview, KVM exporter architecture, component identification | references/cobalt-core.md | ~50 lines |

Loading rule. Read the references whose signals match the task before responding.


Phase 1: TRIAGE

Determine which Kubernetes domain the request targets:

| Domain | Load references | Action |

|--------|----------------|--------|

| Pod failure, CrashLoop, OOM | crash-diagnosis, resource-debugging | Triage flow |

| Network, DNS, service resolution | network-debugging, network-policies | Connectivity diagnosis |

| RBAC, permissions, roles | rbac-patterns | Access control |

| Pod hardening, container security | pod-security | Security posture |

| Image signing, secrets, admission | supply-chain | Supply chain |

| Cobaltcore / KVM exporter | kvm-exporter + cobalt refs | Component-specific |

Always specify -n <namespace> explicitly in every kubectl command.

Gate: Domain identified and relevant references loaded.


Phase 2: DIAGNOSE / RESPOND

For debugging: follow the triage flow — describe, logs, events, exec. Use read-only commands to gather evidence before proposing changes.

For security: provide concrete YAML manifests and specific configurations. Answer with reference-backed specifics, not generic advice.

For cobaltcore: use component-specific reference knowledge for architecture, metrics, configuration, and deployment details.

Gate: Specific, reference-backed diagnosis or response provided.


Phase 3: VERIFY

For debugging: confirm the fix resolves the symptom.

For security: validate against the misconfiguration table in supply-chain.md.

For cobaltcore: verify against component test patterns.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 419
本站分层T2
该仓技能数122
原文件路径skills/infrastructure/kubernetes/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 122 个技能