k8s-policy
Identifies installed policy engines to manage security rules, check compliance, and review constraint templates.
Install
mkdir -p .claude/skills/k8s-policy && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/5544" && unzip -o skill.zip -d .claude/skills/k8s-policy && rm skill.zipInstalls to .claude/skills/k8s-policy
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Kubernetes policy management with Kyverno and Gatekeeper. Use when enforcing security policies, validating resources, or auditing policy compliance.Key capabilities
- →Audits active Kyverno and Gatekeeper engines
- →Lists policy violations from cluster reports
- →Retrieves constraint template definitions
- →Enables validation of manifests against policies
How it works
Interfaces with the Kubernetes API to read custom resources related to policy engines and parse their violation status.
Inputs & outputs
When to use k8s-policy
- →List all active Kyverno policies
- →Audit compliance violations in the cluster
- →Check Gatekeeper constraint templates
- →Validate resource configurations against policies
About this skill
Kubernetes Policy Management
Manage policies using kubectl-mcp-server's Kyverno and Gatekeeper tools.
When to Apply
Use this skill when:
- User mentions: "Kyverno", "Gatekeeper", "OPA", "policy", "compliance"
- Operations: enforcing policies, checking violations, policy audit
- Keywords: "require labels", "block privileged", "validate", "enforce"
Priority Rules
| Priority | Rule | Impact | Tools |
|---|---|---|---|
| 1 | Detect policy engine first | CRITICAL | kyverno_detect_tool, gatekeeper_detect_tool |
| 2 | Use Audit mode before Enforce | HIGH | validationFailureAction |
| 3 | Check policy reports for violations | HIGH | kyverno_clusterpolicyreports_list_tool |
| 4 | Review constraint templates | MEDIUM | gatekeeper_constrainttemplates_list_tool |
Quick Reference
| Task | Tool | Example |
|---|---|---|
| List Kyverno cluster policies | kyverno_clusterpolicies_list_tool | kyverno_clusterpolicies_list_tool() |
| Get Kyverno policy | kyverno_clusterpolicy_get_tool | kyverno_clusterpolicy_get_tool(name) |
| List Gatekeeper constraints | gatekeeper_constraints_list_tool | gatekeeper_constraints_list_tool() |
| Get constraint | gatekeeper_constraint_get_tool | gatekeeper_constraint_get_tool(kind, name) |
Kyverno
Detect Installation
kyverno_detect_tool()
List Policies
kyverno_clusterpolicies_list_tool()
kyverno_policies_list_tool(namespace="default")
Get Policy Details
kyverno_clusterpolicy_get_tool(name="require-labels")
kyverno_policy_get_tool(name="require-resources", namespace="default")
Policy Reports
kyverno_clusterpolicyreports_list_tool()
kyverno_policyreports_list_tool(namespace="default")
Common Kyverno Policies
kubectl_apply(manifest="""
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-labels
spec:
validationFailureAction: Enforce
rules:
- name: require-app-label
match:
resources:
kinds:
- Pod
validate:
message: "Label 'app' is required"
pattern:
metadata:
labels:
app: "?*"
""")
kubectl_apply(manifest="""
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-limits
spec:
validationFailureAction: Enforce
rules:
- name: require-cpu-memory
match:
resources:
kinds:
- Pod
validate:
message: "CPU and memory limits required"
pattern:
spec:
containers:
- resources:
limits:
cpu: "?*"
memory: "?*"
""")
Gatekeeper (OPA)
Detect Installation
gatekeeper_detect_tool()
List Constraints
gatekeeper_constraints_list_tool()
gatekeeper_constrainttemplates_list_tool()
Get Constraint Details
gatekeeper_constraint_get_tool(
kind="K8sRequiredLabels",
name="require-app-label"
)
gatekeeper_constrainttemplate_get_tool(name="k8srequiredlabels")
Common Gatekeeper Policies
kubectl_apply(manifest="""
apiVersion: templates.gatekeeper.sh/v1
kind: ConstraintTemplate
metadata:
name: k8srequiredlabels
spec:
crd:
spec:
names:
kind: K8sRequiredLabels
validation:
openAPIV3Schema:
type: object
properties:
labels:
type: array
items:
type: string
targets:
- target: admission.k8s.gatekeeper.sh
rego: |
package k8srequiredlabels
violation[{"msg": msg}] {
provided := {label | input.review.object.metadata.labels[label]}
required := {label | label := input.parameters.labels[_]}
missing := required - provided
count(missing) > 0
msg := sprintf("Missing labels: %v", [missing])
}
""")
kubectl_apply(manifest="""
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sRequiredLabels
metadata:
name: require-app-label
spec:
match:
kinds:
- apiGroups: [""]
kinds: ["Pod"]
parameters:
labels: ["app", "env"]
""")
Policy Audit Workflow
kyverno_detect_tool()
kyverno_clusterpolicies_list_tool()
kyverno_clusterpolicyreports_list_tool()
Prerequisites
- Kyverno: Required for Kyverno tools
kubectl create -f https://github.com/kyverno/kyverno/releases/latest/download/install.yaml - Gatekeeper: Required for Gatekeeper tools
kubectl apply -f https://raw.githubusercontent.com/open-policy-agent/gatekeeper/master/deploy/gatekeeper.yaml
Related Skills
- k8s-security - RBAC and security
- k8s-operations - Apply policies
When not to use it
- →Creating infrastructure resources directly
- →Managing non-policy related cluster objects
Prerequisites
Limitations
- →Only as effective as the installed policies
- →Read-only focus limits remediation capabilities
How it compares
It centralizes security auditing instead of searching for policies across different API groups manually.
Compared to similar skills
k8s-policy side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| k8s-policy (this skill) | 1 | 6mo | Review | Advanced |
| k8s-security | 1 | 6mo | Review | Advanced |
| security-automation | 1 | 7mo | Review | Advanced |
| k8s-security-policies | 3 | 5mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by rohitg00
View all by rohitg00 →You might also like
k8s-security
rohitg00
Audit Kubernetes RBAC, enforce policies, and manage secrets. Use for security reviews, permission audits, policy enforcement with Kyverno/Gatekeeper, and secret management.
security-automation
Ed1s0nZ
安全自动化的专业技能和方法论
k8s-security-policies
wshobson
Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.
container-security-testing
Ed1s0nZ
容器安全测试的专业技能和方法论
k8s-certs
rohitg00
Kubernetes certificate management with cert-manager. Use when managing TLS certificates, configuring issuers, or troubleshooting certificate issues.
benchmarking-kubernetes-with-kube-bench
mukul975
Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.