K8

k8s-service-mesh

Facilitates Kubernetes service mesh operations including traffic management and security policy enforcement.

Install

mkdir -p .claude/skills/k8s-service-mesh && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/5602" && unzip -o skill.zip -d .claude/skills/k8s-service-mesh && rm skill.zip

Installs to .claude/skills/k8s-service-mesh

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Manage Istio service mesh for traffic management, security, and observability. Use for traffic shifting, canary releases, mTLS, and service mesh troubleshooting.
161 chars✓ has a “when” trigger
Advanced

Key capabilities

  • Detect Istio installations
  • Analyze service mesh configurations
  • Inspect VirtualServices and DestinationRules
  • Verify sidecar injection status
  • Implement traffic shifting patterns

How it works

It uses specific Istio tools to analyze cluster state, verify proxy health, and apply traffic management policies via kubectl.

Inputs & outputs

You give it
Namespace or service name
You get back
Istio configuration analysis or traffic routing status

When to use k8s-service-mesh

  • Configure canary releases
  • Manage traffic shifting
  • Implement mTLS security policies
  • Troubleshoot service mesh proxies

About this skill

Kubernetes Service Mesh (Istio)

Traffic management, security, and observability using kubectl-mcp-server's Istio/Kiali tools.

When to Apply

Use this skill when:

  • User mentions: "Istio", "service mesh", "mTLS", "VirtualService", "traffic shifting"
  • Operations: traffic management, canary deployments, security policies
  • Keywords: "sidecar", "proxy", "traffic split", "mutual TLS"

Priority Rules

PriorityRuleImpactTools
1Detect Istio installation firstCRITICAListio_detect_tool
2Run analyze before changesHIGHistio_analyze_tool
3Check proxy status for syncHIGHistio_proxy_status_tool
4Verify sidecar injectionMEDIUMistio_sidecar_status_tool

Quick Reference

TaskToolExample
Detect Istioistio_detect_toolistio_detect_tool()
Analyze configistio_analyze_toolistio_analyze_tool(namespace)
Proxy statusistio_proxy_status_toolistio_proxy_status_tool()
List VirtualServicesistio_virtualservices_list_toolistio_virtualservices_list_tool(namespace)

Quick Status Check

Detect Istio Installation

istio_detect_tool()

Check Proxy Status

istio_proxy_status_tool()
istio_sidecar_status_tool(namespace)

Analyze Configuration

istio_analyze_tool(namespace)

Traffic Management

VirtualServices

List and inspect:

istio_virtualservices_list_tool(namespace)
istio_virtualservice_get_tool(name, namespace)

See TRAFFIC-SHIFTING.md for canary and blue-green patterns.

DestinationRules

istio_destinationrules_list_tool(namespace)

Gateways

istio_gateways_list_tool(namespace)

Traffic Shifting Patterns

Canary Release (Weight-Based)

VirtualService for 90/10 split:

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: my-service
spec:
  hosts:
  - my-service
  http:
  - route:
    - destination:
        host: my-service
        subset: stable
      weight: 90
    - destination:
        host: my-service
        subset: canary
      weight: 10

Apply and verify:

kubectl_apply(vs_yaml, namespace)
istio_virtualservice_get_tool("my-service", namespace)

Header-Based Routing

Route beta users:

http:
- match:
  - headers:
      x-user-type:
        exact: beta
  route:
  - destination:
      host: my-service
      subset: canary
- route:
  - destination:
      host: my-service
      subset: stable

Security (mTLS)

See MTLS.md for detailed mTLS configuration.

PeerAuthentication (mTLS Mode)

istio_peerauthentications_list_tool(namespace)

AuthorizationPolicy

istio_authorizationpolicies_list_tool(namespace)

Observability

Proxy Metrics

istio_proxy_status_tool()

Hubble (Cilium Integration)

If using Cilium with Istio:

hubble_flows_query_tool(namespace)
cilium_endpoints_list_tool(namespace)

Troubleshooting

Sidecar Not Injected

istio_sidecar_status_tool(namespace)

Traffic Not Routing

istio_analyze_tool(namespace)
istio_virtualservice_get_tool(name, namespace)
istio_destinationrules_list_tool(namespace)
istio_proxy_status_tool()

mTLS Failures

istio_peerauthentications_list_tool(namespace)

Common Issues

SymptomCheckResolution
503 errorsistio_analyze_tool()Fix VirtualService/DestinationRule
No sidecaristio_sidecar_status_tool()Label namespace
Config not appliedistio_proxy_status_tool()Wait for sync or restart pod

Multi-Cluster Service Mesh

Istio multi-cluster setup:

istio_proxy_status_tool(context="primary")
istio_virtualservices_list_tool(namespace, context="primary")

istio_proxy_status_tool(context="remote")

Prerequisites

  • Istio: Required for all Istio tools
    istioctl install --set profile=demo
    

Related Skills

When not to use it

  • When managing non-Kubernetes networking
  • When performing manual proxy configuration without Istio

Prerequisites

Istio installed in the Kubernetes cluster

Limitations

  • Requires Istio to be installed
  • Troubleshooting depends on correct namespace labeling

How it compares

It provides a dedicated interface for Istio-specific operations, whereas manual kubectl usage is prone to configuration errors.

Compared to similar skills

k8s-service-mesh side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
k8s-service-mesh (this skill)16moReviewAdvanced
debug-cluster28moReviewIntermediate
lucas-runbook16moNo flagsBeginner
k8s-core06moNo flagsBeginner

Try saying

Example prompts that trigger this skill in your AI assistant.

More by rohitg00

View all by rohitg00

Search skills

Search the agent skills registry