skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
beclab/olares197 installs

olares-cluster

Olares ControlHub K8s runtime view via olares-cli cluster — inspect pods, containers, workloads, logs, jobs, cronjobs, namespaces, nodes, and middleware; exec, scale, restart, or delete K8s objects. Use for raw runtime objects and logs, not app lifecycle (market), resource metrics (dashboard), or host install.

How do I install this agent skill?

npx skills add https://github.com/beclab/olares --skill olares-cluster
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill allows an agent to manage Kubernetes clusters via the olares-cli tool, providing capabilities for container command execution and middleware password access. These features present risks of indirect prompt injection and credential exposure, though the skill implements permission gates to restrict unauthorized access to namespaces.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

cluster (per-user K8s view)

Shared front door: load ../olares-shared/SKILL.md for suite routing, active-profile selection, platform entry points, and the auth proceed/stop gate. Load its auth reference only when login, profile switching, token storage, or auth recovery is actually needed.

Load the shared platform model when the task depends on app namespaces, application spaces, cross-namespace DNS, or system middleware. Use olares-cli cluster <noun> <verb> --help for syntax.

When to use

  • Inspect K8s runtime objects, YAML, events, logs, or identity context.
  • Execute a one-shot command in a container.
  • Scale, restart, stop, start, or delete a workload; suspend/resume cronjobs; rerun jobs.
  • Watch pod, workload, application, or log state.

Diagnosing why an app is broken (stuck install, crash loop, running but unreachable, image won't pull, resource pressure) is ../olares-doctor/SKILL.md — it orchestrates these cluster commands into symptom→root-cause routing. cluster stays the raw runtime view and the place that mutates K8s objects.

workload stop/start changes controller replicas; it does not update the Market lifecycle row. Use market stop/resume for app-level lifecycle.

Fast paths

TaskReadFirst command
See whether an app's pods are uppod operationsolares-cli cluster pod list -n <namespace> -o json, then read each .status.phase
Read a container's logspod operationsolares-cli cluster pod logs <pod> -n <namespace>
Find what this profile can see at allthis fileolares-cli cluster context -o json
Restart a workloadworkload operationsolares-cli cluster workload restart <name> -n <namespace>

The identity-vs-server-decides principle (cross-cutting)

  • Identity is the active profile; there is no per-invocation profile override.
  • The server decides visibility and authorization. cluster context is identity display, not a permission preflight.
  • Surface a 403 as authoritative. The exception is exec, whose namespace safety gate is described in its reference.

Verb index

NounVerbsRead when triggered
context(single verb)The ControlHub-side identity and scope of the active profile — what this tree can see at all, before any noun below returns empty
podlist, get, yaml, events, logs, delete, restart, execexec requires Olares 1.12.7+; pod operations; exec safety
containerlist, env, logs, execexec requires Olares 1.12.7+; exec safety
workload (wl)list, images, get, yaml, rollout-status, scale, restart, stop, start, deleteworkload operations
application (app)list, get, workloads, pods, statusapplication aggregation
namespace (alias ns)list, getScoped to the active profile, so this is the user's namespaces rather than the cluster's
node (alias nodes)list, getThe node names other trees ask for: files addresses cache/<node>/ and external/<node>/ by them, and a file task is retained per node
job (jobs)list, get, yaml, pods, events, rerunjob operations
cronjob (cronjobs, cj)list, get, yaml, jobs, suspend, resumecronjob operations
middleware (mw)listmiddleware model

Watch and asynchronous semantics

  • Watches and log follow poll; they are not streaming API watches.
  • Transient network/5xx failures are retried within a bounded streak. Terminal 4xx responses stop immediately; 408 and 429 remain retryable.
  • Ctrl-C stops the local poll cleanly. It does not undo a mutation already accepted by the server.
  • A rollout/status watch ending is not proof that the application entrance is healthy; use olares-doctor when runtime symptoms remain.

Safety and escalation

  • Confirm every destructive runtime mutation before invoking it, even if --yes is available.
  • exec is a remote code-execution boundary. Confirm namespace, pod, container, command, and whether writes are expected. Prefer one-shot execution; interactive TTY belongs to the human.
  • Do not delete or restart objects merely because a diagnostic found them unhealthy. Establish controller ownership and the app-level consequence first.
  • A 404 may hide a namespace the profile cannot see. Compare against cluster application list; do not broaden scope or switch identity without user approval.
  • For complete image-reference diagnostics use doctor images, not a paginated workload listing.
  • Stop on ambiguous namespace/resource identity, missing permission, or any request to access another user's container.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/beclab/olares/olares-cluster">View olares-cluster on skillZs</a>