frontend-forge-fe-oper…
Operate FrontendExtension (FE) resources in frontend-forge: create, update, rebuild, inspect package artifacts, download packages, publish, unpublish, delete,…
KubeSphere multi-tenant management Skill. Use when user requests to create users, workspaces, projects, or assign roles/permissions. Supports user lifecycle management, workspace configuration, project creation, role binding. Do not perform any delete operations, do not create
$ npx -y skills add kubesphere/kubesphere --skill kubesphere-multi-tenant-management --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/kubesphere-multi-tenant-managementContext preview
The summary Claude sees to decide when to auto-load this skill.
KubeSphere multi-tenant management Skill. Use when user requests to create users, workspaces, projects, or assign roles/permissions. Supports user lifecycle management, workspace configuration, project creation, role binding. Do not perform any delete operations, do not create
name: kubesphere-multi-tenant-management description: KubeSphere multi-tenant management Skill. Use when user requests to create users, workspaces, projects, or assign roles/permissions. Supports user lifecycle management, workspace configuration, project creation, role binding. Do not perform any delete operations, do not create custom roles.
1. **Never use kubectl edit/delete** - Do NOT use `kubectl edit`, `kubectl delete`, or similar commands to modify or delete workspaces, projects, users, roles, or role bindings. These operations are sensitive and should be performed via KubeSphere Console with proper approval workflow.
2. **Never perform delete operations via API** - Do NOT delete users, workspaces, projects, roles, or role bindings via API. These operations must be performed manually via KubeSphere Console with proper approval workflow. Only use this skill for creating and querying resources.
3. **Never create custom roles** - Do NOT create custom roles (Role, WorkspaceRole, GlobalRole). Only use built-in roles provided by KubeSphere. If custom permissions are needed, instruct the user to configure them via KubeSphere Console.
4. **Default to least privilege** - When creating users or assigning permissions, always use the minimum required access level:
The top-level organizational unit in KubeSphere, representing a team, department, or business unit. A workspace can contain multiple projects and serves as the basic boundary for resource grouping and access control. **Workspaces can span multiple clusters**, enabling centralized management of resources distributed across different clusters.
KubeSphere's enhanced Kubernetes namespace, representing a specific application, environment, or workload within a workspace. Each project maps to a separate namespace.
**Project Roles** (`roles.iam.kubesphere.io`):
**Workspace Roles** (WorkspaceRole, `workspaceroles.iam.kubesphere.io`):
**Platform Roles** (GlobalRole, `globalroles.iam.kubesphere.io`):
**Role Binding** (KubeSphere API endpoints, binds roles to Users):
Set up authentication using the provided CLI tool. First, navigate to the scripts directory:
# Navigate to the skill's scripts directory # Example path (replace with your actual kubesphere-skills location): cd ~/kubesphere-skills/core/kubesphere-core/scripts # Install required Python package pip install requests # Set host endpoint (optional, defaults to http://ks-apiserver.kubesphere-system) export KUBESPHERE_HOST="http://<kubesphere-host>" # Login to get token (token will be cached) python ks_api.py --login --username admin --password <your-password> # Token is cached in ~/.kubesphere_token and auto-refreshed # Optional: Clear cached token python ks_api.py --clear-cache
**Required parameters:**
# Create workspace via Python CLI
python ks_api.py POST /kapis/tenant.kubesphere.io/v1beta1/workspacetemplates '{
"apiVersion": "iam.kubesphere.io/v1beta1",
"kind": "WorkspaceTemplate",
"metadata": {
"name": "<workspace-name>",
"annotations": {
"kubesphere.io/creator": "<creator>"
}
},
"spec": {
"template": {
"spec": {
"manager": "<manager>"
},
"metadata": {
"annotations": {
"kubesphere.io/creator": "<creator>"
}
}
},
"placement": {
"clusters": [
{"name": "<cluster-name>"}
]
}
}
}'**Note:** Before creating a workspace, always ask the user for:
**Required parameters:**
# Create project within workspace via Python CLI python ks_api.py POST /clusters/<cluster-name>/kapis/tenant.kubesphere.io/v1bet
The container platform tailored for Kubernetes multi-cloud, datacenter, and edge management ⎈ 🖥 ☁️
Repo: kubesphere/kubesphere
Operate FrontendExtension (FE) resources in frontend-forge: create, update, rebuild, inspect package artifacts, download packages, publish, unpublish, delete,…
Operate FrontendIntegration resources and the frontend-forge extension. Use when Codex needs to create a FrontendIntegration from FrontendIntegration YAML,…
Generate canonical FrontendIntegration YAML from a simplified single-menu authoring model for frontend-forge.
Use when deploying KubeEye for cluster inspection, creating InspectRule/InspectPlan resources, or retrieving inspection results. Covers InstallPlan-based…
KubeSphere cluster query Skill (read-only). Use when user requests to view cluster list, cluster status, cluster details, or cluster version info. Do not…
KubeSphere central controller Skill. Routes to specific Skills based on user requests: multi-cluster management (kubesphere-cluster-management), multi-tenant…