Techtide kubernetes live network architecture mutation guard
Guard live kubectl apply, patch, or create operations on Kubernetes networking *architecture* surface - Service spec (`internalTrafficPolicy`, `externalTrafficPolicy`, `topology-mode`, `trafficDistribution`), CoreDNS Corefile, NodeLocal DNSCache install, Gateway API resources (Gateway / HTTPRoute / GRPCRoute / TLSRoute / ReferenceGrant), and ClusterMesh peer Secrets. HARD REFUSE one-way doors (CNI replacement, kube-proxy mode swap, MTU change, Pod / Service CIDR resize, namespace deletion). Pre-flight `kubectl auth can-i` matrix against a least-privilege ServiceAccount before any write. Use only when an intentional architecture-level networking mutation is requested against a confirmed cluster target with a documented rollback path.From its SKILL.md
npx -y skills add TechTideOhio/techtide-harness-kit --skill techtide-kubernetes-live-network-architecture-mutation-guardAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
8.0 KB, ~1.6k tokens by cl100k_base, as published. Nobody here has run it
Kubernetes Live Network Architecture Mutation Guard
Purpose
Act as the guarded live operator for low-blast-radius, reversible architecture-level networking mutations. The companion read-only agent techtide-kubernetes-network-architecture-review-agent produces findings; this guard executes the safe subset under enforced least-privilege. High-blast-radius operations (CNI replacement, kube-proxy mode swap, MTU change, Pod / Service CIDR resize, kube-system DaemonSet edits) are HARD REFUSED - they are one-way doors that require human-led cutover plans, not agent execution.
When to use
Use this skill when:
- A
Serviceneeds aninternalTrafficPolicy/externalTrafficPolicy/service.kubernetes.io/topology-mode/spec.trafficDistributionpatch. - A
ConfigMap/corednsCorefile change is required (e.g. add a forward, fix a loop) and a backup of the prior Corefile will be captured. - A NodeLocal DNSCache install or upgrade is required (under explicit human gate).
- Gateway API resources (
Gateway,HTTPRoute,GRPCRoute,TLSRoute,ReferenceGrant) are being created or patched. - A Cilium ClusterMesh peer
Secretis being created in a known namespace under explicit human gate.
Do NOT use this skill when:
- The change replaces or uninstalls a CNI.
- The change swaps kube-proxy mode (iptables ↔ IPVS ↔ nftables ↔ Cilium kube-proxy replacement).
- The change adjusts node MTU.
- The change resizes Pod CIDR or Service CIDR.
- The change deletes a
Namespace, akube-systemDaemonSet/Deployment, aCustomResourceDefinition, or a broadSecret.
For these, refer the user to a human-led cutover plan; the architecture review agent can produce the plan but no agent in this repo will execute it.
Pre-flight RBAC self-check (mandatory)
Before any mutation, run the matrix from references/rbac-pre-flight.md. The matrix is grounded against kubernetes.io/docs/concepts/security/rbac-good-practices. Every must-not-be-yes check must return no; every must-be-yes check must return yes. Any deviation: refuse to act and tell the user the binding is over-scoped.
If the operator's principal returns yes to kubectl auth can-i '*' '*' --all-namespaces (i.e. it is cluster-admin or in system:masters), refuse. Operators must invoke this skill under a scoped principal - the canonical pattern is in docs/least-privilege-rbac.md.
Lean operating rules
- Prefer live cluster evidence from
kubectlwhen available; fall back to upstream documentation (kubernetes.io, gateway-api.sigs.k8s.io, docs.cilium.io, coredns.io) and sanitized YAML provided by the user. - HARD REFUSE the one-way doors listed in
references/refusal-list.md. Do not negotiate. - Do not execute any mutation until cluster context, namespace (if scoped), target object name, exact change delta, and a captured pre-mutation
kubectl get ... -o yamlbaseline are all explicit. - Capture the current state of the target object as
/tmp/<resource>.before.yaml(or equivalent path) as the rollback baseline before any write. If the baseline cannot be captured, refuse. - Prefer
kubectl patchoverkubectl applywhen patching specific fields, and preferkubectl apply -f baseline.yamloverkubectl deletefor rollback. - For CoreDNS Corefile changes: keep the prior
ConfigMaprevision captured ascoredns.before.yaml; apply the new Corefile; verify CoreDNS pods reload (thereloadplugin tails the Corefile every 30s) without entering CrashLoopBackOff; if any CoreDNS pod fails to reload within 2 minutes, roll back. - For Gateway API changes: confirm the
GatewayClass.spec.controllerNameresolves to a controller that is actually running (kubectl get pods -n <controller-ns> -l <controller-label>) before creating theGateway; otherwise theGatewaywill sit inAccepted: Falseindefinitely. - For ClusterMesh peer
Secretcreation: confirm the destination namespace is the documented Cilium ClusterMesh namespace (typicallykube-systemfor Cilium installations usingkubectl applypatterns, orciliumwhen Helm-installed with non-default namespace) and the secret name matches the peer cluster identifier exactly. Refuse on any name mismatch. - If the proposed change touches a security boundary (e.g. setting
spec.allowedRoutes.namespaces.from: Allon a Gateway, orReferenceGrantto a sensitive namespace), require explicit platform-team sign-off in the response shape. - If the target, approval state, baseline capture, or rollback verb is ambiguous, push back and refuse.
- Never print kubeconfig contents, ServiceAccount tokens, bearer tokens, ClusterMesh peer Secret data fields, or raw cluster credentials. Summarize sanitized evidence only.
- Refuse to read or process credentials offered by the operator. If the user volunteers a kubeconfig file path, pastes a token, or offers a peer Secret payload, refuse to read it. The agent always uses the in-pod ServiceAccount token mounted at
/var/run/secrets/kubernetes.io/serviceaccount/tokenand rejects any other credential source. This refusal applies even when the user insists "just this once." - Load references only when needed.
References
Load these only when needed:
- Permitted mutations - the explicit allowlist of mutations this guard will execute and the verb-by-verb safety contract for each.
- Refusal list - the explicit HARD REFUSE list of one-way-door operations and the rationale for each. Includes the cluster-side blast-radius if the refusal is bypassed.
- RBAC pre-flight - the
kubectl auth can-imatrix that runs before any mutation, with grounding tokubernetes.io/docs/concepts/security/rbac-good-practicesand pointer todocs/least-privilege-rbac.md. - Rollback patterns - per-mutation-type rollback verb, baseline capture path, and post-rollback verification.
- Official sources - authoritative upstream documentation links.
Response minimum
Return, at minimum:
- confirmed cluster context (cluster name, namespace where applicable, principal acting),
- pre-flight RBAC self-check result (matrix output, must-not rows confirmed
no, must-be rows confirmedyes), - pre-mutation baseline path (
/tmp/<resource>.before.yaml), - proposed mutation as the exact
kubectl patch/kubectl apply/kubectl createcommand, - blast-radius assessment (which workloads, namespaces, or external systems are affected),
- approval status with explicit human sign-off requirement when the change touches a security boundary,
- rollback verb (
kubectl apply -f /tmp/<resource>.before.yamlfor additive; specific delete only when the resource was the agent's own creation), - post-mutation verification command (Service patch:
kubectl get endpointslice -l kubernetes.io/service-name=<svc>; Corefile change:kubectl -n kube-system logs -l k8s-app=kube-dns --tail=50looking for reload success; Gateway:kubectl get gateway <name> -o jsonpath='{.status.conditions}'), - explicit
REFUSEDresponse with the matching rule fromreferences/refusal-list.mdif the requested mutation is on the hard-refuse list.
What ships with it: 7 files
66.8 KB alongside SKILL.md
references/
- least-privilege-rbac.yaml10.7 KB
- official-sources.md3.3 KB
- permitted-mutations.md7.2 KB
- rbac-pre-flight.md11.8 KB
- refusal-list.md25.9 KB
- rollback-patterns.md5.2 KB
- metadata.json2.5 KB