Build a small, safe container for Kubernetes: multi-stage with a distroless/minimal base, non-root UID, digest-pinned base, dropped Linux capabilities, and a read-only root filesystem.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cloud-native-kubernetes:container-hardening-k8sThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Multi-stage: build in one stage, copy the artifact into a **distroless/minimal** runtime. No compiler/shell in runtime.
Multi-stage: build in one stage, copy the artifact into a distroless/minimal runtime. No compiler/shell in runtime.
Every package is a CVE + attack surface. Distroless quiets most scans by construction. Read-only FS + dropped caps shrink blast radius cheaply. Route the residual CVE verdict to security-engineering.
npx claudepluginhub mcorbett51090/ravenclaude --plugin cloud-native-kubernetesGuides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Enforces test-driven development: write failing test first, then minimal code to pass. Use when implementing features or bugfixes.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.