Operate a safe multi-tenant cluster: namespace-per-tenant with scoped RBAC (no workload cluster-admin), default-deny NetworkPolicies, resource quotas/LimitRanges, policy admission control, and tested PDB-respecting upgrades.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cloud-native-kubernetes:k8s-platform-opsThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Namespace per team/app; RBAC scoped to it. **No** workload gets cluster-admin.
Namespace per team/app; RBAC scoped to it. No workload gets cluster-admin.
Default-deny pod-to-pod, then allow required flows. (Pairs with mesh mTLS.)
ResourceQuota + LimitRange per namespace so no tenant starves the cluster.
Admission policy-as-code rejects privileged pods, missing limits, :latest. Preventive > detective.
Deprecated-API audit -> non-prod test -> drain respecting PDBs -> stay within version-skew -> rollback posture.
npx claudepluginhub mcorbett51090/ravenclaude --plugin cloud-native-kubernetesGuides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Enforces test-driven development: write failing test first, then minimal code to pass. Use when implementing features or bugfixes.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.