{
  "id": "kubernetes-maestro",
  "name": "Kubernetes Maestro",
  "type": "skill",
  "provider": "kubernetes",
  "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"],
  "summary": "Route Kubernetes tasks to the narrowest specialist or team of specialists. Classifies task domains across RBAC, admission security, network policy, mesh, GitOps, observability, and workload identity. Never auto-dispatches live-guard agents.",
  "source_type": "original",
  "official_docs": [
    "https://kubernetes.io/docs/reference/access-authn-authz/rbac/",
    "https://kubernetes.io/docs/concepts/security/pod-security-admission/",
    "https://kyverno.io/docs/",
    "https://istio.io/latest/docs/ambient/",
    "https://docs.cilium.io/en/stable/",
    "https://argo-cd.readthedocs.io/en/stable/",
    "https://opentelemetry.io/docs/kubernetes/",
    "https://kubernetes.io/docs/concepts/workloads/pods/service-accounts/"
  ],
  "security_notes": "Live-guard gate is non-negotiable: kubernetes-live-rbac-mutation-guard-agent, kubernetes-live-admission-policy-guard-agent, kubernetes-live-mesh-policy-guard-agent, kubernetes-live-argocd-sync-guard-agent, and kubernetes-live-network-policy-guard-agent must never be auto-dispatched. Always surface blast-radius and rollback path and require explicit written human confirmation before routing to any live-guard agent.",
  "last_verified": "2026-05-01",
  "path": "skills/kubernetes/kubernetes-maestro",
  "author": "github: VincentChuWaiChow",
  "version": "0.1.0"
}
