filippobuletto

Kubectl Guard For Claude Code — DevOps skill for Claude Code

DevOps community

A PreToolUse hook for Claude Code that restricts what an AI agent can do with kubectl and helm through the Bash tool.

How to install Kubectl Guard For Claude Code

This entry records only its repository, not the path inside it, so there is no exact command to give. Open filippobuletto/kubectl-Guard-for-Claude-Code and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Kubectl Guard For Claude Code does

A PreToolUse hook for Claude Code that restricts what an AI agent can do with kubectl and helm through the Bash tool. It uses an allowlist: only known read-only operations run freely, everything else is either blocked or sent to you for confirmation.

Alternatives in DevOps

  • Cccc — Coordinate your coding agents like a group chat — read receipts, delivery tracking, and remote ops from your p 1.1k ★
  • Proxy — route Claude Code requests through multiple upstream providers (OpenCode Go, OpenCode Zen, and AWS Bedrock) wi 957 ★
  • WP CLI And Ops — WordPress CLI and operations management 902 ★

README

kubectl Guard for Claude Code

A `PreToolUse` hook for [Claude Code](https://claude.com/claude-code) that restricts what an AI agent can do with `kubectl` and `helm` through the Bash tool. It uses an **allowlist**: only known read-only operations run freely, everything else is either blocked or sent to you for confirmation.

Goal

Let an agent inspect a Kubernetes cluster (pods, logs, events, rollout status, ...) without being able to change it, read secrets, or switch identity, even if it is mistaken or prompt-injected.

This hook is a **convenience guard, not a security boundary**. It inspects the command string before it runs. The real enforcement should be Kubernetes RBAC (see [Caveats](#caveats)).

How it works

Claude Code runs the script before every Bash tool call and passes the call as JSON on stdin. The script extracts `.tool_input.command` with `jq` and decides:

Outcome Mechanism Effect
Allow exit 0, no output Command runs normally
Ask prints JSON with permissionDecision: "ask", exit 0 Claude Code shows a confirmation prompt with the reason
Deny message on stderr, exit 2 Command is blocked and the message is fed back to the agent

Decision flow

  1. Direct API access: curl/wget against the API server (:6443, kubernetes.default, service account token path) is always denied.
  2. Relevance check: if the command doesn't mention kubectl, kubecolor, helm, oc, k9s, kubectx or kubens, it is allowed untouched.
  3. Shell indirection: $VAR, $(...), backticks, eval and sh -c alongside k8s tooling are always denied, since the hook can't know what they expand to.
  4. Environment overrides: KUBECONFIG= and KUBECTL_*= are always denied.
  5. Segment splitting: the command is split on &&, ||, ;, | and &, and every kubectl/helm invocation is checked, including ones after xargs or pipes.
  6. Per-invocation checks:
    • Denied flags (always de