Kubectl Guard For Claude Code — DevOps skill for Claude Code
A PreToolUse hook for Claude Code that restricts what an AI agent can do with kubectl and helm through the Bash tool.
How to install Kubectl Guard For Claude Code
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open filippobuletto/kubectl-Guard-for-Claude-Code and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Kubectl Guard For Claude Code does
A PreToolUse hook for Claude Code that restricts what an AI agent can do with kubectl and helm through the Bash tool. It uses an allowlist: only known read-only operations run freely, everything else is either blocked or sent to you for confirmation.
Alternatives in DevOps
- Cccc — Coordinate your coding agents like a group chat — read receipts, delivery tracking, and remote ops from your p 1.1k ★
- Proxy — route Claude Code requests through multiple upstream providers (OpenCode Go, OpenCode Zen, and AWS Bedrock) wi 957 ★
- WP CLI And Ops — WordPress CLI and operations management 902 ★
README
kubectl Guard for Claude Code
A `PreToolUse` hook for [Claude Code](https://claude.com/claude-code) that restricts what an AI agent can do with `kubectl` and `helm` through the Bash tool. It uses an **allowlist**: only known read-only operations run freely, everything else is either blocked or sent to you for confirmation.
Goal
Let an agent inspect a Kubernetes cluster (pods, logs, events, rollout status, ...) without being able to change it, read secrets, or switch identity, even if it is mistaken or prompt-injected.
This hook is a **convenience guard, not a security boundary**. It inspects the command string before it runs. The real enforcement should be Kubernetes RBAC (see [Caveats](#caveats)).
How it works
Claude Code runs the script before every Bash tool call and passes the call as JSON on stdin. The script extracts `.tool_input.command` with `jq` and decides:
| Outcome | Mechanism | Effect |
|---|---|---|
| Allow | exit 0, no output |
Command runs normally |
| Ask | prints JSON with permissionDecision: "ask", exit 0 |
Claude Code shows a confirmation prompt with the reason |
| Deny | message on stderr, exit 2 |
Command is blocked and the message is fed back to the agent |
Decision flow
- Direct API access:
curl/wgetagainst the API server (:6443,kubernetes.default, service account token path) is always denied. - Relevance check: if the command doesn't mention
kubectl,kubecolor,helm,oc,k9s,kubectxorkubens, it is allowed untouched. - Shell indirection:
$VAR,$(...), backticks,evalandsh -calongside k8s tooling are always denied, since the hook can't know what they expand to. - Environment overrides:
KUBECONFIG=andKUBECTL_*=are always denied. - Segment splitting: the command is split on
&&,||,;,|and&, and everykubectl/helminvocation is checked, including ones afterxargsor pipes. - Per-invocation checks:
- Denied flags (always de
Related Skills
Cc AWS Keepalive
Keep Claude Code sessions alive through AWS credential expiry -- proactive expiration warnings, credential ref
Se Conops
Concept of Operations (CREATE) — surface operational concerns (config/creds/user-mgmt/deploy) BEFORE use cases
Codejam Code Based Agents
Learn how to write code-based agents using Python, JavaScript and well-known industry standard frameworks. Lea
Omcr Setup
Install OMCR infrastructure (CLAUDE.md markers, agent-memory dirs, bibliography files, permission allowlist).
Cloudflare Codemode Bash
Claude Code skill for interacting with the Cloudflare API via bash + node
Hol Guard AWS Preflight
Fail-closed pre-execution HOL Guard skill for agents running aws CLI commands. Implements the aws/agent-toolki
Related Agents
Log Reader
Use proactively to read logs, test output, stack traces, CI/CD pipeline output, kubectl/helm/argocd output, PH
Worker Opus
Same rules as worker-sonnet, opus model. ONLY for critical architecture/design decisions or security-critical
Minimal Diff
Implements the smallest change that solves the stated problem, and refuses everything else. Use when scope cre