ankra skills
Install the curated Ankra Agent Skills into the AI assistants you use. The skills teach an agent to follow Ankra’s practices for the CLI, getting started, building and importing clusters (provider, region, instance family), domains/DNS/TLS, ImportCluster YAML, stacks and addons, applications and their CI/CD, shipping code end to end through Ankra Pipelines, stack profiles, GitOps, SOPS secrets, Helm registries, observability, troubleshooting, security, and the AI agent surface. Claude Code, the Claude app, Cursor, Codex, GitHub Copilot, Windsurf, Gemini CLI, OpenCode, Cline, Zed and OpenClaw are supported, plus any assistant that reads AGENTS.md. With no--client, install picks the assistants configured on this
machine; ‘ankra skills clients’ shows what was detected.
Three things are installed per client:
--with-hooks to also install an agent hook that pauses direct kubectl/helm
cluster mutations for confirmation.
ankra skills clients
List every supported assistant, whether it is configured here, and where skills would be installed for it. Detection is what--client auto (the default)
selects; pass --project <DIR> to see the repository-scoped locations instead.
ankra skills guard
Read an agent hook event (JSON) from stdin and print a permission decision. Wired by ‘ankra skills install--with-hooks’ into Cursor’s
beforeShellExecution hook and Claude Code’s PreToolUse hook. Shell commands
that would mutate a Kubernetes cluster out-of-band (kubectl apply, helm
upgrade, …) return an “ask” decision explaining the Ankra GitOps workflow;
read-only commands and anything unparseable pass through unchanged.
ankra skills install
Install all skills (default) or only the named ones. Without--client, install targets every assistant configured on this machine
(see ‘ankra skills clients’), falling back to Claude Code and Cursor when none
is detected. --client all installs everywhere; --client <id> (repeatable, or
comma-separated) picks specific ones.
By default skills install for your user, available in every project. Use
--project <DIR> to install into a repository instead (--project . for the
current directory) - the right scope for GitHub Copilot, whose instructions
file is per repository.
The Claude app cannot read your filesystem, so --client claude-app writes one
uploadable .zip bundle per skill and prints where to upload them.
Install also writes an always-applied rule so the agent treats Ankra as the
default route for Kubernetes work, and - for clients that do not discover
skills on their own - an index naming each skill and its path (skip both with
--no-rules). Clients with slash commands additionally get the Ankra workflow
commands (skip with --no-workflows). With --with-hooks it installs the agent
hook (‘ankra skills guard’) that intercepts direct kubectl/helm cluster
mutations and asks for confirmation.
ankra skills list
List the available Ankra skillsankra skills uninstall
Remove the named skills, or all Ankra skills when none are given. The client selection works as it does for install, except that--client auto
(the default) resolves to the assistants that actually have Ankra skills
installed, so a plain ‘ankra skills uninstall’ undoes a plain install.
A full uninstall (no skill names) also removes the always-applied rule, the
workflow commands, and the ‘ankra skills guard’ hook that install added for
each client and scope; uninstalling named skills leaves them in place.