competition-k8s-control-plane
Installation
SKILL.md
Competition K8s Control Plane
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when the decisive path runs through Kubernetes control-plane state, API permissions, or controller behavior rather than a single container's runtime alone.
Reply in Simplified Chinese unless the user explicitly requests English.
Quick Start
- Separate manifest intent from live cluster state: API objects, mutations, controllers, secrets, and resulting workloads.
- Identify the active principal first: service account, kubeconfig identity, node credential, webhook, or controller.
- Map the smallest control-plane edge to its workload effect.
- Keep RBAC, service accounts, owner references, namespace boundaries, and secret consumers in compact evidence blocks.
- Reproduce the smallest cluster action that yields the decisive workload or secret effect.