DeepSeek Harness Plugin

WODE25500/dsh-kubectl

Stars ★ 2 Category Development & Runtime Added 2026-08-21

Kubernetes ops for the agent: get resources with structured JSON output, describe, logs, exec, apply/delete (user-confirmed) and port-forward.

Install

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:WODE25500/dsh-kubectl

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

Kubernetes (kubectl) integration for DeepSeek Harness (dsh) — let the dsh agent inspect clusters, get resources, read logs, port-forward, and run one-off commands. Read-only commands emit structured JSON (reliable for the model); write operations require explicit confirmation.

Independent community project, not official. Based on kubernetes/kubectl (Apache-2.0).

Why

Kubernetes (40k+ stars) has no DSH adaptation plugin yet. kubectl's -o json structured output is ideal for agents — far better than table output:

Capability Notes
kubectl_get get resources, -o json structured output
kubectl_describe / kubectl_logs the troubleshooting trio
kubectl_status version/context/cluster info
kubectl_exec / kubectl_apply / kubectl_delete exec/deploy/delete (confirm first)
kubectl_port_forward local access to cluster services

Prerequisites

  • DeepSeek Harness (dsh)
  • kubectl installed with a configured kubeconfig (kubectl config get-contexts)

Install

- insert:
    - id: kubectl
      name: './src/index.js'
      config:
        kubectlPath: kubectl
        context: my-cluster
        namespace: default
pnpm dsh web --patch ./dsh-kubectl/cordis.patch.yml

Tools

Tool Behavior Safety
kubectl_get get resources (JSON) 🔵 read-only
kubectl_describe resource details 🔵 read-only
kubectl_logs pod logs (tail/previous/container) 🔵 read-only
kubectl_status version/context 🔵 read-only
kubectl_exec run command in container 🟡 confirm
kubectl_apply apply manifest 🔴 confirm
kubectl_delete delete resources 🔴 confirm
kubectl_port_forward port forwarding 🟡 long-running

Config

Key Default Purpose
kubectlPath kubectl kubectl path
context — default context
namespace — default namespace
timeoutMs 60000 per-call timeout

Known limitations

  • Without a cluster, commands return connection-refused errors (stderr verbatim)
  • port-forward is long-running; this version does not auto-stop it
  • Write operations rely on user confirmation; SKILL.md marks the red lines

Layout

dsh-kubectl/
  src/index.js            # 8 tools + config
  skills/kubectl/SKILL.md
  docs/
  cordis.patch.yml

License

MIT.

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.