Kubernetes ops for the agent: get resources with structured JSON output, describe, logs, exec, apply/delete (user-confirmed) and port-forward.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:WODE25500/dsh-kubectl
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Kubernetes (kubectl) integration for DeepSeek Harness (dsh) — let the dsh agent inspect clusters, get resources, read logs, port-forward, and run one-off commands. Read-only commands emit structured JSON (reliable for the model); write operations require explicit confirmation.
Independent community project, not official. Based on kubernetes/kubectl (Apache-2.0).
Why
Kubernetes (40k+ stars) has no DSH adaptation plugin yet. kubectl's -o json
structured output is ideal for agents — far better than table output:
| Capability | Notes |
|---|---|
kubectl_get |
get resources, -o json structured output |
kubectl_describe / kubectl_logs |
the troubleshooting trio |
kubectl_status |
version/context/cluster info |
kubectl_exec / kubectl_apply / kubectl_delete |
exec/deploy/delete (confirm first) |
kubectl_port_forward |
local access to cluster services |
Prerequisites
- DeepSeek Harness (dsh)
- kubectl installed with a configured kubeconfig (
kubectl config get-contexts)
Install
- insert:
- id: kubectl
name: './src/index.js'
config:
kubectlPath: kubectl
context: my-cluster
namespace: default
pnpm dsh web --patch ./dsh-kubectl/cordis.patch.yml
Tools
| Tool | Behavior | Safety |
|---|---|---|
kubectl_get |
get resources (JSON) | 🔵 read-only |
kubectl_describe |
resource details | 🔵 read-only |
kubectl_logs |
pod logs (tail/previous/container) | 🔵 read-only |
kubectl_status |
version/context | 🔵 read-only |
kubectl_exec |
run command in container | 🟡 confirm |
kubectl_apply |
apply manifest | 🔴 confirm |
kubectl_delete |
delete resources | 🔴 confirm |
kubectl_port_forward |
port forwarding | 🟡 long-running |
Config
| Key | Default | Purpose |
|---|---|---|
kubectlPath |
kubectl |
kubectl path |
context |
— | default context |
namespace |
— | default namespace |
timeoutMs |
60000 |
per-call timeout |
Known limitations
- Without a cluster, commands return connection-refused errors (stderr verbatim)
port-forwardis long-running; this version does not auto-stop it- Write operations rely on user confirmation; SKILL.md marks the red lines
Layout
dsh-kubectl/
src/index.js # 8 tools + config
skills/kubectl/SKILL.md
docs/
cordis.patch.yml
License
MIT.
Links
More in this category
yjh051108/dsh-routing-suite★ 7000
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3678
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 324
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 212
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
Fishquito7/dsh-skill-mcp-panel★ 175
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
lire1131/dsh-undo-savepoint★ 172
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.