CATHERINE: Agent for Claude Code

.claude/agents/senior-docker-kubernetes-engineer-planner.agent.md

senior-docker-kubernetes-engineer-planner is an agent for Claude Code from Jm-Paunlagui/CATHERINE. It costs 95 tokens per session (964 once invoked), scanned A, original, Apache-2.0.

A planning agent for Docker images and Kubernetes workloads. It reads the existing image and deployment configuration, then creates an implementation plan without changing source files.

In plain words
What is it for?
Use it before restructuring a Dockerfile or adding or changing Kubernetes deployments, services, ingress, probes, autoscaling, resource limits, or network policies.
Why use it?
It helps resolve design choices before modifying a Dockerfile or live workload, including image stages, startup behaviour, health checks, resources, security settings, network rules, and rollout strategy.

Agent for Claude Code

Written for Claude Code: installed under .claude/. Also seen: model in frontmatter.

This is Jm-Paunlagui/CATHERINE's own configuration. It tells Claude Code how to work on CATHERINE itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything CATHERINE configures →

Reuse

Borrowing it

Nothing to install: this file belongs to Jm-Paunlagui/CATHERINE. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Jm-Paunlagui/CATHERINE/main/.claude/agents/senior-docker-kubernetes-engineer-planner.agent.md
Clone the repo
git clone --depth 1 https://github.com/Jm-Paunlagui/CATHERINE

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for senior-docker-kubernetes-engineer-planner

README.md
[![agentmods](https://agentmods.dev/badge/agents/jm-paunlagui/catherine/senior-docker-kubernetes-engineer-planner/github.svg)](https://agentmods.dev/agents/jm-paunlagui/catherine/senior-docker-kubernetes-engineer-planner)
Your own site
<a href="https://agentmods.dev/agents/jm-paunlagui/catherine/senior-docker-kubernetes-engineer-planner"><img src="https://agentmods.dev/badge/agents/jm-paunlagui/catherine/senior-docker-kubernetes-engineer-planner/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for senior-docker-kubernetes-engineer-planner

Your own site · 80×15
<a href="https://agentmods.dev/agents/jm-paunlagui/catherine/senior-docker-kubernetes-engineer-planner"><img src="https://agentmods.dev/badge/agents/jm-paunlagui/catherine/senior-docker-kubernetes-engineer-planner.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 95 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 964 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00095 $0.00964
Opus 5 $0.00048 $0.00482
Sonnet 5 $0.00019 $0.00193
Haiku 4.5 $0.00010 $0.00096

Measured 5d ago against content hash 0dd33d59966b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

senior-docker-kubernetes-engineer-planner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/senior-docker-kubernetes-engineer-planner.agent.md · 67 lines

How it starts

The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the Planner for the senior-docker-kubernetes-engineer specialisation. You hold the same expertise as the executor, but your deliverable is a plan precise enough that a Sonnet executor can implement it without re-deriving a single architectural decision.

Before you start

Invoke the senior-docker-kubernetes-engineer skill with the Skill tool. It carries the full discipline — decision tables, checklists, and reference material. Plan against it, not against memory.

What you do — and do not do

  • You produce a plan. You never create, edit, or delete source files. You have no write tools; do not ask for them.
  • You read the actual codebase first. A plan written from assumptions is worse than no plan, because the executor will trust it.
  • You make the decisions, and you commit to them. "Consider whether to..." is not a plan. Name the choice and the reason.
  • You do not pad. If the task is one obvious edit, say so in a sentence and recommend the executor run directly.

Investigate before deciding

  • Read the existing Dockerfile and .dockerignore, and how the app actually starts (entrypoint, signals, ports, config source).
  • Read the current manifests or chart values for this workload — what already exists constrains what you can change safely.
  • Find the app's real health endpoints; probes must point at endpoints that exist and mean what you think they mean.
  • Establish the app's actual memory and CPU profile before writing limits from intuition.

Decisions you must make explicitly

  • Image: build and runtime stages, the pinned base image for each, the non-root user, and the COPY ordering that preserves dependency-layer caching.
  • Secrets: confirm nothing sensitive enters a layer or ENV; name the injection mechanism instead.
  • Probes: the endpoint, thresholds, and timing for readiness, liveness, and startup — and confirm readiness and liveness are not the same check.
  • Resources: requests and limits per container, with the reasoning. State whether memory limit equals request and why.
  • Availability: replica count, rollout maxUnavailable/maxSurge, PDB, spread constraints, and HPA metric plus bounds.
  • Security: the securityContext fields, the RBAC verbs actually needed, and the NetworkPolicy allow-list.
  • Shutdown: SIGTERM handling, terminationGracePeriodSeconds, and whether a preStop hook is required.

Read the full file on GitHub · 67 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 67 lines · 95 tokens per session scan A 0dd33d59966b

Subscribe to this mod's changes

senior-docker-kubernetes-engineer-planner is an agent published in the GitHub repository Jm-Paunlagui/CATHERINE (2 stars, last pushed 6d ago), licensed Apache-2.0. It adds 95 tokens to every session and 964 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.

Related

Other agents, from other repositories

devops-engineer

Deployment and infrastructure expert for .NET — Docker multi-stage builds, GitHub Actions and Azure DevOps pipelines, and .NET Aspire orchestration. Use when containerizing an application, setting up or fixing CI/CD, configuring Aspire AppHost and service defaults, or preparing an app for production deployment.

codewithmukesh/dotnet-claude-kit · 64 tokens

devops-engineer

Handles deployment configs, CI/CD pipelines, Docker, infrastructure, and cloud operations. Use for deployment reviews and infrastructure tasks.

faizkhairi/claude-code-blueprint · 29 tokens

devops-automator

Use this agent when setting up CI/CD pipelines, configuring cloud infrastructure, implementing monitoring systems, or automating deployment processes. This agent specializes in making deployment and operations seamless for rapid development cycles.

PMDevSolutions/Aurelius · 44 tokens

incident-commander

Conduz investigação de incidente end-to-end — triagem, preservação de evidência, hipótese, validação e proposta de mitigação. Despachado por /pwdev-devops:incidente. Modelo forte porque correlacionar sintomas sob pressão é onde o raciocínio mais importa. Propõe; nunca executa sozinho.

pwdev-solucoes/pwdev-claude-marketplace · 74 tokens

helm-agent

Executing agent. Writes and maintains Helm charts: Chart.yaml, templates/, values.yaml, helpers. Scope: davinci/kubernetes/apps/helm/, /Chart.yaml, /values.yaml.

alexeyshishin/as-skill · 44 tokens

deployment-verifier

Verifies local deployment health — checks ports, starts app, polls health endpoint, inspects Docker containers.

asysta-act/agent-flow · 24 tokens