kube-agents: Instructions file for Codex

AGENTS.md

kube-agents AGENTS.md is an instructions file for Codex, OpenCode from gke-labs/kube-agents. It costs 8,809 tokens per session, scanned A, original, Apache-2.0.

A set of repository instructions for kube-agents, a Kubernetes agent system for managing Google Kubernetes Engine environments.

In plain words
What is it for?
Use it when modifying agent configurations, understanding the chat, platform, and cluster profiles, locating tests, or integrating Kubernetes and GKE operations.
Why use it?
It explains the project layout and separates source agent blueprints from runtime profiles and review skills, which helps prevent changes in the wrong directory.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: reads .claude/ paths; mentions CLAUDE.md; mentions subagents.

This is gke-labs/kube-agents's own configuration. It tells Codex and OpenCode how to work on kube-agents itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything kube-agents configures →

Reuse

Borrowing it

Nothing to install: this file belongs to gke-labs/kube-agents. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/gke-labs/kube-agents/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/gke-labs/kube-agents

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for kube-agents AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/gke-labs/kube-agents/agents-md.svg)](https://agentmods.dev/instructions/gke-labs/kube-agents/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/gke-labs/kube-agents/agents-md"><img src="https://agentmods.dev/badge/instructions/gke-labs/kube-agents/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 8,809 This file is loaded in full into every session.
When invoked 8,809 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.08809 $0.08809
Opus 5 $0.04405 $0.04405
Sonnet 5 $0.01762 $0.01762
Haiku 4.5 $0.00881 $0.00881

Measured 2d ago against content hash 95f01e17403b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

kube-agents AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 495 lines

How it starts

The opening of the file, as written. The whole thing — 495 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md

Project Overview

This repository contains the Kubernetes Agentic Harness (kube-agents). It is a collection of agent configurations, personas, and skills designed to manage Kubernetes/GKE operations. It utilizes a Platform Agent to transition from reactive manual management to proactive, intent-driven operations.

Repository Layout

  • agents/: Source of truth for agent blueprints (personas and skills).
    • chat/: The Planning Agent front door — the default Hermes profile that receives chat ingress, plans the work, and delegates each piece to a specialist.
    • platform/: Configuration for the Platform Agent, scaffolded at pod startup into the platform profile.
    • cluster/: The Cluster Agent profile template (persona, scoped config, and runtime-debugging skills). The Platform Agent scaffolds this into per-cluster Hermes profiles at runtime; it is not deployed directly.
  • .agents/skills/: Repository-level skills, not shipped in the agent images — review skills (adversarial change review, security audits, docs-drift, skill quality) run against pull requests and clusters, with review-preflight running the pre-PR set of them in a context that did not write the change, plus the install-kube-agents/uninstall-kube-agents/upgrade-kube-agents lifecycle skills that drive the repository's installer scripts.
  • .agents/rules/: Repository-level rules an agent follows, one file per family and none shipped in the agent images — core_engineering.md for the code itself, github_actions.md for workflow authoring, pre_pr_review.md for the mechanics of the two pre-PR passes. This file states each rule and links there for the form it takes; the split keeps AGENTS.md inside the context budget scripts/check_context_budget.py enforces.
  • a2a/: Go module for the agent-to-agent bus — wire-protocol library and a2a topics CLI per docs/designs/spec-a2a-payloads.md, plus agent profiles. Nothing imports it yet.
  • charts/: Canonical Helm charts (kube-agents) for deploying the Kube-Agents operator and profiles.
  • terraform/: Companion reusable Terraform modules (gke-cluster, kube-agents-iam, chat-pubsub, github-minter, gke-backup-plan, drift-pubsub) for infrastructure provisioning, plus examples/full-install/, the single-apply composition that installs the Helm chart on top. drift-pubsub is not yet part of that composition.
  • deploy/: Deployment infrastructure code (Dockerfile, Kustomize bases, shared runtime assets).
  • docs/: Documentation.
    • site/: The published documentation site (Astro + Starlight) — the canonical home for user-facing docs.
    • architecture/: The end-state architecture specification (0109). Describes the target, not what ships today.
    • designs/: Per-feature design documents.
  • k8s-operator/: Go/Kubebuilder operator reconciling PlatformAgent Custom Resources.
  • scripts/: Repository tooling — installer/ (what the front doors share), dev/, release/.
  • examples/: Example integrations (LiteLLM provider configs, vLLM serving, inference replay).
  • bench/: Evaluation harness that runs kubernetes-sigs/devops-bench against the Platform Agent as a pip-installed library.
  • images.json: Inventory of every container image an install pulls, with its upstream reference and pin. Read by make mirror-images, the kustomize deploy targets, and the docs generator.
  • INSTALL.md: Installation guide.
  • README.md: Project overview.

Read the full file on GitHub · 495 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · +3 lines · +47 tokens per session 95f01e17403b
  2. 3d ago Changed · -5 lines · -123 tokens per session f06cacafb920
  3. 4d ago Changed · +12 lines · +308 tokens per session a6d85d7ed063
  4. 4d ago Changed · -1 lines · -103 tokens per session 63d612344478
  5. 8d ago First seen · 486 lines · 8,680 tokens per session scan A b4f1f672d4ac

Subscribe to this mod's changes

kube-agents AGENTS.md is an instructions file published in the GitHub repository gke-labs/kube-agents (53 stars, last pushed today), licensed Apache-2.0. It adds 8,809 tokens to every session, about $0.0440 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens