Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/openshift/cluster-kube-apiserver-operator/agents-mdgit clone --depth 1 https://github.com/openshift/cluster-kube-apiserver-operatorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/openshift/cluster-kube-apiserver-operator/agents-md)<a href="https://agentmods.dev/instructions/openshift/cluster-kube-apiserver-operator/agents-md"><img src="https://agentmods.dev/badge/instructions/openshift/cluster-kube-apiserver-operator/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01284 | $0.01284 |
| Opus 5 | $0.00642 | $0.00642 |
| Sonnet 5 | $0.00257 | $0.00257 |
| Haiku 4.5 | $0.00128 | $0.00128 |
Grade A, and why
cluster-kube-apiserver-operator AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cluster Kube API Server Operator
A static pod operator that manages the lifecycle of kube-apiserver on OpenShift control plane nodes. Built on the library-go static pod operator framework, it observes cluster configuration, rotates certificates, manages encryption at rest, and reconciles the target kube-apiserver config into static pod manifests. Installed by the Cluster Version Operator (CVO).
See ARCHITECTURE.md for the full design and data flow.
Build and Test
make build # Build all binaries (operator + OTE test runner)
make test # Unit tests (./pkg/... ./cmd/...)
make verify # Formatting, vetting, golang version checks
make test-e2e # E2E operator tests (3h timeout, serial)
make test-e2e-encryption-aescbc # Encryption tests with aescbc provider (4h)
make test-e2e-encryption-kms # KMS encryption tests (4h)
make update-bindata-v4.1.0 # Copy apirequestcounts CRD from vendor/
make verify-bindata-v4.1.0 # Verify apirequestcounts CRD is in sync
Go version: see go.mod.
Project Structure
| Directory | Purpose |
|---|---|
cmd/cluster-kube-apiserver-operator/ |
Operator binary entry point (operator, render, installer, pruner, startup-monitor, cert controllers, and more) |
cmd/cluster-kube-apiserver-operator-tests-ext/ |
OpenShift Tests Extension (OTE) test runner entry point |
pkg/operator/starter.go |
Operator initialization — creates clients, informers, and starts all controllers |
pkg/operator/targetconfigcontroller/ |
Renders observed config + defaults into kube-apiserver ConfigMaps/Secrets |
pkg/operator/configobservation/ |
Configuration observers — each observer watches a cluster state to infer the operand config |
pkg/operator/certrotationcontroller/ |
Certificate rotation for serving, LB, aggregator, kubelet, etc. certs |
pkg/operator/resourcesynccontroller/ |
Syncs ConfigMaps/Secrets between namespaces |
pkg/operator/operatorclient/ |
Namespace constants and operator client interfaces |
pkg/cmd/render/ |
Bootstrap manifest renderer for cluster installation |
pkg/recovery/ |
Disaster recovery API server pod generation |
bindata/ |
Embedded assets: default config, static pod template, alerts, RBAC, bootstrap manifests |
manifests/ |
CVO deployment manifests (namespace, deployment, RBAC, ServiceMonitors) |
test/e2e*/ |
E2E test suites (operator, encryption, encryption-rotation, encryption-perf, KMS, SNO) |
test/library/ |
Shared test utilities |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 71 lines · 1,284 tokens per session scan A c5f50f23c39f
cluster-kube-apiserver-operator AGENTS.md is an instructions file published in the GitHub repository openshift/cluster-kube-apiserver-operator (83 stars, last pushed 3d ago), licensed Apache-2.0. It adds 1,284 tokens to every session, about $0.0064 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other instructions, from other repositories
dingtalk-workspace-cli AGENTS.md
AGENTS.md instructions for DingTalk-Real-AI/dingtalk-workspace-cli, covering repository agent guide, build and test, command framework declaration, flag / help / schema homology and agent schema contract.
azure-sdk-for-go go-code.instructions.md
Instructions for Azure/azure-sdk-for-go: All code should follow the guidelines from the Azure Go SDK Guidelines. This document is a summary of the most important guidelines to follow when contributing to the Azure Go SDK.
coral CLAUDE.md
Instructions for cdknorow/coral, covering claude.md - coral go, mission, testing, go unit tests and legacy parity tools (historical reference).
agentcat-go-sdk CLAUDE.md
Claude Code instructions for agentcathq/agentcat-go-sdk, covering claude.md, what this is, build & test commands, module layout and architecture.
oastools GEMINI.md
Instructions for erraggy/oastools, covering gemini.md, project overview, building and running, key commands and development conventions.
claw-code-go CLAUDE.md
Claude Code instructions for SocialGouv/claw-code-go, covering claw-code-go and downstream consumer: iterion.