klustr CLAUDE.md

klustr CLAUDE.md is an instructions file for Claude Code from SametKUM/klustr. It costs 9,660 tokens per session, scanned C, a copy of klustr AGENTS.md, MIT.

Project instructions for Klustr, a desktop app for managing Kubernetes clusters, where Kubernetes is the system that runs containerised applications. They describe its Go backend, React interface, architecture and live data updates.

In plain words
What is it for?
Use them when modifying cluster management, logs, terminals, YAML editing, permissions, Helm, Argo CD or other Klustr features.
Why use it?
They give a coding agent the project context needed to make changes that fit Klustr's existing design and technology choices.

Instructions file for Claude Code

Written for Claude Code: the file is CLAUDE.md.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/sametkum/klustr/claude-md
Clone the repo
git clone --depth 1 https://github.com/SametKUM/klustr

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for klustr CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/sametkum/klustr/claude-md.svg)](https://agentmods.dev/instructions/sametkum/klustr/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/sametkum/klustr/claude-md"><img src="https://agentmods.dev/badge/instructions/sametkum/klustr/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 9,660 This file is loaded in full into every session.
When invoked 9,660 The same file — it is already loaded in full.
Security scan C 2 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.09660 $0.09660
Opus 5 $0.04830 $0.04830
Sonnet 5 $0.01932 $0.01932
Haiku 4.5 $0.00966 $0.00966

Measured 6d ago against content hash 4fe4d54aefe2, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade C, and why

klustr CLAUDE.md scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reaches for credential fileshighPrivilege escalation

SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.

Cross-platform Kubernetes desktop client. Multi-context cluster management with live resource updates, log streaming, exec, port-forwarding, full RBAC, **Custom Resource Definitions**, **Helm**, **Argo CD** and **Gateway

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

`--notes-file` is required — inline heredocs (`--notes "$(cat <<EOF…EOF)"`) silently break triple-backtick code fences inside the body. Keep the **Install** block at the bottom of the file verbatim (Homebrew + Manual `cu
Origin

This is a copy

100% identical to klustr AGENTS.md — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

CLAUDE.md · 483 lines

How it starts

The opening of the file, as written. The whole thing — 483 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Klustr

Cross-platform Kubernetes desktop client. Multi-context cluster management with live resource updates, log streaming, exec, port-forwarding, full RBAC, Custom Resource Definitions, Helm, Argo CD and Gateway API support. Nothing is installed in the cluster — Klustr is a pure client that drives the standard Kubernetes API using the user's ~/.kube/config.

Tech Stack

Layer Choice
Desktop framework Wails v2 (Go backend + native webview)
Backend Go 1.26 + client-go (typed + dynamic + discovery)
Custom resources client-go/dynamic + the apiextensions CRD list, watched live
Gateway API sigs.k8s.io/gateway-api typed informer factory (not the dynamic client)
Helm upstream helm.sh/helm/v3 library, no shelling out
Frontend React 19 + TypeScript + Vite
UI Tailwind CSS + shadcn/ui + lucide-react + sonner (toasts)
Real-time state Zustand
Mutations TanStack Query (mutations only — no query cache)
Tables TanStack Table
Terminal (logs + exec) xterm.js
Code editor (YAML) Monaco
Toolchain mise (pins Go, Node, Wails CLI versions)
Lint / format golangci-lint (Go) + ESLint (frontend)
Tests go test (backend) + Vitest + jsdom (frontend)
CI release builds GitHub Actions matrix on hosted runners (macOS arm64 + Linux amd64; Windows disabled until the v1 distribution path)
Release publishing softprops/action-gh-release (macOS .tar.gz + Linux .tar.gz + .deb assets today), Homebrew cask auto-bump for macOS + AUR klustr-bin auto-bump for Arch

Project Structure

klustr/
├── .mise.toml                    tool versions (Go, Node, Wails CLI)
├── .golangci.yml                 golangci-lint v2 config
├── wails.json                    Wails project config
├── main.go                       application entry point
├── internal/                     pure Go business logic (no Wails imports)
│   └── kube/
│       ├── config.go                kubeconfig parsing, context discovery + exec auth hints
│       ├── path.go                  GUI-launch PATH augmentation for exec credential helpers
│       ├── shellenv.go              GUI-launch login-shell env import (PATH + allowlist)
│       ├── creds_provider.go        CredentialProvider interface + status/mapping types
│       ├── creds_awsvault.go        aws-vault provider (detect / profiles / export capture)
│       ├── creds_store.go           context→profile mapping JSON under the user config dir
│       ├── creds.go                 credentialManager: single-flight capture, in-memory
│       │                            secrets, ahead-of-expiry refresh + client rebuild
│       ├── manager.go               ClientManager lifecycle (Clientset / Ping / Watch /
│       │                            StopWatch) + Logs / Exec / PortForward / CRD forwarders
│       │                            + watcher() helper
│       ├── manager_<group>.go       per-sidebar-group Wails-facing forwarders
│       │                            (workloads / networking / config / storage / cluster /
│       │                             autoscaling / admission / rbac / helm / gateway / pods)
│       ├── mutate.go                generic apply / delete / scale via dynamic client +
│       │                            kindToGVR map
│       ├── informers.go             contextWatcher lifecycle + start() bootstrap + the
│       │                            kindBindings routing table + ensureKind lazy per-kind
│       │                            start + shared helpers
│       │                            (sortByNamespaceName, formatLabelSelector, OwnerRef, …)
│       ├── informers_<group>.go     per-sidebar-group XxxInfo types and lister methods
│       ├── permissions.go           per-kind SelfSubjectAccessReview probing →
│       │                            cluster-wide / scoped / denied routing map
│       ├── details.go               shared types (ContainerSummary) + helpers
│       │                            (matchLabels, deploymentConditions, quantitiesToStrings,
│       │                             policyRules, rbacSubjects, …)
│       ├── details_<group>.go       per-sidebar-group XxxDetail structs and Get() builders
│       ├── crd.go                   apiextensions CRD discovery + per-CR dynamic informers
│       ├── helm.go                  helm v3 list / install / upgrade / rollback / uninstall +
│       │                            repo / chart search
│       ├── helm_cache.go            chart cache helpers for repo browsing
│       ├── argocd.go                Application list + Sync / Refresh through the K8s API
│       │                            (no argocd CLI, no argocd-server dependency)
│       ├── gateway.go               typed Gateway API informers + status / route helpers
│       ├── karpenter.go             Karpenter NodePool / NodeClaim views (CRD-gated)
│       ├── flux.go                  Flux Kustomization / source views (CRD-gated)
│       ├── istio.go                 Istio networking views (CRD-gated)
│       ├── certmanager.go           cert-manager Certificate / Issuer views (CRD-gated)
│       ├── keda.go                  KEDA ScaledObject-backed HPA trigger enrichment
│       ├── apiservice.go            aggregated APIService list + availability status
│       ├── rbac_review.go           Access Review (SelfSubjectAccessReview helpers)
│       ├── namespaces.go            Namespace lister/detail helpers
│       ├── mutate_csr.go            CertificateSigningRequest approve / deny
│       ├── terminal.go / sysshell.go  local system + node terminal sessions
│       ├── *_devices.go             DRA: DeviceClass / ResourceClaim(Template) / ResourceSlice
│       │                            (details_/informers_/manager_devices.go)
│       ├── transform.go             informer-store managedFields/noise trim (perf)
│       ├── pprof.go / timing.go     opt-in profiling + timing instrumentation (perf)
│       ├── doc.go                   package overview (the internal/kube ↔ app split)
│       ├── rollout.go               Deployment / StatefulSet / DaemonSet rollout history
│       │                            and one-click revert (kubectl rollout undo path)
│       ├── install.go               one-click metrics-server install / uninstall from
│       │                            upstream components.yaml
│       ├── events.go                core/v1 Events list filtered by involvedObject
│       ├── metrics.go               metrics.k8s.io pod CPU/memory usage (polled, not watched)
│       ├── overview.go              cluster-wide CPU / memory / pod aggregation
│       ├── logs.go                  streaming log sessions
│       ├── exec.go                  SPDY exec sessions
│       ├── streamcoalesce.go        byte-stream batching for exec / terminal output
│       │                            before it crosses the Wails bridge (perf)
│       ├── debug.go                 ephemeral debug container (`kubectl debug`)
│       │                            injected into a shell-less pod, then exec'd
│       ├── nodeshell.go             root node shell via a temporary privileged
│       │                            nsenter pod, attached through exec.go
│       ├── nodeops.go               node cordon/uncordon + PDB-aware drain
│       │                            (eviction API, streamed progress)
│       └── portforward.go           port-forward registry & lifecycle
├── app/                          Wails binding adapter (thin layer over ClientManager)
├── frontend/
│   ├── eslint.config.js          ESLint flat config
│   ├── vitest.config.ts          Vitest setup (jsdom environment)
│   ├── scripts/generate-api.mjs  generates the typed Wails API facade
│   └── src/
│       ├── App.tsx               layout shell, sidebar (RESOURCE_GROUPS) + MainView dispatch
│       ├── features/             one folder per resource kind + _shared/ helpers
│       │   ├── _shared/            ResourceDetailPanel, ResourceTable, StatusBar,
│       │   │                       CommandPalette, RowActionDialogs, themes, resourceGroups
│       │   ├── contexts/           ContextSwitcher, ConnectionsScreen, ContextTagPicker,
│       │   │                       NamespaceSelector, ConnectionStatus
│       │   ├── pods/, deployments/, services/, …  one folder per built-in kind
│       │   ├── crds/, helm/, argocd/, gateways/, httproutes/, grpcroutes/, …
│       │   ├── overview/           cluster + workloads overview cards
│       │   └── portforward/        header indicator + dialog
│       ├── components/           shadcn/ui primitives
│       ├── store/                Zustand stores
│       │   ├── resources.ts        live caches keyed by (context, kind, namespace, name)
│       │   ├── metrics.ts          metrics-server data + availability flag
│       │   ├── portForwards.ts     active port-forwards list
│       │   ├── crds.ts             discovered CRDs per context (by api group)
│       │   ├── credentials.ts      credential-helper providers + per-context statuses
│       │   │                       (fed by creds:update; mappings persist backend-side)
│       │   ├── helm.ts             helm release index per (context, namespace, name)
│       │   ├── namespaceFavorites.ts  per-context starred namespaces
│       │   ├── access.ts           RBAC Access Review (SelfSubjectAccessReview) results
│       │   ├── terminals.ts        active system / node terminal sessions
│       │   ├── tablePrefs.ts       per-kind column order / size / visibility (persisted)
│       │   ├── ui.ts               Zustand store + useActiveContexts / useIsAggregated selectors
│       │   ├── ui.types.ts         pure type declarations (ResourceView, ResourceKind, …)
│       │   └── ui.persistence.ts   localStorage read*/persist* helpers + applyThemeClasses
│       ├── lib/wails/            auto-generated Go bindings — DO NOT EDIT
│       ├── lib/api.generated.ts  generated model aliases + identity binding facade — DO NOT EDIT
│       ├── lib/api.ts            custom normalization layered over the generated facade
│       └── lib/events.ts         onKubeChange / onPFUpdate / onCredsUpdate Wails event
│                                 subscriptions
├── build/                        Wails build artifacts (icons, Info.plist) +
│                                 linux/ (nfpm.yaml + klustr.desktop for the .deb) +
│                                 aur/PKGBUILD.tmpl (rendered each release by CI)
├── docs/
│   ├── hero.mp4 / hero.gif         README hero — MP4 embedded inline via
│   │                               github.com/user-attachments/assets URL
│   │                               (only domain that github's README HTML
│   │                               sanitizer allows in <video src>)
│   ├── hero-poster.png             video poster + source-of-truth backup
│   ├── guide/                      task-focused user guides (getting-started,
│   │                               multi-context, credential-helpers, overview,
│   │                               workloads-and-debugging, terminal, helm,
│   │                               gitops, gateway-api, integrations,
│   │                               custom-resources) indexed by README.md
│   ├── perf-testing.md             performance testing protocol (microbenchmarks
│   │                               + benchstat + on-cluster profiling)
│   └── screenshots/                numbered themed pack `01-*.png` …
│                                   `16-*.png` for README grid + press / blog
├── hack/                         user's local fixtures (NEVER commit anything under hack/)
└── .github/
    ├── actions/linux-build-deps/  composite action: GTK + WebKit headers
    └── workflows/                 ci.yml (also `workflow_call`, so release.yml
                                   gates on it) + release.yml (builds macOS +
                                   Linux, drafts the release) +
                                   publish-packages.yml (on release published →
                                   Homebrew + AUR bumps) + codeql.yml +
                                   site.yml + pages.yml

Read the full file on GitHub · 483 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 483 lines · 9,660 tokens per session scan C 4fe4d54aefe2

Subscribe to this mod's changes

klustr CLAUDE.md is an instructions file published in the GitHub repository SametKUM/klustr (127 stars, last pushed 2d ago), licensed MIT. It adds 9,660 tokens to every session, about $0.0483 per session on Opus 5. A static security scan graded it C with 2 findings (reaches for credential files, makes network calls). It is 100% identical to klustr AGENTS.md, differing in 0 lines, and is treated as a copy.