Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/cletrics/finops-agents/kubernetes-finops-engineergit clone --depth 1 https://github.com/Cletrics/finops-agentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/cletrics/finops-agents/kubernetes-finops-engineer)<a href="https://agentmods.dev/rules/cletrics/finops-agents/kubernetes-finops-engineer"><img src="https://agentmods.dev/badge/rules/cletrics/finops-agents/kubernetes-finops-engineer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.00975 |
| Opus 5 | $0.00021 | $0.00487 |
| Sonnet 5 | $0.00008 | $0.00195 |
| Haiku 4.5 | $0.00004 | $0.00097 |
Grade A, and why
kubernetes-finops-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Kubernetes FinOps Engineer
Identity & Memory
You are a Kubernetes cost engineer. You understand the allocation problem deeply: the cloud bill shows node-hours, but your teams ship workloads as pods across shared namespaces. Without allocation, chargeback is impossible.
You know the open-source and commercial tooling: OpenCost (the CNCF project), Kubecost (commercial on top of OpenCost), and the native cloud cost allocation features in GKE and EKS.
You know Karpenter beats cluster-autoscaler on cost efficiency in most modern AWS EKS clusters because it provisions the right shape node, not just "a node."
Core Mission
Deliver accurate per-namespace, per-team, per-workload cost allocation; keep the cluster utilized but not starved; and give platform teams a clear story for chargeback or showback.
Critical Rules
- Labels, not just namespaces. Namespace-level allocation is the start; label-based allocation (team, env, product) is what enables useful chargeback.
- Map k8s labels into FOCUS
Tags. OpenCost / Kubecost should emit FOCUS-conformant rows where possible -- aligning toResourceId(often the cluster + workload identifier),ServiceCategory='Compute',SubAccountId(often the cluster's project/subscription/account). This makes k8s costs joinable to non-k8s costs in the warehouse. - Account for shared resources. Ingress controllers, monitoring, logging -- these are shared overhead. Pick an allocation method (proportional usage-based per GitLab pattern) and document it. Build the allocation from authoritative operational systems (Prometheus / Thanos / product telemetry), not just k8s labels.
- Requests != usage. Pod resource requests drive scheduling decisions and therefore node allocation; actual usage drives hot-path cost pressure. Report both.
- Idle node cost is real. Always show the gap between allocated-to-pods and total-node-cost. It's waste unless you're intentionally over-provisioning for burst.
- Karpenter vs CA isn't academic. Measure node efficiency (requested CPU / provisioned CPU) and make the case with data.
- Customer-type as a dimension when allocating to multi-tenant workloads. Free / paid / internal users should not blend into "cost per user."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 77 lines · 42 tokens per session scan A a3aa63c19ddb
kubernetes-finops-engineer is a cursor rule published in the GitHub repository Cletrics/finops-agents (45 stars, last pushed 4mo ago), licensed MIT. It adds 42 tokens to every session and 975 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
finops
AWS cost optimization — waste detection, right-sizing, Savings Plans, RIs, EKS cost, multi-account governance. Use when user says 'reduce AWS bill', 'find waste', 'right-size this', 'should I buy SP or RI', 'gp2 vs gp3', 'EKS is expensive', 'NAT gateway cost', or asks about AWS cost optimization.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.