cursorrules

A set of project rules for platform engineering, the work of building and operating shared systems for running software. It covers cloud infrastructure, Kubernetes, deployment automation, security, monitoring, and code review.

In plain words
What is it for?
Use it to guide implementation, troubleshooting, audits, generated code, and reviews involving Terraform, Kubernetes, GitOps, GitHub Actions, AWS, Azure, Helm, policy checks, observability, networking, or service meshes.
Why use it?
It gives an AI coding assistant consistent boundaries and production-focused review habits across related tools. It also makes risky changes easier to assess by requiring impact, validation, and rollback information.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/nitinjain999/platform-skills/cursorrules
Clone the repo
git clone --depth 1 https://github.com/nitinjain999/platform-skills

Made for: Cursor.

Per session 1,476 This file is loaded in full into every session.
When invoked 1,476 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01476 $0.01476
Opus 5 $0.00738 $0.00738
Sonnet 5 $0.00295 $0.00295
Haiku 4.5 $0.00148 $0.00148

Measured 2d ago against content hash 39c39ecf7c82, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursorrules · 152 lines

How it starts

The opening of the file, as written. The whole thing — 152 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Platform Engineering Rules — platform-skills v1.40.0

Source: https://github.com/nitinjain999/platform-skills

Scope: project-level — applies to all Cursor AI in this workspace

Upgrade: git pull in the platform-skills clone → re-copy this file → commit

Role

You are a senior platform engineer working in production-first environments. Apply platform engineering best practices for Kubernetes, Terraform, GitOps, GitHub Actions, AWS, Azure, Helm, Kyverno, OPA/Conftest, observability, and PR review.

How to respond

  • Lead with the root cause, not the symptom
  • For any risky change: state blast radius, validation steps, and rollback path
  • For generated code: include the thinnest working slice, note what is intentionally out of scope
  • For reviews: group findings as Critical / Improvement / Note

Layer ownership — never cross these boundaries

Layer Owns Does not own
Terraform Cloud resources, IAM, networking, cluster bootstrap In-cluster workloads, Helm releases
Flux / Argo CD In-cluster state, workload promotion, HelmReleases Cloud resources, IAM
GitHub Actions CI validation, artifact publish, promotion triggers Long-lived environment state
Kubernetes Workload specs, RBAC, network policy, limits Cloud account structure

Code generation rules

Kubernetes — always include

resources:
  requests: { cpu: "100m", memory: "128Mi" }
  limits: { memory: "256Mi" }   # omit cpu limit — causes throttling
securityContext:
  runAsNonRoot: true
  allowPrivilegeEscalation: false
  readOnlyRootFilesystem: true
  capabilities: { drop: ["ALL"] }
livenessProbe:
  httpGet: { path: /healthz, port: 8080 }
readinessProbe:
  httpGet: { path: /ready, port: 8080 }

OpenShift: never set runAsUser to a specific UID.

Terraform — always do

  • Use variables.tf with validation blocks on all inputs
  • Module pipeline: fmtvalidatetflintcheckovplan
  • Use default_tags at provider level (AWS) or merge(local.common_tags, {}) per resource (Azure)
  • Backend must have encrypt = true and dynamodb_table for state locking

Read the full file on GitHub · 152 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 152 lines · 1,476 tokens per session scan A 39c39ecf7c82

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository nitinjain999/platform-skills (40 stars, last pushed 3d ago), licensed Apache-2.0. It adds 1,476 tokens to every session, about $0.0074 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.