Borrowing it
Nothing to install: this file belongs to openshift/hypershift. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/openshift/hypershift/main/.claude/skills/konflux-build/SKILL.mdgit clone --depth 1 https://github.com/openshift/hypershiftWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/openshift/hypershift/konflux-build)<a href="https://agentmods.dev/skills/openshift/hypershift/konflux-build"><img src="https://agentmods.dev/badge/skills/openshift/hypershift/konflux-build.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.01745 |
| Opus 5 | $0.00012 | $0.00873 |
| Sonnet 5 | $0.00005 | $0.00349 |
| Haiku 4.5 | $0.00002 | $0.00175 |
Grade A, and why
konflux-build scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 155 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create a manual Konflux build from a PR
Given a PR and a component name, create a manual PipelineRun that produces a container image. By default the image expires after 30 days. Use --non-expiring to produce a permanent image.
Usage Examples
-
Build a specific component from a PR number (expires in 30 days):
/konflux-build 7813 hypershift-release-mce-26 -
Build from a PR URL (will prompt for component):
/konflux-build https://github.com/openshift/hypershift/pull/7813 -
Build a non-expiring image for a hotfix:
/konflux-build 7813 hypershift-operator --non-expiring -
Build using a specific pipeline template:
/konflux-build 7813 .tekton/hypershift-release-mce-26-push.yaml -
Build the main operator from a PR:
/konflux-build 7500 hypershift-operator
What This Command Does
- Verifies you are logged into the Konflux cluster (
stone-prd-rh01) - Resolves the PR to get its head commit SHA and base branch
- Finds the matching push pipeline template from
.tekton/on the base branch - Generates a manual PipelineRun YAML with template variables resolved
- Sets image expiry to 30 days (or removes it if
--non-expiringis specified) - Creates the PipelineRun and polls until completion
- Reports the final image reference with
@sha256:digest
Input
- PR: $ARGUMENTS (GitHub PR URL or number for openshift/hypershift)
- Component or pipeline file: either a component name (e.g.,
hypershift-operator) or a path to a specific pipeline template (e.g.,.tekton/hypershift-release-mce-26-push.yaml). If not specified, ask the user which component to build. - If
--non-expiringis present in the arguments, produce a permanent image; otherwise setimage-expires-after: 30d
Steps
0. Pre-check: verify OpenShift login
Before doing anything else, verify the user is logged in to the correct cluster and project:
- Run
oc whoami --show-serverand confirm it returnshttps://api.stone-prd-rh01.pg1f.p1.openshiftapps.com:6443. If not, stop and tell the user to log in:oc login https://api.stone-prd-rh01.pg1f.p1.openshiftapps.com:6443 - Run
oc project -qand confirm it returnscrt-redhat-acm-tenant. If not, switch to it:
If the switch fails, stop and tell the user they don't have access to the required namespace.oc project crt-redhat-acm-tenant
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 155 lines · 23 tokens per session scan A 1208bd99dd09
konflux-build is a skill published in the GitHub repository openshift/hypershift (540 stars, last pushed yesterday), licensed Apache-2.0. It adds 23 tokens to every session and 1,745 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
deployment-patterns
Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.
scanning-containers-with-trivy-in-cicd
This skill covers integrating Aqua Security's Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and…
performing-container-security-scanning-with-trivy
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
devops
DevOps - Docker, CI/CD, cloud infra, monitoring.
devops-automator
Expert DevOps engineer for CI/CD, IaC, Kubernetes, and deployment automation. Activate on: CI/CD, GitHub Actions, Terraform, Docker, Kubernetes, Helm, ArgoCD, GitOps, deployment pipeline, infrastructure as code, container orchestration. NOT for: application code (use language skills), database schema (use…
devops-infrastructure
Guides Docker, CI/CD pipelines, deployment strategies, infrastructure as code, and observability setup. Use when writing Dockerfiles, configuring GitHub Actions, planning deployments, setting up monitoring, or when asked about containers, pipelines, Terraform, or production infrastructure.