Introduction

The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In Kubernetes operations, kubectl is the standard tool, but its traditional output (such as tables) is not agent-friendly. dsh-kubectl solves this issue by encapsulating kubectl capabilities into the DSH plugin system, allowing agents to inspect clusters, query resources, read logs, and perform port forwarding in read-only or explicit confirmation mode.

Plugin Overview

dsh-kubectl is an independent community project (unofficial) maintained by WODE25500. It is built based on kubernetes/kubectl (Apache-2.0). The plugin mainly converts common kubectl operations into DSH-recognizable skills, outputs JSON structured data to improve parsing reliability, and adds an explicit confirmation mechanism for write operations.

Core Features

The plugin currently includes the following capabilities:

  • kubectl_get: Query resources and use -o json to obtain structured output.
  • kubectl_describe / kubectl_status: View resource details, version/context information.
  • kubectl_logs: Retrieve Pod logs, with support for parameters such as tail, previous, and container.
  • kubectl_exec: Execute a one-time command inside a container.
  • kubectl_apply / kubectl_delete: Deploy or delete resources.
  • kubectl_port_forward: Establish a port forwarding channel so that local environments can access services inside the cluster.

Installation and Configuration

Installation requires the DSH patch command:

pnpm dsh web --patch ./dsh-kubectl/cordis.patch.yml

After installation, you usually need to specify the kubectl path, context, and namespace in the DSH configuration. A configuration example is as follows:

- insert:
    - id: kubectl
      name: './src/index.js'
      config:
        kubectlPath: kubectl
        context: my-cluster
        namespace: default

Typical Usage

  • Query resources: Agents can directly call kubectl_get to retrieve resource lists.
  • Read logs: Use kubectl_logs to fetch the latest Pod logs or historical logs.
  • Port forwarding: After initiating kubectl_port_forward, cluster services can be accessed locally through the forwarded port.
  • Write operations: When executing kubectl_apply or kubectl_delete, the system requires user confirmation to avoid accidental operations.

Use Cases and Notes

  • Connection issues: If the current environment has no cluster connection, commands will return a connection-refused error (stderr is returned as-is).
  • Process management: kubectl_port_forward starts as a persistent process. The current version does not provide an automatic stop mechanism, so manual management is required.
  • Write operation red lines: All write operations (apply/delete) rely on explicit user confirmation, and SKILL.md contains clear operational red lines. Please read them carefully.
  • Permissions: The plugin runs with the permissions of the current DSH process. Before installation, check the source code and license.

dsh-kubectl provides agents with a structured and confirmable way to interact for Kubernetes operational tasks. More details and the source code are available at: GitHub