julianobarbosa/claude-code-skills

managing-infra

Infrastructure patterns for Kubernetes, Terraform, Helm, Kustomize, and GitHub Actions. Use when making K8s architectural decisions, choosing between Helm vs Kustomize, structuring Terraform modules, writing CI/CD workflows, or applying security best practices.

First seen Jan 24, 2026

Installation

$ npx skills add julianobarbosa/claude-code-skills --skill managing-infra

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from julianobarbosa/claude-code-skills · top by installs.

npx skills add julianobarbosa/claude-code-skills

Browse all from julianobarbosa/claude-code-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 10
License LICENSE
Default branch main
Open issues 1
Status Active

Skill metadata

Parsed from SKILL.md frontmatter.

Allowed toolsRead, Bash, Grep, Glob
Declared agents claude-code

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,129 B
  • docs SUMMARY.md 283 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 109 installs

SKILL.md

Infrastructure Patterns

When to Use What

Tool Use For
Raw K8s YAML Simple deployments, one-off resources
Kustomize Environment variations, overlays without templating
Helm Complex apps, third-party charts, heavy templating
Terraform Cloud resources, infrastructure lifecycle
GitHub Actions CI/CD, automated testing, releases
Makefile Build automation, self-documenting targets
Dockerfile Container builds, multi-stage, multi-arch

Quick Decisions

Kustomize when: Simple env differences, readable manifests, patching YAML Helm when: Complex templating, third-party charts, release management

K8s Security Defaults

Every workload: non-root user, read-only filesystem, no privilege escalation, dropped capabilities, network policies.

GitHub Actions Patterns

  • CI workflow: Lint, test, compile on PRs (run on both x86 + ARM)
  • Release workflow: Multi-arch Docker build on tags (native ARM runners)
  • Pin actions by SHA, least-privilege permissions

References

  • [KUBERNETES.md](KUBERNETES.md) - K8s resource patterns
  • [TERRAFORM.md](TERRAFORM.md) - Terraform module patterns
  • [GITHUB-ACTIONS.md](GITHUB-ACTIONS.md) - CI/CD workflow patterns
  • [MAKEFILE.md](MAKEFILE.md) - Build automation patterns
  • [DOCKERFILE.md](DOCKERFILE.md) - Container build patterns
  • [templates/](templates/) - Ready-to-use templates

Commands

kubectl apply -k ./              # Apply kustomize
helm upgrade --install NAME .    # Install/upgrade chart
terraform plan && terraform apply

Gotchas

  • Terraform state lock contention: default 10-min lock timeout; bumped timeout doesn't help if the lock holder hung — force-unlock only after confirming the process is dead.
  • Helm release name reuse on uninstalled-but-not-purged release fails install with "already exists" — use --no-hooks + explicit purge, or never reuse names.
  • Kustomize patches that match nothing silently produce empty diffs — verify with kustomize build after every patch addition.
  • Terraform for_each over a computed value forces apply-time count — can cause spurious re-creation of resources between plans.
  • helm upgrade --install on a changed values schema can silently drop fields that no longer match — diff the rendered output, not just the values file.
  • kubectl apply --server-side vs client-side conflicts when both have been used: client-side last-applied-config can shadow server-side managed fields without error.