Kelos Skill
Use this skill when you need to author, debug, or operate Kelos resources
(Task, Workspace, AgentConfig, TaskSpawner) on a Kubernetes cluster.
Installing Kelos
Install the controller and CRDs into a Kubernetes cluster:
kelos install
Uninstall:
kelos uninstall
Initialize a local config file at ~/.kelos/config.yaml:
kelos init
Core Resources
Kelos defines four custom resources:
| Resource |
Purpose |
| Task |
A single agent run — prompt, credentials, optional workspace and config |
| Workspace |
A git repository to clone for the agent |
| AgentConfig |
Reusable instructions, skills, agents, MCP servers |
| TaskSpawner |
Automatically creates Tasks from GitHub issues, Jira tickets, or cron |
Task
A Task runs an AI agent with a prompt. Key fields:
spec.type (required): claude-code, codex, gemini, opencode, or cursor
spec.prompt (required): The task prompt
spec.credentials (required): type (api-key or oauth) and secretRef.name
spec.workspaceRef.name: Reference to a Workspace
spec.agentConfigRef.name: Reference to an AgentConfig
spec.branch: Git branch mutex — only one Task with the same branch runs at a time
spec.dependsOn: Task names that must succeed first
spec.ttlSecondsAfterFinished: Auto-delete after completion (seconds)
spec.model: Model override
spec.podOverrides: Resource limits, timeout, env vars, node selector
Task status phases: Pending -> Running -> Succeeded or Failed.
Tasks with unmet dependencies enter Waiting.
Workspace
A Workspace defines a git repository for the agent:
spec.repo (required): Git URL (HTTPS, git://, or SSH)
spec.ref: Branch, tag, or commit to checkout
spec.secretRef.name: Secret with GITHUB_TOKEN (PAT) or GitHub App credentials (appID, installationID, privateKey)
spec.remotes: Additional git remotes (name must not be origin)
spec.files: Files to inject into the repo before the agent starts (e.g., CLAUDE.md, skills)
AgentConfig
An AgentConfig injects reusable instructions and tools into Tasks:
spec.agentsMD: Instructions written to the agent's config (e.g., ~/.claude/CLAUDE.md). Additive — does not overwrite repo files
spec.plugins: Plugin bundles with skills and sub-agents
plugins[].name: Plugin name (directory namespace)
plugins[].skills[].name / .content: Skill definitions (become SKILL.md)
plugins[].agents[].name / .content: Agent definitions (become <name>.md)
spec.skills: skills.sh ecosystem packages
skills[].source: Package in owner/repo format
skills[].skill: Optional specific skill name
spec.mcpServers: MCP server configurations
- Supports
stdio, http, and sse transport types
- Use
headersFrom / envFrom with a secretRef for sensitive values
TaskSpawner
A TaskSpawner auto-creates Tasks from external sources:
spec.when.githubIssues: Discover from GitHub issues (labels, state, assignee, author, commentPolicy, priority labels)
spec.when.githubPullRequests: Discover from GitHub PRs (labels, state, reviewState, author, draft, commentPolicy, priority labels)
spec.when.cron: Trigger on a cron schedule
spec.when.jira: Discover from Jira (project, JQL filter, secret with JIRA_TOKEN)
spec.when.githubIssues.commentPolicy / spec.when.githubPullRequests.commentPolicy: Comment-based workflow control with authorization
triggerComment: Command that must appear for the item to be included (e.g., "/kelos pick-up")
excludeComments: Commands that exclude items; when combined with triggerComment, the most recent authorized command wins
allowedUsers: Restrict comment control to specific GitHub usernames
allowedTeams: Restrict to GitHub teams in org/team-slug format
minimumPermission: Require at least this repo permission (read, triage, write, maintain, admin)
spec.taskTemplate: Template for spawned Tasks (same fields as Task spec)
promptTemplate and branch support Go text/template variables: {{.ID}}, {{.Number}}, {{.Title}}, {{.Body}}, {{.URL}}, {{.Labels}}, {{.Comments}}, {{.Kind}}, {{.Time}}, {{.Schedule}}
spec.pollInterval: Polling frequency (default 5m)
spec.maxConcurrency: Limit concurrent running Tasks
spec.maxTotalTasks: Lifetime task creation limit
spec.suspend: Pause/resume without deleting
CLI Quick Reference
Running Tasks
# Simple task
kelos run -p "Fix the login bug" --type claude-code
# With workspace and agent config
kelos run -p "Add tests" --workspace my-ws --agent-config my-ac
# With model override and branch
kelos run -p "Refactor auth" --model opus --branch feature/auth
# Watch task progress
kelos run -p "Fix bug" -w
Creating Resources
# Create a workspace
kelos create workspace my-ws \
--repo https://github.com/org/repo.git \
--ref main \
--secret github-token
# Create an agent config with inline skill
kelos create agentconfig my-ac \
--skill review="Review the PR for correctness and security" \
--agents-md @instructions.md
# Create an agent config with skills.sh package
kelos create agentconfig my-ac \
--skills-sh anthropics/skills:skill-creator
# Create an agent config with MCP server
kelos create agentconfig my-ac \
--mcp github='{"type":"http","url":"https://api.githubcopilot.com/mcp/"}'
# Dry-run to preview YAML
kelos create agentconfig my-ac --skill review=@review.md --dry-run
Managing Resources
# List resources
kelos get tasks
kelos get taskspawners
kelos get workspaces
# View details
kelos get task my-task -d
kelos get task my-task -o yaml
# Stream logs
kelos logs my-task -f
# Suspend / resume a spawner
kelos suspend taskspawner my-spawner
kelos resume taskspawner my-spawner
# Delete
kelos delete task my-task
Configuration
Config file at ~/.kelos/config.yaml:
oauthToken: <token> # or apiKey: <key>
model: claude-sonnet-4-5-20250929
namespace: default
workspace:
repo: https://github.com/org/repo.git
ref: main
token: <github-token>
CLI flags always override config file values.
Dependency Chains
Tasks can depend on other Tasks using dependsOn. Dependent tasks access
upstream results via Go template syntax in the prompt:
dependsOn: [scaffold]
prompt: |
Code is on branch {{index .Deps "scaffold" "Results" "branch"}}.
PR: {{index .Deps "scaffold" "Results" "pr"}}
Available result keys: branch, commit, base-branch, pr, input-tokens, output-tokens, cost-usd.
Troubleshooting
Task stuck in Pending
- Check if the credentials secret exists:
kubectl get secret <name>
- Check controller logs:
kubectl logs deployment/kelos-controller-manager -n kelos-system
Task stuck in Waiting
- Check if a dependency in
dependsOn has not yet succeeded
- Check if another Task holds the branch lock (same
spec.branch)
Task fails immediately
- Verify agent credentials are valid
- Check the workspace repository is accessible
- Review pod logs:
kelos logs <task-name> or kubectl logs -l job-name=<job-name>
TaskSpawner not creating Tasks
- Check spawner status:
kubectl get taskspawner <name> -o yaml
- Verify the Workspace exists:
kubectl get workspace
- Check if
maxConcurrency is reached (active tasks at limit)
- Check if
maxTotalTasks limit is reached
- Check if
suspend: true is set
AgentConfig not taking effect
- Verify the Task references it:
spec.agentConfigRef.name must match
- Check plugin structure: skills become
<plugin>/skills/<skill>/SKILL.md
- For skills.sh: ensure the package source is valid
owner/repo format
Agent cannot push or create PRs
- Ensure the workspace secret has a valid
GITHUB_TOKEN
- Verify the token has
repo (and workflow if needed) permissions
- For GitHub Apps, check that
appID, installationID, and privateKey are correct
Supported Agent Types
| Type |
CLI |
Credential Env Var |
claude-code |
claude |
ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN |
codex |
codex |
CODEX_API_KEY or CODEX_AUTH_JSON |
gemini |
gemini |
GEMINI_API_KEY |
opencode |
opencode |
OPENCODE_API_KEY |
cursor |
agent (Cursor) |
CURSOR_API_KEY |
References
See the references/ directory next to this file for complete YAML examples:
task.yaml — Task patterns
workspace.yaml — Workspace patterns
agentconfig.yaml — AgentConfig patterns
taskspawner.yaml — TaskSpawner patterns
1---2name: kelos3description: Author, debug, and operate Kelos resources (Task, Workspace, AgentConfig, TaskSpawner) on Kubernetes. Use when working with Kelos CRDs or the kelos CLI.4---5
6# Kelos Skill
7
8Use this skill when you need to author, debug, or operate Kelos resources
9(Task, Workspace, AgentConfig, TaskSpawner) on a Kubernetes cluster.
10
11## Installing Kelos
12
13Install the controller and CRDs into a Kubernetes cluster:
14
15```bash
16kelos install
17```
18
19Uninstall:
20
21```bash
22kelos uninstall
23```
24
25Initialize a local config file at `~/.kelos/config.yaml`:
26
27```bash
28kelos init
29```
30
31## Core Resources
32
33Kelos defines four custom resources:
34
35| Resource | Purpose |
36|----------|---------|
37| **Task** | A single agent run — prompt, credentials, optional workspace and config |
38| **Workspace** | A git repository to clone for the agent |
39| **AgentConfig** | Reusable instructions, skills, agents, MCP servers |
40| **TaskSpawner** | Automatically creates Tasks from GitHub issues, Jira tickets, or cron |
41
42### Task
43
44A Task runs an AI agent with a prompt. Key fields:
45
46- `spec.type` (required): `claude-code`, `codex`, `gemini`, `opencode`, or `cursor`
47- `spec.prompt` (required): The task prompt
48- `spec.credentials` (required): `type` (`api-key` or `oauth`) and `secretRef.name`
49- `spec.workspaceRef.name`: Reference to a Workspace
50- `spec.agentConfigRef.name`: Reference to an AgentConfig
51- `spec.branch`: Git branch mutex — only one Task with the same branch runs at a time
52- `spec.dependsOn`: Task names that must succeed first
53- `spec.ttlSecondsAfterFinished`: Auto-delete after completion (seconds)
54- `spec.model`: Model override
55- `spec.podOverrides`: Resource limits, timeout, env vars, node selector
56
57Task status phases: `Pending` -> `Running` -> `Succeeded` or `Failed`.
58Tasks with unmet dependencies enter `Waiting`.
59
60### Workspace
61
62A Workspace defines a git repository for the agent:
63
64- `spec.repo` (required): Git URL (HTTPS, git://, or SSH)
65- `spec.ref`: Branch, tag, or commit to checkout
66- `spec.secretRef.name`: Secret with `GITHUB_TOKEN` (PAT) or GitHub App credentials (`appID`, `installationID`, `privateKey`)
67- `spec.remotes`: Additional git remotes (name must not be `origin`)
68- `spec.files`: Files to inject into the repo before the agent starts (e.g., `CLAUDE.md`, skills)
69
70### AgentConfig
71
72An AgentConfig injects reusable instructions and tools into Tasks:
73
74- `spec.agentsMD`: Instructions written to the agent's config (e.g., `~/.claude/CLAUDE.md`). Additive — does not overwrite repo files
75- `spec.plugins`: Plugin bundles with skills and sub-agents
76 - `plugins[].name`: Plugin name (directory namespace)
77 - `plugins[].skills[].name` / `.content`: Skill definitions (become `SKILL.md`)
78 - `plugins[].agents[].name` / `.content`: Agent definitions (become `<name>.md`)
79- `spec.skills`: skills.sh ecosystem packages
80 - `skills[].source`: Package in `owner/repo` format
81 - `skills[].skill`: Optional specific skill name
82- `spec.mcpServers`: MCP server configurations
83 - Supports `stdio`, `http`, and `sse` transport types
84 - Use `headersFrom` / `envFrom` with a `secretRef` for sensitive values
85
86### TaskSpawner
87
88A TaskSpawner auto-creates Tasks from external sources:
89
90- `spec.when.githubIssues`: Discover from GitHub issues (labels, state, assignee, author, commentPolicy, priority labels)
91- `spec.when.githubPullRequests`: Discover from GitHub PRs (labels, state, reviewState, author, draft, commentPolicy, priority labels)
92- `spec.when.cron`: Trigger on a cron schedule
93- `spec.when.jira`: Discover from Jira (project, JQL filter, secret with `JIRA_TOKEN`)
94- `spec.when.githubIssues.commentPolicy` / `spec.when.githubPullRequests.commentPolicy`: Comment-based workflow control with authorization
95 - `triggerComment`: Command that must appear for the item to be included (e.g., "/kelos pick-up")
96 - `excludeComments`: Commands that exclude items; when combined with triggerComment, the most recent authorized command wins
97 - `allowedUsers`: Restrict comment control to specific GitHub usernames
98 - `allowedTeams`: Restrict to GitHub teams in `org/team-slug` format
99 - `minimumPermission`: Require at least this repo permission (`read`, `triage`, `write`, `maintain`, `admin`)
100- `spec.taskTemplate`: Template for spawned Tasks (same fields as Task spec)
101 - `promptTemplate` and `branch` support Go `text/template` variables: `{{.ID}}`, `{{.Number}}`, `{{.Title}}`, `{{.Body}}`, `{{.URL}}`, `{{.Labels}}`, `{{.Comments}}`, `{{.Kind}}`, `{{.Time}}`, `{{.Schedule}}`
102- `spec.pollInterval`: Polling frequency (default `5m`)
103- `spec.maxConcurrency`: Limit concurrent running Tasks
104- `spec.maxTotalTasks`: Lifetime task creation limit
105- `spec.suspend`: Pause/resume without deleting
106
107## CLI Quick Reference
108
109### Running Tasks
110
111```bash
112# Simple task
113kelos run -p "Fix the login bug" --type claude-code
114
115# With workspace and agent config
116kelos run -p "Add tests" --workspace my-ws --agent-config my-ac
117
118# With model override and branch
119kelos run -p "Refactor auth" --model opus --branch feature/auth
120
121# Watch task progress
122kelos run -p "Fix bug" -w
123```
124
125### Creating Resources
126
127```bash
128# Create a workspace
129kelos create workspace my-ws \
130 --repo https://github.com/org/repo.git \
131 --ref main \
132 --secret github-token
133
134# Create an agent config with inline skill
135kelos create agentconfig my-ac \
136 --skill review="Review the PR for correctness and security" \
137 --agents-md @instructions.md
138
139# Create an agent config with skills.sh package
140kelos create agentconfig my-ac \
141 --skills-sh anthropics/skills:skill-creator
142
143# Create an agent config with MCP server
144kelos create agentconfig my-ac \
145 --mcp github='{"type":"http","url":"https://api.githubcopilot.com/mcp/"}'
146
147# Dry-run to preview YAML
148kelos create agentconfig my-ac --skill review=@review.md --dry-run
149```
150
151### Managing Resources
152
153```bash
154# List resources
155kelos get tasks
156kelos get taskspawners
157kelos get workspaces
158
159# View details
160kelos get task my-task -d
161kelos get task my-task -o yaml
162
163# Stream logs
164kelos logs my-task -f
165
166# Suspend / resume a spawner
167kelos suspend taskspawner my-spawner
168kelos resume taskspawner my-spawner
169
170# Delete
171kelos delete task my-task
172```
173
174### Configuration
175
176Config file at `~/.kelos/config.yaml`:
177
178```yaml
179oauthToken: <token> # or apiKey: <key>
180model: claude-sonnet-4-5-20250929
181namespace: default
182workspace:
183 repo: https://github.com/org/repo.git
184 ref: main
185 token: <github-token>
186```
187
188CLI flags always override config file values.
189
190## Dependency Chains
191
192Tasks can depend on other Tasks using `dependsOn`. Dependent tasks access
193upstream results via Go template syntax in the prompt:
194
195```yaml
196dependsOn: [scaffold]
197prompt: |
198 Code is on branch {{index .Deps "scaffold" "Results" "branch"}}.
199 PR: {{index .Deps "scaffold" "Results" "pr"}}
200```
201
202Available result keys: `branch`, `commit`, `base-branch`, `pr`, `input-tokens`, `output-tokens`, `cost-usd`.
203
204## Troubleshooting
205
206### Task stuck in Pending
207- Check if the credentials secret exists: `kubectl get secret <name>`
208- Check controller logs: `kubectl logs deployment/kelos-controller-manager -n kelos-system`
209
210### Task stuck in Waiting
211- Check if a dependency in `dependsOn` has not yet succeeded
212- Check if another Task holds the branch lock (same `spec.branch`)
213
214### Task fails immediately
215- Verify agent credentials are valid
216- Check the workspace repository is accessible
217- Review pod logs: `kelos logs <task-name>` or `kubectl logs -l job-name=<job-name>`
218
219### TaskSpawner not creating Tasks
220- Check spawner status: `kubectl get taskspawner <name> -o yaml`
221- Verify the Workspace exists: `kubectl get workspace`
222- Check if `maxConcurrency` is reached (active tasks at limit)
223- Check if `maxTotalTasks` limit is reached
224- Check if `suspend: true` is set
225
226### AgentConfig not taking effect
227- Verify the Task references it: `spec.agentConfigRef.name` must match
228- Check plugin structure: skills become `<plugin>/skills/<skill>/SKILL.md`
229- For skills.sh: ensure the package source is valid `owner/repo` format
230
231### Agent cannot push or create PRs
232- Ensure the workspace secret has a valid `GITHUB_TOKEN`
233- Verify the token has `repo` (and `workflow` if needed) permissions
234- For GitHub Apps, check that `appID`, `installationID`, and `privateKey` are correct
235
236## Supported Agent Types
237
238| Type | CLI | Credential Env Var |
239|------|-----|--------------------|
240| `claude-code` | `claude` | `ANTHROPIC_API_KEY` or `CLAUDE_CODE_OAUTH_TOKEN` |
241| `codex` | `codex` | `CODEX_API_KEY` or `CODEX_AUTH_JSON` |
242| `gemini` | `gemini` | `GEMINI_API_KEY` |
243| `opencode` | `opencode` | `OPENCODE_API_KEY` |
244| `cursor` | `agent` (Cursor) | `CURSOR_API_KEY` |
245
246## References
247
248See the `references/` directory next to this file for complete YAML examples:
249
250- `task.yaml` — Task patterns
251- `workspace.yaml` — Workspace patterns
252- `agentconfig.yaml` — AgentConfig patterns
253- `taskspawner.yaml` — TaskSpawner patterns