Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Use when working with KubeSphere DevOps extension, CI/CD pipelines, Jenkins integration, or pipeline troubleshooting
.claude/skills/kubesphere-kubesphere-devops-overview/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 74% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 129% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 94% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 91% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 200% | 0% |
KubeSphere DevOps provides CI/CD capabilities through Jenkins integration, supporting both graphical pipeline editing and Jenkinsfile-based pipelines. It enables automated builds, testing, and deployments across multi-cluster environments with ArgoCD integration for GitOps continuous deployment.
KubeSphere DevOps maps resources across three layers:
KubeSphere Kubernetes Jenkins
─────────────────────────────────────────────────────────────
Workspace Workspace CR (authorization)
└── DevOpsProject ├── DevOpsProject CR └── Folder
(Namespace) └── Namespace (with label)
└── Pipeline ├── Pipeline CR └── WorkflowJob
└── Run ├── PipelineRun CR └── Build #NKey Concept: A "DevOps Project" in KubeSphere is fundamentally a Kubernetes namespace with the devops.kubesphere.io/managed=true label. The DevOpsProject CR exists as a wrapper resource, but when querying for accessible DevOps projects, you interact with namespaces, not the DevOpsProject CRs directly.
For tenants: Use the /kapis/devops.kubesphere.io/v1alpha3/workspaces/{workspace}/namespaces endpoint to list accessible DevOps projects (returns namespace resources). The /apis/devops.kubesphere.io/v1alpha3/devopsprojects endpoint requires cluster-scoped permissions and returns 403 for tenants.
DevOps projects have two forms of names:
| Name Type | Example | Source | Usage | |-----------|---------|--------|-------| | Shortname | devopstest | .metadata.generateName in DevOpsProject CR | Display/user-friendly name | | Fullname | devopstestc2nj7 | .metadata.name in DevOpsProject CR and Namespace | Actual resource identifier |
Important:
devopstestc2nj7)devopstest, KubeSphere generates a unique fullname by appending random charactersDevOpsProjects belong to a Workspace via label:
yamlapiVersion: devops.kubesphere.io/v1alpha3 kind: DevOpsProject metadata: name: my-project labels: kubesphere.io/workspace: demo # Associates with Workspace 'demo'
To create and associate:
bash# 1. Create Workspace kubectl apply -f - <<EOF apiVersion: tenant.kubesphere.io/v1beta1 kind: Workspace metadata: name: demo EOF # 2. Create DevOpsProject with label kubectl apply -f - <<EOF apiVersion: devops.kubesphere.io/v1alpha3 kind: DevOpsProject metadata: name: my-project labels: kubesphere.io/workspace: demo EOF
┌──────────────────────────────────────────────────────────────┐
│ DevOps Project │
│ (Namespace with devops.kubesphere.io/managed=true label) │
└──────────────────────┬───────────────────────────────────────┘
│
┌──────────────┼──────────────┐
│ │ │
┌───────▼──────┐ ┌─────▼─────┐ ┌──────▼──────┐
│ Pipelines │ │Credentials│ │ Webhooks │
│ │ │ │ │ │
│ - Graphical │ │ - SSH │ │ - GitHub │
│ - Jenkinsfile│ │ - Basic │ │ - GitLab │
│ - Multi-branch│ │ - Token │ │ - Generic │
└──────────────┘ └───────────┘ └─────────────┘Minimal Installation (Default Config) - RECOMMENDED:
yamlapiVersion: kubesphere.io/v1alpha1 kind: InstallPlan metadata: name: devops namespace: kubesphere-system spec: extension: name: devops version: 1.2.4 enabled: true upgradeStrategy: Manual # Required for production # Note: spec.config is omitted to use extension default values
When to use minimal installation:
Custom Configuration (Only When Needed):
yamlapiVersion: kubesphere.io/v1alpha1 kind: InstallPlan metadata: name: devops namespace: kubesphere-system spec: extension: name: devops version: 1.2.4 enabled: true upgradeStrategy: Manual # Required for production # config: leave empty to use default values
Custom Configuration (Override Defaults):
yamlapiVersion: kubesphere.io/v1alpha1 kind: InstallPlan metadata: name: devops namespace: kubesphere-system spec: extension: name: devops version: 1.2.4 enabled: true upgradeStrategy: Manual # Required for production config: | # Overrides values from DevOps chart's values.yaml agent: jenkins: Master: NodeSelector: {} resources: requests: cpu: "500m" memory: "4Gi" limits: cpu: "2000m" memory: "8Gi" Agent: Image: "jenkins/inbound-agent" Tag: "3309.v27b_9314fd1a_4-1-jdk21" Privileged: false
Important:
upgradeStrategy: Manual for productionconfig is optional - omit or leave empty to use extension defaultsvalues.yaml settingsTo install DevOps agent on member clusters, add clusterScheduling:
yamlapiVersion: kubesphere.io/v1alpha1 kind: InstallPlan metadata: name: devops namespace: kubesphere-system spec: extension: name: devops version: 1.2.4 enabled: true upgradeStrategy: Manual config: | # Base config for all clusters agent: jenkins: Master: resources: requests: cpu: "500m" memory: "4Gi" clusterScheduling: placement: clusters: - host # Install on host cluster - member1 # Install on member1 - member2 # Install on member2 # Optional: per-cluster overrides overrides: member1: | agent: jenkins: Master: resources: limits: memory: "8Gi" # Larger master for member1 member2: | agent: jenkins: Agent: NodeSelector: zone: west
Key Points:
clusterScheduling.placement.clusters: List clusters where DevOps agent runsclusterScheduling.overrides: Cluster-specific config overridesclusterScheduling, DevOps only runs on the host clusterbashhelm upgrade --install devops kse-extensions/devops \ -n kubesphere-devops-system \ --create-namespace
Verify the DevOps installation:
bash# Check DevOps pods kubectl get pods -n kubesphere-devops-system # Check InstallPlan status kubectl get installplan devops -n kubesphere-system # For multi-cluster: check agent status on each cluster kubectl get installplan devops -n kubesphere-system -o jsonpath='{.status.clusterSchedulingStatuses}'
| Component | Purpose | Namespace | |-----------|---------|-----------| | devops-jenkins | Jenkins master | kubesphere-devops-system | | devops-apiserver | DevOps API service | kubesphere-devops-system | | devops-controller | Resource controllers | kubesphere-devops-system | | devops-argocd- | ArgoCD (GitOps) | argocd | | Jenkins Agent | Pipeline executors | Dynamic (per pipeline) | |-----------|---------|-----------| | devops-jenkins | Jenkins master | kubesphere-devops-system | | devops-apiserver | DevOps API service | kubesphere-devops-system | | devops-controller | Resource controllers | kubesphere-devops-system | | Jenkins Agent | Pipeline executors | Dynamic (per pipeline) |
KubeSphere DevOps integrates with Jenkins for CI/CD execution. The secret devops-jenkins contains the admin token for direct Jenkins access:
bash# Get Jenkins admin token TOKEN=$(kubectl -n kubesphere-devops-system get secret devops-jenkins -o jsonpath='{.data.jenkins-admin-token}' | base64 -d) # Access Jenkins API kubectl run curl-jenkins --rm -i --restart=Never --image=curlimages/curl \ -- "http://admin:${TOKEN}@devops-jenkins.kubesphere-devops-system:80/api/json"
Jenkins NodePort:
bashkubectl get svc devops-jenkins -n kubesphere-devops-system # Default: 30180
Access Jenkins Console:
http://<node-ip>:30180adminKubeSphere DevOps includes ArgoCD v2.11.7 for GitOps continuous deployment:
ArgoCD Components: | Component | Purpose | |-----------|---------| | application-controller | Manages Application state | | applicationset-controller | Manages ApplicationSet resources | | dex-server | SSO authentication | | notifications-controller | Event notifications | | repo-server | Repository operations | | argocd-server | API/UI server | | redis | Cache layer |
Access ArgoCD:
bash# Get ArgoCD server URL kubectl get svc devops-agent-argocd-server -n argocd # Get admin password kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath='{.data.password}' | base64 -d
Key Features:
| Resource | API Version | Purpose | |----------|-------------|---------| | Pipeline | devops.kubesphere.io/v1alpha3 | CI/CD pipeline definition | | DevOpsProject | devops.kubesphere.io/v1alpha3 | DevOps project (namespace wrapper) | | Credential | v1/Secret | Repository and deployment credentials |
bash# List DevOps projects kubectl get devopsprojects # List pipelines in a project kubectl get pipelines -n <devops-project-namespace> # Get pipeline runs kubectl get pipelineruns -n <devops-project-namespace> # Check Jenkins status kubectl -n kubesphere-devops-system get pods -l app=devops-jenkins # View Jenkins logs kubectl -n kubesphere-devops-system logs -l app=devops-jenkins # Get Jenkins admin password kubectl -n kubesphere-devops-system get secret devops-jenkins -o jsonpath='{.data.jenkins-admin-password}' | base64 -d
| Type | Description | Use Case | |------|-------------|----------| | Graphical | Visual pipeline editor | Simple pipelines, no code | | Jenkinsfile (SCM) | Pipeline defined in repository | Version-controlled pipelines | | Jenkinsfile (Inline) | Pipeline defined in KubeSphere | Quick testing | | Multi-branch | Auto-discovers branches | GitFlow, feature branches |
| Mistake | Fix | |---------|-----| | Pipeline fails with "No agent" | Check Jenkins agent configuration | | Cannot access Git repository | Verify credentials and webhook setup | | kubeconfig credentials fail | Use string type instead of kubeconfigContent (v1.2+) | | Jenkins out of memory | Increase Jenkins master resources | | Pipeline hangs | Check agent pod status and resource limits |
| DevOps | Jenkins | Notes | |--------|---------|-------| | v1.2.x | 2.504.1 LTS | kubernetes-cd plugin removed | | v1.1.x | 2.346.3 LTS | Legacy kubeconfigContent supported |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-14 | pass→pass | 8,132 | 3,668 | -55% | 1 | 1 | 0% | 1,489 | 3,829 | +157% | 0 | 0 | — |
case-03 | fail→pass | 15,098 | 7,551 | -50% | 1 | 1 | 0% | 2,656 | 4,633 | +74% | 0 | 0 | — |
case-04 | pass→pass | 6,439 | 2,708 | -58% | 1 | 1 | 0% | 1,296 | 3,695 | +185% | 0 | 0 | — |
case-01 | fail→pass | 9,399 | 4,366 | -54% | 1 | 1 | 0% | 1,810 | 4,142 | +129% | 0 | 0 | — |
case-02 | fail→pass | 12,510 | 23,276 | +86% | 1 | 1 | 0% | 2,266 | 4,392 | +94% | 0 | 0 | — |
case-05 | pass→pass | 10,452 | 2,754 | -74% | 1 | 1 | 0% | 1,671 | 3,747 | +124% | 0 | 0 | — |
case-06 | fail→pass | 20,535 | 9,001 | -56% | 1 | 1 | 0% | 1,993 | 3,797 | +91% | 0 | 0 | — |
case-07 | fail→pass | 7,021 | 7,178 | +2% | 1 | 1 | 0% | 1,214 | 3,638 | +200% | 0 | 0 | — |
case-08 | pass→pass | 6,803 | 1,705 | -75% | 1 | 1 | 0% | 732 | 3,465 | +373% | 0 | 0 | — |
case-13 | pass→pass | 9,597 | 2,624 | -73% | 1 | 1 | 0% | 1,500 | 3,747 | +150% | 0 | 0 | — |
case-09 | fail→pass | 14,268 | 7,286 | -49% | 1 | 1 | 0% | 1,624 | 4,348 | +168% | 0 | 0 | — |
case-10 | fail→pass | 11,150 | 4,973 | -55% | 1 | 1 | 0% | 1,867 | 4,099 | +120% | 0 | 0 | — |
case-11 | fail→pass | 7,983 | 1,767 | -78% | 1 | 1 | 0% | 1,446 | 3,552 | +146% | 0 | 0 | — |
case-12 | pass→pass | 4,217 | 2,162 | -49% | 1 | 1 | 0% | 816 | 3,592 | +340% | 0 | 0 | — |
case-15 | fail→pass | 7,780 | 1,116 | -86% | 1 | 1 | 0% | 1,250 | 3,413 | +173% | 0 | 0 | — |
case-16 | pass→pass | 10,536 | 8,244 | -22% | 1 | 1 | 0% | 1,813 | 4,593 | +153% | 0 | 0 | — |
case-17 | pass→pass | 6,804 | 2,390 | -65% | 1 | 1 | 0% | 903 | 3,595 | +298% | 0 | 0 | — |
case-18 | pass→pass | 7,203 | 3,112 | -57% | 1 | 1 | 0% | 1,201 | 3,755 | +213% | 0 | 0 | — |
case-19 | pass→pass | 6,519 | 4,351 | -33% | 1 | 1 | 0% | 1,044 | 3,889 | +273% | 0 | 0 | — |
case-20 | pass→pass | 15,183 | 13,016 | -14% | 1 | 1 | 0% | 2,924 | 5,762 | +97% | 0 | 0 | — |
case-21 | pass→pass | 11,879 | 11,512 | -3% | 1 | 1 | 0% | 2,107 | 5,482 | +160% | 0 | 0 | — |
case-22 | pass→pass | 15,749 | 11,617 | -26% | 1 | 1 | 0% | 2,804 | 5,188 | +85% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +41 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.