Back to Skills

gke-app-onboarding

Manages GKE application onboarding, covering containerization, deployment manifests, and migration. Use when onboarding or deploying an application to GKE for the first time, or containerizing an app for GKE. Don't use for general GKE cluster administration or upgrades (use gke-basics or gke-upgrades instead).

15,350stars1,203forksUpdated 7/31/2026

Security Assessment

Safe(95/100)
Security Score95/100

About gke-app-onboarding

GKE App Onboarding is a Google Kubernetes Engine workflow skill that guides taking an application from source code to a running deployment on GKE for the first time. It solves the end-to-end onboarding problem — assessing the app, containerizing it, building and storing an image, generating Kubernetes manifests, and deploying — while steering toward secure, production-sensible defaults. It explicitly scopes itself to first-time onboarding and containerization, deferring general cluster administration and upgrades to sibling skills.

The workflow starts with an app assessment (language and framework, dependencies, configuration, statefulness, networking, and health endpoints), then covers containerization with best practices such as multi-stage builds, distroless or minimal base images, running as a non-root user, and logging to stdout/stderr, with Cloud Native Buildpacks as an alternative to writing a Dockerfile. It handles image management via Artifact Registry, including configuring Docker auth and enabling vulnerability scanning, then generates Deployment and Service manifests with resource requests and limits, liveness and readiness probes, and multiple replicas. Deployment is done through preferred MCP tools (apply_k8s_manifest, get_k8s_rollout_status, get_k8s_resource, and related) with a kubectl fallback, and it points to follow-on skills for autoscaling, observability, security hardening, and reliability.

It targets developers and platform engineers onboarding services to GKE. Use cases include containerizing an existing app, writing a first Dockerfile and deployment manifest, pushing to Artifact Registry with scanning enabled, and rolling out and verifying a workload. The commands are standard, security-conscious build and deploy operations against the user's own cloud project.

FAQ

When should I use this skill versus other GKE skills?

Use it for onboarding or deploying an application to GKE for the first time or containerizing an app; for general cluster administration or upgrades, use gke-basics or gke-upgrades instead.

What containerization best practices does it recommend?

Multi-stage builds for small images, distroless or minimal base images to reduce attack surface, running as a non-root user, and logging to stdout/stderr for Cloud Logging. Cloud Native Buildpacks are offered as an alternative to writing a Dockerfile.

How is the app deployed?

Through preferred MCP tools such as apply_k8s_manifest and get_k8s_rollout_status, with a kubectl fallback (kubectl apply, rollout status, and get pods).

What does it check for in the generated manifests?

Resource requests and limits, configured liveness and readiness probes, at least two replicas for production, and an appropriate Service type (ClusterIP for internal, Gateway API for external).

Does it address image security?

Yes. It configures Docker auth for Artifact Registry and recommends enabling automatic vulnerability scanning, then checking scan results for base-image and dependency issues before deploying.

All Files

5 files
assets/package.json0.1 KB
View
SKILL.md4.7 KB
View
assets/index.js0.4 KB
View
assets/deployment.yaml1.5 KB
View
assets/Dockerfile0.4 KB
View

Install gke-app-onboarding

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

google/skills