konnect-control-plane-bootstrap — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited konnect-control-plane-bootstrap (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Help an operator stand up a new Konnect Gateway control plane with the right bootstrap assumptions before the problem becomes Gateway drift or runtime troubleshooting.
Use this skill for initial setup, first-run topology choices, naming, labels, ownership boundaries, and "what should we create first?" decisions. Do not use it for ongoing incident triage, retrofitting generic Gateway config, or fixing an already unhealthy existing control plane unless the missing piece is still bootstrap scope.
kong-konnect MCP server first for live inspection ofexisting control planes, groups, and adjacent Konnect Gateway resources.
attachment, health, rollout, or config-application symptoms, hand off to konnect-gateway-triage instead of treating the problem as bootstrap.
be codified: use terraform-konnect for HCL-managed control planes, kongctl-declarative for kongctl YAML, and deck-gateway only after the control plane exists and the task becomes Gateway-entity configuration.
the durable repo-managed setup distinct in your explanation.
kong-konnect MCP is not connected, say soearly and continue with user-provided artifacts or repo context.
Load only the reference file that matches the active branch:
references/topology-choice.mdquick local bootstrap versus durable shared environment, or environment shape.
references/bootstrap-artifacts.mdattachment, and first Gateway config into concrete bootstrap milestones.
references/ownership-boundaries.mdpath is the real bootstrap decision.
First determine whether the user is:
If the real problem is health, rollout, connectivity, or config application on an existing control plane, hand off early to konnect-gateway-triage.
Clarify:
or both
serverless / Kong-managed where applicable
Do not treat a tutorial quickstart as the final production shape by default.
Load references/topology-choice.md when the deployment shape itself is still the hard part.
Decide:
Bootstrap errors here cause long-lived confusion later, especially when several control planes look similar.
Load references/ownership-boundaries.md when region, labels, names, or team ownership are the main source of ambiguity.
For a new control plane, keep these concerns distinct:
The control plane is not “done” just because it exists in Konnect.
Load references/bootstrap-artifacts.md when the operator needs the bootstrap milestones spelled out more explicitly.
Default decision rule:
terraform-konnect
kongctl, bootstrap inkongctl-declarative
separately and then point to the durable management path
Do not force migration between tools during bootstrap unless the user asked for it.
Before calling the bootstrap complete, verify:
or runtime verification
Common next steps:
konnect-gateway-triage if the control plane exists but connectivity orrollout is unhealthy
deck-gateway for first Gateway-entity config in a decK repoterraform-konnect or kongctl-declarative for durable control-planecodification
milestones.
recommending creation steps.
drift failures.
the first config rollout will succeed.
decK is not the control-plane bootstrap tool; it becomes relevant after thecontrol plane exists.
Before answering, verify that you can state:
konnect-gateway-triage when the bootstrap is complete enough that theremaining problem is health, connectivity, or rollout.
terraform-konnect or kongctl-declarative when the user wants thecontrol plane managed as code.
deck-gateway once the control plane exists and the task becomes Gatewayentity configuration.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.