nodegroup — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited nodegroup (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to perform real nodegroup-related operations in the edgewize-io/nodegroup environment.
This skill should help with:
NodeGroupNodeGroupconfig/nodegroupPrefer using the bundled script scripts/nodegroup_api.py for authenticated KAPI operations. Use kubectl only as a verification or fallback tool when the API path is unavailable.
Use the bundled script:
scripts/nodegroup_api.pyAuthentication model:
/oauth/token~/.kubesphere_tokenKUBESPHERE_HOST, KUBESPHERE_USERNAME, KUBESPHERE_PASSWORD, and KUBESPHERE_TOKENSetup:
cd scripts
pip install requests
export KUBESPHERE_HOST="http://<kubesphere-host>"
python nodegroup_api.py login --username admin --password <password>Token helpers:
python nodegroup_api.py clear-cache
python nodegroup_api.py request GET /kapis/infra.kubesphere.io/v1alpha1/nodegroupsWhen you need to confirm how an operation works, read these files first from the nodegroup source repository root:
pkg/kapis/infra/v1alpha1/register.gopkg/kapis/infra/v1alpha1/handler.gopkg/kapis/infra/v1alpha1/workspace_handler.gopkg/controller/nodegroup/nodegroup_controller.gopkg/constants/constants.goDo not invent unsupported operations. Base the workflow on the source repository.
Cluster-scoped resource.
Important fields:
spec.aliasspec.descriptionspec.managerstatus.statepython nodegroup_api.py ... query commands.For any write operation, follow this order:
python nodegroup_api.py nodegroup list
python nodegroup_api.py nodegroup get <name>python nodegroup_api.py nodegroup create \
--name <nodegroup-name> \
--alias "<alias>" \
--description "<description>" \
--manager "<manager>"
python nodegroup_api.py nodegroup get <nodegroup-name>Prefer patching for small changes.
python nodegroup_api.py nodegroup patch <name> \
--alias "<new-alias>" \
--description "<new-description>" \
--manager "<manager>"
python nodegroup_api.py nodegroup get <name>For unsupported fields or ad hoc testing, use raw request mode.
For PATCH, send a JSON Patch array:
python nodegroup_api.py request PATCH /kapis/infra.kubesphere.io/v1alpha1/nodegroups/<name> '[{"op":"add","path":"/spec/alias","value":"<new-alias>"}]'Only do this when explicitly requested.
python nodegroup_api.py nodegroup delete <name>If delete hangs, inspect finalizers:
python nodegroup_api.py nodegroup get <name>Relevant finalizer:
finalizers.nodegroups.kubesphere.ioNode binding is implemented through nodegroup APIs and reflected with label:
apps.edgewize.io/nodegroup=<nodegroup-name>Read current state:
kubectl get node <node-name> --show-labels
kubectl get nodes -l apps.edgewize.io/nodegroup=<nodegroup-name>Operate through the bundled script:
python nodegroup_api.py bind node --nodegroup <nodegroup-name> --node <node-name>
python nodegroup_api.py unbind node --nodegroup <nodegroup-name> --node <node-name>
# Verify
kubectl get nodes -l apps.edgewize.io/nodegroup=<nodegroup-name>
kubectl get node <node-name> -o yamlRead current state:
kubectl get ns <namespace> --show-labelsOperate through the bundled script:
python nodegroup_api.py bind namespace --nodegroup <nodegroup-name> --namespace <namespace>
python nodegroup_api.py unbind namespace --nodegroup <nodegroup-name> --namespace <namespace>
# Verify
python nodegroup_api.py nodegroup get <nodegroup-name>
kubectl get ns <namespace> -o yamlpython nodegroup_api.py bind workspace --nodegroup <nodegroup-name> --workspace <workspace>
python nodegroup_api.py unbind workspace --nodegroup <nodegroup-name> --workspace <workspace>When an operation appears to succeed but state is wrong, check these in order:
Useful checks:
python nodegroup_api.py nodegroup get <name>
kubectl get node <node-name> -o yaml
kubectl get ns <namespace> -o yaml
kubectl get cm nodegroup-config -n kubesphere-system -o yaml
kubectl get pods -n kubesphere-system | grep nodegroupImportant constants:
apps.edgewize.io/nodegroupapps.edgewize.io/namespace-nodegroup.infra.kubesphere.io/parentinfra.kubesphere.io/ippool-If the user asks how nodegroup is deployed or configured, inspect these files from the nodegroup source repository root:
config/nodegroup/templates/nodegroup-apiserver.ymlconfig/nodegroup/templates/nodegroup-controller-manager.yamlconfig/nodegroup/templates/nodegroup-config.yamlconfig/nodegroup/values.yamlConfigMap key:
nodegroup.yamlNotable config sections:
schedulingpolicyrbacippoolIf the user asks for an operation that already has a dedicated nodegroup API, prefer the bundled script and the dedicated nodegroup API semantics over manual label hacking.
Examples:
python nodegroup_api.py bind node ...python nodegroup_api.py bind namespace ...python nodegroup_api.py bind workspace ...python nodegroup_api.py request ...Only fall back to direct manifest edits or label repair when the request is explicitly about low-level repair.
When using this skill:
nodegroup_api.py command or API path to run next~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.