swarmr-kube
Kubernetes incident response team for swarmr. Diagnoses a live cluster and proves the root cause.
Read-only twice over: the credential grants only get/list/watch, and filesystem
permissions deny writes outside evidence/. Nothing about the cluster is
hardcoded — the team profiles it at startup and injects what it found into every
prompt.
Install
Core and this team must land in the same environment.
uv tool install "swarmr[kube]" --with-executables-from swarmr-kube
That exposes teams, teams-mcp and incident-credentials on your PATH.
--with-executables-from is required for the third. From a checkout:
uv tool install ../swarmr --with ../swarmr-kube --with-executables-from swarmr-kube.
teams --target k8s_incident
teams k8s_incident "payments.demo.local returns 502, namespace demo"
Over MCP the tool is start_k8s_incident.
Credentials
This team needs a read-only credential. It refuses your ambient kubeconfig, which is usually cluster-admin.
incident-credentials --list
incident-credentials --context archdev
incident-credentials --print-manifest
That creates the incident-reader ServiceAccount and ClusterRole, mints an 8h
token, writes .incident-reader.<context>.kubeconfig at mode 600, then asks the
API server to confirm the credential can list pods and cannot delete them.
Each cluster gets its own credential file. Selection is explicit:
INCIDENT_KUBECONFIG (exact path), else INCIDENT_CONTEXT (context name), else
the single minted credential. Several credentials with no choice expressed is an
error rather than a guess.
The 8h token refreshes itself: every run reads the expiry before opening a
connection and re-mints when under five minutes remain. Only files this team
minted are ever rewritten. INCIDENT_NO_REFRESH=1 turns it off.
Design notes and internals: CLAUDE.md.
Metadata
Release files for swarmr-kube 1.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmr_kube-1.1.1.tar.gz | 67.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmr_kube-1.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 122.3 kB
Release files / swarmr_kube-1.1.1.tar.gz
| Download URL | swarmr_kube-1.1.1.tar.gz |
|---|---|
| Size | 67.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6e9b793ee890caab46143e896b02fc6d85afc7a4e97b3645354d249a0d8a68ca
|
|
BLAKE2b-256 checksum How to use checksums |
0971eb847940f38942c89ba365c9c0f4cd62d4b2799687764e9b1a0b72863e65
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmr_kube-1.1.1-py3-none-any.whl
| Download URL | swarmr_kube-1.1.1-py3-none-any.whl |
|---|---|
| Size | 55.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b3deca268b5adec20b7563cf51e66b1d9a24df4265fcc7e9d8435a5e88eae806
|
|
BLAKE2b-256 checksum How to use checksums |
e971f697104b540c03a25fb6bee5c76e216e33fc8920bd4fb53a5af970e3ee3f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|