Skip to main content

swarmr-kube

Kubernetes incident response team for swarmr. Diagnoses a live cluster and proves the root cause.

Read-only twice over: the credential grants only get/list/watch, and filesystem permissions deny writes outside evidence/. Nothing about the cluster is hardcoded — the team profiles it at startup and injects what it found into every prompt.

Install

Core and this team must land in the same environment.

uv tool install "swarmr[kube]" --with-executables-from swarmr-kube

That exposes teams, teams-mcp and incident-credentials on your PATH. --with-executables-from is required for the third. From a checkout: uv tool install ../swarmr --with ../swarmr-kube --with-executables-from swarmr-kube.

teams --target k8s_incident
teams k8s_incident "payments.demo.local returns 502, namespace demo"

Over MCP the tool is start_k8s_incident.

Credentials

This team needs a read-only credential. It refuses your ambient kubeconfig, which is usually cluster-admin.

incident-credentials --list
incident-credentials --context archdev
incident-credentials --print-manifest

That creates the incident-reader ServiceAccount and ClusterRole, mints an 8h token, writes .incident-reader.<context>.kubeconfig at mode 600, then asks the API server to confirm the credential can list pods and cannot delete them.

Each cluster gets its own credential file. Selection is explicit: INCIDENT_KUBECONFIG (exact path), else INCIDENT_CONTEXT (context name), else the single minted credential. Several credentials with no choice expressed is an error rather than a guess.

The 8h token refreshes itself: every run reads the expiry before opening a connection and re-mints when under five minutes remain. Only files this team minted are ever rewritten. INCIDENT_NO_REFRESH=1 turns it off.

Design notes and internals: CLAUDE.md.

Metadata

Release files for swarmr-kube 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmr-kube 1.1.0
File Size Uploaded
swarmr_kube-1.1.0.tar.gz 66.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmr-kube 1.1.0
File Interpreter ABI Platform
swarmr_kube-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 122.1 kB

Release files / swarmr_kube-1.1.0.tar.gz

Download URL swarmr_kube-1.1.0.tar.gz
Size 66.8 kB
Tags Source
SHA-256 checksum
How to use checksums
9d29ffd18fe5a2431abe6b8985de2b1341e8dbac727887957f51595044f72abd
BLAKE2b-256 checksum
How to use checksums
78c780904df94c39760703356459eb6a66713071a2a9bdb4fccde7cf76399211
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmr_kube-1.1.0-py3-none-any.whl

Download URL swarmr_kube-1.1.0-py3-none-any.whl
Size 55.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
baa79ce20b5109112f7410024045443b03927a6e256e0f6cbe9dca15fd3f6c9d
BLAKE2b-256 checksum
How to use checksums
878fc31893df5b856ee5aabc680817cc52b880c37cc294c89091adf9bf99d8cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

1.1.1

2 release files

This release

1.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page