swarmr-kube
Kubernetes incident response team for swarmr. Diagnoses a live cluster and proves the root cause.
Read-only twice over: the credential grants only get/list/watch, and filesystem
permissions deny writes outside evidence/. Nothing about the cluster is
hardcoded — the team profiles it at startup and injects what it found into every
prompt.
Install
Core and this team must land in the same environment.
uv tool install "swarmr[kube]" --with-executables-from swarmr-kube
That exposes teams, teams-mcp and incident-credentials on your PATH.
--with-executables-from is required for the third. From a checkout:
uv tool install ../swarmr --with ../swarmr-kube --with-executables-from swarmr-kube.
teams --target k8s_incident
teams k8s_incident "payments.demo.local returns 502, namespace demo"
Over MCP the tool is start_k8s_incident.
Credentials
This team needs a read-only credential. It refuses your ambient kubeconfig, which is usually cluster-admin.
incident-credentials --list
incident-credentials --context archdev
incident-credentials --print-manifest
That creates the incident-reader ServiceAccount and ClusterRole, mints an 8h
token, writes .incident-reader.<context>.kubeconfig at mode 600, then asks the
API server to confirm the credential can list pods and cannot delete them.
Each cluster gets its own credential file. Selection is explicit:
INCIDENT_KUBECONFIG (exact path), else INCIDENT_CONTEXT (context name), else
the single minted credential. Several credentials with no choice expressed is an
error rather than a guess.
The 8h token refreshes itself: every run reads the expiry before opening a
connection and re-mints when under five minutes remain. Only files this team
minted are ever rewritten. INCIDENT_NO_REFRESH=1 turns it off.
Design notes and internals: CLAUDE.md.
Metadata
Release files for swarmr-kube 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmr_kube-1.1.0.tar.gz | 66.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmr_kube-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 122.1 kB
Release files / swarmr_kube-1.1.0.tar.gz
| Download URL | swarmr_kube-1.1.0.tar.gz |
|---|---|
| Size | 66.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9d29ffd18fe5a2431abe6b8985de2b1341e8dbac727887957f51595044f72abd
|
|
BLAKE2b-256 checksum How to use checksums |
78c780904df94c39760703356459eb6a66713071a2a9bdb4fccde7cf76399211
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmr_kube-1.1.0-py3-none-any.whl
| Download URL | swarmr_kube-1.1.0-py3-none-any.whl |
|---|---|
| Size | 55.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
baa79ce20b5109112f7410024045443b03927a6e256e0f6cbe9dca15fd3f6c9d
|
|
BLAKE2b-256 checksum How to use checksums |
878fc31893df5b856ee5aabc680817cc52b880c37cc294c89091adf9bf99d8cd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|