Skip to main content

swarmr-kube

Kubernetes incident response team for swarmr. Diagnoses a live cluster and proves the root cause.

Read-only twice over: the credential grants only get/list/watch, and filesystem permissions deny writes outside evidence/. Nothing about the cluster is hardcoded — the team profiles it at startup and injects what it found into every prompt.

Install

Core and this team must land in the same environment.

uv tool install "swarmr[kube]" --with-executables-from swarmr-kube

That exposes teams, teams-mcp and incident-credentials on your PATH. --with-executables-from is required for the third. From a checkout: uv tool install ../swarmr --with ../swarmr-kube --with-executables-from swarmr-kube.

teams --target k8s_incident
teams k8s_incident "payments.demo.local returns 502, namespace demo"

Over MCP the tool is start_k8s_incident.

Credentials

This team needs a read-only credential. It refuses your ambient kubeconfig, which is usually cluster-admin.

incident-credentials --list
incident-credentials --context archdev
incident-credentials --print-manifest

That creates the incident-reader ServiceAccount and ClusterRole, mints an 8h token, writes .incident-reader.<context>.kubeconfig at mode 600, then asks the API server to confirm the credential can list pods and cannot delete them.

Each cluster gets its own credential file. Selection is explicit: INCIDENT_KUBECONFIG (exact path), else INCIDENT_CONTEXT (context name), else the single minted credential. Several credentials with no choice expressed is an error rather than a guess.

The 8h token refreshes itself: every run reads the expiry before opening a connection and re-mints when under five minutes remain. Only files this team minted are ever rewritten. INCIDENT_NO_REFRESH=1 turns it off.

Design notes and internals: CLAUDE.md.

Metadata

Release files for swarmr-kube 1.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmr-kube 1.1.1
File Size Uploaded
swarmr_kube-1.1.1.tar.gz 67.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmr-kube 1.1.1
File Interpreter ABI Platform
swarmr_kube-1.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 122.3 kB

Release files / swarmr_kube-1.1.1.tar.gz

Download URL swarmr_kube-1.1.1.tar.gz
Size 67.0 kB
Tags Source
SHA-256 checksum
How to use checksums
6e9b793ee890caab46143e896b02fc6d85afc7a4e97b3645354d249a0d8a68ca
BLAKE2b-256 checksum
How to use checksums
0971eb847940f38942c89ba365c9c0f4cd62d4b2799687764e9b1a0b72863e65
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmr_kube-1.1.1-py3-none-any.whl

Download URL swarmr_kube-1.1.1-py3-none-any.whl
Size 55.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b3deca268b5adec20b7563cf51e66b1d9a24df4265fcc7e9d8435a5e88eae806
BLAKE2b-256 checksum
How to use checksums
e971f697104b540c03a25fb6bee5c76e216e33fc8920bd4fb53a5af970e3ee3f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

1.1.1 This release

2 release files

1.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page