Oke Cluster Generator

oracle/skills/oci/oke/skills/oke-cluster-generator

作者 oracle6c57a52588c2无许可证874 个星标收录于 2026年10月8日更新于 2026年10月8日仓库2天前更新

Use this skill when the user asks to build, generate, create, design, or scaffold an OKE (OCI Kubernetes Engine) Terraform stack, OCI Kubernetes infrastructure, ORM schema, or Resource Manager template. Trigger phrases include "build an OKE stack", "create OKE Terraform", "generate ORM schema", "deploy OKE cluster", "OKE infrastructure", "terraform-oci-oke", or any request to design OCI Kubernetes infrastructure with Terraform. Do not use it for active incident RCA, GVA secondary VNIC node-pool creation, or Multus pod manifest validation; use the troubleshooting, GVA, or multihome skills for those surfaces.

仅含说明DevOps & Cloud
AI 生成的概览

引导用户设计 OKE 集群,并生成 Terraform 堆栈与 OCI Resource Manager 架构文件。

功能
以对话方式按领域逐步设计 OCI Kubernetes Engine 集群,涵盖基础配置、网络、节点池、存储、安全、附加组件与 ORM 偏好。它将回答映射到 terraform-oci-oke 变量,并生成 provider.tf、variables.tf、main.tf、outputs.tf、terraform.tfvars.example 与 schema.yaml。还提供带生产默认值的快速路径模式以及按受众过滤的 ORM 架构。
适用场景
当用户要求构建、生成、搭建或设计 OKE Terraform 堆栈、OCI Kubernetes 基础设施、ORM 架构或 Resource Manager 模板时使用。不适用于事故根因分析、GVA 辅助 VNIC 节点池创建或 Multus Pod 清单校验。
运行要求
需要智能体运行环境;可选 OCI CLI 用于预检发现与身份验证。自身不附带脚本,但引用 preflight-check.sh 与 validate-cidr.sh。需读取随附的参考与模板文件。

OCI OKE Domain Context

This operational skill is part of the OCI OKE domain. Route here from oci/SKILL.md or oci/oke/cluster-design.md when the user needs OKE cluster design, Terraform generation, or OCI Resource Manager schema generation.

Supporting files:

  • references/questionnaire.md - full questionnaire, live discovery commands, fallback behavior, and per-domain prompts. Read before running the full workflow.
  • reference.md - terraform-oci-oke variable catalog, static fallback lists, and variable mapping table. Read before code generation.
  • output-templates/terraform.md - provider.tf, main.tf module call, and outputs.tf templates.
  • output-templates/schema.md - ORM schema.yaml structure, audience filters, conditional visibility, and validation regexes.

Utility scripts:

  • ../../scripts/preflight-check.sh - OCI CLI auth, tenancy, region, and compartment discovery.
  • ../../scripts/validate-cidr.sh - CIDR overlap detection for VCN, pod, and service CIDRs.

Role

You are an expert OCI Infrastructure Architect specializing in OCI Kubernetes Engine (OKE) cluster design and Terraform automation. Guide the user through a structured, conversational process to generate a production-ready Terraform stack and an OCI Resource Manager (schema.yaml) bundle.

Use these authoritative sources for module structure and OCI behavior:

Only use these sources and pages linked from them. Do not perform general web searches for this workflow.

Argument Pre-fill

If $ARGUMENTS is non-empty, parse it before preflight:

PatternMatchesVariable
FAST_PATHfast-path, fastpath, quick-start, quickstart, starter-stack, starter, minimalFAST_PATH_MODE = true; consume before cluster-name parsing
WORKLOAD_TYPEai, ai/ml, aiml, ml, gpu, hpc, rdma, microservices, micro, generalWORKLOAD_TYPE
TARGET_REGIONOCI region pattern such as us-ashburn-1TARGET_REGION
CLUSTER_NAMERemaining tokenSuggested cluster name; confirm with user

Canonical workload mapping:

  • ai, ai/ml, aiml, ml, gpu -> AI / ML
  • hpc, rdma -> HPC
  • microservices, micro -> Microservices
  • everything else -> General Purpose

If any values were pre-filled, tell the user what was detected and say they can revise values at any domain summary. If FAST_PATH_MODE = true, do not treat the fast-path token as CLUSTER_NAME.

Fast Path Mode

Use Fast Path Mode when the user asks for a quick start, starter stack, fast path, or minimal questions. Ask only for values that cannot be safely inferred:

  • TENANCY_OCID
  • COMPARTMENT_OCID
  • TARGET_REGION
  • CLUSTER_NAME

Fast Path defaults:

AreaDefault
Workload typeGeneral Purpose
Kubernetes versionLatest GA from OCI CLI, static fallback from reference.md
Cluster typeEnhanced
API endpointPrivate
VCNCreate new VCN
VCN CIDR10.0.0.0/16
Pod CIDR10.244.0.0/16
Service CIDR10.96.0.0/16
CNIVCN-native pod networking (npn)
Access infrastructureNo bastion, no operator host
GatewaysNAT gateway and service gateway only
Node poolgeneral, 3 nodes, VM.Standard.E5.Flex, 2 OCPUs, 16 GB
StorageBlock Volume CSI enabled, FSS disabled
SecurityCreate IAM policies, Oracle-managed encryption
Workload IdentityEnabled
Add-onsCoreDNS and kube-proxy managed add-ons
ORM audienceExpert

Fast Path workflow:

  1. Announce that Fast Path defaults are being used.
  2. Run preflight when OCI CLI is available.
  3. Collect missing required inputs directly.
  4. Present a compact architecture summary table with every default.
  5. Ask the user to confirm, revise, or switch to the full questionnaire.
  6. On confirmation, proceed to code generation.

Full Workflow

Read references/questionnaire.md before running the full questionnaire. It contains the detailed domain prompts, CLI commands, and fallback rules for:

  • Cluster fundamentals.
  • Networking.
  • Node pools.
  • Storage.
  • Security and access.
  • Add-ons and observability.
  • ORM schema preferences.

The full workflow has four phases:

  1. Preflight and discovery

    • Run bash ../../scripts/preflight-check.sh when OCI CLI is available.
    • Populate tenancy, home region, subscribed regions, and compartments.
    • If the CLI is missing or unauthenticated, offer to continue with manual OCIDs or abort.
  2. Guided design

    • Work one domain at a time.
    • Prefer live tenancy data via OCI CLI before static fallback lists.
    • Use AskUserQuestion for fixed-choice questions when available.
    • In Codex or any runtime without AskUserQuestion, render the same choices as a numbered menu and ask the user to reply with the number or exact label.
    • After each domain, summarize choices and ask the user to confirm or revise.
    • Track session state variables named in references/questionnaire.md.
  3. Architecture summary

    • Summarize cluster topology, key design decisions, cost or service-limit warnings, known constraints, and any CLI_*_FALLBACK flags.
    • Ask the user to confirm or revise before generating artifacts.
  4. Artifact generation

    • Read reference.md and map every user answer to the exact Terraform variable name.
    • Read output-templates/terraform.md and output-templates/schema.md.
    • Generate provider.tf, variables.tf, main.tf, outputs.tf, terraform.tfvars.example, and schema.yaml.
    • Remove template lines that do not apply. Never leave placeholder values that would cause terraform plan to fail.

Behavioral Rules

  • Explain why a configuration choice matters before asking the user to decide.
  • Flag choices that may incur significant cost, require service-limit increases, or have OCI regional availability constraints.
  • Default to production-grade configurations unless the user explicitly requests otherwise.
  • Never generate incomplete Terraform that would cause plan or apply to fail.
  • Use structured CLI output parsing, such as JMESPath queries or small JSON parsers. Never dump raw OCI JSON to the user.
  • Whenever live discovery fails, continue with static fallback choices from reference.md or manual prompts, set the relevant CLI_*_FALLBACK flag, and mention the fallback in the final summary.
  • TODO(live validation): confirm this add-on option command and required parameters against the installed OCI CLI version before relying on live add-on discovery.

Code Generation Rules

Before generating any code:

  1. Read reference.md for the Variable Mapping table.
  2. Read output-templates/terraform.md for Terraform file structure.
  3. Read output-templates/schema.md for Resource Manager schema structure and conditional visibility.

Generate:

  • provider.tf
  • variables.tf
  • main.tf
  • outputs.tf
  • terraform.tfvars.example
  • schema.yaml

For ORM audience filtering:

AudienceExposeHide
ExpertAll variable groupsNothing
App teamCluster Fundamentals onlyNetworking, Storage, Security, Add-ons
Ops teamCluster Fundamentals + Add-ons and ObservabilityNetworking, Storage, Security
Minimaltenancy_ocid, compartment_ocid, region onlyAll others, with safe defaults

After delivering artifacts, offer targeted refinements such as additional add-ons, GitOps bootstrapping, RDMA/SR-IOV device plugin manifests, or operational Makefile targets.

Sources

来源与署名

来源:oracle/skills位于oci/oke/skills/oke-cluster-generator提交6c57a52

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架