EKS Cluster: Part 9.5 – Ai Ops/Dev = Kubectl-Ai, & Kiro

Series of blog posts show progress of updating/adding to EKS Cluster, this post covers adding Kubectl-Ai, & Kiro under Ai Operations. See below for past posts:

Kubectl-Ai: AI operations assistant for troubleshooting, explanations, not a security scanner – It can translate intent into Kubernetes operations and use tools like kubectl/bash.

  • Convert plain English into commands or YAML manifests like;
    • kubectl ai “create a deployment with 3 replicas”
  • Flow goes;
    • Terminal → ~/.kube/config → EKS cluster → AWS profile → Amazon Bedrock → kubectl-ai
    • kubectl-ai recommendation
    • → edit say_when_git_ops
    • → git commit/push
    • → Argo CD reconciles
  • Sources:

Abstract/Table of Contents:

  • Below is the order of items addressed:
    • 3 Steps below
      • Config kubectl-ai NOT pushed to get
        • 2 options to install locally
      • Configure AWS Profile
      • Check Available Bedrock Models
    • Important Note: 1st time AWS request-form to utilize AWS Bedrock Anthropic Model
    • Helpful Kubectl-ai commands
      • Example cost messing around

3 Steps below:

Config kubectl-ai: NOT pushed to git

=====================
ls -la ~
=====================
ls -la ~/.config
=====================
mkdir -p ~/.config/kubectl-ai/config.yaml
=====================
llmProvider: bedrock
model: us.anthropic.claude-sonnet-4-20250514-v1:0
kubeconfig: ~/.kube/config
skipPermissions: false
maxIterations: 10
quiet: false
removeWorkdir: true
uiType: terminal
=====================
sed -n '1,200p' ~/.config/kubectl-ai/config.yaml
=====================
~/.config/
├── argocd/
├── helm/
├── htop/
├── k8sGPT/
├── k9s/
└── kubectl-ai/
└── config.yaml

Option 1 – Install Locally: curl github repo w/sh

=====================
curl -sSL \
https://raw.githubusercontent.com/GoogleCloudPlatform/kubectl-ai/main/install.sh |
bash
=====================
kubectl-ai version
=====================

Option 2 – Install Locally: Git-Tracked: kubectl-ai/config.example.yaml:

cd ~/x/y/z
=====================
mkdir -p docs/kubectl-ai
=====================
nano/vi/IDE docs/kubectl-ai/config.example.yaml
=====================
# kubectl-ai local configuration example
#
# This file is tracked in Git for documentation.
# Copy it to ~/.config/kubectl-ai/config.yaml before using kubectl-ai.
#
# AWS credentials are intentionally not stored here.
# kubectl-ai uses the normal AWS SDK credential chain.
# Amazon Bedrock provider
llmProvider: bedrock
# Bedrock cross-region inference profile
model: us.anthropic.claude-sonnet-4-20250514-v1:0
# Use the current user's Kubernetes configuration
kubeconfig: ~/.kube/config
# Require approval before commands are executed
skipPermissions: false
# Limit the number of agent/tool iterations per request
maxIterations: 10
# Use interactive terminal output
quiet: false
uiType: terminal
# Remove temporary working files after each session
removeWorkdir: true
=====================
sed -n '1,200p' docs/kubectl-ai/config.example.yaml
=====================
git add docs/kubectl-ai/config.example.yaml
git commit -m "document kubectl-ai Bedrock configuration"
git push
=====================
command -v kubectl-ai
=====================
kubectl-ai version
=====================
  • The 8 settings are official Bedrock documentation options/recommendations

Configure AWS Profile

=====================
export AWS_REGION=us-east-1
export AWS_DEFAULT_REGION=us-east-1
export AWS_PROFILE=<your-profile>
=====================
kubectl config current-context
=====================
kubectl cluster-info
=====================
kubectl get nodes
=====================
aws sts get-caller-identity
=====================
aws configure list
=====================
aws sts get-caller-identity --profile <your-profile>

Check available Bedrock models:

=====================
aws bedrock list-foundation-models \
--region us-east-1 \
--by-provider anthropic \
--query 'modelSummaries[].{Name:modelName,ID:modelId}' \
--output table
=====================
aws bedrock list-inference-profiles \
--region us-east-1 \
--query 'inferenceProfileSummaries[].{Name:inferenceProfileName,ID:inferenceProfileId,Status:status}' \
--output table
=====================
kubectl-ai --quiet model
us.anthropic.claude-sonnet-4-20250514-v1:0
=====================

Important Note: First time users will fill out a request-form, wait about 15 minutes.

Kubectl-ai Costs:

  • For Claude Sonnet 4, the approximate on-demand rate is:
    • Input: $3 per 1 million tokens
    • Output: $15 per 1 million tokens
kubectl-ai taskExample usageApproximate cost
Simple question5K input + 1K output$0.03
Normal diagnosis10K input + 2K output$0.06
Larger investigation25K input + 5K output$0.15
Very large session100K input + 20K output$0.60

Commands while your waiting for submission form to be approved:

=====================
- cd ~/x/y/z
- mkdir -p ~/.config/kubectl-ai
- cp docs/kubectl-ai/config.example.yaml \
- ~/.config/kubectl-ai/config.yaml
- chmod 600 ~/.config/kubectl-ai/config.yaml
=====================
sed -n '1,200p' ~/.config/kubectl-ai/config.yaml
=====================
- command -v kubectl-ai
- kubectl-ai version
- aws sts get-caller-identity
- kubectl cluster-info
=====================

15 minutes is up – lets check it

  • Should see an email like this
=====================
aws bedrock-runtime converse \
--region us-east-1 \
--model-id us.anthropic.claude-sonnet-4-20250514-v1:0 \
--messages '[{"role":"user","content":[{"text":"Reply with exactly: Bedrock works"}]}]' \
--inference-config '{"maxTokens":20}' \
--output json \
> /tmp/bedrock-test.json
=====================
jq -r '.output.message.content[0].text' \
/tmp/bedrock-test.json
Bedrock works
=====================
grep -E '^(llmProvider|model):' \
~/.config/kubectl-ai/config.yaml
llmProvider: bedrock
model: us.anthropic.claude-sonnet-4-20250514-v1:0
=====================

Kubectl-ai commands:

  • Can increase code iteration to 20 if 10 is not getting you enough
=====================
kubectl ai \
"List unhealthy pods across all namespaces and explain the problems. Do not make any changes."
=====================
kubectl ai \
"Check Argo CD Applications that are not Healthy or Synced. Do not modify anything."
=====================
kubectl ai \
"Review pending pods and explain the scheduling failures. Do not make changes."
=====================
kubectl ai \
"Inspect recent warning events across the cluster and summarize the most important problems. Do not change resources."
=====================
kubectl ai \
"Diagnose the unhealthy Tempo StatefulSet and show the GitOps YAML change you recommend. Do not apply the change."
"Review all Argo CD Applications and identify anything that is not Synced or Healthy. Do not modify the cluster."
=====================
kubectl-ai \
"Show the current Kubernetes context and list unhealthy pods across all namespaces. Explain the problems but do not make any changes."
"Review all Argo CD Applications and identify anything that is not Synced or Healthy. Do not modify the cluster."
=====================
kubectl-ai \
"Review all Argo CD Applications and identify anything that is not Synced or Healthy. Do not modify the cluster."
=====================
kubectl ai
=====================
exit
=====================

Example cost messing around for about 45 minutes:

ModelInput costOutput costTotal
Claude Sonnet 4.643,286 × $3/M = $0.130948 × $15/M = $0.014$0.14
Legacy Claude Sonnet 4438,571 × $3/M = $1.3166,404 × $15/M = $0.096$1.41
Combined$1.56

Kiro: Kiro is an agentic coding IDE/service for specs, code, docs, tests, and larger repo-level tasks.

=====================
curl -fsSL https://cli.kiro.dev/install | bash
=====================
exec "$SHELL" -l
=====================
kiro-cli --version
=====================
kiro-cli login --use-device-flow
=====================

Kiro-CLI Example to utilize:

=====================
Analyze this Terraform repository without changing any files or creating any AWS resources.
Explain:
1. The architecture this code deploys.
2. How EKS, VPC, IAM, IRSA, EBS CSI, S3, Thanos, Argo CD, and GitOps connect.
3. Security, reliability, and cost concerns.
4. Any Terraform errors, stale configuration, hard-coded values, or unnecessary resources.
5. The five highest-priority improvements.
You may run only read-only commands such as:
git status
terraform fmt -check
terraform validate
terraform plan
Do not run terraform apply, terraform destroy, git commit, git push, or modify files.
=====================

Infra Repo:

  • From either infra or gitops repo it will provide you a link to click for creation/log-in to your AWS builder ID
=====================
Review my IAM and IRSA Terraform code only. Do not modify files. Identify excessive permissions, incorrect trust relationships, and hard-coded account-specific values.
=====================
=====================
Review this repository for unnecessary AWS costs. Do not modify files or create resources. Estimate which resources generate costs while the EKS cluster is running.
=====================
=====================
Create a dependency map showing the order in which this Terraform code creates the VPC, EKS cluster, IAM roles, EBS CSI driver, Argo CD, and GitOps bootstrap. Do not change files.
=====================

Gitops Repo:

=====================
Analyze this Kubernetes GitOps repository without modifying any files.
Review:
1. The Argo CD application hierarchy, sync waves, and dependencies.
2. Helm chart versions and values-file references.
3. Kyverno CEL validating policies and their Audit or Deny actions.
4. NetworkPolicies for DNS, Kubernetes API, Prometheus, Grafana, Loki, Tempo, and Thanos.
5. Resource requests, limits, security contexts, image tags, RBAC, namespaces, and storage.
6. K8sGPT, kube-bench, Popeye, Falco, Trivy Operator, and the monitoring stack.
7. Invalid YAML, duplicate policies, missing manifests, selector mismatches, and configuration drift.
8. The five highest-priority improvements.
You may run only read-only commands. Do not modify files, run kubectl apply, perform an Argo CD sync, commit, or push anything.
=====================