SkillAtlasSkill 详情

openpitrix

The container platform tailored for Kubernetes multi-cloud, datacenter, and edge management

审核状态:已审核Quality 72Security 52

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月1日

banner

The container platform tailored for Kubernetes multi-cloud, datacenter, and edge management

A+ good first issue follow on Twitter


What is KubeSphere

English | 中文

KubeSphere is a distributed operating system for cloud-native application management, using Kubernetes as its kernel. It provides a plug-and-play architecture, allowing third-party applications to be seamlessly integrated into its ecosystem. KubeSphere is also a multi-tenant container platform with full-stack automated IT operation and streamlined DevOps workflows. It provides developer-friendly wizard web UI, helping enterprises to build out a more robust and feature-rich platform, which includes most common functionalities needed for enterprise Kubernetes strategy, see Feature List for details.

The following screenshots give a close insight into KubeSphere. Please check What is KubeSphere for further information.

WorkbenchProject Resources
CI/CD PipelineApp Store

Demo environment

🎮 KubeSphere Lite provides you with free, stable, and out-of-the-box managed cluster service. After registration and login, you can easily create a K8s cluster with KubeSphere installed in only 5 seconds and experience feature-rich KubeSphere.

🖥 You can view the Demo Video to get started with KubeSphere.

Features

🧩 Extensible Architecture Designed for flexibility, supporting plugin-based extensions and seamless integrations. Easily customize and expand functionalities to meet evolving needs. Learn more.
🕸 Provisioning Kubernetes Cluster Support deploy Kubernetes on any infrastructure, support online and air-gapped installation. Learn more.
🔗 Kubernetes Multi-cluster Management Provide a centralized control plane to manage multiple Kubernetes clusters, and support the ability to propagate an app to multiple K8s clusters across different cloud providers.
🤖 Kubernetes DevOps Provide GitOps-based CD solutions and use Argo CD to provide the underlying support, collecting CD status information in real time. With the mainstream CI engine Jenkins integrated, DevOps has never been easier. Learn more.
🔎 Cloud Native Observability Multi-dimensional monitoring, events and auditing logs are supported; multi-tenant log query and collection, alerting and notification are built-in. Learn more.
🌐 Service Mesh (Istio-based) Provide fine-grained traffic management, observability and tracing for distributed microservice applications, provides visualization for traffic topology. Learn more.
💻 App Store Provide an App Store for Helm-based applications, and offer application lifecycle management on Kubernetes platform. Learn more.
💡 Edge Computing Platform KubeSphere integrates KubeEdge to enable users to deploy applications on the edge devices and view logs and monitoring metrics of them on the console. Learn more.
🗃 Support Multiple Storage and Networking Solutions
  • Support GlusterFS, CephRBD, NFS, LocalPV solutions, and provide CSI plugins to consume storage from multiple cloud providers.
  • Provide Load Balancer Implementation OpenELB for Kubernetes in bare-metal, edge, and virtualization.
  • Provides network policy and Pod IP pools management, support Calico, Flannel, Kube-OVN
  • ..
    🏢 Multi-Tenancy Isolated workspaces with role-based access control ensure secure resource sharing across multiple tenants. Supports fine-grained permissions and quota management. Learn more.
    🧠 GPU Workloads Scheduling and Monitoring Create GPU workloads on the GUI, schedule GPU resources, and manage GPU resource quotas by tenant.

    Architecture

    KubeSphere 4.x adopts a microkernel + extension components architecture (codename LuBan). The core part (KubeSphere Core) only includes the essential basic functions required for system operation, with independent functional modules split and provided in the form of extension components. Users can dynamically manage the extension components during system operation. With the extension capabilities, KubeSphere can support more application scenarios and meet the needs of different users.

    Architecture


    Latest release

    🎉 KubeSphere v4.1.2 was released! It brings enhancements and better user experience, see the Release Notes For 4.1.2 for the updates.

    Installation

    KubeSphere can run anywhere from on-premise datacenter to any cloud to edge. In addition, it can be deployed on any version-compatible Kubernetes cluster. KubeSphere consumes very few resources, and you can optionally install additional extensions after installation.

    Quick start

    Installing on K8s

    Run the following commands to install KubeSphere on an existing Kubernetes cluster:

    helm upgrade --install -n kubesphere-system --create-namespace ks-core https://charts.kubesphere.io/main/ks-core-1.1.3.tgz --debug --wait
    

    KubeSphere for hosted Kubernetes services

    KubeSphere is hosted on the following cloud providers, and you can try KubeSphere by one-click installation on their hosted Kubernetes services.

    You can also install KubeSphere on other hosted Kubernetes services within minutes, see the step-by-step guides to get started.

    👨‍💻 No internet access? Refer to the Air-gapped Installation.

    Guidance, discussion, contribution, and support

    You can reach the KubeSphere community and developers via the following channels:

    :hugs: Please submit any KubeSphere bugs, issues, and feature requests to KubeSphere GitHub Issue.

    :heart_decoration: The KubeSphere team also provides efficient official ticket support to respond in hours. For more information, click KubeSphere Online Support.

    Contribution

    Code of conduct

    Participation in the KubeSphere community is governed by the Code of Conduct.

    Security

    The security process for reporting vulnerabilities is described in SECURITY.md.

    Who are using KubeSphere

    The user case studies page includes the user list of the project. You can leave a comment to let us know your use case.




        

    KubeSphere is a member of CNCF and a Kubernetes Conformance Certified platform , which enriches the CNCF CLOUD NATIVE Landscape.

    Agent / MCP / Skill 创作

    高风险

    • 来源需自行核对维护者身份。
    • 包含脚本或命令调用,安装前请复核。
    • 可能需要外部 token、网络权限或第三方服务。
    • 存在潜在风险命令,请谨慎安装。
    • 扫描发现:4 条。

    Codex — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/openpitrix" 文件夹复制到 Codex 的 skills 目录中。
    4. 重启 Codex 让新的 skill 生效。

    Codex — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Codex 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Codex 让新的 skill 生效。

    Claude Code — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/openpitrix" 文件夹复制到 Claude Code 的 skills 目录中。
    4. 重启 Claude Code 让新的 skill 生效。

    Claude Code — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Claude Code 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Claude Code 让新的 skill 生效。

    Cursor — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/openpitrix" 文件夹复制到 Cursor 的 skills 目录中。
    4. 重启 Cursor 让新的 skill 生效。

    Cursor — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Cursor 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Cursor 让新的 skill 生效。

    GitHub Copilot — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/openpitrix" 文件夹复制到 GitHub Copilot 的 skills 目录中。
    4. 重启 GitHub Copilot 让新的 skill 生效。

    GitHub Copilot — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 GitHub Copilot 让新的 skill 生效。

    Windsurf — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/openpitrix" 文件夹复制到 Windsurf 的 skills 目录中。
    4. 重启 Windsurf 让新的 skill 生效。

    Windsurf — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Windsurf 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Windsurf 让新的 skill 生效。
    查看 SKILL.md 原文
    name: openpitrix
    description: KubeSphere OpenPitrix application management Skill. Use when users ask about KubeSphere App Store, OpenPitrix, Helm/YAML application templates, application repositories, app versions, app releases, categories, review states, repository sync, or troubleshooting application installation and upgrade issues.

    OpenPitrix Application Management

    Overview

    OpenPitrix is KubeSphere's application management capability for app repositories, app templates, versions, reviews, and app releases. In KubeSphere 4.x the runtime API group is application.kubesphere.io/v2; older OpenPitrix extension code used openpitrix.io/v2 CRUD APIs and openpitrix.io/v2alpha1 read/list wrappers over application.kubesphere.io/v1alpha1 resources.

    Use the v2 objects and APIs first:

    ConceptKubeSphere 4.x objectOlder OpenPitrix object
    RepositoryRepoHelmRepo
    App templateApplicationHelmApplication
    App template versionApplicationVersionHelmApplicationVersion
    App release / installed appApplicationReleaseHelmRelease
    CategoryCategoryHelmCategory

    Core namespace and labels:

    ItemValue
    Application data namespaceextension-openpitrix
    Repository labelapplication.kubesphere.io/repo-name
    App labelapplication.kubesphere.io/app-id
    App version labelapplication.kubesphere.io/appversion-id
    App type labelapplication.kubesphere.io/app-type
    Cluster labelkubesphere.io/cluster
    Namespace labelkubesphere.io/namespace
    Workspace labelkubesphere.io/workspace

    Architecture

    Helm repo index or uploaded package
            |
            v
    Repo sync / upload API
            |
            v
    Application -> ApplicationVersion -> ApplicationRelease
                                          |
                                          v
                             Helm executor Job or YAML installer
                                          |
                                          v
                              Workloads in target cluster/namespace
    

    Important controllers:

    ControllerWatchesPurpose
    helmrepo-controllerRepoLoads Helm repository indexes, creates/deletes Application and ApplicationVersion, updates repository sync state.
    appversion-controllerApplicationVersionCleans stored chart/YAML data after version deletion when it is no longer used.
    apprelease-helminstallerApplicationReleaseCreates, upgrades, verifies, and uninstalls app releases through Helm executor Jobs or YAML installer logic.
    appcategory-controllerCategoryMaintains category counts and prevents deleting categories that still own apps.

    Navigation and Feature Coverage

    When the user says "应用商店", first identify whether they mean the enterprise-space app management pages or the global component-dock App Store management extension. They share the same OpenPitrix/KSE v2 resources, but the intent and scope differ.

    Enterprise-space application management under a workspace:

    Console areaTypical routeUser intentMain resource/API
    应用管理 / 应用/workspaces/{workspace}/deployList, create, edit, upgrade, or delete installed apps in projects.ApplicationRelease; /workspaces/{workspace}/applications, /namespaces/{namespace}/applications
    应用管理 / 自制应用workspace custom app areaWork with user-created/custom applications before or outside App Store publication.Usually app template/upload flows; verify against Application and ApplicationVersion before assuming release APIs.
    应用管理 / 应用模板/workspaces/{workspace}/app-templatesCreate/upload Helm or YAML app templates, edit template metadata, submit versions for review, manage versions.Application, ApplicationVersion; /workspaces/{workspace}/apps, /workspaces/{workspace}/apps/{app}/versions
    应用管理 / 应用仓库/workspaces/{workspace}/app-reposAdd, sync, inspect, or delete Helm repos available to the workspace.Repo; /workspaces/{workspace}/repos

    Component-dock App Store management:

    Console areaTypical routeUser intentMain resource/API
    组件坞 / 应用商店管理 / 应用/apps-manage/storePlatform-level App Store template list, publish/unpublish, edit metadata, delete, open detail pages.Application, ApplicationVersion; /workspaces/{workspace}/apps, /apps/{app}/action
    组件坞 / 应用商店管理 / 应用分类/apps-manage/categoriesCreate, edit, delete categories and assign applications to categories.Category; /categories, /workspaces/{workspace}/apps/{app}
    组件坞 / 应用商店管理 / 应用审核/apps-manage/reviewsReview uploaded app versions submitted from enterprise spaces.ApplicationVersion; /reviews, /workspaces/{workspace}/apps/{app}/versions/{version}/action
    组件坞 / 应用商店管理 / 应用仓库/apps-manage/repoManage global/platform view of App Store repositories.Repo; /workspaces/{workspace}/repos
    组件坞 / 应用商店管理 / 部署管理/apps-manage/deployManage installed app releases across workspace/cluster/namespace scope.ApplicationRelease; /workspaces/{workspace}/applications, /namespaces/{namespace}/applications

    Resource selection rules:

    • Use Application and ApplicationVersion for app templates, App Store listings, uploaded packages, version review, screenshots, metadata, and categories.
    • Use Repo for app repositories and repository sync.
    • Use Category for App Store category management.
    • Use ApplicationRelease only for installed/deployed apps, including workspace "应用" pages and platform "部署管理" pages.
    • Do not troubleshoot an App Store template with release Job/Pod commands unless the user is installing or upgrading an ApplicationRelease.
    • Uploaded/self-made app templates use the repository label value application.kubesphere.io/repo-name=upload. Do not write uploaded.
    • KSE v2 app and version action examples use {"state":"..."} with optional message, not legacy {"action":"..."}. Legacy openpitrix.io/v2 action APIs use action.
    • For kubectl get/describe of OpenPitrix application CRDs, do not add -n extension-openpitrix by default. These resources are queried by resource kind and labels; use labels such as kubesphere.io/workspace, application.kubesphere.io/repo-name, application.kubesphere.io/app-id, or application.kubesphere.io/app-release-name. Use extension-openpitrix only when inspecting extension component Pods or storage fallback objects.

    Tool Selection

    Choose the tool by task. Prefer the first matching option:

    ToolUse forAuthentication
    kubectlInspect CRDs/resources, events, controller state, executor Jobs/Pods/logs, and cluster-side troubleshooting.Uses the current kubeconfig.
    ks_api.pyKubeSphere JSON KAPIs under /kapis/...; recommended for create/update/list/action calls that send JSON.Run login once; token is cached in ~/.kubesphere_token.
    curlMultipart uploads, package/file downloads, custom headers, reproducing exact HTTP requests, or when the user explicitly asks for curl.Requires Authorization: Bearer $TOKEN; get the token with ks_api.py --login or set it manually.

    Set up ks_api.py first when using KubeSphere KAPIs:

    cd skills/kubesphere-core/scripts
    export KUBESPHERE_HOST="http://<kubesphere-host>"
    python ks_api.py --login --username admin --password <password>
    

    For curl, reuse the token cached by ks_api.py:

    export KUBESPHERE_HOST="http://<kubesphere-host>"
    export TOKEN=$(python -c 'import json, os; print(json.load(open(os.path.expanduser("~/.kubesphere_token")))["token"])')
    

    If ks_api.py is unavailable, obtain an OAuth token directly:

    export KUBESPHERE_HOST="http://<kubesphere-host>"
    export TOKEN=$(curl -sS -X POST "$KUBESPHERE_HOST/oauth/token" \
      -H "Content-Type: application/x-www-form-urlencoded" \
      -d "grant_type=password" \
      -d "username=<username>" \
      -d "password=<password>" \
      -d "client_id=kubesphere" \
      -d "client_secret=kubesphere" | jq -r '.access_token')
    

    Then pass -H "Authorization: Bearer $TOKEN" on every curl request to /kapis/....

    Quick Inspection

    Start with cluster resources before calling KAPIs:

    kubectl get repos.application.kubesphere.io
    kubectl get applications.application.kubesphere.io
    kubectl get applicationversions.application.kubesphere.io
    kubectl get applicationreleases.application.kubesphere.io
    kubectl get categories.application.kubesphere.io
    

    For workspace-scoped views, filter by workspace label:

    kubectl get repos.application.kubesphere.io \
      -l kubesphere.io/workspace=<workspace>
    
    kubectl get applications.application.kubesphere.io \
      -l kubesphere.io/workspace=<workspace>
    

    For an installed app:

    kubectl get applicationreleases.application.kubesphere.io \
      -l kubesphere.io/cluster=<cluster>,kubesphere.io/namespace=<namespace>
    
    kubectl describe applicationrelease.application.kubesphere.io <release-name>
    

    KAPI Routes

    Use /kapis/application.kubesphere.io/v2 in KubeSphere 4.x.

    Repository routes:

    OperationRoute
    List repositoriesGET /workspaces/{workspace}/repos
    Create repositoryPOST /workspaces/{workspace}/repos
    Update repositoryPATCH /workspaces/{workspace}/repos/{repo}
    Delete repositoryDELETE /workspaces/{workspace}/repos/{repo}
    Manual syncPOST /workspaces/{workspace}/repos/{repo}/action
    Repository eventsGET /workspaces/{workspace}/repos/{repo}/events

    App template routes:

    OperationRoute
    List appsGET /workspaces/{workspace}/apps
    Create uploaded appPOST /workspaces/{workspace}/apps
    Describe appGET /workspaces/{workspace}/apps/{app}
    Create/update app metadataPOST /workspaces/{workspace}/apps/{app}
    Patch metadataPATCH /workspaces/{workspace}/apps/{app}
    Delete appDELETE /workspaces/{workspace}/apps/{app}
    Review/action appPOST /apps/{app}/action

    Version and release routes:

    OperationRoute
    List versionsGET /workspaces/{workspace}/apps/{app}/versions
    Create versionPOST /workspaces/{workspace}/apps/{app}/versions
    Describe versionGET /workspaces/{workspace}/apps/{app}/versions/{version}
    Download packageGET /workspaces/{workspace}/apps/{app}/versions/{version}/package
    List chart/YAML filesGET /workspaces/{workspace}/apps/{app}/versions/{version}/files
    Review/action versionPOST /workspaces/{workspace}/apps/{app}/versions/{version}/action
    List releases by workspaceGET /workspaces/{workspace}/applications
    List releases by namespaceGET /namespaces/{namespace}/applications
    Create releasePOST /namespaces/{namespace}/applications
    Describe releaseGET /namespaces/{namespace}/applications/{application}
    Delete releaseDELETE /namespaces/{namespace}/applications/{application}

    App Store management routes:

    OperationRoute
    List categoriesGET /categories
    Create categoryPOST /categories
    Update categoryPOST /categories/{category}
    Describe categoryGET /categories/{category}
    Delete categoryDELETE /categories/{category}
    List app reviewsGET /reviews
    Upload attachmentPOST /workspaces/{workspace}/attachments
    Describe attachmentGET /workspaces/{workspace}/attachments/{attachment}
    Delete attachmentsDELETE /workspaces/{workspace}/attachments/{attachment}

    Older OpenPitrix extension routes use /kapis/openpitrix.io/v2alpha1, primarily as read/list wrappers around HelmRepo, HelmApplication, HelmApplicationVersion, HelmRelease, and HelmCategory.

    Assume KUBESPHERE_HOST, ks_api.py login, and TOKEN have already been set up from Tool Selection before using the examples below.

    KSE Application API examples

    Use these examples for KubeSphere 4.x application.kubesphere.io/v2.

    # Create or update repository.
    python ks_api.py POST /kapis/application.kubesphere.io/v2/workspaces/<workspace>/repos '{
      "metadata": {
        "name": "<repo-name>",
        "labels": {
          "kubesphere.io/workspace": "<workspace>"
        },
        "annotations": {
          "kubesphere.io/display-name": "<display-name>"
        }
      },
      "spec": {
        "url": "https://example.com/charts",
        "description": "<description>",
        "syncPeriod": 0
      }
    }'
    
    # Manually trigger repository sync.
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/repos/<repo-name>/action
    
    # List apps in a workspace.
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps
    
    # Describe an app and list versions.
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>
    
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>/versions
    
    # Review or publish an app version.
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>/versions/<version>/action \
      '{"state":"active","message":"publish"}'
    
    # App-level publish/suspend/recover actions also use state, not legacy action.
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/apps/<app>/action \
      '{"state":"suspended","message":"suspend from App Store"}'
    
    # Create or update an application release.
    # Important:
    # - Use /namespaces/<namespace>/applications, not /workspaces/<workspace>/namespaces/<namespace>/applications.
    # - Required release references are spec.appID, spec.appVersionID, spec.appType, and labels.
    # - Do not invent spec.name or spec.namespace; release name and namespace are metadata/path concerns.
    # - spec.values is a JSON []byte field: use "" for empty values, or base64-encoded YAML bytes for non-empty values. Do not use {}.
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/namespaces/<namespace>/applications '{
        "metadata": {
          "name": "<release-name>",
          "labels": {
            "application.kubesphere.io/app-id": "<app-id>",
            "application.kubesphere.io/appversion-id": "<app-version-id>",
            "application.kubesphere.io/app-type": "helm",
            "kubesphere.io/cluster": "<cluster>",
            "kubesphere.io/namespace": "<namespace>",
            "kubesphere.io/workspace": "<workspace>"
          },
          "annotations": {
            "kubesphere.io/creator": "<username>"
          }
        },
        "spec": {
          "appID": "<app-id>",
          "appVersionID": "<app-version-id>",
          "appType": "helm",
          "values": ""
        }
      }'
    
    # List or describe releases in a namespace.
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/namespaces/<namespace>/applications
    
    # Or list releases by workspace.
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/applications
    
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/namespaces/<namespace>/applications/<release-name>
    
    # Categories and reviews.
    python ks_api.py GET /kapis/application.kubesphere.io/v2/categories
    python ks_api.py GET /kapis/application.kubesphere.io/v2/reviews
    

    Use curl only when the API needs multipart upload, streaming download, or custom headers that ks_api.py does not support.

    Curl equivalents for JSON KAPIs:

    export KUBESPHERE_HOST="http://<kubesphere-host>"
    export TOKEN="<kubesphere-access-token>"
    
    # Create or update repository.
    curl -sS -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/repos" \
      -H "Authorization: Bearer $TOKEN" \
      -H "Content-Type: application/json" \
      -d '{
        "metadata": {
          "name": "<repo-name>",
          "labels": {
            "kubesphere.io/workspace": "<workspace>"
          },
          "annotations": {
            "kubesphere.io/display-name": "<display-name>"
          }
        },
        "spec": {
          "url": "https://example.com/charts",
          "description": "<description>",
          "syncPeriod": 0
        }
      }'
    
    # Manually trigger repository sync.
    curl -sS -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/repos/<repo-name>/action" \
      -H "Authorization: Bearer $TOKEN" \
      -H "Content-Type: application/json" \
      -d '{}'
    
    # For KSE v2 repository sync, use an empty JSON body or omit the body.
    # Do not send legacy {"action":"sync"} or {"action":"index"} unless using openpitrix.io/v2.
    
    # List apps in a workspace.
    curl -sS \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps" \
      -H "Authorization: Bearer $TOKEN"
    
    # Publish or review an app version.
    curl -sS -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>/versions/<version>/action" \
      -H "Authorization: Bearer $TOKEN" \
      -H "Content-Type: application/json" \
      -d '{"state":"active","message":"publish"}'
    
    # Create or update an application release.
    # Keep the body shape aligned with ApplicationReleaseSpec. Do not add spec.name/spec.namespace.
    # Use values: "" for empty values; do not use values: {}.
    curl -sS -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/namespaces/<namespace>/applications" \
      -H "Authorization: Bearer $TOKEN" \
      -H "Content-Type: application/json" \
      -d '{
        "metadata": {
          "name": "<release-name>",
          "labels": {
            "application.kubesphere.io/app-id": "<app-id>",
            "application.kubesphere.io/appversion-id": "<app-version-id>",
            "application.kubesphere.io/app-type": "helm",
            "kubesphere.io/cluster": "<cluster>",
            "kubesphere.io/namespace": "<namespace>",
            "kubesphere.io/workspace": "<workspace>"
          }
        },
        "spec": {
          "appID": "<app-id>",
          "appVersionID": "<app-version-id>",
          "appType": "helm",
          "values": ""
        }
      }'
    

    Legacy OpenPitrix API examples

    Use these only when the installed OpenPitrix extension exposes the old openpitrix.io KAPIs. Prefer application.kubesphere.io/v2 for KubeSphere 4.x. The legacy request/response fields use OpenPitrix-style snake_case names such as repo_id, version_id, sync_period, and app_default_status.

    Read/list wrappers from /kapis/openpitrix.io/v2alpha1:

    # Repositories.
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/repos
    
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/repos/<repo-id>
    
    # App templates and versions.
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/apps
    
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/apps/<app-id>
    
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/apps/<app-id>/versions
    
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/apps/<app-id>/versions/<version-id>
    
    # Installed applications.
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/clusters/<cluster>/namespaces/<namespace>/applications
    
    python ks_api.py GET \
      /kapis/openpitrix.io/v2alpha1/workspaces/<workspace>/clusters/<cluster>/namespaces/<namespace>/applications/<application-id>
    
    # Categories.
    python ks_api.py GET /kapis/openpitrix.io/v2alpha1/categories
    python ks_api.py GET /kapis/openpitrix.io/v2alpha1/categories/<category-id>
    

    Older CRUD-style APIs from /kapis/openpitrix.io/v2:

    # Create repository. Use validate=true to validate without persisting.
    python ks_api.py POST \
      /kapis/openpitrix.io/v2/workspaces/<workspace>/repos?validate=true '{
        "name": "<repo-name>",
        "url": "https://example.com/charts",
        "type": "helm",
        "visibility": "public",
        "providers": ["kubernetes"],
        "sync_period": "0s",
        "app_default_status": "active",
        "credential": ""
      }'
    
    # Trigger repository indexing/sync.
    python ks_api.py POST \
      /kapis/openpitrix.io/v2/workspaces/<workspace>/repos/<repo-id>/action \
      '{"action":"index","workspace":"<workspace>"}'
    
    # Create an app template from a base64-encoded chart package.
    python ks_api.py POST \
      /kapis/openpitrix.io/v2/workspaces/<workspace>/apps '{
        "name": "<app-name>",
        "version_name": "0.1.0",
        "version_type": "helm",
        "version_package": "<base64-chart-tgz>"
      }'
    
    # Create another version for an existing app.
    python ks_api.py POST \
      /kapis/openpitrix.io/v2/workspaces/<workspace>/apps/<app-id>/versions '{
        "app_id": "<app-id>",
        "name": "0.2.0",
        "type": "helm",
        "package": "<base64-chart-tgz>"
      }'
    
    # Submit, pass, reject, suspend, recover, or activate an app version.
    python ks_api.py POST \
      /kapis/openpitrix.io/v2/workspaces/<workspace>/apps/<app-id>/versions/<version-id>/action \
      '{"action":"submit","message":"submit for review"}'
    
    # Deploy an app release.
    python ks_api.py POST \
      /kapis/openpitrix.io/v2/workspaces/<workspace>/clusters/<cluster>/namespaces/<namespace>/applications '{
        "name": "<release-name>",
        "app_id": "<app-id>",
        "version_id": "<version-id>",
        "runtime_id": "<cluster>",
        "conf": "{}",
        "advanced_param": []
      }'
    

    App Store and Workspace App Management Workflow

    KubeSphere's OpenPitrix extension serves both enterprise-space application management and component-dock App Store management. Map the console area to the KSE v2 APIs before choosing commands:

    UI areaMain purposePrimary APIs
    /workspaces/{workspace}/deployEnterprise-space installed apps./workspaces/{workspace}/applications, /namespaces/{namespace}/applications
    /workspaces/{workspace}/app-templatesEnterprise-space app templates created from Helm/YAML packages./workspaces/{workspace}/apps, /workspaces/{workspace}/apps/{app}/versions, /workspaces/{workspace}/attachments
    /workspaces/{workspace}/app-reposEnterprise-space app repositories./workspaces/{workspace}/repos
    /apps-manage/storeManage application templates in the App Store: list, create/upload, edit metadata, delete, open detail pages./workspaces/{workspace}/apps, /workspaces/{workspace}/apps/{app}, /workspaces/{workspace}/attachments
    /apps-manage/store/{app}Inspect template details, versions, audit records, and deployed instances./workspaces/{workspace}/apps/{app}, /workspaces/{workspace}/apps/{app}/versions, /workspaces/{workspace}/applications
    /apps-manage/categoriesManage categories and assign apps to categories./categories, /categories/{category}, /workspaces/{workspace}/apps/{app}
    /apps-manage/reviewsReview uploaded app versions./reviews, /workspaces/{workspace}/apps/{app}/versions/{version}/action
    /apps-manage/repoManage Helm repositories that feed App Store templates./workspaces/{workspace}/repos
    /apps-manage/deployManage installed app releases./namespaces/{namespace}/applications, /workspaces/{workspace}/applications

    List and filter behavior:

    • App template and App Store pages list Application templates, not installed ApplicationRelease objects.
    • Workspace "应用" and App Store "部署管理" pages list installed ApplicationRelease objects.
    • The UI filters list queries through KubeSphere list query parameters such as conditions, status, order, limit, and workspace query scope.
    • Public store display commonly focuses on active|suspended apps; management views include draft, passed, active, and suspended states.
    • Uploaded apps are identified with application.kubesphere.io/repo-name=upload.

    Inspect app templates:

    python ks_api.py GET \
      "/kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps?conditions=status=draft|active|suspended|passed&sortBy=create_time"
    
    kubectl get applications.application.kubesphere.io \
      -l kubesphere.io/workspace=<workspace>
    

    Inspect installed apps/releases:

    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/applications
    
    python ks_api.py GET \
      /kapis/application.kubesphere.io/v2/namespaces/<namespace>/applications
    
    kubectl get applicationreleases.application.kubesphere.io \
      -l kubesphere.io/workspace=<workspace>
    

    Patch app template metadata. This is how the enterprise-space template page and App Store management page edit alias, description, icon, category, screenshots/attachments, abstraction, and home URL:

    python ks_api.py PATCH \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app> '{
        "aliasName": "<display-name>",
        "description": "<description>",
        "categoryName": "<category>",
        "icon": "<base64-icon-or-url>",
        "attachments": ["<attachment-id>"],
        "abstraction": "<short-summary>",
        "appHome": "https://example.com"
      }'
    

    The patch handler writes these fields to:

    Request fieldStored as
    categoryNamemetadata.labels["application.kubesphere.io/app-category-name"]
    aliasNamemetadata.annotations["kubesphere.io/display-name"]
    descriptionmetadata.annotations["kubesphere.io/description"]
    iconspec.icon
    attachmentsspec.attachments
    abstractionspec.abstraction
    appHomespec.appHome

    Manage attachments for App Store screenshots and other assets. This API is multipart, so prefer curl with the bearer token:

    curl -sS -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/attachments" \
      -H "Authorization: Bearer $TOKEN" \
      -F "file=@./screenshot.png"
    
    curl -sS \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/attachments/<attachment-id>" \
      -H "Authorization: Bearer $TOKEN"
    
    curl -sS -X DELETE \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/attachments/<attachment-id>" \
      -H "Authorization: Bearer $TOKEN"
    

    Manage categories:

    python ks_api.py GET /kapis/application.kubesphere.io/v2/categories
    
    python ks_api.py POST /kapis/application.kubesphere.io/v2/categories '{
      "metadata": {
        "name": "<category>",
        "annotations": {
          "kubesphere.io/display-name": "<display-name>",
          "kubesphere.io/description": "<description>"
        }
      },
      "spec": {
        "icon": "database"
      }
    }'
    
    python ks_api.py POST /kapis/application.kubesphere.io/v2/categories/<category> '{
      "metadata": {
        "name": "<category>",
        "annotations": {
          "kubesphere.io/display-name": "<display-name>",
          "kubesphere.io/description": "<description>"
        }
      },
      "spec": {
        "icon": "database"
      }
    }'
    
    python ks_api.py DELETE /kapis/application.kubesphere.io/v2/categories/<category>
    

    Do not delete kubesphere-app-uncategorized, and do not delete a category whose status.total is greater than zero. To move apps between categories, patch each app's categoryName through /workspaces/{workspace}/apps/{app}.

    Review uploaded app versions:

    python ks_api.py GET \
      "/kapis/application.kubesphere.io/v2/reviews?conditions=status=submitted"
    
    python ks_api.py GET \
      "/kapis/application.kubesphere.io/v2/reviews?conditions=status=active|rejected|passed|submitted|suspended"
    
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>/versions/<version>/action \
      '{"state":"passed","message":"approve"}'
    
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>/versions/<version>/action \
      '{"state":"rejected","message":"reject reason"}'
    

    /reviews lists uploaded app versions only; the handler selects versions whose repo label is application.kubesphere.io/repo-name=upload. If a review item is missing, first verify that the ApplicationVersion belongs to the upload repo and is in a review state such as submitted.

    Important KSE v2 App Store API shapes:

    # Correct uploaded/self-made template label.
    kubectl get applicationversions.application.kubesphere.io \
      -l application.kubesphere.io/repo-name=upload
    
    # Correct category create/update body is a Category object.
    python ks_api.py POST /kapis/application.kubesphere.io/v2/categories '{
      "metadata": {
        "name": "<category>",
        "annotations": {
          "kubesphere.io/display-name": "<display-name>",
          "kubesphere.io/description": "<description>"
        }
      },
      "spec": {
        "icon": "database"
      }
    }'
    
    # Correct repository create/update body is a Repo object shape.
    python ks_api.py POST /kapis/application.kubesphere.io/v2/workspaces/<workspace>/repos '{
      "metadata": {
        "name": "<repo-name>",
        "labels": {
          "kubesphere.io/workspace": "<workspace>"
        },
        "annotations": {
          "kubesphere.io/display-name": "<display-name>"
        }
      },
      "spec": {
        "url": "https://example.com/charts",
        "description": "<description>",
        "syncPeriod": 0
      }
    }'
    
    # Correct KSE v2 review/action body uses state.
    python ks_api.py POST \
      /kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps/<app>/versions/<version>/action \
      '{"state":"passed","message":"approve"}'
    

    Avoid these common mistakes for application.kubesphere.io/v2:

    • Do not use application.kubesphere.io/repo-name=uploaded; the built-in upload repo key is upload.
    • Do not send top-level category bodies such as {"name":"...","displayName":"..."}; send a Category object with metadata and spec.
    • Do not send top-level repo bodies such as {"name":"...","url":"..."}; send a Repo object with metadata and spec.
    • Do not send {"action":"approve"}, {"action":"reject"}, or {"action":"sync"} to KSE v2 action routes; use state for app/version actions and an empty body for repository manual sync.

    Repository Workflow

    Create or update a repository with a valid Helm repository URL. The API validates the URL by loading the repository index before persisting it. User info embedded in the URL is copied into spec.credential.

    apiVersion: application.kubesphere.io/v2
    kind: Repo
    metadata:
      name: <repo-name>
      labels:
        kubesphere.io/workspace: <workspace>
      annotations:
        kubesphere.io/display-name: <display-name>
    spec:
      url: https://example.com/charts
      description: <description>
      syncPeriod: 0
    

    Sync behavior:

    • spec.syncPeriod: 0 means no periodic sync.
    • Manual sync sets status.state to manualTrigger.
    • Successful sync sets status.state to successful.
    • Repo sync creates app IDs as <repo-name>-<short-hash-of-chart-name>.
    • Repo versions become active automatically because they came from a trusted repository.

    Troubleshoot repository sync:

    kubectl describe repo.application.kubesphere.io <repo-name>
    kubectl get events --field-selector involvedObject.name=<repo-name>
    kubectl logs -n kubesphere-system deploy/ks-controller-manager \
      | grep -E "helmrepo-controller|<repo-name>"
    

    Common checks:

    • Confirm .spec.url has a reachable index.yaml.
    • Confirm credentials, CA, cert/key, and insecureSkipTLSVerify when using private HTTPS repositories.
    • If apps disappeared after sync, check whether the chart was removed from the upstream index; the controller deletes apps no longer present for that repo.
    • If sync loops, check whether the workspace label points to a deleted WorkspaceTemplate; the controller deletes workspace repos for deleted workspaces.

    Uploaded App Workflow

    Uploaded apps are stored as Repo=upload and start in review state draft. Helm charts and YAML packages share the same API path; appType distinguishes helm and yaml.

    Validation-only upload:

    Authenticate through KubeSphere first. Prefer the kubesphere-core ks_api.py helper for JSON KAPIs because it handles login and cached tokens consistently with other KubeSphere skills. File uploads are multipart requests, so use ks_api.py to login and then curl with the cached token:

    cd skills/kubesphere-core/scripts
    export KUBESPHERE_HOST="http://<kubesphere-host>"
    python ks_api.py --login --username admin --password <password>
    
    TOKEN=$(python -c 'import json, os; print(json.load(open(os.path.expanduser("~/.kubesphere_token")))["token"])')
    
    curl -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps?validate=true" \
      -H "Authorization: Bearer $TOKEN" \
      -H "Content-Type: multipart/form-data" \
      -F 'jsonData={"appType":"helm","workspace":"<workspace>"}' \
      -F "file=@./chart.tgz"
    

    If the helper is unavailable, use curl with an explicit bearer token:

    TOKEN=<kubesphere-access-token>
    curl -X POST \
      "$KUBESPHERE_HOST/kapis/application.kubesphere.io/v2/workspaces/<workspace>/apps?validate=true" \
      -H "Authorization: Bearer $TOKEN" \
      -H "Content-Type: multipart/form-data" \
      -F 'jsonData={"appType":"helm","workspace":"<workspace>"}' \
      -F "file=@./chart.tgz"
    

    After upload:

    kubectl get applications.application.kubesphere.io \
      -l application.kubesphere.io/repo-name=upload,kubesphere.io/workspace=<workspace>
    
    kubectl get applicationversions.application.kubesphere.io \
      -l application.kubesphere.io/repo-name=upload,application.kubesphere.io/app-id=<app>
    

    Review states:

    StateMeaning
    draftUploaded but not published.
    submittedSubmitted for review.
    passedReview passed.
    activePublished/visible.
    rejectedReview rejected.
    suspendedTemporarily hidden.

    Use app or version action routes to move review state. App activation requires at least one active or passed version.

    Release Workflow

    An ApplicationRelease installs a selected ApplicationVersion into a target cluster and namespace.

    Minimal Helm release object:

    apiVersion: application.kubesphere.io/v2
    kind: ApplicationRelease
    metadata:
      name: <release-name>
      labels:
        application.kubesphere.io/app-id: <app-id>
        application.kubesphere.io/appversion-id: <app-version-id>
        application.kubesphere.io/app-type: helm
        kubesphere.io/cluster: <cluster>
        kubesphere.io/namespace: <namespace>
        kubesphere.io/workspace: <workspace>
      annotations:
        kubesphere.io/creator: <username>
    spec:
      appID: <app-id>
      appVersionID: <app-version-id>
      appType: helm
      values: <base64-or-api-provided-bytes>
    

    Release states:

    StateMeaning
    creatingFirst reconciliation started.
    createdHelm/YAML executor Job was created.
    upgradingSpec changed and upgrade started.
    upgradedUpgrade Job was created.
    activeHelm release deployed or YAML install completed.
    timeoutHelm reported timeout; controller performs limited rechecks.
    deployFailedExecutor Job failed or disappeared.
    failedHelm/YAML install, upgrade, or status verification failed.
    deletingUninstall started.
    clusterDeletedTarget cluster was deleted.

    Troubleshoot releases:

    kubectl describe applicationrelease.application.kubesphere.io <release-name>
    
    TARGET_NS=$(kubectl get applicationrelease.application.kubesphere.io <release-name> \
      -o jsonpath="{.metadata.labels['kubesphere.io/namespace']}")
    
    kubectl -n "$TARGET_NS" get jobs \
      -l application.kubesphere.io/app-release-name=<release-name>
    
    kubectl -n "$TARGET_NS" get pods \
      -l application.kubesphere.io/app-release-name=<release-name>
    

    Always prefer the application.kubesphere.io/app-release-name=<release-name> label selector for executor Jobs and Pods. Do not use broad kubectl get jobs -A | grep <release-name> or kubectl get pods -A | grep <release-name> as the primary path; use grep only as a fallback when labels are missing or suspected to be wrong.

    Then inspect the executor Job pod logs:

    POD=$(kubectl -n "$TARGET_NS" get pods \
      -l application.kubesphere.io/app-release-name=<release-name> \
      -o jsonpath='{.items[0].metadata.name}')
    
    kubectl -n "$TARGET_NS" logs "$POD" --all-containers
    

    Common checks:

    • Ensure spec.appVersionID exists and points to an ApplicationVersion.
    • Ensure target cluster and namespace labels are correct; missing namespace defaults to default, missing cluster defaults to host.
    • For Helm apps, check whether stored chart data can be loaded from S3 or the ConfigMap fallback.
    • For YAML apps, verify spec.values contains valid YAML documents and the target cluster RESTMapper recognizes every GVR.
    • For upgrade loops, compare .status.specHash with the current .spec; spec changes drive upgrades.
    • For timeout, inspect annotation application.kubesphere.io/timeout-recheck; the controller only performs limited timeout rechecks.

    Categories

    Categories are cluster-scoped resources. Application category is carried by application.kubesphere.io/app-category-name; uncategorized apps use kubesphere-app-uncategorized.

    kubectl get categories.application.kubesphere.io
    kubectl get applications.application.kubesphere.io \
      -l application.kubesphere.io/app-category-name=<category>
    

    Do not delete a category until no applications reference it.

    Development Notes

    When changing implementation:

    • Prefer application.kubesphere.io/v2 CRDs and KAPIs for new KubeSphere code.
    • Keep backward compatibility in mind when touching older OpenPitrix extension paths under /kapis/openpitrix.io/v2 and /kapis/openpitrix.io/v2alpha1.
    • Preserve the object relationship: Repo owns synced apps, Application owns versions, and releases reference app/version through labels and spec fields.
    • Status updates are subresource updates or merge patches; avoid normal spec updates for status-only changes.
    • Uploaded package storage uses S3 when configured and falls back to ConfigMaps in extension-openpitrix.
    • Keep review state transitions consistent with app and app-version action handlers.

    发现问题?提交给管理员复核

    评分:

    评论 (0)

    暂无评论,成为第一个评论者吧!