# Create and Manage mirrord Preview Environments

Reviewing service changes in a shared Kubernetes cluster requires careful traffic routing and cleanup. This skill guides mirrord preview configuration, reviewer links, and pull request workflows.

## Install

```bash
npx skillstore add metalbear-co/mirrord-prev-env
```

## Metadata

- Status: approved
- Slug: metalbear-co-mirrord-prev-env
- Version: 2.5
- Author version: 2.5
- Skillstore revision: r1
- Version status: invalid
- Tree hash: 08a04f1c0895961601a269c06d8793c922342be0534628fa2a8c05dfcd649dcf
- Author: metalbear-co
- GitHub username: metalbear-co
- License: MIT
- Repository: https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-prev-env
- Ref: bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: confirmation\_required
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, filesystem, network, env\_access
- Quality score: 38
- Quality tier: warning
- Public page: https://skillstore.pages.dev/skills/metalbear-co-mirrord-prev-env
- Manifest: https://skillstore.pages.dev/api/skills/metalbear-co-mirrord-prev-env/manifest

## Capabilities

- Guide preview start, status, logs, replacement, and teardown commands with documented version requirements.
- Draft preview configuration for targets, traffic filters, expiration, and creation timeouts.
- Explain header propagation across HTTP, gRPC, Kafka, and SQS.
- Outline pull request workflows using the mirrord-preview Action or direct CLI calls.
- Explain share-ingress setup, TLS prerequisites, and authenticated stable preview hosts.
- Troubleshoot image pulls, routing failures, CronJob restrictions, and queue-only previews for scaled-to-zero workloads.

## Use Cases

- Validate a Backend Change: Prepare a staging preview for a built image, route selected requests, inspect failures, and define cleanup.
- Standardize Pull Request Previews: Design trusted-PR deployment workflows with scoped authentication, stable session keys, finite expiration, and close-event teardown.
- Review Changes Through a Browser: Coordinate authenticated preview links and verify header propagation so reviewers can exercise the intended service version.

## Prompt Templates

### Check Preview Prerequisites

```
Help me prepare my first mirrord staging preview. Ask for my operator version, CLI version, license, target, image, and cluster access before suggesting commands.
```

### Configure a Developer Preview

```
Draft preview configuration for [target] in [namespace] using [image] and key [key]. Include an exact-key traffic filter, finite TTL, validation, logs, and teardown.
```

### Prepare Reviewer Access

```
Plan authenticated share-ingress access for previews under [domain]. Explain DNS, TLS, header propagation, stable-host tradeoffs, and expiration without installing anything.
```

### Design a Hardened PR Workflow

```
Draft a mirrord preview workflow for [repository] and [staging target]. Use trusted-PR gates, pinned Actions, verified CLI, short-lived authentication, exact-key filters, finite TTL, concurrency, and close-event cleanup.
```

## Limitations

- Requires an Enterprise plan or qualifying trial, supported mirrord versions, cluster access, and a built container image.
- Provides guidance and examples, not bundled deployment software; commands require your installed tools and permissions.
- Traffic filtering does not isolate every dependency or data write; use staging targets and review shared-resource access.
- CI and filter examples need security hardening before reuse; ingress authentication and infrastructure remain platform responsibilities.

## Best Practices

- Use trusted images on staging targets, complete-key traffic filters, finite TTLs, and explicit teardown.
- Gate CI on trusted contributions; pin Actions and use verified CLI binaries with short-lived, least-privilege cluster credentials.
- Authenticate reviewer links and test header propagation through every participating service.

## Anti Patterns

- Deploying untrusted PR images into a credentialed shared cluster or targeting production.
- Treating routing headers, random hostnames, or shared dependencies as complete security isolation.
- Copying mutable Action references, persistent tokens, or prefix-matching filters without review.

## Security Audit

- Audited at: 2026-09-29T21:57:00.123\+00:00
- Summary: All 162 static matches are false positives involving Markdown syntax, documentation links, or expected setup operations. Four contextual risks remain: persistent CI credentials, mutable Action references, a missing trusted-PR guard, and traffic filters that match key prefixes. No evidence found of prompt injection, credential exfiltration, or malicious intent in the two reviewed files.

## Stats

- Views: 0
- Downloads: 2
- Favorites: 0
- Popularity score: 0
