Kubernetes ExternalDNS Cross-Check
Compare Kubernetes service intent with Cloudflare DNS records to diagnose ExternalDNS drift.
@Aident2,645278Updated Aug 12, 2026
Works with
name: kubernetes-externaldns-cross-check description: "Compare Kubernetes service intent with Cloudflare DNS records to diagnose ExternalDNS drift."
Kubernetes ExternalDNS Cross-Check
Compare Kubernetes service intent with Cloudflare DNS records to diagnose ExternalDNS drift.
Required Aident Actions
- <action-tag>composio:cloudflare_tools:cloudflare_list_zones</action-tag> (required inputs: inspect the current schema): Lists, searches, sorts, and filters zones in the authenticated account. Use
page/per_pageto paginate; checkresult_info.total_pagesin the response to iterate all pages. Does not return DNS records - extract... - <action-tag>composio:cloudflare_tools:cloudflare_list_dns_records</action-tag> (required inputs: zone_id): Tool to list and search DNS records in a Cloudflare zone. Use when you need to find existing DNS record IDs for update or delete operations, especially after a "record already exists" error during creation. Returns...
- <action-tag>cli:kubectl:get_services</action-tag>Action · List Zonesction-tag>cli:kubectl:get_deployments</action-tag> (required inputs: namespace): List deployments in a namespace (JSON).
- <action-tag>cli:kubectl:get_pods</action-tag> (required inputs: namespace): List pods in a namespace (JSON).
Use Aident Loadout to read the currAction · List Dns Recordsonnection in Aident Vault. If an Action is billable or mutating, run Aident preflight, show the affected target and quoted cost or risk, and wait for explicit user confirmation before execution.
Workflow
- Confirm the requested outcome, sourceAction · Get Servicesd acceptance criteria.
- Apply the source-derived guidance below to cAction · Get Deploymentsking an Action.
- Select only the Aident Actions whose documented effectAction · Get Podsnot invoke every listed Action by default.
- Inspect the current schema and prepare the minimum valid input for each selected Action.
- Preflight each selected Action. Execute it only after any required confirmation, in dependency order, and carry returned IDs or asset URLs into later steps.
- Verify the returned IDs, URLs, statuses, or artifacts against the acceptance criteria. Report partial completion precisely and do not repeat paid or mutating calls blindly.
Source-Derived Guidance
- Confirm namespace, service hostname, and Cloudflare zone before comparing state.
- Report missing, stale, or conflicting records and the Kubernetes evidence behind each finding.
Execution Boundaries
- Treat upstream provider-specific commands as background knowledge only. Execute the workflow through the exact Aident Actions above.
- Never request raw credentials in chat. Use Aident Vault connection flows for required accounts.
- Preserve user-provided wording, brand constraints, rights restrictions, and target identifiers. Do not invent authorization.
- Read current state before a mutation, state the exact target, and include a rollback or recovery step in the result.
- Stop when a required integration is disconnected, preflight rejects the input, the target is ambiguous, or the user declines a required confirmation.
Output
Return the execution plan, selected Action names, confirmed targets, Aident result identifiers or asset URLs, verification evidence, and any remaining blocked step.
Attribution
This Skill adapts the reviewed upstream workflow. See for the pinned source and for the preserved license.