skaffold-testing

v2026.09.24

Container image validation with Skaffold test/verify stages — container-structure-tests, security scans. Use when configuring pre-deploy tests or integration tests in Skaffold.

GitHub
Install command
npx skhub add laurigates/skaffold-testing
Markdown
SKILL.md

Skaffold Testing

When to Use This Skill

Use this skill when...Use another skill instead when...
Configuring container-structure-testsWriting Dockerfiles (use container skills)
Adding security scans to Skaffold pipelinesGeneral Skaffold build/deploy (use skaffold-development)
Setting up post-deploy verificationUnit testing application code
Validating image contents pre-deployKubernetes manifest authoring

Testing Lifecycle

Build -> Test -> Deploy -> Verify
          ^                  ^
     Pre-deploy         Post-deploy
StagePurposeRuns During
testValidate images before deploymentdev, run, test
verifyValidate deployment works correctlydev, run, verify

Failed tests block deployment. Use --skip-tests to bypass.

Test Stage Overview

Two mechanisms for pre-deploy validation:

TypePurposeTool Required
structureTestsValidate image contentscontainer-structure-test binary
customRun arbitrary commandsNone (uses $IMAGE env var)

Container Structure Tests

Validate image contents without running the container.

Configuration

apiVersion: skaffold/v4beta11
kind: Config
test:
  - image: my-app
    structureTests:
      - ./tests/structure/*.yaml
    structureTestsArgs:
      - --driver=tar      # Faster, no Docker daemon needed
      - -q                # Quiet output

Test Types Summary

TypePurposeKey Fields
commandTestsVerify binaries workcommand, args, expectedOutput, exitCode
fileExistenceTestsVerify files present/absentpath, shouldExist, permissions, uid, gid
fileContentTestsValidate file contentspath, expectedContents, excludedContents
metadataTestValidate image configenvVars, user, entrypoint, cmd, exposedPorts, workdir

Custom Tests

Run arbitrary commands with access to built image via $IMAGE env var.

test:
  - image: my-app
    custom:
      - command: grype $IMAGE --fail-on high --only-fixed
        timeoutSeconds: 300
      - command: trivy image --exit-code 1 --severity HIGH,CRITICAL $IMAGE
        timeoutSeconds: 300

Dependencies

Control when tests re-run:

custom:
  - command: ./scripts/integration-test.sh
    timeoutSeconds: 600
    dependencies:
      paths:
        - "src/**/*.go"
        - "go.mod"
      ignore:
        - "**/*_test.go"

Verify Stage (Post-Deploy)

Run integration tests after deployment succeeds.

Execution Modes

ModeEnvironmentUse Case
local (default)Docker on hostQuick tests, local dev
kubernetesClusterK8s JobIntegration tests needing cluster access

Basic Configuration

verify:
  - name: health-check
    container:
      name: curl-test
      image: curlimages/curl:latest
      command: ["/bin/sh"]
      args: ["-c", "curl -f http://my-app.default.svc:8080/health"]
    executionMode:
      kubernetesCluster: {}

Agentic Optimizations

ContextCommand
Quick structure testcontainer-structure-test test --driver=tar -q --image $IMAGE --config tests/structure/security.yaml
Security scan (critical only)grype $IMAGE --fail-on critical -q
Skip tests in devskaffold dev --skip-tests
Run only testsskaffold test
Run only verifyskaffold verify
CI with JUnit outputcontainer-structure-test test --image $IMAGE --config test.yaml --test-report junit.xml

Quick Reference

Container Structure Test Flags

FlagDescription
--driver=tarUse tar driver (faster, no Docker daemon)
--driver=dockerUse Docker driver (default)
-qQuiet output
--test-report FILEGenerate test report
--output jsonJSON output format

Skaffold Test Flags

FlagDescription
--skip-testsSkip test phase
-p PROFILEUse specific profile
--build-artifacts FILEUse pre-built artifacts

Custom Test Environment

VariableDescription
$IMAGEBuilt image with tag/digest

For detailed examples, advanced patterns, and best practices, see REFERENCE.md.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

container-plugin/skills/skaffold-testing

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3