Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
akin-ozer avatar

Fluentbit Validator

  • 371 installs
  • 286 repo stars
  • Updated July 26, 2026
  • akin-ozer/cc-devops-skills

fluentbit-validator is a Claude Code DevOps skill that statically lints and dry-runs Fluent Bit classic-mode configs for INPUT, FILTER, OUTPUT, and tag routing before Kubernetes or VM log collector rollout.

About

fluentbit-validator is an agent skill in akin-ozer/cc-devops-skills for deterministic Fluent Bit config review. Stage 0 checks `python3` and `fluent-bit` binaries; Stage 1 runs `python3 scripts/validate_config.py --file <config> --check all` covering structure, sections, tags, security, performance, and best-practices; Stage 2 optionally runs `fluent-bit -c <config> --dry-run`. Findings use only Error, Warning, and Recommendation severities, with `--fail-on-warning` for CI gates and `--require-dry-run` when the binary must be present. Sample valid and invalid configs live under `tests/*.conf` with `tests/test_validate_config.py` regression coverage. Reach for fluentbit-validator before promoting fluent-bit.conf to K8s DaemonSets or edge nodes. Skip it when you are not running Fluent Bit or only need unrelated log stack tooling.

  • Fluent Bit config linting
  • Catches parser and output mistakes pre-deploy
  • Protects log shipping reliability
  • Kubernetes and VM collector friendly
  • Reduces silent observability gaps

Fluentbit Validator by the numbers

  • 371 all-time installs (skills.sh)
  • Ranked #314 of 1,435 DevOps & CI/CD skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/akin-ozer/cc-devops-skills --skill fluentbit-validator

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs371
repo stars286
Last updatedJuly 26, 2026
Repositoryakin-ozer/cc-devops-skills

How do you validate Fluent Bit configs before deploy?

Validate Fluent Bit configs for log routing, parsers, filters, and outputs before rollout to Kubernetes nodes, VMs, or edge collectors.

Who is it for?

Platform engineers editing Fluent Bit INPUT, FILTER, OUTPUT, or tag routes who need repeatable linting before DaemonSet or VM rollout.

Skip if: Skip fluentbit-validator when the stack does not use Fluent Bit or you only need unrelated logging platform setup.

When should I use this skill?

The user asks to validate, lint, audit, or dry-run a fluent-bit.conf before deploy.

What you get

Validation report with Error, Warning, and Recommendation findings plus optional fluent-bit --dry-run pass or skip note.

  • validation report
  • JSON findings with --json flag

By the numbers

  • Seven targeted --check scopes plus combined --check all
  • Four-stage execution model from precheck through remediation report
  • Catalog reports 280 installs for fluentbit-validator

Files

SKILL.mdMarkdownGitHub ↗

Fluent Bit Validator

Use this skill to run deterministic, repeatable validation for Fluent Bit classic-mode configs.

Trigger Phrases

Use this skill when prompts look like:

  • "Validate this fluent-bit.conf before deploy"
  • "Lint my Fluent Bit config and report issues"
  • "Check tag routing and output matches in Fluent Bit"
  • "Run security checks for Fluent Bit config"
  • "Dry-run Fluent Bit config and tell me what failed"

Execution Model

Run steps in order. Do not skip Stage 0.

Stage 0: Precheck (Required)

Run from skill directory:

cd devops-skills-plugin/skills/fluentbit-validator

Check required and optional binaries:

command -v python3 >/dev/null 2>&1 && echo "python3: available" || echo "python3: missing"
command -v fluent-bit >/dev/null 2>&1 && echo "fluent-bit: available" || echo "fluent-bit: missing (dry-run will be skipped)"

Precheck protocol:

  • If python3 is missing: stop script-based validation, report blocker, and switch to manual config review only.
  • If fluent-bit is missing: continue static checks, skip dry-run, and record a Recommendation explaining skip reason and next step.

Stage 1: Static Validation (Required)

Default command:

python3 scripts/validate_config.py --file <config-file> --check all

Use targeted checks only when requested:

python3 scripts/validate_config.py --file <config-file> --check structure
python3 scripts/validate_config.py --file <config-file> --check sections
python3 scripts/validate_config.py --file <config-file> --check tags
python3 scripts/validate_config.py --file <config-file> --check security
python3 scripts/validate_config.py --file <config-file> --check performance
python3 scripts/validate_config.py --file <config-file> --check best-practices
python3 scripts/validate_config.py --file <config-file> --check dry-run

Strict CI gate (optional):

python3 scripts/validate_config.py --file <config-file> --check all --fail-on-warning

Stage 2: Dry-Run Handling (Conditional)

Dry-run command:

fluent-bit -c <config-file> --dry-run

Skip protocol:

  • If fluent-bit is unavailable, do not fail static validation by default.
  • Emit one explicit finding:
  • Recommendation: Dry-run skipped because fluent-bit binary is not available in PATH; run dry-run in CI or a Fluent Bit runtime image.
  • If user explicitly requires dry-run as a release gate, run:
python3 scripts/validate_config.py --file <config-file> --check dry-run --require-dry-run
  • In release-gate mode, missing fluent-bit must be reported as Error.

Stage 3: Reference Lookup (Optional)

Use only when plugin/parameter behavior is unclear after local checks.

Lookup order: 1. Context7 Fluent Bit docs. 2. Official docs at docs.fluentbit.io. 3. Broader web search limited to official/plugin sources.

Capture only:

  • required fields,
  • allowed values and defaults,
  • version caveats relevant to the user config.

Stage 4: Report and Remediation (Required)

Use exactly these severity labels:

  • Error
  • Warning
  • Recommendation

Do not introduce alternate labels (Info, Best Practice, Critical, etc.).

Report format:

Validation Report: <config-file>

Error:
- <blocking issue>

Warning:
- <non-blocking risk>

Recommendation:
- <improvement or skipped-step guidance>

Remediation flow: 1. Present findings with file/line context when available. 2. Ask for approval before changing user files. 3. Apply approved changes. 4. Re-run the same validation command(s). 5. Return delta: what changed, what remains, and final status.

No-issue fast path:

  • If no findings exist, return a short pass summary and note whether dry-run was executed or skipped.

Fallback Matrix

ConstraintBehavior
python3 missingStop scripted validator, report blocker as Error, provide manual review-only output.
fluent-bit missingContinue static checks, skip dry-run, emit one Recommendation with next step.
No network/docs accessContinue local validation, report unknown plugin details as Warning with explicit "doc lookup deferred".
User requests report-onlyDo not edit files; return findings and rerun command suggestion.

Canonical Flows

Full validation flow

bash scripts/validate.sh --precheck
python3 scripts/validate_config.py --file tests/valid-basic.conf --check all

Constrained environment flow (fluent-bit unavailable)

bash scripts/validate.sh --precheck
python3 scripts/validate_config.py --file tests/invalid-security-issues.conf --check all --json

Expected outcome:

  • Static findings still produced.
  • Dry-run skipped and reported under Recommendation.

Done Criteria

Work is done only when all are true:

  • Precheck was executed and binary availability was stated explicitly.
  • Validation command(s) and scope are clear and reproducible.
  • All findings use only Error, Warning, Recommendation.
  • Dry-run path is explicit: executed or skipped with reason.
  • Fallback behavior for tool/runtime constraints is documented in output.
  • If fixes were applied, validation was re-run and post-fix status was reported.

Local Assets

  • scripts/validate_config.py: main validator.
  • scripts/validate.sh: wrapper and environment precheck helper.
  • tests/*.conf: sample valid/invalid configs.
  • tests/test_validate_config.py: regression coverage for parser and severity behavior.

Related skills

How it compares

Use fluentbit-validator instead of manual fluent-bit --dry-run alone when you also need tag-routing, security, and performance linting with CI-friendly severity labels.

FAQ

What checks does fluentbit-validator run?

fluentbit-validator runs `validate_config.py` with scopes structure, sections, tags, security, performance, best-practices, and optional dry-run. Use `--check all` for the full gate or target individual scopes when debugging one concern.

What happens if fluent-bit is not installed?

fluentbit-validator still runs static Python checks and records a Recommendation that dry-run was skipped because the fluent-bit binary is missing. Use `--require-dry-run` when dry-run is a hard release gate and missing binary must surface as an Error.

Which severity labels does fluentbit-validator use?

fluentbit-validator reports only Error, Warning, and Recommendation—no alternate labels. Blocking issues are Errors; risks are Warnings; improvements and skipped-step guidance are Recommendations, with optional `--fail-on-warning` for strict CI.

DevOps & CI/CDmonitoringinfradeploy

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.