You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Start here. Look up a plugin by category below. Install with tinycode plugin install <name> and enable it in ~/.config/tinycode/tinycode.json. What each plugin needs for credentials is plugin-credentials.md. How to write one is plugin-development.md.
Complete reference for the 30 plugins and 4 core builtins shipped with tinycode.
Quick Start
# Optional Red Hat plugin/role setup (not first-run; models via /connect or Ollama)
tinycode init
# Or install plugins manually
tinycode plugin install safety-net
tinycode plugin install ocp-context-injection
# List plugins with category filter
tinycode plugin list
tinycode plugin list --category sre
Enable plugins in your tinycode config (~/.config/tinycode/tinycode.json):
Example configs for common roles are available in configs/.
Core Builtins (Always Available)
These features are built into tinycode and require no installation or configuration. They were promoted from plugins to core builtins because every user benefits from them.
Builtin
Type
Description
context-pruning
Hook (ToolExecAfter)
Detects duplicate tool outputs within a sliding window and annotates them to save context
notify
Tool
Send desktop notifications (macOS via osascript, Linux via notify-send)
code-review
Tool
Git diff formatted as a markdown code review block
Authenticate to an OpenShift cluster with API token
ocp-must-gather
Offline cluster analysis from must-gather archives. Uses pkg/mustgather/ library. For etcd and HAProxy deep-dives, use the specialist plugins (etcd-diag, ingress-inspect).
Tool
Description
mg_use
Set the active must-gather directory path
mg_cluster_version
Cluster version, update channel, upgrade history
mg_nodes
Node status, roles, conditions, capacity
mg_operators
ClusterOperator available/degraded/progressing status
Validate deployment YAML against security policies
rhacs_violations
List active policy violations
rhacs_risk
Risk score and factors for a deployment
rhacs_compliance_scan
Trigger a compliance scan
rhacs_compliance_status
Compliance results by standard (CIS, NIST, PCI)
lightwell
Tool
Description
lightwell_check_package
Check a package against Lightwell repos
lightwell_check_deps
Scan pom.xml or requirements.txt for patches
lightwell_osv
Query OSV vulnerability data for a package
lightwell_provenance
Verify SLSA Level 3 build provenance
lightwell_config_check
Audit build config for Lightwell repo configuration
lightwell_scan_containerfile
Scan Containerfile for dependency and base image issues
container-linter
Tool
Description
container_lint
Lint Containerfile against Red Hat best practice rules
bootc_validate
Validate bootc-compatible image builds
container_base_suggest
Suggest UBI base image for a use case
log-sanitizer
Hook-only plugin. Intercepts every tool output and applies regex-based redaction: PEM key blocks, API key prefixes (OpenAI, GitHub, AWS, Slack), bearer tokens, and high-entropy catch-all for 40+ character mixed-class strings. Matches are replaced with [REDACTED:<type>]. Zero configuration.
safety-net
Hook-only plugin. Intercepts permission.ask for bash-type permissions and blocks: filesystem destructive (rm -rf /, mkfs, fork bombs), Kubernetes/OCP destructive (kubectl delete namespace, helm uninstall in kube-system), and git destructive (git push --force main). Scoped paths like ./build are allowed.
AI/ML — AI/ML / Data Science (3 plugins)
Model serving, experiment tracking, pipelines, and evaluation on RHOAI.
Plugin
Tools
Description
rhoai-mlflow
10
MLflow experiments, model registry, session metrics
rhoai-pipelines
4
Data Science Pipelines (Kubeflow)
rhoai-serving
14
Model serving, evaluation, TrustyAI, workbenches, sandbox
rhoai-mlflow
Merged from rhoai-mlflow-tools + rhoai-experiment-tracker. Includes 4 session lifecycle hooks.
Tool
Description
mlflow_experiments
List MLflow experiments
mlflow_runs
List runs for an experiment with optional filter
mlflow_compare
Compare multiple runs side by side (metrics, parameters)
mlflow_artifacts
List artifacts for a run
mlflow_model_registry
List registered models
mlflow_model_version
Detailed info for a specific model version
mlflow_promote
Transition model version stage (Staging, Production, Archived)
mlflow_log_metric
Log a metric to a run
experiment_last_session
Last tracked experiment session (metrics, parameters)
mlflow_setup
Instructions for deploying MLflow on OpenShift
rhoai-pipelines
Tool
Description
rhoai_pipeline_list
List Data Science Pipelines
rhoai_pipeline_run
Trigger a pipeline run (with confirmation)
rhoai_pipeline_status
Check status of a pipeline run
rhoai_pipeline_create
Create a pipeline from a workflow definition
rhoai-serving
Merged from rhoai-eval-trustyai + rhoai-model-serving. Combined health tool.
Tool
Description
rhoai_list_models
List deployed inference services (models)
rhoai_model_status
Detailed model status (pods, GPU allocation)
rhoai_list_runtimes
Available serving runtimes (vLLM, Caikit, TGIS)
rhoai_sandbox_status
Developer Sandbox environment status
rhoai_sandbox_provision
Provision a Developer Sandbox
rhoai_eval_run
Start model evaluation (lm-eval, ragas, garak, guidellm)
rhoai_eval_status
Check evaluation status and results
rhoai_eval_compare
Compare multiple evaluation runs
rhoai_trusty_metrics
TrustyAI fairness and drift metrics for a model
rhoai_trusty_alerts
Active TrustyAI alerts for drift and bias
rhoai_workbench_list
List RHOAI workbenches (Jupyter notebooks)
rhoai_serving_health
Connectivity check to all dependent services
Platform — Platform / Infrastructure (5 plugins)
Fleet management, CI/CD, automation, and infrastructure management.
Plugin
Tools
Description
rhacm
7
ACM multi-cluster management
tekton
6
Tekton pipelines
aap-bridge
7
Ansible Automation Platform
satellite
11
Red Hat Satellite host/content management
rhdp-provisioner
4
Developer Platform demo environments
rhacm
Tool
Description
acm_clusters
List managed clusters with status, version, provider
acm_cluster_detail
Detailed cluster info with addon status
acm_policies
Governance policies with compliance status
acm_violations
Active policy violations across fleet
acm_applications
ACM-managed ArgoCD applications
acm_app_deploy
Deploy ApplicationSet (with confirmation)
acm_observability
Federated PromQL via ACM Thanos
tekton
Tool
Description
tekton_list_pipelines
List pipelines with task details
tekton_list_runs
PipelineRuns with status and duration
tekton_run_status
Detailed PipelineRun status
tekton_run_logs
Logs for a task in a PipelineRun
tekton_list_tasks
Available Tasks and ClusterTasks
tekton_start_run
Start a pipeline run (with confirmation)
aap-bridge
Tool
Description
aap_list_templates
Job templates with last run status
aap_launch_job
Launch a job template (with confirmation)
aap_job_status
Running/completed job status
aap_job_output
Full stdout/stderr of a completed job
aap_list_inventories
Inventories with host counts
aap_hub_search
Search Automation Hub for certified collections
aap_lint_playbook
Lint an Ansible playbook
satellite
Tool
Description
satellite_health_check
Probe connectivity on ports 443, 9090, 23443
satellite_hosts
Search managed hosts by name, OS, environment
satellite_host_facts
System facts for a host (CPU, memory, OS, networking)
satellite_errata
Search errata by ID, title, type, severity
satellite_content_views
Content views with name, composite flag, publish date
satellite_services
Service health (database, cache, candlepin, pulp)
satellite_tasks
Foreman tasks with optional search filter
satellite_proxies
Smart proxies (capsules) with registered features
satellite_repositories
Repositories in org or content view
satellite_rex_run
Run a shell command on a host via REX
satellite_rex_result
Get REX job status and output
rhdp-provisioner
Tool
Description
rhdp_search
Search RHDP demo catalog
rhdp_provision
Provision a demo environment (with confirmation)
rhdp_status
Check provisioning status
rhdp_list_active
List active demo environments with expiration
Developer (5 plugins)
Registry, API discovery, content, and developer hub integration.
GITEA_TOKEN, GITHUB_TOKEN or GH_TOKEN, GITLAB_TOKEN (one required)
Auto-detects platform from git remote. Override with PILOT_PROVIDER. See also GITEA_URL, GITLAB_URL.
telemetry
TELEMETRY_DB (optional)
Default: ~/.tinycode/telemetry.db
Plugins not listed above require no configuration.
Shared Library
All Red Hat plugins share internal/redhat/, which provides:
Component
Description
OcClient
Typed wrapper around oc CLI (get, describe, logs, apply, raw)
APIClient
HTTP client with token injection, retry on 401/5xx, configurable timeouts
ConsoleAuthClient
SSO token exchange for console.redhat.com APIs with in-memory caching
PromQLClient
Prometheus/Thanos query and alert management (instant, range, alerts, silencing)
MlflowClient
MLflow tracking server operations (experiments, runs, artifacts, registry)
ContainerfileParser
Multi-stage Containerfile parsing and dependency extraction
HTML Utilities
HTML tag stripping for web scraping plugins
See internal/redhat/ for implementation details and internal/redhat/*_test.go for usage examples.
Development
Plugins are standalone Go binaries using the pkg/plugin/ SDK. See plugin-development.md for the full SDK reference, wire protocol, testing patterns, and examples. See plugin-sdk-design.md for design rationale.