Agent skill

F5 Config Mgmt

by automateyournetwork in automateyournetwork/netclaw

F5 BIG-IP configuration management - safe change workflow with baseline capture, planning, creation/update/deletion of virtual servers, pools, iRules, and profiles with full verification.

Apache-2.0Auto-check passedDevOps & Cloud

Install F5 Config Mgmt

skills CLI
$ npx skills add automateyournetwork/netclaw --skill f5-config-mgmt -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw f5-config-mgmt --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/f5-config-mgmt .claude/skills/f5-config-mgmt && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
f5-config-mgmt
GitHub stars
676
Token cost
~5.7k tokens
SKILL.md length
1,237 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

F5 BIG-IP configuration management - safe change workflow with baseline capture, planning, creation/update/deletion of virtual servers, pools, iRules, and profiles with full verification.

  • Works in 5 steps: Pre-Change Baseline → Plan the Change → Apply Configuration → …
  • Modifying F5 virtual servers
  • SKILL.md covers Golden Rule, How to Call the Tools, Change Workflow and Change Documentation, plus 3 more sections
  • Calls python3

What it does

F5 Config Mgmt is an agent skill from automateyournetwork/netclaw. F5 BIG-IP configuration management - safe change workflow with baseline capture, planning, creation/update/deletion of virtual servers, pools, iRules, and profiles with full verification. Use when creating or modifying F5 virtual servers, adding pool members, deploying iRules, performing blue-green traffic shifts, or rolling back a BIG-IP change.

Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Modifying F5 virtual servers
  • Adding pool members
  • Deploying iRules
  • Performing blue-green traffic shifts

Example prompts

  • “/f5-config-mgmt”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pre-Change Baseline
  2. Plan the Change
  3. Apply Configuration
  4. Post-Change Verification
  5. Rollback (If Verification Fails)

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

F5 Config Mgmt loads about 5.7k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 1,237 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 1,237 words, ~5,720 tokens.

Download SKILL.mdSave it as .claude/skills/f5-config-mgmt/SKILL.md (or your agent's skills folder).
name
f5-config-mgmt
description
F5 BIG-IP configuration management - safe change workflow with baseline capture, planning, creation/update/deletion of virtual servers, pools, iRules, and profiles with full verification. Use when creating or modifying F5 virtual servers, adding pool members, deploying iRules, performing blue-green traffic shifts, or rolling back a BIG-IP change.
license
Apache-2.0
user-invocable
true

F5 BIG-IP Configuration Management

Golden Rule

NEVER apply configuration without first capturing a baseline. If the change goes wrong, you need to know what to restore.

How to Call the Tools

The F5 MCP server provides 6 tools. Call them via mcp-call with the required environment variables:

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" <tool_name> '{"param":"value"}'
Available Tools
ToolPurposeHTTP MethodKey Arguments
list_toolList F5 objectsGETobject_name, object_type
show_stats_toolShow object statisticsGETobject_name, object_type
show_logs_toolShow system logsGETlines_number
create_toolCreate objectsPOSTurl_body, object_type
update_toolUpdate objectsPATCHurl_body, object_type, object_name
delete_toolDelete objectsDELETEobject_type, object_name

Object types: virtual, pool, irule, profile


Change Workflow

Phase 1: Pre-Change Baseline

Capture the current state of everything the change might affect. This is the rollback reference.

1A: Capture Virtual Server State
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" list_tool '{"object_name":"","object_type":"virtual"}'

Store the full list of virtual servers, their configurations, pool assignments, and profiles.

1B: Capture Pool State
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" list_tool '{"object_name":"","object_type":"pool"}'

Store pool configurations, member lists, monitor assignments, and load balancing methods.

1C: Capture Statistics Baseline

For each affected object, capture current stats to compare post-change:

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"my_virtual_server","object_type":"virtual"}'
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"my_pool","object_type":"pool"}'
1D: Capture Log Baseline

Record the last 50 lines of logs to establish a timestamp reference:

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_logs_tool '{"lines_number":"50"}'

Note the most recent log timestamp -- any errors after this timestamp are change-related.

1E: Capture iRule and Profile State (if affected)
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" list_tool '{"object_name":"","object_type":"irule"}'
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" list_tool '{"object_name":"","object_type":"profile"}'
Phase 2: Plan the Change

Before applying any configuration, explicitly state:

  1. What objects will be created, updated, or deleted
  2. Why the change is needed (business justification)
  3. Expected effect on traffic flow and application delivery
  4. Risk assessment -- what could go wrong
  5. Verification criteria -- how to confirm success
  6. Rollback plan -- exact steps to undo the change
Phase 3: Apply Configuration
Creating Objects

Use create_tool to create new objects via POST. The url_body dict contains the iControl REST API body.

Example: Create a Pool with Members
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"pool_webapp","monitor":"http","loadBalancingMode":"round-robin","members":["10.1.1.10:80","10.1.1.11:80","10.1.1.12:80"]},"object_type":"pool"}'

Pool creation best practices:

  • Always assign a health monitor (http, https, tcp, icmp, or a custom monitor)
  • Choose the appropriate load balancing method:
    • round-robin -- default, equal distribution
    • least-connections-member -- best for unequal server capacity or variable request duration
    • ratio-member -- weighted distribution for heterogeneous backends
    • fastest-node -- route to fastest responding server
  • Specify the serviceDownAction for graceful failure handling:
    • none -- connections persist on down member until timeout
    • reset -- RST sent to clients
    • reselect -- reselect a new member (recommended for HTTP)
    • drop -- silently drop connections
  • Set minActiveMembers to trigger action when too many members fail
  • Include description for documentation
Example: Create a Pool with Advanced Options
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"pool_api_backend","monitor":"https_443","loadBalancingMode":"least-connections-member","minActiveMembers":2,"serviceDownAction":"reselect","slowRampTime":300,"description":"API backend pool - managed by NetClaw","members":["10.2.1.20:443","10.2.1.21:443","10.2.1.22:443","10.2.1.23:443"]},"object_type":"pool"}'
Example: Create a Virtual Server
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"vs_webapp_https","destination":"10.100.1.50:443","ipProtocol":"tcp","pool":"pool_webapp","sourceAddressTranslation":{"type":"automap"},"profiles":[{"name":"clientssl"},{"name":"http"},{"name":"tcp-wan-optimized","context":"clientside"},{"name":"tcp-lan-optimized","context":"serverside"}],"description":"HTTPS virtual server for webapp - managed by NetClaw"},"object_type":"virtual"}'

Virtual server creation best practices:

  • Always specify destination as VIP_IP:port
  • Always assign sourceAddressTranslation (automap or SNAT pool) unless servers have BIG-IP as default gateway
  • Assign appropriate profiles:
    • Client SSL profile for HTTPS termination
    • HTTP profile for HTTP inspection, compression, X-Forwarded-For
    • TCP profiles: tcp-wan-optimized on clientside, tcp-lan-optimized on serverside
    • Persistence profile if session affinity is required
  • Set pool to the backend pool name
  • Include description for documentation
  • Consider connectionLimit to protect backend servers
Example: Create an HTTP Virtual Server (Non-SSL)
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"vs_webapp_http","destination":"10.100.1.50:80","ipProtocol":"tcp","pool":"pool_webapp","sourceAddressTranslation":{"type":"automap"},"profiles":[{"name":"http"},{"name":"tcp-wan-optimized","context":"clientside"},{"name":"tcp-lan-optimized","context":"serverside"}],"description":"HTTP virtual server for webapp - managed by NetClaw"},"object_type":"virtual"}'
Example: Create an HTTP-to-HTTPS Redirect Virtual Server
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"vs_webapp_redirect","destination":"10.100.1.50:80","ipProtocol":"tcp","profiles":[{"name":"http"}],"rules":["/Common/redirect_to_https"],"description":"HTTP-to-HTTPS redirect - managed by NetClaw"},"object_type":"virtual"}'
Example: Create an iRule
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"redirect_to_https","apiAnonymous":"when HTTP_REQUEST {\n  HTTP::redirect https://[HTTP::host][HTTP::uri]\n}"},"object_type":"irule"}'

iRule creation best practices:

  • Keep iRules as simple as possible -- complexity degrades performance
  • Avoid log statements in production iRules on high-traffic virtual servers
  • Always pair HTTP::collect with HTTP::release to prevent memory leaks
  • Use catch blocks for error handling in complex iRules
  • Test iRule syntax before deploying (syntax errors can prevent virtual server from starting)
Example: HTTP Header Insertion iRule
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"insert_headers","apiAnonymous":"when HTTP_REQUEST {\n  HTTP::header insert X-Forwarded-Proto https\n  HTTP::header insert X-Real-IP [IP::client_addr]\n}\nwhen HTTP_RESPONSE {\n  HTTP::header insert Strict-Transport-Security \"max-age=31536000; includeSubDomains\"\n}"},"object_type":"irule"}'
Example: Maintenance Page iRule
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"maintenance_page","apiAnonymous":"when HTTP_REQUEST {\n  HTTP::respond 503 content \"<html><body><h1>Service Temporarily Unavailable</h1><p>We are performing scheduled maintenance. Please try again later.</p></body></html>\" Content-Type \"text/html\"\n}"},"object_type":"irule"}'
Example: URI-Based Pool Selection iRule
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"uri_routing","apiAnonymous":"when HTTP_REQUEST {\n  switch -glob [string tolower [HTTP::uri]] {\n    \"/api/*\" { pool pool_api_backend }\n    \"/static/*\" { pool pool_static_content }\n    default { pool pool_webapp }\n  }\n}"},"object_type":"irule"}'
Updating Objects

Use update_tool to modify existing objects via PATCH. Only include the fields you want to change.

Example: Update Pool Members (Add a Member)
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"members":["10.1.1.10:80","10.1.1.11:80","10.1.1.12:80","10.1.1.13:80"]},"object_type":"pool","object_name":"pool_webapp"}'

WARNING: The members list in an update is a full replacement, not an append. Always include ALL desired members (existing + new) in the list. Omitting existing members will remove them.

Example: Update Pool Load Balancing Method
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"loadBalancingMode":"least-connections-member"},"object_type":"pool","object_name":"pool_webapp"}'
Example: Update Pool Monitor
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"monitor":"https_443"},"object_type":"pool","object_name":"pool_api_backend"}'
Example: Update Virtual Server Pool Assignment
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"pool":"pool_webapp_v2"},"object_type":"virtual","object_name":"vs_webapp_https"}'
Example: Add iRule to Virtual Server
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"rules":["/Common/redirect_to_https","/Common/insert_headers"]},"object_type":"virtual","object_name":"vs_webapp_https"}'

WARNING: The rules list in an update is a full replacement. Include ALL desired iRules in the list.

Example: Disable a Virtual Server (Maintenance)
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"enabled":false},"object_type":"virtual","object_name":"vs_webapp_https"}'
Example: Re-enable a Virtual Server
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"enabled":true},"object_type":"virtual","object_name":"vs_webapp_https"}'
Deleting Objects

Use delete_tool to remove objects. Always verify no dependencies exist before deletion.

Example: Delete a Pool
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" delete_tool '{"object_type":"pool","object_name":"pool_old_webapp"}'

CRITICAL: You cannot delete a pool that is still assigned to a virtual server. Remove the pool reference from the virtual server first, or reassign to a different pool.

Example: Delete a Virtual Server
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" delete_tool '{"object_type":"virtual","object_name":"vs_old_webapp"}'
Example: Delete an iRule
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" delete_tool '{"object_type":"irule","object_name":"old_redirect_rule"}'

CRITICAL: You cannot delete an iRule that is still assigned to a virtual server. Remove the iRule reference from the virtual server first.

Show full SKILL.md (493 more words)Show less
Deletion Order (Dependencies)

When decommissioning a full application stack, delete in this order:

  1. Remove iRule references from virtual servers (update)
  2. Delete virtual servers
  3. Delete pools
  4. Delete orphaned iRules
  5. Delete orphaned profiles

Reversing this order will cause dependency errors.


Traffic Shifting / Blue-Green Deployment

A common F5 change pattern is shifting traffic between pool versions for deployments.

Step 1: Create the New Pool (Green)
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" create_tool '{"url_body":{"name":"pool_webapp_v2","monitor":"http","loadBalancingMode":"round-robin","members":["10.1.2.10:80","10.1.2.11:80","10.1.2.12:80"],"description":"Webapp v2.0 pool - blue/green deployment"},"object_type":"pool"}'
Step 2: Verify New Pool Health
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"pool_webapp_v2","object_type":"pool"}'

Confirm all members are available and passing health checks before shifting traffic.

Step 3: Shift Virtual Server to New Pool
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"pool":"pool_webapp_v2"},"object_type":"virtual","object_name":"vs_webapp_https"}'
Step 4: Monitor Post-Shift
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"vs_webapp_https","object_type":"virtual"}'
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"pool_webapp_v2","object_type":"pool"}'
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_logs_tool '{"lines_number":"100"}'

Verify traffic is flowing to the new pool, no errors in logs, and response times are acceptable.

Step 5: Rollback (If Needed)

If the new pool is unhealthy, immediately revert to the old pool:

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"pool":"pool_webapp"},"object_type":"virtual","object_name":"vs_webapp_https"}'
Step 6: Cleanup Old Pool (After Burn-In)

Once the new pool is verified stable (after appropriate burn-in period), remove the old pool:

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" delete_tool '{"object_type":"pool","object_name":"pool_webapp"}'

Phase 4: Post-Change Verification

Immediately after applying configuration, verify the change.

4A: Verify Object Was Created/Updated
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" list_tool '{"object_name":"pool_webapp","object_type":"pool"}'

Compare with the pre-change baseline to confirm only intended changes were made.

4B: Verify Object Health
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"pool_webapp","object_type":"pool"}'

Confirm:

  • Pool members are marked available (passing health checks)
  • Virtual server is available and accepting connections
  • Statistics are incrementing (traffic is flowing)
4C: Check for Errors in Logs
bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_logs_tool '{"lines_number":"100"}'

Look for new error messages that appeared after the Phase 1D baseline timestamp.

4D: Verify Dependent Objects

If you changed a pool, verify the virtual servers that reference it are still healthy:

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" show_stats_tool '{"object_name":"vs_webapp_https","object_type":"virtual"}'
Phase 5: Rollback (If Verification Fails)

If verification fails, roll back by restoring the baseline state.

For created objects: Delete the newly created object.

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" delete_tool '{"object_type":"pool","object_name":"pool_webapp_v2"}'

For updated objects: Patch the object with the original values from the baseline.

bash
IP_ADDRESS=$F5_IP_ADDRESS Authorization_string=$F5_AUTH_STRING python3 $MCP_CALL "python3 -u $F5_MCP_SCRIPT" update_tool '{"url_body":{"pool":"pool_webapp"},"object_type":"virtual","object_name":"vs_webapp_https"}'

For deleted objects: Recreate the object using the baseline configuration.

After rollback, re-verify that the BIG-IP returned to its baseline state.


Change Documentation

After every change, produce a change report:

F5 Change Report -- YYYY-MM-DD HH:MM UTC
Device: $F5_IP_ADDRESS
Requestor: [who requested the change]

Change Description:
  Created pool_webapp with 3 members for new web application

Objects Modified:
  [CREATED] pool_webapp (pool) -- 3 members, round-robin, HTTP monitor
  [CREATED] vs_webapp_https (virtual) -- 10.100.1.50:443, SSL offload, automap

Pre-Change State:
  - Virtual servers: 4 active
  - Pools: 3 active
  - No errors in logs

Post-Change State:
  - Virtual servers: 5 active (+1 vs_webapp_https)
  - Pools: 4 active (+1 pool_webapp)
  - pool_webapp: 3/3 members available
  - vs_webapp_https: available, accepting connections
  - New log entries: pool_webapp member 10.1.1.10:80 monitor status up (expected)

Verification: PASSED
Rollback Required: No

ServiceNow Change Request Integration

When ServiceNow is available ($SERVICENOW_MCP_SCRIPT is set), every F5 configuration change MUST be gated by an approved Change Request.

Pre-Change: Create CR
bash
python3 $MCP_CALL "python3 -u $SERVICENOW_MCP_SCRIPT" create_change_request '{"short_description":"Create pool_webapp and vs_webapp_https on F5 BIG-IP","description":"Create new pool with 3 web server members (10.1.1.10-12:80) and HTTPS virtual server (10.100.1.50:443) with SSL offload. Health monitor: HTTP. Load balancing: round-robin. Rollback: delete vs_webapp_https then pool_webapp.","category":"Network","priority":"3","risk":"moderate","impact":"3"}'
Approval Gate
bash
python3 $MCP_CALL "python3 -u $SERVICENOW_MCP_SCRIPT" get_change_request_details '{"change_id":"CHG0012345"}'

STOP if state is not approved. Inform the human and wait.

Post-Change: Close CR

If verification passes:

bash
python3 $MCP_CALL "python3 -u $SERVICENOW_MCP_SCRIPT" update_change_request '{"change_id":"CHG0012345","work_notes":"Change applied and verified. pool_webapp 3/3 members available, vs_webapp_https accepting connections, no errors in logs.","state":"closed"}'

If verification fails:

bash
python3 $MCP_CALL "python3 -u $SERVICENOW_MCP_SCRIPT" update_change_request '{"change_id":"CHG0012345","work_notes":"Post-change verification FAILED. Rollback initiated. Objects removed. Human review required.","state":"review"}'

Integration with Other Skills

SkillIntegration Point
f5-health-checkPre-change health validation and post-change verification
f5-troubleshootInvestigate failures during verification phase
servicenow-change-workflowCR creation, approval gate, closure
drawio-diagramGenerate before/after topology diagrams
markmap-vizVisualize change plan as a mind map
gait-session-trackingAudit trail for every phase

GAIT Audit Trail

Record every phase of the change in GAIT:

bash
python3 $MCP_CALL "python3 -u $GAIT_MCP_SCRIPT" gait_record_turn '{"artifacts":["f5-change-report.txt"],"user_text":"F5 config change: Create pool_webapp and vs_webapp_https","assistant_text":"Phase 1 baseline captured (4 virtuals, 3 pools, no errors). Phase 2 plan approved. Phase 3 applied: created pool_webapp (3 members, HTTP monitor, round-robin) and vs_webapp_https (10.100.1.50:443, SSL offload, automap). Phase 4 verification PASSED: all members available, VIP accepting connections, no log errors. ServiceNow CR CHG0012345 closed successful."}'

The 5-phase workflow with GAIT creates an immutable record:

  1. Baseline -- GAIT commit with pre-change object state
  2. Plan -- GAIT commit with change plan and CR number
  3. Apply -- GAIT commit with exact API calls made
  4. Verify -- GAIT commit with post-change state and diff
  5. Document -- GAIT commit with final summary and CR closure

Audit examples are illustrative. Replace their request and outcomes with observed session evidence; inspect MCP isError, returned ok and recorded GAIT text.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/f5-config-mgmt of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

F5 Config Mgmt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

F5 Config Mgmt compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
F5 Config Mgmt this skillautomateyournetwork/netclaw676—~5.7kAutomated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
KubeSphere ServiceMesh Managerkubesphere/kubesphere17k—~2.4kAutomated safety check: PassCustom licence
Vercelremotion-dev/remotion63k—~1.2kAutomated safety check: PassCustom licence
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    63k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated yesterday
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about F5 Config Mgmt

What does F5 Config Mgmt do?

F5 BIG-IP configuration management - safe change workflow with baseline capture, planning, creation/update/deletion of virtual servers, pools, iRules, and profiles with full verification. F5 Config Mgmt is an agent skill from automateyournetwork/netclaw. F5 BIG-IP configuration management - safe change workflow with baseline capture, planning, creation/update/deletion of virtual servers, pools, iRules, and profiles with full verification.

When should I use F5 Config Mgmt?

F5 Config Mgmt fits situations like: modifying F5 virtual servers; adding pool members; deploying iRules; performing blue-green traffic shifts.

How do I install F5 Config Mgmt in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill f5-config-mgmt -a claude-code`. Or copy the skill folder (workspace/skills/f5-config-mgmt in automateyournetwork/netclaw) into .claude/skills/f5-config-mgmt in your project. Claude Code loads it when a task matches its description.

How do I install F5 Config Mgmt in Codex?

Run `npx skills add automateyournetwork/netclaw --skill f5-config-mgmt -a codex`. Or copy the skill folder (workspace/skills/f5-config-mgmt in automateyournetwork/netclaw) into .agents/skills/f5-config-mgmt in your project. Codex loads it when a task matches its description.

Can I use F5 Config Mgmt in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill f5-config-mgmt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/f5-config-mgmt, .gemini/skills/f5-config-mgmt, .github/skills/f5-config-mgmt and .opencode/skills/f5-config-mgmt in your project.

What does F5 Config Mgmt need to run?

Going by SKILL.md and its folder, F5 Config Mgmt needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does F5 Config Mgmt access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is F5 Config Mgmt safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does F5 Config Mgmt use?

F5 Config Mgmt is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does F5 Config Mgmt use?

About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to F5 Config Mgmt?

Skills that share tags, products or a category with F5 Config Mgmt: Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars) and Vercel (remotion-dev/remotion, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains F5 Config Mgmt?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.