Deploy, diff, or destroy the ABCA CDK stack. An agent skill from aws-samples/sample-autonomous-cloud-coding-agents.

OfficialMIT-0Auto-check passedDevOps & Cloud

Install Deploy

skills CLI
$ npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/sample-autonomous-cloud-coding-agents deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/sample-autonomous-cloud-coding-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/abca-plugin/skills/deploy .claude/skills/deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploy
GitHub stars
157
Token cost
~1.4k tokens
SKILL.md length
648 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT-0

At a glance

Deploy, diff, or destroy the ABCA CDK stack. An agent skill from aws-samples/sample-autonomous-cloud-coding-agents.

  • Works in 4 steps: Build is clean → Docker is running — Required for CDK… → Build host architecture — The agent… → …
  • The user says deploy
  • SKILL.md covers Determine Action, Pre-Deployment Checks, Deploy Workflow and Diff Workflow, plus 4 more sections
  • Calls mise, aws and docker

What it does

Deploy is an agent skill from aws-samples/sample-autonomous-cloud-coding-agents, published by the product's own GitHub organization. Deploy, diff, or destroy the ABCA CDK stack. Handles pre-deployment validation, synthesis, and post-deployment verification. Use when the user says "deploy", "cdk deploy", "deploy the stack", "destroy", "cdk diff", "what changed", "redeploy", or "update the stack".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. It works with Amazon Web Services. The repository describes itself as: Autonomous background coding agents on AWS. Turn tasks into pull requests via isolated runtimes, with built-in orchestration, observability, and governance. The licence is MIT-0.

When your agent uses it

  • The user says deploy
  • Deploy the stack
  • Update the stack

Example prompts

  • “deploy”
  • “cdk deploy”
  • “deploy the stack”
  • “/deploy”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Build is clean
  2. Docker is running — Required for CDK asset bundling.
  3. Build host architecture — The agent image targets linux/arm64 (AgentCore is Graviton). On an x86_64 host without QEMU/binfmt, the deploy…
  4. AWS credentials are configured — aws sts get-caller-identity (confirm it's the intended account/region).

What it can do on your machine

Read from SKILL.md and the folder at commit cd9bc54. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mise
    • aws
    • docker
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, docker and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploy loads about 1.4k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 648 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/sample-autonomous-cloud-coding-agents at commit cd9bc54, republished under its MIT-0 licence (© aws-samples). 648 words, ~1,434 tokens.

Download SKILL.mdSave it as .claude/skills/deploy/SKILL.md (or your agent's skills folder).
name
deploy
description
Deploy, diff, or destroy the ABCA CDK stack. Handles pre-deployment validation, synthesis, and post-deployment verification. Use when the user says "deploy", "cdk deploy", "deploy the stack", "destroy", "cdk diff", "what changed", "redeploy", or "update the stack".

ABCA Deployment

You are managing CDK deployment for the ABCA platform. Determine the user's intent and execute the appropriate workflow.

Determine Action

Ask the user (or infer from context) which action they want:

  • deploy — Build and deploy the CDK stack
  • diff — Show what would change without deploying
  • destroy — Tear down the stack (requires explicit confirmation)
  • synth — Synthesize CloudFormation without deploying

Pre-Deployment Checks

Before any deployment action, verify:

  1. Build is clean:

    bash
    export MISE_EXPERIMENTAL=1
    mise run build

    This runs agent quality checks, CDK compilation + tests, CLI build, and docs build. Do NOT deploy if the build fails. Note: a passing build is noisy — it prints many ERROR/WARN and cdk-nag lines from test fixtures. Trust the exit code (0 = pass), not the log volume.

  2. Docker is running — Required for CDK asset bundling.

  3. Build host architecture — The agent image targets linux/arm64 (AgentCore is Graviton). On an x86_64 host without QEMU/binfmt, the deploy fails partway with exec /bin/sh: exec format error. Register emulation once with docker run --privileged --rm tonistiigi/binfmt --install arm64, or deploy from a native arm64 host (Graviton / Apple Silicon). Skip on arm64 hosts.

  4. AWS credentials are configured — aws sts get-caller-identity (confirm it's the intended account/region).

Deploy Workflow

bash
export MISE_EXPERIMENTAL=1
mise //cdk:deploy -- --require-approval never

--require-approval never lets the deploy run unattended. In a non-interactive shell (CI, agent, script) it's required — without it, cdk deploy hangs forever on the IAM/security-group approval prompt. Drop the flag if you're deploying interactively and want to review those changes.

After successful deployment, retrieve and display stack outputs:

bash
aws cloudformation describe-stacks --stack-name backgroundagent-dev \
  --query 'Stacks[0].Outputs' --output table

Key outputs to highlight: ApiUrl, RuntimeArn, UserPoolId, AppClientId, GitHubTokenSecretArn.

Diff Workflow

bash
export MISE_EXPERIMENTAL=1
mise //cdk:diff

Summarize the changes: new resources, modified resources, removed resources. Flag any potentially destructive changes (resource replacements, security group changes).

Destroy Workflow

CRITICAL: Ask for explicit confirmation before destroying. Use AskUserQuestion to confirm, explaining consequences.

bash
export MISE_EXPERIMENTAL=1
mise //cdk:destroy

Teardown can stall in DELETE_FAILED on a security group / private subnet: AgentCore injects service-managed (Hyperplane) ENIs into the VPC, and AWS reclaims them asynchronously (~20–40 min) after the runtime is gone. Wait for the ENIs to clear, then retry mise //cdk:destroy. Do not force-delete past the stuck VPC resources (--deletion-mode FORCE_DELETE_STACK / retaining them) — that orphans the VPC, and VPCs are quota-capped per Region. Also note: a first-create failure leaves the stack in ROLLBACK_COMPLETE, which can't be updated — destroy and redeploy fresh.

Synth Workflow

bash
export MISE_EXPERIMENTAL=1
mise //cdk:synth

Output goes to cdk/cdk.out/. Useful for reviewing generated CloudFormation templates.

Show full SKILL.md (268 more words)Show less

Post-Deployment

After a successful deploy, remind the user to:

  • Store/update the GitHub PAT in Secrets Manager if this is a fresh deployment.
  • Onboard a repository. bgagent repo onboard <owner/repo> is a runtime operation (no redeploy) that works when the repo can use the platform/default-blueprint setup — the default GitHub token secret, an already-granted model, and the default egress allowlist. A repo that needs its own config — a per-repo GitHub token, a model not yet granted to the runtime, custom egress domains, Cedar HITL policies, or system-prompt overrides — needs a dedicated CDK Blueprint construct and a redeploy (with the correct permissions). See the onboard-repo skill for both paths.
  • Verify readiness before submitting a task: bgagent platform doctor smoke-checks the API, Cognito, GitHub token, Bedrock model access, and onboarded repos — confirm everything is green first.
  • (Lower-level alternative) raw API smoke test: curl -s -H "Authorization: $TOKEN" $API_URL/tasks.

Least-Privilege Bootstrap (the default)

mise //cdk:bootstrap provisions a custom least-privilege CloudFormation execution role by default — NOT AdministratorAccess (ADR-002). It deploys cdk/bootstrap/bootstrap-template.yaml, which creates scoped IaCRole-ABCA-* managed policies (Infrastructure / Application / Observability) generated from cdk/src/bootstrap/policies/.

A consequence worth knowing when you add a new resource type or a new feature on an existing resource: the scoped role must allow the IAM action CloudFormation will call, or the deploy rolls back with AccessDenied on that action (e.g. s3:PutBucketVersioning, lambda:TagResource). The fix is to add the action to the relevant policy in cdk/src/bootstrap/policies/, regenerate (mise //cdk:bootstrap:generate), re-bootstrap, and redeploy. The policy source and the DEPLOYMENT_ROLES.md golden doc are kept in sync by tests.

See docs/design/DEPLOYMENT_ROLES.md for the complete IAM policies, trust policy, runtime role inventory, and tightening recommendations.

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/abca-plugin/skills/deploy of aws-samples/sample-autonomous-cloud-coding-agents.

Open the folder on GitHubat commit cd9bc54

Compare with similar skills

Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploy this skillaws-samples/sample-autonomous-cloud-coding-agents157—~1.4kAutomated safety check: PassMIT-0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
Ecspressokayac/ecspresso1.1k—~1.4kAutomated safety check: PassMIT
Spa Create Configsplunk/splunk-platform-automator137—~3.5kAutomated safety check: PassProprietary
AWS Agentic AIzxkane/aws-skills3671 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Ecspresso

    kayac/ecspresso

    ECS deployment tool - deploy, manage, and troubleshoot ECS services

    1.1k GitHub stars~1.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Spa Create Config

    splunk/splunk-platform-automator

    A skill your agent uses when creating or updating splunkconfig.yml, designing Splunk Enterprise lab topology, multisite IDXC, SHC layout, architecture plan before config, or AWS Terraform block for…

    137 GitHub stars~3.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Agentic AI

    zxkane/aws-skills

    AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.

    367 GitHub starsUsed in 1 repo~2.5k tokens
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from aws-samples/sample-autonomous-cloud-coding-agents

  • Onboard Repo

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Onboard a new GitHub repository to the ABCA platform so the agent can target it.

    157 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Setup

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Guided installation and first-time setup for ABCA. An agent skill from aws-samples/sample-autonomous-cloud-coding-agents.

    157 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Submit Task

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Submit a coding task to the ABCA platform via CLI or REST API.

    157 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Troubleshoot

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Diagnose and fix common ABCA issues: deployment failures, preflight errors, authentication problems, agent failures, and build issues.

    157 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Status

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Check ABCA platform status — stack health, running tasks, and recent task history.

    157 GitHub stars~438 tokensUpdated today
    Auto-check: notes

Categories

Questions about Deploy

What does Deploy do?

Deploy, diff, or destroy the ABCA CDK stack. An agent skill from aws-samples/sample-autonomous-cloud-coding-agents. Deploy is an agent skill from aws-samples/sample-autonomous-cloud-coding-agents, published by the product's own GitHub organization. Deploy, diff, or destroy the ABCA CDK stack.

When should I use Deploy?

Deploy fits situations like: the user says deploy; deploy the stack; update the stack.

How do I install Deploy in Claude Code?

Run `npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill deploy -a claude-code`. Or copy the skill folder (docs/abca-plugin/skills/deploy in aws-samples/sample-autonomous-cloud-coding-agents) into .claude/skills/deploy in your project. Claude Code loads it when a task matches its description.

How do I install Deploy in Codex?

Run `npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill deploy -a codex`. Or copy the skill folder (docs/abca-plugin/skills/deploy in aws-samples/sample-autonomous-cloud-coding-agents) into .agents/skills/deploy in your project. Codex loads it when a task matches its description.

Can I use Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploy, .gemini/skills/deploy, .github/skills/deploy and .opencode/skills/deploy in your project.

What does Deploy need to run?

Going by SKILL.md and its folder, Deploy needs the command-line tools its instructions call (mise, aws, docker and curl). Our summary lists: Docker.

Does Deploy access the network?

SKILL.md contains no URLs. Its commands use docker and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deploy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deploy use?

Deploy is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploy use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deploy?

Skills that share tags, products or a category with Deploy: AWS Cdk Development (zxkane/aws-skills, 367 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), Ecspresso (kayac/ecspresso, 1.1k stars) and Spa Create Config (splunk/splunk-platform-automator, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploy?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/sample-autonomous-cloud-coding-agents, which has 157 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws-samples/sample-autonomous-cloud-coding-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.