Agent skill

Ops Pipelines

by boundless-xyz in boundless-xyz/boundless

Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

Apache-2.0Auto-check passedDevOps & Cloud

Install Ops Pipelines

skills CLI
$ npx skills add boundless-xyz/boundless --skill ops-pipelines -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boundless-xyz/boundless ops-pipelines --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boundless-xyz/boundless.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/ops-pipelines .claude/skills/ops-pipelines && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ops-pipelines
GitHub stars
193
Token cost
~2.7k tokens
SKILL.md length
866 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

  • Works in 4 steps: Monitor a deployment for a freshly… → Approving production deploys → Diagnose a failed deployment → …
  • The user wants to track a deployment after merging a PR
  • SKILL.md covers Setup, Pipelines, Core workflows and Status reference, plus 2 more sections
  • Calls aws, jq and pulumi; reaches us-west-2.console.aws.amazon.com; needs AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY

What it does

Ops Pipelines is an agent skill from boundless-xyz/boundless. Internal — for Boundless team members only. Monitor Boundless deployment pipelines (AWS CodePipeline + CodeBuild) on the ops account. Use when the user wants to track a deployment after merging a PR, check whether a commit has rolled out to staging/prod, diagnose a failed deployment, watch the status of a specific pipeline, or get prompted to approve a production rollout once staging succeeds. Do NOT use for service runtime debugging (use ops-logs-query) or for deploying dev infrastructure (use ops-infra-deploy).

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment and CI/CD. It works with Amazon Web Services and Ansible. The repository describes itself as: Monorepo for Boundless, the universal ZK protocol. The licence is Apache-2.0.

When your agent uses it

  • The user wants to track a deployment after merging a PR
  • Check whether a commit has rolled out to staging/prod
  • Diagnose a failed deployment
  • Watch the status of a specific pipeline

Example prompts

  • “/ops-pipelines”

Requirements

  • Docker
  • A credential in AWS_SECRET_ACCESS_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Monitor a deployment for a freshly merged commit
  2. Approving production deploys
  3. Diagnose a failed deployment
  4. Fleet status overview

What it can do on your machine

Read from SKILL.md and the folder at commit 93e971a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • jq
    • pulumi
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • us-west-2.console.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ops Pipelines loads about 2.7k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 866 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from boundless-xyz/boundless at commit 93e971a, republished under its Apache-2.0 licence (© boundless-xyz). 866 words, ~2,747 tokens.

Download SKILL.mdSave it as .claude/skills/ops-pipelines/SKILL.md (or your agent's skills folder).
name
ops-pipelines
description
Internal — for Boundless team members only. Monitor Boundless deployment pipelines (AWS CodePipeline + CodeBuild) on the ops account. Use when the user wants to track a deployment after merging a PR, check whether a commit has rolled out to staging/prod, diagnose a failed deployment, watch the status of a specific pipeline, or get prompted to approve a production rollout once staging succeeds. Do NOT use for service runtime debugging (use ops-logs-query) or for deploying dev infrastructure (use ops-infra-deploy).

Ops Pipelines

Monitor Boundless service deployments running through AWS CodePipeline / CodeBuild in the ops account. Designed for the post-merge workflow: track a commit through staging, surface failures with build logs, and prompt the user to approve the production rollout.

Setup

Read network_secrets.toml from the repo root and extract [aws.ops] (access_key_id, secret_access_key). These are read-only and can query CodePipeline / CodeBuild / CloudWatch but cannot approve, start, or retry pipelines. If the file is missing, point the user at the Boundless runbook.

bash
export AWS_ACCESS_KEY_ID="..."
export AWS_SECRET_ACCESS_KEY="..."
export AWS_DEFAULT_REGION="us-west-2"

All Boundless pipelines live in us-west-2 in account 968153779208 (BoundlessOps).

Pipelines

Pipeline definitions live in infra/pipelines/pipelines/ — read that dir to see what's deployed, branch config, stage layout per service. The boundless repo's pipelines are the l-* ones; signal-pipeline, kailua-order-generator-pipeline, zeth-requestor-pipeline come from different repos.

Discover the live list any time:

bash
aws codepipeline list-pipelines --query 'pipelines[].name' --output table

Typical stage layout: Source → DeployStaging (parallel CodeBuild per chain) → DeployProduction (manual approval, then parallel CodeBuild per chain). l-prover-ansible-pipeline adds a DeployNightly stage between staging and production.

CodeBuild project names have a Pulumi resource hash suffix (l-indexer-staging-167000-build-aee3645); always derive the suffix from pipeline state, never hardcode it.

Core workflows

1. Monitor a deployment for a freshly merged commit

Primary use case. Given a commit SHA (or PR), find the pipeline executions for that SHA and poll until staging finishes.

Resolve the SHA if needed:

bash
gh pr view <number> --json mergeCommit --jq '.mergeCommit.oid'

Find the matching execution per pipeline (executions store the SHA in sourceRevisions[0].revisionId):

bash
SHA="..."
for P in $(aws codepipeline list-pipelines --query 'pipelines[?starts_with(name, `l-`)].name' --output text); do
  EXEC=$(aws codepipeline list-pipeline-executions --pipeline-name "$P" --max-items 20 \
    --query "pipelineExecutionSummaries[?sourceRevisions[0].revisionId=='$SHA'] | [0].pipelineExecutionId" \
    --output text)
  echo "$P -> $EXEC"
  sleep 1
done

Default to all l-* pipelines unless the user specifies a service. Skip l-prover-ansible-pipeline unless the change touched ansible/ or infra/cw-monitoring/.

If the SHA's execution is Superseded, a later commit took over and that SHA will not deploy to prod on its own. Call this out — common source of confusion when merging PRs back-to-back.

Use the Monitor tool to poll in the background so the user can keep working while staging runs (CodePipeline deployments take 10–30+ minutes). The Monitor tool runs a script in the background and feeds each output line back, so the agent can interject as soon as a stage transitions.

Run one Monitor per tracked pipeline with a script that prints a status heartbeat every 30s and exits on a terminal event. Use the execution's overall status from get-pipeline-execution, and get-pipeline-state to detect the approval gate (filtered to the inbound exec at DeployProduction so a newer superseding exec doesn't trigger a false approval signal):

bash
PIPELINE="l-indexer-pipeline"
EXEC="<pipelineExecutionId from step above>"
while true; do
  STATUS=$(aws codepipeline get-pipeline-execution \
    --pipeline-name "$PIPELINE" --pipeline-execution-id "$EXEC" \
    --query 'pipelineExecution.status' --output text 2>/dev/null || echo Unknown)
  echo "$(date -u +%H:%M:%SZ) $PIPELINE exec=$EXEC status=$STATUS"
  case "$STATUS" in
    Succeeded)
      echo "DONE pipeline=$PIPELINE exec=$EXEC"; break ;;
    Failed|Stopped|Cancelled|Superseded)
      echo "ALERT pipeline=$PIPELINE status=$STATUS exec=$EXEC"; break ;;
    InProgress)
      APPROVAL=$(aws codepipeline get-pipeline-state --name "$PIPELINE" --output json \
        | jq -r --arg E "$EXEC" '
          .stageStates[]
          | select(.stageName=="DeployProduction"
                   and .inboundExecution.pipelineExecutionId == $E)
          | .actionStates[] | select(.actionName=="ApproveDeployToProduction")
          | .latestExecution.status // empty' | head -1)
      if [ "$APPROVAL" = "InProgress" ]; then
        echo "READY-TO-APPROVE pipeline=$PIPELINE exec=$EXEC"; break
      fi ;;
  esac
  sleep 30
done

Each tracked pipeline gets its own Monitor (run them in parallel — the boundless ops account handles the call rate fine at 30s intervals). React when a line starting with ALERT, READY-TO-APPROVE, or DONE arrives:

  • READY-TO-APPROVE → prompt the user to approve production (workflow 2).
  • ALERT ... Failed → surface the failure (workflow 3).
  • ALERT ... Superseded → a newer commit took over; tell the user this SHA will not deploy to prod on its own.
  • DONE ... Succeeded → pipeline fully complete (rare without approval).

If the user cancels the run, moves on to unrelated work, or asks to stop monitoring, cancel the monitors — they cost API calls and clutter context. If the Monitor tool isn't available, fall back to manual polling with get-pipeline-state every 30s.

Show full SKILL.md (367 more words)Show less
2. Approving production deploys

When staging completes, summarise: commit SHA + subject, which pipelines are waiting, and per-pipeline AWS Console links:

https://us-west-2.console.aws.amazon.com/codesuite/codepipeline/pipelines/<pipeline-name>/view?region=us-west-2

Ask the user explicitly whether to approve. The user approves via the AWS Console (or Slack — pipelines emit manual-approval-needed events to the boundless-alerts-launch and boundless-alerts-staging-launch channels).

NEVER attempt the approval call yourself — the read-only ops creds will fail with AccessDenied. After the user approves, optionally keep polling production stages.

3. Diagnose a failed deployment

Find the failed action and its CodeBuild build:

bash
aws codepipeline list-action-executions --pipeline-name "$P" \
  --filter pipelineExecutionId="$EXEC" \
  --query "actionExecutionDetails[?status=='Failed'].{stage:stageName, action:actionName, build:output.executionResult.externalExecutionId, project:input.configuration.ProjectName, url:output.executionResult.externalExecutionUrl}" \
  --output json

build is <project>:<uuid>. Get the failed phase + log location:

bash
aws codebuild batch-get-builds --ids "$BUILD_ID" \
  --query 'builds[].{status:buildStatus, phase:currentPhase, group:logs.groupName, stream:logs.streamName, deepLink:logs.deepLink, start:startTime, end:endTime, failures:phases[?phaseStatus==`FAILED`].[phaseType,contexts[].message]}' \
  --output json

Pull log lines around the failure (CodeBuild logs go to /aws/codebuild/<project-name>):

bash
aws logs filter-log-events \
  --log-group-name "$LOG_GROUP" \
  --log-stream-names "$LOG_STREAM" \
  --start-time "$START_MS" --end-time "$END_MS" \
  --filter-pattern '?ERROR ?error ?Failed ?failed ?"exit code"' \
  --output json | jq '.events[] | {ts: (.timestamp/1000|todate), msg: .message}'

Common Boundless-specific failure patterns:

  • Still using ops account — assume-role didn't take effect; usually transient, retry the stage.
  • pulumi cancel / update is in progress — previous run was killed; next run usually self-recovers via pulumi cancel --yes in the buildspec.
  • Resource ... already exists — Pulumi state drift; manual fix.
  • 401 Unauthorized from ghcr.io / docker.io — token rotation issue.
  • AccessDenied — IAM problem in the target account.
  • unhealthy / failed to start: container (prover-ansible) — cross-reference with ops-logs-query on the bento prover log group.

Surface the failed phase + 10–30 most relevant log lines + console deep link. Don't dump the full build log.

4. Fleet status overview
bash
for P in $(aws codepipeline list-pipelines --query 'pipelines[].name' --output text); do
  echo "=== $P ==="
  aws codepipeline get-pipeline-state --name "$P" \
    --query 'stageStates[].{stage:stageName, status:latestExecution.status}' \
    --output table
  sleep 1
done

Highlight: any Failed stage, any DeployProduction waiting on approval, pipelines with no recent runs.

Status reference

StatusMeaning
InProgressCurrently running.
SucceededFinished successfully.
FailedFailed; pipeline halted.
Stopped / StoppingManually stopped.
SupersededNewer execution took over; this one will not progress further. Common — webhook fires on every push.
CancelledCancelled before completion (rare).

CodeBuild: SUCCEEDED, FAILED, FAULT, TIMED_OUT, IN_PROGRESS, STOPPED.

Tips

  • sleep 1 between AWS calls — CodePipeline TPS limits are low.
  • Prefer get-pipeline-state over list-action-executions for live polling (one call, everything needed).
  • Always show full pipeline name + execution ID + console deep link in any status report.
  • A stage can show Failed while most chain-specific actions inside it succeeded — identify which chain(s) actually failed.

Important

  • NEVER attempt to approve, start, retry, or stop a pipeline — the read-only ops creds fail with AccessDenied. Direct the user to the AWS Console.
  • NEVER fabricate a pipelineExecutionId, actionExecutionId, approval token, or CodeBuild ID. They must come from a live AWS query.
  • This skill is read-only. To modify pipelines themselves, see infra/pipelines/.

© boundless-xyz, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/ops-pipelines of boundless-xyz/boundless.

Open the folder on GitHubat commit 93e971a

Compare with similar skills

Ops Pipelines next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ops Pipelines compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ops Pipelines this skillboundless-xyz/boundless193—~2.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Spa Create Configsplunk/splunk-platform-automator138—~3.5kAutomated safety check: PassProprietary
Spa Add Test Scenariosplunk/splunk-platform-automator138—~2.2kAutomated safety check: PassProprietary
Devops Deploysickn33/agentic-awesome-skills47k2 repos~1.9kAutomated safety check: PassMIT
Phase 9 Deploymentww-w-ai/bkit-claude-code601—~2.7kAutomated safety check: NotesApache-2.0

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Spa Create Config

    splunk/splunk-platform-automator

    A skill your agent uses when creating or updating splunkconfig.yml, designing Splunk Enterprise lab topology, multisite IDXC, SHC layout, architecture plan before config, or AWS Terraform block for…

    138 GitHub stars~3.5k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Spa Add Test Scenario

    splunk/splunk-platform-automator

    A skill your agent uses when adding app scope/routing test coverage (deployer, CM, DS, direct).

    138 GitHub stars~2.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Devops Deploy

    sickn33/agentic-awesome-skills

    DevOps e deploy de aplicacoes — Docker, CI/CD com GitHub Actions, AWS Lambda, SAM, Terraform, infraestrutura como codigo e monitoramento.

    47k GitHub starsUsed in 2 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Phase 9 Deployment

    ww-w-ai/bkit-claude-code

    Deploy to production — CI/CD pipelines, environment config, deployment strategies.

    601 GitHub stars~2.7k tokensUpdated 12 days ago
    DevOps & CloudAuto-check: notes
  • AWS Deployment

    aws/agent-toolkit-for-aws

    Official

    Configures CI/CD pipelines using AWS CodePipeline, CodeBuild, CodeDeploy, CodeConnections, and CodeArtifact.

    2.8k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed

More from boundless-xyz/boundless

All 12 skills in this repo
  • Boundless CLI

    boundless-xyz/boundless

    How to use the Boundless CLI — the primary interface for the Boundless ZK proof marketplace.

    193 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Ops Indexer Query

    boundless-xyz/boundless

    Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

    193 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Ops Query

    boundless-xyz/boundless

    Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

    193 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Localnet

    boundless-xyz/boundless

    Start and interact with the Boundless localnet (docker compose-based local development network).

    193 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ops Add New Chain

    boundless-xyz/boundless

    Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

    193 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Ops Check Balances

    boundless-xyz/boundless

    Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

    193 GitHub stars~4.9k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Ops Pipelines

What does Ops Pipelines do?

Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless. Ops Pipelines is an agent skill from boundless-xyz/boundless. Internal — for Boundless team members only.

When should I use Ops Pipelines?

Ops Pipelines fits situations like: the user wants to track a deployment after merging a PR; check whether a commit has rolled out to staging/prod; diagnose a failed deployment; watch the status of a specific pipeline.

How do I install Ops Pipelines in Claude Code?

Run `npx skills add boundless-xyz/boundless --skill ops-pipelines -a claude-code`. Or copy the skill folder (.claude/skills/ops-pipelines in boundless-xyz/boundless) into .claude/skills/ops-pipelines in your project. Claude Code loads it when a task matches its description.

How do I install Ops Pipelines in Codex?

Run `npx skills add boundless-xyz/boundless --skill ops-pipelines -a codex`. Or copy the skill folder (.claude/skills/ops-pipelines in boundless-xyz/boundless) into .agents/skills/ops-pipelines in your project. Codex loads it when a task matches its description.

Can I use Ops Pipelines in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boundless-xyz/boundless --skill ops-pipelines -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ops-pipelines, .gemini/skills/ops-pipelines, .github/skills/ops-pipelines and .opencode/skills/ops-pipelines in your project.

What does Ops Pipelines need to run?

Going by SKILL.md and its folder, Ops Pipelines needs the command-line tools its instructions call (aws, jq, pulumi and gh) and credentials named AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. Our summary lists: Docker; A credential in AWS_SECRET_ACCESS_KEY.

Does Ops Pipelines access the network?

SKILL.md names 1 domain. In commands or code: us-west-2.console.aws.amazon.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Ops Pipelines safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ops Pipelines use?

Ops Pipelines is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ops Pipelines use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ops Pipelines?

Skills that share tags, products or a category with Ops Pipelines: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Spa Create Config (splunk/splunk-platform-automator, 138 stars), Spa Add Test Scenario (splunk/splunk-platform-automator, 138 stars) and Devops Deploy (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ops Pipelines?

boundless-xyz (a GitHub organization) maintains it in boundless-xyz/boundless, which has 193 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 26, 2026.

Source: boundless-xyz/boundless on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.