Agent skill

Demo Web Ng Fastpath

by carverauto in carverauto/serviceradar

Refresh the Kubernetes demo namespace with a web-ng-only change using the ServiceRadar fast path.

Apache-2.0Auto-check passedDevOps & Cloud

Install Demo Web Ng Fastpath

skills CLI
$ npx skills add carverauto/serviceradar --skill demo-web-ng-fastpath -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install carverauto/serviceradar demo-web-ng-fastpath --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/carverauto/serviceradar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/demo-web-ng-fastpath .claude/skills/demo-web-ng-fastpath && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
demo-web-ng-fastpath
GitHub stars
921
Token cost
~2.4k tokens
SKILL.md length
742 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Refresh the Kubernetes demo namespace with a web-ng-only change using the ServiceRadar fast path.

  • Works in 10 steps: Work from the repo root. → Determine the new immutable tag from git… → Verify the diff only touches… → …
  • The diff only touches elixir/web-ng/ and the user wants a faster local demo rollout without rebuilding the full image graph
  • SKILL.md covers Overview, Workflow, Guardrails and Verify The Scope First, plus 9 more sections
  • Calls kubectl, git and curl; needs VAULT_TOKEN

What it does

Demo Web Ng Fastpath is an agent skill from carverauto/serviceradar. Refresh the Kubernetes demo namespace with a web-ng-only change using the ServiceRadar fast path. Use when the diff only touches elixir/web-ng/ and the user wants a faster local demo rollout without rebuilding the full image graph. Covers scope verification, copying unchanged images forward, rebuilding the production serviceradar-web-ng release locally, pushing with crane, signing with the OpenBao release key, patching Argo, and verifying the rollout. Do not use when non-web-ng services changed or when cutting a…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Elixir and Kubernetes. The repository describes itself as: Open-Source Network Management, Monitoring, ITOM, and Security Analytics. The licence is Apache-2.0.

When your agent uses it

  • The diff only touches elixir/web-ng/ and the user wants a faster local demo rollout without rebuilding the full image graph
  • Non-web-ng services changed
  • Cutting a release

Example prompts

  • “/demo-web-ng-fastpath”

Requirements

  • Docker
  • A credential in VAULT_TOKEN

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Work from the repo root.
  2. Determine the new immutable tag from git rev-parse HEAD.
  3. Verify the diff only touches elixir/web-ng/**.
  4. Identify the currently deployed demo tag.
  5. Copy every unchanged demo image from the old tag to the new tag.
  6. Build a local production web-ng release.
  7. Package and push the new serviceradar-web-ng image with crane.
  8. Sign the new web-ng digest with the OpenBao-backed release key.
  9. Patch serviceradar-demo-prod to the new tag.
  10. Watch Argo and the key workloads until the rollout completes.

What it can do on your machine

Read from SKILL.md and the folder at commit 2563b3f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • git
    • curl
    • jq
    • make
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, git and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VAULT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Demo Web Ng Fastpath loads about 2.4k tokens when it runs. Until then it costs about 139 tokens; SKILL.md has 742 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from carverauto/serviceradar at commit 2563b3f, republished under its Apache-2.0 licence (© carverauto). 742 words, ~2,367 tokens.

Download SKILL.mdSave it as .claude/skills/demo-web-ng-fastpath/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
demo-web-ng-fastpath
description
Refresh the Kubernetes `demo` namespace with a web-ng-only change using the ServiceRadar fast path. Use when the diff only touches `elixir/web-ng/**` and the user wants a faster local demo rollout without rebuilding the full image graph. Covers scope verification, copying unchanged images forward, rebuilding the production `serviceradar-web-ng` release locally, pushing with `crane`, signing with the OpenBao release key, patching Argo, and verifying the rollout. Do not use when non-web-ng services changed or when cutting a release.

Demo Web-NG Fast Path

Overview

Use this skill when a change is isolated to elixir/web-ng/** and the goal is to test it in demo quickly. Rebuild only serviceradar-web-ng, copy the other demo images forward to the new immutable tag, sign the new web-ng image, patch Argo, and verify the rollout.

Formal releases use semver tags, such as v1.2.41, and ArgoCD Image Updater. This skill is only for temporary unpublished sha-... demo testing.

Workflow

  1. Work from the repo root.
  2. Determine the new immutable tag from git rev-parse HEAD.
  3. Verify the diff only touches elixir/web-ng/**.
  4. Identify the currently deployed demo tag.
  5. Copy every unchanged demo image from the old tag to the new tag.
  6. Build a local production web-ng release.
  7. Package and push the new serviceradar-web-ng image with crane.
  8. Sign the new web-ng digest with the OpenBao-backed release key.
  9. Patch serviceradar-demo-prod to the new tag.
  10. Watch Argo and the key workloads until the rollout completes.

Guardrails

  • Use this only when the diff is actually web-ng-only. If anything outside elixir/web-ng/** changed, fall back to $demo-local-rollout.
  • Do not use this for release cuts or any namespace other than demo unless the user explicitly redirects you.
  • Do not leave a formal release rollout on a sha-... tag. After testing is complete, use $release-cut-and-demo-roll to return demo to the published semver/Image Updater path.
  • Do not skip signing. demo admission is Kyverno-enforced.
  • Sign by digest, not by tag, whenever possible.
  • Keep the other demo images identical by copying them forward from the currently deployed tag.

Verify The Scope First

Run:

bash
git diff --name-only <currently-deployed-sha>..HEAD

Proceed only if every changed file is under elixir/web-ng/.

Copy Unchanged Images Forward

Copy the unchanged images from the current demo tag to the new tag with crane:

bash
/tmp/gobin/crane copy \
  registry.carverauto.dev/serviceradar/<image>:sha-<old> \
  registry.carverauto.dev/serviceradar/<image>:sha-<new>

Repeat for:

  • arancini
  • serviceradar-agent
  • serviceradar-agent-gateway
  • serviceradar-core-elx
  • serviceradar-datasvc
  • serviceradar-db-event-writer
  • serviceradar-faker
  • serviceradar-flow-collector
  • serviceradar-log-collector
  • serviceradar-rperf-client
  • serviceradar-tools
  • serviceradar-trapd
  • serviceradar-zen

Leave serviceradar-log-collector-tcp alone unless the user explicitly changed that path too.

Build The Production Web-NG Release

From elixir/web-ng:

bash
MIX_ENV=prod HEX_HTTP_CONCURRENCY=1 HEX_HTTP_TIMEOUT=120 mix deps.compile
MIX_ENV=prod HEX_HTTP_CONCURRENCY=1 HEX_HTTP_TIMEOUT=120 mix compile
MIX_ENV=prod HEX_HTTP_CONCURRENCY=1 HEX_HTTP_TIMEOUT=120 mix assets.deploy
MIX_ENV=prod HEX_HTTP_CONCURRENCY=1 HEX_HTTP_TIMEOUT=120 mix release --path /tmp/serviceradar_web_ng_release_<shortsha>

Package And Push The Web-NG Image

Create the image layer tarball:

bash
tar --owner=10001 --group=10001 --transform='s,^,app/,' \
  -cf /tmp/serviceradar_web_ng_layer_<shortsha>.tar \
  -C /tmp/serviceradar_web_ng_release_<shortsha> .

Append the release onto the pinned Elixir base image and then mutate the runtime config:

bash
/tmp/gobin/crane append \
  --platform linux/amd64 \
  -b index.docker.io/hexpm/elixir:1.19.4-erlang-28.3-debian-bookworm-20251208-slim \
  -f /tmp/serviceradar_web_ng_layer_<shortsha>.tar \
  -t registry.carverauto.dev/serviceradar/serviceradar-web-ng:sha-<new>

/tmp/gobin/crane mutate \
  --platform linux/amd64 \
  --tag registry.carverauto.dev/serviceradar/serviceradar-web-ng:sha-<new> \
  --entrypoint /app/bin/serviceradar_web_ng \
  --cmd start \
  --env HOME=/app \
  --env PATH=/app/bin:/usr/local/bin:/usr/bin:/bin \
  --env PHX_SERVER=true \
  --env MIX_ENV=prod \
  --exposed-ports 4000/tcp \
  --user 10001:10001 \
  --workdir /app \
  registry.carverauto.dev/serviceradar/serviceradar-web-ng:sha-<new>

Capture the pushed digest with:

bash
/tmp/gobin/crane digest registry.carverauto.dev/serviceradar/serviceradar-web-ng:sha-<new>
Show full SKILL.md (387 more words)Show less

Verified Facts (2026-08-22, live run)

These were each confirmed against the live carverauto cluster during a real web-ng roll. Do not re-derive them.

  • OpenBao is HTTPS. Through the port-forward, https://127.0.0.1:18200 works and http:// returns 400 Client sent an HTTP request to an HTTPS server.
  • The role is forgejo-signing-runner (namespace forgejo-actions), NOT forgejo-runner. The plain forgejo-runner role does not exist. A successful login returns policies ["cosign-runner","default","plugin-upload-signing"].
  • .argocd-source-serviceradar-demo-prod.yaml REPLACES helm.parameters at render time. This is stronger than a race: a kubectl patch of spec.source.helm.parameters on serviceradar-demo-prod persists in the Application spec, syncs Synced|Healthy|Succeeded, and is still completely ignored — only the parameters listed in that file on demo/prod-release reach Helm. Any parameter you need (global.imageTag, image.digests.*) must be committed to that file on demo/prod-release.
  • image.digests.<service> is a real per-service escape hatch (_helpers.tpl serviceradar.imageRefSuffix): it short-circuits ahead of the tag, so you can move ONE service and leave every other image on the already-signed release tag — one signature instead of fifteen. Service key for web-ng is webNg. It still has to go in the .argocd-source-... file to take effect.
  • make push_all also moves latest on every image (oci_push carries static_tags = ["latest"]), despite advice elsewhere to "tag only sha-<commit>". It does NOT move v<VERSION>: scripts/workspace_status.sh emits STABLE_VERSION dev unless a matching v<VERSION> git tag points at HEAD, and container_tags.bzl filters vdev. Verify with git tag --points-at HEAD before pushing.
  • Claude Code auto mode blocks the signing flow unless these allow rules exist in .claude/settings.local.json, and the commands are run discretely (a bash -c '...' wrapper defeats prefix matching): Bash(kubectl create token:*), Bash(curl -sS -k -X POST https://127.0.0.1:18200/v1/auth/kubernetes/login:*), Bash(cosign sign:*), Bash(cosign verify:*). Keep the JWT and Vault token in files; never put them on a command line.

Prepare OpenBao Signing Env

Port-forward the signer if needed:

bash
kubectl port-forward -n openbao-system svc/openbao-active 18200:8200

Mint a Forgejo runner service-account token and exchange it for a Vault token:

bash
OPENBAO_ADDR=https://127.0.0.1:18200
OPENBAO_K8S_ROLE=forgejo-signing-runner   # NOT forgejo-runner (that role does not exist -> 403)
sa_jwt="$(kubectl create token -n forgejo-actions forgejo-signing-runner)"
vault_token="$({
  curl -sS -k \
    -H 'Content-Type: application/json' \
    -d "{\"role\":\"${OPENBAO_K8S_ROLE}\",\"jwt\":\"${sa_jwt}\"}" \
    "${OPENBAO_ADDR}/v1/auth/kubernetes/login"  # HTTPS + -k: the listener is TLS, http:// returns 400
} | jq -er '.auth.client_token')"

Export:

bash
export VAULT_ADDR="$OPENBAO_ADDR"
export VAULT_TOKEN="$vault_token"
export COSIGN_KEY_REF=hashivault://cosign-release
export COSIGN_YES=true
export COSIGN_DOCKER_MEDIA_TYPES=1
export COSIGN_REFERRERS_MODE=legacy
export COSIGN_TLOG_UPLOAD=true

If signing fails with 403 permission denied, mint a fresh Vault token and retry.

Sign The Web-NG Digest

bash
cosign sign --key "$COSIGN_KEY_REF" \
  registry.carverauto.dev/serviceradar/serviceradar-web-ng@sha256:<digest>

Patch Demo Argo App

bash
kubectl patch application -n argocd serviceradar-demo-prod \
  --type merge \
  -p '{"spec":{"source":{"helm":{"parameters":[{"name":"global.imageTag","value":"sha-<new>"}]}}}}'

Verify Rollout

Wait for:

text
Synced|Healthy|Succeeded

Use:

bash
kubectl get application -n argocd serviceradar-demo-prod \
  -o jsonpath='{.status.sync.status}{"|"}{.status.health.status}{"|"}{.status.operationState.phase}{"\n"}'

Check the key deployments:

bash
kubectl get deploy -n demo \
  serviceradar-web-ng serviceradar-core serviceradar-agent serviceradar-tools \
  -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{range .spec.template.spec.containers[*]}{.image}{" "}{end}{"\n"}{end}'

Inspect pods and jobs if Argo is still Progressing:

bash
kubectl get pods -n demo -o wide
kubectl get jobs -n demo

Do not report success until the new serviceradar-web-ng pod is running on the new tag and Argo reaches Succeeded.

Report Back

Close with:

  • target immutable tag
  • old tag that was copied forward
  • web-ng digest that was signed
  • final Argo status
  • any lingering rollout risk

© carverauto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/demo-web-ng-fastpath of carverauto/serviceradar.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 2563b3f

Compare with similar skills

Demo Web Ng Fastpath next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Demo Web Ng Fastpath compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Demo Web Ng Fastpath this skillcarverauto/serviceradar921—~2.4kAutomated safety check: PassApache-2.0
Asdfjjmartres/opencode133—~2.1kAutomated safety check: NotesMIT
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • Asdf

    jjmartres/opencode

    A skill your agent uses whenever the user wants to install, configure, or use asdf (asdf-vm), the universal version manager.

    133 GitHub stars~2.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: notes
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from carverauto/serviceradar

All 18 skills in this repo
  • Demo Cnpg Local Web Ng

    carverauto/serviceradar

    Run ServiceRadar web-ng locally against the live Kubernetes demo CNPG database for dashboard, SRQL, services, and UI testing.

    921 GitHub stars~672 tokensUpdated today
    Auto-check passed
  • Web Ng Docker Loop

    carverauto/serviceradar

    Run ServiceRadar elixir/web-ng locally against the Docker Compose CNPG database with copied mTLS certs and Docker secrets, then verify dashboard UI changes with Playwright.

    921 GitHub stars~737 tokensUpdated today
    Auto-check passed
  • Demo Local Rollout

    carverauto/serviceradar

    Build unpublished sha-... An agent skill from carverauto/serviceradar.

    921 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Fieldsurvey Local Web Ng

    carverauto/serviceradar

    Run ServiceRadar web-ng locally against the Kubernetes demo namespace FieldSurvey data, including CNPG NodePort access, NATS Object Store artifact access, authenticated browser checks, and…

    921 GitHub stars~785 tokensUpdated today
    Auto-check passed
  • Release Cut And Demo Roll

    carverauto/serviceradar

    Cut a ServiceRadar release and roll the Kubernetes demo namespace to the resulting published semver image tag through the guarded ArgoCD release branch.

    921 GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Daisyui

    carverauto/serviceradar

    Official daisyUI component library skill. An agent skill from carverauto/serviceradar.

    921 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Demo Web Ng Fastpath

What does Demo Web Ng Fastpath do?

Refresh the Kubernetes demo namespace with a web-ng-only change using the ServiceRadar fast path. Demo Web Ng Fastpath is an agent skill from carverauto/serviceradar. Refresh the Kubernetes demo namespace with a web-ng-only change using the ServiceRadar fast path.

When should I use Demo Web Ng Fastpath?

Demo Web Ng Fastpath fits situations like: the diff only touches elixir/web-ng/ and the user wants a faster local demo rollout without rebuilding the full image graph; non-web-ng services changed; cutting a release.

How do I install Demo Web Ng Fastpath in Claude Code?

Run `npx skills add carverauto/serviceradar --skill demo-web-ng-fastpath -a claude-code`. Or copy the skill folder (.agents/skills/demo-web-ng-fastpath in carverauto/serviceradar) into .claude/skills/demo-web-ng-fastpath in your project. Claude Code loads it when a task matches its description.

How do I install Demo Web Ng Fastpath in Codex?

Run `npx skills add carverauto/serviceradar --skill demo-web-ng-fastpath -a codex`. Or copy the skill folder (.agents/skills/demo-web-ng-fastpath in carverauto/serviceradar) into .agents/skills/demo-web-ng-fastpath in your project. Codex loads it when a task matches its description.

Can I use Demo Web Ng Fastpath in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add carverauto/serviceradar --skill demo-web-ng-fastpath -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/demo-web-ng-fastpath, .gemini/skills/demo-web-ng-fastpath, .github/skills/demo-web-ng-fastpath and .opencode/skills/demo-web-ng-fastpath in your project.

What does Demo Web Ng Fastpath need to run?

Going by SKILL.md and its folder, Demo Web Ng Fastpath needs the command-line tools its instructions call (kubectl, git, curl, jq, make and bash) and credentials named VAULT_TOKEN. Our summary lists: Docker; A credential in VAULT_TOKEN.

Does Demo Web Ng Fastpath access the network?

SKILL.md contains no URLs. Its commands use git and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Demo Web Ng Fastpath safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Demo Web Ng Fastpath use?

Demo Web Ng Fastpath is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Demo Web Ng Fastpath use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Demo Web Ng Fastpath?

Skills that share tags, products or a category with Demo Web Ng Fastpath: Asdf (jjmartres/opencode, 133 stars), Sim Helm (simstudioai/sim, 30k stars), Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars) and Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Demo Web Ng Fastpath?

carverauto (a GitHub organization) maintains it in carverauto/serviceradar, which has 921 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 10, 2026.

Source: carverauto/serviceradar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.