Devops Excellence
majiayu000/spellbook
DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.
Atmos Modernization: migrate deprecated or legacy Atmos patterns to current names, Native CI, Atmos Pro drift detection, dependencies.components, nametemplate, and declared secrets
$ npx skills add cloudposse/atmos --skill atmos-modernization -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cloudposse/atmos atmos-modernization --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-modernization .claude/skills/atmos-modernization && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "atmos-modernization" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernization into .claude/skills/atmos-modernization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-modernization", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernizationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cloudposse/atmos --skill atmos-modernization -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cloudposse/atmos atmos-modernization --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agent-skills/skills/atmos-modernization .agents/skills/atmos-modernization && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "atmos-modernization" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernization into .agents/skills/atmos-modernization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-modernization", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudposse/atmos --skill atmos-modernization -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cloudposse/atmos atmos-modernization --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agent-skills/skills/atmos-modernization .cursor/skills/atmos-modernization && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "atmos-modernization" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernization into .cursor/skills/atmos-modernization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-modernization", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cloudposse/atmos.git --path agent-skills/skills/atmos-modernization--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cloudposse/atmos --skill atmos-modernization -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cloudposse/atmos atmos-modernization --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agent-skills/skills/atmos-modernization .gemini/skills/atmos-modernization && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "atmos-modernization" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernization into .gemini/skills/atmos-modernization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-modernization", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cloudposse/atmos atmos-modernizationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cloudposse/atmos --skill atmos-modernization -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .github/skills && cp -r skills-src/agent-skills/skills/atmos-modernization .github/skills/atmos-modernization && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "atmos-modernization" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernization into .github/skills/atmos-modernization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-modernization", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudposse/atmos --skill atmos-modernization -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cloudposse/atmos atmos-modernization --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agent-skills/skills/atmos-modernization .opencode/skills/atmos-modernization && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "atmos-modernization" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-modernization into .opencode/skills/atmos-modernization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-modernization", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
atmos-modernizationAtmos Modernization: migrate deprecated or legacy Atmos patterns to current names, Native CI, Atmos Pro drift detection, dependencies.components, nametemplate, and declared secrets
Atmos Modernization is an agent skill from cloudposse/atmos. Atmos Modernization: migrate deprecated or legacy Atmos patterns to current names, Native CI, Atmos Pro drift detection, dependencies.components, nametemplate, and declared secrets
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Legacy modernization and GitOps. It works with Terraform and GitHub Actions. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 36726ae. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
apt-getFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Atmos Modernization loads about 1.8k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 653 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cloudposse/atmos at commit 36726ae, republished under its Apache-2.0 licence (© cloudposse). 653 words, ~1,828 tokens.
.claude/skills/atmos-modernization/SKILL.md (or your agent's skills folder).Use this skill when updating older Atmos projects to current conventions. "Atmos Modernization" is the umbrella term for replacing legacy patterns with supported, current patterns.
| Legacy pattern | Replace with |
|---|---|
name_pattern | name_template or explicit stack name |
settings.depends_on | dependencies.components |
Custom command type: component/type: stack on arguments, or semantic_type: component/semantic_type: stack on flags | provides: component/provides: stack on both arguments and flags |
cloudposse/github-action-atmos* wrapper actions | Native CI with direct atmos commands |
cloudposse/github-action-atmos-component-updater | atmos vendor update --pull-request with native GitHub PR publishing |
cloudposse/github-action-setup-atmos as default | GitHub Actions container ghcr.io/cloudposse/atmos:<version> |
apt-get install docker.io in an Atmos container job | Remove it: the official Atmos image already ships with docker.io |
GitHub Actions concurrency around jobs or workflows that invoke atmos | An explicit promotion workflow or deployment controller — environments and merge queues are approval/merge-order controls, not deployment-order guarantees; a concurrency group evicts its pending run regardless of cancel-in-progress |
hashicorp/setup-terraform / opentofu/setup-opentofu in Atmos jobs | Atmos dependencies.tools and toolchain |
Manual atmos toolchain install <tool> preinstall steps for Atmos-owned tools | Declarative dependencies.tools at the owning component, workflow, hook, or custom command |
Large inline workflow/custom-command shell scripts, repeated echo, shell loops, ad hoc sleeps | Native step types such as atmos, toast, table, parallel, matrix, wait, container, emulator, and http |
| Hand-rolled scheduled drift GitHub Actions | Atmos Pro drift detection |
cloudposse/github-action-atmos-terraform-drift-* | settings.pro.drift_detection plus atmos terraform plan --upload-status |
| Secret values through raw store calls | Declared secrets.vars plus !secret |
| Legacy hook event spelling | Modern dotted lifecycle events such as after.terraform.plan |
| Static GitHub tokens in URLs | Atmos Auth github/sts through Atmos Pro |
cloudposse/terraform-aws-components sources | Repos in the cloudposse-terraform-components organization |
Parser-specific doubled double quotes ("") in !terraform.state or !terraform.output expressions | Direct YQ expressions; quote only as required by YAML |
atmos describe stacks, atmos list components, and
atmos validate stacks.atmos describe component <component> -s <stack> before changing CI.Older stack manifests may wrap an entire YQ expression in double quotes and double its inner
double quotes. That parser-specific escaping is obsolete: !terraform.state and
!terraform.output parse the component, optional stack, and remaining expression directly.
Replace legacy string-default quoting:
# Before
username: !terraform.output config ".username // ""default-user"""
# After
username: !terraform.output config .username // "default-user"Replace legacy string-concatenation quoting:
# Before
postgres_url: !terraform.state aurora-postgres ".master_hostname | ""jdbc:postgresql://"" + . + "":5432/events"""
# After
postgres_url: !terraform.state 'aurora-postgres .master_hostname | "jdbc:postgresql://" + . + ":5432/events"'The outer single quotes in the concatenation example are YAML quoting, not function-parser escaping. Use YAML quoting only when the scalar requires it; for complete YAML and YQ quoting guidance, see the atmos-yaml-functions skill.
New CI should run Atmos directly, preferably in the Atmos container image:
jobs:
plan:
runs-on: ubuntu-latest
container:
image: ghcr.io/cloudposse/atmos:${{ vars.ATMOS_VERSION }}
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@v6
- run: atmos terraform plan vpc -s prodThe official Atmos image includes docker.io, so do not add an apt-get install docker.io step
to containerized Atmos jobs. Docker-backed commands use the runner-provided Docker daemon/socket.
Use atmos describe affected --format=matrix for PR matrices and atmos list instances --format=matrix for full estate operations.
Replace the legacy Component Updater action with checkout plus atmos vendor update --pull-request.
Keep update selection under vendor.update (including named groups) and PR/summary policy under
vendor.ci. Grant only contents: write, pull-requests: write, and issues: write where
needed. Atmos writes a native GitHub step summary for every vendor update; it links to any created
or reused PR. Do not use third-party actions for update, commit, push, or PR creation. For exact
configuration and staged migration, use the vendoring
component-updater reference and migration
from-component-updater reference.
Atmos Pro is the product path for drift detection. Enable drift per stack/component:
settings:
pro:
enabled: true
drift_detection:
enabled: trueThen upload plan status:
atmos terraform plan vpc -s prod --upload-statusUse dependencies.components for component, file, and folder dependencies:
dependencies:
components:
- component: vpc
- component: dns-zone
stack: plat-ue2-prod
- kind: file
path: configs/service.yaml
- kind: folder
path: src/lambdaTreat settings.depends_on as migration-only syntax.
Check source, vendor.yaml, component.yaml, Terraform module sources, and documentation
examples for cloudposse/terraform-aws-components. That monorepo is deprecated; components moved
to individual repositories in the cloudposse-terraform-components organization.
For example, migrate VPC references from the old monorepo form:
source: "github.com/cloudposse/terraform-aws-components.git//modules/vpc?ref=1.450.0"to the component repository form:
source: "github.com/cloudposse-terraform-components/aws-vpc.git?ref=1.450.0"Keep versions pinned when changing sources, and validate the target repository/tag exists before updating production stacks.
© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agent-skills/skills/atmos-modernization of cloudposse/atmos.
Open the folder on GitHubat commit 36726ae
Atmos Modernization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Atmos Modernization this skillcloudposse/atmos | 1.4k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Devops Excellencemajiayu000/spellbook | 286 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Devops EngineerYikai-Liao/symusic | 189 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Devops Automatorcuriositech/some_claude_skills | 243 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| CI CDEliasOulkadi/shokunin | 114 | — | ~3.4k | Automated safety check: Notes | MIT |
majiayu000/spellbook
DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.
Yikai-Liao/symusic
Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.
curiositech/some_claude_skills
Expert DevOps engineer for CI/CD, IaC, Kubernetes, and deployment automation.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
EliasOulkadi/shokunin
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…
fluxcd/agent-skills
Flux CD and Flux Operator expert — answers questions and generates schema-validated YAML for all Flux CRDs (not repo auditing or live cluster debugging).
cloudposse/atmos
A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…
cloudposse/atmos
Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.
cloudposse/atmos
Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.
cloudposse/atmos
Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…
cloudposse/atmos
Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…
cloudposse/atmos
Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…
Works with
Categories
Atmos Modernization: migrate deprecated or legacy Atmos patterns to current names, Native CI, Atmos Pro drift detection, dependencies.components, nametemplate, and declared secrets. Atmos Modernization is an agent skill from cloudposse/atmos.
Atmos Modernization fits situations like: tasks that involve Legacy modernization; tasks that involve GitOps.
Run `npx skills add cloudposse/atmos --skill atmos-modernization -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-modernization in cloudposse/atmos) into .claude/skills/atmos-modernization in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cloudposse/atmos --skill atmos-modernization -a codex`. Or copy the skill folder (agent-skills/skills/atmos-modernization in cloudposse/atmos) into .agents/skills/atmos-modernization in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-modernization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-modernization, .gemini/skills/atmos-modernization, .github/skills/atmos-modernization and .opencode/skills/atmos-modernization in your project.
Going by SKILL.md and its folder, Atmos Modernization needs the command-line tools its instructions call (apt-get). Our summary lists: Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Atmos Modernization is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Atmos Modernization: Devops Excellence (majiayu000/spellbook, 286 stars), Devops Engineer (Yikai-Liao/symusic, 189 stars), Devops Automator (curiositech/some_claude_skills, 243 stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,396 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 8, 2026.
Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.