Database Backups
sickn33/agentic-awesome-skills
Implement database backup strategies. An agent skill from sickn33/agentic-awesome-skills.
A skill your agent uses when deploying or operating a workload on DigitalOcean — Droplet vs App Platform vs Functions, doctl, app spec YAML, Managed Postgres/MySQL/Valkey on the VPC, S3-compatible…
$ npx skills add ericrisco/rsc-harness --skill digitalocean -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness digitalocean --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/digitalocean .claude/skills/digitalocean && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "digitalocean" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/digitalocean into .claude/skills/digitalocean/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "digitalocean", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/digitaloceanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill digitalocean -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness digitalocean --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/digitalocean .agents/skills/digitalocean && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "digitalocean" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/digitalocean into .agents/skills/digitalocean/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "digitalocean", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill digitalocean -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness digitalocean --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/digitalocean .cursor/skills/digitalocean && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "digitalocean" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/digitalocean into .cursor/skills/digitalocean/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "digitalocean", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/digitalocean--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill digitalocean -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness digitalocean --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/digitalocean .gemini/skills/digitalocean && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "digitalocean" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/digitalocean into .gemini/skills/digitalocean/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "digitalocean", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness digitaloceanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill digitalocean -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/digitalocean .github/skills/digitalocean && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "digitalocean" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/digitalocean into .github/skills/digitalocean/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "digitalocean", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill digitalocean -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness digitalocean --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/digitalocean .opencode/skills/digitalocean && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "digitalocean" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/digitalocean into .opencode/skills/digitalocean/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "digitalocean", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
digitaloceanA skill your agent uses when deploying or operating a workload on DigitalOcean — Droplet vs App Platform vs Functions, doctl, app spec YAML, Managed Postgres/MySQL/Valkey on the VPC, S3-compatible…
Digitalocean is an agent skill from ericrisco/rsc-harness. Use when deploying or operating a workload on DigitalOcean — Droplet vs App Platform vs Functions, doctl, app spec YAML, Managed Postgres/MySQL/Valkey on the VPC, S3-compatible Spaces + CDN. NOT host-agnostic CI/CD or rollback strategy (that is deployment), NOT a bare Hetzner VPS (that is hetzner), NOT another managed PaaS (that is railway).
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/app-spec.md`).
It sits in DevOps & Cloud, covering File uploads and storage and CI/CD. It works with MySQL and PostgreSQL. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
doctlbrewFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
nyc3.digitaloceanspaces.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_SIGNING_KEYSPACES_KEYSPACES_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Digitalocean loads about 2.8k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,182 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# tar xf doctl-*.tar.gz && sudo mv doctl /usr/local/binAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,182 words, ~2,840 tokens.
.claude/skills/digitalocean/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.You own one decision: where on DO does this run, and how do I ship it. Host-agnostic
CI/CD, release gating and rollback strategy are ../deployment/SKILL.md; authoring the
Dockerfile is docker; DNS records and the registrar are domains-dns; a bare Hetzner box
and its economics are hetzner. Pick the compute model first, then wire data and storage,
then the ops that bite in production.
workload → [Droplet | App Platform | Functions] → Managed DB (VPC private host) → Spaces (S3 + CDN)
raw VPS managed PaaS event fn Postgres/MySQL/Valkey object storeSettle this before writing a single command. Most web apps want App Platform; reach for a Droplet only when you need the box itself.
| Axis | Droplet (VPS) | App Platform (PaaS) | Functions |
|---|---|---|---|
| Control | Full root, any daemon, any port | Build+run only, no SSH | Per-invocation, no host |
| Ops burden | You patch/secure/restart it | DO runs it, auto TLS, auto deploy | Zero infra |
| Price floor | Per-second billing since 2026-01-01, min 60s or $0.01 | 3 static sites free; dynamic from $5/mo per service | Pay per call |
| Scaling | Resize/clone/load-balance yourself | Set instance count + size, autoscale | Implicit |
| Best for | Stateful daemons, cron hosts, custom networking, "give me a Linux box" | Web service / API / worker / static site from a repo | Event glue, webhooks |
Rules of thumb:
doctl is the official DO CLI; it drives everything below.
# macOS
brew install doctl
# Linux: download the release tarball from github.com/digitalocean/doctl/releases, then:
# tar xf doctl-*.tar.gz && sudo mv doctl /usr/local/bin
# Authenticate with a token from cloud.digitalocean.com/account/api/tokens
doctl auth init # pastes a token, validates, stores a context
doctl auth init --context prod # a named context per account/env
doctl auth switch --context prod # switch the active context
doctl account get # verify the token worksNever commit the token. It is a full-account credential. Keep it in your shell keychain,
a secret manager, or CI secret — never in the repo, never in an app spec. Why: a leaked
dop_v1_… token lets anyone create/destroy your whole account.
App Platform deploys from an app spec (YAML or JSON). Treat the spec as the source of truth, version it, and apply it with doctl.
# .do/app.yaml — minimal web service + managed Postgres
name: my-api
region: nyc
services:
- name: web
github:
repo: me/my-api
branch: main
deploy_on_push: true
instance_size_slug: apps-s-1vcpu-1gb # ~$5/mo basic; sizes go up to dedicated
instance_count: 1
http_port: 8080
envs:
- key: NODE_ENV
value: production
scope: RUN_TIME # RUN_TIME | BUILD_TIME | RUN_AND_BUILD_TIME
- key: DATABASE_URL
value: ${db.DATABASE_URL} # injected from the managed DB below
scope: RUN_TIME
- key: API_SIGNING_KEY
value: ${API_SIGNING_KEY}
type: SECRET # encrypted at rest; never plaintext
scope: RUN_TIME
databases:
- name: db
engine: PG
production: trueLifecycle — validate, then create or update:
doctl apps spec validate .do/app.yaml # structural lint, no deploy
doctl apps create --spec .do/app.yaml # first deploy; prints the app id
doctl apps update <app-id> --spec .do/app.yaml # apply changes (and to roll back: re-apply the prior spec)
doctl apps list # find the idEnv scoping that matters:
type: SECRET encrypts the value at rest and hides it in the dashboard. Use it for every
key, token, password. Plain value: is readable.scope: BUILD_TIME for things only the build needs; RUN_TIME for runtime; don't leak
build-only secrets into the running container.${db.DATABASE_URL} (and ${db.HOSTNAME}, ${db.PORT}, etc.) are auto-injected when the
service references a databases: entry — you never paste the connection string.Operate:
doctl apps logs <app-id> --type run --follow # run | build | deploy
doctl apps logs <app-id> <component> --type run # one componentRollback = re-apply the previous spec (git-revert .do/app.yaml and doctl apps update),
or redeploy a prior deployment from the dashboard. There is no magic rollback verb — your
git history of the spec is the rollback mechanism.
For multi-component apps (web + worker + static_site + job + db, health checks, ingress
routes, autoscaling, instance-size table, alerts) see references/app-spec.md.
A Droplet is a Linux VPS. Bootstrap it declaratively, lock it down with a cloud firewall.
doctl compute droplet create web-1 \
--region nyc3 --size s-1vcpu-1gb --image ubuntu-24-04-x64 \
--ssh-keys <fingerprint> \
--vpc-uuid <vpc-uuid> \
--user-data-file cloud-init.yaml \
--waitufw. A cloud firewall filters at DO's edge before traffic
reaches the box, and applies to a tag/group of Droplets. Use it as the real perimeter;
host ufw is defense-in-depth, not the only line. Why: a misconfigured ufw after a
reboot still leaves the edge firewall protecting you.Cloud-init recipes, firewall inbound/outbound rule sets, snapshot cadence + restore,
reserved-IP failover, and the VPC + private-DB layout live in references/droplet-ops.md.
Use the Managed Database product for Postgres/MySQL/Valkey — DO handles patching, failover, and backups.
../postgresdb/SKILL.md,
not here. This skill only provisions and wires the cluster.Spaces is S3-API-compatible object storage with a built-in CDN.
aws-cli/s3cmd against the regional endpoint:# boto3 against DO Spaces (nyc3 region/endpoint)
import boto3
s3 = boto3.client(
"s3",
endpoint_url="https://nyc3.digitaloceanspaces.com",
region_name="nyc3",
aws_access_key_id="<SPACES_KEY>", # Spaces key, not the DO API token
aws_secret_access_key="<SPACES_SECRET>",
)
s3.upload_file("photo.jpg", "my-bucket", "photo.jpg", ExtraArgs={"ACL": "public-read"})Serve public assets through the bucket's CDN edge URL; set CORS on the bucket if a browser fetches it cross-origin, and a lifecycle rule to expire/transition old objects.
../monitoring.instance_count/instance_size_slug in the spec and re-applying;
capacity strategy that's host-agnostic is ../scaling.| Anti-pattern | Why it bites | Do instead |
|---|---|---|
Hardcoding a dop_v1_… token or DB password as a plain value: in the app spec | Spec is in git, value is readable, full-account compromise | type: SECRET env, or ${db.*} injection; token only in doctl auth |
| Connecting app→DB over the public host | Public exposure + egress cost + latency | VPC private host + trusted source |
| Running a stateful long-lived daemon as an App Platform service | Components are restartable/stateless; state is lost | Droplet (or a job/worker designed to be stateless) |
Sizing a dedicated apps-d-2vcpu-4gb (~$78/mo) for a hobby app | Paying enterprise rates for toy traffic | Start apps-s-1vcpu-1gb (~$5) and scale up on real metrics |
ufw on the Droplet as the only firewall | A bad reboot/config leaves the host open | Cloud firewall at the edge + host ufw as defense-in-depth |
| Hand-installing Postgres on a Droplet "to save money" | You now own patching, backups, failover | Managed Database unless you have a hard reason |
| Powering off a Droplet to stop billing | Powered-off Droplets still bill for storage | Snapshot then destroy |
| Leaving a reserved IP unassigned | It's billed when not attached | Release it |
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/digitalocean of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Digitalocean next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Digitalocean this skillericrisco/rsc-harness | 156 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Database Backupssickn33/agentic-awesome-skills | 47k | 2 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Chdb SQLvemetric/vemetric | 394 | 1 repos | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Mfs Findzilliztech/mfs | 150 | — | ~4k | Automated safety check: Pass | Apache-2.0 | |
| Mfs Ingestzilliztech/mfs | 150 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Create Environmentgodatadriven/whirl | 205 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
sickn33/agentic-awesome-skills
Implement database backup strategies. An agent skill from sickn33/agentic-awesome-skills.
vemetric/vemetric
A skill your agent uses when the user wants to run SQL — especially analytical SQL — on local files (parquet/csv/json), URLs, S3 paths, or remote databases (Postgres, MySQL, MongoDB, ClickHouse…
zilliztech/mfs
Search, grep, browse, and read across registered MFS data sources via the mfs CLI — codebases, docs, PDFs, web crawls, databases (postgres/mysql/mongo/snowflake/bigquery), issue trackers…
zilliztech/mfs
Register, update, or re-sync data sources for MFS so they become searchable — postgres / mysql / mongo / snowflake / bigquery, github / jira / linear / notion / hubspot / zendesk, slack / discord /…
godatadriven/whirl
Create a new Whirl environment in the envs/ directory. An agent skill from godatadriven/whirl.
Aedelon/claude-code-blueprint
Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when deploying or operating a workload on DigitalOcean — Droplet vs App Platform vs Functions, doctl, app spec YAML, Managed Postgres/MySQL/Valkey on the VPC, S3-compatible…. Digitalocean is an agent skill from ericrisco/rsc-harness. Use when deploying or operating a workload on DigitalOcean — Droplet vs App Platform vs Functions, doctl, app spec YAML, Managed Postgres/MySQL/Valkey on the VPC, S3-compatible Spaces + CDN.
Digitalocean fits situations like: operating a workload on DigitalOcean — Droplet vs App Platform vs Functions; managed Postgres/MySQL/Valkey on the VPC; S3-compatible Spaces + CDN.
Run `npx skills add ericrisco/rsc-harness --skill digitalocean -a claude-code`. Or copy the skill folder (skills/digitalocean in ericrisco/rsc-harness) into .claude/skills/digitalocean in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill digitalocean -a codex`. Or copy the skill folder (skills/digitalocean in ericrisco/rsc-harness) into .agents/skills/digitalocean in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill digitalocean -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/digitalocean, .gemini/skills/digitalocean, .github/skills/digitalocean and .opencode/skills/digitalocean in your project.
Going by SKILL.md and its folder, Digitalocean needs a shell for the scripts in its folder, the command-line tools its instructions call (doctl and brew) and credentials named API_SIGNING_KEY, SPACES_KEY and SPACES_SECRET. Our summary lists: Python 3; A Bash shell; Docker; A credential in API_SIGNING_KEY; A credential in SPACES_KEY.
SKILL.md names 1 domain. In commands or code: nyc3.digitaloceanspaces.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Digitalocean is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Digitalocean: Database Backups (sickn33/agentic-awesome-skills, 47k stars), Chdb SQL (vemetric/vemetric, 394 stars), Mfs Find (zilliztech/mfs, 150 stars) and Mfs Ingest (zilliztech/mfs, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.