Agent skill

Fly Io

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when deploying or operating an app on Fly.io — writing fly.toml, placing Machines in regions near users, attaching Volumes, managing secrets, or picking a scaling lever…

MITAuto-check passedDevOps & Cloud

Install Fly Io

skills CLI
$ npx skills add ericrisco/rsc-harness --skill fly-io -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness fly-io --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fly-io .claude/skills/fly-io && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fly-io
GitHub stars
156
Token cost
~2.8k tokens
SKILL.md length
1,097 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when deploying or operating an app on Fly.io — writing fly.toml, placing Machines in regions near users, attaching Volumes, managing secrets, or picking a scaling lever…

  • Operating an app on Fly.io — writing fly.toml
  • SKILL.md covers Mental model, Deploy fast (4 commands), A fly.toml that works and Regions: place Machines near…, plus 6 more sections
  • Runs Shell scripts from its folder; calls fly; needs STRIPE_KEY and SESSION_SECRET
  • Placing Machines in regions near users

What it does

Fly Io is an agent skill from ericrisco/rsc-harness. Use when deploying or operating an app on Fly.io — writing fly.toml, placing Machines in regions near users, attaching Volumes, managing secrets, or picking a scaling lever (autostop/autostart, scale count, fly-replay). NOT choosing which host to deploy on (that is deployment), NOT a git-push PaaS with no regions model (that is railway).

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/fly-toml.md`).

It sits in DevOps & Cloud, covering Deployment. It works with Git. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Operating an app on Fly.io — writing fly.toml
  • Placing Machines in regions near users
  • Attaching Volumes
  • Managing secrets

Example prompts

  • “/fly-io”

Requirements

  • A Bash shell
  • Docker
  • A credential in STRIPE_KEY
  • A credential in SESSION_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • fly

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STRIPE_KEY
    • SESSION_SECRET
    • OLD_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fly Io loads about 2.8k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,097 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,097 words, ~2,827 tokens.

Download SKILL.mdSave it as .claude/skills/fly-io/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
fly-io
description
Use when deploying or operating an app on Fly.io — writing fly.toml, placing Machines in regions near users, attaching Volumes, managing secrets, or picking a scaling lever (autostop/autostart, scale count, fly-replay). NOT choosing which host to deploy on (that is `deployment`), NOT a git-push PaaS with no regions model (that is `railway`).
tags
fly-io, deployment, machines, regions, scaling
recommends
docker, scaling, postgresdb, railway, domains-dns
origin
risco

Deploy on Fly.io

You are deploying an app to Fly.io: a fly.toml, Machines (Firecracker microVMs) placed in regions close to users, optional region-pinned Volumes, secrets, and the right scaling lever. Get the mental model right first, then the config follows. If none of that placement control matters, ../railway/SKILL.md is the git-push PaaS with no Machines/regions model.

Mental model

  • App is the logical unit. It owns a name, a primary_region, and config in fly.toml. Why: every command targets an app.
  • Process groups ([processes], e.g. web, worker) split one image into roles. Why: a web group takes traffic, a worker group does not — they bind services and VMs separately.
  • Machines are Firecracker microVMs running your image. Each runs in exactly one region. Why: latency and volumes are per-Machine, so placement is the whole game.
  • Fly Proxy is the anycast front door. It routes a request to the nearest running Machine, can start a stopped one, and obeys fly-replay headers. Why: it is what makes "global" cheap — you do not run a load balancer.
  • Volumes are local NVMe disks pinned to one Machine in one region. No replication. Why: this single fact dictates every stateful architecture decision below.

Deploy fast (4 commands)

bash
fly launch                              # detects framework, generates fly.toml + Dockerfile, creates the app
fly secrets set DATABASE_URL=postgres://...  # restarts every Machine; never put this in [env]
fly deploy                              # builds image, runs release_command, rolls out Machines
fly scale count 2 --region iad,ams      # place Machines in Virginia + Amsterdam

fly launch is interactive and writes a starter fly.toml. Treat that file as a draft — review it against the next section before the first real deploy. Run fly status and fly logs after any deploy.

A fly.toml that works

toml
app            = "my-api"
primary_region = "iad"            # 3-letter region code: iad, ord, ams, syd, gru, nrt...

[build]
  # dockerfile = "Dockerfile"     # Fly builds from your Dockerfile; see ../docker/SKILL.md

[deploy]
  release_command = "npm run migrate"   # one-shot Machine that runs BEFORE the new version goes live
  strategy        = "rolling"            # rolling | bluegreen | canary | immediate

[processes]
  web    = "node server.js"
  worker = "node worker.js"

[http_service]
  internal_port       = 8080
  force_https         = true
  auto_stop_machines  = "stop"   # "off" | "stop" | "suspend" — set WITH auto_start_machines
  auto_start_machines = true
  min_machines_running = 0       # 0 = scale to zero; honored only in primary_region
  processes           = ["web"]

  [http_service.concurrency]
    type       = "requests"
    soft_limit = 200             # Proxy starts spreading load past this
    hard_limit = 250             # Proxy stops sending past this

[[vm]]                            # formerly [[compute]]
  size       = "shared-cpu-1x"
  memory     = "512mb"
  cpu_kind   = "shared"          # "shared" | "performance"
  processes  = ["web"]

[[mounts]]
  source       = "data"          # volume NAME, created with `fly volumes create data`
  destination  = "/data"
  processes    = ["web"]
  initial_size = "1gb"

Full field surface ([[services]] vs [http_service], health checks, [[statics]], [[files]], all VM sizes, [restart], [metrics]) lives in references/fly-toml.md — read it when you need a key that is not above. Custom domains, certs and registrar-level DNS are ../domains-dns/SKILL.md.

Regions: place Machines near users

Pick the branch first, then run the commands.

Your app is...StrategyHow
Stateless (no local disk; DB elsewhere)Replicate the Machine into more regionsfly scale count 2 --region iad,ams,syd
Stateful with a VolumeKeep writes in primary_region, add read replicas + fly-replaysee references/multi-region.md
Needs one extra box nowClone a single Machine (gets a fresh volume)fly machine clone <id> --region syd
bash
fly platform regions              # list region codes + names
fly scale count web=2 --region ams   # per-process, per-region count
fly scale show                    # what runs where, right now

Rules:

  • A request with no pinned region goes to the fastest Machine for that caller via anycast — multi-region is mostly "run Machines in more places."
  • fly scale count N --region a,b is the per-region count, not a total. Why: count 2 --region iad,ams means 2 in each, i.e. 4 Machines.
  • If any target region is out of capacity, the whole scale op fails — no partial placement. Retry with fewer regions or a different code.
  • "Slow for users in Sydney, app runs in iad" => add syd, not a bigger VM. Latency is distance, not CPU.

Volumes

A Fly Volume is a local NVMe disk pinned to one Machine in one region. There is no automatic replication between volumes. Encrypted at rest by default (--no-encryption to opt out — almost never do).

bash
fly volumes create data --region iad --size 3
fly volumes list
  • One volume attaches to one Machine. Two Machines cannot share a volume. Why: it is block storage on one host, not a network filesystem.
  • fly scale count on a group with a [[mounts]] creates a new empty volume per new Machine — it does not copy your data. This is the #1 stateful gotcha.
toml
# Bad: expecting two web Machines to "share" /data — they each get their own empty disk
[[mounts]]
  source      = "data"
  destination = "/data"
  processes   = ["web"]   # then `fly scale count web=3` => 3 separate, unsynced disks
toml
# Good: one writer with the volume; replicas are stateless and read via the DB/fly-replay
[[mounts]]
  source      = "data"
  destination = "/data"
  processes   = ["writer"]   # a single-Machine process group; scale `web` separately, stateless

Replication is your app's job (LiteFS, app-level streaming, or a managed DB), never the volume's. See references/multi-region.md.

Secrets

bash
fly secrets set STRIPE_KEY=sk_live_... SESSION_SECRET=...   # one rollout
fly secrets list           # shows NAME + digest + timestamp — never the value
fly secrets unset OLD_KEY
  • fly secrets set updates every Machine and restarts them — it resets the ephemeral filesystem. Why: batch your sets into one command so you trigger one rollout, not five.
  • Secrets arrive as environment variables in the guest. Read process.env.STRIPE_KEY.
  • Need a secret as a file on disk (a cert, a service-account JSON)? Use [[files]] with secret_name — see references/fly-toml.md.
toml
# Bad: secret baked into the image / committed config
[env]
  STRIPE_KEY = "sk_live_51H..."   # in git, in the image layers, leaked
bash
# Good: out of the repo, out of the image, encrypted in Fly's vault
fly secrets set STRIPE_KEY=sk_live_51H...

Treat secret hygiene as non-negotiable — see ../secure-coding/SKILL.md.

Show full SKILL.md (489 more words)Show less

Scaling: pick the right lever

LeverWhat it doesReach for it when
auto_stop_machines / auto_start_machinesFly Proxy stops/starts a pre-created pool by load; never creates/destroysBursty or idle traffic; cut cost on quiet hours
fly scale countYou set how many Machines exist per region/processSteady baseline capacity; geographic spread
fly-autoscaler (superfly/fly-autoscaler)Scales Machine count off any Prometheus metricQueue depth / custom-metric driven autoscaling
fly-replay headerApp returns fly-replay so Proxy replays the request elsewhereForward writes to primary region; route by tenant

Key distinction: autostop ≠ autoscaler. Autostop only toggles Machines that already exist; it never changes the count. The metrics autoscaler is what actually adds/removes Machines. Set auto_stop_machines and auto_start_machines together — configuring one without the other is undefined behavior.

fly-replay is the multi-region write-forwarding pattern: read-replicas serve local reads, a write replies with fly-replay: region=<primary> and the Proxy re-runs the request there. Full header forms and the primary/replica split are in references/multi-region.md. These are the Fly levers only; platform-agnostic scaling theory (queues, sharding, load shedding) is ../scaling/SKILL.md.

Cost & HA

  • min 2 Machines for HA. A single Machine = a single point of failure; Fly recommends ≥2 per group in production.
  • Stopped Machines are cheap — you pay for rootfs/volume storage, not running compute. So a warm pool with auto_stop_machines = "stop" is the default cost play.
  • Scale to zero (min_machines_running = 0) trades cost for a cold start on the next request. If the first-request latency hurts, set min_machines_running = 1 to keep one warm. Note: min_machines_running is honored only in the primary region.
  • "suspend" resumes faster than "stop" (keeps memory snapshot) but is supported on fewer setups — verify before relying on it.

Verify

After writing or editing a fly.toml, run the checker:

bash
scripts/verify.sh path/to/fly.toml   # defaults to ./fly.toml

It prefers fly config validate when flyctl is on PATH, else does structural checks (app, primary_region, an internal_port, and the autostop-pair lint). Read-only; exits nonzero on any FAIL.

Anti-patterns

Anti-patternWhy it bitesDo instead
Secrets in [env] or the DockerfileCommitted to git, baked into image layersfly secrets set
fly scale count on a [[mounts]] group expecting shared dataEach new Machine gets an empty volumeSingle writer + stateless replicas + DB/fly-replay
Setting only auto_stop_machinesHalf-configured autostop is undefinedSet start + stop keys together
Assuming autostop changes Machine countIt only toggles a fixed poolUse fly scale count or fly-autoscaler
One Machine in productionNo HA; a host blip = downtime≥2 Machines per group
Bigger VM to fix far-away latencyDistance, not CPU, is the costAdd a Machine in the user's region
Volume in a different region than its MachineCannot attach across regionsCreate the volume in the Machine's region
Treating Fly Postgres as managedFly Postgres is unmanaged; you operate itRoute to it here; operate it via ../postgresdb/SKILL.md
min_machines_running in a non-primary regionIgnored outside primaryKeep warm capacity via scale count there
fly deploy with no release_command for a schema changeNew code hits an old schema mid-rolloutrelease_command runs the migration first

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/fly-io of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/fly-toml.md
  • references/multi-region.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Fly Io next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fly Io compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fly Io this skillericrisco/rsc-harness156—~2.8kAutomated safety check: PassMIT
Agr Releasecomputerlovetech/agr451—~1.6kAutomated safety check: PassMIT
GitOps with ArgoCD and Fluxwshobson/agents40k11 repos~1.5kAutomated safety check: PassMIT
Demo Local Rolloutcarverauto/serviceradar921—~4.2kAutomated safety check: PassApache-2.0
Homerail Install Opsxiaotianfotos/homerail991—~2kAutomated safety check: PassMIT
Buzz Self Hostingtonbistudio/buzz-skills274—~2.2kAutomated safety check: NotesMIT

Similar skills

  • Agr Release

    computerlovetech/agr

    Release process for the agr package. An agent skill from computerlovetech/agr.

    451 GitHub stars~1.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 11 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Demo Local Rollout

    carverauto/serviceradar

    Build unpublished sha-... An agent skill from carverauto/serviceradar.

    921 GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Homerail Install Ops

    xiaotianfotos/homerail

    Install, configure, start, verify, update, and troubleshoot a local-source HomeRail deployment for AI-agent use.

    991 GitHub stars~2k tokensUpdated 12 days ago
    DevOps & CloudAuto-check passed
  • Buzz Self Hosting

    tonbistudio/buzz-skills

    A skill your agent uses when helping a user set up, debug, or operate a self-hosted Buzz relay through Docker Compose.

    274 GitHub stars~2.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Update Qm

    yc-software/qm

    Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR.

    15k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Fly Io

What does Fly Io do?

A skill your agent uses when deploying or operating an app on Fly.io — writing fly.toml, placing Machines in regions near users, attaching Volumes, managing secrets, or picking a scaling lever…. Fly Io is an agent skill from ericrisco/rsc-harness.toml, placing Machines in regions near users, attaching Volumes, managing secrets, or picking a scaling lever (autostop/autostart, scale count, fly-replay).

When should I use Fly Io?

Fly Io fits situations like: operating an app on Fly.io — writing fly.toml; placing Machines in regions near users; attaching Volumes; managing secrets.

How do I install Fly Io in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill fly-io -a claude-code`. Or copy the skill folder (skills/fly-io in ericrisco/rsc-harness) into .claude/skills/fly-io in your project. Claude Code loads it when a task matches its description.

How do I install Fly Io in Codex?

Run `npx skills add ericrisco/rsc-harness --skill fly-io -a codex`. Or copy the skill folder (skills/fly-io in ericrisco/rsc-harness) into .agents/skills/fly-io in your project. Codex loads it when a task matches its description.

Can I use Fly Io in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill fly-io -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fly-io, .gemini/skills/fly-io, .github/skills/fly-io and .opencode/skills/fly-io in your project.

What does Fly Io need to run?

Going by SKILL.md and its folder, Fly Io needs a shell for the scripts in its folder, the command-line tools its instructions call (fly) and credentials named STRIPE_KEY, SESSION_SECRET and OLD_KEY. Our summary lists: A Bash shell; Docker; A credential in STRIPE_KEY; A credential in SESSION_SECRET.

Does Fly Io access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fly Io safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Fly Io use?

Fly Io is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fly Io use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Fly Io?

Skills that share tags, products or a category with Fly Io: Agr Release (computerlovetech/agr, 451 stars), GitOps with ArgoCD and Flux (wshobson/agents, 40k stars), Demo Local Rollout (carverauto/serviceradar, 921 stars) and Homerail Install Ops (xiaotianfotos/homerail, 991 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fly Io?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.