Agent skill

Render

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when deploying or fixing an app on Render — web services, background workers, cron jobs, private services, managed Postgres and Key-Value, and especially the render.yaml…

MITAuto-check passedDevOps & Cloud

Install Render

skills CLI
$ npx skills add ericrisco/rsc-harness --skill render -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness render --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/render .claude/skills/render && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
render
GitHub stars
156
Token cost
~3k tokens
SKILL.md length
1,141 words
Files
5 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when deploying or fixing an app on Render — web services, background workers, cron jobs, private services, managed Postgres and Key-Value, and especially the render.yaml…

  • Fixing an app on Render — web services
  • SKILL.md covers The one decision that decides…, Blueprint-first: everything…, Minimal correct render.yaml… and Port binding — do this first…, plus 8 more sections
  • Runs Shell scripts from its folder; calls gunicorn; needs SESSION_SECRET
  • Background workers

What it does

Render is an agent skill from ericrisco/rsc-harness. Use when deploying or fixing an app on Render — web services, background workers, cron jobs, private services, managed Postgres and Key-Value, and especially the render.yaml Blueprint. Covers deploys that fail with no open ports detected, 502s on first deploy, free-tier cold starts, and a free Postgres about to expire with its data. NOT the generic ship and release flow (that is deployment), NOT another PaaS such as railway or fly-io.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/blueprint-reference.md`).

It sits in DevOps & Cloud, covering Deployment. It works with Render and PostgreSQL. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Fixing an app on Render — web services
  • Background workers
  • Private services
  • Managed Postgres and Key-Value

Example prompts

  • “/render”

Requirements

  • Python 3
  • A Bash shell
  • Docker
  • A credential in SESSION_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gunicorn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SESSION_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Render loads about 3k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,141 words, ~3,034 tokens.

Download SKILL.mdSave it as .claude/skills/render/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
render
description
Use when deploying or fixing an app on Render — web services, background workers, cron jobs, private services, managed Postgres and Key-Value, and especially the render.yaml Blueprint. Covers deploys that fail with no open ports detected, 502s on first deploy, free-tier cold starts, and a free Postgres about to expire with its data. NOT the generic ship and release flow (that is `deployment`), NOT another PaaS such as `railway` or `fly-io`.
tags
render, paas, deployment, render-yaml, cron, background-worker, infrastructure-as-code
recommends
deployment, postgresdb, docker, domains-dns, github-actions, scaling
origin
risco

Render — make this repo deploy correctly, wired as code

Take any repo and make it deploy on Render (render.com) in one pass: pick the right service type, declare everything in a version-controlled render.yaml Blueprint, bind the port the way Render expects, and wire DATABASE_URL / secrets across services so they survive rotation. Steer clear of the four traps that eat first deploys: the "no open ports detected" 502, the free-tier spin-down, the 30-day free-Postgres expiry, and the 12-hour cron kill.

text
pick service type → render.yaml at repo root → bind 0.0.0.0:$PORT → wire env across services → push (auto-deploy)
        │                                                                                            │
   web|worker|cron|pserv|static|keyvalue                                       full key surface → references/blueprint-reference.md

Facts here are dated to 2026-06-02 against render.com/docs. Render ships changes; if a key or limit looks off, confirm against the live Blueprint spec before betting a deploy on it.

The one decision that decides everything: service type

Pick the type before you write a line of YAML. The type sets the billing model, whether the process gets a public URL, and whether Render expects it to bind a port. Choosing wrong means a worker that never starts because Render waited for a port, or a 12-hour job that dies silently as a cron.

The process…Typeruntime required?Gets a public URL?
serves HTTP/WebSocket trafficwebyesyes
runs forever, no inbound URL (queue consumer, Celery)workeryesno
runs, does work, exits — on a schedulecronyesno
internal-only API, reachable only inside Render's networkpservyesno (internal host only)
pre-built static assets (SPA, docs)web + runtime: staticyes (static)yes
cache / queue / Redis-compatible storekeyvaluenono (internal)

runtime enum (everything except keyvalue): node, python, docker, image, static, go, ruby, elixir, rust.

Blueprint-first: everything lives in render.yaml

Rule: declare every service, database, and env var group in render.yaml at the repo root. Touch the dashboard only for sync: false secrets and one-off debugging. Why: the Blueprint is the reproducible, reviewable source of truth — it powers preview environments and a clean re-deploy, while dashboard-only config is invisible state that drifts and can't be code-reviewed.

Top-level keys: services, databases, envVarGroups, projects, previews.

Minimal correct render.yaml (annotated)

A multi-service app — a Node web service, a Python worker, a nightly cron, a Postgres db, and a shared env group. Every load-bearing key is commented.

yaml
databases:
  - name: app-db
    plan: starter            # NOT free for anything you care about — free expires in 30 days
    postgresMajorVersion: "17"
    region: frankfurt

envVarGroups:
  - name: app-shared
    envVars:
      - key: LOG_LEVEL
        value: info
      - key: SENTRY_DSN
        sync: false          # prompt once at setup; never stored in git

services:
  - type: web
    name: api
    runtime: node
    region: frankfurt
    plan: starter            # $7/mo — avoids the free-tier 15-min spin-down on an API
    buildCommand: npm ci && npm run build
    startCommand: npm start  # MUST bind 0.0.0.0 and read $PORT — see next section
    healthCheckPath: /healthz # gates zero-downtime rollout; new instance must pass first
    preDeployCommand: npm run migrate  # runs before the new instance serves traffic
    autoDeployTrigger: commit          # commit | checksPass | off
    envVars:
      - fromGroup: app-shared
      - key: DATABASE_URL
        fromDatabase:
          name: app-db
          property: connectionString   # never hardcode the URL
      - key: SESSION_SECRET
        generateValue: true            # Render generates a random secret

  - type: worker
    name: jobs
    runtime: python
    plan: starter
    buildCommand: pip install -r requirements.txt
    startCommand: celery -A app worker -l info  # no port — workers don't bind one
    envVars:
      - fromGroup: app-shared
      - key: DATABASE_URL
        fromDatabase: { name: app-db, property: connectionString }
      - key: API_URL
        fromService:                   # reference another service
          name: api
          type: web
          property: hostport

  - type: cron
    name: nightly-cleanup
    runtime: python
    schedule: "0 3 * * *"              # required for cron; 03:00 UTC daily
    buildCommand: pip install -r requirements.txt
    startCommand: python -m app.cleanup
    envVars:
      - key: DATABASE_URL
        fromDatabase: { name: app-db, property: connectionString }

Port binding — do this first (the #1 first-deploy failure)

Rule: a web service MUST listen on host 0.0.0.0 and read the PORT env var (Render sets it, default 10000). If Render detects no bound port within its window, the deploy fails with "no open ports detected" and visitors get a 502. This is the single most common first-deploy break — binding localhost/127.0.0.1 or a hardcoded port does it.

javascript
// Bad — binds the wrong host and ignores Render's PORT → "no open ports detected"
app.listen(3000);

// Good — bind 0.0.0.0 and honor $PORT
app.listen(process.env.PORT || 3000, "0.0.0.0");
bash
# Bad — gunicorn on a fixed local port
gunicorn app:app --bind 127.0.0.1:8000

# Good — bind 0.0.0.0 and Render's $PORT
gunicorn app:app --bind 0.0.0.0:$PORT

Only web services need this. A worker/cron that tries to bind a port is fine but pointless; a web service that doesn't is broken.

Wiring env vars across services

Rule: never hardcode DATABASE_URL, REDIS_URL, or shared secrets as literal value: strings. Reference the resource so the value survives a rotation, recreate, or region move, and so secrets never land in git.

FormUse it for
fromDatabase: { name, property: connectionString }the Postgres connection string
fromService: { name, type, property }another service's host/port/URL (property: hostport, host, or port)
fromGroup: <group-name>pull a whole shared env var group
generateValue: truea random secret Render generates and stores (session keys)
sync: falsea secret you type once at setup; not stored in the repo

For a Key Value store, reference its connection string the same way you reference Postgres, via fromService against the keyvalue service.

Migrations and zero-downtime deploys

  • preDeployCommand — runs once, before the new instance starts serving traffic. Put migrations here, not in startCommand (a startCommand migration runs on every instance and races under multiple replicas).
  • healthCheckPath — Render polls it on the new instance and only shifts traffic once it passes, giving zero-downtime rollout. Point it at a route that checks real readiness.
  • autoDeployTrigger — commit (deploy every push), checksPass (wait for CI status), or off (manual / deploy-hook only).
Show full SKILL.md (507 more words)Show less

Free-tier traps

Render's free tier is generous for hobby work and a landmine for anything you care about.

TrapWhat happensFix
Free web spin-downafter 15 min of no inbound traffic the instance sleeps; next request waits 30–60s to wakeStarter at $7/mo per service
750 free instance-hrs/moshared across the workspace; spun-down time doesn't count toward itbudget it, or pay Starter
Free Postgres expirydeleted 30 days after creation (14-day grace to upgrade), all data gone; only one free Postgres per workspaceStarter Postgres ($7/mo) from day one for anything real
Free Key Valueno disk persistence — data is lost on restartpaid plan if you need durability

Cron specifics

  • schedule: (standard cron expression) is required for type: cron.
  • Render guarantees at most one active run at a time — runs don't overlap.
  • A run is killed after 12 hours. Anything that can exceed that must be a worker with its own scheduler/queue, not a cron. A long cron fails silently mid-job — partial work, no clean error.

Scaling and disk knobs

This is the concrete Render surface, not capacity strategy (that's scaling).

yaml
services:
  - type: web
    name: api
    runtime: node
    scaling:
      minInstances: 1
      maxInstances: 4
      targetCPUPercent: 70
      targetMemoryPercent: 80   # autoscale between min/max on CPU/mem
    disk:
      name: data
      mountPath: /var/data
      sizeGB: 10                # a disk PINS the service to ONE instance — blocks horizontal scale

Use numInstances for a fixed replica count instead of scaling when you don't want autoscaling. A persistent disk and horizontal scaling are mutually exclusive — pick one.

Regions: oregon, ohio, virginia, frankfurt, singapore. Plans: free, starter, standard, pro, pro plus, pro max, pro ultra.

Anti-patterns

Anti-patternWhy it bitesDo instead
Hardcoding a port (listen(3000))"no open ports detected" → deploy fails / 502bind 0.0.0.0 and $PORT
Hardcoding DATABASE_URLbreaks on rotation / db recreatefromDatabase reference
A long job as a cronkilled at 12h, silent partial workworker + its own scheduler/queue
Free Postgres for productiondeleted 30 days after creationStarter ($7/mo) from day one
Secrets as literal value: in render.yamlleaked in git historysync: false or generateValue: true
Migrations in startCommandruns on every instance, races under replicaspreDeployCommand
Free web service for a real APIcold-start 502s after idleStarter, or accept it only for a hobby toy
Dashboard-only configinvisible drift, no preview envs, no reviewdeclare in render.yaml

When to hand off

  • Schema design, queries, indexing, tuning → ../postgresdb/SKILL.md. This skill only provisions and connects Render's managed Postgres.
  • Writing the Dockerfile Render consumes via runtime: docker → docker.
  • Registrar-side DNS records for a custom domain → domains-dns. (The Render domains: block and verification stay here.)
  • Cross-platform release strategy, promotion, rollback flow → ../deployment/SKILL.md and ship. This skill is Render config and platform mechanics.
  • Build steps Render's native build doesn't run (custom CI) → github-actions. Render auto-deploys on push; only reach for Actions when you genuinely need it.
  • Capacity/load strategy beyond the scaling: knobs → scaling.
  • A different PaaS → its own sibling: ../fly-io/SKILL.md, railway, vercel, ../netlify/SKILL.md, coolify, digitalocean.

Full key surface

The exhaustive render.yaml key tables per service type, all database keys (postgresMajorVersion, diskSizeGB, readReplicas, highAvailability, previewPlan), every env-var reference form, region/plan enums, and four complete copy-paste recipes (Next.js web+pg; FastAPI web+worker+cron+keyvalue; Docker monorepo with rootDir; static SPA with routes rewrites) live in references/blueprint-reference.md — pull it open when you need a key this body didn't cover.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/render of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/blueprint-reference.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Render next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Render compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Render this skillericrisco/rsc-harness156—~3kAutomated safety check: PassMIT
Monstermq Broker Configvogler75/monster-mq142—~2.2kAutomated safety check: PassGPL-3.0
Deployclacky-ai/openclacky1.2k—~1.9kAutomated safety check: PassMIT
RenderLeoYeAI/openclaw-master-skills2.2k—~4.8kAutomated safety check: PassMIT
Docker Deploymentfossasia/eventyay1.7k—~574Automated safety check: NotesApache-2.0
PayRam Agent OnboardingPayRam/payram-mcp158—~3.6kAutomated safety check: PassNone

Similar skills

  • Monstermq Broker Config

    vogler75/monster-mq

    Guide for configuring, deploying, and operating the MonsterMQ broker.

    142 GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Deploy

    clacky-ai/openclacky

    Deploy Rails applications to Railway. An agent skill from clacky-ai/openclacky.

    1.2k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Render

    LeoYeAI/openclaw-master-skills

    Deploy and operate apps on Render (Blueprint + one-click Dashboard deeplink, same flow as Codex render-deploy).

    2.2k GitHub stars~4.8k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed
  • Docker Deployment

    fossasia/eventyay

    Docker Compose, container services, deployment. An agent skill from fossasia/eventyay.

    1.7k GitHub stars~574 tokensUpdated today
    DevOps & CloudAuto-check: notes
  • PayRam Agent Onboarding

    PayRam/payram-mcp

    Installs and runs the PayRam crypto payment gateway from the command line for agents, CI pipelines and serverless setups, with no web dashboard.

    158 GitHub stars~3.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Azure PostgreSQL Flexible Server SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 6 repos~4k tokens
    DevOps & CloudAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Render

What does Render do?

A skill your agent uses when deploying or fixing an app on Render — web services, background workers, cron jobs, private services, managed Postgres and Key-Value, and especially the render.yaml…. Render is an agent skill from ericrisco/rsc-harness.yaml Blueprint.

When should I use Render?

Render fits situations like: fixing an app on Render — web services; background workers; private services; managed Postgres and Key-Value.

How do I install Render in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill render -a claude-code`. Or copy the skill folder (skills/render in ericrisco/rsc-harness) into .claude/skills/render in your project. Claude Code loads it when a task matches its description.

How do I install Render in Codex?

Run `npx skills add ericrisco/rsc-harness --skill render -a codex`. Or copy the skill folder (skills/render in ericrisco/rsc-harness) into .agents/skills/render in your project. Codex loads it when a task matches its description.

Can I use Render in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill render -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/render, .gemini/skills/render, .github/skills/render and .opencode/skills/render in your project.

What does Render need to run?

Going by SKILL.md and its folder, Render needs a shell for the scripts in its folder, the command-line tools its instructions call (gunicorn) and credentials named SESSION_SECRET. Our summary lists: Python 3; A Bash shell; Docker; A credential in SESSION_SECRET.

Does Render access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Render safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Render use?

Render is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Render use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Render?

Skills that share tags, products or a category with Render: Monstermq Broker Config (vogler75/monster-mq, 142 stars), Deploy (clacky-ai/openclacky, 1.2k stars), Render (LeoYeAI/openclaw-master-skills, 2.2k stars) and Docker Deployment (fossasia/eventyay, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Render?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.