AWS GitHub Oidc Scoped Role
mizchi/skills
OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.
Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.
$ npx skills add grafana/skills --skill admin -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install grafana/skills admin --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-cloud/admin .claude/skills/admin && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "admin" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-cloud/admin into .claude/skills/admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/grafana/skills/tree/main/skills/grafana-cloud/adminType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add grafana/skills --skill admin -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install grafana/skills admin --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/grafana-cloud/admin .agents/skills/admin && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "admin" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-cloud/admin into .agents/skills/admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/skills --skill admin -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install grafana/skills admin --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/grafana-cloud/admin .cursor/skills/admin && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "admin" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-cloud/admin into .cursor/skills/admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/grafana/skills.git --path skills/grafana-cloud/admin--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add grafana/skills --skill admin -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install grafana/skills admin --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/grafana-cloud/admin .gemini/skills/admin && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "admin" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-cloud/admin into .gemini/skills/admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install grafana/skills adminInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add grafana/skills --skill admin -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/grafana-cloud/admin .github/skills/admin && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "admin" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-cloud/admin into .github/skills/admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/skills --skill admin -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install grafana/skills admin --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/grafana-cloud/admin .opencode/skills/admin && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "admin" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-cloud/admin into .opencode/skills/admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "admin", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
adminManage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.
Admin is an agent skill from grafana/skills, published by the product's own GitHub organization. Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures SSO providers, and provisions teams/folders/dashboards via Terraform. Use when managing Grafana Cloud access, configuring SSO/SAML/OAuth, setting up service accounts for Terraform/CI/CD, assigning RBAC roles, inviting…
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/api-reference.md`, `references/sso.md` and `references/terraform.md`).
It sits in DevOps & Cloud, covering Monitoring and alerting, Authentication and Authorization and RBAC. It works with Grafana, Terraform and GitHub. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
grafana.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Admin loads about 1.5k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 197 tokens; SKILL.md has 262 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 262 words, ~1,492 tokens.
.claude/skills/admin/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Docs: https://grafana.com/docs/grafana-cloud/account-management.md
# 1. Create the stack via Cloud API
curl -X POST https://grafana.com/api/instances \
-H "Authorization: Bearer <grafana-com-api-key>" \
-H "Content-Type: application/json" \
-d '{"name": "my-new-stack", "slug": "my-new-stack", "region": "us-east-0", "plan": "grafana-cloud-free"}'
# 2. Verify the stack is reachable (poll until 200)
until curl -fs https://my-new-stack.grafana.net/api/health > /dev/null; do sleep 2; done
# 3. Mint an admin service-account token (see § Service Accounts below)
# 4. Test the token
curl https://my-new-stack.grafana.net/api/org -H "Authorization: Bearer <token>"
# Returns 200 + org JSON → token worksPOST /api/org/invites (one curl per user — see references/api-reference.md § Stack API)POST /api/teamsPOST /api/teams/{teamId}/membersGET /api/teams/{teamId}/members returns the expected user listgrafana.ini# 1. Delete via Cloud API
curl -X DELETE https://grafana.com/api/instances/{id} \
-H "Authorization: Bearer <grafana-com-api-key>"
# 2. Verify the stack is gone (must return 404)
curl https://grafana.com/api/instances/{id} \
-H "Authorization: Bearer <grafana-com-api-key>"If the GET still returns 200 after a few seconds, the delete didn't apply — re-check the stack ID and Cloud API key.
Grafana Cloud Account
└── Organization (billing unit)
├── Stack 1 (prod) → dedicated Grafana, Prometheus, Loki, Tempo URLs
├── Stack 2 (staging)
└── Stack 3 (dev)| Role | Scope | Permissions |
|---|---|---|
| Org Admin | Organization | Manage stacks, users, billing, API keys |
| Admin | Stack | Data sources, plugins, users, provisioning |
| Editor | Stack | Create/edit dashboards, alerts |
| Viewer | Stack | Read-only dashboards |
Define a custom role + assignment in provisioning YAML:
# provisioning/access-control/roles.yaml
apiVersion: 1
roles:
- name: TeamDashboardEditor
description: Edit dashboards within team folder
permissions:
- action: dashboards:read
scope: folders:UID:team-folder
- action: dashboards:write
scope: folders:UID:team-folder
- action: dashboards:create
scope: folders:UID:team-folder# provisioning/access-control/assignments.yaml
apiVersion: 1
roleAssignments:
- roleName: TeamDashboardEditor
users:
- alice@example.com
- bob@example.com
teams:
- platform-teamAfter committing the YAML and restarting Grafana, verify the role applied: GET /api/access-control/roles | jq '.[] | select(.name=="TeamDashboardEditor")'.
Service accounts are the recommended way for programmatic access (CI/CD, Terraform, agents).
# 1. Create the service account
curl -X POST https://yourstack.grafana.net/api/serviceaccounts \
-H "Authorization: Bearer <admin-token>" \
-H "Content-Type: application/json" \
-d '{"name": "terraform-provisioner", "role": "Admin", "isDisabled": false}'
# 2. Mint a token for it
curl -X POST https://yourstack.grafana.net/api/serviceaccounts/{id}/tokens \
-H "Authorization: Bearer <admin-token>" \
-H "Content-Type: application/json" \
-d '{"name": "ci-token", "secondsToLive": 0}'
# 3. Verify the token works (test on a harmless endpoint)
curl https://yourstack.grafana.net/api/org \
-H "Authorization: Bearer <new-token>"
# 200 + org JSON → token works. Anything else → re-check role assignment in step 1.Provisioning equivalent (YAML, declarative):
# provisioning/access-control/service_accounts.yaml
apiVersion: 1
serviceAccounts:
- name: alloy-writer
orgId: 1
role: Editor
tokens:
- name: alloy-tokenreferences/sso.md — OAuth / SAML / GitHub OAuth config + the 5-step SSO verification pattern + common failure modesreferences/terraform.md — Terraform provider config + common resource patterns (teams, users, folders, dashboards) + drift troubleshootingreferences/api-reference.md — full Cloud API + Stack API endpoint reference + audit-log queries© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/grafana-cloud/admin of grafana/skills.
Open the folder on GitHubat commit 1ccacf2
Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Admin this skillgrafana/skills | 278 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| AWS GitHub Oidc Scoped Rolemizchi/skills | 356 | — | ~1.6k | Automated safety check: Pass | None | |
| Neo4j Aura Provisioning Skillneo4j-contrib/neo4j-skills | 114 | — | ~3.7k | Automated safety check: Notes | MIT | |
| Cloud Devopsdavila7/claude-code-templates | 32k | 4 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Devops Pipelineluongnv89/skills | 131 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Sdaf Plan And Test SemanticsAzure/sap-automation | 145 | — | ~1.6k | Automated safety check: Pass | MIT |
mizchi/skills
OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.
neo4j-contrib/neo4j-skills
Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
luongnv89/skills
Configure pre-commit hooks and lean GitHub Actions for shift-left quality assurance.
Azure/sap-automation
Explain SDAF plan-only / test / apply semantics without pretending they are universal.
magnus919/agent-skills
A skill your agent uses when building or operating internal developer platforms: infrastructure as code, CI/CD, container orchestration, service networking, secrets, and observability, or when…
grafana/skills
Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).
grafana/skills
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…
grafana/skills
Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…
grafana/skills
A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.
grafana/skills
Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.
grafana/skills
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…
Categories
Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Admin is an agent skill from grafana/skills, published by the product's own GitHub organization. Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.
Admin fits situations like: managing Grafana Cloud access; configuring SSO/SAML/OAuth; setting up service accounts for Terraform/CI/CD; assigning RBAC roles.
Run `npx skills add grafana/skills --skill admin -a claude-code`. Or copy the skill folder (skills/grafana-cloud/admin in grafana/skills) into .claude/skills/admin in your project. Claude Code loads it when a task matches its description.
Run `npx skills add grafana/skills --skill admin -a codex`. Or copy the skill folder (skills/grafana-cloud/admin in grafana/skills) into .agents/skills/admin in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admin, .gemini/skills/admin, .github/skills/admin and .opencode/skills/admin in your project.
Going by SKILL.md and its folder, Admin needs the command-line tools its instructions call (curl and jq).
SKILL.md names 1 domain. In commands or code: grafana.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Admin is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Admin: AWS GitHub Oidc Scoped Role (mizchi/skills, 356 stars), Neo4j Aura Provisioning Skill (neo4j-contrib/neo4j-skills, 114 stars), Cloud Devops (davila7/claude-code-templates, 32k stars) and Devops Pipeline (luongnv89/skills, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 278 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 6, 2026.
Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.