Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Consolidate all open Renovate PRs on quickpizza into tested, reviewable PRs.
$ npx skills add grafana/quickpizza --skill renovate-batch-update -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install grafana/quickpizza renovate-batch-update --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/grafana/quickpizza.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/renovate-batch-update .claude/skills/renovate-batch-update && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "renovate-batch-update" agent skill from https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-update into .claude/skills/renovate-batch-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "renovate-batch-update", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-updateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add grafana/quickpizza --skill renovate-batch-update -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install grafana/quickpizza renovate-batch-update --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/quickpizza.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/renovate-batch-update .agents/skills/renovate-batch-update && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "renovate-batch-update" agent skill from https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-update into .agents/skills/renovate-batch-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "renovate-batch-update", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/quickpizza --skill renovate-batch-update -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install grafana/quickpizza renovate-batch-update --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/quickpizza.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/renovate-batch-update .cursor/skills/renovate-batch-update && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "renovate-batch-update" agent skill from https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-update into .cursor/skills/renovate-batch-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "renovate-batch-update", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/grafana/quickpizza.git --path .claude/skills/renovate-batch-update--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add grafana/quickpizza --skill renovate-batch-update -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install grafana/quickpizza renovate-batch-update --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/quickpizza.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/renovate-batch-update .gemini/skills/renovate-batch-update && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "renovate-batch-update" agent skill from https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-update into .gemini/skills/renovate-batch-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "renovate-batch-update", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install grafana/quickpizza renovate-batch-updateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add grafana/quickpizza --skill renovate-batch-update -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/grafana/quickpizza.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/renovate-batch-update .github/skills/renovate-batch-update && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "renovate-batch-update" agent skill from https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-update into .github/skills/renovate-batch-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "renovate-batch-update", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/quickpizza --skill renovate-batch-update -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install grafana/quickpizza renovate-batch-update --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/quickpizza.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/renovate-batch-update .opencode/skills/renovate-batch-update && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "renovate-batch-update" agent skill from https://github.com/grafana/quickpizza/tree/main/.claude/skills/renovate-batch-update into .opencode/skills/renovate-batch-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "renovate-batch-update", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
renovate-batch-updateConsolidate all open Renovate PRs on quickpizza into tested, reviewable PRs.
Renovate Batch Update is an agent skill from grafana/quickpizza, published by the product's own GitHub organization. Consolidate all open Renovate PRs on quickpizza into tested, reviewable PRs. Splits GitHub Actions bumps into their own PR (validated by their own CI run) from code/library bumps (validated by local build + k6), merges as many as will merge cleanly into each batch branch, risk-assesses the survivors, and opens draft PRs summarizing what's in and what got dropped.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Load testing and CI/CD. It works with GitHub Actions, Grafana and Docker. The repository describes itself as: Demo app for learning observability with Grafana and performance testing with k6. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8943426. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghmakegodockernpmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
claude.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Renovate Batch Update loads about 3.2k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 1,613 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from grafana/quickpizza at commit 8943426, republished under its Apache-2.0 licence (© grafana). 1,613 words, ~3,202 tokens.
.claude/skills/renovate-batch-update/SKILL.md (or your agent's skills folder).Turns the weekly pile of individual Renovate PRs on grafana/quickpizza into tested
PRs, instead of reviewing/merging each one by hand.
Boundary: this skill opens draft PRs to main. It never merges to main
itself — that's a shared-branch action and stays a human call.
Produces two separate PRs, not one: a code/dependency batch (Go modules, npm packages, Docker base image tags, security patches) and, only if any exist, a GitHub Actions batch. This is a hard split, not optional risk-tiering — see "Why GitHub Actions bumps get their own PR" below.
git status). If not, stop and tell the user —
don't stash or discard their work.git fetch origin --prune.lsof -i :3333). Quickpizza's port is
hardcoded in cmd/main.go with no override, and a long-running local Docker
container (docker ps --filter publish=3333) commonly holds it. If so, ask the
user before touching it. If they agree, docker stop <name> before Step 4 and
docker start <name> again once k6 finishes, pass or fail.A GitHub Actions version bump changes the CI workflow itself — the thing meant to
validate the batch. This skill's local testing (make build + make test-go + k6)
can't exercise workflow-level behavior at all; only that PR's own CI run can.
ci.yaml) is a main-level CI change,
out of scope for a dependency-bump PR.This holds regardless of which Actions bump happens to break something — the reason is structural (only a workflow's own run can validate a change to that workflow), not tied to any specific action.
gh pr list --state open --json number,title,headRefName,labels \
--search "head:renovate/ OR head:security-" --limit 100Renovate branches are prefixed renovate/; security branches use the
additionalBranchPrefix: "security-" from renovate.json, so also match
security-* heads. From each PR's labels, note: update-major / update-minor /
update-patch, and any severity:* / automerge-security-update.
Don't request mergeable from gh pr list — GitHub computes it lazily and it's
UNKNOWN for most PRs right after a fetch. Step 2's actual git merge is the only
reliable mergeability check.
Dedupe overlapping PRs before merging, not by discovering conflicts.
renovate.json groups npm/go/docker updates into one PR (e.g.
renovate/npm-dependencies), but Renovate also opens narrower individual security-*
PRs for the same packages. If a grouped PR and a security PR touch the same package
(compare titles), merge the grouped one and skip the narrower one — it's
superseded, and merging both guarantees a conflict.
Exclude the observability-stack container images group entirely. These are the
Grafana observability stack images (Alloy, LGTM, etc.) upgraded manually while deciding
whether to adopt new stack features — batching them defeats that review. Read
renovate.json's packageRules, find the rule matching
matchManagers: ["docker-compose", "terraform"], and take its groupName. Exclude any
PR whose title contains that groupName, including its (major) variant. Don't merge
these, risk-assess them, or mention them in the batch PR body — they're out of scope
for this skill, not a drop. Tell the user how many were left untouched by design.
Split off GitHub Actions bumps into their own batch — filter by the
github-actions label (applied via presets/github-actions in renovate.json's
extends), not by branch name or title. Steps 2-6 below run twice: once for the
code/dependency PRs, once for the Actions PRs, each on its own branch and its own PR.
Within the Actions set, dedupe the same way as above — e.g. a digest-only pin and a
major-version bump for the same action will conflict; keep the lower-risk one.
# Code/dependency batch:
git checkout -b renovate-batch/$(date +%Y-%m-%d) origin/main
# GitHub Actions batch, if any Actions PRs exist:
git checkout -b renovate-actions-batch/$(date +%Y-%m-%d) origin/mainMerge order within the code/dependency batch: lowest-risk first (security-patch, security-minor), then grouped patch/minor PRs, then majors last (majors are the first candidates to drop if later steps fail).
git merge --no-ff origin/<headRefName> -m "merge: <PR title> (#<number>)"On a clean merge, continue. On a conflict, git merge --abort, record <PR> — dropped: merge conflict, and continue to the next PR. Don't attempt manual conflict
resolution.
Why conflicts are common here: this repo vendors Go dependencies (vendor/), so
any single-module bump touches go.mod, go.sum, and often unrelated files under
vendor/ (shared semconv/version directories get rewritten wholesale). Once one
otel/grpc/x-net-family bump is merged, every other PR touching a related module will
conflict with it, even though the version bumps are logically compatible. Treat these
as expected noise in the batch PR summary, not as unsafe changes that got rejected.
Risk-assessing before merging wastes effort on PRs that just get dropped as conflicts. Assess only the PRs that are actually in each batch branch.
For the code/dependency batch, route by ecosystem:
grafana-engineering:dependency-bump-contextgrafana-engineering:analyze-image-dep-bump-prFor the GitHub Actions batch, no skill covers this — read each action's actual
release notes between the current and target version
(gh release view <version> -R <owner>/<repo>), looking specifically for breaking
changes to the action's runtime behavior, not just its own dependency bumps. Version
number alone doesn't reveal this kind of change, and skipping the check is how a
CI-breaking bump gets through unnoticed.
Build a table — PR #, title, ecosystem, update type, severity, risk verdict — and keep it; it becomes the batch PR body.
Applies to the code/dependency batch only. The Actions batch has no local build/test step — skip straight to Step 6 for it.
make buildUse make build, not npm run build / go build directly — the frontend build needs
PUBLIC_BACKEND_ENDPOINT/PUBLIC_BACKEND_WS_ENDPOINT exported first, which only the
Makefile target does.
If npm install modified pkg/web/package-lock.json beyond what the merged PRs
already changed, discard that diff (git checkout -- pkg/web/package-lock.json) — it's
typically platform-specific optional-dependency drift, not a real change, and it must
not leak into the batch PR.
If the build fails, drop the most recently merged high-risk (major) update via git revert -m 1 <merge-commit> and retry, up to twice. If it still fails, stop and report
the failure without opening a PR — don't keep reverting blindly.
If the build succeeds, run the Go unit tests next — they're fast and catch regressions
in pure logic (e.g. pkg/password's bcrypt round-trip) that a black-box k6 test might
not exercise:
make test-goApply the same drop-and-retry logic on failure as the build step above.
If that succeeds, run the app and the k6 suite against it:
./bin/quickpizza > /tmp/qp_batch.log 2>&1 &
QP_PID=$!
sleep 2
./k6/run-tests.sh -u http://localhost:3333 -t "k6/foundations/*.js"
K6_EXIT=$?
kill $QP_PIDDefault to k6/foundations/*.js, not the full k6/**/*.js tree — some subtrees
(browser, extension examples) need the custom xk6 quickpizza extension binary or extra
credentials that aren't guaranteed to be available locally.
This can exceed a 180s foreground command timeout and move to background — that's expected for the full 17-file suite. Treat the background task's exit code as the pass/fail signal; the captured output may only contain the tail once it's moved.
If K6_EXIT is non-zero, apply the same drop-and-retry logic as a build failure, and
check /tmp/qp_batch.log for server-side errors, not just the exit code.
Keep a running list of every PR dropped and why (merge conflict / build failure / test failure). Group conflict-drops by root cause (e.g. "conflicted with the otel bumps already in the batch") rather than listing them as unexplained failures.
For the code/dependency batch, only after Step 4 succeeds (or partially succeeds with drops recorded):
git push -u origin renovate-batch/$(date +%Y-%m-%d)
gh pr create --draft --title "chore(deps): batch renovate update $(date +%Y-%m-%d)" --body "$(cat <<'EOF'
## Included
<table from Step 3, filtered to what's actually merged>
## Dropped
<list from Step 5, grouped by root cause — omit if nothing was dropped>
## Testing
- `make build`: <pass/fail>
- `make test-go`: <pass/fail>
- `./k6/run-tests.sh`: <pass/fail, note any skipped/dropped-due-to-failure items>
🤖 Generated with [Claude Code](https://claude.com/claude-code)
EOF
)"For the Actions batch, push and open it unconditionally — there's no local gate, its own CI run is the test:
git push -u origin renovate-actions-batch/$(date +%Y-%m-%d)
gh pr create --draft --title "chore(deps): batch GitHub Actions update $(date +%Y-%m-%d)" --body "$(cat <<'EOF'
Separate from the code/dependency batch — see "Why GitHub Actions bumps get their own PR"
in the skill. This PR's own CI run is the test.
## Included
<table from Step 3>
## Dropped
<list from Step 5, if any>
## Risk notes
<anything found reading release notes in Step 3 — call out a breaking runtime/behavior
change explicitly, don't bury it in a version number>
🤖 Generated with [Claude Code](https://claude.com/claude-code)
EOF
)"If the Actions batch's CI comes back red, don't silently drop the offending PR and
re-push. Edit the PR body to report which check failed and why, and let the human
decide whether to drop that PR or fix the CI config alongside it — the latter is a
main-level change, out of scope for this skill to make unilaterally.
Tell the user both PRs are drafts and summarize what's in/out for each. Don't mark either ready for review or merge them.
Don't close or comment on the individual Renovate PRs. Once a batch PR merges, Renovate
detects the deps are already at target versions on main and closes its own PRs on its
next run.
main.The real fix for the vendor/lockfile conflict problem in Step 2 is to stop merging each
Renovate branch's generated diff, and instead collect the target version for each
accepted PR, apply them directly on the batch branch (go get <module>@<version> for
Go, edit package.json for npm), then run go mod tidy && go mod vendor / npm install once for the whole batch. That would avoid nearly all vendor-churn conflicts,
at the cost of a more complex Step 2 — worth building once this skill is used
regularly enough to justify it.
© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/renovate-batch-update of grafana/quickpizza.
Open the folder on GitHubat commit 8943426
Renovate Batch Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Renovate Batch Update this skillgrafana/quickpizza | 171 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| GitHub Actions CreatorFNOSP/FlyNarwhal | 509 | 1 repos | ~2.4k | Automated safety check: Pass | AGPL-3.0 | |
| Swig CI Reproswig/swig | 6.3k | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Megalinter Checknvuillam/npm-groovy-lint | 248 | 1 repos | ~3.9k | Automated safety check: Notes | MIT | |
| DDNS Build and Release MaintenanceNewFuture/DDNS | 4.7k | — | ~444 | Automated safety check: Pass | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
FNOSP/FlyNarwhal
A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.
swig/swig
Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…
nvuillam/npm-groovy-lint
Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.
NewFuture/DDNS
Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.
EliasOulkadi/shokunin
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…
Works with
Categories
Consolidate all open Renovate PRs on quickpizza into tested, reviewable PRs. Renovate Batch Update is an agent skill from grafana/quickpizza, published by the product's own GitHub organization. Consolidate all open Renovate PRs on quickpizza into tested, reviewable PRs.
Renovate Batch Update fits situations like: tasks that involve Load testing; tasks that involve CI/CD.
Run `npx skills add grafana/quickpizza --skill renovate-batch-update -a claude-code`. Or copy the skill folder (.claude/skills/renovate-batch-update in grafana/quickpizza) into .claude/skills/renovate-batch-update in your project. Claude Code loads it when a task matches its description.
Run `npx skills add grafana/quickpizza --skill renovate-batch-update -a codex`. Or copy the skill folder (.claude/skills/renovate-batch-update in grafana/quickpizza) into .agents/skills/renovate-batch-update in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/quickpizza --skill renovate-batch-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/renovate-batch-update, .gemini/skills/renovate-batch-update, .github/skills/renovate-batch-update and .opencode/skills/renovate-batch-update in your project.
Going by SKILL.md and its folder, Renovate Batch Update needs the command-line tools its instructions call (git, gh, make, go, docker and npm). Our summary lists: Node.js; Docker.
SKILL.md names 1 domain. In commands or code: claude.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Renovate Batch Update is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Renovate Batch Update: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), GitHub Actions Creator (FNOSP/FlyNarwhal, 509 stars), Swig CI Repro (swig/swig, 6.3k stars) and Megalinter Check (nvuillam/npm-groovy-lint, 248 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
grafana (a GitHub organization, an official publisher) maintains it in grafana/quickpizza, which has 171 GitHub stars. The repository was last updated on October 9, 2026.
Source: grafana/quickpizza on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.