Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Configure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures.
$ npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-runtime-resolution --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-runtime-resolution .claude/skills/configuration-runtime-resolution && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-runtime-resolution" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolution into .claude/skills/configuration-runtime-resolution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-runtime-resolution", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolutionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-runtime-resolution --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-runtime-resolution .agents/skills/configuration-runtime-resolution && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-runtime-resolution" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolution into .agents/skills/configuration-runtime-resolution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-runtime-resolution", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-runtime-resolution --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-runtime-resolution .cursor/skills/configuration-runtime-resolution && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-runtime-resolution" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolution into .cursor/skills/configuration-runtime-resolution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-runtime-resolution", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-runtime-resolution--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-runtime-resolution --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-runtime-resolution .gemini/skills/configuration-runtime-resolution && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-runtime-resolution" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolution into .gemini/skills/configuration-runtime-resolution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-runtime-resolution", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-runtime-resolutionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-runtime-resolution .github/skills/configuration-runtime-resolution && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-runtime-resolution" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolution into .github/skills/configuration-runtime-resolution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-runtime-resolution", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-runtime-resolution --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-runtime-resolution .opencode/skills/configuration-runtime-resolution && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-runtime-resolution" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-runtime-resolution into .opencode/skills/configuration-runtime-resolution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-runtime-resolution", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-runtime-resolutionConfigure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures.
Configuration Runtime Resolution is an agent skill from greenpau/caddy-security. Configure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures. Use to determine which fields resolve and preserve exact values; manager blocks belong to secrets.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SMTP_PASSWORDOIDC_CLIENT_SECRETJWT_SHARED_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration Runtime Resolution loads about 3.7k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 1,743 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,743 words, ~3,729 tokens.
.claude/skills/configuration-runtime-resolution/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill when generated Caddyfiles rely on values resolved during
provisioning. Runtime replacement is implemented in caddyfile_resolve.go and
tested by caddyfile_resolve_test.go.
Keep this skill aligned with github.com/greenpau/go-authcrunch config shapes:
some sections preserve raw encoded directive arguments and are revalidated after
replacement, while others are typed structs where only selected fields are
resolved.
Use Caddy replacer placeholders for environment-backed values:
password {env.SMTP_PASSWORD}
client_secret {env.OIDC_CLIENT_SECRET}
crypto key sign-verify {env.JWT_SHARED_KEY}Use secrets manager lookups for values provided by security.secrets modules:
password "secrets:users/jsmith:password" overwrite
crypto key sign-verify "secrets:access_token:shared_secret"Secret lookup syntax is:
secrets:<secret_id>:<key>The secret_id must match the second argument of a secrets <plugin> <secret_id>
block, and <key> must be returned by that secrets manager.
Secret lookups run after Caddy replacer expansion and must be the entire value. The parser accepts exactly three colon-separated parts, so the secret key cannot contain another colon.
ResolveRuntimeAppConfig mutates the authcrunch app config, then calls the
affected authcrunch Validate methods so derived configs are rebuilt.
The app supplies a fresh config copy for each runtime; never run resolution on
a serving graph. JSON inputs can omit optional portal UI and cookie settings.
Resolve those fields only when present and leave their defaults to AuthCrunch.
Reject null entries in typed component collections, including nested ACL,
redirect, credential, and registration objects, before calling validators or
constructors. app_config.go uses explicit typed validators and generic slice
and map helpers for those checks, following the coding skill's prohibition on
reflect. When upstream adds a component collection, extend its typed validator
and unit/E2E coverage. The checks permit omitted optional objects and leave
flexible parameter maps to the resolver. After substitution, decode
local/LDAP/OAuth/SAML parameter maps
into AuthCrunch's exported config types and check decoding errors and null
objects. Some dispatch validators ignore JSON decoding errors; do not let a
partially decoded user or provider config reach construction. Reuse upstream
types and semantic validation instead of maintaining field allowlists here.
Object lists in those maps must contain objects throughout;
do not silently skip a null or scalar entry after the first object. Return field
paths so malformed replacements fail without disrupting the active deployment.
The unit tests in app_lifecycle_test.go and actual Caddy reload tests in
app_lifecycle_e2e_test.go cover these JSON provisioning cases.
Guard raw instruction argument counts before calling AuthCrunch's dispatch
parsers: a one-token crypto statement or messaging/registration kind statement
can otherwise panic during provisioning. For crypto, credentials, messaging,
registration and transform instructions, check resolved tokens before cfgutil.EncodeArgs,
which trims trailing empty tokens. Reject empty arguments and report the
field/statement index without including secret values.
Keep command semantics in AuthCrunch. Include literal empty tokens and empty
environment replacements in unit and Caddy reload rejection tests, verifying
that the old deployment still authorizes requests.
Resolve these app config areas:
state.directory: replace the original scalar in the private config copy,
then run the shared state validator without creating files. Whole environment
and secrets-manager references retain exact token boundaries; unresolved or
empty replacements fail with a redacted error. See
persistent runtime state.credentials.raw_credential_configs, messaging.raw_configs, and
user_registration.raw_configs: decode each instruction, replace each
argument independently, then re-encode it for AuthCrunch validation. A resolved
value is one argument, including spaces, quotes, and newlines; it must not
inject instruction syntax. Resolve secret references at the argument level,
where the command word cannot hide them. Preserve single-token flags such as
messaging passwordless. Invoke these parsing
validators only when raw instructions are present. Empty sections and typed
configurations restored without raw instructions are preserved; values in
those typed sections must already be resolved.identity_stores[].params and identity_providers[].params: recursively
replace map keys, string values, string lists, lists of maps, and nested lists
supported by substitute. JSON booleans and floating-point numbers remain
unchanged; do not assume arbitrary Go scalar or slice types are supported.
List handling is bounded to the shapes in substitute, not an unrestricted
recursive JSON walk.sso_providers[]: replace entity_id, cert_path, private_key_path, and
each locations entry. Do not assume name or driver is replaced.authentication_portals[]: replace raw crypto key-store lines,
user-transformer matcher/action encoded arguments, selected UI strings
(logo_url, logo_description, meta fields, auto_redirect_url, custom CSS
and JS paths, template paths, private link titles/links, static asset path,
content type, and filesystem path), cookie path, cookie domain map keys, and
per-domain domain/path values.
Resolve domain-map keys into a fresh map and reject collisions before replacing
the map; in-place key updates can silently overwrite settings or process a newly
inserted key twice.authorization_policies[]: replace raw crypto key-store lines and direct
oauth string fields (provider, public origin, base path and cookie names).
Complete runtime-backed OAuth bodies live in oauth_authorization_directives,
resolve each token once, and reparse before policy defaults/validation; typed
oauth and deferred directives are mutually exclusive. Literal-only bodies
adapt directly to typed config. See direct OAuth.
The subsequent policy validation rebuilds crypto_key_store_config. For
JWT-only policies, pin absent cookie names to AUTHP_SESSION_ID and the
default access-cookie list before construction, preventing implicit
cross-portal discovery. Never add those JWT defaults to direct OAuth policies.Cookie Caddyfile statements containing runtime placeholders are held separately
in App.PortalCookieDirectives (portal_cookie_directives in Caddy JSON), keyed
by portal name. After ResolveRuntimeAppConfig, app provisioning resolves
that portal's entire statement collection and applies one validated snapshot
through the shared cookie parser and PortalConfig.ConfigureCookies. This
supports runtime names, prefixes, domains, and attributes without partially
validating an unresolved cookie config. The deferred snapshot replaces any
existing typed cookie config and is applied after other replacement to avoid expanding substituted
paths a second time. Literal-only statements adapt directly to typed
cookie config. See cookie configuration.
After replacement, legacy translation treats braces in a resolved path as data;
it must not defer that statement again. Keep cookie values as tokens until that
translation and lossless encoding; an intermediate EncodeArgs roundtrip can
silently trim an invalid name's trailing whitespace. Reject CR/LF in saved cookie
statements before decoding so additional records cannot hide settings. See the
cookie skill for the exact argument-preservation checks and reload regressions.
Token refresh blocks with runtime references are preserved in
App.PortalTokenRefreshDirectives (portal_token_refresh_directives). Resolve
each argument once and attach the shared parser's *authn.TokenRefreshConfig
before portal validation; do not also supply typed refresh_tokens for that
portal. Defer that portal's complete cookie statements too, including literal
ones, until the enabled refresh override is known: collision checks must use
the effective names. Literal refresh blocks need no snapshot. Native JSON origin, base path, cookie
name and individual realm values support replacement. See
token refresh placeholders
for numeric/state values, duplicate checks, and JSON restoration coverage.
OAuth provider statements with runtime references are also retained separately,
in App.OAuthProviderDirectives (oauth_provider_directives in Caddy JSON).
They pass shared validation during adaptation. App provisioning then resolves
each original argument once and reparses the whole provider, replacing the
adapted Params instead of substituting that already-normalized map. This keeps
Google client-ID suffixes and driver-derived URLs from changing secret lookup
keys. Snapshot names must identify exactly one OAuth provider. Shared duplicate,
state, key-file, and typed-only-field validation remains authoritative after
replacement. Substituted strings are data and are not expanded again.
See the OAuth reference
for boundaries and the unit/TLS E2E coverage. Keep this app-level snapshot when
copying adapted JSON; ResolveRuntimeAppConfig alone accepts an AuthCrunch config
and does not carry app-level snapshots.
The route plugins have separate runtime replacement: authenticate ... with {env.PORTAL} and authorize ... with {env.POLICY} resolve their portal or
gatekeeper names during plugin provisioning, not in ResolveRuntimeAppConfig.
Do not claim every string in authcrunch.Config is walked. If a placeholder is
needed in an unsupported typed field, add explicit resolver coverage and a
fixture instead of assuming the existing recursive helper will reach it.
Unsupported app fields currently include portal and policy names, portal enabled identity store/provider/SSO references, trusted redirect configs, portal role sets and patterns, most token options, cookie names in typed portal JSON (use deferred cookie statements instead), authorization policy ACL rules, bypass configs, header injection configs, auth proxy raw config, auth URL and forbidden URL fields, and access-token or session-cookie name fields.
Adapt fixtures may include:
<prefix>.Caddyfile for source configuration.<prefix>.env for environment variables used by {env.*} placeholders.<prefix>.json for adapted JSON before runtime resolution.<prefix>_resolved.json for expected JSON after runtime resolution.TestResolveRuntimeAppConfig lists the fixtures that exercise runtime
resolution. It extracts apps.security.config from <prefix>.json, loads <prefix>.env,
runs app-aware resolution (including apps.security.oauth_provider_directives and
apps.security.portal_token_refresh_directives)
followed by any apps.security.portal_cookie_directives snapshot, and compares
the dumped authcrunch config to <prefix>_resolved.json.
For fixtures covered by TestResolveRuntimeAppConfig, the test fails when
unresolved {env. tokens remain. Plain adapt fixtures may still contain
placeholders unless they are also listed in the runtime-resolution test.
Only user-transformer matcher/action arguments preserve {claims.*} for the
AuthCrunch runtime. Claim expansion applies to supported action values; ACL
matcher values stay literal. Resolution uses a scoped replacer without mutating the
shared Caddy replacer; other fields still reject unknown placeholders. Resolve
mixed environment/claim arguments and whole-value secret references as single
arguments, then compile the resulting transformer with the shared parser.
Empty replacements must fail before the codec can drop a token and change its
meaning. Reject CR/LF in raw transform instructions before decoding, since the
CSV decoder can discard later records. Shared validation also rejects multiline
resolved transform values. Native JSON transformers receive the same validation.
Selected AuthCrunch v1.3.11 supports match any without timestamps, including
refresh/OIDC/System API identity checks and quoted/runtime-resolved encodings.
Keep shared compilation and single-line validation; see
unconditional matching.
TestPortalTransformRuntimeValues and TestPortalTransformRuntimeBoundaries
cover mixed environment/claim values, quoted secrets, empty/unknown tokens,
replacer isolation and invalid native JSON. The challenges adapt/resolution
fixture and actual Caddy challenge E2E verify claim expansion after login.
Prefer placeholders for secrets in examples intended for real deployment. Use literal values only in tests or intentionally local examples.
When a generated config includes secret lookups, also include the matching
secrets <plugin> <secret_id> blocks or tell the user which external secrets
manager module must provide them.
When adding a new placeholder-bearing field, check the authcrunch struct and
validation path first. Raw encoded directive fields usually need
cfgutil.DecodeArgs, replacement of each argument, cfgutil.EncodeArgs, and
validation. Typed fields need explicit assignment in caddyfile_resolve.go.
caddyfile_resolve_instructions_test.go checks encoded credentials, messaging,
and registration values with environment and secret lookups. The credentials
adapt/resolution fixture includes quoted literal and resolved passwords.
The Caddy lifecycle E2E suite loads both kinds of replacement, checks the runtime
values, performs login/authorization, and verifies a missing secret leaves the
old deployment usable.
Those tests establish exact credential/sender/title values after resolution;
they do not prove SMTP delivery or a completed signup flow. A syntactically
malformed secret reference is not recognized by hasSecretKey and may survive
as a literal value. Treat the documented three-part lookup syntax as an input
requirement, not a promise that every secrets:-prefixed typo is rejected.
Secrets manager block syntax belongs to configuration-secrets.
© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/configuration-runtime-resolution of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration Runtime Resolution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration Runtime Resolution this skillgreenpau/caddy-security | 2.3k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Nestjs Best Practicesrolling-scopes/rsschool-app | 10k | 6 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Sub2API AdminWei-Shaw/sub2api | 44k | 1 repos | ~717 | Automated safety check: Pass | LGPL-3.0 | |
| Firecrawl Build Onboardingfirecrawl/firecrawl | 190k | 1 repos | ~1.4k | Automated safety check: Notes | ISC | |
| Obsidian BasesAtmosphere/atmosphere | 3.8k | 22 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
rolling-scopes/rsschool-app
NestJS best practices and architecture patterns for building production-ready applications.
Wei-Shaw/sub2api
Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.
firecrawl/firecrawl
Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.
Atmosphere/atmosphere
Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Categories
Configure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures. Configuration Runtime Resolution is an agent skill from greenpau/caddy-security. Configure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures.
Configuration Runtime Resolution fits situations like: determine which fields resolve and preserve exact values; manager blocks belong to secrets.
Run `npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a claude-code`. Or copy the skill folder (.codex/skills/configuration-runtime-resolution in greenpau/caddy-security) into .claude/skills/configuration-runtime-resolution in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a codex`. Or copy the skill folder (.codex/skills/configuration-runtime-resolution in greenpau/caddy-security) into .agents/skills/configuration-runtime-resolution in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-runtime-resolution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-runtime-resolution, .gemini/skills/configuration-runtime-resolution, .github/skills/configuration-runtime-resolution and .opencode/skills/configuration-runtime-resolution in your project.
Going by SKILL.md and its folder, Configuration Runtime Resolution needs credentials named SMTP_PASSWORD, OIDC_CLIENT_SECRET and JWT_SHARED_KEY. Our summary lists: A credential in OIDC_CLIENT_SECRET; A credential in JWT_SHARED_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration Runtime Resolution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Configuration Runtime Resolution: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.