Agent skill

Configuration State

by greenpau in greenpau/caddy-security

Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration State

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-state -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-state --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-state .claude/skills/configuration-state && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-state
GitHub stars
2.3k
Token cost
~1.6k tokens
SKILL.md length
666 words
Files
3 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

  • Root state blocks and process-level restart guarantees
  • SKILL.md covers Configuration, Lifecycle and operation and Validation
  • Calls go

What it does

Configuration State is an agent skill from greenpau/caddy-security. Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery. Use for root state blocks and process-level restart guarantees.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/operations.md`).

It sits in Backend & APIs. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Root state blocks and process-level restart guarantees

Example prompts

  • “/configuration-state”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration State loads about 1.6k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 666 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 666 words, ~1,559 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-state/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
configuration-state
description
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery. Use for root state blocks and process-level restart guarantees.

Persistent Runtime State

Use this skill for security { state { ... } }, native config.state JSON, restart persistence, and its lifecycle boundary. OAuth client registrations and identity databases retain their existing owners. Keep changes and test output in this repository; sibling AuthCrunch source is a read-only reference under the repository scope.

Configuration

Add one optional block inside the global security app:

caddyfile
{
	security {
		state {
			directory /var/lib/authcrunch/runtime
		}
		# Existing providers, portals and/or authorization policies follow.
	}
}

This is a fragment: a usable security app also needs a portal or policy. The JSON field is apps.security.config.state, with the library's shape: "state":{"directory":"/var/lib/authcrunch/runtime"}. Paths must be absolute, non-root and private. Quote spaces. Omission retains volatile behavior; an empty block, duplicate block/setting, extra arguments, unknown settings and nested blocks are errors. Closing braces end their lines. Use {$VARIABLE} for adaptation-time substitution. {env.VARIABLE} and whole secrets:manager:key references remain declarative until provisioning; an empty or invalid resolved directory fails instead of disabling persistence.

caddyfile_state.go owns traversal and cfgutil.EncodeArgs encoding; go-authcrunch/pkg/state/parser.NewStateConfigFromDirectives owns grammar and normalization. Deferred values use a validation-only stand-in, retain their original token in Config.State, and are resolved/revalidated in the private configuration copy. Never open the stand-in, choose a process-specific directory, implement another directory grammar, or copy the library's records, encryption, session DTOs, replay history or locks into Caddy.

Lifecycle and operation

Pending cross-device interactions are always volatile. Reload or complete stop/start discards them even when completed sessions use persistent state. The existing rejection of overlapping persistent reload still applies. See cross-device lifecycle.

Read operator guidance when enabling persistence, planning deployment/recovery, or explaining its guarantees. Persistent runtimes are constructed by App.Start, not Provision, so adaptation and validation do not initialize keys or state files. Route provisioning validates declared names; admission stays closed until NewServer succeeds.

Caddy v2.11.7 provisions and starts a replacement before retiring the old app. There is no atomic drain/construct/rollback facility. A candidate persistent app checks Caddy's active app during provisioning and rejects replacement of a live persistent runtime before candidate HTTP routes start. This deliberately also rejects changing directories by reload. Use a complete stop/start. The library independently enforces exclusive directory ownership across processes. Do not add a host storage lock or shared runtime/snapshot map.

App.Cleanup closes admission, drains every admitted portal/gatekeeper call (including callbacks, token and profile APIs), then closes the root. A failed candidate never closes the serving root. Failed construction unwinds its own resources. Close neither flushes nor deletes committed data. Preserve handled 503/protocol failures and never issue fallback credentials or retry rotations.

Policy-only OAuth needs neither a placeholder portal nor a local database. The direct OAuth policy contract owns those settings; mount callback/logout paths through the same policy.

Show full SKILL.md (245 more words)Show less

Validation

The selected published go-authcrunch v1.3.4 supplies Config.State and both public parsers; no dependency replacement is needed. Recheck the selected module before changing the contract. Library tests alone do not certify this host.

  • caddyfile_state_test.go, caddyfile_authz_oauth_test.go and the testcase_security_state adaptation fixture cover grammar, exact paths, JSON, placeholders, redacted failures and policy-only configuration.
  • app_state_test.go covers no-I/O provisioning, single ownership, failed initialization, retry, 503 route admission before startup/after cleanup and drain before storage release.
  • TestAuthzResponseContract tests the actual three-outcome route handler.
  • TestCaddyRuntimeStateE2E builds an actual Caddy command from testdata/runtime_state_caddy, with standard/production modules and only an isolated test CA pool added to the main program. TLS verification remains enabled; no machine trust is changed. It uses SIGKILL and the same origin, directory and config across fresh processes. It covers direct OAuth, ACLs, lost pending callbacks, sessions/JWKS/signatures, browser/native refresh, OIDC consent/code/access/refresh and replay, logout, password/DB rollback, configuration transitions, competing processes, corrupt/lost storage, permissions, write failures, real snapshot capacity and overlapping reload under admitted callbacks and application traffic. Deferred state-directory resolution preserves its placeholder in autosave. Omitted-state behavior and failed persistence activation retaining the volatile deployment's routes and sessions remain separate phases. The snapshot-capacity fixture writes tens of MiB.

When changing the state parser or runtime implementation, run focused unit/adaptation tests and go test -mod=readonly -race -count=1 -timeout=8m -run 'TestCaddyRuntimeStateE2E|TestPersistentApp' .. Retain the existing OAuth, lifecycle, composition and browser refresh coverage. Ordinary configuration review uses the relevant grammar, path/ownership and deployment checks; skill-only changes need metadata/link/source validation. Full regression/report runs follow testing-and-ci.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .codex/skills/configuration-state of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml
  • references/operations.md

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration State next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration State compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration State this skillgreenpau/caddy-security2.3k—~1.6kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Users

    greenpau/caddy-security

    Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.

    2.3k GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Configuration State

What does Configuration State do?

Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery. Configuration State is an agent skill from greenpau/caddy-security. Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

When should I use Configuration State?

Configuration State fits situations like: root state blocks and process-level restart guarantees.

How do I install Configuration State in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-state -a claude-code`. Or copy the skill folder (.codex/skills/configuration-state in greenpau/caddy-security) into .claude/skills/configuration-state in your project. Claude Code loads it when a task matches its description.

How do I install Configuration State in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-state -a codex`. Or copy the skill folder (.codex/skills/configuration-state in greenpau/caddy-security) into .agents/skills/configuration-state in your project. Codex loads it when a task matches its description.

Can I use Configuration State in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-state -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-state, .gemini/skills/configuration-state, .github/skills/configuration-state and .opencode/skills/configuration-state in your project.

What does Configuration State need to run?

Going by SKILL.md and its folder, Configuration State needs the command-line tools its instructions call (go).

Does Configuration State access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration State safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration State use?

Configuration State is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration State use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Configuration State?

Skills that share tags, products or a category with Configuration State: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration State?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.