Devops Excellence
majiayu000/spellbook
DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
$ npx skills add irahardianto/awesome-agv --skill ci-cd -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install irahardianto/awesome-agv ci-cd --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/irahardianto/awesome-agv.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci-cd .claude/skills/ci-cd && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ci-cd" agent skill from https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cd into .claude/skills/ci-cd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-cd", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cdType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add irahardianto/awesome-agv --skill ci-cd -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install irahardianto/awesome-agv ci-cd --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/irahardianto/awesome-agv.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ci-cd .agents/skills/ci-cd && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ci-cd" agent skill from https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cd into .agents/skills/ci-cd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-cd", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add irahardianto/awesome-agv --skill ci-cd -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install irahardianto/awesome-agv ci-cd --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/irahardianto/awesome-agv.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ci-cd .cursor/skills/ci-cd && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ci-cd" agent skill from https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cd into .cursor/skills/ci-cd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-cd", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/irahardianto/awesome-agv.git --path .agents/skills/ci-cd--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add irahardianto/awesome-agv --skill ci-cd -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install irahardianto/awesome-agv ci-cd --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/irahardianto/awesome-agv.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ci-cd .gemini/skills/ci-cd && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ci-cd" agent skill from https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cd into .gemini/skills/ci-cd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-cd", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install irahardianto/awesome-agv ci-cdInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add irahardianto/awesome-agv --skill ci-cd -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/irahardianto/awesome-agv.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ci-cd .github/skills/ci-cd && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ci-cd" agent skill from https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cd into .github/skills/ci-cd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-cd", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add irahardianto/awesome-agv --skill ci-cd -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install irahardianto/awesome-agv ci-cd --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/irahardianto/awesome-agv.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ci-cd .opencode/skills/ci-cd && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ci-cd" agent skill from https://github.com/irahardianto/awesome-agv/tree/main/.agents/skills/ci-cd into .opencode/skills/ci-cd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-cd", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ci-cdRules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
The skill scales its rules to deployment complexity. Level 0 applies to every project and fixes the stage order: lint, build, unit test, integration test, security scan and deploy, with rules such as failing fast, keeping pipelines deterministic and under 15 minutes, never skipping a failing step and building once so the same artifact moves through every environment. Level 1 adds multi-stage builds, image scanning and SBOM attestation for container artifacts, and Level 2 adds deployment strategies and GitOps for Kubernetes.
Deploy-target snippets show Docker Compose, Cloud Run, Vercel and Kubernetes through GitOps. The GitHub Actions manifest rules say to pin action versions, order stages with needs, cache dependencies, read versions from version files and keep secrets out of workflow files. The Level 2 material sits in references/gitops-kubernetes.md and is loaded only when a project reaches that level.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9e997ba. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockergcloudvercelnpmyarnkubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, gcloud, vercel, npm, yarn and kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
POSTGRES_PASSWORDDB_PASSWORDCOSIGN_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CI/CD Pipeline Principles loads about 2.7k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 843 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Never copy `.env`, secrets, or `.git` into imagesenv_file: .env # Environment configAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from irahardianto/awesome-agv at commit 9e997ba, republished under its MIT licence (© irahardianto). 843 words, ~2,716 tokens.
.claude/skills/ci-cd/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Agent scope: This rule applies when writing CI/CD manifests (Dockerfile, docker-compose, GitHub Actions, GitLab CI, etc.). It is layered by deployment complexity — apply only the levels relevant to the project.
| Level | Applies When | Key Additions |
|---|---|---|
| 0 — All projects | Always | Lint, test, security scan, secrets management |
| 1 — Containerized | Docker image is the artifact | Multi-stage build, image scan, SBOM attestation |
| 2 — Orchestrated | Kubernetes or managed container platform | Deployment strategies, GitOps |
Load supplementary rules when reaching Level 2:
Pipeline Stages (in order):
Rules:
The deploy stage varies by target. The pipeline stages before it are identical.
Docker Compose (local / staging):
docker compose up --buildCloud Run:
gcloud run deploy myapp \
--image gcr.io/project/myapp:$GIT_SHA \
--region us-central1Vercel (frontend SPA):
vercel deploy --prodKubernetes: Use GitOps — see references/gitops-kubernetes.md.
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod # Pin via go.mod
cache: true # Cache dependencies
- run: gofumpt -l -e -d .
- run: go vet ./...
- run: staticcheck ./...
test:
needs: lint # Fail fast: lint before test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
cache: true
- run: go test -race -cover ./...
security:
needs: test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan for secrets
uses: trufflesecurity/trufflehog@v3 # Pin to release tag
- name: Audit dependencies
run: go run golang.org/x/vuln/cmd/govulncheck@latest ./...Rules:
@v4, not @latest or @main)needs: to enforce stage orderingcache: true in setup actions)go-version-file / node-version-file instead of hardcoding versions${{ secrets.NAME }}# Stage 1: Build
FROM golang:1.22-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download # Cache dependencies
COPY . .
RUN CGO_ENABLED=0 go build -o /bin/api ./cmd/api
# Stage 2: Runtime (minimal image)
FROM gcr.io/distroless/static-debian12
COPY --from=builder /bin/api /bin/api
EXPOSE 8080
CMD ["/bin/api"]Rules:
:latest).env, secrets, or .git into imagesservices:
backend:
build:
context: ./apps/backend # Path per project-structure.md
ports:
- "8080:8080"
env_file: .env # Environment config
depends_on:
postgres:
condition: service_healthy
postgres:
image: postgres:16-alpine # Pin versions
environment:
POSTGRES_DB: ${DB_NAME}
POSTGRES_USER: ${DB_USER}
POSTGRES_PASSWORD: ${DB_PASSWORD}
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${DB_USER}"]
interval: 5s
timeout: 5s
retries: 5
volumes:
- pgdata:/var/lib/postgresql/data
volumes:
pgdata:Rules:
depends_on with condition: service_healthyAfter building and pushing a container image, scan it and attach a signed SBOM attestation.
Preferred approach: Cosign keyless signing (no key management required)
Cosign integrates with your CI provider's OIDC token (GitHub Actions, GitLab CI) to sign images and attestations without storing or rotating cryptographic keys. The signature is anchored to a transparency log (Rekor), making it auditable and policy-enforceable.
build:
needs: security
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write # Required for Cosign keyless signing
steps:
- uses: actions/checkout@v4
- name: Install Cosign
uses: sigstore/cosign-installer@v3
- name: Build and push image
id: build
run: |
docker build -t ghcr.io/${{ github.repository }}:${{ github.sha }} .
docker push ghcr.io/${{ github.repository }}:${{ github.sha }}
- name: Scan container image
run: |
trivy image \
--severity HIGH,CRITICAL \
--exit-code 1 \
ghcr.io/${{ github.repository }}:${{ github.sha }}
- name: Generate SBOM
run: |
syft ghcr.io/${{ github.repository }}:${{ github.sha }} \
-o cyclonedx-json > sbom.json
- name: Attest SBOM to image (keyless, OIDC-backed)
run: |
cosign attest \
--predicate sbom.json \
--type cyclonedx \
ghcr.io/${{ github.repository }}:${{ github.sha }}
# Cosign uses the GitHub Actions OIDC token automatically.
# No COSIGN_PASSWORD or secret keys required.How the SBOM travels with the image:
The SBOM attestation is stored as an OCI reference in the same container registry alongside the image digest. It requires no additional infrastructure — any registry that supports OCI artifacts (ghcr.io, Google Artifact Registry, AWS ECR, Docker Hub) works out of the box.
To verify the attestation at any time:
cosign verify-attestation \
--type cyclonedx \
ghcr.io/org/app@sha256:<digest>Use ORAS instead of Cosign when:
oras attach ghcr.io/org/app@sha256:<digest> scan-report.jsonRules:
npm audit/yarn audit instead;
no SBOM attachment appliesCode deployment and feature release are separate concerns. When the PRD or technical architecture explicitly requires gradual rollout, A/B testing, or kill switches, feature flags can decouple them.
Agent rule: Do NOT implement feature flags unless explicitly required by the PRD or technical architecture document. See @.agents/skills/feature-flags/SKILL.md for implementation guidance when they are required.
dev → staging → productionRules:
Always (all projects):
If building container images (Level 1):
If deploying to Kubernetes (Level 2):
kubectl apply in production?If feature flags are required by PRD/architecture:
© irahardianto, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .agents/skills/ci-cd of irahardianto/awesome-agv.
Open the folder on GitHubat commit 9e997ba
CI/CD Pipeline Principles next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CI/CD Pipeline Principles this skillirahardianto/awesome-agv | 157 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Devops Excellencemajiayu000/spellbook | 287 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Deployment Automationaiskillstore/marketplace | 430 | 1 repos | ~3k | Automated safety check: Notes | None | |
| Devops EngineerYikai-Liao/symusic | 189 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| CI CDEliasOulkadi/shokunin | 114 | — | ~3.4k | Automated safety check: Notes | MIT |
majiayu000/spellbook
DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.
aiskillstore/marketplace
Automate application deployment to cloud platforms and servers.
Yikai-Liao/symusic
Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
EliasOulkadi/shokunin
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…
rohitg00/awesome-claude-code-toolkit
CI/CD pipeline design with GitHub Actions, Docker, Kubernetes, Helm, and GitOps patterns
irahardianto/awesome-agv
Commits to one bold aesthetic direction, sets up a CSS token system for it, then builds the interface in Vue or plain HTML using those tokens.
irahardianto/awesome-agv
Profile-driven performance optimization protocol. An agent skill from irahardianto/awesome-agv.
irahardianto/awesome-agv
Coding conventions for Angular 19 and later: standalone components, signals, OnPush change detection, lazy routes and where RxJS still belongs.
irahardianto/awesome-agv
Hono lightweight web framework patterns: type-safe route handlers, middleware composition, Zod validation, and RPC clients for Cloudflare Workers, Node, or Bun.
irahardianto/awesome-agv
Mobile E2E testing patterns — Flutter integrationtest, Patrol, Maestro, golden testing, device matrix, and test data management.
irahardianto/awesome-agv
Next.js App Router architecture: React Server Components (RSC), Server Actions, nested layouts, route handlers, and streaming.
Categories
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments. The skill scales its rules to deployment complexity. Level 0 applies to every project and fixes the stage order: lint, build, unit test, integration test, security scan and deploy, with rules such as failing fast, keeping pipelines deterministic and under 15 minutes, never skipping a failing step and building once so the same artifact moves through every environment.
CI/CD Pipeline Principles fits situations like: designing a CI pipeline for a new repository; writing a multi-stage Dockerfile with image scanning; debugging a slow or flaky GitHub Actions or GitLab CI pipeline; setting up promotion of one build artifact across environments.
Run `npx skills add irahardianto/awesome-agv --skill ci-cd -a claude-code`. Or copy the skill folder (.agents/skills/ci-cd in irahardianto/awesome-agv) into .claude/skills/ci-cd in your project. Claude Code loads it when a task matches its description.
Run `npx skills add irahardianto/awesome-agv --skill ci-cd -a codex`. Or copy the skill folder (.agents/skills/ci-cd in irahardianto/awesome-agv) into .agents/skills/ci-cd in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add irahardianto/awesome-agv --skill ci-cd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-cd, .gemini/skills/ci-cd, .github/skills/ci-cd and .opencode/skills/ci-cd in your project.
Going by SKILL.md and its folder, CI/CD Pipeline Principles needs the command-line tools its instructions call (docker, gcloud, vercel, npm, yarn and kubectl) and credentials named POSTGRES_PASSWORD, DB_PASSWORD and COSIGN_PASSWORD.
SKILL.md contains no URLs. Its commands use docker and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
CI/CD Pipeline Principles is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with CI/CD Pipeline Principles: Devops Excellence (majiayu000/spellbook, 287 stars), Deployment Automation (aiskillstore/marketplace, 430 stars), Devops Engineer (Yikai-Liao/symusic, 189 stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
irahardianto (a GitHub user) maintains it in irahardianto/awesome-agv, which has 157 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 5, 2026.
Source: irahardianto/awesome-agv on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.