Agent skill

Cockpit Headless Deploy

by jmagly in jmagly/aiwg

Guide or repair a headless Linux AIWG Cockpit plus Agentic Sandbox deployment when host topology, SSH access, service persistence, or runtime readiness must be planned safely.

MITAuto-check passedDevOps & Cloud

Install Cockpit Headless Deploy

skills CLI
$ npx skills add jmagly/aiwg --skill cockpit-headless-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jmagly/aiwg cockpit-headless-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agentic/code/addons/agentic-installer/skills/cockpit-headless-deploy .claude/skills/cockpit-headless-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cockpit-headless-deploy
GitHub stars
220
Token cost
~929 tokens
SKILL.md length
430 words
Files
2 (incl. scripts)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Guide or repair a headless Linux AIWG Cockpit plus Agentic Sandbox deployment when host topology, SSH access, service persistence, or runtime readiness must be planned safely.

  • Tasks that involve Deployment
  • SKILL.md covers Topology gate, Preview and authorization, Deployment and Verification and rollback
  • Runs JavaScript scripts from its folder; reaches aiwg.io

What it does

Cockpit Headless Deploy is an agent skill from jmagly/aiwg. Guide or repair a headless Linux AIWG Cockpit plus Agentic Sandbox deployment when host topology, SSH access, service persistence, or runtime readiness must be planned safely.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in DevOps & Cloud, covering Deployment. It works with Linux. The repository describes itself as: Cognitive architecture for AI-augmented software development. Specialized agents, structured workflows, and multi-platform deployment. Claude Code · Codex · Copilot · Cursor ·… The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment

Example prompts

  • “/cockpit-headless-deploy”

Requirements

  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit dda238f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • aiwg.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cockpit Headless Deploy loads about 929 tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 430 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~929

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jmagly/aiwg at commit dda238f, republished under its MIT licence (© jmagly). 430 words, ~929 tokens.

Download SKILL.mdSave it as .claude/skills/cockpit-headless-deploy/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cockpit-headless-deploy
description
Guide or repair a headless Linux AIWG Cockpit plus Agentic Sandbox deployment when host topology, SSH access, service persistence, or runtime readiness must be planned safely.
namespace
aiwg
platforms
all
script.entrypoint
scripts/headless-plan.mjs
script.runtime
node
script.cwd
project-root
script.argsHint
plan|stage|rollback --manifest <setup.aiwg.yaml> --cockpit-host <host> [--executor-host <host>]

Cockpit Headless Deployment

Own the guided deployment or repair of Cockpit and Agentic Sandbox on a headless Linux host. The canonical installation contract is https://aiwg.io/agentic-sandbox/setup.aiwg.yaml; fetch or locate it, verify its release provenance when acquired remotely, and validate it with aiwg setup-validate before proposing mutation. Do not reproduce its package or installation action contract in this skill, and do not pass this provider-orchestrated manifest to deterministic aiwg setup-run.

Topology gate

Establish three facts separately:

  • the host running Cockpit and its Bridge;
  • the host running Agentic Sandbox;
  • the operator host and its access path to the Bridge.

If the executor host is neither proven equal to nor explicitly different from the Cockpit host, stop before mutation and ask exactly one question:

Will Agentic Sandbox run on the Cockpit host <host>, or a different host?

After the answer, record same-host or cross-host. Model operator-to-Bridge access separately from Bridge-to-executor transport. A cross-host deployment requires an explicit trusted transport plan; never infer a forward from an ambiguous hostname.

Preview and authorization

Run the bundled planner after manifest validation:

bash
aiwg run skill cockpit-headless-deploy -- plan \
  --manifest setup.aiwg.yaml \
  --cockpit-host <host> \
  --executor-host <host> \
  --operator-host <host>

Review its value-free preview of packages (owned by the manifest), services, ports, runtime tiers, mounts, egress, persistence, and cleanup. All application listeners default to 127.0.0.1. Require explicit operator authorization immediately before packages, services, tunnels, mounts, or host policy change. Preserve dirty source checkouts; prefer verified release packages or a clean clone. Do not replace or clean an existing checkout to make deployment easier.

Show full SKILL.md (193 more words)Show less

Deployment

Apply the validated SetupManifest through the provider-orchestrated installer handoff. Use stage only to materialize the value-free user-service plan and attempt ledger inside an explicitly chosen staging root; review those files before installing them as user units. Host and Docker readiness are independent requirements. Claim VM readiness only when KVM evidence exists.

Keep Cockpit/Bridge and executor listeners on loopback. For cross-host topologies, bind both applications locally and add only the reviewed transport between the declared endpoints. Order the Cockpit user unit after the executor unit when they share a host, enable only the created units, and record every created or changed resource in the attempt ledger.

Verification and rollback

Run aiwg cockpit doctor with the declared topology and hosts. Do not report success until its package, Bridge, real-executor, host, Docker, listener, and persistence rows meet the selected runtime plan. A VM row may remain a warning when VM isolation was not selected.

On failure, restore only resources marked as created or changed by this attempt. The bundled rollback command removes only ledger-owned staged files; it refuses paths outside the recorded staging root. Never perform generic container, image, VM, worktree, package-cache, or data-directory cleanup.

© jmagly, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in agentic/code/addons/agentic-installer/skills/cockpit-headless-deploy of jmagly/aiwg.

  • SKILL.md
  • scripts/headless-plan.mjs

Open the folder on GitHubat commit dda238f

Compare with similar skills

Cockpit Headless Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cockpit Headless Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cockpit Headless Deploy this skilljmagly/aiwg220—~929Automated safety check: PassMIT
Openbkn Deployopenbkn-ai/bkn-foundry645—~1.9kAutomated safety check: NotesCustom licence
Spa Create Configsplunk/splunk-platform-automator138—~3.5kAutomated safety check: PassProprietary
Setup Workshopbrevdev/workshop-build-an-agent146—~2.3kAutomated safety check: NotesApache-2.0
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence
Nullprivate DeployNullPrivate/NullPrivate111—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • Openbkn Deploy

    openbkn-ai/bkn-foundry

    Deploy or upgrade OpenBKN on a customer-authorized Linux server through the repository's deploy scripts, with preflight checks, explicit confirmation, secret handling, and post-deployment…

    645 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Spa Create Config

    splunk/splunk-platform-automator

    A skill your agent uses when creating or updating splunkconfig.yml, designing Splunk Enterprise lab topology, multisite IDXC, SHC layout, architecture plan before config, or AWS Terraform block for…

    138 GitHub stars~3.5k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Setup Workshop

    brevdev/workshop-build-an-agent

    This skill should be used when the user wants to set up, install, deploy, bootstrap, or "spin up" the Build-an-Agent workshop (a.k.a.

    146 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Nullprivate Deploy

    NullPrivate/NullPrivate

    构建并发布 NullPrivate 镜像到阿里云容器镜像服务,更新 k3s 工作负载并完成 rollout、镜像 digest、Pod、Service、Gateway/Ingress、HTTPS 与 DNS/DoH 验收。Use when: 推送 dev 镜像、发布 NullPrivate、更新 public3 Pod、部署 adguardprivate、回滚 public3、检查…

    111 GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Work out why the blot-container-{blue,green,yellow} Docker containers from the most recent production deployment have restarted — distinguishing a normal deploy-triggered restart from a crash (V8…

    2k GitHub stars~4.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from jmagly/aiwg

All 11 skills in this repo
  • Review editorial phrase patterns and suggest contextual alternatives; legacy name does not imply authorship detection.

    220 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Voice Apply

    jmagly/aiwg

    Apply a voice profile to transform content. An agent skill from jmagly/aiwg.

    220 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Mutation Test

    jmagly/aiwg

    Run mutation testing to validate test quality beyond code coverage.

    220 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • TDD Enforce

    jmagly/aiwg

    Configure TDD enforcement via pre-commit hooks and CI coverage gates.

    220 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Detect project type, AIWG framework state, team configuration, and active work to summarize status and recommend next actions

    220 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Manage artifact metadata, versioning, ownership, and review history across the SDLC lifecycle

    220 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Cockpit Headless Deploy

What does Cockpit Headless Deploy do?

Guide or repair a headless Linux AIWG Cockpit plus Agentic Sandbox deployment when host topology, SSH access, service persistence, or runtime readiness must be planned safely. Cockpit Headless Deploy is an agent skill from jmagly/aiwg. Guide or repair a headless Linux AIWG Cockpit plus Agentic Sandbox deployment when host topology, SSH access, service persistence, or runtime readiness must be planned safely.

When should I use Cockpit Headless Deploy?

Cockpit Headless Deploy fits situations like: tasks that involve Deployment.

How do I install Cockpit Headless Deploy in Claude Code?

Run `npx skills add jmagly/aiwg --skill cockpit-headless-deploy -a claude-code`. Or copy the skill folder (agentic/code/addons/agentic-installer/skills/cockpit-headless-deploy in jmagly/aiwg) into .claude/skills/cockpit-headless-deploy in your project. Claude Code loads it when a task matches its description.

How do I install Cockpit Headless Deploy in Codex?

Run `npx skills add jmagly/aiwg --skill cockpit-headless-deploy -a codex`. Or copy the skill folder (agentic/code/addons/agentic-installer/skills/cockpit-headless-deploy in jmagly/aiwg) into .agents/skills/cockpit-headless-deploy in your project. Codex loads it when a task matches its description.

Can I use Cockpit Headless Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jmagly/aiwg --skill cockpit-headless-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cockpit-headless-deploy, .gemini/skills/cockpit-headless-deploy, .github/skills/cockpit-headless-deploy and .opencode/skills/cockpit-headless-deploy in your project.

What does Cockpit Headless Deploy need to run?

Going by SKILL.md and its folder, Cockpit Headless Deploy needs JavaScript for the scripts in its folder. Our summary lists: Node.js; Docker.

Does Cockpit Headless Deploy access the network?

SKILL.md names 1 domain. In commands or code: aiwg.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cockpit Headless Deploy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cockpit Headless Deploy use?

Cockpit Headless Deploy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cockpit Headless Deploy use?

About 929 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cockpit Headless Deploy?

Skills that share tags, products or a category with Cockpit Headless Deploy: Openbkn Deploy (openbkn-ai/bkn-foundry, 645 stars), Spa Create Config (splunk/splunk-platform-automator, 138 stars), Setup Workshop (brevdev/workshop-build-an-agent, 146 stars) and Release All (paperboytm/spool, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cockpit Headless Deploy?

jmagly (a GitHub user) maintains it in jmagly/aiwg, which has 220 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: jmagly/aiwg on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.