Agent skill

Devops Excellence

by majiayu000 in majiayu000/spellbook

DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

MITAuto-check: notesDevOps & Cloud

Install Devops Excellence

skills CLI
$ npx skills add majiayu000/spellbook --skill devops-excellence -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/spellbook devops-excellence --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/devops-excellence .claude/skills/devops-excellence && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
devops-excellence
GitHub stars
287
Token cost
~2.4k tokens
SKILL.md length
432 words
Files
7
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

  • Setting up pipelines
  • SKILL.md covers Core Principles, Hard Rules (Must Follow), Quick Reference and CI/CD Pipeline Best Practices, plus 3 more sections
  • Calls docker; needs AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY
  • Containerizing applications

What it does

Devops Excellence is an agent skill from majiayu000/spellbook. DevOps and CI/CD expert. Use when setting up pipelines, containerizing applications, deploying to Kubernetes, or implementing release strategies. Covers GitHub Actions, Docker, K8s, Terraform, and GitOps.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `reference/cicd.md`, `reference/containers.md` and `reference/extended.md`).

It sits in DevOps & Cloud, covering Container orchestration, CI/CD and Deployment. It works with Kubernetes, Docker, GitHub Actions and Terraform. The repository describes itself as: Cross-runtime skills for Claude Code, Codex, and multi-agent workflows. The licence is MIT.

When your agent uses it

  • Setting up pipelines
  • Containerizing applications
  • Deploying to Kubernetes
  • Implementing release strategies

Example prompts

  • “Use the devops-excellence skill to devop and CI/CD expert. An agent skill from majiayu000/spellbook”
  • “/devops-excellence”

Requirements

  • Node.js
  • Docker
  • A credential in AWS_SECRET_ACCESS_KEY
  • A credential in API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit ed52af7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY
    • DATABASE_PASSWORD
    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Devops Excellence loads about 2.4k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 432 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:75
    COPY .env /app/.env
  • NoteMentions a .env fileSKILL.md:263
    .env
  • NoteMentions a .env fileSKILL.md:264
    .env.local

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/spellbook at commit ed52af7, republished under its MIT licence (© majiayu000). 432 words, ~2,413 tokens.

Download SKILL.mdSave it as .claude/skills/devops-excellence/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
devops-excellence
description
DevOps and CI/CD expert. Use when setting up pipelines, containerizing applications, deploying to Kubernetes, or implementing release strategies. Covers GitHub Actions, Docker, K8s, Terraform, and GitOps.

DevOps Excellence

Core Principles

  • Shift Left — Address security and quality early in SDLC
  • GitOps — Git as single source of truth for infrastructure and deployments
  • Infrastructure as Code — All infrastructure versioned and reproducible
  • Progressive Delivery — Gradual rollouts with feature flags and canary releases
  • Immutable Infrastructure — Replace, don't modify running systems
  • Observability-First — Monitor metrics tied to deployments and features
  • Policy as Code — Enforce compliance and security automatically
  • Platform Engineering — Build golden paths and self-service portals

Hard Rules (Must Follow)

These rules are mandatory. Violating them means the skill is not working correctly.

No Static Credentials

Never use long-lived static credentials. Always use OIDC or short-lived tokens.

yaml
# ❌ FORBIDDEN: Static AWS credentials
env:
  AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
  AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}

# ✅ REQUIRED: OIDC-based authentication
- name: Configure AWS Credentials
  uses: aws-actions/configure-aws-credentials@v4
  with:
    role-to-assume: arn:aws:iam::123456789012:role/GitHubActions
    aws-region: us-east-1
    # No long-lived secrets - uses GitHub OIDC provider
No Root Containers

Containers must NEVER run as root. Always specify a non-root user.

dockerfile
# ❌ FORBIDDEN: Running as root (default)
FROM node:20
WORKDIR /app
CMD ["node", "server.js"]

# ❌ FORBIDDEN: Explicit root user
USER root

# ✅ REQUIRED: Non-root user with UID > 1000
FROM node:20-alpine
RUN addgroup -g 1001 -S nodejs && \
    adduser -S nodejs -u 1001
USER nodejs
WORKDIR /app
CMD ["node", "server.js"]
No Secrets in Images

Never bake secrets into Docker images. Use runtime injection or secrets managers.

dockerfile
# ❌ FORBIDDEN: Secrets in build args or ENV
ARG DATABASE_PASSWORD
ENV API_KEY=sk-xxx

# ❌ FORBIDDEN: Copying secret files
COPY .env /app/.env
COPY credentials.json /app/

# ✅ REQUIRED: Mount secrets at runtime
# docker run -v /secrets:/app/secrets:ro myapp
# Or use Kubernetes secrets/configmaps
Protected Production Deployments

Production deployments must require approval and be restricted to main branch.

yaml
# ❌ FORBIDDEN: Direct production deploy without protection
deploy:
  runs-on: ubuntu-latest
  steps:
    - run: deploy-to-prod.sh

# ✅ REQUIRED: Environment protection
deploy:
  runs-on: ubuntu-latest
  environment:
    name: production
    url: https://myapp.com
  # Requires: approval + main branch only

Quick Reference

When to Use What
ScenarioTool/PatternReason
Public GitHub projectGitHub ActionsNative integration, free for public repos
Enterprise GitLabGitLab CIUnified platform, advanced security scanning
Multi-cloud IaCTerraformMature ecosystem, wide provider support
Developer-centric IaCPulumiReal programming languages, better testing
Kubernetes deploymentsArgoCD + KustomizeGitOps standard, declarative config
Zero-downtime releasesBlue-Green or CanaryInstant rollback capability
Gradual feature rolloutFeature flags (LaunchDarkly)Progressive delivery with targeting
Deployment Strategy Selection
StrategyDowntimeCostRollback SpeedComplexityBest For
RollingMinimalLowMediumLowRegular updates, cost-conscious
Blue-GreenZeroHigh (2x)InstantMediumCritical systems, easy rollback
CanaryZeroMediumFastHighRisk mitigation, data-driven
RecreateHighLowN/AVery LowNon-critical, dev/test only

Show full SKILL.md (167 more words)Show less

CI/CD Pipeline Best Practices

Pipeline Security
yaml
# Short-lived credentials (not static keys)
- name: Configure AWS Credentials
  uses: aws-actions/configure-aws-credentials@v4
  with:
    role-to-assume: arn:aws:iam::123456789012:role/GitHubActions
    aws-region: us-east-1
    # OIDC provider - no long-lived secrets!

# Protected environments for production
environment:
  name: production
  # Requires approval + restricts to main branch
Speed Optimization
  • 10-minute build rule — Most projects should build in <10 minutes
  • Parallel jobs — Run tests, linting, security scans concurrently
  • Cache dependencies — Cache node_modules, .m2, pip packages
  • Conditional execution — Skip jobs when files haven't changed
yaml
# Example: conditional job execution
jobs:
  backend-tests:
    if: contains(github.event.head_commit.modified, 'backend/')
    runs-on: ubuntu-latest
Testing Pyramid
              /\
             /E2E\        <- Few (slow, expensive)
            /------\
           /Integration\ <- Some (medium speed)
          /------------\
         /  Unit Tests  \ <- Many (fast, cheap)
        /----------------\
  • 70% Unit tests (fast, isolated)
  • 20% Integration tests (service interactions)
  • 10% E2E tests (full user workflows)
Security Scanning Integration
yaml
# Multi-layer security scanning
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      # SAST - Static code analysis
      - uses: github/codeql-action/init@v3

      # SCA - Dependency vulnerabilities
      - name: Run Trivy
        uses: aquasecurity/trivy-action@master
        with:
          scan-type: 'fs'
          format: 'sarif'

      # Secret scanning
      - name: Gitleaks
        uses: gitleaks/gitleaks-action@v2

      # Container scanning
      - name: Scan Docker image
        run: trivy image myapp:${{ github.sha }}

Docker Best Practices

Multi-Stage Builds
dockerfile
# Build stage - includes build tools (900MB+)
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production

# Runtime stage - minimal image (<100MB)
FROM node:20-alpine AS runtime
RUN addgroup -g 1001 -S nodejs && \
    adduser -S nodejs -u 1001
WORKDIR /app
COPY --from=builder --chown=nodejs:nodejs /app/node_modules ./node_modules
COPY --chown=nodejs:nodejs . .
USER nodejs
EXPOSE 3000
CMD ["node", "server.js"]
Security Hardening
  • Non-root user — ALWAYS run as non-root (UID 1001)
  • Minimal base images — Use alpine, distroless, or scratch
  • Read-only filesystem — docker run --read-only
  • No secrets in layers — Use build secrets or external vaults
  • Resource limits — Set CPU/memory limits to prevent DoS
  • Signed images — Enable Docker Content Trust
dockerfile
# Security best practices example
FROM gcr.io/distroless/nodejs20-debian12
COPY --chown=65532:65532 /app /app
USER 65532
EXPOSE 8080
.dockerignore
# Version control
.git
.gitignore

# Dependencies (install fresh in container)
node_modules
vendor/
*.pyc
__pycache__

# Secrets and configs
.env
.env.local
secrets/
*.key
*.pem

# Development files
README.md
Dockerfile
docker-compose.yml
.vscode/
.idea/

# Testing and CI
tests/
*.test.js
.github/

Kubernetes Deployment Patterns

Resource Management (Right-Sizing)
yaml
# 99.94% of clusters are over-provisioned!
# Average CPU usage: 10%, Memory: 23%
resources:
  requests:
    memory: "128Mi"  # Guaranteed allocation
    cpu: "100m"      # 0.1 CPU cores
  limits:
    memory: "256Mi"  # Maximum allowed
    cpu: "200m"      # Hard cap

# Use tools: Kubecost, Goldilocks, VPA
Health Checks
yaml
# Liveness: Is container alive?
livenessProbe:
  httpGet:
    path: /health
    port: 8080
  initialDelaySeconds: 30
  periodSeconds: 10
  timeoutSeconds: 5
  failureThreshold: 3

# Readiness: Can it receive traffic?
readinessProbe:
  httpGet:
    path: /ready
    port: 8080
  initialDelaySeconds: 5
  periodSeconds: 5
  successThreshold: 1

# Startup: Has initialization completed?
startupProbe:
  httpGet:
    path: /startup
    port: 8080
  failureThreshold: 30  # 30*10s = 5min for slow starts
  periodSeconds: 10
ConfigMaps and Secrets
yaml
# Group related resources in single manifest
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: app-config
data:
  APP_ENV: production
  LOG_LEVEL: info
---
apiVersion: v1
kind: Secret
metadata:
  name: app-secrets
type: Opaque
stringData:
  DATABASE_URL: postgresql://user:pass@db:5432/mydb
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: myapp
spec:
  template:
    spec:
      containers:
      - name: app
        envFrom:
        - configMapRef:
            name: app-config
        - secretRef:
            name: app-secrets
Security Best Practices
yaml
# Pod Security Standards
securityContext:
  runAsNonRoot: true
  runAsUser: 1000
  fsGroup: 1000
  seccompProfile:
    type: RuntimeDefault
  capabilities:
    drop:
    - ALL

# Network Policies (deny-by-default)
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: deny-all-ingress
spec:
  podSelector: {}
  policyTypes:
  - Ingress

Extended Reference

Detailed material starting at ## Infrastructure as Code (Terraform/Pulumi) has been moved to reference/extended.md to keep this skill concise. Load that reference when the task requires the moved examples, command catalogs, checklists, platform details, or implementation templates.

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in skills/devops-excellence of majiayu000/spellbook.

  • SKILL.md
  • reference/cicd.md
  • reference/containers.md
  • reference/extended.md
  • reference/release-strategies.md
  • templates/Dockerfile
  • templates/github-actions.yaml

Open the folder on GitHubat commit ed52af7

Compare with similar skills

Devops Excellence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Devops Excellence compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Devops Excellence this skillmajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
Devops Deploymentyonatangross/orchestkit290—~2.7kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Devops Automatorcuriositech/some_claude_skills243—~1.8kAutomated safety check: PassMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    290 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Devops Automator

    curiositech/some_claude_skills

    Expert DevOps engineer for CI/CD, IaC, Kubernetes, and deployment automation.

    243 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Devops Infrastructure

    CloudAI-X/claude-workflow-v2

    Guides Docker, CI/CD pipelines, deployment strategies, infrastructure as code, and observability setup.

    1.4k GitHub stars~2.7k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes

More from majiayu000/spellbook

All 97 skills in this repo
  • Skill Ecosystem Doctor

    majiayu000/spellbook

    Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.

    287 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • AGENTS.md Scaffold

    majiayu000/spellbook

    Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.

    287 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Product Demo Builder

    majiayu000/spellbook

    Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.

    287 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Flowguard Task Guard

    majiayu000/spellbook

    Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.

    287 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Product Manager Toolkit

    majiayu000/spellbook

    Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.

    287 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Devops Excellence

What does Devops Excellence do?

DevOps and CI/CD expert. An agent skill from majiayu000/spellbook. Devops Excellence is an agent skill from majiayu000/spellbook. DevOps and CI/CD expert.

When should I use Devops Excellence?

Devops Excellence fits situations like: setting up pipelines; containerizing applications; deploying to Kubernetes; implementing release strategies.

How do I install Devops Excellence in Claude Code?

Run `npx skills add majiayu000/spellbook --skill devops-excellence -a claude-code`. Or copy the skill folder (skills/devops-excellence in majiayu000/spellbook) into .claude/skills/devops-excellence in your project. Claude Code loads it when a task matches its description.

How do I install Devops Excellence in Codex?

Run `npx skills add majiayu000/spellbook --skill devops-excellence -a codex`. Or copy the skill folder (skills/devops-excellence in majiayu000/spellbook) into .agents/skills/devops-excellence in your project. Codex loads it when a task matches its description.

Can I use Devops Excellence in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill devops-excellence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/devops-excellence, .gemini/skills/devops-excellence, .github/skills/devops-excellence and .opencode/skills/devops-excellence in your project.

What does Devops Excellence need to run?

Going by SKILL.md and its folder, Devops Excellence needs the command-line tools its instructions call (docker) and credentials named AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, DATABASE_PASSWORD and API_KEY. Our summary lists: Node.js; Docker; A credential in AWS_SECRET_ACCESS_KEY; A credential in API_KEY.

Does Devops Excellence access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Devops Excellence safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Devops Excellence use?

Devops Excellence is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Devops Excellence use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Devops Excellence?

Skills that share tags, products or a category with Devops Excellence: Devops Engineer (Yikai-Liao/symusic, 189 stars), Devops Deployment (yonatangross/orchestkit, 290 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and Devops Automator (curiositech/some_claude_skills, 243 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Devops Excellence?

majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 287 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.

Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.