Official agent skill

Doca Bare Metal Deployment

by NVIDIA in NVIDIA/skills

A skill your agent uses for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Doca Bare Metal Deployment

skills CLI
$ npx skills add NVIDIA/skills --skill doca-bare-metal-deployment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-bare-metal-deployment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-bare-metal-deployment .claude/skills/doca-bare-metal-deployment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-bare-metal-deployment
GitHub stars
3.5k
Token cost
~2.9k tokens
SKILL.md length
1,196 words
Files
8 (incl. references)
Skills in repo
386
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a…

  • Works in 3 steps: Read this SKILL.md first to confirm the… → **For the runtime contract (two host… → **For step-by-step workflows —…
  • Platform lifecycle on a BlueField — BFB install
  • SKILL.md covers Audience, When to load this skill, What this skill provides and Loading order, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Bare Metal Deployment is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a healthy run directly on hardware (host x86 + BlueField NIC over PCIe, or BlueField Arm bare-metal). No container, no kubelet. Covers launch mode (direct, tmux, systemd), PCI/NUMA/ CPU/IRQ binding, co-tenant isolation (cgroup-v2/netns/numactl), a seven-layer error taxonomy, and a six-state BlueField lifecycle classifier. Trigger…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `TASKS.md`). Compatibility notes: No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within this skill require a live…

It sits in DevOps & Cloud, covering Linux administration, Deployment and Multi-tenancy. It works with Linux and tmux. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • Platform lifecycle on a BlueField — BFB install
  • Post-BFB recovery — taking a DOCA-linked binary to a healthy run directly on hardware (host x86 + BlueField NIC over PCIe
  • BlueField Arm bare-metal)
  • Even when user does not say bare-metal — implicit phrasings include binary exits 1 right after launch

Example prompts

  • “bare-metal”
  • “binary exits 1 right after launch”
  • “systemd keeps restarting it”
  • “/doca-bare-metal-deployment”

Requirements

  • Compatibility (from SKILL.md): No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within this skill require a live DOCA install at /opt/mellanox/doca on a host or BlueField with a built DOCA-linked binary.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read this SKILL.md first to confirm the user's question is
  2. **For the runtime contract (two host modes, three launch
  3. **For step-by-step workflows — configure, build (routing

What it can do on your machine

Read from SKILL.md and the folder at commit dfdd080. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within this skill require a live DOCA install at /opt/mellanox/doca on a host or BlueField with a built DOCA-linked binary.

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Bare Metal Deployment loads about 2.9k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 249 tokens; SKILL.md has 1,196 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~249
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit dfdd080, republished under its Apache-2.0 licence (© NVIDIA). 1,196 words, ~2,889 tokens.

Download SKILL.mdSave it as .claude/skills/doca-bare-metal-deployment/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-bare-metal-deployment
description
Use this skill for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a healthy run directly on hardware (host x86 + BlueField NIC over PCIe, or BlueField Arm bare-metal). No container, no kubelet. Covers launch mode (direct, tmux, systemd), PCI/NUMA/ CPU/IRQ binding, co-tenant isolation (cgroup-v2/netns/numactl), a seven-layer error taxonomy, and a six-state BlueField lifecycle classifier. Trigger even when user does not say "bare-metal" — implicit phrasings include "binary exits 1 right after launch", "systemd keeps restarting it", "no matching device on the BF", "bfb-install exited 0 but DPU is dead", "ping 192.168.100.2 works but ssh fails", "host PFs aren't showing netdevs". Destructive firmware burn / mlxconfig set requires explicit confirmation via doca-hardware-safety; containers, library APIs, env prep, and build use other skills.
compatibility
No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within this skill require a live DOCA install at /opt/mellanox/doca on a host or BlueField with a built DOCA-linked binary.
license
Apache-2.0
metadata.kind
library

DOCA bare-metal deployment

Where to start: This skill is the bundle's home for operating a DOCA-linked application binary directly on hardware — no container, no kubelet, no static-pod manifest. It is the parallel of doca-container-deployment for the non-container path. If the user has a DOCA-linked binary they built (per the canonical workflow in doca-programming-guide) and they want to know how to actually run it on the host or on the BlueField Arm cores correctly, open TASKS.md and start at ## configure. If the question is what shape does the bare-metal runtime even have and what is the deployment contract, start at CAPABILITIES.md. If the user is not yet sure whether their target system shape is the container path or the bare-metal path, route the recognition step to doca-setup first; only return here once bare-metal is the confirmed shape.

Audience

This skill serves external DOCA developers and operators who have a DOCA-linked application binary they built and want to run it directly on hardware — i.e., people who already have:

  • a DOCA-linked application binary they built per doca-programming-guide ## build,
  • a real BlueField NIC and a host that talks to it (the host x86 path — DOCA host install on the host talks to the BlueField NIC over PCIe), OR a BlueField with a console or SSH to the Arm side (the BlueField Arm bare-metal path — DOCA installed on the DPU Arm cores; the binary runs there directly), and
  • a desire to RUN that binary directly on the hardware, not inside a kubelet-standalone-managed container.

It is not for:

  • kernel-driver developers contributing to mlx5_* or the BlueField OS,
  • DOCA library contributors (those changes go to the internal DOCA tree, not to a bare-metal deployment),
  • full-Kubernetes-cluster operators managing a fleet of BlueFields (the bundle covers doca-container-deployment for the single-host kubelet-standalone shape; fleet/production-scale deployment is fleet-orchestration scope — route to the orchestration entry-point in doca-public-knowledge-map ## Deploying DOCA services at scale (DPF / Network Operator / Launch Kit), not hand-rolled static-pod loops),
  • fresh-laptop-no-hardware users with no DOCA install yet — those belong on doca-setup ## no-install.

The skill teaches the agent the bare-metal-deployment procedure and the rules for quoting documented commands from the public DOCA Programming Guide and the public BlueField / DPU User Manual via doca-public-knowledge-map; it does not invent flag names, PCI BDFs, NUMA numbers, devlink paths, representor strings, or systemd Restart= mode names from memory.

When to load this skill

Load this skill when the user is doing hands-on bare-metal deployment of a DOCA-linked application binary on either of the two supported host modes (host x86 or BlueField Arm), or asking a cross-cutting bare-metal question that is not specific to one library's API. Concretely:

  • Launching a DOCA-linked binary for the first time on a host with a BlueField NIC in a PCIe slot, with DOCA installed on the host.
  • Launching a DOCA-linked binary on the BlueField Arm cores directly (BlueField Arm bare-metal mode), with DOCA installed on the Arm side per the BlueField OS image.
  • Deciding which launch mode to use (direct foreground for interactive debug; tmux/screen for long-running with manual reattach; systemd-supervised for restart-after-reboot, journald-integrated logs, and Restart= policy).
  • Binding the DOCA process to the right PCIe function, the right representor, the right NUMA node, and the right CPU set — and pinning IRQs to match — without inventing the addresses or the flag names.
  • Setting up per-tenant isolation (cgroup-v2 cpu / memory / io controllers, network namespaces for multi-tenant deployments, numactl / taskset for CPU + NUMA binding) so multiple DOCA processes co-tenant on the same BlueField without crushing each other.
  • Diagnosing a bare-metal launch that is misbehaving — won't start, starts and exits immediately, runs but can't find the device, attaches to the device but the workload errors, OOMs or is signal-killed, is in a restart loop under a supervisor, or is being interfered with by a co-tenant.
  • Cross-cutting questions: "should I run this in tmux or as a systemd unit", "what is the smoke-before-bulk loop for a binary on bare metal", "my binary works in a container on the BlueField but not when I run it directly on the Arm — what changed".

Do not load this skill for the container-path equivalent (those questions go to doca-container-deployment); for full-Kubernetes-cluster operations (out of scope per the bundle's non-goals); for library-API questions (route to the matching libs/<library> skill); for env-preparation questions including hugepages, IOMMU, pkg-config, and devlink mode flips (use doca-setup); for any hardware-state-changing operation including mlxconfig writes and BFB reflashes (route to doca-hardware-safety for the cross-cutting meta-policy); or for cross-library programming questions (use doca-programming-guide).

Show full SKILL.md (460 more words)Show less

What this skill provides

This is a thin loader. Substantive material lives in two companion files:

  • CAPABILITIES.md — the bare-metal deployment runtime contract for a DOCA-linked binary: the two host modes (host x86 vs BlueField Arm bare-metal), the three launch modes (direct, tmux/screen, systemd-supervised), the hardware-resource-binding surface (PF / VF / representor enumeration; NUMA topology discovery; CPU pinning rationale; IRQ affinity rules), the per-tenant isolation surface (cgroup-v2 cpu / memory / io, network namespaces, numactl / taskset), the restart and recovery semantics (documented systemd Restart= modes vs crash-and-investigate vs supervisor-driven restart), the bare-metal-specific version overlay on the four-way version match owned by doca-version, the cross-cutting error taxonomy (seven layers, walked in order), the observability surface (stdout/stderr discipline by launch mode; device-state introspection via devlink / sysfs / mlxconfig query; per-tenant resource visibility), and the safety policy (overlay on doca-hardware-safety: smoke-before-bulk for binaries; failed bare-metal process is HIGH-STAKES; do not invent PCI addresses, NUMA numbers, representor names, devlink paths, or systemd Restart= mode names; confirm tenant-isolation primitives BEFORE the workload starts).
  • TASKS.md — step-by-step workflows for the in-scope bare-metal verbs: configure, build, modify, run (with an explicit ### isolation sub-anchor covering cgroup-v2 / namespaces / numactl per-tenant primitives), test, debug, bluefield-lifecycle (the BFB-install → RShim/TMFIFO → post-BFB-recovery operational sequencing ladder, with the six-state bluefield-state-classifier sub-anchor), the Command appendix (documented commands the agent may quote, each cross-linked to its public-doc source — no invented commands), and the Deferred task verbs block routing container-path / cluster / library-API / env-prep / hardware-state-change / cross-library questions out to their owning skills. (The change-application discipline for any mutating burn invoked from ## bluefield-lifecycle is still meta-policy owned by doca-hardware-safety, loaded alongside.)

The skill assumes a host or BlueField target where:

  • DOCA is already installed and healthy (per doca-setup ## test),
  • the user has a DOCA-linked application binary they built (per doca-programming-guide ## build),
  • the user has the host-OS permissions to enumerate devices, reserve hugepages, write systemd units (if they choose that launch mode), and bind processes to NUMA nodes.

It does not cover installing DOCA — that path goes through doca-setup — and it does not cover building the binary — that path goes through doca-programming-guide.

Loading order

  1. Read this SKILL.md first to confirm the user's question is in scope (bare-metal launch of a DOCA-linked binary on host x86 or BlueField Arm; NOT the container path, NOT a full cluster, NOT a library-API question).
  2. For the runtime contract (two host modes, three launch modes, hardware-binding surface, per-tenant isolation, version overlay, seven-layer error taxonomy, observability surface, bare-metal safety overlay), see CAPABILITIES.md.
  3. For step-by-step workflows — configure, build (routing stub), modify (routing stub), run (with ### isolation sub-anchor), test, debug, bluefield-lifecycle (BFB install + RShim/TMFIFO + post-BFB recovery + the six-state bluefield-state-classifier), plus the Command appendix and the Deferred task verbs block — see TASKS.md.

Example questions this skill answers well

See references/details.md.

What this skill deliberately does not ship

See references/details.md.

See references/details.md.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/doca-bare-metal-deployment of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • TASKS.md
  • evals/evals.json
  • references/details.md
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit dfdd080

Compare with similar skills

Doca Bare Metal Deployment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Bare Metal Deployment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Bare Metal Deployment this skillNVIDIA/skills3.5k—~2.9kAutomated safety check: PassApache-2.0
Openbkn Deployopenbkn-ai/bkn-foundry645—~1.9kAutomated safety check: NotesCustom licence
Enterprise Agent Opsaffaan-m/ECC276k4 repos~384Automated safety check: PassMIT
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Spa Create Configsplunk/splunk-platform-automator138—~3.5kAutomated safety check: PassProprietary
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only

Similar skills

  • Openbkn Deploy

    openbkn-ai/bkn-foundry

    Deploy or upgrade OpenBKN on a customer-authorized Linux server through the repository's deploy scripts, with preflight checks, explicit confirmation, secret handling, and post-deployment…

    645 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Operational controls for long-lived or cloud-hosted agent systems — runtime lifecycle (start, pause, stop, restart), observability (logs, metrics, traces), least-privilege safety scopes and kill…

    276k GitHub starsUsed in 4 repos~384 tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Spa Create Config

    splunk/splunk-platform-automator

    A skill your agent uses when creating or updating splunkconfig.yml, designing Splunk Enterprise lab topology, multisite IDXC, SHC layout, architecture plan before config, or AWS Terraform block for…

    138 GitHub stars~3.5k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Setup Workshop

    brevdev/workshop-build-an-agent

    This skill should be used when the user wants to set up, install, deploy, bootstrap, or "spin up" the Build-an-Agent workshop (a.k.a.

    146 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from NVIDIA/skills

All 386 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated today
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Doca Bare Metal Deployment

What does Doca Bare Metal Deployment do?

A skill your agent uses for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a…. Doca Bare Metal Deployment is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a healthy run directly on hardware (host x86 + BlueField NIC over PCIe, or BlueField Arm bare-metal).

When should I use Doca Bare Metal Deployment?

Doca Bare Metal Deployment fits situations like: platform lifecycle on a BlueField — BFB install; post-BFB recovery — taking a DOCA-linked binary to a healthy run directly on hardware (host x86 + BlueField NIC over PCIe; blueField Arm bare-metal); even when user does not say bare-metal — implicit phrasings include binary exits 1 right after launch.

How do I install Doca Bare Metal Deployment in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-bare-metal-deployment -a claude-code`. Or copy the skill folder (skills/doca-bare-metal-deployment in NVIDIA/skills) into .claude/skills/doca-bare-metal-deployment in your project. Claude Code loads it when a task matches its description.

How do I install Doca Bare Metal Deployment in Codex?

Run `npx skills add NVIDIA/skills --skill doca-bare-metal-deployment -a codex`. Or copy the skill folder (skills/doca-bare-metal-deployment in NVIDIA/skills) into .agents/skills/doca-bare-metal-deployment in your project. Codex loads it when a task matches its description.

Can I use Doca Bare Metal Deployment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-bare-metal-deployment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-bare-metal-deployment, .gemini/skills/doca-bare-metal-deployment, .github/skills/doca-bare-metal-deployment and .opencode/skills/doca-bare-metal-deployment in your project.

What does Doca Bare Metal Deployment need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Bare Metal Deployment is instructions for the agent only. Compatibility (from SKILL.md): No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within this skill require a live DOCA install at /opt/mellanox/doca on a host or BlueField with a built DOCA-linked binary. .

Does Doca Bare Metal Deployment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Bare Metal Deployment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Bare Metal Deployment use?

Doca Bare Metal Deployment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Bare Metal Deployment use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Doca Bare Metal Deployment?

Skills that share tags, products or a category with Doca Bare Metal Deployment: Openbkn Deploy (openbkn-ai/bkn-foundry, 645 stars), Enterprise Agent Ops (affaan-m/ECC, 276k stars), Openclaw Live Updater (openclaw/openclaw, 392k stars) and Spa Create Config (splunk/splunk-platform-automator, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Bare Metal Deployment?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,546 GitHub stars. The repository holds 386 skills in this directory. The repository was last updated on October 9, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.