Official agent skill

Doca Container Deployment

by NVIDIA in NVIDIA/skills

A skill your agent uses when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Doca Container Deployment

skills CLI
$ npx skills add NVIDIA/skills --skill doca-container-deployment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-container-deployment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-container-deployment .claude/skills/doca-container-deployment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-container-deployment
GitHub stars
3.5k
Token cost
~2.5k tokens
SKILL.md length
1,155 words
Files
8 (incl. references)
Skills in repo
380
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod…

  • Works in 3 steps: Read this SKILL.md first to confirm the… → **For the kubelet-standalone-mode… → **For step-by-step workflows —…
  • The user is hands-on deploying an in-bundle DOCA service container (Argus
  • SKILL.md covers Audience, When to load this skill, What this skill provides and Loading order, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Container Deployment is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod manifests directory, YAML pod-spec drop, kubelet status / ENTRYPOINT logs / per-service liveness, smoke-before-bulk, and the layered error taxonomy (pod-spec, scheduling, image pull, runtime, mount, network, version, host). Trigger even when the user does not say "container deployment" — typical implicit phrasings include "how do I…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `TASKS.md`). Compatibility notes: No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA…

It sits in DevOps & Cloud, covering Deployment, Messaging and chat bots and Container orchestration. It works with NVIDIA AI Platform and Kubernetes. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • The user is hands-on deploying an in-bundle DOCA service container (Argus
  • UROM service) on a BlueField — kubelet standalone watching a static-pod manifests directory
  • YAML pod-spec drop
  • Kubelet status / ENTRYPOINT logs / per-service liveness

Example prompts

  • “container deployment”
  • “how do I run my built service on the BlueField?”
  • “where do I drop the pod-spec YAML?”
  • “/doca-container-deployment”

Requirements

  • Compatibility (from SKILL.md): No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA install at /opt/mellanox/doca.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read this SKILL.md first to confirm the user's question is in
  2. **For the kubelet-standalone-mode runtime shape, the static-pod
  3. **For step-by-step workflows — configure, build, modify, run,

What it can do on your machine

Read from SKILL.md and the folder at commit 0e0d506. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA install at /opt/mellanox/doca.

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Container Deployment loads about 2.5k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 253 tokens; SKILL.md has 1,155 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~253
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit 0e0d506, republished under its Apache-2.0 licence (© NVIDIA). 1,155 words, ~2,513 tokens.

Download SKILL.mdSave it as .claude/skills/doca-container-deployment/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-container-deployment
description
Use this skill when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod manifests directory, YAML pod-spec drop, kubelet status / ENTRYPOINT logs / per-service liveness, smoke-before-bulk, and the layered error taxonomy (pod-spec, scheduling, image pull, runtime, mount, network, version, host). Trigger even when the user does not say "container deployment" — typical implicit phrasings include "how do I run my built service on the BlueField?", "where do I drop the pod-spec YAML?", "pod stuck in Pending / ImagePullBackOff / CrashLoopBackOff", "container Running but service isn't ready", "pod restart-loops after edit", or "DMS and Firefly together". Refuse and route elsewhere for per-service config schemas, DOCA install, library-API questions, external NVIDIA services (BlueMan, HBN, SNAP, Virtio-net), or full Kubernetes-cluster ops — those belong to other skills.
compatibility
No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA install at /opt/mellanox/doca.
license
Apache-2.0
metadata.kind
library

DOCA container deployment

Where to start: This skill is for operating the cross-cutting DOCA container-deployment runtime — the shared pattern every DOCA service on the BlueField uses to come up (kubelet standalone agent on the BlueField Arm watching a static-pod manifests directory; the operator drops a YAML pod spec into that directory; kubelet schedules the pod and runs the container).

If the developer has NOT yet decided container vs. bare-metal ("I just got a BlueField, what now?", "my code is built, how do I run it?", "how do I deploy this?"), route them BACK to doca-setup ## recognize first. That is the front-door routing decision. The wrong failure mode is to silently push every developer onto the container path because the agent loaded this skill first. ## recognize detects the system shape, asks the minimum residual question, and lands the developer on either this skill (when the workload is a packaged DOCA service to drop on a BlueField) or the bare-metal-path sibling doca-bare-metal-deployment (when the workload is a DOCA-linked application binary the developer launches directly).

If the developer is already on the container path, open TASKS.md and start at ## configure. If the question is what shape of runtime is this and what does the deployment contract look like, start at CAPABILITIES.md. For per-service overlays, follow the per-service skill under skills/services/ that layers on top of this one — the supported overlays are Argus, DMS, Firefly, and UROM service. Flow-Inspector and OS-Inspector are policy-excluded from this public bundle; route them through doca-public-knowledge-map instead of applying this runtime overlay. Externally-productized NVIDIA services (BlueMan, HBN, SNAP, Virtio-net, DOCA Telemetry Service as productized, …) are also out of scope and route through that map. If DOCA is not installed on the BlueField target yet, route to doca-setup first.

Audience

This skill serves external operators and platform teams who deploy DOCA service containers on BlueField — i.e., people who have a BlueField with DOCA installed on the Arm side, a container runtime plus the kubelet standalone agent already present per the BlueField OS image, and the host-OS permissions the public DOCA Container Deployment Guide names for the chosen service. The skill is the shared deployment runtime; each per-service skill in the bundle (see the list in ## Related skills) supplies the service-specific config schema, paired-workload contract, and "healthy" definition.

It is not for NVIDIA developers contributing to the BlueField container runtime or to kubelet itself, and it is not a generic Kubernetes tutorial. Kubelet runs on the BlueField in standalone mode here — no full Kubernetes control plane, no kubectl against a cluster API server — and the substantive answer to most container-deployment questions on the BlueField is the public DOCA Container Deployment Guide. This skill teaches the agent which guide to quote, in what order to walk it, and how to map a symptom to a layer; it does NOT re-invent kubelet flags, pod-spec field names, or static-pod path strings. The shared deployment runtime described here is the cross-cutting layer; the per-service skill (doca-argus, doca-dms, doca-firefly, doca-urom-svc) supplies the per-service config schema, paired-workload contract, and "healthy" definition.

When to load this skill

Load this skill when the user is doing hands-on container deployment of any DOCA service on a BlueField target, or asking a cross-service deployment question that is not specific to one service's config schema. Concretely:

  • Dropping a YAML pod spec into the documented static-pod manifests directory on the BlueField Arm so kubelet standalone schedules the pod and runs the DOCA service container.
  • Inspecting pod status, container logs, and the documented liveness signal for any supported in-bundle DOCA service container — Argus, DMS, Firefly, or UROM service — so the agent answers "did the container come up, and is the service inside actually ready" the same way for every service.
  • Walking the smoke-before-bulk loop (pod reaches Running; ENTRYPOINT logs are clean; service answers a trivial liveness probe) BEFORE the BlueField is put under workload.
  • Diagnosing a deployment that is misbehaving — pod-spec YAML is in the directory but the pod never schedules; pod schedules but image-pull fails; image pulls but container ENTRYPOINT immediately exits; container runs but the service inside never answers; container is in a restart loop after a config edit; a volume mount the pod spec names is missing on the host; a network policy or host-firewall rule is blocking the service.
  • Cross-service questions: "can I have DMS and Firefly on the same BlueField", "how do I list every DOCA service pod that is currently running", "what is the documented stop / restart semantics if I edit a pod-spec file in place".

Do not load this skill for per-service config schema questions (those belong to the matching per-service skill); for installing DOCA itself or preparing the BlueField env (use doca-setup); for library-API questions (use the matching libs/<library> skill); or for general Kubernetes-cluster operations (this skill covers kubelet standalone mode on the BlueField, not a full Kubernetes control plane).

Show full SKILL.md (351 more words)Show less

What this skill provides

This is a thin loader. Substantive material lives in two companion files:

  • CAPABILITIES.md — the cross-cutting DOCA container-deployment runtime contract on the BlueField (kubelet standalone agent on BlueField Arm watching a documented static-pod manifests directory; YAML pod-spec drop is the unit of operator input; the same pattern applies across every DOCA service), the BlueField preconditions (DOCA install, container runtime, BFB version, per-service firmware slot when the service emulates a device, image-pull reachability to NGC, host-OS permissions), the observability surface (kubelet status, container logs, service- side liveness signal — three layers, each with its own owner), the cross-cutting error taxonomy (pod-spec syntax → pod scheduling → image pull → runtime → volume mount → network policy → version → cross-cutting host) covering exactly eight layers, and the safety policy (smoke before bulk; failed pod is high-stakes — clear the root cause before letting kubelet restart-loop the pod; do NOT invent pod-spec field names / kubelet flags / image tags from memory).
  • TASKS.md — step-by-step workflows for the in-scope deployment verbs: configure, build, modify, run, test, debug, plus a Deferred task verbs block routing per-service config questions, host-firmware-slot work, paired-workload work, and full-Kubernetes-cluster work out to their owning skills.

The skill assumes a BlueField target where DOCA is already installed on the Arm side, the BlueField OS image ships kubelet standalone + the container runtime per the public DOCA Container Deployment Guide, and the operator has the host-OS permissions that guide names. It does not cover installing DOCA — that path goes through doca-setup — and it does not re-document the per-service config schema, which is the canonical concern of each DOCA service's public guide reached through doca-public-knowledge-map.

Loading order

  1. Read this SKILL.md first to confirm the user's question is in scope (cross-cutting deployment runtime, NOT a per-service config-schema question).
  2. For the kubelet-standalone-mode runtime shape, the static-pod manifests directory rule, the host-OS / BFB / firmware-slot / image-pull preconditions, the eight-layer error taxonomy, the observability surface, and the safety / smoke-before-bulk policy, see CAPABILITIES.md.
  3. For step-by-step workflows — configure, build, modify, run, test, debug — see TASKS.md.

Example questions this skill answers well

See references/details.md.

What this skill deliberately does not ship

See references/details.md.

See references/details.md.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/doca-container-deployment of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • TASKS.md
  • evals/evals.json
  • references/details.md
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit 0e0d506

Compare with similar skills

Doca Container Deployment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Container Deployment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Container Deployment this skillNVIDIA/skills3.5k—~2.5kAutomated safety check: PassApache-2.0
Deploy Controllerai-runway/airunway101—~927Automated safety check: PassApache-2.0
Model Serving Kubernetessickn33/agentic-awesome-skills47k1 repos~2.3kAutomated safety check: PassMIT
Model Serving Kubernetesmajiayu000/claude-skill-registry6661 repos~2.1kAutomated safety check: PassMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Openbkn Deployopenbkn-ai/bkn-foundry629—~1.9kAutomated safety check: NotesCustom licence

Similar skills

  • Deploy Controller

    ai-runway/airunway

    Interactively build, push or load, and deploy an airunway component (controller or any provider) to the cluster

    101 GitHub stars~927 tokensUpdated 10 days ago
    DevOps & CloudAuto-check passed
  • Model Serving Kubernetes

    sickn33/agentic-awesome-skills

    Deploy ML models on Kubernetes with KServe (formerly KFServing) and NVIDIA Triton Inference Server.

    47k GitHub starsUsed in 1 repo~2.3k tokens
    DevOps & CloudAuto-check passed
  • Model Serving Kubernetes

    majiayu000/claude-skill-registry

    Deploy ML models on Kubernetes with KServe (formerly KFServing) and NVIDIA Triton Inference Server.

    666 GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Openbkn Deploy

    openbkn-ai/bkn-foundry

    Deploy or upgrade OpenBKN on a customer-authorized Linux server through the repository's deploy scripts, with preflight checks, explicit confirmation, secret handling, and post-deployment…

    629 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 24 days ago
    DevOps & CloudAuto-check passed

More from NVIDIA/skills

All 380 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated today
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated today
    Auto-check: notes

Categories

Questions about Doca Container Deployment

What does Doca Container Deployment do?

A skill your agent uses when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod…. Doca Container Deployment is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod manifests directory, YAML pod-spec drop, kubelet status / ENTRYPOINT logs / per-service liveness, smoke-before-bulk, and the layered error taxonomy (pod-spec, scheduling, image pull, runtime, mount, network, version, host).

When should I use Doca Container Deployment?

Doca Container Deployment fits situations like: the user is hands-on deploying an in-bundle DOCA service container (Argus; UROM service) on a BlueField — kubelet standalone watching a static-pod manifests directory; YAML pod-spec drop; kubelet status / ENTRYPOINT logs / per-service liveness.

How do I install Doca Container Deployment in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-container-deployment -a claude-code`. Or copy the skill folder (skills/doca-container-deployment in NVIDIA/skills) into .claude/skills/doca-container-deployment in your project. Claude Code loads it when a task matches its description.

How do I install Doca Container Deployment in Codex?

Run `npx skills add NVIDIA/skills --skill doca-container-deployment -a codex`. Or copy the skill folder (skills/doca-container-deployment in NVIDIA/skills) into .agents/skills/doca-container-deployment in your project. Codex loads it when a task matches its description.

Can I use Doca Container Deployment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-container-deployment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-container-deployment, .gemini/skills/doca-container-deployment, .github/skills/doca-container-deployment and .opencode/skills/doca-container-deployment in your project.

What does Doca Container Deployment need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Container Deployment is instructions for the agent only. Compatibility (from SKILL.md): No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA install at /opt/mellanox/doca. .

Does Doca Container Deployment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Container Deployment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Container Deployment use?

Doca Container Deployment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Container Deployment use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Doca Container Deployment?

Skills that share tags, products or a category with Doca Container Deployment: Deploy Controller (ai-runway/airunway, 101 stars), Model Serving Kubernetes (sickn33/agentic-awesome-skills, 47k stars), Model Serving Kubernetes (majiayu000/claude-skill-registry, 666 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Container Deployment?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,534 GitHub stars. The repository holds 380 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.