Agent skill

CI CD Patterns

by softspark in softspark/ai-toolkit

CI/CD: GitHub Actions, GitLab CI, Jenkins, caching, blue-green, canary.

Apache-2.0Auto-check passedDevOps & Cloud

Install CI CD Patterns

skills CLI
$ npx skills add softspark/ai-toolkit --skill ci-cd-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit ci-cd-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/ci-cd-patterns .claude/skills/ci-cd-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci-cd-patterns
GitHub stars
179
Token cost
~2.3k tokens
SKILL.md length
513 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

CI/CD: GitHub Actions, GitLab CI, Jenkins, caching, blue-green, canary.

  • Tasks that involve CI/CD
  • SKILL.md covers GitHub Actions, GitLab CI, Docker Multi-stage Builds and Caching Strategies, plus 8 more sections
  • Calls git; needs API_KEY and GITHUB_TOKEN
  • Tasks that involve Deployment

What it does

CI CD Patterns is an agent skill from softspark/ai-toolkit. CI/CD: GitHub Actions, GitLab CI, Jenkins, caching, blue-green, canary. Triggers: CI, CD, pipeline, GitHub Actions, workflow YAML, release, canary, rollout.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Deployment. It works with GitHub Actions, GitLab, Jenkins and Docker. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CI/CD
  • Tasks that involve Deployment

Example prompts

  • “/ci-cd-patterns”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in GITHUB_TOKEN
  • A credential in API_KEY
  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI CD Patterns loads about 2.3k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 513 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 513 words, ~2,301 tokens.

Download SKILL.mdSave it as .claude/skills/ci-cd-patterns/SKILL.md (or your agent's skills folder).
name
ci-cd-patterns
description
CI/CD: GitHub Actions, GitLab CI, Jenkins, caching, blue-green, canary. Triggers: CI, CD, pipeline, GitHub Actions, workflow YAML, release, canary, rollout.
allowed-tools
Read
effort
medium
user-invocable
false

CI/CD Patterns

GitHub Actions

Standard Pipeline
yaml
name: CI
on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

jobs:
  lint:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-node@v6
        with:
          node-version: 20
          cache: "npm"
      - run: npm ci
      - run: npm run lint
      - run: npm run typecheck

  test:
    runs-on: ubuntu-latest
    needs: lint
    strategy:
      matrix:
        node-version: [18, 20, 22]
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-node@v6
        with:
          node-version: ${{ matrix.node-version }}
          cache: "npm"
      - run: npm ci
      - run: npm test -- --coverage
      - uses: actions/upload-artifact@v4
        with:
          name: coverage-${{ matrix.node-version }}
          path: coverage/

  build:
    runs-on: ubuntu-latest
    needs: test
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-node@v6
        with:
          node-version: 20
          cache: "npm"
      - run: npm ci
      - run: npm run build
Python CI
yaml
name: Python CI
on: [push, pull_request]

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-python@v5
        with:
          python-version: "3.12"
          cache: "pip"
      - run: pip install -e ".[dev]"
      - run: ruff check .
      - run: mypy --strict src/
      - run: pytest --cov=src --cov-report=xml
Docker Build & Push
yaml
  build-docker:
    runs-on: ubuntu-latest
    needs: test
    steps:
      - uses: actions/checkout@v6
      - uses: docker/setup-buildx-action@v3
      - uses: docker/login-action@v3
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}
      - uses: docker/build-push-action@v5
        with:
          context: .
          push: ${{ github.ref == 'refs/heads/main' }}
          tags: ghcr.io/${{ github.repository }}:${{ github.sha }}
          cache-from: type=gha
          cache-to: type=gha,mode=max

GitLab CI

yaml
stages:
  - lint
  - test
  - build
  - deploy

lint:
  stage: lint
  image: node:20
  cache:
    key: $CI_COMMIT_REF_SLUG
    paths: [node_modules/]
  script:
    - npm ci
    - npm run lint

test:
  stage: test
  image: node:20
  services:
    - postgres:16
  variables:
    DATABASE_URL: "postgresql://postgres:postgres@postgres/test"
  script:
    - npm ci
    - npm test

build:
  stage: build
  image: docker:24
  services:
    - docker:24-dind
  script:
    - docker build -t $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA .
    - docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
  only:
    - main

Docker Multi-stage Builds

Node.js
dockerfile
# Stage 1: Dependencies
FROM node:20-alpine AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci --production

# Stage 2: Build
FROM node:20-alpine AS build
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci
COPY . .
RUN npm run build

# Stage 3: Production
FROM node:20-alpine AS production
WORKDIR /app
ENV NODE_ENV=production
COPY --from=deps /app/node_modules ./node_modules
COPY --from=build /app/dist ./dist
USER node
EXPOSE 3000
CMD ["node", "dist/index.js"]
Python
dockerfile
FROM python:3.12-slim AS builder
WORKDIR /app
COPY pyproject.toml .
RUN pip install --no-cache-dir --target=/deps .

FROM python:3.12-slim
WORKDIR /app
COPY --from=builder /deps /usr/local/lib/python3.12/site-packages
COPY src/ ./src/
USER nobody
CMD ["python", "-m", "src.main"]

Caching Strategies

npm/pnpm
yaml
- uses: actions/cache@v4
  with:
    path: ~/.npm
    key: ${{ runner.os }}-npm-${{ hashFiles('**/package-lock.json') }}
    restore-keys: ${{ runner.os }}-npm-
pip
yaml
- uses: actions/cache@v4
  with:
    path: ~/.cache/pip
    key: ${{ runner.os }}-pip-${{ hashFiles('**/pyproject.toml') }}
Docker Layer Caching
yaml
- uses: docker/build-push-action@v5
  with:
    cache-from: type=gha
    cache-to: type=gha,mode=max

Kubernetes Deployment

Rolling Update
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: api
spec:
  replicas: 3
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxSurge: 1
      maxUnavailable: 0
  template:
    spec:
      containers:
        - name: api
          image: ghcr.io/org/api:latest
          readinessProbe:
            httpGet:
              path: /ready
              port: 3000
            initialDelaySeconds: 5
          livenessProbe:
            httpGet:
              path: /live
              port: 3000
            initialDelaySeconds: 10

Secret Management

yaml
# GitHub Actions - use secrets
env:
  DATABASE_URL: ${{ secrets.DATABASE_URL }}
  API_KEY: ${{ secrets.API_KEY }}

# Never hardcode secrets in pipelines
# Use OIDC for cloud provider auth (no long-lived credentials)
- uses: aws-actions/configure-aws-credentials@v4
  with:
    role-to-assume: arn:aws:iam::123456789:role/deploy
    aws-region: us-east-1

Release Automation

Semantic Release
json
{
  "branches": ["main"],
  "plugins": [
    "@semantic-release/commit-analyzer",
    "@semantic-release/release-notes-generator",
    "@semantic-release/changelog",
    "@semantic-release/npm",
    "@semantic-release/github",
    "@semantic-release/git"
  ]
}
Conventional Commits for Auto-versioning
PrefixVersion BumpExample
fix:Patch (0.0.x)fix: resolve null pointer in auth
feat:Minor (0.x.0)feat: add user search endpoint
feat!: / BREAKING CHANGE:Major (x.0.0)feat!: change API response format

Common Rationalizations

ExcuseWhy It's Wrong
"CI is green, ship it"CI tests the happy path — verify edge cases, security, and performance separately
"Manual deploys give us more control"Manual deploys give you more human error — automate the repeatable parts
"We'll set up CI when the project is bigger"Small projects grow fast — CI debt compounds and retrofitting is painful
"Caching isn't worth the complexity"Uncached builds waste developer time daily — caching pays for itself in a week
"Feature flags are over-engineering"Feature flags decouple deploy from release — they're the cheapest safety net

Anti-Patterns

  • Secrets in pipeline logs or environment dumps
  • No caching (slow builds)
  • Running tests only on main (should run on PRs)
  • Manual deployments to production
  • No rollback strategy
  • Skipping linting/type-checking in CI

Rules

  • MUST include lint, test, and build stages in every pipeline — deploy-only pipelines defer failure to production
  • MUST cache dependencies by lockfile hash, not by branch name — branch keys grow unbounded and leak cache across unrelated work
  • NEVER commit secrets to the pipeline config — use the platform's secret store and reference by name
  • NEVER echo secrets to job logs; GitHub Actions masks known secrets only if they came from secrets.*, not from arbitrary env vars
  • CRITICAL: every deployment path has a defined rollback — "we'll figure it out" is not a plan and will cost hours during an incident
  • MANDATORY: PR builds run the same checks as main builds; drift between the two hides failures until merge
Show full SKILL.md (202 more words)Show less

Gotchas

  • GitHub Actions masks secret values sourced from ${{ secrets.X }} only. Secrets routed through env: and then transformed (base64, JSON) lose the mask and appear in logs verbatim.
  • Workflows triggered by pull_request from forks run without repository secrets by default (security). Jobs that need secrets either gate on github.event.pull_request.head.repo.full_name == github.repository or use pull_request_target with explicit code-review — the latter is easy to get wrong and allow token theft.
  • actions/cache restore is best-effort — a cache miss is silent. Jobs that rely on the cache (e.g., skipping tests when nothing changed) must verify cache hits explicitly via the cache-hit output.
  • GitLab CI's rules: and only:/except: are mutually exclusive at the job level. Mixing parses only at pipeline run, not at git push.
  • Semantic-release assumes a linear history. Merge commits on main confuse the commit parser and produce no release — stick to squash merges if you rely on it.

When NOT to Load

  • For generating a pipeline file for the current project — use /ci (this skill is knowledge, not code)
  • For one-off deployment commands — use /deploy
  • For language-specific build toolchain nuances — pair with /typescript-patterns, /python rules, etc.
  • For observability or alerting around deploys — use /observability-patterns
  • For security scanning (SAST, SCA) steps in pipelines — use /security-patterns and /cve-scan

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/ci-cd-patterns of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

CI CD Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI CD Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI CD Patterns this skillsoftspark/ai-toolkit179—~2.3kAutomated safety check: PassApache-2.0
CI CDEliasOulkadi/shokunin114—~3.4kAutomated safety check: NotesMIT
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Playwright CIzebbern/claude-code-guide4.6k2 repos~675Automated safety check: PassMIT
Infrastructure Devops Devops Engineerchendongqi/OPB-Skills125—~1.4kAutomated safety check: PassNone
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Playwright CI

    zebbern/claude-code-guide

    Production-ready CI/CD configurations for Playwright — GitHub Actions, GitLab CI, CircleCI, Azure DevOps, Jenkins, Docker, parallel sharding, reporting, code coverage, and global setup/teardown.

    4.6k GitHub starsUsed in 2 repos~675 tokens
    DevOps & CloudAuto-check passed
  • DevOps助手 - 专业的DevOps实践与自动化专家。适用场景: (1) CI/CD流水线设计与实现 (2) 部署策略与发布管理 (3) 基础设施即代码(IaC) (4) 容器化与Kubernetes部署 (5) 监控告警与可观测性 (6) DevOps工具链选型 (7) DevOps文化与实践推广 触发关键词:DevOps、CI/CD、持续集成、持续部署、Jenkins、GitLab…

    125 GitHub stars~1.4k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    DevOps & CloudAuto-check: notes

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Categories

Questions about CI CD Patterns

What does CI CD Patterns do?

CI/CD: GitHub Actions, GitLab CI, Jenkins, caching, blue-green, canary. CI CD Patterns is an agent skill from softspark/ai-toolkit. CI/CD: GitHub Actions, GitLab CI, Jenkins, caching, blue-green, canary.

When should I use CI CD Patterns?

CI CD Patterns fits situations like: tasks that involve CI/CD; tasks that involve Deployment.

How do I install CI CD Patterns in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill ci-cd-patterns -a claude-code`. Or copy the skill folder (app/skills/ci-cd-patterns in softspark/ai-toolkit) into .claude/skills/ci-cd-patterns in your project. Claude Code loads it when a task matches its description.

How do I install CI CD Patterns in Codex?

Run `npx skills add softspark/ai-toolkit --skill ci-cd-patterns -a codex`. Or copy the skill folder (app/skills/ci-cd-patterns in softspark/ai-toolkit) into .agents/skills/ci-cd-patterns in your project. Codex loads it when a task matches its description.

Can I use CI CD Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill ci-cd-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-cd-patterns, .gemini/skills/ci-cd-patterns, .github/skills/ci-cd-patterns and .opencode/skills/ci-cd-patterns in your project.

What does CI CD Patterns need to run?

Going by SKILL.md and its folder, CI CD Patterns needs the command-line tools its instructions call (git) and credentials named API_KEY and GITHUB_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in GITHUB_TOKEN; A credential in API_KEY. Its frontmatter pre-approves these tools: Read.

Does CI CD Patterns access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI CD Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI CD Patterns use?

CI CD Patterns is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI CD Patterns use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CI CD Patterns?

Skills that share tags, products or a category with CI CD Patterns: CI CD (EliasOulkadi/shokunin, 114 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars), Playwright CI (zebbern/claude-code-guide, 4.6k stars) and Infrastructure Devops Devops Engineer (chendongqi/OPB-Skills, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI CD Patterns?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.