Agent skill

Supercheck Infrastructure Deployment

by supercheck-io in supercheck-io/supercheck

Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

AGPL-3.0Auto-check: notesDevOps & Cloud

Install Supercheck Infrastructure Deployment

skills CLI
$ npx skills add supercheck-io/supercheck --skill supercheck-infrastructure-deployment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install supercheck-io/supercheck supercheck-infrastructure-deployment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/supercheck-io/supercheck.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/infrastructure-deployment .claude/skills/supercheck-infrastructure-deployment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supercheck-infrastructure-deployment
GitHub stars
215
Token cost
~1.4k tokens
SKILL.md length
604 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

  • Works in 6 steps: Use an explicit kubeconfig/context for… → Render/validate manifests or Compose… → Deploy an immutable exact SHA/version… → …
  • Tasks that involve Backup and disaster recovery
  • SKILL.md covers Deployment surfaces, Docker Compose and self-hosting, Kubernetes and gVisor and OpenTofu and Hetzner, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Supercheck Infrastructure Deployment is an agent skill from supercheck-io/supercheck. Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery, Deployment and Infrastructure as code. It works with Docker, Kubernetes, Terraform and Redis. The repository describes itself as: Open-Source Testing, Monitoring, and AI SRE — as Code. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Backup and disaster recovery
  • Tasks that involve Deployment
  • Tasks that involve Infrastructure as code

Example prompts

  • “/supercheck-infrastructure-deployment”

Requirements

  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Use an explicit kubeconfig/context for every production command.
  2. Render/validate manifests or Compose config and review destructive/resource changes.
  3. Deploy an immutable exact SHA/version through a bounded rollout.
  4. Inspect pods, events, logs, probes, revision labels, migrations, KEDA/autoscaler/control-plane health, and pressure.
  5. Run disposable user and execution acceptance, then remove fixtures.
  6. Keep DNS/TLS, provider accounts, credentials, spending, destructive changes, and final production approval as explicit gates.

What it can do on your machine

Read from SKILL.md and the folder at commit 155da39. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are mermaid).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supercheck Infrastructure Deployment loads about 1.4k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 604 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:30
    tion/storage/Redis secrets and keep all `.env` files untracked.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from supercheck-io/supercheck at commit 155da39, republished under its AGPL-3.0 licence (© supercheck-io). 604 words, ~1,413 tokens.

Download SKILL.mdSave it as .claude/skills/supercheck-infrastructure-deployment/SKILL.md (or your agent's skills folder).
name
supercheck-infrastructure-deployment
description
Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

Supercheck infrastructure and deployment

mermaid
flowchart TD
  RELEASE[Immutable app/worker release] --> CLUSTER[K3s cluster]
  TOFU[OpenTofu infrastructure] --> CLUSTER
  SECRETS[Secret manager] --> CLUSTER
  CLUSTER --> APP[App replicas and schedulers]
  CLUSTER --> WORK[Regional worker pools]
  WORK --> JOB[gVisor execution Jobs]
  APP --> EXT[(PostgreSQL, Redis, object storage)]
  WORK --> EXT
  KEDA[KEDA and cluster autoscaler] --> WORK

Deployment surfaces

  • deploy/docker contains public self-hosted Compose assets. Inspect current files to choose bundled dependencies, secure/TLS, external services, remote worker, or local-source behavior.
  • Production K3s/OpenTofu assets may be maintained outside this repository, but contributors must preserve the contracts described here when changing app/worker/deploy code.
  • Local macOS Kubernetes may use OrbStack. Local exceptions must not weaken production defaults.

Docker Compose and self-hosting

  • App, worker, PostgreSQL, Redis, MinIO/object storage, proxy/TLS, and K3s dependencies start in a health-aware order.
  • Generate unique auth/encryption/storage/Redis secrets and keep all .env files untracked.
  • Browser URL, API URL, OAuth callbacks, cookie domain, trusted proxy, status-page domain, and TLS routing must agree.
  • Bind stateful services privately; do not publish PostgreSQL, Redis, or object storage to the internet.
  • Remote workers use authenticated network paths, a unique supported location, and an app/worker-compatible release.
  • Capacity equals usable worker execution concurrency, not merely a replica count. Verify location queue routing and resource availability.

Kubernetes and gVisor

  • Production execution fails closed on the configured gVisor RuntimeClass.
  • Execution Jobs run in the dedicated namespace with zero-permission service account, non-root/read-only containers, dropped capabilities, no privilege escalation, resource requests/limits, deadlines, TTL cleanup, and bounded writable storage.
  • Namespace default-deny NetworkPolicy, DNS allowance, LimitRange, and ResourceQuota stay aligned with worker-generated Job resources.
  • App/worker workloads use probes, disruption/rollout settings, anti-affinity/topology behavior, and service accounts appropriate to their role.
  • Node-local DNS configuration must match cluster DNS IP, host paths, interface/listen behavior, and upstream configuration before rollout.

OpenTofu and Hetzner

  • Infrastructure is declarative; review plan output and exact targets before apply.
  • Keep control-plane/stateful nodes protected. Replaceable workers may scale down according to current availability/cost policy.
  • Never commit cloud tokens, kubeconfigs, generated secrets, private keys, state, or live inventory.
  • OpenTofu state is critical persistent data. Store it remotely with locking/versioning and never apply artifact lifecycle deletion to it.
  • Firewall and SSH/admin access use least privilege and restricted source networks. Prefer non-root administrative users with audited sudo.

External services and secrets

  • Supported deployments require PostgreSQL, BullMQ-compatible Redis, S3-compatible object storage, and optionally SMTP, OAuth, CAPTCHA, AI, billing, support, and observability providers.
  • Provider names, pricing, limits, product IDs, regions, and setup UI are drift-prone; verify live before operational decisions.
  • Redis uses maxmemory-policy noeviction and sufficient connection capacity.
  • PostgreSQL connection pooling/SSL must match the provider endpoint and migration strategy.
  • Secrets are injected through the approved secret manager/CI mechanism, rotated by environment, and unavailable to untrusted CI jobs.
Show full SKILL.md (209 more words)Show less

Autoscaling

  • KEDA/worker scaling follows queue pressure and capacity policy; cluster autoscaler node pools must permit the corresponding location labels/taints and scale bounds.
  • Preserve the current pre-launch baseline unless explicitly changed: one warm EU worker for scheduled monitor availability; US/APAC may scale to zero.
  • Scale-to-zero acceptance proves node bootstrap, CNI/DNS readiness, image pull, worker registration, execution, and cleanup—not only VM creation.
  • Validate app schedulers and queue capacity independently from node autoscaling.

Disaster recovery

  • Define and test backups for PostgreSQL, object storage, infrastructure state, cluster configuration, and required secrets.
  • RPO/RTO claims require measured restore evidence; do not promise timings from an untested workstation bootstrap.
  • Never run cluster reset on a healthy control plane or delete a stateful PVC/host before validating off-host restore material.
  • Restore into an isolated environment when practical; verify integrity, migration compatibility, auth, queues, storage, and a disposable execution.

Deployment verification

  1. Use an explicit kubeconfig/context for every production command.
  2. Render/validate manifests or Compose config and review destructive/resource changes.
  3. Deploy an immutable exact SHA/version through a bounded rollout.
  4. Inspect pods, events, logs, probes, revision labels, migrations, KEDA/autoscaler/control-plane health, and pressure.
  5. Run disposable user and execution acceptance, then remove fixtures.
  6. Keep DNS/TLS, provider accounts, credentials, spending, destructive changes, and final production approval as explicit gates.

© supercheck-io, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/infrastructure-deployment of supercheck-io/supercheck.

Open the folder on GitHubat commit 155da39

Compare with similar skills

Supercheck Infrastructure Deployment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supercheck Infrastructure Deployment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supercheck Infrastructure Deployment this skillsupercheck-io/supercheck215—~1.4kAutomated safety check: NotesAGPL-3.0
Devops Excellencemajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit290—~2.7kAutomated safety check: PassMIT
Discover Infrarand/cc-polymath181—~783Automated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    287 GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    290 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Discover Infra

    rand/cc-polymath

    Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC

    181 GitHub stars~783 tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Kubernetes

    EliasOulkadi/shokunin

    Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…

    114 GitHub stars~3.3k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes

More from supercheck-io/supercheck

All 12 skills in this repo
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Supercheck Architecture

    supercheck-io/supercheck

    Work on Supercheck system architecture, Next.js routes and actions, React data hooks, Drizzle schemas and migrations, app-worker boundaries, or cross-package contracts.

    215 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Supercheck Code Review

    supercheck-io/supercheck

    Review Supercheck staged, unstaged, commit, branch, or pull-request changes for correctness, regressions, security, tenancy, architecture, tests, docs, licensing, and commit/merge/release readiness.

    215 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Supercheck Data Storage

    supercheck-io/supercheck

    Work on Supercheck PostgreSQL data, S3 or MinIO artifacts, signed URLs and asset proxying, retention cleanup, dashboard/report queries, exports, or audit logging.

    215 GitHub stars~942 tokensUpdated today
    Auto-check passed
  • Supercheck Execution Engine

    supercheck-io/supercheck

    Work on Supercheck BullMQ queues, schedulers, capacity management, Playwright or k6 execution, monitors, dynamic locations, cancellation, Redis, Kubernetes Jobs, gVisor, or app-worker execution…

    215 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Supercheck Feature Implementation

    supercheck-io/supercheck

    Implement a new or changed Supercheck feature end to end across schema, auth/RBAC, services, routes/actions, UI, queues/workers, CLI/recorder, tests, docs, and deployment contracts.

    215 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Supercheck Infrastructure Deployment

What does Supercheck Infrastructure Deployment do?

Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment. Supercheck Infrastructure Deployment is an agent skill from supercheck-io/supercheck. Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

When should I use Supercheck Infrastructure Deployment?

Supercheck Infrastructure Deployment fits situations like: tasks that involve Backup and disaster recovery; tasks that involve Deployment; tasks that involve Infrastructure as code.

How do I install Supercheck Infrastructure Deployment in Claude Code?

Run `npx skills add supercheck-io/supercheck --skill supercheck-infrastructure-deployment -a claude-code`. Or copy the skill folder (.agents/skills/infrastructure-deployment in supercheck-io/supercheck) into .claude/skills/supercheck-infrastructure-deployment in your project. Claude Code loads it when a task matches its description.

How do I install Supercheck Infrastructure Deployment in Codex?

Run `npx skills add supercheck-io/supercheck --skill supercheck-infrastructure-deployment -a codex`. Or copy the skill folder (.agents/skills/infrastructure-deployment in supercheck-io/supercheck) into .agents/skills/supercheck-infrastructure-deployment in your project. Codex loads it when a task matches its description.

Can I use Supercheck Infrastructure Deployment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add supercheck-io/supercheck --skill supercheck-infrastructure-deployment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supercheck-infrastructure-deployment, .gemini/skills/supercheck-infrastructure-deployment, .github/skills/supercheck-infrastructure-deployment and .opencode/skills/supercheck-infrastructure-deployment in your project.

What does Supercheck Infrastructure Deployment need to run?

SKILL.md names no scripts, command-line tools or credentials: Supercheck Infrastructure Deployment is instructions for the agent only. Our summary lists: Docker.

Does Supercheck Infrastructure Deployment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Supercheck Infrastructure Deployment safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Supercheck Infrastructure Deployment use?

Supercheck Infrastructure Deployment is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supercheck Infrastructure Deployment use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supercheck Infrastructure Deployment?

Skills that share tags, products or a category with Supercheck Infrastructure Deployment: Devops Excellence (majiayu000/spellbook, 287 stars), Devops Deployment (yonatangross/orchestkit, 290 stars), Discover Infra (rand/cc-polymath, 181 stars) and Devops Engineer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supercheck Infrastructure Deployment?

supercheck-io (a GitHub organization) maintains it in supercheck-io/supercheck, which has 215 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.

Source: supercheck-io/supercheck on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.