Agent skill

Pluggedin Stack Ops

by VeriTeknik in VeriTeknik/pluggedin-app

A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…

MITAuto-check: notesDevOps & Cloud

Install Pluggedin Stack Ops

skills CLI
$ npx skills add VeriTeknik/pluggedin-app --skill pluggedin-stack-ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VeriTeknik/pluggedin-app pluggedin-stack-ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pluggedin-stack-ops .claude/skills/pluggedin-stack-ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pluggedin-stack-ops
GitHub stars
103
Token cost
~1.3k tokens
SKILL.md length
615 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…

  • Rolling back the containerised plugged.in production stack
  • SKILL.md covers Quick reference, Deploying is not just git pull, Verifying a change actually… and Rollback, plus 2 more sections
  • Calls docker, git and curl; reaches traefik.plugged.in and plugged.in
  • The site returns 404

What it does

Pluggedin Stack Ops is an agent skill from VeriTeknik/pluggedin-app. Use when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when changing infra/docker-compose.yml, infra/traefik/ or the app image.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering MCP servers, Containers and Git workflow. It works with Git, Docker and Model Context Protocol. The repository describes itself as: The Crossroads for AI Data Exchanges. A unified, self-hostable web interface for discovering, configuring, and managing Model Context Protocol (MCP) servers—bringing together AI… The licence is MIT.

When your agent uses it

  • Rolling back the containerised plugged.in production stack
  • The site returns 404
  • 5xx after a deploy
  • Changing infra/docker-compose.yml

Example prompts

  • “/pluggedin-stack-ops”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit a65f1ff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • git
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • traefik.plugged.in
    • plugged.in

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pluggedin Stack Ops loads about 1.3k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 615 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:70
    sudo systemctl enable --now nginx pluggedin

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VeriTeknik/pluggedin-app at commit a65f1ff, republished under its MIT licence (© VeriTeknik). 615 words, ~1,285 tokens.

Download SKILL.mdSave it as .claude/skills/pluggedin-stack-ops/SKILL.md (or your agent's skills folder).
name
pluggedin-stack-ops
description
Use when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when changing infra/docker-compose.yml, infra/traefik/ or the app image.

Operating the plugged.in production stack

plugged.in runs as a Docker Compose stack: Traefik on :80/:443, the Next.js app, Postgres 16 + pgvector, Redis, Ofelia (cron), and a docker-socket-proxy. The native nginx + systemd stack it replaced is stopped and disabled but still installed.

Entry point is always infra/scripts/deploy.sh. Running compose by hand skips secret decryption, so the secrets file and the staged Traefik config never appear.

Quick reference

TaskCommand
Deploy./infra/scripts/deploy.sh
Smoke test./infra/scripts/verify.sh (add --quick to skip the RAG canary)
Logsdocker compose -f infra/docker-compose.yml logs -f --tail=50 pluggedin-app traefik
Which routers existTraefik dashboard at https://traefik.plugged.in/api/http/routers (basic auth)

Health must report "status":"healthy" and "database":true. The endpoint never emits "ok" — asserting that is a bug that once made the smoke test unpassable.

Deploying is not just git pull

git pull alone can 404 the site.

infra/traefik/dynamic/ is bind-mounted straight from the git working tree, and Traefik hot-watches it. Any git operation that rewrites those files — pull, checkout, rebase — can be observed mid-write. Traefik then loads a file missing a middleware, every router referencing it errors, and the site returns 404 until the next reload. Observed for ~40s after a git checkout where the before and after content were identical: content equality is not write atomicity.

Until the dynamic config is staged outside the working tree, treat any git operation against this checkout as a change window: run it, then immediately check

bash
curl -s -o /dev/null -w '%{http_code}\n' https://plugged.in/
docker logs --since 2m traefik 2>&1 | grep -i 'does not exist'

middleware "X@file" does not exist is the signature. It self-heals on the next reload; touch infra/traefik/dynamic/middlewares.yml forces one.

Verifying a change actually reached production

Mounts and environment are fixed at create time, and docker compose up -d only recreates a container if its definition changed — rewriting a mounted file does not. Secrets now come from a mounted file loaded at process start, so a changed secret needs the container restarted, not merely the file rewritten. If a change must take effect, confirm the container was recreated:

bash
docker inspect pluggedin-app --format '{{.State.StartedAt}}'

Check from outside the host, not just via verify.sh, which only probes internally. A stack can be internally green and externally 404 — that is exactly what a broken Traefik provider looks like, because Traefik's own healthcheck stays green while it serves nothing.

Show full SKILL.md (256 more words)Show less

Rollback

The native units are disabled but present:

bash
sudo systemctl enable --now nginx pluggedin
docker compose -f infra/docker-compose.yml stop traefik
crontab /home/pluggedin/crontab.pre-ofelia.backup

This returns traffic to the external Postgres. Writes made against the containerised database after cutover are not replayed; the dumps in /var/backups/pluggedin/ are the reconciliation input, and they are encrypted with the rotated data key.

Traps that have already cost an outage

TrapDetail
Traefik ≤ v3.5Pins Docker API 1.24; Engine 29 rejects it. No label router is discovered, site 404s, healthcheck stays green. v3.7 is a floor, not a preference.
systempaths in composeTakes =, not :. The colon form fails the recreate, not the config parse — the old container keeps serving and the error is easy to miss.
MCP sandboxingNeeds CAP_SYS_ADMIN + apparmor:unconfined + seccomp:unconfined + systempaths=unconfined. Any missing one silently falls back to no isolation, because MCP_ISOLATION_FALLBACK=none. Verify with bwrap ... /usr/bin/env sh -c 'echo OK; echo $$' inside the container — pid=2 proves the namespace.
Image disk growthCI builds a ~4 GB image per push on this same host with no retention. Reclaim with docker image prune -af --filter until=90m.
Restoring a DB dumpDumps from the external PG are encrypted with the pre-rotation data key. Run infra/scripts/reencrypt-data-key.mjs --apply then --verify, or the app cannot read 5,305 values.

Common mistakes

MistakeResult
git pull without checking the site afterPossible silent 404 window
Trusting verify.sh aloneInternal-only; misses a broken public route
Assuming an edited mounted file took effectContainers keep old env until recreated
Running compose directly instead of deploy.shSecrets never decrypted; Traefik config never staged
Restoring a dump without re-encryptingEvery MCP config and OAuth token unreadable

© VeriTeknik, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/pluggedin-stack-ops of VeriTeknik/pluggedin-app.

Open the folder on GitHubat commit a65f1ff

Compare with similar skills

Pluggedin Stack Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pluggedin Stack Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pluggedin Stack Ops this skillVeriTeknik/pluggedin-app103—~1.3kAutomated safety check: NotesMIT
Create Connectorharness/harness-skills115—~2kAutomated safety check: PassApache-2.0
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT
Devsydevsy-org/devsy109—~1.7kAutomated safety check: PassMPL-2.0
Skillz Integrationgithub/gh-aw5.3k—~905Automated safety check: PassMIT

Similar skills

  • Create Connector

    harness/harness-skills

    Generate Harness Connector YAML for integrations and create/test via MCP.

    115 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    109 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Skillz Integration

    github/gh-aw

    Official

    Run and integrate Skillz MCP server with Docker for skill execution.

    5.3k GitHub stars~905 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ssh Skill

    badseal/ssh-skill

    A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…

    535 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from VeriTeknik/pluggedin-app

  • Sops Secrets

    VeriTeknik/pluggedin-app

    A skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…

    103 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Questions about Pluggedin Stack Ops

What does Pluggedin Stack Ops do?

A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…. Pluggedin Stack Ops is an agent skill from VeriTeknik/pluggedin-app.yml, infra/traefik/ or the app image.

When should I use Pluggedin Stack Ops?

Pluggedin Stack Ops fits situations like: rolling back the containerised plugged.in production stack; the site returns 404; 5xx after a deploy; changing infra/docker-compose.yml.

How do I install Pluggedin Stack Ops in Claude Code?

Run `npx skills add VeriTeknik/pluggedin-app --skill pluggedin-stack-ops -a claude-code`. Or copy the skill folder (.claude/skills/pluggedin-stack-ops in VeriTeknik/pluggedin-app) into .claude/skills/pluggedin-stack-ops in your project. Claude Code loads it when a task matches its description.

How do I install Pluggedin Stack Ops in Codex?

Run `npx skills add VeriTeknik/pluggedin-app --skill pluggedin-stack-ops -a codex`. Or copy the skill folder (.claude/skills/pluggedin-stack-ops in VeriTeknik/pluggedin-app) into .agents/skills/pluggedin-stack-ops in your project. Codex loads it when a task matches its description.

Can I use Pluggedin Stack Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeriTeknik/pluggedin-app --skill pluggedin-stack-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pluggedin-stack-ops, .gemini/skills/pluggedin-stack-ops, .github/skills/pluggedin-stack-ops and .opencode/skills/pluggedin-stack-ops in your project.

What does Pluggedin Stack Ops need to run?

Going by SKILL.md and its folder, Pluggedin Stack Ops needs the command-line tools its instructions call (docker, git and curl). Our summary lists: Docker.

Does Pluggedin Stack Ops access the network?

SKILL.md names 2 domains. In commands or code: traefik.plugged.in and plugged.in; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Pluggedin Stack Ops safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pluggedin Stack Ops use?

Pluggedin Stack Ops is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pluggedin Stack Ops use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pluggedin Stack Ops?

Skills that share tags, products or a category with Pluggedin Stack Ops: Create Connector (harness/harness-skills, 115 stars), Devcontainer Dev (stacklok/toolhive-studio, 170 stars), Unraid (dinglebear-ai/unraid, 135 stars) and Devsy (devsy-org/devsy, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pluggedin Stack Ops?

VeriTeknik (a GitHub organization) maintains it in VeriTeknik/pluggedin-app, which has 103 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.

Source: VeriTeknik/pluggedin-app on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.