DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
vincentchuwaichow Bundle Terraform Policy EvidenceUse this skill to turn a Terraform or OpenTofu change into an auditable control decision: which controls it touches, whether the enforcing policy blocks or merely warns, whether the policy evaluates the plan or only the source text, whether an exception is scoped and expiring, and what evidence artifact could be produced months later. Advisory only — it never grants an exception, signs an attestation, or runs a policy engine.
-
vincentchuwaichow Bundle Alibaba Devops Cicd OperatorBuild CI/CD pipelines with RDC (Research and Development Collaboration), Cloud Build, Flow pipeline automation, ACR (Container Registry) image lifecycle, and environment promotion strategies.
-
vincentchuwaichow Bundle Alibaba Ecs Compute OperatorOperate ECS instances, Auto Scaling groups, ECI serverless containers, and Cloud Assistant O&M automation. Handle instance lifecycle, image management, placement groups, spot/preemptible instances, and scheduled scaling.
-
vincentchuwaichow Bundle AWS Serverless Rollout CorrectorPatch AWS serverless rollout definitions across Lambda, API Gateway, EventBridge, SQS, SNS, event source wiring, aliases, versions, and deployment config. Prefer this for repo-side rollout corrections; do not perform live rollout actions or destructive operations.
-
vincentchuwaichow Bundle AWS Waf Cost Optimization ReviewReview AWS workload cost posture against the Well-Architected Framework Cost Optimization Pillar. Covers cost visibility, tagging compliance, commitment coverage, rightsizing, Spot and managed service adoption, and idle resource identification. Use when auditing cloud spend, planning Savings Plans purchases, or preparing for a formal WAF Cost Optimization Pillar review.
-
vincentchuwaichow Bundle GCP Apigee API Platform OperatorDesign and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.
-
vincentchuwaichow Bundle GCP Cloud Run Functions OperatorDeploy and operate Cloud Run services, Cloud Functions gen2, Eventarc triggers, traffic splitting for progressive delivery, and cold-start optimization strategies.
-
vincentchuwaichow Bundle GCP Compliance Assured WorkloadsConfigure Assured Workloads for regulated workloads (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5), audit controls implementation, and gather compliance evidence using Security Command Center and Asset Inventory.
-
vincentchuwaichow Bundle GCP Live Iam Policy Change GuardGate IAM binding mutations, org policy changes, and Service Account key creation against the GCP resource hierarchy. IAM bindings at org level propagate to all folders and projects — this guard enforces blast-radius assessment, audit-trail confirmation, and explicit authority approval before any policy mutation is executed.
-
vincentchuwaichow Bundle GCP Secret Kms Lifecycle StewardAudit and govern Cloud KMS key lifecycles, Secret Manager secrets, CMEK configurations across GCP services (Cloud SQL, BigQuery, GCS, Compute), key rotation schedules, and envelope encryption patterns. Prefer gcp-iam-least-privilege-review for IAM binding review on KMS keys and gcp-security-posture-hardening for broad org-level encryption policy gaps.
-
vincentchuwaichow Bundle GCP Waf Cost Optimization ReviewEvaluate GCP workload cost efficiency against the Google Cloud Well-Architected Framework cost optimization pillar — covering FinOps culture, cloud spending alignment with business value, resource rightsizing, commitment strategy, idle resource elimination, and continuous optimization. Use when reviewing cloud costs, designing cost-aware architectures, or identifying cost reduction opportunities in GCP.
-
vincentchuwaichow Bundle Huawei Compliance SovereigntyAdvise on Huawei Cloud MLPS 2.0 Level 3 technical controls mapping, China data localization requirements, Trusted Cloud (CAICT) certification controls, and government cloud configuration requirements for sovereignty-aware workloads.
-
vincentchuwaichow Bundle Huawei Landing Zone ArchitectSet up Huawei Cloud Organizations with SCP baseline, IAM fine-grained permission structure, Enterprise Projects governance model, and master account structure for multi-account/multi-project governance.
-
vincentchuwaichow Bundle Huawei Resilience Bcdr ReviewReview Huawei Cloud workload HA and BCDR designs — GaussDB High Availability (HA) instance failover, CBR (Cloud Backup and Recovery) cross-region vault, CCE multi-AZ deployment, DRS (Data Replication Service) for DR, RTO/RPO target analysis, and runbook completeness.
-
vincentchuwaichow Bundle Huawei Waf Reliability ReviewAssess Huawei Cloud workload reliability using the Well-Architected Framework Reliability pillar: AZ distribution, ELB load balancing, Auto Scaling, GaussDB and RDS multi-AZ HA, and CBR data protection.
-
vincentchuwaichow Bundle Alibaba Change Impact AdvisorPre-change blast radius analysis for Alibaba Cloud — Resource Directory OU scope mapping, RAM policy cascade effects, VPC peering and CEN impact, SLB backend pool changes, RDS connection pool disruption, and safe change sequencing.
-
vincentchuwaichow Bundle AWS Ecs Fargate Platform OperatorReview Amazon ECS and Fargate platform operations across services, task definitions, task roles, execution roles, capacity providers, load balancers, deployment circuit breakers, blue/green, autoscaling, health checks, logs, secrets, networking, and rollback. Use only for ECS/Fargate; prefer EKS operator for Kubernetes.
-
vincentchuwaichow Bundle AWS Kms Secrets Lifecycle StewardReview AWS KMS and Secrets Manager lifecycle posture across key policies, grants, rotation, multi-Region keys, imported key material, aliases, secret rotation, replication, caching, endpoint conditions, recovery, and break-glass access. Prefer this for cryptography/secret lifecycle; prefer IAM skill for general permissions review.
-
vincentchuwaichow Bundle AWS Live Serverless Release GuardGuard live Lambda and serverless release actions with lambda alias, codedeploy, canary, linear, alarms, rollback, and approval gates. Use only for intentional live serverless rollout actions against confirmed targets.
-
vincentchuwaichow Bundle Fetch Foundation Model PricingFetch live per-token, per-image, and per-GPU-hour prices for foundation models across Anthropic, OpenAI, Google, AWS Bedrock, Azure OpenAI, OCI Generative AI, and Vertex AI. Supports single-model lookup and comparative multi-provider tables. Every price is labeled with source URL and ISO 8601 fetch timestamp. No credentials accepted.
-
vincentchuwaichow Bundle GCP Live Cost Budget Action GuardGate Cloud Billing budget threshold changes, committed-use discount (CUD) purchases, and quota increase requests with explicit financial-authority approval. CUD contracts are 1-3 year financial commitments that cannot be cancelled — this guard ensures every billing action is backed by spend-impact assessment, budget inventory review, and confirmed financial authority before execution.
-
vincentchuwaichow Bundle Ionos Cost Optimization AnalystAnalyze IONOS Cloud cost posture and identify optimization opportunities across compute, storage, and managed services. Covers idle server and volume identification, CPU and memory utilization rightsizing, snapshot and backup cost review, managed service tier evaluation, contract and pricing strategy, cross-region consolidation feasibility, and cost showback. Use when the user asks to reduce, explain, or attribute IONOS Cloud spending.
-
vincentchuwaichow Bundle Kubernetes Pod Spec ReviewUse this skill when reviewing a Kubernetes Pod spec, Deployment spec, or StatefulSet spec for correctness, security posture, and production-readiness. Trigger on any request to audit, validate, or score a workload manifest.
-
vincentchuwaichow Bundle Netsuite Sso OAUTH Tba SkillStatic review of NetSuite OAuth 2.0, TBA, and SSO/SAML configurations. Validates OAuth scope (REST/RESTlets only, not SOAP), TBA fallback timeline, SAML correctness, deprecated NLAuth, and sandbox re-authorization. Trigger: OAuth 2.0, TBA, SSO/SAML, token auth, RESTlet auth, SuiteAnalytics Connect auth, sandbox re-auth, SOAP auth migration. Escalate: role design (use identity-access-role-permission), SDF deploy (use sdf-devops-release), SuiteScript security (use suitescript-secure-code-review), live token ops (use live-org-mutation-guard), AI Connector auth (use ai-connector-mcp).
-
vincentchuwaichow Bundle Python Developer Tooling BuildUse this skill to statically review Python developer tooling and build configuration: whether linters, type-checkers, and tests are wired to catch meaningful defects (not stylistic noise), CI gate coverage, tox/nox environment isolation, build-backend and project layout, and the pre-commit developer feedback loop. Reads tool, CI, and build configuration only; it never runs ruff, mypy, tox, pre-commit, or the CI pipeline.
-
vincentchuwaichow Bundle Kubernetes Manifest Quality ReviewUse this skill when the user provides raw Kubernetes YAML manifests or asks to review K8s manifests for quality, security, or policy compliance — covering Deployment, StatefulSet, DaemonSet, Service, Ingress, NetworkPolicy, RBAC, and CRD resources.
-
vincentchuwaichow Bundle Sap Cloud Alm Sre Incident ReviewSAP Cloud ALM SRE and Incident Review
-
vincentchuwaichow Bundle Terraform Plan Blast RadiusUse this skill to read a Terraform or OpenTofu plan and explain why the engine is replacing or destroying anything, what the replacement ordering means for availability, whether address churn is causing mass recreation, and whether the reviewed plan will actually bind the apply. Engine-level plan mechanics across every cloud. Reads plan output and source only — it never runs the engine and never approves an apply.
-
vincentchuwaichow Bundle Terraform State ReliabilityUse this skill to judge the reliability, recoverability, and confidentiality of Terraform or OpenTofu state: backend and locking configuration, backup and restore posture, whether a proposed `state mv`/`state rm`/`force-unlock` is justified and reversible, OpenTofu's native state encryption and its key-loss risk, and which sensitive values state records in the clear. Advisory only — it reads backend blocks and state metadata, never a raw state file, and never performs a state operation.
-
vincentchuwaichow Bundle Alibaba Landing Zone ArchitectDesign Alibaba Cloud landing zone — Resource Management org tree, Cloud SSO, Control Policy (SCP equivalent), multi-account governance baseline, billing account structure, and ActionTrail centralization.
-
vincentchuwaichow Bundle Alibaba Resilience Bcdr ReviewReview Alibaba Cloud workload HA and BCDR designs — RDS High-Availability Edition failover, PolarDB Global Database Network, ACK multi-zone, ECS disaster recovery cross-region, RTO/RPO target analysis, and HBR (Hybrid Backup Recovery) coverage.
-
vincentchuwaichow Bundle Alibaba Waf Reliability ReviewAssess Alibaba Cloud workload reliability: multi-AZ ECS topology, SLB/ALB/NLB load balancing, Auto Scaling health policies, RDS/PolarDB HA failover, backup and cross-region DR, and Cloud Monitor/ARMS observability coverage.
-
vincentchuwaichow Bundle AWS Cost Anomaly Watch CoordinatorReview AWS cost anomalies using Cost Explorer, Cost Anomaly Detection, Budgets, usage spikes, commitments, and tagging gaps. Prefer this for proactive FinOps watch and non-destructive escalation; prefer aws-cost-optimization-governor for broader optimization strategy.
-
vincentchuwaichow Bundle AWS Data Protection Backup StewardReview AWS backup and data protection implementation across AWS Backup, EBS/RDS/EFS/S3 recovery patterns, vaults, vault lock, retention, encryption, cross-account/cross-Region copy, restore testing, lifecycle, and recovery evidence. Prefer resilience BCDR review for broader RTO/RPO, failover, and business continuity design.
-
vincentchuwaichow Bundle AWS Ec2 Compute Operations StewardReview Amazon EC2 compute operations across instances, Auto Scaling groups, Launch Templates, AMIs, Systems Manager, Patch Manager, Session Manager, EBS volumes, snapshots, health checks, instance refresh, lifecycle hooks, patch compliance, and fleet reliability. Use for EC2 day-2 operations and legacy workload stewardship.
-
vincentchuwaichow Bundle Azure Cosmosdb Platform OperatorAzure Cosmos DB Platform Operator
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include alibaba-resilience-bcdr-review, terraform-policy-evidence, alibaba-devops-cicd-operator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.