DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
cyberstrikeus Skill Cis Ocp V160 2 4Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 2 5Ensure that the --peer-client-cert-auth argument is set to true (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 2 6Ensure that the --peer-auto-tls argument is not set to true (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 2 7Ensure that a unique Certificate Authority is used for etcd (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 2 6Verify that the kubelet certificate authority is set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 2 7Ensure that the --authorization-mode argument is not set to AlwaysAllow (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 2 8Verify that RBAC is enabled (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 2 9Ensure that the APIPriorityAndFairness feature gate is enabled (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 3 1Ensure that controller manager healthz endpoints are protected by RBAC (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 3 2Ensure that the --use-service-account-credentials argument is set to true (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 3 3Ensure that the --service-account-private-key-file argument is set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 3 4Ensure that the --root-ca-file argument is set as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 3 5Ensure that the --bind-address argument is set to 127.0.0.1 (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 4 1Ensure that the healthz endpoints for the scheduler are protected by RBAC (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 1 4 2Verify that the scheduler API service is protected by RBAC (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 3 1 1Client certificate authentication should not be used for users (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 3 2 1Ensure that a minimal audit policy is created (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 3 2 2Ensure that the audit policy covers key security concerns (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 1Ensure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 2Ensure that the kubelet service file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 3If proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictive (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 4If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 5Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 6Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 7Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 8Ensure that the client certificate authorities file ownership is set to root:root (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 1 9Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 1Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 2Ensure that the --anonymous-auth argument is set to false (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 3Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 4Ensure that the --client-ca-file argument is set as appropriate (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 5Verify that the read only port is not used or is set to 0 (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 6Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 7Ensure that the --make-iptables-util-chains argument is set to true (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 8Ensure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture (Manual)
Audited -
cyberstrikeus Skill Cis Ocp V160 4 2 9Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
Audited
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include cis-ocp-v160-2.4, cis-ocp-v160-2.5, cis-ocp-v160-2.6. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.