Infrastructure as Code
-
alirezarezvani Bundle Cto AdvisorProvides technical leadership frameworks for architecture decisions, engineering team scaling, technology strategy, and technical debt assessment.
Audited 20.4k -
alirezarezvani Bundle Senior DevopsGenerates CI/CD pipelines, Terraform modules, and Kubernetes deployment manifests with health-check gates and rollback support for AWS, GCP, and Azure.
20.4k -
microsoft Skill Azure RbacFinds the least-privilege Azure RBAC role for an identity, generates CLI commands and Bicep code to assign it, and provides guidance on permissions needed to grant roles.
Audited 2.7k -
microsoft Bundle Azure PrepareGenerate infrastructure code (Bicep/Terraform), azure.yaml, and Dockerfiles for Azure deployment, with a mandatory planning workflow.
2.7k -
microsoft Bundle Azure Enterprise Infra PlannerArchitect and provision enterprise Azure infrastructure from workload descriptions, generating Bicep or Terraform for networking, identity, security, and multi-resource topologies aligned with the Well-Architected Framework.
2.7k -
itsmostafa Bundle CloudformationManage AWS infrastructure as code with CloudFormation templates, stacks, change sets, and nested stacks.
Audited 1.1k -
itsmostafa Bundle Step FunctionsDesign, build, and manage AWS Step Functions state machines for serverless workflow orchestration, including error handling, parallel execution, and integration with AWS services.
Audited 1.1k -
nvidia Bundle Jetson Customize UsbEnable, disable, or change the role of USB2/USB3 SS ports on Jetson custom carriers by generating kernel-DT overlays that flip lane, port, and host xHCI phys in lockstep.
Audited 2.2k -
nvidia Bundle Jetson Customize PcieGenerates kernel device-tree overlay fragments to enable or disable individual PCIe controllers and configure lane count and link speed on Jetson Thor/Orin custom carriers.
Audited 2.2k -
nvidia Bundle Tao Setup Nvidia Gpu HostChecks and installs NVIDIA driver, CUDA Toolkit, and NVIDIA Container Toolkit for GPU-accelerated Docker and Kubernetes hosts. Supports multiple Linux distributions with automated install and read-only check modes.
Audited 2.2k -
affaan-m Skill Cisco IOS PatternsReview Cisco IOS and IOS-XE configurations, choose read-only show commands, check ACL wildcard masks and interface direction, and build safe change-window verification checklists.
Audited 226k -
antigravity Skill AWS SkillsProvides guidance and patterns for AWS development, infrastructure automation, and cloud architecture.
Audited 42.4k -
google Bundle Google Cloud Recipe Foundation BuilderDeploys a secure, enterprise-grade Google Cloud landing zone foundation with organization policies, resource hierarchy, billing association, and centralized logging and monitoring.
14.4k -
cloudflare Bundle CloudflareBuild and manage applications on the Cloudflare platform, including Workers, Pages, storage, AI, networking, security, and infrastructure-as-code.
Audited 2.1k -
oracle Bundle Oke Cluster GeneratorGuides users through a structured, conversational process to generate a production-ready Terraform stack and OCI Resource Manager schema for OKE clusters on Oracle Cloud Infrastructure.
736 -
adobe Bundle Config AuthoringCreate, modify, review, and harden configuration for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEM 6.5 LTS environments only.
Audited 142 -
adobe Bundle Technical AdvisoryProvides advisory guidance for the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration in AEM 6.5 / AMS workflows, with public-doc citations and AMS-specific MCP verification plans.
Audited 142 -
adobe Bundle Outbound Call TimeoutsDetects outbound HTTP clients constructed without explicit timeouts in AEM Cloud Service code and applies mechanical fixes with CSO-aligned defaults to prevent request-thread pool saturation.
142 -
github Skill Az Cost OptimizeAnalyze Azure resources and IaC files to identify cost optimization opportunities, calculate savings, and create GitHub issues for tracking.
36.2k -
github Skill AWS Well Architected ReviewReviews AWS infrastructure as code and deployed resources against the Well-Architected Framework, generating findings and GitHub issues for remediation.
36.2k -
github Skill Update Avm Modules In BicepUpdate Azure Verified Modules (AVM) to their latest versions in Bicep files, with support for non-breaking changes and manual review for breaking changes.
36.2k -
github Skill Import Infrastructure As CodeImport existing Azure resources into Terraform using Azure CLI discovery and Azure Verified Modules (AVM).
36.2k -
github Skill Qdrant Scaling Data VolumeGuides scaling decisions for Qdrant vector databases when data volume exceeds single-node capacity, covering tenant scaling, time window rotation, vertical scaling, and horizontal sharding.
Audited 36.2k -
github Bundle Terraform Azurerm Set Diff AnalyzerAnalyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.
36.2k -
mukul975 Bundle Configuring Pfsense Firewall RulesGuides the configuration of pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation and protect network zones.
24.6k -
mukul975 Bundle Implementing Network Access ControlEnforces identity-based network access with 802.1X, RADIUS authentication, dynamic VLAN assignment, and endpoint posture assessment using PacketFence.
24.6k -
mukul975 Bundle Implementing Ics Firewall With TofinoDeploy and configure Tofino industrial firewalls to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones.
24.6k -
mukul975 Bundle Deploying Tailscale For Zero Trust VpnDeploy and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
24.6k -
mukul975 Bundle Implementing Security Chaos EngineeringDeliberately disables or degrades security controls to verify detection and response capabilities, including WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess.
24.6k -
mukul975 Bundle Implementing Network Segmentation For OtDesign and implement network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking, following the Purdue Model and IEC 62443 standards.
24.6k -
mukul975 Bundle Securing Remote Access To Ot EnvironmentImplements secure remote access architecture for OT/ICS environments with jump servers, MFA, session recording, and privileged access management.
24.6k -
mukul975 Bundle Deploying Osquery For Endpoint MonitoringDeploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.
24.6k -
mukul975 Bundle Implementing AWS Iam Permission BoundariesConfigure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.
24.6k -
mukul975 Bundle Implementing Privileged Access WorkstationDesign and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.
Audited 24.6k -
mukul975 Bundle Implementing Rbac Hardening For KubernetesHarden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.
24.6k -
mukul975 Bundle Implementing Secrets Management With VaultCentralize secrets management with HashiCorp Vault, including dynamic secret generation, transit encryption, PKI certificate management, and Kubernetes integration.
24.6k