Overview
Drone is a container-native CI/CD platform where each pipeline step runs in a Docker container. Simple YAML configuration, plugin ecosystem, and built-in secrets management.
Capabilities
- Container-native steps (each step is a Docker container)
- YAML pipeline configuration (.drone.yml)
- Plugin ecosystem (Docker, Slack, S3, etc.)
- Encrypted secrets at repo/org level
- Multi-machine runners (Docker, SSH, Kubernetes)
- Matrix builds for testing across environments
When to Use
Trigger phrases:
"drone ci"
"Drone CI — container-native CI/CD, YAML pipelines, plugins, secrets, multi-machi"
Want simple, container-based CI/CD
Need lightweight CI that runs anywhere Docker runs
Prefer YAML-driven pipelines over Groovy/scripted CI
Self-hosted CI with minimal infrastructure
When NOT to Use
- Task is outside your authorization scope
- You need to implement controls (use implementing-* skills)
- Task is about analysis, not action (use analyzing-* skills)
- You don't have access to target systems
- Task requires compliance expertise (consult professionals)
- Task is about defense, not offense (use defensive skills)
Pseudo Code
The drone-ci workflow follows a standard pipeline pattern.
Core flow:
# drone-ci primary flow
input = prepare(raw_data)
result = process(input, config={builds, container, drone, machine, multi})
validate(result)
deliver(result)
Error handling:
on error:
log(error_details)
retry_with_backoff(max=3)
if still_failing: alert_and_escalate()
Basic Pipeline
# .drone.yml
kind: pipeline
type: docker
name: default
steps:
- name: test
image: node:20
commands:
- npm ci
- npm test
- name: build
image: plugins/docker
settings:
repo: myapp
tags:
- ${DRONE_COMMIT_SHA:0:8}
- latest
username:
from_secret: docker_username
password:
from_secret: docker_password
- name: deploy
image: appleboy/drone-ssh
settings:
host: prod.example.com
username: deploy
key:
from_secret: ssh_key
script:
- docker pull myapp:latest
- docker-compose up -d
Matrix Build
kind: pipeline
type: docker
name: test
platform:
os: linux
arch: amd64
steps:
- name: test
image: node:${NODE_VERSION}
commands:
- npm ci
- npm test
matrix:
NODE_VERSION:
- 18
- 20
- 22
Multi-Pipeline (Dependency)
---
kind: pipeline
type: docker
name: build
steps:
- name: build
image: plugins/docker
settings:
repo: myapp
tags: latest
---
kind: pipeline
type: docker
name: deploy
depends_on: [build]
steps:
- name: deploy
image: appleboy/drone-ssh
settings:
host: prod.example.com
script:
- docker-compose up -d
Common Patterns
- Secrets:
drone secret add --name docker_username --value admin myorg/myrepo
- Caching: Use
drone-s3-cache plugin for dependency caching
- Concurrency:
concurrency: { limit: 1 } to prevent parallel deploys
- Conditions:
when: { branch: [main], event: [push] } for conditional steps
- Plugins: Most integrations are Docker images (plugins/docker, plugins/slack, plugins/s3, and community plugins)
How to Use
- Define infrastructure as code (Terraform, CloudFormation, Pulumi)
- Review changes through PR process before applying
- Configure monitoring and alerting for critical paths
- Set up secrets management (Vault, AWS Secrets Manager, etc.)
- Document runbooks for deployment, rollback, and incident response
- Test disaster recovery procedures regularly
Red Flags
- Infrastructure changes without review: Unreviewed changes cause outages — use PRs for infra code
- No rollback strategy: Every deployment needs a tested rollback plan before it runs
- Secrets in configuration files: Secrets in YAML/JSON get committed to version control
- Missing monitoring and alerting: Without monitoring, outages go undetected until users report them
- No documentation for runbooks: Without runbooks, on-call engineers waste time re-discovering procedures
Verification
Process
- Analyze the task requirements
- Apply domain expertise
- Verify output quality
Anti-Rationalization Table
| Rationalization |
Reality |
| "Manual deployments are fine" |
Manual deployments are error-prone and不可 repeatable. Automate. |
| "We do not need monitoring" |
Without monitoring, you are flying blind. Add observability from day one. |
| "Infrastructure as code is overkill" |
IaC enables reproducibility, version control, and disaster recovery. |
1---2name: drone-ci3description: Configure container-native CI/CD pipelines with Drone, including YAML pipeline definitions, plugins, secrets, and multi-machine builds.4license: Apache-2.05---6789## Overview1011Drone is a container-native CI/CD platform where each pipeline step runs in a Docker container. Simple YAML configuration, plugin ecosystem, and built-in secrets management.1213## Capabilities1415- Container-native steps (each step is a Docker container)16- YAML pipeline configuration (.drone.yml)17- Plugin ecosystem (Docker, Slack, S3, etc.)18- Encrypted secrets at repo/org level19- Multi-machine runners (Docker, SSH, Kubernetes)20- Matrix builds for testing across environments2122## When to Use23**Trigger phrases:**24- "drone ci"25- "Drone CI — container-native CI/CD, YAML pipelines, plugins, secrets, multi-machi"262728- Want simple, container-based CI/CD29- Need lightweight CI that runs anywhere Docker runs30- Prefer YAML-driven pipelines over Groovy/scripted CI31- Self-hosted CI with minimal infrastructure3233## When NOT to Use3435- Task is outside your authorization scope36- You need to implement controls (use implementing-* skills)37- Task is about analysis, not action (use analyzing-* skills)38- You don't have access to target systems39- Task requires compliance expertise (consult professionals)40- Task is about defense, not offense (use defensive skills)414243## Pseudo Code4445The drone-ci workflow follows a standard pipeline pattern.4647Core flow:48```49# drone-ci primary flow50input = prepare(raw_data)51result = process(input, config={builds, container, drone, machine, multi})52validate(result)53deliver(result)54```5556Error handling:57```58on error:59 log(error_details)60 retry_with_backoff(max=3)61 if still_failing: alert_and_escalate()62```636465### Basic Pipeline66```yaml67# .drone.yml68kind: pipeline69type: docker70name: default7172steps:73 - name: test74 image: node:2075 commands:76 - npm ci77 - npm test7879 - name: build80 image: plugins/docker81 settings:82 repo: myapp83 tags:84 - ${DRONE_COMMIT_SHA:0:8}85 - latest86 username:87 from_secret: docker_username88 password:89 from_secret: docker_password9091 - name: deploy92 image: appleboy/drone-ssh93 settings:94 host: prod.example.com95 username: deploy96 key:97 from_secret: ssh_key98 script:99 - docker pull myapp:latest100 - docker-compose up -d101```102103### Matrix Build104```yaml105kind: pipeline106type: docker107name: test108109platform:110 os: linux111 arch: amd64112113steps:114 - name: test115 image: node:${NODE_VERSION}116 commands:117 - npm ci118 - npm test119120matrix:121 NODE_VERSION:122 - 18123 - 20124 - 22125```126127### Multi-Pipeline (Dependency)128```yaml129---130kind: pipeline131type: docker132name: build133steps:134 - name: build135 image: plugins/docker136 settings:137 repo: myapp138 tags: latest139140---141kind: pipeline142type: docker143name: deploy144depends_on: [build]145steps:146 - name: deploy147 image: appleboy/drone-ssh148 settings:149 host: prod.example.com150 script:151 - docker-compose up -d152```153154## Common Patterns155156- **Secrets**: `drone secret add --name docker_username --value admin myorg/myrepo`157- **Caching**: Use `drone-s3-cache` plugin for dependency caching158- **Concurrency**: `concurrency: { limit: 1 }` to prevent parallel deploys159- **Conditions**: `when: { branch: [main], event: [push] }` for conditional steps160- **Plugins**: Most integrations are Docker images (plugins/docker, plugins/slack, plugins/s3, and community plugins)161162## How to Use1631641. Define infrastructure as code (Terraform, CloudFormation, Pulumi)1652. Review changes through PR process before applying1663. Configure monitoring and alerting for critical paths1674. Set up secrets management (Vault, AWS Secrets Manager, etc.)1685. Document runbooks for deployment, rollback, and incident response1696. Test disaster recovery procedures regularly170171## Red Flags172173- **Infrastructure changes without review**: Unreviewed changes cause outages — use PRs for infra code174- **No rollback strategy**: Every deployment needs a tested rollback plan before it runs175- **Secrets in configuration files**: Secrets in YAML/JSON get committed to version control176- **Missing monitoring and alerting**: Without monitoring, outages go undetected until users report them177- **No documentation for runbooks**: Without runbooks, on-call engineers waste time re-discovering procedures178179## Verification180181- [ ] Skill output matches expected behavior182183## Process1841851. Analyze the task requirements1862. Apply domain expertise1873. Verify output quality188189## Anti-Rationalization Table190191| Rationalization | Reality |192|---|---|193| "Manual deployments are fine" | Manual deployments are error-prone and不可 repeatable. Automate. |194| "We do not need monitoring" | Without monitoring, you are flying blind. Add observability from day one. |195| "Infrastructure as code is overkill" | IaC enables reproducibility, version control, and disaster recovery. |