本文へ移動
cccskills
無料GitHub で公開

deployment-pipelines

Use when authoring or reviewing CI/CD pipelines — GitHub Actions workflows, reusable workflows, composite actions, OIDC federation to AWS/GCP, caching, artifacts, and pipeline security hardening. Triggers on edits to .github/workflows/**, action.yml, composite action definitions, or mentions of "CI", "CD", "pipeline", "GitHub Actions", "workflow", "OIDC", "runner", "deploy script", "release", or "build pipeline".

インストール方法を見る

含まれるファイル(8)

  • SKILL.md5.7 KB
  • references/caching-and-artifacts.md3.5 KB
  • references/debugging.md3.7 KB
  • references/deploy-patterns.md3.8 KB
  • references/oidc-and-secrets.md3.4 KB
  • references/performance-and-cost.md3.2 KB
  • references/security-hardening.md4.2 KB
  • references/workflow-structure.md3.9 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Deployment Pipelines

You are operating as an infrastructure engineer with the CI/CD lens. Pipelines are production code: untrusted inputs (PRs, third-party actions, package registries) flow through privileged contexts. Default to least privilege, pinned versions, and fast-fail behavior over convenience.

Currently implemented on GitHub Actions with OIDC federation to AWS and GCP — no long-lived credentials. Workflows live in .github/workflows/. Reusable workflows and composite actions are versioned alongside the repos that consume them.

Universal Rules

Security

  1. No long-lived secrets — use OIDC to assume cloud roles. AWS access keys in repo secrets are a bug.
  2. Pin third-party actions to a full commit SHA, not a tag. Tags are mutable; SHAs are not. actions/* from GitHub itself may use @vN.
  3. Default permissions: {} at workflow level, then grant the minimum each job needs (contents: read, id-token: write, etc.). Never rely on the org default.
  4. Never pull_request_target with checkout of PR code unless you fully understand the privilege escalation. Default to pull_request.
  5. Mask and never echo secrets. No env: dumps in debug steps.
  6. Restrict who can approve deploys via environment protection rules, not branch rules alone.
  7. No inline scripts that interpolate untrusted input (${{ github.event.issue.title }} in run:) — write the value to an env var first.

Reliability

  1. Pin runner OS (ubuntu-24.04, not ubuntu-latest) for any pipeline whose stability matters.
  2. Set timeout-minutes on every job. Default 360 is a hung-runner trap.
  3. Use concurrency groups to cancel superseded runs on the same ref.
  4. Fail fast on lint/type errors before running expensive tests.
  5. Cache deterministically — lockfile-derived keys, never date-based.
  6. Idempotent deploys — re-running the same workflow on the same SHA must be safe.

Maintainability

  1. One responsibility per workflow file — ci.yml, deploy-staging.yml, release.yml. Not one mega-workflow with conditionals.
  2. Reusable workflows (workflow_call) for shared logic across repos. Composite actions for shared steps within a repo.
  3. No copy-pasted YAML across jobs — extract to a composite action or matrix.
  4. Pin action versions in one place when possible (e.g., a versions.env file or Dependabot grouping).
  5. Treat workflows like code: they get reviewed, tested (act / branch deploys), and refactored.

Cost

  1. Path filters (paths: / paths-ignore:) so doc-only changes don't trigger full CI.
  2. Cancel-in-progress for pull request runs.
  3. Right-size runners — don't put a 1-minute lint job on a 16-core runner.
  4. Cache aggressively but invalidate on lockfile changes.

References

Related skills

  • security-engineering — pipeline security review, supply-chain hardening, secret-handling rules
  • release-manager — coordinates the release itself (CHANGELOG, version tag, stakeholder comms) once the pipeline is authored
  • devops-engineer — build-system, artifact-registry, and environment-promotion mechanics beyond GitHub Actions YAML

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use when adversarially reviewing a document that makes formal or technical claims — math derivations, physics papers, statistical analyses, benchmark reports, whitepapers. Inventories every equation and quantitative claim, verifies each AS NAMED in the text (never a paraphrase or a neighboring statement), and classifies VERIFIED / REFUTED / UNVERIFIABLE / VACUOUS. Triggers on "check this paper", "verify these claims", "is this derivation right", "review this proof", "audit this benchmark", "does the math hold up". For source-code review see code-review-and-quality; for skill/agent library audits see skill-library-review; for content quality scoring see content-ops.

日本語の概要は準備中です。原文の説明を表示しています。

LazyIsEfficient/agentic-os172026年7月17日 更新

Run Karpathy-style autoresearch optimization on any content. Generates 50+ variants, scores with a 5-expert simulated panel, evolves winners through multiple rounds, outputs optimized version + full experiment log. Use when optimizing landing pages, email sequences, ad copy, headlines, form pages, CTA text, or any conversion-focused content. Triggers on "optimize this page", "run autoresearch", "score these variants", "A/B test this copy".

日本語の概要は準備中です。原文の説明を表示しています。

LazyIsEfficient/agentic-os172026年7月17日 更新

Tests in real browsers. Use when building or debugging anything that runs in a browser. Use when you need to inspect the DOM, capture console errors, analyze network requests, profile performance, or verify visual output with real runtime data via Chrome DevTools MCP.

日本語の概要は準備中です。原文の説明を表示しています。

LazyIsEfficient/agentic-os172026年7月17日 更新

Conducts multi-axis code review across correctness, readability, architecture, security, and performance. Use before merging any change. Use when reviewing code written by yourself, another agent, or a human. Triggers on "review my PR", "review this diff", "code review", "review this changeset", "is this ready to merge", "pre-merge review".

日本語の概要は準備中です。原文の説明を表示しています。

LazyIsEfficient/agentic-os172026年7月17日 更新

Estimate the full development cost of an existing codebase from lines of code, architectural complexity, and team-composition overhead. Use for 'how much would this cost to build', 'what did this codebase cost', development-cost or build-cost estimates, calendar-time estimates, and Claude/AI ROI on a delivered codebase. Estimates by measured LOC and complexity, not by ticket volume.

日本語の概要は準備中です。原文の説明を表示しています。

LazyIsEfficient/agentic-os172026年7月17日 更新

Auto-assembles a domain-specific expert panel (7–10 experts), scores any content or strategy artifact against a typed rubric, and iterates until the aggregate hits 90+ (max 3 rounds). Use as a quality gate on copy, email sequences, landing-page drafts, strategy docs, charts, titles, or recruiting evaluations — or when another skill needs a final review gate on its output. Triggers on "expert panel this", "score this", "rate these variants", "quality check this", "panel review", "expert score", "evaluate this copy/strategy/page". For variant generation and multi-round conversion optimization see autoresearch; for live-URL CRO auditing see conversion-ops; for the scripted content-production pipeline see content-pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

LazyIsEfficient/agentic-os172026年7月17日 更新

LazyIsEfficient のスキルをすべて見る

このスキルの問題を報告する