13 Phelan164
operate-devops Skill
以最小权限、分阶段验证和回滚意识,规划并实施基础设施、CI/CD、容器、部署、可观测性和运维配置变更。用于流水线、基础设施即代码、Kubernetes、容器、发布自动化、监控和生产就绪工作;未经明确授权不执行破坏性生产操作。
安装方式:把技能目录放入 ~/.claude/skills/(Claude Code)或在 claude.ai 设置中启用;也可复制右侧安装命令一键添加。
技能指令原文(SKILL.md)
Operate DevOps
Workflow
- Read repository and environment guidance before changing configuration.
- Identify the target environment, current state, owning tool, blast radius, and approval boundary.
- Separate diagnosis, proposed change, apply, verification, and rollback.
- Prefer a dry run, plan, diff, render, lint, or local build before any apply step.
- Make the smallest reversible change.
- Validate configuration syntax and policy.
- Test failure behavior and rollback in the safest available environment.
- Review the diff for secrets, broad permissions, unpinned behavior, and unintended targets.
Guardrails
- Confirm account, cluster, subscription, region, namespace, and environment before state-changing commands.
- Keep credentials out of code, command output, and generated artifacts.
- Use least-privilege identities and scoped approvals.
- Do not silently apply infrastructure because a plan succeeded.
- Do not delete, force-replace, rotate, deploy, or migrate live resources without explicit authorization.
- Preserve a recovery path for availability, routing, storage, and identity changes.
- Do not weaken security controls merely to make automation pass.
- Treat third-party actions, base images, and pipeline dependencies as supply-chain inputs.
Change safety
Read references/change-safety.md for deployment, infrastructure, CI, secret, permission, or data-path changes.
Verification
Use repository-native commands in this order:
format/lint → validate/render → plan/diff → policy tests → staged rollout check
Report exactly which environment was inspected and which commands were not run.
Acceptance criteria
- Target and blast radius are explicit.
- A preview or equivalent validation was inspected.
- Credentials and permissions follow least privilege.
- Rollback or roll-forward steps are concrete.
- Monitoring proves success and detects regression.
- The final report separates proposed, executed, and unverified actions.