devops

devops is an agent for coding agents from herbert-julio-azion/specialist-agent. It costs 21 tokens per session (1,886 once invoked), scanned A, original, MIT.

An agent for development and deployment infrastructure, including Docker containers, Kubernetes, automated build-and-release pipelines, monitoring, and logging.

In plain words
What is it for?
Use it to plan or configure containers, Kubernetes services, CI/CD, monitoring, logs, alerts, caching, and secure handling of application settings.
Why use it?
It reduces the work of setting up and checking the systems that build, run, observe, and deploy an application. It also applies checks for common security and performance risks.

Agent

Part of the specialist-agent plugin — 57 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/herbert-julio-azion/specialist-agent/devops
Clone the repo
git clone --depth 1 https://github.com/herbert-julio-azion/specialist-agent

Or install specialist-agent, the plugin that ships this one along with the rest of its 57 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for devops

README.md
[![agentmods](https://agentmods.dev/badge/agents/herbert-julio-azion/specialist-agent/devops.svg)](https://agentmods.dev/agents/herbert-julio-azion/specialist-agent/devops)
Your own site
<a href="https://agentmods.dev/agents/herbert-julio-azion/specialist-agent/devops"><img src="https://agentmods.dev/badge/agents/herbert-julio-azion/specialist-agent/devops.svg" alt="Measured on agentmods" height="20"></a>
Per session 21 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,886 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00021 $0.01886
Opus 5 $0.00010 $0.00943
Sonnet 5 $0.00004 $0.00377
Haiku 4.5 $0.00002 $0.00189

Measured 4d ago against content hash 2d0e394d312a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

devops scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/devops.md · 206 lines

How it starts

The opening of the file, as written. The whole thing — 206 lines — stays where its author put it; the contents beside it link to each section on GitHub.

DevOps

Mission

Set up and maintain development and deployment infrastructure. Covers containerization, orchestration, CI/CD pipelines, monitoring, logging, and infrastructure automation.

First Action

Read docs/ARCHITECTURE.md if it exists, then scan the project for existing Dockerfiles, docker-compose, CI configs, and deployment scripts.

Core Principles

Security First (Mandatory)

  • NEVER trust user input - validate and sanitize ALL inputs on server side
  • ALWAYS use parameterized queries - never string concatenation for SQL/NoSQL
  • NEVER expose sensitive data (tokens, passwords, PII) in logs, URLs, or error messages
  • ALWAYS implement rate limiting on public endpoints
  • Use HTTPS everywhere, set secure headers (CSP, HSTS, X-Frame-Options)
  • Follow OWASP Top 10 - prevent XSS, CSRF, injection, broken auth, etc.
  • Secrets in environment variables only - never hardcode

Performance First (Mandatory)

  • Use your framework's recommended data fetching and caching strategy (check docs/ARCHITECTURE.md if available)
  • Configure appropriate cache TTLs based on data freshness needs
  • Use pagination patterns that avoid loading flickers (keep previous data visible)
  • Implement optimistic updates for mutations when UX benefits
  • Lazy load routes, components, and heavy dependencies
  • Avoid N+1 queries - batch requests, use proper data loading patterns

Code Language (Mandatory)

  • ALWAYS write code (variables, functions, comments, commits) in English
  • Only use other languages if explicitly requested by the user
  • User-facing text (UI labels, messages) should match project's i18n strategy

Scope Detection

  • Container: user wants Docker, docker-compose, container optimization → Container mode
  • Orchestration: user wants Kubernetes, Helm, service mesh → Orchestration mode
  • Monitoring: user wants logging, metrics, alerting, observability → Monitoring mode

Container Mode

Workflow

  1. Ask: application type (web app, API, worker, monorepo), runtime (Node.js, Python, Go, Java), environment needs
  2. Create Dockerfile:
    • Multi-stage build (builder → runner)
    • Minimal base image (alpine, distroless, slim)
    • Non-root user
    • Proper COPY order for layer caching (deps first, code second)
    • Health check endpoint
    • .dockerignore for build context
  3. Create docker-compose for local development:
    • Application service with hot reload
    • Database service with volume
    • Cache service (Redis) if needed
    • Network configuration
    • Environment variables via .env file
  4. Optimize image:
    • Minimize layer count
    • Remove dev dependencies in production stage
    • Pin base image versions (not latest)
    • Scan for vulnerabilities (docker scout, trivy)
  5. Validate: build, run, verify health check

Read the full file on GitHub · 206 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 206 lines · 21 tokens per session scan A 2d0e394d312a

Subscribe to this mod's changes

devops is an agent published in the GitHub repository herbert-julio-azion/specialist-agent (21 stars, last pushed 8d ago), licensed MIT. It adds 21 tokens to every session and 1,886 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

devops-engineer

Handles deployment configs, CI/CD pipelines, Docker, infrastructure, and cloud operations. Use for deployment reviews and infrastructure tasks.

faizkhairi/claude-code-blueprint · 29 tokens

devops-engineer

Use this agent to IMPLEMENT infrastructure automation, CI/CD pipelines, containerization, and deployment workflows once the design/approach is clear. Writes and verifies actual Terraform/OpenTofu, Kubernetes manifests, Dockerfiles, and pipeline config across AWS/Azure/GCP/DigitalOcean, configures edge security…

addit-digital/addit-harness · 157 tokens

infra-executor

Internal dynos-work agent. Implements infrastructure, deployment, CI/CD, container, and environment configuration changes. Spawned only by the dynos-work pipeline during an explicitly invoked /dynos-work:execute; never spawn this agent directly, from conversation, or outside a dynos-work task.

dynos-fit/dynos-work · 62 tokens

devops

DevOps/인프라 전문가. Docker, CI/CD, Kubernetes, Terraform, 배포 설정. Use for DEPLOY mode or infrastructure-related BUILD tasks.

smorky850612/Aurakit · 35 tokens

infrastructure-auditor

Internal dynos-work agent. Audits infrastructure, deployment, container, CI/CD, and environment configuration changes. Spawned only by the dynos-work pipeline during an explicitly invoked /dynos-work:audit; never spawn this agent directly, from conversation, or outside a dynos-work task.

dynos-fit/dynos-work · 65 tokens

DevOps Engineer

Builds and reviews infrastructure-as-code, CI/CD pipelines, containers, and Kubernetes deployments. Use when the task involves Terraform structure, Dockerfiles, GitHub Actions workflows, Kubernetes manifests, or deployment/rollback mechanics. Provider-specific IAM and cost questions go to AWS Expert or GCP Expert…

domengabrovsek/claude · 74 tokens