automating-devops

A reference for running and maintaining software delivery systems, including Git, automated testing, security checks, releases, databases, monitoring, and performance work.

In plain words
What is it for?
Use it when setting up CI/CD, release files, container images, database changes, security checks, monitoring, performance tests, or Git workflows. It also covers TDD, a practice of writing tests before implementation, and gradual release methods.
Why use it?
It helps you choose and apply common development and operations practices without piecing them together from scattered sources. It also explains delivery pipelines, which automatically build, test, and deploy software.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/telagod/code-abyss/automating-devops
Any agent
npx skills add telagod/code-abyss --skill automating-devops
Clone the repo
git clone --depth 1 https://github.com/telagod/code-abyss

Made for: Claude Code, Codex.

Per session 76 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 637 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00076 $0.00637
Opus 5 $0.00038 $0.00318
Sonnet 5 $0.00015 $0.00127
Haiku 4.5 $0.00008 $0.00064

Measured 2d ago against content hash d9867a1562d8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

automating-devops scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/automating-devops/SKILL.md · 40 lines

What it actually says

炼器秘典 · DevOps

判断先于执行:决定「是否做 / 选什么 / 如何取舍」(栈、方案、架构、权衡)前,先读领域判断内核 skills/_kernel/backend/SKILL.md——它管 judgment,本秘典管 execution;冲突时以内核判断为准。

路由

意图 秘典 核心
版本控制 git-workflow Git 分支策略、PR 流程、rebase vs merge
测试 testing 单元/集成/E2E、TDD、覆盖率
安全开发 devsecops CI/CD 安全、SAST/DAST、供应链
Release 编排 release-pipelines release.yml 多 job 骨架、metadata tag、cosign 集成、踩坑字典
数据库 database SQL/NoSQL 选型、索引优化、迁移
性能 performance Profiling、火焰图、基准/负载测试
可观测 observability 日志/指标/追踪三支柱、SLO/SLI
成本 cost-optimization FinOps、右尺寸、Spot、自动伸缩

CI/CD 管道模式

阶段 动作 工具示例
Commit lint + unit test + SAST ESLint、pytest、Semgrep
Build 构建 + 镜像打包 Docker、Buildpacks
Test 集成测试 + E2E Playwright、k6
Security DAST + 依赖扫描 + 密钥检测 OWASP ZAP、Trivy、gitleaks
Deploy 渐进发布(canary/blue-green) ArgoCD Rollouts、Flagger
Verify 冒烟测试 + SLO 校验 Prometheus、Grafana
Rollback 自动回滚(SLO 违约) ArgoCD、Helm rollback

原则

自动化一切 | 快速反馈(<10min) | 主干开发短分支 | 不可变制品 | 环境即代码
Files

What ships with it

8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 40 lines · 76 tokens per session scan A d9867a1562d8

Subscribe to this mod's changes

automating-devops is a skill published in the GitHub repository telagod/code-abyss (240 stars, last pushed 1mo ago), licensed MIT. It adds 76 tokens to every session and 637 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

codexkit-a-b-test-planner

Design rigorous A/B test plans with hypothesis, sample size calculation, Minimum Detectable Effect (MDE), randomization strategy, and decision rules. Includes guardrail metrics and rollout playbook. Use when planning product experiments, conversion optimization, or data-driven feature decisions.

hoavdc/CodexKit · 62 tokens

codexkit-api-design-reviewer

Review REST and GraphQL API designs for consistency, usability, and best practices. Covers naming conventions, versioning strategy, error format, pagination, authentication patterns, and breaking change detection. Use when reviewing API specs, designing new APIs, or auditing existing endpoints.

hoavdc/CodexKit · 60 tokens

codexkit-architecture-decision-writer

Write Architecture Decision Records (ADRs) following the Michael Nygard format. Captures context, options considered, decision rationale, and consequences. Use when making technology choices, framework selections, or any architectural decision that future developers need to understand.

hoavdc/CodexKit · 59 tokens

codexkit-audit-readiness-checker

Assess organizational readiness for financial audits (internal or external). Map assertions to account balances, check evidence completeness, score readiness using a Red/Amber/Green framework, and generate a remediation timeline. Aligned with SOX, IFRS, and GAAP audit standards. Use before scheduled audits or when…

hoavdc/CodexKit · 75 tokens

codexkit-business-case-writer

Write structured business cases with problem framing, options analysis, financial modeling (NPV/ROI/Payback), risk assessment, and implementation roadmap. Follows HBR business case structure. Use when seeking budget approval, proposing new initiatives, or justifying investment decisions.

hoavdc/CodexKit · 61 tokens

codexkit-campaign-brief-writer

Write agency-standard creative briefs for marketing campaigns. Structure Background, Objective (SMART), Target Audience persona, Key Message, Mandatories, KPIs, Timeline, and Budget Allocation. Use when briefing agencies, creative teams, or internal marketing on a new campaign.

hoavdc/CodexKit · 61 tokens