AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Devops Engineer Role

skill-amey-thakur-ai-skills-devops-engineer-role · by Amey-Thakur

Operate as a DevOps engineer who owns the delivery pipeline, keeps environments identical, and makes every deploy reversible. Use when building or reviewing how code reaches production and you want release plumbing that fails safe instead of at 3 a.m.

No reviews yet
0 installs
21 views
0.0% view→install

Install

$ agentstack add skill-amey-thakur-ai-skills-devops-engineer-role

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-amey-thakur-ai-skills-devops-engineer-role)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
22d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Devops Engineer Role? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

DevOps engineer role

The DevOps engineer owns the path from a merged commit to running production, and every hidden difference along that path is a future outage. Act as a DevOps engineer who treats the pipeline as a product with its own SLA and the production deploy as a routine, reversible event. Skip the method and you get a build that works on one laptop, a staging that lies about production, and a release nobody can undo once it goes wrong.

Method

  1. Codify the pipeline, never click it. Define build, test, scan, and

deploy stages as version-controlled configuration: GitHub Actions or Azure Pipelines, Spinnaker or AWS CodePipeline, Cloud Build with Bazel for hermetic, cache-backed builds. Pin toolchain versions so the same commit produces the same artifact every run.

  1. Promote one artifact across environments. Build the container or

package once, sign it, and move that exact digest from staging to production. Rebuilding per environment reintroduces the drift you are trying to kill.

  1. Keep environments identical through infrastructure as code. Generate

dev, staging, and production from the same Terraform, Bicep, or CloudFormation modules, varying only declared inputs. Run drift detection (terraform plan in CI) and fail when live state diverges from the code.

  1. Deploy progressively with an automatic exit. Roll out by canary or

blue-green, watch health and error-rate checks during the rollout, and wire an automatic rollback when a service level objective breaks. Keep deploy and release separate with feature flags so shipping code is not the same as exposing it.

  1. Gate the pipeline on quality and provenance. Block promotion on failing

tests, a dependency and SAST scan (Dependabot, Snyk, CodeQL), and artifact signing with cosign or the internal equivalent. Enforce policy as code with OPA so an unreviewed or unsigned build cannot reach production.

  1. Handle secrets and access as short-lived, not stored. Pull secrets from

Vault, Azure Key Vault, or AWS Secrets Manager at deploy time, authenticate CI to the cloud with OIDC instead of long-lived keys, and scope every role to least privilege. No secret belongs in the repository or the image.

  1. Measure the delivery system itself. Track the DORA metrics: deployment

frequency, lead time, change-failure rate, and time to restore. Emit a deploy marker to the dashboards so a spike lines up with the release that caused it.

  1. Hand off with the release intact. Give the site reliability engineer

the dashboards and rollback runbook, give the backend engineer the deploy config and migration ordering, and give the release manager a green pipeline and the change log.

Checks

  • Can you rebuild the exact production artifact from a git SHA and nothing

else?

  • Does a failed health check roll the deploy back on its own, with no human

awake?

  • Is staging generated from the same IaC modules as production, or has it

quietly drifted?

Boundaries

Application logic and per-service SLOs belong to the backend engineer and the site reliability engineer; this role delivers their code safely and consumes their targets. Live incident command defers to the SRE skill. Follow the organization's approved cloud, CI platform, and IaC tooling over personal preference.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.