Token导航 LogoToken导航TokenDH.com
运维和基础设施external-servicegithub未标认证来源可访问许可证需确认审计提醒

ci-cd-architectureCI CD 架构

Agent Skill

ci-cd-architecture 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

738

周安装

50

GitHub Stars

10

下载量

231
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:ci-cd-architecture(CI CD 架构)
来源仓库:https://github.com/oakoss/agent-skills
仓库路径:skills/ci-cd-architecture
安装命令:
npx skills add https://github.com/oakoss/agent-skills --skill ci-cd-architecture
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/oakoss/agent-skills --skill ci-cd-architecture

简介

用于设计高安全性的 CI/CD 架构,重点支持 GitHub Actions 与云服务商 OIDC 集成。

  • 涵盖从 MVP 到企业级部署的多阶段发布策略和资源优化建议。
  • 使用时需评估团队规模、推送频率和合规要求以选择合适模式。
  • 通过 GitHub 安装,需遵循最小权限原则配置 GITHUB_TOKEN 作用域。
  • ci-cd-architecture 属于运维和基础设施类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

CI/CD & Deployment

Overview

Covers CI/CD pipeline design, deployment platform selection, and production infrastructure. Focuses on GitHub Actions with hardened security (OIDC, permission scoping, action pinning), Bun-first build optimization, and deployment patterns from MVP to enterprise scale.

When to use: Setting up GitHub Actions workflows, choosing deployment targets, configuring OIDC for cloud providers, optimizing CI performance, planning multi-environment pipelines.

When NOT to use: Application-level architecture decisions (use framework-specific skills), Kubernetes cluster management (use dedicated IaC tools), cloud provider console configuration.

Quick Reference

NeedSolution
MVP deploy (< 1K users)Vercel, Netlify, Railway, Cloudflare Pages
Growing product (1K-100K)AWS Amplify, Cloud Run, Fly.io, Render
Enterprise (100K+)AWS ECS/EKS, GKE, DigitalOcean App Platform
Static siteVercel, Netlify, Cloudflare Pages
Full-stack + DBRailway, Render, AWS Amplify
Global low latencyCloudflare Workers, Vercel Edge, Fly.io
Compliance (HIPAA, SOC 2)AWS, GCP, Azure
Cloud auth from CIOIDC roles (never long-lived keys)
Action pinningPin to commit SHA, not tag
Bun CI caching~/.bun/install/cache keyed on lockfile
Pipeline securityStepSecurity Harden-Runner for egress control
Container buildsMulti-stage Dockerfile: builder + runtime stage
Docker layer caching--cache-from + actions/cache for buildx
Multi-platform buildsdocker buildx targeting linux/amd64,linux/arm64
Image scanningTrivy or Snyk in pipeline before push
Registry pushGHCR (ghcr.io), ECR, Docker Hub
Pipeline stagesbuild → test → security scan → deploy
DORA: deploy frequencyTrack deployments per day/week per service
DORA: lead timeCommit-to-production time; target < 1 hour
DORA: change failure rate% of deploys causing incidents; target < 5%
DORA: MTTRMean time to restore; target < 1 hour

Common Mistakes

MistakeCorrect Pattern
Storing long-lived AWS/GCP/Azure keys as GitHub secretsUse OIDC roles with id-token: write permission for zero-trust cloud auth
Pinning GitHub Actions to tags instead of commit SHAsPin third-party actions to full commit SHA to prevent supply chain attacks
Leaving permissions as default (broad) on workflowsExplicitly scope permissions at the job level; default to contents: read
Running full CI on every branch pushUse on.pull_request filters and path-based triggers to avoid wasted compute
Over-engineering infrastructure before product-market fitStart with managed platforms (Vercel, Railway); scale to AWS/GKE only when needed
Using outdated action versions (v3 or older)Use current major versions: checkout@v6, cache@v5, configure-aws-credentials@v5
Caching only bun.lockb without considering bun.lockBun 1.2+ uses text-based bun.lock; hash whichever lockfile format the project uses
Skipping preview deployments for PRsEvery PR should get a preview URL for testing before merge

Relationship to Other Skills

If the github-actions skill is available, delegate detailed workflow authoring, matrix strategies, and composite actions to it. This skill covers CI/CD architecture and platform selection; github-actions covers workflow syntax depth. If the deployment-strategy skill is available, delegate deployment pattern selection (blue-green, canary, rolling) to it. This skill covers platform selection and CI pipeline mechanics.

Delegation

  • Audit existing CI workflow security and permissions: Use Explore agent to scan workflow YAML files for broad permissions, unpinned actions, and exposed secrets
  • Set up multi-environment deployment pipelines: Use Task agent to create dev/staging/prod workflows with environment protection rules
  • Plan migration from managed platform to containerized infrastructure: Use Plan agent to evaluate current deployment, define migration steps, and select target architecture

References

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.66%
按下载量换算85

Claude

30.83%
按下载量换算71

Cursor

16.71%
按下载量换算39

Gemini CLI

9.59%
按下载量换算22

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills