devops-infra-core
Installation
SKILL.md
DevOps & Infra Core
Shared model for the devops-infra cluster. The container, network, and homelab spokes span
very different tools, but they all turn on one decision: is this action read-only, or does
it change state? Keep that boundary consistent here so no spoke quietly normalizes a risky
change.
1. The decision the whole cluster turns on (the safety boundary)
Every spoke has two paths. The default is read-only; the change path is gated.
DIAGNOSE (read-only) ──> PLAN change + rollback ──> CHANGE WINDOW ──> VERIFY ──> rollback if regressed
always safe write down the undo out-of-band access prove it cheap because planned
- Read-only / diagnose — show commands, counters, logs,
uc inspect, a canary probe, a config review. Run freely, anytime, in production. This is where triage starts and usually ends. - Change / mutate — a config line pushed, a firewall or ACL or VLAN rule, a
ucdeploy or scale, a container restart, a VPN route. Requires: a known rollback, a maintenance window, and secured console / out-of-band access before you touch anything.