devops-infra-core

Installation
SKILL.md

DevOps & Infra Core

Shared model for the devops-infra cluster. The container, network, and homelab spokes span very different tools, but they all turn on one decision: is this action read-only, or does it change state? Keep that boundary consistent here so no spoke quietly normalizes a risky change.

1. The decision the whole cluster turns on (the safety boundary)

Every spoke has two paths. The default is read-only; the change path is gated.

DIAGNOSE (read-only)  ──>  PLAN change + rollback  ──>  CHANGE WINDOW  ──>  VERIFY  ──>  rollback if regressed
   always safe              write down the undo        out-of-band access     prove it       cheap because planned
  • Read-only / diagnose — show commands, counters, logs, uc inspect, a canary probe, a config review. Run freely, anytime, in production. This is where triage starts and usually ends.
  • Change / mutate — a config line pushed, a firewall or ACL or VLAN rule, a uc deploy or scale, a container restart, a VPN route. Requires: a known rollback, a maintenance window, and secured console / out-of-band access before you touch anything.
Installs
1
First Seen
Jun 21, 2026