BagelHole/DevOps-Security-Agent-Skills
这个仓库里有 163 个技能,GitHub 星标 ★ 1,096。
- audit-loggingImplement centralized audit logging and SIEM integration. Configure log retentio
- aws-cloudtrailConfigure AWS CloudTrail for audit logging. Set up organization trails and event
- azure-monitor-auditConfigure Azure Monitor and Activity Log for auditing. Set up diagnostic setting
- gcp-audit-logsConfigure GCP Cloud Audit Logs for compliance. Set up log routing and BigQuery a
- business-continuityDevelop business continuity plans and impact analysis. Implement BCP testing and
- disaster-recoveryImplement disaster recovery strategies and runbooks. Configure RPO/RTO targets a
- incident-managementImplement incident management processes and escalation procedures. Configure on-
- runbook-creationCreate operational runbooks and standard operating procedures. Document troubles
- fedramp-complianceImplement FedRAMP requirements for federal cloud services. Configure NIST 800-53
- gdpr-complianceImplement GDPR data protection requirements. Configure consent management, data
- hipaa-complianceImplement HIPAA security and privacy rules. Configure PHI protections and BAA re
- iso27001-complianceImplement ISO 27001 Information Security Management System. Configure ISMS contr
- pci-dss-complianceImplement PCI DSS requirements for payment card data. Configure cardholder data
- soc2-complianceImplement SOC 2 Trust Services Criteria. Configure security, availability, and p
- access-reviewConduct periodic access reviews and certifications. Implement access governance
- asset-inventoryMaintain IT asset inventory and configuration management database. Track hardwar
- change-managementImplement change management processes. Configure CAB reviews, change windows, an
- policy-as-codeImplement policy as code with OPA, Sentinel, and Kyverno. Automate policy enforc
- vendor-managementImplement vendor risk management programs. Assess third-party security and maint
- agent-evalsBuild automated evaluation suites for AI agents using golden datasets, rubrics,
- agent-observabilityInstrument AI agents with tracing, token metrics, latency, and cost visibility.
- ai-pipeline-orchestrationOrchestrate AI/ML pipelines for data ingestion, model training, batch inference,
- ai-sre-incident-responseBuild AI-focused SRE incident response practices for LLM outages, degraded quali
- llm-cachingImplement multi-layer LLM caching with exact match, semantic similarity, and pro
- llm-cost-optimizationReduce LLM API and infrastructure costs through model selection, prompt caching,
- llmops-platform-engineeringBuild production LLMOps platforms with CI/CD, model promotion workflows, evaluat
- model-registry-governanceEstablish model registry standards, governance controls, metadata schemas, appro
- rag-observability-evalsMonitor and evaluate RAG systems with retrieval quality metrics, groundedness ch
- azure-devopsSet up Azure Pipelines for CI/CD, configure build and release pipelines, manage
- circleciConfigure CircleCI workflows and orbs for continuous integration and deployment.
- github-actionsBuild, test, and deploy applications using GitHub Actions workflows. Create CI/C
- gitlab-ciConfigure GitLab CI/CD pipelines and runners for automated building, testing, an
- jenkinsCreate and manage Jenkins CI/CD pipelines, configure agents, manage plugins, and
- container-registriesManage container registries including ECR, ACR, GCR, and Docker Hub. Push and pu
- docker-composeDefine and run multi-container Docker applications using Docker Compose. Create
- docker-managementBuild, optimize, and troubleshoot Docker containers and images. Create efficient
- podmanManage containers using Podman, the daemonless container engine. Run rootless co
- devcontainers-nixCreate reproducible development environments with Dev Containers, Nix flakes, an
- alerting-oncallSet up alerting rules, configure on-call rotations, and manage incident response
- datadogImplement Datadog monitoring and APM for infrastructure and applications. Config
- ebpf-observabilityUse eBPF for deep kernel-level observability — trace syscalls, network flows, an
- elk-stackDeploy and manage the ELK Stack (Elasticsearch, Logstash, Kibana) for log aggreg
- loki-loggingConfigure Grafana Loki for log aggregation and analysis. Set up Promtail for log
- new-relicConfigure New Relic observability platform for infrastructure and application mo
- opentelemetryInstrument applications and infrastructure with OpenTelemetry for unified traces
- prometheus-grafanaSet up metrics collection and visualization with Prometheus and Grafana. Configu
- sre-dashboardsDesign and operationalize SRE dashboards that surface reliability, latency, erro
- argocd-gitopsImplement GitOps with ArgoCD for declarative Kubernetes deployments. Configure a
- helm-chartsCreate, manage, and deploy Helm charts for Kubernetes package management. Build
- kubernetes-opsDeploy, scale, and manage Kubernetes workloads. Create deployments, services, an
- kustomizeCustomize Kubernetes manifests without templating using Kustomize. Create base c
- model-serving-kubernetesDeploy ML models on Kubernetes with KServe (formerly KFServing) and NVIDIA Trito
- openshiftManage Red Hat OpenShift clusters and deployments. Configure projects, routes, b
- platform-engineeringBuild internal developer platforms (IDPs) with self-service infrastructure, gold
- blue-green-deployConfigure zero-downtime deployment strategies including blue-green, canary, and
- feature-flagsImplement feature flags for progressive feature rollout using LaunchDarkly, Unle
- git-workflowImplement Git branching strategies, PR workflows, and release management pattern
- semantic-versioningAutomate versioning and changelog generation using semantic versioning principle
- aws-cost-optimizationReduce AWS spend with rightsizing, autoscaling, commitment planning, and storage
- aws-ec2Manage EC2 instances, AMIs, and auto-scaling groups. Configure security groups,
- aws-ecs-fargateDeploy containers on ECS and Fargate. Configure task definitions, services, and
- aws-iamManage IAM users, roles, and policies. Implement least-privilege access and secu
- aws-lambdaBuild and deploy serverless functions on AWS Lambda. Configure triggers, manage
- aws-rdsProvision and manage RDS databases. Configure backups, replication, and security
- aws-s3Configure S3 buckets, policies, and lifecycle rules. Implement versioning, repli
- aws-vpcDesign and implement VPCs and networking. Configure subnets, route tables, and s
- cloudformationDeploy AWS resources with CloudFormation templates. Create stacks, use nested st
- terraform-awsProvision AWS infrastructure with Terraform. Create modules, manage state, and i
- arm-templatesDeploy Azure resources with ARM templates and Bicep. Create modular deployments
- azure-aksDeploy and manage Azure Kubernetes Service clusters. Configure node pools, netwo
- azure-functionsBuild serverless applications on Azure Functions. Configure triggers, bindings,
- azure-networkingConfigure Azure VNets, NSGs, and Azure Firewall. Implement hub-spoke topology an
- azure-sqlProvision Azure SQL Database and Cosmos DB. Configure security, backups, and rep
- azure-vmsManage Azure Virtual Machines and scale sets. Configure availability sets and ma
- terraform-azureProvision Azure infrastructure with Terraform. Configure providers, manage state
- gcp-cloud-functionsDeploy serverless functions on Google Cloud Functions. Configure triggers and ma
- gcp-cloud-sqlProvision Cloud SQL and Spanner databases. Configure high availability, backups,
- gcp-computeManage Compute Engine instances and instance templates. Configure managed instan
- gcp-gkeDeploy and manage Google Kubernetes Engine clusters. Configure node pools, netwo
- gcp-networkingConfigure VPCs, firewall rules, and Cloud NAT. Implement shared VPC and private
- terraform-gcpProvision GCP infrastructure with Terraform. Configure providers and deploy Goog
- cloudflare-pagesDeploy static sites and full-stack apps on Cloudflare Pages with previews, funct
- cloudflare-r2Manage Cloudflare R2 buckets, lifecycle, and signed URLs. Use for low-egress obj
- cloudflare-workersBuild and deploy edge functions with Cloudflare Workers and Wrangler. Use for AP
- cloudflare-zero-trustProtect internal apps with Cloudflare Access, device posture, and Zero Trust pol
- database-backupsImplement database backup strategies. Configure automated backups, retention, an
- mongodbAdminister MongoDB databases. Configure replica sets, sharding, and backups. Use
- mysqlAdminister MySQL/MariaDB databases. Configure replication and optimize performan
- planetscaleOperate MySQL-compatible databases on PlanetScale with branching workflows, safe
- postgresqlAdminister PostgreSQL databases. Configure replication, backups, and performance
- redisConfigure Redis for caching and data storage. Set up clustering, persistence, an
- vector-database-opsDeploy, manage, and optimize vector databases for AI applications. Covers Qdrant
- opentofu-migrationMigrate from Terraform to OpenTofu with state compatibility, provider registry s
- identity-access-managementSet up and manage SSO, SCIM provisioning, and MFA for startup teams using Google
- mdm-device-managementManage and secure company devices with MDM solutions — enroll macOS, Windows, iO
- saas-security-postureAudit and harden your SaaS tool stack — enforce SSO, review OAuth grants, manage
- startup-it-troubleshootingPractical IT troubleshooting playbooks for small teams without dedicated IT staf
- gpu-kubernetes-operationsOperate GPU-backed Kubernetes clusters for AI inference and training with schedu
- llm-fine-tuningSet up infrastructure for fine-tuning LLMs with QLoRA, LoRA, and full fine-tunin
- llm-inference-scalingAuto-scale LLM inference clusters on Kubernetes using KEDA, custom GPU metrics,
- mac-mini-llm-labConfigure a Mac mini as a reliable local LLM server with remote access, observab
- multi-tenant-llm-hostingDesign secure, multi-tenant LLM hosting platforms with tenant isolation, quotas,
- ollama-stackRun local LLM workloads with Ollama, Open WebUI, and GPU-aware tuning for privat
- openclaw-local-mac-miniSet up OpenClaw locally and run it reliably on a Mac mini for private, always-on
- openclaw-security-hardeningHarden OpenClaw self-hosted environments with baseline host controls, auth tight
- rag-infrastructureBuild and operate Retrieval-Augmented Generation (RAG) infrastructure with vecto
- vllm-serverDeploy and manage vLLM for high-throughput LLM inference. Configure continuous b
- ai-inference-service-meshUse service mesh patterns for AI inference traffic management, mTLS, canary rele
- cdn-setupConfigure CDNs for content delivery. Set up CloudFront, Cloudflare, and Fastly.
- dns-managementConfigure DNS zones and records. Manage Route53, Cloud DNS, and self-hosted DNS.
- llm-gatewayDeploy an API gateway for LLM traffic with load balancing, rate limiting, key ma
- load-balancingConfigure load balancers and traffic distribution. Implement health checks and S
- reverse-proxyConfigure nginx and Traefik as reverse proxies. Implement SSL termination and ro
- service-meshImplement Istio and Linkerd service meshes. Configure mTLS, traffic management,
- convex-backendBuild reactive backends with Convex functions, schema validation, auth integrati
- firebase-app-platformBuild and operate apps on Firebase using Auth, Firestore, Cloud Functions, and H
- vercel-deploymentsDeploy frontend and full-stack apps on Vercel with previews, edge functions, env
- gpu-server-managementSet up and manage NVIDIA GPU servers for AI workloads — driver installation, CUD
- linux-administrationSystem administration for Linux servers. Manage packages, services, and system c
- performance-tuningOptimize Linux system performance. Configure kernel parameters, analyze bottlene
- ssh-configurationConfigure SSH servers and clients securely. Manage keys, tunnels, and config fil
- systemd-servicesCreate and manage systemd services and timers. Configure service dependencies an
- user-managementManage users, groups, and permissions on Linux systems. Configure sudo and acces
- windows-serverAdminister Windows Server systems. Manage IIS, Active Directory, and PowerShell
- backup-recoveryImplement backup and recovery strategies. Configure rsync, Restic, and cloud bac
- block-storageManage block storage volumes and LVM. Configure cloud block storage and local di
- nfs-storageConfigure NFS servers and clients. Implement network file sharing for Linux syst
- object-storageConfigure object storage with S3, GCS, and MinIO. Implement lifecycle policies a
- ai-agent-securitySecure AI agents against prompt injection, tool abuse, and data exfiltration wit
- ai-coding-agent-guardrailsSecure AI coding agents (Claude Code, Cursor, Codex, Copilot) with permission bo
- ai-red-teamingRun structured AI red team exercises for jailbreak resistance, data exfiltration
- ai-security-hardeningHarden AI/LLM deployments against prompt injection, data exfiltration, model the
- llm-app-securitySecure LLM-powered applications with input validation, output controls, tenant i
- mcp-server-securitySecure Model Context Protocol (MCP) servers with transport encryption, tool auth
- model-supply-chain-securitySecure the AI model supply chain with artifact signing, provenance attestation,
- prompt-injection-defenseDefend AI systems against prompt injection and indirect prompt attacks using inp
- cis-benchmarksAudit and remediate CIS benchmark violations. Use automated tools to assess comp
- container-hardeningSecure Docker images and container runtime configurations. Implement non-root us
- kubernetes-hardeningImplement Kubernetes security contexts, Pod Security Standards, and network poli
- linux-hardeningApply CIS benchmarks and secure Linux servers. Configure SSH, manage users, impl
- openclaw-deployment-hardeningSecure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, c
- windows-hardeningHarden Windows servers per security baselines and CIS benchmarks. Configure Grou
- firewall-configConfigure iptables, nftables, and cloud firewalls. Implement network segmentatio
- ssl-tls-managementManage SSL/TLS certificates with Let's Encrypt and internal PKI. Configure secur
- vpn-setupConfigure WireGuard, OpenVPN, and cloud VPNs. Implement secure remote access and
- waf-setupDeploy and tune Web Application Firewalls. Configure rules for OWASP Top 10 prot
- zero-trustImplement zero-trust network architecture. Configure identity-based access, micr
- incident-responseHandle security incidents with IR playbooks and procedures. Implement detection,
- penetration-testingPerform basic penetration testing and security assessments. Use reconnaissance,
- security-automationAutomate security workflows and remediation. Build security pipelines, automate
- threat-modelingConduct threat modeling using STRIDE methodology. Identify threats, assess risks
- container-scanningScan container images for vulnerabilities using Trivy, Grype, and cloud-native t
- dast-scanningPerform dynamic application security testing with OWASP ZAP, Burp Suite, and Nik
- dependency-scanningScan package dependencies for known vulnerabilities using Snyk, Dependabot, and
- sast-scanningPerform static application security testing with tools like Semgrep, CodeQL, and
- sbom-supply-chainGenerate, sign, and verify SBOMs and provenance attestations to secure the softw
- supply-chain-attack-responseDetect, respond to, and prevent software supply chain attacks on package registr
- vulnerability-scanningScan systems and dependencies for CVEs and security vulnerabilities. Use tools l
- aws-secrets-managerStore and rotate secrets in AWS Secrets Manager. Configure automatic rotation, a
- azure-keyvaultManage secrets and certificates in Azure Key Vault. Configure access policies, i
- gcp-secret-managerSecure secrets in Google Cloud Secret Manager. Configure IAM policies, integrate
- hashicorp-vaultManage secrets and PKI with HashiCorp Vault. Configure secret engines, authentic
- sops-encryptionEncrypt files and configs with Mozilla SOPS. Integrate with AWS KMS, GCP KMS, or
想一次拿到这个仓库的全部技能?
本站把开放许可(MIT / Apache 等)的仓库按整仓打包整理到网盘,点一下转存到你自己的网盘。许可未声明的仓库只给原始仓库链接,不打包。