# 0024 — Deploy skills: write-ci-pipeline, write-deployment-config, write-ai-review-workflow, deployment-checklist **Type:** HITL **Parent PRD:** `docs/prd/chunk-3-skills-library.md` ## What to build The 4 deploy phase skills. All are new. Authored via `write-skill` (0018), evals via `write-eval` (0017). **Skills and trigger descriptions:** | Flat name | Trigger description | |---|---| | `write-ci-pipeline` | Write CI pipeline, create Gitea Actions workflow | | `write-deployment-config` | Write deployment config, Docker Compose, K8s manifest | | `write-ai-review-workflow` | Create AI review workflow, automated PR review | | `deployment-checklist` | Pre-deployment checklist, ready to deploy, deployment validation | **Key constraints per skill:** - `write-ci-pipeline`: targets Gitea Actions YAML; includes secret scan, dependency scan, licence scan, test, and build steps by default - `write-deployment-config`: pinned image/provider versions; resource limits on all K8s resources; no hardcoded secrets; secrets via env vars - `write-ai-review-workflow`: calls AI API via script; posts findings via Gitea API; never auto-merges; human remains in the loop - `deployment-checklist`: validates — linked issue exists and is closed or in-progress; secrets scan clean; dependency scan clean; licence scan clean; tests passing; rollback plan documented; `docs/spec/` updated if behaviour changed; which reviewer roles (Architect, Reviewer, Security) have been invoked on this change ## Implementation notes Follow the per-skill workflow defined in `docs/notes/skill-implementation-workflow.md` (produced by issue 0016). **Known upstream sources to review:** - `bmad-method/bmad-method` — BMAD ops/deploy patterns and deployment checklist approach - Search GitHub for open-source Gitea Actions skill examples - Gitea Actions documentation (Gitea-specific CI syntax differences from GitHub Actions) ## Acceptance criteria - [ ] All 4 SKILL.md files exist at `.agents/skills//SKILL.md`; `metadata.category: deploy`; authoring standard met - [ ] `deployment-checklist` includes all listed validation checks, including reviewer role invocation check - [ ] `write-ai-review-workflow` includes explicit constraint that it never auto-merges - [ ] `source:` fields populated for any adopted upstream content - [ ] Each skill has a co-located eval at `.agents/evals/deploy//eval.yaml` via `write-eval` - [ ] `install.sh` deploys all 4 to `~/.agents/skills/` - [ ] **HITL:** human runs behavioral test per skill - [ ] **HITL:** human reviews each SKILL.md and eval before committing - [ ] _(Further criteria to be refined after issue 0016 grill session)_ ## Blocked by - 0016 (per-skill workflow) - 0017 (`write-eval`) - 0018 (`write-skill`)