Files
holocron/docs/issues/0024-deploy-skills.md
Defame1297 d98d0dae18 chore: migrate legacy pre-commit hook to .pre-commit-config.yaml
Replaces shell script (.git/hooks/pre-commit.legacy) with ecosystem-managed pre-commit framework:
- gitleaks/gitleaks: secret scanning
- jumanjihouse/pre-commit-hooks: shellcheck wrapper
- pre-commit/pre-commit-hooks: JSON/YAML validation, end-of-file-fixer, trailing-whitespace
- local hooks: SKILL.md frontmatter validation

Uses pinned versions for reproducibility across environments. Includes auto-fixes from hook runs (formatting, trailing whitespace, JSON beautification).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-06-27 18:54:37 +00:00

3.3 KiB

0024 — Deploy skills: write-ci-pipeline, write-deployment-config, write-ai-review-workflow, deployment-checklist

Type: HITL Parent PRD: docs/prd/chunk-3-skills-library.md

What to build

The 4 deploy phase skills. All are new. Authored via write-skill (0018), evals via write-eval (0017).

Skills and trigger descriptions:

Flat name Trigger description
write-ci-pipeline Write CI pipeline, create Gitea Actions workflow
write-deployment-config Write deployment config, Docker Compose, K8s manifest
write-ai-review-workflow Create AI review workflow, automated PR review
deployment-checklist Pre-deployment checklist, ready to deploy, deployment validation

Key constraints per skill:

  • write-ci-pipeline: targets Gitea Actions YAML; includes secret scan, dependency scan, licence scan, test, and build steps by default
  • write-deployment-config: pinned image/provider versions; resource limits on all K8s resources; no hardcoded secrets; secrets via env vars
  • write-ai-review-workflow: calls AI API via script; posts findings via Gitea API; never auto-merges; human remains in the loop
  • deployment-checklist: validates — linked issue exists and is closed or in-progress; secrets scan clean; dependency scan clean; licence scan clean; tests passing; rollback plan documented; docs/spec/ updated if behaviour changed; which reviewer roles (Architect, Reviewer, Security) have been invoked on this change

Implementation notes

Follow the per-skill workflow defined in docs/notes/skill-implementation-workflow.md.

Known upstream sources to review:

  • bmad-method/bmad-method — BMAD ops/deploy patterns and deployment checklist approach
  • Search GitHub for open-source Gitea Actions skill examples
  • Gitea Actions documentation (Gitea-specific CI syntax differences from GitHub Actions)

Acceptance criteria

  • All 4 SKILL.md files exist at .agents/skills/<skill-name>/SKILL.md; metadata.category: deploy; authoring standard met
  • deployment-checklist includes all listed validation checks, including reviewer role invocation check
  • write-ai-review-workflow includes explicit constraint that it never auto-merges
  • source: fields populated for any adopted upstream content
  • Each skill has a co-located eval at .agents/evals/deploy/<skill-name>/eval.yaml via write-eval
  • install.sh deploys all 4 to ~/.agents/skills/
  • HITL: human runs behavioral test per skill
  • HITL: human reviews each SKILL.md and eval before committing
  • Per-skill process followed for all 4 skills: source discovery (sub-agent) → source review with licence/security check (sub-agent) → conflict check against constitution + factory principles (sub-agent) → synthesis grill → co-write iteratively
  • Trigger description for each skill tested against explicit, implicit, and negative queries before body written
  • when: frontmatter field present in all SKILL.md files
  • source: and references: fields correctly populated or absent
  • eval.yaml for each skill contains all 5 required test types
  • Body ≤500 lines for each skill
  • docs/spec/overview.md updated to reflect all 4 skills deployed

Blocked by

  • 0016 (per-skill workflow)
  • 0017 (write-eval)
  • 0018 (write-skill)