Files
holocron/docs/issues/0026-iac-skills.md
Defame1297 9457efff36 docs: Chunk 3 issues 0015-0028 and doc updates
14 issues created covering AGENTS.md refactor prerequisite, skill
implementation workflow grill, bootstrap skills (write-eval, write-skill),
remaining factory skills, and one issue per skill category group through
to chunk closure. All HITL; acceptance criteria for 0017-0028 to be
refined after 0016 grill session.

Doc updates: CONTEXT.md PRD/issue scope clarified (HOW distribution
across architecture-review and issue design notes); ROADMAP.md housekeeping
updated with bootstrap order and issue range; spec/overview.md recent
changes entry added; PRD updated (skills-index: delete → update).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-17 15:18:36 +00:00

2.4 KiB

0026 — IaC skills: write-docker-compose, iac-security-review

Type: HITL
Parent PRD: docs/prd/chunk-3-skills-library.md

What to build

The 2 IaC domain skills scoped for Chunk 3. Both are new. The 5 deferred IaC skills (Ansible, Molecule, Terraform, K8s, Proxmox) are explicitly out of scope. Authored via write-skill (0018), evals via write-eval (0017).

Skills and trigger descriptions:

Flat name Trigger description
write-docker-compose Write Docker Compose, compose stack for X
iac-security-review Security review this IaC, check Terraform/Ansible for issues

Key constraints per skill:

  • write-docker-compose: pinned image versions; secrets via env vars (never hardcoded); healthchecks included on all services
  • iac-security-review: checks — hardcoded secrets, overly permissive access, missing resource limits, unpinned versions, Terraform provisioners (HashiCorp designates these "last resort"; break idempotency), non-idempotent Ansible patterns (shell/command without creates: guards, missing notify, unconditional handlers)

Implementation notes

Follow the per-skill workflow defined in docs/notes/skill-implementation-workflow.md (produced by issue 0016).

Known upstream sources to review:

  • Search GitHub and agentskills.io for open-source Docker Compose and IaC security review skills
  • OWASP IaC security guidance for iac-security-review checklist
  • HashiCorp provisioner documentation (to understand and reference the "last resort" designation)

Acceptance criteria

  • Both SKILL.md files exist at .agents/skills/<skill-name>/SKILL.md; metadata.category: iac; authoring standard met
  • write-docker-compose defaults to pinned versions, env-var secrets, and healthchecks without requiring the user to ask
  • iac-security-review covers all listed check categories; non-idempotent Ansible patterns are explicitly enumerated
  • source: fields populated for any adopted upstream content
  • Each skill has a co-located eval at .agents/evals/iac/<skill-name>/eval.yaml via write-eval
  • install.sh deploys both to ~/.agents/skills/
  • HITL: human runs behavioral test per skill
  • HITL: human reviews each SKILL.md and eval before committing
  • (Further criteria to be refined after issue 0016 grill session)

Blocked by

  • 0016 (per-skill workflow)
  • 0017 (write-eval)
  • 0018 (write-skill)