14 issues created covering AGENTS.md refactor prerequisite, skill implementation workflow grill, bootstrap skills (write-eval, write-skill), remaining factory skills, and one issue per skill category group through to chunk closure. All HITL; acceptance criteria for 0017-0028 to be refined after 0016 grill session. Doc updates: CONTEXT.md PRD/issue scope clarified (HOW distribution across architecture-review and issue design notes); ROADMAP.md housekeeping updated with bootstrap order and issue range; spec/overview.md recent changes entry added; PRD updated (skills-index: delete → update). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
47 lines
2.4 KiB
Markdown
47 lines
2.4 KiB
Markdown
# 0026 — IaC skills: write-docker-compose, iac-security-review
|
|
|
|
**Type:** HITL
|
|
**Parent PRD:** `docs/prd/chunk-3-skills-library.md`
|
|
|
|
## What to build
|
|
|
|
The 2 IaC domain skills scoped for Chunk 3. Both are new. The 5 deferred IaC skills (Ansible, Molecule, Terraform, K8s, Proxmox) are explicitly out of scope. Authored via `write-skill` (0018), evals via `write-eval` (0017).
|
|
|
|
**Skills and trigger descriptions:**
|
|
|
|
| Flat name | Trigger description |
|
|
|---|---|
|
|
| `write-docker-compose` | Write Docker Compose, compose stack for X |
|
|
| `iac-security-review` | Security review this IaC, check Terraform/Ansible for issues |
|
|
|
|
**Key constraints per skill:**
|
|
- `write-docker-compose`: pinned image versions; secrets via env vars (never hardcoded); healthchecks included on all services
|
|
- `iac-security-review`: checks — hardcoded secrets, overly permissive access, missing resource limits, unpinned versions, Terraform provisioners (HashiCorp designates these "last resort"; break idempotency), non-idempotent Ansible patterns (shell/command without `creates:` guards, missing `notify`, unconditional handlers)
|
|
|
|
## Implementation notes
|
|
|
|
Follow the per-skill workflow defined in `docs/notes/skill-implementation-workflow.md` (produced by issue 0016).
|
|
|
|
**Known upstream sources to review:**
|
|
- Search GitHub and agentskills.io for open-source Docker Compose and IaC security review skills
|
|
- OWASP IaC security guidance for `iac-security-review` checklist
|
|
- HashiCorp provisioner documentation (to understand and reference the "last resort" designation)
|
|
|
|
## Acceptance criteria
|
|
|
|
- [ ] Both SKILL.md files exist at `.agents/skills/<skill-name>/SKILL.md`; `metadata.category: iac`; authoring standard met
|
|
- [ ] `write-docker-compose` defaults to pinned versions, env-var secrets, and healthchecks without requiring the user to ask
|
|
- [ ] `iac-security-review` covers all listed check categories; non-idempotent Ansible patterns are explicitly enumerated
|
|
- [ ] `source:` fields populated for any adopted upstream content
|
|
- [ ] Each skill has a co-located eval at `.agents/evals/iac/<skill-name>/eval.yaml` via `write-eval`
|
|
- [ ] `install.sh` deploys both to `~/.agents/skills/`
|
|
- [ ] **HITL:** human runs behavioral test per skill
|
|
- [ ] **HITL:** human reviews each SKILL.md and eval before committing
|
|
- [ ] _(Further criteria to be refined after issue 0016 grill session)_
|
|
|
|
## Blocked by
|
|
|
|
- 0016 (per-skill workflow)
|
|
- 0017 (`write-eval`)
|
|
- 0018 (`write-skill`)
|