mirror of
https://github.com/BagelHole/DevOps-Security-Agent-Skills.git
synced 2026-08-22 12:49:53 +02:00
Add OpenClaw local and Mac mini setup skill
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
---
|
||||
name: cloudflare-pages
|
||||
description: Deploy static sites and full-stack apps on Cloudflare Pages with previews, functions, and custom domains.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Cloudflare Pages
|
||||
|
||||
Deploy frontend projects with preview builds and edge functions.
|
||||
|
||||
## Connect Project
|
||||
|
||||
1. Create a Pages project in Cloudflare dashboard.
|
||||
2. Link your GitHub repository.
|
||||
3. Set build command and output directory.
|
||||
4. Configure environment variables per environment.
|
||||
|
||||
## Wrangler-Based Deploy
|
||||
|
||||
```bash
|
||||
npm install -D wrangler
|
||||
npx wrangler pages project create my-site
|
||||
npx wrangler pages deploy dist --project-name=my-site
|
||||
```
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Require previews for pull requests.
|
||||
- Separate production and preview secrets.
|
||||
- Enable Web Analytics for performance visibility.
|
||||
- Add Cloudflare WAF rules for abuse protection.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [cloudflare-workers](../cloudflare-workers/) - Edge backend logic
|
||||
- [vercel-deployments](../../platforms/vercel-deployments/) - Alternative frontend hosting
|
||||
@@ -0,0 +1,42 @@
|
||||
---
|
||||
name: cloudflare-r2
|
||||
description: Manage Cloudflare R2 buckets, lifecycle, and signed URLs. Use for low-egress object storage and media delivery.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Cloudflare R2
|
||||
|
||||
Use S3-compatible object storage without egress fees.
|
||||
|
||||
## Setup
|
||||
|
||||
```bash
|
||||
# Create bucket
|
||||
npx wrangler r2 bucket create app-assets
|
||||
|
||||
# List buckets
|
||||
npx wrangler r2 bucket list
|
||||
|
||||
# Upload object
|
||||
npx wrangler r2 object put app-assets/logo.png --file ./logo.png
|
||||
```
|
||||
|
||||
## S3-Compatible Access
|
||||
|
||||
- Generate R2 API tokens with least privilege.
|
||||
- Use endpoint format: `https://<accountid>.r2.cloudflarestorage.com`.
|
||||
- Configure lifecycle rules for archive/delete.
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Use short-lived signed URLs for private content.
|
||||
- Store user uploads in tenant-specific prefixes.
|
||||
- Enable object versioning for recovery-critical buckets.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [cloudflare-workers](../cloudflare-workers/) - Signed URL generation
|
||||
- [object-storage](../../storage/object-storage/) - Storage patterns
|
||||
@@ -0,0 +1,46 @@
|
||||
---
|
||||
name: cloudflare-workers
|
||||
description: Build and deploy edge functions with Cloudflare Workers and Wrangler. Use for APIs, cron jobs, and edge middleware.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Cloudflare Workers
|
||||
|
||||
Deploy JavaScript/TypeScript functions globally at the edge.
|
||||
|
||||
## Quick Start
|
||||
|
||||
```bash
|
||||
npm create cloudflare@latest my-worker
|
||||
cd my-worker
|
||||
npx wrangler login
|
||||
npx wrangler deploy
|
||||
```
|
||||
|
||||
## Common Commands
|
||||
|
||||
```bash
|
||||
# Local dev
|
||||
npx wrangler dev
|
||||
|
||||
# Set secret
|
||||
npx wrangler secret put API_TOKEN
|
||||
|
||||
# Tail logs
|
||||
npx wrangler tail
|
||||
```
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Keep workers stateless and fast.
|
||||
- Use KV, D1, or R2 for persistence.
|
||||
- Add rate limits for public APIs.
|
||||
- Version Wrangler config in git.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [cloudflare-pages](../cloudflare-pages/) - Frontend deployments
|
||||
- [cloudflare-r2](../cloudflare-r2/) - Object storage at the edge
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
name: cloudflare-zero-trust
|
||||
description: Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Cloudflare Zero Trust
|
||||
|
||||
Secure access to internal services without exposing public VPN endpoints.
|
||||
|
||||
## Core Workflow
|
||||
|
||||
1. Register application in Cloudflare Access.
|
||||
2. Integrate identity provider (Google Workspace, Okta, Entra ID).
|
||||
3. Define access policies by group, email domain, and device posture.
|
||||
4. Add logging and alerts for blocked requests.
|
||||
|
||||
## Tunnel Setup
|
||||
|
||||
```bash
|
||||
cloudflared tunnel login
|
||||
cloudflared tunnel create internal-app
|
||||
cloudflared tunnel route dns internal-app app.example.com
|
||||
cloudflared tunnel run internal-app
|
||||
```
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Enforce MFA and managed-device posture checks.
|
||||
- Use service tokens for CI/CD automation.
|
||||
- Review app policies quarterly.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [zero-trust](../../../security/network/zero-trust/) - Zero trust architecture fundamentals
|
||||
- [dns-management](../../networking/dns-management/) - DNS routing concepts
|
||||
@@ -0,0 +1,31 @@
|
||||
---
|
||||
name: planetscale
|
||||
description: Operate MySQL-compatible databases on PlanetScale with branching workflows, safe migrations, and production rollouts.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# PlanetScale
|
||||
|
||||
Use PlanetScale for serverless MySQL with non-blocking schema change workflows.
|
||||
|
||||
## Branching Workflow
|
||||
|
||||
1. Create a database branch for schema work.
|
||||
2. Apply migrations to the branch.
|
||||
3. Open a deploy request and run checks.
|
||||
4. Merge to production during low-risk windows.
|
||||
|
||||
## Operational Best Practices
|
||||
|
||||
- Keep schema changes backward compatible first.
|
||||
- Use connection pooling for serverless apps.
|
||||
- Monitor query insights for slow statements.
|
||||
- Define rollback strategy for every deploy request.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [mysql](../mysql/) - MySQL tuning fundamentals
|
||||
- [database-backups](../database-backups/) - Recovery planning
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
name: startup-it-troubleshooting
|
||||
description: Practical IT troubleshooting playbooks for small teams without dedicated IT staff.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Startup IT Troubleshooting
|
||||
|
||||
Run lightweight IT operations for startups and small teams.
|
||||
|
||||
## Priority Triage Order
|
||||
|
||||
1. Company-wide outages (internet, SSO, email)
|
||||
2. Executive or customer-facing blockers
|
||||
3. Team-wide performance degradations
|
||||
4. Individual workstation issues
|
||||
|
||||
## Common Fix Playbooks
|
||||
|
||||
- Identity and access lockouts
|
||||
- VPN and Wi-Fi reliability issues
|
||||
- Laptop disk and memory pressure
|
||||
- Endpoint patching and update failures
|
||||
- Printer and conferencing room failures
|
||||
|
||||
## Process Best Practices
|
||||
|
||||
- Keep an internal runbook and known-issues log.
|
||||
- Standardize onboarding/offboarding checklists.
|
||||
- Track asset ownership and warranty windows.
|
||||
- Escalate recurring incidents into root-cause fixes.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [incident-management](../../../compliance/continuity/incident-management/) - Structured incident handling
|
||||
- [runbook-creation](../../../compliance/continuity/runbook-creation/) - Documentation standards
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
name: mac-mini-llm-lab
|
||||
description: Configure a Mac mini as a reliable local LLM server with remote access, observability, and power-safe operation.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Mac mini LLM Lab
|
||||
|
||||
Turn a Mac mini into a low-noise, always-on local AI appliance.
|
||||
|
||||
## System Setup
|
||||
|
||||
1. Update macOS and Xcode command line tools.
|
||||
2. Install Homebrew and core packages (`tmux`, `htop`, `ollama`).
|
||||
3. Enable automatic login and restart-after-power-failure.
|
||||
4. Configure Tailscale or WireGuard for remote access.
|
||||
|
||||
## Reliability Checklist
|
||||
|
||||
- Keep device on wired Ethernet.
|
||||
- Use UPS for power protection.
|
||||
- Schedule weekly reboot window.
|
||||
- Add launchd service for Ollama auto-start.
|
||||
|
||||
## Security Checklist
|
||||
|
||||
- Disable unnecessary sharing services.
|
||||
- Enforce FileVault and strong local admin password.
|
||||
- Restrict SSH to key-based auth only.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [ollama-stack](../ollama-stack/) - Local inference software stack
|
||||
- [ssh-configuration](../../servers/ssh-configuration/) - Secure remote shell access
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
name: ollama-stack
|
||||
description: Run local LLM workloads with Ollama, Open WebUI, and GPU-aware tuning for private development environments.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Ollama Stack
|
||||
|
||||
Deploy a local LLM stack for offline and privacy-first workflows.
|
||||
|
||||
## Minimal Setup
|
||||
|
||||
```bash
|
||||
curl -fsSL https://ollama.com/install.sh | sh
|
||||
ollama serve
|
||||
ollama pull llama3.1:8b
|
||||
ollama run llama3.1:8b
|
||||
```
|
||||
|
||||
## Docker Compose Pattern
|
||||
|
||||
- Ollama container with persistent model volume
|
||||
- Open WebUI for chat interface
|
||||
- Optional LiteLLM proxy for unified API routing
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Pin model versions for reproducibility.
|
||||
- Monitor VRAM, RAM, and swap utilization.
|
||||
- Restrict network exposure to trusted subnets.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [mac-mini-llm-lab](../mac-mini-llm-lab/) - Apple Silicon optimization
|
||||
- [docker-compose](../../../devops/containers/docker-compose/) - Service orchestration
|
||||
@@ -0,0 +1,74 @@
|
||||
---
|
||||
name: openclaw-local-mac-mini
|
||||
description: Set up OpenClaw locally and run it reliably on a Mac mini for private, always-on local agent workflows.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# OpenClaw Local + Mac mini Setup
|
||||
|
||||
Use this skill when you want to run [OpenClaw](https://github.com/openclaw/openclaw) on a developer laptop or promote it to a stable Mac mini host.
|
||||
|
||||
## Local Setup (any modern dev machine)
|
||||
|
||||
1. Clone and enter repository.
|
||||
2. Follow upstream prerequisites from OpenClaw README (runtime, package manager, model/provider requirements).
|
||||
3. Create a local environment file from the example and configure keys/endpoints.
|
||||
4. Install dependencies and run the development command.
|
||||
5. Validate startup by loading the local UI/API health endpoint.
|
||||
|
||||
```bash
|
||||
git clone https://github.com/openclaw/openclaw.git
|
||||
cd openclaw
|
||||
# Follow upstream bootstrap steps in repo docs
|
||||
# cp .env.example .env
|
||||
# <install deps>
|
||||
# <run dev server>
|
||||
```
|
||||
|
||||
## Mac mini Production-ish Setup
|
||||
|
||||
### Host baseline
|
||||
|
||||
- Keep macOS updated and enable automatic security updates.
|
||||
- Use wired Ethernet and a UPS for stability.
|
||||
- Enable FileVault and lock down local admin access.
|
||||
- Configure Tailscale or WireGuard for secure remote admin.
|
||||
|
||||
### Service operation
|
||||
|
||||
- Run OpenClaw in a dedicated user account.
|
||||
- Store secrets in macOS Keychain or a managed secret store (avoid plain-text files in shared folders).
|
||||
- Use `tmux` for manual operation or `launchd` for auto-start on reboot.
|
||||
- Keep logs rotated and monitor disk usage.
|
||||
|
||||
### launchd pattern (example)
|
||||
|
||||
Create `/Library/LaunchDaemons/com.openclaw.service.plist` to run startup command from the OpenClaw directory, then:
|
||||
|
||||
```bash
|
||||
sudo launchctl load -w /Library/LaunchDaemons/com.openclaw.service.plist
|
||||
sudo launchctl list | rg openclaw
|
||||
```
|
||||
|
||||
## Validation Checklist
|
||||
|
||||
- App starts after reboot without manual intervention.
|
||||
- Health check succeeds from local network.
|
||||
- Secrets are not committed and not world-readable.
|
||||
- Access to admin interfaces is restricted to trusted users/devices.
|
||||
|
||||
## Troubleshooting Quick Hits
|
||||
|
||||
- Slow responses: verify model backend availability and local RAM/CPU pressure.
|
||||
- Boot failures: inspect launchd logs and working directory paths.
|
||||
- Auth errors: re-check provider keys, scopes, and endpoint URLs.
|
||||
- Random crashes: pin dependency versions and restart with clean environment.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [ollama-stack](../ollama-stack/) - Local model serving patterns
|
||||
- [mac-mini-llm-lab](../mac-mini-llm-lab/) - Mac mini reliability and security baseline
|
||||
- [startup-it-troubleshooting](../../it/startup-it-troubleshooting/) - Small-team operational triage
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
name: convex-backend
|
||||
description: Build reactive backends with Convex functions, schema validation, auth integration, and deployment workflows.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Convex Backend
|
||||
|
||||
Use Convex to build type-safe backend logic with realtime data sync.
|
||||
|
||||
## Quick Start
|
||||
|
||||
```bash
|
||||
npm install convex
|
||||
npx convex dev
|
||||
npx convex deploy
|
||||
```
|
||||
|
||||
## Implementation Tips
|
||||
|
||||
- Define schema and validation before writing functions.
|
||||
- Keep mutations idempotent where possible.
|
||||
- Use auth identity checks in every privileged query/mutation.
|
||||
- Add indexing early for high-read collections.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [firebase-app-platform](../firebase-app-platform/) - Alternative managed backend
|
||||
- [agent-observability](../../../devops/ai/agent-observability/) - Instrument AI-driven backend flows
|
||||
@@ -0,0 +1,33 @@
|
||||
---
|
||||
name: firebase-app-platform
|
||||
description: Build and operate apps on Firebase using Auth, Firestore, Cloud Functions, and Hosting.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Firebase App Platform
|
||||
|
||||
Ship mobile and web backends with Firebase managed services.
|
||||
|
||||
## Core Setup
|
||||
|
||||
```bash
|
||||
npm install -g firebase-tools
|
||||
firebase login
|
||||
firebase init
|
||||
firebase deploy
|
||||
```
|
||||
|
||||
## Security and Scale
|
||||
|
||||
- Write strict Firestore security rules first.
|
||||
- Separate environments by Firebase project.
|
||||
- Enable budget alerts and quota monitoring.
|
||||
- Move privileged logic into Cloud Functions.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [gcp-cloud-functions](../../cloud-gcp/gcp-cloud-functions/) - Function runtime patterns
|
||||
- [vercel-deployments](../vercel-deployments/) - Frontend deployment option
|
||||
@@ -0,0 +1,34 @@
|
||||
---
|
||||
name: vercel-deployments
|
||||
description: Deploy frontend and full-stack apps on Vercel with previews, edge functions, and environment promotion.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# Vercel Deployments
|
||||
|
||||
Ship web apps quickly with preview environments and managed edge infrastructure.
|
||||
|
||||
## Core Workflow
|
||||
|
||||
```bash
|
||||
npm i -g vercel
|
||||
vercel login
|
||||
vercel link
|
||||
vercel
|
||||
vercel --prod
|
||||
```
|
||||
|
||||
## Production Guardrails
|
||||
|
||||
- Require preview checks before merge.
|
||||
- Separate preview and production environment variables.
|
||||
- Use branch protection with required deployment status.
|
||||
- Monitor function duration and cold start behavior.
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [github-actions](../../../devops/ci-cd/github-actions/) - Automated deployment gates
|
||||
- [cloudflare-pages](../../cloudflare/cloudflare-pages/) - Alternative edge hosting
|
||||
Reference in New Issue
Block a user