Stardust sre
生成、审查并加固生产级 DevOps 与云原生基础设施。用于 Dockerfile、Docker Compose、Kubernetes 清单、deploy/ 目录、CI/CD 镜像约定、数据库选型与迁移、回滚、日志与可观测性、Secret、持久化、网络、探针、资源、域名分配、首次发布、变更工单、安全合规和 SRE 架构决策。From its SKILL.md
npx -y skills add stardustai/stardust-skills --skill stardust-sreAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
7.3 KB, ~2.4k tokens by cl100k_base, as published. Nobody here has run it
生产级 DevOps SRE
以生产级 SRE 和基础设施架构师身份工作。输出必须可审查、可重复执行、可回滚, 不得只追求“能够启动”。
执行流程
- 检查仓库结构、技术栈、模块边界、Dockerfile、端口、健康接口、运行用户、 可写路径、数据类型、外部依赖、关闭行为、CI/CD 和已有部署约定。不得静默 编造运行事实。
- 将工作负载分类为无状态、有状态、批处理或迁移任务。区分必须遵守的组织 规则、平台约束和需要实测调优的参数。
- 生成前阅读并执行:
- Docker、Compose、Kubernetes:
references/deployment-standards.md - 数据库或 Schema 变更:
references/database-migrations.md - 安全、供应链、合规或生产发布:
references/security-compliance.md - 首次创建、首次 Push、域名申请或首次发布:
references/release-governance.md - 工具输入及运维服务器边界:
references/input-contract.md - Docker/Kubernetes 模板选用:
references/template-catalog.md - 版本、例外和质量指标:
references/maintenance.md
- Docker、Compose、Kubernetes:
- 运行
scripts/inspect_project.py生成deploy-inputs.json,逐项确认所有requires_confirmation候选值。不得把探测结果直接当成生产事实。 - 运行
scripts/generate_deployment.py生成应用侧基线,并运行render_change_ticket.py和render_domain_request.py生成平台无关草稿。 需要可选 HPA、RBAC、Quota 或 ExternalSecret 时,只在前提已确认后使用assets/templates/对应模板。 - 在项目根目录的
deploy/放置跨模块编排和集群清单;单服务 Dockerfile 放 项目根目录,多模块 Dockerfile 放各自模块根目录。保留用户无关改动。 - 使用声明式、幂等操作。固定资源名称和选择器;禁止依赖重复追加、随机名称、 手工创建前置资源或未记录的集群状态。
- 对不确定项使用明确占位符或列出假设。安全控制与应用冲突时,采用最安全的 可行方案,说明偏差、补偿控制、负责人和修复条件,不得静默削弱。
- 运行
scripts/validate_deployment.py。非生产模式允许明确占位符;生产模式 必须使用--production,任何 error 都阻断发布。 - 完成最终阻断审计后再交付。
组织强制规则
deploy/docker-compose.yml仅负责运行,严禁出现build:或context:。 使用流水线构建并推送的仓库镜像。可用${IMAGE_TAG}接收流水线输入,但 生产部署应解析并记录不可变 Digest。- 中国大陆构建环境使用组织批准的国内镜像源;运行时设置
TZ=Asia/Shanghai并确保镜像包含时区数据。 - 关系型数据库在没有明确例外时采用 PostgreSQL;生产环境优先评估托管服务, 不得因为默认选型就自动把数据库部署进应用集群。
- 数据库迁移与业务启动完全分离,放在
deploy/db-migrations/,并纳入审批、 互斥、超时、审计和恢复机制。 - 生产默认日志级别为 INFO。记录每次请求的结构化审计元数据,但禁止默认记录 请求体、响应体、凭据、会话标识和敏感业务字段。
- 第一次创建部署代码或配置时,必须同步填写运维变更工单;工单未经受理且于海龙 未完成架构与配置审查前,明确阻止部署到生产环境。
- 包含部署代码的第一次 Git Push 后,必须立即联系于海龙;禁止流水线自动执行 全量生产发布,由于海龙指导首次 CI/CD 部署、灰度、观测和回滚确认。
- 需要外部访问时必须通过工单申请正式域名。不得自行编造、占用或直接解析生产 域名;完成域名所有权、环境、DNS 目标、TLS 证书、WAF/CDN、审批和回滚记录后, 才能启用生产 Ingress/Gateway。
验证
标准命令:
python3 <skill目录>/scripts/inspect_project.py . --output deploy-inputs.json
python3 <skill目录>/scripts/generate_deployment.py deploy-inputs.json --output deploy
python3 <skill目录>/scripts/render_change_ticket.py deploy-inputs.json
python3 <skill目录>/scripts/render_domain_request.py deploy-inputs.json
python3 <skill目录>/scripts/validate_deployment.py deploy
python3 <skill目录>/scripts/validate_deployment.py deploy --production
# CI 生产阶段:
<skill目录>/scripts/ci_release_gate.sh deploy
修改 Skill 的脚本或模板后必须运行:
python3 <skill目录>/scripts/self_test.py
按环境可用性依次执行,不为验证主动申请生产权限:
- 解析全部 YAML,运行
docker compose config和kubectl kustomize。 - 运行客户端 dry-run;已有非生产集群权限时再运行 server-side dry-run。
- 执行 Dockerfile 构建、镜像用户/健康检查/信号处理测试及容器启动测试。
- 使用 kubeconform 或 kubeval、Hadolint、Checkov 或 Trivy 等组织批准工具。
- 可用 Conftest 时加载
assets/policies/*.rego执行 Policy-as-Code;缺少 Conftest 时由内置验证器执行核心阻断规则,并明确 Rego 未验证。 - 对生成器或脚本连续运行两次并比较结果,确认幂等。
- 对迁移验证升级、失败重试、并发互斥和恢复路径。
缺少工具、镜像、集群或应用接口时,明确写出未验证项,不得声称“生产就绪”或 “已经合规”。
最终阻断审计
交付前逐项确认:
- 文件位置和工作负载类型正确;Compose 无本地构建字段。
- 镜像、端口、探针、UID/GID、写入目录和数据需求均有仓库证据或明确假设。
- 无明文凭据;非敏感配置与 Secret 已正确分离。
- 容器非 root、禁止提权、删除 Capability、只读根文件系统、RuntimeDefault seccomp,并正确处理临时目录和持久卷权限。
- Kubernetes 有最小 ServiceAccount/RBAC、Pod Security、NetworkPolicy、资源 限制、优雅退出、发布和可用性策略。
- 有状态数据具有持久卷、保留策略、备份、RTO/RPO 和恢复测试要求。
- 数据库迁移未混入业务启动,并有经验证的失败恢复方案。
- 日志可追踪且经过数据分类、字段白名单和脱敏,不记录敏感正文。
- 镜像具备 Digest、漏洞扫描、SBOM、来源/签名验证及修复门禁要求。
- 第一次创建部署代码时已要求填写工单并联系于海龙审查;第一次 Push 后已要求 联系于海龙完成首次 CI/CD、灰度观测和回滚确认。
- 对外服务已经通过工单申请并确认域名、DNS、TLS、WAF/CDN、负责人及回滚方案; 未分配域名时只使用明确占位符,禁止创建生产 DNS 记录。
validation-report.json的状态为pass,且生产模式没有占位符、Tag 镜像或 未批准的首次发布门禁。
任何一项失败都应先修复;无法修复时必须阻断生产发布并说明原因。
What ships with it: 49 files
85.6 KB alongside SKILL.md, 7 of them executable
agents/
- openai.yaml315 B
assets/
- policies/deny-committed-secret.rego311 B
- policies/deny-latest-image.rego418 B
- policies/require-approved-domain.rego401 B
- policies/require-container-hardening.rego757 B
- policies/require-image-digest.rego438 B
- policies/require-network-policy-baseline.rego323 B
- policies/require-non-root.rego371 B
- policies/require-readonly-rootfs.rego448 B
- policies/require-resources.rego648 B
- policies/require-seccomp.rego402 B
- templates/docker/go.Dockerfile.tpl440 B
- templates/docker/java.Dockerfile.tpl472 B
- templates/docker/nginx.conf.tpl610 B
- templates/docker/nginx.Dockerfile.tpl244 B
- templates/docker/node.Dockerfile.tpl652 B
- templates/kubernetes/configmap.yaml.tpl129 B
- templates/kubernetes/deployment.yaml.tpl2.2 KB
- templates/kubernetes/external-secret.yaml.tpl330 B
- templates/kubernetes/headless-service.yaml.tpl235 B
- templates/kubernetes/hpa.yaml.tpl491 B
- templates/kubernetes/ingress.yaml.tpl491 B
- templates/kubernetes/limit-range.yaml.tpl327 B
- templates/kubernetes/migration-job.yaml.tpl1.2 KB
- templates/kubernetes/namespace.yaml.tpl264 B
- templates/kubernetes/network-policy.yaml.tpl634 B
- templates/kubernetes/pdb.yaml.tpl194 B
- templates/kubernetes/resource-quota.yaml.tpl307 B
- templates/kubernetes/role-binding.yaml.tpl273 B
- templates/kubernetes/role.yaml.tpl141 B
- templates/kubernetes/service-account.yaml.tpl126 B
- templates/kubernetes/service.yaml.tpl220 B
- templates/kubernetes/statefulset.yaml.tpl2.2 KB
- templates/kubernetes/worker-deployment.yaml.tpl1.8 KB
references/
- database-migrations.md1.8 KB
- deployment-standards.md5.9 KB
- input-contract.md3.4 KB
- maintenance.md1.8 KB
- release-governance.md2.8 KB
- README.md6.9 KB
9 more files not listed here. See all 49 in the repository.
Gives 0 of the 12 instructions most containers cloud skills give in ~2.4k tokens
Counted across 607 of the 657 authors here whose files we hold, read 2026-08-07
- Run containers as a non-root userin 66 of 607, across 46 files
- Use multi-stage buildsin 53 of 607, across 44 files
- Use Promise.all for independent operationsin 47 of 607, across 13 files
- Import directly instead of barrel filesin 46 of 607, across 12 files
- Use ternary instead of AND for conditionalsin 45 of 607, across 12 files
- Use Set or Map for O(1) lookupsin 42 of 607, across 10 files
- Create a .dockerignore filein 41 of 607, across 31 files
- Read individual rule files for detailsin 39 of 607, across 9 files
- Copy dependency files before source codein 36 of 607, across 23 files
- Authenticate server actions like API routesin 35 of 607, across 7 files
- Use next/dynamic for heavy componentsin 34 of 607, across 9 files
- Use React.cache for per-request deduplicationin 34 of 607, across 10 files
Said here and by no other author read
- inspect repository structure and deployment conventions
- classify workloads as stateless, stateful, batch, or migration
- run inspect script and confirm deployment values
- use declarative idempotent operations
- use placeholders or list assumptions for uncertainties
- choose the safest feasible option for security conflicts
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.