Cloud-ops agent skills¶
skills/ in the repo holds agentskills-style skills that a coding or ops agent (Claude
Code, Cursor, a CI bot) can load to operate Ramen safely. Each skill is a folder with a SKILL.md
(front matter name / description, numbered steps, explicit boundaries).
| Skill | Purpose |
|---|---|
deploy-gcp |
Terraform + images + Helm bring-up on GKE, then first zone/group/deploy through the API |
deploy-aws |
Same for EKS (untested path; the skill says so and demands a dry run) |
rotate-keys |
Rotate rmk_ MCP keys, rmn_ API keys, the admin key and the Fernet key without downtime |
backup-restore |
Versioned JSON backups to local/bucket and restores |
scale-zone |
Add a zone, scale counts/sizes, rebalance, remove a zone |
Validation sub-agent convention¶
Every skill ends with a Validate section. The convention is that the agent running the skill spawns a cheaper,
read-only sub-agent with only that section and the URLs/keys it needs; the sub-agent reports PASS/FAIL with the
evidence (HTTP status, gRPC status, job status, tools/call result) and never mutates anything. The parent agent may not
declare the task done until the validator has passed. skills/README.md has the exact wording to hand to the
sub-agent.