All skills
lukemurraynz avatar

lukemurraynz/hve-agent-skills

Production-hardened AI coding-agent skills for Azure platform work

main Updated last monthGitHub
README badge for lukemurraynz/hve-agent-skills

Repository statistics

  • Indexed skills

    9

  • Skill groups

    1

  • GitHub stars

    1

  • Forks

    1

9 total

/aks-cluster-architecture

AKS cluster architecture decisions for new Azure Kubernetes Service projects: AKS Automatic vs Standard, networking topology, dual-stack (IPv4/IPv6), Kubernetes version and OS currency, node pool strategy, identity, production NetworkPolicy, namespaces, autoscaling, ingress and Gateway API, observability, operations, resilience, GPU and AI workloads, GPU partitioning (MIG, time-slicing, MPS), batch scheduling (Kueue), AKS on bare metal, AI Runway and KAITO model serving, AKS MCP server access, kars (Agent Reference Stack for Kubernetes) for agent isolation, Kata MicroVM pod sandboxing, Azure Kubernetes Fleet Manager, multi-cluster governance, update orchestration, resource placement, cross-cluster networking, and cost. WHEN: designing new AKS clusters, reviewing production readiness, choosing CNI or outbound connectivity, planning node pools, defining namespace, network and security controls, evaluating Fleet Manager, deploying AI agent runtimes on AKS, or making hard-to-reverse infrastructure decisions.

/container-supply-chain

Production implementation guide for new container image supply-chain security: OCI image signing, digest-first builds, GitHub artifact attestations, Cosign keyless signing, optional Notation/ACR signing, Rekor audit lookup, SBOM generation and attestation, vulnerability scanning, waiver governance, SLSA Build track evidence, deployment admission gates, and artifact-leakage prevention. USE FOR: implementing build-sign-attest-scan-verify pipelines, hardening GHCR or ACR container release workflows, verifying image provenance, configuring Kubernetes/AKS deployment gates, preventing Docker/package artifact leakage, and producing auditable supply-chain records.

/hitl-design-patterns

Design human-in-the-loop (HITL) approval gates for AI agent workflows. Use when you need to decide "where do I put a human approval gate", "should this agent action need confirmation", "classify this action's reversibility", "design the confirmation UX", "set a timeout and fallback policy", "define an escalation path", or "wire HITL into MCP / MAF / CopilotKit / Copilot Studio". Covers maker-checker / four-eyes approval, confirmation dialogs, fail-closed timeouts, and audit. Do not use for general security review, runtime policy enforcement (use agent-governance-toolkit instead), or fully automated loops with no human decision point. Pairs with owasp-agentic for the threat-model perspective (ASI09).

/identity-managed-identity

Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead.

The badge links readers to this page. It shows the skilld mark and no counts, and it follows the reader's light or dark GitHub theme.

<a href="https://skilld.dev/gh/lukemurraynz/hve-agent-skills"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://skilld.dev/b/lukemurraynz/hve-agent-skills?theme=dark"> <source media="(prefers-color-scheme: light)" srcset="https://skilld.dev/b/lukemurraynz/hve-agent-skills?theme=light"> <img alt="Skill repository on skilld.dev" src="https://skilld.dev/b/lukemurraynz/hve-agent-skills?theme=light"> </picture> </a>