All skills

USE FOR: Drasi continuous-query solutions - real-time queries, change detection, reactive events, data-trigger pipelines on Drasi Server, Drasi for Kubernetes, or drasi-lib. Router: load bundle guides as needed. DO NOT USE for non-Drasi messaging (event-driven-messaging) or pure AKS/ACA hosting (aks-cluster-architecture, azure-container-apps).

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/drasi

This session only. Nothing lands on disk.

bundlesexamplesguide.md

≈2.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Examples bundle

Use this bundle for minimal scaffolds and example patterns. Keep examples small and update them against current Drasi docs before copying into production.

5-minute Hello Drasi (Drasi Server)

The shortest possible Drasi pipeline. One mock source, one Cypher query selecting one field, one Log (Debug) reaction, one verification call. Use this strictly to confirm Drasi Server is reachable and the source-to-query-to-reaction chain is wired. It is NOT production-shaped - graduate to the stitched example below for that. Confirm field names and REST paths at the current release before adapting.

Prerequisites: Docker installed and running. Step 2 below uses docker inspect --format to resolve the digest with no extra tooling. The richer docker inspect | jq form in Step 0 of the stitched example below is functionally equivalent - use whichever is convenient (jq is not required for this Hello example). Do not use the floating latest tag in production; the :latest reference here exists only to resolve the immutable digest, which you then reuse in the run command. All commands below run from the same working directory; the docker run mounts $PWD into /c so hello.yaml must live in that directory.

  1. Author hello.yaml in your current working directory:

    apiVersion: drasi.io/v1
    host: 127.0.0.1
    port: 8080
    sources:
      - kind: mock
        id: hello-src
        autoStart: true
        dataType: { type: sensorReading, sensorCount: 1, intervalMs: 1000 }
    queries:
      - id: hello-q
        queryLanguage: Cypher
        query: "MATCH (s:SensorReading) RETURN s.id AS id"
        sources: [{ sourceId: hello-src }]
        autoStart: true
    reactions:
      - kind: log
        id: hello-log
        queries: [hello-q]
        autoStart: true
  2. Resolve the current image digest into a shell variable, then run Drasi Server locally with the digest pinned (do not use the floating latest tag in production - these two lines exist only to resolve it to an immutable digest, which is then reused in the run command):

    docker pull ghcr.io/drasi-project/drasi-server:latest
    DIGEST=$(docker inspect --format '{{index .RepoDigests 0}}' ghcr.io/drasi-project/drasi-server:latest)
    echo "Resolved: $DIGEST"   # sanity check
    docker run --rm -p 8080:8080 -v "$PWD:/c" "$DIGEST" --config /c/hello.yaml
  3. Verify in a second terminal (the result body shape should be confirmed at the current release):

    curl --fail http://localhost:8080/api/v1/queries/hello-q/results

Expected: a non-empty result row containing an id field, and a log line from the hello-log reaction. If either is missing, jump to bundles/operations/guide.md. Cleanup: Ctrl-C in the Step 2 terminal stops Drasi Server; --rm ensures the container is removed automatically. Do not use the floating latest tag in production; this snippet is local-only.

Example rules

  • Examples are starting points, not authoritative schemas.
  • Verify provider docs before use.
  • Replace inline secrets with Key Vault, Kubernetes Secrets, or provider-supported identity for production.
  • Pin versions in deployment examples.
  • Include validation commands with every example.
  • Include cleanup commands for disposable examples.

Drasi Server: minimal stitched example

This is the smallest end-to-end Drasi Server pipeline. It uses a mock source so it runs without a real database, proves the source → query → reaction chain, and is easy to delete cleanly. Verify the field shapes against the upstream README at https://github.com/drasi-project/drasi-server before adapting to your environment.

Step 0: resolve a digest. Every <resolve-current-digest> placeholder below is illustrative - do not copy it literally. Do not use the floating latest tag in production. Resolve the digest once and reuse the same value everywhere in this example:

docker pull ghcr.io/drasi-project/drasi-server:latest
docker inspect ghcr.io/drasi-project/drasi-server:latest | jq -r '.[0].RepoDigests[0]'

Sample output (illustrative - your digest will differ; do not reuse this value):

ghcr.io/drasi-project/drasi-server@sha256:a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2

Capture the digest you actually got into versions.md and substitute it for <resolve-current-digest> in every command below. Do not use the floating latest tag in production; the docker pull :latest line above exists solely to resolve the immutable digest and should not appear in deployed manifests. Re-resolve when the upstream image is rebuilt.

  1. Pull and run the server with the pinned digest from Step 0:

    docker pull ghcr.io/drasi-project/drasi-server@sha256:<resolve-current-digest>
    docker run --rm -p 8080:8080 ghcr.io/drasi-project/drasi-server@sha256:<resolve-current-digest>
    curl --fail http://localhost:8080/health

    The verification command in SKILL.md (docker run --rm -p 8080:8080 ghcr.io/drasi-project/drasi-server@sha256:<digest> then curl http://localhost:8080/health) is the same shape - use the resolved digest in both places.

  2. Create config/server.yaml with one source, one query, one reaction:

    apiVersion: drasi.io/v1
    host: 0.0.0.0
    port: 8080
    logLevel: info
    enableUi: false
    sources:
      - kind: mock
        id: sensor-feed
        autoStart: true
        dataType:
          type: sensorReading
          sensorCount: 5
          intervalMs: 3000
    queries:
      - id: high-temp
        queryLanguage: Cypher
        query: "MATCH (s:SensorReading) WHERE s.temperature > 25 RETURN s"
        sources:
          - sourceId: sensor-feed
        autoStart: true
    reactions:
      - kind: log
        id: temp-logger
        queries:
          - high-temp
        autoStart: true
  3. Start with this config and verify the pipeline end-to-end:

    docker run --rm -p 8080:8080 -v "$PWD/config:/config" \
      ghcr.io/drasi-project/drasi-server@sha256:<resolve-current-digest> --config /config/server.yaml
    curl --fail http://localhost:8080/api/v1/sources
    curl --fail http://localhost:8080/api/v1/queries/high-temp
    curl --fail http://localhost:8080/api/v1/queries/high-temp/results

    Expected: high-temp query returns one or more SensorReading rows with temperature > 25.

  4. Stream live events to prove change propagation:

    curl -N http://localhost:8080/api/v1/events
  5. Tear down by stopping the container. Field shapes (kind, queryLanguage, sources[].sourceId, reactions[].queries) and REST paths (/api/v1/sources, /api/v1/queries/{id}/results, /api/v1/events, /api/v1/docs/) are taken from the drasi-server README; re-verify before pinning a production digest.

Production hardening checklist for this example:

  • Replace kind: mock with a real source (kind: postgres, kind: http, kind: grpc).
  • Replace kind: log with a durable reaction (kind: http, kind: sse, kind: grpc).
  • Set enableUi: false for any non-development deployment, or place the UI behind auth.
  • Bind to 127.0.0.1 (not 0.0.0.0) and front the server with a reverse proxy that enforces TLS, auth, and rate limits before exposing /api/v1/... to anything beyond localhost.
  • Pin the image by digest (@sha256:...), not a floating tag.

Minimal Drasi for Kubernetes flow

Author resources in this order:

  1. Source.
  2. ContinuousQuery.
  3. Reaction.
  4. Synthetic source change.
  5. Validation.

Delete in reverse order:

  1. Reaction.
  2. ContinuousQuery.
  3. Source.

Minimal Source skeleton

apiVersion: v1
kind: Source
name: example-source
spec:
  kind: <ProviderKind>
  properties:
    <provider-specific-properties>: <values>

Before using this skeleton, load sources and verify the provider schema.

Minimal ContinuousQuery review shape

apiVersion: v1
kind: ContinuousQuery
name: example-query
spec:
  mode: query
  queryLanguage: Cypher
  sources:
    subscriptions:
      - id: example-source
  query: >
    MATCH (n:Example)
    RETURN n.id AS id

Before using this shape, load continuous-queries and verify current schema and source model.

Minimal Reaction review shape

apiVersion: v1
kind: Reaction
name: example-reaction
spec:
  kind: <ReactionKind>
  queries:
    example-query:
      <reaction-specific-mapping>: <values>

Before using this shape, load reactions and verify current schema.

Azure Container Apps Drasi Server review shape

Production examples should include:

  • Pinned ghcr.io/drasi-project/drasi-server:<version> image, preferably with digest.
  • Internal ingress by default.
  • Health probe to /health.
  • Authenticated front door if public.
  • Secret references for sensitive configuration.
  • Log Analytics and revision diagnostics.
  • Post-deploy validation that calls /health, /api/v1/openapi.json, and a source/query/reaction flow.

When to add a new example

Add a new example only when it teaches a reusable pattern that cannot be expressed by a checklist. Keep one example per file or section, and do not duplicate provider docs.

Exit criteria

An example or scaffold is complete only when:

  • It states the target runtime and versions.
  • It avoids production latest tags and unbounded crate/action versions.
  • It includes source, query, and reaction pieces or clearly states why one is intentionally absent.
  • It has a clean setup path, validation path, and cleanup path.
  • A controlled source change proves the expected query result and reaction side effect.
  • Security warnings are explicit for any local-only shortcut.

Source: SKILL.md on GitHub

1 warning8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The Drasi skill package is a highly structured and security-conscious set of instructions for managing data change detection pipelines. It includes extensive documentation on threat modeling, workload identity setup on AKS, and specific guidance for preventing prompt injection when source data is fed into AI agents. All documented commands and scripts are legitimate operational tools for the Drasi platform, and no malicious patterns such as obfuscation, persistence, or data exfiltration were found.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: MEDIUM · 1 issue

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
metadata
{
  "last_verified": "2026-08-25"
}

README badge

README badge for lukemurraynz/hve-agent-skills/drasi