All skills
nvidia avatar

/doca-bf4-deployment

@f64fa0e
by NVIDIA Corporationnvidia/skills3.5k stars
424

WARNING: guides potentially IRREVERSIBLE BlueField-4 hardware operations (PLDM firmware burns, ISO reflashes, power cycles, BMC factory resets) that can brick firmware, corrupt boot media, or cause outages — a maintenance window and rollback plan are required, and every mutating step is governed by doca-hardware-safety, loaded alongside. Use this skill for BlueField-4 (BF4) day-1 platform bring-up from the BMC: installing the BlueField/DOCA bundle ISO onto the DPU (Grace, the Arm complex) over UEFI HTTP Boot, PXE, or Redfish Virtual Media; the PLDM firmware-update flow (BMC, NIC firmware, SBIOS, ERoT) via the Redfish UpdateService and pldmtool; and a Grace Ubuntu image with optional cloud-init. Trigger on BlueField-4/BF4 bring-up phrasings even without "BF4": {bring up my new BlueField-4}, {the BlueField ISO will not boot over HTTP from the BMC}, {attach BF4 virtual media via Redfish}, {BF4 firmware Task stuck at Running}. BF3 bring-up, application launch, and library APIs belong to other skills.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-bf4-deployment

This session only. Nothing lands on disk.

referencesdetails.md

≈1.9k tokens on demand. Your agent reads this file only when SKILL.md points to it.

doca-bf4-deployment — reference detail

Moved out of SKILL.md to keep the loader under the per-file size budget. This is supporting detail, not routing logic.

Example questions this skill answers well

The CLASSES of BF4-bring-up questions this skill is built to answer, each with one worked example. The class is the load-bearing piece; the worked example is one instance.

What this skill deliberately does not ship

This skill is agent guidance for the documented BF4 day-1 bring-up flows, not a credentials / images / firmware bundle. To keep the boundary clean, it deliberately does not contain — and pull requests should not add:

  • BlueField-3 bring-up. BF3 is a different platform with different methods; route to doca-bf3-deployment. This skill is BlueField-4-specific (Grace, the dpu-bmc Redfish surface, the BF4 install methods).
  • Container or bare-metal application launch. Running a DOCA service container or a DOCA-linked binary on an already-working BlueField is owned by doca-container-deployment and doca-bare-metal-deployment. This skill stops at "Grace installed, firmware at the target level."
  • The hardware-change meta-policy. The preflight / OOB-console / maintenance-window / rollback discipline that wraps every PLDM burn, ISO reflash, power cycle, and BMC factory reset is owned by doca-hardware-safety. This skill cross-links it and never redefines it.
  • Real credentials, internal hostnames, internal paths, or pre-release firmware version strings. This skill uses only placeholders ({bmc-ip}, {bmc-user}, {bmc-password}, {iso-uri}, {http-server-ip}, {device-name}, {fw-image}, {eid}, {task-id}) for anything site-specific. It never prints a default-credential string, never names an internal hostname or NFS path, and never cites a specific pre-release firmware version — those come from the public release notes and the operator's own environment. This is the load-bearing public-safety rule for this skill.
  • A samples/, templates/, images/, or firmware/ subtree of any kind. A mock or partial artifact in this skill's tree, even one labeled "reference", is misleading: operators will read it as production-ready, and a stored credential or firmware blob would fail the bundle's public-release gates.

Related skills

  • doca-hardware-safety — the CRITICAL cross-cutting meta-policy for any change touching DPU / NIC hardware state. Every PLDM firmware burn, ISO reflash, power cycle, and BMC factory reset in this skill is a MUTATING op; the change-application discipline lives there and this skill loads it ALONGSIDE, never duplicating it. This skill's ## Safety policy overlays that meta-policy with BF4-specific rules (never print a credential, always detach media, public information only).
  • doca-bare-metal-deployment — the downstream skill for launching a DOCA-linked binary directly on the BlueField Arm once this skill has brought Grace up. Its ## bluefield-lifecycle anchor covers the BF3-era BFB / RShim / TMFIFO lifecycle; this skill is the BF4 BMC-driven day-1 analog.
  • doca-container-deployment — the downstream skill for deploying a DOCA service container on the BlueField once Grace is up.
  • doca-setup — env preparation on the installed Grace OS (install verification, hugepages, pkg-config path, devlink mode, representor visibility). This skill hands off to it once the platform is up.
  • doca-version — the four-way version match rule. This skill's ## Version compatibility cross-links the body there and adds only the BF4 overlay (install / firmware targets come from the public release notes; the Redfish FirmwareInventory and pldmtool GetFwParams are the post-update anchors; cat /etc/mlnx-release is the Grace install anchor).
  • doca-public-knowledge-map — the routing table to the public BlueField/DOCA documentation, release notes, and download surface. This skill does not duplicate URLs or invent exact doc anchors; it points at the map. The BlueField BSP / BMC rows there are the route for any externally-productized layer beyond this skill's day-1 carve-out.
  • doca-bf3-deployment — the sibling skill for BlueField-3 day-1 bring-up. This skill is BF4-only; BF3 questions route there.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill provides guidance for BlueField-4 (BF4) hardware bring-up and platform management. It contains extensive safety warnings and mandates the use of a secondary safety skill for any irreversible or destructive hardware operations. No malicious patterns or unauthorized access behaviors were detected.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at f64fa0e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
metadata
{
  "kind": "library"
}
Other metadata
compatibility
No DOCA install is required to read this skill; it teaches the documented BlueField-4 BMC-driven bring-up flows (UEFI HTTP Boot, PXE, Redfish Virtual Media, PLDM firmware update). Executing the steps requires a BlueField-4 with an out-of-band-reachable BMC, a host or HTTP/HTTPS server to host the bundle ISO, and the target versions from the public BlueField/DOCA release notes.

README badge

README badge for nvidia/skills/doca-bf4-deployment