All skills
nvidia avatar

/doca-bf4-deployment

@f64fa0e
by NVIDIA Corporationnvidia/skills3.5k stars
424

WARNING: guides potentially IRREVERSIBLE BlueField-4 hardware operations (PLDM firmware burns, ISO reflashes, power cycles, BMC factory resets) that can brick firmware, corrupt boot media, or cause outages — a maintenance window and rollback plan are required, and every mutating step is governed by doca-hardware-safety, loaded alongside. Use this skill for BlueField-4 (BF4) day-1 platform bring-up from the BMC: installing the BlueField/DOCA bundle ISO onto the DPU (Grace, the Arm complex) over UEFI HTTP Boot, PXE, or Redfish Virtual Media; the PLDM firmware-update flow (BMC, NIC firmware, SBIOS, ERoT) via the Redfish UpdateService and pldmtool; and a Grace Ubuntu image with optional cloud-init. Trigger on BlueField-4/BF4 bring-up phrasings even without "BF4": {bring up my new BlueField-4}, {the BlueField ISO will not boot over HTTP from the BMC}, {attach BF4 virtual media via Redfish}, {BF4 firmware Task stuck at Running}. BF3 bring-up, application launch, and library APIs belong to other skills.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-bf4-deployment

This session only. Nothing lands on disk.

skill-card.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Description: <br>

Guides potentially irreversible BlueField-4 hardware operations (PLDM firmware burns, ISO reflashes, power cycles, BMC factory resets) for day-1 platform bring-up from the BMC, including installing the BlueField/DOCA bundle ISO onto the DPU via UEFI HTTP Boot, PXE, or Redfish Virtual Media, and the PLDM firmware-update flow. <br>

This skill is ready for commercial/non-commercial use. <br>

Owner

NVIDIA <br>

License/Terms of Use: <br>

Apache 2.0 AND CC-BY-4.0 <br>

Use Case: <br>

External operators and infrastructure engineers performing day-1 BlueField-4 DPU bring-up via the BMC, including OS installation, PLDM firmware updates, and Grace Ubuntu image deployment with optional cloud-init. <br>

Deployment Geography for Use: <br>

Global <br>

Requirements / Dependencies: <br>

Requires API Key or External Credential: [Not Specified] <br> Credential Type(s): [None identified] <br>

Do not include secrets in prompts/logs/output; use least-privilege credentials; rotate keys as appropriate. <br>

Known Risks and Mitigations: <br>

Risk: Review before execution as proposals could introduce incorrect or misleading guidance into skills. <br> Mitigation: Review and scan skill before deployment. <br>

Reference(s): <br>

Skill Output: <br>

Output Type(s): [Shell commands, Configuration instructions] <br> Output Format: [Markdown with inline bash code blocks] <br> Output Parameters: [1D] <br> Other Properties Related to Output: [None] <br>

Evaluation Agents Used: <br>

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8) <br>
  • Codex (openai/openai/gpt-5.5) <br>

Evaluation Tasks: <br>

Evaluated against 3 evaluation tasks (2 positive skill-activation, 1 negative) in the external profile using a k8s-sandbox environment. <br>

Evaluation Metrics Used: <br>

Reported benchmark dimensions: <br>

  • Security: Checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access. <br>
  • Correctness: Checks whether the agent follows the expected workflow and produces the correct final output. <br>
  • Discoverability: Checks whether the agent loads the skill when relevant and avoids using it when irrelevant. <br>
  • Effectiveness: Checks whether the agent performs measurably better with the skill than without it. <br>
  • Efficiency: Checks whether the agent uses fewer tokens and avoids redundant work. <br>

Underlying evaluation signals used in this run: <br>

  • security: Checks for unsafe operations, secret leakage, and unauthorized access. <br>
  • skill_execution: Verifies that the agent loaded the expected skill and workflow. <br>
  • skill_efficiency: Checks routing quality, decoy avoidance, and redundant tool usage. <br>
  • accuracy: Grades final-answer correctness against the reference answer. <br>
  • goal_accuracy: Checks whether the overall user task completed successfully. <br>
  • behavior_check: Verifies expected behavior steps, including safety expectations. <br>

Evaluation Results: <br>

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 3 100% (+0%) 100% (+0%)
Correctness 3 100% (+73%) 100% (+33%)
Discoverability 3 100% (+33%) 94% (+27%)
Effectiveness 3 98% (+54%) 100% (+29%)
Efficiency 3 72% (+19%) 79% (+29%)

Skill Version(s): <br>

a62f6e2 (source: git SHA, committed 2026-07-22) <br>

Ethical Considerations: <br>

NVIDIA believes Trustworthy AI is a shared responsibility and we have established policies and practices to enable development for a wide array of AI applications. When downloaded or used in accordance with our terms of service, developers should work with their internal team to ensure this skill meets requirements for the relevant industry and use case and addresses unforeseen product misuse. <br>

(For Release on NVIDIA Platforms Only) <br> Please report quality, risk, security vulnerabilities or NVIDIA AI Concerns here. <br>

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill provides guidance for BlueField-4 (BF4) hardware bring-up and platform management. It contains extensive safety warnings and mandates the use of a secondary safety skill for any irreversible or destructive hardware operations. No malicious patterns or unauthorized access behaviors were detected.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at f64fa0e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
metadata
{
  "kind": "library"
}
Other metadata
compatibility
No DOCA install is required to read this skill; it teaches the documented BlueField-4 BMC-driven bring-up flows (UEFI HTTP Boot, PXE, Redfish Virtual Media, PLDM firmware update). Executing the steps requires a BlueField-4 with an out-of-band-reachable BMC, a host or HTTP/HTTPS server to host the bundle ISO, and the target versions from the public BlueField/DOCA release notes.

README badge

README badge for nvidia/skills/doca-bf4-deployment