用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/aiFabricoCom/fabrico-collections-codex --skill fabrico-implementing-ci-cd命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | fabrico-implementing-ci-cd |
| description | CI/CD pipeline and deployment-strategy patterns. |
Check which CI/CD platform the project uses:
.github/workflows/*.yml → GitHub Actionsbitbucket-pipelines.yml → Bitbucket Pipelines.gitlab-ci.yml → GitLab CIazure-pipelines.yml → Azure PipelinesJenkinsfile → JenkinsUse the context7 MCP server to look up platform-specific syntax for the detected platform.
Lint → Test → Build → Deploy (staging) → Deploy (production)
↓
Artifacts & Caching
Rule: Each stage should be independent and cacheable.
| Strategy | Use When | Rollback | Risk |
|---|---|---|---|
| Rolling | Stateless apps, can tolerate mixed versions | Slow | Low |
| Blue-Green | Need instant rollback, DB migrations | Instant | Low |
| Canary | High traffic, want gradual validation | Instant | Very Low |
| Recreate | Dev/test, breaking changes only | Slow | High |
| Scenario | Approach |
|---|---|
| AWS from GitHub/GitLab | OIDC federation (no long-lived keys) |
| AWS from Bitbucket | Repository variables + IAM role |
| Multi-cloud | HashiCorp Vault with CI/CD auth |
| Simple/small team | Platform native secrets |
Rule: Prefer OIDC federation over long-lived access keys. Use the fabrico-managing-secrets skill (.agents/skills/fabrico-managing-secrets/SKILL.md) for implementation details.
| Tool | Detection | Approach |
|---|---|---|
| Nx | nx.json | nx affected --target=build |
| Turborepo | turbo.json | turbo run build --filter=...[origin/main] |
| None | - | Path filtering in CI config |
fabrico-technical-context-discovering skill (.agents/skills/fabrico-technical-context-discovering/SKILL.md) to find existing CI patternsfabrico-managing-secrets skill (.agents/skills/fabrico-managing-secrets/SKILL.md)@latest)latest tags in production imagesLint (fmt) → Validate → Security Scan → Plan → [Manual Approval] → Apply
↓
Save Plan Artifact
↓
PR Comment with Diff
Rule: Never use local state in CI/CD. Always configure remote backend before pipeline runs.
| Element | Implementation | Why |
|---|---|---|
| AWS Credentials | aws-actions/configure-aws-credentials@v4 with OIDC | No long-lived secrets |
| State Backend | S3 + DynamoDB locking | Persistent state, concurrent access protection |
| Plan Artifact | terraform plan -out=tfplan + upload artifact | Ensure apply matches reviewed plan |
| PR Comment | actions/github-script or terraform-pr-commenter | Reviewers see changes before merge |
| Security Scan | aquasecurity/tfsec-action or bridgecrewio/checkov-action | Catch misconfigurations early |
| Production Guard | environment: production with required reviewers | Human approval before infra changes |
| Cache | actions/cache for .terraform directory | Faster init, reduced API calls |
permissions:
id-token: write
contents: read
steps:
- uses: aws-actions/configure-aws-credentials@v4
with:
role-to-arn: ${{ secrets.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Rule: Always use OIDC federation. Never store AWS access keys as secrets.
apply:
runs-on: ubuntu-latest
needs: plan
environment: production # Requires manual approval
if: github.ref == 'refs/heads/main' && github.event_name == 'push'
Configure in GitHub: Settings → Environments → production → Required reviewers.
plan:
steps:
- run: terraform plan -out=tfplan
- uses: actions/upload-artifact@v4
with:
name: tfplan
path: tfplan
apply:
steps:
- uses: actions/download-artifact@v4
with:
name: tfplan
- run: terraform apply tfplan
Rule: Apply must use the exact plan that was reviewed, not regenerate it.
apply -auto-approve without environment protection gatesterraform init in every job without cachelatest provider versions instead of pinned versionsversions.tf.terraform directory cached between runsfabrico-managing-secrets - For credential configurationfabrico-technical-context-discovering - For finding existing patterns