{
  "markdown": "# TrueFoundry Deploy Skills\n\n[![CI](https://github.com/truefoundry/tfy-deploy-skills/actions/workflows/ci.yml/badge.svg)](https://github.com/truefoundry/tfy-deploy-skills/actions/workflows/ci.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)\n\nDeploy, monitor, and manage ML infrastructure on TrueFoundry using AI coding assistants.\n\nWorks as a **plugin** for Claude Code and Codex CLI (with enforced workflows, automatic health verification, and failure diagnosis), and as **rules + skills** for Cursor.\n\n## Quick Start\n\n### Prerequisites\n\nSet your TrueFoundry credentials via environment variables or a `.env` file in your project root:\n\n```bash\nexport TFY_BASE_URL=https://your-org.truefoundry.cloud\nexport TFY_API_KEY=tfy-...\n```\n\nNo account yet? Run `uv run tfy register` to sign up. The `tfy` CLI and workspace selection are handled automatically -- skills install the CLI if missing and list your available workspaces at deploy time.\n\n### Claude Code (Plugin -- Full Enforcement)\n\nAdd the marketplace and install the plugin:\n\n```\n/plugin marketplace add truefoundry/tfy-deploy-skills\n/plugin install truefoundry@truefoundry-deploy-skills\n```\n\nOr interactively: `/plugin` → **Discover** tab → select **truefoundry** → **Install now**.\n\nWhat you get:\n- 22 skills loaded automatically\n- 2 specialized agents (deploy orchestrator, troubleshoot)\n- 5 hooks enforcing safe deployment workflows\n- Automatic credential checks on session start\n- Post-deploy health verification and failure diagnosis\n\n### Codex CLI (Plugin -- Full Enforcement)\n\nClone the repo and point Codex at it, or install via the Codex plugin system:\n\n```bash\ncodex install truefoundry/tfy-deploy-skills\n```\n\nEnable hooks in your `config.toml`:\n\n```toml\ncodex_hooks = true\n```\n\nSame hooks and skills as Claude Code. Agents are defined in `AGENTS.md` for Codex.\n\n### Cursor (Rules -- Advisory)\n\nCopy the skills into Cursor's config directory:\n\n```bash\nnpx skills add truefoundry/tfy-deploy-skills -g -a cursor -s '*' -y\n```\n\nWhat you get:\n- 22 skills as context rules\n- No hook enforcement (Cursor does not support hooks)\n- Skills provide guidance but cannot block unsafe operations\n\n### Standalone Skills (Any Agent)\n\nFor any agent that supports the [Agent Skills](https://agentskills.io) open format:\n\n```bash\nnpx skills add truefoundry/tfy-deploy-skills -g -a claude-code -a cursor -a codex -s '*' -y\n```\n\nOr install for all detected agents:\n\n```bash\nnpx skills add truefoundry/tfy-deploy-skills --all\n```\n\n## What You Can Do\n\nJust ask your agent in plain English:\n\n- *\"deploy my FastAPI app\"*\n- *\"launch a Jupyter notebook with a GPU\"*\n- *\"deploy Postgres with Helm\"*\n- *\"deploy an LLM with vLLM\"*\n- *\"show logs for my-service\"*\n- *\"what's my connection status?\"*\n\n## What's Included\n\n### 22 Skills\n\n| Category | Skills |\n|----------|--------|\n| **Deploy** | [applications](skills/applications), [deploy](skills/deploy), [gitops](skills/gitops), [helm](skills/helm), [jobs](skills/jobs), [llm-deploy](skills/llm-deploy), [ml-repos](skills/ml-repos), [notebooks](skills/notebooks), [service-test](skills/service-test), [ssh-server](skills/ssh-server), [tracing](skills/tracing), [volumes](skills/volumes), [workflows](skills/workflows), [workspaces](skills/workspaces) |\n| **Operate** | [logs](skills/logs), [monitor](skills/monitor), [status](skills/status) |\n| **Manage** | [access-control](skills/access-control), [access-tokens](skills/access-tokens), [docs](skills/docs), [onboarding](skills/onboarding), [secrets](skills/secrets) |\n\nInstalled skill names are namespaced as `truefoundry-<skill>` (e.g., `truefoundry-deploy`).\n\n### Plugin Hooks (Claude Code and Codex)\n\n| Hook | Type | What It Does |\n|------|------|-------------|\n| **Session Start** | SessionStart | Verifies credentials, auto-installs/upgrades the `tfy` CLI, tests API connectivity, lists accessible workspaces |\n| **Block Deletes** | PreToolUse | Blocks all DELETE API calls -- redirects users to the TrueFoundry dashboard for manual deletion |\n| **Auto-Approve API** | PreToolUse | Auto-approves `tfy-api.sh` and `tfy-version.sh` calls so the agent does not prompt for each API request |\n| **Secret Scan** | PreToolUse | Blocks commands containing hardcoded API keys, tokens, or credentials -- enforces `tfy-secret://` references |\n| **Deploy Monitor** | PostToolUse | Detects `tfy apply`/`tfy deploy` commands, polls deployment status with adaptive intervals, fetches logs on failure, verifies health on success |\n| **Verification Gate** | Stop | Prevents the agent from finishing if a deployment is in progress or an endpoint is unreachable |\n\n### Agents (Claude Code)\n\n| Agent | Purpose |\n|-------|---------|\n| **deploy-orchestrator** | Orchestrates the full deployment lifecycle: credential check, workspace selection, secret creation, manifest validation, deploy, and post-deploy verification. Enforces strict tier ordering for multi-service deployments. |\n| **troubleshoot** | Diagnoses deployment failures by fetching status, logs, and pod events. Matches error patterns (OOMKilled, CrashLoopBackOff, ImagePullBackOff, etc.) to root causes and suggests fixes. |\n\n### Safety Guardrails\n\n- **No delete operations** -- all delete requests are blocked and redirected to the dashboard\n- **No hardcoded secrets** -- commands with inline credentials are blocked before execution\n- **Mandatory workspace confirmation** -- agents always list workspaces and ask you to choose\n- **Deployment verification gate** -- the agent cannot finish until deployments reach a terminal state and endpoints are reachable\n\n## Architecture\n\n```\ntfy-deploy-skills/\n  .claude-plugin/\n    plugin.json            # Plugin manifest (name, version, userConfig)\n    marketplace.json       # Marketplace metadata\n  hooks/\n    hooks.json             # Hook definitions (SessionStart, PreToolUse, PostToolUse, Stop)\n    auto-approve-tfy-api.sh\n  plugin-scripts/          # Hook implementations\n    session-start.sh       # Credential + CLI bootstrap\n    block-delete-operations.sh\n    pre-tool-secret-scan.sh\n    post-deploy-monitor.sh # Deployment polling + health checks\n    stop-review-gate.sh    # Verification gate\n  agents/\n    deploy-orchestrator.md\n    troubleshoot.md\n  skills/\n    _shared/               # Canonical copies of shared scripts and references\n      scripts/             # tfy-api.sh, tfy-version.sh\n      references/          # 13 shared reference docs\n    deploy/SKILL.md        # One directory per skill\n    monitor/SKILL.md\n    ...\n  scripts/                 # Dev tooling (lint, validate, sync, install)\n```\n\nShared scripts and references live in `skills/_shared/` and are synced to individual skill directories via `./scripts/sync-shared.sh`. Never edit files in `skills/*/scripts/` or `skills/*/references/` directly.\n\n## Feature Comparison\n\n| Feature | Claude Code | Codex CLI | Cursor | Standalone Skills |\n|---------|:-----------:|:---------:|:------:|:-----------------:|\n| 22 skills | yes | yes | yes | yes |\n| Hook enforcement | yes | yes | no | no |\n| Auto credential check | yes | yes | no | no |\n| Deploy monitoring | yes | yes | no | no |\n| Delete blocking | yes | yes | no | no |\n| Secret scan | yes | yes | no | no |\n| Verification gate | yes | yes | no | no |\n| Specialized agents | yes | no | no | no |\n| CLI auto-install | yes | yes | no | no |\n\n## Development\n\n```bash\n./scripts/sync-shared.sh              # Sync shared files to all skills\n./scripts/validate-skills.sh           # Validate skill structure\n./scripts/validate-skill-security.sh   # Offline security checks\n./scripts/test-tfy-api.sh             # Unit tests (needs python3 + curl)\n./scripts/install.sh                   # Install locally\n```\n\nShell scripts must pass `shellcheck`. See [CONTRIBUTING.md](CONTRIBUTING.md) for details.\n\n## License\n\nMIT\n",
  "bytes": 7811,
  "sha": "cfe4354757a0d5f9eb0ae92232a4caaa76198989bbf13a1b0266fb9b28bc37bc",
  "repo_slug": "truefoundry/tfy-deploy-skills",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_truefoundry_tfy_deploy_skills_truefoundr_324a2765/readme"
}