Skip to content
Back to skills

devops-anti-patterns-never-do-these

ASecurity

ANTI-PATTERNS — NEVER DO THESE — extracted from roles.json deepPrompt for devops

  • 8 stars
  • 0 votes
  • 0 copies
  • 7 views
  • Added May 27, 2026
data-aishellbashnodeterraformdatabasebackenddevops

Security analysis

A100/100

Pro scans all 21 files and shows the line behind each finding

Scanned May 27, 2026

npx -y skills add iampantherr/SecureContext --skill skills --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of devops-anti-patterns-never-do-these?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for devops-anti-patterns-never-do-these
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/iampantherr-devops-anti-patterns-never-do-these/badge)](https://www.skillsdirectory.com/skills/iampantherr-devops-anti-patterns-never-do-these)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
id: devops-anti-patterns-never-do-these@1@global
name: devops-anti-patterns-never-do-these
version: 1
scope: global
description: ANTI-PATTERNS — NEVER DO THESE — extracted from roles.json deepPrompt for devops
intended_roles: [devops]
mutation_guidance: |
  This skill encodes a behavioral procedure originally embedded in the
  devops role's deepPrompt. When mutating, preserve the imperative
  voice and the numbered/bulleted structure. Sub-rules within a numbered
  point can be edited; the top-level numbering should not change without
  operator approval (it's referenced by other skills + role text).
tags: [devops, role-extracted, v0-19-bootstrap]
acceptance_criteria:
  min_outcome_score: 0.6
  completes_in_seconds: 600
---
# ANTI-PATTERNS — NEVER DO THESE

_(Extracted from `roles.json` deepPrompt for the **devops** role during the v0.19.0 role/skill split. Original content preserved verbatim. Edit freely; the mutator will propose improvements based on skill_runs telemetry once this skill is invoked by an agent.)_

---

- Running kubectl exec into a prod pod to fix a live issue without first capturing state and opening an incident ticket. The pod is ephemeral; your manual fix evaporates on the next restart and leaves no audit trail.
- Hardcoding environment-specific values (URLs, ports, feature flags) in application code instead of in environment configuration. Config belongs in the environment, not baked into the artifact.
- Using the latest tag as an image reference in any environment beyond local development. Latest is not a version — it is an aliased pointer that breaks reproducibility and makes rollbacks impossible.
- Setting CPU limits lower than CPU requests, or omitting memory limits on JVM-based services. The JVM will consume all available node memory and trigger OOMKill on neighboring pods.
- Running database migrations as part of application startup. Migrations run at deploy time by a migration job, not at boot time by every application replica — startup migrations mean every pod restart on a bad migration kills the entire deployment simultaneously.
- Storing Terraform state locally or in a non-versioned, non-locked backend. State files contain sensitive output values; they must be encrypted, locked against concurrent writes, and backed up.
- Alerting on raw percentage thresholds (CPU above 80%) without context of what that means for the workload. Alert on SLO burn rate or direct user-facing symptoms — not infrastructure saturation that may or may not affect users.
- Granting cluster-admin to a CI service account. CI needs permission to deploy to specific namespaces — nothing broader.
- Running terraform apply -auto-approve in production without a human reviewing the plan output. This is how managed databases get destroyed and production networks get re-created.
- Writing long bash scripts embedded in CI YAML. Shell in YAML is untestable, unreadable, and unversionable as logic. Extract to versioned scripts in the repository or use a Makefile target that is testable locally.
- Skipping the postmortem because the incident resolved quickly. A 10-minute incident that recurs monthly is more damaging than a 1-hour incident that never happens again. Postmortems exist for the former, not just the latter.

---

Files in this skill

  • _staging_v0_19/_REPORT.md32.8 KB
  • _staging_v0_19/_role_account-executive.slimmed-deepprompt.md2.8 KB
  • _staging_v0_19/_role_account-manager.slimmed-deepprompt.md2.8 KB
  • _staging_v0_19/_role_accountant.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_analyst.slimmed-deepprompt.md5 KB
  • _staging_v0_19/_role_architect.slimmed-deepprompt.md2.8 KB
  • _staging_v0_19/_role_blogger.slimmed-deepprompt.md2.6 KB
  • _staging_v0_19/_role_board-advisor.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_brand-architect.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_brand-designer.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_brand-manager.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_brand-strategist.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_business-analyst.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_channel-manager.slimmed-deepprompt.md2.8 KB
  • _staging_v0_19/_role_chief-of-staff.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_comp-analyst.slimmed-deepprompt.md2.8 KB
  • _staging_v0_19/_role_competitive-intel.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_compliance-officer.slimmed-deepprompt.md2.8 KB
  • _staging_v0_19/_role_consultant.slimmed-deepprompt.md2.7 KB
  • _staging_v0_19/_role_content-marketer.slimmed-deepprompt.md2.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…