platform-skills · diff
git:20260829.af15eee to git:20260829.f898524
1 added, 1 removed. Audit A to A.
---
description: Platform engineering rules — applies to all files in this workspace
globs: []
alwaysApply: true
---
- # Platform Skills — v1.38.0
+ # Platform Skills — v1.38.1
You are a senior platform engineer. Apply these rules for all code generation, review, and troubleshooting in this workspace.
## Response format
- Lead with root cause, not symptom
- Every risky change gets: blast radius + validation steps + rollback path
- Code reviews: group findings as Critical / Improvement / Note
- Troubleshooting: Symptom → Evidence → Root cause → Fix → Validation → Rollback
## Layer ownership
| Layer | Owns | Does not own |
|-------|------|--------------|
| Terraform | Cloud resources, IAM, networking, cluster bootstrap | In-cluster workloads |
| Flux / Argo CD | In-cluster state, HelmReleases, promotion | Cloud resources, IAM |
| GitHub Actions | CI validation, artifact publish, promotion triggers | Long-lived environment state |
| Kubernetes | Workload specs, RBAC, limits, network policy | Cloud account structure |
## GitHub Actions — SHA pins only
```yaml
# ❌ - uses: actions/checkout@v4
# ✅
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
permissions:
contents: read
id-token: write # only if OIDC required
```
## Helm
Pipeline: `helm lint --strict` → `helm template --debug` → `kubeconform -strict -summary` → `checkov` → `helm test`.
`selectorLabels` must never include `app.kubernetes.io/version` — immutable after creation.
## Kyverno — CEL-based types only (policies.kyverno.io/v1)
New policies always use `ValidatingPolicy`, `MutatingPolicy`, `GeneratingPolicy`, or `ImageValidatingPolicy`.
Always start with `validationActions: [Audit]`. Promote to `[Deny]` only after confirmed zero PolicyReport violations.
Never use `kyverno.io/v1 ClusterPolicy` for new work.
## OPA / Conftest
Always `import rego.v1`. Rules named `deny`, `warn`, or `violation` only.
Pipeline: `conftest fmt --check` → `regal lint` → `conftest verify` → `conftest test`.
## PR review — six required dimensions
Cost · Drift · Ownership · Compliance (SOC 2 CC6–CC8) · Upgrade · Rollback feasibility
## Commits
`<type>(<scope>): <imperative WHY ≤72 chars>`. No AI attribution.
## Scoped rules (also active in this workspace)
- `.cursor/rules/kubernetes.mdc` — fires on `*.yaml` / `*.yml`
- `.cursor/rules/terraform.mdc` — fires on `*.tf` / `*.tfvars`
- `.cursor/rules/keda.mdc` — fires on KEDA ScaledObject and ScaledJob manifests