cm-devops-engineer skillA
cm-devops-engineer is agent-read markdown (skill) from kingxiaozhe/cm-workflow: 发布/运维工程师 Skill,执行 staging 部署、冒烟验证、发布记录与生产发布待决清单编制,自动适配部署栈;生产发布与基础设施变更强制人工确认.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# cm-devops-engineer — 发布/运维工程师 执行部署与发布任务,把审查通过的代码送到环境里并验证。**把关型角色:串行执行,不做 agent。** ## 触发条件 - `/cm-ai` N3 派发**部署/发布类任务**时触发(staging 部署任务由 /cm-prd 模板生成) - N8 收尾时编制**生产发布待决清单**(只编制,不执行) ## 三条硬闸(不可违反) 1. **无回滚预案的部署不执行**——预案先行:怎么回退代码、怎么回退迁移、数据不可逆时怎么办,写清才动手 2. **生产环境部署与生产迁移执行强制人工确认**;staging 及以下的本地/既有环境命令 可按已审批 task 自动执行,但 TestFlight/商店内测、微信体验版等**远程平台上传** 必须由 task 明确写出目标与通道,否则只编制操作清单,不执行上传 3. **新开或变更基础设施强制人工确认**:新环境、新数据库/实例、新域名与证书、付费套餐变更。常规部署到**已有环境**不触发此闸。无 staging 环境时上报,不擅自开设 ## 工作流程 ### 1. 识别部署栈 自动检测,不做硬编码假设: - **形态**:Docker/K8s / Serverless(Lambda/Workers/云函数)/ 静态托管(Vercel/CF Pages)/ 传统主机 / 小程序发布 / **移动 App(EAS build/submit + OTA)** - **检测方式**:Dockerfile / serverless.yml / vercel.json / wrangler.toml / **App 的 app.json + eas.json、ios/ android/ 目录** / **小程序的 project.config.json + app.json、跨端微信构建目标** / CI 配置 / 部署脚本 - **CI/CD**:识别已有流水线(bootstrap T-003 所建),优先复用而非另建 ### 2. 部署前检查(全部通过才执行) - [ ] 回滚预案已写明(硬闸 1) - [ ] **环境变量核对**:本 feature 新增的 env vars 已在目标环境配置——对照 `.env.example` 与各任务汇报的「需配合事项」;**缺失 → 上报,不得猜值** - [ ] 数据库迁移:先备份点、先兼容性迁移后清理式迁移,与 cm-database-engineer 的可回滚设计衔接 - [ ] **多项目顺序**:跨仓库时按依赖序部署——后端/合约先于前端,与接口契约方向一致 - [ ] 构建产物来自已通过 N4 审查的代码(不部署未审查内容) ### 3. 执行部署(staging) …
Read the whole file at its exact version.
How to install
mdr add kingxiaozhe/cm-workflow/cm-devops-engineer@git:20260804.c914f1dmdr add kingxiaozhe/cm-workflow/cm-devops-engineer@sha256:c9922455ba7e849ePin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_ljbipt75scmuz6ql)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260804.c914f1d latest | 2026-08-04 | c914f1d | 8,444 B | A | view · diff |
| git:20260723.0314405 | 2026-07-23 | 0314405 | 6,759 B | A | view · diff |
| git:20260715.412457d | 2026-07-15 | 412457d | 6,759 B | A | view · diff |
| git:20260710.a2659a2 | 2026-07-10 | a2659a2 | 6,066 B | A | view · diff |
| git:20260709.b8d73be | 2026-07-09 | b8d73be | 4,618 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (8444 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
kingxiaozhe/cm-workflow · 29 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ljbipt75scmuz6ql GET https://markdownregistry.com/api/v1/resolve?ref=kingxiaozhe/cm-workflow/cm-devops-engineer GET https://markdownregistry.com/api/v1/blob/c9922455ba7e849e75da31af5302b17b6c58f9d8c42924d4ddb7a41489ba4958
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.