Agent Plugins Marketplace
← All plugins

devops

v2.28.0

DevOps and deployment skills for eRegistrations infrastructure — Docker Swarm migration, Bitbucket→GitHub Actions repo migration, mule3-* post-migration alignment (CI/CD + propagator wiring), eRegistrations platform-version instance upgrades (orchestrator + per-env/per-version-pair sub-skills), configuration management, and deployment automation.

Claude Code16 Skills

By UNCTAD Trade Facilitation SectionLicense: SEE LICENSE IN LICENSE0 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Claude Code
Parsed components
16 skill or MCP entries
Source updated
Sep 30, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install devops for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install devops-5@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/UNCTAD-eRegistrations/plugin-marketplace

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/devops/.

Plugin files

plugins/devops/
├── .claude-plugin/plugin.json
├── skills/align-mule3-repo/SKILL.md
├── skills/bitbucket-jenkins-to-github-actions/SKILL.md
├── skills/cas-to-keycloak/SKILL.md
├── skills/cas-to-keycloak-add-service/SKILL.md
├── skills/cas-to-keycloak-migrate-apps/SKILL.md
├── skills/cas-to-keycloak-orchestrator/SKILL.md
├── skills/cas-to-keycloak-prepare-realm/SKILL.md
├── skills/cas-to-keycloak-rewrite-bpa-postgres/SKILL.md
├── skills/cas-to-keycloak-rewrite-camunda-role-groups/SKILL.md
├── skills/correct-db-passwords/SKILL.md
├── skills/create-draft-instance/SKILL.md
├── skills/decrypt-edit-encrypt/SKILL.md
├── skills/docker-swarm-migration/SKILL.md
├── skills/env-to-docker-secret/SKILL.md
├── skills/prepare-instance-for-live/SKILL.md
└── skills/release-platform/SKILL.md

Included Skills16

align-mule3-reposkills/align-mule3-repo/SKILL.md

Align a freshly-imported `mule3-<country>` GitHub repo with the conventions shared by `mule3-benin` / `mule3-colombia`: GitHub Actions CI/CD (replacing any Jenkinsfile), Dockerfile that consumes a host-built artifact, npm `standard-version` sourced from the propagator's packages-branch tarball, `develop` as the default branch with a delete-protection ruleset, the `v4-development` org team with push, a one-time `mule-common` / `mule3-datamapping-connector` pom bump to current packages-branch versions, and PRs against `mule-common` and `mule3-datamapping-connector` adding the repo to their `propagate-version` consumer matrices so future bumps land automatically. Idempotent — detects what is already aligned and skips it. Use immediately after a mule3-<country> repo is created/imported on GitHub and before its first dev push, or whenever a mule3-<country> CI build fails with `mule-common <old> not found in packages branch`.

bitbucket-jenkins-to-github-actionsskills/bitbucket-jenkins-to-github-actions/SKILL.md

Migrate a repository from Bitbucket+Jenkins to GitHub+GitHub Actions, including git history, branches, tags, CI/CD pipeline conversion (Jenkinsfile → ci-cd.yml), helm chart updates, branch deletion ruleset, and post-migration validation. Asks clarifying questions and handles external dependencies interactively. Use when migrating UNCTAD-eRegistrations repos from Bitbucket to GitHub.

cas-to-keycloakskills/cas-to-keycloak/SKILL.md

End-to-end CAS → Keycloak user / role migration pipeline for eRegistrations country instances. Three operational modes: `fetch` (dump cas + partc schemas from a source Postgres via ssh + sudo), `seed` (run a throwaway Docker stack that imports the realm JSON and produces an enriched `sql/keycloak.sql` ready to load into a target Keycloak's Postgres), and `backfill` (apply only the realm-role + role-mapping diff against an already-running Keycloak — idempotent, useful when the previous seed was buggy or new custom roles appear in partc later). Generic across country instances; ships Cuba's SQL extracts as a reference; tested against the Cuba MINCEX preview deployment.

cas-to-keycloak-add-serviceskills/cas-to-keycloak-add-service/SKILL.md

Add the Keycloak service to an eRegistrations instance that currently uses CAS authentication. Inserts the keycloak service block into the country's docker-compose.yml / docker-stack.yml (docker-compose or swarm shape) and the keycloak ACLs + backends into the haproxy.cfg. Idempotent — if a keycloak block is already present, surfaces it for the operator and exits without changes. Phase 0a in the cas-to-keycloak orchestrator chain.

cas-to-keycloak-migrate-appsskills/cas-to-keycloak-migrate-apps/SKILL.md

Flip an eRegistrations country instance's application services from CAS to Keycloak. Removes the cas-backend / cas-frontend / partc-backend / partc-frontend service blocks from the compose, removes CAS/PARTC ACLs + backends from the haproxy, and updates each remaining service's env vars (KEYCLOAK_*, AUTH_SERVICE_*, OAUTH_*) to point at the new Keycloak. Resolves the two realm UUIDs from realm.json (institutions group + eregistrations client scope) — never hardcoded. Diffs against kenya LIVE as the canonical reference. Phase 4 in the cas-to-keycloak orchestrator chain.

cas-to-keycloak-orchestratorskills/cas-to-keycloak-orchestrator/SKILL.md

End-to-end orchestrator for the CAS → Keycloak cutover. Walks the ten-phase chain (verify → add-service → prepare-realm → fetch → seed → deploy → migrate-apps → backfill → rewrite-bpa-postgres → rewrite-camunda-role-groups) by invoking the sibling skills via the Skill tool, threading context (resolved realm UUIDs, generated OAuth secrets, dump paths, target ssh host) so the operator is asked each question once. Surfaces a confirmation gate before any mutating step (deploy, migrate-apps, backfill, rewrite-bpa-postgres, rewrite-camunda-role-groups). Operators wanting to run just one phase can keep invoking the individual sibling skills directly — this orchestrator is the all-in-one path.

cas-to-keycloak-prepare-realmskills/cas-to-keycloak-prepare-realm/SKILL.md

Prepare a Keycloak realm JSON configuration file by substituting all `*_PLACEHOLDER` tokens in the canonical starter-conf template with concrete values (realm code, domain, OAuth client IDs, generated client-secret UUIDs, SMTP config). Writes the realm.json to the target country's `Conf-<ENV>/compose/<country>/`. Phase 0b in the cas-to-keycloak orchestrator chain.

cas-to-keycloak-rewrite-bpa-postgresskills/cas-to-keycloak-rewrite-bpa-postgres/SKILL.md

Rewrite legacy PARTC integer institution_id / unit_id values in BPA's own postgres to the corresponding Keycloak group UUIDs after a CAS-to-KC migration. Required cutover step — without it, BPA-frontend's institution picker calls KC `/admin/realms/<R>/groups/{id}/children` with stale PARTC integers and 404s. Reads the `partc_institution_id` / `partc_unit_id` attributes stamped on KC groups by the `cas-to-keycloak` seed phase (accepts the legacy `partc_institution_unit_id` key for back-compat). Phase 8 in the cas-to-keycloak orchestrator chain.

cas-to-keycloak-rewrite-camunda-role-groupsskills/cas-to-keycloak-rewrite-camunda-role-groups/SKILL.md

Rewrite legacy CAS-style tokens (`i<partc_id>[_<role>]`, `u<partc_id>[_<role>]`, bare unit ids) in Camunda's `ereg_service_role_group` table to the Keycloak group UUIDs created by the CAS-to-KC migration. Required cutover step — without it ds-backend's institution filter (`apps/utilities/institution_permissions.py`) finds no overlap between the user's KC group UUIDs and the stored legacy tokens, so every PartB operator sees an empty service list until each service is republished through BPA. Reads the `partc_institution_id` / `partc_unit_id` attributes stamped on KC groups by the `cas-to-keycloak` seed phase. Phase 9 in the cas-to-keycloak orchestrator chain.

correct-db-passwordsskills/correct-db-passwords/SKILL.md

Generate a script that resets PostgreSQL and MongoDB user passwords on the DB hosts backing an eRegistrations stack to match the values in the host's `.env` file. Handles BOTH the legacy compose shape (variable-driven — `=$BPA_POSTGRES_DB_USER`, `=$BPA_POSTGRES_DB_PASSWORD`) and the swarm post-cleanup shape (hardcoded literal usernames + Docker-secret-named passwords — `=bpa`, `=DOCKER_SECRET:BPA_POSTGRES_DB_PASSWORD`), and any mixture of the two within a single stack. Discovery is service-block-scoped: for every service that talks to Postgres or MongoDB it extracts the user / database / password-source triple from environment lines and JDBC URLs, then emits `sync-db-passwords.sh` — a self-contained bash script that runs `ALTER USER` on Postgres and `db.changeUserPassword` on MongoDB. Idempotent. Password-only — never creates users or databases.

create-draft-instanceskills/create-draft-instance/SKILL.md

Create a draft (UAT) instance configuration for an eRegistrations LIVE instance, and wire the LIVE side to point at it. Strips LIVE-only services (keycloak, bpa-*, websocket, public-pages-*), adds the publisher service, rewrites own-domain refs to `draft.<base>.eregistrations.org`, keeps cross-refs (BPA, Keycloak) pointing at LIVE, and patches LIVE bpa-backend `EXTERNAL_SERVERS` + gdb `GDB_CLIENT_URL_1`. Keycloak-only — CAS instances are out of scope. Use when standing up a new draft alongside an existing LIVE instance for UAT of upcoming platform versions.

decrypt-edit-encryptskills/decrypt-edit-encrypt/SKILL.md

Walk an operator through the decrypt then read/edit then re-encrypt cycle for `.env.enc` and `.secrets.enc` files (and any sibling) protected with `openssl enc -aes-256-cbc -pbkdf2`. Auto-discovers `*.enc` files in the target directory, verifies the plaintext sibling is git-ignored before decrypting, runs openssl interactively so the operator types the password at openssl's own prompt (the skill never sees, logs, or stores it), supports in-band (Read/Edit) or out-of-band (operator's editor) editing, re-encrypts with matching parameters, then securely removes the plaintext. Idempotent and abortable; never deletes ciphertext, never overwrites a newer plaintext without confirmation, never embeds the password on a command line.

docker-swarm-migrationskills/docker-swarm-migration/SKILL.md

Convert Docker Compose files to Docker Swarm stack format for eRegistrations deployments. Handles env var replacement, secrets management, init-swarm.sh generation, reference stack validation, and dry-run preview. Use when migrating docker-compose.yml to docker-stack.yml, adding deploy sections, configuring overlay networks, or converting environment secrets to Docker Swarm secrets.

env-to-docker-secretskills/env-to-docker-secret/SKILL.md

Generate `env-to-secrets.sh`, a self-contained converter that reads a `.env` file (`KEY=VALUE` lines) and emits a `.secrets` file containing one `printf '%s' 'VALUE' | docker secret create KEY -` line per entry. Skips comments and blank lines, strips surrounding single/double quotes from values (standard `.env` convention), and escapes embedded single quotes so the resulting `printf '...'` blocks are safe to feed back into bash. Supports dry-run (preview to stdout, no file written), custom input/output paths, and filter/exclude patterns. Use when standing up a Docker Swarm stack from an existing `.env` and you need every variable mirrored as a Docker secret without hand-typing the commands.

prepare-instance-for-liveskills/prepare-instance-for-live/SKILL.md

Generate `prepare-instance-for-live.sh` — a self-contained bash script that prepares a prelive eRegistrations instance for go-live by clearing all runtime/published artifacts. Drops and recreates the Camunda and ds-backend (`display_system`) Postgres databases (Camunda's `schema-update: true` re-bootstraps the engine schema on restart; Django runs migrations on startup), re-applies the post-recreate privileges the apps need (`pg_trgm` extension on display_system; read-only GRANTs to the statistics role on camunda), drops the Mongo `formio` database, and deletes the `_id: 'activeservices'` document from `documents.settings`. Service-block-scoped discovery against `docker-stack.yml` extracts per-instance Postgres DB names + owner roles + the statistics role name. Live backends are terminated via `pg_terminate_backend` before each `DROP DATABASE`. Idempotent. Typed instance-name confirmation rail. Admin users are not touched — they re-sync from Keycloak on next login.

release-platformskills/release-platform/SKILL.md

Cut a new platform release across all 28 eRegistrations repositories. Creates `release/<version>` branches from `develop`, pushes them, and bumps the minor version on `develop` in every repo. Supports `--dry-run` to preview without mutating, and an optional repo filter to operate on a subset. Usage - /release-platform [version] [--dry-run] [repo1 repo2 ...]

Plugin manifests1

plugins/devops/.claude-plugin/plugin.json
{
  "name": "devops",
  "description": "DevOps and deployment skills for eRegistrations infrastructure — Docker Swarm migration, Bitbucket→GitHub Actions repo migration, mule3-* post-migration alignment (CI/CD + propagator wiring), eRegistrations platform-version instance upgrades (orchestrator + per-env/per-version-pair sub-skills), configuration management, and deployment automation.",
  "version": "2.28.0",
  "author": {
    "name": "UNCTAD Trade Facilitation Section"
  },
  "license": "SEE LICENSE IN LICENSE"
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[devops on Agent Plugins Marketplace](https://pluginsmp.com/plugins/devops-5)