Production-grade platform engineering handbook — Kubernetes, Terraform, Flux CD, GitHub Actions, AWS, and more.
67
84%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Passed
No known issues
Status: Stable
Working examples for the /platform-skills:supply-chain skill.
| File | Description |
|---|---|
sign-and-push.yaml | GitHub Actions: build, sign with Cosign keyless, and push |
sbom-attest.yaml | GitHub Actions: generate SBOM with Syft and attest |
trivy-gate.yaml | GitHub Actions: Trivy CVE scan with CRITICAL+HIGH severity gate |
kyverno-verify-image.yaml | Kyverno ImageValidatingPolicy: block unsigned images |
slsa-provenance.yaml | GitHub Actions: SLSA Level 2 provenance via slsa-github-generator |
Copy the relevant file into your .github/workflows/ or policies/ directory and substitute <org> and <image> placeholders.
bash examples/supply-chain/supply-chain-validate.sh.claude-plugin
.github
commands
docs
examples
agent-self-improve
argocd
awesome-docs
aws
cloudfront
functions
lambda-edge
functions
azure
compliance
conventional-commits
datadog
llm-observability
demo
documentation
dora
dynatrace
fluxcd
github-actions
composite-actions
configure-cloud
db-migrate
docker-build-push
k8s-deploy
notify-slack
pr-comment
release-tag
security-scan
setup-env
setup-terraform
terraform-plan
helm
web-service
templates
kubernetes
kyverno
mcp
observability
openshift
pr-review
ownership
runtime-security
supply-chain
terraform
references
scripts
skills
platform-skills
tests