CtrlK
BlogDocsLog inGet started
Tessl Logo

devsecops-architecture

DevSecOps pipeline architecture — CI/CD design, shift-left security, supply chain integrity, release management, and compliance automation. Use when the user asks to 'design the CI/CD pipeline', 'integrate security into delivery', 'set up SBOM and artifact signing', 'automate compliance', 'measure DORA metrics', or mentions SAST, SCA, DAST, secrets scanning, IaC scanning, canary deployment, or policy-as-code. [EXPLICIT]

SKILL.md
Quality
Evals
Security

Devsecops Architecture

Generic, brand-neutral engineering capability; deep, sourced playbooks live in references/ and knowledge/. [DOC]

Generic, brand-neutral engineering capability; sourced playbooks in references//knowledge/. [DOC]

TL;DR

DevSecOps architecture designs how software is built, tested, secured, and released to production. It integrates security into every stage of the delivery pipeline, ensuring code quality, compliance, and supply chain integrity [EXPLICIT]

When to Use

  • Designing CI/CD pipelines (build, test, deploy stages, environments)
  • Integrating security into delivery (shift-left: SAST, SCA, secrets scanning)
  • Designing supply chain security (SBOM, dependency verification, artifact signing)
  • Implementing release management (versioning, feature flags, canary deployments)
  • Building pipeline observability (DORA metrics)
  • Automating compliance (policy-as-code, audit trails, evidence collection)
  • Establishing minimum controls (security gates per pipeline stage)

When NOT to Use

  • Internal software structure → software-architecture
  • End-to-end solution design → solutions-architecture
  • Enterprise portfolio alignment → enterprise-architecture
  • Infrastructure and platform → infrastructure-architecture

Sub-capabilities (resource map)

Deep, evidence-tagged playbooks — open the one the task needs (ICM Layer 3, on-demand). [INFERENCE]

Reference
references/devsecops-patterns.md
references/full-playbook.md
references/knowledge-graph.mmd
references/state-of-the-art.md

Procedure

  1. Resolve the sub-capability; open the matching references/ playbook. [EXPLICIT]
  2. Apply its decision tables; pick the strategy explicitly. [EXPLICIT]
  3. Validate against the Quality Criteria and tag every claim. [EXPLICIT]

Quality Criteria

  • Sub-capability resolved to one playbook. [INFERENCE]
  • Claims evidence-tagged. [EXPLICIT]

Contract

  • Aceptación: capability resolved to its reference playbook, applied, validated, evidence-tagged. [EXPLICIT]
  • Límites: · Pipeline architecture constrained by application architecture (see software-architecture) · Deployment safety depends on infrastructure availability (see **infrastructure-arc. [EXPLICIT]
  • Casos borde: Caso Estrategia de Manejo --- --- Sistema legacy sin pipeline Construir pipeline incrementalmente: tests primero, luego automatizacion, luego gates; no intentar todo de. [EXPLICIT]
  • Supuestos: · Software development process in place (teams, repositories, tools) · Containerization (Docker) is the deployment unit · Infrastructure provisioned (cloud or on-premises) · Compli. [SUPUESTO]
  • Trade-off: Decision Enables Constrains When to Use --- --- --- --- Continuous Deployment Rapid feedback, fast rollback, low batch size High ops burden, strong automation. [EXPLICIT]

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.