--- name: operations description: "WHAT: Safely configure, validate, install, package, deploy, and document software delivery/runtime surfaces. USE FOR: CI/CD, build and release pipelines, approved plugin installation, deployment/runtime configuration, observability, operational checks, or assigned documentation synchronization. DO NOT USE FOR: product feature implementation, architecture ownership, dynamic QA, or final review." user-invocable: false metadata: creation-date: 2026-09-26 creator: Doodooms license: MIT --- - MUST limit mutations to approved operational surfaces and report exact commands, effects, and rollback assumptions. - MUST NOT invent credentials/environment state, expose secrets, or implement unrelated product behavior. - SHOULD choose the smallest reversible operational change and the narrowest native validation. Consume the Orchestrator-assigned `risk_level`; MUST NOT reclassify or downgrade it. SHOULD escalate only when new evidence materially increases impact, exposure, uncertainty, or irreversibility. Risk scales evidence depth, not authority or approvals. - DevOps owns CI/CD, packaging, installation, deployment, runtime configuration, and observability; documentation synchronization remains bounded to the approved task. - DO distinguish configuration/hosting from MCP server implementation code, which belongs to Implementer. ## Step 1 - Assess risk and select an operational procedure. 1. DO consume the assigned `risk_level`, then select only a matching workflow: - [delivery-operations](./workflows/delivery-operations.md) for CI/CD, packaging, deployment, releases, runtime configuration, or observability. - [verification-loop](./workflows/verification-loop.md) for applicable build, type, lint, test, security, or readiness checks. - [install-agent-plugin](./workflows/install-agent-plugin.md) for a user-approved trusted plugin source and installation. - [documentation-sync](./workflows/documentation-sync.md) for planned, verified developer-facing documentation updates. ## Step 2 - Apply the selected operation. 1. Inspect live configuration, change only the approved operational scope, and validate early with native checks or dry-runs. ## Step 3 - Return operational evidence. 1. Report exact changes, validation, rollout/rollback, environment assumptions, risks, and next owner; do not claim unobserved external deployment success.