~ / rigs / plkarin / gitops-agentic-platform

plkarin/gitops-agentic-platform

Enterprise-grade agentic AI platform built on GitOps principles — immutable audit trails, FedRAMP-aligned compliance controls, and automated security pipelines for Claude Code deployments.

↗ GitHub ★ 0 mit updated 4mo ago project Claude Code
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~2.2k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit plkarin/gitops-agentic-platform/.claude ./rig-gitops-agentic-platform  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/backward-compatibility-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/backward-compatibility-check.md
$ curl -fsSL --create-dirs -o .claude/agents/change-impact-assessment.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/change-impact-assessment.md
$ curl -fsSL --create-dirs -o .claude/agents/runtime-risk-estimation.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/runtime-risk-estimation.md
$ curl -fsSL --create-dirs -o .claude/agents/session-audit.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/session-audit.md
$ curl -fsSL --create-dirs -o .claude/agents/ansible-idempotency-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/ansible-idempotency-check.md
$ curl -fsSL --create-dirs -o .claude/agents/bash-strict-mode-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/bash-strict-mode-check.md
$ curl -fsSL --create-dirs -o .claude/agents/config-drift-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/config-drift-detection.md
$ curl -fsSL --create-dirs -o .claude/agents/hardcoded-path-risk.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/hardcoded-path-risk.md
$ curl -fsSL --create-dirs -o .claude/agents/repo-structure-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/repo-structure-check.md
$ curl -fsSL --create-dirs -o .claude/agents/invocation.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/invocation.md
$ curl -fsSL --create-dirs -o .claude/agents/cli-ux-consistency.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/cli-ux-consistency.md
$ curl -fsSL --create-dirs -o .claude/agents/complexity-hotspot-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/complexity-hotspot-detection.md
$ curl -fsSL --create-dirs -o .claude/agents/dead-code-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/dead-code-detection.md
$ curl -fsSL --create-dirs -o .claude/agents/docstring-quality.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/docstring-quality.md
$ curl -fsSL --create-dirs -o .claude/agents/interface-contract-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/interface-contract-check.md
$ curl -fsSL --create-dirs -o .claude/agents/layering-violation-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/layering-violation-check.md
$ curl -fsSL --create-dirs -o .claude/agents/logging-consistency.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/logging-consistency.md
$ curl -fsSL --create-dirs -o .claude/agents/refactor-safety-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/refactor-safety-check.md
$ curl -fsSL --create-dirs -o .claude/agents/dependency-vulnerability-audit.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/dependency-vulnerability-audit.md
$ curl -fsSL --create-dirs -o .claude/agents/malware-scan.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/malware-scan.md
$ curl -fsSL --create-dirs -o .claude/agents/privilege-escalation-risk.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/privilege-escalation-risk.md
$ curl -fsSL --create-dirs -o .claude/agents/rootkit-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/rootkit-detection.md
$ curl -fsSL --create-dirs -o .claude/agents/secrets-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/secrets-detection.md
$ curl -fsSL --create-dirs -o .claude/agents/supply-chain-risk.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/supply-chain-risk.md
$ curl -fsSL --create-dirs -o .claude/agents/unsafe-tempfile-usage.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/unsafe-tempfile-usage.md
$ curl -fsSL --create-dirs -o .claude/agents/vulnerability-scan.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/vulnerability-scan.md
$ curl -fsSL --create-dirs -o .claude/agents/checkpoint.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/workflow/checkpoint.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Subagents (27)

backward-compatibility-check
model: claude-haiku-4-5-20251001
>
change-impact-assessment
model: claude-haiku-4-5-20251001
>
runtime-risk-estimation
model: claude-haiku-4-5-20251001
>
session-audit
model: claude-haiku-4-5-20251001
>
ansible-idempotency-check
model: claude-haiku-4-5-20251001
>
bash-strict-mode-check
model: claude-haiku-4-5-20251001
>
config-drift-detection
model: claude-haiku-4-5-20251001
>
hardcoded-path-risk
model: claude-haiku-4-5-20251001
>
repo-structure-check
model: claude-haiku-4-5-20251001
>
invocation—
cli-ux-consistency
model: claude-haiku-4-5-20251001
>
complexity-hotspot-detection
model: claude-haiku-4-5-20251001
>
dead-code-detection
model: claude-haiku-4-5-20251001
>
docstring-quality
model: claude-haiku-4-5-20251001
>
interface-contract-check
model: claude-haiku-4-5-20251001
>
layering-violation-check
model: claude-haiku-4-5-20251001
>
logging-consistency
model: claude-haiku-4-5-20251001
>
refactor-safety-check
model: claude-haiku-4-5-20251001
>
dependency-vulnerability-audit
model: claude-haiku-4-5-20251001
>
malware-scan
model: claude-haiku-4-5-20251001
>
privilege-escalation-risk
model: claude-haiku-4-5-20251001
>
rootkit-detection
model: claude-haiku-4-5-20251001
>
secrets-detection
model: claude-haiku-4-5-20251001
>
supply-chain-risk
model: claude-haiku-4-5-20251001
>
unsafe-tempfile-usage
model: claude-haiku-4-5-20251001
>
vulnerability-scan
model: claude-haiku-4-5-20251001
>
checkpoint
model: claude-sonnet-4-6
>

Similar rigs

copied ✓