Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Paas Deploy

ASecurity

Deploying applications on Platform-as-a-Service — build, config, and release patterns that work on any PaaS.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentspythongosqlnodedockerdebugginggitapidatabase

Works with

cliapi

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill paas-deploy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Paas Deploy?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Paas Deploy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-paas-deploy/badge)](https://www.skillsdirectory.com/skills/aicodedecode-paas-deploy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: paas-deploy
description: Deploying applications on Platform-as-a-Service — build, config, and release patterns that work on any PaaS.
category: railway
---

## Overview

Platform-as-a-Service offerings (Render, Fly.io, Heroku-style platforms, and
similar) abstract away servers: you provide code, they handle building,
running, networking, and scaling. The concepts transfer across providers —
buildpacks vs Dockerfiles, config via environment, ephemeral filesystems, and
managed add-ons. This skill covers deploying well on any PaaS.

## When to use

- Deploying a web app or API to a PaaS for the first time
- Choosing between buildpacks, Nixpacks-style detectors, and Dockerfiles
- Managing environment variables, secrets, and per-environment config
- Handling deploys: zero-downtime releases, rollbacks, preview environments
- Debugging failed builds or crashed deployments on a PaaS

## Core concepts

**The platform builds from your repo.** Most PaaS providers detect your stack
(Python/Node/Go/…) and build automatically, or accept a Dockerfile for full
control. Dockerfiles are more reproducible and portable across providers;
auto-detection is faster to start. For anything beyond a prototype, prefer an
explicit Dockerfile — it documents the runtime and behaves identically
everywhere.

**Config comes from the environment.** Twelve-factor: no config in code or
the repo. Environment variables for secrets, URLs, and per-environment
settings; managed secret stores where the platform offers them. Never commit
`.env` files; document required variables in a `.env.example`.

**Filesystems are ephemeral.** Local disk doesn't persist across deploys or
restarts on most PaaS platforms. Uploads, caches, and SQLite files need
object storage or a persistent volume add-on — design for statelessness from
day one.

**Releases are atomic-ish.** Platforms typically build → health-check → swap
traffic. Understand your provider's exact semantics: does the old version
serve until the new one passes checks? How do you roll back (redeploy the
previous build vs git revert)? Know this before the incident, not during.

**Preview environments multiply value.** Per-PR ephemeral environments catch
integration bugs early. They're cheap on PaaS — use them, with seeded data
and realistic config, as part of the review workflow.

## Practical workflow

1. **Containerize explicitly:** write a multi-stage Dockerfile (small final
   image, non-root user, healthcheck), `.dockerignore` aggressively.
2. **Externalize config:** enumerate every env var in `.env.example` with
   descriptions; set them per environment in the platform dashboard/CLI;
   validate required vars at boot with a clear error.
3. **Wire health checks:** a lightweight `/health` endpoint; configure the
   platform's checks so broken deploys never receive traffic.
4. **Set up the pipeline:** main branch auto-deploys (or manual promotion),
   preview envs per PR, database migrations as a release step (expand-
   contract compatible).
5. **Add the essentials:** managed Postgres/Redis add-ons (or external),
   log drains to your aggregator, metrics/alerts, and a custom domain with
   TLS.
6. **Practice the failure paths:** trigger a failed deploy (does traffic stay
   on the old version?), roll back once deliberately, and restore the
   database from backup to a scratch environment.

## Common pitfalls

- **State on ephemeral disk** — uploads vanish on redeploy; use object
  storage or persistent volumes from the start.
- **Builds that work locally but fail on the platform** — missing system
  deps, different Node/Python versions, devDependencies needed at build
  time; pin versions and test the Docker build in CI.
- **Secrets in the repo or build logs** — leaked via committed `.env` or
  echoed in build output; use the platform's secret management.
- **No health checks** — broken code passes "deploy succeeded" and takes
  traffic; health checks are what make deploys safe.
- **Migrations run at the wrong time** — against the new code before it's
  live, or not at all; make migrations a deliberate release phase.
- **Vendor-specific assumptions baked in** — keep the Dockerfile and config
  portable so the app can move providers without a rewrite.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →