distros/skills/debian-debootstrap/SKILL.md
Bootstrap-from-scratch Debian rootfs via debootstrap inside a privileged builder (from: builder:debootstrap, bootstrap_builder_image: debian-debootstrap-builder). Retained for offline/air-gapped builds and as a worked example of the from: builder:debootstrap pattern. Lives in the overthinkos/debian submodule (box/debian). MUST be invoked before building or troubleshooting debian-debootstrap.
npx skillsauth add overthinkos/overthink-plugins debian-debootstrapInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Bootstrap-from-scratch Debian root filesystem, built via debootstrap inside
the privileged /charly-distros:debian-debootstrap-builder container
(from: builder:debootstrap, bootstrap_builder_image: debian-debootstrap-builder).
Lives in
overthinkos/debian(git submodule atbox/debian). Build:charly -C box/debian box build debian-debootstrap.
The canonical Debian base (/charly-distros:debian) pulls the upstream-published
debian:13 OCI image from Docker Hub — that is the recommended, faster path
(no privileged build). This debootstrap variant exists for offline /
air-gapped builds and as a worked example of the from: builder:debootstrap +
bootstrap_builder_image: pattern (the deb-family counterpart of
/charly-distros:arch-pacstrap / /charly-distros:cachyos-pacstrap).
| Property | Value |
|----------|-------|
| From | builder:debootstrap |
| bootstrap_builder_image | debian-debootstrap-builder |
| Distro | debian:13, debian |
| Build | deb |
| Home repo | overthinkos/debian (box/debian) |
The debian distro config (debootstrap suite trixie, mirror
http://deb.debian.org/debian, base packages, bootloader template) lives in the
embedded build vocabulary (charly/charly.yml, baked into the charly binary)
and is resolved by name from the submodule's distro: debian reference.
/charly-distros:debian — the recommended Docker-Hub base/charly-distros:debian-debootstrap-builder — the privileged builder it uses/charly-vm:debian — the VM built via the same debootstrap pathMUST be invoked before building or debugging the Debian debootstrap rootfs. Invoke BEFORE reading source code or launching Explore agents.
tools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).