coder/skills/ov-full/SKILL.md
Full ov toolchain composition with CLI, virtualization, encrypted storage, and console access. Works identically on container/pod targets AND on host/local/bootc targets via the unified virtualization layer's mixed-`service:` schema — one layer for every target, no `-host` sibling.
npx skillsauth add overthinkos/overthink-plugins ov-fullInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Layers (composition) | ov, virtualization, gocryptfs, socat |
| Install files | none (pure composition) |
| Target context | works for kind: image (container/pod), kind: vm (bootc/cloud_image), AND kind: local (host install) — the underlying virtualization layer handles init-system polymorphism via the mixed-entry service: pattern |
ONE ov-full layer covers both contexts. The unified virtualization layer carries BOTH a supervisord-rendered form (custom exec: for virtqemud/virtnetworkd) AND a systemd-rendered form (use_packaged: virtqemud.socket / virtnetworkd.socket) under the same name: — the init system at deploy time picks the matching form. See CLAUDE.md "Init-system polymorphism via mixed service: entries" for the rule and /ov-infrastructure:virtualization for the canonical worked example.
# overthink.yml
image:
my-vm-host:
layers:
- ov-full # works on pod images
local:
my-host-profile:
layers:
- ov-full # works on host installs (target: local)
The same layer reference works for both shapes; no -host variant is needed or available.
/ov-tools:ov -- ov CLI binary (included)/ov-infrastructure:virtualization -- QEMU/KVM/libvirt stack with mixed-entry service: for both supervisord and systemd (included; canonical worked example of the polymorphism pattern)/ov-infrastructure:gocryptfs -- encrypted filesystem for ov config encrypted volumes (included)/ov-infrastructure:socat -- socket relay for console access and port_relay (included)/ov-distros:bootc-base -- often paired for OS images/ov-coder:arch-ov/ov-distros:fedora-ov/ov-distros:githubrunner/ov-distros:auroraov-cachyos kind:local templateUse when the user asks about:
ov-full layer serves pod, VM, and host targets (no -host variant)/ov-image:layer — layer authoring; "Service Declaration" + "Anti-pattern: <name>-host / <name>-pod sibling layers" subsections/ov-infrastructure:supervisord — init system documentation for container-side rendering/ov-eval:eval — declarative testing (eval: block, ov eval image, ov eval live)service: entries" Key Ruletools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).