ov-coder/skills/ov-full/SKILL.md
Full ov toolchain composition with CLI, virtualization, encrypted storage, and console access. Works identically on container/pod targets AND on host/local/bootc targets via the unified virtualization layer's mixed-`service:` schema. The previous ov-full-host sibling was deleted in the 2026-05 init-system-polymorphism cutover.
npx skillsauth add overthinkos/overthink-plugins ov-fullInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Layers (composition) | ov, virtualization, gocryptfs, socat |
| Install files | none (pure composition) |
| Target context | works for kind: image (container/pod), kind: vm (bootc/cloud_image), AND kind: local (host install) — the underlying virtualization layer handles init-system polymorphism via the mixed-entry service: pattern |
Before: two sibling layers — ov-full (container/pod, used virtualization + gvisor-tap-vsock + podman-machine) and ov-full-host (host installs, used virtualization-host and dropped the container-only artifacts). They drifted because every change had to be applied twice.
After: ONE ov-full layer for both contexts. The container-only gvisor-tap-vsock + podman-machine packages were dropped entirely (legacy/unused per audit; nothing in the codebase invoked them). The unified virtualization layer carries BOTH a supervisord-rendered form (custom exec: for virtqemud/virtnetworkd) AND a systemd-rendered form (use_packaged: virtqemud.socket / virtnetworkd.socket) under the same name: — the init system at deploy time picks the matching form. See CLAUDE.md "Init-system polymorphism via mixed service: entries" for the rule and /ov-foundation:virtualization for the canonical worked example.
# overthink.yml
image:
my-vm-host:
layers:
- ov-full # works on pod images
local:
my-host-profile:
layers:
- ov-full # works on host installs (target: local)
The same layer reference works for both shapes; no -host variant is needed or available.
/ov-foundation:ov -- ov CLI binary (included)/ov-foundation:virtualization -- QEMU/KVM/libvirt stack with mixed-entry service: for both supervisord and systemd (included; canonical worked example of the polymorphism pattern)/ov-foundation:gocryptfs -- encrypted filesystem for ov config encrypted volumes (included)/ov-foundation:socat -- socket relay for console access and port_relay (included)/ov-foundation:bootc-base -- often paired for OS images/ov-coder:arch-ov/ov-foundation:fedora-ov/ov-foundation:githubrunner/ov-foundation:aurora (disabled)ov-cachyos kind:local template (post-2026-05)Use when the user asks about:
ov-full-host no longer exists/ov-build:layer — layer authoring; "Service Declaration" + "Anti-pattern: <name>-host / <name>-pod sibling layers" subsections/ov-foundation:supervisord — init system documentation for container-side rendering/ov-build:eval — declarative testing (eval: block, ov eval image, ov eval live)service: entries" Key Ruletools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).