doca-bf3-deployment
Use this skill for BlueField-3 (BF3) day-1 platform bring-up via the classic RShim/BFB path: pushing a BlueField bundle (BFB) to the DPU over RShim with bfb-install from the host, the host-to-DPU TMFIFO management channel (tmfifo_net0, the 192.168.100.x convention), RShim daemon state and console-ov
- 0
- Installs
- —
- Rating
- —
- Success rate
- 7
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 53b79045c2ef14e5… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
DOCA BlueField-3 (BF3) deployment
Where to start: This skill is the bundle's home for BlueField-3
day-1 platform bring-up — taking a BF3 from "powered card in the
slot" (or a card that just came back broken from a BFB push) to
"Arm OS healthy, TMFIFO up, host PFs bound, four-way version match
closed, ready to run a workload". It owns the classic RShim/BFB
path that BF3 uses today; the newer BMC-Redfish provisioning path
is the sibling skill
doca-bf4-deployment (the BF4
equivalent). If the user has a BF3 and needs to push a BFB, recover
a DPU that did not come back, or verify the install, open
TASKS.md and start at
## configure. If the question is what shape
does the BF3 platform-bring-up surface even have, start at
CAPABILITIES.md. Once the BF3 is healthy, this
skill routes onward to the deployment skills — running a binary
goes to
doca-bare-metal-deployment;
deploying a service container goes to
doca-container-deployment.
Every mutating burn invoked from a bring-up step — the BFB
reflash itself, any mlxconfig set (including a DPU/separated-host
mode flip), a firmware burn, or a kernel-boot-parameter change — is
governed by the change-application meta-policy in
doca-hardware-safety, which
the agent loads ALONGSIDE this skill. This skill adds only the
BF3-specific operational sequencing on top; it does NOT redefine
the preflight / OOB-console / maintenance-window / rollback
discipline that meta-policy owns.
Audience
This skill serves external DOCA operators bringing up a real BlueField-3 — i.e. people who already have:
- a physical BlueField-3 in a host (or a standalone BF3 they can reach over its console / management network),
- host-side RShim access to the DPU (the RShim userspace daemon and
the
/dev/rshim*character-device tree present over the PCIe or USB RShim interface), and - a matching DOCA-Host install on the host plus a BlueField bundle (BFB) image downloaded from the public DOCA Downloads page.
It is not for:
- BlueField-4 bring-up (the BMC-Redfish provisioning path) — route
to
doca-bf4-deployment, the BF4 equivalent of this skill, - kernel-driver or BlueField-OS developers contributing to
mlx5_*or the BFB image itself (that is internal-tree work, not a field deployment), - operators who already have a healthy BF3 and just want to run a
binary (route to
doca-bare-metal-deployment) or deploy a service container (route todoca-container-deployment), - fresh-no-hardware users with no DOCA install — route to
doca-setup ## no-install.
The skill teaches the agent the BF3 bring-up procedure and the
rules for quoting documented commands from the public BlueField
Platform Software Manual, the public DOCA Installation Guide, and
the MFT manual via
doca-public-knowledge-map;
it does not invent bfb-install flag sets, BFB image filenames,
RShim character-device paths, bf.cfg schema keys, mlxconfig
parameter names, or TMFIFO subnets from memory. Where a fact is
already vetted in
doca-bare-metal-deployment ## bluefield-lifecycle,
this skill reuses that exact fact rather than restating a new one.
When to load this skill
Load this skill when the user is doing hands-on BlueField-3 platform bring-up over the RShim/BFB path, or asking a cross-cutting BF3 lifecycle question that is not specific to one library's API. Concretely:
- Pushing a BFB image to a BF3 for the first time (or re-pushing
after a failed install), from the host over the RShim interface
with
bfb-install. - Bringing up or recovering the host-to-DPU TMFIFO management
channel (
tmfifo_net0, the documented192.168.100.xconvention) and the RShim console. - Confirming RShim driver/daemon state on the host (the userspace
rshimdaemon and the/dev/rshim*tree) before any push or console capture. - Deciding (and routing) a DPU-mode change — DPU / embedded-function
mode vs separated-host / NIC mode — knowing the actual
mlxconfig setburn leaves this skill fordoca-hardware-safety. - Recovering a BF3 that did not come back after a BFB push:
bfb-installexited 0 but the DPU never reached the documentedDPU is readymarker;ping 192.168.100.2works but SSH refuses; host PFs are present inlspci -d 15b3:but their netdevs are gone. - Verifying a BF3 install —
cat /etc/mlnx-releaseon the Arm side, the four-way version match perdoca-version— and distinguishing the host-side DOCA install from the BlueField-Arm-side DOCA install. - Cross-cutting questions: "is DOCA on the host or on the Arm
side, and which one do I install?", "my BF3 was fine last week
and after a BFB push it never came back — where do I start?",
"how do I tell which
/dev/rshim<N>is which BlueField on a multi-DPU host?".
Do not load this skill for: BlueField-4 bring-up (route to
doca-bf4-deployment, the BF4
equivalent); running a DOCA-linked binary on a healthy BF3 (route to
doca-bare-metal-deployment);
deploying a DOCA service container (route to
doca-container-deployment);
env-preparation including hugepages, IOMMU, pkg-config, and devlink
mode flips (use doca-setup); the body of
the version-match rule (use doca-version);
or any hardware-state-changing burn itself — the change-application
discipline is meta-policy owned by
doca-hardware-safety, loaded
ALONGSIDE this skill.
What this skill provides
This is a thin loader. Substantive material lives in two companion files:
CAPABILITIES.md— the BF3 platform-bring-up contract: the RShim/BFB transport surface (the userspace RShim daemon, the/dev/rshim*tree, console-over-rshim, the BFB image as the unit of input), the TMFIFO management-channel surface (tmfifo_net0/tm-br, the documented192.168.100.xconvention, theip route get-before-pingloopback gotcha), the DPU-mode surface (DPU / embedded-function vs separated-host / NIC mode, set viamlxconfigat BFB-install time — a MUTATING burn routed todoca-hardware-safety), the host-side-vs-Arm-side DOCA install distinction, the BF3-version overlay on the four-way match owned bydoca-version, the cross-cutting error taxonomy, the observability surface, and the safety policy (overlay ondoca-hardware-safety).TASKS.md— step-by-step workflows for the in-scope BF3 lifecycle verbs:configure,build(routing stub),modify,run(the BFB-install + RShim/TMFIFO bring-up sequence),test(the post-BFB readiness smoke),debug(the six-statebluefield-state-classifier), and theDeferred task verbsblock routing app-launch / container / install / library-API / hardware-state-change / BF4 questions out to their owning skills.
The skill assumes a target where:
- a BlueField-3 is physically present and powered, reachable from a
host that has the RShim daemon and
/dev/rshim*tree available, - the operator has a BFB image downloaded from the public DOCA
Downloads page (route via
doca-public-knowledge-map), and - the operator has an out-of-band path (BMC console, serial-over-LAN, or physical UART) to reach the BF3 if a push breaks the Arm OS.
It does not cover installing DOCA on a host from scratch (that
goes through doca-setup), and it does
not cover BlueField-4 (that goes through
doca-bf4-deployment).
Loading order
- Read this
SKILL.mdfirst to confirm the user's question is in scope (BF3 platform bring-up over the RShim/BFB path; NOT BF4, NOT app-launch, NOT a library-API question). - For the bring-up contract (RShim/BFB transport, TMFIFO channel, DPU-mode surface, host-vs-Arm install distinction, BF3-version overlay, error taxonomy, observability surface, BF3 safety overlay), see CAPABILITIES.md.
- For step-by-step workflows —
configure,build(routing stub),modify,run(BFB install + RShim/TMFIFO bring-up),test(post-BFB readiness smoke),debug(the six-statebluefield-state-classifier), plus theDeferred task verbsblock — see TASKS.md.
Example questions this skill answers well
What this skill deliberately does not ship
Related skills
Files
7- BENCHMARK.md
ad0ae3f29e4.0 KB - CAPABILITIES.md
b537b6859c18.9 KB - SKILL.md
a7e6c617a110.7 KB - TASKS.md
b087aa013b21.3 KB - evals/evals.json
b910e5063f2.6 KB - references/details.md
7ee5895c998.2 KB - skill-card.md
6992d5c3e04.3 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from NVIDIA/skills8
Official NVIDIA-authored guidance for NVIDIA cuDF GPU DataFrames, pandas acceleration, dask-cuDF, ETL, joins, groupby, CSV/Parquet I/O, nullable semantics, and multi-GPU DataFrame workloads.
Use when asked to install, deploy, run, validate, troubleshoot, or stop NVIDIA AI-Q Blueprint infrastructure.
Use when asked to run deep research or AI-Q research through a reachable NVIDIA AI-Q Blueprint backend.
Customize NVIDIA Nemotron Voice Agent's Generic Pipecat example for healthcare appointment, five-field patient intake, or custom tool-calling workflows without a separate backend.
Calibrate a new dataset from live RTSP camera streams via the AutoMagicCalib REST API. Use when the user provides RTSP URLs or asks to calibrate live cameras; VIOS records clips, AMC ingests them, then runs calibration.
Run end-to-end calibration on the shipped sample dataset (sdg_08_2_sample_data_010926.zip) against a running AMC microservice. Use when user says 'test sample dataset', 'run sample calibration', 'verify AMC install', or 'launch and test'.
Calibrates pre-recorded `cam_*.mp4` datasets through the AutoMagicCalib REST API. Use for user-supplied local MP4s; route live RTSP streams to `amc-run-rtsp-calibration`.
Launch AutoMagicCalib microservice and web UI from NGC release images via Docker Compose. Use when user says 'deploy auto calibration', 'launch auto calibration', 'launch AMC', 'start MS+UI', or 'set up auto-magic-calib'. Requires NGC API key.
Related devops skillsscan passed
Post-deploy canary monitoring. (gstack)
Pre-deployment checks for router and switch configuration, including dangerous commands, duplicate addresses, subnet overlaps, stale references, management-plane risk, and IOS-style security hygiene. Use when reviewing a router or switch configuration before deployment.
Migrate Cloudflare Sandbox apps from stable @cloudflare/sandbox to @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-next for apps already on the preview.
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.
Deploys and configures classic Firebase Hosting for static websites, single-page apps (SPAs), and microservices. Use when deploying static sites/SPAs, setting up custom domains, configuring firebase.json hosting settings (redirects, rewrites, headers, multi-site), or managing preview channels. Don't