vastai-enterprise-rbac
Configures API key separation, budgets, and access control policies for team-based GPU usage on Vast.ai.
Install
mkdir -p .claude/skills/vastai-enterprise-rbac && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7609" && unzip -o skill.zip -d .claude/skills/vastai-enterprise-rbac && rm skill.zipInstalls to .claude/skills/vastai-enterprise-rbac
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Implement team access control and spending governance for Vast.ai GPUKey capabilities
- →Configure team-specific API keys
- →Enforce GPU model whitelists
- →Set instance limits and daily budgets
- →Generate audit logs for provisioning actions
- →Produce team spending reports
How it works
The skill implements a policy enforcement layer that checks provisioning requests against team-specific whitelists and budget caps before interacting with the Vast.ai API.
Inputs & outputs
When to use vastai-enterprise-rbac
- →Setting up team-specific API keys for billing isolation
- →Enforcing GPU model restrictions per project
- →Implementing daily budget limits
- →Managing multi-team access to GPU resources
About this skill
Native Vast.ai Team and Key Governance
Overview
Use the platform's Teams and permission-category model instead of inventing an application-only proxy. Separate human roles from automation keys, constrain high-risk endpoints when possible, and prove both required access and expected denial.
Prerequisites
- Team owner and inventory of members, services, resources, and environments
- Actor-by-action matrix for instance, user, billing, machine, miscellaneous, and team categories
- Joiner, mover, leaver, emergency-access, and periodic-review procedures
Instructions
Step 1: Model responsibilities
Map each actor to read and write operations. Keep billing-write, team-write, machine-write, and instance destruction separate unless a documented duty requires them.
Step 2: Choose default or custom roles
Use Owner, Manager, or Member only when the preset matches. Otherwise create a named custom role from the minimum documented permission categories.
Step 3: Constrain automation keys
Create a different named key per service and environment. Use endpoint and ID constraints where the API supports eq, gte, or lte.
Step 4: Test both directions
For every role or key, run one required action and one prohibited action. A role is not accepted until the denial is observed.
Step 5: Operate membership lifecycle
Assign roles during invitation, review movers before expanding access, remove departed members, revoke stale keys, and record effective context.
Step 6: Review and recover
Export members, roles, keys, and audit evidence on schedule; time-bound emergency elevation and verify removal afterward.
Authentication
Team roles govern member actions; scoped API keys govern programmatic access. Do not share personal full-access keys, and never give monitoring or cost-analysis jobs write authority by convenience.
Tool Discipline
Use Read and Grep to inspect manifests, configuration, provider output, and existing tests before proposing a mutation. Use Write or Edit only for the approved plan, implementation, test, or redacted receipt; do not create, update, destroy, or fund Vast.ai resources without explicit operator approval.
Output
- Actor/action matrix and role/key design
- Positive and negative access-test evidence
- Membership, key, review, and emergency-access receipt
Return team context, role/key IDs, permission categories and constraints, tests, exceptions, reviewer, and next review date.
Examples
A deployment service gets misc, user_read, instance_read, and instance_write; a monitoring key gets only read categories; neither receives billing-write or team-write, and prohibited credit transfer is tested.
Error Handling
| Failure | Response |
|---|---|
| Required action is denied | Add only the missing documented permission and rerun the denial suite. |
| Prohibited action succeeds | Remove excess access immediately and review audit logs. |
| Member context is ambiguous | Stop mutation and confirm personal versus team context. |
| Emergency elevation outlives its window | Revoke it, verify denial, and open a governance incident. |
Resources
Prerequisites
Limitations
- →Requires manual wiring of logger into operations
- →Budget enforcement depends on accurate audit logs
How it compares
This provides a programmatic governance layer over the marketplace model, enabling cost control and access isolation that is not native to the platform.
Compared to similar skills
vastai-enterprise-rbac side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| vastai-enterprise-rbac (this skill) | 1 | 2mo | Review | Advanced |
| secrets-management | 5 | 5mo | Review | Advanced |
| healthcheck | 10 | 4mo | Review | Intermediate |
| secops-setup-antigravity | 4 | 8mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
secrets-management
wshobson
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
healthcheck
openclaw
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
secops-setup-antigravity
Helps the user configure the Google SecOps Remote MCP Server for Antigravity. Use this when the user asks to "set up" or "configure" the security tools for Antigravity.
cloud-penetration-testing
davila7
This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.
security-scanning-security-hardening
sickn33
Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
incident-response-incident-response
sickn33
Use when working with incident response incident response