VA

vastai-enterprise-rbac

Configures API key separation, budgets, and access control policies for team-based GPU usage on Vast.ai.

Install

mkdir -p .claude/skills/vastai-enterprise-rbac && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7609" && unzip -o skill.zip -d .claude/skills/vastai-enterprise-rbac && rm skill.zip

Installs to .claude/skills/vastai-enterprise-rbac

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Implement team access control and spending governance for Vast.ai GPU
69 charsno explicit “when” trigger
Advanced

Key capabilities

  • →Configure team-specific API keys
  • →Enforce GPU model whitelists
  • →Set instance limits and daily budgets
  • →Generate audit logs for provisioning actions
  • →Produce team spending reports

How it works

The skill implements a policy enforcement layer that checks provisioning requests against team-specific whitelists and budget caps before interacting with the Vast.ai API.

Inputs & outputs

You give it
Team configuration and policy constraints
You get back
Audit logs and spending reports

When to use vastai-enterprise-rbac

  • →Setting up team-specific API keys for billing isolation
  • →Enforcing GPU model restrictions per project
  • →Implementing daily budget limits
  • →Managing multi-team access to GPU resources

About this skill

Native Vast.ai Team and Key Governance

Overview

Use the platform's Teams and permission-category model instead of inventing an application-only proxy. Separate human roles from automation keys, constrain high-risk endpoints when possible, and prove both required access and expected denial.

Prerequisites

  • Team owner and inventory of members, services, resources, and environments
  • Actor-by-action matrix for instance, user, billing, machine, miscellaneous, and team categories
  • Joiner, mover, leaver, emergency-access, and periodic-review procedures

Instructions

Step 1: Model responsibilities

Map each actor to read and write operations. Keep billing-write, team-write, machine-write, and instance destruction separate unless a documented duty requires them.

Step 2: Choose default or custom roles

Use Owner, Manager, or Member only when the preset matches. Otherwise create a named custom role from the minimum documented permission categories.

Step 3: Constrain automation keys

Create a different named key per service and environment. Use endpoint and ID constraints where the API supports eq, gte, or lte.

Step 4: Test both directions

For every role or key, run one required action and one prohibited action. A role is not accepted until the denial is observed.

Step 5: Operate membership lifecycle

Assign roles during invitation, review movers before expanding access, remove departed members, revoke stale keys, and record effective context.

Step 6: Review and recover

Export members, roles, keys, and audit evidence on schedule; time-bound emergency elevation and verify removal afterward.

Authentication

Team roles govern member actions; scoped API keys govern programmatic access. Do not share personal full-access keys, and never give monitoring or cost-analysis jobs write authority by convenience.

Tool Discipline

Use Read and Grep to inspect manifests, configuration, provider output, and existing tests before proposing a mutation. Use Write or Edit only for the approved plan, implementation, test, or redacted receipt; do not create, update, destroy, or fund Vast.ai resources without explicit operator approval.

Output

  • Actor/action matrix and role/key design
  • Positive and negative access-test evidence
  • Membership, key, review, and emergency-access receipt

Return team context, role/key IDs, permission categories and constraints, tests, exceptions, reviewer, and next review date.

Examples

A deployment service gets misc, user_read, instance_read, and instance_write; a monitoring key gets only read categories; neither receives billing-write or team-write, and prohibited credit transfer is tested.

Error Handling

FailureResponse
Required action is deniedAdd only the missing documented permission and rerun the denial suite.
Prohibited action succeedsRemove excess access immediately and review audit logs.
Member context is ambiguousStop mutation and confirm personal versus team context.
Emergency elevation outlives its windowRevoke it, verify denial, and open a governance incident.

Resources

Prerequisites

Vast.ai account with API keysUnderstanding of team GPU usageBudget allocation per team

Limitations

  • →Requires manual wiring of logger into operations
  • →Budget enforcement depends on accurate audit logs

How it compares

This provides a programmatic governance layer over the marketplace model, enabling cost control and access isolation that is not native to the platform.

Compared to similar skills

vastai-enterprise-rbac side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
vastai-enterprise-rbac (this skill)12moReviewAdvanced
secrets-management55moReviewAdvanced
healthcheck104moReviewIntermediate
secops-setup-antigravity48moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore →

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

Search skills

Search the agent skills registry