Imported from SongketMail/aws-3tier-deployment-for-ai-infra (
.agents/skills/jules-knowledge/SKILL.md). Install upstream withnpx skills add SongketMail/aws-3tier-deployment-for-ai-infra --skill jules-knowledge. Copyright stays with the author.
Google Jules Infrastructure & Cloud Engineering Skill
This skill embeds the full engineering knowledge, context, standards, and constraints of Google Jules—an elite Cloud and Systems Engineer assisting in maintaining and optimizing the secure AWS 3-Tier Web & AI Infrastructure workspace. Other AI Agents, including Google Antigravity, must strictly follow and leverage this knowledge base.
1. Introduction, Core Purpose, and Navigation
- Google Antigravity & Agent Skills Integration: The repository supports Google Antigravity Skills, with this workspace-specific skill located at
.agents/skills/jules-knowledge/SKILL.mdcontaining comprehensive guidelines, architectural mapping, and standard operating procedures curated from Google Jules. - Developer Integration Guide: A developer integration guide for Google Antigravity Skills and the Agent Skills ecosystem is documented at
docs/antigravity-skills.mdand registered across all major documentation indices (docs/index.md,README.md, andllms.txt). - AI Agent Guidelines (
AGENTS.md): TheAGENTS.mdfile in the root directory outlines operating guidelines, standards, and behavioral constraints tailored for AI agents (specifically Google Jules) to ensure deterministic OpenTofu practices and strict adherence to architectural standards. - LLM Crawling Index (
llms.txt): Thellms.txtfile is located in the root directory following thellmstxt.orgspecification, serving as an index for LLM web crawlers and AI agents to discover, parse, and navigate all architecture, costing, scripting, and disaster recovery guides. - Developer Portal (
README.md): The rootREADME.mdis fully updated to serve as a comprehensive developer portal, structuring navigation paths to local repository files, OpenTofu (Terraform) submodules, and their fully compiled, respective Jekyll GitHub Pages documentation URLs. - Comprehensive Documentation Standard: The project requires comprehensive Markdown documentation for all modules, scripts, and workflows to support generating documentation pages for GitHub Pages. Centralized documentation is stored in the
docs/folder configured for Jekyll. - Sovereign GitHub Pages base URL: The deployed GitHub Pages site's base URL is
https://songketmail.github.io/aws-3tier-deployment-for-ai-infra/(as per Item 41).
2. Regional Defaults & Cloud Platform Target
- Default Target Region & Compute: The default deployment target is the AWS Asia Pacific (Malaysia) region (
ap-southeast-5), using ARM64/Graviton instances (t4g.microfor EC2/ASG anddb.t4g.microfor RDS PostgreSQL 16) by default. - Dynamic AMI Selection: The Auto Scaling Group (
asg) module dynamically selects the appropriate Amazon Linux 2023 AMI (ARM64 or x86_64) based on the configured EC2 instance type family. - Native OpenTofu Alignment: The infrastructure configuration and documentation have been updated to target OpenTofu natively. Outdated Terraform references were corrected, including setting the recommended version specification to
OpenTofu >= 1.6.0(while preserving backward compatibility withTerraform >= 1.5.0). - Sandbox Execution Constraint: The sandbox execution environment does not have the
terraformortofuCLI binaries installed by default.
3. Security, Hardening & Wazuh SIEM/XDR Deep-Dive
- Wazuh SIEM & XDR Integration: A comprehensive Wazuh SIEM & XDR Deep-Dive Guide (
docs/wazuh-detailed.md) outlines Wazuh's core functions, cloud and on-premises deployment modes, and critical operational guidance regarding Antivirus coexistence (including Windows Defender compatibility, third-party AV compatibility, potential conflict areas, and mutual exclusions configurations). This document is fully integrated into site navigations (docs/_config.yml), index files (docs/index.md,README.md,llms.txt), compilation pages (docs/print_all.md), and search sitemaps (sitemap.txt,sitemap.xml) (as per Item 1). - Dedicated Licensing & Technology Risk Register (TS/MC Series): Documented at
docs/licensing-risks.mdand integrated into Jekyll navigation, index files (docs/index.md,README.md), and guides (docs/tech-stack-comparison.md,docs/costing.md). It defines and tracks six critical risk/decision codes: LangChain4j SLA (TS-02), standalone Wazuh SIEM (TS-04), permissive/open-source licensing compliance (TS-05), self-hosted database operations (TS-06), Qwen3 LLM inference via Amazon Bedrock (MC-01), and Qwen3 embedding indexing (MC-02) (as per Item 46). - Legal Notice & Disclaimer (
docs/legal-notice.md): Conforms to OKF v0.1 format and is fully integrated into the layout footer (docs/_layouts/default.html), navigation bar (docs/_config.yml), index and portal documents (docs/index.md,README.md,llms.txt), print compilation (docs/print_all.md), and search sitemaps (sitemap.txt,sitemap.xml) (as per Item 8). - Context7 AI Widget & Page: A dedicated integration page at
docs/context7.mdcontains comprehensive documentation for the Context7 chat assistant widget. This page is formatted in compliance with OKF v0.1 front matter guidelines and integrated across all index files includingdocs/_config.yml,docs/index.md,README.md,llms.txt, anddocs/print_all.md(as per Item 30).
4. Software Stack Comparison, Role-Based Directories & SEO
- AWS-vs-Onprem 12-Layer Stack Comparison Guide: Documented at
docs/aws-vs-onprem-stack-comparison.md, this guide maps AWS services to onsite open-source equivalents across all core infrastructure layers (from Frontend to Error Tracking) and is fully integrated across all major portal indexes (as per Item 10). - Technology Stack Comparison Guide: Documented at
docs/tech-stack-comparison.mdand integrated into Jekyll navigation and indexes (docs/index.md,README.md,llms.txt), comparing the local containerized developer stack (Spring Boot, React, React Native, Redis, PostgreSQL, RAGFlow, Twilio, Meta) against AWS equivalents (as per Item 50). - Role-Based Architectural Directories: The architectural documentation is modularised into dedicated, role-based subdirectories:
docs/executive/(housing the 36-month TCO, non-AWS operational overheads, quarterly OpEx curves, and regulatory risk compliance under PDPA 2010 and 2025 CBPDT Guidelines) anddocs/engineering/(containing low-level DevOps materials like OpenTofu module structures, systemd DNS troubleshooting steps, Ansible ASIMP hardening playbooks, and EFS shared storage mount scripts) (as per Item 28). - Standard SEO Indexer Suite: The repository contains a suite of standard SEO indexer files in the root directory:
sitemap.txt(plain text list of all documentation URLs starting withhttps://),sitemap.xml(the standard XML sitemap for search engines with location, priority, lastmod, and changefreq tags), androbots.txt(which allows all search crawlers and points to the XML sitemap URL) (as per Item 29).
5. Deep State of Mind (DSOM) Framework & Sovereign AI Topology
- DSOM Adoption & Entry Points: Adopted the Deep State of Mind (DSOM) For My AI framework (
https://linuxmalaysia.github.io/deep-state-of-mind-for-my-ai/START-HERE/). Navigated via Diátaxis principles across 19 entry points (scaffolding, cognitive persona, crawlers, daily operations, MCP integration, subagents, skills, LLM WIKI, defensive GitOps, token efficiency, knowledge-first discovery, boot sequences, state sync, tri-phasic mind, OpenWiki, legal risk, OKF engine, guardrails, and episodic anchors) (as per Item 52). - Tri-Phasic Mind Cognitive Model: Cognition is split into 3 execution states:
- Active State (Conscious): Low-latency MCP server (
tools/mcp/server.py) interface for real-time task execution. - Twilight State (Subconscious): Near-real-time inline checks, token usage calculations, pre-flight audits (
tools/audit-pre-flight.sh), and state compaction. - Deep State (Unconscious/Dream): Out-of-band scheduled rituals (SOD/EOD palace sync) for semantic consolidation and repository synchronization.
- Active State (Conscious): Low-latency MCP server (
- Four Core Functional Subsystems:
- Cognitive Architecture: System 1 (reactive skills execution) vs System 2 (reflective discovery monologue).
- Memory Stratification: Stratified storage across Token Buffer, Active Context (
.agents/brain/active_context_manifest.md), Episodic Memory (.agents/brain/walkthrough.md), and Semantic Memory (.agents/brain/wings/). - Dreaming & Consolidation: EOD semantic pruning, synthetic failure test generation, and concept linking.
- Metacognition & Guardrails: Self-audit via pytest compliance suites, alignment drift prevention, and immutable constitutional anchors (
.agents/AGENTS.md).
- AI Boot & Initialization Sequence: Upon reanimation, the AI follows a strict 5-step boot sequence: (1) Genesis Read (
.agents/AGENTS.md), (2) Memory Restoration (.agents/brain/), (3) Master Onboarding Map (START-HERE.md), (4) Governance Topography (docs/governance/), and (5) Procedural Automation (.agents/skills/).
6. Script Hardening, Testing & Formatting Compliance
- Bash Script Navigation & Input Checks: Bash scripts (
scripts/deploy.shandscripts/destroy.sh) are hardened to enforce success checks on directory navigation (cd ... || exit 1), quote variables consistently, and use standardread -r -pflag options for user input (as per Item 2). - Python Codebase Formatting Cleanup: Codebase formatting is cleaned up by removing unused
pytestimports from all test files and correcting an extraneousfprefix on a log statement inscripts/prepare_docs.py, verified withruff checkand thepytestsuite (as per Item 4). - Complete Script Docstrings: All major script files in the repository are updated with complete docstrings: PEP-257-compliant docstrings for
scripts/prepare_docs.py, JSDoc-compliant comments forscripts/generate_pdf.js, and comprehensive header documentation with inline explanations for Bash scriptsscripts/deploy.sh,scripts/destroy.sh, andscripts/user_data.sh(as per Item 5). - Automated Pytest Suite: The project features a comprehensive
pytesttest suite under thetests/directory containing 11 tests that validate: document preparation utilities (test_prepare_docs.py), FQCN-compliance and privilege separation in embedded Ansible playbooks (test_ansible_playbooks.py), valid systemd INI syntax and unprivileged user namespace mappings (UserNS=keep-id:uid=2001,gid=2001) in Podman Quadlet specifications (test_podman_quadlets.py), and OKF front matter / DSOM footer compliance across Markdown files (test_md_compliance.py) (as per Item 6). - DRY Script Refactoring: The pre-build Python script
scripts/prepare_docs.pywas refactored to eliminate a severe DRY violation (code duplication) by extracting duplicate string-unescaping and quote-stripping code blocks fromparse_yaml()into a single, clean helper functionunescape_string(val). This refactoring preserved full operational parity and strict OKF parsing behavior (as per Item 34). - Root Caches & IaC Exclusions: The root
.gitignorefile includes exclusions for standard Python compilation and caching bytecode (__pycache__/,*.py[cod],*$py.class) alongside standard OpenTofu/Terraform state and system configurations to ensure the git workspace remains clean during documentation preparation or test runs (as per Item 35).
Deep State of Mind (DSOM) For My AI Protocol | Harisfazillah Jamel (LinuxMalaysia) | 2026-07-26 Standard: UK English | DBP-standard Bahasa Melayu Malaysia (Piawai) | GNU General Public License v3.0