{"slug":"doca-bare-metal-deployment","title":"doca-bare-metal-deployment","summary":"Use this skill for launching, supervising, debugging, OR platform lifecycle on a BlueField — BFB install, RShim/TMFIFO, host PF rebind, post-BFB recovery — taking a DOCA-linked binary to a healthy run directly on hardware (host x86 + BlueField NIC over PCIe, or BlueField Arm bare","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-26T16:30:38.98639Z","repo":{"url":"https://github.com/NVIDIA/skills","stars":3445,"forks":416,"license":"Apache-2.0","updatedAt":"2026-09-25T03:14:56Z"},"bodyHtml":"<hr>\n<h2>license: Apache-2.0\nname: doca-bare-metal-deployment\ndescription: &gt;\nUse this skill for launching, supervising, debugging, OR\nplatform lifecycle on a BlueField — BFB install, RShim/TMFIFO,\nhost PF rebind, post-BFB recovery — taking a DOCA-linked binary\nto a healthy run directly on hardware (host x86 + BlueField NIC\nover PCIe, or BlueField Arm bare-metal). No container, no\nkubelet. Covers launch mode (direct, tmux, systemd), PCI/NUMA/\nCPU/IRQ binding, co-tenant isolation (cgroup-v2/netns/numactl),\na seven-layer error taxonomy, and a six-state BlueField\nlifecycle classifier. Trigger even when user does not say\n\"bare-metal\" — implicit phrasings include \"binary exits 1 right\nafter launch\", \"systemd keeps restarting it\", \"no matching\ndevice on the BF\", \"bfb-install exited 0 but DPU is dead\",\n\"ping 192.168.100.2 works but ssh fails\", \"host PFs aren't\nshowing netdevs\". Destructive firmware burn / mlxconfig set\nrequires explicit confirmation via doca-hardware-safety;\ncontainers, library APIs, env prep, and build use other skills.\nmetadata:\nkind: library\ncompatibility: &gt;\nNo DOCA install required to read this skill (it is an overlay\nloaded against any DOCA artifact skill); the validation steps\nwithin this skill require a live DOCA install at /opt/mellanox/doca on\na host or BlueField with a built DOCA-linked binary.</h2>\n<h1>DOCA bare-metal deployment</h1>\n<p><strong>Where to start:</strong> This skill is the bundle's home for <em>operating</em>\na DOCA-linked application binary <strong>directly on hardware</strong> — no\ncontainer, no kubelet, no static-pod manifest. It is the parallel\nof <a href=\"../doca-container-deployment/SKILL.md\"><code>doca-container-deployment</code></a>\nfor the non-container path. If the user has a DOCA-linked binary\nthey built (per the canonical workflow in\n<a href=\"../doca-programming-guide/SKILL.md\"><code>doca-programming-guide</code></a>)\nand they want to know <em>how to actually run it on the host or on\nthe BlueField Arm cores correctly</em>, open\n<a href=\"TASKS.md\"><code>TASKS.md</code></a> and start at\n<a href=\"TASKS.md#configure\"><code>## configure</code></a>. If the question is <em>what\nshape does the bare-metal runtime even have and what is the\ndeployment contract</em>, start at <a href=\"CAPABILITIES.md\"><code>CAPABILITIES.md</code></a>.\nIf the user is not yet sure whether their target system shape is\nthe container path or the bare-metal path, route the recognition\nstep to <a href=\"../doca-setup/SKILL.md\"><code>doca-setup</code></a> first; only return\nhere once <em>bare-metal</em> is the confirmed shape.</p>\n<h2>Audience</h2>\n<p>This skill serves <strong>external DOCA developers and operators who\nhave a DOCA-linked application binary they built and want to run\nit directly on hardware</strong> — i.e., people who already have:</p>\n<ul>\n<li>a DOCA-linked application binary they built per\n<a href=\"../doca-programming-guide/TASKS.md#build\"><code>doca-programming-guide ## build</code></a>,</li>\n<li>a real BlueField NIC and a host that talks to it (the <strong>host\nx86</strong> path — DOCA host install on the host talks to the\nBlueField NIC over PCIe), OR a BlueField with a console or SSH\nto the Arm side (the <strong>BlueField Arm bare-metal</strong> path — DOCA\ninstalled on the DPU Arm cores; the binary runs there\ndirectly), and</li>\n<li>a desire to RUN that binary directly on the hardware, not\ninside a kubelet-standalone-managed container.</li>\n</ul>\n<p>It is <strong>not</strong> for:</p>\n<ul>\n<li>kernel-driver developers contributing to <code>mlx5_*</code> or the\nBlueField OS,</li>\n<li>DOCA library contributors (those changes go to the internal\nDOCA tree, not to a bare-metal deployment),</li>\n<li>full-Kubernetes-cluster operators managing a fleet of\nBlueFields (the bundle covers\n<a href=\"../doca-container-deployment/SKILL.md\"><code>doca-container-deployment</code></a>\nfor the single-host kubelet-standalone shape; <strong>fleet/production-scale\ndeployment is fleet-orchestration scope</strong> — route to the orchestration\nentry-point in\n<a href=\"../doca-public-knowledge-map/references/map.md#deploying-doca-services-at-scale--orchestration-entry-point-personascale-routing\"><code>doca-public-knowledge-map ## Deploying DOCA services at scale</code></a>\n(DPF / Network Operator / Launch Kit), not hand-rolled static-pod loops),</li>\n<li>fresh-laptop-no-hardware users with no DOCA install yet — those\nbelong on\n<a href=\"../doca-setup/TASKS.md#no-install\"><code>doca-setup ## no-install</code></a>.</li>\n</ul>\n<p>The skill teaches the agent the bare-metal-deployment <em>procedure</em>\nand the rules for quoting documented commands from the public DOCA\nProgramming Guide and the public BlueField / DPU User Manual via\n<a href=\"../doca-public-knowledge-map/SKILL.md\"><code>doca-public-knowledge-map</code></a>;\nit does not invent flag names, PCI BDFs, NUMA numbers, devlink\npaths, representor strings, or systemd <code>Restart=</code> mode names from\nmemory.</p>\n<h2>When to load this skill</h2>\n<p>Load this skill when the user is doing <strong>hands-on bare-metal\ndeployment of a DOCA-linked application binary</strong> on either of the\ntwo supported host modes (host x86 or BlueField Arm), or asking a\ncross-cutting bare-metal question that is not specific to one\nlibrary's API. Concretely:</p>\n<ul>\n<li>Launching a DOCA-linked binary for the first time on a host\nwith a BlueField NIC in a PCIe slot, with DOCA installed on the\nhost.</li>\n<li>Launching a DOCA-linked binary on the BlueField Arm cores\ndirectly (BlueField Arm bare-metal mode), with DOCA installed\non the Arm side per the BlueField OS image.</li>\n<li>Deciding which launch mode to use (direct foreground for\ninteractive debug; tmux/screen for long-running with manual\nreattach; systemd-supervised for restart-after-reboot,\njournald-integrated logs, and Restart= policy).</li>\n<li>Binding the DOCA process to the right PCIe function, the right\nrepresentor, the right NUMA node, and the right CPU set — and\npinning IRQs to match — without inventing the addresses or the\nflag names.</li>\n<li>Setting up per-tenant isolation (cgroup-v2 cpu / memory / io\ncontrollers, network namespaces for multi-tenant deployments,\n<code>numactl</code> / <code>taskset</code> for CPU + NUMA binding) so multiple DOCA\nprocesses co-tenant on the same BlueField without crushing each\nother.</li>\n<li>Diagnosing a bare-metal launch that is misbehaving — won't\nstart, starts and exits immediately, runs but can't find the\ndevice, attaches to the device but the workload errors, OOMs or\nis signal-killed, is in a restart loop under a supervisor, or\nis being interfered with by a co-tenant.</li>\n<li>Cross-cutting questions: <em>\"should I run this in tmux or as a\nsystemd unit\"</em>, <em>\"what is the smoke-before-bulk loop for a\nbinary on bare metal\"</em>, <em>\"my binary works in a container on the\nBlueField but not when I run it directly on the Arm — what\nchanged\"</em>.</li>\n</ul>\n<p>Do <strong>not</strong> load this skill for the container-path equivalent\n(those questions go to\n<a href=\"../doca-container-deployment/SKILL.md\"><code>doca-container-deployment</code></a>);\nfor full-Kubernetes-cluster operations (out of scope per the\nbundle's non-goals); for library-API questions (route to the\nmatching <code>libs/&lt;library&gt;</code> skill); for env-preparation questions\nincluding hugepages, IOMMU, pkg-config, and devlink mode flips\n(use <a href=\"../doca-setup/SKILL.md\"><code>doca-setup</code></a>); for any\nhardware-state-changing operation including <code>mlxconfig</code> writes\nand BFB reflashes (route to\n<a href=\"../doca-hardware-safety/SKILL.md\"><code>doca-hardware-safety</code></a> for the\ncross-cutting meta-policy); or for cross-library programming\nquestions (use\n<a href=\"../doca-programming-guide/SKILL.md\"><code>doca-programming-guide</code></a>).</p>\n<h2>What this skill provides</h2>\n<p>This is a <strong>thin loader</strong>. Substantive material lives in two\ncompanion files:</p>\n<ul>\n<li><code>CAPABILITIES.md</code> — the bare-metal deployment runtime contract\nfor a DOCA-linked binary: the two host modes (host x86 vs\nBlueField Arm bare-metal), the three launch modes (direct,\ntmux/screen, systemd-supervised), the hardware-resource-binding\nsurface (PF / VF / representor enumeration; NUMA topology\ndiscovery; CPU pinning rationale; IRQ affinity rules), the\nper-tenant isolation surface (cgroup-v2 cpu / memory / io,\nnetwork namespaces, <code>numactl</code> / <code>taskset</code>), the restart and\nrecovery semantics (documented <code>systemd</code> <code>Restart=</code> modes vs\ncrash-and-investigate vs supervisor-driven restart), the\nbare-metal-specific version overlay on the four-way version\nmatch owned by\n<a href=\"../doca-version/SKILL.md\"><code>doca-version</code></a>, the cross-cutting\nerror taxonomy (seven layers, walked in order), the observability\nsurface (stdout/stderr discipline by launch mode; device-state\nintrospection via <code>devlink</code> / <code>sysfs</code> / <code>mlxconfig</code> <em>query</em>;\nper-tenant resource visibility), and the safety policy (overlay\non\n<a href=\"../doca-hardware-safety/SKILL.md\"><code>doca-hardware-safety</code></a>:\nsmoke-before-bulk for binaries; failed bare-metal process is\nHIGH-STAKES; do not invent PCI addresses, NUMA numbers,\nrepresentor names, devlink paths, or systemd <code>Restart=</code> mode\nnames; confirm tenant-isolation primitives BEFORE the workload\nstarts).</li>\n<li><code>TASKS.md</code> — step-by-step workflows for the in-scope bare-metal\nverbs: <code>configure</code>, <code>build</code>, <code>modify</code>, <code>run</code> (with an explicit\n<code>### isolation</code> sub-anchor covering cgroup-v2 / namespaces /\nnumactl per-tenant primitives), <code>test</code>, <code>debug</code>,\n<code>bluefield-lifecycle</code> (the BFB-install → RShim/TMFIFO →\npost-BFB-recovery operational sequencing ladder, with the\nsix-state <code>bluefield-state-classifier</code> sub-anchor), the\n<code>Command appendix</code> (documented commands the agent may quote,\neach cross-linked to its public-doc source — no invented\ncommands), and the <code>Deferred task verbs</code> block routing\ncontainer-path / cluster / library-API / env-prep /\nhardware-state-change / cross-library questions out to their\nowning skills. (The change-application discipline for any\nmutating burn invoked from <code>## bluefield-lifecycle</code> is still\nmeta-policy owned by\n<a href=\"../doca-hardware-safety/SKILL.md\"><code>doca-hardware-safety</code></a>,\nloaded alongside.)</li>\n</ul>\n<p>The skill assumes a host or BlueField target where:</p>\n<ul>\n<li>DOCA is already installed and healthy (per\n<a href=\"../doca-setup/TASKS.md#test\"><code>doca-setup ## test</code></a>),</li>\n<li>the user has a DOCA-linked application binary they built (per\n<a href=\"../doca-programming-guide/TASKS.md#build\"><code>doca-programming-guide ## build</code></a>),</li>\n<li>the user has the host-OS permissions to enumerate devices,\nreserve hugepages, write systemd units (if they choose that\nlaunch mode), and bind processes to NUMA nodes.</li>\n</ul>\n<p>It does not cover installing DOCA — that path goes through\n<a href=\"../doca-setup/SKILL.md\"><code>doca-setup</code></a> — and it does not cover\nbuilding the binary — that path goes through\n<a href=\"../doca-programming-guide/SKILL.md\"><code>doca-programming-guide</code></a>.</p>\n<h2>Loading order</h2>\n<ol>\n<li>Read this <code>SKILL.md</code> first to confirm the user's question is\nin scope (bare-metal launch of a DOCA-linked binary on host\nx86 or BlueField Arm; NOT the container path, NOT a full\ncluster, NOT a library-API question).</li>\n<li><strong>For the runtime contract (two host modes, three launch\nmodes, hardware-binding surface, per-tenant isolation, version\noverlay, seven-layer error taxonomy, observability surface,\nbare-metal safety overlay), see\n<a href=\"CAPABILITIES.md\">CAPABILITIES.md</a>.</strong></li>\n<li><strong>For step-by-step workflows — <code>configure</code>, <code>build</code> (routing\nstub), <code>modify</code> (routing stub), <code>run</code> (with <code>### isolation</code>\nsub-anchor), <code>test</code>, <code>debug</code>, <code>bluefield-lifecycle</code> (BFB\ninstall + RShim/TMFIFO + post-BFB recovery + the six-state\n<code>bluefield-state-classifier</code>), plus the <code>Command appendix</code> and\nthe <code>Deferred task verbs</code> block — see <a href=\"TASKS.md\">TASKS.md</a>.</strong></li>\n</ol>\n<h2>Example questions this skill answers well</h2>\n<p>See <a href=\"references/details.md#example-questions-this-skill-answers-well\"><code>references/details.md</code></a>.</p>\n<h2>What this skill deliberately does not ship</h2>\n<p>See <a href=\"references/details.md#what-this-skill-deliberately-does-not-ship\"><code>references/details.md</code></a>.</p>\n<h2>Related skills</h2>\n<p>See <a href=\"references/details.md#related-skills\"><code>references/details.md</code></a>.</p>\n","files":[{"path":"BENCHMARK.md","sizeBytes":4099,"isText":true},{"path":"CAPABILITIES.md","sizeBytes":41484,"isText":true},{"path":"evals/evals.json","sizeBytes":3444,"isText":true},{"path":"references/details.md","sizeBytes":10775,"isText":true},{"path":"skill-card.md","sizeBytes":4386,"isText":true},{"path":"SKILL.md","sizeBytes":11602,"isText":true},{"path":"skill.oms.sig","sizeBytes":5269,"isText":false},{"path":"TASKS.md","sizeBytes":64667,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"notes-only","suspicious":0,"notes":2,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-26T16:31:44.451295Z","sha256":"1FFA093C64C3120FCB27D910A1549E39B1BFFD26E815A9A8CD693D2AF4980A0E","sizeBytes":52627},"review":null,"source":{"repositoryUrl":"https://github.com/NVIDIA/skills","path":"skills/doca-bare-metal-deployment","license":"Apache-2.0","commit":"d8519c57da6db5d9bea274ec1724a4a7a56a3dee","subtreeSha":"56B769BEF30FFB20A33D607705640896798D371B9840547D13CF8016041B04C6","lastSyncedAt":"2026-09-26T16:30:30.547995Z"},"reviewedAt":"2026-09-26T16:33:47.786485Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/NVIDIA/skills/tree/main/skills/doca-bare-metal-deployment"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install nvidia-skills@llmmart"},{"target":"git","command":"git clone https://github.com/NVIDIA/skills.git"}]}