
DOCA BlueField-4 Deployment
OfficialFreeStreamline BlueField-4 hardware operations safely.
Free · Opens the source repo
What DOCA BlueField-4 Deployment does
The DOCA BlueField-4 Deployment skill is designed specifically for operators who are tasked with bringing up a new BlueField-4 Data Processing Unit (DPU) using the Baseboard Management Controller (BMC). This skill provides a structured approach to executing critical hardware operations, including installing the BlueField/DOCA bundle ISO, performing PLDM firmware updates, and setting up a Grace Ubuntu image. It is essential for ensuring that the DPU is configured correctly and is ready to handle workloads efficiently.
One of the key features of this skill is its strict adherence to safety protocols. Given the potential for irreversible hardware changes, such as firmware burns and factory resets, the skill includes a built-in safety mechanism that requires explicit user confirmation before executing any destructive actions. This ensures that operators are fully aware of the implications of their actions and can prevent accidental misconfigurations that could lead to downtime or equipment failure.
This skill is particularly useful for external operators who have a BlueField-4 with accessible BMC and the necessary installation media ready. It guides users through the day-1 platform bring-up process, detailing the various methods available for installing the operating system and updating firmware. Additionally, it provides troubleshooting assistance for common issues that may arise during the bring-up process, such as boot failures or firmware task hangs.
However, it is important to note that this skill does not cover application deployment or operations related to BlueField-3, nor does it provide a comprehensive overview of the hardware-change meta-policy. For those tasks, users should refer to the appropriate skills within the DOCA bundle. Overall, the DOCA BlueField-4 Deployment skill is a critical tool for ensuring a smooth and safe bring-up of BlueField-4 DPUs in production environments.
When to use it
Use this skill when performing day-1 bring-up of a BlueField-4 DPU via the BMC, especially for OS installation and firmware updates.
When not to use it
Avoid this skill for BlueField-3 operations or for running applications on an already configured BlueField-4; it is not designed for those scenarios.
What you can build with it
First-Time OS Installation
Use this skill to install the BlueField/DOCA bundle ISO onto a new BlueField-4 DPU for the first time.
Firmware Updates
Execute PLDM firmware updates across BMC, NIC firmware, and other components using the Redfish UpdateService.
Troubleshooting Boot Issues
Diagnose and resolve problems when the DPU fails to boot or when firmware tasks hang during the bring-up process.
How to install DOCA BlueField-4 Deployment
View source1. Install with the skills CLI
npx skills add nvidia/skills/doca-bf4-deployment --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by nvidiaDOCA BlueField-4 (BF4) deployment
⚠️ WARNING — irreversible hardware operations. This skill guides operators through potentially destructive, irreversible BlueField-4 hardware operations: PLDM firmware burns, ISO reflashes, power cycles, and BMC factory resets. These can brick firmware, corrupt boot media, or cause production outages. Do not proceed without a maintenance window and a tested rollback plan. Every mutating step is governed by
doca-hardware-safety, which MUST be loaded alongside this skill before any destructive action.Before executing any mutating step — PLDM firmware burn, ISO reflash, power cycle, or BMC factory reset — the agent MUST show the exact command and its blast radius (which device, what becomes unavailable, whether it is reversible) and obtain the user's explicit confirmation for that specific action. Never chain destructive steps or run them speculatively as a side effect of another task.
Where to start: This skill is the bundle's deliberate in-bundle
home for day-1 platform bring-up of a BlueField-4 DPU via the
BMC — getting a powered-but-bare BF4 to "Grace OS installed,
firmware at the target level, ready to deploy a workload." It is the
upstream of the two application-deployment skills
(doca-container-deployment
and
doca-bare-metal-deployment):
those skills assume a working BlueField; this skill is how the
BlueField-4 GETS to working. If the user has a fresh BF4 and wants to
install the OS or update firmware, open TASKS.md and
start at ## configure. If the question is
what bring-up methods even exist and what is the contract for each,
start at CAPABILITIES.md.
Scope note — BF4 day-1 is in scope by directive. The bundle's
AGENTS.md ## Non-goalsitem 7 lists the BlueField BSP / BFB / RShim / TMFIFO layer and the BlueField BMC software as externally-productized. BlueField-4 day-1 bring-up via the BMC is carved into scope for this skill by directive because day-1 has no other home in the bundle. The carve-out is narrow: this skill teaches the documented BMC-driven install and firmware-update FLOWS (the CLASS), routing every mutating step throughdoca-hardware-safetyfor the change-application meta-policy. It does NOT redefine that meta-policy, and it does NOT cover BF3 (route todoca-bf3-deployment), application launch, or library APIs.
Audience
This skill serves external operators standing up a new BlueField-4 who already have:
- a BlueField-4 with its BMC reachable out-of-band (BMC SSH plus the documented Redfish endpoint), so the DPU can be driven without physical access,
- the BlueField/DOCA bundle ISO (and, for the Grace-Ubuntu path, a Grace Ubuntu image) downloaded from the public NVIDIA download surface, hosted at {iso-uri} on the operator's own HTTP/HTTPS server, and
- the target firmware and OS versions read from the public BlueField/DOCA release notes (this skill never quotes a specific pre-release firmware version).
It is not for:
- BlueField-3 (BF3) bring-up — route to
doca-bf3-deployment, - developers who want to RUN a DOCA service container or a DOCA-linked
binary on an already-working BlueField — route to
doca-container-deploymentordoca-bare-metal-deployment, - the cross-cutting hardware-change meta-policy itself (preflight, OOB
console discipline, maintenance window, rollback) — that is owned by
doca-hardware-safetyand this skill cross-links it, never duplicates it, - fleet-scale / orchestrated DPU provisioning — that is DOCA Platform
Framework territory, routed via
doca-public-knowledge-map.
The skill teaches the agent the documented bring-up procedure and
the rules for quoting Redfish / PLDM / UEFI standard operations and
public BlueField/DOCA documentation via
doca-public-knowledge-map;
it does not invent BMC credentials, ISO URIs, firmware version
strings, EIDs, Redfish task IDs, or device names from memory.
When to load this skill
Load this skill when the user is doing hands-on day-1 bring-up of a BlueField-4 via the BMC, or asking a cross-cutting BF4-bring-up question that is not specific to a later application-deployment step. Concretely:
- Installing the BlueField/DOCA bundle ISO onto the DPU (Grace) for the first time, and choosing between the three documented install methods — UEFI HTTP Boot (recommended), PXE Boot, or Redfish Virtual Media.
- Running the PLDM firmware-update flow across the BMC / NIC firmware
/ SBIOS / ERoT components: pushing the
.fwpkgbundle through the Redfish UpdateService multipart endpoint, monitoring the returned Task, verifying pending images withpldmtool, and activating with a power cycle. - Installing a Grace Ubuntu image (with optional cloud-init via a CIDATA-labelled config ISO) through Redfish Virtual Media, with either local hosting on the BMC eMMC or remote hosting on an HTTPS server.
- Reaching the DPU's OOB serial console (BMC SSH plus
obmc-console-client) to watch the installer or UEFI menus. - Diagnosing a bring-up that is misbehaving — the ISO will not boot, virtual media will not attach, a firmware Task hangs or reports an Exception, a pending image never activates, cloud-init is ignored, or the DPU is stuck in a boot loop because media was never detached.
- Cross-cutting questions: "HTTP Boot or Redfish Virtual Media — which do I use, and when do I actually need PXE?", "how do I know the firmware update actually took effect?", "the ISO landed but the NIC firmware update sub-step seems to have failed — what now?".
Do not load this skill for BF3 bring-up (route to
doca-bf3-deployment); for running an application on an
already-working BlueField (route to
doca-container-deployment
or
doca-bare-metal-deployment);
for env preparation on the installed Grace OS such as hugepages /
pkg-config / devlink (use doca-setup); for
the cross-cutting hardware-change meta-policy (route to
doca-hardware-safety); or for
fleet-scale orchestrated provisioning (route via
doca-public-knowledge-map).
What this skill provides
This is a thin loader. Substantive material lives in two companion files:
CAPABILITIES.md— the BF4 day-1 bring-up contract: the three OS install methods (UEFI HTTP Boot, PXE Boot, Redfish Virtual Media) and the Grace-Ubuntu-plus-cloud-init Virtual Media path; the PLDM firmware-update surface across BMC / NIC firmware / SBIOS / ERoT; the version-compatibility overlay ondoca-version(the install and firmware targets come from the public release notes, never from memory); the bring-up error taxonomy (boot-source -> virtual-media-attach -> firmware-Task -> activation -> cloud-init -> boot-loop); the observability surface (the OOB console, the Redfish Task resource, the Redfish FirmwareInventory,pldmtoolGetFwParams, and the installed-build checkcat /etc/mlnx-release); and the safety policy (an overlay ondoca-hardware-safety: every PLDM burn / ISO reflash / power cycle / BMC factory reset is a MUTATING hardware op; never print a real password; always detach virtual media to avoid boot loops; only public hosts for any NVIDIA URL).TASKS.md— step-by-step workflows for the in-scope bring-up verbs:configure,build(routing stub),modify(routing stub),run(the three install methods plus the PLDM firmware-update flow plus the Grace-Ubuntu cloud-init path, as###sub-anchors),test(the post-install / post-update verification sweep),debug(the layered bring-up diagnosis), and theDeferred task verbsblock routing BF3 / application-launch / library-API / env-prep / hardware-meta-policy / fleet questions out to their owning skills.
The skill assumes a BlueField-4 target where:
- the BMC is reachable out-of-band and the operator has BMC credentials ({bmc-user} / {bmc-password}) they supply — never invented here,
- the bundle ISO (and any Grace Ubuntu image / cloud-init config ISO) is downloaded from the public NVIDIA download surface and hosted at {iso-uri},
- the operator has read the target firmware and OS versions from the public BlueField/DOCA release notes.
It does not cover installing DOCA tooling on the host — that path goes
through doca-setup — and it does not cover
running a workload once Grace is up — those paths go through the two
application-deployment skills.
Loading order
- Read this
SKILL.mdfirst to confirm the user's question is in scope (BF4 day-1 bring-up via the BMC; NOT BF3, NOT application launch, NOT a library-API question, NOT the hardware-change meta-policy itself). - For the bring-up contract (the three install methods, the Grace-Ubuntu cloud-init path, the PLDM firmware-update surface, the version overlay, the bring-up error taxonomy, the observability surface, and the BF4 safety overlay), see CAPABILITIES.md.
- For step-by-step workflows —
configure,build(routing stub),modify(routing stub),run(with the three install methods, the PLDM flow, and the Grace-Ubuntu cloud-init path as###sub-anchors),test,debug, plus theDeferred task verbsblock — see TASKS.md. - Load
doca-hardware-safetyALONGSIDE whenever the question reaches a mutating step (PLDM firmware burn, ISO reflash, power cycle, BMC factory reset).
Example questions this skill answers well
What this skill deliberately does not ship
Related skills
Frequently asked questions about DOCA BlueField-4 Deployment
Similar skills
Turborepo
Optimized build system for JavaScript/TypeScript monorepos.
Azure Pipelines Validation
Streamline your Azure DevOps pipeline changes locally.
Azure Developer CLI
Streamline your Azure project workflows with best practices.
Azure Container Registry CLI
Manage Azure Container Registry resources with ease.
Aspire
Build and orchestrate polyglot distributed applications seamlessly.
Vercel CLI
Manage and deploy Vercel projects from the command line.
