onboard-marin
marin-community/marin/.agents/skills/onboard-marin/SKILL.md
Verify or complete a new internal Marin developer's local setup and access to GitHub, GCP, Iris, Weights & Biases, Hugging Face, and optional CoreWeave storage. Use when a team member asks to onboard, validate onboarding, or diagnose missing development access.
Skill3.9k starsChanged 25 days ago
- Reads credentials
What's in it
- Onboard a Marin developer
- Sources
- Verify
- Smoke tests
- Report
---
name: onboard-marin
description: Verify or complete a new internal Marin developer's local setup and access to GitHub, GCP, Iris, Weights & Biases, Hugging Face, and optional CoreWeave storage. Use when a team member asks to onboard, validate onboarding, or diagnose missing development access.
---
# Onboard a Marin developer
Establish which parts of the developer environment are ready, fix local setup
when safe, and identify each missing external grant. Keep secrets out of
command output and the final report.
## Sources
Use these as the current sources of truth:
- Local installation: `docs/tutorials/installation.md`.
- Development workflow: `docs/dev-guide/contributing.md`.
- Iris authentication and access checks: `lib/iris/OPS.md` and the `use-iris`
skill.
- CoreWeave credentials and routing: `docs/tutorials/cloud-gpu.md`.
- Pulumi operator grants and state access: `infra/pulumi/README.md`, the
`add-grant` skill, and the `review-grant` skill.
Do not copy procedures from `infra/README.md`; it is an infrastructure index.
## Verify
Start with read-only checks. Report each area as ready, missing access, missing
local setup, or not checked.
1. Confirm the command is running from a Marin checkout and inspect the working
tree without changing user work.
2. Check the required local tools and Python version. Check dependency and
pre-commit setup against the installation and contributing guides. Install
or repair local dependencies when the user's onboarding request authorizes
it.
3. Check GitHub authentication and repository push permission without pushing a
branch.
4. Check the active GCP account, the `hai-gcp-models` project, Application
Default Credentials, and read access to `gs://marin-us-central2`. Confirm the
current principal has `projects/hai-gcp-models/roles/marindev` with a filtered
IAM query that prints only the matching role name. Do not print credential
contents or the complete project policy.
5. When the user will operate the `marin` GCP Pulumi stack:
- In addition to the `marindev` check above, confirm the current principal
has `projects/hai-gcp-models/roles/marinPulumiAdmin` with the same filtered
IAM query.
- Check that the Pulumi CLI and repository deploy dependencies are present.
Run `pulumi -C infra/pulumi stack export --stack marin >/dev/null` to verify
state access without printing state contents.
- Report CoreWeave kubeconfig access separately when the user will operate a
CoreWeave stack.
Do not run `pulumi up` as an onboarding check. Do not grant roles or mutate
live IAM unless the user asks for the grant workflow.
6. Check Iris authentication and read-only cluster status. Use `iris login`
only for an interactive human session; let the browser or headless login flow
request the human's input.
7. Check whether `WANDB_API_KEY` and `HF_TOKEN` are present without printing
their values. When useful, perform a read-only identity check with the
service's CLI and confirm access to the `marin-community` W&B entity. Do not
persist a token outside the user's chosen credential store.
8. Check CoreWeave object-storage access only when the user needs to inspect GPU
job outputs. Do not treat storage credentials as proof of GPU scheduling
access; Iris controls compute access separately.
Distinguish local configuration failures from permissions that a maintainer
must grant. GCP project access, Iris IAP access, GitHub access, Weights & Biases,
Hugging Face, Pulumi operator access, and CoreWeave storage are independent.
## Smoke tests
Run local import or CPU checks when they are cheap and do not download a large
dataset. A remote Iris job changes shared state: submit one only when the user
explicitly authorizes the smoke job. Keep it CPU-only, small, and bounded. Never
request a GPU or TPU during onboarding.
Do not start, stop, restart, deploy, or otherwise mutate a shared cluster.
## Report
Give the user a compact checklist of verified capabilities and remaining
actions. Include the failing command category and error summary without secret
values. Distinguish grants the user can request from local fixes. Do not edit
IAM data or file a grant request unless the user asks.
More agent context in marin-community/marin
43 other files this repository gives its agents.
AGENTS.md
CLAUDE.md
Skill
- ab-test-zephyr.agents/skills/ab-test-zephyr/SKILL.md
- add-dataset.agents/skills/add-dataset/SKILL.md
- add-grant.agents/skills/add-grant/SKILL.md
- add-pallas-kernel.agents/skills/add-pallas-kernel/SKILL.md
- archive-experiments.agents/skills/archive-experiments/SKILL.md
- babysit-zephyr.agents/skills/babysit-zephyr/SKILL.md
- change-grug.agents/skills/change-grug/SKILL.md
- commit.agents/skills/commit/SKILL.md
- consult-echo.agents/skills/consult-echo/SKILL.md
- debug.agents/skills/debug/SKILL.md
- deploy-hero-change.agents/skills/deploy-hero-change/SKILL.md
- file-issue.agents/skills/file-issue/SKILL.md
- fix-issue.agents/skills/fix-issue/SKILL.md
- launch-rl.agents/skills/launch-rl/SKILL.md
- lint-review.agents/skills/lint-review/SKILL.md
- manage-hero-run.agents/skills/manage-hero-run/SKILL.md
- marina-applet.agents/skills/marina-applet/SKILL.md
- noslop.agents/skills/noslop/SKILL.md
- organize-experiments.agents/skills/organize-experiments/SKILL.md
- profile-training.agents/skills/profile-training/SKILL.md
- query-finelog.agents/skills/query-finelog/SKILL.md
- refresh-fork.agents/skills/refresh-fork/SKILL.md
- research.agents/skills/research/SKILL.md
- review-grant.agents/skills/review-grant/SKILL.md
- review-pr.agents/skills/review-pr/SKILL.md
- run-ferries.agents/skills/run-ferries/SKILL.md
- scan-logs.agents/skills/scan-logs/SKILL.md
- scrub-docs-code-parity.agents/skills/scrub-docs-code-parity/SKILL.md
- scrub-experiment-issue-tldrs.agents/skills/scrub-experiment-issue-tldrs/SKILL.md
- scrub-reflection-self-improvement.agents/skills/scrub-reflection-self-improvement/SKILL.md
- trace-pulumi-diff.agents/skills/trace-pulumi-diff/SKILL.md
- triage-canary.agents/skills/triage-canary/SKILL.md
- update-docs.agents/skills/update-docs/SKILL.md
- upload-hf-model.agents/skills/upload-hf-model/SKILL.md
- use-fsutil.agents/skills/use-fsutil/SKILL.md
- use-iris.agents/skills/use-iris/SKILL.md
- write-ops-log.agents/skills/write-ops-log/SKILL.md
- write-pipeline.agents/skills/write-pipeline/SKILL.md
- write-tests.agents/skills/write-tests/SKILL.md
- writing-style.agents/skills/writing-style/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool registry_write, action report. How to connect one.

