Automation & Ops ✓ NVIDIA · Official bluefield-4dpu-deploymentbmcredfishpldm-firmwareuefi-http-bootpxe-bootvirtual-media

DOCA BlueField-4 Deployment

Guides BMC-driven BlueField-4 day-one bring-up, firmware updates, installation, and boot troubleshooting.

FollowSkills review · FSRS-2.0
Not recommended
57/ 100 5-point scale 2.9 / 5
Trust18 / 25 · 3.6/5

The document explicitly identifies the irreversible risks of firmware burns, ISO reflashes, power cycles, and BMC resets; requires a maintenance window, rollback plan, per-action confirmation, credential redaction, placeholders, and verified OOB access. However, rollback details are delegated to the external doca-hardware-safety skill, while least privilege, credential lifecycle, data-flow disclosure, and dependency security remain incomplete, so points are deducted.

Reliability8 / 20 · 2.0/5

The workflow is internally organized with prerequisites, six diagnostic layers, task-state checks, version checks, and media-state checks. However, key Redfish endpoints, compatibility details, and environment assumptions depend on external documentation; there are no executable tests covering the skill itself and failure guidance remains partly procedural. Under the static cap, reliability cannot exceed 10, so 8 is awarded conservatively.

Adaptability11 / 15 · 3.7/5

The audience, BF4 day-1 bring-up scenarios, trigger phrases, and non-fit boundaries for BF3, applications, and fleet provisioning are clearly stated. However, Chinese-language support and mainland-China reachability are not addressed, and core use depends on public NVIDIA download and documentation surfaces, so points are deducted.

Convention10 / 15 · 3.3/5

The skill has a useful information architecture, loading order, task-verb organization, related-skill routing, risk notes, dependency notes, Apache-2.0 metadata, and NVIDIA ownership signals. It lacks an author field, a formal changelog, and a clear maintenance/update path; BENCHMARK also reports missing recommended Instructions and Examples sections, and the skill-card's CC-BY-4.0 statement is not fully aligned with SKILL.md metadata. Points are therefore deducted.

Effectiveness6 / 15 · 2.0/5

The files cover three installation methods, PLDM updates, cloud-init, verification, and layered debugging, with a clear operational goal and potentially useful outputs. However, the skill is explicitly a thin loader, depends on companion files, live target versions, and external public documentation, and provides no statically verifiable representative result or comparison with alternatives. The static ceiling is 7, so 6 is awarded.

Verifiability4 / 10 · 2.0/5

The committed benchmark report, static-validation findings, evaluation metrics, and traceable command/state checks provide limited auditability. The evaluation dataset is unavailable, there is no real CI plus committed key-path test suite, and standards/documentation are referenced only generally, preventing independent reproduction; 4 points are awarded.

Evidence confidence:Low Reviewed Jul 20, 2026 Reviewed revision 55f18499943e
The upstream repository has new commits since this review. The score still applies to the reviewed revision shown and may not cover the latest changes.
Before you use it
  • Firmware, reflashing, power-cycle, and BMC-reset actions can make the device unavailable or brick it; load doca-hardware-safety first, verify target versions, OOB access, maintenance window, and a testable rollback plan, and obtain confirmation for each action.
  • Do not treat placeholders, example URIs, EIDs, task IDs, or command parameters as site values; verify Redfish behavior, dpu-bmc support, firmware layout, and release targets against current documentation for the target device.
  • Chinese usability and mainland-China network reachability are not demonstrated; when NVIDIA download or documentation services are required, validate reachability and prepare a compliant local alternative.
See the full review method →

What does this skill do, and when should you use it?

This skill is for external operators bringing up a new BlueField-4 DPU through its BMC. It covers installing the BlueField/DOCA bundle ISO onto Grace, updating BMC, NIC firmware, SBIOS, and ERoT through PLDM, and installing a Grace Ubuntu image with optional cloud-init. The documented installation methods are UEFI HTTP Boot, PXE Boot, and Redfish Virtual Media. Because the workflows can include irreversible firmware burns, ISO reflashes, power cycles, and BMC factory resets, the skill requires doca-hardware-safety, a maintenance window, a tested rollback plan, and action-specific confirmation.

Guides agents through BlueField/DOCA bundle ISO installation using UEFI HTTP Boot, PXE Boot, or Redfish Virtual Media; uploads .fwpkg bundles through the Redfish UpdateService multipart endpoint and monitors or verifies PLDM updates with Redfish Task, FirmwareInventory, and pldmtool; installs Grace Ubuntu and optional CIDATA cloud-init configuration through Redfish Virtual Media; reaches the out-of-band serial console using BMC SSH and obmc-console-client; checks /etc/mlnx-release; and diagnoses boot-source, virtual-media, firmware-task, activation, cloud-init, and boot-loop failures.

  1. An operator needs to install Grace OS on a fresh BlueField-4 through the BMC.
  2. An administrator needs to update BMC, NIC firmware, SBIOS, or ERoT through Redfish UpdateService during a maintenance window.
  3. An engineer needs to choose among UEFI HTTP Boot, PXE Boot, and Redfish Virtual Media.
  4. An operator is investigating a firmware Task stuck at Running, reporting an Exception, or failing to activate a pending image.
  5. An administrator needs to install Grace Ubuntu with an optional cloud-init configuration ISO.
  6. A field engineer needs the out-of-band serial console to investigate ISO boot, virtual-media, or boot-loop problems.

What are this skill's strengths and limitations?

Pros
  • Covers the principal BlueField-4 day-one bring-up paths.
  • Combines OS installation, PLDM firmware updates, console observability, and layered troubleshooting.
  • Clearly separates BF4 bring-up from BF3, application deployment, environment preparation, and fleet orchestration.
  • Defines explicit safety controls for operations that may damage hardware or cause outages.
Limitations
  • Limited to BlueField-4; BlueField-3 is out of scope.
  • Does not cover application launch, DOCA tooling installation, library APIs, or post-install environment preparation.
  • Assumes an accessible BMC, operator-hosted image files, an HTTP/HTTPS server, and target version information.
  • SKILL.md is a thin loader whose substantive guidance depends on companion files such as CAPABILITIES.md, TASKS.md, and references/details.md.
  • The supplied source provides no specific hardware test matrix or standalone test-suite evidence.

How do you install this skill?

Install the specific skill with the skills CLI command documented by the repository README:

npx skills add nvidia/skills --skill doca-bf4-deployment --yes

The source does not document another dedicated installation method for this skill. After installation, the skill becomes available when an agent loads skills and encounters a relevant task; manual repository cloning or folder copying is not required.

How do you use this skill?

After installation, trigger it with requests such as “bring up my new BlueField-4,” “the BlueField ISO will not boot over HTTP from the BMC,” “attach BF4 virtual media via Redfish,” or “BF4 firmware Task stuck at Running.” Before any PLDM burn, ISO reflash, power cycle, or BMC factory reset, load doca-hardware-safety alongside it, show the exact command and blast radius, and obtain explicit confirmation for that specific action. Use CAPABILITIES.md for the bring-up contract and TASKS.md for procedural workflows.

How does this skill compare with similar options?

The skill explicitly covers three installation alternatives: recommended UEFI HTTP Boot, PXE Boot, and Redfish Virtual Media. It provides no comparison with non-NVIDIA vendors or unrelated tools.

FAQ

Is DOCA installation required to use this skill?
No DOCA installation is required to read the skill. Execution requires a BlueField-4, an out-of-band reachable BMC, a server hosting the required images, and target version information.
Will the skill automatically perform destructive hardware operations?
It should not do so unconditionally. Each PLDM burn, ISO reflash, power cycle, or BMC factory reset requires the exact command, blast-radius explanation, and explicit confirmation for that action.
Should I use this skill to deploy applications or configure Grace?
Not as the primary skill. Application deployment belongs to doca-container-deployment or doca-bare-metal-deployment, while installed-Grace environment preparation belongs to doca-setup.

More skills from this repository

All from NVIDIA/skills

Automation & Ops ✓ NVIDIA · Official

DOCA Hardware Safety

A rollback-oriented operating discipline for live DPU and NIC hardware changes.

Dev & Engineering ✓ NVIDIA · Official

DOCA Environment Setup

Verify, prepare, and troubleshoot the DOCA environment while routing workloads to the right deployment path.

Dev & Engineering ✓ NVIDIA · Official

DOCA Rivermax Receive Development

Guides developers through building, validating, and debugging DOCA Rivermax receive applications for real-time network streams.

Automation & Ops ✓ NVIDIA · Official

DOCA Socket Relay

Bridge an existing socket application to a BlueField DPU without rewriting it

Dev & Engineering ✓ NVIDIA · Official

DOCA Compress Hardware Offload

Guides hands-on DEFLATE and LZ4 decompression development and debugging on BlueField and ConnectX platforms.

Dev & Engineering ✓ NVIDIA · Official

DOCA AES-GCM Acceleration

Configure, validate, and debug DOCA AES-GCM offload on BlueField DPUs and ConnectX NICs.

Dev & Engineering ✓ NVIDIA · Official

DOCA RDMA Initiator

Guides accelerator-initiated one-sided RDMA development on the DPA datapath.

Automation & Ops ✓ NVIDIA · Official

DOCA BlueField-3 Bring-Up

Guides operators through BF3 day-one bring-up, recovery, RShim/BFB provisioning, and installation validation.

Dev & Engineering ✓ NVIDIA · Official

DOCA RDMA Programming Guide

Helps developers build, configure, and debug DOCA RDMA applications on BlueField, ConnectX, and DOCA hosts.

Dev & Engineering ✓ NVIDIA · Official

DOCA SHA Acceleration

Guidance for offloading SHA hashing to NVIDIA BlueField and ConnectX hardware.

Dev & Engineering ✓ NVIDIA · Official

DOCA Arg Parser CLI

Guides developers in building and debugging standard CLIs for DOCA applications.

Dev & Engineering ✓ NVIDIA · Official

DOCA Common Foundation

A shared programming foundation for DOCA applications on BlueField and ConnectX.

Dev & Engineering ✓ NVIDIA · Official

DOCA Ethernet Queue Development

Develop and debug DOCA Ethernet RX/TX queues on BlueField DPUs and ConnectX NICs.

Dev & Engineering ✓ NVIDIA · Official

DOCA DMA Development Guide

Guides hands-on DOCA DMA memory-copy development on BlueField and ConnectX systems.

Dev & Engineering ✓ NVIDIA · Official

DOCA Flow Tune

Guides engineers through snapshotting, analyzing, and optimizing live or captured DOCA Flow pipelines.

Automation & Ops ✓ NVIDIA · Official

DOCA BlueField Bare-Metal Deployment

Run, supervise, and troubleshoot DOCA binaries directly on BlueField hardware.

Dev & Engineering ✓ NVIDIA · Official

DOCA Comch Host–DPU Messaging

Guides developers through configuring, building, and debugging Comch messaging between a host and a BlueField DPU.

Dev & Engineering ✓ NVIDIA · Official

DOCA Device Management Development Skill

Programmatically manage BlueField and ConnectX state through the DOCA C API.

Automation & Ops ✓ NVIDIA · Official

DOCA Container Deployment

Deploy, validate, and troubleshoot DOCA service containers on NVIDIA BlueField.

Dev & Engineering ✓ NVIDIA · Official

DOCA GPI GPU-Initiated RDMA Skill

Helps CUDA kernels drive RDMA queues directly from GPU memory without host-CPU mediation.

Related skills