Deepgram Deploy IntegrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: deepgram-deploy-integration description: 'Deploy Deepgram integrations to production environments. Use when deploying to cloud platforms, configuring containers, or setting up Deepgram in Docker/Kubernetes/serverless. Trigger: "deploy deepgram", "deepgram docker", "deepgram kubernetes", "deepgram production deploy", "deepgram cloud run", "deepgram lambda". ' allowed-tools: Read, Write, Edit, Bash(docker:*), Bash(kubectl:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - deepgram - deployment - docker - kubernetes - serverless compatibility: Designed for Claude Code --- # Deepgram Deploy Integration ## Examples Deploy a versioned integration to staging with a scoped secret reference and a short licensed fixture, then verify health, timeout/retry behavior, redacted metrics, and the rollback command. Promote through a controlled production canary only after data/consent and quality checks pass; do not deploy a key or audio fixture in the manifest. ## Overview Deploy Deepgram transcription services to Docker, Kubernetes, AWS Lambda, and Google Cloud Run. Includes production Dockerfile, K8s manifests with secret management, serverless handlers for event-driven transcription, and health check patterns. ## Prerequisites - Working Deepgram integration (tested locally) - Production API key in secret manager - Container registry access (Docker Hub, ECR, GCR) - Target platform CLI installed ## Instructions ### Step 1: Production Dockerfile ```dockerfile # Multi-stage build for minimal production image FROM node:20-alpine AS builder WORKDIR /app COPY package*.json ./ RUN npm ci --production=false COPY tsconfig.json ./ COPY src/ ./src/ RUN npm run build FROM node:20-alpine AS runtime # Security: non-root user RUN addgroup -g 1001 -S app && adduser -S app -u 1001 WORKDIR /app # Production dependencies only COPY package*.json ./ RUN npm ci --production && npm cache clean --force # Copy built application COPY --from=builder /app/dist ./dist # Health check (tests Deepgram connectivity) HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \ CMD wget -q --spider http://localhost:3000/health || exit 1 USER app EXPOSE 3000 CMD ["node", "dist/server.js"] ``` ### Step 2: Docker Compose ```yaml # docker-compose.yml version: '3.8' services: deepgram-service: build: . ports: - "3000:3000" environment: - NODE_ENV=production - DEEPGRAM_API_KEY=${DEEPGRAM_API_KEY} - DEEPGRAM_MODEL=nova-3 healthcheck: test: ["CMD", "wget", "-q", "--spider", "http://localhost:3000/health"] interval: 30s timeout: 10s retries: 3 restart: unless-stopped deploy: resources: limits: memory: 512M cpus: '1.0' redis: image: redis:7-alpine ports: - "6379:6379" volumes: - redis-data:/data volumes: redis-data: ``` ### Step 3: Kubernetes Deployment ```yaml # k8s/deployment.yaml apiVersion: apps/v1 kind: Deployment metadata: name: deepgram-service labels: app: deepgram-service spec: replicas: 3 selector: matchLabels: app: deepgram-service template: metadata: labels: app: deepgram-service spec: containers: - name: deepgram-service image: your-registry/deepgram-service:latest ports: - containerPort: 3000 env: - name: NODE_ENV value: production - name: DEEPGRAM_API_KEY valueFrom: secretKeyRef: name: deepgram-secrets key: api-key - name: DEEPGRAM_MODEL value: nova-3 resources: requests: memory: "256Mi" cpu: "250m" limits: memory: "512Mi" cpu: "1000m" livenessProbe: httpGet: path: /health port: 3000 initialDelaySeconds: 10 periodSeconds: 30 readinessProbe: httpGet: path: /health port: 3000 initialDelaySeconds: 5 periodSeconds: 10 --- apiVersion: v1 kind: Service metadata: name: deepgram-service spec: selector: app: deepgram-service ports: - port: 80 targetPort: 3000 type: ClusterIP --- apiVersion: autoscaling/v2 kind: HorizontalPodAutoscaler metadata: name: deepgram-service-hpa spec: scaleTargetRef: apiVersion: apps/v1 kind: Deployment name: deepgram-service minReplicas: 2 maxReplicas: 10 metrics: - type: Resource resource: name: cpu target: type: Utilization averageUtilization: 70 ``` ```bash # Create secret kubectl create secret generic deepgram-secrets \ --from-literal=api-key=$DEEPGRAM_API_KEY # Deploy kubectl apply -f k8s/ ``` ### Step 4: AWS Lambda Handler ```typescript // lambda/handler.ts import { createClient } from '@deepgram/sdk'; import { S3Client, GetObjectCommand } from '@aws-sdk/client-s3'; import type { S3Event } from 'aws-lambda'; const deepgram = createClient(process.env.DEEPGRAM_API_KEY!); const s3 = new S3Client({}); // Trigger: S3 upload of audio file -> Lambda -> Deepgram -> Store result export async function handler(event: S3Event) { for (const record of event.Records) { const bucket = record.s3.bucket.name; const key = decodeURIComponent(record.s3.object.key); console.log(`Processing: s3://${bucket}/${key}`); // Get audio from S3 const { Body } = await s3.send(new GetObjectCommand({ Bucket: bucket, Key: key })); const audio = Buffer.from(await Body!.transformToByteArray()); // Transcribe const { result, error } = await deepgram.listen.prerecorded.transcribeFile( audio, { model: 'nova-3', smart_format: true, diarize: true, utterances: true,
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__deepgram-deploy-integration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Deepgram Deploy Integration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Deepgram Deploy Integration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Deepgram Deploy Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Deepgram Deploy Integration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.