PluginBench
Skill
Pass
Audit score 90

platform-metadata-deploy

forcedotcom/sf-skills

Salesforce DevOps automation: deploy metadata, manage orgs, and orchestrate CI/CD pipelines with sf CLI v2.

What is platform-metadata-deploy?

Automates Salesforce metadata deployment, scratch-org management, and CI/CD workflows using the sf CLI v2. Use this skill when deploying metadata changes, validating deployments, managing sandboxes, setting up pipelines, or troubleshooting deployment failures—but delegate Apex authoring, LWC components, custom object/field creation, and data operations to their respective skills.

  • Validate and deploy metadata using dry-run, manifest, or source-dir scopes with sf project deploy start
  • Manage scratch orgs and sandboxes with proper authentication and environment configuration
  • Orchestrate safe deployment sequencing (objects → permission sets → Apex → Flows) to prevent dependency failures
  • Troubleshoot deployment errors, test failures, and dependency ordering issues
  • Provide CI/CD pipeline guidance including test-level selection, validation gates, and rollback strategies
  • Generate deployment reports and verify post-deploy state

How to install platform-metadata-deploy

npx skills add https://github.com/forcedotcom/sf-skills --skill platform-metadata-deploy
Prerequisites
  • sf CLI v2 (>=2.0.0) installed and authenticated to target org
  • git (>=2.0.0) for version control
  • curl (>=7.0.0) and jq (>=1.7.0) for API calls and JSON processing
  • Valid sfdx-project.json in repository root
  • Target org alias configured via sf org list
Claude Code
Cursor
Windsurf
Cline

How to use platform-metadata-deploy

  1. 1.Run preflight checks: sf --version, sf org list, and sf org display --target-org <alias> --json
  2. 2.Gather deployment context: target org, scope (source-dir/manifest/metadata), and test level requirements
  3. 3.Validate first with --dry-run: sf project deploy start --dry-run --source-dir force-app --target-org <alias> --wait 30 --json
  4. 4.Review validation results and address any errors before proceeding
  5. 5.Deploy using the appropriate scope: source-dir, manifest, or quick deploy after successful validation
  6. 6.Verify deployment with sf project deploy report --job-id <job-id> --target-org <alias> --json
  7. 7.Confirm tests passed, Flows are in correct state, and permission sets are assigned

Use cases

Good for
  • Validating a metadata change set before production deployment using --dry-run
  • Deploying a targeted set of custom objects and permission sets to a sandbox
  • Setting up a CI/CD pipeline with static analysis, validation gates, and automated testing
  • Troubleshooting a failed deployment due to missing field-level security or validation rule conflicts
  • Quick-deploying a previously validated changeset to production
Who it's for
  • Salesforce DevOps engineers and release managers
  • CI/CD pipeline architects
  • Developers troubleshooting deployment failures
  • Teams managing multi-org release workflows

platform-metadata-deploy FAQ

When should I use --dry-run vs. actual deploy?

Always use --dry-run first to validate metadata and catch errors before real deployment. Only deploy after validation succeeds and you've reviewed the changeset.

What is the recommended deployment order for metadata?

Deploy in this order: custom objects/fields → permission sets → Apex → Flows (as Draft) → Flow activation. This prevents dependency and field-level security failures.

How do I deploy only specific metadata instead of everything?

Use --manifest with a package.xml file, --metadata with a comma-separated list, or --source-dir to scope to a specific directory.

What should I do if a deployment fails with INVALID_CROSS_REFERENCE_KEY?

This indicates a missing dependency. Identify the referenced metadata, include it in your deployment scope, and redeploy in the correct order.

Can I use this skill for Apex code authoring or Flow creation?

No. Delegate Apex authoring to platform-apex-generate, Flow creation to automation-flow-generate, and custom object/field creation to their respective skills. This skill handles deployment and orchestration only.

Full instructions (SKILL.md)

Source of truth, from forcedotcom/sf-skills.


name: platform-metadata-deploy description: "Salesforce DevOps automation using sf CLI v2. TRIGGER when: user deploys metadata, creates/manages scratch orgs or sandboxes, sets up CI/CD pipelines, or troubleshoots deployment errors with sf project deploy. DO NOT TRIGGER when: writing Apex code (use platform-apex-generate), building LWC components (use experience-lwc-generate), creating metadata definitions (use platform-custom-object-generate or platform-custom-field-generate), or querying org data (use platform-data-manage)." metadata: version: "1.1" domains: ["Platform", "Developer Experience"] relatedSkills: - "agentforce-generate" - "agentforce-test" - "automation-flow-generate" - "experience-lwc-generate" - "integration-connectivity-connected-app-configure" - "integration-connectivity-generate" - "platform-apex-generate" - "platform-apex-test-run" - "platform-custom-field-generate" - "platform-custom-object-generate" - "platform-data-manage" cliTools: - tool: ["curl"] semver: ">=7.0.0" - tool: ["git"] semver: ">=2.0.0" - tool: ["jq"] semver: ">=1.7.0" - tool: ["sf"] semver: ">=2.0.0"

platform-metadata-deploy: Comprehensive Salesforce DevOps Automation

Use this skill when the user needs deployment orchestration: dry-run validation, targeted or manifest-based deploys, CI/CD workflow advice, scratch-org management, failure triage, or safe rollout sequencing for Salesforce metadata.

When This Skill Owns the Task

Use platform-metadata-deploy when the work involves:

  • sf project deploy start, quick, report, or retrieval workflows
  • release sequencing across objects, permission sets, Apex, and Flows
  • CI/CD gates, test-level selection, or deployment reports
  • troubleshooting deployment failures and dependency ordering

Delegate elsewhere when the user is:

  • authoring Apex code → platform-apex-generate
  • authoring LWC components → experience-lwc-generate
  • creating custom objects or fields → platform-custom-object-generate, platform-custom-field-generate
  • building Flows → automation-flow-generate
  • doing org data operations → platform-data-manage
  • authoring or testing Agentforce agents → agentforce-generate

Critical Operating Rules

  • Use sf CLI v2 only.
  • On non-source-tracking orgs, deploy/retrieve commands require an explicit scope such as --source-dir, --metadata, or --manifest.
  • Prefer --dry-run first before real deploys.
  • For Flows, deploy safely and activate only after validation.
  • Keep test-data creation guidance delegated to platform-data-manage after metadata is validated or deployed.

Default deployment order

PhaseMetadata
1Custom objects / fields
2Permission sets
3Apex
4Flows as Draft
5Flow activation / post-verify

This ordering prevents many dependency and FLS failures.


Required Context to Gather First

Ask for or infer:

  • target org alias and environment type
  • deployment scope: source-dir, metadata list, or manifest
  • whether this is validate-only, deploy, quick deploy, retrieve, or CI/CD guidance
  • required test level and rollback expectations
  • whether special metadata types are involved (Flow, permission sets, agents, packages)

Preflight checks:

sf --version
sf org list
sf org display --target-org <alias> --json
test -f sfdx-project.json

Recommended Workflow

1. Preflight

Confirm auth, repo shape, package directories, and target scope.

2. Validate first

sf project deploy start --dry-run --source-dir force-app --target-org <alias> --wait 30 --json

Use manifest- or metadata-scoped validation when the change set is targeted.

3. If validation succeeds, offer the next safe workflow

After a successful validation, guide the user to the correct next action:

  1. deploy now
  2. assign permission sets
  3. create test data via platform-data-manage
  4. run tests / smoke checks
  5. orchestrate multiple post-deploy steps in order

4. Deploy the smallest correct scope

# source-dir deploy
sf project deploy start --source-dir force-app --target-org <alias> --wait 30 --json

# manifest deploy
sf project deploy start --manifest manifest/package.xml --target-org <alias> --test-level RunLocalTests --wait 30 --json

# manifest deploy with Spring '26 relevant-test selection
sf project deploy start --manifest manifest/package.xml --target-org <alias> --test-level RunRelevantTests --wait 30 --json

# quick deploy after successful validation
sf project deploy quick --job-id <validation-job-id> --target-org <alias> --json

5. Verify

sf project deploy report --job-id <job-id> --target-org <alias> --json

Then verify tests, Flow state, permission assignments, and smoke-test behavior.

6. Report clearly

Summarize what deployed, what failed, what was skipped, and what the next safe action is.

Output template: references/deployment-report-template.md


High-Signal Failure Patterns

Error / symptomLikely causeDefault fix direction
FIELD_CUSTOM_VALIDATION_EXCEPTIONvalidation rule or bad test dataadjust data or rule timing
INVALID_CROSS_REFERENCE_KEYmissing dependencyinclude referenced metadata first
CANNOT_INSERT_UPDATE_ACTIVATE_ENTITYtrigger / Flow / validation side effectinspect automation stack and failing logic
tests fail during deploybroken code or fragile testsrun targeted tests, fix root cause, revalidate
field/object not found in permsetwrong orderdeploy objects/fields before permission sets
Flow invalid / version conflictdependency or activation problemdeploy as Draft, verify, then activate

Full workflows: references/orchestration.md, references/trigger-deployment-safety.md


CI/CD Guidance

Default pipeline shape:

  1. authenticate
  2. validate repo / org state
  3. static analysis
  4. dry-run deploy
  5. tests + coverage gates
  6. deploy
  7. verify + notify
  • When org policy and release risk allow it, consider --test-level RunRelevantTests for Apex-heavy deployments.
  • Pair this with modern Apex test annotations such as @IsTest(testFor=...) and @IsTest(isCritical=true) — see platform-apex-generate for authoring guidance.

Static analysis now uses Code Analyzer v5 (sf code-analyzer), not retired sf scanner.

Deep reference: references/deployment-workflows.md


Agentforce Deployment Note

Use this skill to orchestrate deployment/publish sequencing around agents, but use the agent-specific skill for authoring decisions:

  • agentforce-generate for .agent authoring, Agent Builder, Prompt Builder, and metadata config

For full agent DevOps details, including Agent: pseudo metadata, publish/activate, and sync-between-orgs, see:


Cross-Skill Integration

NeedDelegate toReason
custom object creationplatform-custom-object-generatedefine objects before deploy
custom field creationplatform-custom-field-generatedefine fields before deploy
Apex authoring / fixesplatform-apex-generatecode authoring and repair
Flow creation / repairautomation-flow-generateFlow authoring and activation guidance
test data or seed recordsplatform-data-managedescribe-first data setup and cleanup
Agent authoring and publish readinessagentforce-generateagent-specific correctness

Reference Map

Start here

Specialized deployment safety

Asset templates


Score Guide

ScoreMeaning
90+strong deployment plan and execution guidance
75–89good deploy guidance with minor review items
60–74partial coverage of deployment risk
< 60insufficient confidence; tighten plan before rollout

Completion Format

Deployment goal: <validate / deploy / retrieve / pipeline>
Target org: <alias>
Scope: <source-dir / metadata / manifest>
Result: <passed / failed / partial>
Key findings: <errors, ordering, tests, skipped items>
Next step: <safe follow-up action>