Security

Alibaba Cloud Security KMS

Discover, call, and verify Alibaba Cloud KMS operations through OpenAPI or official SDKs.

What it does

Manage Alibaba Cloud Key Management Service resources through RPC OpenAPI calls using official SDKs or OpenAPI Explorer. The workflow confirms region and resource IDs, discovers Kms API schemas, executes the requested list, configuration, or status operation, then verifies results with describe/list APIs. API inventories and operation evidence are saved under `output/alicloud-security-kms/`.

When to use it

  • Inventorying KMS resources
  • Changing KMS resource configuration
  • Checking resource status
  • Discovering KMS API schemas

The skill document

Category: service

Key Management Service

Validation

mkdir -p output/alicloud-security-kms
python -m py_compile skills/security/key-management/alicloud-security-kms/scripts/list_openapi_meta_apis.py && echo "py_compile_ok" > output/alicloud-security-kms/validate.txt

Pass criteria: command exits 0 and output/alicloud-security-kms/validate.txt is generated.

Output And Evidence

  • Save KMS API discovery outputs and operation results in output/alicloud-security-kms/.
  • Keep at least one request parameter example per operation type.

Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for KeyManagementService.

Workflow

  1. Confirm region, resource identifiers, and desired action.
  2. Discover API list and required parameters (see references).
  3. Call API with SDK or OpenAPI Explorer.
  4. Verify results with describe/list APIs.

AccessKey priority (must follow)

  1. Environment variables: ALICLOUD_ACCESS_KEY_ID / ALICLOUD_ACCESS_KEY_SECRET / ALICLOUD_REGION_ID Region policy: ALICLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user.
  2. Shared config file: ~/.alibabacloud/credentials

API discovery

  • Product code: Kms
  • Default API version: 2016-01-20
  • Use OpenAPI metadata endpoints to list APIs and get schemas (see references).

High-frequency operation patterns

  1. Inventory/list: prefer List* / Describe* APIs to get current resources.
  2. Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations.
  3. Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.

Minimal executable quickstart

Use metadata-first discovery before calling business APIs:

python scripts/list_openapi_meta_apis.py

Optional overrides:

python scripts/list_openapi_meta_apis.py --product-code  --version 

The script writes API inventory artifacts under the skill output directory.

Output policy

If you need to save responses or generated artifacts, write them under: output/alicloud-security-kms/

Prerequisites

  • Configure least-privilege Alibaba Cloud credentials before execution.
  • Prefer environment variables: ALICLOUD_ACCESS_KEY_ID, ALICLOUD_ACCESS_KEY_SECRET, optional ALICLOUD_REGION_ID.
  • If region is unclear, ask the user before running mutating operations.

References

  • Sources: references/sources.md

Questions people ask

How does it choose the correct KMS API and parameters?
It uses OpenAPI metadata endpoints to list APIs and retrieve schemas for product code `Kms`, with API version `2016-01-20` as the default.
Which credential sources and region settings does it use?
It prioritizes `ALICLOUD_ACCESS_KEY_ID` and `ALICLOUD_ACCESS_KEY_SECRET` environment variables, with optional `ALICLOUD_REGION_ID`, then falls back to `~/.alibabacloud/credentials`. If the region is unclear, it asks before mutating resources.
What output is retained after an operation?
KMS API discovery artifacts and operation results are written to `output/alicloud-security-kms/`, with at least one request-parameter example retained for each operation type.

Related skills

Encrypt, upload, verify, retain, and restore scoped OpenClaw backups in S3-compatible storage.

89 installs4 stars

Architect, troubleshoot, secure, and cost-control AWS infrastructure with explicit cost and blast-radius guidance.

by Iván138 installs2 stars