Manage and verify Alibaba Cloud SWAS resources through the 2020-06-01 OpenAPI.
Security
Alibaba Cloud Security KMS
Discover, call, and verify Alibaba Cloud KMS operations through OpenAPI or official SDKs.
What it does
Manage Alibaba Cloud Key Management Service resources through RPC OpenAPI calls using official SDKs or OpenAPI Explorer. The workflow confirms region and resource IDs, discovers Kms API schemas, executes the requested list, configuration, or status operation, then verifies results with describe/list APIs. API inventories and operation evidence are saved under `output/alicloud-security-kms/`.
When to use it
- Inventorying KMS resources
- Changing KMS resource configuration
- Checking resource status
- Discovering KMS API schemas
The skill document
Category: service
Key Management Service
Validation
mkdir -p output/alicloud-security-kms
python -m py_compile skills/security/key-management/alicloud-security-kms/scripts/list_openapi_meta_apis.py && echo "py_compile_ok" > output/alicloud-security-kms/validate.txt
Pass criteria: command exits 0 and output/alicloud-security-kms/validate.txt is generated.
Output And Evidence
- Save KMS API discovery outputs and operation results in
output/alicloud-security-kms/. - Keep at least one request parameter example per operation type.
Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for KeyManagementService.
Workflow
- Confirm region, resource identifiers, and desired action.
- Discover API list and required parameters (see references).
- Call API with SDK or OpenAPI Explorer.
- Verify results with describe/list APIs.
AccessKey priority (must follow)
- Environment variables:
ALICLOUD_ACCESS_KEY_ID/ALICLOUD_ACCESS_KEY_SECRET/ALICLOUD_REGION_IDRegion policy:ALICLOUD_REGION_IDis an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. - Shared config file:
~/.alibabacloud/credentials
API discovery
- Product code:
Kms - Default API version:
2016-01-20 - Use OpenAPI metadata endpoints to list APIs and get schemas (see references).
High-frequency operation patterns
- Inventory/list: prefer
List*/Describe*APIs to get current resources. - Change/configure: prefer
Create*/Update*/Modify*/Set*APIs for mutations. - Status/troubleshoot: prefer
Get*/Query*/Describe*StatusAPIs for diagnosis.
Minimal executable quickstart
Use metadata-first discovery before calling business APIs:
python scripts/list_openapi_meta_apis.py
Optional overrides:
python scripts/list_openapi_meta_apis.py --product-code --version
The script writes API inventory artifacts under the skill output directory.
Output policy
If you need to save responses or generated artifacts, write them under:
output/alicloud-security-kms/
Prerequisites
- Configure least-privilege Alibaba Cloud credentials before execution.
- Prefer environment variables:
ALICLOUD_ACCESS_KEY_ID,ALICLOUD_ACCESS_KEY_SECRET, optionalALICLOUD_REGION_ID. - If region is unclear, ask the user before running mutating operations.
References
- Sources:
references/sources.md
Questions people ask
- How does it choose the correct KMS API and parameters?
- It uses OpenAPI metadata endpoints to list APIs and retrieve schemas for product code `Kms`, with API version `2016-01-20` as the default.
- Which credential sources and region settings does it use?
- It prioritizes `ALICLOUD_ACCESS_KEY_ID` and `ALICLOUD_ACCESS_KEY_SECRET` environment variables, with optional `ALICLOUD_REGION_ID`, then falls back to `~/.alibabacloud/credentials`. If the region is unclear, it asks before mutating resources.
- What output is retained after an operation?
- KMS API discovery artifacts and operation results are written to `output/alicloud-security-kms/`, with at least one request-parameter example retained for each operation type.
Related skills
Generate Qwen images through DashScope with normalized requests, responses, and saved run evidence.
Generate Wan text-to-video and image-to-video through a normalized DashScope Python interface.
Convert text into WAV audio URLs or streamed 24 kHz PCM using DashScope Qwen TTS models.
Encrypt, upload, verify, retain, and restore scoped OpenClaw backups in S3-compatible storage.
Architect, troubleshoot, secure, and cost-control AWS infrastructure with explicit cost and blast-radius guidance.