Category: service
Key Management Service
Validation
CODEBLOCK0
Pass criteria: command exits 0 and output/alicloud-security-kms/validate.txt is generated.
Output And Evidence
- - Save KMS API discovery outputs and operation results in
output/alicloud-security-kms/. - Keep at least one request parameter example per operation type.
Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for KeyManagementService.
Workflow
1) Confirm region, resource identifiers, and desired action.
2) Discover API list and required parameters (see references).
3) Call API with SDK or OpenAPI Explorer.
4) Verify results with describe/list APIs.
AccessKey priority (must follow)
1) Environment variables: ALICLOUD_ACCESS_KEY_ID / ALICLOUD_ACCESS_KEY_SECRET / ALICLOUD_REGION_ID
Region policy: ALICLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user.
2) Shared config file: INLINECODE6
API discovery
- - Product code: INLINECODE7
- Default API version: INLINECODE8
- Use OpenAPI metadata endpoints to list APIs and get schemas (see references).
High-frequency operation patterns
1) Inventory/list: prefer List* / Describe* APIs to get current resources.
2) Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations.
3) Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.
Minimal executable quickstart
Use metadata-first discovery before calling business APIs:
CODEBLOCK1
Optional overrides:
CODEBLOCK2
The script writes API inventory artifacts under the skill output directory.
Output policy
If you need to save responses or generated artifacts, write them under:
INLINECODE18
Prerequisites
- - Configure least-privilege Alibaba Cloud credentials before execution.
- Prefer environment variables:
ALICLOUD_ACCESS_KEY_ID, ALICLOUD_ACCESS_KEY_SECRET, optional ALICLOUD_REGION_ID. - If region is unclear, ask the user before running mutating operations.
References
技能名称: alicloud-security-kms
详细描述:
类别: 服务
密钥管理服务
验证
bash
mkdir -p output/alicloud-security-kms
python -m pycompile skills/security/key-management/alicloud-security-kms/scripts/listopenapimetaapis.py && echo pycompileok > output/alicloud-security-kms/validate.txt
通过标准: 命令退出码为0,且已生成 output/alicloud-security-kms/validate.txt。
输出与证据
- - 将KMS API发现结果和操作结果保存在 output/alicloud-security-kms/ 目录下。
- 每种操作类型至少保留一个请求参数示例。
使用阿里云OpenAPI(RPC)配合官方SDK或OpenAPI Explorer来管理KeyManagementService的资源。
工作流程
1) 确认地域、资源标识符和所需操作。
2) 发现API列表和所需参数(参见参考资料)。
3) 使用SDK或OpenAPI Explorer调用API。
4) 使用describe/list类API验证结果。
AccessKey优先级(必须遵守)
1) 环境变量: ALICLOUDACCESSKEYID / ALICLOUDACCESSKEYSECRET / ALICLOUDREGIONID
地域策略: ALICLOUDREGIONID 为可选默认值。若未设置,则为任务选择最合理的地域;若不明确,则询问用户。
2) 共享配置文件: ~/.alibabacloud/credentials
API发现
- - 产品代码: Kms
- 默认API版本: 2016-01-20
- 使用OpenAPI元数据端点来列出API并获取模式(参见参考资料)。
高频操作模式
1) 清单/列表: 优先使用 List / Describe 类API获取当前资源。
2) 变更/配置: 优先使用 Create / Update / Modify / Set 类API进行变更操作。
3) 状态/故障排查: 优先使用 Get / Query / Describe*Status 类API进行诊断。
最小可执行快速入门
在调用业务API之前,先进行元数据优先的发现:
bash
python scripts/listopenapimeta_apis.py
可选覆盖参数:
bash
python scripts/listopenapimeta_apis.py --product-code --version
该脚本会将API清单产物写入技能输出目录下。
输出策略
如需保存响应或生成的产物,请写入以下目录:
output/alicloud-security-kms/
前置条件
- - 执行前配置好最小权限的阿里云凭证。
- 优先使用环境变量: ALICLOUDACCESSKEYID、ALICLOUDACCESSKEYSECRET,可选 ALICLOUDREGIONID。
- 若地域不明确,在执行变更操作前请询问用户。
参考资料
- - 来源: references/sources.md