Agent skill

Alicloud Acs Cluster

by cinience in cinience/alicloud-skills

Create, inspect, connect to, inventory, and delete Alibaba Cloud Container Compute Service (ACS) clusters through the official CS OpenAPI.

MITAuto-check passedBackend & APIs

Install Alicloud Acs Cluster

skills CLI
$ npx skills add cinience/alicloud-skills --skill alicloud-acs-cluster -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cinience/alicloud-skills alicloud-acs-cluster --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cinience/alicloud-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compute/acs/alicloud-acs-cluster .claude/skills/alicloud-acs-cluster && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
alicloud-acs-cluster
GitHub stars
397
Token cost
~1.7k tokens
SKILL.md length
517 words
Files
5 (incl. scripts, references)
Skills in repo
96
Repo updated
First seen
Licence
MIT

At a glance

Create, inspect, connect to, inventory, and delete Alibaba Cloud Container Compute Service (ACS) clusters through the official CS OpenAPI.

  • Works in 9 steps: Read references/cluster-lifecycle.md… → Set ALIBABACLOUD_ACCESS_KEY_ID,… → Before creating the network, confirm… → …
  • Codex must bootstrap an ACS cluster from an existing VPC and VSwitches
  • SKILL.md covers Workflow, Safety, Commands and Output And Evidence, plus 2 more sections
  • Runs Python scripts from its folder; calls python3; needs ALIBABACLOUD_ACCESS_KEY_ID and ALIBABACLOUD_ACCESS_KEY_SECRET

What it does

Alicloud Acs Cluster is an agent skill from cinience/alicloud-skills. Create, inspect, connect to, inventory, and delete Alibaba Cloud Container Compute Service (ACS) clusters through the official CS OpenAPI. Use when Codex must bootstrap an ACS cluster from an existing VPC and VSwitches, obtain a short-lived KubeConfig, verify cluster readiness, inspect associated cloud resources, change deletion protection, or perform an explicitly confirmed full cluster teardown.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/cluster-lifecycle.md` and `references/sources.md`).

It sits in Backend & APIs, covering OpenAPI specifications. It works with Alibaba Cloud and OpenAPI. The repository describes itself as: alibaba cloud skills,qwen ,wan and all skills. The licence is MIT.

When your agent uses it

  • Codex must bootstrap an ACS cluster from an existing VPC and VSwitches
  • Obtain a short-lived KubeConfig
  • Verify cluster readiness
  • Inspect associated cloud resources

Example prompts

  • “/alicloud-acs-cluster”

Requirements

  • Python 3
  • A credential in ALIBABACLOUD_ACCESS_KEY_SECRET
  • A credential in ALIBABACLOUD_SECURITY_TOKEN

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Read references/cluster-lifecycle.md before creating or deleting a cluster.
  2. Set ALIBABACLOUD_ACCESS_KEY_ID, ALIBABACLOUD_ACCESS_KEY_SECRET, and optionally ALIBABACLOUD_SECURITY_TOKEN. Set…
  3. Before creating the network, confirm that the Alibaba Cloud account has already authorized both CSI service roles
  4. Install the official SDK
  5. Preview the exact create request without credentials or mutation
  6. Run the same command without --dry-run after confirming the cost and public API exposure. Save the result under…
  7. Require state=running, profile=Acs, the expected VPC/VSwitches, healthy virtual nodes, managed-coredns addon active, and a kube-dns…
  8. Request a short-lived KubeConfig and protect it as a secret
  9. Before deletion, remove workloads and list associated resources. Delete only after exact cluster-ID confirmation.

What it can do on your machine

Read from SKILL.md and the folder at commit 1818263. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ALIBABACLOUD_ACCESS_KEY_ID
    • ALIBABACLOUD_ACCESS_KEY_SECRET
    • ALIBABACLOUD_SECURITY_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Alicloud Acs Cluster loads about 1.7k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 517 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from cinience/alicloud-skills at commit 1818263, republished under its MIT licence (© cinience). 517 words, ~1,653 tokens.

Download SKILL.mdSave it as .claude/skills/alicloud-acs-cluster/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
alicloud-acs-cluster
description
Create, inspect, connect to, inventory, and delete Alibaba Cloud Container Compute Service (ACS) clusters through the official CS OpenAPI. Use when Codex must bootstrap an ACS cluster from an existing VPC and VSwitches, obtain a short-lived KubeConfig, verify cluster readiness, inspect associated cloud resources, change deletion protection, or perform an explicitly confirmed full cluster teardown.

Manage ACS clusters

Use the bundled OpenAPI client for the ACS cluster lifecycle. Use $aliyun-vpc-manage first when the VPC and VSwitches do not exist, and use $alicloud-acs-agent-sandbox after the cluster is ready.

Workflow

  1. Read references/cluster-lifecycle.md before creating or deleting a cluster.

  2. Set ALIBABACLOUD_ACCESS_KEY_ID, ALIBABACLOUD_ACCESS_KEY_SECRET, and optionally ALIBABACLOUD_SECURITY_TOKEN. Set ALIBABACLOUD_REGION_ID=cn-hangzhou for Hangzhou.

  3. Before creating the network, confirm that the Alibaba Cloud account has already authorized both CSI service roles:

    • AliyunCSManagedCsiPluginRole with AliyunCSManagedCsiPluginRolePolicy
    • AliyunCSManagedCsiProvisionerRole with AliyunCSManagedCsiProvisionerRolePolicy

    These are account-level, one-time authorizations. If the execution identity cannot call ram:GetRole, have the Alibaba Cloud account owner or a RAM administrator complete the official authorization pages. Container Service permissions alone cannot create these roles.

  4. Install the official SDK:

bash
python3 -m pip install "alibabacloud-cs20151215==7.0.4" "alibabacloud-tea-openapi"
  1. Preview the exact create request without credentials or mutation:
bash
python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py create \
  --region cn-hangzhou \
  --name <cluster-name> \
  --vpc-id <vpc-id> \
  --vswitch-id <vswitch-a> \
  --vswitch-id <vswitch-b> \
  --service-cidr 172.21.0.0/20 \
  --snat --public-api --enterprise-security-group --deletion-protection \
  --addon managed-coredns \
  --addon alb-ingress-controller \
  --dry-run

--dry-run is a local request-shape preview. It does not call Alibaba Cloud and therefore cannot validate service-role authorization, quota, capacity, or addon availability. 6. Run the same command without --dry-run after confirming the cost and public API exposure. Save the result under output/alicloud-acs-cluster/. 7. Require state=running, profile=Acs, the expected VPC/VSwitches, healthy virtual nodes, managed-coredns addon active, and a kube-dns Service before installing Agent Sandbox. Explicit addon lists can result in a cluster without CoreDNS; base Pods may run while Agent Identity storage later fails DNS. 8. Request a short-lived KubeConfig and protect it as a secret:

bash
acs_kubeconfig_path="$(mktemp)"
python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py kubeconfig \
  --region cn-hangzhou --cluster-id <cluster-id> \
  --temporary-minutes 60 --output "$acs_kubeconfig_path"
  1. Before deletion, remove workloads and list associated resources. Delete only after exact cluster-ID confirmation.

Manage addons without exposing their configuration. addon-status omits the config because Manager configs can contain an admin API key. Supply install/modify config only through a mode 0600 file:

bash
python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py install-addon \
  --region cn-hangzhou --cluster-id <cluster-id> \
  --addon-name managed-coredns

python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py addon-status \
  --region cn-hangzhou --cluster-id <cluster-id> \
  --addon-name managed-coredns
Show full SKILL.md (251 more words)Show less

Safety

  • Never print, commit, or copy KubeConfig, AccessKeys, certificates, component API keys, or bearer tokens into evidence.
  • Never use the unredacted all-addon version response as evidence: addon config can contain the Sandbox Manager admin API key. Use addon-status; use a protected --config-file for install/modify.
  • Treat --public-api and --snat as chargeable network changes. Restrict API Server access according to the current official control-plane access guidance.
  • Use at least two VSwitches in different zones for a non-disposable environment. Do not overlap VPC, VSwitch, Service, peer-VPC, or on-premises CIDRs.
  • Keep deletion protection enabled during build and validation. Disable it only immediately before an approved teardown.
  • Always run resources --with-addon-resources before cluster deletion. The delete API can retain ALB, SLS, PrivateZone, or other resources depending on their delete behavior.
  • delete --delete-associated is destructive. It requires --confirm-cluster-id to exactly match --cluster-id; still verify the post-delete inventory and delete separately created VPC resources afterward.
  • Do not assume an OpenAPI task response means completion. Poll the cluster state and verify the cloud resource inventory.
  • Do not assume cluster NotFound means every ACS Pod ENI has already disappeared. Poll VPC network interfaces before deleting VSwitches; never force-delete an in-use primary ENI.

Commands

bash
# Safe inspection
python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py describe \
  --region cn-hangzhou --cluster-id <cluster-id>

python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py resources \
  --region cn-hangzhou --cluster-id <cluster-id> --with-addon-resources

# Destructive teardown after workload cleanup
python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py disable-deletion-protection \
  --region cn-hangzhou --cluster-id <cluster-id> \
  --confirm-cluster-id <cluster-id>

python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py delete \
  --region cn-hangzhou --cluster-id <cluster-id> \
  --confirm-cluster-id <cluster-id> --delete-associated

Output And Evidence

Write sanitized request previews, cluster summaries, resource inventories, task IDs, and acceptance results under output/alicloud-acs-cluster/<operation>/. Store KubeConfig in a separate mktemp path with mode 0600, exclude it from reports, and remove it after teardown.

Sources

Use references/sources.md to verify current API fields, supported regions, network constraints, and deletion behavior before a live run.

Validation

bash
python3 skills/compute/acs/alicloud-acs-cluster/scripts/acs_cluster.py --help
python3 scripts/quick_validate.py skills/compute/acs/alicloud-acs-cluster

© cinience, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/compute/acs/alicloud-acs-cluster of cinience/alicloud-skills.

  • SKILL.md
  • agents/openai.yaml
  • references/cluster-lifecycle.md
  • references/sources.md
  • scripts/acs_cluster.py

Open the folder on GitHubat commit 1818263

Compare with similar skills

Alicloud Acs Cluster next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Alicloud Acs Cluster compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Alicloud Acs Cluster this skillcinience/alicloud-skills397—~1.7kAutomated safety check: PassMIT
ToolJet Marketplace Plugin BuilderToolJet/ToolJet41k—~2.1kAutomated safety check: PassAGPL-3.0
Step Partsearthtojake/text-to-cad19k1 repos~1.5kAutomated safety check: PassMIT
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT

Similar skills

  • Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.

    41k GitHub stars~2.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Step Parts

    earthtojake/text-to-cad

    Find, evaluate, and download common purchasable CAD parts from step.parts, including named off-the-shelf actuators, servos, motors, electronics boards, connectors, screws, bolts, nuts, washers…

    19k GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • CLI Creator

    huangruiteng/CS-Notes

    Build a composable CLI for Codex from API docs, an OpenAPI spec, existing curl examples, an SDK, a web app, an admin tool, or a local script.

    4k GitHub starsUsed in 2 repos~2.7k tokens
    Backend & APIsAuto-check passed

More from cinience/alicloud-skills

All 96 skills in this repo
  • Aliyun Skill Creator

    cinience/alicloud-skills

    A skill your agent uses when creating, migrating, or optimizing skills for this alicloud-skills repository.

    397 GitHub stars~2.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Alicloud Acs Agent Sandbox

    cinience/alicloud-skills

    Bootstrap, create, connect to, operate, secure, scale, upgrade, troubleshoot, inspect, and tear down Alibaba Cloud Container Compute Service (ACS) Agent Sandbox environments.

    397 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Aliyun Adb Mysql

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud AnalyticDB for MySQL (ADB) via OpenAPI/SDK, including the user needs AnalyticDB resource lifecycle and configuration operations, status checks, or…

    397 GitHub stars~708 tokensUpdated 2 mo ago
    Auto-check passed
  • Aliyun Aicontent Generate

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud AIContent (AiContent) via OpenAPI/SDK, including the user needs AI content generation or content workflow operations in Alibaba Cloud, including…

    397 GitHub stars~734 tokensUpdated 2 mo ago
    Auto-check passed
  • Aliyun Aimiaobi Generate

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud Quan Miao (AiMiaoBi) via OpenAPI/SDK, including the user asks for Alibaba Cloud MiaoBi content operations, including listing resources…

    397 GitHub stars~724 tokensUpdated 2 mo ago
    Auto-check passed
  • Aliyun Airec Manage

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud AIRec (Airec) via OpenAPI/SDK, including the user needs recommendation-engine resource operations in Alibaba Cloud, including list/create/update…

    397 GitHub stars~713 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Alicloud Acs Cluster

What does Alicloud Acs Cluster do?

Create, inspect, connect to, inventory, and delete Alibaba Cloud Container Compute Service (ACS) clusters through the official CS OpenAPI. Alicloud Acs Cluster is an agent skill from cinience/alicloud-skills. Create, inspect, connect to, inventory, and delete Alibaba Cloud Container Compute Service (ACS) clusters through the official CS OpenAPI.

When should I use Alicloud Acs Cluster?

Alicloud Acs Cluster fits situations like: Codex must bootstrap an ACS cluster from an existing VPC and VSwitches; obtain a short-lived KubeConfig; verify cluster readiness; inspect associated cloud resources.

How do I install Alicloud Acs Cluster in Claude Code?

Run `npx skills add cinience/alicloud-skills --skill alicloud-acs-cluster -a claude-code`. Or copy the skill folder (skills/compute/acs/alicloud-acs-cluster in cinience/alicloud-skills) into .claude/skills/alicloud-acs-cluster in your project. Claude Code loads it when a task matches its description.

How do I install Alicloud Acs Cluster in Codex?

Run `npx skills add cinience/alicloud-skills --skill alicloud-acs-cluster -a codex`. Or copy the skill folder (skills/compute/acs/alicloud-acs-cluster in cinience/alicloud-skills) into .agents/skills/alicloud-acs-cluster in your project. Codex loads it when a task matches its description.

Can I use Alicloud Acs Cluster in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cinience/alicloud-skills --skill alicloud-acs-cluster -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alicloud-acs-cluster, .gemini/skills/alicloud-acs-cluster, .github/skills/alicloud-acs-cluster and .opencode/skills/alicloud-acs-cluster in your project.

What does Alicloud Acs Cluster need to run?

Going by SKILL.md and its folder, Alicloud Acs Cluster needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named ALIBABACLOUD_ACCESS_KEY_ID, ALIBABACLOUD_ACCESS_KEY_SECRET and ALIBABACLOUD_SECURITY_TOKEN. Our summary lists: Python 3; A credential in ALIBABACLOUD_ACCESS_KEY_SECRET; A credential in ALIBABACLOUD_SECURITY_TOKEN.

Does Alicloud Acs Cluster access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Alicloud Acs Cluster safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Alicloud Acs Cluster use?

Alicloud Acs Cluster is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Alicloud Acs Cluster use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Alicloud Acs Cluster?

Skills that share tags, products or a category with Alicloud Acs Cluster: ToolJet Marketplace Plugin Builder (ToolJet/ToolJet, 41k stars), Step Parts (earthtojake/text-to-cad, 19k stars), OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars) and Use Yaak (mountain-loop/yaak, 19k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Alicloud Acs Cluster?

cinience (a GitHub user) maintains it in cinience/alicloud-skills, which has 397 GitHub stars. The repository holds 96 skills in this directory. The repository was last updated on August 11, 2026.

Source: cinience/alicloud-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.