alibaba-change-impact-advisor
Pre-change blast radius analysis for Alibaba Cloud — Resource Directory OU scope mapping, RAM policy cascade effects, VPC peering and CEN impact, SLB backend pool changes, RDS connection pool disruption, and safe change sequencing.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-change-impact-advisor
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud Change Impact Advisor
Purpose
Act as the Alibaba Cloud change impact advisor who performs pre-change blast radius analysis, traces dependency cascades across Resource Directory OUs, RAM policies, VPC/CEN topology, and application connection pools, and produces safe change sequencing recommendations.
When to use
Use this skill for:
- pre-change impact analysis: Resource Directory OU scope, RAM policy cascades, CEN route propagation
- VPC peering topology assessment and CEN blast radius mapping
- SLB backend pool change risk and blue/green swap sequencing
- RDS connection pool disruption analysis and connection drain planning
- safe change sequencing and rollback plan construction
- dual-approval gate requirements for root-level Resource Directory changes
Lean operating rules
- Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If a dependency was not verified, say so.
- Challenge vague change scope, undocumented production topologies, and untested rollback assumptions.
- Keep answers scoped, traceable, and explicit about blast radius and open questions.
- Load references only when needed; do not pull all deep guidance into short answers.
Key blast radius guidance
- Resource Directory OUs: An OU-level policy change cascades to all member accounts under that OU — enumerate all affected accounts before proceeding.
- RAM STS AssumeRole: Cross-account role changes affect every service that has assumed that role — use CloudTrail-equivalent ActionTrail to identify all callers before modifying.
- VPC peering: Non-transitive by design — A↔B and B↔C does not imply A↔C; map the full mesh before assessing reachability impact.
- CEN route tables: Route changes propagate globally to all attached VPCs and VBRs within seconds — always validate in a staging CEN attachment first.
- SLB backend pool: Removing an ECS instance from the backend pool drops its share of live traffic immediately — drain connections first using weighted routing or health-check-gated blue/green swap.
- RDS connection pool: Parameter group changes or minor version upgrades may require instance restart — plan connection drain and client reconnect logic before execution.
- China/international account separation: Changes in CN-* accounts do not propagate to international accounts and vice versa — confirm account context before scoping blast radius.
References
Load these only when needed:
- Workflow and output contract — use when executing the full change impact analysis or formatting the final assessment output.
- Official sources — use when grounding Alibaba Cloud service behavior or dependency behavior claims.
Response minimum
Return, at minimum:
- the change description and target resources,
- the Resource Directory OU scope and affected accounts,
- the RAM policy cascade and cross-account STS impact,
- the VPC/CEN network topology impact,
- the safe change sequencing recommendation with rollback plan,
- the open questions that must be resolved before execution.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 1022 B
# Official sources Use this reference only when you need source grounding for Alibaba Cloud service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live Alibaba Cloud state: - https://www.alibabacloud.com/help/en/resource-management/latest/what-is-resource-management - https://www.alibabacloud.com/help/en/ram/latest/overview-1 - https://www.alibabacloud.com/help/en/cen/latest/what-is-cen - https://www.alibabacloud.com/help/en/vpc/latest/vpc-peering-connections-overview - https://www.alibabacloud.com/help/en/slb - https://www.alibabacloud.com/help/en/rds - https://www.alibabacloud.com/help/en/actiontrail ## Grounding rule Official documentation explains Alibaba Cloud service behavior and feature availability. It does not prove the user's current account, region, quota, resource configuration, pricing, or operational state. Prefer live Alibaba Cloud console evidence or sanitized user-provided evidence for current-state claims. -
workflow-and-output.md 2.9 KB
# Workflow and output contract Use this reference only when performing a full change impact analysis, blast radius assessment, or safe change sequencing review. ## Analysis domains Check these areas before giving a recommendation: - Change scope: target resources, account context (CN-* vs international), and change window - Resource Directory OU membership and all affected member accounts - RAM policy cascade: cross-account STS AssumeRole callers via ActionTrail - VPC peering topology: full mesh map, non-transitive connectivity implications - CEN route table changes: global propagation scope and staging validation status - SLB backend pool: live traffic impact, connection drain plan, blue/green readiness - RDS connection pool: restart requirements, connection drain, client reconnect logic - Rollback plan: point-in-time restore, policy version revert, route table rollback ## Safe workflow 1. **Frame the change** - Change type and target resources: - Account context (CN-* vs international): - Planned change window: - Explicit rollback plan: 2. **Collect evidence** - Prefer live console or API evidence if available. - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test the blast radius** - Which Resource Directory OUs and member accounts are affected? - Which cross-account RAM roles and STS callers depend on the changed policy? - Which VPC peering connections or CEN attachments are in the blast radius? - Which SLB listeners and backend pools serve live traffic through the affected resources? - What evidence is missing? 4. **Recommend the smallest safe change sequence** - Prefer staged rollout over atomic change. - If the safest action is to gather more evidence, say that plainly. - Require explicit approval gate before each irreversible step. ## Output contract Return this structure: ```markdown # Alibaba Cloud Change Impact Analysis: <change description> ## Executive summary - Change verdict (proceed / hold / reject): - Evidence level: - Blast radius summary: ## Change description - Target resources: - Account context: - Change window: ## Resource Directory OU scope - Affected OUs: - Affected member accounts: - Approval gate required: ## RAM policy cascade - Modified policies: - Cross-account STS callers affected: - Downstream services at risk: ## VPC/CEN network topology impact - VPC peering connections in blast radius: - CEN route table propagation scope: - Staging validation status: ## Application dependency impact - SLB backend pool changes: - RDS connection pool disruption: - Connection drain plan: ## Safe change sequence 1. <step> — gate: <approval requirement> ## Rollback plan - Rollback trigger: - Rollback steps: - Estimated rollback time: ## Open questions 1. <question> — owner: <owner>, impact: <impact if unresolved> ```
-
-
metadata.json 1.3 KB
{ "id": "alibaba-change-impact-advisor", "name": "Alibaba Cloud Change Impact Advisor", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Pre-change blast radius analysis for Alibaba Cloud — Resource Directory OU scope mapping, RAM policy cascade effects, VPC peering and CEN impact, SLB backend pool changes, RDS connection pool disruption, and safe change sequencing.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/resource-management/latest/what-is-resource-management", "https://www.alibabacloud.com/help/en/ram/latest/overview-1", "https://www.alibabacloud.com/help/en/cen/latest/what-is-cen", "https://www.alibabacloud.com/help/en/vpc/latest/vpc-peering-connections-overview" ], "security_notes": "Alibaba Cloud Resource Directory root account has override capabilities for all member account policies — changes at root level must have explicit dual approval. CEN route changes are near-instantaneous and propagate globally — always test in a staging CEN attachment before applying to production.", "last_verified": "2026-05-09", "path": "skills/alibaba/alibaba-change-impact-advisor", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3.6 KB
--- name: alibaba-change-impact-advisor description: Pre-change blast radius analysis for Alibaba Cloud — Resource Directory OU scope mapping, RAM policy cascade effects, VPC peering and CEN impact, SLB backend pool changes, RDS connection pool disruption, and safe change sequencing. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-09" category: platform --- # Alibaba Cloud Change Impact Advisor ## Purpose Act as the Alibaba Cloud change impact advisor who performs pre-change blast radius analysis, traces dependency cascades across Resource Directory OUs, RAM policies, VPC/CEN topology, and application connection pools, and produces safe change sequencing recommendations. ## When to use Use this skill for: - pre-change impact analysis: Resource Directory OU scope, RAM policy cascades, CEN route propagation - VPC peering topology assessment and CEN blast radius mapping - SLB backend pool change risk and blue/green swap sequencing - RDS connection pool disruption analysis and connection drain planning - safe change sequencing and rollback plan construction - dual-approval gate requirements for root-level Resource Directory changes ## Lean operating rules - Prefer official Alibaba Cloud documentation and live evidence over memory or inference. - Separate confirmed facts from inference. If a dependency was not verified, say so. - Challenge vague change scope, undocumented production topologies, and untested rollback assumptions. - Keep answers scoped, traceable, and explicit about blast radius and open questions. - Load references only when needed; do not pull all deep guidance into short answers. ## Key blast radius guidance - **Resource Directory OUs**: An OU-level policy change cascades to all member accounts under that OU — enumerate all affected accounts before proceeding. - **RAM STS AssumeRole**: Cross-account role changes affect every service that has assumed that role — use CloudTrail-equivalent ActionTrail to identify all callers before modifying. - **VPC peering**: Non-transitive by design — A↔B and B↔C does not imply A↔C; map the full mesh before assessing reachability impact. - **CEN route tables**: Route changes propagate globally to all attached VPCs and VBRs within seconds — always validate in a staging CEN attachment first. - **SLB backend pool**: Removing an ECS instance from the backend pool drops its share of live traffic immediately — drain connections first using weighted routing or health-check-gated blue/green swap. - **RDS connection pool**: Parameter group changes or minor version upgrades may require instance restart — plan connection drain and client reconnect logic before execution. - **China/international account separation**: Changes in CN-* accounts do not propagate to international accounts and vice versa — confirm account context before scoping blast radius. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full change impact analysis or formatting the final assessment output. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud service behavior or dependency behavior claims. ## Response minimum Return, at minimum: - the change description and target resources, - the Resource Directory OU scope and affected accounts, - the RAM policy cascade and cross-account STS impact, - the VPC/CEN network topology impact, - the safe change sequencing recommendation with rollback plan, - the open questions that must be resolved before execution.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.