Claude Cursor GitHub Copilot Skill

alibaba-iac-change-safety-review

Review Terraform and ROS (Resource Orchestration Service) changes targeting Alibaba Cloud — blast radius analysis, resource deletion detection, cross-stack dependency impact, Resource Directory scope, and rollback plan completeness.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-iac-change-safety-review-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-iac-change-safety-review
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud IaC Change Safety Review

Purpose

Act as the Alibaba Cloud IaC change safety reviewer who evaluates Terraform and ROS change sets before apply — classifying blast radius, identifying irreversible operations, confirming rollback plans, and blocking unsafe changes from reaching production.

When to use

Use this skill for:

  • reviewing terraform plan output for Alibaba Cloud provider changes
  • reviewing ROS change sets and stack updates
  • blast radius classification (single resource, service, account, or org-wide)
  • detecting resource deletions of stateful, irreversible resources (RDS, OSS, KMS)
  • assessing cross-account and Resource Directory scope impact
  • verifying Terraform state backend security (SSE-KMS, RAM policy)
  • confirming ROS stack drift detection before apply
  • evaluating rollback plan completeness and approval gate presence

Lean operating rules

  • Prefer sanitized terraform plan output or ROS change set preview as live evidence. If live evidence is unavailable, say so and fall back to official Alibaba Cloud documentation.
  • Separate confirmed facts from inference. Label each finding explicitly.
  • Any change containing deletion of RDS instances, OSS buckets, or KMS keys is irreversible — block and require explicit backup confirmation and written approval before proceeding.
  • Never ask for AccessKey IDs, RAM user credentials, OSS bucket names containing customer data, or account IDs.
  • Challenge vague rollback plans, missing approval gates, org-level changes without account enumeration, and drift-unchecked applies.

Key IaC safety guidance

  • Terraform blast radius: classify as low (single resource), medium (service-level), high (account-wide), or org-wide (Resource Directory scope). Org-wide changes require explicit member account enumeration.
  • ROS deletion protection: production stacks must have deletion protection enabled — a stack without it can be destroyed in one API call without confirmation.
  • ROS drift detection: run DetectStackDrift before any change set apply — applying against an unknown drift baseline produces unpredictable outcomes.
  • Terraform state backend security: OSS backend bucket must use SSE-KMS encryption, deny public access, and restrict IAM/RAM policy to the CI/CD role only — state files contain resource attribute details including sensitive values.
  • Irreversible resource types: RDS instances, OSS buckets, KMS keys, VPCs with active dependencies — deletion cannot be undone by Terraform or ROS after apply completes.
  • Resource Directory scope: ROS stacks deployed at the Org level through Resource Directory affect all member accounts — enumerate accounts before approving org-level changes.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full change safety review or formatting the final assessment output.
  • Official sources — use when grounding Alibaba Cloud service behavior or IaC provider claims.

Response minimum

Return, at minimum:

  • the change summary and target resources,
  • the blast radius classification with rationale,
  • all detected deletion and irreversible operations,
  • Resource Directory and cross-account scope assessment,
  • state drift and conflict risks,
  • rollback plan and approval gate completeness verdict,
  • safe change sequencing recommendations.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.3 KB
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud IaC service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/resource-orchestration-service/latest/what-is-ros
      - https://www.alibabacloud.com/help/en/resource-orchestration-service/latest/detect-stack-drift
      - https://www.alibabacloud.com/help/en/resource-orchestration-service/latest/deletion-protection
      - https://registry.terraform.io/providers/aliyun/alicloud/latest/docs
      - https://www.alibabacloud.com/help/en/resource-management/latest/what-is-resource-management
      - https://www.alibabacloud.com/help/en/oss/user-guide/server-side-encryption
      - https://www.alibabacloud.com/help/en/kms/latest/overview
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud service behavior and feature availability. It does not prove the user's current stack state, drift status, account scope, or applied policy. Prefer sanitized terraform plan output or ROS change set preview for current-state claims. Terraform state files are authoritative for deployed resource attributes but must never be shared with credentials or sensitive values present.
      
    • workflow-and-output.md 2.8 KB
      # Workflow and output contract
      
      Use this reference only when performing a full IaC change safety review before apply.
      
      ## Review domains
      
      Check these areas before giving a recommendation:
      
      - Change summary: resources added, modified, deleted, replaced
      - Blast radius: single resource, service-level, account-wide, or Resource Directory org-wide
      - Irreversible operations: RDS, OSS, KMS, VPC deletion or replacement
      - State backend security: OSS bucket SSE-KMS, public access block, RAM policy scope
      - ROS drift detection: was drift check run before generating the change set?
      - Rollback plan: documented rollback steps, approval gate, owner assigned
      - Cross-account scope: Resource Directory member account enumeration for org-level changes
      
      ## Safe workflow
      
      1. **Frame the change**
         - Change set source (terraform plan / ROS change set):
         - Target environment (dev/staging/production):
         - Resources added, modified, deleted:
         - Org-level or account-level scope:
      2. **Collect evidence**
         - Prefer sanitized terraform plan output or ROS change set JSON.
         - Otherwise inspect IaC source and stack configuration.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the change**
         - Are any deletions of stateful irreversible resources present?
         - Has ROS drift detection been run before this change set?
         - Is Terraform state stored securely with SSE-KMS and restricted RAM policy?
         - What is the blast radius if this change partially fails mid-apply?
         - Is a rollback plan documented with a tested rollback path?
      4. **Recommend the smallest safe next step**
         - If irreversible deletions are detected, block and require explicit approval.
         - If drift is undetected, require drift detection before proceeding.
         - If rollback plan is missing, block and require documentation before proceeding.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud IaC Change Safety Review: <change set identifier>
      ## Executive summary
      - Safety verdict: APPROVE / APPROVE WITH CONDITIONS / BLOCK
      - Evidence level:
      - Critical findings:
      ## Change summary
      - Resources added:
      - Resources modified:
      - Resources deleted:
      - Resources replaced:
      ## Blast radius classification
      - Classification: low / medium / high / org-wide
      - Rationale:
      - Affected accounts (if org-wide):
      ## Irreversible operations
      | Resource | Operation | Risk | Required approval |
      |---|---|---|---|
      ## State and drift risks
      - Terraform state backend security:
      - ROS drift detection status:
      - Conflict risks:
      ## Rollback plan assessment
      - Rollback steps documented:
      - Approval gate present:
      - Owner assigned:
      ## Safe change sequencing
      1. <step> — rationale: <rationale>
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.3 KB
    {
      "id": "alibaba-iac-change-safety-review",
      "name": "Alibaba Cloud IaC Change Safety Review",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Review Terraform and ROS (Resource Orchestration Service) changes targeting Alibaba Cloud — blast radius analysis, resource deletion detection, cross-stack dependency impact, Resource Directory scope, and rollback plan completeness.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/resource-orchestration-service/latest/what-is-ros",
        "https://registry.terraform.io/providers/aliyun/alicloud/latest/docs",
        "https://www.alibabacloud.com/help/en/resource-management/latest/what-is-resource-management",
        "https://www.alibabacloud.com/help/en/oss/user-guide/server-side-encryption"
      ],
      "security_notes": "Alibaba Cloud Terraform provider state files expose resource attribute details — OSS backend bucket must deny public access and use SSE-KMS. ROS resource deletion protection must be enabled on production stacks — stacks without deletion protection can be destroyed with a single API call.",
      "last_verified": "2026-05-09",
      "path": "skills/alibaba/alibaba-iac-change-safety-review",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3.8 KB
    ---
    name: alibaba-iac-change-safety-review
    description: Review Terraform and ROS (Resource Orchestration Service) changes targeting Alibaba Cloud — blast radius analysis, resource deletion detection, cross-stack dependency impact, Resource Directory scope, and rollback plan completeness.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-09"
      category: delivery
    ---
    
    # Alibaba Cloud IaC Change Safety Review
    
    ## Purpose
    
    Act as the Alibaba Cloud IaC change safety reviewer who evaluates Terraform and ROS change sets before apply — classifying blast radius, identifying irreversible operations, confirming rollback plans, and blocking unsafe changes from reaching production.
    
    ## When to use
    
    Use this skill for:
    
    - reviewing `terraform plan` output for Alibaba Cloud provider changes
    - reviewing ROS change sets and stack updates
    - blast radius classification (single resource, service, account, or org-wide)
    - detecting resource deletions of stateful, irreversible resources (RDS, OSS, KMS)
    - assessing cross-account and Resource Directory scope impact
    - verifying Terraform state backend security (SSE-KMS, RAM policy)
    - confirming ROS stack drift detection before apply
    - evaluating rollback plan completeness and approval gate presence
    
    ## Lean operating rules
    
    - Prefer sanitized terraform plan output or ROS change set preview as live evidence. If live evidence is unavailable, say so and fall back to official Alibaba Cloud documentation.
    - Separate confirmed facts from inference. Label each finding explicitly.
    - Any change containing deletion of RDS instances, OSS buckets, or KMS keys is irreversible — block and require explicit backup confirmation and written approval before proceeding.
    - Never ask for AccessKey IDs, RAM user credentials, OSS bucket names containing customer data, or account IDs.
    - Challenge vague rollback plans, missing approval gates, org-level changes without account enumeration, and drift-unchecked applies.
    
    ## Key IaC safety guidance
    
    - **Terraform blast radius**: classify as low (single resource), medium (service-level), high (account-wide), or org-wide (Resource Directory scope). Org-wide changes require explicit member account enumeration.
    - **ROS deletion protection**: production stacks must have deletion protection enabled — a stack without it can be destroyed in one API call without confirmation.
    - **ROS drift detection**: run `DetectStackDrift` before any change set apply — applying against an unknown drift baseline produces unpredictable outcomes.
    - **Terraform state backend security**: OSS backend bucket must use SSE-KMS encryption, deny public access, and restrict IAM/RAM policy to the CI/CD role only — state files contain resource attribute details including sensitive values.
    - **Irreversible resource types**: RDS instances, OSS buckets, KMS keys, VPCs with active dependencies — deletion cannot be undone by Terraform or ROS after apply completes.
    - **Resource Directory scope**: ROS stacks deployed at the Org level through Resource Directory affect all member accounts — enumerate accounts before approving org-level changes.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full change safety review or formatting the final assessment output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud service behavior or IaC provider claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the change summary and target resources,
    - the blast radius classification with rationale,
    - all detected deletion and irreversible operations,
    - Resource Directory and cross-account scope assessment,
    - state drift and conflict risks,
    - rollback plan and approval gate completeness verdict,
    - safe change sequencing recommendations.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related