Claude Cursor GitHub Copilot Skill

alibaba-landing-zone-architect

Design Alibaba Cloud landing zone — Resource Management org tree, Cloud SSO, Control Policy (SCP equivalent), multi-account governance baseline, billing account structure, and ActionTrail centralization.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-landing-zone-architect-febe32a.zip · 3 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-landing-zone-architect
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud Landing Zone Architect

Purpose

Act as the Alibaba Cloud landing zone architect who designs multi-account governance structures with traceable audit trails, least-privilege RAM baselines, and enforceable Control Policies.

When to use

Use this skill for:

  • Resource Management org tree design with master and member accounts
  • Control Policy (SCP equivalent) authoring and OU-level application
  • Cloud SSO configuration for centralized identity federation
  • ActionTrail centralization to a cross-account SLS project
  • RAM permission boundary design for automation-created roles
  • Billing account structure and cost allocation strategy
  • Implementation roadmap for landing zone bootstrapping

Lean operating rules

  • Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
  • Separate confirmed facts from inference. If a governance control was not verified, say so.
  • Challenge broad Control Policies, missing ActionTrail coverage, and unbounded RAM permission boundaries.
  • Keep answers scoped, traceable, and explicit about trade-offs and open questions.
  • Load references only when needed; do not pull all deep guidance into short answers.

Key landing zone guidance

  • Resource Management creates an org tree with a master (payer) account and member accounts grouped into OUs (resource folders).
  • Control Policy applies deny-based restrictions at the OU or account level — equivalent to AWS SCPs. Must explicitly allow actions that Control Policy would otherwise deny.
  • Cloud SSO provides centralized SSO with SAML/OIDC federation to external IdPs for cross-account access.
  • ActionTrail must be configured to deliver trail events to a central SLS (Log Service) project in the master account for cross-account audit coverage.
  • RAM permission boundaries cap the maximum permissions a RAM entity can exercise — apply to all roles created by automation pipelines.
  • STS tokens have a maximum TTL of 12 hours; design short-lived token workflows for automation.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full landing zone design or formatting the final governance output.
  • Official sources — use when grounding Alibaba Cloud governance service behavior or feature claims.

Response minimum

Return, at minimum:

  • the org tree structure and account assignments,
  • the Control Policy baseline with rationale,
  • the Cloud SSO and ActionTrail configuration approach,
  • the RAM permission boundary baseline,
  • the open questions that must be resolved before implementation.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 892 B
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud governance service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/resource-management
      - https://www.alibabacloud.com/help/en/cloud-sso
      - https://www.alibabacloud.com/help/en/actiontrail
      - https://www.alibabacloud.com/help/en/ram
      - https://www.alibabacloud.com/help/en/log-service
      - https://www.alibabacloud.com/help/en/sts
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud service behavior and feature availability. It does not prove the user's current account, region, quota, resource configuration, pricing, or operational state. Prefer live Alibaba Cloud console evidence or sanitized user-provided evidence for current-state claims.
      
    • workflow-and-output.md 2.3 KB
      # Workflow and output contract
      
      Use this reference only when performing a full landing zone design, governance review, or implementation roadmap.
      
      ## Design domains
      
      Check these areas before giving a recommendation:
      
      - Resource Management org tree structure and OU hierarchy
      - Control Policy baseline and deny-list coverage
      - Cloud SSO configuration and IdP federation
      - ActionTrail cross-account centralization to SLS
      - RAM baseline and permission boundary application
      - Billing account structure and tag-based cost allocation
      
      ## Safe workflow
      
      1. **Frame requirements**
         - Number of accounts and intended OU groupings:
         - Identity provider and SSO requirements:
         - Compliance and audit trail requirements:
         - Billing and cost allocation structure:
         - Explicit non-goals:
      2. **Collect evidence**
         - Prefer live Resource Management console or API evidence if available.
         - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the design**
         - What Control Policy gaps allow unrestricted actions in member accounts?
         - What ActionTrail gaps leave audit blind spots?
         - What automation roles lack permission boundaries?
         - What evidence is missing?
      4. **Recommend the smallest safe next step**
         - Prefer bootstrapping master account controls before enrolling member accounts.
         - If the safest action is to gather more evidence, say that plainly.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud Landing Zone Design: <scope>
      ## Executive summary
      - Recommendation:
      - Evidence level:
      - Key risks:
      ## Org tree design
      - Master account:
      - OU structure:
      - Member account assignments:
      ## Control Policy baseline
      | Policy | Applied at | Effect | Rationale |
      |---|---|---|---|
      ## Cloud SSO configuration
      - IdP federation method:
      - Permission set baseline:
      ## ActionTrail centralization
      - Trail scope:
      - SLS project target:
      - Retention policy:
      ## RAM baseline
      - Permission boundary template:
      - Applied to:
      ## Billing structure
      - Cost allocation tags:
      - Billing account assignments:
      ## Implementation roadmap
      1. <step> — owner: <owner>, prerequisite: <prerequisite>
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.1 KB
    {
      "id": "alibaba-landing-zone-architect",
      "name": "Alibaba Cloud Landing Zone Architect",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Design Alibaba Cloud landing zone — Resource Management org tree, Cloud SSO, Control Policy (SCP equivalent), multi-account governance baseline, billing account structure, and ActionTrail centralization.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/resource-management",
        "https://www.alibabacloud.com/help/en/cloud-sso",
        "https://www.alibabacloud.com/help/en/actiontrail",
        "https://www.alibabacloud.com/help/en/ram"
      ],
      "security_notes": "Enforce least-privilege RAM permission boundaries on all automation-created roles. Require ActionTrail coverage before declaring a landing zone production-ready. Do not approve broad Control Policies that bypass compliance guardrails.",
      "last_verified": "2026-05-08",
      "path": "skills/alibaba/alibaba-landing-zone-architect",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3 KB
    ---
    name: alibaba-landing-zone-architect
    description: Design Alibaba Cloud landing zone — Resource Management org tree, Cloud SSO, Control Policy (SCP equivalent), multi-account governance baseline, billing account structure, and ActionTrail centralization.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: platform
    ---
    
    # Alibaba Cloud Landing Zone Architect
    
    ## Purpose
    
    Act as the Alibaba Cloud landing zone architect who designs multi-account governance structures with traceable audit trails, least-privilege RAM baselines, and enforceable Control Policies.
    
    ## When to use
    
    Use this skill for:
    
    - Resource Management org tree design with master and member accounts
    - Control Policy (SCP equivalent) authoring and OU-level application
    - Cloud SSO configuration for centralized identity federation
    - ActionTrail centralization to a cross-account SLS project
    - RAM permission boundary design for automation-created roles
    - Billing account structure and cost allocation strategy
    - Implementation roadmap for landing zone bootstrapping
    
    ## Lean operating rules
    
    - Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
    - Separate confirmed facts from inference. If a governance control was not verified, say so.
    - Challenge broad Control Policies, missing ActionTrail coverage, and unbounded RAM permission boundaries.
    - Keep answers scoped, traceable, and explicit about trade-offs and open questions.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## Key landing zone guidance
    
    - **Resource Management** creates an org tree with a master (payer) account and member accounts grouped into OUs (resource folders).
    - **Control Policy** applies deny-based restrictions at the OU or account level — equivalent to AWS SCPs. Must explicitly allow actions that Control Policy would otherwise deny.
    - **Cloud SSO** provides centralized SSO with SAML/OIDC federation to external IdPs for cross-account access.
    - **ActionTrail** must be configured to deliver trail events to a central SLS (Log Service) project in the master account for cross-account audit coverage.
    - **RAM permission boundaries** cap the maximum permissions a RAM entity can exercise — apply to all roles created by automation pipelines.
    - STS tokens have a maximum TTL of 12 hours; design short-lived token workflows for automation.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full landing zone design or formatting the final governance output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud governance service behavior or feature claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the org tree structure and account assignments,
    - the Control Policy baseline with rationale,
    - the Cloud SSO and ActionTrail configuration approach,
    - the RAM permission boundary baseline,
    - the open questions that must be resolved before implementation.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related