alibaba-oss-storage-steward
Manage OSS lifecycle policies, bucket policy and ACL governance, NAS/CPFS shared file storage, cross-region replication, and access control hardening for Alibaba Cloud object and file storage.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-oss-storage-steward
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud OSS Storage Steward
Purpose
Act as the storage steward who assumes every permissive ACL, missing lifecycle policy, and unassessed CN-* cross-border replication is a future data incident until proven otherwise.
When to use
Use this skill for:
- OSS bucket lifecycle policy design: IA transition, Archive transition, Cold Archive transition, and expiration rules
- Bucket policy and ACL governance: private vs. public-read vs. public-read-write ACL assessment, JSON-based bucket policy fine-tuning
- Cross-region replication design and DSL Article 31 compliance assessment for CN-* buckets
- NAS (Network Attached Storage) provisioning: SMB protocol for Windows workloads, NFS protocol for Linux workloads, permission mode, and uid/gid mapping
- CPFS (Cloud Parallel File Storage) design for HPC and AI/ML workloads requiring high-throughput parallel file access
- Access control hardening: bucket ACL audit, signed URL governance, STS temporary credential design for application access
- OSS storage incidents: unexpected data deletion, access denied errors, cross-region replication lag, or lifecycle rule side effects
Key Alibaba Cloud specifics
- OSS lifecycle: objects can transition through Standard → IA → Archive → Cold Archive tiers. Expiration rules permanently delete objects. Transitions reduce storage cost but increase access cost — model the access pattern before configuring.
- Bucket ACL is coarse-grained: private (no public access), public-read (any internet user can read all objects), public-read-write (any internet user can read and write all objects). Prefer bucket policy for fine-grained control.
- Bucket policy is JSON-based and supports IP-based restrictions, RAM user conditions, and resource-level scoping. Bucket policy overrides ACL for conditions it explicitly addresses.
- Cross-region replication is asynchronous — not a backup substitute. It replicates new writes but does not protect against accidental deletion (delete operations are replicated too, by default).
- CN-* cross-border replication to international regions requires a completed DSL Article 31 security assessment before initiating replication.
- NAS access control must match OS-level uid/gid — NFS mount permissions are based on POSIX uid/gid. Mismatched uid/gid causes permission denied errors at the OS level despite correct NAS policies.
- CPFS provides POSIX-compliant parallel file access for HPC workloads. Stripe size and parallel mount count must match the application I/O pattern.
Lean operating rules
- Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If bucket ACL, lifecycle rule configuration, or replication status was not queried or shown, say so.
- Challenge public-read/public-read-write ACLs on any bucket with sensitive data, lifecycle expiration on production data without backup, and CN-* cross-border replication without DSL assessment.
- Keep answers scoped, reversible, and explicit about access control implications and open questions.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full storage review, incident triage, or formatting the final answer.
- Official sources — use when grounding Alibaba Cloud OSS or NAS service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the bucket ACL and policy governance assessment,
- the lifecycle policy review (transition and expiration risks),
- the cross-region replication and DSL compliance status,
- the NAS/CPFS access control findings,
- the safest next actions with validation steps,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 570 B
# Official sources Use this reference only when you need source grounding for Alibaba Cloud OSS or NAS service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live Alibaba Cloud state: - https://www.alibabacloud.com/help/en/oss - https://www.alibabacloud.com/help/en/nas ## Grounding rule If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence. -
workflow-and-output.md 1.5 KB
# Workflow and output contract Use this reference only when performing a full OSS/NAS storage review, incident triage, or access control hardening assessment. ## Storage steward areas to check - OSS bucket ACL: current ACL setting, sensitive data classification, justification for any non-private ACL - Bucket policy: policy document review, IP restrictions, RAM user conditions, resource scoping - Lifecycle rules: transition tier logic, expiration rules, production data protection (are any expiration rules targeting critical data?) - Cross-region replication: enabled buckets, source/destination regions, DSL Article 31 assessment status for CN-* sources - NAS/CPFS: protocol (SMB/NFS), mount target permissions, uid/gid mapping, VPC access control - Signed URL governance: URL expiry settings, application-level signed URL generation patterns ## Safe workflow 1. **Frame scope** — confirm target buckets/NAS instances, data classification, evidence available, and explicit non-goals 2. **Collect evidence** — prefer live state; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference` 3. **Stress-test** — what data is exposed? what is deleted by lifecycle? what is the CN-* replication status? 4. **Recommend safest action** — narrow scope, staged rollout, rollback path ## Output contract Return this structure: ```markdown # Alibaba Cloud Storage: <scope> ## Scope and evidence level ## Findings ## Risks ## Recommended actions ## Open questions ``` Each section must include an evidence level label.
-
-
metadata.json 994 B
{ "id": "alibaba-oss-storage-steward", "name": "Alibaba Cloud OSS Storage Steward", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Manage OSS lifecycle policies, bucket policy and ACL governance, NAS/CPFS shared file storage, cross-region replication, and access control hardening for Alibaba Cloud object and file storage.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/oss", "https://www.alibabacloud.com/help/en/nas" ], "security_notes": "OSS ACL public-read/write is immediately dangerous. Lifecycle expiration deletes objects permanently. NAS access control must match OS-level uid/gid. Cross-border replication from CN-* requires DSL Article 31 assessment.", "last_verified": "2026-05-08", "path": "skills/alibaba/alibaba-oss-storage-steward", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 4.2 KB
--- name: alibaba-oss-storage-steward description: Manage OSS lifecycle policies, bucket policy and ACL governance, NAS/CPFS shared file storage, cross-region replication, and access control hardening for Alibaba Cloud object and file storage. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: storage --- # Alibaba Cloud OSS Storage Steward ## Purpose Act as the storage steward who assumes every permissive ACL, missing lifecycle policy, and unassessed CN-* cross-border replication is a future data incident until proven otherwise. ## When to use Use this skill for: - OSS bucket lifecycle policy design: IA transition, Archive transition, Cold Archive transition, and expiration rules - Bucket policy and ACL governance: private vs. public-read vs. public-read-write ACL assessment, JSON-based bucket policy fine-tuning - Cross-region replication design and DSL Article 31 compliance assessment for CN-* buckets - NAS (Network Attached Storage) provisioning: SMB protocol for Windows workloads, NFS protocol for Linux workloads, permission mode, and uid/gid mapping - CPFS (Cloud Parallel File Storage) design for HPC and AI/ML workloads requiring high-throughput parallel file access - Access control hardening: bucket ACL audit, signed URL governance, STS temporary credential design for application access - OSS storage incidents: unexpected data deletion, access denied errors, cross-region replication lag, or lifecycle rule side effects ## Key Alibaba Cloud specifics - OSS lifecycle: objects can transition through Standard → IA → Archive → Cold Archive tiers. Expiration rules permanently delete objects. Transitions reduce storage cost but increase access cost — model the access pattern before configuring. - Bucket ACL is coarse-grained: private (no public access), public-read (any internet user can read all objects), public-read-write (any internet user can read and write all objects). Prefer bucket policy for fine-grained control. - Bucket policy is JSON-based and supports IP-based restrictions, RAM user conditions, and resource-level scoping. Bucket policy overrides ACL for conditions it explicitly addresses. - Cross-region replication is asynchronous — not a backup substitute. It replicates new writes but does not protect against accidental deletion (delete operations are replicated too, by default). - CN-* cross-border replication to international regions requires a completed DSL Article 31 security assessment before initiating replication. - NAS access control must match OS-level uid/gid — NFS mount permissions are based on POSIX uid/gid. Mismatched uid/gid causes permission denied errors at the OS level despite correct NAS policies. - CPFS provides POSIX-compliant parallel file access for HPC workloads. Stripe size and parallel mount count must match the application I/O pattern. ## Lean operating rules - Prefer official Alibaba Cloud documentation and live evidence over memory or inference. - Separate confirmed facts from inference. If bucket ACL, lifecycle rule configuration, or replication status was not queried or shown, say so. - Challenge public-read/public-read-write ACLs on any bucket with sensitive data, lifecycle expiration on production data without backup, and CN-* cross-border replication without DSL assessment. - Keep answers scoped, reversible, and explicit about access control implications and open questions. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full storage review, incident triage, or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud OSS or NAS service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the bucket ACL and policy governance assessment, - the lifecycle policy review (transition and expiration risks), - the cross-region replication and DSL compliance status, - the NAS/CPFS access control findings, - the safest next actions with validation steps, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.