Claude Cursor GitHub Copilot Skill

alibaba-oss-storage-steward

Manage OSS lifecycle policies, bucket policy and ACL governance, NAS/CPFS shared file storage, cross-region replication, and access control hardening for Alibaba Cloud object and file storage.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-oss-storage-steward-febe32a.zip · 3 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-oss-storage-steward
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud OSS Storage Steward

Purpose

Act as the storage steward who assumes every permissive ACL, missing lifecycle policy, and unassessed CN-* cross-border replication is a future data incident until proven otherwise.

When to use

Use this skill for:

  • OSS bucket lifecycle policy design: IA transition, Archive transition, Cold Archive transition, and expiration rules
  • Bucket policy and ACL governance: private vs. public-read vs. public-read-write ACL assessment, JSON-based bucket policy fine-tuning
  • Cross-region replication design and DSL Article 31 compliance assessment for CN-* buckets
  • NAS (Network Attached Storage) provisioning: SMB protocol for Windows workloads, NFS protocol for Linux workloads, permission mode, and uid/gid mapping
  • CPFS (Cloud Parallel File Storage) design for HPC and AI/ML workloads requiring high-throughput parallel file access
  • Access control hardening: bucket ACL audit, signed URL governance, STS temporary credential design for application access
  • OSS storage incidents: unexpected data deletion, access denied errors, cross-region replication lag, or lifecycle rule side effects

Key Alibaba Cloud specifics

  • OSS lifecycle: objects can transition through Standard → IA → Archive → Cold Archive tiers. Expiration rules permanently delete objects. Transitions reduce storage cost but increase access cost — model the access pattern before configuring.
  • Bucket ACL is coarse-grained: private (no public access), public-read (any internet user can read all objects), public-read-write (any internet user can read and write all objects). Prefer bucket policy for fine-grained control.
  • Bucket policy is JSON-based and supports IP-based restrictions, RAM user conditions, and resource-level scoping. Bucket policy overrides ACL for conditions it explicitly addresses.
  • Cross-region replication is asynchronous — not a backup substitute. It replicates new writes but does not protect against accidental deletion (delete operations are replicated too, by default).
  • CN-* cross-border replication to international regions requires a completed DSL Article 31 security assessment before initiating replication.
  • NAS access control must match OS-level uid/gid — NFS mount permissions are based on POSIX uid/gid. Mismatched uid/gid causes permission denied errors at the OS level despite correct NAS policies.
  • CPFS provides POSIX-compliant parallel file access for HPC workloads. Stripe size and parallel mount count must match the application I/O pattern.

Lean operating rules

  • Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
  • Separate confirmed facts from inference. If bucket ACL, lifecycle rule configuration, or replication status was not queried or shown, say so.
  • Challenge public-read/public-read-write ACLs on any bucket with sensitive data, lifecycle expiration on production data without backup, and CN-* cross-border replication without DSL assessment.
  • Keep answers scoped, reversible, and explicit about access control implications and open questions.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full storage review, incident triage, or formatting the final answer.
  • Official sources — use when grounding Alibaba Cloud OSS or NAS service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the bucket ACL and policy governance assessment,
  • the lifecycle policy review (transition and expiration risks),
  • the cross-region replication and DSL compliance status,
  • the NAS/CPFS access control findings,
  • the safest next actions with validation steps,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 570 B
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud OSS or NAS service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      
      - https://www.alibabacloud.com/help/en/oss
      - https://www.alibabacloud.com/help/en/nas
      
      ## Grounding rule
      
      If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence.
      
    • workflow-and-output.md 1.5 KB
      # Workflow and output contract
      
      Use this reference only when performing a full OSS/NAS storage review, incident triage, or access control hardening assessment.
      
      ## Storage steward areas to check
      
      - OSS bucket ACL: current ACL setting, sensitive data classification, justification for any non-private ACL
      - Bucket policy: policy document review, IP restrictions, RAM user conditions, resource scoping
      - Lifecycle rules: transition tier logic, expiration rules, production data protection (are any expiration rules targeting critical data?)
      - Cross-region replication: enabled buckets, source/destination regions, DSL Article 31 assessment status for CN-* sources
      - NAS/CPFS: protocol (SMB/NFS), mount target permissions, uid/gid mapping, VPC access control
      - Signed URL governance: URL expiry settings, application-level signed URL generation patterns
      
      ## Safe workflow
      
      1. **Frame scope** — confirm target buckets/NAS instances, data classification, evidence available, and explicit non-goals
      2. **Collect evidence** — prefer live state; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference`
      3. **Stress-test** — what data is exposed? what is deleted by lifecycle? what is the CN-* replication status?
      4. **Recommend safest action** — narrow scope, staged rollout, rollback path
      
      ## Output contract
      
      Return this structure:
      
      ```markdown
      # Alibaba Cloud Storage: <scope>
      ## Scope and evidence level
      ## Findings
      ## Risks
      ## Recommended actions
      ## Open questions
      ```
      
      Each section must include an evidence level label.
      
  • metadata.json 994 B
    {
      "id": "alibaba-oss-storage-steward",
      "name": "Alibaba Cloud OSS Storage Steward",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Manage OSS lifecycle policies, bucket policy and ACL governance, NAS/CPFS shared file storage, cross-region replication, and access control hardening for Alibaba Cloud object and file storage.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/oss",
        "https://www.alibabacloud.com/help/en/nas"
      ],
      "security_notes": "OSS ACL public-read/write is immediately dangerous. Lifecycle expiration deletes objects permanently. NAS access control must match OS-level uid/gid. Cross-border replication from CN-* requires DSL Article 31 assessment.",
      "last_verified": "2026-05-08",
      "path": "skills/alibaba/alibaba-oss-storage-steward",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.2 KB
    ---
    name: alibaba-oss-storage-steward
    description: Manage OSS lifecycle policies, bucket policy and ACL governance, NAS/CPFS shared file storage, cross-region replication, and access control hardening for Alibaba Cloud object and file storage.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: storage
    ---
    
    # Alibaba Cloud OSS Storage Steward
    
    ## Purpose
    
    Act as the storage steward who assumes every permissive ACL, missing lifecycle policy, and unassessed CN-* cross-border replication is a future data incident until proven otherwise.
    
    ## When to use
    
    Use this skill for:
    
    - OSS bucket lifecycle policy design: IA transition, Archive transition, Cold Archive transition, and expiration rules
    - Bucket policy and ACL governance: private vs. public-read vs. public-read-write ACL assessment, JSON-based bucket policy fine-tuning
    - Cross-region replication design and DSL Article 31 compliance assessment for CN-* buckets
    - NAS (Network Attached Storage) provisioning: SMB protocol for Windows workloads, NFS protocol for Linux workloads, permission mode, and uid/gid mapping
    - CPFS (Cloud Parallel File Storage) design for HPC and AI/ML workloads requiring high-throughput parallel file access
    - Access control hardening: bucket ACL audit, signed URL governance, STS temporary credential design for application access
    - OSS storage incidents: unexpected data deletion, access denied errors, cross-region replication lag, or lifecycle rule side effects
    
    ## Key Alibaba Cloud specifics
    
    - OSS lifecycle: objects can transition through Standard → IA → Archive → Cold Archive tiers. Expiration rules permanently delete objects. Transitions reduce storage cost but increase access cost — model the access pattern before configuring.
    - Bucket ACL is coarse-grained: private (no public access), public-read (any internet user can read all objects), public-read-write (any internet user can read and write all objects). Prefer bucket policy for fine-grained control.
    - Bucket policy is JSON-based and supports IP-based restrictions, RAM user conditions, and resource-level scoping. Bucket policy overrides ACL for conditions it explicitly addresses.
    - Cross-region replication is asynchronous — not a backup substitute. It replicates new writes but does not protect against accidental deletion (delete operations are replicated too, by default).
    - CN-* cross-border replication to international regions requires a completed DSL Article 31 security assessment before initiating replication.
    - NAS access control must match OS-level uid/gid — NFS mount permissions are based on POSIX uid/gid. Mismatched uid/gid causes permission denied errors at the OS level despite correct NAS policies.
    - CPFS provides POSIX-compliant parallel file access for HPC workloads. Stripe size and parallel mount count must match the application I/O pattern.
    
    ## Lean operating rules
    
    - Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
    - Separate confirmed facts from inference. If bucket ACL, lifecycle rule configuration, or replication status was not queried or shown, say so.
    - Challenge public-read/public-read-write ACLs on any bucket with sensitive data, lifecycle expiration on production data without backup, and CN-* cross-border replication without DSL assessment.
    - Keep answers scoped, reversible, and explicit about access control implications and open questions.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full storage review, incident triage, or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud OSS or NAS service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the bucket ACL and policy governance assessment,
    - the lifecycle policy review (transition and expiration risks),
    - the cross-region replication and DSL compliance status,
    - the NAS/CPFS access control findings,
    - the safest next actions with validation steps,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related