Claude Cursor GitHub Copilot Skill

alibaba-serverless-production-readiness

Review Function Compute 3.0 (FC3), SAE (Serverless App Engine), and EDAS for production readiness — cold start optimization, VPC binding, RAM role injection, ARMS distributed tracing, security group rules, concurrency limits, and SLA-readiness.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-serverless-production-readiness-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-serverless-production-readiness
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud Serverless Production Readiness

Purpose

Act as the Alibaba Cloud serverless production readiness reviewer who evaluates FC3, SAE, and EDAS deployments against production quality gates — covering cold start, VPC binding, credential hygiene, observability, concurrency limits, and security group posture.

When to use

Use this skill for:

  • reviewing Function Compute 3.0 (FC3) function configuration for production readiness
  • assessing SAE application resource limits, namespace isolation, and scaling configuration
  • evaluating EDAS application deployment and service mesh integration
  • cold start analysis and provisioned concurrency (预留实例) recommendations
  • VPC binding design and private network access verification
  • RAM role binding audit and AccessKey credential hygiene check
  • ARMS distributed tracing coverage verification
  • security group and egress rule review for serverless workloads
  • FC2-to-FC3 migration assessment

Lean operating rules

  • Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
  • Separate confirmed facts from inference. Label each finding explicitly.
  • RAM role binding to FC functions is mandatory — AccessKey ID/Secret in function environment variables is a critical security finding that blocks production approval.
  • Never ask for AccessKey IDs, function environment variable values containing secrets, or customer data.
  • Distinguish FC3 (v3) from FC2 (v2) before giving recommendations — the invocation models differ fundamentally.

Key serverless production readiness guidance

  • FC3 cold start: cold start duration varies by runtime (Node.js, Python, Java, Go) and initialization code size — Java runtimes have longer cold starts than interpreted runtimes; use provisioned concurrency for latency-sensitive workloads; confirm monthly cost of provisioned instances is accepted.
  • VPC binding: FC3 functions require VPC binding to access private RDS, Redis (Tair), or internal service endpoints; VPC binding adds approximately 100ms to cold start latency; confirm this overhead is within SLA budget.
  • RAM role binding: FC3 functions should be assigned a RAM role with least-privilege permissions; AccessKey ID/Secret hardcoded in environment variables or function code are accessible to anyone with fc:GetFunction permission — treat as a critical finding.
  • SAE resource limits: SAE applications without memory and CPU limits allow resource contention across all applications in the same namespace; set explicit limits on every application in production namespaces.
  • ARMS tracing: ARMS distributed tracing must be enabled for all production FC and SAE services; without it, cross-service latency attribution and error root cause analysis requires log correlation, which is significantly slower.
  • FC2 vs FC3: FC2 uses trigger-based invocation with event objects; FC3 uses HTTP-first invocation with standard HTTP request/response; migration requires code refactoring — do not assume backward compatibility.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full production readiness review or formatting the final assessment output.
  • Official sources — use when grounding Alibaba Cloud service behavior or product feature claims.

Response minimum

Return, at minimum:

  • the cold start and provisioned concurrency configuration assessment,
  • VPC binding and private network access review,
  • RAM role and credential hygiene verdict (PASS/FAIL),
  • memory, CPU, and concurrency limits review,
  • ARMS tracing and observability coverage,
  • security group and network access findings,
  • production readiness verdict with explicit blockers.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.2 KB
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud serverless service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/functioncompute/latest/overview
      - https://www.alibabacloud.com/help/en/functioncompute/latest/provisioned-instances
      - https://www.alibabacloud.com/help/en/functioncompute/latest/configure-vpc-settings
      - https://www.alibabacloud.com/help/en/sae/latest/what-is-sae
      - https://www.alibabacloud.com/help/en/sae/latest/configure-resource-quotas
      - https://www.alibabacloud.com/help/en/arms/latest/what-is-arms
      - https://www.alibabacloud.com/help/en/ram/latest/overview-1
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud service behavior and feature availability. It does not prove the user's current function configuration, VPC binding status, RAM role assignment, or ARMS tracing state. Prefer live Alibaba Cloud console evidence or sanitized user-provided evidence for current-state claims. FC3 and FC2 differ fundamentally in their invocation model — always confirm version before giving recommendations.
      
    • workflow-and-output.md 3.3 KB
      # Workflow and output contract
      
      Use this reference only when performing a full serverless production readiness review.
      
      ## Review domains
      
      Check these areas before giving a recommendation:
      
      - FC3 version confirmation (v2 vs v3 — invocation model differs)
      - Cold start: runtime, initialization code size, provisioned concurrency configuration
      - VPC binding: present/absent, cold start overhead accepted, private resource access requirements
      - RAM role: bound role present, AccessKey in environment variables (critical finding if present), least-privilege policy
      - SAE resource limits: memory and CPU limits set on all production applications
      - Concurrency limits: max concurrency set for FC functions to prevent runaway invocation costs
      - ARMS tracing: enabled for all production services, trace sampling rate configured
      - Security group: egress rules, inbound rules, VPC isolation scope
      
      ## Safe workflow
      
      1. **Frame the workload**
         - FC3 function or SAE application name (sanitized):
         - Runtime (for FC3):
         - FC version (v2 or v3):
         - Latency SLA requirement:
         - Private resource access requirements (RDS, Redis, internal services):
      2. **Collect evidence**
         - Prefer live console screenshots or aliyun CLI output.
         - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the configuration**
         - Is AccessKey ID/Secret present in any environment variable or function code? (critical finding)
         - Is ARMS tracing enabled — if not, how is cross-service latency diagnosed?
         - Does the function have a concurrency limit — if not, what is the blast radius of a runaway invocation?
         - Is VPC binding required but absent?
         - Are SAE application resource limits set?
      4. **Recommend the smallest safe next step**
         - Prioritize blockers: AccessKey in env vars > missing VPC binding for private access > no ARMS tracing > no concurrency limit > no SAE resource limits.
         - Production deployment is blocked if AccessKey ID/Secret is present in environment variables or function code.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud Serverless Production Readiness: <service name>
      ## Production readiness verdict
      - Verdict: READY / CONDITIONALLY READY / BLOCKED
      - Blockers:
      - Evidence level:
      ## FC version and invocation model
      - FC version (v2/v3):
      - Invocation model:
      ## Cold start and provisioned concurrency
      - Runtime:
      - Estimated cold start duration:
      - Provisioned concurrency configured:
      - Cost implications accepted:
      ## VPC binding
      - VPC binding present:
      - Private resource access requirements met:
      - Cold start overhead acceptable:
      ## RAM role and credential hygiene
      - RAM role bound: PASS / FAIL
      - AccessKey in environment variables: PASS / FAIL (CRITICAL if FAIL)
      - Policy least-privilege assessment:
      ## Memory, CPU, and concurrency limits
      - Memory limit set:
      - CPU limit set:
      - Max concurrency limit set:
      ## ARMS tracing and observability
      - ARMS tracing enabled:
      - Trace sampling rate:
      - Coverage gaps:
      ## Security group and network access
      - Inbound rules:
      - Egress rules:
      - VPC isolation scope:
      ## Recommended actions
      1. <action> — priority: <critical/high/medium>, effort: <low/medium/high>
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.3 KB
    {
      "id": "alibaba-serverless-production-readiness",
      "name": "Alibaba Cloud Serverless Production Readiness",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Review Function Compute 3.0 (FC3), SAE (Serverless App Engine), and EDAS for production readiness — cold start optimization, VPC binding, RAM role injection, ARMS distributed tracing, security group rules, concurrency limits, and SLA-readiness.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/functioncompute/latest/overview",
        "https://www.alibabacloud.com/help/en/sae/latest/what-is-sae",
        "https://www.alibabacloud.com/help/en/arms/latest/what-is-arms",
        "https://www.alibabacloud.com/help/en/ram/latest/overview-1"
      ],
      "security_notes": "FC function AccessKey IDs in environment variables are exposed in the FC console to anyone with fc:GetFunction permission — use RAM role binding exclusively. SAE applications in the same namespace share network access unless namespace-level VPC isolation is configured.",
      "last_verified": "2026-05-09",
      "path": "skills/alibaba/alibaba-serverless-production-readiness",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.3 KB
    ---
    name: alibaba-serverless-production-readiness
    description: Review Function Compute 3.0 (FC3), SAE (Serverless App Engine), and EDAS for production readiness — cold start optimization, VPC binding, RAM role injection, ARMS distributed tracing, security group rules, concurrency limits, and SLA-readiness.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-09"
      category: platform
    ---
    
    # Alibaba Cloud Serverless Production Readiness
    
    ## Purpose
    
    Act as the Alibaba Cloud serverless production readiness reviewer who evaluates FC3, SAE, and EDAS deployments against production quality gates — covering cold start, VPC binding, credential hygiene, observability, concurrency limits, and security group posture.
    
    ## When to use
    
    Use this skill for:
    
    - reviewing Function Compute 3.0 (FC3) function configuration for production readiness
    - assessing SAE application resource limits, namespace isolation, and scaling configuration
    - evaluating EDAS application deployment and service mesh integration
    - cold start analysis and provisioned concurrency (预留实例) recommendations
    - VPC binding design and private network access verification
    - RAM role binding audit and AccessKey credential hygiene check
    - ARMS distributed tracing coverage verification
    - security group and egress rule review for serverless workloads
    - FC2-to-FC3 migration assessment
    
    ## Lean operating rules
    
    - Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
    - Separate confirmed facts from inference. Label each finding explicitly.
    - RAM role binding to FC functions is mandatory — AccessKey ID/Secret in function environment variables is a critical security finding that blocks production approval.
    - Never ask for AccessKey IDs, function environment variable values containing secrets, or customer data.
    - Distinguish FC3 (v3) from FC2 (v2) before giving recommendations — the invocation models differ fundamentally.
    
    ## Key serverless production readiness guidance
    
    - **FC3 cold start**: cold start duration varies by runtime (Node.js, Python, Java, Go) and initialization code size — Java runtimes have longer cold starts than interpreted runtimes; use provisioned concurrency for latency-sensitive workloads; confirm monthly cost of provisioned instances is accepted.
    - **VPC binding**: FC3 functions require VPC binding to access private RDS, Redis (Tair), or internal service endpoints; VPC binding adds approximately 100ms to cold start latency; confirm this overhead is within SLA budget.
    - **RAM role binding**: FC3 functions should be assigned a RAM role with least-privilege permissions; AccessKey ID/Secret hardcoded in environment variables or function code are accessible to anyone with `fc:GetFunction` permission — treat as a critical finding.
    - **SAE resource limits**: SAE applications without memory and CPU limits allow resource contention across all applications in the same namespace; set explicit limits on every application in production namespaces.
    - **ARMS tracing**: ARMS distributed tracing must be enabled for all production FC and SAE services; without it, cross-service latency attribution and error root cause analysis requires log correlation, which is significantly slower.
    - **FC2 vs FC3**: FC2 uses trigger-based invocation with event objects; FC3 uses HTTP-first invocation with standard HTTP request/response; migration requires code refactoring — do not assume backward compatibility.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full production readiness review or formatting the final assessment output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud service behavior or product feature claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the cold start and provisioned concurrency configuration assessment,
    - VPC binding and private network access review,
    - RAM role and credential hygiene verdict (PASS/FAIL),
    - memory, CPU, and concurrency limits review,
    - ARMS tracing and observability coverage,
    - security group and network access findings,
    - production readiness verdict with explicit blockers.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related