本文へ移動
cccskills
無料GitHub で公開

volcengine-cloud-trail

Use when the user asks to query Volcengine CloudTrail audit logs, investigate login or resource operations, or manage CloudTrail trails and backfill delivery tasks. Trigger on 操作审计, 审计日志, CloudTrail, cloud_trail, trail, 跟踪, 历史补投, or backfill in a Volcengine context. Audit queries are read-only; trail and backfill mutations require an explicit preview and confirmation.

インストール方法を見る

含まれるファイル(5)

  • SKILL.md10.2 KB
  • references/backfill-delivery-tasks.md4.0 KB
  • references/event-query.md6.0 KB
  • references/event-trail-management.md6.0 KB
  • scripts/cloud_trail.py104.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

火山引擎操作审计

通过 ve cloudtrail(Version=2021-09-01)查询审计事件,并安全管理 Trail 与历史补投任务。

速查

项目说明
适用场景操作审计日志查询、登录/资源操作溯源、Trail 管理、历史补投任务管理
核心能力审计事件查询(只读)、事件名解析(只读)、Trail 列表/创建/更新/启停/删除、补投列表/详情/创建/停止
底层调用scripts/cloud_trail.py 封装 ve cloudtrail <Action>,版本固定 2021-09-01
写操作Trail 创建/更新/启停/删除、补投创建/停止,均先预览,用户确认后执行
主要参考event-query.md、event-trail-management.md、backfill-delivery-tasks.md

能力

能力做什么子命令必读参考
审计事件查询查询登录、资源操作、失败事件,输出摘要或带注释完整日志events lookupevent-query.md
事件名解析根据服务、关键词、资源和读写属性判断 EventSource / EventName 候选events resolveevent-query.md
Trail 管理列出、创建、更新、启停、删除操作审计 Trailtrails ...event-trail-management.md
历史补投列出、查看、创建、停止历史补投任务backfill ...backfill-delivery-tasks.md

什么时候用

  • 用户要查操作审计、审计日志、CloudTrail、登录记录、资源变更记录、失败事件或 RequestID / EventID 对应事件。
  • 用户要确认某个火山资源是谁创建、删除、修改,或需要按资源 ID、用户、事件名、错误码定位审计证据。
  • 用户要创建、更新、开启、停止或删除操作审计 Trail。
  • 用户要查看、创建或停止历史补投任务,或判断补投任务与 Trail 删除之间的依赖。
  • 用户消息里出现「火山 / 火山引擎 / volcengine」且属于操作审计、跟踪、Trail、历史补投、CloudTrail 场景。

前置条件

  • ve CLI 与 python3 可用,并已通过 ve configure 或环境变量完成鉴权。
  • 鉴权、profile、CLI 安装或会话失败时,使用 volcengine-cli skill 处理登录/配置;本 skill 只处理 CloudTrail 业务动作。
  • 固定 profile 后,身份确认和后续 CloudTrail 调用使用同一 profile。每个会话首次签名调用、重新鉴权或 profile 改变后,先只读确认调用账号。
  • 只有用户明确指定时才传 --profile 或 --region。结论里说明账号、profile/default 解析、地域和时间范围。
  • 补投创建能力需要运营开白。账号内已有任一补投任务记录时,可视为当前账号已完成补投能力开白。

agent 内部调用

从本 skill 目录执行:

python3 scripts/cloud_trail.py --help
python3 scripts/cloud_trail.py events lookup --signin-action login --lookback-days 3
python3 scripts/cloud_trail.py events resolve --service vpc --keyword Delete --resource-id vpc-<id> --operation write
python3 scripts/cloud_trail.py trails list
python3 scripts/cloud_trail.py backfill list

默认输出格式就是 JSON,读操作通常直接省略 --format json。需要 md 或 table 时,--format 是全局参数, 放在 events / trails / backfill 之前,例如:

python3 scripts/cloud_trail.py --format table trails list
python3 scripts/cloud_trail.py --format md backfill list --page-number 1 --page-size 100

工作流

所有动作通过 scripts/cloud_trail.py 完成(命令相对本 skill 目录执行)。

审计事件查询(只读)

python3 scripts/cloud_trail.py events lookup --signin-action login --lookback-days 3
python3 scripts/cloud_trail.py events lookup --resource-id vpc-<id> --operation write --lookback-days 7
python3 scripts/cloud_trail.py events lookup --raw --request-id <request-id>
  • 相对时间优先用 --lookback-days <1..90>;绝对时间支持 Unix 秒、RFC3339、YYYY-MM-DD 和本地时间。
  • 贴近 90 天边界时使用秒级安全余量,当前实现预留 60 秒。
  • 单次查询最多 50 条;下一页只在用户明确要求时,携带原查询指纹取一页。
  • EventSource / EventName 不确定时先运行 events resolve。ambiguous 时结合用户原话、动作语义、资源类型 和读写属性判断;语义仍不唯一或结果为 unresolved 时,已安装的 volcengine-api 与 volcengine-knowledge-search 可作为补证。已有 ResourceID 时可去掉存疑条件宽查一次;仍无法判断时请用户补充上下文。

Trail 管理(写操作需确认)

python3 scripts/cloud_trail.py trails list
python3 scripts/cloud_trail.py trails create --trail-name <trail-name> --event-rw All --tos-bucket-region <region> --tos-bucket-name <bucket>
python3 scripts/cloud_trail.py trails update --trail-name <trail-name> --event-rw Write
python3 scripts/cloud_trail.py trails start --trail-name <trail-name>
python3 scripts/cloud_trail.py trails stop --trail-name <trail-name>
python3 scripts/cloud_trail.py trails delete --trail-name <trail-name>
  • 创建 Trail 必须显式传 EventRW=All|Read|Write,并至少配置一个完整 TOS 或 TLS 投递目标。
  • 创建确认后默认执行 CreateTrail -> DescribeTrails 校验 -> StartLogging -> DescribeTrails 校验,不再二次确认开启。
  • 创建跨账号 Trail 时,agent 默认先完成目标账号 IAM 角色和 TOS/TLS 投递资源配置,再创建 Trail;缺少目标账号身份 或权限时请用户补齐。
  • 删除 Trail 前严格分页检查补投任务;全部任务均非 PENDING / RUNNING 后再删除。

历史补投(写操作需确认)

python3 scripts/cloud_trail.py backfill list --page-number 1 --page-size 10
python3 scripts/cloud_trail.py backfill describe --task-id bdt-<id>
python3 scripts/cloud_trail.py backfill create --trail-name <trail-name> --start-time <recent-rfc3339-start> --end-time <recent-rfc3339-end> --enable-tos
python3 scripts/cloud_trail.py backfill stop --task-id bdt-<id>
  • 创建或停止补投前先只读查询补投任务。账号内已有任一补投任务记录时,可直接作为已开白依据。
  • 未发现历史补投任务记录时,预案请用户确认补投功能已开白;用户确认后,agent 加开白确认与写入确认标记执行。
  • 创建前严格分页检查账号内全部任务;存在任一 PENDING / RUNNING 活跃任务时停止创建。
  • 补投窗口满足 EndTime < now、EndTime > StartTime、StartTime 在近 90 天内,单任务跨度不超过 90 天。

agent 执行流程

  1. 判断诉求:事件查询、事件名解析、Trail 管理,还是历史补投。
  2. 读取对应参考文档,按参考文档选择参数和校验条件。
  3. 首次签名调用先只读确认账号、profile/default、地域;身份符合预期后继续。
  4. 查询类请求直接执行并汇报证据。涉及完整日志时使用 events lookup --raw,按 JSONC 注释格式转述。
  5. 写操作先 dry-run,向用户只展示【操作摘要 + 特殊提醒 + 下一步动作】;用户回复「确认执行」后,使用同一参数 加确认标记执行。
  6. 写入成功后读取验证结果。WriteAccepted=true 只表示控制面受理;只有 StateVerified=true 才表述为已生效。

输出规范

  • 查询结论先行,再列 EventTime、EventName、EventSource、UserName、SourceIPAddress、Region、 ErrorCode、RequestID、EventID 和 RelatedResources。
  • 用户要求完整审计日志或原始审计日志时使用 events lookup --raw。该模式 stdout 直接渲染 AnnotatedEventLogs 的 JSONC 文本,格式为 "Field": value, // 字段含义;顶层与嵌套对象字段都带注释。
  • 若事件包含可解析的 EventDetail JSON object,只展示 EventDetail 内部内容并加注释,省略外层 "EventDetail": ... 字段本身。SourceIPAddress 注释为“来源 IP”。
  • 空结果表述为“账号 X 在当前地域与时间范围内无记录”。多条候选按时间倒序;证据不足时明确无法唯一确认。
  • stdout 保持结构化,诊断走 stderr;调用级请求 ID 使用 ResponseMetadata.RequestId,事件字段使用 RequestID。

写操作边界

  • CloudTrail 业务 API 使用脚本 allowlist;STS 身份确认及公开 API/文档查证是明确例外。
  • Trail 与补投写操作都需要预案确认。预案面向用户保持简短,只展示操作摘要、特殊提醒和下一步动作。
  • wrapper 对每个 API 只发起一次 ve 调用;ve / SDK 内部重试由底层控制。
  • StopLogging 是独立写操作,单独预览和确认。DeleteTrail 在确认无活跃补投任务后直接删除。
  • API 响应成功后保留 ApiResponse envelope,并向用户保留顶层 ResponseMetadata.RequestId。

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Query and answer questions about Volcengine API specifications. Use when the user asks about API parameters, error codes, request methods, enum values, required fields, response structures, pagination, parameter dependencies, service capability lists, API availability, or API comparisons, even if they do not explicitly say "API". Typical intent includes checking what an action supports, which fields are required, what values a parameter accepts, why an API returns a specific error, how to pass nested or body parameters, how pagination works, what an API response contains, whether a batch operation exists, what services or versions expose an operation, or how two APIs differ. Use API Explorer data as the authoritative source and preserve constraints, examples, and caveats found in the spec. Answer in Chinese or English. When the user needs runnable SDK code, language-specific examples, or SDK configuration, hand off to volcengine-sdk-generator. When they need CLI operations, hand off to volcengine-cli.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Create and manage Volcengine cloud resources using the Volcengine CLI (`ve` command). Supports all Volcengine services including ECS, VPC, CLB, RDS, Redis, and more. Trigger this skill whenever the user asks to create, query, modify, or delete cloud resources on Volcengine, mentions the `ve` command, says "volcengine CLI", or describes infrastructure tasks such as "create an ECS instance", "set up a VPC", "list security groups", "allocate an EIP". Also trigger on Chinese prompts mentioning "火山引擎" or "火山" (e.g., "火山引擎上有哪些 ECS"、"查一下我火山的云服务器"、 "火山引擎创建一个 VPC"、"火山的 Redis 实例列一下"). Also trigger when the user encounters errors from `ve` commands and needs troubleshooting help. Also use for TOS bucket/object operations, tosutil (sometimes written tosutils), Ark CLI / arkcli model discovery, inference, generation, endpoints, fine-tuning, plans, or usage, and TLS (日志服务) / volclog log search, analysis, ingest, export, or LogCollector collection, through `ve tosutil`, `ve arkcli` and `ve volclog`.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

火山引擎合规最佳实践助手:一是根据用户诉求(要满足的合规标准、关键词、关注的风险等级), 从火山引擎官方内置的合规包模板里推荐该开启哪些、并标出哪些已开启;二是汇总账号当前的合规 态势,把已生效规则/合规包(官方内置 + 用户自定义)的评估结果按类别(法规 / 最佳实践 / 自定义)与严重度聚合成一份合规总览报告;三是当官方基线没覆盖时,指导用户写一条 Rego 策略 作为自定义合规规则并注册评估。可在用户确认后把推荐的模板部署为合规包。Use when 用户想做「合规检查 / 合规巡检 / 安全合规 / 合规最佳实践 / 该开哪些合规规则 / 等保合规 / 我火山账号合规吗 / 有哪些不合规 / 帮我写条自定义合规规则」,或提到火山引擎「配置审计 / Config / 合规包 / conformance pack / Rego 策略」。Trigger on 火山 / 火山引擎 / volcengine 关键词叠加合规场景。部署合规包 / 注册自定义规则属写操作,需用户确认;合规报告 与资源修复严格分离。

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Manage Volcengine's AI-native BaaS platform (Supabase edition / AIDAP / 火山引擎 AI 原生 BaaS 平台 Supabase 版) — a Volcengine-operated distribution that differs from official Supabase. Use when the user asks to create, inspect, or manage Volcengine Supabase or AIDAP resources — workspaces, branches, computes, SQL queries, schema changes, Auth, Realtime, Edge Functions, Storage buckets, frontend static-site hosting (Pages), API keys, connection info, or TypeScript type generation — or when a Volcengine deployment selects AIDAP as its database provider. Also trigger on Chinese prompts mentioning "火山引擎 Supabase" or "火山 Supabase". Operations run through the byted-supabase-cli command-line tool (installed via `npm i -g @byted-supabase/cli`; this is NOT the official `supabase` CLI). Do NOT use it for general database discussions, non-Supabase services (RDS MySQL, Redis), or pure client-side coding unrelated to Supabase backend management.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Deploy a local project directory or Git repository to Volcengine as a running, reachable cloud service. USE WHEN: deploy to Volcengine, deploy to 火山引擎/火山, deploy this repo/project, publish current code, launch the app, run it in the cloud, expose it as a service, deploy to ECS/VKE/veFaaS, run on ECS, push to VKE, deploy as serverless/FaaS, or the user wants the agent to choose a Volcengine hosting target. If the user only asks which Volcengine deployment target to choose, use `volcengine-prepare` skill first. Not for creating a single standalone resource — use `volcengine-cli` skill for that.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Help users draft and, when authorized, submit feedback to volcengine/volcengine-skills: skill problems, missing capabilities, cloud scenarios, and successful Agent workflows. Use for explicit feedback or sharing requests, or an optional invitation at a natural summary after Volcengine CLI errors or an incompletely solved task. Feedback never blocks the main task.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

volcengine のスキルをすべて見る

このスキルの問題を報告する