本文へ移動
cccskills
無料GitHub で公開

volcengine-iac

Use Terraform/IaC for Volcengine resources only when the user explicitly chooses Terraform/IaC, already has a Terraform workflow/state, or confirms they need plan/diff/drift/destroy safety for VKE, managed databases/cache/storage, load balancers, domains/certificates, logging/monitoring, or team-managed infrastructure.

インストール方法を見る

含まれるファイル(132)

  • SKILL.md15.5 KB
  • assets/examples/volcengine-vke-cr-nginx/infra/main.tf10.2 KB
  • assets/examples/volcengine-vke-cr-nginx/workload/main.tf5.4 KB
  • assets/examples/volcenginecc-alb-acl/main.tf564 B
  • assets/examples/volcenginecc-alb-certificate/main.tf1.2 KB
  • assets/examples/volcenginecc-alb-customized-cfg/main.tf589 B
  • assets/examples/volcenginecc-alb-health-check/main.tf1.1 KB
  • assets/examples/volcenginecc-alb/main.tf4.6 KB
  • assets/examples/volcenginecc-apig/main.tf2.1 KB
  • assets/examples/volcenginecc-autoscaling/main.tf7.2 KB
  • assets/examples/volcenginecc-cbr/main.tf715 B
  • assets/examples/volcenginecc-cen/main.tf1.1 KB
  • assets/examples/volcenginecc-clb-acl/main.tf564 B
  • assets/examples/volcenginecc-clb-certificate/main.tf1.2 KB
  • assets/examples/volcenginecc-clb/main.tf2.2 KB
  • assets/examples/volcenginecc-cloudmonitor/main.tf1.4 KB
  • assets/examples/volcenginecc-cr/main.tf1.4 KB
  • assets/examples/volcenginecc-directconnect/main.tf675 B
  • assets/examples/volcenginecc-dns/main.tf870 B
  • assets/examples/volcenginecc-ebs-snapshot-group/main.tf3.9 KB
  • assets/examples/volcenginecc-ebs-snapshot/main.tf1.0 KB
  • assets/examples/volcenginecc-ecs-extras/main.tf1.1 KB
  • assets/examples/volcenginecc-ecs-launch-template-version/main.tf4.4 KB
  • assets/examples/volcenginecc-ecs/invocation.tf.disabled756 B
  • assets/examples/volcenginecc-ecs/main.tf5.8 KB
  • assets/examples/volcenginecc-efs/main.tf812 B
  • assets/examples/volcenginecc-filenas/main.tf764 B
  • assets/examples/volcenginecc-iam-oidc-provider/main.tf702 B
  • assets/examples/volcenginecc-iam-saml-provider/main.tf768 B
  • assets/examples/volcenginecc-iam-users/main.tf1.2 KB
  • assets/examples/volcenginecc-iam/main.tf1.7 KB
  • assets/examples/volcenginecc-kafka-allow-list/main.tf449 B
  • assets/examples/volcenginecc-kafka/main.tf2.2 KB
  • assets/examples/volcenginecc-mongodb/main.tf2.4 KB
  • assets/examples/volcenginecc-network/main.tf5.0 KB
  • assets/examples/volcenginecc-private-nat/main.tf2.1 KB
  • assets/examples/volcenginecc-privatelink/main.tf4.6 KB
  • assets/examples/volcenginecc-privatezone-resolver/main.tf2.2 KB
  • assets/examples/volcenginecc-privatezone/main.tf2.5 KB
  • assets/examples/volcenginecc-rabbitmq/main.tf2.1 KB
  • assets/examples/volcenginecc-rdsmssql/main.tf3.0 KB
  • assets/examples/volcenginecc-rdsmysql/main.tf4.4 KB
  • assets/examples/volcenginecc-rdspostgresql/main.tf4.4 KB
  • assets/examples/volcenginecc-redis-public-address/main.tf3.3 KB
  • assets/examples/volcenginecc-redis/main.tf3.3 KB
  • assets/examples/volcenginecc-rocketmq/main.tf2.6 KB
  • assets/examples/volcenginecc-tls-import-task/main.tf2.7 KB
  • assets/examples/volcenginecc-tls-schedule-sql/main.tf2.4 KB
  • assets/examples/volcenginecc-tls/main.tf2.3 KB
  • assets/examples/volcenginecc-tos-notification/main.tf3.0 KB
  • assets/examples/volcenginecc-tos/main.tf1.4 KB
  • assets/examples/volcenginecc-transitrouter/main.tf637 B
  • assets/examples/volcenginecc-vefaas/main.tf2.6 KB
  • assets/examples/volcenginecc-vke/main.tf4.6 KB
  • assets/examples/volcenginecc-vpc-extras/main.tf5.4 KB
  • assets/examples/volcenginecc-vpc-traffic-mirror-filter/main.tf1.4 KB
  • assets/examples/volcenginecc-vpc-traffic-mirror-target/main.tf2.7 KB
  • assets/examples/volcenginecc-vpn-ssl/main.tf2.7 KB
  • assets/examples/volcenginecc-vpn/main.tf3.9 KB
  • assets/modules/cr/main.tf702 B
  • assets/modules/cr/outputs.tf1.1 KB
  • assets/modules/cr/variables.tf1.1 KB
  • assets/modules/network/main.tf1.4 KB
  • assets/modules/network/outputs.tf912 B
  • assets/modules/network/variables.tf838 B
  • assets/modules/rds-mysql/main.tf693 B
  • assets/modules/rds-mysql/outputs.tf377 B
  • assets/modules/rds-mysql/variables.tf1.4 KB
  • assets/modules/redis/main.tf843 B
  • assets/modules/redis/outputs.tf377 B
  • assets/modules/redis/variables.tf2.1 KB
  • assets/modules/tos/main.tf614 B
  • assets/modules/tos/outputs.tf616 B
  • assets/modules/tos/variables.tf1.2 KB
  • assets/modules/vke/main.tf2.2 KB
  • assets/modules/vke/outputs.tf712 B
  • assets/modules/vke/variables.tf1.8 KB
  • references/backend-tos.md4.1 KB
  • references/modules.md6.1 KB
  • references/provider-versions.md36.6 KB
  • references/volcengine-vke-cr-nginx.md5.9 KB
  • references/volcenginecc-alb.md8.2 KB
  • references/volcenginecc-apig.md3.8 KB
  • references/volcenginecc-autoscaling.md6.5 KB
  • references/volcenginecc-blocked.md133.8 KB
  • references/volcenginecc-cbr.md1.7 KB
  • references/volcenginecc-cen.md2.7 KB
  • references/volcenginecc-clb.md4.8 KB
  • references/volcenginecc-cloudmonitor.md2.1 KB
  • references/volcenginecc-cr.md3.1 KB
  • references/volcenginecc-directconnect.md2.6 KB
  • references/volcenginecc-dns.md2.3 KB
  • references/volcenginecc-ebs-snapshot-group.md3.9 KB
  • references/volcenginecc-ebs-snapshot.md2.1 KB
  • references/volcenginecc-ecs-extras.md2.2 KB
  • references/volcenginecc-ecs-launch-template-version.md2.9 KB
  • references/volcenginecc-ecs.md6.1 KB
  • references/volcenginecc-efs.md2.4 KB
  • references/volcenginecc-filenas.md3.4 KB
  • references/volcenginecc-iam-oidc-provider.md2.5 KB
  • references/volcenginecc-iam-saml-provider.md3.0 KB
  • references/volcenginecc-iam-users.md2.6 KB
  • references/volcenginecc-iam.md3.8 KB
  • references/volcenginecc-kafka.md2.5 KB
  • references/volcenginecc-mongodb.md2.1 KB
  • references/volcenginecc-network.md6.1 KB
  • references/volcenginecc-private-nat.md2.6 KB
  • references/volcenginecc-privatelink.md3.8 KB
  • references/volcenginecc-privatezone-resolver.md2.3 KB
  • references/volcenginecc-privatezone.md2.6 KB
  • references/volcenginecc-rabbitmq.md2.1 KB
  • references/volcenginecc-rdsmssql.md6.1 KB
  • references/volcenginecc-rdsmysql.md6.3 KB
  • references/volcenginecc-rdspostgresql.md4.8 KB
  • references/volcenginecc-redis-public-address.md3.0 KB
  • references/volcenginecc-redis.md4.4 KB
  • references/volcenginecc-rocketmq.md2.7 KB
  • references/volcenginecc-tls.md8.6 KB
  • references/volcenginecc-tos-notification.md3.7 KB
  • references/volcenginecc-tos.md4.2 KB
  • references/volcenginecc-transitrouter.md2.9 KB
  • references/volcenginecc-vefaas.md7.9 KB
  • references/volcenginecc-vke.md6.5 KB
  • references/volcenginecc-vpc-extras.md4.0 KB
  • references/volcenginecc-vpc-traffic-mirror-filter.md3.2 KB
  • references/volcenginecc-vpc-traffic-mirror-target.md3.0 KB
  • references/volcenginecc-vpn-ssl.md3.4 KB
  • references/volcenginecc-vpn.md4.2 KB
  • scripts/check_drift.sh2.2 KB
  • scripts/export_outputs.sh1.6 KB
  • scripts/gen_tfvars.py6.2 KB
  • scripts/plan_summary.sh2.1 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Volcengine IaC Skill

Generate, plan, and apply Volcengine infrastructure with Terraform when the user chooses IaC. volcengine-deploy still owns application packaging, runtime rollout, health checks, and CLI resource-ledger deployment.

When writing new examples, prefer the Cloud Control provider volcengine/volcenginecc. Start from verified examples under assets/examples/, then read the matching references/volcenginecc-*.md note for validation results and pitfalls. Blocked resources are tracked in references/volcenginecc-blocked.md. Existing reusable modules under assets/modules/ still use the legacy volcengine/volcengine provider until each component is re-verified with volcenginecc.

Use this skill when one of these is true:

  • the user asks for Terraform or IaC,
  • the user already has Terraform state/workspace,
  • plan/diff/drift detection matters,
  • the infrastructure is intended for long-term team-managed operation and the user chooses IaC,
  • the deployment needs VKE, managed databases/cache/storage, load balancers, domains/certificates, IAM/KMS, logging, monitoring, or Serverless triggers and the user chooses IaC.

Do not use this skill just because a deployment is long-lived, VKE-based, or has managed dependencies. Recommend IaC where appropriate, but let the user choose. Do not use this skill when the user asks for CLI, a temporary demo/quick validation, a pure ECS single-VM service with no plan/diff/destroy requirement, or when Terraform/provider installation is blocked and the target can safely use the CLI fallback.

The skill ships verified volcenginecc examples under assets/examples/, legacy reusable modules under assets/modules/, and wrapper scripts for tfvars generation, plan summaries, output export, and drift checks. Select files only after the target shape is known; do not load broad catalogs into context for small Terraform edits.

Resources outside the six legacy modules (CLB/ALB, VKE, CR, databases, caches, object storage) should be added as verified volcenginecc examples first, then wrapped only after repeated use proves the interface is stable.


0. Prerequisites

Required env vars: VOLCENGINE_ACCESS_KEY, VOLCENGINE_SECRET_KEY, VOLCENGINE_REGION.

Required tools: terraform >= 1.5, jq, git, python3 (for gen_tfvars.py).

Optional: .volcengine/deploy-choice.json from volcengine-prepare/volcengine-deploy. If absent, ask a short batch of Terraform-specific questions.

The skill writes Terraform working files into .volcengine/terraform/ by default. State can use a TOS S3-compatible backend when the user wants remote state; see references/backend-tos.md. Local state is acceptable for small one-off experiments when the user accepts the tradeoff.

If invoked by volcengine-deploy, return outputs in .volcengine/iac-outputs.json and let deploy continue with image build/push, Cloud Assistant commands, Kubernetes manifests, veFaaS release, migrations, and health checks.


1. Generation Flow

Path A — driven by .volcengine/deploy-choice.json

work_dir="${work_dir:-.volcengine/terraform}"
workload="${workload:-standard}"
mkdir -p "$work_dir"

python3 scripts/gen_tfvars.py \
  --input ".volcengine/deploy-choice.json" \
  --output "$work_dir/terraform.tfvars" \
  --workload "$workload"

gen_tfvars.py derives:

  • project, region, AZ pair from the choice file and environment
  • enable_vke / enable_cr / enable_rds / enable_redis / enable_tos flags from the chosen mode and known dependencies
  • Sizing (instance type, node count, RDS spec, Redis capacity) from a coarse --workload tier

The user can override any value before applying.

Path B — natural language input

When no prepare report exists, ask the user one batch of questions, then create a Terraform working directory from verified examples or legacy modules and generate matching variable values. Required answers:

  1. Project name (resource prefix)
  2. Region (e.g. cn-beijing)
  3. Need VKE? (yes/no)
  4. Stateful deps needed: MySQL? PostgreSQL? Redis? TOS bucket?
  5. Workload tier: light / standard / heavy

Files written

gen_tfvars.py writes only terraform.tfvars. The Terraform configuration files come from copied verified examples under assets/examples/ or from a small root module assembled from assets/modules/; edit those files to match the selected stack instead of expecting the script to generate them.

FilePurpose
main.tf / variables.tfCopied or assembled Terraform configuration
terraform.tfvarsConcrete values generated by gen_tfvars.py or edited by hand
backend.tfGenerated only when TOS remote state is selected; otherwise omit it

The full per-module variable schema lives in references/modules.md. For new volcenginecc work, start from a verified example under assets/examples/ instead of these legacy modules unless the user explicitly needs the old provider.

Path C — volcenginecc verified examples

Copy the relevant verified example, then run the same init/validate/plan sequence:

cp -R "assets/examples/<example-name>" "$work_dir/<component>"
cd "$work_dir/<component>"
terraform init -backend=false -input=false
terraform validate
terraform plan -out=tfplan.binary -input=false

Before apply, show the plan summary and require explicit user confirmation. Read the matching reference before changing inputs or destroying resources; the references contain field choices, validation notes, import IDs, and provider pitfalls.


2. Deployment stack mapping

Use the deployment shape to choose a small set of verified examples. Start with examples; wrap into reusable modules only after repeated use proves the interface stable. Typical stacks combine:

  • ECS: volcenginecc-network, volcenginecc-ecs, optional TLS/CloudMonitor
  • VKE: volcenginecc-network, volcenginecc-vke, volcenginecc-cr, CLB or ALB
  • veFaaS: volcenginecc-vefaas, optional APIG/TLS
  • Stateful web app: runtime stack plus RDS, Redis, and/or TOS examples
  • Private service: runtime stack plus private NAT or network connectivity examples
  • Domain entry: runtime stack plus DNS and load balancer certificate examples

This mapping is a guide, not a promise that a prebuilt module exists. Copy relevant examples into .volcengine/terraform/<component> and keep component boundaries clear so plan/destroy output remains readable.

For the end-to-end VKE private CR nginx path, use assets/examples/volcengine-vke-cr-nginx/ and read references/volcengine-vke-cr-nginx.md first. That example exists for the CR credential addon, core-dns, CR token expiry, and image architecture pitfalls found in a real run.


3. Catalog

Use the filesystem as the catalog. After selecting a deployment shape, list only the relevant directories under assets/examples/, then read the matching references/volcenginecc-*.md file for validation notes, import IDs, and provider caveats. Do not load every example into context up front.

Common example families:

  • volcenginecc-network, VPC extras, NAT, VPN, DirectConnect, CEN, TransitRouter, PrivateLink, DNS, PrivateZone
  • volcenginecc-ecs, ECS extras, launch template versions, EBS snapshots, Auto Scaling
  • volcenginecc-vke, volcenginecc-cr, CLB/ALB entry, APIG, veFaaS
  • volcenginecc-rdsmysql, volcenginecc-rdspostgresql, volcenginecc-rdsmssql, Redis, Kafka allowlist
  • volcenginecc-tos, TOS notification, TLS, CloudMonitor, IAM, FileNAS, EFS

Legacy volcengine modules are still available under assets/modules/; read references/modules.md before using them.

Legacy modules currently cover network, vke, cr, rds-mysql, redis, and tos. ECS and CLB/ALB stay as verified examples because their workload shapes vary too much for one stable module interface.


4. Init & Backend

cd "$work_dir"

# Map Volcengine creds to the Terraform s3 backend's required env variable names.
export AWS_ACCESS_KEY_ID="$VOLCENGINE_ACCESS_KEY"
export AWS_SECRET_ACCESS_KEY="$VOLCENGINE_SECRET_KEY"
export AWS_EC2_METADATA_DISABLED=true

terraform init -input=false
tf_workspace="${tf_workspace:-default}"
terraform workspace select "$tf_workspace" || \
  terraform workspace new "$tf_workspace"

When remote state is requested, generate backend.tf from references/backend-tos.md. The verified TOS backend shape requires skip_requesting_account_id = true and must not set force_path_style or use_path_style.

Provider download (~30–60 seconds first time) goes through registry.terraform.io. In China networks this may be blocked or slow. If public registry access fails and the user still wants IaC, configure Terraform provider_installation with a filesystem or internal mirror. Otherwise return to volcengine-deploy and ask whether to use the CLI resource-ledger path.

For the TOS bucket prerequisite (must exist before init), see references/backend-tos.md. Without a TOS bucket, omit backend.tf and Terraform falls back to local state.


5. Plan

terraform plan -out=tfplan.binary -input=false
terraform show -json tfplan.binary > tfplan.json
bash scripts/plan_summary.sh tfplan.json

plan_summary.sh groups changes by action (CREATE / UPDATE / DELETE / REPLACE) and prints a one-line summary at the end. Show this to the user before any apply.

Watch for:

  • DELETEs you didn't ask for — usually a sign of drift or a mistakenly removed module call
  • REPLACEs on stateful resources — RDS / Redis replace = data loss; abort and inspect the diff with terraform show tfplan.binary

6. Apply

Always require explicit user confirmation. Do not pass -auto-approve. The pattern:

The plan above will create N resources, change M, destroy K. Approve apply? [yes/no]

After yes:

terraform apply tfplan.binary

VKE cluster creation takes ~10–15 minutes. RDS HA instances take ~20 minutes. Surface the long-running message to the user once at apply start so they don't think it hung.

After apply succeeds, run export_outputs.sh automatically:

bash scripts/export_outputs.sh
echo "Resources ready. .volcengine/iac-outputs.json now contains downstream consumption keys."

7. Outputs for Downstream

export_outputs.sh writes terraform output -json to .volcengine/iac-outputs.json with mode 0600. Downstream skills commonly consume VPC/subnet/security group IDs, VKE kubeconfig, CR repository data, RDS/Redis endpoints or IDs, and TOS bucket names. Some keys are conditional on which examples/modules were enabled; consumers must use defensive jq defaults.


8. Destroy

# Show what will be destroyed first
terraform plan -destroy -out=destroy.binary
terraform show -json destroy.binary | bash scripts/plan_summary.sh

Then:

This will permanently delete N resources including RDS / Redis / TOS bucket data. Confirm? [yes/no]

On yes:

terraform destroy
# Note: provider does not accept -auto-approve=false; we rely on the agent-level prompt above.

Hard rule: never destroy in prod workspace without a second confirmation. The agent should explicitly re-prompt:

Workspace = prod. Re-confirm destroy by typing 'destroy prod':

9. Drift Detection

bash scripts/check_drift.sh

Returns:

  • 0 and {"drift": false, ...} — no drift
  • 2 and {"drift": true, "changed_resources": N, ...} — N resources changed outside Terraform
  • 1 and {"drift": "error", ...} — refresh-only plan errored

Use this:

  • After known manual interventions (someone resized a node pool via console)
  • Periodically as a CI job (weekly)
  • Before any non-trivial apply to confirm baseline matches state

10. Import Existing Resources

If the user wants to adopt resources created via volcengine-cli or console, use terraform import. Import IDs differ by resource; read the matching references/volcenginecc-*.md or references/modules.md before importing. After import, run terraform plan and reconcile by editing config, not state.


11. Safety Rules

  • Never read ~/.volcengine/config.json; it may contain plaintext AK/SK.
  • Never commit terraform.tfstate* or .volcengine/iac-outputs.json.
  • Never pass -auto-approve to terraform apply or terraform destroy.
  • Run check_drift.sh before every apply on shared environments.
  • Set mode 0600 on files holding kubeconfig or secrets.
  • Pin provider versions in every module/example.

The scripts enforce file permissions where possible. Apply and destroy gates are the agent's responsibility.


12. Troubleshooting

Look up by the exact error string; act on the mapped cause before suspecting unrelated layers.

SymptomCauseFix
terraform init: "Failed to query available provider packages"outbound to registry.terraform.io blockedConfigure provider_installation with a filesystem/internal mirror and rerun init; otherwise return to volcengine-deploy and ask whether CLI resource-ledger provisioning is acceptable
terraform init: "InvalidAccessKeyId" against TOS backends3 backend env vars not exportedExport AWS_ACCESS_KEY_ID="$VOLCENGINE_ACCESS_KEY", AWS_SECRET_ACCESS_KEY="$VOLCENGINE_SECRET_KEY", AWS_EC2_METADATA_DISABLED=true
terraform init: TOS backend returns InvalidPathAccesspath-style access or unsupported workspace prefixUse the verified template in references/backend-tos.md: keep skip_requesting_account_id = true, remove force_path_style/use_path_style
apply succeeds for VPC but subnet fails with InvalidVpc.InvalidStatusVPC not yet Available (consistency window)Add depends_on = [volcengine_vpc.main] (already wired in the network module)
VKE cluster stuck in Creating for >20 minquota or AZ capacityve vke ListClusters --body '{"Filter":{"Ids":["..."]}}' | jq .Result.Items[0].Status for the real reason
redis output missing endpointprovider does not export itResolve via ve redis DescribeDBInstanceDetail --InstanceId $(jq -r '.redis_instance_id.value' .volcengine/iac-outputs.json)
terraform plan shows unexpected changes after no editsdrift, or provider patch bump silently changing a defaultRun check_drift.sh, inspect tfplan.json, decide whether to accept or revert
Two engineers' apply collideTOS backend has no DynamoDB-style lockingCoordinate manually; see references/backend-tos.md
Resource-specific apply/import driftprovider caveat for that resourceRead the matching references/volcenginecc-*.md note before editing config

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Query and answer questions about Volcengine API specifications. Use when the user asks about API parameters, error codes, request methods, enum values, required fields, response structures, pagination, parameter dependencies, service capability lists, API availability, or API comparisons, even if they do not explicitly say "API". Typical intent includes checking what an action supports, which fields are required, what values a parameter accepts, why an API returns a specific error, how to pass nested or body parameters, how pagination works, what an API response contains, whether a batch operation exists, what services or versions expose an operation, or how two APIs differ. Use API Explorer data as the authoritative source and preserve constraints, examples, and caveats found in the spec. Answer in Chinese or English. When the user needs runnable SDK code, language-specific examples, or SDK configuration, hand off to volcengine-sdk-generator. When they need CLI operations, hand off to volcengine-cli.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Create and manage Volcengine cloud resources using the Volcengine CLI (`ve` command). Supports all Volcengine services including ECS, VPC, CLB, RDS, Redis, and more. Trigger this skill whenever the user asks to create, query, modify, or delete cloud resources on Volcengine, mentions the `ve` command, says "volcengine CLI", or describes infrastructure tasks such as "create an ECS instance", "set up a VPC", "list security groups", "allocate an EIP". Also trigger on Chinese prompts mentioning "火山引擎" or "火山" (e.g., "火山引擎上有哪些 ECS"、"查一下我火山的云服务器"、 "火山引擎创建一个 VPC"、"火山的 Redis 实例列一下"). Also trigger when the user encounters errors from `ve` commands and needs troubleshooting help. Also use for TOS bucket/object operations, tosutil (sometimes written tosutils), Ark CLI / arkcli model discovery, inference, generation, endpoints, fine-tuning, plans, or usage, and TLS (日志服务) / volclog log search, analysis, ingest, export, or LogCollector collection, through `ve tosutil`, `ve arkcli` and `ve volclog`.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Use when the user asks to query Volcengine CloudTrail audit logs, investigate login or resource operations, or manage CloudTrail trails and backfill delivery tasks. Trigger on 操作审计, 审计日志, CloudTrail, cloud_trail, trail, 跟踪, 历史补投, or backfill in a Volcengine context. Audit queries are read-only; trail and backfill mutations require an explicit preview and confirmation.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

火山引擎合规最佳实践助手:一是根据用户诉求(要满足的合规标准、关键词、关注的风险等级), 从火山引擎官方内置的合规包模板里推荐该开启哪些、并标出哪些已开启;二是汇总账号当前的合规 态势,把已生效规则/合规包(官方内置 + 用户自定义)的评估结果按类别(法规 / 最佳实践 / 自定义)与严重度聚合成一份合规总览报告;三是当官方基线没覆盖时,指导用户写一条 Rego 策略 作为自定义合规规则并注册评估。可在用户确认后把推荐的模板部署为合规包。Use when 用户想做「合规检查 / 合规巡检 / 安全合规 / 合规最佳实践 / 该开哪些合规规则 / 等保合规 / 我火山账号合规吗 / 有哪些不合规 / 帮我写条自定义合规规则」,或提到火山引擎「配置审计 / Config / 合规包 / conformance pack / Rego 策略」。Trigger on 火山 / 火山引擎 / volcengine 关键词叠加合规场景。部署合规包 / 注册自定义规则属写操作,需用户确认;合规报告 与资源修复严格分离。

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Manage Volcengine's AI-native BaaS platform (Supabase edition / AIDAP / 火山引擎 AI 原生 BaaS 平台 Supabase 版) — a Volcengine-operated distribution that differs from official Supabase. Use when the user asks to create, inspect, or manage Volcengine Supabase or AIDAP resources — workspaces, branches, computes, SQL queries, schema changes, Auth, Realtime, Edge Functions, Storage buckets, frontend static-site hosting (Pages), API keys, connection info, or TypeScript type generation — or when a Volcengine deployment selects AIDAP as its database provider. Also trigger on Chinese prompts mentioning "火山引擎 Supabase" or "火山 Supabase". Operations run through the byted-supabase-cli command-line tool (installed via `npm i -g @byted-supabase/cli`; this is NOT the official `supabase` CLI). Do NOT use it for general database discussions, non-Supabase services (RDS MySQL, Redis), or pure client-side coding unrelated to Supabase backend management.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

Deploy a local project directory or Git repository to Volcengine as a running, reachable cloud service. USE WHEN: deploy to Volcengine, deploy to 火山引擎/火山, deploy this repo/project, publish current code, launch the app, run it in the cloud, expose it as a service, deploy to ECS/VKE/veFaaS, run on ECS, push to VKE, deploy as serverless/FaaS, or the user wants the agent to choose a Volcengine hosting target. If the user only asks which Volcengine deployment target to choose, use `volcengine-prepare` skill first. Not for creating a single standalone resource — use `volcengine-cli` skill for that.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/volcengine-skills212026年9月23日 更新

volcengine のスキルをすべて見る

このスキルの問題を報告する