Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
cinience avatar

Alicloud Security Cloudfw

  • 262 installs
  • 396 repo stars
  • Updated July 18, 2026
  • cinience/alicloud-skills

alicloud-security-cloudfw is an agent skill that deploys and tunes Alibaba Cloud Firewall policies to control north-south traffic, segment workloads, and enforce allow-deny rules.

About

alicloud-security-cloudfw is a cinience/alicloud-skills skill for Alibaba Cloud Firewall. It helps developers deploy firewall policies, control north-south traffic, segment workloads, and enforce allow-deny rules ahead of production exposure or compliance reviews. Use it when moving Alibaba Cloud services toward production rather than relying on default wide-open security groups. Combine skill guidance with your network topology diagrams and Alibaba Cloud Firewall console or API documentation for rule specificity and audit evidence.

  • Cloud Firewall policy design
  • North-south traffic control
  • Workload segmentation rules
  • Audit-ready allow-deny lists
  • Pre-launch perimeter hardening

Alicloud Security Cloudfw by the numbers

  • 262 all-time installs (skills.sh)
  • Ranked #664 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/cinience/alicloud-skills --skill alicloud-security-cloudfw

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs262
repo stars396
Last updatedJuly 18, 2026
Repositorycinience/alicloud-skills

How do you configure Alibaba Cloud Firewall policies?

Deploy and tune Alibaba Cloud Firewall policies to control north-south traffic, segment workloads, and enforce allow-deny rules before production exposure or compliance audits.

Who is it for?

Security-minded platform engineers preparing Alibaba Cloud workloads for production or compliance audits.

Skip if: Local-only prototypes without Alibaba Cloud networking or teams that only need application unit test coverage.

When should I use this skill?

User asks to deploy, tune, or audit Alibaba Cloud Firewall policies and north-south traffic rules.

What you get

Cloud Firewall policy sets, segmented workload rules, and north-south traffic control configurations.

  • Firewall policy configurations
  • Segmented network rule sets

Files

SKILL.mdMarkdownGitHub ↗

Category: service

Cloud Firewall

Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for Cloud Firewall.

Workflow

1) Confirm region, resource identifiers, and desired action. 2) Discover API list and required parameters (see references). 3) Call API with SDK or OpenAPI Explorer. 4) Verify results with describe/list APIs.

AccessKey priority (must follow)

1) Environment variables: ALICLOUD_ACCESS_KEY_ID / ALICLOUD_ACCESS_KEY_SECRET / ALICLOUD_REGION_ID Region policy: ALICLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. 2) Shared config file: ~/.alibabacloud/credentials

API discovery

  • Product code: Cloudfw
  • Default API version: 2017-12-07
  • Use OpenAPI metadata endpoints to list APIs and get schemas (see references).

High-frequency operation patterns

1) Inventory/list: prefer List* / Describe* APIs to get current resources. 2) Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations. 3) Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.

Minimal executable quickstart

Use metadata-first discovery before calling business APIs:

python scripts/list_openapi_meta_apis.py

Optional overrides:

python scripts/list_openapi_meta_apis.py --product-code <ProductCode> --version <Version>

The script writes API inventory artifacts under the skill output directory.

Output policy

If you need to save responses or generated artifacts, write them under: output/alicloud-security-cloudfw/

Validation

mkdir -p output/alicloud-security-cloudfw
for f in skills/security/firewall/alicloud-security-cloudfw/scripts/*.py; do
  python3 -m py_compile "$f"
done
echo "py_compile_ok" > output/alicloud-security-cloudfw/validate.txt

Pass criteria: command exits 0 and output/alicloud-security-cloudfw/validate.txt is generated.

Output And Evidence

  • Save artifacts, command outputs, and API response summaries under output/alicloud-security-cloudfw/.
  • Include key parameters (region/resource id/time range) in evidence files for reproducibility.

Prerequisites

  • Configure least-privilege Alibaba Cloud credentials before execution.
  • Prefer environment variables: ALICLOUD_ACCESS_KEY_ID, ALICLOUD_ACCESS_KEY_SECRET, optional ALICLOUD_REGION_ID.
  • If region is unclear, ask the user before running mutating operations.

References

  • Sources: references/sources.md

Related skills

FAQ

What does alicloud-security-cloudfw help deploy?

alicloud-security-cloudfw deploys and tunes Alibaba Cloud Firewall policies for north-south traffic control, workload segmentation, and allow-deny enforcement before production or compliance audits.

When should developers use Cloud Firewall skill?

Use alicloud-security-cloudfw when hardening Alibaba Cloud networks for production or audits, not for local dev environments without cloud firewall resources.

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.