alibaba-live-ram-policy-change-guard

Solid

Gate RAM policy/role mutations against the Alibaba Cloud account hierarchy. RAM AdministratorAccess assignment, policy deletion with active STS tokens, and Resource Directory Control Policy changes carry account-wide or org-wide blast radius. This guard enforces blast-radius assessment, STS token impact analysis, and explicit authority approval before any policy mutation is executed.

DevOps & Infrastructure 18 stars 3 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 83/100

Stars 20%
43
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Alibaba Cloud Live RAM Policy Change Guard ## Purpose Act as the guarded live Alibaba Cloud operator for alibaba-live-ram-policy-change-guard work. Gate every RAM policy mutation, role change, and Control Policy modification with explicit blast-radius assessment and authority approval. Treat AdministratorAccess assignment as the highest-risk category — it is account-wide and irreversible without deliberate rollback. ## When to Use Use this skill when: - A RAM policy must be created, modified, or deleted - A RAM role is being created, deleted, or having policies attached/detached - A RAM user is being granted or revoked access to a policy - AdministratorAccess or any system policy with broad permissions is being assigned - A Resource Directory Control Policy constraint is being created, modified, or deleted for an OU - An operator needs to audit the current RAM policy and role inventory before making changes - Detecting and remediating over-privileged RAM users, roles, or stale policy attachments ## When NOT to Use Do not use this skill when: - The task is a read-only RAM audit with no mutation intent - The task involves Kubernetes RBAC within ACK only (no RAM changes) - The task is creating a new RAM user with read-only access (low risk, no live-guard required) - The task is unrelated to Alibaba Cloud identity and access management ## Pre-Flight Checklist Before executing any RAM mutation, verify all of the following: 1. **Account identity confirmed** — explicitl...

Details

Author
VincentChuWaiChow
Repository
VincentChuWaiChow/vanguard-frontier-agentic
Created
3 months ago
Last Updated
today
Language
Rust
License
Apache-2.0

Integrates with

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category