Alibaba Cloud OOS ChatOps Agent for natural-language cloud resource management and O&M operations. Supports querying ECS/RDS/VPC/SLB resources, executing ope...
Documents
tencentcloud-oceanus-ops
Try itUse for TencentCloud Oceanus (流计算 Oceanus) operations: SQL/JAR job CRUD, job config, run/stop jobs, dependency/resource management, job events/logs, workspac...
What it does
Use for TencentCloud Oceanus (流计算 Oceanus) operations: SQL/JAR job CRUD, job config, run/stop jobs, dependency/resource management, job events/logs, workspace/folder ops. Trigger on keywords: job, 作业, workspace, 工作空间, 集群, 依赖, resource, 日志, log, or IDs matching space-*, cluster-*, cql-*. Also trigger when user asks to run oceanus_ops.py. Do NOT trigger for generic cloud tasks (CVM, COS, TKE, billing) or cluster lifecycle (create/scale/delete cluster).
The skill document
TencentCloud Oceanus Ops
Operate Oceanus workspace resources via CLI:
python scripts/oceanus_ops.py [args]
This file is the navigation hub. Detailed protocol, command catalog, enums,
and step-by-step playbooks live under references/. Always load the linked
reference for any non-trivial task instead of guessing.
Mandatory Execution Rule
When this skill is triggered, you MUST execute real CLI commands using
python scripts/oceanus_ops.py. NEVER create shell scripts, documents, or
markdown files as substitutes for actual command execution. NEVER use tccli,
kubectl, or any other CLI — only python scripts/oceanus_ops.py.
Once triggered, execute a concrete CLI command immediately. Never stop at
templates, --help output, or pure explanation.
Scope & Boundaries
In scope — Oceanus workspace operations:
- SQL jobs / JAR jobs (create, configure, publish, run, stop, savepoint)
- Workspace, folder, dependency-resource (jar/config) management
- Catalog / database / table metadata browsing
- Job observability — events, running logs, COS log files
Out of scope (do NOT handle):
- Cluster lifecycle (create / scale / delete cluster)
- Container or pod troubleshooting
- Other compute engines (EMR, DLC, …)
- Generic cloud infrastructure (CVM / VPC / billing)
Trigger Conditions
Trigger this skill when the request matches Oceanus context and at least one of:
- Operation keywords:
job,SQL作业,JAR作业,作业配置,workspace,工作空间,集群,folder,文件夹,依赖,dependency,resource,jar,配置文件,上传,事件,日志,运行日志,log,catalog,元数据,metadata,数据库,database,表,table. - Resource ID patterns:
space-*,cluster-*,cql-*,folder-*,resource-*. - Oceanus-specific verbs: create / describe / run / stop / publish a job; upload / version / query a resource; query job events / running log / COS files.
Do NOT trigger for generic cloud prompts without Oceanus context.
Execution Protocol (Hard Rules)
Region is mandatory
Every command MUST include --region . If the user omits it, default
to --region ap-guangzhou. Never run a command without --region.
Approval gates
| Class | Examples | Rule |
|---|---|---|
| Read | describe_* | Execute directly. |
| Write | modify_draft, check_sql | Execute directly (no --confirm needed). These modify draft state but are safe / idempotent. |
| Mutation | create_job, run_jobs, create_resource, upload_resource, create_job_config | Requires --confirm. Direct imperative ("帮我创建/运行") counts as approval; tentative phrasing ("能不能/先看看") requires explicit confirmation first. |
| Destructive | stop_jobs, delete_folders | Requires explicit user intent and --confirm. State the impact before executing. |
Draft confirmation (独立门控) — CRITICAL
create_job_config produces a draft summary before publishing. This is a
mandatory human-review gate that is independent of the --confirm
approval gate above.
Hard rules (NEVER violate):
- NEVER pass
--skip_draft_confirmunless the user's message contains an explicit phrase such as "跳过审核", "skip review", "直接发布", "不用确认草稿". Implied urgency or convenience is NOT sufficient. - When the draft summary is displayed, you MUST present it to the user and wait for explicit approval ("确认发布", "OK", "没问题", "发布吧") before proceeding. Do NOT auto-approve on behalf of the user.
- If the CLI outputs the draft to a temporary file, read and display the key changes (SQL diff / resource changes / config deltas) to the user.
- Violation of this gate is a critical protocol breach — equivalent to executing a destructive operation without consent.
--skip_draft_confirm: skip the review (automation-only flag; agent must NEVER use it unless user explicitly opted out of review).
Credential safety (CRITICAL)
TENCENTCLOUD_SECRET_ID / TENCENTCLOUD_SECRET_KEY /
TENCENTCLOUD_SECURITY_TOKEN are secrets. Hard rules:
- NEVER read, print, or echo their values (no
echo $TENCENTCLOUD_*,env | grep TENCENT,printenv, …). - NEVER ask the user to paste keys into chat. Have them configure locally.
- Never embed credentials in command arguments or generated files. The CLI reads them from the environment.
- If a tool result accidentally surfaces a credential value, redact it
(
***REDACTED***) before quoting back to the user. - On
MissingCredentialserror: stop further execution, follow the OS-tailored setup flow inreferences/credential-setup.md, and wait for "已配置".
Full setup templates and reply boilerplate: references/credential-setup.md.
Resources Map
Always consult after triggering
references/agent-operating-protocol.md— Execution flow, classification, output interpretation, parameter auto-resolution.references/command-map.md— Intent → command routing table with disambiguation rules.references/command-catalog.md— Full command list grouped by module.
Load on demand
references/credential-setup.md— OS-specific persistent credential setup;MissingCredentialsrecovery flow.references/enum-reference.md— Authoritative listing of every enum (Job Status, Job Type, Resource.Type vs ResourceRef.Type, LogCollect request/response sides, Run Type, Stop Type, FolderType, VariableItem.Type).references/error-handling.md— Recovery strategies when a CLI command returnssuccess: falseor non-zero exit.references/oceanus-product-model.md— Domain model (workspace / cluster / job / config / instance).
Playbooks (multi-step workflows)
references/playbooks/create-sql-job.md— SQL job: create_job → [upload deps] → modify_draft → check_sql → create_job_config → run_jobs.references/playbooks/create-jar-job.md— JAR job: upload main jar → create_job → modify_draft → create_job_config → run_jobs.references/playbooks/modify-job-config.md— Modify existing job: describe_job_configs → [resource changes] → modify_draft → [check_sql] → create_job_config.references/playbooks/job-runtime-ops.md— Run / stop / savepoint and the most common operational scenarios.references/playbooks/job-observability.md— Events, running log (CLS / ES), COS log file enumeration, "why is this job restarting" recipe.references/playbooks/dependency-management.md— Resource lifecycle (upload, version, query, folder organization).
Common Args Cheatsheet
--region # required; default ap-guangzhou (Chinese name accepted: "广州")
--workspace_id # space-xxx, or workspace name like "default"
--cluster_id # cluster-xxx, or cluster name
--job_type {1|2} # 1=SQL, 2=JAR — required for create/modify/publish job config
-o {json|table|text} # output format, default json
--confirm # required for Mutation / Destructive
Assets
scripts/oceanus_ops.py— main CLI entryscripts/client.py— TencentCloud API client (TC3-HMAC-SHA256)scripts/job_development.py— job development atomic commands (create / describe / modify_draft / check_sql / create_job_config)scripts/job_config_helpers.py— SQL/JAR payload builders, constants, draft confirmationscripts/folder_management.py— folder CRUD operations (create / describe / query / modify / delete)scripts/resource_change_ops.py— resource change processing utilitiesscripts/job_runtime.py— runtime ops (run / stop / savepoint)scripts/job_observability.py— events / logs / COS log filesscripts/resource_management.py— dependency resource lifecyclescripts/resource_resolver.py— region/workspace/cluster/version auto-resolutionscripts/resource_query.py—describe_regions/describe_workspaces/describe_clustersscripts/metadata_query.py— catalog/database/table metadata browsing (describe_catalogs/describe_meta_catalogs/describe_meta_table/describe_external_meta_databases/describe_external_meta_tables)scripts/unit_test.py— offline unit tests for pure-logic helpers (no network / no credentials). Run viapython scripts/unit_test.pyorpython -m unittest discover -s scripts -p 'unit_test.py' -v.scripts/e2e_test.py— end-to-end CLI tests; requiresTENCENTCLOUD_SECRET_ID/TENCENTCLOUD_SECRET_KEY.assets/requirements.txt— Python dependencies (currently none — stdlib only)
Related skills
Query Huawei Cloud OBS (Object Storage Service) statistics: list buckets with capacity and object counts, query extranet/intranet download traffic with month...
腾讯云 TI-ONE 训推平台查询工具集,支持训练任务、在线服务、开发机、资源组、模型仓库、数据集、日志、事件等模块的查询操作。
Own every OPC (one-person company) Alibaba Cloud package request end to end — BOTH picking the package and provisioning it. WHEN TO USE (any one is enough): the user asks to provision / deploy / create their cloud resources; names a package directly; continues right after the advisor's recommendation; **OR asks which OPC package suits them / asks you to pick one for them / describes what they want to build and asks whether an OPC package can do it — i.e. the SKU is NOT yet settled**. 'No package chosen yet' is NOT a reason to skip: the no-SKU path is this skill's job. A general assistant must NEVER answer such a question itself, compare tiers, or recommend a SKU — a critical violation. Creating cloud resources costs money — never charge without explicit user confirmation. 触发词(中文):帮我开通 / 帮我部署 / 帮我创建资源 / 开始部署;直接报 SKU 名(如"帮我开一个 lite_seed");advisor 推荐完接下来怎么办;**帮我选个套餐 / 哪个套餐合适 / 具体是哪个套餐 / 我想做 X,用 OPC 套餐能实现吗(此时尚无 SKU,同样必须触发本 skill)**。输出用中文。
Use when installing or configuring OpenClaw with DingTalk, Feishu, Discord, and additional channels with Bailian/DashScope models on Linux hosts. Use when pr...
A new ops model for the AI Agent era: an AI-Powered Intelligent Ops Assistant — an agent swarm that autonomously discovers issues and proactively repairs faults. After connecting, it unifies management of monitoring platforms (Signoz / Tencent Cloud / Aliyun / Nightingale) and covers asset discovery