huaweicloud/huaweicloud-skills

huawei-cloud-flexus-l-server-hermes-deployment

One-click deployment tool for Hermes on Huawei Cloud Flexus L instances.

Vedi sorgente
Documento Skill originale

Contenuto dal repository con titoli, esempi, codice, tabelle, link e immagini preservati.

⚠️ Security Execution Rules (Highest Priority):

  1. All scripts MUST be executed via skill action=exec, NEVER run directly in shell
  2. NEVER print script contents or commands containing AK/SK/Token in conversation
  3. NEVER create temporary script files, prefer inline execution (python -c)
  4. On execution failure, only return error info, do NOT rewrite scripts or print full commands
  5. AK/SK/Token MUST be passed via environment variables, NEVER appear in conversation
  6. ABSOLUTELY NEVER expose, log, or print AK/SK/Token values in any form - this is a critical security requirement
  7. When using skill action=exec, credentials are automatically inherited from environment variables (HWACCESSKEY, HWSECRETKEY, HWSECURITYTOKEN), no need to pass them as command line arguments

Hermes One-Click Deployment Skill

Overview

This skill supports one-click deployment of the Hermes AI Agent platform to Huawei Cloud Flexus L instances. It provides a complete workflow including:

  • Automated instance creation with optimized configurations
  • ModelArts large model configuration via COC (Cloud Operations Center)
  • Robot channel configuration (Feishu, WeCom, DingTalk, etc.) via COC
  • Gateway management for deployed instances

This skill supports both interactive mode (step-by-step prompts) and non-interactive mode (scripted operations), suitable for manual and automated deployment scenarios.

Prerequisites

Account Requirements

  • Valid Huawei Cloud account with sufficient permissions
  • Huawei Cloud credentials: Long-term AK/SK OR Temporary AK/SK + security_token
  • Required permissions:
  • Creating Flexus L instances
  • Accessing COC (Cloud Operations Center) services

Credential Acquisition Methods:

This skill supports both long-term and temporary Huawei Cloud credentials:

  1. Long-term AK/SK: No security_token required
  2. Temporary AK/SK: Security token required

Environment Variables (optional):

  • HW_ACCESS_KEY: Access Key AK (long-term or temporary)
  • HW_SECRET_KEY: Secret Key SK (long-term or temporary)
  • HW_SECURITY_TOKEN: Security token for temporary credentials (only required for temporary AK/SK)

Architecture Diagram

This skill is built on multiple Huawei Cloud services, involving the following cloud services and components:

User/Agent      ──────▶│   Flexus L Instance   │──────▶│   Hermes App         │──────▶│ Model Config     │ ──────▶│  Channel Config     │ 
(Skill caller)           (Target Host)                 (AI Agent Platform)             (ModelArts API)           (Feishu/Wecom)            

Component Description:

  • User/Agent: Skill caller that triggers Hermes deployment operations via natural language or API
  • Flexus L Instance: Huawei Cloud Elastic Cloud Server, serving as the target host for Hermes deployment
  • Hermes App: AI Agent platform running on the Flexus L instance
  • Model Config: ModelArts large model configuration (APIBASE, APIKEY, MODEL_NAME)
  • Channel Config: Robot channel configuration (Feishu, WeCom)

Core Commands

Deployment Commands

bash
# Deploy using long-term AK/SK
python scripts/caller.py deploy --ak <AK> --sk <SK> --name hermes-{timestamp} --region cn-north-4

# Deploy using temporary AK/SK (requires security-token)
python scripts/caller.py deploy --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --name hermes-{timestamp} --region cn-north-4

# Deploy in interactive mode (if not specified, auto-generates timestamp format: hermes-20260605143022)
python scripts/caller.py deploy

Instance Name Description:

  • Can customize instance name via --name parameter (e.g., hermes-prod-01, hermes-dev, etc.)
  • If name is not specified, auto-generates timestamp format: hermes-YYYYMMDDHHMMSS (e.g., hermes-20260605143022)

Model Configuration Commands

bash
# Configure model using long-term AK/SK
python scripts/caller.py maas --ak <AK> --sk <SK> --resource-id <instance_id> --region-id cn-north-4 --api-key <api_key> --model-name deepseek-v3.2

# Configure model using temporary AK/SK
python scripts/caller.py maas --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --resource-id <instance_id> --region-id cn-north-4 --api-key <api_key> --model-name deepseek-v3.2

# Configure model in interactive mode
python scripts/caller.py maas

Channel Configuration Commands

bash
# Configure Feishu channel using long-term AK/SK
python scripts/caller.py channel --ak <AK> --sk <SK> --resource-id <instance_id> --region-id cn-north-4 --bot-platform feishu --feishu-app-id <app_id> --feishu-app-secret <app_secret>

# Configure Feishu channel using temporary AK/SK
python scripts/caller.py channel --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --resource-id <instance_id> --region-id cn-north-4 --bot-platform feishu --feishu-app-id <app_id> --feishu-app-secret <app_secret>

# Configure WeCom channel using long-term AK/SK
python scripts/caller.py channel --ak <AK> --sk <SK> --resource-id <instance_id> --region-id cn-north-4 --bot-platform wecom --wecom-bot-id <bot_id> --wecom-secret <secret>

# Configure WeCom channel using temporary AK/SK
python scripts/caller.py channel --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --resource-id <instance_id> --region-id cn-north-4 --bot-platform wecom --wecom-bot-id <bot_id> --wecom-secret <secret>

# Configure channel in interactive mode
python scripts/caller.py channel

Gateway Management Commands

bash
# Restart gateway using long-term AK/SK
python scripts/caller.py gateway --ak <AK> --sk <SK> --resource-id <instance_id> --region-id cn-north-4

# Restart gateway using temporary AK/SK
python scripts/caller.py gateway --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --resource-id <instance_id> --region-id cn-north-4

# Restart gateway in interactive mode
python scripts/caller.py gateway

Query Execution Result Commands

bash
# Query execution result using long-term AK/SK
python scripts/caller.py query --ak <AK> --sk <SK> --execute-uuid SCT2023083109562601af694bf

# Query execution result using temporary AK/SK
python scripts/caller.py query --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --execute-uuid SCT2023083109562601af694bf

Parameters:

  • --execute-uuid: Script execution UUID, format like SCTxxxxxxxxxxxxxxxbf

Status Description:

  • FINISHED: Execution successful
  • ABNORMAL: Execution failed
  • RUNNING: Executing

UniAgent Status Query Commands

bash
# Query UniAgent status using long-term AK/SK
python scripts/caller.py uniagent --ak <AK> --sk <SK> --resource-id <instance_id>

# Query UniAgent status using temporary AK/SK
python scripts/caller.py uniagent --ak <temp_ak> --sk <temp_sk> --security-token <security_token> --resource-id <instance_id>

# Query UniAgent status in interactive mode
python scripts/caller.py uniagent

UniAgent Status Description:

  • ONLINE: UniAgent is running normally, can execute COC scripts
  • OFFLINE: UniAgent is not running, cannot execute COC scripts
  • UNKNOWN: Status cannot be determined

When to Use:

  • Before configuring models or channels, ensure UniAgent is ONLINE
  • Troubleshoot COC script execution failures
  • Verify instance operational status after deployment
  • After the instance creation command is successfully issued (with status codes "200", "201", or "202"), automatically check whether the preconditions are met (status of the gateway and UniAgent). If they are met, you can immediately proceed to the next steps!

Parameter Reference

Global Parameters

ParameterDescriptionRequiredDefault Value
--akHuawei Cloud Access Key AK (supports both long-term and temporary)NoPrompted
--skHuawei Cloud Access Key SK (supports both long-term and temporary)NoPrompted
--security-tokenSecurity token for temporary credentials (optional, only required for temporary AK/SK)NoPrompted
--non-interactiveRun in non-interactive modeNofalse

Deploy Command Parameters

ParameterDescriptionRequiredDefault Value
--nameInstance nameNoAuto-generated
--regionTarget regionNocn-north-4

MaaS Command Parameters

ParameterDescriptionRequiredDefault Value
--resource-idL instance resource IDYes-
--region-idCOC service regionNocn-north-4
--api-keyModelArts API KeyYes-
--model-nameModel nameYes-
--api-base-urlAPI base URLNohttps://api.modelarts-maas.com/v2
--timeoutExecution timeout (seconds)No600
--execute-userExecution userNoroot

Channel Command Parameters

ParameterDescriptionRequiredDefault Value
--resource-idL instance resource IDYes-
--region-idCOC service regionNocn-north-4
--bot-platformBot platform: feishu or wecomYes-
--feishu-app-idFeishu App IDConditional-
--feishu-app-secretFeishu App SecretConditional-
--wecom-bot-idWeCom Bot IDConditional-
--wecom-secretWeCom SecretConditional-
--timeoutExecution timeout (seconds)No600
--execute-userExecution userNoroot

Gateway Command Parameters

ParameterDescriptionRequiredDefault Value
--resource-idL instance resource IDYes-
--region-idCOC service regionNocn-north-4
--timeoutExecution timeout (seconds)No120
--execute-userExecution userNoroot

UniAgent Command Parameters

ParameterDescriptionRequiredDefault Value
--resource-idL instance resource IDYes-

Workflow

The skill follows these workflow steps:

  1. Deploy Hermes: Create and configure a Flexus L instance with Hermes AI Agent platform
  2. Configure Model: Set up ModelArts large model via COC (Cloud Operations Center)
  3. Configure Channel: Set up robot channels (Feishu, WeCom) via COC
  4. Manage Gateway: Restart gateway service when needed

Interactive Mode (Menu)

Run the main entry point to access the interactive menu:

bash
python scripts/caller.py

This will display a menu for selecting operations.

Output Format

Deploy Command Output

json
{
  "status": "success",
  "instance_id": "abc12345-6789-0abc-def1-23456789abc0",
  "instance_name": "my-hermes",
  "region": "cn-north-4",
  "spec": "hf.small.1.linux",
  "created_at": "2024-01-15T10:30:00Z"
}

MaaS Command Output

json
{
  "status": "success",
  "resource_id": "abc12345-6789-0abc-def1-23456789abc0",
  "model_name": "deepseek-v3.2",
  "api_base_url": "https://api.modelarts-maas.com/v2",
  "executed_at": "2024-01-15T10:35:00Z"
}

Channel Command Output

json
{
  "status": "success",
  "resource_id": "abc12345-6789-0abc-def1-23456789abc0",
  "bot_platform": "feishu",
  "channel_id": "channel_123",
  "executed_at": "2024-01-15T10:40:00Z"
}

Gateway Command Output

json
{
  "status": "success",
  "resource_id": "abc12345-6789-0abc-def1-23456789abc0",
  "action": "restart",
  "message": "Hermes gateway restarted successfully"
}

Validation Methods

1. Deployment Validation

bash
# Check instance status
python scripts/caller.py deploy --ak <ak> --sk <sk> --name my-hermes --region cn-north-4 --non-interactive
# Expected output: "Instance created successfully" with instance_id

2. Model Configuration Validation

bash
# Check model configuration
python scripts/caller.py maas --ak <ak> --sk <sk> --resource-id <instance_id> --region-id cn-north-4 --api-key <key> --model-name deepseek-v3.2 --non-interactive
# Expected output: "Model configuration updated successfully"

3. Channel Configuration Validation

bash
# Check channel configuration
python scripts/caller.py channel --ak <ak> --sk <sk> --resource-id <instance_id> --region-id cn-north-4 --bot-platform feishu --feishu-app-id <id> --feishu-app-secret <secret> --non-interactive
# Expected output: "Channel configuration updated successfully"

4. Gateway Validation

bash
# Check gateway restart
python scripts/caller.py gateway --ak <ak> --sk <sk> --resource-id <instance_id> --region-id cn-north-4 --non-interactive
# Expected output: "Hermes gateway restarted successfully"

Best Practices

1. Credential Management

  • Temporary credentials: Use temporary AK/SK + security_token for authentication, providing higher security
  • Temporary credentials are issued by STS service with expiration time limits
  • Use --security-token parameter to pass the security token
  • Supports environment variables, command line parameters, and interactive input methods
  • Use IAM roles with minimal permissions for production environments
  • Rotate credentials regularly according to security policies

2. Region Selection

  • Choose the region closest to your users for better performance
  • Consider regional compliance requirements when deploying
  • Use cn-north-4 as default for China mainland deployments
  • Hermes deployment only supports: cn-north-4, cn-east-3, cn-south-1, cn-southwest-2

3. Instance Management

  • Monitor instance health via Huawei Cloud Console
  • Set up auto-scaling policies for high availability
  • Configure backup policies for data persistence

4. Model Configuration

  • Test models in staging environment before production
  • Have fallback models configured for failover scenarios
  • After initial deployment, the default model configuration is not usable. You must configure the model before using Hermes.

5. Channel Configuration

  • Use dedicated bot accounts for production
  • Monitor channel message throughput
  • Configure rate limits to prevent abuse
  • Currently only Feishu and WeCom bot platforms are supported. Only one bot per platform type is supported.

Notes

General Notes

  1. Instance Creation Time: It may take 5-10 minutes for the instance to be fully provisioned
  2. COC Script Execution: Model and channel configurations are executed remotely via Huawei Cloud COC (Cloud Operations Center)
  3. Security Group: Configure security group rules in Huawei Cloud Console if external access is needed
  4. Cost: Using Huawei Cloud resources will incur costs. Ensure your account has sufficient balance.
  5. Subsequent Steps: When continuing with subsequent steps (configuring models, channels), there is no need to wait for instance creation to complete. The system handles instance status automatically.

Region Notes

  • Fixed Endpoint: When creating a Hermes L Instance, requests are sent to the fixed endpoint hcss.cn-north-4.myhuaweicloud.com. The region parameter only selects instance specifications.
  • Guiyang region (cn-southwest-2) uses spec ahf.small.1.linux
  • Other regions (Beijing/Shanghai/Guangzhou) use spec hf.small.1.linux
  • Status Codes: 200, 201, and 202 all indicate success

COC Region Concepts

COC involves two different region concepts:

1. COC Service Region (--region-id): The region where COC API service is located (cn-north-4, ap-southeast-3, eu-west-101)

2. Target Instance Region: The region where the L instance is located (can be any Huawei Cloud region worldwide)

These can be different - e.g., COC service in cn-north-4 can execute scripts on instances in ap-southeast-1 (Hong Kong).

Troubleshooting

  • Credential Issues: Ensure --ak and --sk parameters are provided, or use interactive mode
  • Region Not Supported: Use supported region IDs or Chinese names in interactive mode
  • Instance Creation Failed: Verify account balance, instance type validity, and network connectivity

Reference Documents

  • scripts/caller.py - Main CLI entry point
  • scripts/deploy.py - Hermes deployment module
  • scripts/models.py - ModelArts model configuration
  • scripts/channels.py - Robot channel configuration
  • scripts/lib.py - Core business logic (instance creation, model/channel installation)
  • scripts/utils.py - Utility functions (credentials setup, input prompts)
dallo stesso repository

Altri Skills

Tutti gli Skills
huaweicloud
Community

huawei-cloud-publish-work-to-gallery

Publish user's work to the Huawei Cloud University Operations Platform (华为云高校运营平台/作品陈列馆). Use this skill whenever the user wants to publish, submit, or upload a project/work to the gallery or a training camp (训练营) on the platform — including casual phrasings like "把作品发布上去", "投稿到陈列馆", "传作品到平台", "提交作品/项目", "报名发布作品", as well as formal ones like "publish to work gallery", "submit to training camp", "upload work to the platform". Do NOT use for general dev questions, git push to GitCode alone, or platform browsing without publishing intent.

installazioni
5
GitHub Stars
50
Aggiornato
23 set
huaweicloud
Community

huawei-cloud-eip-cost-optimizer

Huawei Cloud EIP (Elastic IP) cost optimization skill using hcloud CLI (KooCLI). 1. List and query EIPs across regions with detailed status 2. Identify idle/unbound EIPs and generate cost optimization reports 3. Set up idle EIP monitoring with webhook/email alerts 4. Generate HTML/JSON cost analysis reports 5. Maintain operation audit logs for compliance Read-only analysis only - NO bandwidth adjustment, tag management, or EIP release/deletion. Triggers include: "EIP cost optimization", "idle EIP analysis", "EIP audit", "cost report", "EIP status query", "EIP list", "EIP monitoring", "EIP alert", "cost analysis", "idle monitoring", "operation audit", "EIP 成本优化", "闲置 EIP 分析", "EIP 审计", "成本报告", "EIP 状态查询", "EIP 查询", "EIP 列表", "EIP 监控", "EIP 告警", "成本分析", "闲置监控", "操作审计"

installazioni
1
GitHub Stars
50
Aggiornato
22 set
huaweicloud
Community

huawei-cloud-flexus-l-deploy-jiuwenswarm

One-click deployment of JiuwenSwarm multi-Agent collaboration platform on Huawei Cloud Flexus L instances. Usage scenarios: When users need to quickly deploy JiuwenSwarm/JiuwenClaw on Huawei Cloud Flexus L instances, when they need to automatically create cloud instances and deploy AI Agent platforms, when they need to configure model APIs and message channels (Xiaoyi/Feishu/DingTalk). Automatically create instances, deploy applications via COC, configure models and message channels. Trigger keywords: JiuwenSwarm deployment, JiuwenClaw deployment, 九问Swarm部署, 九问Claw部署, 一键部署JiuwenSwarm, AI智能体平台部署, 部署九问Swarm, 部署九问Claw,云服务器部署AI平台.

installazioni
1
GitHub Stars
50
Aggiornato
22 set
huaweicloud
Community

huawei-cloud-flexus-l-server-flexusagent-deployment

Deploy AI Agent development platform (Dify) on Huawei Cloud Flexus L instance, providing deployment operations, password management, MaaS model configuration, and workflow import capabilities. Trigger keywords: deploy flexusagent/一键部署Flexus AI Agent开发平台、change password/修改开发平台管理员密码、change dify password/修改dify平台密码、add maas provider/添加MaaS模型供应商、configure maas model/配置MaaS模型、view workflow/查看AI Agent工作流、import workflow/导入AI Agent工作流

installazioni
1
GitHub Stars
50
Aggiornato
22 set