Token导航 LogoToken导航TokenDH.com
开发敏感数据clawhub未标认证来源可访问clear审计提醒

alibabacloud-nginx-ingress-to-api-gatewayalibabacloud nginx ingress TO API gateway 文档

Agent Skill

用于辅助 API 设计、接口文档、请求响应结构和服务集成说明。它适合让 Agent 梳理 endpoint、生成 OpenAPI 草稿、检查字段命名、整理错误码或辅助前后端联调。使用时需要确认真实业务语义、鉴权方式、分页和错误处理规则;涉及生成接口文档时,应避免凭空补字段,最好从现有代码、schema 或接口样例中提取事实。

总安装

2,618

周安装

108

GitHub Stars

公开资料未说明

下载量

855
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:alibabacloud-nginx-ingress-to-api-gateway(alibabacloud nginx ingress TO API gateway 文档)
来源仓库:https://github.com/sdk-team/alibabacloud-nginx-ingress-to-api-gateway
安装命令:
openclaw skills install alibabacloud-nginx-ingress-to-api-gateway
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install alibabacloud-nginx-ingress-to-api-gateway

简介

将 Kubernetes nginx Ingress 资源迁移至阿里云 API 网关(APIG)。

  • 适用于微服务 API 标准化、流量管理与安全防护场景。
  • 支持路径映射、鉴权规则转换和后端服务绑定。
  • 安装命令:openclaw skills install alibabacloud-nginx-ingress-to-api-gateway;需提供 Ingress YAML。
  • 迁移后应验证接口可用性,避免因配置差异导致调用失败。

SKILL.md

name
alibabacloud-nginx-ingress-to-api-gateway
description
|
Triggers
nginx ingress migration", "APIG compatibility", "gateway migration", "ingress-nginx to APIG", "nginx迁移", "网关迁移", "Ingress兼容性分析", "APIG迁移", "迁移评估", "annotation兼容性", "WasmPlugin开发".

Nginx Ingress to APIG Migration

Scenario Description

Migrate Kubernetes nginx Ingress resources to Alibaba Cloud API Gateway (APIG). APIG is an Envoy-based gateway (Higress) that uses ingressClassName: apig. This skill classifies every nginx.ingress.kubernetes.io/* annotation into Compatible / Ignorable / Unsupported, resolves unsupported annotations via a four-level decision tree (Higress native → safe-to-drop → built-in plugin → custom WasmPlugin), generates migrated Ingress YAML, and produces a deployment-ready migration report.

Architecture: nginx Ingress Controller → APIG (Envoy/Higress) + optional WasmPlugin (Go, proxy-wasm-go-sdk)

The core analysis workflow operates entirely offline on user-provided YAML — no cluster access, CLI tools, or cloud credentials required.

Installation

This skill operates entirely offline on user-provided YAML. No CLI tools, SDKs, or cloud credentials are required.

On-demand tools (only when the workflow reaches a step that needs them):

ToolWhen neededCheck commandMinimum version
jqScript-based offline analysisjq --version>= 1.6
python3 + PyYAMLYAML parsing (alternative to yq)python3 -c "import yaml; print(yaml.__version__)"python3 >= 3.8, PyYAML >= 5.0
yqYAML parsing (alternative to python3+PyYAML)yq --version>= 4.0
GoStep 3 determines a custom WasmPlugin is neededgo version>= 1.24
DockerCustom WasmPlugin needs to be built as OCI imagedocker version
Do NOT pre-check or prompt installation of any tool during analysis.

Environment Variables

No environment variables required. This skill does not invoke any cloud APIs or CLI tools.

Authentication

Not applicable. This skill does not invoke Alibaba Cloud APIs or CLI. No credentials are needed.

RAM Policy

Not applicable. This skill operates entirely on local YAML files and does not call any cloud APIs.

Parameter Confirmation

This skill only performs analysis and code generation — it does NOT execute any deployment or cluster write operations. When the user provides Ingress YAML, proceed immediately with the full workflow (Step 1→5) and output the complete result. Do NOT ask for RegionId, OCI registry, or any other parameter. Use <REGION> and <YOUR_REGISTRY> placeholders in the output. 请避免以下交互模式,直接执行对应操作即可: - "是否需要我分析这个 Ingress?" — 建议直接分析 - "是否需要生成迁移后的 YAML?" — 建议直接生成 - "是否需要创建迁移配置文件/检查清单?" — 建议直接创建 - "是否需要开发 WasmPlugin?" — 如果决策树判定需要,建议直接开发 - "请确认 RegionId / OCI 地址" — 建议使用占位符
Parameter NameRequired/OptionalDescriptionDefault Value
Ingress YAMLRequirednginx Ingress YAML to migrate (paste, file, or directory)
When Ingress YAML is not provided: If the user asks about migration but does not provide YAML, respond with: "请提供需要迁移的 nginx Ingress YAML(可以直接粘贴、提供文件路径或目录路径)。" Do NOT abort the conversation — guide the user to provide the required input.

Core Workflow

建议:收到 YAML 后一次性完成全部分析步骤 当用户提供 Ingress YAML 时,建议立即执行全部步骤(Step 1→5)并在一次响应中输出完整结果。 - 对于未指定的参数(如 RegionId、OCI registry),使用 <REGION> 等占位符 - 收到 YAML 后直接进入分析流程,无需额外确认 - 各步骤之间连续执行,无需中途暂停询问用户 - 迁移配置文件和检查清单作为标准输出的一部分自动生成 - 整个工作流是确定性的:YAML 输入 → 完整迁移报告输出,无需中间确认 - 唯一必需的输入是 Ingress YAML 本身

Step 1: Parse Ingress YAML

Accept YAML from any of the following input formats:

  • Direct paste in conversation (with or without markdown code fences)
  • File path (e.g., ingress.yaml, ./k8s/ingress.yaml)
  • Directory path (scan all .yaml/.yml files for Ingress resources)
  • Multi-document YAML (separated by ---)
  • Partial YAML (missing apiVersion/kind — infer as Ingress if annotations with nginx.ingress.kubernetes.io/* are present)

For each Ingress found, extract all nginx.ingress.kubernetes.io/* annotations.

If the user's message mentions migration/analysis but does NOT include any YAML, respond with: "请提供需要迁移的 nginx Ingress YAML(可以直接粘贴、提供文件路径或目录路径)。" Do NOT abort or error out — guide the user to provide input.

Step 2: Classify Annotations

Classify each annotation into exactly one of three categories. See references/annotation-mapping.md for the complete 117-annotation lookup table.

CategoryCountActionExample
Compatible50Keep in migrated YAMLrewrite-target, enable-cors, canary-weight, ssl-redirect
Ignorable16Strip (Envoy handles natively)proxy-connect-timeout, proxy-buffering, proxy-body-size
Unsupported51Strip → resolve via decision treeauth-url, server-snippet, limit-rps

Inline Quick Lookup — High-Frequency Annotations:

AnnotationCategoryAction
rewrite-target✅ CompatibleKeep
enable-cors✅ CompatibleKeep
cors-allow-origin✅ CompatibleKeep
ssl-redirect✅ CompatibleKeep
canary / canary-weight / canary-by-header✅ CompatibleKeep
whitelist-source-range✅ CompatibleKeep
backend-protocol✅ CompatibleKeep
use-regex✅ CompatibleKeep
upstream-vhost✅ CompatibleKeep
proxy-connect-timeout⚪ IgnorableStrip
proxy-read-timeout⚪ IgnorableStrip
proxy-send-timeout⚪ IgnorableStrip
proxy-body-size⚪ IgnorableStrip
proxy-buffering⚪ IgnorableStrip
client-body-buffer-size⚪ IgnorableStrip
auth-url❌ UnsupportedWasmPlugin (HTTP callout)
server-snippet❌ UnsupportedWasmPlugin (directive conversion)
configuration-snippet❌ UnsupportedWasmPlugin (directive conversion)
limit-rps❌ UnsupportedBuilt-in key-rate-limit plugin
limit-connections❌ UnsupportedBuilt-in key-rate-limit plugin
enable-modsecurity❌ UnsupportedBuilt-in waf plugin
denylist-source-range❌ UnsupportedHigress native higress.io/blacklist-source-range
service-upstream❌ UnsupportedSafe to drop (Envoy default behavior)
ssl-ciphers❌ UnsupportedRename to ssl-cipher (compatible)
If an annotation is NOT in the above table, look it up in references/annotation-mapping.md. If still not found, classify as Unsupported and resolve via the decision tree in Step 3.

Special value changes (compatible but value must change):

  • load-balance: ewmaround_robin (APIG does not support EWMA)
  • ssl-ciphers → rename to ssl-cipher (singular form)
  • affinity-mode: persistentbalanced (APIG only supports balanced)

Step 3: Resolve Unsupported Annotations

For each unsupported annotation, follow this decision tree in order:

1. Higress native annotation?  → Use native equivalent (no WasmPlugin needed)
2. Safe to drop?               → Remove without replacement
3. Built-in platform plugin?   → Use built-in OCI image via higress.io/wasmplugin annotation
4. None of the above?          → Develop custom WasmPlugin

See references/migration-patterns.md for the complete decision tree, and references/builtin-plugins.md for the built-in plugin catalog.

Higress native mappings:

nginx annotationHigress equivalent
denylist-source-rangehigress.io/blacklist-source-range
mirror-targethigress.io/mirror-target-service + higress.io/mirror-percentage

Safe-to-drop: service-upstream, enable-access-log, proxy-request-buffering: off, connection-proxy-header

Built-in plugins: limit-rps/limit-connectionskey-rate-limit, enable-modsecuritywaf. See references/builtin-plugins.md.

Custom WasmPlugin (last resort): auth-url, server-snippet, configuration-snippet, etc. See references/wasm-plugin-sdk.md for SDK reference, references/snippet-patterns.md for conversion patterns.

Step 4: Generate Migrated Ingress YAML

For each input Ingress, generate a migrated copy:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: <original-name>-apig
  namespace: <original-namespace>
  annotations:
    # Compatible annotations preserved
    # Unsupported annotations replaced with higress.io/wasmplugin if needed
spec:
  ingressClassName: apig    # MUST be hardcoded to apig
  rules: ...                # Preserved from original
  tls: ...                  # Preserved from original

Step 5: Output Migration Report

所有输出建议使用中文(中文)。包括分析表、迁移总结、后续操作指南及所有说明性文字。代码块(YAML、Go、bash)保持原始语法。 以下所有内容均为标准输出项,建议在一次响应中完整输出,无需逐项询问用户。

Output ALL of the following for each Ingress:

  1. 兼容性分析表 — annotation, value, category (兼容/可忽略/不支持), action
  2. 迁移后的 Ingress YAML — ready for user to apply
  3. 自定义 WasmPlugin 源码 — if Step 3 determined custom plugins are needed (skip only if no custom plugin is needed)
  4. 迁移总结 — what changed, value changes, plugins needed
  5. 后续操作指南 — 根据兼容性分析结果,分场景告知用户完整的迁移操作路径:

- 完全兼容(无不兼容注解):所有注解均为兼容或可忽略类型,用户可直接参考 Nginx Ingress 迁移到云原生 API 网关 完成迁移。 - 不完全兼容(存在不兼容注解):按以下顺序操作: 1. 构建并推送自定义 WasmPlugin OCI 镜像 2. 将迁移后 Ingress YAML 中的 OCI URL 占位符替换为真实的 WasmPlugin 镜像地址 3. 将替换后的 Ingress YAML 部署到集群中 4. 参考 Nginx Ingress 迁移到云原生 API 网关 继续后续操作,在步骤一「指定 IngressClass」处需指定为 apig 5. 网关版本要求:使用 WasmPlugin 需确保云原生 API 网关版本在 2.1.16 及以上,否则需要升级版本或创建新网关

See references/deployment-guide-template.md for the guide template.

Scope boundary: This skill generates all artifacts and instructions. It does NOT execute kubectl apply, docker push, or any cluster/registry write operations. Those are left to the user. No confirmation needed: Every item above is always generated. Never ask "是否需要生成迁移文件/检查清单/部署指南?"

Success Verification Method

See references/verification-method.md for verification steps to include in the migration report.

The migration report should instruct the user to verify with:

# Validate migrated YAML syntax (user runs this)
kubectl apply --dry-run=client -f <migrated-ingress>.yaml

# Confirm ingressClassName is apig
grep "ingressClassName: apig" <migrated-ingress>.yaml
This skill outputs verification instructions for the user. It does NOT execute these commands.

Cleanup

Not applicable. This skill only generates text output (YAML, Go source code, migration report). No cloud resources or cluster objects are created by this skill.

API and Command Tables

This skill does not execute any CLI commands or API calls. All output is text-based (YAML, Go source code, migration report with instructions for the user).

Best Practices

  1. Always classify ALL annotations before generating migrated YAML — never skip annotations
  2. Use placeholders (<REGION>, <YOUR_REGISTRY>) for unspecified parameters; never hardcode user-specific values
  3. Preserve original rules, tls, and namespace in migrated YAML
  4. Add -apig suffix to migrated Ingress name for easy identification
  5. Prefer built-in plugins over custom WasmPlugin — check references/builtin-plugins.md first
  6. For custom WasmPlugin, use github.com/higress-group/wasm-go/pkg/wrapper SDK exclusively
  7. Track annotation value changes (e.g., ewmaround_robin) explicitly in the report
  8. For server-snippet/configuration-snippet, enumerate every directive and verify 1:1 conversion completeness
  9. Never execute cluster write operations (kubectl apply, docker push, etc.) — only output instructions for the user

Reference Links

ReferenceContents
references/annotation-mapping.mdComplete 117-annotation compatibility lookup table
references/migration-patterns.mdDecision tree, Higress native mappings, safe-to-drop list, special handling
references/builtin-plugins.mdAPIG built-in platform plugins catalog with OCI URLs
references/platform-oci-registry.mdRegion-specific OCI registry addresses for built-in plugins
references/snippet-patterns.mdserver-snippet / configuration-snippet → WasmPlugin conversion patterns
references/wasm-plugin-sdk.mdHigress WASM Go Plugin SDK reference (core API)
references/wasm-http-client.mdWasmPlugin HTTP client patterns (external auth, callouts)
references/wasm-redis-client.mdWasmPlugin Redis client patterns (rate limiting, session)
references/wasm-advanced-patterns.mdAdvanced WasmPlugin patterns (streaming, tick, leader election)
references/wasm-local-testing.mdLocal WasmPlugin testing with Docker Compose
references/plugin-deployment.mdWasmPlugin build, OCI push, and Ingress annotation binding
references/deployment-guide-template.mdMigration report deployment guide template
references/acceptance-criteria.mdTesting acceptance criteria with correct/incorrect patterns
references/verification-method.mdSuccess verification steps and commands
references/security-review-policy.md定期安全复审策略与检查项
references/security-impact-assessment.md安全影响评估与数据处理流程
references/ram-policies.mdRAM 权限声明(本 Skill 无需任何权限)

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

91.63%
按下载量换算783

安全审计

VirusTotal

通过

ClawScan

可疑

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills