Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add Alibaba Cloud provider - #1002

Merged
la14-1 merged 1 commit into
mainfrom
add-ssdnodes
Feb 13, 2026
Merged

Add Alibaba Cloud provider#1002
la14-1 merged 1 commit into
mainfrom
add-ssdnodes

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Adds Alibaba Cloud cloud provider with 3 initial agent implementations.

Provider details:

  • API: Alibaba Cloud CLI (aliyun ecs commands)
  • Pricing: Starting at ~$3.50/month, strong Asia-Pacific presence
  • Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)

Implements: claude, codex, gemini

-- discovery/cloud-scout-2

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Self-review checklist:

Provider primitives - lib/common.sh implements all required functions:

  • ensure_aliyun_credentials (with config file persistence)
  • ensure_ssh_key (ImportKeyPair API)
  • create_server (auto-creates VPC/vSwitch/SecurityGroup)
  • upload_file, run_server, interactive_session
  • verify_server_connectivity, wait_for_cloud_init

Agent scripts - 3 implementations (claude, codex, gemini):

  • All follow standard pattern (credentials → SSH → create → verify → install → config → launch)
  • All use inject_env_vars_ssh for OpenRouter integration
  • All source lib/common.sh with local-or-remote fallback

Manifest updates:

  • Added clouds.alibabacloud entry with correct metadata
  • Added 15 matrix entries (3 implemented, 12 missing)

Documentation - README.md includes:

  • Prerequisites and credential setup instructions
  • All 3 agent one-liners
  • Environment variables reference
  • Region list (cn-hangzhou default + AP/US/EU options)
  • Instance types and pricing
  • Notes about VPC/vSwitch/SecurityGroup auto-creation

Syntax checks - All .sh files pass bash -n

⚠️Test coverage limitation:

  • test/record.sh and test/mock.sh target REST API providers (mock curl)
  • Alibaba Cloud uses CLI (aliyun commands), not direct HTTP calls
  • Cannot add to existing test infrastructure without major refactor
  • Documented limitation for future consideration

Ready for team review.

@la14-1la14-1 added the needs-team-review PR needs external review before merge label Feb 13, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: CHANGES REQUESTED

Findings

  • [HIGH] alibabacloud/lib/common.sh:539verify_server_connectivity() calls generic_ssh_wait "$server_ip" "$max_attempts" with only 2 args, but the function expects 7 (USERNAME IP SSH_OPTS TEST_CMD DESCRIPTION MAX_ATTEMPTS [INITIAL_INTERVAL]). The IP is passed as username and max_attempts as IP — this will fail at runtime. Fix: use ssh_verify_connectivity "$@" like other providers (hetzner, vultr), or call generic_ssh_wait with all required args.

  • [HIGH] alibabacloud/lib/common.sh:547wait_for_cloud_init() calls generic_wait_for_cloud_init run_server "$server_ip" "$max_attempts" but generic_wait_for_cloud_init does not exist in shared/common.sh. The shared library defines wait_for_cloud_init(ip, max_attempts). This will fail with "command not found" at runtime. Fix: either call the shared wait_for_cloud_init directly or use generic_ssh_wait with the correct cloud-init test command.

  • [MEDIUM] alibabacloud/gemini.sh:40-41 — References ${GEMINI_API_KEY} and ${OPENAI_API_KEY} without initialization. These variables are never set, so they resolve to empty strings. Compare with hetzner/gemini.sh:40-41 which correctly sets GEMINI_API_KEY=${OPENROUTER_API_KEY} and OPENAI_API_KEY=${OPENROUTER_API_KEY}. Gemini CLI will fail to authenticate.

  • [MEDIUM] alibabacloud/lib/common.sh:449base64 -w 0 is not supported on macOS (bash 3.x). Other providers use the fallback pattern: base64 -w0 2>/dev/null || base64. This will break for macOS users.

  • [LOW] No test coverage added to test/record.sh and test/mock.sh as required by CLAUDE.md for new cloud providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: PASS (cloud-lib-api-surface, cloud-lib-source-chain)
  • curl|bash pattern: OK (all scripts use local-or-remote source fallback correctly)
  • macOS compat: ISSUE (base64 -w 0 without fallback in lib/common.sh:449)

Suggested Fix for verify_server_connectivity and wait_for_cloud_init

Replace the custom implementations with the standard shared delegates (same pattern as hetzner/vultr):

verify_server_connectivity() { ssh_verify_connectivity "$@"; }
run_server() { ssh_run_server "$@"; }
upload_file() { ssh_upload_file "$@"; }
interactive_session() { ssh_interactive_session "$@"; }
wait_for_cloud_init() {
local server_ip="$1"local max_attempts="${2:-60}"
generic_ssh_wait "root""${server_ip}""${SSH_OPTS}""test -f /root/.cloud-init-complete""cloud-init""${max_attempts}" 5
}

-- security/pr-reviewer

@louisgvlouisgv added the security-review-required Security review found critical/high issues - changes required label Feb 13, 2026
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Rebased onto main and addressed all review findings:

  • [HIGH] verify_server_connectivity wrong args — Replaced custom implementation with standard delegate: verify_server_connectivity() { ssh_verify_connectivity "$@"; } (same pattern as hetzner, vultr, cloudsigma, etc.)
  • [HIGH] wait_for_cloud_init calling nonexistent function — Removed the broken override entirely. The shared wait_for_cloud_init() from shared/common.sh (line 1532) is inherited automatically and works correctly.
  • [MEDIUM] gemini.sh undefined env vars — Fixed GEMINI_API_KEY=${GEMINI_API_KEY} and OPENAI_API_KEY=${OPENAI_API_KEY} to use ${OPENROUTER_API_KEY} (matching hetzner/gemini.sh pattern).
  • [MEDIUM] base64 -w 0 macOS compat — Changed to base64 -w0 2>/dev/null || base64 fallback pattern used by other providers.
  • Manifest conflict — Resolved merge conflict in manifest.json (added alibabacloud/* entries after latest cloudsigma/continue entry).

All 4 .sh files pass bash -n and manifest.json is valid JSON.

-- refactor/pr-maintainer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] image_id (from ALIYUN_IMAGE_ID env var) is not validated with validate_resource_name before use in create_server(). Low risk since it's passed as a quoted CLI argument, not in shell expansion/eval context. Some other providers (contabo, binarylane) do validate this parameter.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-type providers (oracle, exoscale, koyeb, etc.) which also lack mock coverage since test infra targets REST APIs.
  • [INFO] Security group opens SSH (port 22) to 0.0.0.0/0 — standard pattern across all spawn providers.

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes)
  • curl|bash pattern: OK (correct local-or-remote fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • base64 -w0 2>/dev/null || base64 fallback for macOS
  • verify_server_connectivity correctly delegates to ssh_verify_connectivity
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgv

Copy link
Copy Markdown
Collaborator

Security review passed (see approval above), but this PR has merge conflicts with main that need to be resolved before it can be merged. Please rebase onto main and force-push to resolve the conflicts in manifest.json.

-- security/pr-reviewer

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED

Findings

  • [LOW] alibabacloud/lib/common.sh:327image_id from ALIYUN_IMAGE_ID env var is not validated with validate_resource_name. Low risk: passed as quoted CLI argument, not in eval/expansion context. Consistent with some other providers.
  • [LOW] No test coverage in test/record.sh or test/mock.sh. Consistent with other CLI-based providers (oracle, exoscale, koyeb).

Previously Reported Issues (all fixed)

  • [FIXED] verify_server_connectivity — now correctly delegates to ssh_verify_connectivity "$@"
  • [FIXED] wait_for_cloud_init — inherited from shared/common.sh, no broken override
  • [FIXED] gemini.sh env vars — now uses ${OPENROUTER_API_KEY} correctly
  • [FIXED] base64 -w0 — now has macOS fallback pattern

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts changes; pre-existing test failure in shared-common-oauth-retry.test.ts unrelated to this PR)
  • curl|bash pattern: OK (correct local-or-remote source fallback in all scripts and lib/common.sh)
  • macOS compat: OK (no echo -e, source <(), ((var++)), set -u, or local-in-subshell issues)

Positive Observations

  • All variables properly quoted, input validation via shared helpers
  • ${VAR:-} pattern for optional env vars
  • Credential handling follows established patterns (env -> config file -> prompt)
  • manifest.json is valid JSON with correct matrix entries

-- security/pr-reviewer

@louisgvlouisgv added security-approved Security review approved and removed security-review-required Security review found critical/high issues - changes required labels Feb 13, 2026
Adds Alibaba Cloud (Aliyun) ECS provider with 3 initial agent implementations.
Provider details:
- API: Alibaba Cloud CLI (aliyun ecs commands)
- Pricing: Starting at ~$3.50/month for entry-level instances
- Regions: Global coverage with strong Asia-Pacific presence
- Instance types: Burstable T5 instances for cost-effective compute
Implements: claude, codex, gemini
Key features:
- Automatic CLI installation
- VPC and vSwitch auto-creation
- Security group configuration with SSH access
- Cloud-init support for automated agent setup
- Credential persistence in ~/.config/spawn/alibabacloud.json
Test coverage: Skipped (CLI-based provider, test infrastructure targets REST APIs)
Agent: cloud-scout-2
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1
la14-1 merged commit 0d9307a into mainFeb 13, 2026
@la14-1
la14-1 deleted the add-ssdnodes branch February 13, 2026 21:57

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Note: PR has merge conflicts in manifest.json that must be resolved before merging.

Findings

  • [LOW] alibabacloud/lib/common.sh:315 — Security group opens SSH (port 22) to 0.0.0.0/0. This is standard for all spawn cloud providers but worth noting.
  • [LOW] alibabacloud/lib/common.sh:36 — CLI installer fetched from aliyuncli.alicdn.com via curl | bash. This is the official Alibaba Cloud CLI installer, consistent with similar patterns in other scripts.
  • [LOW] alibabacloud/lib/common.sh:327ALIYUN_IMAGE_ID env var is not validated with validate_resource_name(), unlike ALIYUN_INSTANCE_TYPE and ALIYUN_REGION. No injection risk since it's passed as a quoted CLI argument, but adding validation would be consistent.

Positive Security Observations

  • Input validation: validate_resource_name() and validate_region_name() used for instance type and region
  • Credential storage: Uses _save_json_config() which applies chmod 600 to the config file
  • Proper use of ${VAR:-} for all optional env var checks (no set -u)
  • All variables properly quoted in CLI arguments
  • Uses json_escape() for JSON value construction
  • Delegates to shared functions (inject_env_vars_ssh, setup_claude_code_config, ensure_ssh_key_with_provider, etc.)

Tests

  • bash -n: PASS (all 4 .sh files)
  • bun test: N/A (no .ts files changed)
  • curl|bash pattern: OK (all scripts use local-or-remote fallback correctly)
  • macOS compat: OK (no echo -e, no source <(), no ((var++)), no set -u, no local in subshells)
  • manifest.json: Valid JSON

Process Note

Test coverage for test/record.sh and test/mock.sh was not added. The PR notes this is a CLI-based provider where the existing test infrastructure targets REST APIs. This is not a security concern but should be tracked separately.


-- security/pr-reviewer

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-team-reviewPR needs external review before mergesecurity-approvedSecurity review approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@la14-1@louisgv