Install
openclaw skills install @erickeyhu-hug/huawei-cloud-swr-image-managementHuawei Cloud SWR (Software Repository for Container) image lifecycle management skill using hcloud CLI. Use this skill when the user wants to: (1) manage SWR namespaces (organizations) - create/query/delete, (2) manage image repositories - create/query/update/delete, (3) manage image tags/versions - query/create/delete, (4) obtain docker login credentials for SWR, (5) check SWR quotas and usage limits. Trigger: user mentions "SWR image management", "SWR 镜像管理", "container image", "镜像仓库", "SWR 组织", "SWR namespace", "镜像版本", "docker login", "SWR 配额", "SWR tag", "容器镜像", "镜像生命周期", "SWR repository", "SWR 登录", "SWR quota"
openclaw skills install @erickeyhu-hug/huawei-cloud-swr-image-managementThis skill provides lifecycle management capabilities for Huawei Cloud SWR (Software Repository for Container) images using the hcloud CLI.
Architecture: hcloud CLI → SWR Service API → Namespace/Repository/Tag/Auth/Quota resources
Typical Use Cases:
All write operations (Create, Update, Delete) require explicit user confirmation before execution.
Before executing any write operation, the skill must:
Write operations requiring confirmation:
| Operation | Command | Risk Level | Description |
|---|---|---|---|
| Create namespace | CreateNamespace | Medium | Creates a new SWR namespace (consumes quota) |
| Create repository | CreateRepo | Medium | Creates a new image repository |
| Update repository | UpdateRepo | Medium | Changes repository visibility (public/private) |
| Delete namespace | DeleteNamespaces | High | Deletes namespace AND all repos/images under it |
| Delete repository | DeleteRepo | High | Deletes repository AND all image tags permanently |
| Delete tag | DeleteRepoTag | High | Deletes image tag permanently (irreversible) |
hcloud version to verify installationprintf "y\n" | hcloud version to accept privacy statementhcloud CLI supports two credential modes via environment variables, automatically detected at runtime:
Mode A — Long-term AK/SK (permanent access):
export HUAWEI_CLOUD_AK=<your-ak>
export HUAWEI_CLOUD_SK=<your-sk>
export HUAWEI_CLOUD_REGION=cn-north-4
Mode B — Temporary AK/SK + SecurityToken (recommended for temporary or delegated access):
export HUAWEI_CLOUD_AK=<your-temp-ak>
export HUAWEI_CLOUD_SK=<your-temp-sk>
export HUAWEI_CLOUD_SECURITY_TOKEN=<your-security-token>
export HUAWEI_CLOUD_REGION=cn-north-4
When
HUAWEI_CLOUD_SECURITY_TOKENis present, hcloud CLI automatically uses temporary credential authentication. When only AK/SK are set, it uses long-term credential authentication.
echo $HUAWEI_CLOUD_AK or echo $HUAWEI_CLOUD_SK to check credentialsHUAWEI_CLOUD_AK, HUAWEI_CLOUD_SK, HUAWEI_CLOUD_REGION, HUAWEI_CLOUD_SECURITY_TOKEN⚠️ Important Security Notes:
| API Action | Permission | Purpose |
|---|---|---|
swr:namespace:create | Create namespace | Create SWR organizations |
swr:namespace:list | List namespaces | Query all namespaces |
swr:namespace:get | Get namespace | View individual namespace information |
swr:namespace:delete | Delete namespace | Remove organizations |
swr:repository:create | Create repo | Create image repositories |
swr:repository:list | List repos | Query image repositories |
swr:repository:get | Get repo | View repository details |
swr:repository:update | Update repo | Modify repository properties |
swr:repository:delete | Delete repo | Remove image repositories |
swr:tag:list | List tags | Query image tags/versions |
swr:tag:get | Get tag | View specific tag details |
swr:tag:create | Create tag | Create image tag |
swr:tag:delete | Delete tag | Remove image tag |
swr:login:get | Get login token | Obtain docker login credentials |
swr:quota:get | Get quota | Check resource quotas |
See IAM Permission Policies for complete policy JSON.
Permission Failure Handling:
references/iam-policies.mdAll commands follow the standard hcloud KooCLI format:
hcloud SWR <Operation> --param1=value1 --param2=value2 --cli-region=<region>
Key conventions:
SWR (uppercase, matches KooCLI Services listing)ShowNamespace, CreateRepo, ListRepoTags)--cli-region=<value> (default: cn-north-4, or HUAWEI_CLOUD_REGION env var)--cli-output=json (for agent processing)--cli-query="<expression>" (to reduce output)--key={subkey:value}Example — read operation:
hcloud SWR ShowNamespace --namespace=pancake --cli-region=cn-north-4 --cli-output=json
Example — write operation (requires user confirmation):
# Step 1: Display command and parameters for user confirmation
# Step 2: After user confirms, execute:
hcloud SWR CreateNamespace --namespace=my-project --cli-region=cn-north-4
See Task: Namespace Management for detailed workflows.
# List all namespaces
hcloud SWR ListNamespaces --cli-region=cn-north-4
# List namespaces with filter
hcloud SWR ListNamespaces --filter="namespace::group-dev|mode::visible" --cli-region=cn-north-4
# Show namespace details
hcloud SWR ShowNamespace --namespace=group-dev --cli-region=cn-north-4
# Create a namespace
hcloud SWR CreateNamespace --namespace=group-dev --cli-region=cn-north-4
# Delete a namespace (CAUTION: removes all repos under it)
hcloud SWR DeleteNamespaces --namespace=group-dev --cli-region=cn-north-4
Namespace Naming Rules:
See Task: Repository Management for detailed workflows.
# List all repositories
hcloud SWR ListReposDetails --cli-region=cn-north-4
# List repositories in a namespace
hcloud SWR ListReposDetails --namespace=group-dev --cli-region=cn-north-4
# List repositories with pagination and sorting
hcloud SWR ListReposDetails --namespace=group-dev --limit=20 --offset=0 --order_column=updated_time --order_type=desc --cli-region=cn-north-4
# List repositories by category
hcloud SWR ListReposDetails --category=database --cli-region=cn-north-4
# Show repository details
hcloud SWR ShowRepository --namespace=group-dev --repository=nginx --cli-region=cn-north-4
# Create a repository
hcloud SWR CreateRepo --namespace=group-dev --repository=my-app --is_public=false --category=other --description="Custom app image" --cli-region=cn-north-4
# Update repository (change visibility, description, category)
hcloud SWR UpdateRepo --namespace=group-dev --repository=my-app --is_public=true --description="Updated description" --cli-region=cn-north-4
# Delete a repository (CAUTION: removes all image tags)
hcloud SWR DeleteRepo --namespace=group-dev --repository=my-app --cli-region=cn-north-4
Repository Naming Rules:
Repository Categories: app_server, linux, framework_app, database, lang, other, windows, arm
See Task: Tag Management for detailed workflows.
# List all tags in a repository
hcloud SWR ListRepositoryTags --namespace=group-dev --repository=nginx --cli-region=cn-north-4
# List tags with pagination and sorting
hcloud SWR ListRepositoryTags --namespace=group-dev --repository=nginx --limit=50 --offset=0 --order_column=updated_at --order_type=desc --cli-region=cn-north-4
# Search for a specific tag
hcloud SWR ListRepositoryTags --namespace=group-dev --repository=nginx --filter="tag::v1.0" --cli-region=cn-north-4
# Show tag details (image digest, size, create time)
hcloud SWR ShowRepoTag --namespace=group-dev --repository=nginx --tag=v1.0 --cli-region=cn-north-4
# Create a tag (retag existing image)
hcloud SWR CreateRepoTag --namespace=group-dev --repository=nginx --source_tag=v1.0 --destination_tag=v1.0-stable --override=false --cli-region=cn-north-4
# Delete a tag (CAUTION: removes the image version permanently)
hcloud SWR DeleteRepoTag --namespace=group-dev --repository=nginx --tag=v1.0-old --cli-region=cn-north-4
See Task: Auth Management for detailed workflows.
# Get temporary docker login credentials (valid for 12 hours)
hcloud SWR CreateAuthorizationToken --cli-region=cn-north-4
# Get long-term docker login credentials (valid for 1 year)
hcloud SWR CreateSecret --cli-region=cn-north-4
Response Format (verified against actual API):
The response returns a Docker auth config object:
{
"auths": {
"swr.cn-north-4.myhuaweicloud.com": {
"auth": "base64-encoded-auth-token"
}
}
}
auths: Docker config auth object, registry host as keyauth: Base64-encoded username:password stringDocker Login Command:
# Decode auth field: echo <auth_value> | base64 -d → username:password
docker login -u <decoded_username> -p <decoded_password> swr.cn-north-4.myhuaweicloud.com
See Task: Quota Management for detailed workflows.
# Check SWR quotas
hcloud SWR ListQuotas --cli-region=cn-north-4
See Parameter Reference for detailed parameter tables and valid values per command.
See Output Format Reference for JSON response formats of all SWR API commands.
See Verification Method for step-by-step verification.
team-backend, proj-ai)is_public=false for internal images; only set is_public=true for images intended for public sharingv1.0, v1.0-stable, latest) and avoid ambiguous tagsCreateRepoTag to create version aliases rather than pushing the same image multiple timesCreateSecret for automation pipelines; use CreateAuthorizationToken for temporary access| Document | Description |
|---|---|
| SWR API Guide | hcloud SWR API reference |
| Parameter Reference | Parameter tables and region IDs |
| Output Format | JSON response formats |
| IAM Permission Policies | Required permissions and policy JSON |
| Verification Method | Step-by-step verification |
| Common Pitfalls | Troubleshooting guides |
| Task: Namespace Management | Namespace workflows |
| Task: Repository Management | Repository workflows |
| Task: Tag Management | Tag workflows |
| Task: Auth Management | Login credential workflows |
| Task: Quota Management | Quota check workflows |
| CLI Installation Guide | hcloud install, config, verify |
| Acceptance Criteria | Correct/error pattern comparison |
This skill manages SWR namespaces, repositories, tags, auth credentials, and quotas via the hcloud CLI. The following operations are not supported by this skill:
This skill provides docker login credentials via CreateAuthorizationToken or CreateSecret, but does not execute docker push or docker pull. After obtaining credentials, use docker CLI directly:
# Step 1: Get login credentials from this skill
hcloud SWR CreateAuthorizationToken --cli-region=cn-north-4
# Decode the auth field to get username:password
# Step 2: Login and push/pull with docker CLI
docker login -u <user> -p <pass> swr.cn-north-4.myhuaweicloud.com
docker push swr.cn-north-4.myhuaweicloud.com/<namespace>/<repo>:<tag>
docker pull swr.cn-north-4.myhuaweicloud.com/<namespace>/<repo>:<tag>
Image security scanning is not provided by this skill. It strongly depends on Huawei Cloud HSS (Host Security Service) and requires an enterprise SWR instance. The StartManualScanning API is only available in enterprise SWR instances, not in basic SWR. This skill covers basic SWR management only and does not include image scanning capabilities.
The SWR API does not provide build history commands. Image build functionality is available only in the SWR Web Console. Use the Huawei Cloud console at https://console.huawei.com/swr to view build history.
The SWR API does not provide an image import operation. To import an external image (e.g., from Docker Hub):
# Step 1: Pull the external image
docker pull docker.io/library/nginx:latest
# Step 2: Get SWR login credentials from this skill
hcloud SWR CreateAuthorizationToken --cli-region=cn-north-4
# Step 3: Tag and push to SWR
docker tag docker.io/library/nginx:latest swr.cn-north-4.myhuaweicloud.com/<namespace>/nginx:latest
docker push swr.cn-north-4.myhuaweicloud.com/<namespace>/nginx:latest
See Verification Method for write operation return values and post-write verification steps.
See SWR API Guide for pagination parameter scope details.
hcloud SWR <Operation> format--limit and --offset for repositories and tags listingSee Common Pitfalls & Solutions for detailed troubleshooting guides.
Quick Reference:
| Pitfall | Symptom | Quick Fix |
|---|---|---|
| Invalid namespace name | 400 Bad Request | Follow naming rules: lowercase, 1-64 chars |
| Namespace not found | 404 Not Found | Verify namespace exists with ShowNamespace |
| Repo already exists | 409 Conflict | Use ShowRepository to check first |
| Tag digest mismatch | Retag fails | Verify source_tag exists with ShowRepoTag |
| Quota exceeded | 403 Quota limit | Check quotas with ListQuotas |
| Auth token expired | Docker login fails | Regenerate with CreateAuthorizationToken |
Tag field name | Tag query returns unexpected structure | Use Tag (capital T) not name |
num_images not tag_count | Repo listing field mismatch | Response uses num_images; --order_column uses tag_count |