Install
openclaw skills install @volc-sdk-team/volcengine-tlsUse when operating Volcengine TLS (日志服务) through volclog in agent or CI sessions and you need a contract-first workflow for runtime selector resolution, discover/describe/exec routing, App resource or Topic resolution, envelope reading, large-result delivery, and error recovery without guessing commands, fields, or shortcut flows. 当用户提到火山引擎日志服务 TLS、volclog、日志检索/分析/导入/导出、 日志项目或日志主题等操作时调用。
openclaw skills install @volc-sdk-team/volcengine-tlsAdapted from
volclog-coreinvolcengine-tls/ve-tls-cli(Apache-2.0). Command examples keep the upstream nativevolclog ...form; run them asve volclog ...(requiresve >= 1.1.11) with all later arguments unchanged.
Use this skill only for agent-only incremental knowledge.
Treat this file as the dominant generic operating model for volclog, not as an environment-specific bootstrap note and not as an API reference. This file is the behavior summary; references are the authoritative detail. If volclog tool describe ... or volclog workflow describe ... already answers the question, stop and follow that contract instead of adding duplicate guidance here.
tool describe or workflow describe as the contract truth source. Read tool describe or workflow describe first.--profile <name>, one-shot --secrets-file, context.secrets_file, or process-scoped environment credentials.tool for published public APIs, workflow for CLI-owned orchestration, and raw only when method/path is already known.tool; use workflow app.resolve-resources or app.resolve-topic-ids only for CLI-owned cross-call expansion.--input '{...}' when tool exec or workflow exec already supports it.volclog configure list only when local profile discovery is actually relevant.region only when the contract or task explicitly requires an override. Do not infer it from endpoint or domain.--profile/context.profile and --secrets-file/context.secrets_file are runtime selectors, not business input fields.Discover -> Describe -> Exec -> Read Result
volclog configure listvolclog tool listvolclog tool list <group>volclog workflow list <group>volclog tool describe <group.action>volclog tool describe <group.action> --view full when authoring a nested request or when compact output omits an expected optional fieldvolclog workflow describe <group.command>volclog tool exec <group.action> --input '{...}'volclog workflow exec <group.command> --input '{...}'volclog raw --method <METHOD> --path <PATH> --body '{...}'status ("success" or "failed")summary.deliveryModeerror object (when status is "failed")data (when status is "success")tool describe or workflow describe first.contract_cache_hint and contract_digest come from tool describe or workflow describe output. Read contract_cache_hint.safe_scope and contract_cache_hint.refresh_when, and reuse cached results only while the same CLI build still reports the same contract_digest.volclog tool list <group> or volclog workflow list <group> before guessing.risk, recovery, and usage_constraints override the generic recovery map below.high-risk-retry as a warning that retrying is high risk. After an ambiguous result, reconcile only through a get/describe/list action named by the contract; otherwise stop and escalate instead of retrying automatically.tool describe or workflow describe.tool exec or workflow exec request into flag-heavy shortcut form just because the shell path looks shorter.volclog output into jq or grep just to rediscover schema or field paths.--jmes-filter only when you already know the envelope path you want.--dry-run before any write or destructive change, but only on raw, tool exec, or workflow exec.--dry-run as contract or plan validation, not proof that the business query is correct.Use this table as the default first response after a failed envelope only after reading the operation's risk, recovery, and usage_constraints. The operation contract takes precedence. Read references/best-practices.md only when you need runtime-specific detail beyond the quick action below.
| Signal | Next action |
|---|---|
error.kind=validation | Go back to describe and fix shape or selector problems first. |
error.kind=auth or 401 | Re-check runtime selector, then credentials, then endpoint or region override. |
403 Forbidden | Re-check tenant or profile alignment before widening the permission search. |
error.kind=usage | Re-run tool list or workflow list; do not invent aliases. |
error.kind=unsupported_feature | Read error.hint, then remove the unsupported flag or switch to the named surface; non-LogApp Topic resolution should switch to app.resolve-resources. |
error.kind=incompatible_flags | Remove one conflicting flag and rerun. |
error.kind=filesystem | Fix --output-dir, local path, or permissions before retrying. |
error.kind=decode | Read error.hint, remove the wrong filter or projection if present, then rerun unfiltered or with --trace-dir. |
error.kind=server | Read error.code and error.requestId; retry with backoff only when the operation contract permits it and the failure is clearly transient. |
error.kind=config | Run volclog doctor for host-side configuration checks, then inspect the reported runtime issue. |
error.kind=unknown | Read error.hint first, then error.message or error.details, and rerun with --dry-run or --trace-dir only if more detail is still needed. |
ResultStatus=incomplete | Narrow the time window and rerun before trusting counts or emptiness. |
volclog doctor checks host/runtime configuration such as credentials, endpoint, and local setup. It does not replace describe, and it does not validate business query semantics.
--output-dir.summary.deliveryMode tell you what actually happened at runtime.outputMode, deliveryMode, file delivery, and --jmes-filter semantics instead of duplicating them here.| Need | Prefer |
|---|---|
| Public API contract already chosen | volclog tool describe <group.action> / volclog tool exec <group.action> |
| CLI workflow already chosen | volclog workflow describe <group.command> / volclog workflow exec <group.command> |
| Need to discover action or workflow ids | volclog tool list <group> / volclog workflow list <group> |
| Need help choosing the surface | read references/routing.md |
| Need multi-step execution order | read references/sops.md |
| Resolve an App resource graph | volclog workflow describe app.resolve-resources / volclog workflow exec app.resolve-resources |
| Resolve Topic IDs for a LogApp App | volclog workflow describe app.resolve-topic-ids / volclog workflow exec app.resolve-topic-ids |
| Need runtime/error/recovery semantics | read references/best-practices.md |
| Use an exact method/path | volclog raw --method ... --path ... |
| Authenticate a stateless run | host-selected local profile -> one-shot --secrets-file or context.secrets_file |
| Need contract reuse safety | reuse cached results only while the same CLI build still reports the same contract_digest |