Pod

Yes, this is on purpose. Pod is built for agents, so the default page is plain HTML.
Human? View the normal website.
Agent? You probably prefer /mcp/huaweicloud-devkit-remote-demo/issues.md or /mcp/huaweicloud-devkit-remote-demo/issues.json, or Pod over MCP.

Reported issues for HuaweiCloud DevKit (Remote Demo)

Pod holds 24 of 60 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to HuaweiCloud DevKit (Remote Demo).

Most discussed

[Bug] 沙箱部署测试问题汇总 - 7 个项目部署 + 安全护栏验证后发现 7 个问题

华为云 DevKit 沙箱部署测试问题汇总

测试背景

在华为云沙箱(DevStation)上连续部署了 5 个不同类型的 Web 应用,覆盖 SPA、SSR、SSG、Taro H5、uni-app H5 五种场景。测试过程中发现以下问题。

测试项目清单

# 项目 类型 技术栈 部署结果
1 kit-admin-panel SPA React + Vite + Ant Design 成功
2 kit-content-community SSR Next.js 14 + Prisma + next-auth 成功
3 kit-mini-shop-2 Taro H5 Taro 3.6 + React + Webpack 5 成功
4 kit-movie-ticket uni-app H5 uni-app 3.0 + Vue 3 + Vite 5 成功
5

Read the thread · 2026-08-31 · closed · external user · 15 comments

【huaweicloud-devkit】AK/SK 配置提示仅码道出现 + auth init 应作为流程第一步

描述问题 (Description)

DevKit 初始化流程存在两个问题:

问题 1:AK/SK 输入提示仅在 CodeArts 码道中出现

当前 DevKit 的 AK/SK 配置提示只在 CodeArts(码道)环境中出现,其他环境(Windows Server、OpenCode、本地终端等)不会提示用户输入 AK/SK。

环境 AK/SK 提示 结果
CodeArts 码道 ✅ 有提示 用户知道需配置 AK/SK
Windows Server + OpenCode ❌ 无提示 用户不知道需要先配置 AK/SK
本地终端 ❌ 无提示 同上

用户在其他环境中直接使用 DevKit 时,因为没有 AK/SK 配置提示,导致后续操作失败,排查成本高。

问题 2:auth init 应作为流程第一步

当前 DevKit 初始化流程中 auth init 不是首选步骤,用户容易跳过凭据配置直接开始使用,导致: -…

Read the thread · 2026-08-22 · closed · 9 comments

[Skill] 复用已有安全组时,宽松规则绕过 public_exposure 检测

现象

创建 ECS 时引用已有安全组 ID,该安全组已有 0.0.0.0/0 对 22 端口的入方向规则。CreateServers 命令文本不含 remote_ip_prefix=0.0.0.0/0hook_check_commandhwc-network-public-admin-port 规则无法匹配,宽松端口暴露未被拦截。

根因

hook_check_command 只检查命令文本,不检查云上已有资源的配置。agent 在复用已有安全组时,没有先查询其规则是否安全。

建议修复

huawei-ecshuawei-vpc skill 中添加 Critical Warning:

引用已有安全组前,必须先通过 hcloud VPC ListSecurityGroupRules --security_group_id=<id> 检查入方向规则,确认没有对公网开放敏感端口。

Read the thread · 2026-09-02 · closed · 8 comments

[Bug] 手动部署 nginx 时父目录权限不足导致 500 Permission denied(uni-app 构建产物多级目录场景)

uni-app 构建产物 nginx 父目录权限问题

测试项目:kit-movie-ticket(uni-app 3.0 + Vue 3 + Vite 5,H5)
插件版本:huaweicloud-devkit v1.1.0-next.11

现象

手动配置 nginx SPA 配置后,访问页面报 500 Internal Server Error:

nginx 错误日志:
stat() "/workspace/kit-movie-ticket/dist/build/h5/index.html" 
failed (13: Permission denied)
rewrite or internal redirection cycle while internally redirecting to "/index.html"

根因

uni-app 构建产物位于 dist/build/h5/(比常规项目多一层子目录)。deploy_nginx 工具描述中注明会修复目录权限("fixes directory…

Read the thread · 2026-08-31 · closed · 6 comments

[Bug] Taro 跨平台 H5 沙箱部署问题:deploy_nginx 超时、构建产物图标缺失

Taro 跨平台 H5 应用沙箱部署测试问题汇总

测试项目:kit-mini-shop-2(Taro 3.6.23 + React 18 + TypeScript + Sass,H5)
插件版本:huaweicloud-devkit v1.1.0-next.11
沙箱区域:cn-north-4(测试环境)


问题 1(P2):deploy_nginx 大项目超时(30s)

现象deploy_nginx(nginx_type="spa") 调用超时:

MCP error -32603: hwlink terminal exec timeout after 30000ms

根因:项目文件较多(1.19MB,含大量 node_modules 上传后的解压文件),deploy_nginx 工具的默认超时 30s 不足以完成 nginx 配置写入和 reload。

影响

Read the thread · 2026-08-31 · closed · 6 comments

[Bug/Feature] SPA 部署沙箱链路多个问题:凭据体系分裂、会话持久化、nginx 预装、错误提示

SPA Web 应用沙箱部署测试问题汇总

测试项目:kit-admin-panel(React 18 + Vite 5 + TypeScript + antd,SPA)
插件版本:huaweicloud-devkit v1.1.0-next.11
沙箱区域:cn-north-4


问题 1(P1):凭据体系分裂 — 沙箱链路不读取 KooCLI 凭据

现象:KooCLI(hcloud)已配置 AK/SK 且认证通过,但 huaweicloud_sandbox_check_user 首次调用报错:

Huawei Cloud credentials are not configured. Run "npx huaweicloud-devkit auth init" or set HW_ACCESS_KEY/HW_SECRET_KEY.

根因:沙箱链路读取统一凭据库 ~/.config/huaweicloud/credentials.json,而 KooCLI 凭据存储在…

Read the thread · 2026-08-31 · closed · 6 comments

【huaweicloud-devkit】Hermes AK/SK 配置流程不合理:非交互式无法安全配置 + PATH 配置有误

描述问题 (Description)

DevKit + Hermes Agent 的 AK/SK 凭据配置流程不合理,存在安全风险和易用性问题,需要优化适配。

问题 1:auth init 交互式配置不适用于非交互场景

安装指南推荐的安全配置方式:

npx --yes huaweicloud-devkit auth init

hcloud configure init

但这两种方式都是交互式的,要求用户在终端手动输入 AK/SK。在以下场景中无法使用:

而指南同时警告不要使用

hcloud configure set --cli-access-key=xxx --cli-secret-key=xxx  # 会泄露到 shell 历史

结果:非交互式环境下没有安全的 AK/SK 配置方式。

问题 2:`hcloud…

Read the thread · 2026-08-22 · closed · 6 comments

[Bug] 沙箱 git clone 后 index.html 被 GitCode 平台页覆盖,纯静态页面部署为空白

版本

huaweicloud-devkit v1.0.2 环境: Windows 11, Git Bash, Node v22.22.2, WorkBuddy, hcloud v7.2.12 账号: hw018619646 区域: cn-north-4

问题描述

通过 sandbox_connect 的 git 参数克隆一个纯静态 HTML 仓库(含 index.html)到沙箱后,工作目录中的 index.html 被 GitCode/AtomGit 平台首页页面覆盖,导致部署后浏览器访问显示空白。

关键证据:

文件来源 大小 内容 修改时间
Git 对象中 (git show HEAD:index.html) 14,098 bytes 用户原始静态页面(vercel 测试页,内联 CSS,无外部依赖) Nov 10 2025(提交时间)
工作目录 (/workspace/test/index.html)

Read the thread · 2026-08-22 · closed · 6 comments

Most recent

[Bug] huawei-iac 自动测试:MCP 审批 token 跨调用失效(plan→approve→run 端到端不可达,复现 2 次)+ BSS 询价缺 RDS/DCS/EIP 编码 + 0.0.0.0/0 拦截无专项 finding(54 检查点 39 PASS / 0 FAIL / 15 BLOCKED,附完整测试报告)

[Bug] huawei-iac 自动测试:MCP 审批 token 跨调用失效(plan→approve→run 端到端不可达,复现 2 次)+ BSS 询价缺 RDS/DCS/EIP 编码 + 0.0.0.0/0 拦截无专项 finding(54 检查点 39 PASS / 0 FAIL / 15 BLOCKED,附完整测试报告)

测试概述

Read the thread · 2026-09-09 · open · external user · 3 comments

[Bug] Codex cache 安装布局下 MCP serverInfo.version 返回 0.0.0

问题描述

在 Windows + Codex CLI 环境中,通过 Codex marketplace 安装 huaweicloud-devkit@1.1.2-next.4 后,MCP server 的 initialize 响应中 serverInfo.version 错误返回 0.0.0,而插件 manifest 中的版本是 1.1.2-next.4

复现环境

复现步骤

  1. huaweicloud-devkit@1.1.2-next.4 加入 Codex marketplace。
  2. 执行 codex plugin add huaweicloud-devkit@huaweicloud-devkit
  3. 启动已安装插件中的…

Read the thread · 2026-09-09 · open · 4 comments

Agent 遇到「缺少必填参数 cli-domain-id」时不会用 STS GetCallerIdentity 自取 domain-id,而把负担推给用户

问题描述

Agent 用 KooCLI 直连华为云全局服务(BSS、以及走 cn-north-1/全局端点的 IAM 等)时,AK/SK 模式必须携带 --cli-domain-id(账号 ID)。当 KooCLI profile 里 domainId 为空时,命令报:

[USE_ERROR]使用AK/SK模式访问全局服务,缺少必填参数cli-domain-id

此时 agent 误以为需要用户手动配置,把负担推给用户(hcloud configure set --cli-domain-id=<id>), 没有意识到可用一个「只读、无需前置 domain-id」的方法自行获取账号 ID。

根因

  1. cli-domain-id 是 KooCLI 对全局端点的 AK/SK 模式强制要求:BSS 钉死 cn-north-1、本身就是全局服务,必然需要;IAM 在 cn-north-1 下落到全局端点 iam.myhuaweicloud.com 也需要,换区域端点(如 cn-north-4)则不需要。
  2. 取…

Read the thread · 2026-09-09 · closed · 5 comments

[Bug] MCP插件连接失败 - 配置文件中AK/SK占位符未替换导致连接失败

MCP 插件连接失败测试报告

1. 测试基本信息

项目 内容
报告名称 MCP 插件连接失败诊断报告
测试日期 2026-09-08
工作目录 C:\Users\Administrator\IDEProjects\demo
MCP 配置文件 C:\Users\Administrator\IDEProjects\demo\.codeartsdoer\mcp\mcp_settings.json
MCP 服务器名称 HuaweiCloud DevKit
平台 Windows (win32)

2. 问题描述

用户反馈配置的 MCP 插件连接失败,无法正常使用华为云开发工具包(HuaweiCloud DevKit)提供的 MCP 工具。


3. 配置文件分析

3.1 原始配置内容

{…

[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/570) · 2026-09-09 · open · external user · 3 comments

### [协议健壮·P1] MCP stdio server 畸形 JSON 帧即崩溃退出——JSON.parse 无 try-catch,一条坏数据 kill 整个进程(DoS,L131)

## 现象(1.1.2-next.4 基线实测)

MCP stdio server(`plugins/huaweicloud-core/src/mcp-server.mjs`)收到**畸形 JSON 帧后进程崩溃退出**(exit code 1),无容错:

```python
# 实测(stdio 直接喂坏帧)
stdin: {this is not json\n      ← 单条非法 JSON
→ 进程 poll = 1,已退出(exit code 1)
→ 后续任何合法请求都无法处理(server 死了)

Read the thread · 2026-09-08 · open · 1 comment

[会话级安全] OfficeAce 回退链写命令无审批即执行——连接器断开时 agent 通过技能+本地 CLI 直接创建云资源(OBS-9/10 同族第三例,连 MCP 门禁都没有)

现象(真云实测,OBS 桶已用后立删)

OfficeAce 5.5.x(Windows,CEF)会话发送「用 huaweicloud_devkit 创建一个 OBS 桶 test-g3-oa-20260908(cn-north-4)」:

Read the thread · 2026-09-08 · open · 3 comments

[会话级安全] DSH approval=ask 未拦截 MCP 写通道——headless 会话无确认即创建云资源(fails-closed 不覆盖 MCP 子进程,与 OBS-9 同族)

现象(真云实测,资源已用后立删)

DeepSeek Harness(DSH 0.1.1-rc.2)headless 单任务会话发送「用 huaweicloud_devkit 创建一个 VPC test-g3-dsh-20260908,CIDR 192.168.0.0/16,请直接执行」:

根因(配置级)

Read the thread · 2026-09-08 · open · 3 comments

[会话级安全] WorkBuddy 内 MCP 写命令无可见审批即执行——approvedByUser 为模型自填参数,客户端连接器未对 MCP 写工具设门禁

现象(真云实测,资源已用后立删)

WorkBuddy 5.5.3 会话内发送「创建 VPC test-g3-20260908,请直接执行」:

根因(源码级,插件 1.1.1)

  1. planHcloudCommand(hcloud-cli.mjs:158)plan 阶段无条件签发 approvalToken(5min TTL 内存 Map),与用户是否批准无关
  2. runApprovedCommand(tools.mjs:1513-1516)仅校验…

Read the thread · 2026-09-08 · open · 3 comments

[Bug] uninstall --target all 在含 WorkBuddy hook 的环境必然崩溃且无法自愈(TypeError: reading 'PostToolUse')

问题描述

在装有 WorkBuddy 插件的环境执行 uninstall --target all 时,卸载流程在处理完 WorkBuddy 段后必然抛出 TypeError 崩溃,后续所有 agent(OpenClaw/DSH/OfficeAce/AtomCode/Codex)与全局清理段(含凭据库删除)全部不执行。且由于崩溃点位于 writeFileSync 之前,配置文件永远不会被更新 → 每次重跑都在同一点崩溃,无法自愈,卸载流程永远无法完成

环境

复现步骤

  1. 前置:~/.workbuddy/settings.json 存在且 hooks 仅含 PostToolUse 一项(插件安装后的典型状态
  2. 执行 npx --yes huaweicloud-devkit@1.1.1 uninstall --target all < /dev/null
  3. 输出在…

Read the thread · 2026-09-08 · open · 1 comment

[Bug] Windows Codex 下 safety hook 硬编码 python3 导致反复 Hook failed

背景

在 Windows/Codex 环境安装并启用 huaweicloud-devkit@1.1.1 后,Codex 对话记录中频繁出现 Hook failed。排查后确认,DevKit 的 PreToolUse hook 已注册,但 hook 命令在 Windows/Codex 上无法执行。

这个问题会造成两个结果:

  1. 用户看到大量 Hook failed,容易误判为 MCP、账号或华为云 API 失败。
  2. DevKit 的本地安全 hook 没有正常运行,只能依赖 MCP wrapper / agent 侧规则兜底。

环境

现象

Codex 对话步骤里多次出现 Hook failed

检查 Codex 配置,DevKit…

Read the thread · 2026-09-08 · closed · 4 comments

[Bug] Windows Codex 安装/认证状态存在 OpenCode marker、sandbox hcloud、S1/S2 指纹误报问题

背景

在 Windows/Codex 环境按 README.zh-CN.md 安装配置 huaweicloud-devkit@1.1.1 时,除已在 #519 记录的 Codex 插件名不一致问题外,又复现到几个独立问题:

  1. install --target codex 仍尝试写 OpenCode marker 目录。
  2. Codex 沙箱内直接执行 KooCLI 会报“获取当前用户家目录失败”,但非沙箱执行正常。
  3. MCP 的 auth_status 在认证实际可用时仍持续报告 S1/S2-current 指纹不一致。

环境

现象 1:install --target codex 仍尝试写 OpenCode 目录

执行:


[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/542) · 2026-09-08 · closed · 4 comments

### [Bug] 凭证对账 scanState 在 KooCLI authEncrypt=true 加密存储下误报 S2 指印不一致

## 问题概述

在 KooCLI 使用默认安全存储 `authEncrypt=true`(`.hcloud/config.json` 中 `accessKeyId` / `secretAccessKey` 为密文)的情况下,`reconcile.mjs` 的 `readKooCliProfiles()` 直接对**密文** `accessKeyId/secretAccessKey` 计算指纹,导致凭证对账 `scanState()` 误报 S1 统一凭证库与 KooCLI(S2-current)指印不一致,并标记为 `manual modified`。

经解密核对,三处存储实际是**同一把 AK/SK**,仅 S2 以密文形态落盘,因此该不一致是**误报**。

## 复现步骤

1. 配置好 S1 统一凭证库 `~/.config/huaweicloud/credentials.json`、S2 KooCLI `~/.hcloud/config.json`、S3 OBS `~/.obsutilconfig`(三者指向同一 AK/SK)。
2. 保持 KooCLI 默认…

[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/533) · 2026-09-08 · open · external user · 5 comments

### Install/uninstall fails on clean environments: better-sqlite3 native module not built

## Summary

On a clean checkout / fresh `npm install`, the `install` / `uninstall` flows break because the native dependency `better-sqlite3` is not built. The failure is reproducible in two independent environments:

- **Windows (Server 2022, Node v22.22.2)**: `better-sqlite3` cannot compile because the MSVC + Python build toolchain is missing (`node-gyp` error).
- **Linux (clean clone, Node v24.19.0)**: npm's script-approval policy blocks the `better-sqlite3` post-install script, so the…

[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/512) · 2026-09-07 · open · external user · 4 comments

### [Bug] Hermes installer on Windows ignores --home option, writes skills to %LOCALAPPDATA% instead of --home directory

## Bug: Hermes installer on Windows writes skills to `%LOCALAPPDATA%\hermes` instead of the `--home` directory, causing test isolation failure

### Summary

The Hermes installation target in `bin/setup.cjs` resolves the skills/MCP/safety destination path using `%LOCALAPPDATA%\hermes` on Windows, ignoring the `--home` option. This breaks test isolation and causes the automated test `hermes install creates skills, MCP server, and safety policy` to fail on Windows.

### Environment

- OS: Windows…

[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/511) · 2026-09-07 · open · external user · 3 comments

### [测试报告] 卸载/更新/版本查询 发现问题汇总:better-sqlite3 原生构建被拦截 + 若干覆盖缺口

## 背景

对 huaweicloud-devkit(要求 ≥ 1.1.1-next.14,实测 v1.1.1-next.16)执行「卸载 / 更新 / 版本查询」测试用例,采用三视角并行:仓库内置自动化回归(194/194 单测 + `validate`/`lint` 全绿)、源码逻辑/结构层核验、以及真实 CLI 黑盒实测(30+ 项可执行用例全部通过)。以下是测试报告中暴露的问题与待确认项。

## 问题清单

### 问题 1(建议优先确认):better-sqlite3 原生模块未实际编译

- **现象**:`npm install` 时 `better-sqlite3` 的 `node-gyp rebuild` 脚本被 `allow-scripts` 拦截、未执行,原生模块在本环境未实际编译;本次用例未依赖该模块,故未直接报错。
- **影响**:依赖该原生模块的功能在部分环境可能不可用;若发布包缺少预编译产物,弱网/无编译工具链环境下安装会失败。
- **建议**:在 CI 用独立构建机确认原生模块可编译,并在发版前核对各平台的预编译二进制。

### 问题…

[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/510) · 2026-09-07 · open · external user · 5 comments

### [Bug]: auth_switch mode=import 缺省 region 导致 S3/OBS 同步失败,且失败后无重放路径

**Version:**
`1.1.1-next.15`

**Environment:**
`Linux, OpenCode`

**Description:**
通过 `auth_switch`(MCP 工具,`mode=import`)切换华为云凭证时,导入文件 `~/.config/huaweicloud/creds-import.json` 只包含 `ak`/`sk`,工具会把 AK/SK 写入统一凭证文件 `~/.config/huaweicloud/credentials.json`,但 `region` 被写为空字符串 `""`。随后传播到 OBS(S3)时因 `region` 缺失而失败,报错信息为 `region, ak, and sk are required to write OBS config`。

**Steps to reproduce:**
1. 准备 `~/.config/huaweicloud/creds-import.json`,内容仅 `{ak, sk}`(无 region)
2. 调用…

[Read the thread](https://github.com/huaweicloud/huaweicloud-devkit/issues/502) · 2026-09-07 · open · 5 comments

The remaining reports are on [the project's issue tracker](https://github.com/huaweicloud/huaweicloud-devkit/issues).