{"id":"fd6c3a16-476e-491c-bc51-f4e58566bc68","entityType":"agent","slug":"clawhub-zw008-minio-aiops","name":"minio-aiops","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-minio-aiops","canonicalPath":"/agent/clawhub-zw008-minio-aiops","generatedAt":"2026-10-10T21:52:42.049Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":null},"description":"Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket). Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment. Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only). Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:minio-aiops","sourceUrl":"https://clawhub.ai/zw008/minio-aiops","homepage":"https://clawhub.ai/zw008/skills/minio-aiops","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zw008/minio-aiops","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zw008/skills/minio-aiops","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"minio-aiops technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":null},"stars":null,"forks":null,"downloads":1294,"packageName":null,"latestVersion":"0.12.3","tractionLabel":"1.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T18:35:19.633Z","lastCrawledAt":"2026-10-10T18:35:19.633Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T18:35:19.633Z","lastVerifiedAt":null,"highlights":[{"version":"0.12.3","createdAt":"2026-09-15T06:04:31.684Z","changelog":"- Removed the file: skill-card.md - No changes to core features, tools, or documentation were made in this release.","fileCount":7,"zipByteSize":19664},{"version":"0.12.2","createdAt":"2026-09-12T14:28:13.360Z","changelog":"- Removed the redundant skill-card.md file for a cleaner repo. - SKILL.md remains unchanged in functionality or content.","fileCount":7,"zipByteSize":19642},{"version":"0.12.1","createdAt":"2026-09-12T10:12:03.599Z","changelog":"- Removed file: skill-card.md. - Documentation update in SKILL.md; no changes to features or functionality. - No breaking changes; all commands and behaviors remain the same.","fileCount":7,"zipByteSize":19869},{"version":"0.12.0","createdAt":"2026-09-12T01:00:38.982Z","changelog":"minio-aiops 0.12.0 - Updated required binaries: now supports either \"minio-aiops\" or \"uvx\" - Added \"anyBins\" to metadata for improved compatibility checks - Expanded \"optional\" environment variables in metadata; moved env var handling into \"optional\" - Removed skill-card.md, consolidating documentation into SKILL.md - No changes to core functionality or toolset","fileCount":7,"zipByteSize":19695},{"version":"0.11.0","createdAt":"2026-08-13T00:27:52.741Z","changelog":"minio-aiops 0.11.0 - Major expansion: now supports 48 tools (was 31), adding WORM/retention and IAM operations. - New flagship tools: diagnose_retention_gaps, diagnose_iam_exposure. - Object lock (WORM) support: read/add lock status, retention settings, legal holds. - IAM user, group, and policy management added with read/write capabilities. - Documentation updated; CLI reference and capabilities now reflect expanded features. - skill-card.md removed.","fileCount":7,"zipByteSize":19354},{"version":"0.9.0","createdAt":"2026-08-10T06:52:02.440Z","changelog":"- Removed documentation file: skill-card.md. - No changes to functionality or user experience. - All core features remain unchanged.","fileCount":7,"zipByteSize":17633},{"version":"0.8.0","createdAt":"2026-08-10T03:58:23.196Z","changelog":"minio-aiops version 0.8.0 - Documentation updates in SKILL.md and CLI reference to reflect latest usage and features. - Removed skill-card.md file. - No user-facing functionality changes; this release focuses on docs and maintenance.","fileCount":7,"zipByteSize":17696},{"version":"0.7.0","createdAt":"2026-08-03T05:53:22.902Z","changelog":"- Removed the documentation file: skill-card.md - No functional or user-facing changes; documentation file only removed.","fileCount":7,"zipByteSize":17557}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:minio-aiops","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:minio-aiops` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/minio-aiops before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T21:52:42.045Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-minio-aiops/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":null},"readme":"Skill: minio-aiops\n\nOwner: zw008\n\nSummary: Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket). Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment. Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only). Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).\n\nTags: latest:0.12.3\n\nVersion history:\n\nv0.12.3 | 2026-09-15T06:04:31.684Z | auto\n\n- Removed the file: skill-card.md\n- No changes to core features, tools, or documentation were made in this release.\n\nv0.12.2 | 2026-09-12T14:28:13.360Z | auto\n\n- Removed the redundant skill-card.md file for a cleaner repo.\n- SKILL.md remains unchanged in functionality or content.\n\nv0.12.1 | 2026-09-12T10:12:03.599Z | auto\n\n- Removed file: skill-card.md.\n- Documentation update in SKILL.md; no changes to features or functionality.\n- No breaking changes; all commands and behaviors remain the same.\n\nv0.12.0 | 2026-09-12T01:00:38.982Z | auto\n\nminio-aiops 0.12.0\n\n- Updated required binaries: now supports either \"minio-aiops\" or \"uvx\"\n- Added \"anyBins\" to metadata for improved compatibility checks\n- Expanded \"optional\" environment variables in metadata; moved env var handling into \"optional\"\n- Removed skill-card.md, consolidating documentation into SKILL.md\n- No changes to core functionality or toolset\n\nv0.11.0 | 2026-08-13T00:27:52.741Z | auto\n\nminio-aiops 0.11.0\n\n- Major expansion: now supports 48 tools (was 31), adding WORM/retention and IAM operations.\n- New flagship tools: diagnose_retention_gaps, diagnose_iam_exposure.\n- Object lock (WORM) support: read/add lock status, retention settings, legal holds.\n- IAM user, group, and policy management added with read/write capabilities.\n- Documentation updated; CLI reference and capabilities now reflect expanded features.\n- skill-card.md removed.\n\nv0.9.0 | 2026-08-10T06:52:02.440Z | auto\n\n- Removed documentation file: skill-card.md.\n- No changes to functionality or user experience.\n- All core features remain unchanged.\n\nv0.8.0 | 2026-08-10T03:58:23.196Z | auto\n\nminio-aiops version 0.8.0\n\n- Documentation updates in SKILL.md and CLI reference to reflect latest usage and features.\n- Removed skill-card.md file.\n- No user-facing functionality changes; this release focuses on docs and maintenance.\n\nv0.7.0 | 2026-08-03T05:53:22.902Z | auto\n\n- Removed the documentation file: skill-card.md\n- No functional or user-facing changes; documentation file only removed.\n\nv0.6.0 | 2026-08-02T09:40:07.444Z | auto\n\nVersion 0.6.0\n\n- Removed the file skill-card.md from the package.\n- No other user-facing changes noted.\n\nv0.5.0 | 2026-07-21T09:41:37.955Z | auto\n\nminio-aiops v0.5.0\n\n- Governance harness documentation clarified: skill no longer claims policy or approval-gate controls; all operations are now always audited with risk tiers described per action.\n- Updated references to highlight that authorization is handled by access key permissions, not by an internal read-only switch or policy file.\n- Reference and setup documentation improved for smaller/local model (agent-guardrails) compatibility.\n- Various explanatory clarifications in tool descriptions, with no changes to the toolset (31 tools total).\n- Obsolete skill-card.md file removed.\n\nv0.4.0 | 2026-07-20T11:15:51.121Z | auto\n\nminio-aiops 0.4.0\n\n- Removed the sample file skill-card.md from the project.\n- No changes to core functionality or features.\n\nv0.3.0 | 2026-07-19T17:34:41.715Z | auto\n\n## minio-aiops v0.3.0\n\n- Removed the file: skill-card.md\n- No functional or API changes noted; this release is limited to file removal and cleanup.\n\nv0.2.1 | 2026-07-19T13:12:47.416Z | auto\n\n- Removed the file skill-card.md from the package.\n- No changes to functionality or behavior; update is limited to documentation cleanup.\n\nv0.2.0 | 2026-07-19T03:51:54.819Z | auto\n\nminio-aiops 0.2.0\n\n- Added undo support: new tools undo_list and undo_apply, bringing the total to 31 tools.\n- Introduced agent guardrails documentation for safer automation and usage in local/low-trust agent settings.\n- Improved documentation structure and skill metadata, including a concise summary, display name, tags, and verification notes.\n- Enhanced read-only mode: setting MINIO_READ_ONLY=1 now hides all write tools and blocks write operations.\n- Removed legacy file (skill-card.md) and updated reference guides for clarity and completeness.\n\nv0.1.0 | 2026-07-17T05:57:44.946Z | auto\n\nminio-aiops 0.1.0 (PREVIEW)\n\n- Initial release: governed MinIO object storage operations with integrated audit, undo, risk-tiers, and policy controls.\n- Features 29 tools (capacity, health, exposure, healing, audits, bucket and policy management, safe write operations).\n- All write operations are double-confirmed, audited, and reversible when possible; secrets are stored encrypted on disk.\n- Flagship analyses: capacity RCA, bucket exposure audit, lifecycle gap analysis, and healing health checks.\n- Standalone package with no external skill-family dependency; for MinIO only (not Ceph/TrueNAS/etc.).\n- Preview version, mock-validated only; not yet tested against live server endpoints.\n\nArchive index:\n\nArchive v0.12.3: 7 files, 19664 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (7259b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (2637b), SKILL.md (18191b), _meta.json (131b)\n\nFile v0.12.3:SKILL.md\n\n---\nname: minio-aiops\nslug: minio-aiops\ndisplayName: \"MinIO AIops\"\nsummary: \"Governed MinIO ops: capacity RCA, exposure audit, ILM, WORM retention, IAM, healing, 48 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/MinIO-AIops\ntags: [aiops, mcp, governance, minio]\ndescription: >\n  Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket).\n  Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment.\n  Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only).\n  Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).\ninstaller:\n  kind: uv\n  package: minio-aiops\nargument-hint: \"[minio question or describe your object-storage task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"minio-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"MINIO_AIOPS_CONFIG\",\"MINIO_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/MinIO-AIops\",\"emoji\":\"🪣\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed MinIO operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency. Works against any reasonably current MinIO server (single-node or distributed/erasure-coded); admin features (quota, server info) need admin-capable keys.\n  All write operations are audited to a local SQLite DB under ~/.minio-aiops/ (relocatable via MINIO_AIOPS_HOME).\n  Connection: the S3 API endpoint (host:port, default 9000; SigV4 via the official SDK), plus the unauthenticated health endpoints (/minio/health/live|ready|cluster) and the cluster metrics endpoint (/minio/v2/metrics/cluster — public mode or the default bearer-token mode; the token is derived from the stored credentials, no extra secret). The access key lives in config.yaml; the secret key is stored ENCRYPTED in ~/.minio-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'minio-aiops init' to onboard, or 'minio-aiops secret set <target>' to add one. The store is unlocked by a master password from MINIO_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var MINIO_<TARGET_NAME_UPPER>_SECRET_KEY is still honoured as a fallback with a deprecation warning (migrate with 'minio-aiops secret migrate'). Secrets are held only in memory, never logged or echoed.\n  State-changing operations require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (budget guard + audit + undo + risk-tier labelling). bucket_delete is high-risk, dry-run + double-confirm, and refused unless the bucket is verifiably empty (including versions and delete markers); remove_incomplete_uploads only aborts uploads older than a safety window. Reversible writes (set/delete bucket policy, set_versioning, set/delete lifecycle, set_bucket_quota) capture the prior state and record an inverse undo descriptor.\n  Webhooks: none — no outbound network calls beyond the configured MinIO endpoint.\n  SSL: secure (https) and verify_ssl default to true; disable verification only for self-signed lab certificates.\n  Transitive dependencies: the official minio SDK, httpx, and the MCP SDK. No post-install scripts or background services.\n  Verification status: validated against mocked SDK/HTTP responses; no recorded end-to-end run against a live MinIO server yet. Erasure-set/healing findings need a multi-drive deployment to observe live (a single-node server running 'minio-aiops doctor' is the cheapest live path). See docs/VERIFICATION.md.\n---\n\n# MinIO AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by MinIO, Inc. or any storage vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops) under the MIT license.\n\nGoverned MinIO object-storage operations — **48 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.minio-aiops/`, a token/runaway budget guard, undo-token recording, and a descriptive risk tier on every audit row. The secret key is stored **encrypted** (`~/.minio-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk. Six flagship analyses turn raw state into plain-language **cause + suggested action**: `capacity_rca`, `bucket_exposure_audit`, `lifecycle_gap_analysis`, `healing_health`, `diagnose_retention_gaps`, `diagnose_iam_exposure`.\n\n> **Standalone**: the governance harness is bundled in the package (`minio_aiops.governance`) — minio-aiops has no external skill-family dependency. Verification status and the live-run checklist are in `docs/VERIFICATION.md`.\n\n> **Authorization is not this tool's job**: whether a write is permitted is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate — the guarantee is that every call is audited. Driving this with a smaller / local model? See `references/agent-guardrails.md`.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read or Write |\n|-------|-------|:-----:|:-------------:|\n| **Health** | health_live, health_ready, health_cluster, cluster_status, fleet_overview | 5 | 5 read |\n| **Capacity** | capacity_rca (flagship), usage_by_bucket | 2 | 2 read |\n| **Healing** | healing_health (flagship), drive_status, node_status | 3 | 3 read |\n| **Exposure / ILM** | bucket_exposure_audit (flagship), lifecycle_gap_analysis (flagship) | 2 | 2 read |\n| **Buckets** | bucket_ls, bucket_info, bucket_policy_get, bucket_lifecycle_get, bucket_versioning_get, bucket_quota_get, object_ls, incomplete_uploads_ls, server_info | 9 | 9 read |\n| **Writes** | set_bucket_policy, delete_bucket_policy, set_versioning, set_lifecycle, delete_lifecycle, set_bucket_quota, bucket_delete, remove_incomplete_uploads | 8 | 8 write |\n| **Object lock (WORM)** | bucket_lock_config, object_lock_status, diagnose_retention_gaps (flagship) | 3 | 3 read |\n| | bucket_create, set_default_retention, clear_default_retention, set_legal_hold, set_object_retention | 5 | 5 write |\n| **IAM** | iam_users, iam_groups, iam_policies, diagnose_iam_exposure (flagship) | 4 | 4 read |\n| | create_user, set_user_status, remove_user, attach_user_policy, detach_user_policy | 5 | 5 write |\n| **Undo** | undo_list, undo_apply | 2 | read + replay |\n\nTotals: **48 tools — 28 read, 18 write, 2 undo.** The MCP server exposes all 48; the CLI is a convenience subset.\n\n## Quick Install\n\n```bash\nuv tool install minio-aiops\nminio-aiops init       # interactive wizard: endpoint + access key + encrypted secret key\nminio-aiops doctor\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/minio-aiops\nopenclaw skills info minio-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- **\"Storage is filling up / writes are failing\"** → `capacity_rca` (capacity vs used, offline drives/nodes, hotspots — cause + action per finding), then `usage_by_bucket` for the biggest consumers\n- **\"Is anything exposed?\"** → `bucket_exposure_audit` (ranked: public read/write policies, missing encryption, versioning off, no lifecycle)\n- **\"Where did my space go?\"** → `lifecycle_gap_analysis` (unbounded noncurrent versions, incomplete multipart uploads, reclaimable estimate) then `remove_incomplete_uploads` + `set_lifecycle` to fix it for good\n- **\"How many more drives can fail?\"** → `healing_health` (per-erasure-set online drives vs write quorum, heal backlog/errors)\n- One-shot triage (`fleet_overview` / `minio-aiops overview`): health + capacity headline + exposure headline\n- Per-bucket questions: `bucket_info` (policy/versioning/lifecycle/encryption/quota/tags in one answer)\n- Safely change policy/versioning/lifecycle/quota (reversible, undo recorded) or delete an **empty** bucket (governed, dry-run + double confirm)\n\n**Do NOT use when** the target is not MinIO — for Ceph/RGW use **ceph-aiops**; for TrueNAS use **truenas-aiops**; for a hypervisor, backup product, container cluster, or network device route to the appropriate **other AIops-tools** skill.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| MinIO: capacity RCA, bucket exposure, ILM gaps, healing, bucket writes | **minio-aiops** (this skill) |\n| Ceph/RGW storage | **ceph-aiops** |\n| TrueNAS storage appliances | **truenas-aiops** |\n| Any other target (hypervisor, backup, cluster, network) | the appropriate **other AIops-tools** skill |\n\n## Common Workflows\n\nEach recipe starts from an RCA read and ends in a governed, reversible write.\nEvery write step accepts `--dry-run`; irreversible ones also double-confirm.\n\n### 1. \"Backups are failing — the cluster says it's out of space\"\n\n1. `minio-aiops overview` → one-shot triage: health + capacity headline + exposure headline.\n2. `minio-aiops capacity rca` → ranked findings with cause + action (`CLUSTER_NEARFULL`, `DRIVES_OFFLINE`, `DRIVE_HOTSPOT`, …). Note which finding is actually driving the fill.\n3. `minio-aiops capacity usage` → the biggest buckets, largest first, so you know where the bytes live.\n4. `minio-aiops bucket ilm-gap` → how much of that is reclaimable: unbounded noncurrent versions and abandoned multipart uploads, with an estimate.\n5. Reclaim the abandoned uploads: `minio-aiops bucket purge-uploads <bucket> --older-than-days 7 --dry-run`, then re-run without `--dry-run` (double confirm — this one is irreversible, only uploads older than the window are aborted).\n6. Cap version growth: `minio-aiops bucket lifecycle-set <bucket> --noncurrent-days 30` (reversible — the prior lifecycle config is captured). Abandoned uploads have no server-side rule — MinIO does not honour a lifecycle abort-incomplete rule — so re-run `purge-uploads` periodically instead.\n7. `minio-aiops capacity rca` again to confirm the finding cleared.\n\n**Failure branch**: if `capacity rca` reports `DRIVES_OFFLINE` rather than genuine data growth, stop — do not delete anything. The space is not gone, it is unavailable. Go to recipe 3 and restore drive/erasure-set health first; purging data under a degraded erasure set removes redundancy you may need.\n\n### 2. \"Someone says one of our buckets is readable from the internet\"\n\n1. `minio-aiops bucket audit` → ranked exposure findings, riskiest first (`PUBLIC_WRITE_POLICY`, `PUBLIC_READ_POLICY`, missing encryption, versioning off, no lifecycle).\n2. `minio-aiops bucket info <bucket>` → the full per-bucket picture (policy, versioning, lifecycle, encryption, quota, tags) so you fix the right thing.\n3. Decide the fix. To remove anonymous access entirely: `minio-aiops bucket policy-set <bucket> --file restricted-policy.json --dry-run`, then re-run for real. To drop the policy altogether, use the `delete_bucket_policy` MCP tool. Both are reversible — the prior policy JSON is captured.\n4. `minio-aiops undo list` → confirm an undo token was recorded for the change you just made.\n5. `minio-aiops bucket audit` → confirm the finding is gone.\n\n**Failure branch**: if the write is refused by the server with an access-denied error, the access key you connected with lacks permission for that operation — the tool does not gate the write, the key does. Connect with a key whose IAM policy allows it (or ask whoever owns the key). If the new policy breaks a legitimate consumer, `minio-aiops undo apply <id>` restores the exact prior policy document.\n\n### 3. \"A drive died — how many more failures can we take?\"\n\n1. `minio-aiops health check` and `minio-aiops health status` → is the cluster serving reads and writes at all right now?\n2. `minio-aiops heal status` → per erasure set: online drives vs write quorum, `failureToleranceRemaining`, healing drives, heal backlog and errors.\n3. `minio-aiops heal drives` → which specific drives are offline or healing.\n4. `minio-aiops heal nodes` → whether the failures cluster on one node (a node problem, not a drive problem).\n5. If `WRITE_QUORUM_AT_EDGE` appears, the next failure stops writes: replace drives before any maintenance, and re-run `heal status` until the backlog drains.\n\n**Failure branch**: if the heal backlog is not shrinking between runs, do not start more maintenance. Check `heal nodes` for an offline node first — a down node makes its drives look like many simultaneous drive failures, and replacing hardware will not fix it.\n\n### 4. \"The auditor asked whether our retained data is actually protected\"\n\n1. `minio-aiops lock gaps` → ranked WORM findings across every bucket. The two that matter most: `LOCK_ENABLED_NO_DEFAULT_RETENTION` (the bucket advertises object lock but retains nothing unless each upload asks) and `LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION` (an expiry rule that retention outlives, so the capacity never returns — both day counts are in the finding).\n2. `minio-aiops lock config <bucket>` → whether object lock is enabled at all. `objectLockEnabled: false` is terminal: S3 accepts the flag only at bucket creation, so the answer is a new bucket plus a migration, not a setting.\n3. `minio-aiops lock status <bucket> <key>` → for a specific object: retention mode, days remaining, legal hold, and `protection.versionDestroyable` with what is blocking it. Note `deleteMarkerStillPossible`: object lock protects the bytes, not the key's visibility.\n4. Close the gap for future uploads: `minio-aiops lock default-set <bucket> GOVERNANCE --days 365 --dry-run`, then for real (reversible — the prior rule is captured).\n5. `minio-aiops lock gaps` again → confirm the finding cleared, and check whether step 4 introduced the lifecycle contradiction from step 1.\n\n**Failure branch**: `lock default-set` refused with \"does not have object lock enabled\" means the bucket can never be made WORM in place — create one with `minio-aiops lock bucket-create <new> --object-lock` and migrate. If the auditor requires retention nobody can lift, that is COMPLIANCE, not GOVERNANCE — and it is genuinely permanent: verified on a live server, root with `--bypass` could not clear it, downgrade it, or delete the version. `set_object_retention` therefore records **no undo token**, refuses any call that would shorten retention already in force, and requires `acknowledge_irreversible=True`. Use GOVERNANCE unless permanence is the actual requirement.\n\n### 5. \"Decommission a retired bucket\"\n\n1. `minio-aiops bucket ls` → confirm the exact bucket name.\n2. `minio-aiops bucket info <bucket>` → verify it is genuinely retired (check versioning, lifecycle and quota, not just the object count).\n3. `minio-aiops bucket uploads <bucket>` → surface incomplete multipart uploads, which keep a bucket non-empty even when it looks empty.\n4. `minio-aiops bucket purge-uploads <bucket> --older-than-days 7` if any remain (dry-run first, double confirm).\n5. `minio-aiops bucket delete <bucket> --dry-run` → shows the API call, changes nothing.\n6. Re-run without `--dry-run`: double confirm, **high** risk. Execution re-checks emptiness (versions and delete markers included) and refuses otherwise — this tool never mass-deletes data.\n\n**Failure branch**: if the delete is refused as non-empty, that is the guard doing its job — the bucket still holds objects, noncurrent versions, delete markers, or incomplete uploads. Go back to step 3, and never work around the guard by deleting data out-of-band; this tool deliberately has no mass-delete path.\n\n## Governance & Safety\n\n- The skill delivers reads and writes and records them; it does **not** decide whether a write is permitted — that is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate.\n- **Audit is the guarantee**: every tool — MCP and CLI alike — is audited to `~/.minio-aiops/audit.db` (relocatable via `MINIO_AIOPS_HOME`). `MINIO_AUDIT_APPROVED_BY` / `MINIO_AUDIT_RATIONALE` are optional annotations recorded when set, never required.\n- The declared `risk_level` (`bucket_delete` is high) is carried into the audit row as a descriptive tier — a label for the reviewer, not a gate.\n- Destructive writes support `--dry-run` and double confirmation at the CLI.\n- Reversible writes record an inverse descriptor capturing the real prior state (policy JSON, lifecycle XML, versioning state, quota).\n\n## References\n\n- `references/capabilities.md` — full tool → API-surface → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.12.3:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"minio-aiops\",\n  \"version\": \"0.12.3\",\n  \"publishedAt\": 1789452271684\n}\n\nFile v0.12.3:references/agent-guardrails.md\n\n# Agent guardrails — running minio-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The access key you connect with.** Give it a read-only IAM policy. A write\n  then fails at the server, which is the only place the permission actually\n  lives — no skill-side flag can be argued around by a model, but a revoked\n  permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Don't invent a value when a field is missing\" | A field the API did not return comes back as `null`, never as `\"\"` — a bucket with no `createdAt`, an object with no `lastModified`/`versionId`, an upload with no `initiated` time. Absent and empty are distinguishable in the payload. |\n| \"Tell me if the object list was cut off\" | Every bounded listing returns `{\"objects\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}` (and the same shape with `buckets` / `uploads`). Truncation is measured — `object_ls` fetches one row past the limit, the bucket/upload/usage listings measure against the full set — never guessed from the count equalling the limit. |\n| \"Tell me which exposed bucket to fix first\" | `bucket_exposure_audit` returns findings sorted riskiest-first with an explicit `riskScore` and `riskLevel`; `capacity_rca`, `healing_health`, and `lifecycle_gap_analysis` each attach a `severity` plus `cause` and `suggestedAction` to every finding. The priority is in the payload, not implied by list position. |\n| \"Confirm before anything destructive\" | Destructive operations require a `--dry-run`-able preview + double confirmation at the CLI. `bucket_delete` additionally refuses unless the bucket is verifiably empty (including noncurrent versions and delete markers). |\n| \"Log what you did\" | Every call is audited to `~/.minio-aiops/audit.db` regardless of what the model says it did. Reversible writes record their prior state (`priorState`) so `undo_list` / `undo_apply` can roll them back. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a MinIO object-storage deployment through the minio-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current MinIO deployment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result contains a \"truncated\"\n  field that is true, say so and re-run with a higher limit (or a narrower\n  prefix) instead of treating the partial result as complete. An object listing\n  is a page of a bucket, not the bucket.\n- A null field means the API did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  bucket names, object keys, versioning states, or upload IDs.\n- When an analysis returns findings, work in severity order (critical, then\n  warning, then info) and cite the measured number in each finding's \"cause\".\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, exposure, or durability problem unless a tool result\n  supports it. \"usedRatio\" and \"failureToleranceRemaining\" are the numbers that\n  support such a claim.\n- Do not add generic S3 advice that does not follow from the tool output.\n- Do not confuse a bucket name with an object key, or an uploadId with a\n  versionId. A bucket name is the whole bucket; an object key is one object\n  inside it.\n- \"Enabled\", \"Suspended\", and \"Off\" are three distinct versioning states.\n  A suspended bucket is not an unversioned bucket — old versions still exist.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the key's\npermission only when you trust the setup — a `bucket_delete` or a policy change\nis cheap to invoke and expensive to get wrong:\n\n```bash\n# Connect with an access key whose IAM policy is read-only, then:\nminio-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport MINIO_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport MINIO_AUDIT_RATIONALE=\"lifecycle cleanup window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `fleet_overview`, `capacity_rca`, `bucket_exposure_audit`,\n  `lifecycle_gap_analysis`, `healing_health` — they do the multi-step\n  correlation inside one call, so the model does not have to chain reads and\n  keep bucket names straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `limit`/`prefix` on `object_ls` deliberately rather than\n  paging through a whole bucket.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.12.3:references/capabilities.md\n\n# minio-aiops capabilities\n\n> 48 MCP tools (28 read, 18 write, 2 undo) over four access paths:\n> the **S3 API** (official SDK, SigV4), the **admin API**, the unauthenticated\n> **health endpoints**, and the **cluster metrics endpoint**.\n\n## Health (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `health_live` | `GET /minio/health/live` | node liveness (reachable/healthy/status code) |\n| `health_ready` | `GET /minio/health/ready` | node readiness |\n| `health_cluster` | `GET /minio/health/cluster` | write-quorum health (503 = degraded) + live/ready + overall verdict |\n| `cluster_status` | metrics endpoint | nodes/drives online+offline, raw/usable capacity, buckets, objects |\n| `fleet_overview` | composite | health + capacity headline + exposure headline in one call |\n\n## Flagship analyses (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `capacity_rca` | metrics endpoint | findings with **cause + suggestedAction**: CLUSTER_FULL / CLUSTER_NEARFULL / DRIVES_OFFLINE / NODES_OFFLINE / DRIVE_HOTSPOT / DRIVE_IMBALANCE; per-drive usage table |\n| `usage_by_bucket` | metrics endpoint | envelope `{buckets, returned, limit, truncated}` — per-bucket bytes + objects, biggest first |\n| `healing_health` | metrics endpoint | per-erasure-set online drives / write quorum / **failureToleranceRemaining**, healing drives, heal backlog + errors; findings WRITE_QUORUM_LOST / _AT_EDGE / LOW_FAILURE_TOLERANCE / HEALING_IN_PROGRESS / HEAL_ERRORS |\n| `drive_status` | metrics endpoint | per-drive rows (server, drive, used ratio), fullest first |\n| `node_status` | metrics endpoint | nodes online/offline + per-node drive counts |\n| `bucket_exposure_audit` | S3 API per bucket | reports `bucketsAudited`/`bucketsTotal`/`truncated`; **ranked** findings: PUBLIC_WRITE_POLICY / PUBLIC_READ_POLICY / NO_DEFAULT_ENCRYPTION / VERSIONING_OFF / NO_LIFECYCLE with riskScore + riskLevel |\n| `lifecycle_gap_analysis` | S3 API + metrics | reports `bucketsAnalyzed`/`bucketsTotal`/`truncated`; gaps: NONCURRENT_VERSIONS_UNBOUNDED (+reclaimable estimate) / INCOMPLETE_UPLOADS_NO_ABORT_RULE (+counts, ages) / NO_LIFECYCLE_ON_LARGE_BUCKET |\n| `diagnose_retention_gaps` | S3 API per bucket | envelope `{findings, returned, limit, truncated}` + `bucketErrors`; worst-first with `rank`: LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION (both day counts + shortfall) / LOCK_ENABLED_NO_DEFAULT_RETENTION / LOCK_WITHOUT_ACTIVE_VERSIONING / COMPLIANCE_DEFAULT_LONG / GOVERNANCE_DEFAULT_BYPASSABLE |\n\n## Buckets (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `bucket_ls` | `ListBuckets` | envelope `{buckets, returned, limit, truncated}` — name + creation time (`createdAt` is `null`, not `\"\"`, when absent) |\n| `bucket_info` | composite per bucket | policy (present/publicRead/publicWrite), versioning, lifecycle rules, encryption, quota, tags — per-probe failures degrade to an `errors` list |\n| `bucket_policy_get` | `GetBucketPolicy` | verbatim policy JSON + anonymous-access summary |\n| `bucket_lifecycle_get` | `GetBucketLifecycle` | rules as dicts (ruleId, status, prefix, expirationDays, noncurrentExpirationDays, abortIncompleteDays) |\n| `bucket_versioning_get` | `GetBucketVersioning` | Enabled / Suspended / Off |\n| `bucket_quota_get` | admin API | hard quota bytes (0 = unlimited) |\n| `object_ls` | `ListObjectsV2` | envelope `{objects, returned, limit, truncated}` — bounded listing (default 100, max 1000) under a prefix; `truncated` is **measured** (one row over-fetched); `lastModified`/`versionId` are `null` when absent |\n| `incomplete_uploads_ls` | `ListMultipartUploads` | envelope `{uploads, returned, limit, truncated}` — object, uploadId, initiated time (`null` when absent) |\n| `server_info` | admin API | mode, deployment id, server/pool counts |\n\n## Object lock / WORM (read)\n\n| Tool | Returns |\n|------|---------|\n| `bucket_lock_config` | `objectLockEnabled` + `defaultRetention` (+ `defaultRetentionDays`, years converted) + `versioning`. **Keeps two absences apart**: `objectLockEnabled: false` (lock was never enabled and S3 accepts the flag only at bucket creation, so it never can be) vs `true` with `defaultRetention: null` (WORM available, but an upload omitting its own retention header is retained for nothing) |\n| `object_lock_status` | one version's `retention` + `legalHold` + `retentionDaysRemaining`, plus `protection`: `versionDestroyable`, `blockedBy` (they stack), `bypassable`, and `deleteMarkerStillPossible` — a plain DELETE always succeeds on a versioned bucket and hides the key while the retained version survives |\n\n## Writes (governed; all take `dry_run`)\n\n| Tool | Risk | Undo | Notes |\n|------|:----:|:----:|-------|\n| `set_bucket_policy` | medium | prior policy JSON (or delete if none) | policy_json validated as JSON with a Statement |\n| `delete_bucket_policy` | medium | re-apply prior policy JSON | no-op undo when there was none |\n| `set_versioning` | medium | prior state | prior \"Off\" undoes to Suspended (S3 cannot return to Off — noted) |\n| `set_lifecycle` | medium | prior lifecycle XML (or delete if none) | day-count knobs build rules; `lifecycle_xml` applies verbatim (undo path) |\n| `delete_lifecycle` | medium | re-apply prior lifecycle XML | |\n| `set_bucket_quota` | medium | prior quota (0 clears) | admin API |\n| `bucket_delete` | **high** | none (irreversible) | refused unless verifiably empty (versions + delete markers included); priorState = bucket meta |\n| `remove_incomplete_uploads` | medium | none (parts unrecoverable) | age-gated (default: only uploads ≥ 7 days old); priorState = count + sample |\n| `bucket_create` | medium | delete the bucket (empty-only) | `object_lock=True` is the ONLY route to a WORM-capable bucket; reports lock + versioning as **observed**, not echoed |\n| `set_default_retention` | **high** | prior default rule (or clear) | applies to future uploads only; undo restores the rule, objects written under it keep their own retention |\n| `clear_default_retention` | medium | prior default rule | clears the rule only — object lock stays enabled (S3 has no call that disables it) |\n| `set_legal_hold` | medium | prior hold state | the one WORM control reversible by design; stacks with retention |\n| `set_object_retention` | **critical** | **none, and none is possible** | extend-only: shortening/downgrading is refused locally because S3 needs `x-amz-bypass-governance-retention`, which the minio SDK never sends. COMPLIANCE additionally needs `acknowledge_irreversible=True`. Verified on a live MinIO: root with `--bypass` could not clear, downgrade, or version-delete a COMPLIANCE object |\n\n## Out of scope\n\n- Site replication status/management\n- IAM **policy authoring** (creating/editing policy documents; attaching existing\n  ones is supported) and group-membership writes\n- Tiering to remote storage\n\nMissing something you need? **Open an issue or send a PR** — feedback welcome.\n\n## Authorization\n\nThere is no read-only switch, policy file, or approval gate. Whether a write is\npermitted is the agent's decision or the permission of the access key you\nconnect with (a read-only IAM policy makes writes fail at the server). Every\ncall — read or write, MCP or CLI — is audited. See `agent-guardrails.md`.\n\nFile v0.12.3:references/cli-reference.md\n\n# minio-aiops CLI reference\n\n> The CLI is a convenience subset; the full 48-tool surface is via the MCP\n> server (`minio-aiops mcp`). CLI writes delegate to the governed MCP twins,\n> so they are audited + undo-recorded identically.\n\n## Setup & diagnostics\n\n```bash\nminio-aiops init                    # wizard: endpoint, TLS, region, access key; secret key → encrypted store\nminio-aiops doctor                  # config + secrets + live/ready + S3 auth + metrics reachability\nminio-aiops doctor --skip-auth      # config/secrets checks only (no network)\nminio-aiops overview                # health + capacity headline + exposure headline\n```\n\n## Secrets (encrypted store)\n\n```bash\nminio-aiops secret set <target>     # store/replace a secret key (prompted hidden)\nminio-aiops secret list             # names only — values never shown\nminio-aiops secret rm <target>\nminio-aiops secret migrate          # import legacy plaintext .env keys\nminio-aiops secret rotate-password  # re-encrypt under a new master password\n```\n\n## Reads\n\n```bash\nminio-aiops health check            # live + ready + cluster write-quorum\nminio-aiops health status           # nodes/drives/capacity/buckets/objects\nminio-aiops capacity rca            # flagship: capacity findings, cause + action\nminio-aiops capacity usage          # per-bucket usage, biggest first\nminio-aiops heal status             # flagship: erasure-set quorum risk + heal backlog\nminio-aiops heal drives             # per-drive usage, fullest first\nminio-aiops heal nodes              # per-node drive counts\nminio-aiops bucket ls                # --limit caps the listing\nminio-aiops bucket info <bucket>    # policy/versioning/lifecycle/encryption/quota/tags\nminio-aiops bucket audit            # flagship: ranked exposure findings\nminio-aiops bucket ilm-gap          # flagship: ILM gaps + reclaimable estimate\nminio-aiops bucket objects <bucket> # objects under a prefix (--prefix, --limit)\nminio-aiops bucket uploads <bucket> # incomplete multipart uploads\n```\n\n## Writes (all take --dry-run; destructive ones double-confirm)\n\n```bash\nminio-aiops bucket versioning-set <bucket> Enabled|Suspended\nminio-aiops bucket policy-set <bucket> --file policy.json\nminio-aiops bucket lifecycle-set <bucket> --expire-days 90 --noncurrent-days 30 [--prefix logs/]\nminio-aiops bucket quota-set <bucket> <size-bytes>     # 0 clears\nminio-aiops bucket purge-uploads <bucket> [--older-than-days 7]   # double confirm\nminio-aiops bucket delete <bucket>                     # double confirm; refused unless empty\n```\n\n## MCP server\n\n```bash\nexport MINIO_AIOPS_MASTER_PASSWORD=...   # required non-interactively (no TTY)\nminio-aiops mcp                          # or: minio-aiops-mcp\n```\n\nCommon options: `--target/-t <name>` selects a configured target (default: the\nfirst one); `--dry-run` previews a write without executing.\n\n## Truncation\n\nListing commands (`bucket ls`, `bucket objects`, `bucket uploads`,\n`capacity usage`, `bucket audit`, `bucket ilm-gap`) return a\n`{..., \"returned\": N, \"limit\": L, \"truncated\": bool}` envelope and print a\ntrailing `… truncated` note when there is more data — re-run with a higher\n`--limit` rather than treating the output as complete.\n\nFile v0.12.3:references/setup-guide.md\n\n# minio-aiops setup & security guide\n\n> Verification status: mock-validated; no recorded end-to-end run against a\n> live MinIO server yet. The cheapest live check is a single-node server\n> running `minio-aiops doctor` — see `docs/VERIFICATION.md`.\n\n## 1. Install\n\n```bash\nuv tool install minio-aiops        # or: pipx install minio-aiops\n```\n\n## 2. What the tool talks to\n\nFour surfaces on the same MinIO origin:\n\n- **S3 API** (`host:port`, default `9000`) — SigV4-signed via the official\n  SDK; needs an access/secret key pair. Admin features (bucket quota,\n  `server_info`) need **admin-capable** keys.\n- **Health endpoints** — `/minio/health/live`, `/ready`, `/cluster`\n  (unauthenticated by design).\n- **Metrics endpoint** — `/minio/v2/metrics/cluster`. Two auth modes,\n  matching the server's `MINIO_PROMETHEUS_AUTH_TYPE`:\n  - `public` → set `metrics_public: true` for the target; no header sent.\n  - default (`jwt`) → the tool derives a bearer token from the stored\n    credentials at request time. **No extra secret to configure.**\n\n## 3. Onboard a target\n\n```bash\nminio-aiops init\n```\n\nThe wizard prompts for: target name, host, port, **TLS** (default yes),\n**certificate verification** (default yes — answer No only for self-signed lab\ncerts), optional region, access key, secret key (hidden → encrypted store),\nand whether the metrics endpoint is public.\n\nResulting `~/.minio-aiops/config.yaml` (non-secret only):\n\n```yaml\ntargets:\n  - name: lab1\n    host: 192.0.2.10\n    port: 9000\n    access_key: minio-ops\n    secure: true\n    verify_ssl: true\n    region: \"\"\n    metrics_public: false\n```\n\n## 4. Secrets\n\n- Secret keys live **encrypted** in `~/.minio-aiops/secrets.enc`\n  (Fernet + scrypt master password; file chmod 600). Never in config.yaml.\n- Non-interactive use (MCP server, CI): export\n  `MINIO_AIOPS_MASTER_PASSWORD`. MCP clients start the server **without a TTY\n  and without your shell profile** — put the variable in the client's `env`\n  block.\n- Legacy fallback: `MINIO_<TARGET_NAME_UPPER>_SECRET_KEY` (plaintext env) is\n  honoured with a warning — migrate with `minio-aiops secret migrate`.\n\n## 5. Verify\n\n```bash\nminio-aiops doctor\n```\n\nChecks config + secrets, then per target: live/ready endpoints, an\nauthenticated `ListBuckets` (proves the key pair), and metrics reachability\n(the capacity/healing analyses depend on it — a failure prints the\n`metrics_public` hint).\n\n## 6. MCP client config\n\n```json\n{\n  \"mcpServers\": {\n    \"minio-aiops\": {\n      \"command\": \"uvx\",\n      \"args\": [\"--from\", \"minio-aiops\", \"minio-aiops-mcp\"],\n      \"env\": { \"MINIO_AIOPS_MASTER_PASSWORD\": \"your-master-password\" }\n    }\n  }\n}\n```\n\n## 7. Governance state\n\nEverything lives under `~/.minio-aiops/` (relocatable via\n`MINIO_AIOPS_HOME`): `audit.db` (every call) and `undo.db` (inverse descriptors\nfor reversible writes). The tool does not decide whether a write is permitted —\nthat is the agent's judgement or the permission of the access key you connect\nwith (a read-only IAM policy makes writes fail at the server); there is no\nread-only switch, policy file, or approval gate. `MINIO_AUDIT_APPROVED_BY`\n(+ `MINIO_AUDIT_RATIONALE`) are optional audit annotations, recorded when set\nand never required.\n\n## Self-test with a local server\n\nAny single-node MinIO works — run the server binary (or a container image)\nwith a local data directory, create a key pair, then:\n\n```bash\nminio-aiops init      # point at 127.0.0.1:9000, secure: No for plain http\nminio-aiops doctor\nminio-aiops overview\n```\n\nErasure-set / healing findings (`heal status`) only show substance on a\nmulti-drive deployment.\n\nFile v0.12.3:skill-card.md\n\n## Description:\n\nMinIO AIops helps agents diagnose and operate MinIO object storage, including capacity root-cause analysis, bucket exposure audits, lifecycle and retention gap checks, healing health, IAM exposure review, and governed storage changes.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, storage operators, and site reliability engineers use this skill to inspect MinIO health, capacity, bucket exposure, lifecycle behavior, object-lock retention, IAM exposure, and safe remediation options.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill exposes powerful MinIO storage and IAM write operations without an enforceable built-in read-only or approval gate.\n\nMitigation: Start with a read-only MinIO access key, widen permissions only during deliberate maintenance windows, and review dry-run previews and audit records before making changes.\n\nRisk: Operational credentials and the master password can grant broad access to MinIO targets if handled carelessly.\n\nMitigation: Avoid storing the master password in persistent client configuration when possible, protect the local MinIO AIops state directory, and keep write-capable credentials tightly scoped.\n\nRisk: Unpinned package installation can pull a later release than the one reviewed in this card.\n\nMitigation: Pin the minio-aiops package version to 0.12.3 when installing for reviewed or production use.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/minio-aiops)\n- [Project homepage](https://github.com/AIops-tools/MinIO-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [Setup and security guide](references/setup-guide.md)\n- [CLI reference](references/cli-reference.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Tool listings and analysis results may be bounded; when a result reports truncation, users should increase the limit or narrow the query before acting on it.]\n\n## Skill Version(s):\n\n0.12.3 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.12.2: 7 files, 19642 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (7259b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (2667b), SKILL.md (18191b), _meta.json (131b)\n\nFile v0.12.2:SKILL.md\n\n---\nname: minio-aiops\nslug: minio-aiops\ndisplayName: \"MinIO AIops\"\nsummary: \"Governed MinIO ops: capacity RCA, exposure audit, ILM, WORM retention, IAM, healing, 48 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/MinIO-AIops\ntags: [aiops, mcp, governance, minio]\ndescription: >\n  Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket).\n  Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment.\n  Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only).\n  Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).\ninstaller:\n  kind: uv\n  package: minio-aiops\nargument-hint: \"[minio question or describe your object-storage task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"minio-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"MINIO_AIOPS_CONFIG\",\"MINIO_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/MinIO-AIops\",\"emoji\":\"🪣\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed MinIO operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency. Works against any reasonably current MinIO server (single-node or distributed/erasure-coded); admin features (quota, server info) need admin-capable keys.\n  All write operations are audited to a local SQLite DB under ~/.minio-aiops/ (relocatable via MINIO_AIOPS_HOME).\n  Connection: the S3 API endpoint (host:port, default 9000; SigV4 via the official SDK), plus the unauthenticated health endpoints (/minio/health/live|ready|cluster) and the cluster metrics endpoint (/minio/v2/metrics/cluster — public mode or the default bearer-token mode; the token is derived from the stored credentials, no extra secret). The access key lives in config.yaml; the secret key is stored ENCRYPTED in ~/.minio-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'minio-aiops init' to onboard, or 'minio-aiops secret set <target>' to add one. The store is unlocked by a master password from MINIO_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var MINIO_<TARGET_NAME_UPPER>_SECRET_KEY is still honoured as a fallback with a deprecation warning (migrate with 'minio-aiops secret migrate'). Secrets are held only in memory, never logged or echoed.\n  State-changing operations require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (budget guard + audit + undo + risk-tier labelling). bucket_delete is high-risk, dry-run + double-confirm, and refused unless the bucket is verifiably empty (including versions and delete markers); remove_incomplete_uploads only aborts uploads older than a safety window. Reversible writes (set/delete bucket policy, set_versioning, set/delete lifecycle, set_bucket_quota) capture the prior state and record an inverse undo descriptor.\n  Webhooks: none — no outbound network calls beyond the configured MinIO endpoint.\n  SSL: secure (https) and verify_ssl default to true; disable verification only for self-signed lab certificates.\n  Transitive dependencies: the official minio SDK, httpx, and the MCP SDK. No post-install scripts or background services.\n  Verification status: validated against mocked SDK/HTTP responses; no recorded end-to-end run against a live MinIO server yet. Erasure-set/healing findings need a multi-drive deployment to observe live (a single-node server running 'minio-aiops doctor' is the cheapest live path). See docs/VERIFICATION.md.\n---\n\n# MinIO AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by MinIO, Inc. or any storage vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops) under the MIT license.\n\nGoverned MinIO object-storage operations — **48 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.minio-aiops/`, a token/runaway budget guard, undo-token recording, and a descriptive risk tier on every audit row. The secret key is stored **encrypted** (`~/.minio-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk. Six flagship analyses turn raw state into plain-language **cause + suggested action**: `capacity_rca`, `bucket_exposure_audit`, `lifecycle_gap_analysis`, `healing_health`, `diagnose_retention_gaps`, `diagnose_iam_exposure`.\n\n> **Standalone**: the governance harness is bundled in the package (`minio_aiops.governance`) — minio-aiops has no external skill-family dependency. Verification status and the live-run checklist are in `docs/VERIFICATION.md`.\n\n> **Authorization is not this tool's job**: whether a write is permitted is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate — the guarantee is that every call is audited. Driving this with a smaller / local model? See `references/agent-guardrails.md`.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read or Write |\n|-------|-------|:-----:|:-------------:|\n| **Health** | health_live, health_ready, health_cluster, cluster_status, fleet_overview | 5 | 5 read |\n| **Capacity** | capacity_rca (flagship), usage_by_bucket | 2 | 2 read |\n| **Healing** | healing_health (flagship), drive_status, node_status | 3 | 3 read |\n| **Exposure / ILM** | bucket_exposure_audit (flagship), lifecycle_gap_analysis (flagship) | 2 | 2 read |\n| **Buckets** | bucket_ls, bucket_info, bucket_policy_get, bucket_lifecycle_get, bucket_versioning_get, bucket_quota_get, object_ls, incomplete_uploads_ls, server_info | 9 | 9 read |\n| **Writes** | set_bucket_policy, delete_bucket_policy, set_versioning, set_lifecycle, delete_lifecycle, set_bucket_quota, bucket_delete, remove_incomplete_uploads | 8 | 8 write |\n| **Object lock (WORM)** | bucket_lock_config, object_lock_status, diagnose_retention_gaps (flagship) | 3 | 3 read |\n| | bucket_create, set_default_retention, clear_default_retention, set_legal_hold, set_object_retention | 5 | 5 write |\n| **IAM** | iam_users, iam_groups, iam_policies, diagnose_iam_exposure (flagship) | 4 | 4 read |\n| | create_user, set_user_status, remove_user, attach_user_policy, detach_user_policy | 5 | 5 write |\n| **Undo** | undo_list, undo_apply | 2 | read + replay |\n\nTotals: **48 tools — 28 read, 18 write, 2 undo.** The MCP server exposes all 48; the CLI is a convenience subset.\n\n## Quick Install\n\n```bash\nuv tool install minio-aiops\nminio-aiops init       # interactive wizard: endpoint + access key + encrypted secret key\nminio-aiops doctor\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/minio-aiops\nopenclaw skills info minio-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- **\"Storage is filling up / writes are failing\"** → `capacity_rca` (capacity vs used, offline drives/nodes, hotspots — cause + action per finding), then `usage_by_bucket` for the biggest consumers\n- **\"Is anything exposed?\"** → `bucket_exposure_audit` (ranked: public read/write policies, missing encryption, versioning off, no lifecycle)\n- **\"Where did my space go?\"** → `lifecycle_gap_analysis` (unbounded noncurrent versions, incomplete multipart uploads, reclaimable estimate) then `remove_incomplete_uploads` + `set_lifecycle` to fix it for good\n- **\"How many more drives can fail?\"** → `healing_health` (per-erasure-set online drives vs write quorum, heal backlog/errors)\n- One-shot triage (`fleet_overview` / `minio-aiops overview`): health + capacity headline + exposure headline\n- Per-bucket questions: `bucket_info` (policy/versioning/lifecycle/encryption/quota/tags in one answer)\n- Safely change policy/versioning/lifecycle/quota (reversible, undo recorded) or delete an **empty** bucket (governed, dry-run + double confirm)\n\n**Do NOT use when** the target is not MinIO — for Ceph/RGW use **ceph-aiops**; for TrueNAS use **truenas-aiops**; for a hypervisor, backup product, container cluster, or network device route to the appropriate **other AIops-tools** skill.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| MinIO: capacity RCA, bucket exposure, ILM gaps, healing, bucket writes | **minio-aiops** (this skill) |\n| Ceph/RGW storage | **ceph-aiops** |\n| TrueNAS storage appliances | **truenas-aiops** |\n| Any other target (hypervisor, backup, cluster, network) | the appropriate **other AIops-tools** skill |\n\n## Common Workflows\n\nEach recipe starts from an RCA read and ends in a governed, reversible write.\nEvery write step accepts `--dry-run`; irreversible ones also double-confirm.\n\n### 1. \"Backups are failing — the cluster says it's out of space\"\n\n1. `minio-aiops overview` → one-shot triage: health + capacity headline + exposure headline.\n2. `minio-aiops capacity rca` → ranked findings with cause + action (`CLUSTER_NEARFULL`, `DRIVES_OFFLINE`, `DRIVE_HOTSPOT`, …). Note which finding is actually driving the fill.\n3. `minio-aiops capacity usage` → the biggest buckets, largest first, so you know where the bytes live.\n4. `minio-aiops bucket ilm-gap` → how much of that is reclaimable: unbounded noncurrent versions and abandoned multipart uploads, with an estimate.\n5. Reclaim the abandoned uploads: `minio-aiops bucket purge-uploads <bucket> --older-than-days 7 --dry-run`, then re-run without `--dry-run` (double confirm — this one is irreversible, only uploads older than the window are aborted).\n6. Cap version growth: `minio-aiops bucket lifecycle-set <bucket> --noncurrent-days 30` (reversible — the prior lifecycle config is captured). Abandoned uploads have no server-side rule — MinIO does not honour a lifecycle abort-incomplete rule — so re-run `purge-uploads` periodically instead.\n7. `minio-aiops capacity rca` again to confirm the finding cleared.\n\n**Failure branch**: if `capacity rca` reports `DRIVES_OFFLINE` rather than genuine data growth, stop — do not delete anything. The space is not gone, it is unavailable. Go to recipe 3 and restore drive/erasure-set health first; purging data under a degraded erasure set removes redundancy you may need.\n\n### 2. \"Someone says one of our buckets is readable from the internet\"\n\n1. `minio-aiops bucket audit` → ranked exposure findings, riskiest first (`PUBLIC_WRITE_POLICY`, `PUBLIC_READ_POLICY`, missing encryption, versioning off, no lifecycle).\n2. `minio-aiops bucket info <bucket>` → the full per-bucket picture (policy, versioning, lifecycle, encryption, quota, tags) so you fix the right thing.\n3. Decide the fix. To remove anonymous access entirely: `minio-aiops bucket policy-set <bucket> --file restricted-policy.json --dry-run`, then re-run for real. To drop the policy altogether, use the `delete_bucket_policy` MCP tool. Both are reversible — the prior policy JSON is captured.\n4. `minio-aiops undo list` → confirm an undo token was recorded for the change you just made.\n5. `minio-aiops bucket audit` → confirm the finding is gone.\n\n**Failure branch**: if the write is refused by the server with an access-denied error, the access key you connected with lacks permission for that operation — the tool does not gate the write, the key does. Connect with a key whose IAM policy allows it (or ask whoever owns the key). If the new policy breaks a legitimate consumer, `minio-aiops undo apply <id>` restores the exact prior policy document.\n\n### 3. \"A drive died — how many more failures can we take?\"\n\n1. `minio-aiops health check` and `minio-aiops health status` → is the cluster serving reads and writes at all right now?\n2. `minio-aiops heal status` → per erasure set: online drives vs write quorum, `failureToleranceRemaining`, healing drives, heal backlog and errors.\n3. `minio-aiops heal drives` → which specific drives are offline or healing.\n4. `minio-aiops heal nodes` → whether the failures cluster on one node (a node problem, not a drive problem).\n5. If `WRITE_QUORUM_AT_EDGE` appears, the next failure stops writes: replace drives before any maintenance, and re-run `heal status` until the backlog drains.\n\n**Failure branch**: if the heal backlog is not shrinking between runs, do not start more maintenance. Check `heal nodes` for an offline node first — a down node makes its drives look like many simultaneous drive failures, and replacing hardware will not fix it.\n\n### 4. \"The auditor asked whether our retained data is actually protected\"\n\n1. `minio-aiops lock gaps` → ranked WORM findings across every bucket. The two that matter most: `LOCK_ENABLED_NO_DEFAULT_RETENTION` (the bucket advertises object lock but retains nothing unless each upload asks) and `LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION` (an expiry rule that retention outlives, so the capacity never returns — both day counts are in the finding).\n2. `minio-aiops lock config <bucket>` → whether object lock is enabled at all. `objectLockEnabled: false` is terminal: S3 accepts the flag only at bucket creation, so the answer is a new bucket plus a migration, not a setting.\n3. `minio-aiops lock status <bucket> <key>` → for a specific object: retention mode, days remaining, legal hold, and `protection.versionDestroyable` with what is blocking it. Note `deleteMarkerStillPossible`: object lock protects the bytes, not the key's visibility.\n4. Close the gap for future uploads: `minio-aiops lock default-set <bucket> GOVERNANCE --days 365 --dry-run`, then for real (reversible — the prior rule is captured).\n5. `minio-aiops lock gaps` again → confirm the finding cleared, and check whether step 4 introduced the lifecycle contradiction from step 1.\n\n**Failure branch**: `lock default-set` refused with \"does not have object lock enabled\" means the bucket can never be made WORM in place — create one with `minio-aiops lock bucket-create <new> --object-lock` and migrate. If the auditor requires retention nobody can lift, that is COMPLIANCE, not GOVERNANCE — and it is genuinely permanent: verified on a live server, root with `--bypass` could not clear it, downgrade it, or delete the version. `set_object_retention` therefore records **no undo token**, refuses any call that would shorten retention already in force, and requires `acknowledge_irreversible=True`. Use GOVERNANCE unless permanence is the actual requirement.\n\n### 5. \"Decommission a retired bucket\"\n\n1. `minio-aiops bucket ls` → confirm the exact bucket name.\n2. `minio-aiops bucket info <bucket>` → verify it is genuinely retired (check versioning, lifecycle and quota, not just the object count).\n3. `minio-aiops bucket uploads <bucket>` → surface incomplete multipart uploads, which keep a bucket non-empty even when it looks empty.\n4. `minio-aiops bucket purge-uploads <bucket> --older-than-days 7` if any remain (dry-run first, double confirm).\n5. `minio-aiops bucket delete <bucket> --dry-run` → shows the API call, changes nothing.\n6. Re-run without `--dry-run`: double confirm, **high** risk. Execution re-checks emptiness (versions and delete markers included) and refuses otherwise — this tool never mass-deletes data.\n\n**Failure branch**: if the delete is refused as non-empty, that is the guard doing its job — the bucket still holds objects, noncurrent versions, delete markers, or incomplete uploads. Go back to step 3, and never work around the guard by deleting data out-of-band; this tool deliberately has no mass-delete path.\n\n## Governance & Safety\n\n- The skill delivers reads and writes and records them; it does **not** decide whether a write is permitted — that is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate.\n- **Audit is the guarantee**: every tool — MCP and CLI alike — is audited to `~/.minio-aiops/audit.db` (relocatable via `MINIO_AIOPS_HOME`). `MINIO_AUDIT_APPROVED_BY` / `MINIO_AUDIT_RATIONALE` are optional annotations recorded when set, never required.\n- The declared `risk_level` (`bucket_delete` is high) is carried into the audit row as a descriptive tier — a label for the reviewer, not a gate.\n- Destructive writes support `--dry-run` and double confirmation at the CLI.\n- Reversible writes record an inverse descriptor capturing the real prior state (policy JSON, lifecycle XML, versioning state, quota).\n\n## References\n\n- `references/capabilities.md` — full tool → API-surface → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.12.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"minio-aiops\",\n  \"version\": \"0.12.2\",\n  \"publishedAt\": 1789223293360\n}\n\nFile v0.12.2:references/agent-guardrails.md\n\n# Agent guardrails — running minio-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The access key you connect with.** Give it a read-only IAM policy. A write\n  then fails at the server, which is the only place the permission actually\n  lives — no skill-side flag can be argued around by a model, but a revoked\n  permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Don't invent a value when a field is missing\" | A field the API did not return comes back as `null`, never as `\"\"` — a bucket with no `createdAt`, an object with no `lastModified`/`versionId`, an upload with no `initiated` time. Absent and empty are distinguishable in the payload. |\n| \"Tell me if the object list was cut off\" | Every bounded listing returns `{\"objects\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}` (and the same shape with `buckets` / `uploads`). Truncation is measured — `object_ls` fetches one row past the limit, the bucket/upload/usage listings measure against the full set — never guessed from the count equalling the limit. |\n| \"Tell me which exposed bucket to fix first\" | `bucket_exposure_audit` returns findings sorted riskiest-first with an explicit `riskScore` and `riskLevel`; `capacity_rca`, `healing_health`, and `lifecycle_gap_analysis` each attach a `severity` plus `cause` and `suggestedAction` to every finding. The priority is in the payload, not implied by list position. |\n| \"Confirm before anything destructive\" | Destructive operations require a `--dry-run`-able preview + double confirmation at the CLI. `bucket_delete` additionally refuses unless the bucket is verifiably empty (including noncurrent versions and delete markers). |\n| \"Log what you did\" | Every call is audited to `~/.minio-aiops/audit.db` regardless of what the model says it did. Reversible writes record their prior state (`priorState`) so `undo_list` / `undo_apply` can roll them back. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a MinIO object-storage deployment through the minio-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current MinIO deployment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result contains a \"truncated\"\n  field that is true, say so and re-run with a higher limit (or a narrower\n  prefix) instead of treating the partial result as complete. An object listing\n  is a page of a bucket, not the bucket.\n- A null field means the API did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  bucket names, object keys, versioning states, or upload IDs.\n- When an analysis returns findings, work in severity order (critical, then\n  warning, then info) and cite the measured number in each finding's \"cause\".\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, exposure, or durability problem unless a tool result\n  supports it. \"usedRatio\" and \"failureToleranceRemaining\" are the numbers that\n  support such a claim.\n- Do not add generic S3 advice that does not follow from the tool output.\n- Do not confuse a bucket name with an object key, or an uploadId with a\n  versionId. A bucket name is the whole bucket; an object key is one object\n  inside it.\n- \"Enabled\", \"Suspended\", and \"Off\" are three distinct versioning states.\n  A suspended bucket is not an unversioned bucket — old versions still exist.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the key's\npermission only when you trust the setup — a `bucket_delete` or a policy change\nis cheap to invoke and expensive to get wrong:\n\n```bash\n# Connect with an access key whose IAM policy is read-only, then:\nminio-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport MINIO_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport MINIO_AUDIT_RATIONALE=\"lifecycle cleanup window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `fleet_overview`, `capacity_rca`, `bucket_exposure_audit`,\n  `lifecycle_gap_analysis`, `healing_health` — they do the multi-step\n  correlation inside one call, so the model does not have to chain reads and\n  keep bucket names straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `limit`/`prefix` on `object_ls` deliberately rather than\n  paging through a whole bucket.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.12.2:references/capabilities.md\n\n# minio-aiops capabilities\n\n> 48 MCP tools (28 read, 18 write, 2 undo) over four access paths:\n> the **S3 API** (official SDK, SigV4), the **admin API**, the unauthenticated\n> **health endpoints**, and the **cluster metrics endpoint**.\n\n## Health (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `health_live` | `GET /minio/health/live` | node liveness (reachable/healthy/status code) |\n| `health_ready` | `GET /minio/health/ready` | node readiness |\n| `health_cluster` | `GET /minio/health/cluster` | write-quorum health (503 = degraded) + live/ready + overall verdict |\n| `cluster_status` | metrics endpoint | nodes/drives online+offline, raw/usable capacity, buckets, objects |\n| `fleet_overview` | composite | health + capacity headline + exposure headline in one call |\n\n## Flagship analyses (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `capacity_rca` | metrics endpoint | findings with **cause + suggestedAction**: CLUSTER_FULL / CLUSTER_NEARFULL / DRIVES_OFFLINE / NODES_OFFLINE / DRIVE_HOTSPOT / DRIVE_IMBALANCE; per-drive usage table |\n| `usage_by_bucket` | metrics endpoint | envelope `{buckets, returned, limit, truncated}` — per-bucket bytes + objects, biggest first |\n| `healing_health` | metrics endpoint | per-erasure-set online drives / write quorum / **failureToleranceRemaining**, healing drives, heal backlog + errors; findings WRITE_QUORUM_LOST / _AT_EDGE / LOW_FAILURE_TOLERANCE / HEALING_IN_PROGRESS / HEAL_ERRORS |\n| `drive_status` | metrics endpoint | per-drive rows (server, drive, used ratio), fullest first |\n| `node_status` | metrics endpoint | nodes online/offline + per-node drive counts |\n| `bucket_exposure_audit` | S3 API per bucket | reports `bucketsAudited`/`bucketsTotal`/`truncated`; **ranked** findings: PUBLIC_WRITE_POLICY / PUBLIC_READ_POLICY / NO_DEFAULT_ENCRYPTION / VERSIONING_OFF / NO_LIFECYCLE with riskScore + riskLevel |\n| `lifecycle_gap_analysis` | S3 API + metrics | reports `bucketsAnalyzed`/`bucketsTotal`/`truncated`; gaps: NONCURRENT_VERSIONS_UNBOUNDED (+reclaimable estimate) / INCOMPLETE_UPLOADS_NO_ABORT_RULE (+counts, ages) / NO_LIFECYCLE_ON_LARGE_BUCKET |\n| `diagnose_retention_gaps` | S3 API per bucket | envelope `{findings, returned, limit, truncated}` + `bucketErrors`; worst-first with `rank`: LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION (both day counts + shortfall) / LOCK_ENABLED_NO_DEFAULT_RETENTION / LOCK_WITHOUT_ACTIVE_VERSIONING / COMPLIANCE_DEFAULT_LONG / GOVERNANCE_DEFAULT_BYPASSABLE |\n\n## Buckets (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `bucket_ls` | `ListBuckets` | envelope `{buckets, returned, limit, truncated}` — name + creation time (`createdAt` is `null`, not `\"\"`, when absent) |\n| `bucket_info` | composite per bucket | policy (present/publicRead/publicWrite), versioning, lifecycle rules, encryption, quota, tags — per-probe failures degrade to an `errors` list |\n| `bucket_policy_get` | `GetBucketPolicy` | verbatim policy JSON + anonymous-access summary |\n| `bucket_lifecycle_get` | `GetBucketLifecycle` | rules as dicts (ruleId, status, prefix, expirationDays, noncurrentExpirationDays, abortIncompleteDays) |\n| `bucket_versioning_get` | `GetBucketVersioning` | Enabled / Suspended / Off |\n| `bucket_quota_get` | admin API | hard quota bytes (0 = unlimited) |\n| `object_ls` | `ListObjectsV2` | envelope `{objects, returned, limit, truncated}` — bounded listing (default 100, max 1000) under a prefix; `truncated` is **measured** (one row over-fetched); `lastModified`/`versionId` are `null` when absent |\n| `incomplete_uploads_ls` | `ListMultipartUploads` | envelope `{uploads, returned, limit, truncated}` — object, uploadId, initiated time (`null` when absent) |\n| `server_info` | admin API | mode, deployment id, server/pool counts |\n\n## Object lock / WORM (read)\n\n| Tool | Returns |\n|------|---------|\n| `bucket_lock_config` | `objectLockEnabled` + `defaultRetention` (+ `defaultRetentionDays`, years converted) + `versioning`. **Keeps two absences apart**: `objectLockEnabled: false` (lock was never enabled and S3 accepts the flag only at bucket creation, so it never can be) vs `true` with `defaultRetention: null` (WORM available, but an upload omitting its own retention header is retained for nothing) |\n| `object_lock_status` | one version's `retention` + `legalHold` + `retentionDaysRemaining`, plus `protection`: `versionDestroyable`, `blockedBy` (they stack), `bypassable`, and `deleteMarkerStillPossible` — a plain DELETE always succeeds on a versioned bucket and hides the key while the retained version survives |\n\n## Writes (governed; all take `dry_run`)\n\n| Tool | Risk | Undo | Notes |\n|------|:----:|:----:|-------|\n| `set_bucket_policy` | medium | prior policy JSON (or delete if none) | policy_json validated as JSON with a Statement |\n| `delete_bucket_policy` | medium | re-apply prior policy JSON | no-op undo when there was none |\n| `set_versioning` | medium | prior state | prior \"Off\" undoes to Suspended (S3 cannot return to Off — noted) |\n| `set_lifecycle` | medium | prior lifecycle XML (or delete if none) | day-count knobs build rules; `lifecycle_xml` applies verbatim (undo path) |\n| `delete_lifecycle` | medium | re-apply prior lifecycle XML | |\n| `set_bucket_quota` | medium | prior quota (0 clears) | admin API |\n| `bucket_delete` | **high** | none (irreversible) | refused unless verifiably empty (versions + delete markers included); priorState = bucket meta |\n| `remove_incomplete_uploads` | medium | none (parts unrecoverable) | age-gated (default: only uploads ≥ 7 days old); priorState = count + sample |\n| `bucket_create` | medium | delete the bucket (empty-only) | `object_lock=True` is the ONLY route to a WORM-capable bucket; reports lock + versioning as **observed**, not echoed |\n| `set_default_retention` | **high** | prior default rule (or clear) | applies to future uploads only; undo restores the rule, objects written under it keep their own retention |\n| `clear_default_retention` | medium | prior default rule | clears the rule only — object lock stays enabled (S3 has no call that disables it) |\n| `set_legal_hold` | medium | prior hold state | the one WORM control reversible by design; stacks with retention |\n| `set_object_retention` | **critical** | **none, and none is possible** | extend-only: shortening/downgrading is refused locally because S3 needs `x-amz-bypass-governance-retention`, which the minio SDK never sends. COMPLIANCE additionally needs `acknowledge_irreversible=True`. Verified on a live MinIO: root with `--bypass` could not clear, downgrade, or version-delete a COMPLIANCE object |\n\n## Out of scope\n\n- Site replication status/management\n- IAM **policy authoring** (creating/editing policy documents; attaching existing\n  ones is supported) and group-membership writes\n- Tiering to remote storage\n\nMissing something you need? **Open an issue or send a PR** — feedback welcome.\n\n## Authorization\n\nThere is no read-only switch, policy file, or approval gate. Whether a write is\npermitted is the agent's decision or the permission of the access key you\nconnect with (a read-only IAM policy makes writes fail at the server). Every\ncall — read or write, MCP or CLI — is audited. See `agent-guardrails.md`.\n\nFile v0.12.2:references/cli-reference.md\n\n# minio-aiops CLI reference\n\n> The CLI is a convenience subset; the full 48-tool surface is via the MCP\n> server (`minio-aiops mcp`). CLI writes delegate to the governed MCP twins,\n> so they are audited + undo-recorded identically.\n\n## Setup & diagnostics\n\n```bash\nminio-aiops init                    # wizard: endpoint, TLS, region, access key; secret key → encrypted store\nminio-aiops doctor                  # config + secrets + live/ready + S3 auth + metrics reachability\nminio-aiops doctor --skip-auth      # config/secrets checks only (no network)\nminio-aiops overview                # health + capacity headline + exposure headline\n```\n\n## Secrets (encrypted store)\n\n```bash\nminio-aiops secret set <target>     # store/replace a secret key (prompted hidden)\nminio-aiops secret list             # names only — values never shown\nminio-aiops secret rm <target>\nminio-aiops secret migrate          # import legacy plaintext .env keys\nminio-aiops secret rotate-password  # re-encrypt under a new master password\n```\n\n## Reads\n\n```bash\nminio-aiops health check            # live + ready + cluster write-quorum\nminio-aiops health status           # nodes/drives/capacity/buckets/objects\nminio-aiops capacity rca            # flagship: capacity findings, cause + action\nminio-aiops capacity usage          # per-bucket usage, biggest first\nminio-aiops heal status             # flagship: erasure-set quorum risk + heal backlog\nminio-aiops heal drives             # per-drive usage, fullest first\nminio-aiops heal nodes              # per-node drive counts\nminio-aiops bucket ls                # --limit caps the listing\nminio-aiops bucket info <bucket>    # policy/versioning/lifecycle/encryption/quota/tags\nminio-aiops bucket audit            # flagship: ranked exposure findings\nminio-aiops bucket ilm-gap          # flagship: ILM gaps + reclaimable estimate\nminio-aiops bucket objects <bucket> # objects under a prefix (--prefix, --limit)\nminio-aiops bucket uploads <bucket> # incomplete multipart uploads\n```\n\n## Writes (all take --dry-run; destructive ones double-confirm)\n\n```bash\nminio-aiops bucket versioning-set <bucket> Enabled|Suspended\nminio-aiops bucket policy-set <bucket> --file policy.json\nminio-aiops bucket lifecycle-set <bucket> --expire-days 90 --noncurrent-days 30 [--prefix logs/]\nminio-aiops bucket quota-set <bucket> <size-bytes>     # 0 clears\nminio-aiops bucket purge-uploads <bucket> [--older-than-days 7]   # double confirm\nminio-aiops bucket delete <bucket>                     # double confirm; refused unless empty\n```\n\n## MCP server\n\n```bash\nexport MINIO_AIOPS_MASTER_PASSWORD=...   # required non-interactively (no TTY)\nminio-aiops mcp                          # or: minio-aiops-mcp\n```\n\nCommon options: `--target/-t <name>` selects a configured target (default: the\nfirst one); `--dry-run` previews a write without executing.\n\n## Truncation\n\nListing commands (`bucket ls`, `bucket objects`, `bucket uploads`,\n`capacity usage`, `bucket audit`, `bucket ilm-gap`) return a\n`{..., \"returned\": N, \"limit\": L, \"truncated\": bool}` envelope and print a\ntrailing `… truncated` note when there is more data — re-run with a higher\n`--limit` rather than treating the output as complete.\n\nFile v0.12.2:references/setup-guide.md\n\n# minio-aiops setup & security guide\n\n> Verification status: mock-validated; no recorded end-to-end run against a\n> live MinIO server yet. The cheapest live check is a single-node server\n> running `minio-aiops doctor` — see `docs/VERIFICATION.md`.\n\n## 1. Install\n\n```bash\nuv tool install minio-aiops        # or: pipx install minio-aiops\n```\n\n## 2. What the tool talks to\n\nFour surfaces on the same MinIO origin:\n\n- **S3 API** (`host:port`, default `9000`) — SigV4-signed via the official\n  SDK; needs an access/secret key pair. Admin features (bucket quota,\n  `server_info`) need **admin-capable** keys.\n- **Health endpoints** — `/minio/health/live`, `/ready`, `/cluster`\n  (unauthenticated by design).\n- **Metrics endpoint** — `/minio/v2/metrics/cluster`. Two auth modes,\n  matching the server's `MINIO_PROMETHEUS_AUTH_TYPE`:\n  - `public` → set `metrics_public: true` for the target; no header sent.\n  - default (`jwt`) → the tool derives a bearer token from the stored\n    credentials at request time. **No extra secret to configure.**\n\n## 3. Onboard a target\n\n```bash\nminio-aiops init\n```\n\nThe wizard prompts for: target name, host, port, **TLS** (default yes),\n**certificate verification** (default yes — answer No only for self-signed lab\ncerts), optional region, access key, secret key (hidden → encrypted store),\nand whether the metrics endpoint is public.\n\nResulting `~/.minio-aiops/config.yaml` (non-secret only):\n\n```yaml\ntargets:\n  - name: lab1\n    host: 192.0.2.10\n    port: 9000\n    access_key: minio-ops\n    secure: true\n    verify_ssl: true\n    region: \"\"\n    metrics_public: false\n```\n\n## 4. Secrets\n\n- Secret keys live **encrypted** in `~/.minio-aiops/secrets.enc`\n  (Fernet + scrypt master password; file chmod 600). Never in config.yaml.\n- Non-interactive use (MCP server, CI): export\n  `MINIO_AIOPS_MASTER_PASSWORD`. MCP clients start the server **without a TTY\n  and without your shell profile** — put the variable in the client's `env`\n  block.\n- Legacy fallback: `MINIO_<TARGET_NAME_UPPER>_SECRET_KEY` (plaintext env) is\n  honoured with a warning — migrate with `minio-aiops secret migrate`.\n\n## 5. Verify\n\n```bash\nminio-aiops doctor\n```\n\nChecks config + secrets, then per target: live/ready endpoints, an\nauthenticated `ListBuckets` (proves the key pair), and metrics reachability\n(the capacity/healing analyses depend on it — a failure prints the\n`metrics_public` hint).\n\n## 6. MCP client config\n\n```json\n{\n  \"mcpServers\": {\n    \"minio-aiops\": {\n      \"command\": \"uvx\",\n      \"args\": [\"--from\", \"minio-aiops\", \"minio-aiops-mcp\"],\n      \"env\": { \"MINIO_AIOPS_MASTER_PASSWORD\": \"your-master-password\" }\n    }\n  }\n}\n```\n\n## 7. Governance state\n\nEverything lives under `~/.minio-aiops/` (relocatable via\n`MINIO_AIOPS_HOME`): `audit.db` (every call) and `undo.db` (inverse descriptors\nfor reversible writes). The tool does not decide whether a write is permitted —\nthat is the agent's judgement or the permission of the access key you connect\nwith (a read-only IAM policy makes writes fail at the server); there is no\nread-only switch, policy file, or approval gate. `MINIO_AUDIT_APPROVED_BY`\n(+ `MINIO_AUDIT_RATIONALE`) are optional audit annotations, recorded when set\nand never required.\n\n## Self-test with a local server\n\nAny single-node MinIO works — run the server binary (or a container image)\nwith a local data directory, create a key pair, then:\n\n```bash\nminio-aiops init      # point at 127.0.0.1:9000, secure: No for plain http\nminio-aiops doctor\nminio-aiops overview\n```\n\nErasure-set / healing findings (`heal status`) only show substance on a\nmulti-drive deployment.\n\nFile v0.12.2:skill-card.md\n\n## Description:\n\nMinIO AIops helps agents operate and diagnose MinIO object storage, including capacity root-cause analysis, bucket exposure audits, lifecycle and retention checks, healing health, service status, per-bucket configuration, and governed storage changes.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, SREs, and storage operators use this skill to triage MinIO health, capacity, exposure, lifecycle, WORM retention, IAM, and healing questions, then produce cautious operational guidance or governed CLI/MCP actions for approved maintenance.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can run an unpinned external package while using MinIO storage credentials.\n\nMitigation: Pin minio-aiops to a reviewed exact version or otherwise verify package integrity before installation.\n\nRisk: Write and administrative operations can affect bucket policy, lifecycle, quota, retention, users, and bucket deletion.\n\nMitigation: Use a dedicated read-only MinIO access key by default, grant write or admin permissions only for an approved maintenance window, and review proposed changes before execution.\n\nRisk: A master password or MinIO credentials in committed configuration could expose storage access.\n\nMitigation: Keep MINIO_AIOPS_MASTER_PASSWORD and MinIO secrets out of committed files; use the encrypted secret store and client environment configuration.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/minio-aiops)\n- [Publisher profile](https://clawhub.ai/user/zw008)\n- [Project homepage](https://github.com/AIops-tools/MinIO-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and structured operational guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May propose MinIO CLI or MCP operations; write operations should be reviewed and run with least-privilege credentials.]\n\n## Skill Version(s):\n\n0.12.2 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.12.1: 7 files, 19869 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (7259b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (3259b), SKILL.md (18197b), _meta.json (131b)\n\nFile v0.12.1:SKILL.md\n\n---\nname: minio-aiops\nslug: minio-aiops\ndisplayName: \"MinIO AIops\"\nsummary: \"Governed MinIO ops: capacity RCA, exposure audit, ILM, WORM retention, IAM, healing, 48 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/MinIO-AIops\ntags: [aiops, mcp, governance, minio]\ndescription: >\n  Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket).\n  Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment.\n  Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only).\n  Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).\ninstaller:\n  kind: uv\n  package: minio-aiops\nargument-hint: \"[minio question or describe your object-storage task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"minio-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"MINIO_AIOPS_CONFIG\",\"MINIO_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/MinIO-AIops\",\"emoji\":\"🪣\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed MinIO operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency. Works against any reasonably current MinIO server (single-node or distributed/erasure-coded); admin features (quota, server info) need admin-capable keys.\n  All write operations are audited to a local SQLite DB under ~/.minio-aiops/ (relocatable via MINIO_AIOPS_HOME).\n  Connection: the S3 API endpoint (host:port, default 9000; SigV4 via the official SDK), plus the unauthenticated health endpoints (/minio/health/live|ready|cluster) and the cluster metrics endpoint (/minio/v2/metrics/cluster — public mode or the default bearer-token mode; the token is derived from the stored credentials, no extra secret). The access key lives in config.yaml; the secret key is stored ENCRYPTED in ~/.minio-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'minio-aiops init' to onboard, or 'minio-aiops secret set <target>' to add one. The store is unlocked by a master password from MINIO_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var MINIO_<TARGET_NAME_UPPER>_SECRET_KEY is still honoured as a fallback with a deprecation warning (migrate with 'minio-aiops secret migrate'). Secrets are held only in memory, never logged or echoed.\n  State-changing operations require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (budget guard + audit + undo + risk-tier labelling). bucket_delete is high-risk, dry-run + double-confirm, and refused unless the bucket is verifiably empty (including versions and delete markers); remove_incomplete_uploads only aborts uploads older than a safety window. Reversible writes (set/delete bucket policy, set_versioning, set/delete lifecycle, set_bucket_quota) capture the prior state and record an inverse undo descriptor.\n  Webhooks: none — no outbound network calls beyond the configured MinIO endpoint.\n  SSL: secure (https) and verify_ssl default to true; disable verification only for self-signed lab certificates.\n  Transitive dependencies: the official minio SDK, httpx, and the MCP SDK. No post-install scripts or background services.\n  Verification status: validated against mocked SDK/HTTP responses; no recorded end-to-end run against a live MinIO server yet. Erasure-set/healing findings need a multi-drive deployment to observe live (a single-node server running 'minio-aiops doctor' is the cheapest live path). See docs/VERIFICATION.md.\n---\n\n# MinIO AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by MinIO, Inc. or any storage vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops) under the MIT license.\n\nGoverned MinIO object-storage operations — **48 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.minio-aiops/`, a token/runaway budget guard, undo-token recording, and a descriptive risk tier on every audit row. The secret key is stored **encrypted** (`~/.minio-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk. Six flagship analyses turn raw state into plain-language **cause + suggested action**: `capacity_rca`, `bucket_exposure_audit`, `lifecycle_gap_analysis`, `healing_health`, `diagnose_retention_gaps`, `diagnose_iam_exposure`.\n\n> **Standalone**: the governance harness is bundled in the package (`minio_aiops.governance`) — minio-aiops has no external skill-family dependency. Verification status and the live-run checklist are in `docs/VERIFICATION.md`.\n\n> **Authorization is not this tool's job**: whether a write is permitted is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate — the guarantee is that every call is audited. Driving this with a smaller / local model? See `references/agent-guardrails.md`.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read or Write |\n|-------|-------|:-----:|:-------------:|\n| **Health** | health_live, health_ready, health_cluster, cluster_status, fleet_overview | 5 | 5 read |\n| **Capacity** | capacity_rca (flagship), usage_by_bucket | 2 | 2 read |\n| **Healing** | healing_health (flagship), drive_status, node_status | 3 | 3 read |\n| **Exposure / ILM** | bucket_exposure_audit (flagship), lifecycle_gap_analysis (flagship) | 2 | 2 read |\n| **Buckets** | bucket_ls, bucket_info, bucket_policy_get, bucket_lifecycle_get, bucket_versioning_get, bucket_quota_get, object_ls, incomplete_uploads_ls, server_info | 9 | 9 read |\n| **Writes** | set_bucket_policy, delete_bucket_policy, set_versioning, set_lifecycle, delete_lifecycle, set_bucket_quota, bucket_delete, remove_incomplete_uploads | 8 | 8 write |\n| **Object lock (WORM)** | bucket_lock_config, object_lock_status, diagnose_retention_gaps (flagship) | 3 | 3 read |\n| | bucket_create, set_default_retention, clear_default_retention, set_legal_hold, set_object_retention | 5 | 5 write |\n| **IAM** | iam_users, iam_groups, iam_policies, diagnose_iam_exposure (flagship) | 4 | 4 read |\n| | create_user, set_user_status, remove_user, attach_user_policy, detach_user_policy | 5 | 5 write |\n| **Undo** | undo_list, undo_apply | 2 | read + replay |\n\nTotals: **48 tools — 28 read, 18 write, 2 undo.** The MCP server exposes all 48; the CLI is a convenience subset.\n\n## Quick Install\n\n```bash\nuv tool install minio-aiops\nminio-aiops init       # interactive wizard: endpoint + access key + encrypted secret key\nminio-aiops doctor\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@aiops-tools/minio-aiops\nopenclaw skills info minio-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- **\"Storage is filling up / writes are failing\"** → `capacity_rca` (capacity vs used, offline drives/nodes, hotspots — cause + action per finding), then `usage_by_bucket` for the biggest consumers\n- **\"Is anything exposed?\"** → `bucket_exposure_audit` (ranked: public read/write policies, missing encryption, versioning off, no lifecycle)\n- **\"Where did my space go?\"** → `lifecycle_gap_analysis` (unbounded noncurrent versions, incomplete multipart uploads, reclaimable estimate) then `remove_incomplete_uploads` + `set_lifecycle` to fix it for good\n- **\"How many more drives can fail?\"** → `healing_health` (per-erasure-set online drives vs write quorum, heal backlog/errors)\n- One-shot triage (`fleet_overview` / `minio-aiops overview`): health + capacity headline + exposure headline\n- Per-bucket questions: `bucket_info` (policy/versioning/lifecycle/encryption/quota/tags in one answer)\n- Safely change policy/versioning/lifecycle/quota (reversible, undo recorded) or delete an **empty** bucket (governed, dry-run + double confirm)\n\n**Do NOT use when** the target is not MinIO — for Ceph/RGW use **ceph-aiops**; for TrueNAS use **truenas-aiops**; for a hypervisor, backup product, container cluster, or network device route to the appropriate **other AIops-tools** skill.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| MinIO: capacity RCA, bucket exposure, ILM gaps, healing, bucket writes | **minio-aiops** (this skill) |\n| Ceph/RGW storage | **ceph-aiops** |\n| TrueNAS storage appliances | **truenas-aiops** |\n| Any other target (hypervisor, backup, cluster, network) | the appropriate **other AIops-tools** skill |\n\n## Common Workflows\n\nEach recipe starts from an RCA read and ends in a governed, reversible write.\nEvery write step accepts `--dry-run`; irreversible ones also double-confirm.\n\n### 1. \"Backups are failing — the cluster says it's out of space\"\n\n1. `minio-aiops overview` → one-shot triage: health + capacity headline + exposure headline.\n2. `minio-aiops capacity rca` → ranked findings with cause + action (`CLUSTER_NEARFULL`, `DRIVES_OFFLINE`, `DRIVE_HOTSPOT`, …). Note which finding is actually driving the fill.\n3. `minio-aiops capacity usage` → the biggest buckets, largest first, so you know where the bytes live.\n4. `minio-aiops bucket ilm-gap` → how much of that is reclaimable: unbounded noncurrent versions and abandoned multipart uploads, with an estimate.\n5. Reclaim the abandoned uploads: `minio-aiops bucket purge-uploads <bucket> --older-than-days 7 --dry-run`, then re-run without `--dry-run` (double confirm — this one is irreversible, only uploads older than the window are aborted).\n6. Cap version growth: `minio-aiops bucket lifecycle-set <bucket> --noncurrent-days 30` (reversible — the prior lifecycle config is captured). Abandoned uploads have no server-side rule — MinIO does not honour a lifecycle abort-incomplete rule — so re-run `purge-uploads` periodically instead.\n7. `minio-aiops capacity rca` again to confirm the finding cleared.\n\n**Failure branch**: if `capacity rca` reports `DRIVES_OFFLINE` rather than genuine data growth, stop — do not delete anything. The space is not gone, it is unavailable. Go to recipe 3 and restore drive/erasure-set health first; purging data under a degraded erasure set removes redundancy you may need.\n\n### 2. \"Someone says one of our buckets is readable from the internet\"\n\n1. `minio-aiops bucket audit` → ranked exposure findings, riskiest first (`PUBLIC_WRITE_POLICY`, `PUBLIC_READ_POLICY`, missing encryption, versioning off, no lifecycle).\n2. `minio-aiops bucket info <bucket>` → the full per-bucket picture (policy, versioning, lifecycle, encryption, quota, tags) so you fix the right thing.\n3. Decide the fix. To remove anonymous access entirely: `minio-aiops bucket policy-set <bucket> --file restricted-policy.json --dry-run`, then re-run for real. To drop the policy altogether, use the `delete_bucket_policy` MCP tool. Both are reversible — the prior policy JSON is captured.\n4. `minio-aiops undo list` → confirm an undo token was recorded for the change you just made.\n5. `minio-aiops bucket audit` → confirm the finding is gone.\n\n**Failure branch**: if the write is refused by the server with an access-denied error, the access key you connected with lacks permission for that operation — the tool does not gate the write, the key does. Connect with a key whose IAM policy allows it (or ask whoever owns the key). If the new policy breaks a legitimate consumer, `minio-aiops undo apply <id>` restores the exact prior policy document.\n\n### 3. \"A drive died — how many more failures can we take?\"\n\n1. `minio-aiops health check` and `minio-aiops health status` → is the cluster serving reads and writes at all right now?\n2. `minio-aiops heal status` → per erasure set: online drives vs write quorum, `failureToleranceRemaining`, healing drives, heal backlog and errors.\n3. `minio-aiops heal drives` → which specific drives are offline or healing.\n4. `minio-aiops heal nodes` → whether the failures cluster on one node (a node problem, not a drive problem).\n5. If `WRITE_QUORUM_AT_EDGE` appears, the next failure stops writes: replace drives before any maintenance, and re-run `heal status` until the backlog drains.\n\n**Failure branch**: if the heal backlog is not shrinking between runs, do not start more maintenance. Check `heal nodes` for an offline node first — a down node makes its drives look like many simultaneous drive failures, and replacing hardware will not fix it.\n\n### 4. \"The auditor asked whether our retained data is actually protected\"\n\n1. `minio-aiops lock gaps` → ranked WORM findings across every bucket. The two that matter most: `LOCK_ENABLED_NO_DEFAULT_RETENTION` (the bucket advertises object lock but retains nothing unless each upload asks) and `LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION` (an expiry rule that retention outlives, so the capacity never returns — both day counts are in the finding).\n2. `minio-aiops lock config <bucket>` → whether object lock is enabled at all. `objectLockEnabled: false` is terminal: S3 accepts the flag only at bucket creation, so the answer is a new bucket plus a migration, not a setting.\n3. `minio-aiops lock status <bucket> <key>` → for a specific object: retention mode, days remaining, legal hold, and `protection.versionDestroyable` with what is blocking it. Note `deleteMarkerStillPossible`: object lock protects the bytes, not the key's visibility.\n4. Close the gap for future uploads: `minio-aiops lock default-set <bucket> GOVERNANCE --days 365 --dry-run`, then for real (reversible — the prior rule is captured).\n5. `minio-aiops lock gaps` again → confirm the finding cleared, and check whether step 4 introduced the lifecycle contradiction from step 1.\n\n**Failure branch**: `lock default-set` refused with \"does not have object lock enabled\" means the bucket can never be made WORM in place — create one with `minio-aiops lock bucket-create <new> --object-lock` and migrate. If the auditor requires retention nobody can lift, that is COMPLIANCE, not GOVERNANCE — and it is genuinely permanent: verified on a live server, root with `--bypass` could not clear it, downgrade it, or delete the version. `set_object_retention` therefore records **no undo token**, refuses any call that would shorten retention already in force, and requires `acknowledge_irreversible=True`. Use GOVERNANCE unless permanence is the actual requirement.\n\n### 5. \"Decommission a retired bucket\"\n\n1. `minio-aiops bucket ls` → confirm the exact bucket name.\n2. `minio-aiops bucket info <bucket>` → verify it is genuinely retired (check versioning, lifecycle and quota, not just the object count).\n3. `minio-aiops bucket uploads <bucket>` → surface incomplete multipart uploads, which keep a bucket non-empty even when it looks empty.\n4. `minio-aiops bucket purge-uploads <bucket> --older-than-days 7` if any remain (dry-run first, double confirm).\n5. `minio-aiops bucket delete <bucket> --dry-run` → shows the API call, changes nothing.\n6. Re-run without `--dry-run`: double confirm, **high** risk. Execution re-checks emptiness (versions and delete markers included) and refuses otherwise — this tool never mass-deletes data.\n\n**Failure branch**: if the delete is refused as non-empty, that is the guard doing its job — the bucket still holds objects, noncurrent versions, delete markers, or incomplete uploads. Go back to step 3, and never work around the guard by deleting data out-of-band; this tool deliberately has no mass-delete path.\n\n## Governance & Safety\n\n- The skill delivers reads and writes and records them; it does **not** decide whether a write is permitted — that is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate.\n- **Audit is the guarantee**: every tool — MCP and CLI alike — is audited to `~/.minio-aiops/audit.db` (relocatable via `MINIO_AIOPS_HOME`). `MINIO_AUDIT_APPROVED_BY` / `MINIO_AUDIT_RATIONALE` are optional annotations recorded when set, never required.\n- The declared `risk_level` (`bucket_delete` is high) is carried into the audit row as a descriptive tier — a label for the reviewer, not a gate.\n- Destructive writes support `--dry-run` and double confirmation at the CLI.\n- Reversible writes record an inverse descriptor capturing the real prior state (policy JSON, lifecycle XML, versioning state, quota).\n\n## References\n\n- `references/capabilities.md` — full tool → API-surface → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.12.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"minio-aiops\",\n  \"version\": \"0.12.1\",\n  \"publishedAt\": 1789207923599\n}\n\nFile v0.12.1:references/agent-guardrails.md\n\n# Agent guardrails — running minio-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The access key you connect with.** Give it a read-only IAM policy. A write\n  then fails at the server, which is the only place the permission actually\n  lives — no skill-side flag can be argued around by a model, but a revoked\n  permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Don't invent a value when a field is missing\" | A field the API did not return comes back as `null`, never as `\"\"` — a bucket with no `createdAt`, an object with no `lastModified`/`versionId`, an upload with no `initiated` time. Absent and empty are distinguishable in the payload. |\n| \"Tell me if the object list was cut off\" | Every bounded listing returns `{\"objects\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}` (and the same shape with `buckets` / `uploads`). Truncation is measured — `object_ls` fetches one row past the limit, the bucket/upload/usage listings measure against the full set — never guessed from the count equalling the limit. |\n| \"Tell me which exposed bucket to fix first\" | `bucket_exposure_audit` returns findings sorted riskiest-first with an explicit `riskScore` and `riskLevel`; `capacity_rca`, `healing_health`, and `lifecycle_gap_analysis` each attach a `severity` plus `cause` and `suggestedAction` to every finding. The priority is in the payload, not implied by list position. |\n| \"Confirm before anything destructive\" | Destructive operations require a `--dry-run`-able preview + double confirmation at the CLI. `bucket_delete` additionally refuses unless the bucket is verifiably empty (including noncurrent versions and delete markers). |\n| \"Log what you did\" | Every call is audited to `~/.minio-aiops/audit.db` regardless of what the model says it did. Reversible writes record their prior state (`priorState`) so `undo_list` / `undo_apply` can roll them back. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a MinIO object-storage deployment through the minio-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current MinIO deployment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result contains a \"truncated\"\n  field that is true, say so and re-run with a higher limit (or a narrower\n  prefix) instead of treating the partial result as complete. An object listing\n  is a page of a bucket, not the bucket.\n- A null field means the API did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  bucket names, object keys, versioning states, or upload IDs.\n- When an analysis returns findings, work in severity order (critical, then\n  warning, then info) and cite the measured number in each finding's \"cause\".\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, exposure, or durability problem unless a tool result\n  supports it. \"usedRatio\" and \"failureToleranceRemaining\" are the numbers that\n  support such a claim.\n- Do not add generic S3 advice that does not follow from the tool output.\n- Do not confuse a bucket name with an object key, or an uploadId with a\n  versionId. A bucket name is the whole bucket; an object key is one object\n  inside it.\n- \"Enabled\", \"Suspended\", and \"Off\" are three distinct versioning states.\n  A suspended bucket is not an unversioned bucket — old versions still exist.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the key's\npermission only when you trust the setup — a `bucket_delete` or a policy change\nis cheap to invoke and expensive to get wrong:\n\n```bash\n# Connect with an access key whose IAM policy is read-only, then:\nminio-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport MINIO_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport MINIO_AUDIT_RATIONALE=\"lifecycle cleanup window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `fleet_overview`, `capacity_rca`, `bucket_exposure_audit`,\n  `lifecycle_gap_analysis`, `healing_health` — they do the multi-step\n  correlation inside one call, so the model does not have to chain reads and\n  keep bucket names straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `limit`/`prefix` on `object_ls` deliberately rather than\n  paging through a whole bucket.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.12.1:references/capabilities.md\n\n# minio-aiops capabilities\n\n> 48 MCP tools (28 read, 18 write, 2 undo) over four access paths:\n> the **S3 API** (official SDK, SigV4), the **admin API**, the unauthenticated\n> **health endpoints**, and the **cluster metrics endpoint**.\n\n## Health (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `health_live` | `GET /minio/health/live` | node liveness (reachable/healthy/status code) |\n| `health_ready` | `GET /minio/health/ready` | node readiness |\n| `health_cluster` | `GET /minio/health/cluster` | write-quorum health (503 = degraded) + live/ready + overall verdict |\n| `cluster_status` | metrics endpoint | nodes/drives online+offline, raw/usable capacity, buckets, objects |\n| `fleet_overview` | composite | health + capacity headline + exposure headline in one call |\n\n## Flagship analyses (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `capacity_rca` | metrics endpoint | findings with **cause + suggestedAction**: CLUSTER_FULL / CLUSTER_NEARFULL / DRIVES_OFFLINE / NODES_OFFLINE / DRIVE_HOTSPOT / DRIVE_IMBALANCE; per-drive usage table |\n| `usage_by_bucket` | metrics endpoint | envelope `{buckets, returned, limit, truncated}` — per-bucket bytes + objects, biggest first |\n| `healing_health` | metrics endpoint | per-erasure-set online drives / write quorum / **failureToleranceRemaining**, healing drives, heal backlog + errors; findings WRITE_QUORUM_LOST / _AT_EDGE / LOW_FAILURE_TOLERANCE / HEALING_IN_PROGRESS / HEAL_ERRORS |\n| `drive_status` | metrics endpoint | per-drive rows (server, drive, used ratio), fullest first |\n| `node_status` | metrics endpoint | nodes online/offline + per-node drive counts |\n| `bucket_exposure_audit` | S3 API per bucket | reports `bucketsAudited`/`bucketsTotal`/`truncated`; **ranked** findings: PUBLIC_WRITE_POLICY / PUBLIC_READ_POLICY / NO_DEFAULT_ENCRYPTION / VERSIONING_OFF / NO_LIFECYCLE with riskScore + riskLevel |\n| `lifecycle_gap_analysis` | S3 API + metrics | reports `bucketsAnalyzed`/`bucketsTotal`/`truncated`; gaps: NONCURRENT_VERSIONS_UNBOUNDED (+reclaimable estimate) / INCOMPLETE_UPLOADS_NO_ABORT_RULE (+counts, ages) / NO_LIFECYCLE_ON_LARGE_BUCKET |\n| `diagnose_retention_gaps` | S3 API per bucket | envelope `{findings, returned, limit, truncated}` + `bucketErrors`; worst-first with `rank`: LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION (both day counts + shortfall) / LOCK_ENABLED_NO_DEFAULT_RETENTION / LOCK_WITHOUT_ACTIVE_VERSIONING / COMPLIANCE_DEFAULT_LONG / GOVERNANCE_DEFAULT_BYPASSABLE |\n\n## Buckets (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `bucket_ls` | `ListBuckets` | envelope `{buckets, returned, limit, truncated}` — name + creation time (`createdAt` is `null`, not `\"\"`, when absent) |\n| `bucket_info` | composite per bucket | policy (present/publicRead/publicWrite), versioning, lifecycle rules, encryption, quota, tags — per-probe failures degrade to an `errors` list |\n| `bucket_policy_get` | `GetBucketPolicy` | verbatim policy JSON + anonymous-access summary |\n| `bucket_lifecycle_get` | `GetBucketLifecycle` | rules as dicts (ruleId, status, prefix, expirationDays, noncurrentExpirationDays, abortIncompleteDays) |\n| `bucket_versioning_get` | `GetBucketVersioning` | Enabled / Suspended / Off |\n| `bucket_quota_get` | admin API | hard quota bytes (0 = unlimited) |\n| `object_ls` | `ListObjectsV2` | envelope `{objects, returned, limit, truncated}` — bounded listing (default 100, max 1000) under a prefix; `truncated` is **measured** (one row over-fetched); `lastModified`/`versionId` are `null` when absent |\n| `incomplete_uploads_ls` | `ListMultipartUploads` | envelope `{uploads, returned, limit, truncated}` — object, uploadId, initiated time (`null` when absent) |\n| `server_info` | admin API | mode, deployment id, server/pool counts |\n\n## Object lock / WORM (read)\n\n| Tool | Returns |\n|------|---------|\n| `bucket_lock_config` | `objectLockEnabled` + `defaultRetention` (+ `defaultRetentionDays`, years converted) + `versioning`. **Keeps two absences apart**: `objectLockEnabled: false` (lock was never enabled and S3 accepts the flag only at bucket creation, so it never can be) vs `true` with `defaultRetention: null` (WORM available, but an upload omitting its own retention header is retained for nothing) |\n| `object_lock_status` | one version's `retention` + `legalHold` + `retentionDaysRemaining`, plus `protection`: `versionDestroyable`, `blockedBy` (they stack), `bypassable`, and `deleteMarkerStillPossible` — a plain DELETE always succeeds on a versioned bucket and hides the key while the retained version survives |\n\n## Writes (governed; all take `dry_run`)\n\n| Tool | Risk | Undo | Notes |\n|------|:----:|:----:|-------|\n| `set_bucket_policy` | medium | prior policy JSON (or delete if none) | policy_json validated as JSON with a Statement |\n| `delete_bucket_policy` | medium | re-apply prior policy JSON | no-op undo when there was none |\n| `set_versioning` | medium | prior state | prior \"Off\" undoes to Suspended (S3 cannot return to Off — noted) |\n| `set_lifecycle` | medium | prior lifecycle XML (or delete if none) | day-count knobs build rules; `lifecycle_xml` applies verbatim (undo path) |\n| `delete_lifecycle` | medium | re-apply prior lifecycle XML | |\n| `set_bucket_quota` | medium | prior quota (0 clears) | admin API |\n| `bucket_delete` | **high** | none (irreversible) | refused unless verifiably empty (versions + delete markers included); priorState = bucket meta |\n| `remove_incomplete_uploads` | medium | none (parts unrecoverable) | age-gated (default: only uploads ≥ 7 days old); priorState = count + sample |\n| `bucket_create` | medium | delete the bucket (empty-only) | `object_lock=True` is the ONLY route to a WORM-capable bucket; reports lock + versioning as **observed**, not echoed |\n| `set_default_retention` | **high** | prior default rule (or clear) | applies to future uploads only; undo restores the rule, objects written under it keep their own retention |\n| `clear_default_retention` | medium | prior default rule | clears the rule only — object lock stays enabled (S3 has no call that disables it) |\n| `set_legal_hold` | medium | prior hold state | the one WORM control reversible by design; stacks with retention |\n| `set_object_retention` | **critical** | **none, and none is possible** | extend-only: shortening/downgrading is refused locally because S3 needs `x-amz-bypass-governance-retention`, which the minio SDK never sends. COMPLIANCE additionally needs `acknowledge_irreversible=True`. Verified on a live MinIO: root with `--bypass` could not clear, downgrade, or version-delete a COMPLIANCE object |\n\n## Out of scope\n\n- Site replication status/management\n- IAM **policy authoring** (creating/editing policy documents; attaching existing\n  ones is supported) and group-membership writes\n- Tiering to remote storage\n\nMissing something you need? **Open an issue or send a PR** — feedback welcome.\n\n## Authorization\n\nThere is no read-only switch, policy file, or approval gate. Whether a write is\npermitted is the agent's decision or the permission of the access key you\nconnect with (a read-only IAM policy makes writes fail at the server). Every\ncall — read or write, MCP or CLI — is audited. See `agent-guardrails.md`.\n\nFile v0.12.1:references/cli-reference.md\n\n# minio-aiops CLI reference\n\n> The CLI is a convenience subset; the full 48-tool surface is via the MCP\n> server (`minio-aiops mcp`). CLI writes delegate to the governed MCP twins,\n> so they are audited + undo-recorded identically.\n\n## Setup & diagnostics\n\n```bash\nminio-aiops init                    # wizard: endpoint, TLS, region, access key; secret key → encrypted store\nminio-aiops doctor                  # config + secrets + live/ready + S3 auth + metrics reachability\nminio-aiops doctor --skip-auth      # config/secrets checks only (no network)\nminio-aiops overview                # health + capacity headline + exposure headline\n```\n\n## Secrets (encrypted store)\n\n```bash\nminio-aiops secret set <target>     # store/replace a secret key (prompted hidden)\nminio-aiops secret list             # names only — values never shown\nminio-aiops secret rm <target>\nminio-aiops secret migrate          # import legacy plaintext .env keys\nminio-aiops secret rotate-password  # re-encrypt under a new master password\n```\n\n## Reads\n\n```bash\nminio-aiops health check            # live + ready + cluster write-quorum\nminio-aiops health status           # nodes/drives/capacity/buckets/objects\nminio-aiops capacity rca            # flagship: capacity findings, cause + action\nminio-aiops capacity usage          # per-bucket usage, biggest first\nminio-aiops heal status             # flagship: erasure-set quorum risk + heal backlog\nminio-aiops heal drives             # per-drive usage, fullest first\nminio-aiops heal nodes              # per-node drive counts\nminio-aiops bucket ls                # --limit caps the listing\nminio-aiops bucket info <bucket>    # policy/versioning/lifecycle/encryption/quota/tags\nminio-aiops bucket audit            # flagship: ranked exposure findings\nminio-aiops bucket ilm-gap          # flagship: ILM gaps + reclaimable estimate\nminio-aiops bucket objects <bucket> # objects under a prefix (--prefix, --limit)\nminio-aiops bucket uploads <bucket> # incomplete multipart uploads\n```\n\n## Writes (all take --dry-run; destructive ones double-confirm)\n\n```bash\nminio-aiops bucket versioning-set <bucket> Enabled|Suspended\nminio-aiops bucket policy-set <bucket> --file policy.json\nminio-aiops bucket lifecycle-set <bucket> --expire-days 90 --noncurrent-days 30 [--prefix logs/]\nminio-aiops bucket quota-set <bucket> <size-bytes>     # 0 clears\nminio-aiops bucket purge-uploads <bucket> [--older-than-days 7]   # double confirm\nminio-aiops bucket delete <bucket>                     # double confirm; refused unless empty\n```\n\n## MCP server\n\n```bash\nexport MINIO_AIOPS_MASTER_PASSWORD=...   # required non-interactively (no TTY)\nminio-aiops mcp                          # or: minio-aiops-mcp\n```\n\nCommon options: `--target/-t <name>` selects a configured target (default: the\nfirst one); `--dry-run` previews a write without executing.\n\n## Truncation\n\nListing commands (`bucket ls`, `bucket objects`, `bucket uploads`,\n`capacity usage`, `bucket audit`, `bucket ilm-gap`) return a\n`{..., \"returned\": N, \"limit\": L, \"truncated\": bool}` envelope and print a\ntrailing `… truncated` note when there is more data — re-run with a higher\n`--limit` rather than treating the output as complete.\n\nFile v0.12.1:references/setup-guide.md\n\n# minio-aiops setup & security guide\n\n> Verification status: mock-validated; no recorded end-to-end run against a\n> live MinIO server yet. The cheapest live check is a single-node server\n> running `minio-aiops doctor` — see `docs/VERIFICATION.md`.\n\n## 1. Install\n\n```bash\nuv tool install minio-aiops        # or: pipx install minio-aiops\n```\n\n## 2. What the tool talks to\n\nFour surfaces on the same MinIO origin:\n\n- **S3 API** (`host:port`, default `9000`) — SigV4-signed via the official\n  SDK; needs an access/secret key pair. Admin features (bucket quota,\n  `server_info`) need **admin-capable** keys.\n- **Health endpoints** — `/minio/health/live`, `/ready`, `/cluster`\n  (unauthenticated by design).\n- **Metrics endpoint** — `/minio/v2/metrics/cluster`. Two auth modes,\n  matching the server's `MINIO_PROMETHEUS_AUTH_TYPE`:\n  - `public` → set `metrics_public: true` for the target; no header sent.\n  - default (`jwt`) → the tool derives a bearer token from the stored\n    credentials at request time. **No extra secret to configure.**\n\n## 3. Onboard a target\n\n```bash\nminio-aiops init\n```\n\nThe wizard prompts for: target name, host, port, **TLS** (default yes),\n**certificate verification** (default yes — answer No only for self-signed lab\ncerts), optional region, access key, secret key (hidden → encrypted store),\nand whether the metrics endpoint is public.\n\nResulting `~/.minio-aiops/config.yaml` (non-secret only):\n\n```yaml\ntargets:\n  - name: lab1\n    host: 192.0.2.10\n    port: 9000\n    access_key: minio-ops\n    secure: true\n    verify_ssl: true\n    region: \"\"\n    metrics_public: false\n```\n\n## 4. Secrets\n\n- Secret keys live **encrypted** in `~/.minio-aiops/secrets.enc`\n  (Fernet + scrypt master password; file chmod 600). Never in config.yaml.\n- Non-interactive use (MCP server, CI): export\n  `MINIO_AIOPS_MASTER_PASSWORD`. MCP clients start the server **without a TTY\n  and without your shell profile** — put the variable in the client's `env`\n  block.\n- Legacy fallback: `MINIO_<TARGET_NAME_UPPER>_SECRET_KEY` (plaintext env) is\n  honoured with a warning — migrate with `minio-aiops secret migrate`.\n\n## 5. Verify\n\n```bash\nminio-aiops doctor\n```\n\nChecks config + secrets, then per target: live/ready endpoints, an\nauthenticated `ListBuckets` (proves the key pair), and metrics reachability\n(the capacity/healing analyses depend on it — a failure prints the\n`metrics_public` hint).\n\n## 6. MCP client config\n\n```json\n{\n  \"mcpServers\": {\n    \"minio-aiops\": {\n      \"command\": \"uvx\",\n      \"args\": [\"--from\", \"minio-aiops\", \"minio-aiops-mcp\"],\n      \"env\": { \"MINIO_AIOPS_MASTER_PASSWORD\": \"your-master-password\" }\n    }\n  }\n}\n```\n\n## 7. Governance state\n\nEverything lives under `~/.minio-aiops/` (relocatable via\n`MINIO_AIOPS_HOME`): `audit.db` (every call) and `undo.db` (inverse descriptors\nfor reversible writes). The tool does not decide whether a write is permitted —\nthat is the agent's judgement or the permission of the access key you connect\nwith (a read-only IAM policy makes writes fail at the server); there is no\nread-only switch, policy file, or approval gate. `MINIO_AUDIT_APPROVED_BY`\n(+ `MINIO_AUDIT_RATIONALE`) are optional audit annotations, recorded when set\nand never required.\n\n## Self-test with a local server\n\nAny single-node MinIO works — run the server binary (or a container image)\nwith a local data directory, create a key pair, then:\n\n```bash\nminio-aiops init      # point at 127.0.0.1:9000, secure: No for plain http\nminio-aiops doctor\nminio-aiops overview\n```\n\nErasure-set / healing findings (`heal status`) only show substance on a\nmulti-drive deployment.\n\nFile v0.12.1:skill-card.md\n\n## Description:\n\nMinIO AIops helps agents diagnose and operate MinIO object storage through health checks, capacity and lifecycle analysis, exposure audits, healing status, bucket configuration reads, and governed storage administration actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, operators, and storage administrators use this skill to investigate MinIO health, capacity, exposure, lifecycle, WORM retention, IAM, and healing issues, then apply scoped bucket or account changes when appropriate. It is intended for MinIO deployments and explicitly routes non-MinIO storage tasks to other skills.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can perform high-impact MinIO administration actions and does not provide a built-in read-only or approval gate.\n\nMitigation: Start with a read-only MinIO IAM key, grant write or admin credentials only for sessions where changes are intended, and use dry-run previews before state-changing operations.\n\nRisk: The skill relies on an external minio-aiops package that can change outside the skill text.\n\nMitigation: Review the package source or pin installation to an exact trusted release before use in sensitive environments.\n\nRisk: Credential handling is sensitive because the MCP server needs access to a master password for non-interactive use.\n\nMitigation: Avoid storing the real master password in ordinary MCP configuration when possible and prefer environment or secret-management controls appropriate to the deployment.\n\nRisk: Disabling TLS certificate verification can hide endpoint impersonation or misconfiguration outside lab environments.\n\nMitigation: Keep TLS verification enabled for production and shared environments; disable it only for self-signed lab certificates.\n\nRisk: The artifact reports mocked validation but no recorded end-to-end run against a live MinIO server.\n\nMitigation: Run minio-aiops doctor and a non-production overview check against the target deployment before relying on live operational findings.\n\n## Reference(s):\n\n- [MinIO AIops homepage](https://github.com/AIops-tools/MinIO-AIops)\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/minio-aiops)\n- [capabilities.md](references/capabilities.md)\n- [setup-guide.md](references/setup-guide.md)\n- [cli-reference.md](references/cli-reference.md)\n- [agent-guardrails.md](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with command examples and structured MinIO operation results]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include bounded listings, ranked findings, dry-run previews, audit context, and undo guidance depending on the requested MinIO task.]\n\n## Skill Version(s):\n\n0.12.1 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.12.0: 7 files, 19695 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (7259b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (3014b), SKILL.md (17887b), _meta.json (131b)\n\nFile v0.12.0:SKILL.md\n\n---\nname: minio-aiops\nslug: minio-aiops\ndisplayName: \"MinIO AIops\"\nsummary: \"Governed MinIO ops: capacity RCA, exposure audit, ILM, WORM retention, IAM, healing, 48 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/MinIO-AIops\ntags: [aiops, mcp, governance, minio]\ndescription: >\n  Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket).\n  Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment.\n  Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only).\n  Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).\ninstaller:\n  kind: uv\n  package: minio-aiops\nargument-hint: \"[minio question or describe your object-storage task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"minio-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"MINIO_AIOPS_CONFIG\",\"MINIO_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/MinIO-AIops\",\"emoji\":\"🪣\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed MinIO operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency. Works against any reasonably current MinIO server (single-node or distributed/erasure-coded); admin features (quota, server info) need admin-capable keys.\n  All write operations are audited to a local SQLite DB under ~/.minio-aiops/ (relocatable via MINIO_AIOPS_HOME).\n  Connection: the S3 API endpoint (host:port, default 9000; SigV4 via the official SDK), plus the unauthenticated health endpoints (/minio/health/live|ready|cluster) and the cluster metrics endpoint (/minio/v2/metrics/cluster — public mode or the default bearer-token mode; the token is derived from the stored credentials, no extra secret). The access key lives in config.yaml; the secret key is stored ENCRYPTED in ~/.minio-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'minio-aiops init' to onboard, or 'minio-aiops secret set <target>' to add one. The store is unlocked by a master password from MINIO_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var MINIO_<TARGET_NAME_UPPER>_SECRET_KEY is still honoured as a fallback with a deprecation warning (migrate with 'minio-aiops secret migrate'). Secrets are held only in memory, never logged or echoed.\n  State-changing operations require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (budget guard + audit + undo + risk-tier labelling). bucket_delete is high-risk, dry-run + double-confirm, and refused unless the bucket is verifiably empty (including versions and delete markers); remove_incomplete_uploads only aborts uploads older than a safety window. Reversible writes (set/delete bucket policy, set_versioning, set/delete lifecycle, set_bucket_quota) capture the prior state and record an inverse undo descriptor.\n  Webhooks: none — no outbound network calls beyond the configured MinIO endpoint.\n  SSL: secure (https) and verify_ssl default to true; disable verification only for self-signed lab certificates.\n  Transitive dependencies: the official minio SDK, httpx, and the MCP SDK. No post-install scripts or background services.\n  Verification status: validated against mocked SDK/HTTP responses; no recorded end-to-end run against a live MinIO server yet. Erasure-set/healing findings need a multi-drive deployment to observe live (a single-node server running 'minio-aiops doctor' is the cheapest live path). See docs/VERIFICATION.md.\n---\n\n# MinIO AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by MinIO, Inc. or any storage vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/MinIO-AIops](https://github.com/AIops-tools/MinIO-AIops) under the MIT license.\n\nGoverned MinIO object-storage operations — **48 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.minio-aiops/`, a token/runaway budget guard, undo-token recording, and a descriptive risk tier on every audit row. The secret key is stored **encrypted** (`~/.minio-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk. Six flagship analyses turn raw state into plain-language **cause + suggested action**: `capacity_rca`, `bucket_exposure_audit`, `lifecycle_gap_analysis`, `healing_health`, `diagnose_retention_gaps`, `diagnose_iam_exposure`.\n\n> **Standalone**: the governance harness is bundled in the package (`minio_aiops.governance`) — minio-aiops has no external skill-family dependency. Verification status and the live-run checklist are in `docs/VERIFICATION.md`.\n\n> **Authorization is not this tool's job**: whether a write is permitted is the agent's judgement or the permission of the access key you connect with (a read-only IAM policy makes writes fail at the server). There is no read-only switch, policy file, or approval gate — the guarantee is that every call is audited. Driving this with a smaller / local model? See `references/agent-guardrails.md`.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read or Write |\n|-------|-------|:-----:|:-------------:|\n| **Health** | health_live, health_ready, health_cluster, cluster_status, fleet_overview | 5 | 5 read |\n| **Capacity** | capacity_rca (flagship), usage_by_bucket | 2 | 2 read |\n| **Healing** | healing_health (flagship), drive_status, node_status | 3 | 3 read |\n| **Exposure / ILM** | bucket_exposure_audit (flagship), lifecycle_gap_analysis (flagship) | 2 | 2 read |\n| **Buckets** | bucket_ls, bucket_info, bucket_policy_get, bucket_lifecycle_get, bucket_versioning_get, bucket_quota_get, object_ls, incomplete_uploads_ls, server_info | 9 | 9 read |\n| **Writes** | set_bucket_policy, delete_bucket_policy, set_versioning, set_lifecycle, delete_lifecycle, set_bucket_quota, bucket_delete, remove_incomplete_uploads | 8 | 8 write |\n| **Object lock (WORM)** | bucket_lock_config, object_lock_status, diagnose_retention_gaps (flagship) | 3 | 3 read |\n| | bucket_create, set_default_retention, clear_default_retention, set_legal_hold, set_object_retention | 5 | 5 write |\n| **IAM** | iam_users, iam_groups, iam_policies, diagnose_iam_exposure (flagship) | 4 | 4 read |\n| | create_user, set_user_status, remove_user, attach_user_policy, detach_user_policy | 5 | 5 write |\n| **Undo** | undo_list, undo_apply | 2 | read + replay |\n\nTotals: **48 tools — 28 read, 18 write, 2 undo.** The MCP server exposes all 48; the CLI is a convenience subset.\n\n## Quick Install\n\n```bash\nuv tool install minio-aiops\nminio-aiops init       # interactive wizard: endpoint + access key + encrypted secret key\nminio-aiops doctor\n```\n\n## When to Use This Skill\n\n- **\"Storage is filling up / writes are failing\"** → `capacity_rca` (capacity vs used, offline drives/nodes, hotspots — cause + action per finding), then `usage_by_bucket` for the biggest consumers\n- **\"Is anything exposed?\"** → `bucket_exposure_audit` (ranked: public read/write policies, missing encryption, versioning off, no lifecycle)\n- **\"Where did my space go?\"** → `lifecycle_gap_analysis` (unbounded noncurrent versions, incomplete multipart uploads, reclaimable estimate) then `remove_incomplete_uploads` + `set_lifecycle` to fix it for good\n- **\"How many more drives can fail?\"** → `healing_health` (per-erasure-set online drives vs write quorum, heal backlog/errors)\n- One-shot triage (`fleet_overview` / `minio-aiops overview`): health + capacity headline + exposure headline\n- Per-bucket questions: `bucket_info` (policy/versioning/lifecycle/encryption/quota/tags in one answer)\n- Safely change policy/versioning/lifecycle/quota (reversible, undo recorded) or delete an **empty** bucket (governed, dry-run + double confirm)\n\n**Do NOT use when** the target is not MinIO — for Ceph/RGW use **ceph-aiops**; for TrueNAS use **truenas-aiops**; for a hypervisor, backup product, container cluster, or network device route to the appropriate **other AIops-tools** skill.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| MinIO: capacity RCA, bucket exposure, ILM gaps, healing, bucket writes | **minio-aiops** (this skill) |\n| Ceph/RGW storage | **ceph-aiops** |\n| TrueNAS storage appliances | **truenas-aiops** |\n| Any other target (hypervisor, backup, cluster, network) | the appropriate **other AIops-tools** skill |\n\n## Common Workflows\n\nEach recipe starts from an RCA read and ends in a governed, reversible write.\nEvery write step accepts `--dry-run`; irreversible ones also double-confirm.\n\n### 1. \"Backups are failing — the cluster says it's out of space\"\n\n1. `minio-aiops overview` → one-shot triage: health + capacity headline + exposure headline.\n2. `minio-aiops capacity rca` → ranked findings with cause + action (`CLUSTER_NEARFULL`, `DRIVES_OFFLINE`, `DRIVE_HOTSPOT`, …). Note which finding is actually driving the fill.\n3. `minio-aiops capacity usage` → the biggest buckets, largest first, so you know where the bytes live.\n4. `minio-aiops bucket ilm-gap` → how much of that is reclaimable: unbounded noncurrent versions and abandoned multipart uploads, with an estimate.\n5. Reclaim the abandoned uploads: `minio-aiops bucket purge-uploads <bucket> --older-than-days 7 --dry-run`, then re-run without `--dry-run` (double confirm — this one is irreversible, only uploads older than the window are aborted).\n6. Cap version growth: `minio-aiops bucket lifecycle-set <bucket> --noncurrent-days 30` (reversible — the prior lifecycle config is captured). Abandoned uploads have no server-side rule — MinIO does not honour a lifecycle abort-incomplete rule — so re-run `purge-uploads` periodically instead.\n7. `minio-aiops capacity rca` again to confirm the finding cleared.\n\n**Failure branch**: if `capacity rca` reports `DRIVES_OFFLINE` rather than genuine data growth, stop — do not delete anything. The space is not gone, it is unavailable. Go to recipe 3 and restore drive/erasure-set health first; purging data under a degraded erasure set removes redundancy you may need.\n\n### 2. \"Someone says one of our buckets is readable from the internet\"\n\n1. `minio-aiops bucket audit` → ranked exposure findings, riskiest first (`PUBLIC_WRITE_POLICY`, `PUBLIC_READ_POLICY`, missing encryption, versioning off, no lifecycle).\n2. `minio-aiops bucket info <bucket>` → the full per-bucket picture (policy, versioning, lifecycle, encryption, quota, tags) so you fix the right thing.\n3. Decide the fix. To remove anonymous access entirely: `minio-aiops bucket policy-set <bucket> --file restricted-policy.json --dry-run`, then re-run for real. To drop the policy altogether, use the `delete_bucket_policy` MCP tool. Both are reversible — the prior policy JSON is captured.\n4. `minio-aiops undo list` → confirm an undo token was recorded for the change you just made.\n5. `minio-aiops bucket audit` → confirm the finding is gone.\n\n**Failure branch**: if the write is refused by the server with an access-denied error, the access key you connected with lacks permission for that operation — the tool does not gate the write, the key does. Connect with a key whose IAM policy allows it (or ask whoever owns the key). If the new policy breaks a legitimate consumer, `minio-aiops undo apply <id>` restores the exact prior policy document.\n\n### 3. \"A drive died — how many more failures can we take?\"\n\n1. `minio-aiops health check` and `minio-aiops health status` → is the cluster serving reads and writes at all right now?\n2. `minio-aiops heal status` → per erasure set: online drives vs write quorum, `failureToleranceRemaining`, healing drives, heal backlog and errors.\n3. `minio-aiops heal drives` → which specific drives are offline or healing.\n4. `minio-aiops heal nodes` → whether the failures cluster on one node (a node problem, not a drive problem).\n5. If `WRITE_QUORUM_AT_EDGE` appears, the next failure stops writes: replace drives before any maintenance, and re-run `heal status` until the backlog drains.\n\n**Failure branch**: if the heal backlog is not shrinking between runs, do not start more maintenance. Check `heal nodes` for an offline node first — a down node makes its drives look like many simultaneous drive failures, and replacing hardware will not fix it.\n\n### 4. \"The auditor asked whether our retained data is actually protected\"\n\n1. `minio-aiops lock gaps` → ranked WORM findings across every bucket. The two that matter most: `LOCK_ENABLED_NO_DEFAULT_RETENTION` (the bucket advertises object lock but retains nothing unless each upload asks) and `LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION` (an expiry rule that retention outlives, so the capacity never returns — both day counts are in the finding).\n2. `minio-aiops lock config <bucket>` → whether object lock is enabled at all. `objectLockEnabled: false` is terminal: S3 accepts the flag only at bucket creation, so the answer is a new bucket plus a migration, not a setting.\n3. `minio-aiops lock status <bucket> <key>` → for a specific object: retention mode, days remaining, legal hold, and `protection.versionDestroyable` with what is blocking it. Note `deleteMarkerStillPossible`: object lock protects the bytes, not the key's visibility.\n4. Close the gap for future uploads: `minio-aiops lock default-set <bucket> GOVERNANCE --days 365 --dry-run`, then for real (reversible — the prior rule is captured).\n5. `minio-aiops lock gaps` again → confirm the f\n\nArchive v0.11.0: 7 files, 19354 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (7259b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (2223b), SKILL.md (17989b), _meta.json (131b)\n\nArchive v0.9.0: 7 files, 17633 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (5071b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (2564b), SKILL.md (15552b), _meta.json (130b)\n\nArchive v0.8.0: 7 files, 17696 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (5071b), references/cli-reference.md (3217b), references/setup-guide.md (3627b), skill-card.md (2849b), SKILL.md (15552b), _meta.json (130b)\n\nArchive v0.7.0: 7 files, 17557 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (5071b), references/cli-reference.md (3232b), references/setup-guide.md (3627b), skill-card.md (2650b), SKILL.md (15412b), _meta.json (130b)\n\nArchive v0.6.0: 7 files, 17608 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (5071b), references/cli-reference.md (3232b), references/setup-guide.md (3627b), skill-card.md (2799b), SKILL.md (15412b), _meta.json (130b)\n\nArchive v0.5.0: 7 files, 17705 bytes\n\nFiles: references/agent-guardrails.md (6712b), references/capabilities.md (5071b), references/cli-reference.md (3232b), references/setup-guide.md (3627b), skill-card.md (3101b), SKILL.md (15412b), _meta.json (130b)","readmeExcerpt":"Skill: minio-aiops Owner: zw008 Summary: Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysi","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"uv tool install minio-aiops\nminio-aiops init       # interactive wizard: endpoint + access key + encrypted secret key\nminio-aiops doctor"},{"language":"bash","snippet":"openclaw plugins install clawhub:@zw008/minio-aiops\nopenclaw skills info minio-aiops          # expect: Visible to model: yes"},{"language":"text","snippet":"You operate a MinIO object-storage deployment through the minio-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current MinIO deployment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result contains a \"truncated\"\n  field that is true, say so and re-run with a higher limit (or a narrower\n  prefix) instead of treating the partial result as complete. An object listing\n  is a page of a bucket, not the bucket.\n- A null field means the API did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  bucket names, object keys, versioning states, or upload IDs.\n- When an analysis returns findings, work in severity order (critical, then\n  warning, then info) and cite the measured number in each finding's \"cause\".\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, exposure, or durability problem unless a tool result\n  supports it. \"usedRatio\" and \"failureToleranceRemaining\" are the numbers that\n  support such a claim.\n- Do not add generic S3 advice that does not follow from the tool output.\n- Do not confuse a bucket name with an object key, or an uploadId with a\n  versionId. A bucket name is the whole bucket; an object key is one object\n  inside it.\n- \"Enabled\", \"Suspended\", and \"Off\" are three distinct versioning states.\n  A suspended bucket is not an unversioned bucket — old versions still exist."},{"language":"bash","snippet":"# Connect with an access key whose IAM policy is read-only, then:\nminio-aiops doctor"},{"language":"bash","snippet":"export MINIO_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport MINIO_AUDIT_RATIONALE=\"lifecycle cleanup window 2026-07-20\""},{"language":"bash","snippet":"minio-aiops init                    # wizard: endpoint, TLS, region, access key; secret key → encrypted store\nminio-aiops doctor                  # config + secrets + live/ready + S3 auth + metrics reachability\nminio-aiops doctor --skip-auth      # config/secrets checks only (no network)\nminio-aiops overview                # health + capacity headline + exposure headline"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: minio-aiops\nslug: minio-aiops\ndisplayName: \"MinIO AIops\"\nsummary: \"Governed MinIO ops: capacity RCA, exposure audit, ILM, WORM retention, IAM, healing, 48 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/MinIO-AIops\ntags: [aiops, mcp, governance, minio]\ndescription: >\n  Use this skill whenever the user needs to operate or diagnose MinIO object storage — explain why the cluster is filling up or refusing writes (capacity_rca), find publicly exposed buckets and hygiene gaps (bucket_exposure_audit), find storage that lifecycle/ILM should be reclaiming but isn't, including noncurrent versions and incomplete multipart uploads (lifecycle_gap_analysis), check heal backlog and erasure-set write-quorum risk (healing_health), read service health / cluster status / per-bucket config (policy, versioning, lifecycle, encryption, quota, tags) — plus governed writes (set or delete bucket policy, enable/suspend versioning, set or delete lifecycle rules, set bucket quota, purge incomplete uploads, delete an empty bucket).\n  Always use this skill for \"minio health\", \"why is my object storage full\", \"which bucket is biggest\", \"is any bucket public / anonymous access\", \"versioning / noncurrent versions piling up\", \"incomplete multipart uploads\", \"lifecycle / ILM rules\", \"bucket quota\", \"erasure set / drive failure tolerance\", \"healing backlog\", or \"delete a bucket safely\" when the context is a MinIO deployment.\n  Do NOT use when the target is not MinIO — for Ceph/RGW use ceph-aiops; for TrueNAS storage use truenas-aiops; for a hypervisor, backup product, container cluster, or network device route to the appropriate other AIops-tools skill (negative routing hint only).\n  Common MinIO ops with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).\ninstaller:\n  kind: uv\n  package: minio-aiops\nargument-hint: \"[minio question or describe your object-storage task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"minio-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"MINIO_AIOPS_CONFIG\",\"MINIO_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/MinIO-AIops\",\"emoji\":\"🪣\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed MinIO operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency. Works against any reasonably current MinIO server (single-node or distributed/erasure-coded); admin features (quota, server info) need admin-capable keys.\n  All write operations are audited to a local SQLite DB under ~/.minio-aiops/ (relocatable via MINIO_AIOPS_HOME).\n  Connection: the S3 API endpoint (host:port, default 9000; SigV4 via the official SDK), plus the unauthenticated health endpoints (/minio/health/live|ready|cluster) and the cluster metrics endpoint (/minio/v2/metrics/cluster — public mode or the default bearer-token mode; the token is derived from the stored credentials, no extra secret). The acc"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"minio-aiops\",\n  \"version\": \"0.12.3\",\n  \"publishedAt\": 1789452271684\n}"},{"path":"references/agent-guardrails.md","content":"# Agent guardrails — running minio-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The access key you connect with.** Give it a read-only IAM policy. A write\n  then fails at the server, which is the only place the permission actually\n  lives — no skill-side flag can be argued around by a model, but a revoked\n  permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Don't invent a value when a field is missing\" | A field the API did not return comes back as `null`, never as `\"\"` — a bucket with no `createdAt`, an object with no `lastModified`/`versionId`, an upload with no `initiated` time. Absent and empty are distinguishable in the payload. |\n| \"Tell me if the object list was cut off\" | Every bounded listing returns `{\"objects\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}` (and the same shape with `buckets` / `uploads`). Truncation is measured — `object_ls` fetches one row past the limit, the bucket/upload/usage listings measure against the full set — never guessed from the count equalling the limit. |\n| \"Tell me which exposed bucket to fix first\" | `bucket_exposure_audit` returns findings sorted riskiest-first with an explicit `riskScore` and `riskLevel`; `capacity_rca`, `healing_health`, and `lifecycle_gap_analysis` each attach a `severity` plus `cause` and `suggestedAction` to every finding. The priority is in the payload, not implied by list position. |\n| \"Confirm before anything destructive\" | Destructive operations require a `--dry-run`-able preview + double confirmation at the CLI. `bucket_delete` additionally refuses unless the bucket is verifiably empty (including noncurrent versions and delete markers). |\n| \"Log what you did\" | Every call is audited to `~/.minio-aiops/audit.db` regardless of what the model says it did. Reversible writes record their prior state (`priorState`) so `undo_list` / `undo_apply` can roll them b"},{"path":"references/capabilities.md","content":"# minio-aiops capabilities\n\n> 48 MCP tools (28 read, 18 write, 2 undo) over four access paths:\n> the **S3 API** (official SDK, SigV4), the **admin API**, the unauthenticated\n> **health endpoints**, and the **cluster metrics endpoint**.\n\n## Health (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `health_live` | `GET /minio/health/live` | node liveness (reachable/healthy/status code) |\n| `health_ready` | `GET /minio/health/ready` | node readiness |\n| `health_cluster` | `GET /minio/health/cluster` | write-quorum health (503 = degraded) + live/ready + overall verdict |\n| `cluster_status` | metrics endpoint | nodes/drives online+offline, raw/usable capacity, buckets, objects |\n| `fleet_overview` | composite | health + capacity headline + exposure headline in one call |\n\n## Flagship analyses (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `capacity_rca` | metrics endpoint | findings with **cause + suggestedAction**: CLUSTER_FULL / CLUSTER_NEARFULL / DRIVES_OFFLINE / NODES_OFFLINE / DRIVE_HOTSPOT / DRIVE_IMBALANCE; per-drive usage table |\n| `usage_by_bucket` | metrics endpoint | envelope `{buckets, returned, limit, truncated}` — per-bucket bytes + objects, biggest first |\n| `healing_health` | metrics endpoint | per-erasure-set online drives / write quorum / **failureToleranceRemaining**, healing drives, heal backlog + errors; findings WRITE_QUORUM_LOST / _AT_EDGE / LOW_FAILURE_TOLERANCE / HEALING_IN_PROGRESS / HEAL_ERRORS |\n| `drive_status` | metrics endpoint | per-drive rows (server, drive, used ratio), fullest first |\n| `node_status` | metrics endpoint | nodes online/offline + per-node drive counts |\n| `bucket_exposure_audit` | S3 API per bucket | reports `bucketsAudited`/`bucketsTotal`/`truncated`; **ranked** findings: PUBLIC_WRITE_POLICY / PUBLIC_READ_POLICY / NO_DEFAULT_ENCRYPTION / VERSIONING_OFF / NO_LIFECYCLE with riskScore + riskLevel |\n| `lifecycle_gap_analysis` | S3 API + metrics | reports `bucketsAnalyzed`/`bucketsTotal`/`truncated`; gaps: NONCURRENT_VERSIONS_UNBOUNDED (+reclaimable estimate) / INCOMPLETE_UPLOADS_NO_ABORT_RULE (+counts, ages) / NO_LIFECYCLE_ON_LARGE_BUCKET |\n| `diagnose_retention_gaps` | S3 API per bucket | envelope `{findings, returned, limit, truncated}` + `bucketErrors`; worst-first with `rank`: LIFECYCLE_CANNOT_EXPIRE_UNDER_RETENTION (both day counts + shortfall) / LOCK_ENABLED_NO_DEFAULT_RETENTION / LOCK_WITHOUT_ACTIVE_VERSIONING / COMPLIANCE_DEFAULT_LONG / GOVERNANCE_DEFAULT_BYPASSABLE |\n\n## Buckets (read)\n\n| Tool | Surface | Returns |\n|------|---------|---------|\n| `bucket_ls` | `ListBuckets` | envelope `{buckets, returned, limit, truncated}` — name + creation time (`createdAt` is `null`, not `\"\"`, when absent) |\n| `bucket_info` | composite per bucket | policy (present/publicRead/publicWrite), versioning, lifecycle rules, encryption, quota, tags — per-probe failures degrade to an `errors` list |\n| `bucket_policy_get` | `GetBucketPolicy` | verbatim policy JSON + anonymous-access s"},{"path":"references/cli-reference.md","content":"# minio-aiops CLI reference\n\n> The CLI is a convenience subset; the full 48-tool surface is via the MCP\n> server (`minio-aiops mcp`). CLI writes delegate to the governed MCP twins,\n> so they are audited + undo-recorded identically.\n\n## Setup & diagnostics\n\n```bash\nminio-aiops init                    # wizard: endpoint, TLS, region, access key; secret key → encrypted store\nminio-aiops doctor                  # config + secrets + live/ready + S3 auth + metrics reachability\nminio-aiops doctor --skip-auth      # config/secrets checks only (no network)\nminio-aiops overview                # health + capacity headline + exposure headline\n```\n\n## Secrets (encrypted store)\n\n```bash\nminio-aiops secret set <target>     # store/replace a secret key (prompted hidden)\nminio-aiops secret list             # names only — values never shown\nminio-aiops secret rm <target>\nminio-aiops secret migrate          # import legacy plaintext .env keys\nminio-aiops secret rotate-password  # re-encrypt under a new master password\n```\n\n## Reads\n\n```bash\nminio-aiops health check            # live + ready + cluster write-quorum\nminio-aiops health status           # nodes/drives/capacity/buckets/objects\nminio-aiops capacity rca            # flagship: capacity findings, cause + action\nminio-aiops capacity usage          # per-bucket usage, biggest first\nminio-aiops heal status             # flagship: erasure-set quorum risk + heal backlog\nminio-aiops heal drives             # per-drive usage, fullest first\nminio-aiops heal nodes              # per-node drive counts\nminio-aiops bucket ls                # --limit caps the listing\nminio-aiops bucket info <bucket>    # policy/versioning/lifecycle/encryption/quota/tags\nminio-aiops bucket audit            # flagship: ranked exposure findings\nminio-aiops bucket ilm-gap          # flagship: ILM gaps + reclaimable estimate\nminio-aiops bucket objects <bucket> # objects under a prefix (--prefix, --limit)\nminio-aiops bucket uploads <bucket> # incomplete multipart uploads\n```\n\n## Writes (all take --dry-run; destructive ones double-confirm)\n\n```bash\nminio-aiops bucket versioning-set <bucket> Enabled|Suspended\nminio-aiops bucket policy-set <bucket> --file policy.json\nminio-aiops bucket lifecycle-set <bucket> --expire-days 90 --noncurrent-days 30 [--prefix logs/]\nminio-aiops bucket quota-set <bucket> <size-bytes>     # 0 clears\nminio-aiops bucket purge-uploads <bucket> [--older-than-days 7]   # double confirm\nminio-aiops bucket delete <bucket>                     # double confirm; refused unless empty\n```\n\n## MCP server\n\n```bash\nexport MINIO_AIOPS_MASTER_PASSWORD=...   # required non-interactively (no TTY)\nminio-aiops mcp                          # or: minio-aiops-mcp\n```\n\nCommon options: `--target/-t <name>` selects a configured target (default: the\nfirst one); `--dry-run` previews a write without executing.\n\n## Truncation\n\nListing commands (`bucket ls`, `bucket objects`, `bucket uploads`,\n`capacity usage`, `bucket audit`, `bucket ilm-gap`) retur"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2168,"uniquenessScore":39,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T18:35:19.633Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T21:52:42.049Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}