Overview
IaC Code provides cloud resource planning, query, deployment, and lifecycle management capabilities to programmatic callers such as IDE tools, development platforms, user interfaces, automation systems, and other agents. This topic compares the integration methods and locates the onboarding topic for the method that you choose.
Choose an integration method
Integration method | Communication model | Scenario | Onboarding topic |
Headless | Local child process invocation | Shell, CI/CD, scheduled tasks, and simple backend tasks | |
ACP | Stdio JSON-RPC, or HTTP+SSE | IDEs, editors, and clients that require sessions, events, and permissions interactions | |
A2A | A2A 1.0 remote invocation | Agent platforms, multi-agent collaboration, and service discovery | |
AG-UI | HTTP POST and SSE event stream | Web consoles, chat interfaces, and applications that need to display an agent’s process in real time | |
Agent Skill | Skill package and local runtime, or cloud ROS Agent | External agents that support Skills and want to delegate cloud resource tasks directly |
Use the following criteria to select a method:
Headless — Use Headless when one input corresponds to one result and the caller can manage local processes.
ACP — Use ACP when the caller is an agent client, such as an IDE tool or an editor, that creates sessions, receives structured streaming events, and handles permission requests.
A2A — Use A2A when IaC Code needs to serve as a remotely discoverable and collaborative specialized agent.
AG-UI — Use AG-UI when user-facing applications need to display text, thinking, tools, steps, and interaction interruptions in real time.
Agent Skill — Use Agent Skills when the host agent already supports Skills and you want to quickly gain IaC Code capabilities through an installation package.
If your caller only needs to run a command and read the result, do not adopt ACP or A2A only to gain protocol capabilities which adds unnecessary integration complexity. If the host agent already supports Skill, there is no need to implement an A2A client yourself.
Common prerequisites
Headless, ACP, AG-UI, and A2A are already installed and configured with IaC Code. For more information, see Install and configure IaC Code. Agent Skill should be downloaded and installed according to the corresponding sub-document, and does not require installing IaC Code via pip.
The project working directory that IaC Code can access is determined, and so is the identity that IaC Code runs as.
A RAM identity is available for the cloud query and write operations.
The calling side can handle timeouts, cancellations, errors, logs, and credential injection.
Each onboarding topic adds only the prerequisites that are specific to its transport and protocol, and does not repeat the common setup listed above.
Common security requirements
Credential separation — Keep model service credentials, Alibaba Cloud identities, and ACP, AG-UI, or A2A service authentication credentials separate. One type of credential cannot substitute for another.
Least privilege and auditing — Cloud query and write operations run under a RAM identity that has least privilege access. Cloud write operations require precise authorization and auditing.
Access scope — Restrict the working directories, executable tools, and cloud API operations that can be accessed.
Network exposure — Configure authentication for network services, and restrict the request sources by using a private network, a firewall, or a reverse proxy.
Secret handling — Do not hardcode real secrets in command parameters, protocol messages, logs, or examples.
Runtime boundaries — Set timeouts, concurrency limits, cancellation, and failure retry boundaries for processes and network requests.
FAQ
What is the difference between ACP, AG-UI, and A2A?
ACP is designed for agent clients such as IDEs and editors, focusing on session and permission interactions. AG-UI is designed for user-facing applications such as Web consoles and chat interfaces, focusing on standardized real-time display and interrupt recovery. A2A is designed for interoperability between agents, focusing on Agent Cards, remote tasks, context continuation, and service authentication.
What is the difference between Agent Skill and A2A?
Agent Skill is intended for host agents that support Skills. You can install the local iac-code Runtime Skill, or invoke the cloud ROS Agent through the alibabacloud-ros-agent Skill. A2A is intended for agent platforms that need to deploy, discover, and remotely invoke IaC Code on their own; callers need to handle service authentication, tasks, and context. When using Agent Skill, ordinary users do not need to implement an A2A client themselves.
Can the Web version be used as an integration interface?
No. The IaC Code Web version is a browser-based workbench for users, not a stable protocol for programmatic access. Use Headless, ACP, AG-UI, or A2A for programmatic calls. For instructions on using the Web version, see Use the Web version.
Do I need to configure the model and cloud credentials separately for each integration method?
No. Under the same runtime user and configuration directory, you do not need to repeat the configuration. For different hosts, containers, or service accounts, provide the required configuration through a secret management solution and keep permissions isolated.