Integrate IaC Code via A2A
The Agent2Agent Protocol (A2A) is used to discover and invoke remote agents. IaC Code can be published as an A2A 1.0 Server to expose cloud resource management capabilities for use by other agents and workflow platforms. This document covers server startup, Agent Card, the first message, context continuation, and authentication.
Prerequisites
IaC Code is installed and configured. For more information, see Install and configure IaC Code.
The optional A2A dependencies are installed.
The server’s allowed working directory and the RAM identity required to invoke cloud resources have been determined.
The network deployment is ready for service authentication, access control, and secret management.
Start the A2A server
Install the optional dependencies and start a local server:
python -m pip install "iac-code[a2a]"
iac-code a2a --host 127.0.0.1 --port 41242Expected result: The server exposes endpoints for health checks, the Agent Card, and A2A requests.
Get the Agent Card
Use the built-in client:
iac-code a2a-client discover --url http://127.0.0.1:41242/Use HTTP:
curl http://127.0.0.1:41242/.well-known/agent-card.jsonExpected result: The response contains the agent name, the A2A interfaces, the accepted input and output modes, and published capabilities such as iac_generation, iac_review, and aliyun_ros_operations.
Send the first message
iac-code a2a-client call \
--url http://127.0.0.1:41242/ \
--prompt "Query the ROS stacks in cn-hangzhou and summarize the abnormal states. Do not perform any write operations." \
--cwd "$PWD" \
--streamExpected result: The client returns streaming output of task updates and the final result. --cwd is sent as working directory metadata and must be an absolute path that the Server is allowed to access. Paths on a remote Server are server-side filesystem paths, not arbitrary paths on the client’s local machine.
Continue the context and manage tasks
The result of the first call returns the A2A contextId. Later messages carry this value to reuse the IaC Code context.
iac-code a2a-client call \
--url http://127.0.0.1:41242/ \
--context-id "<context-id>" \
--prompt "Continue to analyze the events of the abnormal stacks and provide handling suggestions. Do not perform write operations." \
--cwd "$PWD" \
--streamUse task-get, task-list, task-cancel, and task-subscribe to query, list, cancel, or subscribe to tasks. A task ID represents one A2A execution, and contextId represents the conversation context that you can reuse across messages.
Configure authentication and the working directory
Authentication
An IaC Code A2A server without authentication is suitable only for a trusted local environment. For a network deployment, enable at least one of Bearer Token, Basic Auth, or API key.
For instance, set a Bearer Token through the Secret of the deployment environment:
export IACCODE_A2A_HTTP_TOKEN="${A2A_SERVICE_TOKEN}"
iac-code a2a --host 127.0.0.1 --port 41242The caller reads the same Secret through --token or through the client configuration. Use IACCODE_A2A_ALLOWED_CWDS to set the list of allowed directories, separated by the path separator of the operating system that runs the server. Configure Agent Card signature and client verification as needed, so that tasks are not sent to a forged endpoint.
Do not write the token directly into the command history or into a repository.
Permission considerations
A2A requests usually have no local user to handle permission prompts in real time. The server should configure explicit policies for allowed read and write operations, and by default deny unauthorized write tools. Cloud write APIs still require fine-grained authorization and local auditing, and A2A service authentication cannot replace Alibaba Cloud RAM permissions.
FAQ
The Agent Card or a request returns 401
Agent Card discovery is also protected by the configured authentication method. Make sure that the client sends the correct Bearer Token, Basic Auth, or API key during both discovery and invocation.
A request reports that the working directory is not allowed
Pass in an absolute directory and make sure that it is included in IACCODE_A2A_ALLOWED_CWDS. Do not add the entire file system root directory to the allowlist.
Write operations on the cloud are not performed
Check the tool access policies on the server and the RAM permissions of the identity that the server uses. Do not resolve the issue by turning off permission checks. Allow only the target API operations that the task actually needs, and keep approval and audit records.