Use the Web version
The Web mode is the browser-based cloud resource management workbench of IaC Code. Use it to configure models and cloud credentials, manage multiple sessions, review tool approvals, and track the architecture, cost, and deployment process of a Pipeline. This topic describes the installation, configuration, workbench operations, and network security requirements that are specific to the Web version.
Prerequisites
Python 3.10 or later is installed.
Git Bash is installed on Windows. For common installation requirements, see Install and configure IaC Code.
Model service credentials are ready. To query or manage cloud resources, also prepare the corresponding Alibaba Cloud identity.
Install and start the Web version
Install the optional Web dependencies:
python -m pip install "iac-code[http]"Start the local service:
iac-code webExpected result: The service listens on 127.0.0.1:8766 and automatically opens http://127.0.0.1:8766. To change the port or prevent the browser from opening automatically, run the following command:
iac-code web --port 9000 --no-openConfigure a model
Configure a model directly in the Web version. You do not need to enter the REPL first.
Choose Settings > Models.
Select a model provider, and then select or enter a model. Enter the API key. If you use a compatible interface or a self-managed service, enter the API base URL as needed.
Select the reasoning effort as needed. In the advanced settings, you can configure the maximum output tokens and, for supported models, the thinking budget.
Click Save configuration, and then click Set as current model.
A provider that is configured successfully is shown as available. After you save multiple services, you can switch the provider, model, and reasoning effort for the current session in the session input area.
Configure an Alibaba Cloud identity
Choose Settings > Cloud credentials and select Alibaba Cloud.
Select the default region for cloud resource operations.
Select an authentication method and enter the required information.
Authentication method
Web operation
AccessKeyEnter the
AccessKeyID andAccessKey Secretof the RAM user.Security Token Service (STS) token
Enter the temporary
AccessKeyand the STS token.RAM role
Enter the base identity, the ARN of the target role, and an optional session name.
ECS RAM Role
Enter the role name, or leave it blank on an ECS instance to discover the role from the instance metadata.
OAuthbrowser logonSelect the China site or the international site, and then click Log on with browser.
For methods other than
OAuth, click Save cloud credentials. ForOAuth, the credentials are saved automatically after the authorization succeeds.
Expected result: The Alibaba Cloud entry is then shown as configured. Use a RAM identity with least privilege, and avoid storing a long-term AccessKey of your Alibaba Cloud account. For credential security principles, see Install and configure IaC Code.
Create your first session
Click New chat and select an IaC working directory.
Select standard mode or an available Pipeline, and set the model, thinking toggle, and permission mode for the current session.
Enter the following read-only request:
List the ROS stacks under the current account in cn-hangzhou, group them by status, and explain the cause of each abnormal status. Query only. Do not perform write operations.Review the tool name and parameters on the tool card, and approve or deny the permission request as needed.
Expected result: The reply is displayed as a stream, and tool calling, results, and approval records are kept in the session. You can then continue to ask IaC Code to plan a new environment, generate and validate IaC, estimate the cost, and deploy after confirmation. You can also query, update, or delete an existing stack.
Use the Web workbench
Functional area | Operations that you can perform |
Session sidebar | Switch projects, and create, search for, pin, rename, archive, and restore sessions. |
Input area | Switch the model, reasoning effort, thinking toggle, and permission mode. Use slash commands, Skill, |
Conversation and tool cards | View model replies, tool parameters, results, and errors, and approve or deny operations. |
Pipeline workspace | View the stages, diagnostics, architecture diagram, cost, deployment progress, and handover information of a multi-step task. |
Settings | Manage models, cloud credentials, the default session mode, permissions, language, memory, and other runtime settings. |
Plug-ins | View, enable, and disable Skill, and add, check, authenticate, enable, disable, or delete MCP Server. |
Manage projects and sessions
Each session is associated with a project directory. After you switch the working directory in the project selector, you can view the sessions of that project. The sidebar supports session search, pinning, renaming, and archiving. Choose Settings > Archived chats to restore or delete archived records.
The Web version and the REPL share the same session storage. Sessions created from the command-line interface (CLI) appear in the Web version. You can also continue a Web session from a terminal by running the following command:
iac-code --resume <session ID or name>Use standard mode and Pipeline
Standard mode displays the conversation, tool calls, and results directly, which suits exploratory cloud resource tasks. A Pipeline splits a complex task into fixed stages and shows solution candidates, validation, cost, deployment progress, diagnostics, and handover information in the workspace. Before you select a Pipeline, confirm that it applies to your current business scenario.
Manage tool approvals
The permission mode of a session determines when an approval is requested. When a confirmation is required, the Web mode displays a permission card in the conversation. Before you approve, check the target files, commands, cloud API operations, regions, and resources. Confirm high-risk operations such as deletion, update, or Internet exposure one at a time.
Use Skills and MCP
Choose Settings > Plug-ins to switch between the Skills and MCP tabs. On the Skills tab, you can view, search for, enable, and disable extended processes. On the MCP tab, you can add or edit servers, check connections and capabilities, complete OAuth, handle project-level trust, and enable, disable, or delete configurations. For complete operations, see Extend IaC Code.
Network access security
If no access token is set, the Web version listens only on the loopback address of the local host and cannot use 0.0.0.0. To allow access from another host, explicitly enable the encrypted token mode with a high-strength random token, and restrict access by using a firewall, a trusted network, and an HTTPS reverse proxy. For example, on Linux or macOS, run the following commands:
python -c "import base64,secrets; print(base64.urlsafe_b64encode(secrets.token_bytes(32)).decode().rstrip('='))" > web-access.token
chmod 600 web-access.token
iac-code web --host 0.0.0.0 --access-token-file ./web-access.token --no-openA client must enter this token on first access.
Do not commit the token to a repository, send it to logs, or distribute it over an insecure channel. If you do not need network access, keep the default loopback address configuration.
FAQ
The Web page is inaccessible
Confirm that the service in the terminal has not exited, and check the address and port. If the port is in use, run iac-code web --port <available port>. In the default mode, the Web version is accessible only from the host that runs IaC Code.
A model shows as unavailable
Choose Settings > Models and check the model name, API base URL, and API key. Confirm that the model is set as the current model after you save it. In an enterprise environment, also check the proxy and the connectivity to the target model service.
A cloud resource operation reports insufficient permissions
Choose Settings > Cloud credentials and check the authentication method, validity period, and region. Confirm that the RAM identity has the least privilege required for the target operation. After temporary credentials such as OAuth or STS credentials expire, log on again or refresh them.
Existing sessions or Skill do not appear in the Web version
Confirm that the currently selected project directory is correct. Sessions and project-level Skill are both discovered by working directory. If a read-only session was created from an external entry point, allow it to appear in the general settings under Settings.