Use the Web version

Updated at:

The Web mode is the browser-based cloud resource management workbench of IaC Code. Use it to configure models and cloud credentials, manage multiple sessions, review tool approvals, and track the architecture, cost, and deployment process of a Pipeline. This topic describes the installation, configuration, workbench operations, and network security requirements that are specific to the Web version.

Prerequisites

  • Python 3.10 or later is installed.

  • Git Bash is installed on Windows. For common installation requirements, see Install and configure IaC Code.

  • Model service credentials are ready. To query or manage cloud resources, also prepare the corresponding Alibaba Cloud identity.

Install and start the Web version

Install the optional Web dependencies:

python -m pip install "iac-code[http]"

Start the local service:

iac-code web

Expected result: The service listens on 127.0.0.1:8766 and automatically opens http://127.0.0.1:8766. To change the port or prevent the browser from opening automatically, run the following command:

iac-code web --port 9000 --no-open

Configure a model

Configure a model directly in the Web version. You do not need to enter the REPL first.

  1. Choose Settings > Models.

  2. Select a model provider, and then select or enter a model. Enter the API key. If you use a compatible interface or a self-managed service, enter the API base URL as needed.

  3. Select the reasoning effort as needed. In the advanced settings, you can configure the maximum output tokens and, for supported models, the thinking budget.

  4. Click Save configuration, and then click Set as current model.

    A provider that is configured successfully is shown as available. After you save multiple services, you can switch the provider, model, and reasoning effort for the current session in the session input area.

Configure an Alibaba Cloud identity

  1. Choose Settings > Cloud credentials and select Alibaba Cloud.

  2. Select the default region for cloud resource operations.

  3. Select an authentication method and enter the required information.

    Authentication method

    Web operation

    AccessKey

    Enter the AccessKey ID and AccessKey Secret of the RAM user.

    Security Token Service (STS) token

    Enter the temporary AccessKey and the STS token.

    RAM role

    Enter the base identity, the ARN of the target role, and an optional session name.

    ECS RAM Role

    Enter the role name, or leave it blank on an ECS instance to discover the role from the instance metadata.

    OAuth browser logon

    Select the China site or the international site, and then click Log on with browser.

  4. For methods other than OAuth, click Save cloud credentials. For OAuth, the credentials are saved automatically after the authorization succeeds.

Expected result: The Alibaba Cloud entry is then shown as configured. Use a RAM identity with least privilege, and avoid storing a long-term AccessKey of your Alibaba Cloud account. For credential security principles, see Install and configure IaC Code.

Create your first session

  1. Click New chat and select an IaC working directory.

  2. Select standard mode or an available Pipeline, and set the model, thinking toggle, and permission mode for the current session.

  3. Enter the following read-only request:

    List the ROS stacks under the current account in cn-hangzhou, group them by status, and explain the cause of each abnormal status. Query only. Do not perform write operations.
  4. Review the tool name and parameters on the tool card, and approve or deny the permission request as needed.

Expected result: The reply is displayed as a stream, and tool calling, results, and approval records are kept in the session. You can then continue to ask IaC Code to plan a new environment, generate and validate IaC, estimate the cost, and deploy after confirmation. You can also query, update, or delete an existing stack.

Use the Web workbench

Functional area

Operations that you can perform

Session sidebar

Switch projects, and create, search for, pin, rename, archive, and restore sessions.

Input area

Switch the model, reasoning effort, thinking toggle, and permission mode. Use slash commands, Skill, @ file references, and image attachments.

Conversation and tool cards

View model replies, tool parameters, results, and errors, and approve or deny operations.

Pipeline workspace

View the stages, diagnostics, architecture diagram, cost, deployment progress, and handover information of a multi-step task.

Settings

Manage models, cloud credentials, the default session mode, permissions, language, memory, and other runtime settings.

Plug-ins

View, enable, and disable Skill, and add, check, authenticate, enable, disable, or delete MCP Server.

Manage projects and sessions

Each session is associated with a project directory. After you switch the working directory in the project selector, you can view the sessions of that project. The sidebar supports session search, pinning, renaming, and archiving. Choose Settings > Archived chats to restore or delete archived records.

The Web version and the REPL share the same session storage. Sessions created from the command-line interface (CLI) appear in the Web version. You can also continue a Web session from a terminal by running the following command:

iac-code --resume <session ID or name>

Use standard mode and Pipeline

Standard mode displays the conversation, tool calls, and results directly, which suits exploratory cloud resource tasks. A Pipeline splits a complex task into fixed stages and shows solution candidates, validation, cost, deployment progress, diagnostics, and handover information in the workspace. Before you select a Pipeline, confirm that it applies to your current business scenario.

Manage tool approvals

The permission mode of a session determines when an approval is requested. When a confirmation is required, the Web mode displays a permission card in the conversation. Before you approve, check the target files, commands, cloud API operations, regions, and resources. Confirm high-risk operations such as deletion, update, or Internet exposure one at a time.

Use Skills and MCP

Choose Settings > Plug-ins to switch between the Skills and MCP tabs. On the Skills tab, you can view, search for, enable, and disable extended processes. On the MCP tab, you can add or edit servers, check connections and capabilities, complete OAuth, handle project-level trust, and enable, disable, or delete configurations. For complete operations, see Extend IaC Code.

Network access security

If no access token is set, the Web version listens only on the loopback address of the local host and cannot use 0.0.0.0. To allow access from another host, explicitly enable the encrypted token mode with a high-strength random token, and restrict access by using a firewall, a trusted network, and an HTTPS reverse proxy. For example, on Linux or macOS, run the following commands:

python -c "import base64,secrets; print(base64.urlsafe_b64encode(secrets.token_bytes(32)).decode().rstrip('='))" > web-access.token
chmod 600 web-access.token
iac-code web --host 0.0.0.0 --access-token-file ./web-access.token --no-open

A client must enter this token on first access.

Warning

Do not commit the token to a repository, send it to logs, or distribute it over an insecure channel. If you do not need network access, keep the default loopback address configuration.

FAQ

The Web page is inaccessible

Confirm that the service in the terminal has not exited, and check the address and port. If the port is in use, run iac-code web --port <available port>. In the default mode, the Web version is accessible only from the host that runs IaC Code.

A model shows as unavailable

Choose Settings > Models and check the model name, API base URL, and API key. Confirm that the model is set as the current model after you save it. In an enterprise environment, also check the proxy and the connectivity to the target model service.

A cloud resource operation reports insufficient permissions

Choose Settings > Cloud credentials and check the authentication method, validity period, and region. Confirm that the RAM identity has the least privilege required for the target operation. After temporary credentials such as OAuth or STS credentials expire, log on again or refresh them.

Existing sessions or Skill do not appear in the Web version

Confirm that the currently selected project directory is correct. Sessions and project-level Skill are both discovered by working directory. If a read-only session was created from an external entry point, allow it to appear in the general settings under Settings.

References