An ECS instance is placed under a security lock if a security event is triggered due to security violations, such as cryptocurrency mining, fraud, or the distribution of harmful information. This topic describes how a security lock affects API calls to the instance.
Determine if an instance is security-locked
Call the DescribeInstances operation. If the
OperationLocksparameter in the response containsLockReason: security, the instance is security-locked.Log on to the ECS console. In the left-side navigation pane, choose . An instance is security-locked if an event for it appears on the Events of Instances Blocked for Security Reasons tab.
On the Events of Instances Blocked for Security Reasons tab, the table shows event details. For example, the event name is Instance Blocked for Security Violation, the event level is Critical, the event status is Pending, and the event reason is "Violation of Article 15 of the Measures for the Administration of Internet Information Services".
API call impact
API operations not listed in the following table are unaffected.
API | Impact |
StartInstance | The operation fails and returns the |
StopInstance | Unaffected. |
RebootInstance | The operation fails and returns the |
RebootInstances | The operation fails and returns the |
DeleteInstance | Unaffected. |
DeleteInstances | Unaffected. |
DescribeInstanceStatus | Unaffected. |
DescribeInstances | Unaffected. |
DescribeInstanceTypes | Unaffected. |
DescribeInstanceAttribute | Unaffected. |
ModifyInstanceAttribute | The operation fails and returns the |
ModifyInstanceChargeType | The operation fails and returns the |
ModifyInstanceSpec | The operation fails and returns the |
ModifyPrepayInstanceSpec | The operation fails and returns the |
ModifyInstanceAutoReleaseTime | The operation fails and returns the |
AttachInstanceRamRole | Unaffected. |
DescribeInstanceRamRole | Unaffected. |
DetachInstanceRamRole | Unaffected. |
DescribeInstanceVncUrl | The operation fails and returns the |
ModifyInstanceVncPasswd | Unaffected. |
ModifyInstanceMetadataOptions | Unaffected. |
DescribeUserData | Unaffected. |
RenewInstance | Unaffected. |
DescribeInstanceAutoRenewAttribute | Unaffected. |
ModifyInstanceAutoRenewAttribute | Unaffected. |
ReActivateInstances | The operation fails. |
CreateImage | The operation fails with the |
CreateDisk | Unaffected. |
DescribeDisks | Unaffected. |
AttachDisk | Unaffected. |
DetachDisk | This error is reported when a cloud disk attached to the ECS instance is in the |
ResizeDisk | When a cloud disk attached to the ECS instance is in use ( |
ModifyDiskAttribute | Unaffected. |
ModifyDiskChargeType | The InstanceLockedForSecurity error occurs when a cloud disk that is attached to the ECS instance is in the |
ModifyDiskSpec | The |
ReplaceSystemDisk | An error occurs if the cloud disk attached to the ECS instance is in the |
ResetDisk | An error occurs when a cloud disk attached to the ECS instance is in the |
ResetDisks | Unaffected. |
ReInitDisk | When a cloud disk mounted on the ECS instance is in the |
DeleteDisk | An error is reported if the cloud disk attached to the ECS instance is in the |
CreateSnapshot | An error is reported when the cloud disk attached to the ECS instance is in use ( |
DescribeSnapshots | Unaffected. |
DeleteSnapshot | Unaffected. |
ModifyAutoSnapshotPolicy | Unaffected. |
ModifyInstanceNetworkSpec | The operation fails and returns the |
AllocatePublicIpAddress | The operation fails and returns the |
ConvertNatPublicIpToEip | The operation fails and returns the |
ModifyInstanceVpcAttribute | Unaffected. |
JoinSecurityGroup | Unaffected. |
LeaveSecurityGroup | Unaffected. |
AttachKeyPair | Unaffected. |
DetachKeyPair | Unaffected. |
RunCommand | The command is accepted but fails to run. No error is returned. |
InvokeCommand | The command is accepted but fails to run. No error is returned. |
GetInstanceScreenshot | The operation fails and returns the |
GetInstanceConsoleOutput | The operation fails and returns the |
DescribeInstanceAttachmentAttributes | Unaffected. |
ModifyInstanceAttachmentAttributes | The operation fails and returns the |
DescribeInstancesFullStatus | Unaffected. |
DescribeDisksFullStatus | Unaffected. |
DescribeInstanceHistoryEvents | Unaffected. |
CreateSimulatedSystemEvents | Unaffected. |
CancelSimulatedSystemEvents | Unaffected. |
AcceptInquiredSystemEvent | Unaffected. |
CreateDiagnosticReport | Unaffected. |
DescribeDiagnosticReports | Unaffected. |
DescribeDiskMonitorData | Unaffected. |
DescribeInstanceMonitorData | Unaffected. |
DescribeInstanceMaintenanceAttributes | Unaffected. |
ModifyInstanceMaintenanceAttributes | Unaffected. |
RedeployInstance | The operation fails. |
ReportInstancesStatus | Unaffected. |
TagResources | Unaffected. |
ListTagResources | Unaffected. |
UntagResources | Unaffected. |
JoinResourceGroup | Unaffected. |