All Products
Search
Document Center

Elastic Compute Service:CreateLaunchTemplate

Last Updated:Sep 17, 2026

Creates an ECS instance launch template. A launch template eliminates the need to configure a large number of parameters every time you create an instance.

Operation description

After you call CreateLaunchTemplate to create a template, a default version with version number 1 is automatically generated. You can then create multiple versions based on this template (CreateLaunchTemplateVersion), with version numbers incrementing sequentially from 1. If you do not specify a template version when creating instances (RunInstances), the default version is used.

A launch template version contains the configurations used to create instances, such as the region, image ID, instance type, security group ID, and public bandwidth. If a specific instance configuration is not specified in the version, you must specify it when creating instances.

When you call this operation, take note of the following items:

  • Each account can create up to 30 launch templates per region, and each template can have up to 30 versions.

  • Most parameters in a launch template are optional. When you create a template, Alibaba Cloud does not verify the existence or validity of the parameter values. The validity of parameter values is verified only when you actually create instances.

  • If a specific configuration is set in the launch template, it cannot be filtered out when you create instances (RunInstances). For example, if the template sets HostName=LocalHost and the HostName value is left empty in RunInstances, the hostname of the instance is still LocalHost. To override the HostName=LocalHost configuration, set HostName=MyHost or another value in RunInstances.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

ecs:CreateLaunchTemplate

create

*LaunchTemplate

acs:ecs:{#regionId}:{#accountId}:launchtemplate/*

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID. You can call DescribeRegions to query the most recent region list.

cn-hangzhou

TemplateTag

array<object>

No

The tag information of the launch template itself.

Note

Currently, you can create and query tags for launch templates only by calling API operations. You cannot create or view these tags in the console.

object

No

The tag key-value pairs of the launch template itself.

Key

string

No

The tag key of the launch template. Valid values of N: 1 to 20. The tag key cannot be an empty string. The tag key can be up to 128 characters in length and cannot start with aliyun or acs:. The tag key cannot contain http:// or https://.

TestKey

Value

string

No

The tag value of the launch template. Valid values of N: 1 to 20. The tag value can be an empty string. The tag value can be up to 128 characters in length and cannot start with aliyun or acs:. The tag value cannot contain http:// or https://.

TestValue

RegionId

string

Yes

The name of the launch template. The name must be 2 to 128 characters in length. It must start with a letter and cannot start with http:// or https://. The name can contain digits, colons (:), underscores (_), and hyphens (-).

testLaunchTemplateName

LaunchTemplateName

string

Yes

The description of the launch template version. The description must be 2 to 256 characters in length and cannot start with http:// or https://.

testVersionDescription

VersionDescription

string

No

The image ID. You can call DescribeImages to query available image resources.

win2008r2_64_ent_sp1_en-us_40G_alibase_20170915.vhd

ImageId

string

No

The source of the image. Valid values:

  • system: public images provided by Alibaba Cloud.

  • self: custom images that you created.

  • others: shared images from other Alibaba Cloud accounts.

  • marketplace: images provided by Alibaba Cloud Marketplace. You can use Alibaba Cloud Marketplace images directly without subscribing to them first. Check the billing details of Alibaba Cloud Marketplace images on your own.

system

ImageOwnerAlias

string

No

Specifies whether to use the preset password of the image.

Note

When you use this parameter, the Password parameter must be empty. Make sure that the image you use has a password preset.

false

PasswordInherit

boolean

No

The instance type. For more information, see Instance family. You can also invoke DescribeInstanceTypes to query the most recent instance type list.

ecs.g5.large

InstanceType

string

No

The ID of the security group to which the new instance belongs. Instances in the same security group can communicate with each other. A security group can contain up to 1,000 instances.

Note

You cannot specify both SecurityGroupId and SecurityGroupIds.N at the same time.

sg-bp15ed6xe1yxeycg****

SecurityGroupId

string

No

The ID of the virtual private cloud (VPC).

vpc-bp12433upq1y5scen****

VpcId

string

No

The vSwitch ID. This parameter is required when you create a VPC-connected instance.

vsw-bp1s5fnvk4gn2tws0****

VSwitchId

string

No

The name of the instance. The name must be 2 to 128 characters in length and can contain characters from the Unicode letter category (including letters in English, Chinese, and digits). The name can contain colons (:), underscores (_), periods (.), and hyphens (-). The default value is the InstanceId of the instance.

When you create multiple ECS instances, you can set sequential instance names that contain brackets ([]) and commas (,). For more information, see Batch configure sequential names or hostnames for multiple instances.

k8s-node-[1,4]-alibabacloud

InstanceName

string

No

The description of the instance. The description must be 2 to 256 characters in length and cannot start with http:// or https://.

testECSDescription

Description

string

No

The maximum inbound public bandwidth. Unit: Mbit/s. Valid values:

  • If the purchased outbound public bandwidth is less than or equal to 10 Mbit/s: 1 to 10. Default value: 10.

  • If the purchased outbound public bandwidth is greater than 10 Mbit/s: 1 to the value of InternetMaxBandwidthOut. Default value: the value of InternetMaxBandwidthOut.

10

InternetMaxBandwidthIn

integer

No

The maximum outbound public bandwidth. Unit: Mbit/s. Valid values: 0 to 100.

10

InternetMaxBandwidthOut

integer

No

The hostname of the Elastic Compute Service server.

  • The hostname cannot start or end with a period (.) or a hyphen (-). It cannot contain consecutive periods (.) or hyphens (-).

  • For Windows instances: The hostname must be 2 to 15 characters in length and cannot contain periods (.) or consist entirely of digits. It can contain letters, digits, and hyphens (-).

  • For other instances such as Linux: The hostname must be 2 to 64 characters in length. You can use periods (.) to separate the hostname into multiple segments. Each segment can contain letters, digits, and hyphens (-).

testHostName

HostName

string

No

The zone ID of the instance.

cn-hangzhou-g

ZoneId

string

No

The category of the system disk. Valid values:

  • cloud: basic disk.

  • cloud_efficiency: ultra disk.

  • cloud_ssd: standard SSD.

  • cloud_essd: enterprise SSD (ESSD). You can use the SystemDisk.PerformanceLevel parameter to configure the performance level of the disk.

  • cloud_auto: ESSD AutoPL disk.

  • cloud_essd_entry: ESSD Entry disk.

For retired instance types that are not I/O optimized instances, the default value is cloud. For other instance types, the default value is cloud_efficiency.

cloud_ssd

SystemDisk.Category

string

No

The size of the system disk. Unit: GiB. Valid values:

  • cloud: 20 to 500.

  • Other disk categories: 20 to 2048.

The value of this parameter must be greater than or equal to max{20, ImageSize}.

40

SystemDisk.Size

integer

No

The name of the system disk. The name must be 2 to 128 characters in length. It must start with a letter and cannot start with http:// or https://. The name can contain digits, colons (:), underscores (_), and hyphens (-).

testSystemDiskName

SystemDisk.DiskName

string

No

The description of the system disk. The description must be 2 to 256 characters in length and cannot start with http:// or https://.

testSystemDiskDescription

SystemDisk.Description

string

No

Note

This parameter is in invitational preview and is not publicly available.

null

SystemDisk.Iops

integer

No

The performance level of the ESSD used as the system disk. Settings for the performance level of the disk. Valid values:

  • PL0 (default): A single disk can deliver up to 10,000 random read/write IOPS.

  • PL1: A single disk can deliver up to 50,000 random read/write IOPS.

  • PL2: A single disk can deliver up to 100,000 random read/write IOPS.

  • PL3: A single disk can deliver up to 1,000,000 random read/write IOPS.

For information about how to select ESSD performance levels, see Enterprise SSDs.

PL0

SystemDisk.PerformanceLevel

string

No

Specifies whether to release the system disk when the instance is released. Valid values:

  • true: The system disk is released together with the instance.

  • false: The system disk is not released together with the instance.

Default value: true.

true

SystemDisk.DeleteWithInstance

boolean

No

The ID of the automatic snapshot policy applied to the system disk.

sp-gc7c37d4ylw7mtnk****

SystemDisk.AutoSnapshotPolicyId

string

No

The provisioned read/write IOPS of the ESSD AutoPL disk. Valid values: 0 to min{50000, 1000 × Capacity - Baseline performance}.

Baseline performance = min{1,800 + 50 × Capacity, 50,000}

Note

This parameter is available only when DiskCategory is set to cloud_auto. For more information, see ESSD AutoPL disks and Modify the provisioned performance of an ESSD AutoPL disk.

50000

SystemDisk.ProvisionedIops

integer

No

Specifies whether to enable the performance burst feature. Valid values:

  • true: Enable the performance burst feature.

  • false: Disable the performance burst feature.

true

SystemDisk.BurstingEnabled

boolean

No

Specifies whether the instance is I/O optimized. Valid values:

  • none: The instance is not I/O optimized.

  • optimized: The instance is I/O optimized.

optimized

IoOptimized

string

No

The billing method of the instance. Valid values:

  • PrePaid: subscription. If you set this parameter to PrePaid, confirm that your account supports credit payments. Otherwise, an InvalidPayMethod fault is returned.

  • PostPaid: pay-as-you-go.

PrePaid

InstanceChargeType

string

No

The subscription duration of the resource. Unit: months. This parameter takes effect and is required only when InstanceChargeType is set to PrePaid. Valid values: 1, 2, 3, 4, 5, 6, 7, 8, 9, 12, 24, 36, 48, and 60.

1

Period

integer

No

The billing method for network usage. Valid values:

  • PayByBandwidth: pay-by-bandwidth.

  • PayByTraffic: pay-by-traffic.

Note

In pay-by-traffic mode, the peak inbound and outbound bandwidths are used as the upper limits of bandwidths instead of guaranteed performance specifications. When resource contention occurs, these peak bandwidths may be limited. If you want guaranteed bandwidths for your business, use the pay-by-bandwidth billing mode.

PayByTraffic

InternetChargeType

string

No

Specifies whether to enable the operating system configuration of the instance.

Note

This parameter will be deprecated. Use other parameters for better compatibility.

false

EnableVmOsConfig

boolean

No

The network type of the instance. Valid values:

  • classic: classic network. This feature has been retired. For more information, see Retirement notice.

  • vpc: VPC.

vpc

NetworkType

string

No

Instance user data of the instance. Instance user data must be encoded in Base64. The raw data can be up to 32 KB in size.

ZWNobyBoZWxsbyBlY3Mh

UserData

string

No

The name of the key pair.

  • For Windows instances, this parameter is ignored. Even if you specify this parameter, only the Password content is used.

  • For Linux instances, the password logon method is disabled during initialization.

testKeyPairName

KeyPairName

string

No

The name of the instance RAM role. You can call the RAM API ListRoles to query the instance RAM roles that you have created.

testRamRoleName

RamRoleName

string

No

The automatic release time. Specify the time in the ISO 8601 standard in the yyyy-MM-ddTHH:mm:ssZ format. The time must be in UTC.

  • If the value of seconds (ss) is not 00, the time is automatically rounded down to the start of the current minute (mm).

  • The earliest release time must be at least half an hour from the current time.

  • The latest release time cannot be more than three years from the current time.

2018-01-01T12:05:00Z

AutoReleaseTime

string

No

The preemption policy for the pay-as-you-go instance. This parameter takes effect when InstanceChargeType is set to PostPaid. Valid values:

  • NoSpot: The instance is a regular pay-as-you-go instance.

  • SpotWithPriceLimit: The instance is a spot instance with a user-defined maximum hourly price.

  • SpotAsPriceGo: The instance is a spot instance for which the market price at the time of purchase is automatically used as the bid price.

NoSpot

SpotStrategy

string

No

The maximum hourly price of the instance. This parameter supports up to three decimal places and takes effect when SpotStrategy is set to SpotWithPriceLimit.

0.97

SpotPriceLimit

number

No

The protection period of the spot instance. Unit: hours. Default value: 1. Valid values:

  • 1: After a spot instance is created, Alibaba Cloud ensures that the instance is not automatically released within 1 hour. After the 1-hour protection period ends, the system compares the bid price with the market price and checks the resource inventory to determine whether to retain automatic release the instance.

  • 0: After a spot instance is created, Alibaba Cloud does not ensure that the instance runs for 1 hour. The system compares the bid price with the market price and checks the resource inventory to determine whether to retain automatic release the instance.

Alibaba Cloud sends an ECS system event notification 5 minutes before the instance is released. Spot instances are billed by second. Select an appropriate protection period based on the expected task execution duration.

Note

This parameter takes effect when SpotStrategy is set to SpotWithPriceLimit or SpotAsPriceGo.

1

SpotDuration

integer

No

The ID of the enterprise resource group to which the instance, block storage, and network interface controller (NIC) belong.

rg-bp67acfmxazb4p****

ResourceGroupId

string

No

The ID of the enterprise resource group to which the launch template belongs.

rg-bp67acfmxazb4p****

TemplateResourceGroupId

string

No

Specifies whether to enable security hardening for the operating system. Valid values:

  • Active: Enables security hardening. This value is applicable only to public images.

  • Deactive: Disables security hardening. This value is applicable to all image types.

Deactive

SecurityEnhancementStrategy

string

No

The private IP address of the instance.

To assign a private IP address to a VPC-connected ECS instance, select an available IP address from the CIDR block of the vSwitch (VSwitchId).

10.1.**.**

PrivateIpAddress

string

No

The ID of the deployment set.

ds-bp1brhwhoqinyjd6****

DeploymentSetId

string

No

The number of randomly generated IPv6 addresses to assign to the primary ENI. Valid values: 1 to 10.

1

Ipv6AddressCount

integer

No

The list of data disk configurations.

1

DataDisk

array<object>

No

The Elastic Network Interface (ENI) information.

object

No

The Elastic Network Interface (ENI) information.

PerformanceLevel

string

No

The performance level of the enterprise SSD used as a data disk. The value of N must be the same as that in DataDisk.N.Category=cloud_essd. Valid values:

  • PL0: a single disk can deliver up to 10,000 random read/write IOPS.

  • PL1 (default): a single disk can deliver up to 50,000 random read/write IOPS.

  • PL2: a single disk can deliver up to 100,000 random read/write IOPS.

  • PL3: a single disk can deliver up to 1,000,000 random read/write IOPS.

For information about how to select an ESSD performance level, see ESSDs.

PL1

Description

string

No

The description of the secondary Elastic Network Interface (ENI). The description must be 2 to 256 characters in length and cannot start with http:// or https://. The value of N in NetworkInterface.N cannot be greater than 1.

testEniDescription

SnapshotId

string

No

The snapshot ID used to create data disk N. Valid values of N: 1 to 16. After you specify DataDisk.N.SnapshotId, the DataDisk.N.Size parameter is ignored. The actual size of the created disk is the size of the specified snapshot.

Note

Snapshots created on or before July 15, 2013 cannot be used. Requests that use such snapshots are rejected.

s-bp17441ohwka0yuh****

Size

integer

No

The size of data disk N. Valid values of N: 1 to 16. Unit: GiB. Valid values:

  • cloud: 5 to 2000.

  • cloud_efficiency: 20 to 32768.

  • cloud_ssd: 20 to 32768.

  • cloud_essd: The valid value range depends on the value of DataDisk.N.PerformanceLevel.
    • PL0: 1 to 32768.

    • PL1: 20 to 32768.

    • PL2: 461 to 32768.

    • PL3: 1261 to 32768.

  • cloud_auto: 1 to 32,768.

  • cloud_essd_entry: 10 to 32,768.

The value of this parameter must be greater than or equal to the size of the snapshot specified by SnapshotId.

2000

Device

string

No

The mount point of the data disk. The naming convention varies based on the number of data disks attached:

  • 1 to 25 data disks: /dev/xvd[b-z]

  • More than 25 data disks: /dev/xvd[aa-zz]. For example, the 26th data disk is named /dev/xvdaa, the 27th data disk is named /dev/xvdab, and so on.

Note

This parameter is intended only for full image (system image) scenarios. You can set this parameter to the mount point of a data disk in the full image and modify the corresponding DataDisk.N.Size and DataDisk.N.Category parameters to change the disk category and size of the data disk in the full image.

/dev/xvdb

DiskName

string

No

The name of the data disk. The name must be 2 to 128 characters in length. It must start with a letter and cannot start with http:// or https://. The name can contain letters, digits, colons (:), underscores (_), and hyphens (-).

testDataDiskName

Category

string

No

The category of data disk N. Valid values:

  • cloud_efficiency: ultra disk.

  • cloud_ssd: standard SSD.

  • cloud_essd: enterprise SSD.

  • cloud: basic disk.

  • cloud_auto: ESSD AutoPL disk.

  • cloud_regional_disk_auto: regional ESSD.

  • cloud_essd_entry: ESSD Entry disk.
    Note

    The cloud_essd_entry value is supported only when InstanceType is set to an instance type in the ecs.u1 or ecs.e family.

  • elastic_ephemeral_disk_standard: elastic ephemeral disk - Standard.

  • elastic_ephemeral_disk_premium: elastic ephemeral disk - Premium Edition.

For I/O optimized instances, the default value is cloud_efficiency. For non-I/O optimized instances, the default value is cloud. Default value details:

  • If InstanceType is set to a retired instance type that is not I/O optimized, the default parameter value is cloud.

  • In other cases, the default value is cloud_efficiency.

cloud_ssd

DeleteWithInstance

boolean

No

Specifies whether the data disk is released when the instance is released. Valid values:

  • true: The data disk is released together with the instance.

  • false: The data disk is not released together with the instance.

Default value: true.

true

Encrypted

string

No

Specifies whether the data disk is encrypted.

false

AutoSnapshotPolicyId

string

No

The ID of the automatic snapshot policy applied to the data disk.

sp-m5e7fa9ute44ssa****

ProvisionedIops

integer

No

The provisioned read/write IOPS of the ESSD AutoPL disk. Valid values: 0 to min{50000, 1000 × Capacity - Baseline Performance}.

Baseline Performance = min{1,800 + 50 × Capacity, 50,000}

Note

This parameter is supported only when DiskCategory is set to cloud_auto. For more information, see ESSD AutoPL disks and Modify the provisioned performance of an ESSD AutoPL disk.

50000

BurstingEnabled

boolean

No

Specifies whether to enable the performance burst feature. Valid values:

  • true: Enabled.

  • false: Disabled.

true

KMSKeyId

string

No

The KMS key ID for the data disk.

0e478b7a-4262-4802-b8cb-00d****

NetworkInterface

array<object>

No

The tags of the instances, disks, and primary ENIs created by using this template version.

Scenarios

After you call the CreateLaunchTemplate operation to create a template, the auto-generated default version is used to create instances. These tags are applied to the instances, disks, and primary ENIs.

object

No

The tags of the instances, disks, and primary ENIs created by using this template version.

VSwitchId

string

No

The vSwitch ID of the network interface controller (NIC).

Note the following items:

  • Valid values of N: 1 to 2. If you set 1 NIC, you can set either a primary or secondary NIC. If you set 2 NICs, you must set one primary NIC and one secondary NIC.

  • If NetworkInterface.N.InstanceType is set to Primary, this parameter is required. This parameter has the same effect as VSwitchId, but you cannot specify both this parameter and VSwitchId.

  • If NetworkInterface.N.InstanceType is set to Secondary or left empty, this parameter is optional. Default value: the vSwitch of the ECS instance.

vsw-bp1s5fnvk4gn2tws0****

NetworkInterfaceName

string

No

The name of the network interface controller (NIC).

Note the following items:

  • Valid values of N: 1 to 2. If you set 1 NIC, you can set either a primary or secondary NIC. If you set 2 NICs, you must set one primary NIC and one secondary NIC.

  • If NetworkInterface.N.InstanceType is set to Primary, you do not need to set this parameter.

testEniName

Description

string

No

The description of the secondary network interface controller (NIC). The description must be 2 to 256 characters in length and cannot start with http:// or https://. The value of N in NetworkInterface.N cannot be greater than 1.

testEniDescription

SecurityGroupId

string

No

The security group ID of the network interface controller (NIC).

Note the following items:

  • Valid values of N: 1 to 2. If you set 1 NIC, you can set either a primary or secondary NIC. If you set 2 NICs, you must set one primary NIC and one secondary NIC.

  • If NetworkInterface.N.InstanceType is set to Primary, this parameter is required. This parameter has the same effect as SecurityGroupId, but you cannot specify SecurityGroupId, SecurityGroupIds.N, or NetworkInterface.N.SecurityGroupIds.N at the same time.

  • If NetworkInterface.N.InstanceType is set to Secondary or left empty, this parameter is optional. Default value: the security group of the ECS instance.

sg-bp15ed6xe1yxeycg****

PrimaryIpAddress

string

No

Adds a network interface controller (NIC) and sets the primary IP address.

Note the following items:

  • Valid values of N: 1 to 2.

    • If you set 1 NIC, you can set either a primary or secondary NIC. If Amount is greater than 1 and you set a primary NIC with this parameter specified, the specified primary IP address is used as the starting address to sequentially allocate consecutive primary IP addresses to multiple ECS instances in batch. In this case, you cannot attach a secondary NIC to the instance.

    • If you set 2 NICs, you must set one primary NIC and one secondary NIC. If Amount is greater than 1 and this parameter is set for the primary NIC, you cannot set a secondary NIC (that is, you cannot set NetworkInterface.2.InstanceType=Secondary).

  • If NetworkInterface.N.InstanceType is set to Primary, this parameter has the same effect as PrivateIpAddress, but you cannot specify both this parameter and PrivateIpAddress.

  • If NetworkInterface.N.InstanceType is set to Secondary or left empty, this parameter sets the primary IP address for the secondary NIC. By default, an IP address is randomly selected from the vSwitch CIDR block to which the NIC belongs.

Note

When you invoke the CreateLaunchTemplate operation, you can attach up to one secondary NIC. After the instance is created, you can call CreateNetworkInterface and AttachNetworkInterface to attach more secondary NICs.

192.168.**.**

SecurityGroupIds

array

No

The IDs of one or more security groups to which the network interface controller (NIC) belongs.

  • The first N has a valid value range of 1 to 2. If you set 1 NIC, you can set either a primary or secondary NIC. If you set 2 NICs, you must set one primary NIC and one secondary NIC.

  • The second N indicates that you can specify one or more security group IDs. The valid value range of N depends on the maximum number of security groups to which an instance can belong. For more information, see Security group limits.

Note the following items:

  • If NetworkInterface.N.InstanceType is set to Primary, you must set this parameter or NetworkInterface.N.SecurityGroupId. This parameter has the same effect as SecurityGroupIds.N, but you cannot specify SecurityGroupId, SecurityGroupIds.N, or NetworkInterface.N.SecurityGroupId at the same time.

  • If NetworkInterface.N.InstanceType is set to Secondary or left empty, this parameter is optional. Default value: the security group of the ECS instance.

sg-bp67acfmxazb4p****

string

No

The IDs of one or more security groups to which the network interface controller (NIC) belongs.

  • The first N has a valid value range of 1 to 2. If you set 1 NIC, you can set either a primary or secondary NIC. If you set 2 NICs, you must set one primary NIC and one secondary NIC.

  • The second N indicates that you can specify one or more security group IDs. The valid value range of N depends on the maximum number of security groups to which an instance can belong. For more information, see Security group limits.

Note the following items:

  • If NetworkInterface.N.InstanceType is set to Primary, you must set this parameter or NetworkInterface.N.SecurityGroupId. This parameter has the same effect as SecurityGroupIds.N, but you cannot specify SecurityGroupId, SecurityGroupIds.N, or NetworkInterface.N.SecurityGroupId at the same time.

  • If NetworkInterface.N.InstanceType is set to Secondary or left empty, this parameter is optional. Default value: the security group of the ECS instance.

sg-bp67acfmxazb4p****

InstanceType

string

No

The type of the network interface controller (NIC). Valid values of N: 1 to 2. If you set 1 NIC, you can set either a primary or secondary NIC. If you set 2 NICs, you must set one primary NIC and one secondary NIC.

Valid values:

  • Primary: primary NIC.

  • Secondary: secondary NIC.

Default value: Secondary.

Secondary

NetworkInterfaceTrafficMode

string

No

The communication mode of the primary ENI. Valid values:

  • Standard: uses the TCP communication mode.

  • HighPerformance: enables the Elastic RDMA Interface (ERI) and uses the RDMA communication mode.

Standard

DeleteOnRelease

boolean

No

Specifies whether to retain the ENI when the instance is released. Valid values:

  • true: The ENI is not retained.

  • false: The ENI is retained.

Default value: true.

Note

This parameter takes effect only for secondary ENIs.

true

Tag

array<object>

No

The IDs of one or more security groups to which the instance belongs. The valid values of N depend on the maximum number of security groups to which an instance can belong. For more information, see Limits.

Note

You cannot specify both SecurityGroupId and SecurityGroupIds.N.

sg-bp15ed6xe1yxeycg7****

object

No

The IDs of one or more security groups to which the instance belongs. The valid values of N depend on the maximum number of security groups to which an instance can belong. For more information, see Limits.

Note

You cannot specify both SecurityGroupId and SecurityGroupIds.N.

sg-bp15ed6xe1yxeycg7****

Key

string

No

The tag key for instances, disks, and primary ENIs created from this template version. Valid values of N: 1 to 20. The tag key cannot be an empty string. The tag key can be up to 128 characters in length and cannot start with aliyun or acs:. The tag key cannot contain http:// or https://.

TestKey

Value

string

No

The tag value for instances, disks, and primary ENIs created from this template version. Valid values of N: 1 to 20. The tag value can be an empty string. The tag value can be up to 128 characters in length and cannot contain http:// or https://.

TestValue

SecurityGroupIds

array

No

Specifies whether to encrypt the system disk. Valid values:

  • true: encrypts the system disk.

  • false: does not encrypt the system disk.

Default value: false.

Note

Zone D in Hong Kong (China) and Zone A in Singapore do not support system disk encryption when you create an instance.

false

string

No

The IDs of one or more security groups to which the instance belongs. The valid value range of N depends on the maximum number of security groups to which an instance can belong. For more information, see Limits.

Note

You cannot specify both SecurityGroupId and SecurityGroupIds.N.

sg-bp15ed6xe1yxeycg7****

SystemDisk.Encrypted

string

No

The release protection attribute of the instance. Specifies whether the instance can be released from the ECS console or by calling the DeleteInstance operation. Valid values:

  • true: enables release protection for the instance.

  • false: disables release protection for the instance.

Default value: false.

Note

This attribute applies only to pay-as-you-go instances. It can only prevent manual release operations, not system-initiated release operations.

false

DeletionProtection

boolean

No

The running mode of the burstable instance. Valid values:

Standard

CreditSpecification

string

No

Specifies whether to enable auto-renewal. Valid values:

  • true: enables auto-renewal.

  • false: does not enable auto-renewal.

Default value: false.

Note

This parameter takes effect only when InstanceChargeType is set to PrePaid.

true

AutoRenew

boolean

No

The auto-renewal period for a single renewal. Valid values:

If PeriodUnit is set to Month: 1, 2, 3, 6, 12, 24, 36, 48, and 60.

Default value: 1.

1

AutoRenewPeriod

integer

No

The unit of the subscription period. Valid values:

Month (default).

Month

PeriodUnit

string

No

Specifies whether to enable the access channel for instance metadata. Valid values:

  • enabled: enables the access channel.

  • disabled: disables the access channel.

Default value: enabled.

Note

For more information about instance metadata, see Overview of instance metadata.

enabled

HttpEndpoint

string

No

Specifies whether to forcefully use the security-hardened mode (IMDSv2) to access instance metadata. Valid values:

  • optional: does not forcefully use the security-hardened mode.

  • required: forcefully uses the security-hardened mode. After you set this parameter to required, you cannot access instance metadata in normal mode.

Default value: optional.

Note

For more information about the modes for accessing instance metadata, see Overview of instance metadata.

optional

HttpTokens

string

No

Note

This parameter is not available for use.

3

HttpPutResponseHopLimit

integer

No

The KMS key ID of the system disk.

0e478b7a-4262-4802-b8cb-00d3fb40****

SystemDisk.KMSKeyId

string

No

The image-related property information.

0e478b7a-4262-4802-b8cb-00d3fb40****

ImageOptions

object

No

The security options.

LoginAsNonRoot

boolean

No

Specifies whether instances that use this image support logon with the ecs-user account. Valid values:

  • true: Supported.

  • false: Not supported.

false

SecurityOptions

object

No

The security options.

TrustedSystemMode

string

No

The trusted system mode. Set the value to vTPM.

The following instance families support trusted system mode:

  • g7, c7, and r7.

  • Enhanced instance families (g7t, c7t, and r7t).

When you create ECS instances of the preceding instance types, you must set this parameter. Take note of the following items:

  • If you use the Alibaba Cloud Trusted System, set this parameter to vTPM. The Alibaba Cloud Trusted System performs trusted verification when the instance starts.

  • If you do not use the Alibaba Cloud Trusted System, you do not need to set this parameter. However, if the ECS instance that you create uses the Enclave-based confidential computing mode (SecurityOptions.ConfidentialComputingMode=Enclave), the trusted system is also enabled for the instance.

  • When you use an OpenAPI operation to create a trusted ECS instance, you can invoke only RunInstances. CreateInstance does not support the SecurityOptions.TrustedSystemMode parameter.

Note

If you specify the instance as a trusted instance during creation, you can replace the system disk only with an image that supports the trusted system.

For more information about the trusted system, see Overview of trusted features for security-enhanced instances.

vTPM

EnableSecureBoot

boolean

No

Response elements

Element

Type

Description

Example

object

LaunchTemplateId

string

The ID of the launch template.

lt-m5eiaupmvm2op9d****

RequestId

string

The request ID.

473469C7-AA6F-4DC5-B3DB-A3DC0DE3****

LaunchTemplateVersionNumber

integer

The version number of the launch template.

20

Examples

Success response

JSON format

{
  "LaunchTemplateId": "lt-m5eiaupmvm2op9d****",
  "RequestId": "473469C7-AA6F-4DC5-B3DB-A3DC0DE3****",
  "LaunchTemplateVersionNumber": 20
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidRegion.NotExist %s The specified region does not exist.
400 MissingParameter %s A parameter is not specified.
400 InvalidParameter %s The specified parameter is invalid.
400 InvalidLaunchTemplateName.Malformed The specified parameter LaunchTemplateName is not valid. The specified LaunchTemplateName parameter is invalid.
400 InvalidDescription.Malformed The specified parameter "VersionDescription" is not valid.
400 InvalidUserData.SizeExceeded %s The size of your specified user data exceeds the maximum allowed value.
400 InvalidUserData.Base64FormatInvalid %s The specified user data is invalid.
400 Duplicate.TagKey The Tag.N.Key contain duplicate key. The specified tag key already exists. Tag keys must be unique.
400 InvalidTagKey.Malformed The specified Tag.n.Key is not valid. The specified Tag.N.Key parameter is invalid.
400 InvalidTagValue.Malformed The specified Tag.n.Value is not valid. The specified tag value is invalid.
400 InvalidHostName.Malformed The specified parameter "HostName" is not valid. The specified parameter HostName is invalid.
400 InvalidParams.CreateEniParams %s
500 InternalError The request processing has failed due to some unknown error.
403 LaunchTemplateLimitExceed %s The maximum number of launch templates has been reached.
403 LaunchTemplateName.Duplicated %s The specified launch template name already exists.
403 QuotaExceed.Tags %s The number of specified tags exceeds the upper limit. %s is a variable. An error message is dynamically returned based on call conditions.
403 InvalidOperation.InstanceTypeSecureBootUnsupported The instance type does not support secure boot. The instance type does not support secure boot.
403 InvalidOperation.SecureBootRegionNotSupported Secure Boot is not available in the specified region. The current region does not support enabling Secure Boot.
404 InvalidResourceGroup.NotFound The ResourceGroup provided does not exist in our records. The specified resource group does not exist.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.