Creates and runs a Cloud Assistant command on one or more ECS instances. Supports Shell, PowerShell, or Bat script types, and provides features such as scheduled execution, custom parameters, and execution within containers on instances.
Operation description
This is an asynchronous operation. After the request is sent successfully, you can call DescribeInvocations or DescribeInvocationResults to query the execution results by using the returned command ID or invocation ID.
Before you begin
The target instance must be in the Running state. You can call DescribeInstances to query the instance status.
- The target instance must have Cloud Assistant Agent installed. You can install it by calling InstallCloudAssistant and query the installation status by calling DescribeCloudAssistantStatus.
Note
ECS instances created from public images after December 1, 2017 have Cloud Assistant Agent pre-installed by default.
To run PowerShell commands, ensure that the Windows operating system on the target ECS instance has the PowerShell module configured.
Precautions
-
In a single region, you can retain 500 to 50,000 Cloud Assistant commands. You can also request a quota increase. For more information, see Quota management.
-
The Cloud Assistant Agent version must be no earlier than the following versions to support new features of scheduled tasks (execution at fixed intervals, one-time execution at a specified time, and Cron-based scheduled execution with year or time zone specified). If the
ClientNeedUpgradeerror code is returned, see Upgrade or disable upgrades for Cloud Assistant Agent to update the agent to the latest version.- Linux: 2.2.3.282 - Windows: 2.1.3.282 -
When you run a Cron-based scheduled task with a specified time zone, the scheduled execution time is based on the specified time zone. When you do not specify a time zone, the scheduled execution time is based on the system time zone of the ECS instance, and the execution time is determined by the system time of the instance. Ensure that the time or time zone of the ECS instance is consistent with your expectations. For more information about time zones, see Configure the time zone and NTP service for a Linux instance or Configure the NTP service for a Windows instance.
Recommendations
- Timeout settings: You can specify the
Timeoutparameter to set the maximum timeout period for command execution on an ECS instance. When a command times out, Cloud Assistant Agent forcefully stops the process.After a one-time execution times out, the execution status (InvokeRecordStatus) changes to execution fault (Failed).
For scheduled executions, the timeout period applies to each execution record. A timeout in the previous execution does not affect the next execution. After a timeout occurs, the execution status (InvokeRecordStatus) changes to execution fault (Failed).
Execution failures: A command may fail to execute due to abnormal target instance status, network exceptions, or Cloud Assistant Agent exceptions. When a command fails to execute, no execution information is generated. For more information, see Common errors and solutions for execution failures.
Custom parameters: When
EnableParameter=true, the custom parameter feature is enabled. When settingCommandContent, you can define custom parameters in the{{parameter}}format and pass in custom parameter key-value pairs when running the command.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ecs:RunCommand |
update |
*Instance
|
|
None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID. You can call DescribeRegions to query the most recent region list. |
cn-hangzhou |
| ResourceGroupId |
string |
No |
The resource group ID for the command execution. When this parameter is specified:
|
rg-bp67acfmxazb4p**** |
| Name |
string |
No |
The command name. All character sets are supported. The name cannot exceed 128 characters in length. |
testName |
| Description |
string |
No |
The command description. All character sets are supported. The description cannot exceed 512 characters in length. |
testDescription |
| Type |
string |
Yes |
The command type. Valid values:
|
RunShellScript |
| CommandContent |
string |
Yes |
The command content. The command content can be plaintext or Base64-encoded. Note the following items:
|
ZWNobyAxMjM= |
| WorkingDir |
string |
No |
The working directory of the command on the ECS instance. The value cannot exceed 200 characters in length. Default values:
|
/home/user |
| Timeout |
integer |
No |
The timeout period for command execution. Unit: seconds. A timeout occurs when a command cannot be run because of process issues, missing modules, or missing Cloud Assistant Agent. When a timeout occurs, the command process is forcefully terminated. Default value: 60. |
3600 |
| EnableParameter |
boolean |
No |
Specifies whether the command contains custom parameters. Default value: false. |
false |
| RepeatMode |
string |
No |
The execution mode of the command. Valid values:
Default values:
Precautions:
|
Once |
| Timed |
boolean |
No |
[Deprecated] This parameter is deprecated. Passing in this parameter has no effect. |
true |
| Frequency |
string |
No |
The schedule for running the command. Three scheduling methods are supported: execution at fixed intervals (based on Rate expressions), one-time execution at a specified time, and clock-based scheduled execution (based on Cron expressions).
|
0 */20 * * * ? |
| Parameters |
object |
No |
The key-value pairs of custom parameters to pass in when running a command that contains custom parameters. For example, if the command content is The number of custom parameters ranges from 0 to 10. Note the following items:
Default value: empty, which disables custom parameters. |
{"name":"Jack", "accessKey":"LTAI*************"} |
| KeepCommand |
boolean |
No |
Specifies whether to retain the command after execution. Valid values:
Default value: false. |
false |
| ContentEncoding |
string |
No |
The encoding method of the command content (
Default value: PlainText. Invalid values are treated as PlainText. |
Base64 |
| Username |
string |
No |
The username for running the command on the ECS instance. The value cannot exceed 255 characters in length.
You can also specify another existing user on the instance to run the command. Running Cloud Assistant commands as a regular user is more secure. For more information, see Configure a regular user to run Cloud Assistant commands. |
test |
| WindowsPasswordName |
string |
No |
The name of the password for the user who executes the command on a Windows instance. The value cannot exceed 255 characters in length. When you want to execute a command as a non-default user (System) on a Windows instance, you must specify both Note
This parameter is not required when you execute commands as the root user on a Linux instance or the System user on a Windows instance. |
axtSecretPassword |
| InstanceId |
array |
No |
The instance ID array of ECS instances. Array length: 1 to 100. If any of the specified instances does not meet the execution conditions, you must reselect the instances. You can also request a quota increase in Quota Center (quota name: Maximum number of instances supported for command execute). |
i-bp185dy2o3o6neg**** |
|
string |
No |
The ECS instance ID. |
i-bp185dy2o3o6neg**** |
|
| Tag |
array<object> |
No |
The tag pairs. Array length: 0 to 20. |
|
|
object |
No |
The tag pair. |
||
| Value |
string |
No |
The tag value of the command execution. The value can be an empty string. The value can be up to 128 characters in length and cannot contain |
TestValue |
| Key |
string |
No |
The tag key of the command execute. If this value is specified, it cannot be an empty string. When you use a single tag to filter resources, the resource count under that tag cannot exceed 1,000. When you use multiple tags to filter resources, the resource count of resources that are attached to all specified tags cannot exceed 1,000. If the resource count exceeds 1,000, use the ListTagResources operation to query resources. The key can be up to 64 characters in length and cannot start with |
TestKey |
| ContainerId |
string |
No |
The container ID. Only 64-bit hexadecimal strings are supported. The Precautions:
Note
Only Shell scripts are supported in Linux containers. Specifying an interpreter at the beginning of the script in the format of |
ab141ddfbacfe02d9dbc25966ed971536124527097398d419a6746873fea**** |
| ContainerName |
string |
No |
The container name. Precautions:
Note
Only Shell scripts are supported in Linux containers. Specifying an interpreter at the beginning of the script in the format of |
test-container |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. ClientToken can contain only ASCII characters and cannot exceed 64 characters in length. For more information, see How to ensure idempotence. |
123e4567-e89b-12d3-a456-426655440000 |
| OssOutputDelivery |
string |
No |
The OSS delivery configuration for command execution output.
|
oss://testBucket/testPrefix |
| ResourceTag |
array<object> |
No |
The tags used to filter instances. Array length: 0 to 20. You can run commands in batches on instances with the same tags without specifying InstanceId. |
|
|
object |
No |
The tag used to filter instances. You can run commands in batches on instances with the same tags without specifying InstanceId. |
||
| Value |
string |
No |
The tag value used to filter instances. Precautions:
|
TestValue |
| Key |
string |
No |
The tag key used to filter instances. Precautions:
|
TestKey |
| TerminationMode |
string |
No |
The mode for stopping the task (manual stop or timeout interruption). Valid values:
|
ProcessTree |
| Launcher |
string |
No |
The bootstrap program for script execution. The value cannot exceed 1 KB in length. |
python3 -u {{ACS::ScriptFileName|Ext(".py")}} |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
473469C7-AA6F-4DC5-B3DB-A3DC0DE3**** |
| CommandId |
string |
The command ID. |
c-7d2a745b412b4601b2d47f6a768d**** |
| InvokeId |
string |
The invocation ID. |
t-7d2a745b412b4601b2d47f6a768d**** |
Examples
Success response
JSON format
{
"RequestId": "473469C7-AA6F-4DC5-B3DB-A3DC0DE3****",
"CommandId": "c-7d2a745b412b4601b2d47f6a768d****",
"InvokeId": "t-7d2a745b412b4601b2d47f6a768d****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | RegionId.ApiNotSupported | The api is not supported in this region. | The API operation cannot be called in the specified region. Check whether the specified RegionId parameter is valid. |
| 400 | ResourceBusy.SlrCreation | The ServiceLinkedRole is still being created or has not taken effect yet. Please try again later. | |
| 400 | MissingParam.InstanceId | The parameter instanceId is missing or empty. | The instance ID is empty. |
| 400 | NumberExceed.Tags | Ensure the number of tag parameters is not greater than 20. | The number of specified tags exceeds the limit. |
| 400 | InvalidTagValue.Malformed | The specified Tag.n.Value is not valid. | The specified tag value is invalid. |
| 400 | Duplicate.TagKey | The Tag.N.Key contain duplicate key. | The specified tag key already exists. Tag keys must be unique. |
| 400 | InvalidTagKey.Malformed | The specified Tag.n.Key is not valid. | The specified Tag.N.Key parameter is invalid. |
| 400 | MissingParameter.TagKey | You must specify Tag.N.Key. | The tag key is not specified. |
| 400 | InvalidContainerId.Malformed | The specified parameter ContainerId is not valid. | The specified container ID is invalid. |
| 400 | InvalidContainerName.Malformed | The specified parameter ContainerName is not valid. | The specified container name is invalid. |
| 400 | InvalidClientToken.Malformed | The specified parameter clientToken is not valid. | The specified ClientToken parameter does not meet the format requirements. The parameter must contain only ASCII characters and cannot exceed 64 characters in length. |
| 400 | CmdParam.EmptyKey | Command parameters can not be empty. | |
| 400 | CmdParam.InvalidParamName | A command parameter name is invalid. | |
| 400 | CmdContent.DecodeError | The CommandContent can not be base64 decoded. | The command content cannot be Base64-decoded. |
| 400 | InvalidInstance.NotMatch | The specified instance type does not match the command. | |
| 400 | MissingParam.Frequency | The frequency must be specified when you create a timed task. | |
| 400 | InvalidParam.Frequency | The specified frequency is invalid. | |
| 400 | ParameterKey.Duplicate | The parameter may not contain duplicate keys. | The parameter name cannot be duplicated. Verify the parameter name and try again. |
| 400 | Parameter.NotMatched | The parameters of creation do not match those of invocation. | The custom parameters passed in do not match the custom parameters defined when the command was created. |
| 400 | WindowsPasswordName.Missed | WindowsPasswordName must be specified when you create a Windows task. | |
| 400 | Parameter.Disabled | Parameters should not be passed when CreateCommand.EnableParameter is false. | Do not pass custom parameters when you disable the custom parameter feature for a command. |
| 400 | InvalidParameter.WorkingDir | The specified parameter WorkingDir is not valid. | The specified WorkingDir parameter is invalid. |
| 400 | NumberExceed.ResourceTags | The maximum number of ResourceTags is exceeded. | |
| 400 | MissingParameter.ResourceTagKey | You must specify ResourceTag.N.Key. | |
| 400 | InvalidResourceTagKey.Malformed | The specified ResourceTag key is not valid. | |
| 400 | InvalidResourceTagValue.Malformed | The specified ResourceTag value is not valid. | |
| 400 | Duplicate.ResourceTagKey | The ResourceTag contains duplicate keys. | |
| 400 | InvalidResourceTag.InstanceNotFound | InstanceIds are not found by the specified ResourceTag. | |
| 400 | InvalidResourceTag.ConflictWithInstanceIds | The specified param ResourceTag conflicts with InstanceId. | |
| 400 | InvalidOssOutputDelivery.BucketInOtherRegion | The OSS bucket specified in the parameter OssOutputDelivery is in another region. | The OSS bucket specified in the parameter OssOutputDelivery is in another region. |
| 400 | InvalidParameter.OssOutputDelivery | The specified parameter OssOutputDelivery is not valid. | The specified parameter OssOutputDelivery is not valid. |
| 400 | InvalidOssOutputDelivery.KeyPrefixMalformed | The prefix of the OSS key specified in the parameter OssOutputDelivery is not valid. | The prefix of the OSS key specified in the parameter OssOutputDelivery is not valid. |
| 500 | InternalError.Dispatch | An error occurred when you dispatched the request. | An error occurred while the request is being sent. Try again later. |
| 403 | InvalidOssOutputDelivery.BucketAccessDenied | The error message returned by the OSS API is: %s | |
| 403 | CmdContent.ExceedLimit | The length of the command content exceeds the upper limit. | The length of command content exceeds the upper limit. |
| 403 | CmdName.ExceedLimit | The length of the command name exceeds the upper limit. | The length of the command name exceeds the upper limit. |
| 403 | CmdDesc.ExceedLimit | The length of the command description exceeds the upper limit. | The length of the command description exceeds the upper limit. |
| 403 | CmdCount.ExceedQuota | The total number of commands in the current region exceeds the quota. | The maximum number of Cloud Assistant commands in the current region has been exceeded. |
| 403 | CmdParamCount.ExceedLimit | You've reached the limit on the count of command parameters. | |
| 403 | CmdParamName.ExceedLimit | The length of the command parameter name exceeds the limit. | The custom parameter name length in the command exceeds the upper limit. |
| 403 | InstanceIds.ExceedLimit | The number of instance IDs exceeds the upper limit. | The number of specified instance IDs exceeds the upper limit. |
| 403 | Invocation.ExceedQuota | The invocation quota in the current region has been reached for today. | The maximum daily number of commands that can be run in the specified region has been reached. |
| 403 | ParameterCount.ExceedLimit | The number of command parameters exceeds the maximum number that can be set. | The number of custom parameters exceeds the limit. |
| 403 | ParameterKey.ExceedLimit | The length of the specified parameter key exceeds the maximum length that can be set. | The specified parameter key length exceeds the maximum allowed length. |
| 403 | ParameterType.NotSupported | The type of parameter value is not supported. | |
| 403 | Username.ExceedLimit | The length of the username exceeds the upper limit. | The length of the username exceeds the upper limit. |
| 403 | WindowsPasswordName.ExceedLimit | The length of the WindowsPasswordName exceeds the upper limit. | The length of the specified WindowsPasswordName parameter exceeds the upper limit. |
| 403 | ParameterStore.NotSupported | Parameter Store is not supported in this region. | |
| 403 | TemporaryAccessKey.Error | The temporary accessKey is invalid. | |
| 403 | ParameterStore.InvalidParameters | The parameter is invalid in Parameter Store. | The parameter specified by {{oos:?}} in the command content was not found. |
| 403 | ParameterStore.NoPermission | You have no access to Parameter Store. | |
| 403 | OperationDenied.BidOwnResource | Bid user can not own resource. | |
| 403 | Operation.Forbidden | The operation is not permitted. | The operation is not supported. |
| 403 | IdempotentParameterMismatch | The specified parameter has changed while using an already used clientToken. | The specified client token has already been used. |
| 403 | IdempotentProcessing | The previous idempotent request(s) is still processing. | A previous idempotent request is being processed. Try again later. |
| 403 | InvalidStatus.ResourceGroup | You cannot perform an operation on a resource group that is being created or deleted. | Operation not allowed while resource group is being created or deleted. |
| 403 | InvalidParameterCharacter.CommandName | The command Name contains illegal characters. | The command Name contains illegal characters. |
| 403 | InvalidParameterCharacter.CommandDescription | The command Description contains illegal characters. | The command Description contains illegal characters. |
| 403 | InvalidParameterCharacter.CommandWorkingDir | The command WorkingDir contains illegal characters. | The command WorkingDir contains illegal characters. |
| 403 | InvalidLauncher.LengthLimitExceeded | The length of the parameter Launcher exceeds the limit of 1 KB characters. | The length of the argument Launcher exceeds the limit of 1 KB characters. |
| 403 | InvalidParameterCharset.Parameters | The parameter Parameters contains illegal charset. | The command parameter contains an illegal character set. |
| 403 | CreateServiceLinkedRole.NoPermission | You do not have permission to create ServiceLinkedRole for output delivery. | You do not have permission to create ServiceLinkedRole for output delivery. |
| 403 | InvalidTimeout.ExceedLimit | The specified parameter Timeout exceeds the upper limit. | |
| 404 | InvalidCmdType.NotFound | The specified command type does not exist. | |
| 404 | InvalidRepeatMode.NotFound | The specified repeat mode does not exist. | The specified command execution mode does not exist. |
| 404 | InvalidRegionId.NotFound | The RegionId provided does not exist in our records. | Region information error |
| 404 | InvalidInstance.NotFound | The specified instance does not exist. | The specified instance does not exist. |
| 404 | InvalidCmdId.NotFound | The specified command ID does not exist. | The specified CommandId parameter is invalid. Check the parameter value. You can call the DescribeCommands operation to query all available command IDs. |
| 404 | InvalidResourceGroup.NotFound | The ResourceGroup provided does not exist in our records. | The specified resource group does not exist. |
| 404 | InvalidTerminationMode.NotFound | The specified parameter TerminationMode does not exist. | The specified parameter TerminationMode does not exist. |
| 404 | InvalidOssOutputDelivery.BucketNotFound | The OSS bucket specified in the parameter OssOutputDelivery does not exist. | The OSS bucket specified in the parameter OssOutputDelivery does not exist. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.