Creates an Elastic Container Instance (ECI) instance, also known as a container group.
Operation description
When you call CreateContainerGroup to create an ECI instance, the system automatically creates a service-linked role named AliyunServiceRoleForECI to access related cloud services such as ECS and VPC. For more information, see Elastic Container Instance service-linked role.
When you create an ECI instance, you can configure features related to instances, images, storage, and more as needed. For the parameters and descriptions of each feature, see the following documentation:
Instance
ECI supports the following two methods to create instances:
The following features are supported by both creation methods:
Image
Network
Storage
Container configuration
Logging and O&M
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
eci:CreateContainerGroup |
create |
*ContainerGroup
|
|
None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID. |
cn-hangzhou |
| RegionId |
string |
Yes |
The zone to which the instance belongs. If this parameter is left empty, the system automatically selects a zone. Default value: empty. |
cn-hangzhou-b |
| ZoneId |
string |
No |
The ID of the security group to which the instance belongs. Instances within the same security group can access each other. If you do not specify a security group, the system uses the default security group in the region that you selected. Make sure that the inbound rules of the security group contain the protocols and ports that the containers need to expose. If no default security group exists in the region, the system performs automatic creation of a default security group and adds the container protocols and ports that you declared to the inbound rules of the security group. |
sg-uf66jeqopgqa9hdn**** |
| SecurityGroupId |
string |
No |
The ID of the vSwitch to which the instance belongs. You can specify multiple vSwitch IDs (up to 10 at a time), separated by commas (,). Example: If you do not specify a vSwitch, the system uses the default vSwitch in the default VPC of the region that you selected. If no default VPC or default vSwitch exists in the region, the system performs automatic creation of a default VPC and a default vSwitch. Note
The number of IP addresses in the vSwitch CIDR block determines the maximum number of ECI instances that can be created in the vSwitch. Plan the CIDR block in advance. |
vsw-bp1xpiowfm5vo8o3c****,vsw-bp1rkyjgr1xwoho6k**** |
| VSwitchId |
string |
No |
The name of the ECI instance, also known as the container group name. The name must meet the following requirements:
|
nginx-test |
| ContainerGroupName |
string |
Yes |
The restart policy of the instance. Valid values:
Default value: Always. |
Always |
| RestartPolicy |
string |
No |
The ID of the Elastic IP Address (EIP). |
eip-uf66jeqopgqa9hdn**** |
| EipInstanceId |
string |
No |
The number of vCPUs for the instance. Unit: cores. |
1.0 |
| Cpu |
number |
No |
The memory size for the instance. Unit: GiB. |
2.0 |
| Memory |
number |
No |
The resource group ID. |
rg-uf66jeqopgqa9hdn**** |
| ResourceGroupId |
string |
No |
The DNS policy. Valid values:
|
Default |
| DnsPolicy |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can contain only ASCII characters and cannot exceed 64 characters in length. For more information, see How to ensure idempotence. |
123e4567-xxxx-12d3-xxxx-426655440000 |
| ClientToken |
string |
No |
The specified ECS instance type. Multiple instance types are supported. For more information, see Create an instance by specifying ECS instance types. |
ecs.c5.xlarge |
| InstanceType |
string |
No |
The image cache ID. For more information, see Use image caches to accelerate instance creation. |
imc-2zebxkiifuyzzlhl**** |
| ImageSnapshotId |
string |
No |
The name of the instance RAM role. ECI and ECS share instance RAM roles. For more information, see Use an instance RAM role by calling API operations. |
RamTestRole |
| RamRoleName |
string |
No |
The buffer time for the program to handle operations before shutdown. Unit: seconds. |
60 |
| TerminationGracePeriodSeconds |
integer |
No |
Specifies whether to automatically match image caches. Default value: false. |
false |
| AutoMatchImageCache |
boolean |
No |
The number of IPv6 addresses. The value is fixed to 1, which means that an ECI instance can be bindable to one IPv6 address. |
1 |
| Ipv6AddressCount |
integer |
No |
The validity period of the ECI instance. The instance is forcibly terminated after this period expires. Unit: seconds. |
1000 |
| ActiveDeadlineSeconds |
integer |
No |
The bidding policy for the instance. Valid values:
Default value: NoSpot. |
SpotWithPriceLimit |
| SpotStrategy |
string |
No |
The maximum hourly price for the spot instance. The value can be accurate to three decimal places. This parameter is required when SpotStrategy is set to SpotWithPriceLimit. |
0.025 |
| SpotPriceLimit |
number |
No |
The scheduling policy for the ECI instance when multiple zones are configured (by specifying multiple vSwitches through the VSwitchId parameter). Valid values:
For more information, see Create an instance across multiple zones. |
VSwitchOrdered |
| ScheduleStrategy |
string |
No |
The custom directory for saving core files generated by coredump. For more information, see Save core files to a volume. Note
The configured path cannot start with |
/xx/xx/core |
| CorePattern |
string |
No |
Specifies whether to use a shared namespace. Default value: false. |
false |
| ShareProcessNamespace |
boolean |
No |
Indicates whether an EIP is automatically created and associated with the ECI instance. |
true |
| AutoCreateEip |
boolean |
No |
The bandwidth of the EIP. Default value: 5. Unit: Mbit/s. |
5 |
| EipBandwidth |
integer |
No |
The line type of the EIP. Valid values:
|
BGP |
| EipISP |
string |
No |
The existing Internet Shared Bandwidth instance to associate. |
cbwp-2zeukbj916scmj51m**** |
| EipCommonBandwidthPackage |
string |
No |
The hostname. |
test |
| HostName |
string |
No |
The maximum inbound bandwidth. Unit: bytes per second. |
1024000 |
| IngressBandwidth |
integer |
No |
The maximum outbound bandwidth. Unit: bytes per second. |
1024000 |
| EgressBandwidth |
integer |
No |
The number of physical CPU cores. Only specific instance types support custom settings. |
2 |
| CpuOptionsCore |
integer |
No |
The number of threads per core. Only specific instance types support custom settings. A value of 1 disables hyper-threading. |
2 |
| CpuOptionsThreadsPerCore |
integer |
No |
This parameter is not supported. |
1 |
| CpuOptionsNuma |
string |
No |
The additional temporary storage space size. Unit: GiB. |
20 |
| EphemeralStorage |
integer |
No |
The list of tags. You can associate up to 20 tags. For more information, see Use tags to manage instances. |
20 |
| Tag |
array<object> |
No |
The image repository credentials. |
|
|
object |
No |
The image repository credentials. |
||
| Key |
string |
No |
The tag key. This value cannot be an empty string and cannot be duplicate. The tag key can be up to 64 characters in length and cannot start with |
version |
| Value |
string |
No |
The tag value. This value can be an empty string. The tag value can be up to 128 characters in length and cannot start with |
3 |
| ImageRegistryCredential |
array<object> |
No |
The container information. |
|
|
object |
No |
The container information. |
||
| Password |
string |
No |
The password of the image repository. |
yourpassword |
| Server |
string |
No |
The address of the image repository registry. |
registry-vpc.cn-shanghai.aliyuncs.com |
| UserName |
string |
No |
The username of the image repository. |
yourusername |
| Container |
array<object> |
Yes |
The volume information. |
|
|
array<object> |
No |
The volume information. |
||
| ReadinessProbe.TimeoutSeconds |
integer |
No |
The timeout period for the check. Default value: 1 second. Minimum value: 1 second. |
1 |
| ReadinessProbe.SuccessThreshold |
integer |
No |
The minimum number of consecutive successes required to consider the check successful after a failure. Default value: 1. Must be 1. |
1 |
| SecurityContext.Capability.Add |
array |
No |
The permissions granted to processes in the container. Currently, only NET_ADMIN and NET_RAW are supported. Note
NET_RAW is not supported by default and requires a ticket submission. |
|
|
string |
No |
The permissions granted to processes in the container. Currently, only NET_ADMIN and NET_RAW are supported. Note
NET_RAW is not supported by default and requires a ticket submission. |
NET_ADMIN |
|
| ReadinessProbe.TcpSocket.Port |
integer |
No |
The port for TCP Socket health checks. Note
When setting ReadinessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
8000 |
| ReadinessProbe.HttpGet.Scheme |
string |
No |
The protocol type for HTTP request health checks. Valid values:
Note
When setting ReadinessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
HTTP |
| LivenessProbe.PeriodSeconds |
integer |
No |
The interval at which the check is performed. Default value: 10 seconds. Minimum value: 1 second. |
5 |
| SecurityContext.ReadOnlyRootFilesystem |
boolean |
No |
Specifies whether the root file system of the container is read-only. Currently, only true is supported. |
true |
| EnvironmentVar |
array<object> |
No |
The environment variables of the container. |
|
|
object |
No |
The environment variables of the container. |
||
| Key |
string |
No |
The name of the environment variable. The name must be 1 to 128 characters in length. Format: |
PATH |
| Value |
string |
No |
The value of the environment variable. The value must be 0 to 256 characters in length. |
/usr/local/bin |
| FieldRef.FieldPath |
string |
No |
The reference for the environment variable value. Currently, only status.podIP is supported. |
status.podIP |
| LivenessProbe.TcpSocket.Port |
integer |
No |
The port for TCP Socket health checks. Note
When setting LivenessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
8080 |
| Tty |
boolean |
No |
Specifies whether to enable interaction. Default value: false. When Command is /bin/bash, this must be set to true. |
false |
| WorkingDir |
string |
No |
The working directory of the container. |
/usr/local/ |
| Arg |
array |
No |
The arguments for the container startup command. Maximum: 10. |
100 |
|
string |
No |
The arguments for the container startup command. Maximum: 10. |
100 |
|
| Stdin |
boolean |
No |
Specifies whether this container should allocate a buffer for standard input in the container runtime. If not set, reads from standard input in the container will result in EOF. Default value: false. |
false |
| LivenessProbe.InitialDelaySeconds |
integer |
No |
The time to start the check, calculated from when the container finishes starting. |
5 |
| VolumeMount |
array<object> |
No |
The volume mount information. |
|
|
object |
No |
The volume mount information. |
||
| MountPropagation |
string |
No |
The mount propagation setting for the volume. Mount propagation allows volumes mounted by a container to be shared with other containers in the same pod or even with other pods on the same node. Valid values:
Default value: None |
None |
| MountPath |
string |
No |
The directory where the container mounts the volume. Note
The contents under the container mount directory will be directly overwritten by the volume contents. Use with caution. |
/pod/data |
| ReadOnly |
boolean |
No |
Specifies whether the volume is read-only. Default value: false. |
false |
| SubPath |
string |
No |
The sub-path of the volume. |
data2/ |
| Name |
string |
No |
The name of the volume. Same as the Name in Volume. |
default-volume1 |
| ImagePullPolicy |
string |
No |
The image pull policy. Valid values:
|
Always |
| StdinOnce |
boolean |
No |
Specifies whether the standard input stream remains open across multiple attach sessions when standard input is set to true. If StdinOnce is set to true, standard input is opened when the container starts, remains empty until the first client attaches to standard input, then stays open and accepts data until the client disconnects. Standard input is then closed and remains closed until the container restarts. |
false |
| LifecyclePreStopHandlerTcpSocketPort |
integer |
No |
The TCP Socket port for the preStop callback function when using the TCPSocket method. |
90 |
| LifecyclePostStartHandlerHttpGetScheme |
string |
No |
The protocol type for the HTTP Get request when using the HTTP request method to set the postStart callback function. Valid values:
|
HTTPS |
| ReadinessProbe.PeriodSeconds |
integer |
No |
The interval at which the check is performed. Default value: 10 seconds. Minimum value: 1 second. |
3 |
| LivenessProbe.SuccessThreshold |
integer |
No |
The minimum number of consecutive successes required to consider the check successful after a failure. Default value: 1. Must be 1. |
1 |
| Command |
array |
No |
The container startup commands. Maximum: 20. Each command can contain up to 256 characters. |
sleep |
|
string |
No |
The container startup commands. Maximum: 20. Each command can contain up to 256 characters. |
sleep |
|
| LifecyclePostStartHandlerHttpGetHost |
string |
No |
The host address that receives the HTTP Get request when using the HTTP request method to set the postStart callback function. |
10.0.XX.XX |
| TerminationMessagePolicy |
string |
No |
The message notification policy. Default value: empty. Currently, only lightweight message queue notification is supported. |
FallbackToLogsOnError |
| ReadinessProbe.HttpGet.Path |
string |
No |
The path for HTTP Get request health checks. Note
When setting ReadinessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
/healthz |
| LivenessProbe.Exec.Command |
array |
No |
The commands executed in the container for command-based health checks. Note
When setting LivenessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
|
|
string |
No |
The commands executed in the container for command-based health checks. |
cat /tmp/healthy |
|
| LifecyclePostStartHandlerTcpSocketPort |
integer |
No |
The TCP Socket port for the postStart callback function when using the TCPSocket method. |
80 |
| LifecyclePostStartHandlerHttpGetPath |
string |
No |
The HTTP Get request path when using the HTTP request method to set the postStart callback function. |
/healthyz |
| LifecyclePostStartHandlerExec |
array |
No |
The commands executed in the container when using the command method to set the postStart callback function. |
["/bin/sh", "-c", "echo Hello from the postStart handler > /usr/share/message"] |
|
string |
No |
The commands executed in the container when using the command method to set the postStart callback function. |
["/bin/sh", "-c", "echo Hello from the postStart handler > /usr/share/message"] |
|
| LifecyclePreStopHandlerHttpGetPath |
string |
No |
The HTTP Get request path when using the HTTP request method to set the preStop callback function. |
/healthyz |
| Port |
array<object> |
No |
The port numbers. |
|
|
object |
No |
The port numbers. |
||
| Protocol |
string |
No |
The protocol type. Valid values:
|
TCP |
| Port |
integer |
No |
The port number. Valid values: 1 to 65535. |
80 |
| TerminationMessagePath |
string |
No |
The path for the container error message. |
/tmp/termination-log |
| LifecyclePreStopHandlerHttpGetScheme |
string |
No |
The protocol type for the HTTP Get request when using the HTTP request method to set the preStop callback function. Valid values:
|
HTTP |
| LivenessProbe.HttpGet.Scheme |
string |
No |
The protocol type for HTTP request health checks. Valid values:
Note
When setting LivenessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
HTTP |
| ReadinessProbe.HttpGet.Port |
integer |
No |
The port number for HTTP Get request health checks. Note
When setting ReadinessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
8080 |
| LifecyclePostStartHandlerTcpSocketHost |
string |
No |
The host address for TCP Socket detection when using the TCP Socket method to set the postStart callback function. |
10.0.XX.XX |
| Gpu |
integer |
No |
The number of GPUs assigned to the container. |
1 |
| ReadinessProbe.InitialDelaySeconds |
integer |
No |
The time to start the check, calculated from when the container finishes starting. |
3 |
| LifecyclePreStopHandlerExec |
array |
No |
The commands executed in the container when using the command method to set the preStop callback function. |
["/bin/sh", "-c","echo Hello from the preStop handler > /usr/share/message"] |
|
string |
No |
The commands executed in the container when using the command method to set the preStop callback function. |
["/bin/sh", "-c","echo Hello from the preStop handler > /usr/share/message"] |
|
| Memory |
number |
No |
The memory size of the container. Unit: GiB. |
0.5 |
| Name |
string |
Yes |
The volume name. |
default-volume1 |
| LifecyclePreStopHandlerHttpGetHost |
string |
No |
The host address that receives the HTTP Get request when using the HTTP request method to set the preStop callback function. |
10.0.XX.XX |
| LifecyclePreStopHandlerTcpSocketHost |
string |
No |
The host address for TCP Socket detection when using the TCP Socket method to set the preStop callback function. |
10.0.XX.XX |
| Image |
string |
Yes |
The container image. |
registry-vpc.cn-hangzhou.aliyuncs.com/eci_open/nginx:latest |
| LifecyclePreStopHandlerHttpGetPort |
integer |
No |
The HTTP Get request port number when using the HTTP request method to set the preStop callback function. |
88 |
| LivenessProbe.FailureThreshold |
integer |
No |
The minimum number of consecutive failures required to consider the check failed after a success. Default value: 3. |
3 |
| ReadinessProbe.Exec.Command |
array |
No |
The commands executed in the container for command-based health checks. Note
When setting ReadinessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
|
|
string |
No |
The commands executed in the container for command-based health checks. |
cat /tmp/healthy |
|
| LifecyclePreStopHandlerHttpGetHttpHeader |
array<object> |
No |
The HTTP request header parameters. |
|
|
object |
No |
The HTTP request header parameters. |
||
| Value |
string |
No |
The custom field value in the HTTP Get request header when using the HTTP request method to set the preStop callback function. |
test-preStop |
| Name |
string |
No |
The custom field name in the HTTP Get request header when using the HTTP request method to set the preStop callback function. |
Xiao-Custom-Header |
| ReadinessProbe.FailureThreshold |
integer |
No |
The minimum number of consecutive failures required to consider the check failed after a success. Default value: 3. |
3 |
| Cpu |
number |
No |
The vCPU size of the container. Unit: cores. |
0.25 |
| LivenessProbe.HttpGet.Port |
integer |
No |
The port number for HTTP Get request health checks. Note
When setting LivenessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
8888 |
| LivenessProbe.HttpGet.Path |
string |
No |
The path for HTTP Get request health checks. Note
When setting LivenessProbe parameters, only one of the three check methods (HttpGet, Exec, and TcpSocket) can be selected. |
/healthz |
| LivenessProbe.TimeoutSeconds |
integer |
No |
The timeout period for the check. Default value: 1 second. Minimum value: 1 second. |
1 |
| SecurityContext.RunAsUser |
integer |
No |
The user ID used to run the container. |
1000 |
| LifecyclePostStartHandlerHttpGetPort |
integer |
No |
The HTTP Get request port number when using the HTTP request method to set the postStart callback function. |
5050 |
| LifecyclePostStartHandlerHttpGetHttpHeader |
array<object> |
No |
The HTTP request header parameters. |
|
|
object |
No |
The HTTP request header parameters. |
||
| Value |
string |
No |
The custom field value in the HTTP Get request header when using the HTTP request method to set the postStart callback function. |
test-postStart |
| Name |
string |
No |
The custom field name in the HTTP Get request header when using the HTTP request method to set the postStart callback function. |
Xiao-Custom-Header |
| EnvironmentVarHide |
boolean |
No |
Specifies whether to hide environment variable information when querying ECI instance details. Valid values:
|
false |
| SecurityContextRunAsGroup |
integer |
No |
The user group ID used to run the container. |
3000 |
| SecurityContextRunAsNonRoot |
boolean |
No |
Specifies whether to run the container in non-root mode. Valid values:
|
true |
| SecurityContextPrivileged |
boolean |
No |
Specifies whether to enable privilege mode for the container. Valid values:
Note
The privileged container feature is in beta. To use it, submit a ticket. |
true |
| Volume |
array<object> |
No |
The list of init containers. |
|
|
array<object> |
No |
The list of init containers. |
||
| Type |
string |
No |
The volume type. Valid values:
|
ConfigFileVolume |
| DiskVolume.DiskSize |
integer |
No |
The size of the DiskVolume. Unit: GiB. |
15 |
| NFSVolume.Path |
string |
No |
The NFS volume path. |
/share |
| DiskVolume.FsType |
string |
No |
The file system type of the DiskVolume. |
xfs |
| FlexVolume.FsType |
string |
No |
The file system type to mount. Default value depends on the FlexVolume script. |
ext4 |
| HostPathVolume.Type |
string |
No |
The type of the HostPath volume. Valid values:
Note
HostPath volumes are available only to allowlisted users. |
Directory |
| ConfigFileVolume.DefaultMode |
integer |
No |
The default permissions of the ConfigFileVolume. |
0644 |
| NFSVolume.ReadOnly |
boolean |
No |
Specifies whether the NFS volume is read-only. Default value: false. |
false |
| ConfigFileVolume.ConfigFileToPath |
array<object> |
No |
The ConfigFile volume information. If multiple ConfigFileToPath entries are configured, the total length of all corresponding Content values cannot exceed 60 KB. |
|
|
object |
No |
The ConfigFile volume information. |
||
| Path |
string |
No |
The relative file path of the configuration file relative to the mount directory. |
test/config-test.cnf |
| Mode |
integer |
No |
The permissions of the configuration file. If not set, the value of ConfigFileVolume.DefaultMode is used. Represented as a four-digit octal number. For example, 0644 means the permissions are rw-r--r--, where the user permission is rw-, the group permission is r--, and the other permission is r--. Permission descriptions:
|
0644 |
| Content |
string |
No |
The content of the configuration file, which must be Base64-encoded. A single configuration file cannot exceed 32 KB. |
bGl1bWk= |
| HostPathVolume.Path |
string |
No |
The directory path of the HostPath volume on the host. |
/pod/data |
| FlexVolume.Options |
string |
No |
The FlexVolume option list. This is in key-value format and passed as JSON. For example, when mounting a cloud disk via FlexVolume, Options represents the cloud disk configuration parameters. The configurable parameters are as follows:
|
{"volumeId":"d-2zehdahrwoa7srg****","performanceLevel": "PL2"} |
| FlexVolume.Driver |
string |
No |
The driver type when using the FlexVolume plugin to mount volumes. Valid values:
|
alicloud/disk |
| NFSVolume.Server |
string |
No |
The NFS server address. |
3f9cd4a596-naw76.cn-shanghai.nas.aliyuncs.com |
| DiskVolume.DiskId |
string |
No |
The ID of the DiskVolume. |
d-xx |
| Name |
string |
No |
The container name. |
test-init |
| EmptyDirVolume.Medium |
string |
No |
The storage medium for the EmptyDirVolume. Default value: empty, which uses the node file system. The value memory is supported, indicating the use of memory. |
memory |
| EmptyDirVolume.SizeLimit |
string |
No |
The size of the EmptyDirVolume. Unit: GiB. |
2 |
| InitContainer |
array<object> |
No |
The list of IP addresses of DNS servers. |
172.10.*.** |
|
array<object> |
No |
The list of IP addresses of DNS servers. |
172.10.*.** |
|
| SecurityContext.Capability.Add |
array |
No |
The permissions granted to processes in the container. Currently, only NET_ADMIN and NET_RAW are supported. Note
NET_RAW is not supported by default and requires a ticket submission. |
|
|
string |
No |
The permissions granted to processes in the container. Currently, only NET_ADMIN and NET_RAW are supported. Note
NET_RAW is not supported by default and requires a ticket submission. |
NET_ADMIN |
|
| Image |
string |
No |
The image used by the container. |
nginx |
| VolumeMount |
array<object> |
No |
The list of volume mount information. |
|
|
object |
No |
The list of volume mount information. |
||
| MountPropagation |
string |
No |
The mount propagation setting for the volume. Mount propagation allows volumes mounted by a container to be shared with other containers in the same pod or even with other pods on the same node. Valid values:
Default value: None |
None |
| MountPath |
string |
No |
The mount directory. The contents under the container mount directory will be directly overwritten by the volume contents. Use with caution. |
/usr/share/ |
| ReadOnly |
boolean |
No |
Specifies whether the mount path is read-only. Default value: false. |
false |
| SubPath |
string |
No |
The sub-directory of the volume, allowing the pod to mount different directories from the same volume to different container directories. |
/usr/sub/ |
| Name |
string |
No |
The name of the volume to mount. |
test-empty |
| Port |
array<object> |
No |
The init container port numbers. |
|
|
object |
No |
The init container port numbers. |
||
| Protocol |
string |
No |
The protocol type. Valid values:
|
TCP |
| Port |
integer |
No |
The port number. Valid values: 1 to 65535. |
8888 |
| SecurityContext.ReadOnlyRootFilesystem |
boolean |
No |
Specifies whether the root file system of the container is read-only. Currently, only true is supported. |
true |
| TerminationMessagePath |
string |
No |
The source of the container exit message. When the container exits, the termination message is retrieved from the specified termination message file. |
/tmp/termination-log |
| EnvironmentVar |
array<object> |
No |
The list of container environment variables. |
|
|
object |
No |
The list of container environment variables. |
||
| Key |
string |
No |
The name of the environment variable. The name must be 1 to 128 characters in length. Format: |
Path |
| Value |
string |
No |
The value of the environment variable. The value must be 0 to 256 characters in length. |
/usr/bin/ |
| FieldRef.FieldPath |
string |
No |
The reference for the environment variable value. Currently, only status.podIP is supported. |
status.podIP |
| ImagePullPolicy |
string |
No |
The image pull policy. Valid values:
|
Always |
| WorkingDir |
string |
No |
The working directory. |
/usr/local |
| Cpu |
number |
No |
The vCPU size of the container. Unit: cores. |
0.5 |
| Arg |
array |
No |
The container startup arguments. |
10 |
|
string |
No |
The container startup arguments. |
10 |
|
| Command |
array |
No |
The container startup commands. |
sleep |
|
string |
No |
The container startup commands. |
sleep |
|
| Gpu |
integer |
No |
The number of GPUs assigned to the container. |
1 |
| SecurityContext.RunAsUser |
integer |
No |
The user ID used to run the container. |
587 |
| Memory |
number |
No |
The memory size of the container. Unit: GiB. |
1.0 |
| TerminationMessagePolicy |
string |
No |
The mount information. Default value: empty. |
***** |
| Name |
string |
No |
The container name. |
test-init |
| DnsConfig.NameServer |
array |
No |
The list of DNS search domains. |
svc.local.kubenetes |
|
string |
No |
The list of DNS search domains. |
svc.local.kubernetes |
|
| DnsConfig.Search |
array |
No |
The list of object options. |
svc.local.kubenetes |
|
string |
No |
The list of object options. |
svc.local.kubernetes |
|
| DnsConfig.Option |
array<object> |
No |
The host aliases added to the Elastic Container Instance (ECI). |
|
|
object |
No |
The host aliases added to the Elastic Container Instance (ECI). |
||
| Value |
string |
No |
The value of the option. |
value |
| Name |
string |
No |
The name of the option. |
name |
| HostAliase |
array<object> |
No |
Modifies safe sysctl parameters by using the security context. For more information, see Configure Security Context. |
|
|
object |
No |
Modifies safe sysctl parameters by using the security context. For more information, see Configure Security Context. |
||
| Ip |
string |
No |
The IP address to add. |
1.1.1.1 |
| Hostname |
array |
No |
The host names to add. |
hehe.com |
|
string |
No |
The host names to add. |
hehe.com |
|
| SecurityContext.Sysctl |
array<object> |
No |
Modifies unsafe sysctl parameters by using the security context. For more information, see Configure Security Context. |
|
|
object |
No |
Modifies unsafe sysctl parameters by using the security context. For more information, see Configure Security Context. |
||
| Value |
string |
No |
The value of the unsafe sysctl parameter when you modify sysctl parameters by using the security context. |
65536 |
| Name |
string |
No |
The name of the unsafe sysctl parameter when you modify sysctl parameters by using the security context. Valid values:
|
kernel.msgmax |
| HostSecurityContext.Sysctl |
array<object> |
No |
The NTP server. |
ntp.cloud.aliyuncs.com |
|
object |
No |
The NTP server. |
ntp.cloud.aliyuncs.com |
|
| Value |
string |
No |
The value of the unsafe sysctl parameter when modifying sysctl parameters through the security context. |
65536 |
| Name |
string |
No |
The name of the unsafe sysctl parameter when modifying sysctl parameters through the security context. Valid values:
|
kernel.msgmax |
| NtpServer |
array |
No |
The list of Container Registry Enterprise instance information. For more information, see Pull images from Container Registry without a password. |
ntp.cloud.aliyuncs.com |
|
string |
No |
The list of Container Registry Enterprise instance information. |
ntp.cloud.aliyuncs.com |
|
| AcrRegistryInfo |
array<object> |
No |
The protection period of the spot instance. Unit: hours. Default value: 1. A value of 0 indicates no protection period. |
1 |
|
object |
No |
The list of ACR Enterprise Edition instance information. |
||
| Domain |
array |
No |
The domains of the ACR Enterprise Edition instance. By default, all domains of the instance are used. You can specify individual domains, separated by commas. |
*****-****-registry.cn-beijing.cr.aliyuncs.com |
|
string |
No |
The domains of the ACR Enterprise Edition instance. By default, all domains of the instance are used. You can specify individual domains, separated by commas. |
*****-****-registry.cn-beijing.cr.aliyuncs.com |
|
| InstanceName |
string |
No |
The name of the ACR Enterprise Edition instance. |
acr-test |
| InstanceId |
string |
No |
The ID of the ACR Enterprise Edition instance. |
cri-nwj395hgf6f3**** |
| RegionId |
string |
No |
The region of the ACR Enterprise Edition instance. |
cn-beijing |
| ArnService |
string |
No |
The ARN of the RAM role under the account that owns the ECI instance and other resources. |
acs:ram::1609982529******:role/role-assume |
| ArnUser |
string |
No |
The ARN of the RAM role under the account that owns the ACR instance. |
acs:ram::1298452580******:role/role-acr |
| SpotDuration |
integer |
No |
Specifies whether to enable periodic execution.
|
true |
| StrictSpot |
boolean |
No |
The address of the self-pull image repository. If you use an image in a self-pull image repository that uses the HTTP protocol to create an Elastic Container Instance, you must configure this parameter so that Elastic Container Instance pulls the image over HTTP, preventing image pull failures caused by protocol differences. |
"harbor***.pre.com,192.168.XX.XX:5000,reg***.test.com:80" |
| PlainHttpRegistry |
string |
No |
The address of the self-managed image repository. If you use an image in a self-managed image repository that uses a self-signed certificate to create an Elastic Container Instance, you must configure this parameter to skip certificate authentication, preventing image pull failures caused by certificate authentication failures. |
"harbor***.pre.com,192.168.XX.XX:5000,reg***.test.com:80" |
| InsecureRegistry |
string |
No |
The image acceleration mode. Valid values:
|
imc |
| ImageAccelerateMode |
string |
No |
Specifies whether to enable IPv6 Internet access for the Elastic Container Instance. |
true |
| Ipv6GatewayBandwidthEnable |
boolean |
No |
The maximum bandwidth of the IPv6 address when Ipv6GatewayBandwidthEnable is set to true. Valid values:
Default value: the maximum value of Internet bandwidth range for the gateway. |
100 |
| Ipv6GatewayBandwidth |
string |
No |
When the Elastic Container Instance specifications are larger than the requested specifications, you can enable this configuration to ensure that the resources visible inside the container are consistent with the requested resources. |
false |
| ContainerResourceView |
boolean |
No |
Set this parameter to true to enable a fixed IP address for the instance. For more information, see Configure a fixed IP address for an Elastic Container Instance. |
true |
| FixedIp |
string |
No |
The retention period of the fixed IP address after it becomes idle. This is the duration for which the fixed IP address is retained after the instance with the fixed IP address is released. Unit: hours. Default value: 48. |
24 |
| FixedIpRetainHour |
integer |
No |
The data cache bucket. |
default |
| DataCacheBucket |
string |
No |
The performance level (PL) of the cloud disk used for data caching. Enterprise SSDs (ESSDs) are used preferentially. If a standard SSD is used, the default PL is PL1. |
PL1 |
| DataCachePL |
string |
No |
The provisioned read/write IOPS of the ESSD AutoPL cloud disk used for data caching. Valid values: 0 to min{50000, 1000 × capacity - baseline performance}. Baseline performance = min{1800 + 50 × capacity, 50000}. For more information, see ESSD AutoPL cloud disks. |
40000 |
| DataCacheProvisionedIops |
integer |
No |
Specifies whether to enable burst (performance bursting) for the ESSD AutoPL cloud disk used for data caching. For more information, see ESSD AutoPL cloud disks. |
false |
| DataCacheBurstingEnabled |
boolean |
No |
Specifies whether to perform only a dry run. Valid values:
|
false |
| DryRun |
boolean |
No |
The private IP address of the Elastic Container Instance. Currently, only IPv4 addresses are supported. Make sure that the IP address is not already in use. |
172.16.0.1 |
| PrivateIpAddress |
string |
No |
The operating system of the Elastic Container Instance. Valid values:
Note
Windows instances are in invitational preview. To use Windows instances, submit a ticket. |
Windows |
| OsType |
string |
No |
The CPU architecture of the Elastic Container Instance. Valid values:
|
ARM64 |
| CpuArchitecture |
string |
No |
The compute category. For more information, see Create an instance with a specified compute category. |
ARM64 |
| ComputeCategory |
array |
No |
The GPU driver version. Note
Only specific instance types support switching GPU driver versions. For more information, see Create an instance with a specified GPU specification. |
tesla=535 |
|
string |
No |
The compute categories. Valid values:
Multiple compute categories are supported. The system creates instances in the specified order. |
economy |
|
| GpuDriverVersion |
string |
No |
tesla=535 |
|
| MaxPendingMinute |
integer |
No |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
89945DD3-9072-47D0-A318-353284CFC7B3 |
| ContainerGroupId |
string |
The instance ID, which is the container group ID. |
eci-uf6fonnghi50u374**** |
Examples
Success response
JSON format
{
"RequestId": "89945DD3-9072-47D0-A318-353284CFC7B3",
"ContainerGroupId": "eci-uf6fonnghi50u374****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | Account.Arrearage | Your account has an outstanding payment. | Your account has an outstanding payment. |
| 400 | DryRunOperation | Request validation has been passed with DryRun flag set. | Request validation has been passed with DryRun flag set. |
| 400 | InvalidParameter.CPU.Memory | The specified cpu and memory are not allowed | |
| 400 | InvalidParameter.DuplicatedName | The container group include containers with duplicate names. | The container group contains containers with duplicate names. |
| 400 | InvalidParameter.DuplicatedVolumeName | The container group includes volumes with duplicate names. | The container group includes volumes with duplicate names. |
| 400 | IncorrectStatus | %s | The specified instance status is invalid. |
| 400 | ServiceNotEnabled | %s | The service on which this request depends has not been activated. Please activate and try again. |
| 400 | ImageSnapshot.IncorrectStatus | %s | The status of the specified snapshot is invalid. |
| 400 | ImageSnapshot.NotSupport | %s | Image caching based on data disk snapshots is not available for all users. If you want to enable this function, contact us. |
| 400 | DiskVolume.NotSupport | The disk volume is not supported. | Disk volume does not support your structure. If you want to enable this function, contact us. |
| 400 | RamRole.NotSupport | The RAM role is not supported. | The RAM role is not supported. |
| 400 | DiskNumber.LimitExceed | The maximum number of disks in an instance is exceeded. | The maximum number of disks in an instance is exceeded. |
| 400 | InvalidPaymentMethod.InsufficientBalance | No payment method is specified for your account. We recommend that you add a payment method or add funds to the prepayment balance. | No payment method is specified for your account. We recommend that you add a payment method or add funds to the prepayment balance. |
| 400 | DiskVolume.NotInSameZone | The instance to be created and the disk are not in the same zone. | The instance to be created and the disk are not in the same zone. |
| 400 | NoPermission | You are not authorized to use the "Product on ECI" feature. | |
| 400 | HighCpuMemConfigRequired | You need to apply to be added to the whitelist of the specified CPU and memory. | You need to apply to be added to the whitelist of the specified CPU and memory. |
| 400 | RecommendEmpty.InstanceTypeFamilyNotMatched | The recommended instance type is unavailable in the current zone. Try again later. | No recommended instance types are available in the current zone. Try again later or create instances in another zone. |
| 400 | LocalDiskAmountNotMatch | The number of local volumes does not match the instance type. | The number of local disks does not match the instance type. |
| 400 | Payfor.CreditPayInsufficientBalance | Your payment credit line is insufficient. | Your payment credit line is insufficient. |
| 400 | InvalidOperation.KMS.InstanceTypeNotSupport | The specified instance is invalid. Only I/O optimized instances support KMS key. | The specified instance is invalid. Only I/O optimized instances support KMS key. |
| 400 | InvalidParameter.Encrypted.KmsNotEnabled | KMS must be enabled for encrypted disks. | Encrypted cloud disks require Key Management Service to be enabled. |
| 400 | InvalidParameter.KMS.EncryptedIllegal | After configuring the parameter KmsKeyId, you must enable encryption. | After configuring the parameter KmsKeyId, you must enable encryption. |
| 400 | InvalidSpotCpuMemorySpec | The specified CPU and memory are not allowed. You must create spot ECI using standard ECS specifications for CPU and memory. | A standard ECS instance type must be used to create a spot elastic container instance. |
| 400 | Ipv6AddressNotSupportVsw | IPv6 is not supported in the specified vSwitch. | The vSwitch does not have IPv6 enabled. |
| 400 | Ipv6AddressNotSupport | Ipv6 is not supported in specified region. | The current region does not support IPv6 addresses. |
| 400 | Ipv6AddressNotSupportInstanceType | IPv6 is not supported for the specified instance type. | The specified instance type does not support IPv6. |
| 400 | EipPayInsufficientBalance | Your account does not have enough balance to purchase eip. | The current account balance is insufficient to purchase an EIP. |
| 400 | EipPurchaseFlowControl | Request was denied due to eip frequent purchase. | EIP purchases are too frequent. Try again later. |
| 400 | Throttling | You have made too many requests within a short time; your request is denied due to request throttling | |
| 400 | JobInstanceBatchCreateNotSupport | ECI job instance not support batch create | |
| 400 | JobInstanceDiskNotSupport | ECI job instance not support disk volume | |
| 400 | JobInstanceEipNotSupport | ECI job instance not support eip | |
| 400 | JobInstanceFeatureNotMatch | ECI job instance feature not match | |
| 400 | JobInstanceImageCacheNotSupport | ECI job instance not support image cache | |
| 400 | JobInstanceIPv6NotSupport | ECI job instance not support IPv6 | |
| 400 | JobInstanceRamRoleNotSupport | ECI job instance not support ram role | |
| 400 | JobInstanceRegionNotSupport | ECI job instance not support in this region | |
| 400 | JobInstanceSpotNotSupport | ECI job instance not support spot | |
| 400 | InvalidInstanceTypeForEciSpotDurationBuy | Current instance type does not support spot duration instance. | The specified instance type does not support spot instances with custom duration. |
| 400 | InvalidInstanceTypeForEciBuy | Sales of this current instance type is not supported in eci. | The specified instance type is not within the range of container group types available for sale. |
| 400 | InstanceTypeNotMatchCpuArch | %s. | The CPU architecture of the specified ECS instance type does not match the specified CPU architecture. |
| 400 | JobInstanceEcsInstanceTypeNotSupport | Job-optimized elastic container instances cannot be created by specifying ECS instance types. | Job-optimized container group instances do not support creation with a specified ECS instance type. |
| 400 | PrivatePoolInstanceSpotNotSupport | Spot is not supported for PrivatePool. | |
| 400 | DryRun.Success | This request is a dryrun request with successful result. | The dry run request has passed validation. |
| 400 | PrivateIpAddress.Already.InUse | The specific PrivateIpAddress already in use. | The private IP address is already in use. |
| 400 | IncorrectOperation | %s | You cannot perform this operation on the specified resource. |
| 400 | FeatureBasedConstraintConflict | A conflict occurs in specified feature constraints: [%s]. | A conflict occurs in specified feature constraints |
| 400 | OperationFailed.RiskControl | %s. | We have detected that your account has security risks. Please contact customer service personnel for details. |
| 400 | RISK.RISK_CONTROL_REJECTION | To protect the security of your account, your request has been denied by the risk control system. Please contact Alibaba Cloud Customer Service for details. | In order to protect the security of your account, your request was rejected by the wind control system. Please contact customer service for details. |
| 400 | InvalidInstanceTypeForRaid | %s. | The current specification does not support Raid. |
| 400 | RegionDissolved | %s. | Alibaba Cloud is scheduled to make adjustments in this region. ECI service in this region will be suspended. |
| 400 | MultiAttachedCloudDiskNotSupport | %s. | You cannot mount a cloud disk with the multi-mount function enabled (that is, an NVMe shared disk). |
| 403 | OperationDenied.VswZoneMisMatch | The specified VSwitchId is not in the specified Zone. | |
| 403 | QuotaExceeded | %s quota exceeded. | |
| 403 | Zone.NotOnSale | The specified zone is not available for purchase. | The zone in which you want to create the instance is no longer available for purchase. Use a different zone, or the vSwitch of the specified VPC cannot be used in this zone. |
| 403 | Forbidden.RiskControl | This operation has been identified as an abnormal operation and cannot be processed. | This operation has been identified as abnormal and cannot be processed. |
| 403 | Forbidden.SubUser | The specified action is not available for you. | |
| 403 | Forbidden.OnlyForInvitedTest | Eci create action is only open to invited users during public beta. | |
| 403 | OperationDenied.SecurityGroupMisMatch | The specified VSwitchId and SecurityGroupId are not in the same VPC. | |
| 403 | InvalidVSwitchId.IpNotEnough | The specified VSwitch does not have enough IP addresses. | |
| 403 | Forbidden.UserBussinessStatus | This operation is not allowed, because you have overdue bills. Pay the overdue bill and try again. | The operation is forbidden because the account has an overdue payment. Top up your account and try again. |
| 403 | Forbidden.UserNotRealNameAuthentication | This operation is not allowed, because you have not passed the real-name verification. | The operation is forbidden because the user has not completed real-name verification. |
| 403 | InvalidUser.PassRoleForbidden | The RAM user is not authorized to assume a RAM role. | The RAM user is not authorized to assume a RAM role. |
| 403 | NoPermission | The RAM role does not belong to ECS. | |
| 403 | OperationDenied.NoStock | Sales of this resource are temporarily suspended in the specified zone. We recommend that you use the multi-zone creation function to avoid the risk of insufficient resource. For more information, see https://www.alibabacloud.com/help/document_detail/157290.html | |
| 403 | InvalidParameter.KMS.KeyId.Forbidden | You are not authorized to access the specified KMSKeyId. | You are not authorized to access the specified KMSKeyId. |
| 403 | Forbidden.AccountClosed | The operation is forbidden. Your account has been closed. | The operation is forbidden because the user account has been deregistered. |
| 403 | InvalidOperation.ResourceManagedByCloudProduct | The operation is forbidden. The security group has been managed by another cloud product. | The security group is managed by another cloud service and cannot be modified. |
| 403 | Spot.NotMatched | %s. We recommend that you use the create multi-zone function to avoid insufficient inventory. For more information, see https://www.alibabacloud.com/help/document_detail/157290.html | |
| 403 | SecurityRisk.3DVerification | We have detected a security risk with your default credit or debit card. Please proceed with verification via the link in your email. | A security risk has been detected on your default credit or debit card. Verify your card by using the link in the email. |
| 403 | CreateServiceLinkedRole.Denied | Please make sure the account has ram:CreateServiceLinkedRole permission. | Please make sure the account has ram:CreateServiceLinkedRole permission. |
| 403 | Throttling.Vcpu.PerDay | The maximum number of request for the day has been exceeded. | The maximum number of request for the day has been exceeded. |
| 403 | FeatureAccessRestricted | Access to this feature:[%s] is restricted. Please contact Alibaba Cloud ECI support to request access. | Access to this feature is restricted. Please contact Alibaba Cloud ECI support to request access. |
| 404 | ImageSnapshot.NotFound | The specified snapshot does not exist. | The snapshot for the image cache does not exist. |
| 404 | InvalidDiskId.NotFound | The specified disk does not exist. | The specified cloud disk does not exist. |
| 404 | InvalidParameter.KMS.KeyId.NotFound | The specified KMSKeyId does not exist. | The specified KMSKeyId does not exist. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.