{"id":"b4ab303a-9728-4fbf-9321-40566e79ef18","entityType":"agent","slug":"clawhub-sdk-team-alibabacloud-pai-dlc-job","name":"alibabacloud-pai-dlc-job","canonicalUrl":"https://www.xpersona.co/agent/clawhub-sdk-team-alibabacloud-pai-dlc-job","canonicalPath":"/agent/clawhub-sdk-team-alibabacloud-pai-dlc-job","generatedAt":"2026-10-10T22:50:35.558Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:37:34.675Z","emptyReason":null},"description":"Alibaba Cloud PAI-DLC (Deep Learning Containers) job management skill. Covers: distributed training job CRUD, monitoring (logs and events), and GPU sanity check. Triggers: \"DLC\", \"PAI-DLC\", \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", \"list-job-sanity-check-results\".","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-pai-dlc-job","sourceUrl":"https://clawhub.ai/sdk-team/alibabacloud-pai-dlc-job","homepage":"https://clawhub.ai/sdk-team/skills/alibabacloud-pai-dlc-job","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/sdk-team/alibabacloud-pai-dlc-job","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/sdk-team/skills/alibabacloud-pai-dlc-job","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"alibabacloud-pai-dlc-job technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:37:34.675Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:37:34.675Z","emptyReason":null},"stars":null,"forks":null,"downloads":1264,"packageName":null,"latestVersion":"0.0.2","tractionLabel":"1.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:37:34.661Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T20:37:34.675Z","lastCrawledAt":"2026-10-10T20:37:34.661Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T20:37:34.661Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.2","createdAt":"2026-08-14T08:38:10.094Z","changelog":"- Added session-based User-Agent flag with {session-id} template to all API-invoking commands for unified observability and traceability. - Deprecated use of `aliyun configure ai-mode` for User-Agent; now all `--user-agent` flags must be passed explicitly per command. - Updated installation and usage instructions in SKILL.md to reflect new User-Agent and session tracking requirements. - Expanded observability guidance, including session-id generation and export rules. - Removed obsolete helper steps and documentation (e.g., skill-card.md, deprecated ai-mode instructions).","fileCount":9,"zipByteSize":27551},{"version":"0.0.1","createdAt":"2026-05-29T04:18:45.196Z","changelog":"Initial release with reduced scope and refocused features: - Removed JobTemplate and TensorBoard management; skill now provides distributed job CRUD, monitoring (logs/events), and GPU sanity check only. - Updated triggers: now focused on core DLC job operations such as \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", and \"list-job-sanity-check-results\". - Cleaned up documentation and removed files related to deprecated features (JobTemplate, skill card). - Updated references and permission requirements to match supported operations.","fileCount":9,"zipByteSize":27069},{"version":"0.0.1-beta.2","createdAt":"2026-05-25T08:24:48.686Z","changelog":"- Added full lifecycle support for TensorBoard (create, start, stop, update, share) and Ray/generic dashboards. - Updated documentation to clarify field dependencies and override misleading CLI `--help` advice (e.g., `--workspace-id` is always required). - Provided guidance for long-running or sensitive commands on using CLI timeout and retry flags. - Improved parameter confirmation policy and listed authoritative reference sources. - Removed outdated or redundant documentation (e.g., obsolete command references).","fileCount":10,"zipByteSize":34863},{"version":"0.0.1-beta.1","createdAt":"2026-05-21T08:17:35.106Z","changelog":"Initial beta release of Alibaba Cloud PAI-DLC job management skill. - Enables creation, management, and monitoring of PAI-DLC training jobs. - Supports job template creation, listing, and version management. - Includes TensorBoard dashboard creation and discovery commands. - Provides installation steps, permission requirements, and explicit parameter confirmation guides. - Integrates detailed security, authentication, and RAM permission handling instructions.","fileCount":10,"zipByteSize":35225}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-pai-dlc-job","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-pai-dlc-job` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/sdk-team/alibabacloud-pai-dlc-job before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T22:50:35.557Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-dlc-job/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:37:34.675Z","emptyReason":null},"readme":"Skill: alibabacloud-pai-dlc-job\n\nOwner: sdk-team\n\nSummary: Alibaba Cloud PAI-DLC (Deep Learning Containers) job management skill. Covers: distributed training job CRUD, monitoring (logs and events), and GPU sanity check. Triggers: \"DLC\", \"PAI-DLC\", \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", \"list-job-sanity-check-results\".\n\nTags: latest:0.0.2\n\nVersion history:\n\nv0.0.2 | 2026-08-14T08:38:10.094Z | auto\n\n- Added session-based User-Agent flag with {session-id} template to all API-invoking commands for unified observability and traceability.\n- Deprecated use of `aliyun configure ai-mode` for User-Agent; now all `--user-agent` flags must be passed explicitly per command.\n- Updated installation and usage instructions in SKILL.md to reflect new User-Agent and session tracking requirements.\n- Expanded observability guidance, including session-id generation and export rules.\n- Removed obsolete helper steps and documentation (e.g., skill-card.md, deprecated ai-mode instructions).\n\nv0.0.1 | 2026-05-29T04:18:45.196Z | auto\n\nInitial release with reduced scope and refocused features:\n\n- Removed JobTemplate and TensorBoard management; skill now provides distributed job CRUD, monitoring (logs/events), and GPU sanity check only.\n- Updated triggers: now focused on core DLC job operations such as \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", and \"list-job-sanity-check-results\".\n- Cleaned up documentation and removed files related to deprecated features (JobTemplate, skill card).\n- Updated references and permission requirements to match supported operations.\n\nv0.0.1-beta.2 | 2026-05-25T08:24:48.686Z | auto\n\n- Added full lifecycle support for TensorBoard (create, start, stop, update, share) and Ray/generic dashboards.\n- Updated documentation to clarify field dependencies and override misleading CLI `--help` advice (e.g., `--workspace-id` is always required).\n- Provided guidance for long-running or sensitive commands on using CLI timeout and retry flags.\n- Improved parameter confirmation policy and listed authoritative reference sources.\n- Removed outdated or redundant documentation (e.g., obsolete command references).\n\nv0.0.1-beta.1 | 2026-05-21T08:17:35.106Z | auto\n\nInitial beta release of Alibaba Cloud PAI-DLC job management skill.\n\n- Enables creation, management, and monitoring of PAI-DLC training jobs.\n- Supports job template creation, listing, and version management.\n- Includes TensorBoard dashboard creation and discovery commands.\n- Provides installation steps, permission requirements, and explicit parameter confirmation guides.\n- Integrates detailed security, authentication, and RAM permission handling instructions.\n\nArchive index:\n\nArchive v0.0.2: 9 files, 27551 bytes\n\nFiles: references/acceptance-criteria.md (12271b), references/cli-installation-guide.md (11735b), references/job-management.md (4272b), references/ram-policies.md (9618b), references/related-apis.md (6389b), references/verification-method.md (6477b), skill-card.md (2616b), SKILL.md (19977b), _meta.json (143b)\n\nFile v0.0.2:SKILL.md\n\n---\nname: alibabacloud-pai-dlc-job\ndescription: |\n  Alibaba Cloud PAI-DLC (Deep Learning Containers) job management skill. Covers: distributed training job CRUD, monitoring (logs and events), and  GPU sanity check. Triggers: \"DLC\", \"PAI-DLC\", \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", \"list-job-sanity-check-results\".\n---\n\n# PAI-DLC Deep Learning Job Management\n\nManage deep learning training jobs on Alibaba Cloud PAI-DLC (Platform for AI - Deep\nLearning Containers) service.\n\n## Scenario Description\n\nPAI-DLC is a distributed training service provided by Alibaba Cloud's AI Platform PAI,\nsupporting:\n\n- **Job Creation and Execution** — Create distributed training jobs for TensorFlow,\n  PyTorch, XGBoost, and other frameworks\n- **Job Monitoring** — Get job status, logs, events, and monitoring metrics\n- **Compute Health Check** — Check health status of GPU and other compute devices\n- **Job Management** — Update and stop jobs\n\n**Architecture**: PAI Workspace + DLC Job + Computing Resources (ECS public pay-as-you-go\nor Lingjun dedicated quota) + AIWorkSpace catalog (images / datasets / code sources /\nquotas / workspaces).\n\n## Installation Requirements\n\n> **Pre-check: Aliyun CLI >= 3.3.1 required**\n> Run `aliyun version` to verify version >= 3.3.1. If not installed or version is too low,\n> see [references/cli-installation-guide.md](references/cli-installation-guide.md) for\n> installation instructions.\n> Then [Required] run `aliyun configure set --auto-plugin-install true` to enable\n> automatic plugin installation.\n\n> **Note on `--user-agent`:** Every API-invoking `aliyun` command in this skill MUST\n> include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`\n> (unified User-Agent + session-id template — see [Observability](#observability) for\n> the generation rules). Client-side helpers (`aliyun version`,\n> `aliyun configure ...`, `aliyun plugin ...`, `aliyun <product> --help`) do not\n> invoke remote APIs and therefore do not require the flag.\n\n> **Network timeout & retry (rule `--help` doesn't enforce):** `aliyun` CLI\n> defaults to 10s connect / 10s read with no retry. For long-running flows\n> (large list, slow region) explicitly raise via global flags\n> `--connect-timeout 15 --read-timeout 30 --retry-count 2`. Never rely on the\n> default for user-confirmed high-risk calls (`stop-job` / `delete-*`).\n\n```bash\naliyun version\naliyun configure set --auto-plugin-install true\naliyun pai-dlc --help\naliyun aiworkspace --help >/dev/null 2>&1 || aliyun plugin install --names aliyun-cli-aiworkspace\naliyun plugin update\n```\n\n## Observability\n\n> **Why:** every PAI-DLC API call issued by this skill MUST carry a unified\n> User-Agent so platform-side tracing can attribute the request to this skill\n> and correlate all calls within a single agent session.\n\n### User-Agent template\n\nEvery API-invoking `aliyun` command MUST pass:\n\n```\n--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/{session-id}\n```\n\n- Prefix `AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job` is fixed — never alter it.\n- `{session-id}` is a per-session identifier generated by the rules below.\n- Client-side helpers (`aliyun version`, `aliyun configure ...`,\n  `aliyun plugin ...`, `aliyun <product> --help`) do NOT invoke remote APIs and\n  therefore do NOT require the flag.\n\n### session-id generation rules\n\n1. Generate the session-id **once** at the start of the skill session, before\n   the first API call.\n2. Format: lowercase, no spaces, no slashes. Recommended\n   `uuidgen | tr 'A-Z' 'a-z'` or `$(date +%s)-$RANDOM`.\n3. **Reuse the same session-id for every command** in the session — never\n   regenerate per call. This lets tracing group all calls of one session.\n4. Export it once and reference the shell variable in every API call:\n\n```bash\nSESSION_ID=$(uuidgen | tr 'A-Z' 'a-z')\nexport SESSION_ID\n# every API-invoking command then appends:\n#   --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\naliyun pai-dlc list-jobs --region <r> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n> **Do NOT use `aliyun configure ai-mode`** to set the User-Agent. That mode is\n> deprecated for skills. Always pass `--user-agent` explicitly per command with\n> the session-id template, so each session is independently traceable.\n```\n\n## Environment Variables\n\nThis skill does not require any custom environment variables. Credentials are handled\nby the Alibaba Cloud CLI configuration (see Authentication below). Optionally:\n\n| Variable | Required | Purpose |\n|----------|----------|---------|\n| `ALIBABA_CLOUD_PROFILE` | Optional | Selects a non-default `aliyun configure` profile |\n| `ALIBABA_CLOUD_REGION_ID` | Optional | Default region when `--region` is omitted (still recommended to pass `--region` explicitly) |\n\nDo NOT export `ALIBABA_CLOUD_ACCESS_KEY_ID` / `ALIBABA_CLOUD_ACCESS_KEY_SECRET` from\nwithin this session; configure them outside (`aliyun configure` or shell profile).\n\n## Authentication Configuration\n\n> **Pre-check: Alibaba Cloud Credentials Required**\n>\n> **Security Rules:**\n> - **NEVER** read, echo, or print AK/SK values (e.g., `echo $ALIBABA_CLOUD_ACCESS_KEY_ID` is FORBIDDEN)\n> - **NEVER** ask the user to input AK/SK directly in the conversation or command line\n> - **NEVER** use `aliyun configure set` with literal credential values\n> - **ONLY** use `aliyun configure list` to check credential status\n>\n> ```bash\n> aliyun configure list\n> ```\n> Check the output for a valid profile (AK, STS, or OAuth identity).\n>\n> **If no valid profile exists, STOP here.**\n> 1. Obtain credentials from [Alibaba Cloud Console](https://ram.console.aliyun.com/manage/ak)\n> 2. Configure credentials **outside of this session** (via `aliyun configure` in terminal\n>    or environment variables in shell profile)\n> 3. Return and re-run after `aliyun configure list` shows a valid profile\n\n## RAM Permissions\n\n> **[MUST] Permission Failure Handling:** When any command or API call fails due to\n> permission errors at any point during execution, follow this process:\n> 1. Read `references/ram-policies.md` to get the full list of permissions required by this SKILL\n> 2. Use `ram-permission-diagnose` skill to guide the user through requesting the necessary permissions\n> 3. Pause and wait until the user confirms that the required permissions have been granted\n\nFor detailed permission list, see [references/ram-policies.md](references/ram-policies.md).\n\n**Required Permissions Overview:**\n\n| Operation | Required Permission |\n|-----------|---------------------|\n| Create Job | `pai:CreateJob` |\n| List Jobs | `pai:ListJobs` |\n| Get Job Details | `pai:GetJob` |\n| Get Pod Logs | `pai:GetPodLogs` |\n| Get Job Events | `pai:GetJobEvents` |\n| Update Job | `pai:UpdateJob` |\n| Stop Job | `pai:StopJob` |\n| AIWorkSpace Resource Discovery | `paiworkspace:ListWorkspaces` / `paiimage:ListImages,GetImage` / `paidataset:ListDatasets,GetDataset` / `paicodesource:ListCodeSources,GetCodeSource` |\n\n> **AIWorkSpace authorization note:** `Image` / `DataSourceId` / `CodeSourceId` /\n> `WorkspaceId` field values for `create-job` come from the\n> AIWorkSpace resource-discovery APIs. `--resource-id` (QuotaId) is manually provided by the user.\n> RAM users MUST hold the corresponding\n> AIWorkSpace-namespaced permissions listed above (do not abbreviate as `aiworkspace:*`).\n\n## Parameter Confirmation\n\n> **Authoritative parameter reference is `aliyun pai-dlc <cmd> --help`** (must-read\n> before every call). This skill only documents what `--help` does **not** tell\n> you: cross-field rules, cross-product dependencies, hidden behaviors, business\n> labels, and reject patterns. Whenever a rule below contradicts `--help`, the\n> reason is stated inline.\n>\n> **Confirm before call:** all user-customizable values (region, names, CIDR,\n> specs, etc.) MUST be confirmed with the user — never assume defaults.\n\n### Hard rules that override `--help`\n\n| Rule | Why this skill overrides `--help` |\n|------|-----------------------------------|\n| `--workspace-id` is **always required** | `--help` marks it optional, but server silently falls back to the user's **default workspace** if omitted → job often lands in the wrong workspace. Always confirm with user. |\n| `--job-specs[].Image` MUST be a verbatim `ImageUri` from `aiworkspace list-images` | Cross-product contract; `--help` only describes the field type. See §7.6 red line. |\n| `--data-sources[].DataSourceId` from `aiworkspace list-datasets`; `--code-source.CodeSourceId` from `list-code-sources` | Cross-product discovery; `--help` cannot point you to the source product. |\n| `--resource-id` (QuotaId) is **manually supplied** | No CLI discovery step. |\n\n### Cross-field mutual exclusion (`--help` cannot catch these)\n\n- `EcsSpec` ⇄ `ResourceConfig` — within a single TaskSpec, pick exactly one.\n- `Uri` ⇄ `DataSourceId` — within `--data-sources[]`.\n- `Uri` ⇄ `CodeSourceId` — within `--code-source`.\n\n### `--job-type` — Worker `Type` hints per framework\n\n`--help` lists the 9 legal enum values verbatim. What `--help` doesn't tell you\nis which `JobSpecs[].Type` roles each framework expects:\n\n| `--job-type` | Valid `JobSpecs[].Type` roles |\n|---|---|\n| `TFJob` | `Chief` / `PS` / `Worker` / `Evaluator` / `GraphLearn` |\n| `PyTorchJob` | `Worker` (+ optional `Master`, auto-promoted) |\n| `MPIJob` | `Worker` + `Master` |\n| `XGBoostJob` / `OneFlowJob` / `ElasticBatchJob` | `Worker` + optional `Master` |\n| `RayJob` | `Worker` |\n| `SlurmJob` / `DataJuicerJob` | framework-specific roles |\n\n> **Case-sensitive, no aliases.** `tensorflow`, `pytorch`, `tf-job`, `Pytorch`,\n> `PYTORCH_JOB`, `Custom`, `CustomJob` — all rejected.\n>\n> **No `Custom` enum.** For single-container custom workloads, map to\n> `PyTorchJob` (most permissive role set).\n>\n> **Locked after create:** `JobType` cannot be changed via `update-job`.\n\nFull field reference: see [references/related-apis.md](references/related-apis.md).\n\n## Core Workflows\n\n### 7.1 Resource Selection Decision Guide\n\nBefore calling `create-job`, determine the resource path:\n\n- **Public pay-as-you-go** → Use `EcsSpec` in TaskSpec; do NOT pass `--resource-id`.\n  - Use cases: quick start, testing, no dedicated quota.\n  - Example: `\"EcsSpec\": \"ecs.gn6i-c4g1.xlarge\"`\n- **Dedicated quota** (Lingjun / enterprise quota) → Use `ResourceConfig` in TaskSpec\n  AND pass `--resource-id <QuotaId>`.\n  - Use cases: dedicated resource group, Lingjun smart compute, Spot bidding.\n  - Example: `--resource-id quotaXXX` + `\"ResourceConfig\": {\"CPU\": \"4\", \"Memory\": \"8Gi\", \"GPU\": \"1\"}`\n\n> **EcsSpec and ResourceConfig MUST NOT both appear in the same TaskSpec.**\n\n> **Also required before `create-job`:** `--job-specs[].Image` MUST come from\n> `aliyun aiworkspace list-images`; `--data-sources[].DataSourceId` from\n> `list-datasets`; `--code-source.CodeSourceId` from `list-code-sources`.\n> Full discovery flow → see §7.6.\n\n**Distributed architecture choices:**\n\n| Topology | `JobSpecs` shape |\n|---|---|\n| Single-node | One `Worker` only |\n| TFJob PS-Worker | Both `PS` (CPU) and `Worker` (GPU) roles |\n| PyTorch multi-node | One `Worker` with `PodCount > 1` |\n\nOptional flags: `--enable-gang-scheduling true` (all-or-nothing scheduling),\n`Settings.EnableRDMA: true` (high-performance network for multi-node GPU),\n`Settings.EnableSanityCheck: true` (GPU health verification).\n\n> **All commands below require `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`** (omitted in snippets for brevity — see [Observability](#observability)).\n\n### 7.2 Create Training Job\n\nMinimal single-node PyTorch job (public pay-as-you-go) parameter combination:\n\n```bash\naliyun pai-dlc create-job --region <region> --workspace-id <ws-id> \\\n  --display-name \"my-pytorch-training\" --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"<ImageUri>\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]' \\\n  --user-command 'python train.py' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\nMulti-node / Spot / RDMA / data mounting — use `create-job --help`.\nSubsequent snippets omit `--user-agent` for brevity — always include it.\n\n### 7.3 List / Get Job\n\nUse `--cli-query` to project specific fields (essential for log/event flows):\n\n```bash\naliyun pai-dlc list-jobs --region <region> --status Running\naliyun pai-dlc get-job  --region <region> --job-id <id>\naliyun pai-dlc get-job  --region <region> --job-id <id> --cli-query \"Pods[0].PodId\"\n```\n\n### 7.4 Logs and Events\n\n> **Always cap return size:** `--max-lines 100` (logs), `--max-events-num 50` (events).\n\nGet `PodId` first, then query logs/events:\n\n```bash\nPOD_ID=$(aliyun pai-dlc get-job --region <r> --job-id <id> --cli-query \"Pods[0].PodId\")\naliyun pai-dlc get-pod-logs    --region <r> --job-id <id> --pod-id $POD_ID --max-lines 100\naliyun pai-dlc get-pod-events  --region <r> --job-id <id> --pod-id $POD_ID --max-events-num 20\naliyun pai-dlc get-job-events  --region <r> --job-id <id> --max-events-num 50\n```\n\n**Diagnosis order:** `get-job` (status) → `get-job-events` → `get-pod-logs` → `get-pod-events`.\n\n### 7.5 Compute Health Check\n\n```bash\naliyun pai-dlc list-job-sanity-check-results --region <r> --job-id <id>\naliyun pai-dlc get-job-sanity-check-result   --region <r> --job-id <id> --sanity-check-number 1\n```\n\n### 7.6 Pre-Create Resource Discovery (AIWorkSpace)\n\n**Discovery flow:** `list-workspaces` → `list-image-labels` →\n`list-images` → `list-datasets` → `list-code-sources` → `pai-dlc create-job`.\n\n> **Quota (`--resource-id`):** user-supplied. No CLI discovery step.\n\n```bash\naliyun aiworkspace list-workspaces     --region <r>                        # → --workspace-id\naliyun aiworkspace list-image-labels   --region <r>                        # → valid label Key=Value pairs\naliyun aiworkspace list-images         --region <r> --labels \"K1=V1,K2=V2\" # → --job-specs[].Image (use ImageUri verbatim)\naliyun aiworkspace list-datasets       --region <r> --workspace-id <ws>    # → DataSources[].DataSourceId\naliyun aiworkspace list-code-sources   --region <r> --workspace-id <ws>    # → CodeSource.CodeSourceId\n```\n\n> **Labels rules** (not in `--help`): comma-separated `Key=Value` pairs, no\n> JSON / no spaces. Values MUST come from `list-image-labels` — never invent.\n> Do **not** pass `--workspace-id` to `list-images` when discovering **official\n> public images** (they are global). Pass `--workspace-id` only when filtering\n> **custom / private images** scoped to a specific workspace.\n>\n> **RED LINE:** `--job-specs[].Image` MUST be a verbatim `ImageUri` (not\n> `Name` / `ImageId`).\n>\n\nField-mapping, full parameters, and error codes: see\n[references/related-apis.md](references/related-apis.md) and\n[references/verification-method.md](references/verification-method.md).\n\n### 7.7 Job Lifecycle Management (Stop / Update / Web Terminal)\n\nStop is a **high-risk** operation. Before proceeding, query status with\n`get-job`, present the result to the user, and require explicit confirmation.\n\n> **Rules `--help` doesn't tell you (`update-job` silent-no-op family):**\n>\n> - **Stop Job** applies only when status is `Running` or `Queuing`.\n> - **`update-job --priority`** takes effect **only** when (a) the job uses\n>   **quota resources** (`--resource-id`) AND (b) status is `Creating`,\n>   `Queuing`, or `EnvPreparing`. Once the job enters `Running` or later,\n>   priority **cannot be modified** — the API returns `200 OK` but the change\n>   is **silently NOT applied**. Always pre-check status with `get-job`.\n> - **`update-job --accessibility`** takes effect immediately in any status.\n> - **`update-job` does NOT expose `--display-name`** (`--help` lists only\n>   `--job-id`, `--accessibility`, `--description`, `--job-specs`, `--priority`).\n>   To rename a job, recreate it.\n\nFor the full pre-check + confirmation + execution templates, plus the\n`update-job` low-risk path and `get-web-terminal` / `get-token` sharing\ncommands, see [references/job-management.md](references/job-management.md).\n\n### 7.8 Ecs Spec Discovery\n\nDiscover available instance types; the returned `EcsSpec` value goes\nverbatim into `--job-specs[].EcsSpec`.\n\n```bash\naliyun pai-dlc list-ecs-specs --region <r> --accelerator-type GPU --resource-type ECS --page-size 20\n# Lingjun dedicated: --quota-id <id> (whitelisted users only)\n```\n\n> **`list-ecs-specs` does not support `--sort-by`** — even values shown as\n> valid in `--help` (e.g. `CPU` / `GPU` / `Memory` / `GmtCreateTime`) are\n> rejected by the server. Always omit `--sort-by` here and sort the JSON\n> output client-side with `jq` — e.g.\n> `... | jq '.EcsSpecs | sort_by(-.AcceleratorNumber)'`.\n\n## Success Verification Method\n\nFor step-by-step end-to-end verification scripts (resource discovery →\nCreateJob → log query → cleanup), see\n[references/verification-method.md](references/verification-method.md).\n\n**Quick verification:**\n\n- `get-job` → Status should be `Creating` / `Queuing` / `Running` shortly after\n  `create-job` returns.\n- `list-jobs --status Running` → Should return the freshly created Job until it\n  finishes or is stopped.\n- `get-pod-logs` → Should return non-empty log content once the Pod is past\n  `EnvPreparing`.\n\n## Command Tables\n\nThe full command index (5 categories × ~40 commands, with plugin\nattribution) is consolidated in\n[references/related-apis.md](references/related-apis.md) §1.\n\n## Best Practices\n\n> Items below are **decision rules** and **operational habits** — not parameter\n> values (those live in `--help`).\n\n1. **Job naming** — use meaningful, sortable names: `project-model-date`\n   (e.g. `resnet50-imagenet-20260320`). Recreate (not `update-job`) is the\n   only way to rename.\n2. **Resource sizing** — pick GPU type / count by model & dataset size. Verify\n   availability with `list-ecs-specs --accelerator-type GPU` **before** picking\n   `EcsSpec` (see §7.8).\n3. **Diagnose early** — follow the order `get-job` → `get-job-events` →\n   `get-pod-logs` → `get-pod-events`. Cap responses (`--max-lines 100`,\n   `--max-events-num 50`) to keep agent context lean.\n4. **Priority adjustment** — prefer setting `--priority` at `create-job` time.\n   Post-creation `update-job --priority` only works for quota jobs in\n   `Creating` / `Queuing` / `EnvPreparing` phase (§7.7); once `Running`,\n   priority cannot be modified.\n5. **Cost control** — use `--job-max-running-time-minutes` as an auto-stop guard\n   for every long-running experiment. Spot via `SpotSpec` reduces cost at the\n   risk of preemption.\n6. **Health check** — enable `Settings.EnableSanityCheck: true` for GPU\n   training to catch faulty devices before training starts.\n7. **Resource cleanup** — `stop-job` on completed jobs to free quota.\n8. **Idempotency on writes** — PAI-DLC `create-*` APIs do **NOT** expose\n   `--client-token` (verified via `aliyun pai-dlc create-job --help`). Network\n   retries can therefore create duplicate Jobs. Mitigation: before re-issuing\n   a failed `create-*`, run `list-jobs --display-name <name>` to detect a\n   half-committed prior attempt.\n\n## Reference Links\n\n| Reference Document | Description |\n|--------------------|-------------|\n| [references/related-apis.md](references/related-apis.md) | Command index, cross-product field map, lifecycle, red lines, error catalog |\n| [references/ram-policies.md](references/ram-policies.md) | RAM permission policy details |\n| [references/verification-method.md](references/verification-method.md) | End-to-end verification scripts |\n| [references/job-management.md](references/job-management.md) | High-risk Stop/Delete/Update flow + Web Terminal |\n| [references/acceptance-criteria.md](references/acceptance-criteria.md) | Skill testing acceptance criteria |\n| [references/cli-installation-guide.md](references/cli-installation-guide.md) | CLI installation guide |\n\nFile v0.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-pai-dlc-job\",\n  \"version\": \"0.0.2\",\n  \"publishedAt\": 1786696690094\n}\n\nFile v0.0.2:references/acceptance-criteria.md\n\n# Acceptance Criteria: alibabacloud-pai-dlc-job\n\n**Scenario**: PAI-DLC Deep Learning Job Management\n**Purpose**: Skill Testing Acceptance Criteria\n\n> **Note on snippets in this file:** Sections 1-3 below show product names,\n> command names, and parameter names as **pattern placeholders** (e.g.,\n> `aliyun pai-dlc <command>`). These are fragments for mismatch detection,\n> not complete executable commands. The Section 4 \"User-Agent\" rule (and the\n> SKILL.md core workflow) require every API-invoking command to end with\n> `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`; full executable examples carry it.\n\n---\n\n# Correct CLI Command Patterns\n\n## 1. Product — Verify Product Name Exists\n\nCORRECT\n```bash\naliyun pai-dlc <command>\n```\n\nINCORRECT\n```bash\naliyun pai <command>        # Error: product name should be pai-dlc\naliyun dlc <command>        # Error: product name should be pai-dlc\naliyun PAI-DLC <command>    # Error: case-sensitive, should use lowercase\n```\n\n## 2. Command — Verify Command Name Format\n\nCORRECT (Plugin mode, lowercase with hyphens)\n```bash\naliyun pai-dlc create-job\naliyun pai-dlc list-jobs\naliyun pai-dlc get-job\naliyun pai-dlc get-pod-logs\naliyun pai-dlc list-ecs-specs\naliyun pai-dlc get-web-terminal\naliyun pai-dlc stop-job\naliyun pai-dlc update-job\naliyun pai-dlc get-token\naliyun pai-dlc get-job-events\naliyun pai-dlc get-pod-events\naliyun pai-dlc get-job-sanity-check-result\naliyun pai-dlc list-job-sanity-check-results\n```\n\nINCORRECT (Traditional API format)\n```bash\naliyun pai-dlc CreateJob       # Error: should use create-job\naliyun pai-dlc ListJobs        # Error: should use list-jobs\naliyun pai-dlc GetJob          # Error: should use get-job\naliyun pai-dlc GetPodLogs      # Error: should use get-pod-logs\n```\n\n## 3. Parameters — Verify Parameter Name Format\n\nCORRECT (Lowercase with hyphens)\n```bash\n--job-id\n--pod-id\n--display-name\n--job-type\n--job-specs\n--user-command\n--workspace-id\n--resource-id\n--page-number\n--page-size\n--start-time\n--end-time\n--max-lines\n--user-agent\n```\n\nINCORRECT (CamelCase or underscore)\n```bash\n--JobId            # Error: should use --job-id\n--jobId            # Error: should use --job-id\n--job_id           # Error: should use --job-id\n--displayName      # Error: should use --display-name\n--DisplayName      # Error: should use --display-name\n```\n\n## 4. User-Agent — Must Include Identifier\n\nCORRECT\n```bash\naliyun pai-dlc list-jobs --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\nINCORRECT\n```bash\naliyun pai-dlc list-jobs --region cn-hangzhou   # Error: missing --user-agent\n```\n\n## 5. JobSpecs Format — Verify JSON Structure\n\nCORRECT - Method 1: EcsSpec (Public Resources)\n```bash\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch:1.12\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]'\n```\n\nCORRECT - Method 2: ResourceConfig (Dedicated Resource Group)\n```bash\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch:1.12\",\"ResourceConfig\":{\"CPU\":\"4\",\"Memory\":\"16Gi\",\"GPU\":\"1\"}}]'\n```\n\nINCORRECT\n```bash\n# Error: Not a valid JSON array\n--job-specs '{\"Type\":\"Worker\"}'\n\n# Error: Missing required fields\n--job-specs '[{\"Type\":\"Worker\"}]'\n\n# Error: Incorrect field name case\n--job-specs '[{\"type\":\"Worker\",\"podCount\":1}]'\n\n# Error: EcsSpec and ResourceConfig set simultaneously (mutually exclusive!)\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"...\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\",\"ResourceConfig\":{\"CPU\":\"4\"}}]'\n```\n\n## 6. Job Status — Verify Case & Spelling (NOT an exhaustive enum)\n\n> **Authoritative enum source:** `aliyun pai-dlc list-jobs --help`. This section\n> only verifies case-sensitivity and spelling conventions — do NOT treat the\n> samples below as the complete list of legal `--status` values.\n\nCORRECT (representative samples — server accepts more, e.g. `Bidding`,\n`EnvPreparing`, `SanityChecking`, `SucceededReserving`, `FailedReserving`)\n```bash\n--status Creating\n--status Running\n--status Succeeded\n--status Failed\n```\n\nINCORRECT\n```bash\n--status creating     # Error: first letter should be uppercase\n--status RUNNING      # Error: should use Running\n--status success      # Error: should use Succeeded\n```\n\n## 7. Job Type — Verify Job Types\n\nCORRECT\n```bash\n--job-type TFJob\n--job-type PyTorchJob\n--job-type XGBoostJob\n--job-type OneFlowJob\n--job-type ElasticBatchJob\n```\n\nINCORRECT\n```bash\n--job-type tensorflow    # Error: should use TFJob\n--job-type pytorch       # Error: should use PyTorchJob\n--job-type tf-job        # Error: should use TFJob\n```\n\n---\n\n# Credential Patterns\n\n## 1. Credential Verification — Must Use Secure Method\n\nCORRECT\n```bash\n# Only check configuration status\naliyun configure list\n```\n\nINCORRECT\n```bash\n# Error: Prohibited from printing credential values\necho $ALIBABA_CLOUD_ACCESS_KEY_ID\necho $ALIBABA_CLOUD_ACCESS_KEY_SECRET\n\n# Error: Prohibited from using plaintext credentials in command line\naliyun configure set --access-key-id LTAI5tXXXX --access-key-secret 8dXXXX\n```\n\n---\n\n# Complete Command Examples\n\n## Create Job\n\nCORRECT - EcsSpec (Public Resources)\n```bash\naliyun pai-dlc create-job \\\n  --region cn-hangzhou \\\n  --display-name \"my-training-job\" \\\n  --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch-training:1.12-gpu-py38-cu113-ubuntu20.04\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]' \\\n  --user-command \"python train.py\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\nCORRECT - ResourceConfig (Dedicated Resource Group)\n```bash\naliyun pai-dlc create-job \\\n  --region cn-hangzhou \\\n  --resource-id <resource-group-id> \\\n  --display-name \"my-training-job\" \\\n  --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch-training:1.12-gpu-py38-cu113-ubuntu20.04\",\"ResourceConfig\":{\"CPU\":\"4\",\"Memory\":\"16Gi\",\"GPU\":\"1\",\"GPUType\":\"NVIDIA-V100\"}}]' \\\n  --user-command \"python train.py\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## List Jobs\n\nCORRECT\n```bash\naliyun pai-dlc list-jobs \\\n  --region cn-hangzhou \\\n  --status Running \\\n  --page-number 1 \\\n  --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## Get Logs\n\nCORRECT\n```bash\naliyun pai-dlc get-pod-logs \\\n  --region cn-hangzhou \\\n  --job-id dlc12345678 \\\n  --pod-id dlc12345678-worker-0 \\\n  --max-lines 500 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## Stop Job\n\nCORRECT\n```bash\n# Stop job\naliyun pai-dlc stop-job \\\n  --region cn-hangzhou \\\n  --job-id dlc12345678 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n---\n\n# Testing Checklist\n\n- [ ] All commands use plugin mode format (lowercase with hyphens)\n- [ ] All commands include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`\n- [ ] No hardcoded user-specific parameters (RegionId, JobId, etc. need user confirmation)\n- [ ] Credential operations only use `aliyun configure list` for checking\n- [ ] JobSpecs use correct JSON array format\n- [ ] Enum values use correct case\n- [ ] All required parameters provided\n\n---\n\n# AIWorkSpace Resource Discovery Command Standards\n\nThis section covers the 8 AIWorkSpace 2021-02-04 query APIs needed before creating a DLC job. All commands MUST be invoked through the `aliyun-cli-aiworkspace` plugin, and subcommands MUST use the lowercase + hyphen format.\n\n## 8. AIWorkSpace Plugin Query Commands — Verify Subcommand Spelling\n\nCORRECT (lowercase + hyphen subcommands exposed by the plugin)\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --page-number 1 --page-size 20\naliyun aiworkspace list-images --region cn-hangzhou --workspace-id <WORKSPACE_ID>\naliyun aiworkspace get-image --region cn-hangzhou --image-id <IMAGE_ID>\naliyun aiworkspace list-datasets --region cn-hangzhou --workspace-id <WORKSPACE_ID>\naliyun aiworkspace get-dataset --region cn-hangzhou --dataset-id <DATASET_ID>\naliyun aiworkspace list-code-sources --region cn-hangzhou --workspace-id <WORKSPACE_ID>\naliyun aiworkspace get-code-source --region cn-hangzhou --code-source-id <CODE_SOURCE_ID>\n```\n\nINCORRECT — ROA Generic Fallback Invocation (Red Line, Forbidden)\n```bash\n# Forbidden: invoking with the HTTP method + path-pattern ROA generic form\naliyun aiworkspace ListImages --version 2021-02-04 --method GET --pathPattern /api/v1/images --header Content-Type=application/json\n\n# Forbidden: the same ROA fallback is also disallowed on the PAI-DLC side\naliyun pai-dlc CreateJob --version 2020-12-30 --method POST --pathPattern /api/v1/jobs --body '{...}'\n```\n\nINCORRECT — Wrong Product Name\n```bash\n# Error: resource discovery APIs belong to the aiworkspace product, not pai-dlc\naliyun pai-dlc list-images --workspace-id <id>\naliyun pai-dlc list-datasets --workspace-id <id>\naliyun pai-dlc list-workspaces\n```\n\nINCORRECT — Does Not Conform to lowercase + hyphen Convention\n```bash\n# Error: missing hyphen\naliyun aiworkspace listimages --workspace-id <id>\naliyun aiworkspace listdatasets --workspace-id <id>\n\n# Error: using camelCase / PascalCase / underscore naming\naliyun aiworkspace ListImages --workspace-id <id>\naliyun aiworkspace List-Images --workspace-id <id>\naliyun aiworkspace list_images --workspace-id <id>\n```\n\n## 9. AIWorkSpace Command Parameters — Use kebab-case\n\nCORRECT\n```bash\n--workspace-id\n--image-id\n--dataset-id\n--code-source-id\n--page-number\n--page-size\n--workspace-ids       # list-workspaces only, multiple IDs separated by commas\n--display-name        # filter parameter for list-code-sources\n--data-source-types   # filter parameter for list-datasets (NAS / OSS)\n```\n\nINCORRECT\n```bash\n--WorkspaceId            # Error: should use --workspace-id\n--imageId                # Error: should use --image-id\n--code_source_id         # Error: should use --code-source-id\n```\n\n## 10. Resource Discovery -> CreateJob Value Mapping\n\nCORRECT — Look up first, then construct; use plugin return values as CreateJob parameters\n```bash\n# Look up WorkspaceId\nWORKSPACE_ID=$(aliyun aiworkspace list-workspaces --region cn-hangzhou \\\n  --cli-query 'Workspaces[0].WorkspaceId')\n\n# QuotaId (`--resource-id`) is manually provided by the user\n\n# Look up ImageUri\nIMAGE_URI=$(aliyun aiworkspace list-images --region cn-hangzhou --workspace-id $WORKSPACE_ID \\\n  --cli-query 'Images[0].ImageUri')\n```\n\nINCORRECT — Querying ImageUri from the pai-dlc product (wrong product)\n```bash\n# Do not query images under the pai-dlc product; ImageUri can only come from AIWorkSpace.ListImages\naliyun pai-dlc list-images --workspace-id $WORKSPACE_ID\n```\n\n---\n\n# Red Line: ROA Generic Fallback Invocations Are Forbidden\n\n> **Per the user's decision for this task**: Within this skill, using the HTTP method + path-pattern ROA generic fallback invocation is strictly forbidden.\n\n## Scope\n\nThis red line applies to all of the following:\n\n- The 7 AIWorkSpace resource discovery APIs (`ListImages` / `GetImage` / `ListDatasets` / `GetDataset` / `ListCodeSources` / `GetCodeSource` / `ListWorkspaces`). `--resource-id` (QuotaId) is manually provided by the user.\n- All PAI-DLC job APIs (`CreateJob` / `ListJobs` / ...).\n\n## Violation Examples (Must Never Appear in Correct Examples)\n\n```bash\n# Using the ROA generic form to assemble any AIWorkSpace / PAI-DLC API\naliyun aiworkspace ListImages --version 2021-02-04 --method GET --pathPattern /api/v1/images\naliyun aiworkspace GetDataset --version 2021-02-04 --method GET --pathPattern /api/v1/datasets/{DatasetId}\naliyun pai-dlc CreateJob --version 2020-12-30 --method POST --pathPattern /api/v1/jobs --body '{...}'\n```\n\n## Correct Approach\n\n- The skill MUST rely solely on the lowercase + hyphen subcommands exposed by the plugin.\n- If a particular plugin subcommand is unavailable (`unknown command`), run `aliyun plugin update --name aliyun-cli-pai-dlc` or `aliyun plugin install --names aliyun-cli-aiworkspace` to reinstall/upgrade the plugin. If it remains unavailable, stop and ask the user to intervene; **do NOT construct ROA invocations on your own**.\n\nFile v0.0.2:references/cli-installation-guide.md\n\n# Aliyun CLI Installation & Configuration Guide\n\nComplete guide for installing and configuring Aliyun CLI.\n\n> **Aliyun CLI 3.3.1+**: Supports installing and using all published Alibaba Cloud product plugins. Make sure to upgrade to 3.3.1 or later for full functionality.\n\n## Installation\n\n### macOS\n\n**Using Homebrew (Recommended)**\n```bash\nbrew install aliyun-cli\n# Upgrade to latest\nbrew upgrade aliyun-cli\n\n# Verify version (>= 3.3.1)\naliyun version\n```\n\n**Using Binary**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz\n\n# Extract\ntar -xzf aliyun-cli-macosx-latest-amd64.tgz\n\n# Move to PATH\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n### Linux\n\n**Debian/Ubuntu**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**CentOS/RHEL**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**ARM64 Architecture**\n```bash\n# Download ARM64 version\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-arm64.tgz\nsudo mv aliyun /usr/local/bin/\n```\n\n### Windows\n\n**Using Binary**\n1. Download from: https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\n2. Extract the ZIP file\n3. Add the directory to your PATH environment variable\n4. Open new Command Prompt or PowerShell\n5. Verify: `aliyun version`\n\n**Using PowerShell**\n```powershell\n# Download\nInvoke-WebRequest -Uri \"https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\" -OutFile \"aliyun-cli.zip\"\n\n# Extract\nExpand-Archive -Path aliyun-cli.zip -DestinationPath C:\\aliyun-cli\n\n# Add to PATH (requires admin privileges)\n$env:Path += \";C:\\aliyun-cli\"\n[Environment]::SetEnvironmentVariable(\"Path\", $env:Path, [System.EnvironmentVariableTarget]::Machine)\n\n# Verify\naliyun version\n```\n\n## User-Agent for Skill Calls (session-id)\n\n> Do NOT use the deprecated `aliyun configure ai-mode` to set the User-Agent.\n> Instead, pass `--user-agent` explicitly on every API-invoking command using\n> the unified session-id template. See the `Observability` section in `SKILL.md`\n> for the full rules.\n\n```bash\n# Generate the session-id ONCE per skill session, then reuse it everywhere\nSESSION_ID=$(uuidgen | tr 'A-Z' 'a-z')\nexport SESSION_ID\n\n# Every API-invoking command appends the templated User-Agent:\naliyun pai-dlc list-jobs --region cn-hangzhou --page-size 1 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## Configuration\n\n### Quick Start\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id <your-access-key-id> \\\n  --access-key-secret <your-access-key-secret> \\\n  --region cn-hangzhou\n```\n\nAll `aliyun configure` commands support non-interactive flags, which is the recommended approach —\nit works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts.\n\n**Where to Get Access Keys**\n\n1. Log in to Aliyun Console: https://ram.console.aliyun.com/\n2. Navigate to: AccessKey Management\n3. Create a new AccessKey pair\n4. Save the secret immediately — it's only shown once\n\n### Configuration Modes\n\nAliyun CLI supports 6 authentication modes. All examples below use non-interactive flags.\n\n#### 1. AK Mode (Access Key)\n\nMost common mode for personal accounts and scripts.\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nConfiguration is stored in `~/.aliyun/config.json`:\n\n```json\n{\n  \"current\": \"default\",\n  \"profiles\": [\n    {\n      \"name\": \"default\",\n      \"mode\": \"AK\",\n      \"access_key_id\": \"LTAI5tXXXXXXXX\",\n      \"access_key_secret\": \"8dXXXXXXXXXXXXXXXXXXXXXXXX\",\n      \"region_id\": \"cn-hangzhou\",\n      \"output_format\": \"json\",\n      \"language\": \"en\"\n    }\n  ]\n}\n```\n\n#### 2. StsToken Mode (Temporary Credentials)\n\nFor short-lived access (tokens expire in 1-12 hours).\n\n```bash\naliyun configure set \\\n  --mode StsToken \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --sts-token v1.0:XXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nUse cases: CI/CD pipelines, temporary access for external contractors, cross-account access.\n\n#### 3. RamRoleArn Mode (Assume RAM Role)\n\nAssume a RAM role for elevated or cross-account access.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArn \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --ram-role-arn acs:ram::123456789012:role/AdminRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\nUse cases: cross-account resource access, temporary elevated privileges, role-based access control.\n\n#### 4. EcsRamRole Mode (ECS Instance RAM Role)\n\nUse the RAM role attached to an ECS instance — no credentials needed.\n\n```bash\naliyun configure set \\\n  --mode EcsRamRole \\\n  --ram-role-name MyEcsRole \\\n  --region cn-hangzhou\n```\n\nRequirements: must be running on an ECS instance with a RAM role attached.\n\nUse cases: scripts and automation running on ECS instances.\n\n#### 5. RsaKeyPair Mode (RSA Key Pair)\n\nUse RSA key pair for authentication (generate key pair in Aliyun Console first).\n\n```bash\naliyun configure set \\\n  --mode RsaKeyPair \\\n  --private-key /path/to/private-key.pem \\\n  --key-pair-name my-key-pair \\\n  --region cn-hangzhou\n```\n\n#### 6. RamRoleArnWithEcs Mode (ECS + RAM Role)\n\nCombine ECS instance role with RAM role assumption for cross-account access from ECS.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArnWithEcs \\\n  --ram-role-name MyEcsRole \\\n  --ram-role-arn acs:ram::123456789012:role/TargetRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\n### Environment Variables\n\n**Highest priority** - overrides config file\n\n**Access Key Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**STS Token Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_SECURITY_TOKEN=your_sts_token\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**ECS RAM Role Mode**\n```bash\nexport ALIBABA_CLOUD_ECS_METADATA=role_name\n```\n\n**Use Case**:\n- CI/CD pipelines\n- Docker containers\n- Temporary credential override\n\n### Managing Multiple Profiles\n\n**Create Named Profiles**\n\n```bash\naliyun configure set --profile projectA \\\n  --mode AK \\\n  --access-key-id LTAI5tAAAAAAAA \\\n  --access-key-secret 8dAAAAAAAAAAAAAAAAAAAAAAAA \\\n  --region cn-hangzhou\n\naliyun configure set --profile projectB \\\n  --mode AK \\\n  --access-key-id LTAI5tBBBBBBBB \\\n  --access-key-secret 8dBBBBBBBBBBBBBBBBBBBBBBBB \\\n  --region cn-shanghai\n```\n\n**Use Specific Profile**\n\n```bash\naliyun ecs describe-instances --profile projectA\n\nexport ALIBABA_CLOUD_PROFILE=projectA\naliyun ecs describe-instances   # Uses projectA\n```\n\n**List and Switch Profiles**\n\n```bash\naliyun configure list                      # List all profiles\naliyun configure set --current projectA    # Switch default profile\n```\n\n### Credential Priority\n\nCredentials are loaded in this order (first found wins):\n\n1. **Command-line flag**: `--profile <name>`\n2. **Environment variable**: `ALIBABA_CLOUD_PROFILE`\n3. **Environment credentials**: `ALIBABA_CLOUD_ACCESS_KEY_ID`, etc.\n4. **Configuration file**: `~/.aliyun/config.json` (current profile)\n5. **ECS Instance RAM Role**: If running on ECS with attached role\n\n## Verification\n\n### Test Authentication\n\n```bash\n# Basic test - list regions\naliyun ecs describe-regions\n\n# Expected output: JSON array of regions\n```\n\n**If successful**, you'll see:\n```json\n{\n  \"Regions\": {\n    \"Region\": [\n      {\n        \"RegionId\": \"cn-hangzhou\",\n        \"RegionEndpoint\": \"ecs.cn-hangzhou.aliyuncs.com\",\n        \"LocalName\": \"East China 1 (Hangzhou)\"\n      },\n      ...\n    ]\n  },\n  \"RequestId\": \"...\"\n}\n```\n\n**If failed**, you'll see error messages:\n- `InvalidAccessKeyId.NotFound` - Wrong Access Key ID\n- `SignatureDoesNotMatch` - Wrong Access Key Secret\n- `InvalidSecurityToken.Expired` - STS token expired (for StsToken mode)\n- `Forbidden.RAM` - Insufficient permissions\n\n### Debug Configuration\n\n```bash\n# Show current configuration\naliyun configure get\n\n# Test with debug logging\naliyun ecs describe-regions --log-level=debug\n\n# Check credential provider\naliyun configure get mode\n```\n\n## Security Best Practices\n\n### 1. Use RAM Users (Not Root Account)\n\n❌ **Don't**: Use Aliyun root account credentials\n✅ **Do**: Create RAM users with specific permissions\n\n```bash\n# Create RAM user in console\n# Attach only necessary policies\n# Use RAM user's access keys\n```\n\n### 2. Principle of Least Privilege\n\nGrant only the minimum permissions needed:\n\n```bash\n# Example: Read-only ECS access\n# Attach policy: AliyunECSReadOnlyAccess\n```\n\n### 3. Rotate Access Keys Regularly\n\n```bash\n# Create new access key in RAM Console, then update configuration\naliyun configure set --access-key-id NEW_KEY --access-key-secret NEW_SECRET\n# Delete old access key from console\n```\n\n### 4. Use STS Tokens for Temporary Access\n\n```bash\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token XXXX --region cn-hangzhou\n```\n\n### 5. Use ECS RAM Roles When Possible\n\n```bash\naliyun configure set --mode EcsRamRole --ram-role-name MyRole --region cn-hangzhou\n```\n\n### 6. Never Commit Credentials\n\n```bash\n# Add to .gitignore\necho \"~/.aliyun/config.json\" >> .gitignore\n\n# Use environment variables in CI/CD instead\n```\n\n### 7. Secure Config File\n\n```bash\n# Restrict permissions\nchmod 600 ~/.aliyun/config.json\n```\n\n## Troubleshooting\n\n### Issue: Command Not Found\n\n```bash\n# Check installation\nwhich aliyun\n\n# Check PATH\necho $PATH\n\n# Reinstall or add to PATH\n```\n\n### Issue: Authentication Failed\n\n```bash\n# Verify configuration\naliyun configure get\n\n# Test with debug\naliyun ecs describe-regions --log-level=debug\n\n# Check credentials in console\n# Verify access key is active\n```\n\n### Issue: Permission Denied\n\n```bash\n# Error: Forbidden.RAM\n\n# Check RAM user permissions\n# Attach necessary policies in RAM console\n# Example: AliyunECSFullAccess for ECS operations\n```\n\n### Issue: STS Token Expired\n\n```bash\n# Error: InvalidSecurityToken.Expired\n\n# Reconfigure with new token\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token NEW_TOKEN --region cn-hangzhou\n```\n\n### Issue: Wrong Region\n\n```bash\n# Some resources may not exist in the specified region\n\n# Check available regions\naliyun ecs describe-regions\n\n# Update default region\naliyun configure set region cn-shanghai\n```\n\n## Advanced Configuration\n\n### Custom Endpoint\n\n```bash\n# Use custom or private endpoint\nexport ALIBABA_CLOUD_ECS_ENDPOINT=ecs-vpc.cn-hangzhou.aliyuncs.com\n```\n\n### Proxy Settings\n\n```bash\n# HTTP proxy\nexport HTTP_PROXY=http://proxy.example.com:8080\nexport HTTPS_PROXY=http://proxy.example.com:8080\n\n# No proxy for specific domains\nexport NO_PROXY=localhost,127.0.0.1,.aliyuncs.com\n```\n\n### Timeout Settings\n\n```bash\n# Connection timeout (default: 10s)\nexport ALIBABA_CLOUD_CONNECT_TIMEOUT=30\n\n# Read timeout (default: 10s)\nexport ALIBABA_CLOUD_READ_TIMEOUT=30\n```\n\n## References\n\n- Official Documentation: https://help.aliyun.com/zh/cli/\n- RAM Console: https://ram.console.aliyun.com/\n- Access Key Management: https://ram.console.aliyun.com/manage/ak\n- Plugin Repository: https://github.com/aliyun/aliyun-cli\n\nFile v0.0.2:references/job-management.md\n\n# Job Lifecycle Management\n\nOperational rules for `update-job` / `stop-job` / `get-web-terminal` /\n`get-token` — focused on **what `--help` cannot tell you**: status windows,\nsilent-no-op cases, and the high-risk `stop-job` confirmation protocol.\n\nFor the full parameter list of any subcommand, run\n`aliyun pai-dlc <cmd> --help`.\n\n## 1. Status-to-Operation Compatibility\n\n| Operation | Allowed Job Status | Caveat |\n|-----------|--------------------|--------|\n| `update-job --accessibility` | Any | Takes effect immediately |\n| `update-job --description` | Any | Metadata only |\n| `update-job --priority` | `Creating` / `Queuing` / `EnvPreparing` | **AND** job uses quota (`--resource-id`); once `Running`, cannot be modified |\n| `update-job --job-specs` (PodCount) | Elastic-enabled jobs only | Restricted to supported phases |\n| `stop-job` | `Running` / `Queuing` only | Irreversible — three-step protocol below |\n| `get-web-terminal` | `Running` only | Pod must be alive |\n| `get-token` | Any | Read-only sharing |\n\n> **`update-job` does NOT expose `--display-name`** — to rename a job,\n> recreate it.\n\n## 2. `update-job --priority` Pre-check Protocol\n\nAlways probe both `Status` and `ResourceId` before issuing a priority update;\notherwise the API returns `200 OK` while silently dropping the change.\n\n```bash\naliyun pai-dlc get-job \\\n  --region <region> --job-id <job-id> \\\n  --cli-query '{Status: Status, ResourceId: ResourceId}' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\nProceed **only if both** hold:\n\n- `Status` ∈ `Creating` / `Queuing` / `EnvPreparing`\n- `ResourceId` is non-empty (quota-based job, e.g. `quotaXXXX`)\n\nAfter issuing the update, expect a 10–60 second propagation delay before\n`get-job` reflects the new `Priority`.\n\n## 3. `stop-job` — Three-Step Protocol (HIGH RISK)\n\nStopping a `Running` job discards in-memory progress unless the user's script\ncheckpoints. **Never call `stop-job` without explicit user confirmation.**\n\n### Step 1 — Pre-check\n\n```bash\naliyun pai-dlc get-job \\\n  --region <region> --job-id <job-id> \\\n  --cli-query '{Status: Status, Name: DisplayName}' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n### Step 2 — Confirm with the user\n\nPresent `Status` + `DisplayName`. Use this prompt template:\n\n```\nJob <job-id> (\"<DisplayName>\") is currently <Status>.\nStopping a Running job cannot be undone and will discard any in-memory progress.\nAre you sure you want to stop this job? [yes/no]\n```\n\nDo NOT proceed without an explicit `yes`.\n\n### Step 3 — Execute, then verify\n\n```bash\naliyun pai-dlc stop-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\n# Verify (expected: \"Stopped\")\naliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --cli-query \"Status\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## 4. `get-web-terminal`\n\nRequires the Pod to be alive; the URL is short-lived. Typical pattern:\n\n```bash\nPOD_ID=$(aliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --cli-query \"Pods[0].PodId\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID})\n\naliyun pai-dlc get-web-terminal --region <region> --job-id <job-id> \\\n  --pod-id \"$POD_ID\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## 5. `get-token` — Read-Only Sharing\n\nGenerates a token recipients can use to view the job (logs / events /\nmetrics) without RAM access. The token is read-only delegation; it cannot\nmodify the job. **Never share via insecure channels** — logs may contain\nsensitive data.\n\n## Common Pitfalls\n\n- ❌ `stop-job` on a `Stopped` / `Succeeded` / `Failed` job — API rejects with\n  `BadRequest` (terminal state). Always pre-check.\n- ❌ `get-web-terminal` after the Job exits `Running` — Pod gone, URL\n  unreachable.\n- ⚠ `update-job --priority` on a public-resource (`EcsSpec`) job → silent\n  no-op. Only quota-based jobs (`--resource-id`) honor it.\n- ⚠ `update-job --priority` once job is `Running` or later → silent no-op,\n  cannot be modified.\n- ⚠ Display name is **not updatable** — pick the right name at `create-job`.\n\nFile v0.0.2:references/ram-policies.md\n\n# PAI-DLC RAM Permission Policies\n\n## Permission Overview\n\nThe following RAM permissions are required to use PAI-DLC service. Please ensure RAM users or roles have been granted the appropriate permissions.\n\n## Minimum Permission Policy (Read-Only)\n\nQuery job information, logs, and monitoring data only:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:GetPodLogs\",\n        \"pai:GetPodEvents\",\n        \"pai:GetJobEvents\",\n        \"pai:ListEcsSpecs\",\n        \"pai:GetJobSanityCheckResult\",\n        \"pai:ListJobSanityCheckResults\",\n        \"paiworkspace:ListWorkspaces\",\n        \"paiimage:ListImages\",\n        \"paiimage:GetImage\",\n        \"paidataset:ListDatasets\",\n        \"paidataset:GetDataset\",\n        \"paicodesource:ListCodeSources\",\n        \"paicodesource:GetCodeSource\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n> Note: The last 7 Actions above belong to the **AIWorkSpace** product (product name `PAIWorkspace`). The RAM sub-account MUST also be granted the corresponding authorizations in order to query the WorkspaceId / ImageUri / DatasetId / CodeSourceId required for DLC job creation. The QuotaId (`--resource-id`) is manually provided by the user. Without authorization, `aliyun aiworkspace list-*` returns `Forbidden.RAM`.\n\n## Standard Permission Policy (Read-Write)\n\nComplete job management permissions:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:CreateJob\",\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:GetPodLogs\",\n        \"pai:GetPodEvents\",\n        \"pai:GetJobEvents\",\n        \"pai:ListEcsSpecs\",\n        \"pai:GetWebTerminal\",\n        \"pai:GetToken\",\n        \"pai:UpdateJob\",\n        \"pai:StopJob\",\n        \"pai:GetJobSanityCheckResult\",\n        \"pai:ListJobSanityCheckResults\",\n        \"paiworkspace:ListWorkspaces\",\n        \"paiimage:ListImages\",\n        \"paiimage:GetImage\",\n        \"paidataset:ListDatasets\",\n        \"paidataset:GetDataset\",\n        \"paicodesource:ListCodeSources\",\n        \"paicodesource:GetCodeSource\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n> Notes:\n> - The 7 AIWorkSpace-namespaced Actions belong to the **AIWorkSpace** product. They are required for the resource discovery (`list-workspaces` / `list-images` / `list-datasets` / `list-code-sources`) performed before invoking `aliyun pai-dlc create-job`, and MUST be granted to the RAM sub-account together with the `pai:*` Actions above. `--resource-id` (QuotaId) is manually provided by the user.\n## Full Permission Policy (Administrator)\n\nComplete permissions including workspace and resource group management:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:CreateJob\",\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:GetPodLogs\",\n        \"pai:GetPodEvents\",\n        \"pai:GetJobEvents\",\n        \"pai:ListEcsSpecs\",\n        \"pai:GetWebTerminal\",\n        \"pai:GetToken\",\n        \"pai:UpdateJob\",\n        \"pai:StopJob\",\n        \"pai:GetJobSanityCheckResult\",\n        \"pai:ListJobSanityCheckResults\",\n        \"paiworkspace:ListWorkspaces\",\n        \"paiimage:ListImages\",\n        \"paiimage:GetImage\",\n        \"paidataset:ListDatasets\",\n        \"paidataset:GetDataset\",\n        \"paicodesource:ListCodeSources\",\n        \"paicodesource:GetCodeSource\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n> Note: The `pai:ListImages` / `pai:ListDataSources` / `pai:GetDataSource` listed in earlier versions are **NOT correct Action names**. According to the AIWorkSpace OpenAPI metadata `systemTags.ramAction.action`, the following should be used instead:\n>\n> - `paiimage:ListImages` (also includes `paiimage:GetImage`)\n> - `paidataset:ListDatasets` (also includes `paidataset:GetDataset`)\n> - `paicodesource:ListCodeSources` (also includes `paicodesource:GetCodeSource`)\n>\n> All of the above Actions belong to the **AIWorkSpace** product (product name `PAIWorkspace`). The RAM sub-account MUST be granted the corresponding authorizations; granting only `pai:*` is insufficient to invoke `aliyun aiworkspace list-*` / `get-*`. The `pai:GetQuota` / `pai:ListResourceGroups` / `pai:GetResourceGroup` listed in earlier versions do not appear among the 7 resource discovery APIs covered by this task and are therefore not appended to the policy here.\n\n## Permissions by Operation Category\n\n### Job Creation Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Create Training Job | `pai:CreateJob` | Create DLC training job |\n| List Machine Specs | `pai:ListEcsSpecs` | Query available ECS instance specifications |\n\n### Job Query Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| List Jobs | `pai:ListJobs` | Get job list with pagination and filtering |\n| Get Job Details | `pai:GetJob` | Get detailed information of a single job |\n| Get Pod Logs | `pai:GetPodLogs` | Get log output of job nodes |\n| Get Pod Events | `pai:GetPodEvents` | Get system events of job nodes |\n| Get Job Events | `pai:GetJobEvents` | Get job-level system events |\n\n### Job Management Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Update Job | `pai:UpdateJob` | Update job configuration, such as priority |\n| Stop Job | `pai:StopJob` | Stop running job |\n\n### Health Check Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Get Check Result | `pai:GetJobSanityCheckResult` | Get specific compute health check result |\n| List Check Results | `pai:ListJobSanityCheckResults` | Get list of all compute health check results |\n\n### Access and Sharing Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Get Web Terminal | `pai:GetWebTerminal` | Get container Web terminal access link |\n| Get Sharing Token | `pai:GetToken` | Get job sharing token |\n\n## Resource-Level Authorization\n\nTo restrict permissions to specific workspace:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:CreateJob\",\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:UpdateJob\",\n        \"pai:StopJob\"\n      ],\n      \"Resource\": [\n        \"acs:pai:*:*:workspace/<workspace-id>\",\n        \"acs:pai:*:*:workspace/<workspace-id>/*\"\n      ]\n    }\n  ]\n}\n```\n\n## Permission Check Commands\n\nUse the following commands to check current user permissions:\n\n```bash\n# Check current configuration\naliyun configure list\n\n# Test job list permission\naliyun pai-dlc list-jobs --region cn-hangzhou --page-size 1 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\n# If Forbidden.RAM error is returned, insufficient permissions\n```\n\n## Common Errors\n\n| Error Code | Description | Solution |\n|------------|-------------|----------|\n| `Forbidden.RAM` | Insufficient RAM permissions | Contact administrator to add corresponding permissions |\n| `Forbidden.AccessDenied` | No access to this resource | Check resource-level authorization configuration |\n| `InvalidAccessKeyId.NotFound` | AccessKey does not exist | Check if AccessKey is correct |\n| `SignatureDoesNotMatch` | Signature mismatch | Check if AccessKeySecret is correct |\n\n## Best Practices\n\n1. **Principle of Least Privilege** — Only grant permissions users actually need\n2. **Use RAM Roles** — For tasks running on ECS instances, use ECS RAM Role instead of AK/SK\n3. **Regular Auditing** — Regularly check and clean up unnecessary permissions\n4. **Separate Read-Only and Read-Write** — Assign read-only policies to users who only need to view\n5. **Resource Isolation** — Use resource-level authorization to isolate tasks of different projects\n\n## Reference Links\n\n- [PAI RAM Permission Documentation](https://help.aliyun.com/zh/pai/user-guide/create-a-ram-user)\n- [RAM Policy Syntax](https://help.aliyun.com/zh/ram/user-guide/policy-syntax-and-structure)\n- [RAM Best Practices](https://help.aliyun.com/zh/ram/user-guide/ram-best-practices)\n\n---\n\n## Permissions by Operation Category (Resource Discovery)\n\nThe following table covers only the 7 AIWorkSpace resource discovery APIs (QuotaId (`--resource-id`) is manually provided by the user):\n\n| Operation | CLI Subcommand | RAM Action | Product | Lookup Purpose |\n|---|---|---|---|---|\n| List Workspaces | `aliyun aiworkspace list-workspaces` | `paiworkspace:ListWorkspaces` | AIWorkSpace | Obtain `--workspace-id` |\n| List Images | `aliyun aiworkspace list-images` | `paiimage:ListImages` | AIWorkSpace | Obtain candidates for `WorkerSpec.Image` |\n| Get Image Details | `aliyun aiworkspace get-image` | `paiimage:GetImage` | AIWorkSpace | Look up `ImageUri` |\n| List Datasets | `aliyun aiworkspace list-datasets` | `paidataset:ListDatasets` | AIWorkSpace | Obtain `DataSources[].DataSourceId` |\n| Get Dataset Details | `aliyun aiworkspace get-dataset` | `paidataset:GetDataset` | AIWorkSpace | Look up `Uri` / `SourceType` |\n| List Code Sources | `aliyun aiworkspace list-code-sources` | `paicodesource:ListCodeSources` | AIWorkSpace | Obtain `CodeSource.CodeSourceId` |\n| Get Code Source Details | `aliyun aiworkspace get-code-source` | `paicodesource:GetCodeSource` | AIWorkSpace | Look up `Uri` / `CodeBranch` / `CodeCommit` |\n\n**Authorization Tip**: These 7 Actions and PAI-DLC's `pai:*` Actions belong to different products, and both groups MUST appear simultaneously in the RAM sub-account policy. Do NOT abbreviate them as `aiworkspace:*`.\n\nFile v0.0.2:references/related-apis.md\n\n# PAI-DLC API & CLI Reference\n\n> **Single source of truth** for everything `aliyun pai-dlc <cmd> --help` and\n> `aliyun aiworkspace <cmd> --help` do **not** tell you: command index across\n> products, cross-product field contracts, status lifecycle, red lines,\n> error catalog, forbidden patterns.\n>\n> For parameter-level details (flags, types, defaults, enums) — always run\n> `--help` on the subcommand. This document never duplicates `--help` output.\n>\n> Every API-invoking call MUST include\n> `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`. Client-side\n> helpers (`version` / `configure` / `plugin` / `--help`) do not invoke remote\n> APIs and do not need the flag.\n\n---\n\n## 1. Command Index\n\n### 1.1 Client-Side Helpers (no API call)\n\n| CLI Command | Purpose |\n|-------------|---------|\n| `aliyun version` | Verify CLI ≥ 3.3.1 |\n| `aliyun configure list` | Inspect profiles (never echoes AK/SK) |\n| `aliyun configure set --auto-plugin-install true` | Enable auto plugin install |\n| `aliyun plugin list` / `install --names ...` / `update --name ...` | Plugin management |\n| `aliyun pai-dlc --help` / `aliyun aiworkspace --help` | Probe plugin presence |\n| `aliyun pai-dlc <subcommand> --help` | Authoritative parameter reference |\n\n### 1.2 PAI-DLC Job APIs (`pai-dlc` plugin, API 2020-12-03)\n\n| CLI | Action | One-liner |\n|-----|--------|-----------|\n| `create-job` | CreateJob | Submit a distributed training job |\n| `list-jobs` | ListJobs | List jobs with `--status` / `--workspace-id` filters |\n| `get-job` | GetJob | Full job detail (use `--need-detail` for advanced fields) |\n| `update-job` | UpdateJob | Mutate priority / accessibility / description / job-specs |\n| `stop-job` | StopJob | Stop a `Running` / `Queuing` job (high-risk) |\n| `get-pod-logs` | GetPodLogs | Container logs (always cap with `--max-lines`) |\n| `get-pod-events` | GetPodEvents | Pod-level Kubernetes events |\n| `get-job-events` | GetJobEvents | Job-level system events |\n| `list-job-sanity-check-results` / `get-job-sanity-check-result` | SanityCheck | GPU health-check results |\n| `list-ecs-specs` | ListEcsSpecs | Discover available ECS / Lingjun machine types |\n| `get-web-terminal` | GetWebTerminal | Web Terminal URL (Pod must be alive) |\n| `get-token` | GetToken | Read-only sharing token for jobs |\n\n### 1.3 AIWorkSpace Resource Discovery (`aiworkspace` plugin, API 2021-02-04)\n\n| CLI | Returns | Maps to CreateJob field |\n|-----|---------|-------------------------|\n| `list-workspaces` | `Workspaces[].WorkspaceId` | `--workspace-id` |\n| `list-image-labels` | label `Key=Value` pairs | input for `list-images --labels` |\n| `list-images` / `get-image` | `Images[].ImageUri` | `--job-specs[].Image` |\n| `list-datasets` / `get-dataset` | `Datasets[].DatasetId` | `--data-sources[].DataSourceId` |\n| `list-code-sources` / `get-code-source` | `CodeSources[].CodeSourceId` | `--code-source.CodeSourceId` |\n\n> **Quota (`--resource-id`)** is user-supplied — there is no CLI discovery\n> command for QuotaId.\n\n---\n\n## 2. Cross-Product Field Mapping (CreateJob ← AIWorkSpace)\n\nAuthoritative mapping from `create-job` fields back to their AIWorkSpace\ndiscovery API. `--help` cannot point you across products.\n\n| CreateJob field | Source API | Source field |\n|-----------------|------------|--------------|\n| `--workspace-id` | `aiworkspace list-workspaces` | `Workspaces[].WorkspaceId` |\n| `--job-specs[].Image` | `aiworkspace list-images` | `Images[].ImageUri` (verbatim) |\n| `--data-sources[].DataSourceId` | `aiworkspace list-datasets` | `Datasets[].DatasetId` |\n| `--code-source.CodeSourceId` | `aiworkspace list-code-sources` | `CodeSources[].CodeSourceId` |\n| `--resource-id` | (manual) | User-provided QuotaId |\n\n**Recommended discovery order:** `list-workspaces` → `list-image-labels` →\n`list-images` → `list-datasets` → `list-code-sources` → fill into `create-job`.\n\n---\n\n## 3. Job Status Lifecycle\n\n```\nCreating → Queuing → (Bidding) → EnvPreparing → SanityChecking\n        → Running → (Restarting) → Stopping → Succeeded / Failed / Stopped\n```\n\n- `Bidding` only appears for Spot jobs.\n- `SanityChecking` only appears when `Settings.EnableSanityCheck=true`.\n- `Restarting` is a transient state during fault recovery.\n\n> The full enum (14 values, e.g. including `SucceededReserving` /\n> `FailedReserving`) is documented by `aliyun pai-dlc list-jobs --help` under\n> `--status`. The diagram above shows the **operational flow**, not an\n> exhaustive enum.\n\n---\n\n## 4. CreateJob — Red Lines\n\n> ⚠ **Red Line 1: `EcsSpec` ⇄ `ResourceConfig`** — mutually exclusive within\n> a single TaskSpec. Use `EcsSpec` for public pay-as-you-go; `ResourceConfig`\n> (with CPU/Memory/GPU/GPUType) for dedicated quota (and pair with\n> `--resource-id`).\n\n> ⚠ **Red Line 2: Image URI source** — `--job-specs[].Image` MUST be a verbatim\n> `ImageUri` from `aiworkspace list-images`. Never invent, rewrite, or\n> substitute `Name` / `ImageId`.\n\n> ⚠ **Red Line 3: No ROA fallback** — if a plugin subcommand is unavailable,\n> install/upgrade the plugin (`aliyun plugin install --names ...` /\n> `aliyun plugin update --name ...`). Never construct generic ROA calls\n> (`--pathPattern` / `--method GET|POST|PUT|DELETE`).\n\n> ⚠ **Red Line 4: `--workspace-id` is always required** — `--help` marks it\n> optional, but the server silently falls back to the user's default\n> workspace. Always confirm with the user.\n\n---\n\n## 5. Common Errors\n\n| Code | Trigger | Fix |\n|------|---------|-----|\n| `NotFound` | Wrong `JobId` | Re-run the corresponding `list-*` command to confirm |\n| `InvalidParameter` | Format / type / enum violation | Re-check with `--help` |\n| `Forbidden.RAM` | Missing `pai:*` / `paiimage:*` etc. | See [ram-policies.md](ram-policies.md) |\n| `Throttling` | Rate limit | Reduce request frequency; add backoff |\n| `ServiceUnavailable` | Transient | Retry with exponential backoff |\n\n---\n\n## 6. Forbidden Patterns\n\n- ❌ `--pathPattern` / `--method GET|POST|PUT|DELETE` (ROA generic fallback) —\n  install/upgrade the proper plugin instead.\n- ❌ `aliyun pai-dlc list-images` / `list-workspaces` / `list-datasets` /\n  `list-code-sources` — these subcommands belong to **`aiworkspace`**,\n  not `pai-dlc`.\n- ❌ Reading or printing `ALIBABA_CLOUD_ACCESS_KEY_ID` / `_SECRET`; running\n  `aliyun configure set` with literal credential values.\n\nFile v0.0.2:references/verification-method.md\n\n# PAI-DLC Operation Verification Methods\n\nEnd-to-end and per-command verification scripts. These are **runnable\nflows**, not parameter docs — for flag-level details run\n`aliyun pai-dlc <cmd> --help`. The job status enum, common errors, and red\nlines live in [related-apis.md](related-apis.md) (single source of truth).\n\nEvery API call MUST include\n`--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`. Replace\n`<region>` / `<job-id>` / `<pod-id>` / `<workspace-id>` placeholders before\nrunning.\n\n---\n\n## 1. Per-Command Quick Verify\n\n### 1.1 Create Job\n\n```bash\nJOB_ID=$(aliyun pai-dlc create-job \\\n  --region <region> \\\n  --workspace-id <workspace-id> \\\n  --display-name \"verify-job\" \\\n  --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"<ImageUri>\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]' \\\n  --user-command \"python -c 'print(123)'\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query \"JobId\")\n```\n\n**Expect:** `JobId` matches `dlc[0-9a-z]+`; status shortly enters\n`Creating` / `Queuing` / `Running`.\n\n### 1.2 List / Get / Events / Logs / Metrics\n\n```bash\naliyun pai-dlc list-jobs --region <region> --status Running --page-size 10 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\naliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\naliyun pai-dlc get-pod-logs --region <region> --job-id <job-id> --pod-id <pod-id> \\\n  --max-lines 100 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\naliyun pai-dlc get-job-events --region <region> --job-id <job-id> \\\n  --max-events-num 50 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\naliyun pai-dlc get-pod-events --region <region> --job-id <job-id> --pod-id <pod-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n**Expect:** all return non-empty data once the job is past `EnvPreparing`.\nLogs contain stdout/stderr; events sorted by time.\n\n### 1.3 Update / Stop\n\n```bash\n# Priority update (pre-check status & quota first; see SKILL.md §7.8)\naliyun pai-dlc update-job --region <region> --job-id <job-id> --priority 5 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\n# Stop (HIGH-RISK — follow pre-check + user-confirmation protocol in SKILL.md §7.8)\naliyun pai-dlc stop-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n### 1.4 Health Check (only when `Settings.EnableSanityCheck=true`)\n\n```bash\naliyun pai-dlc list-job-sanity-check-results \\\n  --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\naliyun pai-dlc get-job-sanity-check-result \\\n  --region <region> --job-id <job-id> --sanity-check-number 1 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n### 1.5 Debug Helpers\n\n```bash\n# Verbose logging\naliyun pai-dlc <cmd> --region <region> --log-level=debug \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\n# Dry-run (no API call)\naliyun pai-dlc <cmd> --region <region> --cli-dry-run \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n---\n\n## 2. Resource Discovery → CreateJob (E2E)\n\nVerifies the full **discover → fill → create → verify → cleanup** workflow\nusing AIWorkSpace resource discovery. Mirrors the §7.6 flow in `SKILL.md`.\n\n### 2.1 Pre-flight\n\n```bash\naliyun aiworkspace --help >/dev/null 2>&1 \\\n  || aliyun plugin install --names aliyun-cli-aiworkspace\n```\n\n### 2.2 Discover Resources\n\n```bash\nWORKSPACE_ID=$(aliyun aiworkspace list-workspaces \\\n  --region <region> --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query 'Workspaces[0].WorkspaceId')\n\nIMAGE_URI=$(aliyun aiworkspace list-images \\\n  --region <region> --workspace-id $WORKSPACE_ID --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query 'Images[0].ImageUri')\n\nDATASET_ID=$(aliyun aiworkspace list-datasets \\\n  --region <region> --workspace-id $WORKSPACE_ID --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query 'Datasets[0].DatasetId')\n\nCODE_SOURCE_ID=$(aliyun aiworkspace list-code-sources \\\n  --region <region> --workspace-id $WORKSPACE_ID --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query 'CodeSources[0].CodeSourceId')\n```\n\n**Expect:** all four variables non-empty. Optional resources can be omitted\nin step 2.3 if absent.\n\n### 2.3 Create Job with Discovered Resources\n\n> ⚠ When passing `--resource-id` (dedicated quota), use `ResourceConfig` —\n> NOT `EcsSpec`. For pay-as-you-go, use `EcsSpec` and omit `--resource-id`.\n\n```bash\nJOB_SPECS=$(cat <<EOF\n[{\n  \"Type\": \"Worker\",\n  \"PodCount\": 1,\n  \"Image\": \"$IMAGE_URI\",\n  \"ResourceConfig\": {\"CPU\": \"4\", \"Memory\": \"16Gi\", \"GPU\": \"1\", \"SharedMemory\": \"8Gi\"}\n}]\nEOF\n)\n\nJOB_ID=$(aliyun pai-dlc create-job \\\n  --region <region> \\\n  --workspace-id $WORKSPACE_ID \\\n  --resource-id $QUOTA_ID \\\n  --display-name \"e2e-discovery-verify\" \\\n  --job-type PyTorchJob \\\n  --job-specs \"$JOB_SPECS\" \\\n  --data-sources \"[{\\\"DataSourceId\\\":\\\"$DATASET_ID\\\",\\\"MountPath\\\":\\\"/mnt/data\\\"}]\" \\\n  --code-source \"{\\\"CodeSourceId\\\":\\\"$CODE_SOURCE_ID\\\",\\\"MountPath\\\":\\\"/mnt/code\\\"}\" \\\n  --user-command \"python -c 'print(123)'\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query 'JobId')\n```\n\n### 2.4 Verify\n\n```bash\naliyun pai-dlc get-job --region <region> --job-id $JOB_ID \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID} \\\n  --cli-query '{Status:Status,WorkspaceId:WorkspaceId,ResourceId:ResourceId}'\n```\n\n**Expect:** `Status` ∈ `Creating` / `Queuing` / `EnvPreparing` / `Running` /\n`Succeeded`. `WorkspaceId` / `ResourceId` match discovery values.\n\n### 2.5 Discovery Checklist\n\n- [ ] `aliyun aiworkspace list-workspaces --help` returns exit 0\n- [ ] All four discovery variables non-empty\n- [ ] §2.3 returns valid `JobId` (`dlc[0-9a-z]+`)\n- [ ] §2.4 status in expected enum\n- [ ] No ROA calls anywhere in the flow\n- [ ] `EcsSpec` ⇄ `ResourceConfig` mutual exclusion respected\n\nFile v0.0.2:skill-card.md\n\n## Description:\n\nAlibaba Cloud PAI-DLC job management skill for distributed training job CRUD, monitoring logs and events, and GPU sanity checks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sdk-team](https://clawhub.ai/user/sdk-team)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and ML platform engineers use this skill to manage Alibaba Cloud PAI-DLC distributed training jobs, inspect job state, retrieve logs and events, discover required AIWorkSpace resources, and verify GPU health.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can guide high-impact cloud job operations, including stopping jobs, opening web terminals, and generating sharing tokens.\n\nMitigation: Require explicit user approval before high-impact operations, present current job status before stop actions, and prefer read-only or least-privilege RAM permissions when full job management is not required.\n\nRisk: The skill relies on the user's configured Aliyun profile, which may have broad access to Alibaba Cloud resources.\n\nMitigation: Configure credentials outside the agent session, avoid pasting secrets into commands, and use short-lived credentials or scoped roles where available.\n\nRisk: PAI-DLC create operations do not expose a client-token, so retries after network failures can create duplicate jobs.\n\nMitigation: Before reissuing a failed create request, list jobs by display name to detect a previously committed job.\n\n## Reference(s):\n\n- [PAI-DLC API and CLI Reference](references/related-apis.md)\n- [PAI-DLC RAM Permission Policies](references/ram-policies.md)\n- [PAI-DLC Operation Verification Methods](references/verification-method.md)\n- [Job Lifecycle Management](references/job-management.md)\n- [Acceptance Criteria](references/acceptance-criteria.md)\n- [Aliyun CLI Installation and Configuration Guide](references/cli-installation-guide.md)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline bash code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands target Aliyun CLI workflows and should preserve the documented session User-Agent, timeout, confirmation, and least-privilege guidance.]\n\n## Skill Version(s):\n\n0.0.2 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.0.1: 9 files, 27069 bytes\n\nFiles: references/acceptance-criteria.md (12159b), references/cli-installation-guide.md (12441b), references/job-management.md (4188b), references/ram-policies.md (9604b), references/related-apis.md (6375b), references/verification-method.md (6211b), skill-card.md (2787b), SKILL.md (18260b), _meta.json (143b)\n\nFile v0.0.1:SKILL.md\n\n---\nname: alibabacloud-pai-dlc-job\ndescription: |\n  Alibaba Cloud PAI-DLC (Deep Learning Containers) job management skill.\n  Covers: distributed training job CRUD, monitoring (logs and events), and\n  GPU sanity check.\n  Triggers: \"DLC\", \"PAI-DLC\", \"create-job\", \"list-jobs\", \"get-job\",\n  \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\",\n  \"get-pod-events\", \"list-job-sanity-check-results\".\n---\n\n# PAI-DLC Deep Learning Job Management\n\nManage deep learning training jobs on Alibaba Cloud PAI-DLC (Platform for AI - Deep\nLearning Containers) service.\n\n## Scenario Description\n\nPAI-DLC is a distributed training service provided by Alibaba Cloud's AI Platform PAI,\nsupporting:\n\n- **Job Creation and Execution** — Create distributed training jobs for TensorFlow,\n  PyTorch, XGBoost, and other frameworks\n- **Job Monitoring** — Get job status, logs, events, and monitoring metrics\n- **Compute Health Check** — Check health status of GPU and other compute devices\n- **Job Management** — Update and stop jobs\n\n**Architecture**: PAI Workspace + DLC Job + Computing Resources (ECS public pay-as-you-go\nor Lingjun dedicated quota) + AIWorkSpace catalog (images / datasets / code sources /\nquotas / workspaces).\n\n## Installation Requirements\n\n> **Pre-check: Aliyun CLI >= 3.3.1 required**\n> Run `aliyun version` to verify version >= 3.3.1. If not installed or version is too low,\n> see [references/cli-installation-guide.md](references/cli-installation-guide.md) for\n> installation instructions.\n> Then [Required] run `aliyun configure set --auto-plugin-install true` to enable\n> automatic plugin installation.\n\n> **Note on `--user-agent`:** Every API-invoking `aliyun` command in this skill MUST\n> include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job`. Client-side helpers\n> (`aliyun version`, `aliyun configure ...`, `aliyun plugin ...`,\n> `aliyun <product> --help`) do not invoke remote APIs and therefore do not require\n> the flag.\n\n> **Network timeout & retry (rule `--help` doesn't enforce):** `aliyun` CLI\n> defaults to 10s connect / 10s read with no retry. For long-running flows\n> (large list, slow region) explicitly raise via global flags\n> `--connect-timeout 15 --read-timeout 30 --retry-count 2`. Never rely on the\n> default for user-confirmed high-risk calls (`stop-job` / `delete-*`).\n\n```bash\naliyun version\naliyun configure set --auto-plugin-install true\naliyun pai-dlc --help\naliyun aiworkspace --help >/dev/null 2>&1 || aliyun plugin install --names aliyun-cli-aiworkspace\naliyun plugin update\n\naliyun configure ai-mode enable\naliyun configure ai-mode set-user-agent --user-agent \"AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\"\n# After session: aliyun configure ai-mode disable\n```\n\n## Environment Variables\n\nThis skill does not require any custom environment variables. Credentials are handled\nby the Alibaba Cloud CLI configuration (see Authentication below). Optionally:\n\n| Variable | Required | Purpose |\n|----------|----------|---------|\n| `ALIBABA_CLOUD_PROFILE` | Optional | Selects a non-default `aliyun configure` profile |\n| `ALIBABA_CLOUD_REGION_ID` | Optional | Default region when `--region` is omitted (still recommended to pass `--region` explicitly) |\n\nDo NOT export `ALIBABA_CLOUD_ACCESS_KEY_ID` / `ALIBABA_CLOUD_ACCESS_KEY_SECRET` from\nwithin this session; configure them outside (`aliyun configure` or shell profile).\n\n## Authentication Configuration\n\n> **Pre-check: Alibaba Cloud Credentials Required**\n>\n> **Security Rules:**\n> - **NEVER** read, echo, or print AK/SK values (e.g., `echo $ALIBABA_CLOUD_ACCESS_KEY_ID` is FORBIDDEN)\n> - **NEVER** ask the user to input AK/SK directly in the conversation or command line\n> - **NEVER** use `aliyun configure set` with literal credential values\n> - **ONLY** use `aliyun configure list` to check credential status\n>\n> ```bash\n> aliyun configure list\n> ```\n> Check the output for a valid profile (AK, STS, or OAuth identity).\n>\n> **If no valid profile exists, STOP here.**\n> 1. Obtain credentials from [Alibaba Cloud Console](https://ram.console.aliyun.com/manage/ak)\n> 2. Configure credentials **outside of this session** (via `aliyun configure` in terminal\n>    or environment variables in shell profile)\n> 3. Return and re-run after `aliyun configure list` shows a valid profile\n\n## RAM Permissions\n\n> **[MUST] Permission Failure Handling:** When any command or API call fails due to\n> permission errors at any point during execution, follow this process:\n> 1. Read `references/ram-policies.md` to get the full list of permissions required by this SKILL\n> 2. Use `ram-permission-diagnose` skill to guide the user through requesting the necessary permissions\n> 3. Pause and wait until the user confirms that the required permissions have been granted\n\nFor detailed permission list, see [references/ram-policies.md](references/ram-policies.md).\n\n**Required Permissions Overview:**\n\n| Operation | Required Permission |\n|-----------|---------------------|\n| Create Job | `pai:CreateJob` |\n| List Jobs | `pai:ListJobs` |\n| Get Job Details | `pai:GetJob` |\n| Get Pod Logs | `pai:GetPodLogs` |\n| Get Job Events | `pai:GetJobEvents` |\n| Update Job | `pai:UpdateJob` |\n| Stop Job | `pai:StopJob` |\n| AIWorkSpace Resource Discovery | `paiworkspace:ListWorkspaces` / `paiimage:ListImages,GetImage` / `paidataset:ListDatasets,GetDataset` / `paicodesource:ListCodeSources,GetCodeSource` |\n\n> **AIWorkSpace authorization note:** `Image` / `DataSourceId` / `CodeSourceId` /\n> `WorkspaceId` field values for `create-job` come from the\n> AIWorkSpace resource-discovery APIs. `--resource-id` (QuotaId) is manually provided by the user.\n> RAM users MUST hold the corresponding\n> AIWorkSpace-namespaced permissions listed above (do not abbreviate as `aiworkspace:*`).\n\n## Parameter Confirmation\n\n> **Authoritative parameter reference is `aliyun pai-dlc <cmd> --help`** (must-read\n> before every call). This skill only documents what `--help` does **not** tell\n> you: cross-field rules, cross-product dependencies, hidden behaviors, business\n> labels, and reject patterns. Whenever a rule below contradicts `--help`, the\n> reason is stated inline.\n>\n> **Confirm before call:** all user-customizable values (region, names, CIDR,\n> specs, etc.) MUST be confirmed with the user — never assume defaults.\n\n### Hard rules that override `--help`\n\n| Rule | Why this skill overrides `--help` |\n|------|-----------------------------------|\n| `--workspace-id` is **always required** | `--help` marks it optional, but server silently falls back to the user's **default workspace** if omitted → job often lands in the wrong workspace. Always confirm with user. |\n| `--job-specs[].Image` MUST be a verbatim `ImageUri` from `aiworkspace list-images` | Cross-product contract; `--help` only describes the field type. See §7.6 red line. |\n| `--data-sources[].DataSourceId` from `aiworkspace list-datasets`; `--code-source.CodeSourceId` from `list-code-sources` | Cross-product discovery; `--help` cannot point you to the source product. |\n| `--resource-id` (QuotaId) is **manually supplied** | No CLI discovery step. |\n\n### Cross-field mutual exclusion (`--help` cannot catch these)\n\n- `EcsSpec` ⇄ `ResourceConfig` — within a single TaskSpec, pick exactly one.\n- `Uri` ⇄ `DataSourceId` — within `--data-sources[]`.\n- `Uri` ⇄ `CodeSourceId` — within `--code-source`.\n\n### `--job-type` — Worker `Type` hints per framework\n\n`--help` lists the 9 legal enum values verbatim. What `--help` doesn't tell you\nis which `JobSpecs[].Type` roles each framework expects:\n\n| `--job-type` | Valid `JobSpecs[].Type` roles |\n|---|---|\n| `TFJob` | `Chief` / `PS` / `Worker` / `Evaluator` / `GraphLearn` |\n| `PyTorchJob` | `Worker` (+ optional `Master`, auto-promoted) |\n| `MPIJob` | `Worker` + `Master` |\n| `XGBoostJob` / `OneFlowJob` / `ElasticBatchJob` | `Worker` + optional `Master` |\n| `RayJob` | `Worker` |\n| `SlurmJob` / `DataJuicerJob` | framework-specific roles |\n\n> **Case-sensitive, no aliases.** `tensorflow`, `pytorch`, `tf-job`, `Pytorch`,\n> `PYTORCH_JOB`, `Custom`, `CustomJob` — all rejected.\n>\n> **No `Custom` enum.** For single-container custom workloads, map to\n> `PyTorchJob` (most permissive role set).\n>\n> **Locked after create:** `JobType` cannot be changed via `update-job`.\n\nFull field reference: see [references/related-apis.md](references/related-apis.md).\n\n## Core Workflows\n\n### 7.1 Resource Selection Decision Guide\n\nBefore calling `create-job`, determine the resource path:\n\n- **Public pay-as-you-go** → Use `EcsSpec` in TaskSpec; do NOT pass `--resource-id`.\n  - Use cases: quick start, testing, no dedicated quota.\n  - Example: `\"EcsSpec\": \"ecs.gn6i-c4g1.xlarge\"`\n- **Dedicated quota** (Lingjun / enterprise quota) → Use `ResourceConfig` in TaskSpec\n  AND pass `--resource-id <QuotaId>`.\n  - Use cases: dedicated resource group, Lingjun smart compute, Spot bidding.\n  - Example: `--resource-id quotaXXX` + `\"ResourceConfig\": {\"CPU\": \"4\", \"Memory\": \"8Gi\", \"GPU\": \"1\"}`\n\n> **EcsSpec and ResourceConfig MUST NOT both appear in the same TaskSpec.**\n\n> **Also required before `create-job`:** `--job-specs[].Image` MUST come from\n> `aliyun aiworkspace list-images`; `--data-sources[].DataSourceId` from\n> `list-datasets`; `--code-source.CodeSourceId` from `list-code-sources`.\n> Full discovery flow → see §7.6.\n\n**Distributed architecture choices:**\n\n| Topology | `JobSpecs` shape |\n|---|---|\n| Single-node | One `Worker` only |\n| TFJob PS-Worker | Both `PS` (CPU) and `Worker` (GPU) roles |\n| PyTorch multi-node | One `Worker` with `PodCount > 1` |\n\nOptional flags: `--enable-gang-scheduling true` (all-or-nothing scheduling),\n`Settings.EnableRDMA: true` (high-performance network for multi-node GPU),\n`Settings.EnableSanityCheck: true` (GPU health verification).\n\n> **All commands below require `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job`** (omitted in snippets for brevity — see Installation Requirements).\n\n### 7.2 Create Training Job\n\nMinimal single-node PyTorch job (public pay-as-you-go) parameter combination:\n\n```bash\naliyun pai-dlc create-job --region <region> --workspace-id <ws-id> \\\n  --display-name \"my-pytorch-training\" --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"<ImageUri>\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]' \\\n  --user-command 'python train.py' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\nMulti-node / Spot / RDMA / data mounting — use `create-job --help`.\nSubsequent snippets omit `--user-agent` for brevity — always include it.\n\n### 7.3 List / Get Job\n\nUse `--cli-query` to project specific fields (essential for log/event flows):\n\n```bash\naliyun pai-dlc list-jobs --region <region> --status Running\naliyun pai-dlc get-job  --region <region> --job-id <id>\naliyun pai-dlc get-job  --region <region> --job-id <id> --cli-query \"Pods[0].PodId\"\n```\n\n### 7.4 Logs and Events\n\n> **Always cap return size:** `--max-lines 100` (logs), `--max-events-num 50` (events).\n\nGet `PodId` first, then query logs/events:\n\n```bash\nPOD_ID=$(aliyun pai-dlc get-job --region <r> --job-id <id> --cli-query \"Pods[0].PodId\")\naliyun pai-dlc get-pod-logs    --region <r> --job-id <id> --pod-id $POD_ID --max-lines 100\naliyun pai-dlc get-pod-events  --region <r> --job-id <id> --pod-id $POD_ID --max-events-num 20\naliyun pai-dlc get-job-events  --region <r> --job-id <id> --max-events-num 50\n```\n\n**Diagnosis order:** `get-job` (status) → `get-job-events` → `get-pod-logs` → `get-pod-events`.\n\n### 7.5 Compute Health Check\n\n```bash\naliyun pai-dlc list-job-sanity-check-results --region <r> --job-id <id>\naliyun pai-dlc get-job-sanity-check-result   --region <r> --job-id <id> --sanity-check-number 1\n```\n\n### 7.6 Pre-Create Resource Discovery (AIWorkSpace)\n\n**Discovery flow:** `list-workspaces` → `list-image-labels` →\n`list-images` → `list-datasets` → `list-code-sources` → `pai-dlc create-job`.\n\n> **Quota (`--resource-id`):** user-supplied. No CLI discovery step.\n\n```bash\naliyun aiworkspace list-workspaces     --region <r>                        # → --workspace-id\naliyun aiworkspace list-image-labels   --region <r>                        # → valid label Key=Value pairs\naliyun aiworkspace list-images         --region <r> --labels \"K1=V1,K2=V2\" # → --job-specs[].Image (use ImageUri verbatim)\naliyun aiworkspace list-datasets       --region <r> --workspace-id <ws>    # → DataSources[].DataSourceId\naliyun aiworkspace list-code-sources   --region <r> --workspace-id <ws>    # → CodeSource.CodeSourceId\n```\n\n> **Labels rules** (not in `--help`): comma-separated `Key=Value` pairs, no\n> JSON / no spaces. Values MUST come from `list-image-labels` — never invent.\n> Do **not** pass `--workspace-id` to `list-images` when discovering **official\n> public images** (they are global). Pass `--workspace-id` only when filtering\n> **custom / private images** scoped to a specific workspace.\n>\n> **RED LINE:** `--job-specs[].Image` MUST be a verbatim `ImageUri` (not\n> `Name` / `ImageId`).\n>\n\nField-mapping, full parameters, and error codes: see\n[references/related-apis.md](references/related-apis.md) and\n[references/verification-method.md](references/verification-method.md).\n\n### 7.7 Job Lifecycle Management (Stop / Update / Web Terminal)\n\nStop is a **high-risk** operation. Before proceeding, query status with\n`get-job`, present the result to the user, and require explicit confirmation.\n\n> **Rules `--help` doesn't tell you (`update-job` silent-no-op family):**\n>\n> - **Stop Job** applies only when status is `Running` or `Queuing`.\n> - **`update-job --priority`** takes effect **only** when (a) the job uses\n>   **quota resources** (`--resource-id`) AND (b) status is `Creating`,\n>   `Queuing`, or `EnvPreparing`. Once the job enters `Running` or later,\n>   priority **cannot be modified** — the API returns `200 OK` but the change\n>   is **silently NOT applied**. Always pre-check status with `get-job`.\n> - **`update-job --accessibility`** takes effect immediately in any status.\n> - **`update-job` does NOT expose `--display-name`** (`--help` lists only\n>   `--job-id`, `--accessibility`, `--description`, `--job-specs`, `--priority`).\n>   To rename a job, recreate it.\n\nFor the full pre-check + confirmation + execution templates, plus the\n`update-job` low-risk path and `get-web-terminal` / `get-token` sharing\ncommands, see [references/job-management.md](references/job-management.md).\n\n### 7.8 Ecs Spec Discovery\n\nDiscover available instance types; the returned `EcsSpec` value goes\nverbatim into `--job-specs[].EcsSpec`.\n\n```bash\naliyun pai-dlc list-ecs-specs --region <r> --accelerator-type GPU --resource-type ECS --page-size 20\n# Lingjun dedicated: --quota-id <id> (whitelisted users only)\n```\n\n> **`list-ecs-specs` does not support `--sort-by`** — even values shown as\n> valid in `--help` (e.g. `CPU` / `GPU` / `Memory` / `GmtCreateTime`) are\n> rejected by the server. Always omit `--sort-by` here and sort the JSON\n> output client-side with `jq` — e.g.\n> `... | jq '.EcsSpecs | sort_by(-.AcceleratorNumber)'`.\n\n## Success Verification Method\n\nFor step-by-step end-to-end verification scripts (resource discovery →\nCreateJob → log query → cleanup), see\n[references/verification-method.md](references/verification-method.md).\n\n**Quick verification:**\n\n- `get-job` → Status should be `Creating` / `Queuing` / `Running` shortly after\n  `create-job` returns.\n- `list-jobs --status Running` → Should return the freshly created Job until it\n  finishes or is stopped.\n- `get-pod-logs` → Should return non-empty log content once the Pod is past\n  `EnvPreparing`.\n\n## Command Tables\n\nThe full command index (5 categories × ~40 commands, with plugin\nattribution) is consolidated in\n[references/related-apis.md](references/related-apis.md) §1.\n\n## Best Practices\n\n> Items below are **decision rules** and **operational habits** — not parameter\n> values (those live in `--help`).\n\n1. **Job naming** — use meaningful, sortable names: `project-model-date`\n   (e.g. `resnet50-imagenet-20260320`). Recreate (not `update-job`) is the\n   only way to rename.\n2. **Resource sizing** — pick GPU type / count by model & dataset size. Verify\n   availability with `list-ecs-specs --accelerator-type GPU` **before** picking\n   `EcsSpec` (see §7.8).\n3. **Diagnose early** — follow the order `get-job` → `get-job-events` →\n   `get-pod-logs` → `get-pod-events`. Cap responses (`--max-lines 100`,\n   `--max-events-num 50`) to keep agent context lean.\n4. **Priority adjustment** — prefer setting `--priority` at `create-job` time.\n   Post-creation `update-job --priority` only works for quota jobs in\n   `Creating` / `Queuing` / `EnvPreparing` phase (§7.7); once `Running`,\n   priority cannot be modified.\n5. **Cost control** — use `--job-max-running-time-minutes` as an auto-stop guard\n   for every long-running experiment. Spot via `SpotSpec` reduces cost at the\n   risk of preemption.\n6. **Health check** — enable `Settings.EnableSanityCheck: true` for GPU\n   training to catch faulty devices before training starts.\n7. **Resource cleanup** — `stop-job` on completed jobs to free quota.\n8. **Idempotency on writes** — PAI-DLC `create-*` APIs do **NOT** expose\n   `--client-token` (verified via `aliyun pai-dlc create-job --help`). Network\n   retries can therefore create duplicate Jobs. Mitigation: before re-issuing\n   a failed `create-*`, run `list-jobs --display-name <name>` to detect a\n   half-committed prior attempt.\n\n## Reference Links\n\n| Reference Document | Description |\n|--------------------|-------------|\n| [references/related-apis.md](references/related-apis.md) | Command index, cross-product field map, lifecycle, red lines, error catalog |\n| [references/ram-policies.md](references/ram-policies.md) | RAM permission policy details |\n| [references/verification-method.md](references/verification-method.md) | End-to-end verification scripts |\n| [references/job-management.md](references/job-management.md) | High-risk Stop/Delete/Update flow + Web Terminal |\n| [references/acceptance-criteria.md](references/acceptance-criteria.md) | Skill testing acceptance criteria |\n| [references/cli-installation-guide.md](references/cli-installation-guide.md) | CLI installation guide |\n\nFile v0.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-pai-dlc-job\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1780028325196\n}\n\nFile v0.0.1:references/acceptance-criteria.md\n\n# Acceptance Criteria: alibabacloud-pai-dlc-job\n\n**Scenario**: PAI-DLC Deep Learning Job Management\n**Purpose**: Skill Testing Acceptance Criteria\n\n> **Note on snippets in this file:** Sections 1-3 below show product names,\n> command names, and parameter names as **pattern placeholders** (e.g.,\n> `aliyun pai-dlc <command>`). These are fragments for mismatch detection,\n> not complete executable commands. The Section 4 \"User-Agent\" rule (and the\n> SKILL.md core workflow) require every API-invoking command to end with\n> `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job`; full executable examples carry it.\n\n---\n\n# Correct CLI Command Patterns\n\n## 1. Product — Verify Product Name Exists\n\nCORRECT\n```bash\naliyun pai-dlc <command>\n```\n\nINCORRECT\n```bash\naliyun pai <command>        # Error: product name should be pai-dlc\naliyun dlc <command>        # Error: product name should be pai-dlc\naliyun PAI-DLC <command>    # Error: case-sensitive, should use lowercase\n```\n\n## 2. Command — Verify Command Name Format\n\nCORRECT (Plugin mode, lowercase with hyphens)\n```bash\naliyun pai-dlc create-job\naliyun pai-dlc list-jobs\naliyun pai-dlc get-job\naliyun pai-dlc get-pod-logs\naliyun pai-dlc list-ecs-specs\naliyun pai-dlc get-web-terminal\naliyun pai-dlc stop-job\naliyun pai-dlc update-job\naliyun pai-dlc get-token\naliyun pai-dlc get-job-events\naliyun pai-dlc get-pod-events\naliyun pai-dlc get-job-sanity-check-result\naliyun pai-dlc list-job-sanity-check-results\n```\n\nINCORRECT (Traditional API format)\n```bash\naliyun pai-dlc CreateJob       # Error: should use create-job\naliyun pai-dlc ListJobs        # Error: should use list-jobs\naliyun pai-dlc GetJob          # Error: should use get-job\naliyun pai-dlc GetPodLogs      # Error: should use get-pod-logs\n```\n\n## 3. Parameters — Verify Parameter Name Format\n\nCORRECT (Lowercase with hyphens)\n```bash\n--job-id\n--pod-id\n--display-name\n--job-type\n--job-specs\n--user-command\n--workspace-id\n--resource-id\n--page-number\n--page-size\n--start-time\n--end-time\n--max-lines\n--user-agent\n```\n\nINCORRECT (CamelCase or underscore)\n```bash\n--JobId            # Error: should use --job-id\n--jobId            # Error: should use --job-id\n--job_id           # Error: should use --job-id\n--displayName      # Error: should use --display-name\n--DisplayName      # Error: should use --display-name\n```\n\n## 4. User-Agent — Must Include Identifier\n\nCORRECT\n```bash\naliyun pai-dlc list-jobs --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\nINCORRECT\n```bash\naliyun pai-dlc list-jobs --region cn-hangzhou   # Error: missing --user-agent\n```\n\n## 5. JobSpecs Format — Verify JSON Structure\n\nCORRECT - Method 1: EcsSpec (Public Resources)\n```bash\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch:1.12\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]'\n```\n\nCORRECT - Method 2: ResourceConfig (Dedicated Resource Group)\n```bash\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch:1.12\",\"ResourceConfig\":{\"CPU\":\"4\",\"Memory\":\"16Gi\",\"GPU\":\"1\"}}]'\n```\n\nINCORRECT\n```bash\n# Error: Not a valid JSON array\n--job-specs '{\"Type\":\"Worker\"}'\n\n# Error: Missing required fields\n--job-specs '[{\"Type\":\"Worker\"}]'\n\n# Error: Incorrect field name case\n--job-specs '[{\"type\":\"Worker\",\"podCount\":1}]'\n\n# Error: EcsSpec and ResourceConfig set simultaneously (mutually exclusive!)\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"...\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\",\"ResourceConfig\":{\"CPU\":\"4\"}}]'\n```\n\n## 6. Job Status — Verify Case & Spelling (NOT an exhaustive enum)\n\n> **Authoritative enum source:** `aliyun pai-dlc list-jobs --help`. This section\n> only verifies case-sensitivity and spelling conventions — do NOT treat the\n> samples below as the complete list of legal `--status` values.\n\nCORRECT (representative samples — server accepts more, e.g. `Bidding`,\n`EnvPreparing`, `SanityChecking`, `SucceededReserving`, `FailedReserving`)\n```bash\n--status Creating\n--status Running\n--status Succeeded\n--status Failed\n```\n\nINCORRECT\n```bash\n--status creating     # Error: first letter should be uppercase\n--status RUNNING      # Error: should use Running\n--status success      # Error: should use Succeeded\n```\n\n## 7. Job Type — Verify Job Types\n\nCORRECT\n```bash\n--job-type TFJob\n--job-type PyTorchJob\n--job-type XGBoostJob\n--job-type OneFlowJob\n--job-type ElasticBatchJob\n```\n\nINCORRECT\n```bash\n--job-type tensorflow    # Error: should use TFJob\n--job-type pytorch       # Error: should use PyTorchJob\n--job-type tf-job        # Error: should use TFJob\n```\n\n---\n\n# Credential Patterns\n\n## 1. Credential Verification — Must Use Secure Method\n\nCORRECT\n```bash\n# Only check configuration status\naliyun configure list\n```\n\nINCORRECT\n```bash\n# Error: Prohibited from printing credential values\necho $ALIBABA_CLOUD_ACCESS_KEY_ID\necho $ALIBABA_CLOUD_ACCESS_KEY_SECRET\n\n# Error: Prohibited from using plaintext credentials in command line\naliyun configure set --access-key-id LTAI5tXXXX --access-key-secret 8dXXXX\n```\n\n---\n\n# Complete Command Examples\n\n## Create Job\n\nCORRECT - EcsSpec (Public Resources)\n```bash\naliyun pai-dlc create-job \\\n  --region cn-hangzhou \\\n  --display-name \"my-training-job\" \\\n  --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch-training:1.12-gpu-py38-cu113-ubuntu20.04\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]' \\\n  --user-command \"python train.py\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\nCORRECT - ResourceConfig (Dedicated Resource Group)\n```bash\naliyun pai-dlc create-job \\\n  --region cn-hangzhou \\\n  --resource-id <resource-group-id> \\\n  --display-name \"my-training-job\" \\\n  --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch-training:1.12-gpu-py38-cu113-ubuntu20.04\",\"ResourceConfig\":{\"CPU\":\"4\",\"Memory\":\"16Gi\",\"GPU\":\"1\",\"GPUType\":\"NVIDIA-V100\"}}]' \\\n  --user-command \"python train.py\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n## List Jobs\n\nCORRECT\n```bash\naliyun pai-dlc list-jobs \\\n  --region cn-hangzhou \\\n  --status Running \\\n  --page-number 1 \\\n  --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n## Get Logs\n\nCORRECT\n```bash\naliyun pai-dlc get-pod-logs \\\n  --region cn-hangzhou \\\n  --job-id dlc12345678 \\\n  --pod-id dlc12345678-worker-0 \\\n  --max-lines 500 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n## Stop Job\n\nCORRECT\n```bash\n# Stop job\naliyun pai-dlc stop-job \\\n  --region cn-hangzhou \\\n  --job-id dlc12345678 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n---\n\n# Testing Checklist\n\n- [ ] All commands use plugin mode format (lowercase with hyphens)\n- [ ] All commands include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job`\n- [ ] No hardcoded user-specific parameters (RegionId, JobId, etc. need user confirmation)\n- [ ] Credential operations only use `aliyun configure list` for checking\n- [ ] JobSpecs use correct JSON array format\n- [ ] Enum values use correct case\n- [ ] All required parameters provided\n\n---\n\n# AIWorkSpace Resource Discovery Command Standards\n\nThis section covers the 8 AIWorkSpace 2021-02-04 query APIs needed before creating a DLC job. All commands MUST be invoked through the `aliyun-cli-aiworkspace` plugin, and subcommands MUST use the lowercase + hyphen format.\n\n## 8. AIWorkSpace Plugin Query Commands — Verify Subcommand Spelling\n\nCORRECT (lowercase + hyphen subcommands exposed by the plugin)\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --page-number 1 --page-size 20\naliyun aiworkspace list-images --region cn-hangzhou --workspace-id <WORKSPACE_ID>\naliyun aiworkspace get-image --region cn-hangzhou --image-id <IMAGE_ID>\naliyun aiworkspace list-datasets --region cn-hangzhou --workspace-id <WORKSPACE_ID>\naliyun aiworkspace get-dataset --region cn-hangzhou --dataset-id <DATASET_ID>\naliyun aiworkspace list-code-sources --region cn-hangzhou --workspace-id <WORKSPACE_ID>\naliyun aiworkspace get-code-source --region cn-hangzhou --code-source-id <CODE_SOURCE_ID>\n```\n\nINCORRECT — ROA Generic Fallback Invocation (Red Line, Forbidden)\n```bash\n# Forbidden: invoking with the HTTP method + path-pattern ROA generic form\naliyun aiworkspace ListImages --version 2021-02-04 --method GET --pathPattern /api/v1/images --header Content-Type=application/json\n\n# Forbidden: the same ROA fallback is also disallowed on the PAI-DLC side\naliyun pai-dlc CreateJob --version 2020-12-30 --method POST --pathPattern /api/v1/jobs --body '{...}'\n```\n\nINCORRECT — Wrong Product Name\n```bash\n# Error: resource discovery APIs belong to the aiworkspace product, not pai-dlc\naliyun pai-dlc list-images --workspace-id <id>\naliyun pai-dlc list-datasets --workspace-id <id>\naliyun pai-dlc list-workspaces\n```\n\nINCORRECT — Does Not Conform to lowercase + hyphen Convention\n```bash\n# Error: missing hyphen\naliyun aiworkspace listimages --workspace-id <id>\naliyun aiworkspace listdatasets --workspace-id <id>\n\n# Error: using camelCase / PascalCase / underscore naming\naliyun aiworkspace ListImages --workspace-id <id>\naliyun aiworkspace List-Images --workspace-id <id>\naliyun aiworkspace list_images --workspace-id <id>\n```\n\n## 9. AIWorkSpace Command Parameters — Use kebab-case\n\nCORRECT\n```bash\n--workspace-id\n--image-id\n--dataset-id\n--code-source-id\n--page-number\n--page-size\n--workspace-ids       # list-workspaces only, multiple IDs separated by commas\n--display-name        # filter parameter for list-code-sources\n--data-source-types   # filter parameter for list-datasets (NAS / OSS)\n```\n\nINCORRECT\n```bash\n--WorkspaceId            # Error: should use --workspace-id\n--imageId                # Error: should use --image-id\n--code_source_id         # Error: should use --code-source-id\n```\n\n## 10. Resource Discovery -> CreateJob Value Mapping\n\nCORRECT — Look up first, then construct; use plugin return values as CreateJob parameters\n```bash\n# Look up WorkspaceId\nWORKSPACE_ID=$(aliyun aiworkspace list-workspaces --region cn-hangzhou \\\n  --cli-query 'Workspaces[0].WorkspaceId')\n\n# QuotaId (`--resource-id`) is manually provided by the user\n\n# Look up ImageUri\nIMAGE_URI=$(aliyun aiworkspace list-images --region cn-hangzhou --workspace-id $WORKSPACE_ID \\\n  --cli-query 'Images[0].ImageUri')\n```\n\nINCORRECT — Querying ImageUri from the pai-dlc product (wrong product)\n```bash\n# Do not query images under the pai-dlc product; ImageUri can only come from AIWorkSpace.ListImages\naliyun pai-dlc list-images --workspace-id $WORKSPACE_ID\n```\n\n---\n\n# Red Line: ROA Generic Fallback Invocations Are Forbidden\n\n> **Per the user's decision for this task**: Within this skill, using the HTTP method + path-pattern ROA generic fallback invocation is strictly forbidden.\n\n## Scope\n\nThis red line applies to all of the following:\n\n- The 7 AIWorkSpace resource discovery APIs (`ListImages` / `GetImage` / `ListDatasets` / `GetDataset` / `ListCodeSources` / `GetCodeSource` / `ListWorkspaces`). `--resource-id` (QuotaId) is manually provided by the user.\n- All PAI-DLC job APIs (`CreateJob` / `ListJobs` / ...).\n\n## Violation Examples (Must Never Appear in Correct Examples)\n\n```bash\n# Using the ROA generic form to assemble any AIWorkSpace / PAI-DLC API\naliyun aiworkspace ListImages --version 2021-02-04 --method GET --pathPattern /api/v1/images\naliyun aiworkspace GetDataset --version 2021-02-04 --method GET --pathPattern /api/v1/datasets/{DatasetId}\naliyun pai-dlc CreateJob --version 2020-12-30 --method POST --pathPattern /api/v1/jobs --body '{...}'\n```\n\n## Correct Approach\n\n- The skill MUST rely solely on the lowercase + hyphen subcommands exposed by the plugin.\n- If a particular plugin subcommand is unavailable (`unknown command`), run `aliyun plugin update --name aliyun-cli-pai-dlc` or `aliyun plugin install --names aliyun-cli-aiworkspace` to reinstall/upgrade the plugin. If it remains unavailable, stop and ask the user to intervene; **do NOT construct ROA invocations on your own**.\n\nFile v0.0.1:references/cli-installation-guide.md\n\n# Aliyun CLI Installation & Configuration Guide\n\nComplete guide for installing and configuring Aliyun CLI.\n\n> **Aliyun CLI 3.3.4+**: Supports installing and using all published Alibaba Cloud product plugins **and `ai-mode` subcommand**. Make sure to upgrade to 3.3.4 or later for full functionality.\n\n## Installation\n\n### macOS\n\n**Using Homebrew (Recommended)**\n```bash\nbrew install aliyun-cli\n# Upgrade to latest\nbrew upgrade aliyun-cli\n\n# Verify version (>= 3.3.1)\naliyun version\n```\n\n**Using Binary**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz\n\n# Extract\ntar -xzf aliyun-cli-macosx-latest-amd64.tgz\n\n# Move to PATH\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n### Linux\n\n**Debian/Ubuntu**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**CentOS/RHEL**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**ARM64 Architecture**\n```bash\n# Download ARM64 version\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-arm64.tgz\nsudo mv aliyun /usr/local/bin/\n```\n\n### Windows\n\n**Using Binary**\n1. Download from: https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\n2. Extract the ZIP file\n3. Add the directory to your PATH environment variable\n4. Open new Command Prompt or PowerShell\n5. Verify: `aliyun version`\n\n**Using PowerShell**\n```powershell\n# Download\nInvoke-WebRequest -Uri \"https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\" -OutFile \"aliyun-cli.zip\"\n\n# Extract\nExpand-Archive -Path aliyun-cli.zip -DestinationPath C:\\aliyun-cli\n\n# Add to PATH (requires admin privileges)\n$env:Path += \";C:\\aliyun-cli\"\n[Environment]::SetEnvironmentVariable(\"Path\", $env:Path, [System.EnvironmentVariableTarget]::Machine)\n\n# Verify\naliyun version\n```\n\n## AI Mode Configuration\n\n> Available since Aliyun CLI **3.3.4+**. Enables AI agent mode for API calls with a custom User-Agent header.\n\n```bash\n# Enable AI mode\naliyun configure ai-mode enable\n\n# Set custom User-Agent segment (e.g., for Skill-based calls)\naliyun configure ai-mode set-user-agent --user-agent \"AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\"\n\n# Show current AI mode config\naliyun configure ai-mode show\n# Output example:\n# {\n#   \"enabled\": true,\n#   \"user_agent\": \"AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\",\n#   \"effective_user_agent\": \"AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\",\n#   \"request_user_agent_suffix\": \"AlibabaCloud-AI-Mode/enabled AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\",\n#   \"config_file\": \"/Users/jiajindou/.aliyun/ai-mode.json\"\n# }\n\n# Disable AI mode after session\naliyun configure ai-mode disable\n```\n\n### AI Mode Subcommands\n\n| Command | Description |\n|---------|------------|\n| `show` | Display current AI mode configuration |\n| `enable` | Turn on AI mode |\n| `disable` | Turn off AI mode |\n| `set-user-agent` | Set custom User-Agent segment for AI mode |\n| `reset-user-agent` | Clear custom User-Agent segment (use default when AI mode is on) |\n| `set-ossutil` | Set ossutil JSON for cli_ai_ossutil |\n| `reset-ossutil` | Clear ossutil / cli_ai_ossutil blob |\n\n## Configuration\n\n### Quick Start\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id <your-access-key-id> \\\n  --access-key-secret <your-access-key-secret> \\\n  --region cn-hangzhou\n```\n\nAll `aliyun configure` commands support non-interactive flags, which is the recommended approach —\nit works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts.\n\n**Where to Get Access Keys**\n\n1. Log in to Aliyun Console: https://ram.console.aliyun.com/\n2. Navigate to: AccessKey Management\n3. Create a new AccessKey pair\n4. Save the secret immediately — it's only shown once\n\n### Configuration Modes\n\nAliyun CLI supports 6 authentication modes. All examples below use non-interactive flags.\n\n#### 1. AK Mode (Access Key)\n\nMost common mode for personal accounts and scripts.\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nConfiguration is stored in `~/.aliyun/config.json`:\n\n```json\n{\n  \"current\": \"default\",\n  \"profiles\": [\n    {\n      \"name\": \"default\",\n      \"mode\": \"AK\",\n      \"access_key_id\": \"LTAI5tXXXXXXXX\",\n      \"access_key_secret\": \"8dXXXXXXXXXXXXXXXXXXXXXXXX\",\n      \"region_id\": \"cn-hangzhou\",\n      \"output_format\": \"json\",\n      \"language\": \"en\"\n    }\n  ]\n}\n```\n\n#### 2. StsToken Mode (Temporary Credentials)\n\nFor short-lived access (tokens expire in 1-12 hours).\n\n```bash\naliyun configure set \\\n  --mode StsToken \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --sts-token v1.0:XXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nUse cases: CI/CD pipelines, temporary access for external contractors, cross-account access.\n\n#### 3. RamRoleArn Mode (Assume RAM Role)\n\nAssume a RAM role for elevated or cross-account access.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArn \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --ram-role-arn acs:ram::123456789012:role/AdminRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\nUse cases: cross-account resource access, temporary elevated privileges, role-based access control.\n\n#### 4. EcsRamRole Mode (ECS Instance RAM Role)\n\nUse the RAM role attached to an ECS instance — no credentials needed.\n\n```bash\naliyun configure set \\\n  --mode EcsRamRole \\\n  --ram-role-name MyEcsRole \\\n  --region cn-hangzhou\n```\n\nRequirements: must be running on an ECS instance with a RAM role attached.\n\nUse cases: scripts and automation running on ECS instances.\n\n#### 5. RsaKeyPair Mode (RSA Key Pair)\n\nUse RSA key pair for authentication (generate key pair in Aliyun Console first).\n\n```bash\naliyun configure set \\\n  --mode RsaKeyPair \\\n  --private-key /path/to/private-key.pem \\\n  --key-pair-name my-key-pair \\\n  --region cn-hangzhou\n```\n\n#### 6. RamRoleArnWithEcs Mode (ECS + RAM Role)\n\nCombine ECS instance role with RAM role assumption for cross-account access from ECS.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArnWithEcs \\\n  --ram-role-name MyEcsRole \\\n  --ram-role-arn acs:ram::123456789012:role/TargetRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\n### Environment Variables\n\n**Highest priority** - overrides config file\n\n**Access Key Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**STS Token Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_SECURITY_TOKEN=your_sts_token\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**ECS RAM Role Mode**\n```bash\nexport ALIBABA_CLOUD_ECS_METADATA=role_name\n```\n\n**Use Case**:\n- CI/CD pipelines\n- Docker containers\n- Temporary credential override\n\n### Managing Multiple Profiles\n\n**Create Named Profiles**\n\n```bash\naliyun configure set --profile projectA \\\n  --mode AK \\\n  --access-key-id LTAI5tAAAAAAAA \\\n  --access-key-secret 8dAAAAAAAAAAAAAAAAAAAAAAAA \\\n  --region cn-hangzhou\n\naliyun configure set --profile projectB \\\n  --mode AK \\\n  --access-key-id LTAI5tBBBBBBBB \\\n  --access-key-secret 8dBBBBBBBBBBBBBBBBBBBBBBBB \\\n  --region cn-shanghai\n```\n\n**Use Specific Profile**\n\n```bash\naliyun ecs describe-instances --profile projectA\n\nexport ALIBABA_CLOUD_PROFILE=projectA\naliyun ecs describe-instances   # Uses projectA\n```\n\n**List and Switch Profiles**\n\n```bash\naliyun configure list                      # List all profiles\naliyun configure set --current projectA    # Switch default profile\n```\n\n### Credential Priority\n\nCredentials are loaded in this order (first found wins):\n\n1. **Command-line flag**: `--profile <name>`\n2. **Environment variable**: `ALIBABA_CLOUD_PROFILE`\n3. **Environment credentials**: `ALIBABA_CLOUD_ACCESS_KEY_ID`, etc.\n4. **Configuration file**: `~/.aliyun/config.json` (current profile)\n5. **ECS Instance RAM Role**: If running on ECS with attached role\n\n## Verification\n\n### Test Authentication\n\n```bash\n# Basic test - list regions\naliyun ecs describe-regions\n\n# Expected output: JSON array of regions\n```\n\n**If successful**, you'll see:\n```json\n{\n  \"Regions\": {\n    \"Region\": [\n      {\n        \"RegionId\": \"cn-hangzhou\",\n        \"RegionEndpoint\": \"ecs.cn-hangzhou.aliyuncs.com\",\n        \"LocalName\": \"East China 1 (Hangzhou)\"\n      },\n      ...\n    ]\n  },\n  \"RequestId\": \"...\"\n}\n```\n\n**If failed**, you'll see error messages:\n- `InvalidAccessKeyId.NotFound` - Wrong Access Key ID\n- `SignatureDoesNotMatch` - Wrong Access Key Secret\n- `InvalidSecurityToken.Expired` - STS token expired (for StsToken mode)\n- `Forbidden.RAM` - Insufficient permissions\n\n### Debug Configuration\n\n```bash\n# Show current configuration\naliyun configure get\n\n# Test with debug logging\naliyun ecs describe-regions --log-level=debug\n\n# Check credential provider\naliyun configure get mode\n```\n\n## Security Best Practices\n\n### 1. Use RAM Users (Not Root Account)\n\n❌ **Don't**: Use Aliyun root account credentials\n✅ **Do**: Create RAM users with specific permissions\n\n```bash\n# Create RAM user in console\n# Attach only necessary policies\n# Use RAM user's access keys\n```\n\n### 2. Principle of Least Privilege\n\nGrant only the minimum permissions needed:\n\n```bash\n# Example: Read-only ECS access\n# Attach policy: AliyunECSReadOnlyAccess\n```\n\n### 3. Rotate Access Keys Regularly\n\n```bash\n# Create new access key in RAM Console, then update configuration\naliyun configure set --access-key-id NEW_KEY --access-key-secret NEW_SECRET\n# Delete old access key from console\n```\n\n### 4. Use STS Tokens for Temporary Access\n\n```bash\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token XXXX --region cn-hangzhou\n```\n\n### 5. Use ECS RAM Roles When Possible\n\n```bash\naliyun configure set --mode EcsRamRole --ram-role-name MyRole --region cn-hangzhou\n```\n\n### 6. Never Commit Credentials\n\n```bash\n# Add to .gitignore\necho \"~/.aliyun/config.json\" >> .gitignore\n\n# Use environment variables in CI/CD instead\n```\n\n### 7. Secure Config File\n\n```bash\n# Restrict permissions\nchmod 600 ~/.aliyun/config.json\n```\n\n## Troubleshooting\n\n### Issue: Command Not Found\n\n```bash\n# Check installation\nwhich aliyun\n\n# Check PATH\necho $PATH\n\n# Reinstall or add to PATH\n```\n\n### Issue: Authentication Failed\n\n```bash\n# Verify configuration\naliyun configure get\n\n# Test with debug\naliyun ecs describe-regions --log-level=debug\n\n# Check credentials in console\n# Verify access key is active\n```\n\n### Issue: Permission Denied\n\n```bash\n# Error: Forbidden.RAM\n\n# Check RAM user permissions\n# Attach necessary policies in RAM console\n# Example: AliyunECSFullAccess for ECS operations\n```\n\n### Issue: STS Token Expired\n\n```bash\n# Error: InvalidSecurityToken.Expired\n\n# Reconfigure with new token\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token NEW_TOKEN --region cn-hangzhou\n```\n\n### Issue: Wrong Region\n\n```bash\n# Some resources may not exist in the specified region\n\n# Check available regions\naliyun ecs describe-regions\n\n# Update default region\naliyun configure set region cn-shanghai\n```\n\n## Advanced Configuration\n\n### Custom Endpoint\n\n```bash\n# Use custom or private endpoint\nexport ALIBABA_CLOUD_ECS_ENDPOINT=ecs-vpc.cn-hangzhou.aliyuncs.com\n```\n\n### Proxy Settings\n\n```bash\n# HTTP proxy\nexport HTTP_PROXY=http://proxy.example.com:8080\nexport HTTPS_PROXY=http://proxy.example.com:8080\n\n# No proxy for specific domains\nexport NO_PROXY=localhost,127.0.0.1,.aliyuncs.com\n```\n\n### Timeout Settings\n\n```bash\n# Connection timeout (default: 10s)\nexport ALIBABA_CLOUD_CONNECT_TIMEOUT=30\n\n# Read timeout (default: 10s)\nexport ALIBABA_CLOUD_READ_TIMEOUT=30\n```\n\n## References\n\n- Official Documentation: https://help.aliyun.com/zh/cli/\n- RAM Console: https://ram.console.aliyun.com/\n- Access Key Management: https://ram.console.aliyun.com/manage/ak\n- Plugin Repository: https://github.com/aliyun/aliyun-cli\n\nFile v0.0.1:references/job-management.md\n\n# Job Lifecycle Management\n\nOperational rules for `update-job` / `stop-job` / `get-web-terminal` /\n`get-token` — focused on **what `--help` cannot tell you**: status windows,\nsilent-no-op cases, and the high-risk `stop-job` confirmation protocol.\n\nFor the full parameter list of any subcommand, run\n`aliyun pai-dlc <cmd> --help`.\n\n## 1. Status-to-Operation Compatibility\n\n| Operation | Allowed Job Status | Caveat |\n|-----------|--------------------|--------|\n| `update-job --accessibility` | Any | Takes effect immediately |\n| `update-job --description` | Any | Metadata only |\n| `update-job --priority` | `Creating` / `Queuing` / `EnvPreparing` | **AND** job uses quota (`--resource-id`); once `Running`, cannot be modified |\n| `update-job --job-specs` (PodCount) | Elastic-enabled jobs only | Restricted to supported phases |\n| `stop-job` | `Running` / `Queuing` only | Irreversible — three-step protocol below |\n| `get-web-terminal` | `Running` only | Pod must be alive |\n| `get-token` | Any | Read-only sharing |\n\n> **`update-job` does NOT expose `--display-name`** — to rename a job,\n> recreate it.\n\n## 2. `update-job --priority` Pre-check Protocol\n\nAlways probe both `Status` and `ResourceId` before issuing a priority update;\notherwise the API returns `200 OK` while silently dropping the change.\n\n```bash\naliyun pai-dlc get-job \\\n  --region <region> --job-id <job-id> \\\n  --cli-query '{Status: Status, ResourceId: ResourceId}' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\nProceed **only if both** hold:\n\n- `Status` ∈ `Creating` / `Queuing` / `EnvPreparing`\n- `ResourceId` is non-empty (quota-based job, e.g. `quotaXXXX`)\n\nAfter issuing the update, expect a 10–60 second propagation delay before\n`get-job` reflects the new `Priority`.\n\n## 3. `stop-job` — Three-Step Protocol (HIGH RISK)\n\nStopping a `Running` job discards in-memory progress unless the user's script\ncheckpoints. **Never call `stop-job` without explicit user confirmation.**\n\n### Step 1 — Pre-check\n\n```bash\naliyun pai-dlc get-job \\\n  --region <region> --job-id <job-id> \\\n  --cli-query '{Status: Status, Name: DisplayName}' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n### Step 2 — Confirm with the user\n\nPresent `Status` + `DisplayName`. Use this prompt template:\n\n```\nJob <job-id> (\"<DisplayName>\") is currently <Status>.\nStopping a Running job cannot be undone and will discard any in-memory progress.\nAre you sure you want to stop this job? [yes/no]\n```\n\nDo NOT proceed without an explicit `yes`.\n\n### Step 3 — Execute, then verify\n\n```bash\naliyun pai-dlc stop-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\n# Verify (expected: \"Stopped\")\naliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --cli-query \"Status\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n## 4. `get-web-terminal`\n\nRequires the Pod to be alive; the URL is short-lived. Typical pattern:\n\n```bash\nPOD_ID=$(aliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --cli-query \"Pods[0].PodId\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job)\n\naliyun pai-dlc get-web-terminal --region <region> --job-id <job-id> \\\n  --pod-id \"$POD_ID\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n## 5. `get-token` — Read-Only Sharing\n\nGenerates a token recipients can use to view the job (logs / events /\nmetrics) without RAM access. The token is read-only delegation; it cannot\nmodify the job. **Never share via insecure channels** — logs may contain\nsensitive data.\n\n## Common Pitfalls\n\n- ❌ `stop-job` on a `Stopped` / `Succeeded` / `Failed` job — API rejects with\n  `BadRequest` (terminal state). Always pre-check.\n- ❌ `get-web-terminal` after the Job exits `Running` — Pod gone, URL\n  unreachable.\n- ⚠ `update-job --priority` on a public-resource (`EcsSpec`) job → silent\n  no-op. Only quota-based jobs (`--resource-id`) honor it.\n- ⚠ `update-job --priority` once job is `Running` or later → silent no-op,\n  cannot be modified.\n- ⚠ Display name is **not updatable** — pick the right name at `create-job`.\n\nFile v0.0.1:references/ram-policies.md\n\n# PAI-DLC RAM Permission Policies\n\n## Permission Overview\n\nThe following RAM permissions are required to use PAI-DLC service. Please ensure RAM users or roles have been granted the appropriate permissions.\n\n## Minimum Permission Policy (Read-Only)\n\nQuery job information, logs, and monitoring data only:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:GetPodLogs\",\n        \"pai:GetPodEvents\",\n        \"pai:GetJobEvents\",\n        \"pai:ListEcsSpecs\",\n        \"pai:GetJobSanityCheckResult\",\n        \"pai:ListJobSanityCheckResults\",\n        \"paiworkspace:ListWorkspaces\",\n        \"paiimage:ListImages\",\n        \"paiimage:GetImage\",\n        \"paidataset:ListDatasets\",\n        \"paidataset:GetDataset\",\n        \"paicodesource:ListCodeSources\",\n        \"paicodesource:GetCodeSource\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n> Note: The last 7 Actions above belong to the **AIWorkSpace** product (product name `PAIWorkspace`). The RAM sub-account MUST also be granted the corresponding authorizations in order to query the WorkspaceId / ImageUri / DatasetId / CodeSourceId required for DLC job creation. The QuotaId (`--resource-id`) is manually provided by the user. Without authorization, `aliyun aiworkspace list-*` returns `Forbidden.RAM`.\n\n## Standard Permission Policy (Read-Write)\n\nComplete job management permissions:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:CreateJob\",\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:GetPodLogs\",\n        \"pai:GetPodEvents\",\n        \"pai:GetJobEvents\",\n        \"pai:ListEcsSpecs\",\n        \"pai:GetWebTerminal\",\n        \"pai:GetToken\",\n        \"pai:UpdateJob\",\n        \"pai:StopJob\",\n        \"pai:GetJobSanityCheckResult\",\n        \"pai:ListJobSanityCheckResults\",\n        \"paiworkspace:ListWorkspaces\",\n        \"paiimage:ListImages\",\n        \"paiimage:GetImage\",\n        \"paidataset:ListDatasets\",\n        \"paidataset:GetDataset\",\n        \"paicodesource:ListCodeSources\",\n        \"paicodesource:GetCodeSource\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n> Notes:\n> - The 7 AIWorkSpace-namespaced Actions belong to the **AIWorkSpace** product. They are required for the resource discovery (`list-workspaces` / `list-images` / `list-datasets` / `list-code-sources`) performed before invoking `aliyun pai-dlc create-job`, and MUST be granted to the RAM sub-account together with the `pai:*` Actions above. `--resource-id` (QuotaId) is manually provided by the user.\n## Full Permission Policy (Administrator)\n\nComplete permissions including workspace and resource group management:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:CreateJob\",\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:GetPodLogs\",\n        \"pai:GetPodEvents\",\n        \"pai:GetJobEvents\",\n        \"pai:ListEcsSpecs\",\n        \"pai:GetWebTerminal\",\n        \"pai:GetToken\",\n        \"pai:UpdateJob\",\n        \"pai:StopJob\",\n        \"pai:GetJobSanityCheckResult\",\n        \"pai:ListJobSanityCheckResults\",\n        \"paiworkspace:ListWorkspaces\",\n        \"paiimage:ListImages\",\n        \"paiimage:GetImage\",\n        \"paidataset:ListDatasets\",\n        \"paidataset:GetDataset\",\n        \"paicodesource:ListCodeSources\",\n        \"paicodesource:GetCodeSource\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n> Note: The `pai:ListImages` / `pai:ListDataSources` / `pai:GetDataSource` listed in earlier versions are **NOT correct Action names**. According to the AIWorkSpace OpenAPI metadata `systemTags.ramAction.action`, the following should be used instead:\n>\n> - `paiimage:ListImages` (also includes `paiimage:GetImage`)\n> - `paidataset:ListDatasets` (also includes `paidataset:GetDataset`)\n> - `paicodesource:ListCodeSources` (also includes `paicodesource:GetCodeSource`)\n>\n> All of the above Actions belong to the **AIWorkSpace** product (product name `PAIWorkspace`). The RAM sub-account MUST be granted the corresponding authorizations; granting only `pai:*` is insufficient to invoke `aliyun aiworkspace list-*` / `get-*`. The `pai:GetQuota` / `pai:ListResourceGroups` / `pai:GetResourceGroup` listed in earlier versions do not appear among the 7 resource discovery APIs covered by this task and are therefore not appended to the policy here.\n\n## Permissions by Operation Category\n\n### Job Creation Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Create Training Job | `pai:CreateJob` | Create DLC training job |\n| List Machine Specs | `pai:ListEcsSpecs` | Query available ECS instance specifications |\n\n### Job Query Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| List Jobs | `pai:ListJobs` | Get job list with pagination and filtering |\n| Get Job Details | `pai:GetJob` | Get detailed information of a single job |\n| Get Pod Logs | `pai:GetPodLogs` | Get log output of job nodes |\n| Get Pod Events | `pai:GetPodEvents` | Get system events of job nodes |\n| Get Job Events | `pai:GetJobEvents` | Get job-level system events |\n\n### Job Management Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Update Job | `pai:UpdateJob` | Update job configuration, such as priority |\n| Stop Job | `pai:StopJob` | Stop running job |\n\n### Health Check Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Get Check Result | `pai:GetJobSanityCheckResult` | Get specific compute health check result |\n| List Check Results | `pai:ListJobSanityCheckResults` | Get list of all compute health check results |\n\n### Access and Sharing Related\n\n| Operation | Permission Action | Description |\n|-----------|-------------------|-------------|\n| Get Web Terminal | `pai:GetWebTerminal` | Get container Web terminal access link |\n| Get Sharing Token | `pai:GetToken` | Get job sharing token |\n\n## Resource-Level Authorization\n\nTo restrict permissions to specific workspace:\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"pai:CreateJob\",\n        \"pai:ListJobs\",\n        \"pai:GetJob\",\n        \"pai:UpdateJob\",\n        \"pai:StopJob\"\n      ],\n      \"Resource\": [\n        \"acs:pai:*:*:workspace/<workspace-id>\",\n        \"acs:pai:*:*:workspace/<workspace-id>/*\"\n      ]\n    }\n  ]\n}\n```\n\n## Permission Check Commands\n\nUse the following commands to check current user permissions:\n\n```bash\n# Check current configuration\naliyun configure list\n\n# Test job list permission\naliyun pai-dlc list-jobs --region cn-hangzhou --page-size 1 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\n# If Forbidden.RAM error is returned, insufficient permissions\n```\n\n## Common Errors\n\n| Error Code | Description | Solution |\n|------------|-------------|----------|\n| `Forbidden.RAM` | Insufficient RAM permissions | Contact administrator to add corresponding permissions |\n| `Forbidden.AccessDenied` | No access to this resource | Check resource-level authorization configuration |\n| `InvalidAccessKeyId.NotFound` | AccessKey does not exist | Check if AccessKey is correct |\n| `SignatureDoesNotMatch` | Signature mismatch | Check if AccessKeySecret is correct |\n\n## Best Practices\n\n1. **Principle of Least Privilege** — Only grant permissions users actually need\n2. **Use RAM Roles** — For tasks running on ECS instances, use ECS RAM Role instead of AK/SK\n3. **Regular Auditing** — Regularly check and clean up unnecessary permissions\n4. **Separate Read-Only and Read-Write** — Assign read-only policies to users who only need to view\n5. **Resource Isolation** — Use resource-level authorization to isolate tasks of different projects\n\n## Reference Links\n\n- [PAI RAM Permission Documentation](https://help.aliyun.com/zh/pai/user-guide/create-a-ram-user)\n- [RAM Policy Syntax](https://help.aliyun.com/zh/ram/user-guide/policy-syntax-and-structure)\n- [RAM Best Practices](https://help.aliyun.com/zh/ram/user-guide/ram-best-practices)\n\n---\n\n## Permissions by Operation Category (Resource Discovery)\n\nThe following table covers only the 7 AIWorkSpace resource discovery APIs (QuotaId (`--resource-id`) is manually provided by the user):\n\n| Operation | CLI Subcommand | RAM Action | Product | Lookup Purpose |\n|---|---|---|---|---|\n| List Workspaces | `aliyun aiworkspace list-workspaces` | `paiworkspace:ListWorkspaces` | AIWorkSpace | Obtain `--workspace-id` |\n| List Images | `aliyun aiworkspace list-images` | `paiimage:ListImages` | AIWorkSpace | Obtain candidates for `WorkerSpec.Image` |\n| Get Image Details | `aliyun aiworkspace get-image` | `paiimage:GetImage` | AIWorkSpace | Look up `ImageUri` |\n| List Datasets | `aliyun aiworkspace list-datasets` | `paidataset:ListDatasets` | AIWorkSpace | Obtain `DataSources[].DataSourceId` |\n| Get Dataset Details | `aliyun aiworkspace get-dataset` | `paidataset:GetDataset` | AIWorkSpace | Look up `Uri` / `SourceType` |\n| List Code Sources | `aliyun aiworkspace list-code-sources` | `paicodesource:ListCodeSources` | AIWorkSpace | Obtain `CodeSource.CodeSourceId` |\n| Get Code Source Details | `aliyun aiworkspace get-code-source` | `paicodesource:GetCodeSource` | AIWorkSpace | Look up `Uri` / `CodeBranch` / `CodeCommit` |\n\n**Authorization Tip**: These 7 Actions and PAI-DLC's `pai:*` Actions belong to different products, and both groups MUST appear simultaneously in the RAM sub-account policy. Do NOT abbreviate them as `aiworkspace:*`.\n\nFile v0.0.1:references/related-apis.md\n\n# PAI-DLC API & CLI Reference\n\n> **Single source of truth** for everything `aliyun pai-dlc <cmd> --help` and\n> `aliyun aiworkspace <cmd> --help` do **not** tell you: command index across\n> products, cross-product field contracts, status lifecycle, red lines,\n> error catalog, forbidden patterns.\n>\n> For parameter-level details (flags, types, defaults, enums) — always run\n> `--help` on the subcommand. This document never duplicates `--help` output.\n>\n> Every API-invoking call MUST include\n> `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job`. Client-side\n> helpers (`version` / `configure` / `plugin` / `--help`) do not invoke remote\n> APIs and do not need the flag.\n\n---\n\n## 1. Command Index\n\n### 1.1 Client-Side Helpers (no API call)\n\n| CLI Command | Purpose |\n|-------------|---------|\n| `aliyun version` | Verify CLI ≥ 3.3.1 |\n| `aliyun configure list` | Inspect profiles (never echoes AK/SK) |\n| `aliyun configure set --auto-plugin-install true` | Enable auto plugin install |\n| `aliyun plugin list` / `install --names ...` / `update --name ...` | Plugin management |\n| `aliyun pai-dlc --help` / `aliyun aiworkspace --help` | Probe plugin presence |\n| `aliyun pai-dlc <subcommand> --help` | Authoritative parameter reference |\n\n### 1.2 PAI-DLC Job APIs (`pai-dlc` plugin, API 2020-12-03)\n\n| CLI | Action | One-liner |\n|-----|--------|-----------|\n| `create-job` | CreateJob | Submit a distributed training job |\n| `list-jobs` | ListJobs | List jobs with `--status` / `--workspace-id` filters |\n| `get-job` | GetJob | Full job detail (use `--need-detail` for advanced fields) |\n| `update-job` | UpdateJob | Mutate priority / accessibility / description / job-specs |\n| `stop-job` | StopJob | Stop a `Running` / `Queuing` job (high-risk) |\n| `get-pod-logs` | GetPodLogs | Container logs (always cap with `--max-lines`) |\n| `get-pod-events` | GetPodEvents | Pod-level Kubernetes events |\n| `get-job-events` | GetJobEvents | Job-level system events |\n| `list-job-sanity-check-results` / `get-job-sanity-check-result` | SanityCheck | GPU health-check results |\n| `list-ecs-specs` | ListEcsSpecs | Discover available ECS / Lingjun machine types |\n| `get-web-terminal` | GetWebTerminal | Web Terminal URL (Pod must be alive) |\n| `get-token` | GetToken | Read-only sharing token for jobs |\n\n### 1.3 AIWorkSpace Resource Discovery (`aiworkspace` plugin, API 2021-02-04)\n\n| CLI | Returns | Maps to CreateJob field |\n|-----|---------|-------------------------|\n| `list-workspaces` | `Workspaces[].WorkspaceId` | `--workspace-id` |\n| `list-image-labels` | label `Key=Value` pairs | input for `list-images --labels` |\n| `list-images` / `get-image` | `Images[].ImageUri` | `--job-specs[].Image` |\n| `list-datasets` / `get-dataset` | `Datasets[].DatasetId` | `--data-sources[].DataSourceId` |\n| `list-code-sources` / `get-code-source` | `CodeSources[].CodeSourceId` | `--code-source.CodeSourceId` |\n\n> **Quota (`--resource-id`)** is user-supplied — there is no CLI discovery\n> command for QuotaId.\n\n---\n\n## 2. Cross-Product Field Mapping (CreateJob ← AIWorkSpace)\n\nAuthoritative mapping from `create-job` fields back to their AIWorkSpace\ndiscovery API. `--help` cannot point you across products.\n\n| CreateJob field | Source API | Source field |\n|-----------------|------------|--------------|\n| `--workspace-id` | `aiworkspace list-workspaces` | `Workspaces[].WorkspaceId` |\n| `--job-specs[].Image` | `aiworkspace list-images` | `Images[].ImageUri` (verbatim) |\n| `--data-sources[].DataSourceId` | `aiworkspace list-datasets` | `Datasets[].DatasetId` |\n| `--code-source.CodeSourceId` | `aiworkspace list-code-sources` | `CodeSources[].CodeSourceId` |\n| `--resource-id` | (manual) | User-provided QuotaId |\n\n**Recommended discovery order:** `list-workspaces` → `list-image-labels` →\n`list-images` → `list-datasets` → `list-code-sources` → fill into `create-job`.\n\n---\n\n## 3. Job Status Lifecycle\n\n```\nCreating → Queuing → (Bidding) → EnvPreparing → SanityChecking\n        → Running → (Restarting) → Stopping → Succeeded / Failed / Stopped\n```\n\n- `Bidding` only appears for Spot jobs.\n- `SanityChecking` only appears when `Settings.EnableSanityCheck=true`.\n- `Restarting` is a transient state during fault recovery.\n\n> The full enum (14 values, e.g. including `SucceededReserving` /\n> `FailedReserving`) is documented by `aliyun pai-dlc list-jobs --help` under\n> `--status`. The diagram above shows the **operational flow**, not an\n> exhaustive enum.\n\n---\n\n## 4. CreateJob — Red Lines\n\n> ⚠ **Red Line 1: `EcsSpec` ⇄ `ResourceConfig`** — mutually exclusive within\n> a single TaskSpec. Use `EcsSpec` for public pay-as-you-go; `ResourceConfig`\n> (with CPU/Memory/GPU/GPUType) for dedicated quota (and pair with\n> `--resource-id`).\n\n> ⚠ **Red Line 2: Image URI source** — `--job-specs[].Image` MUST be a verbatim\n> `ImageUri` from `aiworkspace list-images`. Never invent, rewrite, or\n> substitute `Name` / `ImageId`.\n\n> ⚠ **Red Line 3: No ROA fallback** — if a plugin subcommand is unavailable,\n> install/upgrade the plugin (`aliyun plugin install --names ...` /\n> `aliyun plugin update --name ...`). Never construct generic ROA calls\n> (`--pathPattern` / `--method GET|POST|PUT|DELETE`).\n\n> ⚠ **Red Line 4: `--workspace-id` is always required** — `--help` marks it\n> optional, but the server silently falls back to the user's default\n> workspace. Always confirm with the user.\n\n---\n\n## 5. Common Errors\n\n| Code | Trigger | Fix |\n|------|---------|-----|\n| `NotFound` | Wrong `JobId` | Re-run the corresponding `list-*` command to confirm |\n| `InvalidParameter` | Format / type / enum violation | Re-check with `--help` |\n| `Forbidden.RAM` | Missing `pai:*` / `paiimage:*` etc. | See [ram-policies.md](ram-policies.md) |\n| `Throttling` | Rate limit | Reduce request frequency; add backoff |\n| `ServiceUnavailable` | Transient | Retry with exponential backoff |\n\n---\n\n## 6. Forbidden Patterns\n\n- ❌ `--pathPattern` / `--method GET|POST|PUT|DELETE` (ROA generic fallback) —\n  install/upgrade the proper plugin instead.\n- ❌ `aliyun pai-dlc list-images` / `list-workspaces` / `list-datasets` /\n  `list-code-sources` — these subcommands belong to **`aiworkspace`**,\n  not `pai-dlc`.\n- ❌ Reading or printing `ALIBABA_CLOUD_ACCESS_KEY_ID` / `_SECRET`; running\n  `aliyun configure set` with literal credential values.\n\nFile v0.0.1:references/verification-method.md\n\n# PAI-DLC Operation Verification Methods\n\nEnd-to-end and per-command verification scripts. These are **runnable\nflows**, not parameter docs — for flag-level details run\n`aliyun pai-dlc <cmd> --help`. The job status enum, common errors, and red\nlines live in [related-apis.md](related-apis.md) (single source of truth).\n\nEvery API call MUST include\n`--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job`. Replace\n`<region>` / `<job-id>` / `<pod-id>` / `<workspace-id>` placeholders before\nrunning.\n\n---\n\n## 1. Per-Command Quick Verify\n\n### 1.1 Create Job\n\n```bash\nJOB_ID=$(aliyun pai-dlc create-job \\\n  --region <region> \\\n  --workspace-id <workspace-id> \\\n  --display-name \"verify-job\" \\\n  --job-type PyTorchJob \\\n  --job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"<ImageUri>\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]' \\\n  --user-command \"python -c 'print(123)'\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job \\\n  --cli-query \"JobId\")\n```\n\n**Expect:** `JobId` matches `dlc[0-9a-z]+`; status shortly enters\n`Creating` / `Queuing` / `Running`.\n\n### 1.2 List / Get / Events / Logs / Metrics\n\n```bash\naliyun pai-dlc list-jobs --region <region> --status Running --page-size 10 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\naliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\naliyun pai-dlc get-pod-logs --region <region> --job-id <job-id> --pod-id <pod-id> \\\n  --max-lines 100 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\naliyun pai-dlc get-job-events --region <region> --job-id <job-id> \\\n  --max-events-num 50 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\naliyun pai-dlc get-pod-events --region <region> --job-id <job-id> --pod-id <pod-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n**Expect:** all return non-empty data once the job is past `EnvPreparing`.\nLogs contain stdout/stderr; events sorted by time.\n\n### 1.3 Update / Stop\n\n```bash\n# Priority update (pre-check status & quota first; see SKILL.md §7.8)\naliyun pai-dlc update-job --region <region> --job-id <job-id> --priority 5 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\n# Stop (HIGH-RISK — follow pre-check + user-confirmation protocol in SKILL.md §7.8)\naliyun pai-dlc stop-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n### 1.4 Health Check (only when `Settings.EnableSanityCheck=true`)\n\n```bash\naliyun pai-dlc list-job-sanity-check-results \\\n  --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\naliyun pai-dlc get-job-sanity-check-result \\\n  --region <region> --job-id <job-id> --sanity-check-number 1 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n### 1.5 Debug Helpers\n\n```bash\n# Verbose logging\naliyun pai-dlc <cmd> --region <region> --log-level=debug \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n\n# Dry-run (no API call)\naliyun pai-dlc <cmd> --region <region> --cli-dry-run \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job\n```\n\n---\n\n## 2. Resource Discovery → CreateJob (E2E)\n\nVerifies the full **discover → fill → create → verify → cleanup** workflow\nusing AIWorkSpace resource discovery. Mirrors the §7.6 flow in `SKILL.md`.\n\n### 2.1 Pre-flight\n\n```bash\naliyun aiworkspace --help >/dev/null 2>&1 \\\n  || aliyun plugin install --names aliyun-cli-aiworkspace\n```\n\n### 2.2 Discover Resources\n\n```bash\nWORKSPACE_ID=$(aliyun aiworkspace list-workspaces \\\n  --region <region> --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job \\\n  --cli-query 'Workspaces[0].WorkspaceId')\n\nIMAGE_URI=$(aliyun aiworkspace list-images \\\n  --region <region> --workspace-id $WORKSPACE_ID --page-size 20 \\\n  --user-agent AlibabaCloud-Agent-Skil\n\nArchive v0.0.1-beta.2: 10 files, 34863 bytes\n\nFiles: references/acceptance-criteria.md (13013b), references/cli-installation-guide.md (12441b), references/job-management.md (4224b), references/job-template-management.md (5934b), references/ram-policies.md (12656b), references/related-apis.md (9721b), references/verification-method.md (10839b), skill-card.md (2910b), SKILL.md (24073b), _meta.json (150b)\n\nArchive v0.0.1-beta.1: 10 files, 35225 bytes\n\nFiles: references/acceptance-criteria.md (13013b), references/cli-installation-guide.md (12441b), references/job-management.md (4592b), references/job-template-management.md (7934b), references/ram-policies.md (12656b), references/related-apis.md (14467b), references/related-commands.md (6977b), references/verification-method.md (12002b), SKILL.md (21496b), _meta.json (150b)","readmeExcerpt":"Skill: alibabacloud-pai-dlc-job Owner: sdk-team Summary: Alibaba Cloud PAI-DLC (Deep Learning Containers) job management skill. Covers: distributed training job CRUD, monitoring (logs and events), and GPU sanity check. Triggers: \"DLC\", \"PAI-DLC\", \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", \"list-job-sanity-check-results\". Tags: latest:0.0.2 Versi","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"aliyun version\naliyun configure set --auto-plugin-install true\naliyun pai-dlc --help\naliyun aiworkspace --help >/dev/null 2>&1 || aliyun plugin install --names aliyun-cli-aiworkspace\naliyun plugin update"},{"language":"text","snippet":"--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/{session-id}"},{"language":"bash","snippet":"SESSION_ID=$(uuidgen | tr 'A-Z' 'a-z')\nexport SESSION_ID\n# every API-invoking command then appends:\n#   --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\naliyun pai-dlc list-jobs --region <r> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}"},{"language":"text","snippet":"## Environment Variables\n\nThis skill does not require any custom environment variables. Credentials are handled\nby the Alibaba Cloud CLI configuration (see Authentication below). Optionally:\n\n| Variable | Required | Purpose |\n|----------|----------|---------|\n| `ALIBABA_CLOUD_PROFILE` | Optional | Selects a non-default `aliyun configure` profile |\n| `ALIBABA_CLOUD_REGION_ID` | Optional | Default region when `--region` is omitted (still recommended to pass `--region` explicitly) |\n\nDo NOT export `ALIBABA_CLOUD_ACCESS_KEY_ID` / `ALIBABA_CLOUD_ACCESS_KEY_SECRET` from\nwithin this session; configure them outside (`aliyun configure` or shell profile).\n\n## Authentication Configuration\n\n> **Pre-check: Alibaba Cloud Credentials Required**\n>\n> **Security Rules:**\n> - **NEVER** read, echo, or print AK/SK values (e.g., `echo $ALIBABA_CLOUD_ACCESS_KEY_ID` is FORBIDDEN)\n> - **NEVER** ask the user to input AK/SK directly in the conversation or command line\n> - **NEVER** use `aliyun configure set` with literal credential values\n> - **ONLY** use `aliyun configure list` to check credential status\n>\n>"},{"language":"text","snippet":"> Check the output for a valid profile (AK, STS, or OAuth identity).\n>\n> **If no valid profile exists, STOP here.**\n> 1. Obtain credentials from [Alibaba Cloud Console](https://ram.console.aliyun.com/manage/ak)\n> 2. Configure credentials **outside of this session** (via `aliyun configure` in terminal\n>    or environment variables in shell profile)\n> 3. Return and re-run after `aliyun configure list` shows a valid profile\n\n## RAM Permissions\n\n> **[MUST] Permission Failure Handling:** When any command or API call fails due to\n> permission errors at any point during execution, follow this process:\n> 1. Read `references/ram-policies.md` to get the full list of permissions required by this SKILL\n> 2. Use `ram-permission-diagnose` skill to guide the user through requesting the necessary permissions\n> 3. Pause and wait until the user confirms that the required permissions have been granted\n\nFor detailed permission list, see [references/ram-policies.md](references/ram-policies.md).\n\n**Required Permissions Overview:**\n\n| Operation | Required Permission |\n|-----------|---------------------|\n| Create Job | `pai:CreateJob` |\n| List Jobs | `pai:ListJobs` |\n| Get Job Details | `pai:GetJob` |\n| Get Pod Logs | `pai:GetPodLogs` |\n| Get Job Events | `pai:GetJobEvents` |\n| Update Job | `pai:UpdateJob` |\n| Stop Job | `pai:StopJob` |\n| AIWorkSpace Resource Discovery | `paiworkspace:ListWorkspaces` / `paiimage:ListImages,GetImage` / `paidataset:ListDatasets,GetDataset` / `paicodesource:ListCodeSources,GetCodeSource` |\n\n> **AIWorkSpace authorization note:** `Image` / `DataSourceId` / `CodeSourceId` /\n> `WorkspaceId` field values for `create-job` come from the\n> AIWorkSpace resource-discovery APIs. `--resource-id` (QuotaId) is manually provided by the user.\n> RAM users MUST hold the corresponding\n> AIWorkSpace-namespaced permissions listed above (do not abbreviate as `aiworkspace:*`).\n\n## Parameter Confirmation\n\n> **Authoritative parameter reference is `aliyun pai-dlc <cmd> --help`** (must"},{"language":"text","snippet":"Multi-node / Spot / RDMA / data mounting — use `create-job --help`.\nSubsequent snippets omit `--user-agent` for brevity — always include it.\n\n### 7.3 List / Get Job\n\nUse `--cli-query` to project specific fields (essential for log/event flows):"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: alibabacloud-pai-dlc-job\ndescription: |\n  Alibaba Cloud PAI-DLC (Deep Learning Containers) job management skill. Covers: distributed training job CRUD, monitoring (logs and events), and  GPU sanity check. Triggers: \"DLC\", \"PAI-DLC\", \"create-job\", \"list-jobs\", \"get-job\", \"stop-job\", \"update-job\", \"get-pod-logs\", \"get-job-events\", \"get-pod-events\", \"list-job-sanity-check-results\".\n---\n\n# PAI-DLC Deep Learning Job Management\n\nManage deep learning training jobs on Alibaba Cloud PAI-DLC (Platform for AI - Deep\nLearning Containers) service.\n\n## Scenario Description\n\nPAI-DLC is a distributed training service provided by Alibaba Cloud's AI Platform PAI,\nsupporting:\n\n- **Job Creation and Execution** — Create distributed training jobs for TensorFlow,\n  PyTorch, XGBoost, and other frameworks\n- **Job Monitoring** — Get job status, logs, events, and monitoring metrics\n- **Compute Health Check** — Check health status of GPU and other compute devices\n- **Job Management** — Update and stop jobs\n\n**Architecture**: PAI Workspace + DLC Job + Computing Resources (ECS public pay-as-you-go\nor Lingjun dedicated quota) + AIWorkSpace catalog (images / datasets / code sources /\nquotas / workspaces).\n\n## Installation Requirements\n\n> **Pre-check: Aliyun CLI >= 3.3.1 required**\n> Run `aliyun version` to verify version >= 3.3.1. If not installed or version is too low,\n> see [references/cli-installation-guide.md](references/cli-installation-guide.md) for\n> installation instructions.\n> Then [Required] run `aliyun configure set --auto-plugin-install true` to enable\n> automatic plugin installation.\n\n> **Note on `--user-agent`:** Every API-invoking `aliyun` command in this skill MUST\n> include `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`\n> (unified User-Agent + session-id template — see [Observability](#observability) for\n> the generation rules). Client-side helpers (`aliyun version`,\n> `aliyun configure ...`, `aliyun plugin ...`, `aliyun <product> --help`) do not\n> invoke remote APIs and therefore do not require the flag.\n\n> **Network timeout & retry (rule `--help` doesn't enforce):** `aliyun` CLI\n> defaults to 10s connect / 10s read with no retry. For long-running flows\n> (large list, slow region) explicitly raise via global flags\n> `--connect-timeout 15 --read-timeout 30 --retry-count 2`. Never rely on the\n> default for user-confirmed high-risk calls (`stop-job` / `delete-*`).\n\n```bash\naliyun version\naliyun configure set --auto-plugin-install true\naliyun pai-dlc --help\naliyun aiworkspace --help >/dev/null 2>&1 || aliyun plugin install --names aliyun-cli-aiworkspace\naliyun plugin update\n```\n\n## Observability\n\n> **Why:** every PAI-DLC API call issued by this skill MUST carry a unified\n> User-Agent so platform-side tracing can attribute the request to this skill\n> and correlate all calls within a single agent session.\n\n### User-Agent template\n\nEvery API-invoking `aliyun` command MUST pass:\n\n```\n--user-agent AlibabaCloud-Agent-Skills/ali"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-pai-dlc-job\",\n  \"version\": \"0.0.2\",\n  \"publishedAt\": 1786696690094\n}"},{"path":"references/acceptance-criteria.md","content":"# Acceptance Criteria: alibabacloud-pai-dlc-job\n\n**Scenario**: PAI-DLC Deep Learning Job Management\n**Purpose**: Skill Testing Acceptance Criteria\n\n> **Note on snippets in this file:** Sections 1-3 below show product names,\n> command names, and parameter names as **pattern placeholders** (e.g.,\n> `aliyun pai-dlc <command>`). These are fragments for mismatch detection,\n> not complete executable commands. The Section 4 \"User-Agent\" rule (and the\n> SKILL.md core workflow) require every API-invoking command to end with\n> `--user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}`; full executable examples carry it.\n\n---\n\n# Correct CLI Command Patterns\n\n## 1. Product — Verify Product Name Exists\n\nCORRECT\n```bash\naliyun pai-dlc <command>\n```\n\nINCORRECT\n```bash\naliyun pai <command>        # Error: product name should be pai-dlc\naliyun dlc <command>        # Error: product name should be pai-dlc\naliyun PAI-DLC <command>    # Error: case-sensitive, should use lowercase\n```\n\n## 2. Command — Verify Command Name Format\n\nCORRECT (Plugin mode, lowercase with hyphens)\n```bash\naliyun pai-dlc create-job\naliyun pai-dlc list-jobs\naliyun pai-dlc get-job\naliyun pai-dlc get-pod-logs\naliyun pai-dlc list-ecs-specs\naliyun pai-dlc get-web-terminal\naliyun pai-dlc stop-job\naliyun pai-dlc update-job\naliyun pai-dlc get-token\naliyun pai-dlc get-job-events\naliyun pai-dlc get-pod-events\naliyun pai-dlc get-job-sanity-check-result\naliyun pai-dlc list-job-sanity-check-results\n```\n\nINCORRECT (Traditional API format)\n```bash\naliyun pai-dlc CreateJob       # Error: should use create-job\naliyun pai-dlc ListJobs        # Error: should use list-jobs\naliyun pai-dlc GetJob          # Error: should use get-job\naliyun pai-dlc GetPodLogs      # Error: should use get-pod-logs\n```\n\n## 3. Parameters — Verify Parameter Name Format\n\nCORRECT (Lowercase with hyphens)\n```bash\n--job-id\n--pod-id\n--display-name\n--job-type\n--job-specs\n--user-command\n--workspace-id\n--resource-id\n--page-number\n--page-size\n--start-time\n--end-time\n--max-lines\n--user-agent\n```\n\nINCORRECT (CamelCase or underscore)\n```bash\n--JobId            # Error: should use --job-id\n--jobId            # Error: should use --job-id\n--job_id           # Error: should use --job-id\n--displayName      # Error: should use --display-name\n--DisplayName      # Error: should use --display-name\n```\n\n## 4. User-Agent — Must Include Identifier\n\nCORRECT\n```bash\naliyun pai-dlc list-jobs --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\nINCORRECT\n```bash\naliyun pai-dlc list-jobs --region cn-hangzhou   # Error: missing --user-agent\n```\n\n## 5. JobSpecs Format — Verify JSON Structure\n\nCORRECT - Method 1: EcsSpec (Public Resources)\n```bash\n--job-specs '[{\"Type\":\"Worker\",\"PodCount\":1,\"Image\":\"registry.cn-hangzhou.aliyuncs.com/pai-dlc/pytorch:1.12\",\"EcsSpec\":\"ecs.gn6i-c4g1.xlarge\"}]'\n```\n\nCORRECT - Method 2: ResourceConfig (Dedicated Resource Group)\n```bash\n--job-specs '[{\"Type\":\"Worker\",\"P"},{"path":"references/cli-installation-guide.md","content":"# Aliyun CLI Installation & Configuration Guide\n\nComplete guide for installing and configuring Aliyun CLI.\n\n> **Aliyun CLI 3.3.1+**: Supports installing and using all published Alibaba Cloud product plugins. Make sure to upgrade to 3.3.1 or later for full functionality.\n\n## Installation\n\n### macOS\n\n**Using Homebrew (Recommended)**\n```bash\nbrew install aliyun-cli\n# Upgrade to latest\nbrew upgrade aliyun-cli\n\n# Verify version (>= 3.3.1)\naliyun version\n```\n\n**Using Binary**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz\n\n# Extract\ntar -xzf aliyun-cli-macosx-latest-amd64.tgz\n\n# Move to PATH\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n### Linux\n\n**Debian/Ubuntu**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**CentOS/RHEL**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**ARM64 Architecture**\n```bash\n# Download ARM64 version\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-arm64.tgz\nsudo mv aliyun /usr/local/bin/\n```\n\n### Windows\n\n**Using Binary**\n1. Download from: https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\n2. Extract the ZIP file\n3. Add the directory to your PATH environment variable\n4. Open new Command Prompt or PowerShell\n5. Verify: `aliyun version`\n\n**Using PowerShell**\n```powershell\n# Download\nInvoke-WebRequest -Uri \"https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\" -OutFile \"aliyun-cli.zip\"\n\n# Extract\nExpand-Archive -Path aliyun-cli.zip -DestinationPath C:\\aliyun-cli\n\n# Add to PATH (requires admin privileges)\n$env:Path += \";C:\\aliyun-cli\"\n[Environment]::SetEnvironmentVariable(\"Path\", $env:Path, [System.EnvironmentVariableTarget]::Machine)\n\n# Verify\naliyun version\n```\n\n## User-Agent for Skill Calls (session-id)\n\n> Do NOT use the deprecated `aliyun configure ai-mode` to set the User-Agent.\n> Instead, pass `--user-agent` explicitly on every API-invoking command using\n> the unified session-id template. See the `Observability` section in `SKILL.md`\n> for the full rules.\n\n```bash\n# Generate the session-id ONCE per skill session, then reuse it everywhere\nSESSION_ID=$(uuidgen | tr 'A-Z' 'a-z')\nexport SESSION_ID\n\n# Every API-invoking command appends the templated User-Agent:\naliyun pai-dlc list-jobs --region cn-hangzhou --page-size 1 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## Configuration\n\n### Quick Start\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id <your-access-key-id> \\\n  --access-key-secret <your-access-key-secret> \\\n  --region cn-hangzhou\n```\n\nAll `aliyun configure` commands support non-in"},{"path":"references/job-management.md","content":"# Job Lifecycle Management\n\nOperational rules for `update-job` / `stop-job` / `get-web-terminal` /\n`get-token` — focused on **what `--help` cannot tell you**: status windows,\nsilent-no-op cases, and the high-risk `stop-job` confirmation protocol.\n\nFor the full parameter list of any subcommand, run\n`aliyun pai-dlc <cmd> --help`.\n\n## 1. Status-to-Operation Compatibility\n\n| Operation | Allowed Job Status | Caveat |\n|-----------|--------------------|--------|\n| `update-job --accessibility` | Any | Takes effect immediately |\n| `update-job --description` | Any | Metadata only |\n| `update-job --priority` | `Creating` / `Queuing` / `EnvPreparing` | **AND** job uses quota (`--resource-id`); once `Running`, cannot be modified |\n| `update-job --job-specs` (PodCount) | Elastic-enabled jobs only | Restricted to supported phases |\n| `stop-job` | `Running` / `Queuing` only | Irreversible — three-step protocol below |\n| `get-web-terminal` | `Running` only | Pod must be alive |\n| `get-token` | Any | Read-only sharing |\n\n> **`update-job` does NOT expose `--display-name`** — to rename a job,\n> recreate it.\n\n## 2. `update-job --priority` Pre-check Protocol\n\nAlways probe both `Status` and `ResourceId` before issuing a priority update;\notherwise the API returns `200 OK` while silently dropping the change.\n\n```bash\naliyun pai-dlc get-job \\\n  --region <region> --job-id <job-id> \\\n  --cli-query '{Status: Status, ResourceId: ResourceId}' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\nProceed **only if both** hold:\n\n- `Status` ∈ `Creating` / `Queuing` / `EnvPreparing`\n- `ResourceId` is non-empty (quota-based job, e.g. `quotaXXXX`)\n\nAfter issuing the update, expect a 10–60 second propagation delay before\n`get-job` reflects the new `Priority`.\n\n## 3. `stop-job` — Three-Step Protocol (HIGH RISK)\n\nStopping a `Running` job discards in-memory progress unless the user's script\ncheckpoints. **Never call `stop-job` without explicit user confirmation.**\n\n### Step 1 — Pre-check\n\n```bash\naliyun pai-dlc get-job \\\n  --region <region> --job-id <job-id> \\\n  --cli-query '{Status: Status, Name: DisplayName}' \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n### Step 2 — Confirm with the user\n\nPresent `Status` + `DisplayName`. Use this prompt template:\n\n```\nJob <job-id> (\"<DisplayName>\") is currently <Status>.\nStopping a Running job cannot be undone and will discard any in-memory progress.\nAre you sure you want to stop this job? [yes/no]\n```\n\nDo NOT proceed without an explicit `yes`.\n\n### Step 3 — Execute, then verify\n\n```bash\naliyun pai-dlc stop-job --region <region> --job-id <job-id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n\n# Verify (expected: \"Stopped\")\naliyun pai-dlc get-job --region <region> --job-id <job-id> \\\n  --cli-query \"Status\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-dlc-job/${SESSION_ID}\n```\n\n## 4. `get-web-terminal`\n\nRequires the Pod to be al"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1773,"uniquenessScore":39,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T20:37:34.675Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T20:37:34.675Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:50:35.558Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}