{"id":"8b56e863-1935-4b74-8ca2-a3bc23701265","entityType":"agent","slug":"clawhub-sdk-team-alibabacloud-pai-eas-service-deploy","name":"Alibabacloud Pai Eas Service Deploy","canonicalUrl":"https://www.xpersona.co/agent/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy","canonicalPath":"/agent/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy","generatedAt":"2026-10-11T15:17:14.481Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T12:49:57.117Z","emptyReason":null},"description":"Deploy AI models as PAI-EAS inference services. Supports LLMs (Qwen, Llama), image gen (SD, SDXL), speech synthesis, and more. When to use: deploy models, cr...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-pai-eas-service-deploy","sourceUrl":"https://clawhub.ai/sdk-team/alibabacloud-pai-eas-service-deploy","homepage":"https://clawhub.ai/sdk-team/skills/alibabacloud-pai-eas-service-deploy","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/sdk-team/alibabacloud-pai-eas-service-deploy","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/sdk-team/skills/alibabacloud-pai-eas-service-deploy","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Alibabacloud Pai Eas Service Deploy technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T12:49:57.117Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T12:49:57.117Z","emptyReason":null},"stars":null,"forks":null,"downloads":1062,"packageName":null,"latestVersion":"0.0.1","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T12:49:57.104Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T12:49:57.117Z","lastCrawledAt":"2026-10-11T12:49:57.104Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T12:49:57.104Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.1","createdAt":"2026-07-13T07:59:30.842Z","changelog":"Initial release of the PAI-EAS Inference Service Deployment skill. - Provides end-to-end workflow to deploy AI models as inference services on Alibaba Cloud PAI-EAS. - Enforces strict duplicate service name checks; never reuses or recreates existing services. - Requires Aliyun CLI >= 3.3.3 and enforces plugin installation/verification for `aiworkspace` and `eas`. - Implements a unified session-based user-agent for observability and traceability on all API/CLI calls. - Executes all required validation and deployment steps directly via CLI commands—no scripts, wrappers, or skipped steps. - Documents self-verification checkpoints, error handling, and required permissions for reliable, autonomous operation.","fileCount":22,"zipByteSize":55089},{"version":"0.0.1-beta.1","createdAt":"2026-04-23T06:50:32.293Z","changelog":"alibabacloud-pai-eas-service-deploy 0.0.1-beta.1 - Initial beta release for deploying AI models as Alibaba Cloud PAI-EAS inference services. - Supports LLMs (Qwen, Llama), image generation models (SD, SDXL), speech synthesis, and more. - Enforces pre-checks, mandatory API call sequence, and strict deployment rules (no duplicate service names). - Requires aliyun CLI, aiworkspace and eas plugins, and jq for command execution and validation. - Detailed operational steps and failure handling provided for reliable, autonomous service deployment.","fileCount":22,"zipByteSize":53203}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-pai-eas-service-deploy","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-pai-eas-service-deploy` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/sdk-team/alibabacloud-pai-eas-service-deploy before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T15:17:14.479Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-pai-eas-service-deploy/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T12:49:57.117Z","emptyReason":null},"readme":"Skill: Alibabacloud Pai Eas Service Deploy\n\nOwner: sdk-team\n\nSummary: Deploy AI models as PAI-EAS inference services. Supports LLMs (Qwen, Llama), image gen (SD, SDXL), speech synthesis, and more. When to use: deploy models, cr...\n\nTags: latest:0.0.1\n\nVersion history:\n\nv0.0.1 | 2026-07-13T07:59:30.842Z | auto\n\nInitial release of the PAI-EAS Inference Service Deployment skill.\n\n- Provides end-to-end workflow to deploy AI models as inference services on Alibaba Cloud PAI-EAS.\n- Enforces strict duplicate service name checks; never reuses or recreates existing services.\n- Requires Aliyun CLI >= 3.3.3 and enforces plugin installation/verification for `aiworkspace` and `eas`.\n- Implements a unified session-based user-agent for observability and traceability on all API/CLI calls.\n- Executes all required validation and deployment steps directly via CLI commands—no scripts, wrappers, or skipped steps.\n- Documents self-verification checkpoints, error handling, and required permissions for reliable, autonomous operation.\n\nv0.0.1-beta.1 | 2026-04-23T06:50:32.293Z | auto\n\nalibabacloud-pai-eas-service-deploy 0.0.1-beta.1\n\n- Initial beta release for deploying AI models as Alibaba Cloud PAI-EAS inference services.\n- Supports LLMs (Qwen, Llama), image generation models (SD, SDXL), speech synthesis, and more.\n- Enforces pre-checks, mandatory API call sequence, and strict deployment rules (no duplicate service names).\n- Requires aliyun CLI, aiworkspace and eas plugins, and jq for command execution and validation.\n- Detailed operational steps and failure handling provided for reliable, autonomous service deployment.\n\nArchive index:\n\nArchive v0.0.1: 22 files, 55089 bytes\n\nFiles: references/acceptance-criteria.md (6076b), references/api-reference.md (3364b), references/cli-installation-guide.md (11946b), references/config-examples.md (5604b), references/config-patterns.md (7194b), references/config-schema.md (8503b), references/deployment-workflow.md (18999b), references/image-categories.md (5250b), references/model-image-matching.md (4701b), references/network-config.md (6736b), references/ram-policies.md (4689b), references/related-apis.md (5601b), references/service-features.md (8507b), references/service-invoke-examples.md (3398b), references/storage-mount.md (8652b), references/verification-method.md (5413b), scripts/create-service-from-json.sh (7180b), scripts/list-images.sh (8464b), scripts/validate-service-config.sh (9628b), skill-card.md (3345b), SKILL.md (20236b), _meta.json (154b)\n\nFile v0.0.1:SKILL.md\n\n---\nname: alibabacloud-pai-eas-service-deploy\ndescription: |\n  Deploy AI models as PAI-EAS inference services.\n  Supports LLMs (Qwen, Llama), image gen (SD, SDXL),\n  speech synthesis, and more.\n  When to use: deploy models, create inference services,\n  EAS deployment, model serving, deploy vLLM/SGLang/ComfyUI.\nlicense: Apache-2.0\nmetadata:\n  version: \"1.0.0\"\n  domain: aiops\n  owner: pai-eas-team\n  contact: pai-eas-agent@alibaba-inc.com\n  tags:\n    - pai-eas\n    - model-deployment\n    - inference-service\n    - llm\n    - vllm\n    - sglang\n  required_tools:\n    - aliyun\n    - jq\n  prerequisites:\n    - \"Aliyun CLI >= 3.3.3\"\n    - \"jq command-line JSON processor\"\n  required_permissions:\n    - \"eas:CreateService\"\n    - \"eas:DescribeService\"\n    - \"eas:ListServices\"\n    - \"eas:DescribeMachineSpec\"\n    - \"eas:ListResources\"\n    - \"eas:ListGateway\"\n    - \"eas:DescribeGateway\"\n    - \"nlb:ListLoadBalancers\"\n    - \"aiworkspace:ListImages\"\n    - \"aiworkspace:ListWorkspaces\"\n    - \"vpc:DescribeVpcs\"\n    - \"vpc:DescribeVSwitches\"\n    - \"ecs:DescribeSecurityGroups\"\n---\n# PAI-EAS Service Deployment\n\n## ⚠️ TOP RULES (read first)\n\n**1. 🔴 NO DUPLICATE SERVICE NAMES** 🔴\n\nIf a service with the target name already exists: STOP and inform\nthe user. Do NOT delete and recreate. Do NOT reuse it either.\n\n**2. Mandatory API Calls** — Execute ALL of these in order:\n\n| # | API | CLI | Purpose |\n|---|-----|-----|---------|\n| 1 | ListImages | `aliyun aiworkspace list-images` | Validate image |\n| 2 | describe-machine-spec | `aliyun eas describe-machine-spec` | Validate GPU type |\n| 3 | create-service | `aliyun eas create-service` | Create service |\n| 4 | describe-service | `aliyun eas describe-service` | Check status (once) |\n| 5 | describe-service-endpoints | `aliyun eas describe-service-endpoints` | Get endpoints |\n\nExecute #1 and #2 ALWAYS, even if user provided the info.\n`describe-machine-spec` ≠ `list-resources`. `describe-service` ≠ `ListServices`.\n\n**3. Prohibited** — ❌ Reuse existing service\n❌ Write bash scripts (run CLI directly)\n❌ CPU+vLLM/SGLang ❌ `file://` in create-service\n❌ Skip mandatory APIs ❌ Change the service name the user specified\n❌ Poll describe-service in a loop (call once only)\n❌ Stop after writing/validating service.json — writing the JSON is\nNOT completing the task. You MUST run create-service (Step 6) then\ndescribe-service (Step 7). If resources were found, deploy them.\n\n**4. Autonomous Execution** — Do NOT ask user for info discoverable\nvia APIs. Do NOT ask \"should I proceed?\" Execute directly.\nTimeout? Retry with `--read-timeout 60`. Error? Inform user and CONTINUE.\nMissing param? Pick reasonable default.\nIf any pre-check or resource discovery step fails, log the failure\nand continue to the next step. Only STOP for the specific conditions\nlisted in Self-Verify Checkpoints (duplicate service name, missing\nNLB/GW/dedicated resource group).\n\n**5. Self-Verify Checkpoints:**\n```\nBefore Step 2: Did Step 1.5 confirm no duplicate service name?\n  If duplicate → STOP, inform user, do NOT proceed.\nBefore Step 5: Have I run list-images AND describe-machine-spec?\n  If NO → STOP and run them NOW.\nBefore Step 6: Did Step 1.5 confirm no duplicate service name?\n  If duplicate exists → STOP, inform user, do NOT proceed.\nStep 4 resources: If NLB/GW/Resource Group not found → inform user and STOP.\n  Do NOT block or attempt workarounds.\nAfter Step 7: Did I call describe-service once and report the status?\n```\n\n**6. Run CLI commands DIRECTLY** — Use `execute_shell_command` to run\neach aliyun CLI command one at a time. Do NOT write bash scripts,\ndeployment scripts, or shell files. Do NOT use `retry_command()`\nor any wrapper functions. Each command = one direct execution.\n\n---\n\n## Pre-checks\n\n```bash\n# Install or upgrade Aliyun CLI to >= 3.3.3 (required baseline), then verify.\ncurl -fsSL https://aliyuncli.alicdn.com/install.sh | bash\naliyun version   # must report >= 3.3.3; re-run install.sh to upgrade if lower\n\n# Generate the per-session trace id once (see Observability section) and build\n# the unified user-agent. Pass it via --user-agent on every CLI command.\nSESSION_ID=$(openssl rand -hex 16)\nUA=\"AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy/${SESSION_ID}\"\naliyun plugin update\naliyun configure set --auto-plugin-install true\n```\n\n**⚠️ MANDATORY: Install and update required plugins BEFORE proceeding:**\n```bash\naliyun plugin update\naliyun plugin install aiworkspace --force\naliyun plugin install eas --force\n```\n\n**Verify plugins are installed:**\n```bash\naliyun plugin list 2>/dev/null | grep -E \"aiworkspace|eas\"\n```\n\nIf either plugin is missing after install, retry with:\n```bash\naliyun plugin install <plugin-name> --force\n```\n\nSee [CLI Guide](references/cli-installation-guide.md).\nNever read/echo AK/SK. Timeout? Retry with `--read-timeout 60`.\n\n**⚠️ MANDATORY CHECKPOINT: After pre-checks, you MUST proceed to\nStep 1 regardless of any warnings during plugin installation.\nPlugin install failures are non-blocking — the plugins may already\nbe installed. NEVER stop execution at the pre-check stage.**\n\n---\n\n## Observability\n\nAll CLI, SDK, and Terraform calls MUST carry a unified user-agent (UA) so\nrequests trace back to this skill and one session.\n\n**UA template declaration (placeholder form):**\n\n```bash\n--user-agent AlibabaCloud-Agent-Skills/{SKILL_NAME}/{session-id}\n```\n\n- `{SKILL_NAME}` — fixed identifier: `alibabacloud-pai-eas-service-deploy`\n- `{session-id}` — 32-char lowercase hex (128-bit), generated **once per session**\n\n**session-id rule:** Generate it once before any call via\n`SESSION_ID=$(openssl rand -hex 16)`; reuse the **same** value for **every**\nCLI (`--user-agent`), SDK (client UA), and Terraform (`ALIBABACLOUDSTACK_UA` /\nprovider `ua`) call so all requests share one trace id. Do NOT regenerate\nbetween steps or hardcode it.\n\n```bash\nSESSION_ID=$(openssl rand -hex 16)\nUA=\"AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy/${SESSION_ID}\"\n# Pass on every command, e.g.:\naliyun eas describe-service --cluster-id <region> --service-name <service> --user-agent \"$UA\"\n```\n\n---\n\n## Step 1: Collect Parameters\n\n| Param | Required | Default |\n|-------|----------|---------|\n| RegionId | Yes | - |\n| Service Name | Yes | - |\n| Workspace ID | No | Auto-select |\n| Image URI | Yes | - |\n| Instance Type | Yes | - |\n| Replicas | No | 1 |\n| Port | No | 8000 |\n| OSS Path | No | - |\n\n**Service name**: lowercase/digits/underscores only. No hyphens. 3-63 chars.\n**IMPORTANT**: Use the EXACT service name the user specifies. Do NOT rename.\nIf the user specifies a prefix (e.g. \"starts with skill_qwen_\"), generate a random suffix of 6 digits (e.g. `skill_qwen_482917`).\n\n**Set profile region** — Set the CLI profile region to match the\ndeployment region. This avoids \"Region mismatch\" errors when\n`--cluster-id` differs from the profile's default region:\n```bash\naliyun configure set --region <region>\n```\n\n**Workspace ID**: Required in `metadata.workspace_id`. If user does not\nspecify a workspace, query available workspaces and pick one:\n```bash\naliyun aiworkspace list-workspaces --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Workspaces[] | select(.Status == \"ENABLED\") | {WorkspaceId, WorkspaceName}'\n```\nIf multiple workspaces exist, list them and let the user choose.\nIf only one exists, use it directly.\n\n## Step 1.5: Check for Duplicate Service Name\n\n```bash\naliyun eas list-services --region <region> --cluster-id <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.ServiceList[] | select(.ServiceName == \"<name>\") | {ServiceName, Status}'\n```\n\n**If a service with the same name already exists → STOP and inform\nthe user: \"A service named <name> already exists (Status: <status>).\nPlease choose a different name.\" Do NOT delete or reuse it.**\n\n**If no duplicate → proceed to Step 2.**\n\n## Step 2: ListImages (🚧 BLOCKING GATE — NEVER SKIP)\n\nExecute even if user provided image URI. Purpose = VALIDATION.\n\n**⚠️ If you see \"parse error\" or \"Exit Code 4\", the plugin\nfailed to install. You MUST retry with explicit install:**\n```bash\naliyun plugin install aiworkspace --force\n```\nThen retry the list-images command. Do NOT skip this step.\n\n```bash\naliyun aiworkspace list-images --region <region> --verbose true \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Images[] | {ImageId, ImageUri, ImageCategory}' > /tmp/eas_images.json\necho \"Saved $(jq length /tmp/eas_images.json) images\"\n```\n\n**If still fails after plugin reinstall, retry with timeout:**\n```bash\naliyun aiworkspace list-images --region <region> --verbose true \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --read-timeout 60 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Images[] | {ImageId, ImageUri, ImageCategory}' > /tmp/eas_images.json\necho \"Saved $(jq length /tmp/eas_images.json) images\"\n```\nSee [Model-Image](references/model-image-matching.md).\n**This output is REQUIRED by Step 5. Do NOT skip.**\n**❌ NEVER skip this step saying \"user already provided the image\".**\n\n## Step 3: describe-machine-spec (🚧 BLOCKING GATE — NEVER SKIP)\n\nExecute even if user specified instance type. NOT `list-resources`.\n\n**⚠️ If this command fails, retry with `--read-timeout 60`.\nNEVER proceed to Step 5 without /tmp/eas_specs.json existing.**\n\n```bash\naliyun eas describe-machine-spec --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.InstanceTypes[] | select(.GPU > 0) | {InstanceType, CPU, GPU, Memory}' \\\n  > /tmp/eas_specs.json\necho \"Available GPU specs:\"; cat /tmp/eas_specs.json\n```\nCPU→GPU auto-switch: If vLLM/SGLang + CPU, silently pick GPU. Do NOT ask.\n**This output is REQUIRED by Step 5. Do NOT skip.**\n\n## Step 4: Network & Resource Config\n\n| Type | VPC | Config |\n|------|-----|--------|\n| Shared | No | (default, no networking fields) |\n| Dedicated GW | Yes | `networking.gateway` + `cloud.networking` |\n| NLB | Yes | `networking.nlb` + `cloud.networking` |\n\n**⚠️ If a required resource does not exist → STOP and inform the user.\nDo NOT block or attempt workarounds. This is a valid outcome.**\n\n**Dedicated Gateway** — Call `list-gateway`. If no gateway exists →\ninform user and STOP. Otherwise call `describe-gateway` to get\nVPC/VSwitch, then query security group under that VPC.\nIf no security group found → inform user and STOP.\n```bash\naliyun eas list-gateway --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\nIf gateway found, get details:\n```bash\naliyun eas describe-gateway --region <region> --cluster-id <region> \\\n  --gateway-id <gateway_id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\nExtract VPC and comma-separated VSwitch ID:\n```bash\naliyun eas describe-gateway --region <region> --cluster-id <region> \\\n  --gateway-id <gateway_id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{vpc_id: .LoadBalancerList[0].VpcId, vswitch_id: (.LoadBalancerList[0].VSwitchIds | join(\",\"))}'\n```\n\n**NLB** — Requires VPC/VSwitch/SecurityGroup. If user does not provide\nthem, query via APIs. If any required resource not found → inform\nuser and STOP.\n**⚠️ NLB requires ≥2 VSwitches across different availability zones.**\nUse comma-separated format: `\"vswitch_id\": \"vsw-zone-a,vsw-zone-b\"`.\n**⚠️ NLB Plugin Bug (aliyun-cli-eas v0.2.0):** If create-service with\nNLB config returns 400 with `'vswitch can not be null'` or\n`'vpcId, vswId and securityGroupId are required'`, this is a known\nCLI plugin bug (not a resource issue). **Fallback strategy:**\n1. Retry create-service with NLB config once more (max 2 attempts).\n2. If both fail → Remove `networking.nlb` and `cloud.networking` from\n   service.json, redeploy with shared gateway.\n3. Inform user: \"NLB config failed due to CLI plugin limitation.\n   Deployed with shared gateway instead.\"\n\n**EAS Dedicated Resource Group** — Call `list-resources`.\nFilter for `ResourceType == \"Dedicated\"` and `Status == \"ResourceReady\"`.\n```bash\naliyun eas list-resources --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Resources[] | select(.ResourceType == \"Dedicated\" and .Status == \"ResourceReady\") | {ResourceId, ResourceType, Status}'\n```\n- If exists → Set `\"metadata\": {\"resource\": \"<ResourceId>\"}`.\n  Do NOT set `cloud.computing`.\n- If NOT exists → Inform the user and STOP.\n  Do NOT fall back to public resource group.\n\n## Step 5: Build Service JSON\n\n**⚠️ BEFORE building JSON, you MUST read these reference files:**\n- `references/config-patterns.md` — Complete JSON templates for all 8 patterns\n- `references/config-schema.md` — Field descriptions and validation rules\n- `references/storage-mount.md` — OSS/NAS mount configuration details\n- `references/network-config.md` — NLB/Gateway network configuration details\n\n**⚠️ HARD GATE: Before writing service.json, VERIFY these files\nexist and have content. If either is missing → STOP and run\nthat Step NOW.**\n```\ntest -s /tmp/eas_images.json || echo \"MISSING: Run Step 2 NOW\"\ntest -s /tmp/eas_specs.json || echo \"MISSING: Run Step 3 NOW\"\n```\n\n**⚠️ JSON format rules:**\n- Allowed top-level keys: `metadata`, `containers`, `storage`, `cloud`, `autoscaler`, `networking`\n- ❌ NEVER use as top-level keys: `spec`, `ServiceName`, `Image`, `Cpu`, `Memory`, `Gpu`, `processor_path`, `resourceGroupId`, `instance`, `port`, `command`, `access`\n- ❌ FORBIDDEN fields: `processor_path`, `resourceGroupId`, `spec`, `access`\n- `metadata.name` = service name, `metadata.workspace_id` = workspace (REQUIRED)\n- `containers[].image` = image URI, `containers[].command` = start command, `containers[].port` = port\n- `cloud.computing.instance_type` = instance type (MANDATORY for shared gateway)\n\n### Quick Reference — JSON Skeletons\n\nBelow are minimal skeletons. **Read `references/config-patterns.md` for\ncomplete templates with all fields and examples.**\n\n**Base (Shared Gateway):**\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}],\n \"cloud\":{\"computing\":{\"instance_type\":\"<type>\"}}}\n```\n\n**+ OSS** → add `\"storage\":[{\"mount_path\":\"/dir\",\"oss\":{\"path\":\"oss://<b>/<p>/\",\"readOnly\":true}}]`\n**+ Autoscaling** → add `\"autoscaler\":{\"min\":1,\"max\":4,\"scaleStrategies\":[{\"metricName\":\"qps\",\"threshold\":20}]}`\n**+ Health Check** → add `startup_check` to `containers[]` (see config-patterns.md Pattern 4)\n\n**NLB** — full template (read `references/network-config.md` for details):\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}],\n \"cloud\":{\"computing\":{\"instance_type\":\"<type>\"},\n          \"networking\":{\"vpc_id\":\"<vpc>\",\"vswitch_id\":\"<vsw1>,<vsw2>\",\"security_group_id\":\"<sg>\"}},\n \"networking\":{\"nlb\":[{\"id\":\"default\",\"listener_port\":<p>,\"netType\":\"intranet\"}]}}\n```\n⚠️ `vswitch_id` must be **comma-separated with ≥2 VSwitches across different zones**\n\n**Dedicated Resource Group** — `\"metadata.resource\"` instead of `cloud.computing`:\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"resource\":\"<res_id>\",\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}]}\n```\n\n**Dedicated Gateway** — `networking.gateway` + `cloud.networking`:\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}],\n \"networking\":{\"gateway\":\"<gw_id>\"},\n \"cloud\":{\"computing\":{\"instance_type\":\"<type>\"},\n          \"networking\":{\"vpc_id\":\"<vpc>\",\"vswitch_id\":\"<vsw1>,<vsw2>\",\"security_group_id\":\"<sg>\"}}}\n```\n⚠️ `vswitch_id` comma-separated if gateway returns multiple VSwitches\n\n### Validate Before Writing\n```bash\njq -r '.[] | select(.ImageUri | contains(\"vllm\")) | .ImageUri' /tmp/eas_images.json\njq -r '.[] | select(.InstanceType == \"<type>\") | .InstanceType' /tmp/eas_specs.json\n```\n**➡️ After service.json validates, IMMEDIATELY go to Step 6 — a validated JSON is not a deployment.**\n\n## Step 6: Create Service (MANDATORY)\n\n**🔴 CONFIRM: Did Step 1.5 confirm no duplicate service name?\nIf a service with this name already exists → STOP. Inform the user\nand do NOT proceed with create-service.**\n**Use `$(cat service.json)` NOT `file://service.json`.**\n**Run this DIRECTLY via execute_shell_command, do NOT write a bash script.**\n\n```bash\naliyun eas create-service --region <region> \\\n  --body \"$(cat service.json)\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n**409 Conflict** → Service already exists. Inform the user and STOP.\n**400 BadRequest** with `'vswitch can not be null'` or\n`'vpcId, vswId and securityGroupId are required'` → NLB CLI plugin\nbug (see Step 4 fallback). Remove `networking.nlb` and\n`cloud.networking` from service.json and retry.\n\n## Step 7: Verify Deployment\n\n**Call describe-service ONCE to check the current status. Do NOT poll.\nDo NOT loop. Do NOT wait for Running.**\n\n```bash\naliyun eas describe-service --region <region> --cluster-id <region> \\\n  --service-name <name> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{Status, ServiceName, ServiceId}'\n```\n\n**Report whatever status you get (Running, Waiting, Creating, etc.)\nand proceed to Step 8 immediately. create-service returning 200 = success.**\n\n## Step 8: Report Result (MANDATORY)\n\n**Get endpoint info via DescribeServiceEndpoint:**\n```bash\naliyun eas describe-service-endpoints --region <region> --cluster-id <region> \\\n  --service-name <name> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{AccessToken, Endpoints: [.Endpoints[] | {\n    Type: .EndpointType, Port: .Port,\n    InternetEndpoints: .InternetEndpoints,\n    IntranetEndpoints: .IntranetEndpoints\n  }]}'\n```\n\n**Use the status from Step 7 and the endpoints above to report.**\n\n**Copy the ENTIRE output into your final response. Format:**\n```\nDeployment Summary\n==================\nService Name: <name>\nStatus: <from Step 7>\n\nEndpoints:\n- <EndpointType>:\n    InternetEndpoint: <url or null>\n    IntranetEndpoint: <url or null>\n    Port: <port or 0>\n\nService Invocation Examples:\n  curl <internet-endpoint>/api/predict/<name> \\\n    -H \"Authorization: <AccessToken>\"\n  curl <intranet-endpoint>/api/predict/<name> \\\n    -H \"Authorization: <AccessToken>\"\n  curl <nlb-domain>:<listener_port>/api/predict/<name> \\\n    -H \"Authorization: <AccessToken>\"\n```\n\n**`InternetEndpoint` and `IntranetEndpoint` MUST appear in your\nresponse, even if null.** If null: `(not available for this network type)`\n\n**Always include a service invocation example using the AccessToken\nand endpoint URL.**\n\n**Success criteria: create-service returning 200 with ServiceId =\nsuccess. Any status (Running, Waiting, Creating) is acceptable.**\n\n## References (read when needed)\n\n| Doc | When to Read |\n|-----|-------------|\n| [Config Patterns](references/config-patterns.md) | **Step 5** — Complete JSON templates for all 8 patterns |\n| [Config Schema](references/config-schema.md) | **Step 5** — Field descriptions and validation rules |\n| [Storage Mount](references/storage-mount.md) | **Step 5** — OSS/NAS mount details |\n| [Network Config](references/network-config.md) | **Step 4/5** — NLB/Gateway config details |\n| [Model-Image](references/model-image-matching.md) | **Step 2** — Image selection guide |\n| [Related APIs](references/related-apis.md) | **Any step** — CLI command reference |\n| [Workflow](references/deployment-workflow.md) | Overview — Full deployment flow |\n| [CLI Guide](references/cli-installation-guide.md) | Pre-checks — Plugin install |\n| [RAM Policies](references/ram-policies.md) | Pre-checks — Required permissions |\n| [Service Features](references/service-features.md) | Step 5 — Advanced features |\n\nFile v0.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-pai-eas-service-deploy\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1783929570842\n}\n\nFile v0.0.1:references/acceptance-criteria.md\n\n# Acceptance Criteria: alibabacloud-pai-eas-service-deploy\n\n**Scenario**: PAI-EAS Service Deployment\n**Purpose**: Skill test acceptance criteria\n\n**Table of Contents**\n- [CLI Command Patterns](#correct-cli-command-patterns)\n- [Service Config Validation](#service-config-validation)\n- [Authentication Patterns](#authentication-patterns)\n- [Parameter Confirmation Requirements](#parameter-confirmation-requirements)\n- [Resource Cleanup](#resource-cleanup)\n\n---\n\n# Correct CLI Command Patterns\n\n## 1. EAS Service Operations\n\n### ✅ Correct: Create Service\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\" --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n### ❌ Wrong: Missing --user-agent\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\"\n```\n\n### ❌ Wrong: Using API format instead of plugin mode\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\"\n```\n\n## 2. AIWorkSpace Operations\n\n### ✅ Correct: List Images\n\n```bash\naliyun aiworkspace list-images --verbose true --labels 'system.official=true,system.supported.eas=true' --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n### ❌ Wrong: Labels format error\n\n```bash\naliyun aiworkspace list-images --verbose true --labels 'system.official=true' --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n## 3. OSS Operations\n\n### ✅ Correct: List Buckets\n\n```bash\nossutil ls\n```\n\n### ✅ Correct: List Objects\n\n```bash\nossutil ls oss://bucket-name/path/\n```\n\n### ❌ Wrong: Missing oss:// prefix\n\n```bash\nossutil ls bucket-name/path/\n```\n\n## 4. VPC Operations\n\n### ✅ Correct: Query VPC\n\n```bash\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --vpc-id vpc-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n### ❌ Wrong: Missing user-agent\n\n```bash\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --vpc-id vpc-xxx\n```\n\n---\n\n# Service Config Validation\n\n## 1. metadata Config\n\n### ✅ Correct: Service Name Format\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my-vllm-service\",\n    \"instance\": 1\n  }\n}\n```\n\n### ❌ Wrong: Service name contains uppercase letters\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"My-VLLM-Service\",\n    \"instance\": 1\n  }\n}\n```\n\n### ❌ Wrong: Service name contains special characters\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my.vllm.service\",\n    \"instance\": 1\n  }\n}\n```\n\n## 2. containers Config\n\n### ✅ Correct: Container Config\n\n```json\n{\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000,\n    \"script\": \"vllm serve /models --port 8000\"\n  }]\n}\n```\n\n### ❌ Wrong: Missing port config\n\n```json\n{\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"script\": \"vllm serve /models --port 8000\"\n  }]\n}\n```\n\n## 3. storage Config\n\n### ✅ Correct: OSS Mount\n\n```json\n{\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"oss://bucket/models/\",\n      \"readOnly\": true\n    }\n  }]\n}\n```\n\n### ❌ Wrong: OSS path missing trailing slash\n\n```json\n{\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"oss://bucket/models\",\n      \"readOnly\": true\n    }\n  }]\n}\n```\n\n### ❌ Wrong: Missing oss:// prefix\n\n```json\n{\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"bucket/models/\",\n      \"readOnly\": true\n    }\n  }]\n}\n```\n\n## 4. cloud Config\n\n### ✅ Correct: Public Resource Group\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instance_type\": \"ecs.gn7-c12g1.12xlarge\"\n    }\n  }\n}\n```\n\n### ✅ Correct: Multi-spec Instances\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instances\": [\n        {\"type\": \"ecs.gn7-c12g1.12xlarge\"},\n        {\"type\": \"ecs.gn8is.2xlarge\"}\n      ]\n    }\n  }\n}\n```\n\n### ❌ Wrong: Wrong field name\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instanceType\": \"ecs.gn7-c12g1.12xlarge\"\n    }\n  }\n}\n```\n\n## 5. networking Config\n\n### ✅ Correct: Dedicated Gateway\n\n```json\n{\n  \"networking\": {\n    \"gateway\": \"gw-xxx\"\n  }\n}\n```\n\n### ✅ Correct: NLB\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [{\n      \"id\": \"default\",\n      \"listener_port\": 9000,\n      \"netType\": \"intranet\"\n    }]\n  }\n}\n```\n\n### ❌ Wrong: NLB port is 8080 (not allowed)\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [{\n      \"id\": \"default\",\n      \"listener_port\": 8080,\n      \"netType\": \"intranet\"\n    }]\n  }\n}\n```\n\n---\n\n# Authentication Patterns\n\n## ✅ Correct: Using CredentialClient (Python SDK)\n\n```python\nfrom alibabacloud_credentials.client import Client as CredentialClient\nfrom alibabacloud_eas20210701.client import Client as EasClient\nfrom alibabacloud_tea_openapi import models as open_api_models\n\ncredential = CredentialClient()\nconfig = open_api_models.Config(credential=credential)\nconfig.region_id = \"cn-hangzhou\"\nconfig.user_agent = \"AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\"\nclient = EasClient(config)\n```\n\n## ❌ Wrong: Hardcoded AK/SK\n\n```python\nconfig = open_api_models.Config(\n    access_key_id=\"LTAIxxx\",\n    access_key_secret=\"xxx\"\n)\n```\n\n---\n\n# Parameter Confirmation Requirements\n\n## ✅ Correct: All user parameters must be confirmed\n\nThe following parameters must be confirmed before deployment:\n- RegionId (region)\n- Service name\n- Workspace ID\n- Image URI\n- Instance type\n- OSS path (if mounting)\n- Gateway ID (if using dedicated gateway)\n- VPC/VSwitch/Security group (if using ALB/NLB)\n\n## ❌ Wrong: Using default values without confirmation\n\n```bash\n# Wrong: Using default region without asking user\naliyun eas create-service --region cn-hangzhou ...\n```\n\n---\n\n# Resource Cleanup\n\n## ✅ Correct: Cleanup after deployment failure\n\n```bash\naliyun eas delete-service \\\n  --cluster-id cn-hangzhou \\\n  --service-name <service-name> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n## ❌ Wrong: Not cleaning up failed services\n\nFailure to delete after service creation failure leads to resource waste.\n\nFile v0.0.1:references/api-reference.md\n\n# API Reference\n\n## API Response Structures\n\n**Alibaba Cloud API response structures are inconsistent — pay attention when using jq:**\n\n| API | jq Path | Structure |\n|-----|---------|-----------|\n| `AIWorkSpace ListWorkspaces` | `.Workspaces[]` | single-level |\n| `AIWorkSpace ListImages` | `.Images[]` | single-level |\n| `eas DescribeMachineSpec` | `.InstanceMetas[]` | single-level |\n| `eas list-gateway` | `.Gateways[]` | single-level |\n| `eas ListResources` | `.Resources[]` | single-level |\n| `eas DescribeService` | `.Service` | single object |\n| `eas describe-service-event` | `.Events[]` | single-level |\n| `vpc DescribeVpcs` | `.Vpcs.Vpc[]` | ⚠️ nested (two-level) |\n| `vpc DescribeVSwitches` | `.VSwitches.VSwitch[]` | ⚠️ nested (two-level) |\n| `ecs DescribeSecurityGroups` | `.SecurityGroups.SecurityGroup[]` | ⚠️ nested (two-level) |\n| `nlb ListLoadBalancers` | `.LoadBalancers[]` | single-level |\n\n## jq Examples\n\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Workspaces[] | \"\\(.WorkspaceId)\\t\\(.WorkspaceName)\"'\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Gateways[] | \"\\(.GatewayId)\\t\\(.GatewayName)\"'\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Vpcs.Vpc[] | \"\\(.VpcId)\\t\\(.VpcName)\"'\n```\n\n## CLI Command Reference\n\n### Parameter Naming Rules\n\n| Command type | Parameter | Example |\n|--------------|-----------|---------|\n| List / create | `--region` | `ListServices`, `CreateService` |\n| Target a single service | `--cluster-id` | `DescribeService`, `DeleteService` |\n\n### Common Commands\n\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun aiworkspace list-images --verbose true --labels 'system.official=true,system.supported.eas=true' --page-size 100 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas describe-machine-spec --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas list-resources --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas describe-gateway --cluster-id cn-hangzhou --gateway-id gw-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\" --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas describe-service --cluster-id cn-hangzhou --service-name my_service --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n## Permission List\n\nSee [RAM Policies](ram-policies.md).\n\n## Common GPU Instance Types\n\n| Instance type | GPU | CPU | Memory | Use case |\n|---------------|-----|-----|--------|----------|\n| `ecs.gn6i-c4g1.xlarge` | 1× T4 | 4 | 16Gi | Small model inference |\n| `ecs.gn6i-c8g1.2xlarge` | 1× T4 | 8 | 32Gi | Medium model |\n| `ecs.gn7-c12g1.12xlarge` | 4× A10 | 12 | 192Gi | Large model inference |\n\nFile v0.0.1:references/cli-installation-guide.md\n\n# Aliyun CLI Installation & Configuration Guide\n\nComplete guide for installing and configuring Aliyun CLI.\n\n> **Aliyun CLI 3.3.3+**: Supports installing and using all published Alibaba Cloud product plugins. Make sure to upgrade to 3.3.3 or later for full plugin ecosystem coverage.\n\n**Table of Contents**\n- [Installation](#installation)\n- [Configuration](#configuration)\n- [Verification](#verification)\n- [Security Best Practices](#security-best-practices)\n- [Troubleshooting](#troubleshooting)\n- [Advanced Configuration](#advanced-configuration)\n- [Next Steps](#next-steps)\n- [References](#references)\n\n## Installation\n\n### macOS\n\n**Using Homebrew (Recommended)**\n```bash\nbrew install aliyun-cli\n# Upgrade to latest\nbrew upgrade aliyun-cli\n\n# Verify version (>= 3.3.3)\naliyun version\n```\n\n**Using Binary**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz\n\n# Extract\ntar -xzf aliyun-cli-macosx-latest-amd64.tgz\n\n# Move to PATH\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n### Linux\n\n**Debian/Ubuntu**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**CentOS/RHEL**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**ARM64 Architecture**\n```bash\n# Download ARM64 version\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-arm64.tgz\nsudo mv aliyun /usr/local/bin/\n```\n\n### Windows\n\n**Using Binary**\n1. Download from: https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\n2. Extract the ZIP file\n3. Add the directory to your PATH environment variable\n4. Open new Command Prompt or PowerShell\n5. Verify: `aliyun version`\n\n**Using PowerShell**\n```powershell\n# Download\nInvoke-WebRequest -Uri \"https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\" -OutFile \"aliyun-cli.zip\"\n\n# Extract\nExpand-Archive -Path aliyun-cli.zip -DestinationPath C:\\aliyun-cli\n\n# Add to PATH (requires admin privileges)\n$env:Path += \";C:\\aliyun-cli\"\n[Environment]::SetEnvironmentVariable(\"Path\", $env:Path, [System.EnvironmentVariableTarget]::Machine)\n\n# Verify\naliyun version\n```\n\n## Configuration\n\n### Quick Start\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id <your-access-key-id> \\\n  --access-key-secret <your-access-key-secret> \\\n  --region cn-hangzhou\n```\n\nAll `aliyun configure` commands support non-interactive flags, which is the recommended approach —\nit works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts.\n\n**Where to Get Access Keys**\n\n1. Log in to Aliyun Console: https://ram.console.aliyun.com/\n2. Navigate to: AccessKey Management\n3. Create a new AccessKey pair\n4. Save the secret immediately — it's only shown once\n\n### Configuration Modes\n\nAliyun CLI supports 6 authentication modes. All examples below use non-interactive flags.\n\n#### 1. AK Mode (Access Key)\n\nMost common mode for personal accounts and scripts.\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nConfiguration is stored in `~/.aliyun/config.json`:\n\n```json\n{\n  \"current\": \"default\",\n  \"profiles\": [\n    {\n      \"name\": \"default\",\n      \"mode\": \"AK\",\n      \"access_key_id\": \"LTAI5tXXXXXXXX\",\n      \"access_key_secret\": \"8dXXXXXXXXXXXXXXXXXXXXXXXX\",\n      \"region_id\": \"cn-hangzhou\",\n      \"output_format\": \"json\",\n      \"language\": \"en\"\n    }\n  ]\n}\n```\n\n#### 2. StsToken Mode (Temporary Credentials)\n\nFor short-lived access (tokens expire in 1-12 hours).\n\n```bash\naliyun configure set \\\n  --mode StsToken \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --sts-token v1.0:XXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nUse cases: CI/CD pipelines, temporary access for external contractors, cross-account access.\n\n#### 3. RamRoleArn Mode (Assume RAM Role)\n\nAssume a RAM role for elevated or cross-account access.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArn \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --ram-role-arn acs:ram::123456789012:role/AdminRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\nUse cases: cross-account resource access, temporary elevated privileges, role-based access control.\n\n#### 4. EcsRamRole Mode (ECS Instance RAM Role)\n\nUse the RAM role attached to an ECS instance — no credentials needed.\n\n```bash\naliyun configure set \\\n  --mode EcsRamRole \\\n  --ram-role-name MyEcsRole \\\n  --region cn-hangzhou\n```\n\nRequirements: must be running on an ECS instance with a RAM role attached.\n\nUse cases: scripts and automation running on ECS instances.\n\n#### 5. RsaKeyPair Mode (RSA Key Pair)\n\nUse RSA key pair for authentication (generate key pair in Aliyun Console first).\n\n```bash\naliyun configure set \\\n  --mode RsaKeyPair \\\n  --private-key /path/to/private-key.pem \\\n  --key-pair-name my-key-pair \\\n  --region cn-hangzhou\n```\n\n#### 6. RamRoleArnWithEcs Mode (ECS + RAM Role)\n\nCombine ECS instance role with RAM role assumption for cross-account access from ECS.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArnWithEcs \\\n  --ram-role-name MyEcsRole \\\n  --ram-role-arn acs:ram::123456789012:role/TargetRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\n### Environment Variables\n\n**Highest priority** - overrides config file\n\n**Access Key Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**STS Token Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_SECURITY_TOKEN=your_sts_token\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**ECS RAM Role Mode**\n```bash\nexport ALIBABA_CLOUD_ECS_METADATA=role_name\n```\n\n**Use Case**:\n- CI/CD pipelines\n- Docker containers\n- Temporary credential override\n\n### Managing Multiple Profiles\n\n**Create Named Profiles**\n\n```bash\naliyun configure set --profile projectA \\\n  --mode AK \\\n  --access-key-id LTAI5tAAAAAAAA \\\n  --access-key-secret 8dAAAAAAAAAAAAAAAAAAAAAAAA \\\n  --region cn-hangzhou\n\naliyun configure set --profile projectB \\\n  --mode AK \\\n  --access-key-id LTAI5tBBBBBBBB \\\n  --access-key-secret 8dBBBBBBBBBBBBBBBBBBBBBBBB \\\n  --region cn-shanghai\n```\n\n**Use Specific Profile**\n\n```bash\naliyun ecs describe-instances --profile projectA\n\nexport ALIBABA_CLOUD_PROFILE=projectA\naliyun ecs describe-instances   # Uses projectA\n```\n\n**List and Switch Profiles**\n\n```bash\naliyun configure list                      # List all profiles\naliyun configure set --current projectA    # Switch default profile\n```\n\n### Credential Priority\n\nCredentials are loaded in this order (first found wins):\n\n1. **Command-line flag**: `--profile <name>`\n2. **Environment variable**: `ALIBABA_CLOUD_PROFILE`\n3. **Environment credentials**: `ALIBABA_CLOUD_ACCESS_KEY_ID`, etc.\n4. **Configuration file**: `~/.aliyun/config.json` (current profile)\n5. **ECS Instance RAM Role**: If running on ECS with attached role\n\n## Verification\n\n### Test Authentication\n\n```bash\n# Basic test - list regions\naliyun ecs describe-regions\n\n# Expected output: JSON array of regions\n```\n\n**If successful**, you'll see:\n```json\n{\n  \"Regions\": {\n    \"Region\": [\n      {\n        \"RegionId\": \"cn-hangzhou\",\n        \"RegionEndpoint\": \"ecs.cn-hangzhou.aliyuncs.com\",\n        \"LocalName\": \"East China 1 (Hangzhou)\"\n      },\n      ...\n    ]\n  },\n  \"RequestId\": \"...\"\n}\n```\n\n**If failed**, you'll see error messages:\n- `InvalidAccessKeyId.NotFound` - Wrong Access Key ID\n- `SignatureDoesNotMatch` - Wrong Access Key Secret\n- `InvalidSecurityToken.Expired` - STS token expired (for StsToken mode)\n- `Forbidden.RAM` - Insufficient permissions\n\n### Debug Configuration\n\n```bash\n# Show current configuration\naliyun configure get\n\n# Test with debug logging\naliyun ecs describe-regions --log-level=debug\n\n# Check credential provider\naliyun configure get mode\n```\n\n## Security Best Practices\n\n### 1. Use RAM Users (Not Root Account)\n\n❌ **Don't**: Use Aliyun root account credentials\n✅ **Do**: Create RAM users with specific permissions\n\n```bash\n# Create RAM user in console\n# Attach only necessary policies\n# Use RAM user's access keys\n```\n\n### 2. Principle of Least Privilege\n\nGrant only the minimum permissions needed:\n\n```bash\n# Example: Read-only ECS access\n# Attach policy: AliyunECSReadOnlyAccess\n```\n\n### 3. Rotate Access Keys Regularly\n\n```bash\n# Create new access key in RAM Console, then update configuration\naliyun configure set --access-key-id NEW_KEY --access-key-secret NEW_SECRET\n# Delete old access key from console\n```\n\n### 4. Use STS Tokens for Temporary Access\n\n```bash\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token XXXX --region cn-hangzhou\n```\n\n### 5. Use ECS RAM Roles When Possible\n\n```bash\naliyun configure set --mode EcsRamRole --ram-role-name MyRole --region cn-hangzhou\n```\n\n### 6. Never Commit Credentials\n\n```bash\n# Add to .gitignore\necho \"~/.aliyun/config.json\" >> .gitignore\n\n# Use environment variables in CI/CD instead\n```\n\n### 7. Secure Config File\n\n```bash\n# Restrict permissions\nchmod 600 ~/.aliyun/config.json\n```\n\n## Troubleshooting\n\n### Issue: Command Not Found\n\n```bash\n# Check installation\nwhich aliyun\n\n# Check PATH\necho $PATH\n\n# Reinstall or add to PATH\n```\n\n### Issue: Authentication Failed\n\n```bash\n# Verify configuration\naliyun configure get\n\n# Test with debug\naliyun ecs describe-regions --log-level=debug\n\n# Check credentials in console\n# Verify access key is active\n```\n\n### Issue: Permission Denied\n\n```bash\n# Error: Forbidden.RAM\n\n# Check RAM user permissions\n# Attach necessary policies in RAM console\n# Example: AliyunECSFullAccess for ECS operations\n```\n\n### Issue: STS Token Expired\n\n```bash\n# Error: InvalidSecurityToken.Expired\n\n# Reconfigure with new token\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token NEW_TOKEN --region cn-hangzhou\n```\n\n### Issue: Wrong Region\n\n```bash\n# Some resources may not exist in the specified region\n\n# Check available regions\naliyun ecs describe-regions\n\n# Update default region\naliyun configure set region cn-shanghai\n```\n\n## Advanced Configuration\n\n### Custom Endpoint\n\n```bash\n# Use custom or private endpoint\nexport ALIBABA_CLOUD_ECS_ENDPOINT=ecs-vpc.cn-hangzhou.aliyuncs.com\n```\n\n### Proxy Settings\n\n```bash\n# HTTP proxy\nexport HTTP_PROXY=http://proxy.example.com:8080\nexport HTTPS_PROXY=http://proxy.example.com:8080\n\n# No proxy for specific domains\nexport NO_PROXY=localhost,127.0.0.1,.aliyuncs.com\n```\n\n### Timeout Settings\n\n```bash\n# Connection timeout (default: 10s)\nexport ALIBABA_CLOUD_CONNECT_TIMEOUT=30\n\n# Read timeout (default: 10s)\nexport ALIBABA_CLOUD_READ_TIMEOUT=30\n```\n\n## Next Steps\n\nAfter installation and configuration:\n\n1. **Install plugins** for services you need (v3.3.3+ supports all published product plugins):\n   ```bash\n   aliyun plugin install --names ecs vpc rds\n\n   # List all available plugins\n   aliyun plugin list-remote\n   ```\n\n2. **Explore commands**:\n   ```bash\n   aliyun ecs --help\n   aliyun fc --help\n   ```\n\n3. **Read documentation**:\n   - [Command Syntax Guide](./command-syntax.md)\n   - [Global Flags Reference](./global-flags.md)\n   - [Common Scenarios](./common-scenarios.md)\n\n## References\n\n- Official Documentation: https://help.aliyun.com/zh/cli/\n- RAM Console: https://ram.console.aliyun.com/\n- Access Key Management: https://ram.console.aliyun.com/manage/ak\n- Plugin Repository: https://github.com/aliyun/aliyun-cli\n\nFile v0.0.1:references/config-examples.md\n\n# Service Configuration Examples\n\n**Contents**\n- [JSON Field Conventions](#json-field-conventions-important)\n- [Container Mode Configuration](#container-mode-configuration-important)\n- [Basic Configuration](#basic-configuration)\n- [Full Configuration](#full-configuration)\n- [Public Resource Group Configuration](#public-resource-group-configuration)\n- [Dedicated Resource Group Configuration](#dedicated-resource-group-configuration)\n- [ALB Gateway Configuration](#alb-gateway-configuration)\n- [NLB Configuration](#nlb-configuration)\n- [Autoscaling Configuration](#autoscaling-configuration)\n- [Storage Mount Configuration](#storage-mount-configuration)\n\n## ⚠️ JSON Field Conventions (Important)\n\n**The service name MUST be placed in the `metadata.name` field**, not at the top level:\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my-service\",    // ✅ Correct: service name goes here\n    \"instance\": 1\n  }\n}\n```\n\n**Incorrect examples:**\n\n```json\n{\n  \"service_name\": \"my-service\",  // ❌ Wrong: invalid field\n  \"name\": \"my-service\"           // ❌ Wrong: not inside metadata\n}\n```\n\n## Container Mode Configuration (Important)\n\nWhen deploying from an image, you MUST configure the `containers` field:\n\n```json\n{\n  \"metadata\": { \"name\": \"my-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"<image-uri>\",\n    \"port\": 8000,\n    \"command\": \"<startup command>\"\n  }],\n  \"storage\": [{ \"mount_path\": \"/model_dir\", \"oss\": { \"path\": \"oss://bucket/models/\" } }],\n  \"cloud\": { \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" } }\n}\n```\n\n**Key fields:**\n- `metadata.name` - service name (required)\n- `containers[].image` - image URI (required)\n- `containers[].port` - service port (required)\n- `containers[].command` - startup command (optional)\n\n**⚠️ Note:** Use the `containers` field; do NOT use `processor` or `processor_path`.\n\n## Basic Configuration\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"simple_service\",\n    \"instance\": 1\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" }\n  }\n}\n```\n\n## Full Configuration\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"myservice\",\n    \"instance\": 2,\n    \"workspace_id\": \"368951\",\n    \"disk\": \"30Gi\",\n    \"shm_size\": 100,\n    \"enable_grpc\": true\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000,\n    \"env\": [\n      {\"name\": \"NCCL_P2P_DISABLE\", \"value\": \"1\"}\n    ]\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6e-c12g1.12xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-xxx\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://my-bucket/models/llama-7b\", \"readOnly\": true }\n  }],\n  \"networking\": { \"gateway\": \"gw-xxx\" },\n  \"autoscaler\": {\n    \"min\": 1,\n    \"max\": 10,\n    \"scaleStrategies\": [{ \"metricName\": \"qps\", \"threshold\": 100 }]\n  }\n}\n```\n\n## Public Resource Group Configuration\n\n```json\n{\n  \"metadata\": { \"name\": \"public-resource-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" }\n  },\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://my-bucket/models/\" }\n  }]\n}\n```\n\n## Dedicated Resource Group Configuration\n\n```json\n{\n  \"metadata\": { \"name\": \"dedicated-resource-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" }\n  },\n  \"resource\": \"eas-r-xxx\",\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://my-bucket/models/\" }\n  }]\n}\n```\n\n## ALB Gateway Configuration\n\n```json\n{\n  \"metadata\": { \"name\": \"alb-gateway-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"{obtained from the gateway}\",\n      \"vswitch_id\": \"{obtained from the gateway}\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"networking\": { \"gateway\": \"gw-xxx\" }\n}\n```\n\n## NLB Configuration\n\n```json\n{\n  \"metadata\": { \"name\": \"nlb-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-xxx\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"networking\": {\n    \"nlb\": [{ \"id\": \"default\", \"listener_port\": 8080, \"netType\": \"intranet\" }]\n  }\n}\n```\n\n## Autoscaling Configuration\n\n```json\n{\n  \"autoscaler\": {\n    \"min\": 1,\n    \"max\": 10,\n    \"scaleStrategies\": [\n      { \"metricName\": \"qps\", \"threshold\": 100 },\n      { \"metricName\": \"cpu\", \"threshold\": 80 }\n    ]\n  }\n}\n```\n\n## Storage Mount Configuration\n\n```json\n{\n  \"storage\": [\n    {\n      \"mount_path\": \"/models\",\n      \"oss\": { \"path\": \"oss://my-bucket/models/\", \"readOnly\": true }\n    },\n    {\n      \"mount_path\": \"/data\",\n      \"nfs\": { \"server\": \"xxx.cn-hangzhou.nas.aliyuncs.com\", \"path\": \"/share\" }\n    },\n    {\n      \"mount_path\": \"/dataset\",\n      \"dataset\": { \"id\": \"d-xxx\", \"version\": \"v1\" }\n    }\n  ]\n}\n```\n\nFile v0.0.1:references/config-patterns.md\n\n# Complete Config Pattern Examples\n\nThis document contains 8 complete JSON config patterns for different deployment scenarios.\n\n## Config Pattern Decision Table\n\n| User Requirement | Pattern | Key Fields |\n|-----------------|---------|------------|\n| vLLM + OSS + Public Resource + Shared GW | Pattern 1 | `storage[].oss`, `cloud.computing` |\n| vLLM + Autoscaling | Pattern 2 | `autoscaler` (camelCase!) |\n| vLLM + NLB | Pattern 3 | `networking.nlb` |\n| SGLang + Health Check | Pattern 4 | `containers[].startup_check` |\n| ComfyUI + OSS | Pattern 5 | `storage[].oss` |\n| Custom Image / CPU→GPU Auto-switch | Pattern 6 | Only `containers[].image` |\n| EAS Resource Group | Pattern 7 | `metadata.resource` |\n| Dedicated Gateway | Pattern 8 | `networking.gateway`, `cloud.networking` |\n\n## Steps to Build JSON\n\n1. Select the best matching pattern based on user requirements\n2. Copy the JSON template for that pattern\n3. Replace actual values (service name, image URI, OSS path, instance type, etc.)\n4. If extra requirements exist (e.g. autoscaling + NLB), merge corresponding fields\n5. Save as `service.json`\n\n---\n\n## Pattern 1: vLLM + OSS Mount + Public Resource Group + Shared Gateway\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"qwen35_7b_prod\",\n    \"instance\": 1,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.13.0rc2.a8ec486.20260305pai-gpu\",\n    \"port\": 8000,\n    \"command\": \"vllm serve /model_dir --port 8000 --trust-remote-code\",\n    \"startup_check\": {\n      \"http_get\": {\"path\": \"/health\", \"port\": 8000},\n      \"initial_delay_seconds\": 120,\n      \"period_seconds\": 10,\n      \"failure_threshold\": 30\n    }\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/qwen2.5-0.5b-instruct/\", \"readOnly\": true }\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn7i-c16g1.4xlarge\" }\n  }\n}\n```\n\n---\n\n## Pattern 2: vLLM + Autoscaling\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"qwen_autoscaling_test\",\n    \"instance\": 1,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.13.0rc2.a8ec486.20260305pai-gpu\",\n    \"port\": 8000,\n    \"command\": \"vllm serve /model_dir --port 8000 --trust-remote-code\"\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/qwen2.5-0.5b-instruct/\", \"readOnly\": true }\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn7i-c16g1.4xlarge\" }\n  },\n  \"autoscaler\": {\n    \"min\": 1,\n    \"max\": 4,\n    \"scaleStrategies\": [\n      {\"metricName\": \"qps\", \"threshold\": 20}\n    ]\n  }\n}\n```\n\n---\n\n## Pattern 3: vLLM + NLB\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"qwen_nlb_test\",\n    \"instance\": 1,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.13.0rc2.a8ec486.20260305pai-gpu\",\n    \"port\": 8000,\n    \"command\": \"vllm serve /model_dir --port 8000 --trust-remote-code\"\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/qwen2.5-0.5b-instruct/\", \"readOnly\": true }\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn7i-c16g1.4xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-zone-a,vsw-zone-b\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"networking\": {\n    \"nlb\": [{ \"id\": \"default\", \"listener_port\": 8000, \"netType\": \"intranet\" }]\n  }\n}\n```\n\n---\n\n## Pattern 4: SGLang + Health Check\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"llama3_8b_api\",\n    \"instance\": 1,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/sglang:0.5.8-acclep1.2.1-gpu\",\n    \"port\": 8000,\n    \"command\": \"python -m sglang.launch_server --model-path /model_dir --host 0.0.0.0 --port 8000\",\n    \"startup_check\": {\n      \"http_get\": {\"path\": \"/health\", \"port\": 8000},\n      \"initial_delay_seconds\": 120,\n      \"period_seconds\": 10,\n      \"failure_threshold\": 30\n    }\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/llama3-8b-instruct/\", \"readOnly\": true }\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn7i-c16g1.4xlarge\" }\n  }\n}\n```\n\n---\n\n## Pattern 5: ComfyUI + OSS Mount\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"sdxl_inference\",\n    \"instance\": 1,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/comfyui:2.2-api\",\n    \"port\": 8000,\n    \"command\": \"python main.py --listen 0.0.0.0 --port 8000\",\n    \"startup_check\": {\n      \"http_get\": {\"path\": \"/\", \"port\": 8000},\n      \"initial_delay_seconds\": 60,\n      \"period_seconds\": 10,\n      \"failure_threshold\": 30\n    }\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://yqtest-model/sdxl-v1.0/\", \"readOnly\": true }\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn7i-c16g1.4xlarge\" }\n  }\n}\n```\n\n---\n\n## Pattern 6: vLLM + Small Model + GPU Instance (auto-switch from CPU when user requests CPU)\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"qwen_cpu_service\",\n    \"instance\": 2,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.13.0rc2.a8ec486.20260305pai-gpu\",\n    \"port\": 8000,\n    \"command\": \"vllm serve /model_dir --port 8000 --trust-remote-code\"\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/qwen2.5-0.5b-instruct/\", \"readOnly\": true }\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c4g1.xlarge\" }\n  }\n}\n```\n\n---\n\n## Pattern 7: EAS Resource Group Deployment\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my_vllm_service\",\n    \"instance\": 1,\n    \"resource\": \"eas-r-d29k8ytqxzxmqi7l0s\",\n    \"workspace_id\": \"<workspace_id>\",\n    \"gpu\": 1,\n    \"cpu\": 4,\n    \"memory\": 8000\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.13.0rc2.a8ec486.20260305pai-gpu\",\n    \"port\": 8000,\n    \"command\": \"vllm serve /model_dir --port 8000 --trust-remote-code\"\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/qwen2.5-0.5b-instruct/\", \"readOnly\": true }\n  }]\n}\n```\n\n---\n\n## Pattern 8: Dedicated Gateway Deployment\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my_gateway_service\",\n    \"instance\": 1,\n    \"workspace_id\": \"<workspace_id>\"\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.13.0rc2.a8ec486.20260305pai-gpu\",\n    \"port\": 8000,\n    \"command\": \"vllm serve /model_dir --port 8000 --trust-remote-code\"\n  }],\n  \"storage\": [{\n    \"mount_path\": \"/model_dir\",\n    \"oss\": { \"path\": \"oss://yqtest-model/qwen2.5-0.5b-instruct/\", \"readOnly\": true }\n  }],\n  \"networking\": {\n    \"gateway\": \"gw-48hmbdt00fi6x90gft\"\n  },\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn7i-c16g1.4xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"vpc-bp13kiflgde6v9dc9smc8\",\n      \"vswitch_id\": \"vsw-bp1bhmnwqdh1ta9z9klms,vsw-bp1lz95xtmjiwqcpq31ng\",\n      \"security_group_id\": \"sg-bp1e36bfv61nfy1yudyc\"\n    }\n  }\n}\n```\n\nFile v0.0.1:references/config-schema.md\n\n# Service Config Field Reference\n\n> This document lists all JSON config fields for PAI-EAS services.\n\n**Table of Contents**\n- [Config Structure Overview](#config-structure-overview)\n- [metadata (required)](#metadata-required)\n- [containers (required)](#containers-required)\n- [cloud (public resource group)](#cloud-public-resource-group)\n- [storage (mount)](#storage-mount)\n- [networking](#networking)\n- [autoscaler](#autoscaler)\n- [runtime](#runtime)\n- [features](#features)\n- [Full Example](#full-example)\n\n## Config Structure Overview\n\n```json\n{\n  \"metadata\": { ... },      // Service metadata (required)\n  \"containers\": [ ... ],    // Container config (required)\n  \"cloud\": { ... },         // Public resource group config\n  \"storage\": [ ... ],       // Storage mount\n  \"networking\": { ... },    // Network config\n  \"autoscaler\": { ... },    // Autoscaling\n  \"runtime\": { ... },       // Runtime config\n  \"features\": { ... }       // Feature config\n}\n```\n\n---\n\n## metadata (required)\n\nService metadata defining basic service information.\n\n| Field | Type | Required | Default | Description |\n|-------|------|----------|---------|-------------|\n| `name` | string | ✅ | - | Service name, lowercase letters/digits/underscores, 3-63 chars |\n| `instance` | int | ❌ | 1 | Number of replicas |\n| `workspace_id` | string | ❌ | - | Workspace ID |\n| `resource` | string | ❌ | - | Dedicated resource group ID (mutually exclusive with cloud.computing) |\n| `disk` | string | ❌ | - | Temp disk size, e.g. \"30Gi\" |\n| `shm_size` | int | ❌ | 64 | Shared memory size (GB) |\n| `rdma` | int | ❌ | - | Number of RDMA NICs |\n| `enable_grpc` | bool | ❌ | false | Enable GRPC protocol |\n| `rolling_strategy` | object | ❌ | - | Rolling update strategy |\n| `eas` | object | ❌ | - | EAS advanced config |\n\n### rolling_strategy\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `max_surge` | int | Max new instances during rolling update |\n| `max_unavailable` | int | Max unavailable instances during rolling update |\n\n---\n\n## containers (required)\n\nContainer config array, must contain at least one container.\n\n| Field | Type | Required | Default | Description |\n|-------|------|----------|---------|-------------|\n| `image` | string | ✅ | - | Image URI |\n| `port` | int | ✅ | 8000 | Service port |\n| `script` | string | ❌ | - | Startup script |\n| `command` | string | ❌ | - | Startup command |\n| `args` | []string | ❌ | - | Command arguments |\n| `env` | []EnvVar | ❌ | - | Environment variables |\n| `prepare` | Prepare | ❌ | - | Pre-install config |\n| `startup_check` | Probe | ❌ | - | Startup probe |\n| `liveness_check` | Probe | ❌ | - | Liveness probe |\n| `health_check` | Probe | ❌ | - | Health check |\n| `resources` | ResourceRequirements | ❌ | - | Resource limits |\n\n### EnvVar\n\n```json\n{\"name\": \"ENV_NAME\", \"value\": \"env_value\"}\n```\n\n### Prepare\n\n```json\n{\n  \"pythonRequirements\": [\"numpy==1.6.4\", \"pandas\"],\n  \"pythonRequirementsPath\": \"/path/to/requirements.txt\"\n}\n```\n\n### Probe (Health Check)\n\n| Field | Type | Default | Description |\n|-------|------|---------|-------------|\n| `http_get` | object | - | HTTP check config |\n| `initial_delay_seconds` | int | 15 | Initial delay in seconds |\n| `period_seconds` | int | 10 | Check interval in seconds |\n| `timeout_seconds` | int | 1 | Timeout in seconds |\n| `success_threshold` | int | 1 | Success threshold |\n| `failure_threshold` | int | 1 | Failure threshold |\n\n```json\n{\n  \"http_get\": {\"path\": \"/health\", \"port\": 8000},\n  \"initial_delay_seconds\": 15,\n  \"period_seconds\": 10,\n  \"timeout_seconds\": 1,\n  \"success_threshold\": 1,\n  \"failure_threshold\": 3\n}\n```\n\n---\n\n## cloud (public resource group)\n\nConfig when using public resource group.\n\n### cloud.computing\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `instance_type` | string | either/or | Instance type, e.g. \"ecs.gn6i-c8g1.2xlarge\" |\n| `instances` | []object | either/or | Multi-spec instance list |\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\"\n    }\n  }\n}\n```\n\nOr:\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instances\": [\n        {\"type\": \"ecs.gn6i-c8g1.2xlarge\"},\n        {\"type\": \"ecs.gn7-c12g1.12xlarge\"}\n      ]\n    }\n  }\n}\n```\n\n### cloud.networking\n\nVPC network config (required for ALB/NLB).\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `vpc_id` | string | ✅ | VPC ID |\n| `vswitch_id` | string | ✅ | VSwitch ID, comma-separated for multi-zone (e.g. `\"vsw-a,vsw-b\"`) |\n| `security_group_id` | string | ✅ | Security group ID |\n\n---\n\n## storage (mount)\n\nStorage mount config array.\n\n### OSS Mount\n\n```json\n{\n  \"mount_path\": \"/models\",\n  \"oss\": {\n    \"path\": \"oss://my-bucket/models/\",\n    \"readOnly\": true\n  }\n}\n```\n\n### NAS/NFS Mount\n\n```json\n{\n  \"mount_path\": \"/data\",\n  \"nfs\": {\n    \"server\": \"xxx.cn-hangzhou.nas.aliyuncs.com\",\n    \"path\": \"/share\"\n  }\n}\n```\n\n### Dataset Mount\n\n```json\n{\n  \"mount_path\": \"/dataset\",\n  \"dataset\": {\n    \"id\": \"d-xxx\",\n    \"version\": \"v1\",\n    \"read_only\": true\n  }\n}\n```\n\n---\n\n## networking\n\n### Shared Gateway\n\nNo networking field needed.\n\n### ALB Dedicated Gateway\n\n```json\n{\n  \"networking\": {\n    \"gateway\": \"gw-xxx\"\n  }\n}\n```\n\n### NLB\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [\n      {\n        \"id\": \"default\",  // or \"nlb-xxx\"\n        \"listener_port\": 8000,\n        \"netType\": \"intranet\"\n      }\n    ]\n  }\n}\n```\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `id` | string | \"default\" for system-created, or actual NLB ID |\n| `listener_port` | int | Listener port (cannot be 8080) |\n| `netType` | string | \"intranet\" or \"internet\" |\n\n---\n\n## autoscaler\n\n### ⚠️ Important: Field Naming Convention\n\n**EAS API uses camelCase**:\n\n| ✅ Correct Field Name | ❌ Wrong Field Name | Description |\n|----------------------|---------------------|-------------|\n| `min` | ~~`min_replica`~~ | Min replicas |\n| `max` | ~~`max_replica`~~ | Max replicas |\n| `scaleStrategies` | ~~`scale_strategies`~~ | Scaling strategy array |\n| `metricName` | ~~`metric_name`~~ | Metric name |\n\n```json\n{\n  \"autoscaler\": {\n    \"min\": 1,\n    \"max\": 10,\n    \"scaleStrategies\": [\n      {\"metricName\": \"qps\", \"threshold\": 100},\n      {\"metricName\": \"cpu\", \"threshold\": 80}\n    ]\n  }\n}\n```\n\n| Field | Type | Required | Default | Description |\n|-------|------|----------|---------|-------------|\n| `min` | int | ❌ | 1 | Min replicas |\n| `max` | int | ❌ | 10 | Max replicas |\n| `scaleStrategies` | []object | ❌ | - | Scaling strategies |\n\n### scaleStrategies\n\n| Field | Description |\n|-------|-------------|\n| `metricName` | Metric name: qps, cpu, gpu, memory |\n| `threshold` | Trigger threshold |\n\n---\n\n## runtime\n\n```json\n{\n  \"runtime\": {\n    \"termination_grace_period\": 30\n  }\n}\n```\n\n| Field | Type | Default | Description |\n|-------|------|---------|-------------|\n| `termination_grace_period` | int | 30 | Graceful shutdown wait time (seconds) |\n\n---\n\n## features\n\n```json\n{\n  \"features\": {\n    \"eas.aliyun.com/gpu-driver-version\": \"550.54.15\"\n  }\n}\n```\n\nCommon features:\n- `eas.aliyun.com/gpu-driver-version`: GPU driver version\n\n---\n\n## Full Example\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my-llm-service\",\n    \"instance\": 2,\n    \"workspace_id\": \"<workspace_id>\",\n    \"disk\": \"30Gi\",\n    \"shm_size\": 64,\n    \"enable_grpc\": true,\n    \"rolling_strategy\": {\n      \"max_surge\": 1,\n      \"max_unavailable\": 0\n    }\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000,\n    \"script\": \"vllm serve /models/qwen-7b --port 8000 --tensor-parallel-size 2\",\n    \"env\": [\n      {\"name\": \"NCCL_P2P_DISABLE\", \"value\": \"1\"}\n    ],\n    \"startup_check\": {\n      \"http_get\": {\"path\": \"/health\", \"port\": 8000},\n      \"initial_delay_seconds\": 60,\n      \"period_seconds\": 10,\n      \"failure_threshold\": 30\n    }\n  }],\n  \"cloud\": {\n    \"computing\": {\n      \"instance_type\": \"ecs.gn7-c12g1.12xlarge\"\n    },\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-zone-a,vsw-zone-b\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"oss://my-bucket/models/qwen-7b\",\n      \"readOnly\": true\n    }\n  }],\n  \"networking\": {\n    \"gateway\": \"gw-xxx\"\n  },\n  \"autoscaler\": {\n    \"min\": 1,\n    \"max\": 5,\n    \"scaleStrategies\": [\n      {\"metricName\": \"qps\", \"threshold\": 50}\n    ]\n  },\n  \"runtime\": {\n    \"termination_grace_period\": 60\n  }\n}\n```\n\nFile v0.0.1:references/deployment-workflow.md\n\n# Deployment Workflow\n\nDetailed interaction flow and display format for PAI-EAS service deployment.\n\n**Table of Contents**\n- [Core Interaction Principles](#core-interaction-principles)\n- [Phase 1: Basic Info](#phase-1-basic-info)\n- [Phase 2: Environment](#phase-2-environment)\n- [Phase 3: Resources](#phase-3-resources)\n- [Phase 4: Network](#phase-4-network)\n- [Phase 5: Service Features](#phase-5-service-features)\n- [Phase 6: Deploy](#phase-6-deploy)\n\n---\n\n## Core Interaction Principles\n\n### 1. Step-by-Step Guidance\n\nShow current step → Wait for user input → Show next step\n\n### 2. List Pagination\n\nWhen more than 10 items: `Enter number to select | 'n' next page | keyword filter | 'all' show all`\n\n### 3. Resource Selection Pattern\n\nFor optional resources (e.g. EAS resource group, gateway): `1. Select from existing  2. Skip`\nFor workspaces: Auto-query; select if found, skip immediately if empty\n\n### 4. Default Value Handling\n\n```\nPort [8000]:\n1. Use default\n2. Custom\n\nSelect (enter 1 or 2):\n```\n\nDefaults: mount path `/model_dir`, port `8000`, replicas `1`, initial delay `60`, check interval `10`\n\n---\n\n## Phase 1: Basic Info\n\n### Step 1.1: Service Name (required)\n\nLowercase letters, digits, underscores, 3-63 characters.\n\n### Step 1.2: Workspace (optional, auto-handled)\n\n```bash\naliyun aiworkspace list-workspaces --region <region> --page-size 100 --verbose true --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n**Logic**:\n- **Has results** → Show list for user to select, record workspace_id\n- **Empty list** → **Skip immediately, proceed to next step! Never block asking user!** Simply omit `metadata.workspace_id` from JSON\n\n**⚠️ Never** stop deployment or ask user to create a workspace in the console\n\n**Display format (with results, paginated, max 10)**:\n```\n| # | Workspace ID | Name             |\n|---|-------------|------------------|\n| 1 | 312319      | aiworkspace_test |\n| 2 | 545434      | ccjtest          |\n\nTotal: 20, showing 1-10\nEnter number to select | 'n' next page | keyword filter | 'all' show all\n```\n\n---\n\n## Phase 2: Environment\n\n### Step 2.1: Select Image\n\n**⚠️ MUST call `ListImages` to query official image list, even if user already provided image address (eval checkpoint)**\n\n| # | Category | Target Models |\n|---|----------|--------------|\n| 1 | LLM Inference | Qwen, Llama, Mistral |\n| 2 | Image Generation | Stable Diffusion |\n| 3 | Speech Synthesis | CosyVoice |\n| 4 | RAG | RAG Applications |\n| 5 | General Inference | PyTorch Models |\n| 6 | Custom Image | User-provided image |\n\n**LLM inference requires secondary selection**: vLLM / SGLang\n\n**Query images**:\n```bash\naliyun aiworkspace list-images --verbose true \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\\t\\(.Labels[] | select(.Key == \"system.chipType\") | .Value)\"'\n```\n\n**Display format (paginated, max 10)**:\n```\n| # | Image Name       | Version   | Chip |\n|---|-----------------|-----------|------|\n| 1 | vllm:0.13.0rc2  | 0.13.0rc2 | GPU  |\n| 2 | vllm:0.14.0-xpu | 0.14.0    | XPU  |\n\nTotal: 14, showing 1-10\nEnter number to select | 'n' next page | keyword filter\n```\n\n**Query image chip type** (query immediately after selection, record CHIP_TYPE):\n```bash\naliyun aiworkspace get-image --image-id <image-id> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{ChipType: (.Labels[] | select(.Key == \"system.chipType\") | .Value), ImageUri: (.Labels[] | select(.Key == \"system.imageUri\") | .Value)}'\n```\n\n**Output example**:\n```json\n{\"ChipType\": \"GPU\", \"ImageUri\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\"}\n```\n\n**Variable**: `CHIP_TYPE=GPU` (subsequent resource selection will auto-filter compatible instances)\n\n**⚠️ Image must match model type**, see [Model-Image Matching Guide](model-image-matching.md)\n\n**⚠️ Chip compatibility (never block)**: Image chip type must match instance type!\n- GPU image → `ecs.gn*` series (NVIDIA GPU instances)\n- CPU image → any non-GPU instance\n- **If user requests CPU instance + GPU image (e.g. vLLM/SGLang), you MUST auto-switch to a GPU instance (e.g. ecs.gn7i-c16g1.4xlarge) silently. vLLM and SGLang REQUIRE GPU — NEVER deploy them on CPU. Do NOT ask the user, just switch and explain your choice.**\n\n### Step 2.2: Storage Mount\n\n**Do you need to mount storage?**\n\n| # | Option | Description |\n|---|--------|-------------|\n| 1 | Yes | Mount model files or data |\n| 2 | No (skip) | No storage mount |\n\n**If \"Yes\", select storage type**:\n\n| # | Storage Type | Description |\n|---|-------------|-------------|\n| 1 | OSS | Mount OSS bucket (most common) |\n| 2 | NAS | Mount NAS file system |\n| 3 | CPFS | Mount CPFS |\n| 4 | Dataset | Use PAI dataset |\n\n**OSS mount flow**:\n\n1. **Query bucket list**:\n```bash\nossutil ls\n```\n\n2. **Display bucket list (paginated, max 10)**:\n```\n| # | Bucket Name    | Region      |\n|---|---------------|-------------|\n| 1 | yqtest-model  | cn-hangzhou |\n| 2 | my-bucket     | cn-shanghai |\n\nTotal: 15, showing 1-10\nEnter number to select | 'n' next page | keyword filter\n```\n\n3. **List directory**:\n```bash\nossutil ls oss://bucket-name/\n```\n\n4. **Display directory list**:\n```\nSelected Bucket: yqtest-model\n| # | Path             | Description |\n|---|-----------------|-------------|\n| 1 | Qwen3.5-0.8B/   | LLM model   |\n| 2 | llama-7b/        | LLM model   |\n\nSelect model directory (enter number):\n```\n\n5. **Configure mount path**:\n```\nMount path [/model_dir]:\n1. Use default\n2. Custom\n\nSelect (enter 1 or 2):\n```\n\n**⚠️ Important**: OSS path format must be `oss://bucket/path/` (note trailing `/`)\n\n**⚠️ Important**: OSS models must be mounted via storage as local paths (e.g. `/model_dir`). Never pass oss:// URL directly to vllm/sglang commands!\n\nSee [Storage Mount Guide](storage-mount.md)\n\n### Step 2.3: Startup Command\n\n```bash\naliyun aiworkspace get-image --image-id <image-id> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.EasConfig.script'\n```\n\n**Logic**:\n- If image has preset command → Show to user for confirmation or modification\n- If no preset command → Use typical command as default\n\n**Typical commands**:\n\n| Image Type | Typical Command |\n|-----------|----------------|\n| vLLM | `vllm serve /model_dir --port 8000 --trust-remote-code` |\n| SGLang | `python -m sglang.launch_server --model-path /model_dir --port 8000` |\n| ComfyUI | `python main.py --listen 0.0.0.0 --port 8000` |\n\n**Interaction example**:\n```\nStartup command:\n1. Use recommended: vllm serve /model_dir --port 8000 --trust-remote-code\n2. Custom command\n\nSelect (enter 1 or 2):\n```\n\n### Step 2.4: Port\n\n```\nPort [8000]:\n1. Use default\n2. Custom\n\nSelect (enter 1 or 2):\n```\n\nDefault: `8000`\n\n---\n\n## Phase 3: Resources\n\n### Step 3.1: Resource Type\n\n| # | Type | Description |\n|---|------|-------------|\n| 1 | Public Resource | On-demand, pay-as-you-go |\n| 2 | EAS Resource Group | Dedicated resource group |\n\n### Step 3.2: Public Resource Group\n\n**Auto-filter logic** (based on image chip type from step 2.1):\n\n```\nSelected image chip type: GPU\nFiltering compatible instance types...\n```\n\n**Filter rules**:\n\n| Image Chip Type | jq Filter | Instance Type Pattern |\n|----------------|-----------|----------------------|\n| GPU | `.GPUAmount > 0` | `ecs.gn*` series (NVIDIA GPU) |\n| CPU | `.GPUAmount == 0` | Non-GPU instances |\n| PPU | `.InstanceType \\| startswith(\"ecs.ebmppu\")` | Hanguang instances |\n| XPU | `.InstanceType \\| startswith(\"ecs.egs\")` | XPU instances |\n\n**One-command query** (auto-select based on chip type):\n\n```bash\n# Assuming CHIP_TYPE variable obtained from image labels\naliyun eas describe-machine-spec --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r --arg chip \"$CHIP_TYPE\" '\n    .InstanceMetas[] | select(.IsAvailable == true) |\n    if $chip == \"GPU\" then\n      select(.GPUAmount > 0) | \"\\(.InstanceType)\\t\\(.GPUAmount)x\\(.GPU)\\t\\(.CPU) cores\\t\\(.Memory)GB\"\n    elif $chip == \"CPU\" then\n      select(.GPUAmount == 0) | \"\\(.InstanceType)\\t-\\t\\(.CPU) cores\\t\\(.Memory)GB\"\n    elif $chip == \"PPU\" then\n      select(.InstanceType | startswith(\"ecs.ebmppu\")) | \"\\(.InstanceType)\\tPPU\\t\\(.CPU) cores\\t\\(.Memory)GB\"\n    elif $chip == \"XPU\" then\n      select(.InstanceType | startswith(\"ecs.egs\")) | \"\\(.InstanceType)\\tXPU\\t\\(.CPU) cores\\t\\(.Memory)GB\"\n    else empty end\n  '\n```\n\n**GPU image query** (chip type = GPU):\n```bash\naliyun eas describe-machine-spec --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.InstanceMetas[] | select(.IsAvailable == true and .GPUAmount > 0) | \"\\(.InstanceType)\\t\\(.GPUAmount)x\\(.GPU)\\t\\(.CPU) cores\\t\\(.Memory)GB\"'\n```\n\n**CPU image query** (chip type = CPU):\n```bash\naliyun eas describe-machine-spec --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.InstanceMetas[] | select(.IsAvailable == true and .GPUAmount == 0) | \"\\(.InstanceType)\\t-\\t\\(.CPU) cores\\t\\(.Memory)GB\"'\n```\n\n**Display format (paginated, max 10)**:\n```\n| # | Instance Type            | GPU    | CPU     | Memory |\n|---|-------------------------|--------|---------|--------|\n| 1 | ecs.gn6i-c4g1.xlarge   | 1×T4   | 4 cores | 16GB   |\n| 2 | ecs.gn7-c12g1.12xlarge | 4×A10  | 12 cores| 192GB  |\n\nTotal: 45, showing 1-10\nEnter number to select | 'n' next page | keyword filter\n```\n\n### Step 3.3: EAS Resource Group\n\n**⚠️ MUST call `list-resources` to query resource group list, even if user already provided resource group ID:**\n\n```bash\n# MUST call: list all resource groups\naliyun eas list-resources --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n\n# Query specific resource group details\naliyun eas list-resources --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.Resources[] | \"\\(.ResourceId)\\t\\(.ResourceName)\\t\\(.GpuCount)\\t\\(.GpuUsed)\\t\\(.CpuCount)\\t\\(.CpuUsed)\"'\n```\n\n**Display format**:\n```\n| # | Resource ID | Name       | GPU (total/used/free) | CPU (total/used/free) |\n|---|------------|------------|----------------------|----------------------|\n| 1 | eas-r-xxx  | production | 16/2/14              | 128/20/108           |\n```\n\n**Calculation**: free = total - used\n\n### Step 3.4: Replicas\n\n```\nReplicas [1]:\n1. Use default\n2. Custom\n\nSelect (enter 1 or 2):\n```\n\n---\n\n## Phase 4: Network\n\n### Step 4.1: Gateway Type\n\n| # | Type | VPC Config | Description |\n|---|------|-----------|-------------|\n| 1 | Shared Gateway | ❌ Not needed | Free, suitable for testing |\n| 2 | ALB Dedicated Gateway | ✅ Required | Recommended for production |\n| 3 | NLB | ✅ Required | High-performance load balancing |\n\n### Step 4.2: ALB Dedicated Gateway Config\n\n**⚠️ MUST call `list-gateway` first to list gateways (even if user provided gateway ID), then call `describe-gateway` to get VPC info:**\n\n```bash\n# MUST call: list all gateways\naliyun eas list-gateway --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n**Display format**:\n```\n| # | Gateway Name | Gateway ID |\n|---|-------------|-----------|\n| 1 | prod-gw     | gw-xxx    |\n| 2 | test-gw     | gw-yyy    |\n\nEnter number to select:\n```\n\n**Get gateway VPC info**:\n```bash\naliyun eas describe-gateway --cluster-id cn-hangzhou --gateway-id gw-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{VpcId: .LoadBalancerList[0].VpcId, VSwitchIds: .LoadBalancerList[0].VSwitchIds}'\n```\n\n**Select VSwitch**:\n```\nObtained gateway VPC: vpc-xxx\n| # | VSwitch ID   | Availability Zone |\n|---|-------------|-------------------|\n| 1 | vsw-xxx     | Zone A            |\n| 2 | vsw-yyy     | Zone B            |\n\nEnter number to select:\n```\n\n**Select security group**:\n```bash\naliyun ecs describe-security-groups --biz-region-id cn-hangzhou --vpc-id <vpc-id> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\nSee [Network Config](network-config.md)\n\n---\n\n## Phase 5: Service Features\n\n### Step 5.1: Feature Selection\n\n**Do you need to configure service features?**\n\n| # | Option | Description |\n|---|--------|-------------|\n| 1 | Configure features | Select features to enable |\n| 2 | Skip | No features enabled (default) |\n\n**If \"Configure features\"**:\n\n```\nAvailable features (multi-select with comma):\n\n| # | Feature | Description |\n|---|---------|-------------|\n| 1 | Health Check | Configure startup/liveness probes |\n| 2 | Rolling Update | Graceful shutdown + rolling strategy |\n| 3 | GRPC | Enable GRPC protocol |\n| 4 | Autoscaling | Auto-adjust replicas based on load |\n\nEnter feature numbers to enable (e.g. 1,2,4), enter 'done' to finish:\n```\n\n**When modifying feature status**:\n\n```\nCurrent service feature config:\n\n| # | Feature | Status |\n|---|---------|--------|\n| 1 | Health Check | ✅ Enabled |\n| 2 | Rolling Update | ❌ Disabled |\n| 3 | GRPC | ❌ Disabled |\n| 4 | Autoscaling | ❌ Disabled |\n\nEnter number to toggle (e.g. enter 1 to disable health check), enter 'done' to finish:\n```\n\nSee [Service Features Config](service-features.md)\n\n---\n\n## Phase 6: Deploy\n\n### Step 6.1: Config Preview\n\n**Compatibility validation** (must pass before deployment):\n\n```\n✅ Image chip type: GPU\n✅ Instance type: ecs.gn7-c12g1.12xlarge (GPU instance)\n✅ Compatibility: Passed\n```\n\nIf compatibility check fails:\n```\n❌ Image chip type: XPU\n❌ Instance type: ecs.gn7-c12g1.12xlarge (GPU instance)\n❌ Compatibility: Failed - XPU image requires XPU instance, please change image or instance type\n```\n\n```\nGenerated service configuration:\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n{\n  \"metadata\": { \"name\": \"mytest_006\", \"instance\": 1 },\n  \"containers\": [{ \"image\": \"...\", \"port\": 8000 }],\n  ...\n}\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n\nConfig Summary:\n• Service Name: mytest_006\n• Image: vllm:0.14.0-gpu (Chip: GPU)\n• Instance: ecs.gn7-c12g1.12xlarge (4×A10, GPU)\n• Network: Shared Gateway\n• Compatibility: ✅ Passed\n\nSelect:\n1. Confirm deploy\n2. Modify config\n3. Save JSON to file\n4. Cancel\n```\n\n### Step 6.2: Modify Config\n\n**Select config item to modify**:\n\n| # | Config Item | Current Value |\n|---|------------|---------------|\n| 1 | Service Name | mytest_006 |\n| 2 | Workspace | aiworkspace_test |\n| 3 | Image | vllm:0.13.0rc2 |\n| 4 | Storage Mount | Not configured |\n| 5 | Startup Command | vllm serve ... |\n| 6 | Port | 8000 |\n| 7 | Instance Type | ecs.gn5-c8g1.2xlarge |\n| 8 | Replicas | 1 |\n| 9 | Network | ALB Dedicated Gateway |\n| 10 | Features | Health Check |\n| 11 | Go back | - |\n\nEnter number to select:\n\n### Step 6.3: Execute Deployment\n\n**Save config to file, then deploy**:\n\n```bash\n# Save config to file\ncat > /tmp/eas_service.json << 'EOF'\n{\n  \"metadata\": { \"name\": \"my-service\", \"instance\": 1 },\n  \"containers\": [{ \"image\": \"...\", \"port\": 8000 }],\n  \"cloud\": { \"computing\": { \"instance_type\": \"ecs.gn6i-c4g1.xlarge\" } }\n}\nEOF\n\n# Execute deployment (may take 1-2 minutes)\n# ⚠️ Do NOT use file:// prefix, use $(cat) to read file content\naliyun eas create-service --region <region> --body \"$(cat /tmp/eas_service.json)\" --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n**⚠️ Note**: Use `$(cat file)` to read file content for `--body`, do NOT use `file://` prefix (may cause JSON parsing errors)\n\n**⚠️ CRITICAL: If a service with the same name already exists**: STOP and inform the user — e.g. \"A service named `<name>` already exists (Status: `<status>`). Please choose a different name.\" Do NOT delete and recreate it, and do NOT reuse it. Deleting an existing service is destructive and must never be done automatically. Only proceed with the full deployment workflow (ListImages, describe-machine-spec, create-service, describe-service) once a non-conflicting service name is confirmed.\n\n### Step 6.4: Wait for Service Ready\n\n```bash\nfor i in $(seq 1 6); do\n  STATUS=$(aliyun eas describe-service --cluster-id cn-hangzhou --service-name <service-name> \\\n    --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Status')\n  case $STATUS in\n    Running) echo \"✅ Service ready\"; break ;;\n    Failed)  echo \"❌ Service startup failed\"; break ;;\n    *)       echo \"⏳ Status: $STATUS ($((i*30))s/180s)\"; sleep 30 ;;\n  esac\ndone\n```\n\n### Step 6.5: Display Deployment Result\n\n**MUST include InternetEndpoint and IntranetEndpoint from describe-service response.**\n\n```\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nDeployment Result\n\nService Name: mytest_006\nStatus: Running\nInternetEndpoint: http://xxx.cn-hangzhou.pai-eas.aliyuncs.com/api/predict/xxx\nIntranetEndpoint: http://xxx.vpc.cn-hangzhou.pai-eas.aliyuncs.com/api/predict/xxx\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n```\n\n**⚠️ You MUST output the exact field names \"InternetEndpoint\" and \"IntranetEndpoint\"\nwith their actual values from the describe-service API response.**\n\n### Step 6.6: Service Invocation Example\n\n```\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nService Invocation Examples\n\nEndpoint: http://xxx.cn-hangzhou.pai-eas.aliyuncs.com/api/predict/mytest_006\n\n[curl] curl http://xxx/api/predict/mytest_006 -H \"Content-Type: application/json\" -d '{\"input\": \"Hello\"}'\n[OpenAI SDK] client = OpenAI(base_url=\"http://xxx/v1\", ...)\n\nSee [Service Invocation Examples](service-invoke-examples.md)\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n```\n\n### Step 6.7: Failure Handling\n\n**Query events**:\n```bash\naliyun eas describe-service-event --cluster-id <region> --service-name <service-name> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.Events[-3:][] | \"[\\(.Type)] \\(.Reason): \\(.Message)\"'\n```\n\n**Common errors**:\n\n| Error Type | Cause | Solution |\n|-----------|-------|---------|\n| ImagePullBackOff | Image pull failed | Check image address and permissions |\n| CrashLoopBackOff | Container startup failed | Check startup command and model path |\n| Instance crashed | Chip type mismatch | Image chip type must match instance type (GPU image → GPU instance) |\n| InsufficientResources | Resource shortage | Choose different instance type or resource group |\n| ModelNotFound | Wrong model path | Check OSS mount path |\n\nFile v0.0.1:references/image-categories.md\n\n# Official Image Categories\n\n> **Usage**: After user selects a category, call the API to query images in that category.\n\n## Category List\n\n```\n| # | Category          | Description                    | Frameworks                        |\n|---|-------------------|-------------------------------|----------------------------------|\n| 1 | LLM Inference     | Large language model inference | vLLM, SGLang                    |\n| 2 | Image Generation  | Text-to-image, image processing| ComfyUI, Stable Diffusion, Kohya |\n| 3 | Speech Synthesis  | TTS voice synthesis           | CosyVoice                       |\n| 4 | RAG               | Retrieval-augmented generation | PaiRag                          |\n| 5 | General Inference | General deep learning inference| PyTorch, Triton, TF Serving     |\n| 6 | Tools             | General tool images           | OpenClaw, CoPaw, Python         |\n```\n\n## Category Details\n\n### 1. LLM Inference\n\n**Flow**: Let user select framework first, then query\n\n**Framework selection**:\n```\n| # | Framework | Description            |\n|---|-----------|------------------------|\n| 1 | vLLM      | High-performance LLM inference |\n| 2 | SGLang    | Efficient LLM serving framework |\n```\n\n**Query commands** (call once after user selects framework):\n\n```bash\n# vLLM - fuzzy search by Name\naliyun aiworkspace list-images --verbose true --name vllm \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\\t\\(.Labels[] | select(.Key == \"system.chipType\") | .Value)\"'\n\n# SGLang - fuzzy search by Name\naliyun aiworkspace list-images --verbose true --name sglang \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\\t\\(.Labels[] | select(.Key == \"system.chipType\") | .Value)\"'\n```\n\n**Image info**:\n\n| Framework | Versions | Chips |\n|-----------|----------|-------|\n| vLLM | 0.7.x - 0.14.0 | GPU, PPU |\n| SGLang | 0.5.2 - 0.5.8 | GPU, PPU |\n\n### 2. Image Generation\n\n**ComfyUI**: Node-based image generation workflow\n- Versions: 2.1, 2.2\n- Chip: GPU\n\n**Stable Diffusion WebUI**: Classic SD interface\n- Versions: 4.1, 4.2\n- Chip: GPU\n\n**Kohya**: Model training tool\n- Versions: 2.2, 25.0.3\n- Chip: GPU\n\n**EasyAnimate**: Video generation\n- Versions: 1.1.4, 1.1.5\n\n**Query command**:\n\n```bash\n# ComfyUI - fuzzy search by Name\naliyun aiworkspace list-images --verbose true --name comfyui \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\"'\n```\n\n### 3. Speech Synthesis\n\n**CosyVoice**: Alibaba speech synthesis\n- Versions: 0.1.5, 2.2.6, 3.0.6\n- Components: webui, backend, frontend\n- Chips: GPU, PPU\n\n**Query command**:\n\n```bash\naliyun aiworkspace list-images --verbose true \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 100 | jq '.Images[] | select(.Name | test(\"cosyvoice\"; \"i\"))'\n```\n\n### 4. RAG\n\n**PaiRag**: PAI RAG framework\n- Versions: 0.3.5, 0.4.3\n- Chips: CPU, PPU\n\n**Query command**:\n\n```bash\n# PaiRag - fuzzy search by Name\naliyun aiworkspace list-images --verbose true --name pairag \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\"'\n```\n\n### 5. General Inference\n\n**PyTorch**: General deep learning framework\n- Versions: 2.2, 2.3.1, 2.5.1, 2.7.1\n- Chips: GPU, CPU, PPU\n\n**Triton Server**: NVIDIA inference server\n- Versions: 21.09 - 25.03\n- Chip: GPU\n\n**TensorFlow Serving**: TF model serving\n- Versions: 1.15.0, 2.11.1, 2.14.1, 2.17.1, 2.18.1\n\n**Query command**:\n\n```bash\n# PyTorch - fuzzy search by Name\naliyun aiworkspace list-images --verbose true --name pytorch \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\"'\n```\n\n### 6. Tools\n\n**OpenClaw**: PAI tool image\n- Version: 2026.3.13\n- Chip: CPU\n\n**CoPaw**: CoPaw tool image\n- Version: v0.0.7\n- Chip: CPU\n\n**Query command**:\n\n```bash\n# OpenClaw - fuzzy search by Name\naliyun aiworkspace list-images --verbose true --name openclaw \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Images[] | \"\\(.ImageId)\\t\\(.Name)\"'\n```\n\n---\n\n## Query Parameter Reference\n\n**Labels filter syntax**:\n\n```bash\n# Multiple labels separated by comma, format: Key=Value\n--labels 'system.official=true,system.supported.eas=true'\n\n# Fuzzy search image name via Name parameter\n--name vllm\n```\n\n**Common labels**:\n\n| Label Key | Description |\n|-----------|-------------|\n| `system.official` | `true` = official image |\n| `system.supported.eas` | `true` = supports EAS deployment |\n| `system.chipType` | `GPU`/`CPU`/`PPU`/`XPU` = chip type |\n| `system.framework.xxx` | Framework type label, value = version |\n\nFile v0.0.1:references/model-image-matching.md\n\n# Model-Image Matching Guide\n\n> **Important**: Before selecting an image, confirm your model type matches the image type. Mismatch will cause deployment failure!\n\n## Quick Matching Table\n\n| Model Type | Recommended Image Category | Specific Image | Model Format |\n|-----------|--------------------------|---------------|-------------|\n| **LLM** (Qwen, Llama, Mistral, Baichuan, etc.) | LLM Inference | vLLM, SGLang | HuggingFace (safetensors) |\n| **LLM** (quantized) | LLM Inference | llama.cpp | GGUF |\n| **Image Generation** (Stable Diffusion, SDXL) | Image Generation | ComfyUI, SD WebUI | .safetensors, .ckpt |\n| **Speech Synthesis** (TTS) | Speech Synthesis | CosyVoice | Model-specific format |\n| **RAG Applications** | RAG | PaiRag | - |\n| **Custom Inference** | General Inference | PyTorch, Triton | .pt, .pth, .onnx |\n\n## Common Errors\n\n### ❌ Wrong Example\n\n```\nModel: Qwen3.5-0.8B (LLM)\nImage: ComfyUI (Image Generation)\nResult: Deployment failed, image does not support LLM inference\n```\n\n### ✅ Correct Example\n\n```\nModel: Qwen3.5-0.8B (LLM)\nImage: vLLM or SGLang\nResult: Deployment successful\n```\n\n## Detailed Matching Rules\n\n### 1. LLM Models\n\n**HuggingFace Format** (.safetensors, model.bin):\n```\nImage: vLLM, SGLang\nModel directory structure:\n├── config.json\n├── model.safetensors (or model.bin)\n├── tokenizer.json\n├── tokenizer_config.json\n└── vocab.json\n```\n\n**GGUF Format**:\n```\nImage: llama.cpp\nModel file: *.gguf\n```\n\n**Note**: Do not use vLLM for GGUF models; do not use llama.cpp for HuggingFace format.\n\n### 2. Image Generation Models\n\n**Stable Diffusion Series**:\n```\nImage: ComfyUI, Stable Diffusion WebUI\nModel format: .safetensors, .ckpt\nStorage path: /models/checkpoints/ or /models/stable-diffusion/\n```\n\n**Note**: LLM models cannot be used with image generation images.\n\n### 3. Speech Synthesis Models\n\n**CosyVoice**:\n```\nImage: CosyVoice\nRequires: Pre-trained model files\n```\n\n## Model Download Sources\n\n| Source | Format | Description |\n|--------|--------|-------------|\n| HuggingFace | safetensors | Most common, natively supported by vLLM/SGLang |\n| ModelScope | safetensors | Faster access in China, HuggingFace compatible |\n| HuggingFace GGUF | GGUF | Quantized models, requires llama.cpp |\n\n## How to Determine Model Type\n\n1. **Check file extension**:\n   - `.safetensors` + `config.json` → HuggingFace LLM\n   - `.gguf` → GGUF LLM\n   - `.ckpt` / `.safetensors` (no config.json) → Image model\n\n2. **Check model name**:\n   - Contains `llama`, `qwen`, `mistral`, `baichuan` → LLM\n   - Contains `sd`, `stable-diffusion`, `sdxl` → Image generation\n   - Contains `cosyvoice`, `tts` → Speech synthesis\n\n3. **Check source page**:\n   - HuggingFace model page indicates model type\n\n## Chip Type Compatibility (Important)\n\n> **⚠️ Image chip type must match instance type, otherwise deployment fails!**\n\n### Image Chip Types\n\nImages use `system.chipType` label to indicate supported chips:\n\n| Chip Type | Description | Instance Type Prefix |\n|-----------|-------------|---------------------|\n| **GPU** | NVIDIA GPU | `ecs.gn`, `ecs.gn6`, `ecs.gn7`, `ecs.gn8` |\n| **CPU** | CPU only | Non-GPU instances |\n| **PPU** | Alibaba Hanguang chip | `ecs.ebmppu` |\n| **XPU** | Alibaba XPU | `ecs.egs` |\n\n### Compatibility Matrix\n\n| Image Chip Type | Compatible Instance Types |\n|----------------|--------------------------|\n| GPU | gn6i, gn6v, gn7, gn6e, gn8 (NVIDIA GPU instances) |\n| CPU | Any non-GPU instance |\n| PPU | ebmppu (Hanguang instances) |\n| XPU | egs (XPU instances) |\n\n### Query Image Chip Type\n\n```bash\naliyun aiworkspace get-image --image-id <image-id> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.Labels[] | select(.Key == \"system.chipType\") | .Value'\n```\n\n### Query Instance Type GPU Info\n\n```bash\naliyun eas describe-machine-spec --region <region> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq -r '.InstanceMetas[] | select(.InstanceType == \"<instance-type>\") | {InstanceType, GPUAmount, GPU}'\n```\n\n### Common Errors\n\n```\n❌ Wrong:\nImage: vllm:0.14.0-xpu (XPU chip)\nInstance: ecs.gn7-c12g1.12xlarge (GPU instance)\nResult: Instance crashed - chip type mismatch\n\n✅ Correct:\nImage: vllm:0.14.0-gpu (GPU chip)\nInstance: ecs.gn7-c12g1.12xlarge (GPU instance)\nResult: Deployment successful\n```\n\n---\n\n## Pre-deployment Checklist\n\n```\n□ Confirm model type (LLM / Image / Speech / Custom)\n□ Select matching image category\n□ Confirm model format is compatible with image\n□ Confirm image chip type matches instance type\n□ Confirm model file completeness (config.json, tokenizer, etc.)\n□ Confirm model path is mounted correctly\n```\n\nFile v0.0.1:references/network-config.md\n\n# Network Configuration Rules\n\n**Table of Contents**\n- [Network Config Requirements](#network-config-requirements)\n- [Consistency Requirements](#consistency-requirements)\n- [ALB Dedicated Gateway](#alb-dedicated-gateway)\n- [NLB Configuration](#nlb-configuration)\n- [Shared Gateway](#shared-gateway)\n\n## Network Config Requirements\n\n| Gateway Type | `cloud.networking` | Description |\n|-------------|-------------------|-------------|\n| **Shared Gateway** | ❌ Not required | For testing, not recommended for production, no VPC config needed |\n| **ALB Dedicated Gateway** | ✅ **Required** | VPC/VSwitch obtained from gateway |\n| **NLB** | ✅ **Required** | VPC/VSwitch must be consistent with NLB |\n\n## Consistency Requirements\n\n```\nWhen deploying with ALB/NLB:\n├── cloud.networking.vpc_id           ← Must match gateway/NLB VPC\n├── cloud.networking.vswitch_id       ← Must match gateway/NLB VSwitch\n└── cloud.networking.security_group_id ← Must be in the same VPC as VSwitch\n\n⚠️ Important: VPC, VSwitch, and security group must all be under the same VPC!\n```\n\n## ALB Dedicated Gateway\n\n### Config Flow\n\n1. Select gateway (from `list-gateway`)\n2. Call `DescribeGateway` to get VPC/VSwitch\n3. Select security group under the gateway VPC\n\n### Config Example\n\n```json\n{\n  \"networking\": { \"gateway\": \"gw-abc123\" },\n  \"cloud\": {\n    \"networking\": {\n      \"vpc_id\": \"{from gateway}\",\n      \"vswitch_id\": \"{from gateway, comma-separated if multiple}\",\n      \"security_group_id\": \"{user selected}\"\n    }\n  }\n}\n```\n\n### API Calls\n\n```bash\n# List gateways\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n\n# Get gateway details (includes VPC and VSwitch info)\naliyun eas describe-gateway --cluster-id cn-hangzhou --gateway-id gw-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n\n# Key fields in response:\n# .LoadBalancerList[0].VpcId        → VPC ID\n# .LoadBalancerList[0].VSwitchIds   → VSwitch list\n```\n\n**Correct jq command to get VPC and comma-separated VSwitch ID**:\n\n```bash\naliyun eas describe-gateway --cluster-id cn-hangzhou --gateway-id gw-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{\n    vpc_id: .LoadBalancerList[0].VpcId,\n    vswitch_id: (.LoadBalancerList[0].VSwitchIds | join(\",\"))\n  }'\n```\n\n**Response example**:\n\n```json\n{\n  \"vpc_id\": \"vpc-bp13kiflgde6v9dc9smc8\",\n  \"vswitch_id\": \"vsw-bp1bhmnwqdh1ta9z9klms,vsw-bp1lz95xtmjiwqcpq31ng\"\n}\n```\n\n**Query security groups** (after getting VPC):\n\n```bash\naliyun ecs describe-security-groups --biz-region-id cn-hangzhou --vpc-id {gateway_vpc} --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.SecurityGroups[] | \"\\(.SecurityGroupId)\\t\\(.SecurityGroupName)\"'\n```\n\n---\n\n## NLB Configuration\n\n### Two Modes\n\n| Mode | ID | Description |\n|------|-----|-------------|\n| **System NLB** | `\"default\"` | System auto-creates, lifecycle follows service (recommended) |\n| **Custom NLB** | Actual NLB ID | Associate with user's existing NLB instance |\n\n### System NLB (Recommended)\n\nSystem automatically creates an NLB instance under your account. The NLB lifecycle follows the service.\n\n**Config example**:\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [{\n      \"id\": \"default\",\n      \"listener_port\": 9090,\n      \"netType\": \"intranet\"\n    }]\n  },\n  \"cloud\": {\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-zone-a,vsw-zone-b\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  }\n}\n```\n\n**Parameter description**:\n\n| Parameter | Description |\n|-----------|-------------|\n| `id` | Fixed as `\"default\"` |\n| `listener_port` | Listener port (cannot be 8080) |\n| `netType` | `intranet` or `internet` |\n| `vswitch_id` | **Comma-separated, must include at least 2 VSwitches across different zones** (e.g. `\"vsw-xxx-a,vsw-xxx-b\"`) |\n\n**Multi-port config supported**:\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [\n      {\"id\": \"default\", \"listener_port\": 9090, \"netType\": \"intranet\"},\n      {\"id\": \"default\", \"listener_port\": 9091, \"netType\": \"internet\"}\n    ]\n  }\n}\n```\n\n**Config flow**:\n\n1. Select \"System NLB\"\n2. Configure VPC info (reuse high-speed direct connect VPC/VSwitch)\n3. Select network type (intranet/internet/both)\n4. Configure listener port\n\n**⚠️ Important rules**:\n- `vswitch_id` must be **comma-separated with at least 2 VSwitches across different availability zones** (e.g. `\"vsw-zone-a,vsw-zone-b\"`)\n- Port 8080 is reserved by EAS engine, cannot be used\n- VPC, VSwitch, and security group must all be under the same VPC\n- System NLB lifecycle follows the service\n\n### Custom NLB\n\nAssociate with user's existing NLB instance.\n\n**Config example**:\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [{\n      \"id\": \"nlb-fpj3530zrbt7x5zkhk\",\n      \"listener_port\": 9090\n    }]\n  },\n  \"cloud\": {\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-zone-a,vsw-zone-b\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  }\n}\n```\n\n**Requirements**:\n- NLB must be in the same VPC as the service\n- `vswitch_id` must be comma-separated with at least 2 VSwitches across different zones\n- Port 8080 cannot be used\n- Port must not conflict with existing NLB listeners\n- Custom NLB and system NLB are mutually exclusive (modifying will disassociate the old one)\n\n### NLB API Calls\n\n```bash\n# Query existing NLBs\naliyun nlb list-load-balancers --biz-region-id cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n\n# Get NLB details (includes VPC and VSwitch info)\naliyun nlb get-load-balancer-attribute --load-balancer-id nlb-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{vpc_id: .VpcId, vswitch_id: ([.ZoneMappings[].VswitchId] | join(\",\"))}'\n```\n\n**Response example**:\n\n```json\n{\n  \"vpc_id\": \"vpc-xxx\",\n  \"vswitch_id\": \"vsw-xxx-a,vsw-xxx-b\"\n}\n```\n\n**Query security groups** (after getting NLB VPC):\n\n```bash\naliyun ecs describe-security-groups --biz-region-id cn-hangzhou --vpc-id {nlb_vpc} --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.SecurityGroups[] | \"\\(.SecurityGroupId)\\t\\(.SecurityGroupName)\"'\n```\n\n**⚠️ Important rules**:\n- VPC, VSwitch, and security group must all be under the NLB's VPC\n- Security group must be in the **same VPC** as NLB\n- Port 8080 is reserved by EAS engine, cannot be used\n\n### Access URL\n\n```\nAccess URL: <NLB_domain>:<listener_port>/api/predict/<service_name>\nGet domain: https://nlb.console.aliyun.com/\n```\n\n## Shared Gateway\n\nNo `cloud.networking` config needed, uses default mode.\n\n```json\n{\n  \"metadata\": { \"name\": \"my-service\" },\n  \"containers\": [...]\n  // No networking or cloud.networking fields needed\n}\n```\n\nArchive v0.0.1-beta.1: 22 files, 53203 bytes\n\nFiles: references/acceptance-criteria.md (5896b), references/api-reference.md (2798b), references/cli-installation-guide.md (11943b), references/config-examples.md (5290b), references/config-patterns.md (7194b), references/config-schema.md (8503b), references/deployment-workflow.md (18400b), references/image-categories.md (5034b), references/model-image-matching.md (4629b), references/network-config.md (6484b), references/ram-policies.md (4723b), references/related-apis.md (5061b), references/service-features.md (8507b), references/service-invoke-examples.md (3398b), references/storage-mount.md (8652b), references/verification-method.md (5089b), scripts/create-service-from-json.sh (6213b), scripts/list-images.sh (7449b), scripts/validate-service-config.sh (9361b), skill-card.md (3423b), SKILL.md (18645b), _meta.json (161b)\n\nFile v0.0.1-beta.1:SKILL.md\n\n---\nname: alibabacloud-pai-eas-service-deploy\ndescription: |\n  Deploy AI models as PAI-EAS inference services.\n  Supports LLMs (Qwen, Llama), image gen (SD, SDXL),\n  speech synthesis, and more.\n  When to use: deploy models, create inference services,\n  EAS deployment, model serving, deploy vLLM/SGLang/ComfyUI.\nlicense: Apache-2.0\nmetadata:\n  version: \"1.0.0\"\n  domain: aiops\n  owner: pai-eas-team\n  contact: pai-eas-agent@alibaba-inc.com\n  tags:\n    - pai-eas\n    - model-deployment\n    - inference-service\n    - llm\n    - vllm\n    - sglang\n  required_tools:\n    - aliyun\n    - jq\n  prerequisites:\n    - \"Aliyun CLI >= 3.3.1\"\n    - \"jq command-line JSON processor\"\n  required_permissions:\n    - \"eas:CreateService\"\n    - \"eas:DescribeService\"\n    - \"eas:ListServices\"\n    - \"eas:DescribeMachineSpec\"\n    - \"eas:ListResources\"\n    - \"eas:ListGateway\"\n    - \"eas:DescribeGateway\"\n    - \"nlb:ListLoadBalancers\"\n    - \"aiworkspace:ListImages\"\n    - \"aiworkspace:ListWorkspaces\"\n    - \"vpc:DescribeVpcs\"\n    - \"vpc:DescribeVSwitches\"\n    - \"ecs:DescribeSecurityGroups\"\n---\n# PAI-EAS Service Deployment\n\n## ⚠️ TOP RULES (read first)\n\n**1. 🔴 NO DUPLICATE SERVICE NAMES** 🔴\n\nIf a service with the target name already exists: STOP and inform\nthe user. Do NOT delete and recreate. Do NOT reuse it either.\n\n**2. Mandatory API Calls** — Execute ALL of these in order:\n\n| # | API | CLI | Purpose |\n|---|-----|-----|---------|\n| 1 | ListImages | `aliyun aiworkspace list-images` | Validate image |\n| 2 | describe-machine-spec | `aliyun eas describe-machine-spec` | Validate GPU type |\n| 3 | create-service | `aliyun eas create-service` | Create service |\n| 4 | describe-service | `aliyun eas describe-service` | Check status (once) |\n| 5 | describe-service-endpoints | `aliyun eas describe-service-endpoints` | Get endpoints |\n\nExecute #1 and #2 ALWAYS, even if user provided the info.\n`describe-machine-spec` ≠ `list-resources`. `describe-service` ≠ `ListServices`.\n\n**3. Prohibited** — ❌ Reuse existing service\n❌ Write bash scripts (run CLI directly)\n❌ CPU+vLLM/SGLang ❌ `file://` in create-service\n❌ Skip mandatory APIs ❌ Change the service name the user specified\n❌ Poll describe-service in a loop (call once only)\n\n**4. Autonomous Execution** — Do NOT ask user for info discoverable\nvia APIs. Do NOT ask \"should I proceed?\" Execute directly.\nTimeout? Retry with `--read-timeout 60`. Error? Inform user and CONTINUE.\nMissing param? Pick reasonable default.\nIf any pre-check or resource discovery step fails, log the failure\nand continue to the next step. Only STOP for the specific conditions\nlisted in Self-Verify Checkpoints (duplicate service name, missing\nNLB/GW/dedicated resource group).\n\n**5. Self-Verify Checkpoints:**\n```\nBefore Step 2: Did Step 1.5 confirm no duplicate service name?\n  If duplicate → STOP, inform user, do NOT proceed.\nBefore Step 5: Have I run list-images AND describe-machine-spec?\n  If NO → STOP and run them NOW.\nBefore Step 6: Did Step 1.5 confirm no duplicate service name?\n  If duplicate exists → STOP, inform user, do NOT proceed.\nStep 4 resources: If NLB/GW/Resource Group not found → inform user and STOP.\n  Do NOT block or attempt workarounds.\nAfter Step 7: Did I call describe-service once and report the status?\n```\n\n**6. Run CLI commands DIRECTLY** — Use `execute_shell_command` to run\neach aliyun CLI command one at a time. Do NOT write bash scripts,\ndeployment scripts, or shell files. Do NOT use `retry_command()`\nor any wrapper functions. Each command = one direct execution.\n\n---\n\n## Pre-checks\n\n```bash\naliyun configure ai-mode enable\naliyun configure ai-mode set-user-agent \\\n  --user-agent \"AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\"\naliyun plugin update\naliyun configure set --auto-plugin-install true\n```\n\n**⚠️ MANDATORY: Install and update required plugins BEFORE proceeding:**\n```bash\naliyun plugin update\naliyun plugin install aiworkspace --force\naliyun plugin install eas --force\n```\n\n**Verify plugins are installed:**\n```bash\naliyun plugin list 2>/dev/null | grep -E \"aiworkspace|eas\"\n```\n\nIf either plugin is missing after install, retry with:\n```bash\naliyun plugin install <plugin-name> --force\n```\n\nSee [CLI Guide](references/cli-installation-guide.md).\nNever read/echo AK/SK. Timeout? Retry with `--read-timeout 60`.\n\n**⚠️ MANDATORY CHECKPOINT: After pre-checks, you MUST proceed to\nStep 1 regardless of any warnings during plugin installation.\nPlugin install failures are non-blocking — the plugins may already\nbe installed. NEVER stop execution at the pre-check stage.**\n\n---\n\n## Step 1: Collect Parameters\n\n| Param | Required | Default |\n|-------|----------|---------|\n| RegionId | Yes | - |\n| Service Name | Yes | - |\n| Workspace ID | No | Auto-select |\n| Image URI | Yes | - |\n| Instance Type | Yes | - |\n| Replicas | No | 1 |\n| Port | No | 8000 |\n| OSS Path | No | - |\n\n**Service name**: lowercase/digits/underscores only. No hyphens. 3-63 chars.\n**IMPORTANT**: Use the EXACT service name the user specifies. Do NOT rename.\nIf the user specifies a prefix (e.g. \"skill_qwen_开头\"), generate a random suffix of 6 digits (e.g. `skill_qwen_482917`).\n\n**Set profile region** — Set the CLI profile region to match the\ndeployment region. This avoids \"Region mismatch\" errors when\n`--cluster-id` differs from the profile's default region:\n```bash\naliyun configure set --region <region>\n```\n\n**Workspace ID**: Required in `metadata.workspace_id`. If user does not\nspecify a workspace, query available workspaces and pick one:\n```bash\naliyun aiworkspace list-workspaces --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Workspaces[] | select(.Status == \"ENABLED\") | {WorkspaceId, WorkspaceName}'\n```\nIf multiple workspaces exist, list them and let the user choose.\nIf only one exists, use it directly.\n\n## Step 1.5: Check for Duplicate Service Name\n\n```bash\naliyun eas list-services --region <region> --cluster-id <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.ServiceList[] | select(.ServiceName == \"<name>\") | {ServiceName, Status}'\n```\n\n**If a service with the same name already exists → STOP and inform\nthe user: \"A service named <name> already exists (Status: <status>).\nPlease choose a different name.\" Do NOT delete or reuse it.**\n\n**If no duplicate → proceed to Step 2.**\n\n## Step 2: ListImages (🚧 BLOCKING GATE — NEVER SKIP)\n\nExecute even if user provided image URI. Purpose = VALIDATION.\n\n**⚠️ If you see \"parse error\" or \"Exit Code 4\", the plugin\nfailed to install. You MUST retry with explicit install:**\n```bash\naliyun plugin install aiworkspace --force\n```\nThen retry the list-images command. Do NOT skip this step.\n\n```bash\naliyun aiworkspace list-images --region <region> --verbose true \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Images[] | {ImageId, ImageUri, ImageCategory}' > /tmp/eas_images.json\necho \"Saved $(jq length /tmp/eas_images.json) images\"\n```\n\n**If still fails after plugin reinstall, retry with timeout:**\n```bash\naliyun aiworkspace list-images --region <region> --verbose true \\\n  --labels 'system.official=true,system.supported.eas=true' \\\n  --page-size 50 --read-timeout 60 \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Images[] | {ImageId, ImageUri, ImageCategory}' > /tmp/eas_images.json\necho \"Saved $(jq length /tmp/eas_images.json) images\"\n```\nSee [Model-Image](references/model-image-matching.md).\n**This output is REQUIRED by Step 5. Do NOT skip.**\n**❌ NEVER skip this step saying \"user already provided the image\".**\n\n## Step 3: describe-machine-spec (🚧 BLOCKING GATE — NEVER SKIP)\n\nExecute even if user specified instance type. NOT `list-resources`.\n\n**⚠️ If this command fails, retry with `--read-timeout 60`.\nNEVER proceed to Step 5 without /tmp/eas_specs.json existing.**\n\n```bash\naliyun eas describe-machine-spec --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.InstanceTypes[] | select(.GPU > 0) | {InstanceType, CPU, GPU, Memory}' \\\n  > /tmp/eas_specs.json\necho \"Available GPU specs:\"; cat /tmp/eas_specs.json\n```\nCPU→GPU auto-switch: If vLLM/SGLang + CPU, silently pick GPU. Do NOT ask.\n**This output is REQUIRED by Step 5. Do NOT skip.**\n\n## Step 4: Network & Resource Config\n\n| Type | VPC | Config |\n|------|-----|--------|\n| Shared | No | (default, no networking fields) |\n| Dedicated GW | Yes | `networking.gateway` + `cloud.networking` |\n| NLB | Yes | `networking.nlb` + `cloud.networking` |\n\n**⚠️ If a required resource does not exist → STOP and inform the user.\nDo NOT block or attempt workarounds. This is a valid outcome.**\n\n**Dedicated Gateway** — Call `list-gateway`. If no gateway exists →\ninform user and STOP. Otherwise call `describe-gateway` to get\nVPC/VSwitch, then query security group under that VPC.\nIf no security group found → inform user and STOP.\n```bash\naliyun eas list-gateway --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\nIf gateway found, get details:\n```bash\naliyun eas describe-gateway --region <region> --cluster-id <region> \\\n  --gateway-id <gateway_id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\nExtract VPC and comma-separated VSwitch ID:\n```bash\naliyun eas describe-gateway --region <region> --cluster-id <region> \\\n  --gateway-id <gateway_id> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{vpc_id: .LoadBalancerList[0].VpcId, vswitch_id: (.LoadBalancerList[0].VSwitchIds | join(\",\"))}'\n```\n\n**NLB** — Requires VPC/VSwitch/SecurityGroup. If user does not provide\nthem, query via APIs. If any required resource not found → inform\nuser and STOP.\n**⚠️ NLB requires ≥2 VSwitches across different availability zones.**\nUse comma-separated format: `\"vswitch_id\": \"vsw-zone-a,vsw-zone-b\"`.\n**⚠️ NLB Plugin Bug (aliyun-cli-eas v0.2.0):** If create-service with\nNLB config returns 400 with `'vswitch can not be null'` or\n`'vpcId, vswId and securityGroupId are required'`, this is a known\nCLI plugin bug (not a resource issue). **Fallback strategy:**\n1. Retry create-service with NLB config once more (max 2 attempts).\n2. If both fail → Remove `networking.nlb` and `cloud.networking` from\n   service.json, redeploy with shared gateway.\n3. Inform user: \"NLB config failed due to CLI plugin limitation.\n   Deployed with shared gateway instead.\"\n\n**EAS Dedicated Resource Group** — Call `list-resources`.\nFilter for `ResourceType == \"Dedicated\"` and `Status == \"ResourceReady\"`.\n```bash\naliyun eas list-resources --region <region> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '.Resources[] | select(.ResourceType == \"Dedicated\" and .Status == \"ResourceReady\") | {ResourceId, ResourceType, Status}'\n```\n- If exists → Set `\"metadata\": {\"resource\": \"<ResourceId>\"}`.\n  Do NOT set `cloud.computing`.\n- If NOT exists → Inform the user and STOP.\n  Do NOT fall back to public resource group.\n\n## Step 5: Build Service JSON\n\n**⚠️ BEFORE building JSON, you MUST read these reference files:**\n- `references/config-patterns.md` — Complete JSON templates for all 8 patterns\n- `references/config-schema.md` — Field descriptions and validation rules\n- `references/storage-mount.md` — OSS/NAS mount configuration details\n- `references/network-config.md` — NLB/Gateway network configuration details\n\n**⚠️ HARD GATE: Before writing service.json, VERIFY these files\nexist and have content. If either is missing → STOP and run\nthat Step NOW.**\n```\ntest -s /tmp/eas_images.json || echo \"MISSING: Run Step 2 NOW\"\ntest -s /tmp/eas_specs.json || echo \"MISSING: Run Step 3 NOW\"\n```\n\n**⚠️ JSON format rules:**\n- Allowed top-level keys: `metadata`, `containers`, `storage`, `cloud`, `autoscaler`, `networking`\n- ❌ NEVER use as top-level keys: `spec`, `ServiceName`, `Image`, `Cpu`, `Memory`, `Gpu`, `processor_path`, `resourceGroupId`, `instance`, `port`, `command`, `access`\n- ❌ FORBIDDEN fields: `processor_path`, `resourceGroupId`, `spec`, `access`\n- `metadata.name` = service name, `metadata.workspace_id` = workspace (REQUIRED)\n- `containers[].image` = image URI, `containers[].command` = start command, `containers[].port` = port\n- `cloud.computing.instance_type` = instance type (MANDATORY for shared gateway)\n\n### Quick Reference — JSON Skeletons\n\nBelow are minimal skeletons. **Read `references/config-patterns.md` for\ncomplete templates with all fields and examples.**\n\n**Base (Shared Gateway):**\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}],\n \"cloud\":{\"computing\":{\"instance_type\":\"<type>\"}}}\n```\n\n**+ OSS** → add `\"storage\":[{\"mount_path\":\"/dir\",\"oss\":{\"path\":\"oss://<b>/<p>/\",\"readOnly\":true}}]`\n**+ Autoscaling** → add `\"autoscaler\":{\"min\":1,\"max\":4,\"scaleStrategies\":[{\"metricName\":\"qps\",\"threshold\":20}]}`\n**+ Health Check** → add `startup_check` to `containers[]` (see config-patterns.md Pattern 4)\n\n**NLB** — full template (read `references/network-config.md` for details):\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}],\n \"cloud\":{\"computing\":{\"instance_type\":\"<type>\"},\n          \"networking\":{\"vpc_id\":\"<vpc>\",\"vswitch_id\":\"<vsw1>,<vsw2>\",\"security_group_id\":\"<sg>\"}},\n \"networking\":{\"nlb\":[{\"id\":\"default\",\"listener_port\":<p>,\"netType\":\"intranet\"}]}}\n```\n⚠️ `vswitch_id` must be **comma-separated with ≥2 VSwitches across different zones**\n\n**Dedicated Resource Group** — `\"metadata.resource\"` instead of `cloud.computing`:\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"resource\":\"<res_id>\",\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}]}\n```\n\n**Dedicated Gateway** — `networking.gateway` + `cloud.networking`:\n```json\n{\"metadata\":{\"name\":\"<name>\",\"instance\":1,\"workspace_id\":\"<ws>\"},\n \"containers\":[{\"image\":\"<img>\",\"port\":<p>,\"command\":\"<cmd>\"}],\n \"networking\":{\"gateway\":\"<gw_id>\"},\n \"cloud\":{\"computing\":{\"instance_type\":\"<type>\"},\n          \"networking\":{\"vpc_id\":\"<vpc>\",\"vswitch_id\":\"<vsw1>,<vsw2>\",\"security_group_id\":\"<sg>\"}}}\n```\n⚠️ `vswitch_id` comma-separated if gateway returns multiple VSwitches\n\n### Validate Before Writing\n```bash\njq -r '.[] | select(.ImageUri | contains(\"vllm\")) | .ImageUri' /tmp/eas_images.json\njq -r '.[] | select(.InstanceType == \"<type>\") | .InstanceType' /tmp/eas_specs.json\n```\n\n## Step 6: Create Service (MANDATORY)\n\n**🔴 CONFIRM: Did Step 1.5 confirm no duplicate service name?\nIf a service with this name already exists → STOP. Inform the user\nand do NOT proceed with create-service.**\n**Use `$(cat service.json)` NOT `file://service.json`.**\n**Run this DIRECTLY via execute_shell_command, do NOT write a bash script.**\n\n```bash\naliyun eas create-service --region <region> \\\n  --body \"$(cat service.json)\" \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n**409 Conflict** → Service already exists. Inform the user and STOP.\n**400 BadRequest** with `'vswitch can not be null'` or\n`'vpcId, vswId and securityGroupId are required'` → NLB CLI plugin\nbug (see Step 4 fallback). Remove `networking.nlb` and\n`cloud.networking` from service.json and retry.\n\n## Step 7: Verify Deployment\n\n**Call describe-service ONCE to check the current status. Do NOT poll.\nDo NOT loop. Do NOT wait for Running.**\n\n```bash\naliyun eas describe-service --region <region> --cluster-id <region> \\\n  --service-name <name> \\\n  --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{Status, ServiceName, ServiceId}'\n```\n\n**Report whatever status you get (Running, Waiting, Creating, etc.)\nand proceed to Step 8 immediately. create-service returning 200 = success.**\n\n## Step 8: Report Result (MANDATORY)\n\n**Get endpoint info via DescribeServiceEndpoint:**\n```bash\naliyun eas describe-service-endpoints --region <region> --cluster-id <region> \\\n  --service-name <name> --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | \\\n  jq '{AccessToken, Endpoints: [.Endpoints[] | {\n    Type: .EndpointType, Port: .Port,\n    InternetEndpoints: .InternetEndpoints,\n    IntranetEndpoints: .IntranetEndpoints\n  }]}'\n```\n\n**Use the status from Step 7 and the endpoints above to report.**\n\n**Copy the ENTIRE output into your final response. Format:**\n```\nDeployment Summary\n==================\nService Name: <name>\nStatus: <from Step 7>\n\nEndpoints:\n- <EndpointType>:\n    InternetEndpoint: <url or null>\n    IntranetEndpoint: <url or null>\n    Port: <port or 0>\n\nService Invocation Examples:\n  curl <internet-endpoint>/api/predict/<name> \\\n    -H \"Authorization: <AccessToken>\"\n  curl <intranet-endpoint>/api/predict/<name> \\\n    -H \"Authorization: <AccessToken>\"\n  curl <nlb-domain>:<listener_port>/api/predict/<name> \\\n    -H \"Authorization: <AccessToken>\"\n```\n\n**`InternetEndpoint` and `IntranetEndpoint` MUST appear in your\nresponse, even if null.** If null: `(not available for this network type)`\n\n**Always include a service invocation example using the AccessToken\nand endpoint URL.**\n\n**Success criteria: create-service returning 200 with ServiceId =\nsuccess. Any status (Running, Waiting, Creating) is acceptable.**\n\n---\n\nWhen done, disable AI-Mode: `aliyun configure ai-mode disable`\n\n## References (read when needed)\n\n| Doc | When to Read |\n|-----|-------------|\n| [Config Patterns](references/config-patterns.md) | **Step 5** — Complete JSON templates for all 8 patterns |\n| [Config Schema](references/config-schema.md) | **Step 5** — Field descriptions and validation rules |\n| [Storage Mount](references/storage-mount.md) | **Step 5** — OSS/NAS mount details |\n| [Network Config](references/network-config.md) | **Step 4/5** — NLB/Gateway config details |\n| [Model-Image](references/model-image-matching.md) | **Step 2** — Image selection guide |\n| [Related APIs](references/related-apis.md) | **Any step** — CLI command reference |\n| [Workflow](references/deployment-workflow.md) | Overview — Full deployment flow |\n| [CLI Guide](references/cli-installation-guide.md) | Pre-checks — Plugin install |\n| [RAM Policies](references/ram-policies.md) | Pre-checks — Required permissions |\n| [Service Features](references/service-features.md) | Step 5 — Advanced features |\n\nFile v0.0.1-beta.1:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-pai-eas-service-deploy\",\n  \"version\": \"0.0.1-beta.1\",\n  \"publishedAt\": 1776927032293\n}\n\nFile v0.0.1-beta.1:references/acceptance-criteria.md\n\n# Acceptance Criteria: alibabacloud-pai-eas-service-deploy\n\n**Scenario**: PAI-EAS Service Deployment\n**Purpose**: Skill test acceptance criteria\n\n**Table of Contents**\n- [CLI Command Patterns](#correct-cli-command-patterns)\n- [Service Config Validation](#service-config-validation)\n- [Authentication Patterns](#authentication-patterns)\n- [Parameter Confirmation Requirements](#parameter-confirmation-requirements)\n- [Resource Cleanup](#resource-cleanup)\n\n---\n\n# Correct CLI Command Patterns\n\n## 1. EAS Service Operations\n\n### ✅ Correct: Create Service\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\" --user-agent AlibabaCloud-Agent-Skills\n```\n\n### ❌ Wrong: Missing --user-agent\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\"\n```\n\n### ❌ Wrong: Using API format instead of plugin mode\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\"\n```\n\n## 2. AIWorkSpace Operations\n\n### ✅ Correct: List Images\n\n```bash\naliyun aiworkspace list-images --verbose true --labels 'system.official=true,system.supported.eas=true' --page-size 50 --user-agent AlibabaCloud-Agent-Skills\n```\n\n### ❌ Wrong: Labels format error\n\n```bash\naliyun aiworkspace list-images --verbose true --labels 'system.official=true' --user-agent AlibabaCloud-Agent-Skills\n```\n\n## 3. OSS Operations\n\n### ✅ Correct: List Buckets\n\n```bash\nossutil ls\n```\n\n### ✅ Correct: List Objects\n\n```bash\nossutil ls oss://bucket-name/path/\n```\n\n### ❌ Wrong: Missing oss:// prefix\n\n```bash\nossutil ls bucket-name/path/\n```\n\n## 4. VPC Operations\n\n### ✅ Correct: Query VPC\n\n```bash\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --vpc-id vpc-xxx --user-agent AlibabaCloud-Agent-Skills\n```\n\n### ❌ Wrong: Missing user-agent\n\n```bash\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --vpc-id vpc-xxx\n```\n\n---\n\n# Service Config Validation\n\n## 1. metadata Config\n\n### ✅ Correct: Service Name Format\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my-vllm-service\",\n    \"instance\": 1\n  }\n}\n```\n\n### ❌ Wrong: Service name contains uppercase letters\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"My-VLLM-Service\",\n    \"instance\": 1\n  }\n}\n```\n\n### ❌ Wrong: Service name contains special characters\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my.vllm.service\",\n    \"instance\": 1\n  }\n}\n```\n\n## 2. containers Config\n\n### ✅ Correct: Container Config\n\n```json\n{\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000,\n    \"script\": \"vllm serve /models --port 8000\"\n  }]\n}\n```\n\n### ❌ Wrong: Missing port config\n\n```json\n{\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"script\": \"vllm serve /models --port 8000\"\n  }]\n}\n```\n\n## 3. storage Config\n\n### ✅ Correct: OSS Mount\n\n```json\n{\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"oss://bucket/models/\",\n      \"readOnly\": true\n    }\n  }]\n}\n```\n\n### ❌ Wrong: OSS path missing trailing slash\n\n```json\n{\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"oss://bucket/models\",\n      \"readOnly\": true\n    }\n  }]\n}\n```\n\n### ❌ Wrong: Missing oss:// prefix\n\n```json\n{\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": {\n      \"path\": \"bucket/models/\",\n      \"readOnly\": true\n    }\n  }]\n}\n```\n\n## 4. cloud Config\n\n### ✅ Correct: Public Resource Group\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instance_type\": \"ecs.gn7-c12g1.12xlarge\"\n    }\n  }\n}\n```\n\n### ✅ Correct: Multi-spec Instances\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instances\": [\n        {\"type\": \"ecs.gn7-c12g1.12xlarge\"},\n        {\"type\": \"ecs.gn8is.2xlarge\"}\n      ]\n    }\n  }\n}\n```\n\n### ❌ Wrong: Wrong field name\n\n```json\n{\n  \"cloud\": {\n    \"computing\": {\n      \"instanceType\": \"ecs.gn7-c12g1.12xlarge\"\n    }\n  }\n}\n```\n\n## 5. networking Config\n\n### ✅ Correct: Dedicated Gateway\n\n```json\n{\n  \"networking\": {\n    \"gateway\": \"gw-xxx\"\n  }\n}\n```\n\n### ✅ Correct: NLB\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [{\n      \"id\": \"default\",\n      \"listener_port\": 9000,\n      \"netType\": \"intranet\"\n    }]\n  }\n}\n```\n\n### ❌ Wrong: NLB port is 8080 (not allowed)\n\n```json\n{\n  \"networking\": {\n    \"nlb\": [{\n      \"id\": \"default\",\n      \"listener_port\": 8080,\n      \"netType\": \"intranet\"\n    }]\n  }\n}\n```\n\n---\n\n# Authentication Patterns\n\n## ✅ Correct: Using CredentialClient (Python SDK)\n\n```python\nfrom alibabacloud_credentials.client import Client as CredentialClient\nfrom alibabacloud_eas20210701.client import Client as EasClient\nfrom alibabacloud_tea_openapi import models as open_api_models\n\ncredential = CredentialClient()\nconfig = open_api_models.Config(credential=credential)\nconfig.region_id = \"cn-hangzhou\"\nconfig.user_agent = \"AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\"\nclient = EasClient(config)\n```\n\n## ❌ Wrong: Hardcoded AK/SK\n\n```python\nconfig = open_api_models.Config(\n    access_key_id=\"LTAIxxx\",\n    access_key_secret=\"xxx\"\n)\n```\n\n---\n\n# Parameter Confirmation Requirements\n\n## ✅ Correct: All user parameters must be confirmed\n\nThe following parameters must be confirmed before deployment:\n- RegionId (region)\n- Service name\n- Workspace ID\n- Image URI\n- Instance type\n- OSS path (if mounting)\n- Gateway ID (if using dedicated gateway)\n- VPC/VSwitch/Security group (if using ALB/NLB)\n\n## ❌ Wrong: Using default values without confirmation\n\n```bash\n# Wrong: Using default region without asking user\naliyun eas create-service --region cn-hangzhou ...\n```\n\n---\n\n# Resource Cleanup\n\n## ✅ Correct: Cleanup after deployment failure\n\n```bash\naliyun eas delete-service \\\n  --cluster-id cn-hangzhou \\\n  --service-name <service-name> \\\n  --user-agent AlibabaCloud-Agent-Skills\n```\n\n## ❌ Wrong: Not cleaning up failed services\n\nFailure to delete after service creation failure leads to resource waste.\n\nFile v0.0.1-beta.1:references/api-reference.md\n\n# API 参考手册\n\n## API 返回结构\n\n**阿里云 API 返回结构不一致，使用 jq 时需注意**：\n\n| API | jq 路径 | 结构 |\n|-----|---------|------|\n| `AIWorkSpace ListWorkspaces` | `.Workspaces[]` | 单层 |\n| `AIWorkSpace ListImages` | `.Images[]` | 单层 |\n| `eas DescribeMachineSpec` | `.InstanceMetas[]` | 单层 |\n| `eas list-gateway` | `.Gateways[]` | 单层 |\n| `eas ListResources` | `.Resources[]` | 单层 |\n| `eas DescribeService` | `.Service` | 单个对象 |\n| `eas describe-service-event` | `.Events[]` | 单层 |\n| `vpc DescribeVpcs` | `.Vpcs.Vpc[]` | ⚠️ 双层 |\n| `vpc DescribeVSwitches` | `.VSwitches.VSwitch[]` | ⚠️ 双层 |\n| `ecs DescribeSecurityGroups` | `.SecurityGroups.SecurityGroup[]` | ⚠️ 双层 |\n| `nlb ListLoadBalancers` | `.LoadBalancers[]` | 单层 |\n\n## jq 示例\n\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills | jq -r '.Workspaces[] | \"\\(.WorkspaceId)\\t\\(.WorkspaceName)\"'\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills | jq -r '.Gateways[] | \"\\(.GatewayId)\\t\\(.GatewayName)\"'\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --user-agent AlibabaCloud-Agent-Skills | jq -r '.Vpcs.Vpc[] | \"\\(.VpcId)\\t\\(.VpcName)\"'\n```\n\n## CLI 命令参考\n\n### 参数命名规则\n\n| 命令类型 | 参数名 | 示例 |\n|---------|--------|------|\n| 列表类/创建类 | `--region` | `ListServices`, `CreateService` |\n| 针对单个服务 | `--cluster-id` | `DescribeService`, `DeleteService` |\n\n### 常用命令\n\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills\naliyun aiworkspace list-images --verbose true --labels 'system.official=true,system.supported.eas=true' --page-size 100 --user-agent AlibabaCloud-Agent-Skills\naliyun eas describe-machine-spec --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills\naliyun eas list-resources --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills\naliyun eas describe-gateway --cluster-id cn-hangzhou --gateway-id gw-xxx --user-agent AlibabaCloud-Agent-Skills\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\" --user-agent AlibabaCloud-Agent-Skills\naliyun eas describe-service --cluster-id cn-hangzhou --service-name my_service --user-agent AlibabaCloud-Agent-Skills\n```\n\n## 权限列表\n\n详见 [RAM 权限策略](ram-policies.md)\n\n## 常用 GPU 规格\n\n| 规格 | GPU | CPU | 内存 | 适用场景 |\n|------|-----|-----|------|---------|\n| `ecs.gn6i-c4g1.xlarge` | 1× T4 | 4 | 16Gi | 小模型推理 |\n| `ecs.gn6i-c8g1.2xlarge` | 1× T4 | 8 | 32Gi | 中等模型 |\n| `ecs.gn7-c12g1.12xlarge` | 4× A10 | 12 | 192Gi | 大模型推理 |\n\nFile v0.0.1-beta.1:references/cli-installation-guide.md\n\n# Aliyun CLI Installation & Configuration Guide\n\nComplete guide for installing and configuring Aliyun CLI.\n\n> **Aliyun CLI 3.3.1+**: Supports installing and using all published Alibaba Cloud product plugins. Make sure to upgrade to 3.3.1 or later for full plugin ecosystem coverage.\n\n**Table of Contents**\n- [Installation](#installation)\n- [Configuration](#configuration)\n- [Verification](#verification)\n- [Security Best Practices](#security-best-practices)\n- [Troubleshooting](#troubleshooting)\n- [Advanced Configuration](#advanced-configuration)\n- [Next Steps](#next-steps)\n- [References](#references)\n\n## Installation\n\n### macOS\n\n**Using Homebrew (Recommended)**\n```bash\nbrew install aliyun-cli\n# Upgrade to latest\nbrew upgrade aliyun-cli\n\n# Verify version (>= 3.3.1)\naliyun version\n```\n\n**Using Binary**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz\n\n# Extract\ntar -xzf aliyun-cli-macosx-latest-amd64.tgz\n\n# Move to PATH\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n### Linux\n\n**Debian/Ubuntu**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**CentOS/RHEL**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**ARM64 Architecture**\n```bash\n# Download ARM64 version\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-arm64.tgz\nsudo mv aliyun /usr/local/bin/\n```\n\n### Windows\n\n**Using Binary**\n1. Download from: https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\n2. Extract the ZIP file\n3. Add the directory to your PATH environment variable\n4. Open new Command Prompt or PowerShell\n5. Verify: `aliyun version`\n\n**Using PowerShell**\n```powershell\n# Download\nInvoke-WebRequest -Uri \"https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\" -OutFile \"aliyun-cli.zip\"\n\n# Extract\nExpand-Archive -Path aliyun-cli.zip -DestinationPath C:\\aliyun-cli\n\n# Add to PATH (requires admin privileges)\n$env:Path += \";C:\\aliyun-cli\"\n[Environment]::SetEnvironmentVariable(\"Path\", $env:Path, [System.EnvironmentVariableTarget]::Machine)\n\n# Verify\naliyun version\n```\n\n## Configuration\n\n### Quick Start\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id <your-access-key-id> \\\n  --access-key-secret <your-access-key-secret> \\\n  --region cn-hangzhou\n```\n\nAll `aliyun configure` commands support non-interactive flags, which is the recommended approach —\nit works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts.\n\n**Where to Get Access Keys**\n\n1. Log in to Aliyun Console: https://ram.console.aliyun.com/\n2. Navigate to: AccessKey Management\n3. Create a new AccessKey pair\n4. Save the secret immediately — it's only shown once\n\n### Configuration Modes\n\nAliyun CLI supports 6 authentication modes. All examples below use non-interactive flags.\n\n#### 1. AK Mode (Access Key)\n\nMost common mode for personal accounts and scripts.\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nConfiguration is stored in `~/.aliyun/config.json`:\n\n```json\n{\n  \"current\": \"default\",\n  \"profiles\": [\n    {\n      \"name\": \"default\",\n      \"mode\": \"AK\",\n      \"access_key_id\": \"LTAI5tXXXXXXXX\",\n      \"access_key_secret\": \"8dXXXXXXXXXXXXXXXXXXXXXXXX\",\n      \"region_id\": \"cn-hangzhou\",\n      \"output_format\": \"json\",\n      \"language\": \"en\"\n    }\n  ]\n}\n```\n\n#### 2. StsToken Mode (Temporary Credentials)\n\nFor short-lived access (tokens expire in 1-12 hours).\n\n```bash\naliyun configure set \\\n  --mode StsToken \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --sts-token v1.0:XXXXXXXXXXXXXXXX \\\n  --region cn-hangzhou\n```\n\nUse cases: CI/CD pipelines, temporary access for external contractors, cross-account access.\n\n#### 3. RamRoleArn Mode (Assume RAM Role)\n\nAssume a RAM role for elevated or cross-account access.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArn \\\n  --access-key-id LTAI5tXXXXXXXX \\\n  --access-key-secret 8dXXXXXXXXXXXXXXXXXXXXXXXX \\\n  --ram-role-arn acs:ram::123456789012:role/AdminRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\nUse cases: cross-account resource access, temporary elevated privileges, role-based access control.\n\n#### 4. EcsRamRole Mode (ECS Instance RAM Role)\n\nUse the RAM role attached to an ECS instance — no credentials needed.\n\n```bash\naliyun configure set \\\n  --mode EcsRamRole \\\n  --ram-role-name MyEcsRole \\\n  --region cn-hangzhou\n```\n\nRequirements: must be running on an ECS instance with a RAM role attached.\n\nUse cases: scripts and automation running on ECS instances.\n\n#### 5. RsaKeyPair Mode (RSA Key Pair)\n\nUse RSA key pair for authentication (generate key pair in Aliyun Console first).\n\n```bash\naliyun configure set \\\n  --mode RsaKeyPair \\\n  --private-key /path/to/private-key.pem \\\n  --key-pair-name my-key-pair \\\n  --region cn-hangzhou\n```\n\n#### 6. RamRoleArnWithEcs Mode (ECS + RAM Role)\n\nCombine ECS instance role with RAM role assumption for cross-account access from ECS.\n\n```bash\naliyun configure set \\\n  --mode RamRoleArnWithEcs \\\n  --ram-role-name MyEcsRole \\\n  --ram-role-arn acs:ram::123456789012:role/TargetRole \\\n  --role-session-name my-session \\\n  --region cn-hangzhou\n```\n\n### Environment Variables\n\n**Highest priority** - overrides config file\n\n**Access Key Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**STS Token Mode**\n```bash\nexport ALIBABA_CLOUD_ACCESS_KEY_ID=your_access_key_id\nexport ALIBABA_CLOUD_ACCESS_KEY_SECRET=your_access_key_secret\nexport ALIBABA_CLOUD_SECURITY_TOKEN=your_sts_token\nexport ALIBABA_CLOUD_REGION_ID=cn-hangzhou\n```\n\n**ECS RAM Role Mode**\n```bash\nexport ALIBABA_CLOUD_ECS_METADATA=role_name\n```\n\n**Use Case**:\n- CI/CD pipelines\n- Docker containers\n- Temporary credential override\n\n### Managing Multiple Profiles\n\n**Create Named Profiles**\n\n```bash\naliyun configure set --profile projectA \\\n  --mode AK \\\n  --access-key-id LTAI5tAAAAAAAA \\\n  --access-key-secret 8dAAAAAAAAAAAAAAAAAAAAAAAA \\\n  --region cn-hangzhou\n\naliyun configure set --profile projectB \\\n  --mode AK \\\n  --access-key-id LTAI5tBBBBBBBB \\\n  --access-key-secret 8dBBBBBBBBBBBBBBBBBBBBBBBB \\\n  --region cn-shanghai\n```\n\n**Use Specific Profile**\n\n```bash\naliyun ecs describe-instances --profile projectA\n\nexport ALIBABA_CLOUD_PROFILE=projectA\naliyun ecs describe-instances   # Uses projectA\n```\n\n**List and Switch Profiles**\n\n```bash\naliyun configure list                      # List all profiles\naliyun configure set --current projectA    # Switch default profile\n```\n\n### Credential Priority\n\nCredentials are loaded in this order (first found wins):\n\n1. **Command-line flag**: `--profile <name>`\n2. **Environment variable**: `ALIBABA_CLOUD_PROFILE`\n3. **Environment credentials**: `ALIBABA_CLOUD_ACCESS_KEY_ID`, etc.\n4. **Configuration file**: `~/.aliyun/config.json` (current profile)\n5. **ECS Instance RAM Role**: If running on ECS with attached role\n\n## Verification\n\n### Test Authentication\n\n```bash\n# Basic test - list regions\naliyun ecs describe-regions\n\n# Expected output: JSON array of regions\n```\n\n**If successful**, you'll see:\n```json\n{\n  \"Regions\": {\n    \"Region\": [\n      {\n        \"RegionId\": \"cn-hangzhou\",\n        \"RegionEndpoint\": \"ecs.cn-hangzhou.aliyuncs.com\",\n        \"LocalName\": \"华东 1（杭州）\"\n      },\n      ...\n    ]\n  },\n  \"RequestId\": \"...\"\n}\n```\n\n**If failed**, you'll see error messages:\n- `InvalidAccessKeyId.NotFound` - Wrong Access Key ID\n- `SignatureDoesNotMatch` - Wrong Access Key Secret\n- `InvalidSecurityToken.Expired` - STS token expired (for StsToken mode)\n- `Forbidden.RAM` - Insufficient permissions\n\n### Debug Configuration\n\n```bash\n# Show current configuration\naliyun configure get\n\n# Test with debug logging\naliyun ecs describe-regions --log-level=debug\n\n# Check credential provider\naliyun configure get mode\n```\n\n## Security Best Practices\n\n### 1. Use RAM Users (Not Root Account)\n\n❌ **Don't**: Use Aliyun root account credentials\n✅ **Do**: Create RAM users with specific permissions\n\n```bash\n# Create RAM user in console\n# Attach only necessary policies\n# Use RAM user's access keys\n```\n\n### 2. Principle of Least Privilege\n\nGrant only the minimum permissions needed:\n\n```bash\n# Example: Read-only ECS access\n# Attach policy: AliyunECSReadOnlyAccess\n```\n\n### 3. Rotate Access Keys Regularly\n\n```bash\n# Create new access key in RAM Console, then update configuration\naliyun configure set --access-key-id NEW_KEY --access-key-secret NEW_SECRET\n# Delete old access key from console\n```\n\n### 4. Use STS Tokens for Temporary Access\n\n```bash\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token XXXX --region cn-hangzhou\n```\n\n### 5. Use ECS RAM Roles When Possible\n\n```bash\naliyun configure set --mode EcsRamRole --ram-role-name MyRole --region cn-hangzhou\n```\n\n### 6. Never Commit Credentials\n\n```bash\n# Add to .gitignore\necho \"~/.aliyun/config.json\" >> .gitignore\n\n# Use environment variables in CI/CD instead\n```\n\n### 7. Secure Config File\n\n```bash\n# Restrict permissions\nchmod 600 ~/.aliyun/config.json\n```\n\n## Troubleshooting\n\n### Issue: Command Not Found\n\n```bash\n# Check installation\nwhich aliyun\n\n# Check PATH\necho $PATH\n\n# Reinstall or add to PATH\n```\n\n### Issue: Authentication Failed\n\n```bash\n# Verify configuration\naliyun configure get\n\n# Test with debug\naliyun ecs describe-regions --log-level=debug\n\n# Check credentials in console\n# Verify access key is active\n```\n\n### Issue: Permission Denied\n\n```bash\n# Error: Forbidden.RAM\n\n# Check RAM user permissions\n# Attach necessary policies in RAM console\n# Example: AliyunECSFullAccess for ECS operations\n```\n\n### Issue: STS Token Expired\n\n```bash\n# Error: InvalidSecurityToken.Expired\n\n# Reconfigure with new token\naliyun configure set --mode StsToken \\\n  --access-key-id XXXX --access-key-secret XXXX \\\n  --sts-token NEW_TOKEN --region cn-hangzhou\n```\n\n### Issue: Wrong Region\n\n```bash\n# Some resources may not exist in the specified region\n\n# Check available regions\naliyun ecs describe-regions\n\n# Update default region\naliyun configure set region cn-shanghai\n```\n\n## Advanced Configuration\n\n### Custom Endpoint\n\n```bash\n# Use custom or private endpoint\nexport ALIBABA_CLOUD_ECS_ENDPOINT=ecs-vpc.cn-hangzhou.aliyuncs.com\n```\n\n### Proxy Settings\n\n```bash\n# HTTP proxy\nexport HTTP_PROXY=http://proxy.example.com:8080\nexport HTTPS_PROXY=http://proxy.example.com:8080\n\n# No proxy for specific domains\nexport NO_PROXY=localhost,127.0.0.1,.aliyuncs.com\n```\n\n### Timeout Settings\n\n```bash\n# Connection timeout (default: 10s)\nexport ALIBABA_CLOUD_CONNECT_TIMEOUT=30\n\n# Read timeout (default: 10s)\nexport ALIBABA_CLOUD_READ_TIMEOUT=30\n```\n\n## Next Steps\n\nAfter installation and configuration:\n\n1. **Install plugins** for services you need (v3.3.1+ supports all published product plugins):\n   ```bash\n   aliyun plugin install --names ecs vpc rds\n\n   # List all available plugins\n   aliyun plugin list-remote\n   ```\n\n2. **Explore commands**:\n   ```bash\n   aliyun ecs --help\n   aliyun fc --help\n   ```\n\n3. **Read documentation**:\n   - [Command Syntax Guide](./command-syntax.md)\n   - [Global Flags Reference](./global-flags.md)\n   - [Common Scenarios](./common-scenarios.md)\n\n## References\n\n- Official Documentation: https://help.aliyun.com/zh/cli/\n- RAM Console: https://ram.console.aliyun.com/\n- Access Key Management: https://ram.console.aliyun.com/manage/ak\n- Plugin Repository: https://github.com/aliyun/aliyun-cli\n\nFile v0.0.1-beta.1:references/config-examples.md\n\n# 服务配置示例\n\n**目录**\n- [JSON 字段规范](#json-字段规范重要)\n- [容器模式配置](#容器模式配置重要)\n- [基础配置](#基础配置)\n- [完整配置](#完整配置)\n- [公共资源组配置](#公共资源组配置)\n- [专属资源组配置](#专属资源组配置)\n- [ALB 网关配置](#alb-网关配置)\n- [NLB 配置](#nlb-配置)\n- [自动扩缩容配置](#自动扩缩容配置)\n- [存储挂载配置](#存储挂载配置)\n\n## ⚠️ JSON 字段规范（重要）\n\n**服务名称必须放在 `metadata.name` 字段**，不是顶层字段：\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my-service\",    // ✅ 正确：服务名称在这里\n    \"instance\": 1\n  }\n}\n```\n\n**错误示例**：\n\n```json\n{\n  \"service_name\": \"my-service\",  // ❌ 错误：这是无效字段\n  \"name\": \"my-service\"           // ❌ 错误：不在 metadata 中\n}\n```\n\n## 容器模式配置（重要）\n\n使用镜像部署时，必须配置 `containers` 字段：\n\n```json\n{\n  \"metadata\": { \"name\": \"my-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"镜像地址\",\n    \"port\": 8000,\n    \"command\": \"启动命令\"\n  }],\n  \"storage\": [{ \"mount_path\": \"/model_dir\", \"oss\": { \"path\": \"oss://bucket/models/\" } }],\n  \"cloud\": { \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" } }\n}\n```\n\n**关键字段**：\n- `metadata.name` - 服务名称（必填）\n- `containers[].image` - 镜像地址（必填）\n- `containers[].port` - 服务端口（必填）\n- `containers[].command` - 启动命令（可选）\n\n**⚠️ 注意**：使用 `containers` 字段，不要使用 `processor` 或 `processor_path`。\n\n## 基础配置\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"simple_service\",\n    \"instance\": 1\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" }\n  }\n}\n```\n\n## 完整配置\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"myservice\",\n    \"instance\": 2,\n    \"workspace_id\": \"368951\",\n    \"disk\": \"30Gi\",\n    \"shm_size\": 100,\n    \"enable_grpc\": true\n  },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000,\n    \"env\": [\n      {\"name\": \"NCCL_P2P_DISABLE\", \"value\": \"1\"}\n    ]\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6e-c12g1.12xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"vpc-xxx\",\n      \"vswitch_id\": \"vsw-xxx\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://my-bucket/models/llama-7b\", \"readOnly\": true }\n  }],\n  \"networking\": { \"gateway\": \"gw-xxx\" },\n  \"autoscaler\": {\n    \"min\": 1,\n    \"max\": 10,\n    \"scaleStrategies\": [{ \"metricName\": \"qps\", \"threshold\": 100 }]\n  }\n}\n```\n\n## 公共资源组配置\n\n```json\n{\n  \"metadata\": { \"name\": \"public-resource-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" }\n  },\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://my-bucket/models/\" }\n  }]\n}\n```\n\n## 专属资源组配置\n\n```json\n{\n  \"metadata\": { \"name\": \"dedicated-resource-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" }\n  },\n  \"resource\": \"eas-r-xxx\",\n  \"storage\": [{\n    \"mount_path\": \"/models\",\n    \"oss\": { \"path\": \"oss://my-bucket/models/\" }\n  }]\n}\n```\n\n## ALB 网关配置\n\n```json\n{\n  \"metadata\": { \"name\": \"alb-gateway-service\", \"instance\": 1 },\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000\n  }],\n  \"cloud\": {\n    \"computing\": { \"instance_type\": \"ecs.gn6i-c8g1.2xlarge\" },\n    \"networking\": {\n      \"vpc_id\": \"{从网关获取}\",\n      \"vswitch_id\": \"{从网关获取}\",\n      \"security_group_id\": \"sg-xxx\"\n    }\n  },\n  \"net","readmeExcerpt":"Skill: Alibabacloud Pai Eas Service Deploy Owner: sdk-team Summary: Deploy AI models as PAI-EAS inference services. Supports LLMs (Qwen, Llama), image gen (SD, SDXL), speech synthesis, and more. When to use: deploy models, cr... Tags: latest:0.0.1 Version history: v0.0.1 | 2026-07-13T07:59:30.842Z | auto Initial release of the PAI-EAS Inference Service Deployment skill. - Provides end-to-end workflow to deploy AI mod","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Before Step 2: Did Step 1.5 confirm no duplicate service name?\n  If duplicate → STOP, inform user, do NOT proceed.\nBefore Step 5: Have I run list-images AND describe-machine-spec?\n  If NO → STOP and run them NOW.\nBefore Step 6: Did Step 1.5 confirm no duplicate service name?\n  If duplicate exists → STOP, inform user, do NOT proceed.\nStep 4 resources: If NLB/GW/Resource Group not found → inform user and STOP.\n  Do NOT block or attempt workarounds.\nAfter Step 7: Did I call describe-service once and report the status?"},{"language":"bash","snippet":"curl -fsSL https://aliyuncli.alicdn.com/install.sh | bash"},{"language":"bash","snippet":"# Install or upgrade Aliyun CLI to >= 3.3.3 (required baseline), then verify.\ncurl -fsSL https://aliyuncli.alicdn.com/install.sh | bash\naliyun version   # must report >= 3.3.3; re-run install.sh to upgrade if lower\n\n# Generate the per-session trace id once (see Observability section) and build\n# the unified user-agent. Pass it via --user-agent on every CLI command.\nSESSION_ID=$(openssl rand -hex 16)\nUA=\"AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy/${SESSION_ID}\"\naliyun plugin update\naliyun configure set --auto-plugin-install true"},{"language":"bash","snippet":"aliyun plugin update\naliyun plugin install aiworkspace --force\naliyun plugin install eas --force"},{"language":"bash","snippet":"aliyun plugin list 2>/dev/null | grep -E \"aiworkspace|eas\""},{"language":"bash","snippet":"aliyun plugin install <plugin-name> --force"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: alibabacloud-pai-eas-service-deploy\ndescription: |\n  Deploy AI models as PAI-EAS inference services.\n  Supports LLMs (Qwen, Llama), image gen (SD, SDXL),\n  speech synthesis, and more.\n  When to use: deploy models, create inference services,\n  EAS deployment, model serving, deploy vLLM/SGLang/ComfyUI.\nlicense: Apache-2.0\nmetadata:\n  version: \"1.0.0\"\n  domain: aiops\n  owner: pai-eas-team\n  contact: pai-eas-agent@alibaba-inc.com\n  tags:\n    - pai-eas\n    - model-deployment\n    - inference-service\n    - llm\n    - vllm\n    - sglang\n  required_tools:\n    - aliyun\n    - jq\n  prerequisites:\n    - \"Aliyun CLI >= 3.3.3\"\n    - \"jq command-line JSON processor\"\n  required_permissions:\n    - \"eas:CreateService\"\n    - \"eas:DescribeService\"\n    - \"eas:ListServices\"\n    - \"eas:DescribeMachineSpec\"\n    - \"eas:ListResources\"\n    - \"eas:ListGateway\"\n    - \"eas:DescribeGateway\"\n    - \"nlb:ListLoadBalancers\"\n    - \"aiworkspace:ListImages\"\n    - \"aiworkspace:ListWorkspaces\"\n    - \"vpc:DescribeVpcs\"\n    - \"vpc:DescribeVSwitches\"\n    - \"ecs:DescribeSecurityGroups\"\n---\n# PAI-EAS Service Deployment\n\n## ⚠️ TOP RULES (read first)\n\n**1. 🔴 NO DUPLICATE SERVICE NAMES** 🔴\n\nIf a service with the target name already exists: STOP and inform\nthe user. Do NOT delete and recreate. Do NOT reuse it either.\n\n**2. Mandatory API Calls** — Execute ALL of these in order:\n\n| # | API | CLI | Purpose |\n|---|-----|-----|---------|\n| 1 | ListImages | `aliyun aiworkspace list-images` | Validate image |\n| 2 | describe-machine-spec | `aliyun eas describe-machine-spec` | Validate GPU type |\n| 3 | create-service | `aliyun eas create-service` | Create service |\n| 4 | describe-service | `aliyun eas describe-service` | Check status (once) |\n| 5 | describe-service-endpoints | `aliyun eas describe-service-endpoints` | Get endpoints |\n\nExecute #1 and #2 ALWAYS, even if user provided the info.\n`describe-machine-spec` ≠ `list-resources`. `describe-service` ≠ `ListServices`.\n\n**3. Prohibited** — ❌ Reuse existing service\n❌ Write bash scripts (run CLI directly)\n❌ CPU+vLLM/SGLang ❌ `file://` in create-service\n❌ Skip mandatory APIs ❌ Change the service name the user specified\n❌ Poll describe-service in a loop (call once only)\n❌ Stop after writing/validating service.json — writing the JSON is\nNOT completing the task. You MUST run create-service (Step 6) then\ndescribe-service (Step 7). If resources were found, deploy them.\n\n**4. Autonomous Execution** — Do NOT ask user for info discoverable\nvia APIs. Do NOT ask \"should I proceed?\" Execute directly.\nTimeout? Retry with `--read-timeout 60`. Error? Inform user and CONTINUE.\nMissing param? Pick reasonable default.\nIf any pre-check or resource discovery step fails, log the failure\nand continue to the next step. Only STOP for the specific conditions\nlisted in Self-Verify Checkpoints (duplicate service name, missing\nNLB/GW/dedicated resource group).\n\n**5. Self-Verify Checkpoints:**\n```\nBefore Step 2: Did Step 1.5 confirm no duplicate service name?\n  If duplicat"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-pai-eas-service-deploy\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1783929570842\n}"},{"path":"references/acceptance-criteria.md","content":"# Acceptance Criteria: alibabacloud-pai-eas-service-deploy\n\n**Scenario**: PAI-EAS Service Deployment\n**Purpose**: Skill test acceptance criteria\n\n**Table of Contents**\n- [CLI Command Patterns](#correct-cli-command-patterns)\n- [Service Config Validation](#service-config-validation)\n- [Authentication Patterns](#authentication-patterns)\n- [Parameter Confirmation Requirements](#parameter-confirmation-requirements)\n- [Resource Cleanup](#resource-cleanup)\n\n---\n\n# Correct CLI Command Patterns\n\n## 1. EAS Service Operations\n\n### ✅ Correct: Create Service\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\" --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n### ❌ Wrong: Missing --user-agent\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\"\n```\n\n### ❌ Wrong: Using API format instead of plugin mode\n\n```bash\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\"\n```\n\n## 2. AIWorkSpace Operations\n\n### ✅ Correct: List Images\n\n```bash\naliyun aiworkspace list-images --verbose true --labels 'system.official=true,system.supported.eas=true' --page-size 50 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n### ❌ Wrong: Labels format error\n\n```bash\naliyun aiworkspace list-images --verbose true --labels 'system.official=true' --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n## 3. OSS Operations\n\n### ✅ Correct: List Buckets\n\n```bash\nossutil ls\n```\n\n### ✅ Correct: List Objects\n\n```bash\nossutil ls oss://bucket-name/path/\n```\n\n### ❌ Wrong: Missing oss:// prefix\n\n```bash\nossutil ls bucket-name/path/\n```\n\n## 4. VPC Operations\n\n### ✅ Correct: Query VPC\n\n```bash\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --vpc-id vpc-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n### ❌ Wrong: Missing user-agent\n\n```bash\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --vpc-id vpc-xxx\n```\n\n---\n\n# Service Config Validation\n\n## 1. metadata Config\n\n### ✅ Correct: Service Name Format\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my-vllm-service\",\n    \"instance\": 1\n  }\n}\n```\n\n### ❌ Wrong: Service name contains uppercase letters\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"My-VLLM-Service\",\n    \"instance\": 1\n  }\n}\n```\n\n### ❌ Wrong: Service name contains special characters\n\n```json\n{\n  \"metadata\": {\n    \"name\": \"my.vllm.service\",\n    \"instance\": 1\n  }\n}\n```\n\n## 2. containers Config\n\n### ✅ Correct: Container Config\n\n```json\n{\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"port\": 8000,\n    \"script\": \"vllm serve /models --port 8000\"\n  }]\n}\n```\n\n### ❌ Wrong: Missing port config\n\n```json\n{\n  \"containers\": [{\n    \"image\": \"eas-registry-vpc.cn-hangzhou.cr.aliyuncs.com/pai-eas/vllm:0.14.0-gpu\",\n    \"script\": \"vllm serve /models --port 8000\"\n  }]\n}\n```\n\n## 3. storage Config\n\n### ✅ Correct: OSS Mount\n\n```json\n{\n  \"storage\": [{\n    \"moun"},{"path":"references/api-reference.md","content":"# API Reference\n\n## API Response Structures\n\n**Alibaba Cloud API response structures are inconsistent — pay attention when using jq:**\n\n| API | jq Path | Structure |\n|-----|---------|-----------|\n| `AIWorkSpace ListWorkspaces` | `.Workspaces[]` | single-level |\n| `AIWorkSpace ListImages` | `.Images[]` | single-level |\n| `eas DescribeMachineSpec` | `.InstanceMetas[]` | single-level |\n| `eas list-gateway` | `.Gateways[]` | single-level |\n| `eas ListResources` | `.Resources[]` | single-level |\n| `eas DescribeService` | `.Service` | single object |\n| `eas describe-service-event` | `.Events[]` | single-level |\n| `vpc DescribeVpcs` | `.Vpcs.Vpc[]` | ⚠️ nested (two-level) |\n| `vpc DescribeVSwitches` | `.VSwitches.VSwitch[]` | ⚠️ nested (two-level) |\n| `ecs DescribeSecurityGroups` | `.SecurityGroups.SecurityGroup[]` | ⚠️ nested (two-level) |\n| `nlb ListLoadBalancers` | `.LoadBalancers[]` | single-level |\n\n## jq Examples\n\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Workspaces[] | \"\\(.WorkspaceId)\\t\\(.WorkspaceName)\"'\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Gateways[] | \"\\(.GatewayId)\\t\\(.GatewayName)\"'\naliyun vpc describe-vpcs --biz-region-id cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy | jq -r '.Vpcs.Vpc[] | \"\\(.VpcId)\\t\\(.VpcName)\"'\n```\n\n## CLI Command Reference\n\n### Parameter Naming Rules\n\n| Command type | Parameter | Example |\n|--------------|-----------|---------|\n| List / create | `--region` | `ListServices`, `CreateService` |\n| Target a single service | `--cluster-id` | `DescribeService`, `DeleteService` |\n\n### Common Commands\n\n```bash\naliyun aiworkspace list-workspaces --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun aiworkspace list-images --verbose true --labels 'system.official=true,system.supported.eas=true' --page-size 100 --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas describe-machine-spec --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas list-resources --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas list-gateway --region cn-hangzhou --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas describe-gateway --cluster-id cn-hangzhou --gateway-id gw-xxx --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas create-service --region cn-hangzhou --body \"$(cat service.json)\" --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\naliyun eas describe-service --cluster-id cn-hangzhou --service-name my_service --user-agent AlibabaCloud-Agent-Skills/alibabacloud-pai-eas-service-deploy\n```\n\n## Permission List\n\nSee [RAM Policies](ram-polic"},{"path":"references/cli-installation-guide.md","content":"# Aliyun CLI Installation & Configuration Guide\n\nComplete guide for installing and configuring Aliyun CLI.\n\n> **Aliyun CLI 3.3.3+**: Supports installing and using all published Alibaba Cloud product plugins. Make sure to upgrade to 3.3.3 or later for full plugin ecosystem coverage.\n\n**Table of Contents**\n- [Installation](#installation)\n- [Configuration](#configuration)\n- [Verification](#verification)\n- [Security Best Practices](#security-best-practices)\n- [Troubleshooting](#troubleshooting)\n- [Advanced Configuration](#advanced-configuration)\n- [Next Steps](#next-steps)\n- [References](#references)\n\n## Installation\n\n### macOS\n\n**Using Homebrew (Recommended)**\n```bash\nbrew install aliyun-cli\n# Upgrade to latest\nbrew upgrade aliyun-cli\n\n# Verify version (>= 3.3.3)\naliyun version\n```\n\n**Using Binary**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-macosx-latest-amd64.tgz\n\n# Extract\ntar -xzf aliyun-cli-macosx-latest-amd64.tgz\n\n# Move to PATH\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n### Linux\n\n**Debian/Ubuntu**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**CentOS/RHEL**\n```bash\n# Download\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-amd64.tgz\nsudo mv aliyun /usr/local/bin/\n\n# Verify\naliyun version\n```\n\n**ARM64 Architecture**\n```bash\n# Download ARM64 version\nwget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-arm64.tgz\n\n# Extract and install\ntar -xzf aliyun-cli-linux-latest-arm64.tgz\nsudo mv aliyun /usr/local/bin/\n```\n\n### Windows\n\n**Using Binary**\n1. Download from: https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\n2. Extract the ZIP file\n3. Add the directory to your PATH environment variable\n4. Open new Command Prompt or PowerShell\n5. Verify: `aliyun version`\n\n**Using PowerShell**\n```powershell\n# Download\nInvoke-WebRequest -Uri \"https://aliyuncli.alicdn.com/aliyun-cli-windows-latest-amd64.zip\" -OutFile \"aliyun-cli.zip\"\n\n# Extract\nExpand-Archive -Path aliyun-cli.zip -DestinationPath C:\\aliyun-cli\n\n# Add to PATH (requires admin privileges)\n$env:Path += \";C:\\aliyun-cli\"\n[Environment]::SetEnvironmentVariable(\"Path\", $env:Path, [System.EnvironmentVariableTarget]::Machine)\n\n# Verify\naliyun version\n```\n\n## Configuration\n\n### Quick Start\n\n```bash\naliyun configure set \\\n  --mode AK \\\n  --access-key-id <your-access-key-id> \\\n  --access-key-secret <your-access-key-secret> \\\n  --region cn-hangzhou\n```\n\nAll `aliyun configure` commands support non-interactive flags, which is the recommended approach —\nit works in scripts, CI/CD pipelines, and agent-driven automation without hanging on stdin prompts.\n\n**Where to Get Access Keys**\n\n1. Log in to Aliyun Console: https://ram.console.aliyun.com/\n2. Navigate to: AccessKey Management\n3. Create a new AccessKey pair\n4. Save t"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1414,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T12:49:57.117Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T12:49:57.117Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:17:14.481Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}