The Application Real-Time Monitoring Service (ARMS) agent must maintain network connectivity to the server-side to function properly. This topic describes the network requirements for data reporting in the default and non-default Cloud Monitor workspaces, and how to check network connectivity.
Network connectivity requirements for the default Cloud Monitor workspace
The default Cloud Monitor workspace uses the original ARMS data reporting link.
Ports to open
Port | Description |
80 | Provided by the trace and metadata endpoint, metrics endpoint, continuous profiling service, and agent self-monitoring service for data reporting. |
8080 | Provided by the ACM service for application configuration. |
8848 | Provided by the ACM service for application configuration. |
9990 | Provided by the trace and metadata endpoint for metadata reporting. |
9092 | Provided by the trace and metadata endpoint for application diagnostics. |
9093 | Provided by the trace and metadata endpoint for application security. |
Domains to open
If your application is deployed in an Virtual Private Cloud (VPC), including scenarios where your on-premises data center is connected to a VPC via Express Connect, use the private endpoint preferentially. If your application is deployed in an on-premises data center or another cloud, use the public endpoint.
Region | Public endpoint | Private endpoint (VPC) |
China (Hangzhou) | arms-dc-hz.aliyuncs.com (trace and metadata) | arms-dc-hz-internal.aliyuncs.com (trace and metadata) |
China (Shanghai) | arms-dc-sh.aliyuncs.com (trace and metadata) | arms-dc-sh-internal.aliyuncs.com (trace and metadata) |
China (Qingdao) | arms-dc-qd.aliyuncs.com (trace and metadata) | arms-dc-qd-internal.aliyuncs.com (trace and metadata) |
China (Beijing) | arms-dc-bj.aliyuncs.com (trace and metadata) | arms-dc-bj-internal.aliyuncs.com (trace and metadata) |
China (Zhangjiakou) | arms-dc-zb.aliyuncs.com (trace and metadata) | arms-dc-zb-internal.aliyuncs.com (trace and metadata) |
China (Hohhot) | dc-cn-huhehaote.arms.aliyuncs.com (trace and metadata) | dc-cn-huhehaote-internal.arms.aliyuncs.com (trace and metadata) |
China (Ulanqab) | dc-cn-wulanchabu.arms.aliyuncs.com (trace and metadata) | dc-cn-wulanchabu-internal.arms.aliyuncs.com (trace and metadata) |
China (Shenzhen) | arms-dc-sz.aliyuncs.com (trace and metadata) | arms-dc-sz-internal.aliyuncs.com (trace and metadata) |
China (Heyuan) | dc-cn-heyuan.arms.aliyuncs.com (trace and metadata) | dc-cn-heyuan-internal.arms.aliyuncs.com (trace and metadata) |
China (Guangzhou) | dc-cn-guangzhou.arms.aliyuncs.com (trace and metadata) | dc-cn-guangzhou-internal.arms.aliyuncs.com (trace and metadata) |
China (Chengdu) | dc-cn-chengdu.arms.aliyuncs.com (trace and metadata) | dc-cn-chengdu-internal.arms.aliyuncs.com (trace and metadata) |
China (Hong Kong) | arms-dc-hk.aliyuncs.com (trace and metadata) | arms-dc-hk-internal.aliyuncs.com (trace and metadata) |
Japan (Tokyo) | arms-dc-jp.aliyuncs.com (trace and metadata) | arms-dc-jp-internal.aliyuncs.com (trace and metadata) |
Singapore | arms-dc-sg.aliyuncs.com (trace and metadata) | arms-dc-sg-internal.aliyuncs.com (trace and metadata) |
Malaysia (Kuala Lumpur) | dc-ap-southeast-3.arms.aliyuncs.com (trace and metadata) | dc-ap-southeast-3-internal.arms.aliyuncs.com (trace and metadata) |
Indonesia (Jakarta) | arms-dc-indonesia.aliyuncs.com (trace and metadata) | arms-dc-indonesia-internal.aliyuncs.com (trace and metadata) |
Germany (Frankfurt) | arms-dc-frankfurt.aliyuncs.com (trace and metadata) | arms-dc-frankfurt-internal.aliyuncs.com (trace and metadata) |
UK (London) | dc-eu-west-1.arms.aliyuncs.com (trace and metadata) | dc-eu-west-1-internal.arms.aliyuncs.com (trace and metadata) |
US (Virginia) | dc-us-east-1.arms.aliyuncs.com (trace and metadata) | dc-us-east-1-internal.arms.aliyuncs.com (trace and metadata) |
US (Silicon Valley) | arms-dc-usw.aliyuncs.com (trace and metadata) | dc-us-west-1-internal.arms.aliyuncs.com (trace and metadata) |
Alibaba Gov Cloud | arms-dc-gov.aliyuncs.com (trace and metadata) | arms-dc-gov-internal.aliyuncs.com (trace and metadata) |
Alibaba Finance Cloud, China (Hangzhou) | arms-dc-hz-finance.aliyuncs.com (trace and metadata) | arms-dc-hz-finance-internal.aliyuncs.com (trace and metadata) |
Alibaba Finance Cloud, China (Shanghai) | arms-dc-sh-finance.aliyuncs.com (trace and metadata) | arms-dc-sh-finance-internal.aliyuncs.com (trace and metadata) |
Alibaba Finance Cloud, China (Shenzhen) | arms-dc-sz-finance.aliyuncs.com (trace and metadata) | arms-dc-sz-finance-internal.aliyuncs.com (trace and metadata) |
By default, the agent auto-detects the network and uses the private endpoint first; if the private endpoint is unreachable, it falls back to the public endpoint.
IP ranges to open
If your application is deployed in a VPC, after ensuring that the private domain names are reachable, open the internal IP ranges for each service. Public endpoints do not have fixed IP ranges; configure your network policy by domain name.
ACM engine IP addresses to open
The agent connects to the ACM engine to retrieve configurations. You can query the engine IPs for your region using the ACM domain:
curl 'http://acm.aliyun.com:8080/diamond-server/diamond'Ensure your firewall allows access to the ACM engine IPs returned.
Network connectivity requirements for the non-default Cloud Monitor workspace
The non-default Cloud Monitor workspace uses the Simple Log Service (SLS) data reporting link. By default, it uses HTTP protocol, IPv4 network, and port 80. If your application and the target workspace are in the same Alibaba Cloud region, it is recommended to use the private service endpoint; otherwise, use the public service endpoint.
When using the SLS public cloud private endpoint, you must use the Alibaba Cloud private DNS addresses 100.100.2.136 and 100.100.2.138; otherwise, the private virtual IP address (VIP) may not resolve correctly.
Public cloud service endpoints
Region | Public service endpoint | Private service endpoint |
China (Hangzhou) | cn-hangzhou.log.aliyuncs.com | cn-hangzhou-intranet.log.aliyuncs.com |
China (Shanghai) | cn-shanghai.log.aliyuncs.com | cn-shanghai-intranet.log.aliyuncs.com |
China (Nanjing) (local region, phasing out) | cn-nanjing.log.aliyuncs.com | cn-nanjing-intranet.log.aliyuncs.com |
China (Fuzhou) (local region, phasing out) | cn-fuzhou.log.aliyuncs.com | cn-fuzhou-intranet.log.aliyuncs.com |
China (Qingdao) | cn-qingdao.log.aliyuncs.com | cn-qingdao-intranet.log.aliyuncs.com |
China (Beijing) | cn-beijing.log.aliyuncs.com | cn-beijing-intranet.log.aliyuncs.com |
China (Zhangjiakou) | cn-zhangjiakou.log.aliyuncs.com | cn-zhangjiakou-intranet.log.aliyuncs.com |
China (Hohhot) | cn-huhehaote.log.aliyuncs.com | cn-huhehaote-intranet.log.aliyuncs.com |
China (Ulanqab) | cn-wulanchabu.log.aliyuncs.com | cn-wulanchabu-intranet.log.aliyuncs.com |
China (Shenzhen) | cn-shenzhen.log.aliyuncs.com | cn-shenzhen-intranet.log.aliyuncs.com |
China (Heyuan) | cn-heyuan.log.aliyuncs.com | cn-heyuan-intranet.log.aliyuncs.com |
China (Guangzhou) | cn-guangzhou.log.aliyuncs.com | cn-guangzhou-intranet.log.aliyuncs.com |
China (Chengdu) | cn-chengdu.log.aliyuncs.com | cn-chengdu-intranet.log.aliyuncs.com |
China (Hong Kong) | cn-hongkong.log.aliyuncs.com | cn-hongkong-intranet.log.aliyuncs.com |
Japan (Tokyo) | ap-northeast-1.log.aliyuncs.com | ap-northeast-1-intranet.log.aliyuncs.com |
South Korea (Seoul) | ap-northeast-2.log.aliyuncs.com | ap-northeast-2-intranet.log.aliyuncs.com |
Singapore | ap-southeast-1.log.aliyuncs.com | ap-southeast-1-intranet.log.aliyuncs.com |
Malaysia (Kuala Lumpur) | ap-southeast-3.log.aliyuncs.com | ap-southeast-3-intranet.log.aliyuncs.com |
Indonesia (Jakarta) | ap-southeast-5.log.aliyuncs.com | ap-southeast-5-intranet.log.aliyuncs.com |
Philippines (Manila) | ap-southeast-6.log.aliyuncs.com | ap-southeast-6-intranet.log.aliyuncs.com |
Thailand (Bangkok) | ap-southeast-7.log.aliyuncs.com | ap-southeast-7-intranet.log.aliyuncs.com |
UAE (Dubai) | me-east-1.log.aliyuncs.com | me-east-1-intranet.log.aliyuncs.com |
Germany (Frankfurt) | eu-central-1.log.aliyuncs.com | eu-central-1-intranet.log.aliyuncs.com |
UK (London) | eu-west-1.log.aliyuncs.com | eu-west-1-intranet.log.aliyuncs.com |
US (Virginia) | us-east-1.log.aliyuncs.com | us-east-1-intranet.log.aliyuncs.com |
US (Silicon Valley) | us-west-1.log.aliyuncs.com | us-west-1-intranet.log.aliyuncs.com |
Alibaba Finance Cloud and Alibaba Gov Cloud service endpoints
Region | Public service endpoint | Private service endpoint |
Alibaba Finance Cloud, China (Hangzhou) | cn-hangzhou-finance.log.aliyuncs.com | cn-hangzhou-finance-intranet.log.aliyuncs.com |
Alibaba Finance Cloud, China (Shanghai) | cn-shanghai-finance-1.log.aliyuncs.com | cn-shanghai-finance-1-intranet.log.aliyuncs.com |
Alibaba Finance Cloud, China (Beijing) (invitation-based testing) | cn-beijing-finance-1.log.aliyuncs.com | cn-beijing-finance-1-intranet.log.aliyuncs.com |
Alibaba Finance Cloud, China (Shenzhen) | cn-shenzhen-finance-1.log.aliyuncs.com | cn-shenzhen-finance-1-intranet.log.aliyuncs.com |
Alibaba Gov Cloud, China (Beijing) | cn-north-2-gov-1.log.aliyuncs.com | cn-north-2-gov-1-intranet.log.aliyuncs.com |
For more service endpoint information, see Service endpoints for different network types in Simple Log Service.
Automatically check network connectivity
Prerequisites
Install curl and nc on the container or machine where your application runs. The script uses curl -4 to force IPv4 HTTP requests, with a connection timeout of 1 second for all checks.
Run the automated check script
Create
check_network.shand add the following content:#!/usr/bin/env bash set -u TIMEOUT_SECONDS=1 REGION_ID="${1:-}" if ! command -v curl >/dev/null 2>&1; then echo "curl is not installed. Please install it from: https://curl.se/" exit 1 fi if ! command -v nc >/dev/null 2>&1; then echo "nc is not installed. Please install it from: https://netcat.sourceforge.net/" exit 1 fi if [ -z "${REGION_ID}" ]; then TOKEN=$(curl -4 -sS --connect-timeout "${TIMEOUT_SECONDS}" --max-time "${TIMEOUT_SECONDS}" -X PUT "http://100.100.100.200/latest/api/token" -H "X-aliyun-ecs-metadata-token-ttl-seconds:300" 2>/dev/null || true) REGION_ID=$(curl -4 -sS --connect-timeout "${TIMEOUT_SECONDS}" --max-time "${TIMEOUT_SECONDS}" -H "X-aliyun-ecs-metadata-token: ${TOKEN}" "http://100.100.100.200/latest/meta-data/region-id" 2>/dev/null || true) fi if [ -z "${REGION_ID}" ]; then echo "Cannot auto-detect region ID. Run: $0 <region_id>" exit 1 fi check_http() { local name="$1" local url="$2" local http_code http_code=$(curl -4 -sS -o /dev/null --connect-timeout "${TIMEOUT_SECONDS}" --max-time "${TIMEOUT_SECONDS}" -w "%{http_code}" "${url}" 2>/dev/null || true) if [ -n "${http_code}" ] && [ "${http_code}" != "000" ]; then printf '%-44s reachable (HTTP %s) ' "${name}" "${http_code}" else printf '%-44s unreachable ' "${name}" fi } check_tcp() { local name="$1" local host="$2" local port="$3" if nc -z -w "${TIMEOUT_SECONDS}" "${host}" "${port}" >/dev/null 2>&1; then printf '%-44s reachable ' "${name}" else printf '%-44s unreachable ' "${name}" fi } get_default_endpoints() { case "$1" in cn-hangzhou) echo "arms-dc-hz.aliyuncs.com|arms-dc-hz-internal.aliyuncs.com|cn-hangzhou.arms.aliyuncs.com|cn-hangzhou-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-hz-internal.edas.aliyun.com" ;; cn-shanghai) echo "arms-dc-sh.aliyuncs.com|arms-dc-sh-internal.aliyuncs.com|cn-shanghai.arms.aliyuncs.com|cn-shanghai-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-sh-internal.edas.aliyun.com" ;; cn-qingdao) echo "arms-dc-qd.aliyuncs.com|arms-dc-qd-internal.aliyuncs.com|cn-qingdao.arms.aliyuncs.com|cn-qingdao-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-qd-internal.edas.aliyun.com" ;; cn-beijing) echo "arms-dc-bj.aliyuncs.com|arms-dc-bj-internal.aliyuncs.com|cn-beijing.arms.aliyuncs.com|cn-beijing-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-bj-internal.edas.aliyun.com" ;; cn-zhangjiakou) echo "arms-dc-zb.aliyuncs.com|arms-dc-zb-internal.aliyuncs.com|cn-zhangjiakou.arms.aliyuncs.com|cn-zhangjiakou-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-cn-zhangjiakou-internal.edas.aliyun.com" ;; cn-huhehaote) echo "dc-cn-huhehaote.arms.aliyuncs.com|dc-cn-huhehaote-internal.arms.aliyuncs.com|cn-huhehaote.arms.aliyuncs.com|cn-huhehaote-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; cn-wulanchabu) echo "dc-cn-wulanchabu.arms.aliyuncs.com|dc-cn-wulanchabu-internal.arms.aliyuncs.com|cn-wulanchabu.arms.aliyuncs.com|cn-wulanchabu-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; cn-shenzhen) echo "arms-dc-sz.aliyuncs.com|arms-dc-sz-internal.aliyuncs.com|cn-shenzhen.arms.aliyuncs.com|cn-shenzhen-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-sz-internal.edas.aliyun.com" ;; cn-heyuan) echo "dc-cn-heyuan.arms.aliyuncs.com|dc-cn-heyuan-internal.arms.aliyuncs.com|cn-heyuan.arms.aliyuncs.com|cn-heyuan-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; cn-guangzhou) echo "dc-cn-guangzhou.arms.aliyuncs.com|dc-cn-guangzhou-internal.arms.aliyuncs.com|cn-guangzhou.arms.aliyuncs.com|cn-guangzhou-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; cn-chengdu) echo "dc-cn-chengdu.arms.aliyuncs.com|dc-cn-chengdu-internal.arms.aliyuncs.com|cn-chengdu.arms.aliyuncs.com|cn-chengdu-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; cn-hongkong) echo "arms-dc-hk.aliyuncs.com|arms-dc-hk-internal.aliyuncs.com|cn-hongkong.arms.aliyuncs.com|cn-hongkong-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-hk-internal.edas.aliyun.com" ;; ap-northeast-1) echo "arms-dc-jp.aliyuncs.com|arms-dc-jp-internal.aliyuncs.com|ap-northeast-1.arms.aliyuncs.com|ap-northeast-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-ap-northeast-1-internal.edas.aliyun.com" ;; ap-southeast-1) echo "arms-dc-sg.aliyuncs.com|arms-dc-sg-internal.aliyuncs.com|ap-southeast-1.arms.aliyuncs.com|ap-southeast-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-singapore-internal.edas.aliyun.com" ;; ap-southeast-3) echo "dc-ap-southeast-3.arms.aliyuncs.com|dc-ap-southeast-3-internal.arms.aliyuncs.com|ap-southeast-3.arms.aliyuncs.com|ap-southeast-3-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; ap-southeast-5) echo "arms-dc-indonesia.aliyuncs.com|arms-dc-indonesia-internal.aliyuncs.com|ap-southeast-5.arms.aliyuncs.com|ap-southeast-5-intranet.arms.aliyuncs.com|acm.aliyun.com|-" ;; eu-central-1) echo "arms-dc-frankfurt.aliyuncs.com|arms-dc-frankfurt-internal.aliyuncs.com|eu-central-1.arms.aliyuncs.com|eu-central-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-eu-central-1-internal.edas.aliyun.com" ;; eu-west-1) echo "dc-eu-west-1.arms.aliyuncs.com|dc-eu-west-1-internal.arms.aliyuncs.com|eu-west-1.arms.aliyuncs.com|eu-west-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-eu-west-1-internal.edas.aliyun.com" ;; us-east-1) echo "dc-us-east-1.arms.aliyuncs.com|dc-us-east-1-internal.arms.aliyuncs.com|us-east-1.arms.aliyuncs.com|us-east-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-us-east-1-internal.edas.aliyun.com" ;; us-west-1) echo "arms-dc-usw.aliyuncs.com|dc-us-west-1-internal.arms.aliyuncs.com|us-west-1.arms.aliyuncs.com|us-west-1-intranet.arms.aliyuncs.com|acm.aliyun.com|arms-dc-usw.aliyuncs.com" ;; cn-north-2-gov-1) echo "arms-dc-gov.aliyuncs.com|arms-dc-gov-internal.aliyuncs.com|cn-north-2-gov-1.arms.aliyuncs.com|cn-north-2-gov-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-cn-north-2-gov-1-internal.edas.aliyun.com" ;; cn-hangzhou-finance) echo "arms-dc-hz-finance.aliyuncs.com|arms-dc-hz-finance-internal.aliyuncs.com|cn-hangzhou-finance.arms.aliyuncs.com|cn-hangzhou-finance-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-hz-internal.jbp.console.aliyun.com" ;; cn-shanghai-finance-1) echo "arms-dc-sh-finance.aliyuncs.com|arms-dc-sh-finance-internal.aliyuncs.com|cn-shanghai-finance-1.arms.aliyuncs.com|cn-shanghai-finance-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-cn-shanghai-finance-1-internal.edas.aliyun.com" ;; cn-shenzhen-finance-1) echo "arms-dc-sz-finance.aliyuncs.com|arms-dc-sz-finance-internal.aliyuncs.com|cn-shenzhen-finance-1.arms.aliyuncs.com|cn-shenzhen-finance-1-intranet.arms.aliyuncs.com|acm.aliyun.com|addr-sz-internal.jbp.console.aliyun.com" ;; *) return 1 ;; esac } echo "Region: ${REGION_ID}" echo echo "Default Cloud Monitor Workspace (original ARMS reporting link)" DEFAULT_ENDPOINTS=$(get_default_endpoints "${REGION_ID}" || true) if [ -n "${DEFAULT_ENDPOINTS}" ]; then IFS='|' read -r TRACE_PUBLIC TRACE_PRIVATE METRIC_PUBLIC METRIC_PRIVATE ACM_PUBLIC ACM_PRIVATE <<EOF ${DEFAULT_ENDPOINTS} EOF check_http "Public trace and metadata endpoint" "http://${TRACE_PUBLIC}/api/checkHealth" check_http "Private trace and metadata endpoint" "http://${TRACE_PRIVATE}/api/checkHealth" check_http "Public metadata endpoint (9990)" "http://${TRACE_PUBLIC}:9990/api/checkHealth" check_http "Private metadata endpoint (9990)" "http://${TRACE_PRIVATE}:9990/api/checkHealth" check_http "Public metrics endpoint" "http://${METRIC_PUBLIC}/health/readiness" check_http "Private metrics endpoint" "http://${METRIC_PRIVATE}/health/readiness" check_http "Public ACM service (8080)" "http://${ACM_PUBLIC}:8080/diamond-server/diamond" if [ "${ACM_PRIVATE}" != "-" ]; then check_http "Private ACM service (8080)" "http://${ACM_PRIVATE}:8080/diamond-server/diamond" else echo "No private ACM service available for this region. Ensure the public ACM endpoint is reachable." fi check_tcp "Public diagnostics port (9092)" "${TRACE_PUBLIC}" 9092 check_tcp "Private diagnostics port (9092)" "${TRACE_PRIVATE}" 9092 check_tcp "Public security port (9093)" "${TRACE_PUBLIC}" 9093 check_tcp "Private security port (9093)" "${TRACE_PRIVATE}" 9093 else echo "No default cloud monitor workspace endpoint configured for this region." fi echo echo "Non-default Cloud Monitor Workspace (SLS reporting link)" check_http "SLS public service endpoint /health" "http://${REGION_ID}.log.aliyuncs.com/health" check_http "SLS private service endpoint /health" "http://${REGION_ID}-intranet.log.aliyuncs.com/health"Add execute permission and run the script:
chmod +x check_network.sh ./check_network.sh ${region_id}${region_id}is the region ID where the workspace is located, for examplecn-hangzhou. If this parameter is not provided, the script attempts to retrieve the region ID from the current ECS instance metadata.
The script checks both the original ARMS reporting link for the default Cloud Monitor workspace, and the SLS public and private service endpoints for the non-default Cloud Monitor workspace. At least one link (public or private) matching your actual deployment network must be reachable.