Changing the operating system
Can I use a custom image that contains a data disk to change the operating system?
What is the difference between changing the operating system and re-initializing the system disk?
What if resizing the system disk fails when changing the operating system?
What if I cannot find the target image and the message "The instance is not I/O optimized" appears?
Linux system issues
Resolve su error: 'failed to execute /bin/bash: Permission denied'
Resolve duplicate or non-existent mount paths from the
dfcommandResolve Apache Bench error: 'apr_pollset_poll: The timeout specified has expired'
Troubleshoot ineffective user-data with a 'Failed to run module scripts-user' error
Troubleshoot unexpected restarts after setting
kernel.unknown_nmi_panicTroubleshoot 'Too many open files' error after adjusting the
nofileparameter
Windows system issues
Patch installation error: "The Windows Modules Installer must be updated to install this package"
Resolving driver installation failures on a Windows instance
Resolving the "'Server Manager.lnk' cannot be found" error in Windows
Resolving issues with instances accessing or joining an AD domain
Resolving "System error 58" when mounting a NAS shared directory on a Windows system
Resolving UI display issues after a remote logon to a Windows system
Resolving incorrect disk space reporting caused by many small files in an NTFS file system
Resolving an unexpected IP address change on a Windows system
Troubleshooting a lost IP address on a Windows instance network interface
Resolving remote logon failures caused by terminal server configuration issues on a Windows instance
Resolving Windows activation failures caused by a changed slmgr.vbs file type
Resolving Windows Update error "8000FFFF" on a Windows Server 2008 instance
Resolving error "0x80073712" during role or feature installation on a Windows instance
Resolving issues where environment variable configurations do not take effect in Windows Server
Troubleshooting services that cannot be manually started on a Windows instance
Resolving Windows activation failures caused by corrupted system components
Resolving Group Policy launch failures caused by file configuration issues
Resolving the "Windows Explorer has stopped working" error after logging on with a custom account
Resolving system updates getting stuck at 0% on a Windows ECS instance
Startup failure on Windows Server 2008 R2 due to an unverified driver signature
Resolving system update error "0x80070422" on a Windows instance
Resolving Windows update error "0x80d02002" after configuring an IE proxy server
Troubleshooting a hostname that reverts after a restart on a Windows instance
How to resolve a Windows activation failure on an ECS instance?
Troubleshooting a black screen after a remote logon to a Windows instance
Resolving lag on a Windows instance caused by excessive hardware-reserved memory
How to resolve a critical Vminit operation failure on a Windows instance?
Troubleshooting a problematic device (ACPI\QEMU*****) in System Information
Issues and recommendations for third-party antivirus software on Windows systems
How to check for residual disk driver entries in the Windows instance registry?
Resolving the "MSVCR100.dll is missing" error when installing MySQL on a Windows ECS instance
What container runtime is included in the Windows Server with Container image?
Offline installation of the virtio driver on a Windows instance
How to manually update the virtio driver on a Windows instance?
Windows Server Semi-Annual Channel image and instance management
Troubleshooting resolution changes on UEFI-based instances using VNC
How to activate a Windows Server system in a VPC by using a specific KMS domain
Resolving the "This copy of Windows is not genuine" message on a Windows Server instance
How to resolve incorrect system time caused by frequent calls to the Windows API timeBeginPeriod?
Are there settings in Windows to evenly distribute a process's threads across all CPUs?
Does Windows thread scheduling consider the CPU cache hit ratio?
In which scheduling scenarios does a Windows thread recalculate and migrate to another CPU?
Red Hat image issues
SUSE image FAQ
CentOS image issues
Ubuntu image issues
FreeBSD image issues
Fedora image issues
Alibaba Cloud Linux issues
General issues
Enabling the CONFIG_PARAVIRT_SPINLOCK kernel option may cause performance issues
A printk deadlock in Alibaba Cloud Linux causes a system crash
How to disable CPU vulnerability fixes in Alibaba Cloud Linux
Resolving a segmentation fault caused by SysAK 2.2.0 when running the DNF command
Customizing DNS configuration with the /etc/resolv.conf file in an Alibaba Cloud Linux instance
Which Alibaba Cloud ECS instance types does Alibaba Cloud Linux support?
Does Alibaba Cloud Linux support 32-bit applications and libraries?
Does Alibaba Cloud Linux support a graphical user interface (GUI)?
Alibaba Cloud Linux 3
Configuring XPS in Alibaba Cloud Linux 3: Methods and impacts
Resolving kernel upgrade errors in the Alibaba Cloud Linux 3.8 image
How to disable CPU vulnerability fixes in Alibaba Cloud Linux 3
Resolving high system load with no workload in Alibaba Cloud Linux 3
Resolving poor read performance of the NFS file system in Alibaba Cloud Linux 3
Alibaba Cloud Linux 2
Tuning performance for transparent huge pages (THP) in Alibaba Cloud Linux 2
Troubleshooting systemd service issues in Alibaba Cloud Linux 2
Installing and enabling a later version of curl in Alibaba Cloud Linux 2
Tuning performance for transparent huge pages (THP) in Alibaba Cloud Linux 2
Can I view the source code of Alibaba Cloud Linux 2 components?
Is Alibaba Cloud Linux 2 backward-compatible with earlier versions of Aliyun Linux?
Which third-party applications are supported on Alibaba Cloud Linux 2?
Guest OS FAQ
Linux guest OS: issues and solutions
Boot failures
Logon failures
Instance access issues
Verify that the kernel parameters for the NAT environment are correct
Verify that processes have started and that common service ports are in a LISTENING state
Network connectivity issues
Performance issues
Windows guest OS: issues and solutions
Logon failures
Verify that the Windows network interface controller is enabled
You cannot log on to a Windows instance if its system network interface controller is unavailable. For more information, see The system network interface controller in a Windows instance is unavailable.
Check if port 3389 is open
The Remote Desktop Protocol (RDP) service lets you manage your Windows instance. If the Remote Desktop Protocol (RDP) service is disabled, you cannot establish a remote desktop connection. For more information, see Start the Remote Desktop Protocol (RDP) service for a Windows instance.
Check if the virtio driver version is outdated
An outdated virtio driver can prevent you from logging on to the instance. For more information, see Update the virtio driver of a Windows instance.
Check that the firewall is correctly configured
Incorrect firewall settings can prevent logon. For more information, see Windows system firewall policy configuration guide.
Performance issues
High CPU utilization
Sustained high CPU utilization can affect system stability and service performance. For more information, see Troubleshoot and resolve high CPU utilization on a Windows instance.
Check the Windows operating system version
Microsoft ended support for Windows Server 2008 and Windows Server 2008 R2 on January 14, 2020. Therefore, Alibaba Cloud no longer provides technical support for ECS instances that run these operating systems. If you have ECS instances that run these operating systems, update them to Windows Server 2012 or a later version as soon as possible. For information about the supported images, see public images or refer to the buy page.
Check the disk capacity
Insufficient space on the C drive can prevent the system from operating correctly. For more information, see How to troubleshoot low space on the C drive of a Windows instance.
AD domain controller installation failures
Other issues
Resolving the mismatch between the CPU frequency in
/proc/cpuinfoand instance specificationsTroubleshooting login failures to an ECS instance when using an RSA key
Resolving crash dump failures on ECS instances based on bare metal instance types
Resolving a softlockup exception when deleting a cgroup on an ECS instance
Resolving NTP synchronization failures on a Linux server after configuring an IPv6 address
Troubleshooting hot-plugging failures on instances created from a custom image
Recovering from an instance shutdown caused by a kernel error
Appendix
Change the operating system (system disk)
You can change the operating system (replace the system disk) by changing the image of an ECS instance.
After you change the operating system (replace the system disk), the original system disk is released and all data on the disk is erased. We recommend that you manually create a snapshot of the system disk to back up data beforehand.
Change the OS with a shared custom image
Yes. Account A must first share the custom image with Account B. Then, Account B can use the image to change the operating system (replace the system disk).
Use an image with data disk snapshots
You can use a custom image that contains data disk snapshots to change the operating system. This operation replaces only the system disk of the instance and does not affect its data disks.
If you use a custom image that contains data disk snapshots to change the operating system, ensure that no service dependencies exist between the system disk and the data disks. Also, ensure that the new system disk's operations do not disrupt your business processes. For example, if your services read data from or write data to a data disk, read or write errors may occur after you change the operating system.
Change OS vs. re-initialize system disk
The main differences are described in the following table.
Item | Re-initialize system disk | Change operating system |
Functional differences | Restores the ECS instance to its initial state. The operating system remains unchanged. | Replaces the current operating system with a different one. |
Impact on the system disk |
|
|
Impact on data disks | Data disks are not affected. | Data disks are not affected. |
Impact on snapshots |
|
|
Billing | Re-initializing a system disk is free of charge. The billing items do not change because the operating system remains the same. | Changing the operating system is free of charge. However, fees apply in the following cases:
|
System disk resize failure during OS change
Resizing a system disk partition during an OS change may fail due to a timeout. If this occurs, you must manually extend the partition. For more information, see Extend partitions and file systems of a Linux disk. This method extends only the system disk partition and does not affect the operating system version.
Troubleshoot the non-I/O optimized instance error
Cause
An instance's I/O optimization attribute must match the image's. I/O optimized instances require I/O optimized images, and non-I/O optimized instances require non-I/O optimized images. A mismatch prevents you from selecting the image. In this case, the "The instance is a non-I/O optimized instance. You can select only an image that supports non-I/O optimized instances when you change the operating system" message appears.
Solution
All available instance types are I/O optimized. We recommend that you change the instance type.
Select an image that supports non-I/O optimized instances to change the operating system (replace the system disk).
You can call the DescribeInstances operation and check the value of the IoOptimized parameter to query the I/O attribute of an instance.
You can call the DescribeImages operation and check the value of the IsSupportIoOptimized parameter to query the I/O attribute of an image.
Reset the system time zone
For a single instance, run the timedatectl set-timezone command to change the time zone.
You can use Cloud Assistant to change the time zones of multiple instances at once.
Container runtime in Windows Server with Container images
Due to changes in Microsoft's support policy for container runtimes (for more information, see Supported Container Runtime on Windows Server), Windows Server with Container images updated by Alibaba Cloud ECS since early 2024 no longer include Mirantis Container Runtime (MCR). Instead, they include the open-source containerd runtime. If you require MCR, you must purchase and install Mirantis Container Runtime from Mirantis.
Starting March 1, 2024, Windows Server with Container images provided by Alibaba Cloud ECS include the following container-related components:
The Windows Server container feature. Hyper-V isolation is not supported. For more information, see Windows and containers.
The containerd runtime, version 1.7.13. For more information, see containerd.
nerdctl.exe, a command-line interface (CLI) for managing containers, version 1.7.13. For more information, see nerdctl.
nat.exe, a Container Network Interface (CNI) plugin for Windows container networking, version 1.0.0. For more information, see windows-container-networking.
User data script write failure on Windows
Issue
When you use a user data script to write data to the C:\Users\Administrator\Desktop\userData_test.txt path, the operation fails with a "path not found" error.
Cause
In Windows, the C:\Users directory and its subdirectories are the default storage locations for user profiles and data. You can access these locations only after logging on to the system. The user data script runs during instance initialization, before a user logs on. Therefore, attempts to write data to the C:\Users directory fail.
Solution
To resolve this issue, modify the write path in your user data script to a directory that is not user-specific, such as the root of the C: drive. For example:
[bat]
echo "userData" > C:\userData_test.txtFor more information, see Customize instance initialization configurations.
Limitations of the Windows Server 2025 image
vCPU: 1 to 640
Memory: 2 GiB to 48 TiB
ECS instance types
Due to compatibility issues, the following ECS instance types do not support this image:
6th generation AMD instance types (general-purpose instance family g6a, compute-optimized instance family c6a, and memory-optimized instance family r6a)
Windows Server KMS activation in a VPC
To activate a Windows instance in a VPC, use a specific KMS domain name. For instructions, see How to use a KMS domain name to activate a Windows instance in a VPC.
To activate a Windows instance in a VPC, use a specific KMS domain name. For instructions, see Activation methods for Windows instances in a VPC.
To activate a Windows instance in a VPC, use a specific KMS domain name. For instructions, see Activation methods for Windows instances in a VPC.
"Windows is not genuine" error
Activate Windows to resolve this error. For instructions, see Activate a Windows Server on an ECS instance with a KMS domain.
Inaccurate system time caused by timeBeginPeriod API
On an ECS instance running Windows Server 2008, frequent calls to the timeBeginPeriod Windows system API can make the system time inaccurate. To resolve this issue, perform the following steps:
To learn about system functions that affect system time precision, see the official Microsoft documentation.
Connect to the ECS instance.
For instructions, see Log on to a Windows instance by using Workbench.
Download the tool.
Unzip CheckTimeBeginPeriod.zip.
Unzip bin.zip, go to the bin directory, and double-click the appropriate .exe file.
For a 64-bit operating system, double-click InjectDllx64.exe.
For a 32-bit operating system, double-click InjectDllx86.exe.
The tool displays the process that is calling the
timeBeginPeriodAPI.Based on your business requirements, stop or update the application that is calling the
timeBeginPeriodAPI.
If the issue persists, submit a ticket.
Handling IE enhanced security configuration blocks
On an ECS or Simple Application Server instance that runs Windows, Internet Explorer may display an error: "Content from the website listed below is being blocked by the Internet Explorer Enhanced Security Configuration". To resolve this issue, see How to resolve content blocking by Internet Explorer Enhanced Security Configuration on a Windows instance.
User data not running after system disk change
Cause
After a Windows ECS instance starts, a marker file is created in the C:\ProgramData\aliyun\vminit\INSTANCE_{instance ID}\METASERVER directory to mark the instance as initialized. If you create a custom image from this ECS instance, the marker file is included in the image. Consequently, when you use this custom image to re-initialize or replace a system disk, Vminit finds the existing marker file in the C:\ProgramData\aliyun\vminit\INSTANCE_{instance ID}\METASERVER directory. Vminit determines whether an instance is starting for the first time based on the presence of this file. Because this file exists, Vminit assumes it is not a first-time boot and skips running the user data script.
Vminit is automatically installed when you create a Windows instance and handles startup initialization, similar to cloud-init for Linux systems. For more information, see Introduction to Initialization Tools.
Solution
Before creating a custom image from the ECS instance, check for and delete the marker file in the C:\ProgramData\aliyun\vminit\INSTANCE_{instance ID}\METASERVER directory.
Even thread distribution on Windows
No.
The Windows operating system offers no direct setting to evenly distribute a process's threads. Instead, the scheduler manages threads based on the collective behavior of all threads in the system. To control a process's thread distribution, you typically need to use third-party tools or manually set thread affinity in the application code.
Windows thread scheduling and CPU cache hit ratio
Yes. To maximize the CPU cache hit ratio, Windows considers two factors when scheduling threads:
Ideal processor: The processor assigned to a thread when it is created. The system typically distributes new threads across available CPUs in a round-robin fashion.
Last processor: The processor where the thread last ran.
Thread CPU reassignment scenarios
A thread can be reassigned to a different CPU in three main scheduling scenarios:
Time slice rotation: When its allocated time slice expires, a thread is returned to the ready queue of the same CPU. By default, it remains on the original CPU, as its CPU assignment is not recalculated.
Preemptive scheduling: When a higher-priority thread preempts a lower-priority thread, the preempted thread is returned to the ready queue of the original CPU. It typically remains on the original CPU, as its assignment is not recalculated.
Voluntary wait: When a thread enters a voluntary wait for a resource (such as I/O or a lock), the system recalculates its CPU assignment upon resumption. The scheduler prioritizes assigning the thread to its ideal processor or the one it last ran on.
Getting technical support for Red Hat Enterprise Linux
Instead of contacting Red Hat directly, you can submit a ticket to Alibaba Cloud for technical support. An Alibaba Cloud support engineer will assist you with your issue. If Alibaba Cloud cannot resolve an issue with the Red Hat Enterprise Linux operating system, we will escalate the ticket to Red Hat.
Included Red Hat subscriptions
Red Hat images from Alibaba Cloud include a Red Hat Enterprise Linux (RHEL) subscription. The following software repositories are available:
RHEL 7
Red Hat Enterprise Linux 7 Server - Extras from RHUI (RPMs)
Red Hat Enterprise Linux 7 Server - Optional from RHUI (RPMs)
Red Hat Enterprise Linux 7 Server from RHUI (RPMs)
RHEL 8 & RHEL 9
BaseOS
AppStream
The latest RHEL 8 and RHEL 9 images also include the CodeReady Linux Builder and Supplementary repositories by default. To use these software repositories on your RHEL 8 or RHEL 9 instance, contact Alibaba Cloud support.
For details about the software repositories and package lists for RHEL 8 and RHEL 9, see the RHEL 8 Package Manifest and RHEL 9 Package Manifest.
Red Hat images from Alibaba Cloud provide packages for RHEL only. To install packages for other Red Hat products, such as Red Hat Satellite or Red Hat Ceph Storage, you must purchase a separate Red Hat subscription, register your host, and subscribe to the required products.
"Unknown" subscription status
This is expected behavior. When you use a Red Hat Enterprise Linux image from Alibaba Cloud, your instance receives updates from Alibaba Cloud's update sources. This differs from the traditional model, where you would use a Red Hat account to get updates directly from Red Hat. Therefore, running the subscription-manager command correctly reports the status as "Unknown":
+-------------------------------------------+
System Status Details
+-------------------------------------------+
Overall Status: Unknown
System Purpose Status: UnknownSupport for SUSE Linux Enterprise Server (SLES)
Alibaba Cloud provides SUSE Linux Enterprise Server (SLES) public images that are regularly synchronized with SUSE update repositories. Alibaba Cloud Enterprise Support includes operating system support for instances created from SLES public images. If you have purchased Alibaba Cloud Enterprise Support, you can submit a ticket for technical support. Alibaba Cloud engineers will help you resolve issues with the SLES operating system.
SLES for SAP FAQ
SUSE Linux Enterprise Server for SAP Applications (SLES for SAP) is a commercial Linux operating system customized for SAP systems.
Accessing Alibaba Cloud Linux 2 source code
Yes, Alibaba Cloud Linux 2 is open source. You can download source code packages using the yumdownloader tool or from the Alibaba Cloud open source site. The kernel source code tree is also available on GitHub.
Backward compatibility
Alibaba Cloud Linux 2 is fully compatible with Aliyun Linux 17.01.
If you use custom-compiled kernel modules, you may need to recompile them on Alibaba Cloud Linux 2.
Supported third-party applications
Alibaba Cloud Linux 2 is binary compatible with the CentOS 7.6.1810 distribution and provides distinct operating system features.
Compared with CentOS and RHEL, Alibaba Cloud Linux 2 offers the following advantages:
A faster release cycle that delivers the latest operating system features, an updated Linux kernel, and newer user-mode software and toolkits.
An out-of-the-box experience with minimal configuration for rapid service deployment.
Enhanced performance through optimizations tightly integrated with the cloud infrastructure.
Commercial support (unlike CentOS) and no runtime billing (unlike RHEL).
Data security
Alibaba Cloud Linux 2 is binary compatible with CentOS 7.6.1810 and RHEL 7.6, and adheres to the RHEL security specification. We ensure data security in the following ways:
We regularly perform security scans using industry-standard vulnerability scanning and security testing tools.
We regularly evaluate CVE patches for CentOS 7 to address security vulnerabilities.
We work with the Alibaba Cloud security team to support existing OS security hardening solutions.
We release security advisories and patch updates using the same mechanism as CentOS 7.
Data encryption
Alibaba Cloud Linux 2 retains the data encryption toolkit from CentOS 7 and supports the same KMS-integrated encryption solutions.
Configure permissions for Alibaba Cloud Linux 2
Alibaba Cloud Linux 2 is an operating system that is source-compatible with CentOS 7. Administrators can use the same management commands as in CentOS 7 to configure permissions. The default permission settings are identical to those of the official Alibaba Cloud CentOS 7 image.
Alibaba Cloud Linux pricing
There is no additional cost for the Alibaba Cloud Linux image. You pay only for the ECS instances and other resources you use.
Supported ECS instance types
Alibaba Cloud Linux supports most Alibaba Cloud ECS instance types, including ECS Bare Metal Instances.
Alibaba Cloud Linux does not support instances that run on the Xen virtualization platform.
32-bit support
No, it does not support 32-bit applications and libraries.
GUI support
Alibaba Cloud Linux does not officially support a graphical user interface (GUI). However, you can install one by following the official CentOS documentation. For more information, see Install a graphical user interface on a Linux instance.
Appendix: wget command errors
"Command not found" error
Symptom
When you run the wget command on a Linux instance, a "command not found" error is reported. When you then run the yum install wget command, a message indicates that the package is "already installed and latest version".
Cause
The wget command file is not found in the /usr/bin directory, but a file named wge exists. This indicates that the command file may have been renamed.
Solution
Follow these steps to resolve the issue.
Connect to your Linux instance.
For more information, see Connect to a Linux instance by using a password or key.
Run the following command to find the path of the
wgecommand:whereis wgeThe following output indicates that the path of the
wgecommand is/usr/bin/wge.wge: /usr/bin/wgeRun the following command to restore the correct filename:
cp /usr/bin/wge /usr/bin/wgetRun the
wgetcommand again to confirm the issue is resolved.
"Permission denied" error
Symptom
When you run the wget command on a Linux ECS instance, the following error is reported:
wget bash: /usr/bin/wget: Permission deniedCause
The permissions for the wget command are set to 000, which denies read, write, and execute permissions.
Solution
Follow these steps to resolve the issue.
Connect to your Linux instance.
For more information, see Connect to a Linux instance by using a password or key.
Run the following command to check the permissions of the
wgetcommand:ls -l /usr/bin/wgetThe command returns the following output, which indicates that the permissions for the
wgetcommand are000(no read, write, or execute permissions).-------- 1 root root 366800 Oct 31 2014 /usr/bin/wgetRun the following command to check the attributes of the
/usr/bin/wgetfile:lsattr /usr/bin/wgetThe command returns the following result, indicating that the attribute of the
/usr/bin/wgetdirectory isi(you cannot create or delete files in the directory).----i--------e- /usr/bin/wgetRun the following command to remove the immutable (
i) attribute from the/usr/bin/wgetfile:chattr -i /usr/bin/wgetRun the following command to grant permissions to the
/usr/bin/wgetdirectory.chmod 755 /usr/bin/wgetRun the
wgetcommand again to confirm the issue is resolved.
AD DS installation error
Symptom
Installing an AD domain controller on a Windows ECS instance fails with the error message: "Installation of Active Directory Domain Services binaries failed".
Cause
The Event Viewer indicates that the Remote Registry service is disabled and cannot start.
Solution
Follow these steps to start the Remote Registry service.
Connect to the Windows instance.
See Connect to a Windows instance by using a password or key.
Go to Start > Run, enter
services.msc, and then click OK.In the Services window, double-click the
Remote Registryservice to open the Remote Registry Properties window. Configure the following settings:Set Startup Type to Automatic.
Under Service status, click Start. Ensure the
Remote Registryservice is running.
Click OK to save the settings.
Error: "This computer has dynamically assigned IP addresses"
Symptoms
When you install an AD domain controller on a Windows ECS instance, the message "This computer has dynamically assigned IP addresses" appears.
Cause
At least one physical network adapter on the Windows ECS instance does not have a static IP address.
Solution
Connect to the Windows instance.
For instructions, see Log on to a Windows instance by using a password or key.
Install the AD domain controller. For instructions, see Build a Windows AD domain on an ECS instance.
When the Static IP Assignment dialog box appears, click Yes.
Because the loopback adapter uses DHCP, you can proceed with the installation without assigning it a static IP address.
AD domain controller installation error 0x0000232B RCODE_NAME_ERROR
Symptoms
When you install an AD domain controller on a Windows ECS instance, the installation fails with the error code "0x0000232B RCODE_NAME_ERROR".
Cause
An incorrect IP address configuration in the DNS server may cause this issue.
Solution
Follow these steps to change the DNS server address on both the internal and external network adapters of the secondary instance to the private IP address of the primary instance.
Connect to the Windows instance.
For more information, see Connect to a Windows instance by using a password or key.
Go to the Internet Protocol Version 4 (TCP/IPv4) Properties window, change the DNS server address, and then click OK.
NoteSet the DNS server address to the private IP address of your primary instance.

Verify that you can ping the DNS server's IP address.
Resolve the "The network path was not found" error
Symptoms
When installing an AD domain controller on a Windows ECS instance, you receive the error message "The network path was not found".
Causes
Possible causes include the following:
The
TCP/IP NetBIOS HelperandRemote Registryservices on the AD domain controller and the client are not running.The DNS configuration on the client or the AD domain controller is incorrect.
A SID conflict exists between the client and the AD domain controller.
A firewall or security software is blocking the connection.
Solutions
Follow these steps to troubleshoot the issue.
Change the client SID
To change the client SID, follow these steps:
Connect to the Windows instance.
For more information, see Connect to a Windows instance by using a password or key.
Download the PowerShell script to change the client SID.
Download link: AutoSysprep.ps1
Source: Alibaba Cloud
Open Command Prompt, enter
PowerShell, and press Enter to open Windows PowerShell.NoteIf your instance runs a 64-bit operating system, do not use 32-bit PowerShell (Windows PowerShell (x86)). Otherwise, an error occurs.
Navigate to the script's directory and run the following command to view the help information:
.\AutoSysprep.ps1 -helpRun the following command to re-initialize the server's SID:
.\AutoSysprep.ps1 -ReserveHostname -ReserveNetwork -SkipRearm -PostAction "reboot"After the initialization is complete, the instance restarts. Note the following:
The IP address assignment method changes from DHCP to a static IP address. Ensure this static IP address matches the original IP address of the ECS instance. Alternatively, switch back to DHCP to automatically use the primary private IP address assigned on the console.
NoteDo not change the primary private IP address of the ECS instance on the console. Otherwise, access issues may occur.
After the SID is re-initialized, the firewall configuration reverts to the Microsoft default settings, which may block ping requests. To resolve this, you can turn off the firewall for the Guest or Public Network profile or add a rule to allow the required ports.
Open Control Panel and turn off the firewall for the Guest or Public Network profile.
You can then ping the server.
Allow client connections through the firewall or security software
For instructions, see Windows system firewall policy configuration guide.
Check for and fix missing IP addresses on CentOS 7 and Windows instances
Resolve dump file generation failures on a CentOS 7.9 ARM system
Recover from rescue mode on a CentOS or Red Hat 7.x system after a systemd upgrade
Resolve slow startup of Red Hat 8.1 or 8.2 images on ECS Bare Metal Instances
Resolve CentOS DNS resolution timeouts
Cause
Due to a change in the DNS resolution mechanism of CentOS 6 and CentOS 7, DNS resolution timeouts may occur on ECS instances that run CentOS 6 or CentOS 7 and were created before February 22, 2017. The issue may also occur on instances created from custom images that were created before that date.
Solution
To resolve this issue, follow these steps:
Download the fix_dns.sh script.
Place the downloaded script in the /tmp directory of your CentOS system.
Run the bash /tmp/fix_dns.sh command to execute the script.
The following sections explain the script's function and logic.
Check and fix missing IP addresses
For the cause and solution, see Fix missing IP addresses on CentOS 7 and Windows instances.
Resolve dump file generation failures
Symptoms
After a CentOS 7.9 ARM system crashes, you run the ls /var/crash command, but no vmcore file is generated.

Cause
The pre-installed version of the makedumpfile software is incompatible with this kernel, which prevents the system from generating a dump file. The kernel of the CentOS 7.9 ARM system includes the CONFIG_ARM64_USER_VA_BITS_52=y feature.
Solution
This solution applies only to systems where you have correctly enabled the kdump service. If you have not enabled the kdump service and follow these steps to fix the issue, you must manually add the crashkernel parameter to the proc/cmdline file.
Run the following command to download the kexec-tools RPM package.
wget http://mirrors.aliyun.com/centos-vault/7.9.2009/os/Source/SPackages/kexec-tools-2.0.15-51.el7.src.rpmRun the following command to install the RPM package.
rpm -ivh kexec-tools-2.0.15-51.el7.src.rpmRun the following commands to download the patch file.
cd /root/rpmbuild/SOURCES wget https://ecs-image-tools.oss-cn-hangzhou.aliyuncs.com/patch/rhelonly-kexec-tools-2.0.20-makedumpfile-arm64-Add-support-for-ARMv8.2-LVA-52-bi.patchModify the kexec-tools.spec file.
Open the
kexec-tools.specfile.cd /root/rpmbuild/SPECS/ vi kexec-tools.specPress
ito enter insert mode, and then add the following two lines in the appropriate locations.Patch999: rhelonly-kexec-tools-2.0.20-makedumpfile-arm64-Add-support-for-ARMv8.2-LVA-52-bi.patch %patch999 -p1Insert the lines in the locations shown in the following figures.


Press
Escto exit insert mode, and then enter:wqto save and exit.
Run the following command to check and install dependencies.
yum-builddep kexec-tools.specRun the following commands to build the RPM package.
yum -y install rpm-build rpmbuild -ba kexec-tools.specRun the following commands to install the modified RPM package.
cd /root/rpmbuild/RPMS/aarch64 rpm -ivh kexec-tools-2.0.15-51.el7.aarch64.rpm
After another crash, run the ls -lh /var/crash command. If a vmcore file is now generated, the issue is resolved.

Recover from rescue mode
Upgrading systemd to version systemd-219-71.el7 on a CentOS 7 or Red Hat 7 series system can cause the instance to enter rescue mode after a restart. This disrupts network services and general application services. For the solution, see A CentOS 7.X or Red Hat 7.X system enters rescue mode after a systemd upgrade and restart.
Resolve slow startup of Red Hat images
On an ECS Bare Metal Instance, an instance running Red Hat 8.1 or 8.2 starts 1 to 2 minutes slower than an instance running Red Hat 7. To resolve this issue, open the /boot/grub2/grubenv file on your Red Hat 8.1 or 8.2 system, change the kernel boot parameter from
console=ttyS0 console=ttyS0,115200n8toconsole=tty0 console=ttyS0,115200n8, and then restart the server to apply the change.
High system load from Server Guard on Ubuntu
The system load on an ECS instance running certain versions of Ubuntu, such as Ubuntu 18.04, increases after the Server Guard process starts.
For the cause and solution, see High system load after the Server Guard process starts on an ECS instance that runs Ubuntu 18.04.
Why do Ubuntu system services restart automatically?
By default, Ubuntu uses the unattended-upgrade service to automatically update packages. This service periodically checks for and installs updates, which can cause related services to restart. If you do not need automatic updates, you can disable this service.
systemctl stop unattended-upgrade
systemctl disable unattended-upgradePatch and compile the FreeBSD kernel
Alibaba Cloud's public FreeBSD images use patched kernels to support booting on generation V or later instance families. You can query the instance families by using the Generation parameter of the DescribeInstanceTypeFamilies operation.
To prevent or resolve boot failures that can occur in the following situations, you can apply a patch to the FreeBSD kernel source code and compile the kernel.
ECS instances of generation V or later instance families may fail to boot when created from a third-party FreeBSD image or a related custom image.
If you use a public FreeBSD image to create an ECS instance and then update the kernel by using a tool such as freebsd-update, the instance may fail to boot on a generation V or later instance family.
Patching is not required for FreeBSD 13 or later. This topic demonstrates how to patch and compile the FreeBSD kernel, using FreeBSD 12.3 as an example.
Download and decompress the FreeBSD kernel source code.
wget http://ftp-archive.freebsd.org/pub/FreeBSD-Archive/old-releases/amd64/12.3-RELEASE/src.txz -O /src.txz cd / tar -zxvf /src.txzDownload the patch package.
In this example, the
0001-virtio.patchis applied to the virtio driver.cd /usr/src/sys/dev/virtio/ wget https://ecs-image-tools.oss-cn-hangzhou.aliyuncs.com/0001-virtio.patch patch -p4 < 0001-virtio.patchCopy the kernel file, and then build and install the kernel.
make -j<N>specifies the number of parallel jobs for compilation. You should determine this value based on the configuration of your build environment. For example, in a 1 vCPU environment, we recommend setting-j2. This means the ratio of vCPU cores to the variable N is1:2.cd /usr/src/ cp ./sys/amd64/conf/GENERIC . make -j2 buildworld KERNCONF=GENERIC make -j2 buildkernel KERNCONF=GENERIC make -j2 installkernel KERNCONF=GENERICAfter the build is complete, delete the source code.
rm -rf /usr/src/* rm -rf /usr/src/.*
FreeBSD system disk not found in KVM
Problem
When logging on to a FreeBSD system in a KVM environment using VNC, the system cannot find the system disk and fails to boot, as shown below.
Solution
In the VNC console, enter ? to view the ufsid of the root file system (rootfs).

Enter
ufs:/dev/ufsid/5565b5a09045****to boot the operating system.Enter the username and password to log on to the system.
Run the following command to view the
/etc/fstabconfiguration:cat /etc/fstabThe
/etc/fstabconfiguration, shown below, uses the UUID mount method. However, FreeBSD does not support this mount method and requires the ufsid method.
Change the system's mount method to ufsid.
Run the following command to open the
/etc/fstabfile:vi /etc/fstabPress i to enter insert mode.
Replace
UUID=5565b5a09045****with/dev/ufsid/5565b5a09045****.Press Esc, enter
:wq, and press Enter to save the changes and exit.
Restart the system to apply the changes:
reboot
Why can't I connect to a Fedora 33 instance with an ssh-rsa key pair?
You may be unable to connect over SSH to an ECS instance running the 64-bit Fedora 33 operating system if you use an SSH key pair with the ssh-rsa signature algorithm. To resolve this issue, use one of the following methods:
Replace the ssh-rsa SSH key pair with one that uses a different signature algorithm, such as ECDSA.
Run the update-crypto-policies --set LEGACY command on the instance to switch the encryption policy from
POLICYtoLEGACY. This allows you to use an SSH key pair that uses the ssh-rsa signature algorithm.
Why do Fedora CoreOS instances show only half the specified CPUs?
On some instances created from a Fedora CoreOS image, such as those from the g5 general-purpose instance family, the
On-line CPU(s) listin the lscpu command output shows only half the number of CPUs for the selected instance type. For example, if you select an instance type with 2 CPU cores, theOn-line CPU(s) listshows only one CPU. The following figure shows an example.
NoteThe
On-line CPU(s) listfield shows the IDs of the online CPUs.This behavior occurs because the kernel of the Fedora CoreOS image includes the
mitigations=auto,nosmtboot parameter by default. This parameter automatically disables simultaneous multi-threading (SMT) on systems with known vulnerabilities, which reduces the number of available CPUs by half. You can view themitigations=auto,nosmtparameter by running the cat /proc/cmdline command.For more information about SMT, see Automatically disable SMT when needed to address vulnerabilities and Policy for disabling SMT.
Appendix: Linux guest OS issues
Stale fstab entries
If the
/etc/fstabfile contains an entry for a block device that is no longer attached to the instance, the system may fail to boot. You must remove the stale entry from the file. For more information, see How to remove an entry for a non-existent block device from the /etc/fstab file of a Linux instance.Incorrectly mounted block devices
If a block device is not mounted correctly, the instance may fail to boot after a restart. For more information, see An improperly mounted disk exists on a Linux instance.
Incorrect fstab file format
If the
/etc/fstabconfiguration file contains format errors, the instance may fail to boot after a restart. For more information, see Format errors exist in the /etc/fstab configuration file of a Linux instance.File system check using fsck
If the file system is corrupted, the instance may fail to boot. For more information, see Check and repair the file system of a Linux instance.
Incorrect limits settings
The
/etc/security/limits.conffile limits system resources. If the value of thenofileparameter exceeds the value of thenr_openparameter, you may be unable to remotely connect to the instance. For more information, see What do I do if a remote connection fails or a "Too many open files" error is reported after I adjust the nofile parameter of a Linux instance?.Missing critical user information
If critical system user information is missing, you may be unable to log on to the Linux instance. For more information, see Repair non-Unix format files in a Linux instance.
Incorrect critical system file format
If critical files are not in Unix format, you may be unable to log on to the Linux instance. For more information, see Repair non-Unix format files in a Linux instance.
Incorrect SSH access permissions
If SSH access permissions on a Linux instance are not configured correctly, you may be unable to log on to the instance. For more information, see Incorrect SSH access permissions prevent remote connections to a Linux instance.
Missing critical files for SSH
If critical files or directories required for SSH access are missing from a Linux instance, such as the
sshd_configconfiguration file, you may be unable to log on to the instance. For more information, see Check whether required files or directories for the SSH service exist on a Linux instance.Oversized huge pages setting
If the huge pages setting of an instance is too large, you may be unable to log on to the Linux instance. You must adjust the value for huge pages in the
/etc/sysctl.conffile. For more information, see Adjust the huge pages setting for a Linux instance.OOM issues
If an OOM issue occurs, you may be unable to log on to the Linux instance. For more information, see How to handle OOM issues on a Linux instance.
System firewall configuration
If the server firewall is enabled and its rules are configured to block external access, remote connections to the server may fail. For more information, see Manage the system firewall of a Linux instance.
TCP SACK status
If TCP SACK is not enabled on a Linux instance, its network performance may be affected. For more information, see Enable TCP SACK for a Linux instance.
UDP buffer overflow
If a UDP buffer overflow occurs in a Linux instance, it may affect network performance and prevent you from logging on to the instance. For more information, see Remote connection to a Linux instance fails due to UDP buffer overflow.
SELinux status
If the SELinux service is enabled on the system, you may encounter an error when trying to connect to the instance remotely. For more information, see Remote SSH connection to a Linux instance is abnormal because the SELinux service is enabled.
SSH or VNC logon failure
You can detach the system disk from the problematic instance and attach it to another instance as a data disk to perform necessary operations. For more information, see Detach the system disk of a Linux instance and attach it to another ECS instance as a data disk.
Instance connection error
When you use the root user to log on to a Linux instance over SSH, you receive the
Permission denied, please try againerror. For more information, see How do I resolve the "Permission denied, please try again" error when I use SSH to log on to a Linux instance?.Incorrect kernel parameters in NAT
If your local network uses NAT for shared Internet access and the Linux system's kernel parameters are incorrectly configured, you may be unable to connect to the Linux instance over SSH, and access to HTTP services on the instance may also fail. For more information, see Linux kernel configuration issues cause access failures for an instance in a NAT environment.
Process and port status
If you cannot access a service on your Linux instance, the service's process may not be running. For more information, see Start common services and query port listening status on a Linux instance.
Incorrect DHCP configuration
By default, an ECS instance uses DHCP to automatically assign an IP address to an elastic network interface and obtain a lease expiration time. Errors in the network interface configuration file or a non-running dhclient process can cause the DHCP service to fail, leading to network connectivity issues. For more information, see Check and fix the DHCP configuration of a local network interface on a Linux instance.
Missing network processes
If a required network process is missing on a Linux system that is configured to use DHCP, the instance may fail to renew its IP address lease after it expires, resulting in a network interruption. For more information, see A network process does not exist on a Linux system.
NIC multi-queue status
NIC multi-queue refers to the maximum number of network interface queues that an instance type supports. If a single CPU on an ECS instance encounters a performance bottleneck when processing network interrupts, you can distribute the network interrupts across multiple CPUs to improve performance. For more information, see NIC multi-queue.
TCP backlog buffer overflow
If a TCP backlog buffer overflow occurs in a Linux instance, it may affect network performance and prevent you from logging on to the instance. For more information, see Remote connection to a Linux instance fails due to TCP backlog buffer overflow.
High CPU utilization
Sustained high CPU utilization can affect system stability and service performance. For more information, see Troubleshoot and resolve high CPU utilization or load on a Linux instance.
Cannot write to disk
If you cannot write files to a disk because it is full, you can resize the disk to expand its capacity. This applies to both system disks and data disks. For more information, see Step 1: Resize cloud disk capacity or Resize a cloud disk offline.
Crash dump failure on ECS bare metal instances
See What to do if some ECS instances fail to generate a crash dump file?.
Softlockup exception during Linux kernel writeback
A softlockup exception can occur during file cache writeback in some earlier versions of the Linux kernel. For a solution, see Solution for a softlockup exception that occurs during kernel writeback on a Linux operating system.
Softlockup exception when deleting a cgroup
See Solution for a softlockup exception that occurs when you delete a cgroup in an ECS instance.
ECS instance downtime
Do public images include FTP services?
No. You must install and configure FTP services yourself. For more information, see Build an FTP site (Windows) and Build an FTP site (Linux).
Default virtual memory and swap configuration
An operating system's memory manager uses a swap partition or a virtual memory file to temporarily move rarely accessed memory data to disk when physical memory is insufficient. This process increases the amount of available memory.
However, this mechanism can degrade performance if memory usage is already high and I/O performance is poor. ECS cloud disks use a distributed file system as the storage backend and maintain multiple strongly consistent replicas for each data block. This approach ensures data durability but also increases I/O operations threefold, reducing storage and I/O performance.
To avoid degrading cloud disk I/O performance under memory pressure, virtual memory is not enabled by default on Windows instances, and swap partitions are not configured by default on Linux instances.
How do I enable Kdump in a public image?
The Kdump service is disabled by default in public images. To generate a core file for downtime analysis, enable the Kdump service. This procedure uses a CentOS 7.2 public image as an example. The steps may vary based on your operating system.
Set the directory where the core file is generated.
Run vim /etc/kdump.conf to open the kdump configuration file. For more information about the vim command, see Vim editor.
Set path to the directory where core files are generated. In this example, to generate core files in the /var/crash directory, the path is set as follows.
path /var/crashSave and close the /etc/kdump.conf file.
Enable the Kdump service.
Use the method supported by your operating system.
Method 1: Run the following commands to enable the Kdump service.
systemctl enable kdump.servicesystemctl start kdump.serviceMethod 2: Run the following commands to enable the Kdump service.
chkconfig kdump onservice kdump startMethod 3: If Cloud Assistant is installed on your server, see How do I resolve instance downtime issues after a migration? to enable the Kdump service.
Set a static IP for a Linux instance
You must establish a remote connection to the ECS instance to configure the settings. For more information, see Set a static IP address in a Linux instance.
Customize DNS on a Linux instance
For more information, see Customize the DNS configuration on a Linux instance.
NTP sync failure after IPv6 configuration
Symptom
When you run the
ntpq -pcommand on the server to synchronize the time, a timeout error occurs, as shown in the following figure.
Solution
NoteThis method applies to CentOS 7 and earlier, Ubuntu 20.04 and earlier, Anolis OS (ANCK and RHCK), Alibaba Cloud Linux, and Debian.
Establish a remote connection to the Linux instance.
For more information, see Log on to a Linux instance by using Workbench.
Run the following command to modify the /etc/ntp.conf configuration file:
vi /etc/ntp.confPress the I key to enter the insert mode.
Add the
restrict -6 ::1line to the file, as shown in the following figure.
Press the Esc key, enter
:wq, and press the Enter key to save the changes and exit.Run the following command to restart the NTP service:
systemctl restart ntp
Hot-plug failure on custom image instances
Symptom
Hot-plugging a cloud disk refers to mounting or detaching a cloud disk while an instance is in the Running state. Hot-plugging a network interface refers to attaching or detaching an elastic network interface while an instance is in the Running state.
Alibaba Cloud supports hot-plug for cloud disks and NICs, but this operation requires support from the operating system kernel. If the kernel does not support hot-plug, the following issues can occur:
After you attach a cloud disk or bind an ENI, the corresponding device is not visible in the operating system.
Detaching a cloud disk or unbinding an ENI fails.
Solution
Kernel support requirements for hot-plug differ between standard cloud instances and bare metal instances. Ensure your kernel supports both Peripheral Component Interconnect (PCI) and Advanced Configuration and Power Management Interface (ACPI) hot-plug features. These features are enabled by default on most systems, except for older versions such as CentOS 5. To verify that your kernel supports PCI and ACPI hot-plug, follow these steps:
Establish a remote connection to the Linux instance.
For more information, see Log on to a Linux instance by using Workbench.
Run the following command to check the current kernel version of the instance:
uname -rThe following output indicates that the current kernel version is
3.10.0-1127.19.1.el7.x86_64.
Run the following command to view the files in the
/bootdirectory:ll /bootThe following output indicates that
config-3.10.0-1127.19.1.el7.x86_64is the system's kernel configuration file.
Run the following command to view the kernel configuration file of the system:
cat /boot/config-3.10.0-1127.19.1.el7.x86_64If the following configuration items are all set to
y, the features are built into the kernel, and the operating system supports hot-plugging.CONFIG_HOTPLUG_PCI_PCIE=y CONFIG_HOTPLUG_PCI=y CONFIG_HOTPLUG_PCI_ACPI=yIf a configuration item is set to
is not set, the feature was not compiled into the kernel. You must recompile the kernel to enable the feature.If a configuration item is set to
m, the feature is compiled as a module. For example, ifCONFIG_HOTPLUG_PCI_ACPIis compiled as a module, you must load the corresponding module.CONFIG_HOTPLUG_PCI_PCIE=y CONFIG_HOTPLUG_PCI=y CONFIG_HOTPLUG_PCI_ACPI=mFor example, in the 2.6 kernel of CentOS 5.x, the module for
CONFIG_HOTPLUG_PCI_ACPIis acpiphp.ko. To load the module, run themodprobe acpiphpcommand. If the module fails to load, you can upgrade to a newer kernel version or stop the instance and perform a cold-plug operation.ImportantWe recommend that you do not arbitrarily upgrade the kernel or operating system of your ECS instance. If you need to upgrade the kernel, see Prevent a Linux instance from failing to start after a kernel upgrade.
Instance shutdown after a kernel panic
Symptom
When a kernel panic occurs, the system loads a second kernel (also known as a capture kernel) to perform a memory dump and generate Kdump logs. Due to a compatibility issue with bare metal instance types, disk discovery can fail during the boot of the capture kernel. This failure prevents the collection of Kdump logs, causes the capture kernel to fail, and shuts down the instance. You must then restart the instance from the console.
For more information about bare metal instance types, see Instance families.
Cause
On bare metal instances, using the Kdump service to generate a dump file may fail.
This issue occurs on 6th-generation ebm* series bare metal instances running one of the following images:
CentOS 8.3 and earlier versions
Ubuntu 16 and 18
Debian 10
Alibaba Cloud Linux 2 with a kernel version that is earlier than
4.19.91-24.al7(This issue is fixed in4.19.91-24.al7and later versions.)
This issue occurs on 7th-generation ebm* series bare metal instances running the Debian 10 image.
Solution
CentOS and other images
We recommend that you change the operating system to a more recent version. For more information, see Change the operating system (replace the system disk).
Alibaba Cloud Linux 2 images
We recommend that you upgrade the kernel to version
4.19.91-24.al7or later. Follow these steps:Establish a remote connection to the ECS instance.
For more information, see Log on to a Linux instance by using Workbench.
Run the following command to check the kernel version:
uname -rRun the following command to upgrade the kernel:
sudo yum update kernelRun the following command to restart the ECS instance for the new kernel to take effect:
sudo reboot







