Troubleshooting common issues
Resolve common issues with PAI CLI authentication, network connectivity, and instance creation.
Authentication and credentials
Q: What do I do if I get a "credential is empty" error or authentication fails?
Check whether credentials are configured by running
pai config list. Sensitive fields are masked, but you can see whether they're empty.Verify that your AccessKey is valid. Go to the Alibaba Cloud console > RAM > Users > Manage AccessKeys.
If you use environment variables, confirm that
PAI_ACCESS_KEY_IDandPAI_ACCESS_KEY_SECRETare set correctly.If you use an ECS RAM role, confirm that the instance is bound to a RAM role and
credential_typeis set toecs_ram_role.
Q: How do I switch between different accounts?
# Switch between profiles
pai dsw instance list --profile dev
pai dsw instance list --profile prodNetwork and connectivity
Q: What do I do if exec or cp commands return "connection refused" or time out?
Confirm that the instance is in the Running state:
pai dsw instance get <instance-id>Check the channel type. The default is the gateway channel. If the instance doesn't have public access enabled, you may need to use the VPC channel.
Try switching channels:
pai dsw instance exec --via vpc <instance-id> -- echo okUse
--debugto view detailed network request logs and identify the specific error.
Q: How do I use the PAI CLI inside a DSW instance?
The PAI CLI comes pre-installed in DSW instances. In most cases, run pai commands directly without configuring an AccessKey. When the instance is bound to an instance RAM role, the CLI automatically obtains temporary credentials from the instance metadata server and runs commands with the permissions of the instance owner. For more information about AccessKey-free authentication, see Configure credentials. If the instance isn't bound to a RAM role, configure credentials by using pai config set or environment variables.
Instance creation and specifications
Q: What do I do if I get a "resource is not enough" error when I create an instance?
Check the availability of the instance type:
pai dsw instance list-ecs-specs --accelerator-type GPU. Pay attention to theis_availablefield.Try a different region or zone by specifying
--region cn-shanghai.Try a preemptible instance, which costs less but may be reclaimed. Configure
--spot-specto use preemptible instances.If you use a subscription instance, check whether your resource quota is sufficient:
pai resource quota get <quota-id>
Q: How do I choose an image?
# List all official preset images
pai image list --type preset
# List custom images
pai image list --type customImage IDs typically follow this format: framework:version-gpu-pyversion-cuda-ubuntuversion. For example, pytorch:2.0.1-gpu-py310-cu118-ubuntu20.04.
Debugging tips
Q: How do I view the actual API requests sent by a command?
# Add --debug to view complete HTTP request/response
pai dsw instance list --debug
# Use --dry-run to preview the operation without executing
pai dsw instance delete <instance-id> --dry-run
# Use --generate-skeleton to generate a request template
pai dsw instance create --generate-skeletonQ: How do I process JSON output with jq?
# Extract the instance ID list
pai dsw instance list -o json | jq '.[].instance_id'
# Filter instances in Running state
pai dsw instance list -o json | jq '.[] | select(.status == "Running")'
# Get the first instance ID
pai dsw instance list -o json | jq -r '.[0].instance_id'Common error reference
Error message | Cause | Solution |
| No credentials are configured | Run |
| The AccessKey ID is invalid | Check whether the AccessKey ID is correct or has been deleted |
| The AccessKey secret is incorrect | Reset the access_key_secret |
| Insufficient RAM permissions | Attach the required policy to the user in the RAM console |
| The instance ID doesn't exist | Check whether the instance ID is correct or has been deleted |
| An invalid parameter value is specified | Check the parameter format. Run --help for usage information |
| The instance is unreachable | Check the instance status and network channel configuration |
| Insufficient resources to create an instance or submit a job | Check quota and specification availability, or switch to a different specification or region |