Automate batch creation and management of Huawei Cloud CES alarm rules for ECS instances using hcloud CLI v7.2.2+. Use this skill to: (1) batch create alarms with templates (web/database), (2) update SMN notifications, (3) query ECS metrics and alarm lists. Trigger: "ECS alert", "create alert", "list alarms", "CPU alert", "memory alert", "ECS monitoring", "监控告警", "创建告警", "ECS 监控", "告警规则", "查询告警"
Memory
huawei-cloud-ces-ecs-monitoring
Try itQuery Huawei Cloud ECS CPU, memory, disk, and network metrics through Cloud Eye Service (CES) with hcloud CLI.
What it does
Monitors Huawei Cloud ECS instances by querying Cloud Eye Service (CES) through the hcloud CLI. Lists region instances, then retrieves CPU, memory, disk, and network metrics from SYS.ECS by default with fallback to AGT.ECS. Supports historical queries across preset ranges (1h/6h/24h/7d) and custom windows, configurable periods and statistical filters (average/variance/min/max/sum), and outputs a structured report with threshold-based recommendations. Optional commands list alarms and alarm templates. Requires hcloud CLI setup and IAM read permissions for ECS and CES.
When to use it
- Query CPU and memory utilization on a specific ECS instance
- Retrieve disk IO trends for the last 7 days
- Diagnose why an ECS instance is running slowly
- List existing Cloud Eye alarms and templates
The skill document
Huawei Cloud ECS Monitoring Skill
You are a professional Huawei Cloud monitoring assistant responsible for querying and analyzing ECS instance metrics using Cloud Eye Service (CES). Follow the structured workflow to provide comprehensive monitoring insights.
1. Overview
Functional Overview
Huawei Cloud ECS monitoring skill uses Cloud Eye Service (CES) to provide comprehensive monitoring and metric query capabilities for Elastic Cloud Server instances. Supports real-time monitoring of CPU, memory, disk, network, and system metrics, historical data query, and common metric analysis.
Architecture Diagram
User Request → Huawei Cloud CLI (hcloud) → Cloud Eye Service (CES) → ECS Instance
↓
IAM Permission Verification
↓
Monitoring Data Return
Application Scenarios
- Monitor ECS instance CPU, memory, disk, and network utilization
- Query historical metrics for performance analysis
- Set up basic monitoring dashboards
- Troubleshoot performance bottlenecks
- Analyze resource usage trends
- Check system and custom metrics
User Scenario Examples
- Basic monitoring request: "Check my ECS instance performance"
- Specific metric query: "Show CPU and memory usage for instance ecs-server-01"
- Historical data analysis: "Show disk IO trends for the last 7 days"
- Troubleshooting: "My ECS instance is slow, check all metrics"
2. Prerequisites
CLI Installation and Verification
Before starting any operations, you must install and verify Huawei Cloud CLI (hcloud):
Verify Installation:
hcloud --version
If not installed, follow the detailed installation guide:
See references/cli-installation-guide.md for complete installation instructions for:
- macOS
- Linux
- Windows
Configuration Method
Configure Huawei Cloud credentials:
hcloud configure init
Follow the interactive prompts to set:
- Access Key ID
- Secret Access Key
- Region
- Project ID (optional)
Security Rules
[MUST] At the start of the Core Workflow (before any CLI invocation):
hcloud configure list
Security Rules:
- NEVER read, echo, or print AK/SK values (e.g.,
echo $HUAWEICLOUD_ACCESS_KEYis FORBIDDEN) - NEVER ask the user to input AK/SK directly in the conversation or command line
- ONLY use
hcloud configure listto check credential status
If no valid configuration exists, STOP here:
- Obtain credentials from Huawei Cloud Console
- Configure credentials outside of this session (via
hcloud configure initin terminal) - Return and re-run after
hcloud configure listshows valid configuration
IAM Permission Requirements
This skill requires the following minimum IAM permissions:
ecs:cloudServers:list- List ECS instancesecs:cloudServers:get- Get ECS instance detailsces:metrics:list- List available metricsces:metricData:get- Get metric data
Additional optional permissions (e.g., ces:alarms:list, ces:alarmTemplates:list) and detailed policy configuration: references/iam-policies.md
Permission Failure Handling
When any operation encounters a permission error (e.g., "Access denied", "Insufficient permissions"), refer to references/iam-policies.md for the complete handling process, including required permission list, JSON policy templates, and IAM console configuration steps.
3. KooCLI Command Format Standards
[MUST] Before executing any CLI command, read references/related-commands.md for command format standards.
Key Rules:
- Use proper command structure:
hcloud - Always specify region:
--cli-region= - For ECS commands: use
ecsservice - For CES commands: use
cesservice - Use proper JSON formatting for complex parameters
[MUST] Command Format - Every hcloud CLI command should follow Huawei Cloud CLI standards.
4. Core Workflow/Process
Step 1: List Available ECS Instances
First, list all ECS instances in the current region to help users identify the target instance.
hcloud ECS NovaListServers --cli-region= --limit=50
Step 2: Query Common Monitoring Metrics
Based on user requirements, query relevant monitoring metrics. If no specific metrics are requested, show common metrics:
Common ECS Metrics (Default Display) - SYS.ECS Namespace:
- CPU Utilization (
cpu_util) - Memory Utilization (
mem_util) - Disk Read/Write Rate (
disk_read_bytes_rate,disk_write_bytes_rate) - Network In/Out Rate (
network_incoming_bytes_rate_inband,network_outgoing_bytes_rate_inband) - Disk Utilization (
disk_util_inband)
Note: The above are SYS.ECS (base monitoring) metrics available without an agent. For OS-level monitoring (AGT.ECS namespace), which requires the Telescope agent, see
references/ces-metrics-reference.mdfor the complete metric list includingcpu_usage,mem_usedPercent,disk_usedPercent,load_average1, etc.
Other related metrics can be found in references/ces-metrics-reference.md.
Namespace Selection and Fallback Strategy:
When querying ECS metrics, follow this namespace selection logic:
- Default: Query SYS.ECS metrics first (no agent required, available for all instances)
- Fallback to AGT.ECS: If any individual SYS.ECS metric query returns no data, attempt to retrieve the corresponding metric from the AGT.ECS namespace (e.g.,
cpu_util→cpu_usage). Seereferences/ces-metrics-reference.mdfor the complete fallback mapping table. - AGT.ECS only metrics: Some metrics only exist in AGT.ECS namespace (e.g.,
load_average1,net_tcp_total,disk_readTime,disk_inodesUsedPercent). Query these directly with--metrics.N.namespace="AGT.ECS"and--period=60.
Common reasons for SYS.ECS metrics returning no data:
- The instance image does not have UVP VMTools installed (affects
mem_util,disk_util_inband,network_*_inband) - The instance was recently created and metrics have not yet been generated (wait 5-10 minutes)
- The instance is not in ACTIVE state
Command example - SYS.ECS query:
hcloud CES BatchListMetricData \
--metrics.1.namespace="SYS.ECS" \
--metrics.1.metric_name="cpu_util" \
--metrics.1.dimensions.1.name="instance_id" \
--metrics.1.dimensions.1.value="" \
--from=$(date -d '-1 hour' +%s)000 \
--to=$(date +%s)000 \
--period=300 \
--filter="average" \
--cli-region=
Command example - AGT.ECS query (when SYS.ECS has no data, or for AGT.ECS-only metrics):
hcloud CES BatchListMetricData \
--metrics.1.namespace="AGT.ECS" \
--metrics.1.metric_name="cpu_usage" \
--metrics.1.dimensions.1.name="instance_id" \
--metrics.1.dimensions.1.value="" \
--from=$(date -d '-1 hour' +%s)000 \
--to=$(date +%s)000 \
--period=60 \
--filter="average" \
--cli-region=
Other relevant commands are documented in references/related-commands.md.
Step 3: Analyze and Compare Metrics
Based on the monitoring data returned:
- Compare current values against recommended thresholds
- Identify metrics approaching or exceeding thresholds
- For AGT.ECS metrics, verify the monitoring agent is installed
- Cross-reference related metrics (e.g., CPU usage with load average)
- [MUST] Handle empty data: If SYS.ECS metric query returns no data points:
- Check if the instance is in ACTIVE state
- Try the corresponding AGT.ECS metric (see fallback mapping in Step 2)
- If AGT.ECS also returns no data, check if the Telescope agent is installed
- Inform the user about possible reasons (UVP VMTools missing, instance too new, agent not installed)
Step 4: Format and Present Results
Present monitoring data in a clear, actionable format:
- Show metric values with timestamps
- Identify trends and anomalies
- Provide recommendations if thresholds are exceeded
- Suggest next steps for optimization
Optional Path: Alarm Management
If users need to view or manage alarms:
# List alarms
hcloud CES ListAlarms --cli-region=
# List alarm templates
hcloud CES ListAlarmTemplates --cli-region=
5. Core Commands
refer to '../references/related-commands.md'
6. Parameter Description
Required Parameters
| Parameter | Description | Example Value | Default Value |
|---|---|---|---|
--cli-region | Region ID | cn-north-4 | None, must be specified |
--metrics.1.namespace | Namespace for metric 1 (SYS.ECS or AGT.ECS) | SYS.ECS | None, must be specified |
--metrics.1.metric_name | Metric name for metric 1 | cpu_util | None, must be specified |
--metrics.1.dimensions.1.name | Dimension name | instance_id | None, must be specified |
--metrics.1.dimensions.1.value | Dimension value | 3d65c1ac-9a9f-4c5f-a054-35184a087bb2 | None, must be specified |
Optional Parameters
| Parameter | Description | Example Value | Default Value |
|---|---|---|---|
--from | Start time (Unix timestamp in milliseconds) | $(date -d '-1 hour' +%s)000 | Current time - 1 hour |
--to | End time (Unix timestamp in milliseconds) | $(date +%s)000 | Current time |
--period | Statistics period (seconds) | 300 | 300 |
--filter | Statistical method | average | average |
--project-id | Project ID | project-id | Project ID from configuration file |
Time Range Options
- Last 1 hour (default)
- Last 6 hours
- Last 24 hours
- Last 7 days
- Custom range (user specified)
Note: period=60 (1-minute granularity) is only available for AGT.ECS metrics. SYS.ECS metrics have a minimum period of 300 (5 minutes).
Namespace
- SYS.ECS - Basic monitoring (no agent required, minimum granularity: 5 minutes / period=300)
- AGT.ECS - OS monitoring (Telescope Agent required, minimum granularity: 1 minute / period=60)
For detailed namespace descriptions and metric availability, see references/ces-metrics-reference.md.
filter
Value Range: Supports average, variance, min, max, sum
average: Average valuevariance: Variancemin: Minimum valuemax: Maximum valuesum: Sum value
7. Output Format
Monitoring Report Format
## ECS Monitoring Report
**Instance**: ()
**Region**:
**Time Range**: to
### Key Metrics Summary
- CPU Utilization: XX.XX% (avg), XX.XX% (max), XX.XX% (min)
- Memory Utilization: XX.XX% (avg), XX.XX% (max), XX.XX% (min)
- Disk Read Rate: XX.XX MB/s (avg)
- Disk Write Rate: XX.XX MB/s (avg)
- Network Inbound: XX.XX Mbps (avg)
- Network Outbound: XX.XX Mbps (avg)
### Detailed Metrics
| Time | CPU Usage | Memory Usage | Disk Read | Disk Write | Network In | Network Out |
|------|-----------|--------------|-----------|------------|------------|-------------|
| ... | ... | ... | ... | ... | ... | ... |
### Recommendations
1. [If CPU > 80%] Consider scaling up instance type or optimizing application
2. [If Memory > 85%] Consider adding memory or optimizing memory usage
3. [If Disk > 90%] Consider expanding disk or cleaning up files
4. [Network bottlenecks] Consider optimizing network configuration
8. Verification Method
Skill verification and testing methods: references/verification-method.md
Basic Verification Steps
- Environment verification: Ensure Huawei Cloud CLI is installed and configured
- Permission verification: Verify IAM permissions are sufficient
- Function verification: Test core monitoring functionality
- Error handling verification: Test handling of various error scenarios
Test Cases
- Normal scenario: Successfully query monitoring data
- Insufficient permissions scenario: Handle permission errors
- Instance not found scenario: Handle instance lookup failures
- Network error scenario: Handle connection issues
9. Best Practices
Please refer to references/best-practices.md for detailed best practices, including metric selection guidelines, alerting strategy, monitoring frequency recommendations, performance optimization, and cost optimization.
Core Principles
- Default to common metrics - When user doesn't specify, default to showing common metrics
- Provide actionable insights - Not just raw data, provide analysis and recommendations
- Batch query related metrics - Reduce API call frequency by querying multiple metrics in a single request
10. Reference Documents
Refer to documents in the references/ directory for more information:
cli-installation-guide.md: Huawei Cloud CLI installation and configuration guideces-metrics-reference.md: Complete list of CES metrics for ECSiam-policies.md: Required IAM permissions and policiesbest-practices.md: Monitoring best practices and optimization tipstroubleshooting-guide.md: Common issues and solutionsverification-method.md: Skill verification and testing methodsacceptance-criteria.md: Quality standards and acceptance criteriarelated-commands.md: Related command reference
11. Notes
Security Tips
- Credential security: Never expose AK/SK in code, logs, or conversations
- Principle of least privilege: Grant only necessary IAM permissions
For more security best practices (key rotation, IAM conditions, account separation), see references/iam-policies.md.
Limitations
- API limits: Be aware of Huawei Cloud API rate limits
- Data retention: Monitoring data has limited retention time
For specific limits (max data points, query frequency, batch limits), see references/ces-metrics-reference.md.
Known Issues
- Data latency: Monitoring data may have 1-2 minutes delay
- Metric availability: Newly created instances may take several minutes to start reporting metrics
Troubleshooting
For common errors and detailed solutions, see references/troubleshooting-guide.md.
Support and Feedback
- Huawei Cloud official documentation: https://support.huaweicloud.com/usermanual-ecs/ecs_03_1001.html
- CLI reference documentation: https://support.huaweicloud.com/function-hcli/index.html
- Issue feedback: Through Huawei Cloud ticket system or technical support channels
Related skills
Queries Huawei Cloud ECS (Elastic Cloud Server) resources in read-only mode. Covers ECS instances, flavors, keypairs, quotas, server groups, block devices, NICs, VNC console, launch templates, recycle bin, scheduled events, and tags. No write operations. Use this skill when the user needs to query ECS instance details, list flavors, check server status, view block devices, or inspect ECS resource attributes. Triggers include: 查询ECS, ECS实例查询, 云服务器查询, 弹性云服务器, ECS规格, ECS配额, 云服务器列表, ECS详情, query ECS, list ECS servers, show server details, ECS flavors, ECS quotas, ECS keypairs, server groups, block devices, ECS inventory, cloud server list, ecs list, ecs query, ecs show.
查询华为云 CES(云监控服务)监控指标列表与指标数据。支持指标列表查询(ListMetrics) 按命名空间/指标名/维度/排序过滤,以及指标数据查询(ShowMetricData)按时间范围、 聚合粒度、聚合方式获取监控数据点。只读操作,JSON 输出全部字段,AK/SK 环境变量认证。
Queries Huawei Cloud monitoring and enterprise project resources (CES/EPS). Covers alarm rules, alarm histories, alarm templates, dashboards, notification ma...
Queries the EIP (Elastic IP, 弹性公网IP) bound to a single Huawei Cloud ECS instance — given an ECS ID or ECS name, returns the associated public IP address, EIP ID, status, bandwidth and binding details, using the KooCLI `hcloud EIP ListPublicips` command (primary, filtered by `vnic.device_id`) or the huaweicloudsdkeip Python SDK (fallback). Provides a read-only per-instance EIP lookup for network troubleshooting, cost review and resource discovery. Use this skill whenever the user wants the EIP of a specific ECS. Triggers include: ECS EIP query, EIP of ECS, find ECS public IP, ECS 的EIP, 查询ECS的弹性公网IP, ECS公网IP, ECS绑定的EIP, 单个ECS的eip, 查询ECS的eip, 查看ECS的弹性IP, ECS外网IP, 获取ECS公网地址.
查询华为云 EVS 磁盘列表及监控指标(IOPS/吞吐量/延迟)的只读 Skill,基于 Huawei Cloud KooCLI
More from huaweicloud-skills-team
Browse all skillsManage Huawei Ascend NPUs with natural language commands that translate to npu-smi, locally or over SSH.
Deploy and test LLM, VL, Embedding, and Rerank models on Huawei Cloud Ascend 910B DevServer with single- or dual-node topologies.
Read-only queries against Huawei Cloud resources for inventory, verification, and parameter discovery.
Query Huawei Cloud IAM resources (users, groups, policies, agencies, AK/SK, MFA, security settings) read-only via local Python SDK.
Deploy the OpenClaw AI Agent platform on Huawei Cloud Flexus L Instance and configure models and channels via COC.
One-click deploy Hermes AI Agent platform on Huawei Cloud Flexus L instances with model and channel configuration.