DataWorks Operations Center assistant for task and workflow operations, alert rule creation and management.
Supports periodic, manual, and triggered tasks/workflows (excludes real-time/streaming tasks).
Installation
Pre-check: Aliyun CLI >= 3.3.3 required
Run aliyun version to verify >= 3.3.3. If not installed or version too low,
run curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash to update,
or see references/cli-installation-guide.md for installation instructions.
Pre-check: Aliyun CLI plugin update required
[MUST] run aliyun configure set --auto-plugin-install true to enable automatic plugin installation.
[MUST] CLI AI-Mode & User-Agent — Before executing any business CLI command:
The aliyun CLI default timeout may cause indefinite hangs. You [MUST] set the following environment variables before executing any API command:
Variable
Description
Default
ALIBABA_CLOUD_CONNECT_TIMEOUT
Connection timeout in milliseconds
10000
ALIBABA_CLOUD_READ_TIMEOUT
Read timeout in milliseconds
30000
For large-volume queries (e.g., paginated task instance lists with 500+ results), ALIBABA_CLOUD_READ_TIMEOUT may be increased to 60000 ms.
If an API call times out, [MUST] retry once with a doubled read timeout value. If the second attempt also fails, report the timeout to the user and suggest checking network connectivity, project ID validity, or RAM permissions.
No other special environment variable requirements.
Authentication
Pre-check: Alibaba Cloud Credentials Required
Security Rules:
NEVER read, echo, or print AK/SK values (e.g., echo $ALIBABA_CLOUD_ACCESS_KEY_ID is FORBIDDEN)
NEVER ask the user to input AK/SK directly in the conversation or command line
NEVER use aliyun configure set with literal credential values
ONLY use aliyun configure list to check credential status
bash
aliyun configure list
Check the output for a valid profile (AK, STS, or OAuth identity).
Configure credentials outside of this session (via aliyun configure in terminal or environment variables in shell profile)
Return and re-run after aliyun configure list shows a valid profile
RAM Permissions
This skill requires the following RAM permissions:
Task Management
API
Permission Action
Description
GetTask
dataworks:GetTask
Get task details
ListTasks
dataworks:ListTasks
Query task list
ListUpstreamTasks
dataworks:ListUpstreamTasks
Query upstream task list
ListDownstreamTasks
dataworks:ListDownstreamTasks
Query downstream task list
ListTaskOperationLogs
dataworks:ListTaskOperationLogs
Query task operation logs
Task Instance Management
API
Permission Action
Description
ListTaskInstances
dataworks:ListTaskInstances
Query task instance list
GetTaskInstance
dataworks:GetTaskInstance
Get task instance details
GetTaskInstanceLog
dataworks:GetTaskInstanceLog
Get task instance logs
ListUpstreamTaskInstances
dataworks:ListUpstreamTaskInstances
Query upstream task instances
ListDownstreamTaskInstances
dataworks:ListDownstreamTaskInstances
Query downstream task instances
ListTaskInstanceOperationLogs
dataworks:ListTaskInstanceOperationLogs
Query task instance operation logs
Workflow (Operations Center, read-only)
API
Permission Action
Description
GetWorkflow
dataworks:GetWorkflow
Get workflow details
ListWorkflows
dataworks:ListWorkflows
Query workflow list
Workflow Instance (Operations Center, read-only)
API
Permission Action
Description
ListWorkflowInstances
dataworks:ListWorkflowInstances
Query workflow instance list
GetWorkflowInstance
dataworks:GetWorkflowInstance
Get workflow instance details
Alert Rules (Custom Monitoring, read-only)
API
Permission Action
Description
ListAlertRules
dataworks:ListAlertRules
Query alert rule list
GetAlertRule
dataworks:GetAlertRule
Get alert rule details
[MUST] Permission Failure Handling: When any command or API call fails due to permission errors at any point during execution, follow this process:
Read references/ram-policies.md to get the full list of permissions required by this SKILL
Use ram-permission-diagnose skill to guide the user through requesting the necessary permissions
Pause and wait until the user confirms that the required permissions have been granted
Parameter Confirmation
IMPORTANT: Parameter Confirmation — Before executing any command or API call,
ALL user-customizable parameters (e.g., ProjectId, RegionId, bizdate, instance IDs, etc.)
MUST be confirmed with the user. Do NOT assume or use default values without explicit user approval.
Parameter
Required/Optional
Description
Default
Region
Required
Target region
None
ProjectId
Required
DataWorks Workspace ID
None
Bizdate
Required (instance-related)
Business date (millisecond timestamp)
Today's business date
Instance status enum values (used for --status parameter):
NotRun - Not Run
Running - Running
Failure - Failed
Success - Success
WaitTime - Waiting for Time
WaitResource - Waiting for Resources
Workflow instance type enum values (used for --type parameter):
Normal - Normal Scheduling
Manual - Manual Run
SmokeTest - Smoke Test
SupplementData - Backfill Data
ManualWorkflow - Manual Workflow
TriggerWorkflow - Trigger Workflow
Core Workflows
0. Confirm Target Region
Confirm the target region with the user. Common regions: