---
title: Alibaba Cloud Integration Troubleshooting
description: Troubleshooting steps for the Datadog Alibaba Cloud integration
breadcrumbs: >-
  Docs > Integrations > Integration Guides > Alibaba Cloud Integration
  Troubleshooting
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Alibaba Cloud Integration Troubleshooting

{% callout %}
# Important note for users on the following Datadog sites: us2.ddog-gov.com

{% alert level="info" %}
To find out if this integration is available in your organization, see your [Datadog Integrations](https://app.datadoghq.com/integrations) page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email [support@ddog-gov.com](mailto:support@ddog-gov.com).
{% /alert %}

{% /callout %}

## Overview{% #overview %}

Use this guide to troubleshoot the Datadog [Alibaba Cloud integration](https://docs.datadoghq.com/integrations/alibaba-cloud.md). Configuration issues appear on the [Alibaba Cloud integration tile](https://app.datadoghq.com/integrations?integrationId=alibaba-cloud).

## Alibaba Cloud access key is invalid or no longer exists{% #alibaba-cloud-access-key-is-invalid-or-no-longer-exists %}

This issue occurs when the access key ID or access key secret configured for the integration is invalid, inactive, or deleted.

To remediate this issue:

- If the access key is inactive, re-enable it in the Alibaba Cloud RAM console.
- If the access key secret is invalid, update the Datadog integration with the correct secret.
- If the access key no longer exists, or the correct secret is unavailable, create a replacement access key for the RAM user that Datadog uses. Copy the new key ID and secret, then update the Alibaba Cloud credentials in the Datadog integration. For instructions, see [Create an AccessKey pair](https://www.alibabacloud.com/help/en/ram/user-guide/create-an-accesskey-pair) in the Alibaba Cloud documentation.

Then confirm that the RAM user has the permissions required by the [Alibaba Cloud integration](https://docs.datadoghq.com/integrations/alibaba-cloud.md).

## Cloud monitoring permissions are missing{% #cloud-monitoring-permissions-are-missing %}

This issue occurs when the RAM user used by the Datadog integration cannot query CloudMonitor metrics.

To remediate this issue, add the `cms:DescribeMetricList` permission to the policy attached to the Datadog integration RAM user. Then wait about 15 minutes for the next collection cycle to confirm that Datadog receives CloudMonitor metrics.

For instructions on editing a RAM policy, see [Grant permissions to a RAM user](https://www.alibabacloud.com/help/en/ram/user-guide/grant-permissions-to-a-ram-user).

## Log collection permissions are missing{% #log-collection-permissions-are-missing %}

This issue occurs when the RAM user used by the Datadog integration lacks the permissions required to read from Simple Log Service (SLS).

To remediate this issue:

1. Review the policy attached to the Datadog integration RAM user.
1. Add the SLS read permissions described in [SLS RAM access control permissions](https://www.alibabacloud.com/help/en/sls/log-service-ram-access-control-permissions-configuration).
1. Confirm that the policy applies to every SLS project and logstore that you want Datadog to collect logs from.

For instructions on editing a RAM policy, see [Grant permissions to a RAM user](https://www.alibabacloud.com/help/en/ram/user-guide/grant-permissions-to-a-ram-user).

## Prometheus permissions for ACK are missing{% #prometheus-permissions-for-ack-are-missing %}

This issue occurs when the RAM user used by the Datadog integration lacks the permissions required to configure Alibaba Cloud Managed Service for Prometheus on an Alibaba Cloud Container Service for Kubernetes (ACK) cluster.

To remediate this issue, add the following permissions to the policy attached to that RAM user. Scope the policy to the intended clusters where possible. The policy must include at least:

- `cs:InstallClusterAddons`
- `cs:UnInstallClusterAddons`

These permissions allow Datadog to install and reinstall the `ack-arms-prometheus` add-on on ACK clusters.

For instructions on editing a RAM policy, see [Grant permissions to a RAM user](https://www.alibabacloud.com/help/en/ram/user-guide/grant-permissions-to-a-ram-user). For resource-scoping options, see [InstallClusterAddons](https://www.alibabacloud.com/help/en/ack/ack-managed-and-ack-dedicated/developer-reference/api-cs-2015-12-15-installclusteraddons).

## Alibaba Cloud Resource Center is not enabled{% #alibaba-cloud-resource-center-is-not-enabled %}

This issue occurs when Alibaba Cloud Resource Center is not enabled for the account. Datadog cannot collect metrics until you enable the service.

To remediate this issue:

1. Sign in to the Alibaba Cloud account that is connected to Datadog.
1. Open [Resource Center](https://resourcecenter.console.aliyun.com/).
1. Enable Resource Center for the account.
1. Attach the `AliyunResourceCenterReadOnlyAccess` policy to the Datadog integration RAM user.
1. Wait about 15 minutes for the next collection cycle to confirm that Datadog receives metrics.

## Alibaba Cloud API quota limit reached{% #alibaba-cloud-api-quota-limit-reached %}

This issue occurs when the account has reached an Alibaba Cloud API quota limit. This is distinct from temporary request throttling.

To remediate this issue:

1. Review the quota and billing status for the Alibaba Cloud account.
1. If applicable, enable pay-as-you-go quotas or resolve outstanding billing issues.
1. If the existing quota is insufficient, [request a quota increase](https://www.alibabacloud.com/help/en/resource-management/user-guide/request-a-quota-increase).
1. Wait for the quota change to take effect, then confirm that Datadog resumes collection.

Still need help? Contact [Datadog support](https://docs.datadoghq.com/help/).
