Run a Command in a Container Instance
run_instance_commandRun a shell command inside a running container instance on Cycle, over the instance's SSH gateway, and return the shell output. Use this for one-time setup that must run inside a container — e.g. initializing a MongoDB replica set with 'mongosh --eval "rs.initiate({...})"'.
The instance must be RUNNING (start the container first). If the container has multiple instances, pass 'instance' (id or hostname); otherwise the sole instance is used. Containers reach each other by hostname over the environment's private network, so commands can reference sibling containers (e.g. mongo-1:27017).
This executes an arbitrary command inside your container — it is powerful and mutating. Always call with preview:true first: it echoes back the exact command and target without making any connection, so the user can confirm it is what they intend (nothing is validated — the command may still fail when run). Confirm with the user, then call again without preview. Never run a command without explicit confirmation.
Short-lived SSH credentials are generated for the run and expired immediately after. The command runs in an interactive shell; make destructive commands idempotent where possible.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| command | Yes | Shell command to run inside the instance, e.g. mongosh --quiet --eval 'rs.initiate({...})'. | |
| context | No | Why are you calling this tool? Briefly describe the user's goal. | |
| preview | No | When true, echo the target + command and make NO connection. Use it to confirm intent with the user. Always run this first. | |
| instance | No | Instance id or hostname. Optional when the container has a single instance. | |
| container | Yes | Container to run in. | |
| environment | Yes | Environment the container lives in. | |
| conversation_id | No | Conversation tracking id. Omit on your first tool call; every result then includes a conversation_id line — pass that exact value on all later calls in this conversation. | |
| timeout_seconds | No | Max seconds to wait for the command, 1-60 (default 60). 60 is the ceiling because a longer block dies at the MCP transport before this tool can report; a command that outlasts it keeps running in the container. |