---
title: "STACKIT Run Command"
description: "Secure, remote execution of template-based scripts and diagnostic commands on virtual machines without open inbound SSH/RDP ports."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Automation", "Compute", "Security", "DevOps", "SysAdmin"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-run-command/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-run-command.mdx"
---

STACKIT Run Command enables centralized, encrypted execution of administrative scripts on Linux and Windows VMs without exposing public access ports.

## Service Overview
- **Enhanced Security Perimeter**: Enables system diagnostics and maintenance without opening internet-facing SSH or RDP ports.
- **Repeatable Operations**: Standardizes administrative tasks using centrally maintained script templates.
- **Audit Logging**: Captures chronological execution history, console outputs, and exit codes centrally.

## Technical Details
- **Agent Architecture**: Relies on the STACKIT Server Agent running locally on the guest instance to process incoming API tasks.
- **Execution Workflow**: Select a template, pass parameter arguments, execute remotely, and view status (exit code 0 = success).
- **Access Control**: Scoped per project and managed through STACKIT IAM permissions.

## Limitations & Constraints
- **No Interactive Execution**: Executed in the background; interactive terminal prompts (e.g., `sudo` password prompts) are unsupported.
- **Strict Template Syntax**: Argument passing depends strictly on pre-defined template parameters; raw ad-hoc command strings are restricted.
- **Mandatory Local Agent**: Commands fail immediately if the guest STACKIT Server Agent is stopped or uninstalled.

<LinkCard title="STACKIT Run Command Documentation" href="https://docs.stackit.cloud" />
