0 9 1-7 * 1
At 09:00 on Monday on day 1, 2, 3, 4, 5, 6 and 7 of the month — note that cron matches either day field, so this fires on whichever comes first, not only when both agree
Field by Field
| Field | Value | Matches |
|---|---|---|
| Minute | 0 | 0 |
| Hour | 9 | 9 |
| Day of month | 1-7 | 1, 2, 3, 4, 5, 6, 7 |
| Month | * | every month |
| Day of week | 1 | 1 |
Two Day Fields, Restricted Together
This is the one place where cron's day-field union rule is useful rather than a trap.
Normally, restricting both day-of-month and day-of-week makes cron match either, which
surprises people. Here the intersection is what we want, and it is achieved by narrowing
day-of-month to 1-7 — a window that contains exactly one of each weekday — and
day-of-week to 1.
Beware: on Vixie cron and its descendants, restricting both fields matches the *union*, so this expression fires on every day from the 1st to the 7th and every Monday. Only schedulers implementing the intersection rule (Quartz, and cron implementations that special-case it) give the first Monday directly.
The Portable Version
Fire every Monday and let the job check the date:
``bash
0 9 * * 1 [ "$(date +%d)" -le 07 ] && /opt/app/monthly.sh
`
That is correct on every implementation, and it is easy to read.
Why the First Monday
Monthly business rhythms attach to it: board packs, team retrospectives, invoice runs and
metric reviews. Unlike "the 1st", it never falls on a weekend, so nothing has to be rescheduled.
Time Zones
Standard crontab evaluates in system local time. Vercel Cron, GitHub Actions, Kubernetes
CronJobs and AWS EventBridge all evaluate in UTC. If converting your local time crosses
midnight, the day-of-week field shifts too — weekdays at 5pm in UTC-07:00 is
0 0 * * 2-6, not 0 0 * * 1-5.
The Day-Field Trap
When both the day-of-month and day-of-week fields are restricted, cron matches either,
not both. 0 0 13 * 5 runs on every 13th *and* every Friday — not Friday the 13th. Leave
one of them as * unless you genuinely want the union.
Other Common Schedules
| Expression | Runs |
|---|---|
* * * * * | Every minute |
*/5 * * * * | Every 5 minutes |
*/15 * * * * | Every 15 minutes |
0 * * * * | Every hour, on the hour |
0 0 * * * | Every day at midnight |
0 9 * * * | Every day at 9am |
0 9 * * 1-5 | Weekdays at 9am |
0 9 * * 1 | Every Monday at 9am |
Making the Job Safe
Assume double firing. DST transitions, restarts and retries all cause it. Make the job
idempotent rather than assuming exactly-once.
- Assume overlap. Cron starts the next run whether or not the last one finished. Take a
lock.
Avoid:00`. Every hourly job on the internet fires at the top of the hour; a random
- Log the start and end. A cron job that silently stops running is invisible until