<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloudpods –
Alibaba Cloud</title><link>/docs/en/tags/alibaba-cloud/</link><description>Recent content in Alibaba Cloud on Cloudpods</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><atom:link href="/docs/en/tags/alibaba-cloud/index.xml" rel="self" type="application/rss+xml"/><item><title>Docs: Create Alibaba Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/aliyun/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/aliyun/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list to open the create cloud account page.&lt;/li&gt;
&lt;li&gt;Select Alibaba Cloud as the cloud platform, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: Alibaba Cloud account name.&lt;/li&gt;
&lt;li&gt;Account type: Currently supports connecting Alibaba Cloud public cloud and finance cloud accounts.&lt;/li&gt;
&lt;li&gt;Key ID / password: Connect to Alibaba Cloud via Access Key authentication. An Access Key consists of a key ID (Access Key ID) and a password (Access Key Secret). See &lt;a href="#how-to-obtain-alibaba-cloud-parameters"&gt;How to obtain Alibaba Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify that the parameters are correct.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” to configure resource sync regions (all regions are synced by default).&lt;/li&gt;
&lt;li&gt;After configuration, click “Next: Billing file access information (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Alibaba Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;To manage a public cloud platform on this platform, the cloud account must at least have management permissions on the resources you operate. Granting the cloud account management permissions for all platform features is recommended.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;The domain of an added cloud account cannot be changed. To sync resources from the cloud account to another domain, delete the cloud account on the platform and add it again to the target domain. Deleting a cloud account on the platform only stops onboarding its resources and does not affect resources on the cloud account.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Alibaba Cloud account you add is new, enable the OSS service on Alibaba Cloud first.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Alibaba Cloud account has Resource Directory enabled and the credentials you enter are an AK/SK under a RAM sub-account (at least AliyunSTSAssumeRole, AccessAliyunOSSReadOnlyAccess, and AliyunResourceDirectoryReadOnlyAccess are required), sub-accounts under the entire Resource Directory are synced by default.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-obtain-alibaba-cloud-parameters"&gt;How to obtain Alibaba Cloud parameters&lt;/h2&gt;
&lt;h3 id="obtain-accesskey-with-the-primary-account"&gt;Obtain AccessKey with the primary account&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Alibaba Cloud console with the primary account, click the profile icon in the upper right, expand the dropdown, and click “accesskeys” to open the security information management page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun-accesskeys.png" alt="Alibaba Cloud AccessKey entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the security information management page, you can view existing AccessKey information or click “Create AccessKey” to create a new user AccessKey. When creating an AccessKey, Alibaba Cloud sends a verification code to the account contact’s phone; the AccessKey can be created only after verification succeeds.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun-get_acceesskey_list.png" alt="Alibaba Cloud AccessKey list"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Access Key Secret is hidden by default. Click “Show”; Alibaba Cloud sends a verification code to the contact phone for the account. The Access Key Secret is displayed only after verification succeeds.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun-get_access_key_secret.png" alt="Alibaba Cloud AccessKey Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="how-a-ram-sub-account-obtains-an-access-key"&gt;How a RAM sub-account obtains an Access Key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Alibaba Cloud console with the sub-account, click the profile icon in the upper right, expand the dropdown, and click “accesskey&amp;hellip;” to open the security information management page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_ram_get_access_key.png" alt="RAM sub-account AccessKey entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the security information management page, click “Create AccessKey” to create an AccessKey.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_get_ram_access_key_create.png" alt="RAM sub-account create AccessKey"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After creation succeeds, the AccessKeySecret is shown only once; save it promptly.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_ram_access_key_get.png" alt="RAM sub-account AccessKey Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;For an AccessKey that has already been created, the AccessKeySecret cannot be viewed again.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;To manage Alibaba Cloud resources through the platform, the cloud account needs sufficient permissions:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission description&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read-write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all Alibaba Cloud resources&lt;/td&gt;
&lt;td&gt;ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AdministratorAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Elastic Compute Service (ECS)&lt;/td&gt;
&lt;td&gt;AliyunECSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunECSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Virtual Private Cloud (VPC)&lt;/td&gt;
&lt;td&gt;AliyunVPCReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunVPCFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Elastic IP Address (EIP)&lt;/td&gt;
&lt;td&gt;AliyunEIPReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunEIPFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ECS elastic network interfaces&lt;/td&gt;
&lt;td&gt;AliyunVPCNetworkIntelligenceReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunECSNetworkInterfaceManagementAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Object Storage Service (OSS)&lt;/td&gt;
&lt;td&gt;AliyunOSSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunOSSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage NAT Gateway&lt;/td&gt;
&lt;td&gt;AliyunNATGatewayReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunNATGatewayFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Application Load Balancer (ALB)&lt;/td&gt;
&lt;td&gt;AliyunALBReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunALBFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Server Load Balancer (SLB)&lt;/td&gt;
&lt;td&gt;AliyunSLBReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunSLBFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ApsaraDB RDS&lt;/td&gt;
&lt;td&gt;AliyunRDSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunRDSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ApsaraDB for Redis&lt;/td&gt;
&lt;td&gt;AliyunKvstoreReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunKvstoreFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ActionTrail&lt;/td&gt;
&lt;td&gt;AliyunActionTrailFullAccess&lt;/td&gt;
&lt;td&gt;AliyunActionTrailFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage File Storage NAS&lt;/td&gt;
&lt;td&gt;AliyunNASReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunNASFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Web Application Firewall (WAF)&lt;/td&gt;
&lt;td&gt;AliyunYundunWAFReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunYundunWAFFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Resource Access Management (RAM)&lt;/td&gt;
&lt;td&gt;AliyunRAMReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunRAMFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Public DNS&lt;/td&gt;
&lt;td&gt;AliyunPubDNSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunPubDNSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Alibaba Cloud DNS&lt;/td&gt;
&lt;td&gt;AliyunDNSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunDNSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage enterprise finance&lt;/td&gt;
&lt;td&gt;AliyunFinanceConsoleReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunFinanceConsoleFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CloudMonitor&lt;/td&gt;
&lt;td&gt;AliyunCloudMonitorReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunCloudMonitorFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="how-to-grant-permissions-to-a-sub-account"&gt;How to grant permissions to a sub-account&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Alibaba Cloud console with the primary account, click the profile icon in the upper right, expand the dropdown, and click “Access control” to open the access control page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_access_control.png" alt="Alibaba Cloud access control entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “User management” in the left menu to open the user management page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_access_control_all.png" alt="Alibaba Cloud user management"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the user management page, click “Authorize” in the actions column for the target user to grant permissions.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_ram_user_access_control.png" alt="Alibaba Cloud user authorization"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="cloud-account-type"&gt;Cloud account type&lt;/h3&gt;
&lt;p&gt;Includes primary account and associated account. Before using an associated account, ensure the primary account has been imported to the platform, and select that primary account when using the associated account.&lt;/p&gt;
&lt;h3 id="bucket-url"&gt;Bucket URL&lt;/h3&gt;
&lt;p&gt;URL of the bucket that stores billing files. See &lt;a href="#how-to-obtain-the-billing-bucket-url"&gt;How to obtain the billing bucket URL?&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="file-prefix"&gt;File prefix&lt;/h3&gt;
&lt;p&gt;When the billing bucket also stores files other than billing files, configure a file prefix to obtain only billing files from the bucket. For Alibaba Cloud, the billing file prefix is the account ID, which you can view under Account management – Security settings.&lt;/p&gt;
&lt;h3 id="billing-analysis-scope"&gt;Billing analysis scope&lt;/h3&gt;
&lt;p&gt;Set the scope for the platform to analyze cloud account billing. Currently only accounts onboarded on this platform are supported.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accounts onboarded on this platform&lt;/strong&gt;: Collect billing for the primary account and its associated sub-accounts. If the primary account is used only as a payer for other accounts, billing files for those other accounts are discarded.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="collect-billing-immediately"&gt;Collect billing immediately&lt;/h3&gt;
&lt;p&gt;By default, the platform automatically collects billing at 04:00 every day. When this option is enabled, billing is collected immediately after billing file access information is configured.&lt;/p&gt;
&lt;h3 id="time-range"&gt;Time range&lt;/h3&gt;
&lt;p&gt;When “Collect billing immediately” is enabled, you can set a time range and collect billing for that range immediately. Collecting 1–6 months of billing is recommended; otherwise the large data volume may put pressure on the system and affect daily billing collection tasks.&lt;/p&gt;
&lt;h3 id="how-to-obtain-the-billing-bucket-url"&gt;How to obtain the billing bucket URL?&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Alibaba Cloud international accounts do not have billing bucket configuration; contact Alibaba Cloud support to assist with pushing billing data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Using an Alibaba Cloud primary account as an example, sign in to the Alibaba Cloud console with the primary account, click “Expenses” at the top, then “User Center” in the dropdown, and open the expenses user center page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunusercenter.png" alt="Alibaba Cloud user center"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Set billing data storage” to open the billing data storage page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunusercenterhome.png" alt="Alibaba Cloud billing data storage"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;View and record the bucket names for BillingItemDetail and SplitItemDetailDaily. If they are not set, subscribe both billing reports to the same bucket on this page. After configuration, daily incremental billing data is stored on the corresponding OSS. Storing only billing files in that bucket is recommended.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunossbucket1.png" alt="Alibaba Cloud OSS Bucket"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Tags for resources such as Alibaba Cloud OSS do not appear in BillingItemDetail and are only shown in split billing. To analyze costs by tags, configure SplitItemDetailDaily to the bucket.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol start="4"&gt;
&lt;li&gt;
&lt;p&gt;On the Object Storage page in the Alibaba Cloud console, view the overview of the corresponding bucket; the bucket domain name is the bucket URL.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunbucketurl.png" alt="Alibaba Cloud Bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item></channel></rss>