<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloudpods –
Multi-Cloud Management</title><link>/docs/en/tags/multi-cloud-management/</link><description>Recent content in Multi-Cloud Management on Cloudpods</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><atom:link href="/docs/en/tags/multi-cloud-management/index.xml" rel="self" type="application/rss+xml"/><item><title>Docs: Cloud Accounts</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/</guid><description>
&lt;p&gt;The cloud management platform connects to different platforms through cloud accounts and syncs their resources for management. Cloud resources under an account belong to a domain; resources in different domains are isolated. Sharing allows other domains to use cloud account resources. When three-level permissions are not enabled, all cloud resources belong to the default domain.&lt;/p&gt;
&lt;h2 id="select-cloud-platform-type"&gt;Select cloud platform type&lt;/h2&gt;
&lt;p&gt;Choose the cloud platform type you need to connect and configure that platform:&lt;/p&gt;
&lt;h3 id="public-cloud"&gt;Public cloud&lt;/h3&gt;
&lt;p&gt;Supports mainstream public cloud platforms, including Alibaba Cloud, AWS, Azure, Huawei Cloud, and Tencent Cloud.&lt;/p&gt;
&lt;div class="provider-grid"&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/aliyun"&gt;
&lt;div class="provider-logo"&gt;Alibaba Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;Alibaba Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports public cloud and finance cloud&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/aws"&gt;
&lt;div class="provider-logo"&gt;AWS&lt;/div&gt;
&lt;div class="provider-name"&gt;AWS&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports Global and China regions, and Organization accounts&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/azure"&gt;
&lt;div class="provider-logo"&gt;Azure&lt;/div&gt;
&lt;div class="provider-name"&gt;Azure&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports Global and China regions&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/huawei"&gt;
&lt;div class="provider-logo"&gt;Huawei Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;Huawei Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Huawei Cloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/qcloud"&gt;
&lt;div class="provider-logo"&gt;Tencent Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;Tencent Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Tencent Cloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/volcengine"&gt;
&lt;div class="provider-logo"&gt;Volcengine&lt;/div&gt;
&lt;div class="provider-name"&gt;Volcengine&lt;/div&gt;
&lt;div class="provider-desc"&gt;Volcengine account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/ucloud"&gt;
&lt;div class="provider-logo"&gt;UCloud&lt;/div&gt;
&lt;div class="provider-name"&gt;UCloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;UCloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/google"&gt;
&lt;div class="provider-logo"&gt;Google&lt;/div&gt;
&lt;div class="provider-name"&gt;Google&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports BigQuery and Bucket billing data sources&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/ctyun"&gt;
&lt;div class="provider-logo"&gt;China Telecom Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;China Telecom Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;China Telecom Cloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/ecloud"&gt;
&lt;div class="provider-logo"&gt;China Mobile Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;China Mobile Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Resource sync only&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/jdcloud"&gt;
&lt;div class="provider-logo"&gt;JD Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;JD Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Resource sync only&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/baidu"&gt;
&lt;div class="provider-logo"&gt;Baidu Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;Baidu Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Baidu Cloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/cucloud"&gt;
&lt;div class="provider-logo"&gt;China Unicom Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;China Unicom Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;China Unicom Cloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/kscloud"&gt;
&lt;div class="provider-logo"&gt;Kingsoft Cloud&lt;/div&gt;
&lt;div class="provider-name"&gt;Kingsoft Cloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;Kingsoft Cloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/qingcloud"&gt;
&lt;div class="provider-logo"&gt;QingCloud&lt;/div&gt;
&lt;div class="provider-name"&gt;QingCloud&lt;/div&gt;
&lt;div class="provider-desc"&gt;QingCloud account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="public/oracle"&gt;
&lt;div class="provider-logo"&gt;Oracle&lt;/div&gt;
&lt;div class="provider-name"&gt;Oracle&lt;/div&gt;
&lt;div class="provider-desc"&gt;Oracle account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="private-cloud"&gt;Private cloud&lt;/h3&gt;
&lt;p&gt;Supports private cloud platforms such as VMware, OpenStack, and ZStack.&lt;/p&gt;
&lt;div class="provider-grid"&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/vmware"&gt;
&lt;div class="provider-logo"&gt;VMware&lt;/div&gt;
&lt;div class="provider-name"&gt;VMware&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports versions 5.0–7.0&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/openstack"&gt;
&lt;div class="provider-logo"&gt;OpenStack&lt;/div&gt;
&lt;div class="provider-name"&gt;OpenStack&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports Mitaka and later&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/zstack"&gt;
&lt;div class="provider-logo"&gt;ZStack&lt;/div&gt;
&lt;div class="provider-name"&gt;ZStack&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports version 3.5.0 and later&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/zettakit"&gt;
&lt;div class="provider-logo"&gt;ZettaKit&lt;/div&gt;
&lt;div class="provider-name"&gt;ZettaKit&lt;/div&gt;
&lt;div class="provider-desc"&gt;ZettaKit account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/apsara"&gt;
&lt;div class="provider-logo"&gt;Apsara Stack&lt;/div&gt;
&lt;div class="provider-name"&gt;Apsara Stack&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports v3.12.0 and later&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/cloudpods"&gt;
&lt;div class="provider-logo"&gt;Cloudpods&lt;/div&gt;
&lt;div class="provider-name"&gt;Cloudpods&lt;/div&gt;
&lt;div class="provider-desc"&gt;Cloudpods account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/hcso"&gt;
&lt;div class="provider-logo"&gt;HCSO&lt;/div&gt;
&lt;div class="provider-name"&gt;HCSO&lt;/div&gt;
&lt;div class="provider-desc"&gt;HCSO account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/hcs"&gt;
&lt;div class="provider-logo"&gt;HCS&lt;/div&gt;
&lt;div class="provider-name"&gt;HCS&lt;/div&gt;
&lt;div class="provider-desc"&gt;HCS account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/nutanix"&gt;
&lt;div class="provider-logo"&gt;Nutanix&lt;/div&gt;
&lt;div class="provider-name"&gt;Nutanix&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports V2&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/proxmox"&gt;
&lt;div class="provider-logo"&gt;Proxmox&lt;/div&gt;
&lt;div class="provider-name"&gt;Proxmox&lt;/div&gt;
&lt;div class="provider-desc"&gt;Proxmox account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="private/h3c"&gt;
&lt;div class="provider-logo"&gt;H3C&lt;/div&gt;
&lt;div class="provider-name"&gt;H3C&lt;/div&gt;
&lt;div class="provider-desc"&gt;H3C account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3 id="object-storage"&gt;Object storage&lt;/h3&gt;
&lt;p&gt;Supports object storage platforms such as S3 and Ceph.&lt;/p&gt;
&lt;div class="provider-grid"&gt;
&lt;div class="provider-card"&gt;
&lt;a href="storage/s3"&gt;
&lt;div class="provider-logo"&gt;S3&lt;/div&gt;
&lt;div class="provider-name"&gt;S3&lt;/div&gt;
&lt;div class="provider-desc"&gt;Supports MinIO and other S3-compatible storage&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="storage/ceph"&gt;
&lt;div class="provider-logo"&gt;Ceph&lt;/div&gt;
&lt;div class="provider-name"&gt;Ceph&lt;/div&gt;
&lt;div class="provider-desc"&gt;Ceph account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="provider-card"&gt;
&lt;a href="storage/xsky"&gt;
&lt;div class="provider-logo"&gt;XSKY&lt;/div&gt;
&lt;div class="provider-name"&gt;XSKY&lt;/div&gt;
&lt;div class="provider-desc"&gt;XSKY account configuration&lt;/div&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;style&gt;
.provider-grid {
display: grid;
grid-template-columns: repeat(auto-fill, minmax(200px, 1fr));
gap: 16px;
margin: 20px 0;
}
.provider-card {
border: 1px solid #e0e0e0;
border-radius: 8px;
padding: 16px;
transition: all 0.3s ease;
background: #fff;
}
.provider-card:hover {
border-color: #1890ff;
box-shadow: 0 4px 12px rgba(24, 144, 255, 0.15);
transform: translateY(-2px);
}
.provider-card a {
text-decoration: none;
color: inherit;
display: block;
}
.provider-logo {
font-size: 24px;
font-weight: bold;
color: #1890ff;
margin-bottom: 8px;
}
.provider-name {
font-size: 16px;
font-weight: 500;
color: #333;
margin-bottom: 4px;
}
.provider-desc {
font-size: 12px;
color: #666;
line-height: 1.4;
}
&lt;/style&gt;
&lt;h2 id="common-configuration-parameters"&gt;Common configuration parameters&lt;/h2&gt;
&lt;p&gt;All cloud platforms support the following common configuration:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Parameter&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Name&lt;/td&gt;
&lt;td&gt;Cloud account name&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain&lt;/td&gt;
&lt;td&gt;Select the domain the cloud account belongs to. When the cloud account is private, all project users under the domain can use the cloud account to create resources.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource ownership method&lt;/td&gt;
&lt;td&gt;Defaults to specified project; ownership by cloud project is also supported&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource owner project&lt;/td&gt;
&lt;td&gt;When resource ownership method is specified project, you can sync cloud account resources to a local project on the platform&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sync policy&lt;/td&gt;
&lt;td&gt;When enabled, maps tags to projects and assigns resources to specified projects by rule&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exclude synced resources&lt;/td&gt;
&lt;td&gt;When enabled, you can select resource types to exclude from sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Proxy&lt;/td&gt;
&lt;td&gt;Set this when the cloud account requires a proxy for normal access; leave empty for a direct connection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Read-only mode&lt;/td&gt;
&lt;td&gt;When enabled, the cloud account only syncs resources and cannot run other tasks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sharing scope&lt;/td&gt;
&lt;td&gt;Set the sharing scope of the cloud account; defaults to not shared&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="cloud-account-operations"&gt;Cloud account operations&lt;/h2&gt;
&lt;h3 id="sync-cloud-account"&gt;Sync cloud account&lt;/h3&gt;
&lt;p&gt;Sync resource information from the cloud account.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Disabled cloud accounts do not support syncing.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Sync duration&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The time required to sync a cloud account is closely related to the number of resources under the account:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Resource scale&lt;/th&gt;
&lt;th&gt;Estimated sync time&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Few resources (&amp;lt;100)&lt;/td&gt;
&lt;td&gt;1–5 minutes&lt;/td&gt;
&lt;td&gt;Suitable for test environments or small projects&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Medium resources (100–1000)&lt;/td&gt;
&lt;td&gt;5–30 minutes&lt;/td&gt;
&lt;td&gt;Suitable for typical enterprise environments&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Large resources (1000–10000)&lt;/td&gt;
&lt;td&gt;30 minutes–2 hours&lt;/td&gt;
&lt;td&gt;Suitable for large enterprises or multi-cloud environments&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Massive resources (&amp;gt;10000)&lt;/td&gt;
&lt;td&gt;2 hours or more&lt;/td&gt;
&lt;td&gt;Incremental or batched sync is recommended&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Factors that affect sync time&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Resource count: More resources take longer to sync&lt;/li&gt;
&lt;li&gt;Resource type: Sync complexity differs by resource type&lt;/li&gt;
&lt;li&gt;Network latency: Quality of the network connection to the cloud platform&lt;/li&gt;
&lt;li&gt;Cloud platform API limits: Some platforms limit API call frequency&lt;/li&gt;
&lt;li&gt;Sync mode: Full sync takes longer than incremental sync&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Optimization tips&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For cloud accounts with many resources, use incremental sync&lt;/li&gt;
&lt;li&gt;Use “Exclude synced resources” to skip resource types you do not need&lt;/li&gt;
&lt;li&gt;Run large-scale syncs during off-peak hours&lt;/li&gt;
&lt;li&gt;Set automatic sync tasks to avoid waiting on manual sync&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Sync a single cloud account&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Sync cloud account” in the actions column for the cloud account to open the sync dialog.&lt;/li&gt;
&lt;li&gt;Select the sync mode: full sync or incremental sync. Incremental sync only syncs newly added and deleted resources.&lt;/li&gt;
&lt;li&gt;Select the resource types to sync, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Batch sync&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, select one or more cloud accounts, click “Batch operations” above the list, then select “Sync cloud account”.&lt;/li&gt;
&lt;li&gt;Select the sync mode: full sync or incremental sync. Incremental sync only syncs newly added and deleted resources.&lt;/li&gt;
&lt;li&gt;Select the resource types to sync, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="enable"&gt;Enable&lt;/h3&gt;
&lt;p&gt;Enable a cloud account in the “Disabled” state. Resources of a disabled cloud account cannot be used.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Enable one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the cloud account page, click “More” in the row actions for the target cloud account, then choose “Enable”.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Enable in batch&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, select one or more cloud account (Disabled), then click “Enable” above the list.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="disable"&gt;Disable&lt;/h3&gt;
&lt;p&gt;Disable a cloud account in the “Enabled” state. Disable the cloud account before deleting it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disable one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the cloud account page, click “More” in the row actions for the target cloud account, then choose “Disable”.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Disable in batch&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, select one or more cloud account (Enabled), then click “Disable” above the list.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="connection-test"&gt;Connection test&lt;/h3&gt;
&lt;p&gt;Test the account connection status and sync resource information from the cloud account. Disabled cloud accounts do not support this operation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Connection test one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the cloud account page, click “More” in the row actions for the target cloud account, then choose “Connection test”.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Connection test in batch&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, select one or more cloud account, then click “Connection test” above the list.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-automatic-sync"&gt;Set automatic sync&lt;/h3&gt;
&lt;p&gt;Set whether the cloud account enables automatic sync and the automatic sync interval. Automatic sync is an incremental sync of cloud account resources and supports resource sync and billing tasks.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Set automatic resource sync for a cloud account&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Automatic sync” to open the scheduled task dialog.&lt;/li&gt;
&lt;li&gt;Select the Resource sync tab, click “Create”, and open the configure automatic resource sync page.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: Scheduled task name.&lt;/li&gt;
&lt;li&gt;Type: Sync cloud account.&lt;/li&gt;
&lt;li&gt;Trigger frequency: Custom time for once, daily, weekly, or monthly.&lt;/li&gt;
&lt;li&gt;Trigger time: Select the specific trigger time.&lt;/li&gt;
&lt;li&gt;Valid period: Can be empty; leaving it unset means long-term validity.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “OK” to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Set billing tasks for a cloud account&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Automatic sync” to open the scheduled task dialog.&lt;/li&gt;
&lt;li&gt;Select the Billing tasks tab, click “Create”, and open the configure billing task page.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Task type: Supports pull billing, prepaid allocation, default project allocation, secondary pricing, and delete billing.&lt;/li&gt;
&lt;li&gt;Time range: Select the effective time range for the task type.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “OK” to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-sync-policy"&gt;Set sync policy&lt;/h3&gt;
&lt;p&gt;Map tags to projects so that resources under the cloud account are assigned to specified projects by rule.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Set sync policy”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Resource ownership method: Defaults to specified project; ownership by cloud project is also supported.&lt;/li&gt;
&lt;li&gt;Resource owner project: When resource ownership method is specified project, you can sync cloud account resources to a local project on the platform.&lt;/li&gt;
&lt;li&gt;Sync policy: When enabled, maps tags to projects and assigns resources to specified projects by rule.&lt;/li&gt;
&lt;li&gt;Sync policy scope: Shown after the sync policy is turned on; supports resource tags and project tags.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “OK” to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="update-account"&gt;Update account&lt;/h3&gt;
&lt;p&gt;Update the account and password information for the cloud account. Parameters differ by platform.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;VMware cloud accounts do not currently support updating the account.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, click “More” in the actions column for the cloud account, then select “Property settings – Update account”.&lt;/li&gt;
&lt;li&gt;Modify the account and password information for the platform, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="read-only-mode"&gt;Read-only mode&lt;/h3&gt;
&lt;p&gt;Set the cloud account to read-only mode. When enabled, the cloud account only syncs resources and cannot run other tasks.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;VMware, JD Cloud, China Mobile Cloud, S3, Ceph, and XSKY do not support read-only mode.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Read-only mode”.&lt;/li&gt;
&lt;li&gt;Set the read-only mode switch, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="enable-passwordless-login"&gt;Enable passwordless login&lt;/h3&gt;
&lt;p&gt;Enable passwordless login for the cloud account. The system’s SAML information is synced to the cloud account, and the system becomes an identity provider for cloud login.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Public cloud platforms that currently support passwordless login: Alibaba Cloud, Tencent Cloud, Huawei Cloud, AWS, Azure, HCSO, and HCS.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Enable passwordless login”.&lt;/li&gt;
&lt;li&gt;Click “OK” to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-sharing"&gt;Set sharing&lt;/h3&gt;
&lt;p&gt;Set the sharing status of the cloud account.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cloud account sharing scopes&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Not shared (private)&lt;/strong&gt;: Resources on the cloud account are available only to the domain the cloud account belongs to.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Share cloud subscription – partial&lt;/strong&gt;: When sharing cloud subscriptions and specifying some domains, administrators can change the project on the subscription page and can only choose projects under the domains the subscription is shared with.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Share cloud subscription – all&lt;/strong&gt;: When sharing cloud subscriptions to all domains, administrators can change the project on the subscription page and can choose projects under any domain.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Share cloud account – partial&lt;/strong&gt;: The cloud account can be shared to specified domains (one or more); only users in the cloud account’s domain and the shared domains can use the cloud account.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Share cloud account – all&lt;/strong&gt;: The cloud account can be shared to all domains; all users in the system can use the cloud account.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Conditions for setting sharing: all of the following must be met&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The current user is in the admin console.&lt;/li&gt;
&lt;li&gt;Three-level permissions are enabled on the platform.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;The sharing scope of resources synced from a cloud account (except security groups) is affected by the cloud account’s sharing scope.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Set sharing”.&lt;/li&gt;
&lt;li&gt;Configure sharing scope parameters.&lt;/li&gt;
&lt;li&gt;Click “OK” to complete the operation.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-proxy"&gt;Set proxy&lt;/h3&gt;
&lt;p&gt;Bind a proxy to an existing cloud account.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Set proxy”.&lt;/li&gt;
&lt;li&gt;Select a proxy, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="update-billing"&gt;Update billing&lt;/h3&gt;
&lt;p&gt;Update the billing file for the cloud account. Supported only for Alibaba Cloud, Huawei Cloud, AWS, Azure, Google, Tencent Cloud, JD Cloud, Volcengine, and Kingsoft Cloud.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, click “More” in the actions column for the cloud account, then select “Billing settings – Update billing”.&lt;/li&gt;
&lt;li&gt;Modify the billing file parameters for the platform, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="set-discount-rate"&gt;Set discount rate&lt;/h3&gt;
&lt;p&gt;Set a discount rate for a public cloud account. After the discount rate is set, the estimated price shown when users create public cloud resources is the discounted price.&lt;/p&gt;
&lt;blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Setting a discount rate on a public cloud account does not affect the actual billing cost on the public cloud.&lt;/li&gt;
&lt;li&gt;The discounted price is shown only when creating resources within the cloud account’s sharing scope.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Billing settings – Set discount rate”.&lt;/li&gt;
&lt;li&gt;Set the discount rate (discounted price = original price × (1 − discount rate)), then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="clone-account"&gt;Clone account&lt;/h3&gt;
&lt;p&gt;Create a new cloud account based on the configuration of an existing cloud account.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Clone account”.&lt;/li&gt;
&lt;li&gt;Open the create cloud account page; parameters are the same as the original cloud account.&lt;/li&gt;
&lt;li&gt;Modify the necessary parameters, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="change-project"&gt;Change project&lt;/h3&gt;
&lt;p&gt;Change the project the cloud account belongs to.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Changing the project is not allowed when the cloud account is shared.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Change project”.&lt;/li&gt;
&lt;li&gt;Select the domain and project, then click “OK”.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="sync-sku"&gt;Sync SKU&lt;/h3&gt;
&lt;p&gt;Sync SKU (specification) information from the cloud platform. Supported resource types: server SKU, cache SKU, database SKU, NAT SKU, and NAS SKU.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Disabled cloud accounts do not support syncing SKUs.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Property settings – Sync SKU”.&lt;/li&gt;
&lt;li&gt;Select the resource types to sync and region (optional).&lt;/li&gt;
&lt;li&gt;Click “OK” to start the sync.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="rerun-billing"&gt;Rerun billing&lt;/h3&gt;
&lt;p&gt;Re-pull billing data for a specified time range.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Supported only for cloud platforms with billing configuration.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the cloud account, then select “Billing settings – Rerun billing”.&lt;/li&gt;
&lt;li&gt;Select the time range.&lt;/li&gt;
&lt;li&gt;Click “OK” to start re-pulling billing.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="create-subscription"&gt;Create subscription&lt;/h3&gt;
&lt;p&gt;Create an Azure subscription. Supported only for Azure cloud accounts.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;You need to provide the subscription name, enrollment account ID, and offer type.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “More” in the actions column for the Azure cloud account, then select “Property settings – Create subscription”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: Subscription name.&lt;/li&gt;
&lt;li&gt;Enrollment account ID: Azure enrollment account ID.&lt;/li&gt;
&lt;li&gt;Offer type: Subscription offer type.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “OK” to create the subscription.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="delete"&gt;Delete&lt;/h3&gt;
&lt;p&gt;Delete a cloud account. Disable the cloud account before deleting it. Deleting a cloud account on the platform does not affect resources on the cloud account.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;When deleting, you can choose whether to also delete billing data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Delete one&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;On the cloud account page, click “More” in the row actions for the target cloud account, then choose “Delete”.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Delete in batch&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;In the cloud account list, select one or more cloud account (Disabled), then click “Delete” above the list.&lt;/li&gt;
&lt;li&gt;Confirm the action.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="cloud-account-details"&gt;Cloud account details&lt;/h2&gt;
&lt;p&gt;On the Cloud Accounts page, click the cloud account name to open the cloud account details page. The details page includes the following tabs:&lt;/p&gt;
&lt;h3 id="basic-information"&gt;Basic information&lt;/h3&gt;
&lt;p&gt;View basic information about the cloud account:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;User tags and external tags&lt;/li&gt;
&lt;li&gt;Resource owner project (editable; opens the project mapping dialog)&lt;/li&gt;
&lt;li&gt;Excluded resource types&lt;/li&gt;
&lt;li&gt;Sharing scope&lt;/li&gt;
&lt;li&gt;Brand&lt;/li&gt;
&lt;li&gt;Account name and account ID&lt;/li&gt;
&lt;li&gt;Proxy settings (clickable to open proxy details)&lt;/li&gt;
&lt;li&gt;Enabled status&lt;/li&gt;
&lt;li&gt;SAML authentication status&lt;/li&gt;
&lt;li&gt;Read-only status&lt;/li&gt;
&lt;li&gt;Last sync time&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="additional-information"&gt;Additional information&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Access URL&lt;/li&gt;
&lt;li&gt;Health status&lt;/li&gt;
&lt;li&gt;Discount rate (public cloud only)&lt;/li&gt;
&lt;li&gt;Balance&lt;/li&gt;
&lt;li&gt;Virtual machine count&lt;/li&gt;
&lt;li&gt;Host count&lt;/li&gt;
&lt;li&gt;Missing permissions (supports clear and export)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="details-page-tabs"&gt;Details page tabs&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tab&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Details&lt;/td&gt;
&lt;td&gt;Cloud account basic information&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hosts&lt;/td&gt;
&lt;td&gt;Host list (IDC / private cloud only)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Usage&lt;/td&gt;
&lt;td&gt;Resource usage information&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud subscriptions&lt;/td&gt;
&lt;td&gt;Associated cloud subscription list&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;External projects&lt;/td&gt;
&lt;td&gt;External project list&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SAML users&lt;/td&gt;
&lt;td&gt;SAML authentication users (shown conditionally)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud users&lt;/td&gt;
&lt;td&gt;Cloud users (shown conditionally; requires brand support)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud groups&lt;/td&gt;
&lt;td&gt;Cloud groups (shown conditionally; requires brand support)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scheduled tasks&lt;/td&gt;
&lt;td&gt;Scheduled sync task list&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tasks&lt;/td&gt;
&lt;td&gt;Task history&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Events&lt;/td&gt;
&lt;td&gt;Event logs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="cloud-account-list-filters"&gt;Cloud account list filters&lt;/h2&gt;
&lt;p&gt;The cloud account list supports the following filters:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Filter&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;ID&lt;/td&gt;
&lt;td&gt;Cloud account ID&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Name&lt;/td&gt;
&lt;td&gt;Cloud account name&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Description&lt;/td&gt;
&lt;td&gt;Cloud account description&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Enabled status&lt;/td&gt;
&lt;td&gt;Enabled / Disabled&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Status&lt;/td&gt;
&lt;td&gt;Cloud account status&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Health status&lt;/td&gt;
&lt;td&gt;Healthy / Abnormal&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Brand&lt;/td&gt;
&lt;td&gt;Cloud platform brand&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Account&lt;/td&gt;
&lt;td&gt;Account name&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Automatic sync&lt;/td&gt;
&lt;td&gt;Whether automatic sync is enabled&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sharing mode&lt;/td&gt;
&lt;td&gt;Sharing scope&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Project domain&lt;/td&gt;
&lt;td&gt;Domain the account belongs to&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Created at&lt;/td&gt;
&lt;td&gt;Creation time range&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="public-cloud-billing-collection-rules"&gt;Public cloud billing collection rules&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Only Alibaba Cloud, AWS, Azure, Huawei Cloud, Google, Volcengine, and Kingsoft Cloud support collecting billing by configuring billing file access information. Tencent Cloud can collect billing via API.&lt;/li&gt;
&lt;li&gt;When users configure or modify billing file information, the current month’s billing is collected.&lt;/li&gt;
&lt;li&gt;When billing is collected multiple times, the result of the last collection takes effect.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Docs: Create Alibaba Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/aliyun/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/aliyun/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list to open the create cloud account page.&lt;/li&gt;
&lt;li&gt;Select Alibaba Cloud as the cloud platform, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: Alibaba Cloud account name.&lt;/li&gt;
&lt;li&gt;Account type: Currently supports connecting Alibaba Cloud public cloud and finance cloud accounts.&lt;/li&gt;
&lt;li&gt;Key ID / password: Connect to Alibaba Cloud via Access Key authentication. An Access Key consists of a key ID (Access Key ID) and a password (Access Key Secret). See &lt;a href="#how-to-obtain-alibaba-cloud-parameters"&gt;How to obtain Alibaba Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify that the parameters are correct.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” to configure resource sync regions (all regions are synced by default).&lt;/li&gt;
&lt;li&gt;After configuration, click “Next: Billing file access information (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Alibaba Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;To manage a public cloud platform on this platform, the cloud account must at least have management permissions on the resources you operate. Granting the cloud account management permissions for all platform features is recommended.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;The domain of an added cloud account cannot be changed. To sync resources from the cloud account to another domain, delete the cloud account on the platform and add it again to the target domain. Deleting a cloud account on the platform only stops onboarding its resources and does not affect resources on the cloud account.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Alibaba Cloud account you add is new, enable the OSS service on Alibaba Cloud first.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Alibaba Cloud account has Resource Directory enabled and the credentials you enter are an AK/SK under a RAM sub-account (at least AliyunSTSAssumeRole, AccessAliyunOSSReadOnlyAccess, and AliyunResourceDirectoryReadOnlyAccess are required), sub-accounts under the entire Resource Directory are synced by default.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-obtain-alibaba-cloud-parameters"&gt;How to obtain Alibaba Cloud parameters&lt;/h2&gt;
&lt;h3 id="obtain-accesskey-with-the-primary-account"&gt;Obtain AccessKey with the primary account&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Alibaba Cloud console with the primary account, click the profile icon in the upper right, expand the dropdown, and click “accesskeys” to open the security information management page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun-accesskeys.png" alt="Alibaba Cloud AccessKey entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the security information management page, you can view existing AccessKey information or click “Create AccessKey” to create a new user AccessKey. When creating an AccessKey, Alibaba Cloud sends a verification code to the account contact’s phone; the AccessKey can be created only after verification succeeds.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun-get_acceesskey_list.png" alt="Alibaba Cloud AccessKey list"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Access Key Secret is hidden by default. Click “Show”; Alibaba Cloud sends a verification code to the contact phone for the account. The Access Key Secret is displayed only after verification succeeds.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun-get_access_key_secret.png" alt="Alibaba Cloud AccessKey Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="how-a-ram-sub-account-obtains-an-access-key"&gt;How a RAM sub-account obtains an Access Key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Alibaba Cloud console with the sub-account, click the profile icon in the upper right, expand the dropdown, and click “accesskey&amp;hellip;” to open the security information management page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_ram_get_access_key.png" alt="RAM sub-account AccessKey entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the security information management page, click “Create AccessKey” to create an AccessKey.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_get_ram_access_key_create.png" alt="RAM sub-account create AccessKey"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After creation succeeds, the AccessKeySecret is shown only once; save it promptly.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_ram_access_key_get.png" alt="RAM sub-account AccessKey Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;For an AccessKey that has already been created, the AccessKeySecret cannot be viewed again.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;To manage Alibaba Cloud resources through the platform, the cloud account needs sufficient permissions:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission description&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read-write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all Alibaba Cloud resources&lt;/td&gt;
&lt;td&gt;ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AdministratorAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Elastic Compute Service (ECS)&lt;/td&gt;
&lt;td&gt;AliyunECSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunECSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Virtual Private Cloud (VPC)&lt;/td&gt;
&lt;td&gt;AliyunVPCReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunVPCFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Elastic IP Address (EIP)&lt;/td&gt;
&lt;td&gt;AliyunEIPReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunEIPFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ECS elastic network interfaces&lt;/td&gt;
&lt;td&gt;AliyunVPCNetworkIntelligenceReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunECSNetworkInterfaceManagementAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Object Storage Service (OSS)&lt;/td&gt;
&lt;td&gt;AliyunOSSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunOSSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage NAT Gateway&lt;/td&gt;
&lt;td&gt;AliyunNATGatewayReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunNATGatewayFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Application Load Balancer (ALB)&lt;/td&gt;
&lt;td&gt;AliyunALBReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunALBFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Server Load Balancer (SLB)&lt;/td&gt;
&lt;td&gt;AliyunSLBReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunSLBFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ApsaraDB RDS&lt;/td&gt;
&lt;td&gt;AliyunRDSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunRDSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ApsaraDB for Redis&lt;/td&gt;
&lt;td&gt;AliyunKvstoreReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunKvstoreFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ActionTrail&lt;/td&gt;
&lt;td&gt;AliyunActionTrailFullAccess&lt;/td&gt;
&lt;td&gt;AliyunActionTrailFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage File Storage NAS&lt;/td&gt;
&lt;td&gt;AliyunNASReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunNASFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Web Application Firewall (WAF)&lt;/td&gt;
&lt;td&gt;AliyunYundunWAFReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunYundunWAFFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Resource Access Management (RAM)&lt;/td&gt;
&lt;td&gt;AliyunRAMReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunRAMFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Public DNS&lt;/td&gt;
&lt;td&gt;AliyunPubDNSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunPubDNSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Alibaba Cloud DNS&lt;/td&gt;
&lt;td&gt;AliyunDNSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunDNSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage enterprise finance&lt;/td&gt;
&lt;td&gt;AliyunFinanceConsoleReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunFinanceConsoleFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CloudMonitor&lt;/td&gt;
&lt;td&gt;AliyunCloudMonitorReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AliyunCloudMonitorFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="how-to-grant-permissions-to-a-sub-account"&gt;How to grant permissions to a sub-account&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Alibaba Cloud console with the primary account, click the profile icon in the upper right, expand the dropdown, and click “Access control” to open the access control page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_access_control.png" alt="Alibaba Cloud access control entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “User management” in the left menu to open the user management page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_access_control_all.png" alt="Alibaba Cloud user management"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the user management page, click “Authorize” in the actions column for the target user to grant permissions.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyun_ram_user_access_control.png" alt="Alibaba Cloud user authorization"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="cloud-account-type"&gt;Cloud account type&lt;/h3&gt;
&lt;p&gt;Includes primary account and associated account. Before using an associated account, ensure the primary account has been imported to the platform, and select that primary account when using the associated account.&lt;/p&gt;
&lt;h3 id="bucket-url"&gt;Bucket URL&lt;/h3&gt;
&lt;p&gt;URL of the bucket that stores billing files. See &lt;a href="#how-to-obtain-the-billing-bucket-url"&gt;How to obtain the billing bucket URL?&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="file-prefix"&gt;File prefix&lt;/h3&gt;
&lt;p&gt;When the billing bucket also stores files other than billing files, configure a file prefix to obtain only billing files from the bucket. For Alibaba Cloud, the billing file prefix is the account ID, which you can view under Account management – Security settings.&lt;/p&gt;
&lt;h3 id="billing-analysis-scope"&gt;Billing analysis scope&lt;/h3&gt;
&lt;p&gt;Set the scope for the platform to analyze cloud account billing. Currently only accounts onboarded on this platform are supported.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accounts onboarded on this platform&lt;/strong&gt;: Collect billing for the primary account and its associated sub-accounts. If the primary account is used only as a payer for other accounts, billing files for those other accounts are discarded.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="collect-billing-immediately"&gt;Collect billing immediately&lt;/h3&gt;
&lt;p&gt;By default, the platform automatically collects billing at 04:00 every day. When this option is enabled, billing is collected immediately after billing file access information is configured.&lt;/p&gt;
&lt;h3 id="time-range"&gt;Time range&lt;/h3&gt;
&lt;p&gt;When “Collect billing immediately” is enabled, you can set a time range and collect billing for that range immediately. Collecting 1–6 months of billing is recommended; otherwise the large data volume may put pressure on the system and affect daily billing collection tasks.&lt;/p&gt;
&lt;h3 id="how-to-obtain-the-billing-bucket-url"&gt;How to obtain the billing bucket URL?&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Alibaba Cloud international accounts do not have billing bucket configuration; contact Alibaba Cloud support to assist with pushing billing data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Using an Alibaba Cloud primary account as an example, sign in to the Alibaba Cloud console with the primary account, click “Expenses” at the top, then “User Center” in the dropdown, and open the expenses user center page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunusercenter.png" alt="Alibaba Cloud user center"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Set billing data storage” to open the billing data storage page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunusercenterhome.png" alt="Alibaba Cloud billing data storage"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;View and record the bucket names for BillingItemDetail and SplitItemDetailDaily. If they are not set, subscribe both billing reports to the same bucket on this page. After configuration, daily incremental billing data is stored on the corresponding OSS. Storing only billing files in that bucket is recommended.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunossbucket1.png" alt="Alibaba Cloud OSS Bucket"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Tags for resources such as Alibaba Cloud OSS do not appear in BillingItemDetail and are only shown in split billing. To analyze costs by tags, configure SplitItemDetailDaily to the bucket.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol start="4"&gt;
&lt;li&gt;
&lt;p&gt;On the Object Storage page in the Alibaba Cloud console, view the overview of the corresponding bucket; the bucket domain name is the bucket URL.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/aliyunbucketurl.png" alt="Alibaba Cloud Bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create AWS Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/aws/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/aws/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list to open the create cloud account page.&lt;/li&gt;
&lt;li&gt;Select AWS as the cloud platform, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: AWS account name.&lt;/li&gt;
&lt;li&gt;Account type: Currently supports connecting AWS Global and China region accounts.&lt;/li&gt;
&lt;li&gt;Key ID / password: Key ID and password for connecting to AWS. See &lt;a href="#how-to-obtain-aws-parameters"&gt;How to obtain AWS parameters&lt;/a&gt;. To onboard AWS Organization accounts, see &lt;a href="#how-to-onboard-aws-organizations-accounts"&gt;How to onboard AWS Organizations accounts&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify that the parameters are correct.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” to configure resource sync regions (all regions are synced by default).&lt;/li&gt;
&lt;li&gt;After configuration, click “Next: Billing file access information (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the AWS account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-obtain-aws-parameters"&gt;How to obtain AWS parameters&lt;/h2&gt;
&lt;h3 id="obtain-aws-access-keys"&gt;Obtain AWS access keys&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the AWS Management Console with the AWS primary account (or a sub-account with Administrator Access), click “IAM”, and open the IAM dashboard.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_aws_1.png" alt="AWS IAM entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Users” in the left menu to open the user list, then click a user name to open the user details page. Choose a user with sufficient management permissions.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_aws_2.png" alt="AWS user list"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click the “Security credentials” tab.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_aws_3.png" alt="AWS security credentials"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Create access key”. In the create access key dialog, you can see the key information: key ID (Access Key ID) and password (Access Key Secret).&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_aws_4.png" alt="AWS create access key"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Private access keys are visible only at creation time. Copy and save them. If lost, create a new key.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;To manage AWS resources through the platform, the cloud account needs the following permissions:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission description&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read-write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all AWS resources&lt;/td&gt;
&lt;td&gt;ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AdministratorAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon EC2&lt;/td&gt;
&lt;td&gt;AmazonEC2ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonEC2FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon VPC&lt;/td&gt;
&lt;td&gt;AmazonVPCReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonVPCFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon S3&lt;/td&gt;
&lt;td&gt;AmazonS3ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonS3FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Elastic Load Balancing (ELB)&lt;/td&gt;
&lt;td&gt;ElasticLoadBalancingReadOnly&lt;/td&gt;
&lt;td&gt;ElasticLoadBalancingFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon RDS&lt;/td&gt;
&lt;td&gt;AmazonRDSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonRDSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon ElastiCache&lt;/td&gt;
&lt;td&gt;AmazonElastiCacheReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonElastiCacheFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage AWS CloudTrail&lt;/td&gt;
&lt;td&gt;AWSCloudTrailReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AWSCloudTrail_FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon EFS&lt;/td&gt;
&lt;td&gt;AmazonElasticFileSystemReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonElasticFileSystemFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage WAF&lt;/td&gt;
&lt;td&gt;AWSWAFReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AWSWAFFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage IAM&lt;/td&gt;
&lt;td&gt;IAMReadOnlyAccess&lt;/td&gt;
&lt;td&gt;IAMFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon Route 53&lt;/td&gt;
&lt;td&gt;AmazonRoute53ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AmazonRoute53FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage billing and cost&lt;/td&gt;
&lt;td&gt;AWSBillingReadOnlyAccess&lt;/td&gt;
&lt;td&gt;Billing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Amazon CloudWatch&lt;/td&gt;
&lt;td&gt;CloudWatchReadOnlyAccess&lt;/td&gt;
&lt;td&gt;CloudWatchFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="cloud-account-type"&gt;Cloud account type&lt;/h3&gt;
&lt;p&gt;Includes primary account and associated account. Before using an associated account, ensure the primary account has been imported to the platform, and select that primary account when using the associated account.&lt;/p&gt;
&lt;h3 id="billing-analysis-scope"&gt;Billing analysis scope&lt;/h3&gt;
&lt;p&gt;Set the scope for the platform to analyze cloud account billing. Includes accounts onboarded on this platform and all accounts.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accounts onboarded on this platform&lt;/strong&gt;: Collect billing for the primary account and its associated organization accounts. If the AWS account is used only as a payer for other AWS accounts, billing files for those other AWS accounts are discarded.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;All billing&lt;/strong&gt;: Collect all billing for the primary account. For billing entries whose corresponding cloud account cannot be found on the platform, the cloud subscription is shown as “this cloud account name – numeric ID of the cloud account associated with the billing entry”.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="how-to-obtain-the-bucket-url"&gt;How to obtain the bucket URL?&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New version (required for AWS accounts created after 2019/08/07)&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the AWS Management Console with the AWS primary account, click the username in the upper right, then “My Billing Dashboard”, and open the Billing and Cost Management dashboard.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsbilling.png" alt="AWS Billing Dashboard"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Cost &amp;amp; Usage Reports” in the left menu. On the AWS Cost and Usage Reports page, click “Create report” to open the create report page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscostreport.png" alt="AWS cost report"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Configure the report name, select “Include resource IDs”, then click “Next” to open the delivery options page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscreatecostreport.png" alt="AWS create cost report"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Configure the S3 bucket. You can select an existing bucket or create a new one.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscosts3.png" alt="AWS S3 bucket"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Configure the report path prefix, set time granularity to “Hourly”, report version to “Create new report version”, and compression type to “ZIP”, then click “Next” to open the review page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscostreportconfig.png" alt="AWS cost report configuration"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After confirming the configuration, record the S3 bucket and report path prefix shown in the red boxes, then click “Review and Complete” to finish configuration and create the report.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscostreportfinish.png" alt="AWS cost report complete"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the S3 storage management page in the AWS console, view the overview of any billing file in the corresponding bucket and record the object URL. The bucket URL is that URL with the file name removed.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscosts3bucketurl.png" alt="AWS S3 Bucket URL"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The file prefix is the report path prefix from step 6.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Legacy version&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the AWS Management Console with the AWS primary account, click the username in the upper right, then “My Billing Dashboard”, and open the Billing and Cost Management dashboard.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Billing preferences” in the left menu. On the preferences page, under “Cost management preferences”, view and record the S3 bucket for “Receive Billing Reports”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsbillingbucket.png" alt="AWS billing preferences"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the S3 storage management page in the AWS console, view the overview of any billing file in the corresponding bucket and record the object URL. The bucket URL is that URL with the file name removed.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsbillingbucketurl.png" alt="AWS billing Bucket URL"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For AWS, the file prefix is the AWS account ID.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-onboard-aws-organizations-accounts"&gt;How to onboard AWS Organizations accounts?&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Configure AWS Organizations: Use an AWS organization account to associate AWS accounts. You can create new AWS accounts or invite existing AWS accounts. Invited AWS accounts must have the “OrganizationAccountAccessRole” role.&lt;/li&gt;
&lt;li&gt;Obtain access keys: Create access keys for an IAM user on the management account of the AWS organization account. Using a user with AdministratorAccess is recommended.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="configure-aws-organizations"&gt;Configure AWS Organizations&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the AWS Management Console with the AWS primary account, click the username in the upper right, then “My Billing Dashboard”, and open the Billing and Cost Management dashboard.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Consolidated Billing” on the right to open the AWS Organizations page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsorgmenu.png" alt="AWS Organizations entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the AWS Organizations – AWS accounts page, add AWS accounts. Two ways to add an AWS account to an Organization are supported:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Create AWS account&lt;/strong&gt;: Set the AWS account name, the account owner’s email address, and the IAM role name (OrganizationAccountAccessRole), then click “Create AWS account”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscreateorgaccount.png" alt="AWS create organization account"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Invite existing AWS account&lt;/strong&gt;: Set the email address or account ID of the AWS account to invite, then click “Send invitation”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsorginviteaccount.png" alt="AWS invite account"&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="how-to-add-the-organizationaccountaccessrole-role-to-an-aws-account"&gt;How to add the OrganizationAccountAccessRole role to an AWS account?&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the AWS Management Console with the AWS primary account, click “IAM”, and open the IAM dashboard.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Roles” on the right. On the roles page, click “Create role”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awscreaterole.png" alt="AWS create role"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Select “Another AWS account” as the trusted entity type, enter the account ID that manages the AWS Organization, then click “Next: Permissions”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsroleconfig.png" alt="AWS role configuration"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Attach the “AdministratorAccess” permission policy, then click “Next: Tags”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsroleconfigpolicy.png" alt="AWS role permission configuration"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Configure tags as needed. After configuration, click “Next: Review”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Set the role name to “OrganizationAccountAccessRole”, then click “Create role”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/awsroleconfigconfirm.png" alt="AWS role confirmation"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Azure Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/azure/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/azure/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list to open the create cloud account page.&lt;/li&gt;
&lt;li&gt;Select Azure as the cloud platform, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: Azure account name.&lt;/li&gt;
&lt;li&gt;Account type: Currently supports connecting Azure Global, China, US Government, and Germany region accounts.&lt;/li&gt;
&lt;li&gt;Tenant ID / Client ID / Client secret: see &lt;a href="#how-to-obtain-azure-parameters"&gt;How to obtain Azure parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify that the parameters are correct.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” to configure resource sync regions (all regions are synced by default).&lt;/li&gt;
&lt;li&gt;After configuration, click “Next: Billing file access information (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Azure account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Enable passwordless login: When enabled, the system becomes an identity provider for cloud login, enabling single sign-on from this system to the public cloud platform. Passwordless login is currently supported only for Azure Global; this option is shown only when the account type is Global.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-obtain-azure-parameters"&gt;How to obtain Azure parameters&lt;/h2&gt;
&lt;h3 id="obtain-azure-tenant-id-and-client-information"&gt;Obtain Azure Tenant ID and Client information&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Sign in to the Azure portal, search for and open “Microsoft Entra ID” (formerly Azure Active Directory), click “App registrations” in the left navigation, and open the app registrations page. Creating a dedicated application for the cloud management platform to call Azure APIs is recommended.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azureregisterapp.png" alt="Azure app registration" style="max-width: 800px;"&gt;&lt;ol start="2"&gt;
&lt;li&gt;Click “New registration”. On the register an application page, set any name, set supported account types to “Accounts in this organizational directory only – Default Directory”, then click “Register”.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azureregisteredapp.png" alt="Azure register application" style="max-width: 700px;"&gt;&lt;ol start="3"&gt;
&lt;li&gt;After creation succeeds, the system automatically opens the application details page. The Application (client) ID on this page is the required Client ID, and the Directory (tenant) ID is the required Tenant ID.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azureclientid.png" alt="Azure Client ID" style="max-width: 1000px;"&gt;&lt;ol start="4"&gt;
&lt;li&gt;On the application details page, click “Certificates &amp;amp; secrets” to open the certificates and secrets page. Click “New client secret”.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azureclientsecretlist.png" alt="Azure certificates and secrets" style="max-width: 900px;"&gt;&lt;ol start="5"&gt;
&lt;li&gt;In the add a client secret dialog, enter a description, select an expiration (up to 24 months), then click “Add” to create the client secret.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azurecreatesecret.png" alt="Azure create secret" style="max-width: 900px;"&gt;&lt;ol start="6"&gt;
&lt;li&gt;
&lt;p&gt;After saving succeeds, immediately copy the secret value shown on the page; this value is the required client secret.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The client secret value is shown only once after creation and cannot be viewed again after you leave the page. Copy and store it securely immediately. After the secret expires, create a new one and update the Azure account configuration on the cloud management platform.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azureclientsecret.png" alt="Azure client secret" style="max-width: 900px;"&gt;&lt;h3 id="how-to-grant-subscription-permissions-to-the-application"&gt;How to grant subscription permissions to the application&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Sign in to the Azure portal, click “All services” in the left navigation, then select and click “Subscriptions” to open the subscriptions list.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azuresub.png" alt="Azure subscriptions" style="max-width: 900px;"&gt;&lt;ol start="2"&gt;
&lt;li&gt;Click the subscription to authorize to open the subscription details page.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azuresublist.png" alt="Azure subscription list" style="max-width: 900px;"&gt;&lt;ol start="3"&gt;
&lt;li&gt;Click “Access control (IAM)”. On the access control page, click “Add role assignment”.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azuresubrole.png" alt="Azure access control" style="max-width: 900px;"&gt;&lt;ol start="4"&gt;
&lt;li&gt;On the “Role” tab, select “Owner”, then click “Next”. On the “Members” tab, assign access to “User, group, or service principal”, click “Select members”, search for the application name created in the previous step, select the application, click “Next”, then click “Review + assign”.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure1.png" alt="Azure role assignment" style="max-width: 900px;"&gt;&lt;img src="/docs/zh/docs/faq/image/azure-add-app.png" alt="Azure role assignment" style="max-width: 900px;"&gt;&lt;ol start="5"&gt;
&lt;li&gt;On the role assignments page, verify that subscription permissions have been granted to the application.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure5.png" alt="Azure role assignment complete" style="max-width: 900px;"&gt;&lt;h3 id="application-api-permission-settings"&gt;Application API permission settings&lt;/h3&gt;
&lt;p&gt;If you do not need to manage Azure users and groups, you can skip the following permissions.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The Azure AD Graph API (&lt;code&gt;graph.windows.net&lt;/code&gt;) is deprecated; use the Microsoft Graph API instead. On the application’s “API permissions” page, add Microsoft Graph application permissions.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Region&lt;/th&gt;
&lt;th&gt;API permissions&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Azure China&lt;/td&gt;
&lt;td&gt;Directory.Read.All, Directory.ReadWrite.All, Domain.Read.All&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Azure Global&lt;/td&gt;
&lt;td&gt;Directory.Read.All, Directory.ReadWrite.All, Domain.Read.All, Domain.ReadWrite.All, Member.Read.Hidden, Policy.Read.All&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;To manage Azure cloud resources, the cloud account needs the following permissions:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission description&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read-write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all resources&lt;/td&gt;
&lt;td&gt;Reader&lt;/td&gt;
&lt;td&gt;Owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage virtual machine resources&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;Virtual Machine Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage network resources&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;Network Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage object storage&lt;/td&gt;
&lt;td&gt;Storage Blob Data Reader&lt;/td&gt;
&lt;td&gt;Storage Blob Data Owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage cloud databases&lt;/td&gt;
&lt;td&gt;Cloud SQL Viewer&lt;/td&gt;
&lt;td&gt;Cloud SQL Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Redis&lt;/td&gt;
&lt;td&gt;Redis Enterprise Cloud Viewer&lt;/td&gt;
&lt;td&gt;Redis Enterprise Cloud Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage file storage&lt;/td&gt;
&lt;td&gt;Storage File Data SMB Share Reader&lt;/td&gt;
&lt;td&gt;Storage File Data SMB Share Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage resource policies and roles&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;Graph Owner, Resource Policy Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage DNS&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;DNS Zone Contributor, Private DNS Zone Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage billing and costs&lt;/td&gt;
&lt;td&gt;Billing Reader, Cost Management Reader&lt;/td&gt;
&lt;td&gt;Cost Management Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage monitoring&lt;/td&gt;
&lt;td&gt;Monitoring Reader&lt;/td&gt;
&lt;td&gt;Monitoring Contributor&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The Azure EA (Enterprise Agreement) reporting API has been fully retired. Configure a billing bucket (Cost Management export) or API billing sync instead. The EA account configuration below applies only where that method is still supported; prefer billing bucket configuration.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="billing-bucket-configuration"&gt;Billing bucket configuration&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Cloud account type: Includes primary account and associated account&lt;/li&gt;
&lt;li&gt;Bucket URL: URL of the bucket that stores billing files&lt;/li&gt;
&lt;li&gt;File prefix: For Azure, the file prefix is the account ID&lt;/li&gt;
&lt;li&gt;Billing analysis scope: Includes accounts onboarded on this platform and all accounts&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="api-billing-configuration"&gt;API billing configuration&lt;/h3&gt;
&lt;p&gt;This method obtains billing data by calling the Azure Cost Management &lt;code&gt;Generate Cost Details Report&lt;/code&gt; REST API. The application (service principal) must have &lt;strong&gt;Cost Management Reader&lt;/strong&gt; or higher at the &lt;strong&gt;billing account&lt;/strong&gt; level.&lt;/p&gt;
&lt;h4 id="configure-billing-api-permissions"&gt;Configure billing API permissions&lt;/h4&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Azure portal, search for and open &lt;strong&gt;“Cost Management”&lt;/strong&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the Cost Management overview page, find and click your &lt;strong&gt;billing account&lt;/strong&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the billing account details page, click &lt;strong&gt;“Access control (IAM)”&lt;/strong&gt; in the left menu to open the billing account access control page.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;“Add”&lt;/strong&gt; and select the “Billing account owner” role.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: You can also select &lt;strong&gt;“Billing account reader”&lt;/strong&gt; (Cost Management Reader) or &lt;strong&gt;“Billing account contributor”&lt;/strong&gt; (Cost Management Contributor). Following least privilege and using Cost Management Reader is recommended.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;!-- Screenshot: billing account access control page, showing add role assignment button --&gt;
&lt;img src="/docs/zh/docs/faq/image/azure-billing-iam.png" alt="Billing account access control" style="max-width: 900px;"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Wait a few minutes for permissions to take effect, then sync billing via the API.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="ea-account-configuration-deprecated"&gt;EA account configuration (deprecated)&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The Azure EA reporting API has been fully retired. This method is for historical reference only. Use &lt;a href="#billing-bucket-configuration"&gt;Billing bucket configuration&lt;/a&gt; to sync billing.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;EA (Enterprise Agreement) account spending obtains billing information via enrollment number and key:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enrollment number: Unique identifier associated with the online enterprise agreement, a number starting with V570&lt;/li&gt;
&lt;li&gt;Key: API access key&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="how-to-obtain-the-azure-billing-bucket"&gt;How to obtain the Azure billing bucket&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Sign in to the Azure portal, search for “Cost Management”, and open it.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-1.png" alt="Azure Cost Management" style="max-width: 900px;"&gt;&lt;ol start="2"&gt;
&lt;li&gt;Click “Exports”, select a scope. Choose a group (root directory requires admin permissions) so that billing for all subscriptions in the group is merged into one file.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-2.png" alt="Azure export scope" style="max-width: 900px;"&gt;&lt;ol start="3"&gt;
&lt;li&gt;After selecting the group as scope, click “Create”, set export type to “Daily export of month-to-date costs”, and fill in other information as prompted.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-3.png" alt="Azure export configuration" style="max-width: 900px;"&gt;&lt;ol start="4"&gt;
&lt;li&gt;After creation succeeds, you can manually trigger a billing job to ensure billing files exist in the billing bucket.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-4.png" alt="Azure trigger billing" style="max-width: 900px;"&gt;&lt;ol start="5"&gt;
&lt;li&gt;Find the storage account configured in the previous step and locate the corresponding billing bucket URL.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-5.png" alt="Azure storage billing" style="max-width: 900px;"&gt;&lt;ol start="6"&gt;
&lt;li&gt;Click Containers, select the container specified in the billing job, then click the name to open details.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-6.png" alt="Azure container details" style="max-width: 900px;"&gt;&lt;ol start="7"&gt;
&lt;li&gt;Click Properties to view the URL information.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_bucket-7.png" alt="Azure URL information" style="max-width: 900px;"&gt;&lt;h3 id="how-to-obtain-the-azure-enrollment-number-and-key-deprecated"&gt;How to obtain the Azure enrollment number and key (deprecated)&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The Azure EA reporting API has been fully retired. The following content is for historical reference only.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;Sign in to the Azure China EA Portal or Azure EA Portal. After signing in, the number in the upper left is the enrollment number.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_number.png" alt="Azure enrollment number" style="max-width: 900px;"&gt;&lt;ol start="2"&gt;
&lt;li&gt;Click “Reports” in the left navigation, select the “Download usage &amp;gt; API Access Key” tab. The primary key on this page is the key.&lt;/li&gt;
&lt;/ol&gt;
&lt;img src="/docs/zh/docs/faq/image/azure_apikey.png" alt="Azure API key" style="max-width: 900px;"&gt;</description></item><item><title>Docs: Create Huawei Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/huawei/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/huawei/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Huawei Cloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Huawei Cloud account name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: credentials for Huawei Cloud. See &lt;a href="#how-to-get-huawei-cloud-parameters"&gt;How to get Huawei Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Huawei Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-huawei-cloud-parameters"&gt;How to get Huawei Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-huawei-cloud-api-key"&gt;How to get a Huawei Cloud API key&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New console&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Huawei Cloud console, hover over the username in the upper right, and choose “My Credentials”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/huaweinewaccount.png" alt="Huawei Cloud credentials entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Access Keys” on the left, then “Create Access Key”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/huaweinewak.png" alt="Huawei Cloud create key"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After verification, an Excel file named credentials is downloaded. Open it to get Access Key ID and Secret Access Key.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_huawei_3.png" alt="Huawei Cloud key info"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Legacy console&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Huawei Cloud console, hover over the username in the upper right, and choose “My Credentials”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Open the “Manage Access Key” tab and click “Create Access Key”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After verification, download the credentials Excel file and obtain Access Key ID and Secret Access Key.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;Permissions required to manage Huawei Cloud resources:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission note&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read/write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all Huawei Cloud resources (except IAM)&lt;/td&gt;
&lt;td&gt;Tenant Guest&lt;/td&gt;
&lt;td&gt;Tenant Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ECS&lt;/td&gt;
&lt;td&gt;ECS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;ECS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage EVS&lt;/td&gt;
&lt;td&gt;EVS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;EVS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage EPS&lt;/td&gt;
&lt;td&gt;EPS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;EPS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage IMS&lt;/td&gt;
&lt;td&gt;IMS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;IMS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage VPC&lt;/td&gt;
&lt;td&gt;VPC ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;VPC FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage NAT Gateway&lt;/td&gt;
&lt;td&gt;NAT ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;NAT FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage OBS&lt;/td&gt;
&lt;td&gt;OBS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;OBS Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage ELB&lt;/td&gt;
&lt;td&gt;ELB ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;ELB FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage RDS&lt;/td&gt;
&lt;td&gt;RDS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;RDS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage DCS&lt;/td&gt;
&lt;td&gt;DCS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;DCS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CTS&lt;/td&gt;
&lt;td&gt;CTS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;CTS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage SFS&lt;/td&gt;
&lt;td&gt;SFS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;SFS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage WAF&lt;/td&gt;
&lt;td&gt;WAF ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;WAF FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage IAM&lt;/td&gt;
&lt;td&gt;IAM ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;Security Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage DNS&lt;/td&gt;
&lt;td&gt;DNS ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;DNS FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Billing Center (BSS)&lt;/td&gt;
&lt;td&gt;BSS Operator&lt;/td&gt;
&lt;td&gt;BSS Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CES&lt;/td&gt;
&lt;td&gt;CES ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;CES FullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="how-to-get-the-bill-bucket-url"&gt;How to get the bill bucket URL?&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New console&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;On Huawei Cloud, open “Billing Center → Bills”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/huaweinewconsum.png" alt="Huawei Cloud Billing Center"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Overview” on the left. Under “Bill data storage” on the right, note the object storage name. If unset, enable bill data storage, configure an OBS bucket, and complete authorization.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/huaweinewbillingbucket.png" alt="Huawei Cloud bill storage"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In OBS, open the bucket overview; the access domain is the bucket URL.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/huaweibillingbucketurl.png" alt="Huawei Cloud Bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Legacy console&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;On Huawei Cloud, open “More → Billing → Consumption overview”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Consumption data storage” on the left and note the bucket name. If unset, configure a bucket and complete authorization.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In OBS, open the bucket overview; the access domain is the bucket URL.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Tencent Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/qcloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/qcloud/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Tencent Cloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Tencent Cloud platform name.&lt;/li&gt;
&lt;li&gt;APP ID / Key ID / Password: APP ID uniquely maps to the account ID. See &lt;a href="#how-to-get-tencent-cloud-parameters"&gt;How to get Tencent Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Tencent Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Tencent Cloud account is new, enable COS on Tencent Cloud first.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-get-tencent-cloud-parameters"&gt;How to get Tencent Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-tencent-cloud-api-key"&gt;How to get a Tencent Cloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Tencent Cloud console, click “Cloud products” in the upper right, search for “Cloud API keys”, and open API key management.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_qcloud_1.png" alt="Tencent Cloud API key entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On API key management, get APP ID, SecretId (key ID), and SecretKey (password).&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/faq_account_qcloud_2.png" alt="Tencent Cloud API key"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;Permissions required to manage Tencent Cloud resources:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission note&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read/write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all Tencent Cloud resources&lt;/td&gt;
&lt;td&gt;ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AdministratorAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CVM&lt;/td&gt;
&lt;td&gt;QcloudCVMReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudCVMFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage VPC&lt;/td&gt;
&lt;td&gt;QcloudVPCReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudVPCFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage EIP&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;QcloudEIPFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage COS&lt;/td&gt;
&lt;td&gt;QcloudCOSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudCOSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CLB&lt;/td&gt;
&lt;td&gt;QcloudCLBReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudCLBFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage cloud databases&lt;/td&gt;
&lt;td&gt;QcloudMariaDBReadOnlyAccess, etc.&lt;/td&gt;
&lt;td&gt;QcloudMariaDBFullAccess, etc.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Redis&lt;/td&gt;
&lt;td&gt;QcloudRedisReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudRedisFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CloudAudit&lt;/td&gt;
&lt;td&gt;QcloudAuditReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudAuditFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CFS&lt;/td&gt;
&lt;td&gt;QcloudCFSReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudCFSFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage WAF&lt;/td&gt;
&lt;td&gt;QcloudWAFReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudWAFFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage CAM&lt;/td&gt;
&lt;td&gt;QcloudCamReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudCamFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage private DNS&lt;/td&gt;
&lt;td&gt;QcloudDNSPodReadOnlyAccess, etc.&lt;/td&gt;
&lt;td&gt;QcloudPrivateDNSFullAccess, etc.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage finance-related content&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;QCloudFinanceFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Monitor&lt;/td&gt;
&lt;td&gt;QcloudMonitorReadOnlyAccess&lt;/td&gt;
&lt;td&gt;QcloudMonitorFullAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="how-to-get-the-bill-bucket-url"&gt;How to get the bill bucket URL&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Tencent Cloud console, open “Billing” → “Bills”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/qcloudeusercenter.png" alt="Tencent Cloud user center"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Bill storage”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/qcloudusercenterhome.png" alt="Tencent Cloud bill storage"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Note the bill storage bucket name. If unset, subscribe to a bucket on this page; daily incremental bill data syncs to COS. Prefer a bucket used only for bill files.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/qcloudossbucket1.png" alt="Tencent Cloud OSS Bucket"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In Object Storage, open the bucket overview; the bucket domain is the bucket URL.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/qcloudbucketurl.png" alt="Tencent Cloud Bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Volcano Engine Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/volcengine/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/volcengine/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Volcano Engine, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Volcano Engine account name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with Access Key (Access Key ID and Access Key Secret). See &lt;a href="#how-to-get-volcano-engine-parameters"&gt;How to get Volcano Engine parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Volcano Engine account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Volcano Engine account is new, enable TOS on Volcano Engine first.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-get-volcano-engine-parameters"&gt;How to get Volcano Engine parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-volcano-engine-api-key"&gt;How to get a Volcano Engine API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Volcano Engine console, open personal info in the upper right, then click “API access keys”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngine-accesskeys.png" alt="Volcano Engine AccessKey entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the key list page, view existing AccessKeys or click “Create key”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngine-get_acceesskey_list.png" alt="Volcano Engine key list"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Access Key Secret is hidden by default. Click “Show”; Volcano Engine sends a verification code to the account contact. After verification, the Secret is shown.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngine-get_access_key_secret.png" alt="Volcano Engine AccessKey Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;Permissions required to manage Volcano Engine resources:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission note&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read/write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all Volcano Engine resources&lt;/td&gt;
&lt;td&gt;ReadOnlyAccess&lt;/td&gt;
&lt;td&gt;AdministratorAccess&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="how-to-authorize-a-sub-account"&gt;How to authorize a sub-account&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in with the primary account, open personal info in the upper right, then click “Access control”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngine_access_control.png" alt="Volcano Engine access control entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Users” on the left.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngine_access_control_all.png" alt="Volcano Engine user management"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Manage” for the user and grant permissions.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngine_ram_user_access_control.png" alt="Volcano Engine user authorization"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="how-to-get-the-bill-bucket-url"&gt;How to get the bill bucket URL&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Volcano Engine console, open “Billing” → “Account overview”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngineusercenter.png" alt="Volcano Engine user center"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Set automatic storage”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngineusercenterhome.png" alt="Volcano Engine bill storage"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Note the ChargeItemDetail bill bucket name. If unset, subscribe to a bucket on this page; daily incremental bill data syncs to TOS. Prefer a bucket used only for bill files.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEngineossbucket1.png" alt="Volcano Engine OSS Bucket"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In Object Storage, open the bucket overview; the bucket domain is the bucket URL.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/VolcEnginebucketurl.png" alt="Volcano Engine Bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create UCloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/ucloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/ucloud/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select UCloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: UCloud platform name.&lt;/li&gt;
&lt;li&gt;Public key / Private key: see &lt;a href="#how-to-get-ucloud-parameters"&gt;How to get UCloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;project_id: required for UCloud sub-accounts; not needed for the primary account.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the UCloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-ucloud-parameters"&gt;How to get UCloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-ucloud-api-key"&gt;How to get a UCloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the UCloud console, click “All products” at the top, search for or select “Open API UAPI”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ucloudapi.png" alt="UCloud API entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Open the “API keys” tab. Click “Show” and complete SMS verification.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ucloudapikeyshow.png" alt="UCloud API keys"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After phone verification, obtain the public and private key values.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ucloudapikeypair.png" alt="UCloud key pair"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For a sub-account, also get project_id from “Access control → User management → Sub-account details” (project ID under personal permissions / application projects).&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ucloudprojectid.png" alt="UCloud Project ID"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;Permissions required to manage UCloud resources:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission policy&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;AdministratorAccess&lt;/td&gt;
&lt;td&gt;Super administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description></item><item><title>Docs: Create Google Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/google/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/google/</guid><description>
&lt;h2 id="prerequisites"&gt;Prerequisites&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ensure network connectivity between the platform and Google Cloud.&lt;/li&gt;
&lt;li&gt;If the platform cannot reach Google Cloud directly, configure a proxy to access Google Cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list to open the create cloud account page.&lt;/li&gt;
&lt;li&gt;Select “Google” as the cloud platform, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure the following parameters:
&lt;ul&gt;
&lt;li&gt;Name: Google Cloud account name.&lt;/li&gt;
&lt;li&gt;project_id, private_key_id, private_key, client_email, and related parameters: see &lt;a href="#how-to-obtain-google-parameters"&gt;How to obtain Google parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify that the parameters are correct.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” to configure resource sync regions (all regions are synced by default).&lt;/li&gt;
&lt;li&gt;After configuration, click “Next: Billing file access information (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Google Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-obtain-google-parameters"&gt;How to obtain Google parameters&lt;/h2&gt;
&lt;h3 id="how-to-obtain-google-cloud-service-account-key-information"&gt;How to obtain Google Cloud service account key information?&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Onboard a specific project&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Open the “IAM &amp;amp; Admin – IAM” page in the GCP Console and sign in.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_iam.png" alt="Google IAM"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Select a project” at the top and choose the project to authorize.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_project.png" alt="Google select project"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In the left navigation pane, go to “IAM &amp;amp; Admin”, click “Service Accounts”, and open the service accounts page.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Create service account” to open the create service account page.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Configure the service account name, service account ID, and description, then click “Create and continue”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_createserviceaccount.png" alt="Google create service account"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Select the Project – Owner or Project – Viewer role. Owner grants management permissions on the project; Viewer grants read-only permissions. Click “Continue”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_serviceaccountpolicy.png" alt="Google service account permissions"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Granting users access to this service account does not affect the cloud management platform; configure as needed. After configuration, click “Continue”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the service accounts page, click the actions button on the right of the newly created service account, then click “Manage keys”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_serviceaccount.png" alt="Google service account keys"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the keys page, click “Add key”, then in the dialog click “Create new key”, select key type “JSON”, and click “Create” to download the JSON key file.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_create1.png" alt="Google create key"&gt;&lt;img src="/docs/zh/docs/faq/image/google_create.png" alt="Google key file"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Onboard multiple projects&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;To use the service account key obtained above to onboard multiple projects, follow these steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Open the “IAM &amp;amp; Admin – IAM” page in the GCP Console and select another project to onboard.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Add” at the top, add the service account created above as a new member, set the role to Project – Owner or Project – Viewer, then click “Save”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/google_serviceaccount_otherproject.png" alt="Google add member"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Repeat the steps above to onboard more projects.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="enable-related-apis"&gt;Enable related APIs&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Google Cloud APIs are project-scoped. When onboarding multiple Google Cloud projects, enable the related APIs in each project.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;APIs required for managing Google Cloud on the platform&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;After obtaining the key file, enable the Cloud Resource Manager API, Cloud Build API (for creating machines from custom images), and Compute Engine API for the authorized project in the Google API Library.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;On the Cloud Resource Manager API page in the API Library, enable the Cloud Resource Manager API for the authorized project.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/cloudresourcemanagerapi.png" alt="Google Cloud Resource Manager API"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the Cloud Build API page in the API Library, enable the Cloud Build API for the authorized project.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/cloudbuildapi.png" alt="Google Cloud Build API"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;APIs required for managing Google Cloud RDS on the platform&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;On the Cloud SQL Admin API page in the API Library, enable the Cloud SQL Admin API.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/cloudsqladminapi.png" alt="Google Cloud SQL Admin API"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;To manage Google Cloud resources through the platform, the cloud account needs the following permissions:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission description&lt;/th&gt;
&lt;th&gt;Read-only&lt;/th&gt;
&lt;th&gt;Read-write&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Manage all Google Cloud resources&lt;/td&gt;
&lt;td&gt;Viewer&lt;/td&gt;
&lt;td&gt;Editor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage compute instances&lt;/td&gt;
&lt;td&gt;Compute Viewer&lt;/td&gt;
&lt;td&gt;Compute Editor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage network resources&lt;/td&gt;
&lt;td&gt;Compute Network Viewer&lt;/td&gt;
&lt;td&gt;Compute Network Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage object storage resources&lt;/td&gt;
&lt;td&gt;Storage Legacy Bucket Reader, Storage Object Viewer&lt;/td&gt;
&lt;td&gt;Storage Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage cloud databases&lt;/td&gt;
&lt;td&gt;Cloud SQL Viewer&lt;/td&gt;
&lt;td&gt;Cloud SQL Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Redis&lt;/td&gt;
&lt;td&gt;Redis Enterprise Cloud Viewer&lt;/td&gt;
&lt;td&gt;Redis Enterprise Cloud Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage logs&lt;/td&gt;
&lt;td&gt;Logs Viewer&lt;/td&gt;
&lt;td&gt;Logging Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage file storage&lt;/td&gt;
&lt;td&gt;Cloud Filestore Viewer&lt;/td&gt;
&lt;td&gt;Cloud Filestore Editor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage all custom roles in the project&lt;/td&gt;
&lt;td&gt;Role Viewer&lt;/td&gt;
&lt;td&gt;Role Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage DNS&lt;/td&gt;
&lt;td&gt;DNS Reader&lt;/td&gt;
&lt;td&gt;DNS Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage account billing&lt;/td&gt;
&lt;td&gt;Billing Account Viewer&lt;/td&gt;
&lt;td&gt;Billing Account Administrator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage monitoring&lt;/td&gt;
&lt;td&gt;Monitoring Viewer&lt;/td&gt;
&lt;td&gt;Monitoring Admin&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="billing-data-source"&gt;Billing data source&lt;/h3&gt;
&lt;p&gt;Select where Google billing data is stored: BigQuery or bucket. Google billing no longer supports bucket.&lt;/p&gt;
&lt;h3 id="how-to-configure-and-obtain-bigquery-settings-on-google-cloud"&gt;How to configure and obtain BigQuery settings on Google Cloud?&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Google Cloud Console, click “Billing” in the left menu, and open the billing page.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/googlebilling.png" alt="Google Billing"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Billing export” in the left menu. Under the BIGQUERY EXPORT tab, enable detailed usage cost and configure the project and dataset name.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/googlebigqueryconfig.png" alt="Google BigQuery configuration"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click the dataset name to open BigQuery, expand the right-side nodes, select the partitioned table under the dataset name, then on that page click the “Details” tab at the top to obtain the table ID.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/gcpbigquerytableid.png" alt="Google BigQuery table ID"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the table details page, click “Edit details” in the upper right and set expiration to None. If an expiration is set, expired data will be cleaned from BigQuery; configure carefully.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/gcomodifytable.png" alt="Google edit table details"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="how-to-obtain-the-billing-file-bucket-url-and-file-prefix"&gt;How to obtain the billing file bucket URL and file prefix?&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Sign in to the Google Cloud Console, click “Billing” in the left menu, and open the billing page.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Billing export” in the left menu. On the billing page, click the “File export” tab, then view and record the storage partition name and report prefix.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/googlebillingbucket.png" alt="Google billing export"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Storage / Browser” in the left menu. On the storage page, click the corresponding storage partition name, then click the “Overview” tab. The link URL is the bucket URL.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/googlebillingbucketurl.png" alt="Google bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create China Telecom Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/ctyun/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/ctyun/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select “China Telecom Cloud”, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: China Telecom Cloud account name.&lt;/li&gt;
&lt;li&gt;Account type: global or China region accounts are supported.&lt;/li&gt;
&lt;li&gt;Key ID and password: see &lt;a href="#how-to-get-china-telecom-cloud-parameters"&gt;How to get China Telecom Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;China Telecom Cloud does not expose Type-2 node APIs, so some region information cannot be retrieved via API.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-get-china-telecom-cloud-parameters"&gt;How to get China Telecom Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-china-telecom-cloud-api-key"&gt;How to get a China Telecom Cloud API key?&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the China Telecom Cloud console and open Security settings from user info in the upper right.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ctyun.png" alt="China Telecom Cloud security settings"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In Security settings, click user AccessKey to view it.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ctyunaccesskey.png" alt="China Telecom Cloud AccessKey"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create China Mobile Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/ecloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/ecloud/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;Currently only resource sync is supported for China Mobile Cloud accounts; resource operations are not supported.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select “China Mobile Cloud”, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: China Mobile Cloud account name.&lt;/li&gt;
&lt;li&gt;Key ID and password: see &lt;a href="#how-to-get-china-mobile-cloud-parameters"&gt;How to get China Mobile Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-china-mobile-cloud-parameters"&gt;How to get China Mobile Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-china-mobile-cloud-api-key"&gt;How to get a China Mobile Cloud API key?&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the China Mobile Cloud console, search for “AK management” under all products, and open AccessKey management.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ecloud.png" alt="China Mobile Cloud AK management"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create a key or view Access key and Secret key for an existing key.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/ecloudaccesskey.png" alt="China Mobile Cloud AccessKey"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="permission-configuration"&gt;Permission configuration&lt;/h2&gt;
&lt;p&gt;Permissions required to manage China Mobile Cloud resources:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Permission policy&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Admin&lt;/td&gt;
&lt;td&gt;Administrator role&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description></item><item><title>Docs: Create JD Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/jdcloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/jdcloud/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;Currently only resource sync is supported for JD Cloud accounts; resource operations are not supported.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select “JD Cloud”, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: JD Cloud account name.&lt;/li&gt;
&lt;li&gt;Key ID and password: see &lt;a href="#how-to-get-jd-cloud-parameters"&gt;How to get JD Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the JD Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-jd-cloud-parameters"&gt;How to get JD Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-jd-cloud-api-key"&gt;How to get a JD Cloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the JD Cloud console, hover over the username in the upper right, and choose “Access Key management”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jdak.png" alt="JD Cloud AK entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;View existing Access Key info, or click “Create” to create one, then “View” to get the Access Key Secret.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jdaksk.png" alt="JD Cloud AK list"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;p&gt;JD Cloud bills are retrieved via API. Configure:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Collect bills immediately: by default the platform collects bills at 04:00 daily.&lt;/li&gt;
&lt;li&gt;Time range: recommend collecting bills from the last 1–6 months.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Docs: Create Baidu Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/baidu/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/baidu/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Baidu Cloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Baidu Cloud platform name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with Access Key. See &lt;a href="#how-to-get-baidu-cloud-parameters"&gt;How to get Baidu Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Baidu Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-baidu-cloud-parameters"&gt;How to get Baidu Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-baidu-cloud-api-key"&gt;How to get a Baidu Cloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Baidu Cloud console with the primary account, open personal info in the upper right, then click “Security authentication” to open Access Key.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/baidu-accesskeys.png" alt="Baidu Cloud AK entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On the Access Key page, view existing keys or click “Create AccessKey”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/baidu-get_accesskey_list.png" alt="Baidu Cloud AK list"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Access Key Secret is hidden by default. Click “Show”; Baidu Cloud sends a verification code to the account contact’s phone. After verification, the Secret is shown.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/baidu-get_access_key_secret.png" alt="Baidu Cloud AK Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create China Unicom Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/cucloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/cucloud/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select China Unicom Cloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: China Unicom Cloud platform name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with Access Key. See &lt;a href="#how-to-get-china-unicom-cloud-parameters"&gt;How to get China Unicom Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the China Unicom Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-china-unicom-cloud-parameters"&gt;How to get China Unicom Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-china-unicom-cloud-api-key"&gt;How to get a China Unicom Cloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the China Unicom Cloud console with the primary account, open personal info in the upper right, then click “Access control” to open IAM.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/liantong-accesskeys.png" alt="China Unicom Cloud AK entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On IAM Access Control, click “Security settings” next to the username.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/liantong-accesskeys1.png" alt="China Unicom Cloud security settings"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Create access key”. China Unicom Cloud sends a verification code to the account contact’s phone; create the key after verification.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/liantong-get_access_key_secret.png" alt="China Unicom Cloud AK Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Kingsoft Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/kscloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/kscloud/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Kingsoft Cloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Kingsoft Cloud platform name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with Access Key. See &lt;a href="#how-to-get-kingsoft-cloud-parameters"&gt;How to get Kingsoft Cloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the Kingsoft Cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;If the Kingsoft Cloud account is new, enable object storage on Kingsoft Cloud first.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="how-to-get-kingsoft-cloud-parameters"&gt;How to get Kingsoft Cloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-kingsoft-cloud-api-key"&gt;How to get a Kingsoft Cloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Kingsoft Cloud console with the primary account, open personal info in the upper right, then click “Access Keys”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jinshan-accesskeys.png" alt="Kingsoft Cloud AK entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Create key”, then “Continue” in the risk warning dialog. Kingsoft Cloud sends a verification code to the account contact’s phone. After verification, the key dialog appears.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jinshan-get_access_key_secret.png" alt="Kingsoft Cloud AK Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="billing-configuration"&gt;Billing configuration&lt;/h2&gt;
&lt;h3 id="how-to-get-the-kingsoft-cloud-bill-bucket-url"&gt;How to get the Kingsoft Cloud bill bucket URL&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the Kingsoft Cloud console, open “Billing” → “Account overview”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jinshanyunusercenter.png" alt="Kingsoft Cloud user center"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Set bill data storage”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jinshanusercenterhome.png" alt="Kingsoft Cloud bill storage"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Note the billing-item detail bill bucket name. If unset, subscribe to a bucket on this page. Kingsoft Cloud requires a KS3 directory (custom input).&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jinshanossbucket.png" alt="Kingsoft Cloud OSS Bucket"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In Object Storage, open the bucket overview; the bucket domain is the bucket URL. When entering it in the cloud management platform, include the directory as well.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/jinshanbucketurl.png" alt="Kingsoft Cloud Bucket URL"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create QingCloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/qingcloud/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/qingcloud/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select QingCloud, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: QingCloud platform name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with API key (Access Key). See &lt;a href="#how-to-get-qingcloud-parameters"&gt;How to get QingCloud parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Click “Next: Bill file access (optional)” to configure billing parameters.&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the QingCloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-qingcloud-parameters"&gt;How to get QingCloud parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-a-qingcloud-api-key"&gt;How to get a QingCloud API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the QingCloud console with the primary account, click personal info in the upper right, then click “API keys”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/qingcloud-accesskeys.png" alt="QingCloud AK entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Create”, then “Submit” in the dialog to generate an API key. You can download the private key.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/qingcloud-get_access_key_secret.png" alt="QingCloud AK Secret"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Oracle Cloud Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/oracle/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/public/oracle/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select ORACLE, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: ORACLE platform name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with an API key made of user, tenancy, and a key file. See &lt;a href="#how-to-get-oracle-parameters"&gt;How to get Oracle parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” (default: all regions).&lt;/li&gt;
&lt;li&gt;Configure scheduled sync (optional), then click “OK” to create the ORACLE cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-oracle-parameters"&gt;How to get Oracle parameters&lt;/h2&gt;
&lt;h3 id="how-to-get-an-oracle-api-key"&gt;How to get an Oracle API key&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to Oracle Cloud with the primary account, open personal info in the upper right, click “My profile”, then “API keys”.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/oraclecloud-accesskeys.png" alt="Oracle AK entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Add API key”, then “Add” in the dialog to generate a key. You can download the private key.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/oraclcloud-get_access_key_secret.png" alt="Oracle AK Secret"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Add” to get the user and tenancy values required by the cloud management platform, and import the private key downloaded earlier.&lt;/p&gt;
&lt;img src="/docs/zh/docs/faq/image/oraclcloud-get_access_key_secret-2.png" alt="Oracle AK info"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create VMware Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/vmware/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/vmware/</guid><description>
&lt;h2 id="supported-versions"&gt;Supported versions&lt;/h2&gt;
&lt;p&gt;VMware 5.0–7.0 are supported.&lt;/p&gt;
&lt;h2 id="vmware-resource-onboarding-flow"&gt;VMware resource onboarding flow&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Create a VMware cloud account. The platform automatically creates Layer 2 networks and IP subnets. Mapping:
&lt;ul&gt;
&lt;li&gt;One vSwitch or Distributed vSwitch maps to one Layer 2 network;&lt;/li&gt;
&lt;li&gt;Contiguous IP ranges with the same VLAN under a Layer 2 network form one IP subnet;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;After the account is added, if auto-created Layer 2 networks and IP subnets do not match your network design, merge wires and IP subnets based on the real VMware environment. Merging wires is irreversible; if misconfigured, delete the cloud account and add it again.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select VMware, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: VMware account name.&lt;/li&gt;
&lt;li&gt;vCenter address: vCenter server domain or IP.&lt;/li&gt;
&lt;li&gt;Port: default 443.&lt;/li&gt;
&lt;li&gt;Account: vCenter admin username.&lt;/li&gt;
&lt;li&gt;Password: vCenter admin password.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the VMware cloud account and related IP subnets and start syncing resources.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;If no resources appear after import, check whether a non-admin account was used.&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Docs: Create OpenStack Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/openstack/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/openstack/</guid><description>
&lt;h2 id="supported-versions"&gt;Supported versions&lt;/h2&gt;
&lt;p&gt;OpenStack Mitaka and later are supported.&lt;/p&gt;
&lt;h2 id="notes"&gt;Notes&lt;/h2&gt;
&lt;p&gt;If the OpenStack auth URL is a domain name, configure DNS resolution on the control node; otherwise resources cannot be synced because the domain cannot be resolved.&lt;/p&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;After creating an OpenStack account, the cloud management platform cannot obtain the true storage capacity on OpenStack. Set OpenStack storage capacity on the “Storage - Block storage” page to the real capacity as much as possible.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select OpenStack, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: OpenStack account name.&lt;/li&gt;
&lt;li&gt;Auth URL: OpenStack management auth URL, such as &lt;code&gt;http://host:5000/v3&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Account: OpenStack admin username, such as admin.&lt;/li&gt;
&lt;li&gt;Password: OpenStack admin password.&lt;/li&gt;
&lt;li&gt;Project: OpenStack project, such as admin.&lt;/li&gt;
&lt;li&gt;Domain Name: OpenStack domain name, such as default.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the OpenStack account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create ZStack Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/zstack/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/zstack/</guid><description>
&lt;h2 id="supported-versions"&gt;Supported versions&lt;/h2&gt;
&lt;p&gt;ZStack 3.5.0 and later are supported.&lt;/p&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select ZStack, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: ZStack account name.&lt;/li&gt;
&lt;li&gt;Auth URL: usually &lt;code&gt;http://host:8080/&lt;/code&gt;, where host is the ZStack control node IP.&lt;/li&gt;
&lt;li&gt;Key ID: Access Key ID on ZStack.&lt;/li&gt;
&lt;li&gt;Password: Access Key Secret on ZStack.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Generate or use an Access Key on the ZStack management platform under “Platform management - Access Key”.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol start="4"&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the ZStack account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Alibaba Apsara Stack Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/apsara/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/apsara/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;This feature onboards Alibaba Apsara Stack private cloud. Currently only resource sync is supported.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="supported-versions"&gt;Supported versions&lt;/h2&gt;
&lt;p&gt;Apsara Stack v3.12.0 and later.&lt;/p&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Apsara Stack (Feitian), then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Apsara Stack account name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with Access Key. See &lt;a href="#how-to-get-apsara-stack-parameters"&gt;How to get Apsara Stack parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Secret ID: if the secret is &lt;code&gt;NbzBaQ94MPzjZf5i&lt;/code&gt; and the highest visible organization ID is &lt;code&gt;4&lt;/code&gt;, enter &lt;code&gt;NbzBaQ94MPzjZf5i/4&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the Apsara Stack private cloud account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-apsara-stack-parameters"&gt;How to get Apsara Stack parameters&lt;/h2&gt;
&lt;h3 id="get-accesskey-on-apsara-stack"&gt;Get AccessKey on Apsara Stack&lt;/h3&gt;
&lt;p&gt;Only operations administrators and first-level organization administrators can get organization AccessKeys.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Log in to the ASCM console as an administrator.&lt;/li&gt;
&lt;li&gt;In the top menu, click “Enterprise”.&lt;/li&gt;
&lt;li&gt;In the left nav, click “Organization management”.&lt;/li&gt;
&lt;li&gt;In the org tree, click the settings icon after the parent organization to add.&lt;/li&gt;
&lt;li&gt;In the dropdown, choose “Get AccessKey”.&lt;/li&gt;
&lt;li&gt;In the dialog, view the organization AccessKey.&lt;/li&gt;
&lt;li&gt;To get organization ID, open browser developer tools, find the ListResourceGroup API response, and take the first organizationID.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="get-endpoint-on-apsara-stack"&gt;Get Endpoint on Apsara Stack&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;In the address bar, open the ASO URL &lt;code&gt;region-id.aso.intranet-domain-id.com&lt;/code&gt; and press Enter.&lt;/li&gt;
&lt;li&gt;Enter username and password, click “Log in”, and open ASO.&lt;/li&gt;
&lt;li&gt;In the left nav, click “Product O&amp;amp;M → Product list → Tianji” to open the Tianji console.&lt;/li&gt;
&lt;li&gt;In Tianji, choose “Reports” in the left nav.&lt;/li&gt;
&lt;li&gt;On “All reports”, search for “Service registration variables” and open it.&lt;/li&gt;
&lt;li&gt;Click the icon next to Service and search for the product service.&lt;/li&gt;
&lt;li&gt;In the Service Registration column, right-click and choose “Select more”.&lt;/li&gt;
&lt;li&gt;On the “Details” page, view the product service Endpoint.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create ZettaKit Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/zettakit/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/zettakit/</guid><description>
&lt;h2 id="supported-versions"&gt;Supported versions&lt;/h2&gt;
&lt;p&gt;Managing ZettaKit platforms is supported.&lt;/p&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Select ZettaKit, then click “Next: Configure cloud account”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Configure:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Name: ZettaKit account name.&lt;/li&gt;
&lt;li&gt;Auth URL: usually &lt;code&gt;http://host:8080/&lt;/code&gt;, where host is the ZettaKit control node IP.&lt;/li&gt;
&lt;li&gt;Key ID: ZettaKit account.&lt;/li&gt;
&lt;li&gt;Password: ZettaKit password.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Connection test” to verify parameters.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “OK” to create the ZettaKit account.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Cloudpods Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/cloudpods/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/cloudpods/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Cloudpods, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Cloudpods cloud account name.&lt;/li&gt;
&lt;li&gt;Auth URL: Keystone service URL. On a Cloudpods control node, get OS_AUTH_URL with &lt;code&gt;ocadm cluster rcadmin&lt;/code&gt;. Usually &lt;code&gt;http://domain(IP):30500/v3&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect with Access Key. See &lt;a href="#how-to-get-cloudpods-parameters"&gt;How to get Cloudpods parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the Cloudpods account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-cloudpods-parameters"&gt;How to get Cloudpods parameters&lt;/h2&gt;
&lt;h3 id="get-an-accesskey-on-cloudpods"&gt;Get an AccessKey on Cloudpods&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to Cloudpods, hover over the username in the upper right, then select “Access credentials”.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/cloudpodsaksk.png" alt="Cloudpods access credentials"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On AccessKey management, click “Create” to create an AccessKey.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/cloudpodsaddaksk.png" alt="Cloudpods create AK"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For an existing AccessKey, the ID and Client Secret are the key ID and password.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/cloudpodsaksklist.png" alt="Cloudpods AK list"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create HCSO Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/hcso/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/hcso/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select HCSO, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: HCSO account name.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect to HCSO with Access Key. See &lt;a href="#how-to-get-hcso-parameters"&gt;How to get HCSO parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Default region / Endpoint domain: for &lt;code&gt;iam.cn-north-1.test.com&lt;/code&gt;, &lt;code&gt;iam&lt;/code&gt; is the identity service, &lt;code&gt;cn-north-1&lt;/code&gt; is the endpoint region, and &lt;code&gt;test.com&lt;/code&gt; is the endpoint domain.&lt;/li&gt;
&lt;li&gt;Subnet DNS: default DNS for subnets in the environment; up to two, separated by commas.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the HCSO account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-hcso-parameters"&gt;How to get HCSO parameters&lt;/h2&gt;
&lt;h3 id="get-an-accesskey-on-hcso"&gt;Get an AccessKey on HCSO&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the HCSO console, hover over the username in the upper right, then select “My credentials”.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/hcsoaksk.png" alt="HCSO credentials entry"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Access keys” on the left, then click “Add access key”.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/hcsoaddaksk.png" alt="HCSO add key"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After verification, an Excel file named credentials is downloaded. Open it to get Access Key ID and Secret Access Key.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create HCS Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/hcs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/hcs/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select HCS, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: HCS cloud account name.&lt;/li&gt;
&lt;li&gt;Notes: notes for the account.&lt;/li&gt;
&lt;li&gt;Key ID / Password: connect to HCS with Access Key. See &lt;a href="#how-to-get-hcs-parameters"&gt;How to get HCS parameters&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Auth URL: HCS management auth URL, such as &lt;code&gt;region1.example.com&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the HCS account.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="how-to-get-hcs-parameters"&gt;How to get HCS parameters&lt;/h2&gt;
&lt;h3 id="get-an-accesskey-on-hcs"&gt;Get an AccessKey on HCS&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Log in to the HCS console, hover over the user in the upper right, then select “Personal settings”.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/hcsaksk.png" alt="HCS personal settings"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click “Manage access keys” under basic information, then click “Add access key”.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/hcsaddaksk.png" alt="HCS add key"&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After clicking “Add access key”, the access key file downloads locally (CSV). Open it to get Access Key ID and Secret Access Key.&lt;/p&gt;
&lt;img src="/docs/en/docs/web_ui/images/multiplecloud/hcsbelongaksk.png" alt="HCS key file"&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Nutanix Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/nutanix/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/nutanix/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;Manage Nutanix platform resources. Nutanix V2 is supported.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Nutanix, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Nutanix cloud account name.&lt;/li&gt;
&lt;li&gt;Notes: notes for the account.&lt;/li&gt;
&lt;li&gt;Prism address: Nutanix Prism web console URL.&lt;/li&gt;
&lt;li&gt;Port: Prism web console port, default 9440.&lt;/li&gt;
&lt;li&gt;Account and password: credentials for the Prism web console.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the Nutanix account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Proxmox Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/proxmox/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/proxmox/</guid><description>
&lt;h2 id="proxmox-resource-onboarding-flow"&gt;Proxmox resource onboarding flow&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;When creating a Proxmox cloud account, the platform does &lt;strong&gt;not&lt;/strong&gt; sync Proxmox bridges as Layer-2 networks / IP subnets. Instead it prepares local networks from IPs on node NICs (including bridges):
&lt;ul&gt;
&lt;li&gt;If an existing local IDC (e.g. KVM) IP subnet already covers those host IPs, reuse it and do not create a new one;&lt;/li&gt;
&lt;li&gt;Otherwise automatically create a Layer-2 network and IP subnet (names like &lt;code&gt;{account-name}-proxmox-host-network&lt;/code&gt;);&lt;/li&gt;
&lt;li&gt;When syncing host NICs later, attach by NIC IP to the matching local Layer-2 network and record the bridge name (e.g. &lt;code&gt;vmbr0&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;After the account is added, if the auto-created Layer-2 network and IP subnet do not match your topology (for example they only cover host IPs, not VM ranges, or one Layer-2 was split into multiple segments), &lt;a href="../../../../network/basic-network/wire/#merge-wires"&gt;merge wires&lt;/a&gt; and &lt;a href="../../../../network/basic-network/network/#merge-ip-subnets"&gt;merge IP subnets&lt;/a&gt; to match the real Proxmox network. Merging wires is irreversible; if misconfigured, delete the cloud account and add it again.&lt;/li&gt;
&lt;li&gt;When syncing existing VMs, NICs match local IP subnets by VM IP and are not tied to Proxmox remote network IDs. Running VM IPs are obtained via QEMU Guest Agent.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="notes"&gt;Notes&lt;/h2&gt;
&lt;h3 id="version-upgrade"&gt;Version upgrade&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: If Proxmox cloud accounts were onboarded before upgrading to 4.0.4, delete those accounts after the upgrade and re-import using this document. 4.0.4 changed the Proxmox network and resource sync model; old accounts leave dirty data and may cause abnormal network, host, or VM status. Deleting a cloud account only removes platform management; Proxmox-side resources are unaffected.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="account-onboarding"&gt;Account onboarding&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Enter only IP or domain for the access address (e.g. &lt;code&gt;192.168.1.10&lt;/code&gt; or &lt;code&gt;pve.example.com&lt;/code&gt;); do not include &lt;code&gt;https://&lt;/code&gt;, path, or port. Port is a separate field (default &lt;code&gt;8006&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;If the access address is a domain, cloud management control nodes must resolve it, or connection tests and sync fail.&lt;/li&gt;
&lt;li&gt;Auth method maps to Proxmox Realm:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;PAM&lt;/strong&gt;: Linux system user auth (commonly &lt;code&gt;root&lt;/code&gt;). Required when creating VMs from local Glance images because remote system-disk mount depends on PAM users.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PVE&lt;/strong&gt;: Proxmox VE local user auth. Only for API operations such as resource sync; &lt;strong&gt;cannot&lt;/strong&gt; remote-mount system disks.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Enter only the username in the account field; the platform appends &lt;code&gt;@pam&lt;/code&gt; or &lt;code&gt;@pve&lt;/code&gt; by auth method. Do not add the suffix yourself.&lt;/li&gt;
&lt;li&gt;Prefer a PAM account with admin rights (e.g. &lt;code&gt;root&lt;/code&gt;). Insufficient permissions may allow a successful connection test but fail to sync hosts, storage, or VMs, or block create/change operations on the platform.&lt;/li&gt;
&lt;li&gt;The platform calls the Proxmox API over HTTPS and skips certificate verification, so self-signed certificates work.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="sync-scope"&gt;Sync scope&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Syncs &lt;strong&gt;QEMU VMs&lt;/strong&gt; only, not LXC containers.&lt;/li&gt;
&lt;li&gt;Syncs nodes (hosts), block storage, and ISO images; VPC uses the platform local Default VPC.&lt;/li&gt;
&lt;li&gt;Only storage whose Content includes &lt;code&gt;images&lt;/code&gt; is enabled as block storage; ISO images come from storage whose Content includes &lt;code&gt;iso&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Does not sync Proxmox bridges as platform IP subnets; VMs and hosts use local Layer-2 networks / IP subnets. Creating or modifying bridges on Proxmox from the platform is not supported.&lt;/li&gt;
&lt;li&gt;Does not sync or manage security groups, EIPs, snapshots, object storage, or load balancers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="vm-management"&gt;VM management&lt;/h3&gt;
&lt;p&gt;Two image methods are supported when creating VMs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Local Glance image (recommended)&lt;/strong&gt;: Choose a public or custom image from platform system images. The platform caches the image to Proxmox storage, then esxi-agent remote-mounts the system disk and injects login and other info so the guest can boot into the OS.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ISO image&lt;/strong&gt;: Mount an ISO as a CD-ROM and create an empty disk. After creation the VM is powered off; power on and install the OS via VNC. Place the ISO in Proxmox storage beforehand, or cache it to the storage from the platform.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="deploy-with-a-local-glance-image"&gt;Deploy with a local Glance image&lt;/h4&gt;
&lt;p&gt;Creating a VM from a public or custom image is similar to VMware and does &lt;strong&gt;not&lt;/strong&gt; use cloud-init:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Upload and cache the Glance image to Proxmox storage (first use of an image takes longer; cached images can be reused).&lt;/li&gt;
&lt;li&gt;Create the VM on Proxmox and attach that system disk.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;esxi-agent&lt;/strong&gt; remote-mounts the system disk; &lt;strong&gt;host-deployer&lt;/strong&gt; injects admin password, SSH keys, and NIC config into the disk filesystem.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Notes for this method:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Auth must be PAM&lt;/strong&gt;: Remote system-disk mount uses a Linux system user (e.g. &lt;code&gt;root@pam&lt;/code&gt;) to access Proxmox nodes. PVE users cannot log in to hosts; deploy fails with PVE auth.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;esxi-agent&lt;/strong&gt;: esxi-agent must be deployed and running (same service as for VMware). The esxi-agent node must reach the Proxmox API and storage, or remote mount and deploy fail.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No cloud-init required on the image&lt;/strong&gt;: Password, keys, and IP are written directly to disk by host-deployer, same as local KVM and VMware.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;VM must be powered off&lt;/strong&gt;: Remote system-disk mount for deploy requires the VM to be off.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;NIC&lt;/strong&gt;: Choose a local IP subnet Layer-2-reachable to the target node. At create time the NIC attaches to the bridge recorded on that Layer-2 network (e.g. &lt;code&gt;vmbr0&lt;/code&gt;); if none is recorded, default is &lt;code&gt;vmbr0&lt;/code&gt;. Ensure the target node has that bridge and Layer-2 connectivity to the chosen IP subnet.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Tip&lt;/strong&gt;: Glance images suit bulk delivery of packaged OSes; ISO suits interactive install or custom partitioning.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Running VM IPs come from QEMU Guest Agent. Without Guest Agent installed/enabled, IPs may be missing after sync.&lt;/li&gt;
&lt;li&gt;Reinstall OS, bind security group, bind EIP, create snapshot, and migrate are not supported.&lt;/li&gt;
&lt;li&gt;Attach disks only when the VM is powered off; detach can be done powered on or off. Creating cloud disks alone from the disk menu is not supported; data disks are added with VM create or add-disk on the VM.&lt;/li&gt;
&lt;li&gt;Disk resize capacity must be an integer multiple of 1 GB; the VM may be on or off.&lt;/li&gt;
&lt;li&gt;Adjusting CPU and memory can be done powered on or off.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Tip&lt;/strong&gt;: If no resources appear after importing the account, check account permissions and whether QEMU VMs exist on Proxmox (LXC containers are not synced).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Proxmox, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Proxmox cloud account name.&lt;/li&gt;
&lt;li&gt;Remarks: optional remarks.&lt;/li&gt;
&lt;li&gt;Access address: Proxmox console IP or domain, without protocol, path, or port.&lt;/li&gt;
&lt;li&gt;Port: Proxmox console port (default 8006).&lt;/li&gt;
&lt;li&gt;Auth method: PAM (Linux system user) or PVE (Proxmox VE local user). Must be PAM when creating VMs from Glance images with remote system-disk mount.&lt;/li&gt;
&lt;li&gt;Account / Password: Proxmox console username and password; do not include &lt;code&gt;@pam&lt;/code&gt; / &lt;code&gt;@pve&lt;/code&gt; in the account.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” and configure related parameters.&lt;/li&gt;
&lt;li&gt;Click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the Proxmox cloud account, related IP subnets, and sync resources on the account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create H3C Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/h3c/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/private/h3c/</guid><description>
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list to open the create page.&lt;/li&gt;
&lt;li&gt;Select H3C as the cloud platform, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: H3C cloud account name.&lt;/li&gt;
&lt;li&gt;Notes: notes for the account.&lt;/li&gt;
&lt;li&gt;Endpoint: H3C console URL.&lt;/li&gt;
&lt;li&gt;Port: H3C console port, default 11000.&lt;/li&gt;
&lt;li&gt;Account and password: credentials for the H3C console.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Configure sync regions” and set related parameters.&lt;/li&gt;
&lt;li&gt;Click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the H3C account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create S3 Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/storage/s3/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/storage/s3/</guid><description>
&lt;p&gt;S3 stands for Simple Storage Service. Before creating an S3 account, deploy an S3-compatible object storage server such as MinIO. For MinIO installation, see the &lt;a href="https://min.io/download#/linux" target="_blank" rel="noopener noreferrer"&gt;reference link&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select S3, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: S3 object storage server name.&lt;/li&gt;
&lt;li&gt;Endpoint: S3 object storage endpoint. For MinIO, use &lt;code&gt;http://IP:9000&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Key ID: Access Key.&lt;/li&gt;
&lt;li&gt;Password: Secret Key.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;On the MinIO server, run the related commands to get Endpoint, Access Key, and Secret Key.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol start="4"&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the S3 account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create Ceph Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/storage/ceph/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/storage/ceph/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;Connect and import Ceph object storage resources.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select Ceph, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: Ceph object storage server name.&lt;/li&gt;
&lt;li&gt;Endpoint: Ceph object storage endpoint.&lt;/li&gt;
&lt;li&gt;Key ID: Ceph object storage key ID.&lt;/li&gt;
&lt;li&gt;Password: password for the key ID.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “OK” to create the Ceph account.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docs: Create XSKY Account</title><link>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/storage/xsky/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/docs/en/docs/web_ui/resource-mgmt/multiplecloud/cloudaccount/storage/xsky/</guid><description>
&lt;blockquote&gt;
&lt;p&gt;Connect and import XSKY storage resources. XSKY object storage must exist in the environment.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="procedure"&gt;Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;On the Cloud Accounts page, click “Create” above the list.&lt;/li&gt;
&lt;li&gt;Select XSKY, then click “Next: Configure cloud account”.&lt;/li&gt;
&lt;li&gt;Configure:
&lt;ul&gt;
&lt;li&gt;Name: XSKY storage server name.&lt;/li&gt;
&lt;li&gt;Endpoint: XSKY storage endpoint.&lt;/li&gt;
&lt;li&gt;Key ID: XSKY object storage key ID.&lt;/li&gt;
&lt;li&gt;Password: password for the key ID.&lt;/li&gt;
&lt;li&gt;Common parameters: see &lt;a href="../../#common-configuration-parameters"&gt;Common configuration parameters&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Click “Connection test” to verify parameters.&lt;/li&gt;
&lt;li&gt;After a successful test, click “Next: Scheduled sync (optional)” to configure scheduled sync.&lt;/li&gt;
&lt;li&gt;Click “OK” to create the XSKY account.&lt;/li&gt;
&lt;/ol&gt;</description></item></channel></rss>