Alibaba Cloud can be integrated with your tenant so you can provision services from Alibaba Cloud.
Alibaba Cloud can be integrated with Enterprise Marketplace, which allows your users to provision services from Alibaba Cloud. It can also be integrated with Cost & Asset Management, which allows you to monitor those provisioned services. However, before your users can provision services from Alibaba Cloud, you must create accounts on the Alibaba website and link to those accounts from Enterprise Marketplace. For more information, see the Alibaba Cloud Official Website.
You must create a Billing Account on the Alibaba Cloud website. You can use the Billing Account to link to Enterprise Marketplace, but more likely you will want to use one or more Resource Access Management (RAM) Accounts to allow access:
Billing Account:
This is the main account that your business will have with Alibaba Cloud. It contains your payment information that Alibaba will use to charge you. For more information, see Creating a Billing Account.
Although this account can be used to link to Enterprise Marketplace, doing so will give everyone in your company full access to everything available from Alibaba.
Resource Access Management (RAM) Account:
These are subaccounts within your Alibaba Billing Account that allow you to grant different types of access to different teams and individuals. For example, you could create a Storage Team RAM Account that only allows the team to provision Alibaba storage. For more information, see Creating a RAM Account.
Creating a Billing Account
Complete the following steps to create a Billing Account in Alibaba. If your organization already has an Alibaba Billing Account, contact your Alibaba Billing Account Administrator to be added to that account.
Review your organization’s security compliance guidelines for providing access to Enterprise Marketplace. Enterprise Marketplace does not require access to your Billing Account for Enterprise Marketplace provisioning or pricing. A RAM user is sufficient. Other applications such as Cost & Asset Management might require such access when Alibaba is supported on those applications in the future. To do this, complete the following steps:
. This can be the Billing Account or a RAM Account that has admin privileges.
Using RAM Accounts increases security because each RAM user can have their own permissions. Generally, set up a separate non-login RAM user for configuring provider accounts for Enterprise Marketplace.
Enter the
Password
for the account and then click
Log On
.
Click the
Actions
icon in the upper left side of the screen.
From the list of available services, click
Resource Access Management
in the
Monitor and Management
section.
On the
Account Overview
page, click
Users
from the left navigation bar.
Click
Create User
.
On the
User Account Information
page, enter the
Logon Name
and the
Display Name
.
Select the
Programmatic Access
check box to enable access using your
AccessKeyID
and
AccessKeySecret
. This information is used to add user details in the Enterprise Marketplace portal.
Click
OK
.
The next page displays your newly created user information. Make sure to save this information in a secure location immediately because the
Logon Password
and
AccessKeySecret
will not be available again after the dialog box is closed. You can either click
Copy
under the
Actions
menu or click
Download CSV file
.
Adding permissions to your RAM account
Complete the following steps to add permissions to your RAM account:
menu for the user that you want to add permissions to and select
Add Permissions
.
Select
Alibaba Cloud Account
as your authorized scope.
Go to the
System Policy
section and select
AdministratorAccess
from the
Authorization Policy Name
list.
Click
OK
, and then
Complete
to finish.
Select
AdministratorAccess
rather than a specific service level access because the user needs access to the entire catalog in Enterprise Marketplace to be able to provision or manage your catalogs. Individual service level access can still be granted but you would need to select all available
FullAccess
permissions in every catalog to make it work in Enterprise Marketplace.
Some Kapplications can be used to manage the Alibaba provider account and the resources contained in it. Such management might include creating and modifying user accounts, and provisioning and de-provisioning resources. Therefore, the credentials used to configure provider accounts in Enterprise Marketplace must have the correct level of permissions assigned to them so that these functions are available.
Review your organization’s security compliance guidelines for accessing your Alibaba account. All credentials are securely encrypted and stored in the provider accounts that you configure.
For more information about how system policies work, go to https://www.alibabacloud.com/ and search for Alibaba Cloud services that support Resource Access Management (RAM).
Configuration on your tenant
To configure your Alibaba Cloud account, first follow the steps to create a provider account in Cloud integrations account management, if you have not done so. After you have a provider account with permissions, complete the steps in this section.
Creating an asset account
After you have created a provider account with permissions, complete the following steps:
page, enter the following information and then click
Create Account
:
Name
Description
Account Number:
Enter any random group of numbers (must be at least 8 digits). Because Alibaba does not have an account number associated to it, the information that you enter in this field is irrelevant. This is a known issue.
Select Existing Master Account:
This is not a mandatory field and can be left blank.
Keep the
Status
as
Active
.
Adding a credential
After you have configured your asset account, click
Add Credential
, enter the following information, and then click
Add
:
Name
Purpose:
Select
Provisioning
for
Enterprise Marketplace
.
Common Discovery
is also supported for Alibaba. If you were to use the same account for Common Discovery as well, then you may select
Asset Ingestion
or
Asset Discovery
.
Support for Cost & Asset Management is not currently available.
Keep the
Status
as
Active
.
Select the
Create New or Update Credential in Vault
checkbox to enable the
Access Key ID
and
Secret Key ID
fields.
Optionally, in the
Credential Reference ID
field, you can enter an existing credential stored in the system.
checkbox and make your desired selections. Depending on the type of restrictions that you want for this account, you need to associate only those business entities that you want to give access to.
For example, if you require certain organizations or teams to use different credentials, configure as many provider accounts as you need and assign them to specific organizations, teams, or custom contexts. Only users from these organizations and teams are able to use these provider accounts.