Hybrid Cloud Management

What is Alibaba Cloud Hybrid Cloud Management?

ZCF provides an entry point for Alibaba Cloud Hybrid Cloud Management and reuses the ZStack Cloud hybrid cloud management capability. It integrates the simple, strong, scalable, and smart (4S) features of a private cloud environment and the advanced, secure, and stable features of Alibaba Cloud Public Cloud. It is a hybrid cloud management solution that seamlessly integrates cloud services and terminals, interconnecting the control panel and data panel.

Concepts

  • Alibaba Cloud Hybrid Cloud Management used through ZCF provides the following cloud computing products of Alibaba Cloud:
    • ECS Instance: An elastic compute service (ECS) instance is a VM instance created on Alibaba Cloud.
    • Disk: A disk provides storage space for an ECS instance created on Alibaba Cloud.
    • Image: An image is a template file that is used to create ECS instances. Images are categorized into custom images and Alibaba Cloud images.
    • Security Group: A security group provides security control services for ECS instances on the L3 network. It filters the inbound or outbound packets of ECS instances based on security rules.
    • VPC: A virtual private cloud (VPC) is a private network dedicated for ECS instances created on Alibaba Cloud.
    • EIP: An elastic IP address (EIP) is an IP address in Alibaba Cloud public networks. You can attach EIPs to ECS instances so that the ECS instances can access public networks by using the EIPs.
  • VPN: Establishes a site-to-site IPsec VPN channel to enable communications between private networks in a local data center and Alibaba Cloud VPC. This section includes:
    • VPN Gateway: A virtual private network (VPN) gateway establishes a secure connection between a local data center and Alibaba Cloud VPC by using an encrypted channel.
    • VPN Customer Gateway: A VPN customer gateway provides services for a local data center.
    • VPN Connection: A VPN connection is an encrypted communication channel established between a VPN gateway and VPN customer gateway.
  • Express Connect: Express Connect uses physical circuits (electric cables or optical fibers leased from operators) to connect local data centers with Alibaba Cloud access points and Alibaba Cloud VPC. This way, private networks on Alibaba Cloud and in local data centers can communicate with each other in a fast, stable, and secure manner. This section includes:
    • Router Interface: A router interface is a virtual device that is used to establish communication channels and control their status.
    • Virtual Border Router: A virtual border router (VBR) is virtualized from a physical switch port on the access point of Alibaba Cloud. It forwards the data on the physical circuit to Alibaba Cloud VPC.
  • Alibaba Cloud NAS: Alibaba Cloud NAS is a network-attached file storage service. It provides highly reliable and available distributed file systems that can be accessed by using standard file access protocols. In addition, Alibaba Cloud NAS is scalable in storage space and performance and can be managed in a namespace while shared with multiple users. ZStack Cloud seamlessly integrates with Alibaba Cloud NAS. You can add primary storage of the AliyunNAS type on ZStack Cloud Private Cloud so as to use the distributed storage independently deployed on Alibaba Cloud. This section includes:
    • File System: A file system is a backend storage system used for Alibaba Cloud NAS primary storage. Before you add an AliyunNAS primary storage, you need to add an NAS file system.
    • Permission Group: A permission group is an allowlist of IP addresses or IP ranges which can access file systems according to specified permission rules.
  • Data Center: Data centers are resources corresponding to Alibaba Cloud regions and zones. These resources include:
    • Region: A region is a physical data center. A region in ZStack Cloud Hybrid Cloud corresponds to a region in Alibaba Cloud.
    • Zone: A zone is a physical area in a region that is independent from other zones in the region in terms of electricity and network supplies.
  • Setting: Alibaba Cloud Hybrid Cloud Management used through ZCF provides the following basic settings:
    • AccessKey Management: An AccessKey pair is an identity credential that has access to APIs of Alibaba Cloud or Private Alibaba Cloud. It has full access to the Cloud. An AccessKey pair consists of AccessKey ID and AccessKey secret.
    • Hybrid Cloud Settings: Hybrid cloud settings allow you to configure settings that take effect on the whole platform.

Physical Deployment

ZStack Cloud Hybrid Cloud uses an in-process micro-service architecture and does not introduce a new module. ZStack Cloud management nodes need to access the Internet so that they can call Alibaba Cloud Public Cloud APIs.

Physical connection-based deployment: uses physical connections to establish local-remote inter-connected networks, thereby connecting a local data center with Alibaba Cloud Public Cloud.
Figure 1. Physical Connection-based Deployment


Architecture

ZStack Cloud Hybrid Cloud includes the following sections:

  • Identity Authentication:
    Alibaba Cloud AccessKey: integrates Resource Access Management of Alibaba Cloud Public Cloud / Private Cloud. A user authorized with an Alibaba Cloud AccessKey pair can access remote resources on Alibaba Cloud.
    Figure 2. Identity Authentication


  • Network Interconnection:

    You can use IPsec tunnels or Alibaba Cloud Express Connect to connect local Private Cloud with Alibaba Cloud Public Cloud. This way, local-remote L3 networks can access each other. The Local-remote network interconnection is the foundation of ZStack Cloud Hybrid Cloud.

    ZStack Cloud Hybrid Cloud allows you to use IPsec tunnels or Alibaba Cloud Express Connect to establish interconnected networks.
    Figure 3. IPsec Tunnel


    Figure 4. Alibaba Cloud Express Connect


  • Resource Management:
    You can authorize a RAM user to manage Alibaba Cloud Public Cloud resources, including ECS instances, VBR, VPC, and virtual switches.

    Resource Management



  • Business Implementation:

    The identity authentication, network interconnection, and resource management mechanisms help establish a flexible and elastic business system architecture. After the hybrid cloud platform is established, you can deploy flexible and multi-dimensional business modes on it.

Characteristics

ZStack Cloud Hybrid Cloud have the following characteristics:
  • Seamless integration:

    ZStack Cloud Hybrid Cloud seamlessly integrates Alibaba Cloud Public Cloud. Combined with the benefits of ZStack Cloud Private Cloud, it provides users a platform to manage both public clouds and private clouds in a unified way.

  • Seamless upgrading:

    ZStack Cloud Hybrid Cloud allows seamless upgrading without affecting business continuity.

  • Easy to use:

    ZStack Cloud Hybrid Cloud seamlessly integrates cloud services and terminals in a unified cloud platform. You can easily manage local private clouds and access resources on the public cloud as needed.

Scenarios

  • Data backup on the Cloud

    Financial, medical and some other industries have a high requirement for the compliance of long-term data storage. However, backing up data in local data centers is relatively risky, cost-consuming, and hard for O&M. To deal with these problems, ZStack Cloud Hybrid Cloud helps you back up the data to the Cloud, providing you with a stable data storage service at a lower cost.

  • Data storage on Cloud

    Enterprises and institutions need to store large amounts of data. In these scenarios, you can use ZStack Cloud Hybrid Cloud to store data on Cloud. This solution lowers your investment and management costs and allows data access from multiple regions and zones.

  • Data migration on Cloud

    High data negotiability is important to some enterprises and institutions whose works are finished based on multi-regional cooperation. In these scenarios, you can use ZStack Cloud Hybrid Cloud to migrate data to Cloud, thus ensuring a stable data transmission and data integrity.

Sync Data

After adding data center resources, you can synchronize corresponding resources on Alibaba Cloud to ZStack Cloud for local managements.

  • Make sure that you have added available regions and zones to ZStack Cloud before you synchronize data.
  • You can synchronize the resources that can be accessed with the current AccessKey and in the added regions and zones, such as ECS instances, volumes, VPCs, vSwithes, security groups, EIPs, VPNs, virtual boarder routers, and router interfaces.
  • When you add a region or a zone to ZStack Cloud for the first time, the resources are automatically synchronized to local.
  • The data synchronization takes a relatively long time when you have added multiple regions or zones.

Create ECS Instance

On the Quick Start Wizard page, click the Create button below the Create ECS Instance card. Then, you begin to create an ECS instance with the quick start wizard.

To create an ECS instance, follow these four steps:
  1. Select Region
    In the Select Region section, set the following parameters:
    • Region: Select a region can be accessed with your Alibaba Cloud AccessKey.
    • Zone: Select an availability zone in the region.
    Note:
    • If you have added no region or zone can be accessed with the current AccessKey to local, you can click the link below the selection box to add corresponding resources.
    • After you add regions and zones, ZStack Cloud synchronizes resources in these regions and zones to local.
    Figure 6. Select Region


  2. Select Image
    In the Select Image section, set the following parameters:
    • Add Type: Choose to use an Alibaba Cloud system image or a custom image.
      • If you are creating an ECS instance for the first time and pursuing a high creation efficient, we recommend that you use an Alibaba Cloud system image.
      • To use a custom image, you need to upload it to Alibaba Cloud via OSS, which takes a relatively long time.
    • Image: Select an image in Alibaba Cloud servers.
    Figure 7. Select Image


  3. Select VPC
    In the Select VPC section, set the following parameters:
    • VPC: Select a VPC for the ECS instance.
    • vSwitch: Select a vSwitch associated with the VPC.
      Note: You can select a vSwitch in the zone you selected in the first step.
    • Security Group: Select a security group according to actual requirements. Make sure that the security group port or protocol allows the private network on ZStack Cloud Private Cloud to pass it.
    Figure 8. Select VPC


  4. Create ECS Instance
    In the Create ECS Instance section, set the following parameters:
    • Name: Enter a name for the ECS instance.
    • Description: Optional. Enter a description for the ECS instance.
    • Image: Displays the image you select in the step 2.
    • Security Group: Displays the security group you select in the step 3.
    • vSwitch: Displays the vSwitch you select on the step 3.
    • Instance Offering: Select an instance offering for the ECS instance. An instance offering is a unit of definitions on ECS instance CPU and memory synchronized from Alibaba Cloud.
    • Private IP: Optional. Specify a static IP address on the private network for the ECS instance.
      • The IP address you enter cannot be used by existing ECS instances.
      • Below this input box, ZStack Cloud displays the CIDR of the vSwithch you select and the number of available IP addresses for your reference.
    • Public IP: Optional. Choose whether to allocate the ECS instance with a public IP. Defalut: Not Allocate. If you set it to Allocate, set a network bandwidth for the ECS instance.
    • Console Password: Enter a 6-character long password that contains digits, lower-case, and upper-case letters.
    • System User Password: Enter a system user password for the ECS instance. The password must be 8 to 30 characters in length and contain at least 3 character types of upper-case letters, lower-case letters, digits, and special characters.
      Note:

      By default, the system user name of a Linux-based ECS instance is root; the system user name of a Windows-based ECS instance is administrator. To log in to the ECS instance, you need to enter the system user name and the password you set here.

    Figure 9. Create ECS Instance


Establish VPN Connection

On the Quick Start Wizard page, click the Create button under the Establish VPN Connection card. Then, you begin to create a VPN connection with the quick start wizard.

To create a VPN connection, follow these steps:
  1. Select Alibaba Cloud Network

    In the Select Alibaba Cloud section, set the following parameters:

    • VPN Gateway (Alibaba Cloud): Choose a VPN gateway purchased on Alibaba Cloud Console.
      Note: If no VPN gateway is available in the selected region, you need to purchase one on Alibaba Cloud Console.
    Figure 10. Select Alibaba Cloud Network


  2. Connection Configuration
    In the Connection Configuration section, set the following parameters:
    • Name: Enter a name for the VPN connection.
    • Description: Optional. Enter a description for the VPN connection.
    • IKE Preshared Key: We recommend that you set a strong key.
    • VPC vRouter (ZStack): Select a VPC vRouter to create the VPN connection.
    • Public Network (ZStack): Select the public network the VPC vRouter attached to.
    • NAT Device: Choose whether an NAT device is used in your local network environment.
      • If an NAT device is used, set the following parameters:
        • Pre-NAT IP: A public network IP used to create the IPsec tunnel. Enter an IP address that can be used to access the public network.
        • Post-NAT IP: The IP address of the VPN customer gateway used to create the IPsec tunnel. Enter an IP address that is transformed from the source IP address (Pre-NAT IP) and can access the Internet directly.
        Note: Make sure that the post-NAT IP is the definite transformation result of the pre-NAT IP (source IP address) in your local network environment.
      • If no NAT device is used, set the following parameters:
        • IP Address: Optional. An available public network IP for the IPsec tunnel. Enter an IP address of the public Internet. If you do not set it, the system allocates an available public network IP randomly to create the IPsec tunnel.
    • Private Network (ZStack): Select L3 networks attached to the VPC vRouter. You can select up to 3 L3 networks.
    • Advanced: We recommend that you do not modify the advanced parameters for the default values can ensure the IPsec connectivity.
      • SA Lifetime (Second): 86400 (Default). Unit: second.
      • IPsec Encoding Algorithm: 3des (Default).
      • IPsec Authentication Algorithm: sha1 (Default).
      • IPsec DH Group: group2 (Default).
      • IKE Version: ikev1 (Default).
      • IKE Negotiation Mode: main (Default).
      • IKE Encoding Algorithm: 3des (Default).
      • IKE Authentication Algorithm: sha1 (Default).
      • IKE DH Group: group2 (Default).
    Figure 11. Connection Configuration




Check Connectivity

Log in to the local VM instance and check whether it can ping the ECS instance. Then, log into the ECS instance and check whether it can ping the local VM instance.
Note:
If you fail to create the VPN connection or the local VM instance and ECS instance cannot intercommunicate with each other, check the following points:
  • Check whether the local VIP used to create the IPsec connection is occupied. If it is occupied, delete this VIP.
  • Check whether an Alibaba Cloud VPN exists. If so, delete the VPN connection both from local and from Alibaba Cloud.
  • Check whether the Alibaba Cloud VPN customer gateway is allocated with a duplicated IP address. If so, delete the IP address both from local and from Alibaba Cloud.
  • Check whether the Alibaba Cloud VPC virtual router is configured with a route rule corresponding to the VPC network of ZStack CloudPrivate Cloud. If so, delete the route rule.

Create Alibaba Cloud Express Connect

To create an Alibaba Cloud Express Connect, follow these steps:
  1. Preparation
    Before you create an Alibaba Cloud express connect, configure networks on CPE IP, ZStack CloudPrivate Cloud, and Alibaba Cloud Public Cloud.
    • CPE IP Network Configuration

      To create an Alibaba Cloud express connect, you need to prepare a physical circuit leased from an operator. The operator is responsible to create a virtual border router and configure router interfaces.

      After configurations, you can obtain the following information:
      • Virtual Border Router (VBR): A router locating between the CPE device and the virtual router in Alibaba Cloud VPC.
      • VBR Interfaces: VBR interfaces consist of one interface connecting ZStack Cloud and one interface connecting Alibaba Cloud.
      • VPC vRouter Interface: The interface of the VPC vRouter.
      • CPE IP: The IP address of the CPE device provided by the ISP.
    • ZStack Cloud Private Cloud Network Configuration
      Before you configure the network on ZStack CloudPrivate Cloud, prepare following network CIDRs:
      • Private network CIDR: The private network CIDR manages the ZStack Cloud VM instance with the VPC vRouter.
      • Management network CIDR: The management network CIDR manages the VPC vRouter with the management node.
      • Public network CIDR: The public network CIDR is attached to the VPC vRouter to enable it to access the Internet.
      • Physical circuit CIDR: The physical circuit CIDR connects the VPC network, CPE IP, and Alibaba Cloud.
      Note: The public network can use a same CIDR with the management network.
      After preparing the CIDRs, you can configure networks on ZStack CloudPrivate Cloud.
      1. Create an L2 private network.
      2. Create an L3 private network (VPC network).
      3. Create an L2 management network.
      4. Create an L3 management network (public network).
      5. Create an L2 public network.
      6. Create an L3 public network (public network).
      7. Create a VM instance on ZStack CloudPrivate Cloud.
      8. Create a VPC vRouter and attach it to the public network.
      9. Create an L2 physical circuit network.
      10. Create an L3 physical circuit network.
      11. Attach the physical circuit network to the VPC vRouter.

      After you finish configurations on ZStack CloudPrivate Cloud, configure routes on the CPE device.

    • Alibaba Cloud Public Cloud Network Configuration
      Make sure that you have following resources on Alibaba Cloud before you make configurations:
      • VPC.
      • vSwitch associated with the VPC.
      • ECS instance.
      With these resources, you can make network configurations on Alibaba Cloud.
  2. Configure ZStack Cloud Network

    On the Quick Start Wizard page, click the Create button under the Create Alibaba Cloud Express Connect card. Then, you begin to create an Alibaba Cloud express connect with the quick start wizard.

    Set the following parameters:
    • VPC vRouter: Select a local VPC vRouter.
    • Public Network: Select a network that can connect the local data center with the VBR interface.
    • VPC Network: Select a local VPC network.
  3. Configure Alibaba Cloud Network
    Set the following parameters:
    • VPC: Select a VPC.
    • Virtual Border Router: Select a virtual border router. The virtual border router is created and configured with routes by the ISP.
    • CPE IP (ISP): The IP address of the client device that is provided by the ISP and used to connect the physical circuit to the local data center.
    During the express connect creation, ZStack Cloud automatically configures the following 4 routes:
    • VPC Custom Route1: The destination address is ZStack Cloud Private Network CIDR. The next hop is the interface of the VPC virtual router.
    • VBR Custom Route1: The destinaion address is ZStack Cloud Private Network CIDR. The next hop is the VBR interface connecting ZStack CloudPrivate Cloud.
    • VBR Custom Route2: The destination address is ECS VPC CIDR. The next hop is the VBR interface connecting Alibaba Cloud.
    • VPC Custom Route2: The destination address is ECS VPC CIDR. The next hop is the IP address of the CPE device.
  4. Configure routes on CPE device.
    You need to manually configure two routes on the CPE device.
    • CPE Custom Route1: The destination address is ZStack Cloud Private Network CIDR. The next hop is the physical circuit IP of the VPC vRouter.
    • CPE Custom Route2: The destination address is ECS VPC CIDR. The next hop is the physical circuit address.

Check the connectivity.

Log in to the local VM instance and check whether it can ping the ECS instance. Then, log in to the ECS instance and check whether it can ping the local VM instance. If the local VM instance and the ECS instance can ping each other, it means that the Alibaba Cloud express connect is created successfully.

Create an ECS Instance

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Products > ECS Instance. On the ECS Instance page, click Create ECS Instance. Then, the Create ECS Instance page is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the ECS instance.
  • Description: Optional. Enter a description for the ECS instance.
  • Quantity: Select the number of the ECS instances you want to create.
  • Image: Select an image on Alibaba Cloud. You can select an Alibaba Cloud image or a custom image.
  • Security Group: Select a security group for the ECS instance.
    Note: Make sure that the protocol or port of the security group allows the ZStack Cloud Private Cloud private network to pass it.
  • vSwitch: Select a vSwitch for the ECS instance.
  • Instance Offering: Select an instance offering for the ECS instance. An instance offering is a unit of definitions on ECS instance CPU and memory synchronized from Alibaba Cloud.
  • Private IP: Optional. Specify a static IP address for the ECS instance.
    • If you specify an IP address, make sure that the IP address is not used by existing ECS instances.
    • ZStack Cloud displays the CIDR of the vSwitch you select and the number of available IP addresses for your reference.
  • Public IP: Optional. Choose whether to allocate the ECS instance with a public IP. Default: Not Allocate. If you set it to Allocate, set a network bandwidth for the ECS instance.
  • Console Password: Enter a 6-character-long password that contains digits, lower-case, and upper-case letters.
  • System User Password: Enter a system user password for the ECS instance. The password must be 8 to 30 characters in length and contain at least 3 character types of upper-case letters, lower-case letters, digits, and special characters.
    Note:

    By default, the system user name of a Linux-based ECS instance is root; the system user name of a Windows-based ECS instance is administrator. To log in to the ECS instance, you need to enter the system user name and the password you set here.

Figure 12. Create an ECS Instance


Note:
  • You can only use an instance offering synchronized from Alibaba Cloud.
  • If the custom image you use does not satisfy the Alibaba Cloud image specifications, you cannot start the ECS instance created from this image.

Manage an ECS Instance

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Products > ECS Instance. Then, the ECS Instance page is displayed.

The following lists the actions that you can perform on an ECS instance:
Action Description ECS Instance State
Edit ECS Instance Edit the name and description of an ECS instance. Running/Stopped
Create ECS Instance Create one or more ECS instances. /
Start ECS Instance Start a stopped ECS instance. Stopped
Stop ECS Instance Stop a running ECS instance. Running
Reboot ECS Instance Reboot a running ECS instance. Running
Launch Console Launch the console of an ECS instance. You need following passwords to log in to the ECS system:
  • Console Password: After entering the console password, click Connect to connect the ECS console.
  • User Password: Enter the user password you set when creating the ECS instance.
    Note:

    By default, the user name of a Linux-based ECS instance is root; the user name of a Windows-based ECS instance is administrator. You need to enter a correct user name and password on the console to log in to the ECS system.

Running
Set Console Password Set a console password for an ECS instance. The new password takes effect immediately.
Note: The password must be 6-character-long and contain digits, lower-case, and upper-case letters. You cannot put a special character in the password.
Running/Stopped
Modify System User Password Modify the system user password of an ECS instance. The new password takes effect after the ECS instance restarts.
Note:
  • You need to restart the ECS instance to make the new system user password to take effect.
  • By default, the user name of a Linux-based ECS instance is root.
  • By default, the user name of a Windows-based ECS instance is administrator.
Running
Delete ECS Instance Delete an ECS instance.
Note:
  • By default, only the local record of the ECS instance is deleted. If you want to delete the ECS instance on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.
  • If the ECS instance is attached with data disks which are set to Delete with ECS instance, these disks are deleted simultaneously.
/

Create a Disk

Log in to ZCF, switch to the corresponding region, and then on the main menu, click Products > Disk. On the Disk page, click Create Disk. Then, the Create Disk page is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the disk.
  • Description: Optional. Enter a description for the disk.
  • Disk Type: Choose a disk type. Valid values: Ultra Cloud Disk and SSD Disk.
  • Zone: Specify a zone the disk resides on.
  • Capacity: Set the disk capacity. Unit: GB.
Figure 13. Create a Disk


Manage a Disk

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Products > Disk. Then, the Disk page is displayed.

The following lists the actions you can perform on a disk.
Action Description
Create Disk Create a disk.
Edit Disk Edit the name and description of a disk.
Attach Disk Attach a disk to an ECS instance.
Note:
  • You can attach only data disks to ECS instances.
  • You can attach disks to running/stopped ECS instances.
Detach Disk Detach a disk from an ECS instance.
Delete Disk Delete a Disk.
Note:
  • By default, only the local record of the disk is deleted. If you want to delete the disk on Alibaba Cloud, select the checkbox of Delete Reosurces on Alibaba Cloud.
  • You cannot delete a system disk.
  • If a data disk is attached to an ECS instance, you can set whether to make it deleted with the ECS instance when the ECS instance is deleted.

Upload an Image

Preparations:
  • Make sure that you have a local image and a default Bucket in the corresponding region.
  • The uploaded image needs to satisfy the image requirements of Alibaba Cloud. For more information, see the document Instructions for importing images provided by Alibaba Cloud.

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > Image. On the Image page, click Upload Image. Then, the Upload Image is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the image.
  • Description: Optional. Enter a description for the image.
  • OS: Select the image operating system.
  • OS Type: Select the image operating system type.
  • Image: Select an image in a local image storage.
  • Region: Select a region that the image is uploaded to.
  • Bucket: The default Bucket in the region is displayed automatically.
Figure 14. Upload an Image


Manage an Image

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > Image. Then, the Image page is displayed.

The following lists the actions you can perform on an image.
Action Description
Edit Image Edit the name and description of an image.
Note: You cannot edit an Alibaba Cloud image.
Upload Image Upload a local image to Alibaba Cloud.
Note: Add a Bucket in the corresponding region before you upload the image.
Delete Image Delete an image.
Note:
  • By default, only the local record of the image is deleted. If you want to delete the image on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.
  • You cannot delete an Alibaba Cloud image.

Create a Security Group

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > Security Group. On the Security Group page, click Create Security Group. Then, the Create Security Group page is displayed.

On the displayed page set the following parameter:
  • Name: Enter a name for the security group.
  • Description: Optional. Enter a description for the security group.
  • VPC: Choose a VPC.
  • Initial Rule: Choose an initial rule for the security group. Following four rules are supported:
    • Prohibit All: Prohibits ingress and egress flows from all ports.
    • Allow All: Allows ingress and egress rules flows from all ports.
    • Disable Some Vulnerable Ports: Prohibits only ingress flows from vulnerable ports, such as 135,137, 139, 42, and 445 (Protocol: UDP or TCP).
    • Allow Commonly Used Ports: Allows only ingress flows from commonly used ports, such as 22, 23, 3389, 443, 80, 6379, 8080, 3306, and 1433 (Protocol: UDP or TCP).
Figure 15. Create a Security Group


Security Group Rule

On the Security Group page, click the name of a security group. Then, the security group details page is displayed. On the Rule tab of the details page, click Add Rule. Then, the Add Rule page is displayed.

On displayed page, set the following parameters:
  • NIC Type: Intranet (Default).
  • Rule Direction: Displays the direction you add the rule to.
  • Authorization Policy: Select an authorization policy. Valid values: Accept and Reject.
  • Protocol: Choose a protocol. Valid values: All, TCP, UDP, ICMP, and GRE. You can choose ALL to allow mutual communications among ECS instances in the group.
  • Port Range: Enter the port range the rule takes effect on.
    Note: The port range is affected by the protocol.
    • ALL: The port range is fixed as -1/-1. This value means no limitation on ports.
    • TCP/UDP: The valid port range is 1~65535 by default. Format: m/n (m must be smaller than n). For example, 1/200 means that the port range is 1~200. If you enter 200/1, an error occurs.
    • ICMP: The port range is fixed as -1/-1. This value means no limitation on ports.
    • GRE: The port range is fixed as -1/-1. This value means no limitation on ports.
  • Authorization Objects: Enter an intranet CIDR the rule takes effect on.
    Note:
    • Enter a CIDR as needed.
    • If you enter 0.0.0.0/0, you allow or reject accesses from all IP addresses. Exercise caution.
  • Priority: Set a priority for the rule. Valid values: 1-100. 1 represents the highest priority. Default: 1.
Figure 16. Add Rule


Manage a Security Group

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > Security Group. Then, the Security Group page is displayed.

The following lists the actions you can perform on a security group.
Action Description
Edit Security Group Edit the name and description of a security group.
Create Security Group Create a new security group.
Delete Security Group Delete a security group.
Note: By default, the local record of the security group and ECS instances associated with the security group are deleted. If you want to delete the security group on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.

Create a VPC

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > VPC. On the VPC page, click Create VPC. Then, the Create VPC page is displayed.

On the displayed page, set the following parameter:
  • Name: Enter a name for the VPC.
  • Description: Optional. Enter a description for the VPC.
  • Region: Choose a region for the VPC.
  • CIDR: Choose a CIDR as needed.
    Note:

    After you choose the region, ZStack Cloud displays available CIDR ranges in this region for your reference.

Figure 17. Create a VPC


Manage a VPC

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > VPC. Then, the VPC page is displayed.

The following lists the actions you can perform on a VPC.
Action Description
Edit VPC Edit the name and description of a VPC.
Create VPC Create a VPC.
Delete VPC Delete a VPC.
Note:
  • By default, only the local record of the VPC is deleted. If you want to delete the VPC on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.
  • Deleting a VPC also deletes ECS instances associated with the VPC.
  • If you have a paid resource (such as a VPN gateway or a physical circuit) associated with a VPC, you may fail to delete the VPC.
Create Express Connect Create an express connect based on the VPC.
Note:
  • Configure a connection environment and synchronize router interfaces before you create an express connect.
  • After creating an express connect, you need to configure two routes on the CPE device and check whether the local VM instance and ECS instance can ping with each other. If VM instance and ECS instance can ping each other, the express connect is created successfully.
Establish VPN Connection Create an IPsec connection based on the VPC.
Note: The CIDRs from the local vRouter and Alibaba Cloud VPC which use the IPsec connection to realize an intercommunication cannot overlap with each other.

vSwith

On the VPC page, click a VPC name. On the displayed VPC details page, choose vSwitch > Create vSwitch. Then, the Create vSwitch page is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the vSwitch.
  • Description: Optional. Enter a description for the vSwitch.
  • Zone: Choose the zone where the VPC resides.
  • CIDR: Enter a CIDR for the vSwitch. The vSwitch CIDR is a sub-CIDR of the VPC. For example, if the VPC CIDR is 172.16.0.0/12, you can set the vSwitch CIDR as 172.22.0.0/16. The system displays the VPC CIDR for your reference.
Figure 18. Create a vSwitch


Manage a vSwitch

On the VPC page, click a VPC name. On the displayed VPC details page, choose vSwitch. Then, the vSwitch tab page is displayed.

The following lists the actions you can perform on a vSwitch.
Action Description
Edit vSwitch Edit the name and description of a vSwitch.
Create vSwitch Create a vSwitch.
Delete vSwitch Delete a vSwitch.
Note:
  • By default, only the local record of the vSwitch is deleted. If you want to delete the vSwitch on Alibaba Cloud, select the checkbox of Delete Reources on Alibaba Cloud.
  • Deleting a vSwitch also deletes its associated ECS instances.

vRouter

On the VPC page, click a VPC name. On the displayed VPC details page, choose vRouter. Then, the vRouter tab page is displayed.

The following lists the actions you can perform on a vRouter.
Action Description
Edit vRouter Edit the name and description of a vRouter.
Add Route Entry Add a route entry to a vRouter on its details page.
Delete Route Entry Delete a route entry of a vRouter on its details page.
Note:
  • By default, the local record of the route entry and the route entry on Alibaba Cloud are deleted.
  • You cannot delete a system route entry.

Create an EIP

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > EIP. On the EIP page, click Create EIP. Then, the Create EIP page is displayed.

On the displayed page, set the following parameters:
  • Region: Choose a region for the EIP.
  • Name: Enter a name for the EIP.
  • Description: Optional. Enter a description for the EIP.
  • Bandwidth: Set a bandwidth for the EIP. Unit: M.
Figure 19. Create an EIP


Manage an EIP

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > EIP. Then, the EIP page is displayed.

The following lists the actions you can perform on an EIP.
Action Description
Edit EIP Edit the name and description of an EIP.
Create EIP Create an EIP.
Attach ECS Instance Attach an EIP to an ECS instance.
Detach ECS Detach an EIP from an ECS instance.
Delete EIP Delete an EIP.
Note: By default, only the local record of the EIP is deleted. If you want to delete the EIP on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.

What is VPN?

VPN is an abbreviation for Virtual Private Network. As the name suggests it is a virtual network created over the internet/public network between two or more physical networks (or devices) to create an extended private network. This helps users/devices send and receive data as if the users are in one directly connected private network. This means that applications in a VPN can get the same functionalities and be managed in the same manner as in a private network.
Note: The CIDRs from the local vRouter to Alibaba Cloud which use the IPsec VPN to realize an intercommunication cannot overlap with each other.

Scenario

Figure 20. IPsec VPN Scenario


Main Procedures

To use ZStack Cloud an IPsec VPN to realize an intercommunication between the local VPC and Alibaba Cloud VPC, follow these steps:
  1. In ZStack Cloud Hybrid Cloud Management, add a region, zone, VPC, and vSwitch associated with the VPC in order.
  2. Purchase a VPN gateway on Alibaba Cloud Console.
  3. Create a Private Cloud VM instance on the VPC netwrok.
  4. Create an ECS instance.
  5. Follow Quick Start Wizard to establish a VPN connection.
    1. Select the purchased VPN gateway. The system can figure out the region, zone, VPC, and vSwitch corresponding to the VPN gateway.
    2. Finish the connection configuration: Select the VPC vRouter automatically created when you create the local VM instance. Select the public network and VPC network the VPC vRouter attached to and enter the pre-shared key. Advanced parameters are automatically configured. We recommend that you do not change these default values.
    3. After the connection configuration, ZStack Cloud automatically finish the following actions:
      1. Selects an available VIP on the public network corresponding to the VPC vRouter.
      2. Uses this VIP to create a VPN customer gateway.
      3. Establishes a VPN connection on Alibaba Cloud.
      4. Configures routes for the Alibaba Cloud VPC virtual router. The destination CIDR is the CIDR of the VPC network the local VPC vRouter attached to. The next hop is VPN Gateway.
      5. Establishes an IPsec connection on ZStack CloudPrivate Cloud.
  6. Check whether the local VM instance and the ECS instance can ping each other. If so, the IPsec VPN is created successfully.

Manage a VPN Gateway

On the main menu of ZStack Cloud Hybrid Cloud Management, choose VPN > VPN Gateway. Then, the VPN Gateway page is displayed.

The following lists the actions you can perform on a VPN gateway:
Action Description
Edit VPN Gateway Edit the name and description of a VPN gateway.
Delete VPN Gateway Delete a VPN gateway.
Note: By default, only the local record of the VPN gateway is deleted. You cannot delete the VPN gateway on Alibaba Cloud.

Create a VPN Customer Gateway

On the main menu of ZStack Cloud Hybrid Cloud Management, choose VPN > VPN Customer Gateway. On the VPN Customer Gateway page, click Create VPN Customer Gateway. Then, the Create VPN Customer Gateway page is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the VPN customer gateway.
  • Description: Optional. Enter a description for the VPN customer gateway.
  • ZStack IP: Enter a VIP on the public network corresponding to local VPV vRouter. You need to create the VIP on ZStack CloudPrivate Cloud in advance.
  • Region: Select the region the VPN gateway resides on.
Figure 21. Create a VPN Customer Gateway


Manage a VPN Customer Gateway

On the main menu of ZStack Cloud Hybrid Cloud Management, choose VPN > VPN Customer Gateway. Then, the VPN Customer Gateway page is displayed.

The following lists the actions you can perform on a VPN customer gateway.
Action Description
Edit VPN Customer Gateway Edit the name and description of a VPN customer gateway.
Create VPN Customer Gateway Create a VPN customer gateway.
Delete VPN Customer Gateway Delete a VPN customer gateway.
Note: By default, only the local record of the VPN customer gateway is deleted. If you want to delete the VPN customer gateway on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.

Establish a VPN Connection

On the main menu of ZStack Cloud Hybrid Cloud Management, choose VPN > VPN Connection. On the VPN Connection page, click Establish VPN Connection. Then, the Establish VPN Connection is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the VPN connection.
  • Description: Optional. Enter a description for the VPN connection.
  • VPC vRouter: Select a VPC vRouter for the VPN connection. You can select multiple L3 network attached to the VPC vRouter to establish the VPN connection.
    Note: If you select multiple L3 networks to establish the VPN connection. An IPsec tunnel attached with multiple sub nets is created on local and multiple VPN connections are created on Alibaba Cloud.
  • Private Network (ZStack): Select L3 networks attached to the VPC vRouter. You can select multiple L3 networks.
  • VPN Gateway (Alibaba Cloud): Select a purchased Alibaba Cloud VPN gateway.
  • Customer Gateway (Alibaba Cloud): Select an Alibaba Cloud Customer Gateway.
  • Pre-Shared Key: We recommend that you set a strong key.
  • Advanced: We recommend that you do not change default values of advanced parameters for they ensure the intercommunication between the local VPC network and Alibaba Cloud VPC.
    • IPSec SA Lifetime: 86400 (Default). Unit: second.
    • IPsec Encoding Algorithm: 3des (Default).
    • IPsec Authentication Algorithm: sha1 (Default).
    • IPsec DH Group: group2 (Default).
    • IKE SA Lifetime: 86400 (Default). Unit: second.
    • IKE IP of Alibaba Cloud: The Alibaba Cloud VPN gateway IP is automatically entered here.
    • IKE IP of ZStack: The Alibaba Cloud customer gateway IP is automatically entered here.
    • IKE Version: ikev1 (Default).
    • IKE Negotiation Mode: main (Default).
    • IKE Encoding Algorithm: 3des (Default).
    • IKE Authentication Algorithm: sha1 (Default).
    • IKE DH Group: group2 (Default).
Figure 22. Create a VPN Connection


Manage a VPN Connection

On the main menu of ZStack Cloud Hybrid Cloud Management, choose VPN > VPN Connection. Then, the VPN Connection page is displayed.

The following lists the actions you can perform on a VPN connection.
Action Description
Edit VPN Connection Edit the name and description of a VPN connection.
Establish VPN Connection Establish a VPN connection.
Delete a VPN Connection Delete a VPN Connection
Note:
  • By default, only the local record of the VPN connection is deleted. If you want to delete the VPN connection on Alibaba Cloud, select the checkbox of Delete Resources on Alibaba Cloud.
  • If you fail to establish an IPsec VPN or the IPsec VPN cannot enable the intercommunication between the local VPC and Alibaba Cloud VPC and you want to reconfigure it, delete this VPC connection and check the following points:
    • Check whether the local VIP used to create the IPsec connection is occupied. If it is occupied, delete this VIP.
    • Check whether the Alibaba Cloud VPN connection exists. If so, delete the VPN connection both from local and from Alibaba Cloud.
    • Check whether the Alibaba Cloud VPN customer gateway is allocated with a duplicated IP address. If so, delete the IP address both from local and from Alibaba Cloud.
    • Check whether the Alibaba Cloud VPC virtual router is configured with a route rule corresponding to the VPC network of ZStack CloudPrivate Cloud. If so, delete the route rule.

What is Express Connect?

Express Connect helps you establish a fast, stable, secure, and private connection between your data center and a virtual private cloud (VPC). Express Connect circuits ensure secure data transmission, prevent network jitters, and reduce the potential for data breaches.

Alibaba Cloud Express Connect

An Alibaba Cloud Express Connect uses a physical circuit (a cable or optical fibers leased from an operator) to connect the local data center with the access point of Alibaba Cloud, thus enabling a fast stable and secure intercommunication between the local data canter and Alibaba Cloud VPC.
Note: The CIDRs from the local vRouter to Alibaba Cloud which use the express connect to realize an intercommunication cannot overlap with each other.
Figure 23. Alibaba Cloud Express Connect Architecture


An Alibaba Cloud express connect has the following advantages:
  • Low latency and high stability.
  • Supporting multiple access methods.
  • Supporting redundant lines.
  • Secure and reliable.

Express Connect Actions

The following lists the actions you can perform on an express connect:
  • Synchronize/Create router interfaces: You can synchronize router interfaces on Alibaba Cloud to local or create router interfaces on local.
  • Synchronize virtual border router (VBR): Synchronize VBRs from Alibaba Cloud to local for a central management.
  • Create Alibaba Cloud Express Connect:
    • You can follow Quick Start Wizard to create an express connect.
    • You can use a VPC to create an express connect on the VPC page and configure route entries.

Add a Router Interface

Router interfaces are categorized into two types:
  • Virtual Border Router Interface
  • VPC vRouter Interface

Add an Interface to a Virtual Border Router

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Express Connect > Router Interface. On the Router Interface page, click Add Router Interface. Then, the Add Router Interface is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the router interface.
  • Description: Optional. Enter a description for the router interface.
  • Specification: Set the bandwidth specification of the VBR interface on Alibaba Cloud.
  • Region: Choose the region where the corresponding Alibaba Cloud VPC virtual router resides.
  • Virtual Border Router: Choose a virtual border router.
  • Access Point: Choose an access point on Alibaba Cloud.
Figure 24. Add an Interface to a Virtual Border Router


Add an Interface to a VPC vRouter

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Express Connect > Router Interface > VPC vRouter. On the VPC vRouter tab page, click Add Router Interface. Then, the Add Router Interface page is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the router interface.
  • Description: Optional. Enter a description for the router interface.
  • Specification: Set the bandwidth specification for the router interface.
  • Region: Choose the region where the corresponding Alibaba Cloud VPC virtual router resides.
  • vRouter: Choose a VPC vRouter.
  • Access Point: Choose an access point for the router interface.
Figure 25. Add an Interface to a VPC vRouter


Configured router interfaces are displayed on the Router Interface page.
Figure 26. Router Interface


Sync VBR

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Express Connect > Virtual Border Router. On the Virtual Border Router page, click Sync VBR. Then, the sync VBR page is displayed.

On the displayed page, choose regions to synchronize the virtual border routers in these regions to local.

Synchronized virtual border routers are displayed in the Virtual Border Router page.
Figure 27. Virtual Border Router


Add a Router Entry

On the Virtual Border Router page, click a name of a virtual border router. On the displayed virtual border router details page, click Route Entry > Add Route Entry. Then, the Add Route Entry page is displayed.

On the displayed page, set the following parameters:
  • Destination Network: Enter a destination CIRR.
  • Next Hop Type: Choose a next hop type. Valid values: Route Interface, ECS Instance, VPN Gateway, and Physical Connection Interface.
  • Then, choose a next hop device.
Figure 28. Add a Route Entry


Manage a VBR

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Express Connect > Virtual Border Router. Then, the Virtual Border Router is displayed.

The following lists the actions that you can perform on a virtual border router (VBR).
Action Description
Edit VBR Edit the name and description of a VBR.
Sync VBR Synchronize a VBR and its route entries from Alibaba Cloud to local.
Modify Interconnection Address Modify the Alibaba Cloud gateway, local private gateway, and netmask used by a VBR.

What is Alibaba Cloud NAS?

Alibaba Cloud NAS is a network file storage service provided by Alibaba Cloud. Alibaba Cloud NAS conforms with the standard file access protocol, which allows users to use distributed file systems featuring unlimited capacity, performance expansion, single namespace, multiple shares, high reliability, and high availability.

ZStack Cloud seamlessly integrates Alibaba Cloud NAS. On ZStack Cloud Private Cloud, you can directly use the independently-deployed Pangu distributed storage service provided by Alibaba Cloud by adding an AliyunNAS primary storage.
Figure 29. ZStack Cloud Seamlessly Integrates Alibaba Cloud NAS


ZStack Cloud seamlessly integartes IaaS+NAS, loading Alibaba Cloud distributed storage service to Private Cloud and providing a new virtualized distributed storage solution.

An AliyunNAS primary storage works with an ImageStore image storage. To add an AliyunNAS primary storage, you need to finish following preparations: setting an Alibaba Cloud service gateway, adding an AK, creating an Alibaba CLoud file system, and adding permission groups and permission rules to control accesses to the file system.

AliyunNAS Primary Storage Advantages

  • Scalable

    The distributed architecture supports unlimited expansions of compute nodes and storage nodes.

  • High Performance

    The distributed architecture supports horizontal storage performance expansions.

  • Easy

    You can easily add an AliyunNAS primary storage on UI within several steps. And then, you can use it just like using other primary storage.

  • Reliable

    Compared with a self-built file storage, an AliyunNAS primary storage improves the data security and reduces your O&M costs.

AliyunNAS Primary Storage Deployment

To deploy an AliyunNAS primary storage, follow these steps:
  1. Finish following configurations in ZStack Cloud Hybrid Cloud Management if you add an AliyunNAS primary storage for the first time:
    1. Set an Alibaba Cloud service gateway.
    2. Add a Private Alibaba Cloud AccessKey and the Private Alibaba Cloud zone the Alibaba Cloud NAS file system resides on.
    3. Create a file system as the backend storage system of the AliyunNAS primary storage.
      • If you have deployed an NAS file system on Alibaba Cloud, you can directly add it to ZStack Cloud.
      • You can also create a new Alibaba Cloud NAS file system on ZStack Cloud.
    4. Create permission groups and rules for the file system to allow specified IP to access the file system.
      • If you have an existing permission group with permission rules on Private Alibaba Cloud, you can directly add the permission group to ZStack Cloud.
      • You can also create a permission group and permission rules on ZStack Cloud.
  2. Add an AliyunNAS primary storage on ZStack Cloud.
  3. Manage the AliyunNAS primary storage.

Create a File System

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Alibaba Cloud NAS > File System. On the File System page, click Create File System. Then, the Create File System page is displayed.

On the displayed page, set the following parameters:
  • Region: Choose a Private Alibaba Cloud region for the file system.
  • Creation Time: Choose to add an existing file system or create a file system.
    • Existing File System: If you have an NAS file system deployed on Alibaba Cloud, you can directly add it to ZStack Cloud.
      If you choose to add an existing file system, set the following parameters:
      • File System: Add the file system deployed on Alibaba Cloud to ZStack Cloud.
      • Name: Enter a name for the file system.
      • Description: Optional. Enter a description for the file system.
    • Create File System:

      You can also create a file system on ZStack Cloud.

      If you choose to create a file system, set the following parameters:
      • Name: Enter a name for the file system.
      • Description: Optional. Enter a description for the file system.
      • Storage Type: Choose a storage type. Valid values: Performance and Capacity.
      • Protocol Type: Choose a protocol type. Valid values: NFS and SMB.

Manage a File System

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Alibaba Cloud NAS > File System. Then, the File System page is displayed.

The following lists the actions you can perform on a file system.
Action Description
Edit File System Edit the name and description of a file system.
Create File System Create an Alibaba Cloud NAS file system as the backend storage system for an AliyunNAS primary storage.
Delete File System Delete a file system.
  • If the file system has been used as the backend storage system for an AliyunNAS primary storage, you cannot delete the file system.
  • If the file system has not been used as the backend storage system for an AliyunNAS primary storage, you can delete the file system.
  • Deleting a file system deletes both its local record and the actual recourse on Private Alibaba Cloud. Proceed caution.

Create a Permission Group

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Alibaba Cloud NAS > Permission Group. On the Permission Group page, click Create Permission Group. Then, the Create Permission Group page is displayed.

On the displayed page, set the following parameters:
  • Region: Select the Private Alibaba Cloud region where the NAS file system resides.
  • Creation Method: You can choose to add an existing permission group or create a permission group.
    • Existing Permission Group: If you have a permission group on Private Alibaba Cloud, you can add the permission group to ZStack Cloud Hybrid Cloud.
      Note: You can add only a classic network permission group.
      If you choose to add an existing permission group, set the following parameters:
      • Permission Group: Add the existing permission group to ZStack Cloud Hybrid Cloud.
      • Name: Enter a name for the permission group.
      • Description: Optional. Enter a description for the permission group.
      Figure 30. Add an Existing Permission Group


    • Create Permission Group:
      You can also create a permission group on ZStack Cloud Hybrid Cloud.
      Note: You can create only a classic network permission group.
      If you choose to create a permission group, set the following parameters:
      • Name: Enter a name for the permission group.
      • Description: Optional. Enter a description for the permission group.
      • Network Type: Classic (Default).
      Figure 31. Create a Permission Group


Create a Permission Rule

On the Permission Group page, click the name of a permission group. On the displayed permission group details page, choose Permission Group Rule > Create Permission Group Rule. Then, the Create Permission Group Rule page is displayed.

On the displayed page, set the following parameters:
  • Network CIDR: Specify an IP address or CIDR as the authorization object of the rule.
  • Priority: Valid values: 1-100. 1 represents the highest priority.
    Note: If you add more than one permission group rules to an authorization object, the rule with the highest priority takes effect.
  • Read/Write Rule: Choose to allow the authorization object to only read the file system (RDONLY) or to read and write in the file system (RDWR).

Manage a Permission Group

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Alibaba Cloud NAS > Permission Group. Then, the Permission Group is displayed.

The following lists the actions you can perform on a permission group.
Action Description
Edit Permission Group Edit the name and description of a permission group.
Create Permission Group Create a permission group.
Note: You can create only a classic network permission group.
Delete Permission Group Delete a permission group.
  • If a file system is used as the backend storage system for an AliyunNAS primary storage, you cannot delete the its permission groups.
  • If a file system is not used as the backend storage system for an AliyunNAS primary storage, you can delete its permission groups.
  • Deleting a permission group deletes both its local record and the corresponding actual resource on Private Alibaba Cloud. Exercise caution.

What is Data Center?

A data center involves regional resources such as Alibaba Cloud regions and availability zones.

Add a Region

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. On the Region page, click Add Region. Then, the Add Region page is displayed.

Add Alibaba Cloud Region

On the displayed page, set the following parameters:
  • Region Type: Choose Alibaba Cloud.
  • Region: Select an Alibaba Cloud Region can be accessed with the current AccessKey.
  • Description: Enter a description for the region.
Figure 32. Add Alibaba Cloud Region


Add Private Alibaba Cloud Region

  • Add Private Alibaba Cloud Region (AliyunNAS)
    On the displayed page, set the following parameter:
    • Region Type: Select Private Alibaba Cloud.
    • Type: Select AliyunNAS.
    • Region: Select a region which can be accessed with the current AccessKey.
    • Description: Enter a description for the region.
    Figure 33. Add Private Alibaba Cloud Region (AliyunNAS)


  • Add Private Alibaba Cloud Region (AliyunEBS)
    On the displayed page, set the following parameters:
    • Region Type: Choose Private Alibaba Cloud.
    • Type: Choose AliyunEBS.
    • Endpoint: Enter the domain name of the Ocean external service.
      Note:
      • Ocean provides an external service with HTTP RESTful APIs.
      • Syntax: http://Ocean_Server_Domain:Port/ocean/api;
      • Domain names varies according to regions.
    • Region: Enter a region can be accessed by the Private Alibaba Cloud AccessKey.
    • Description: Optional. Enter a description for the region.
    Figure 34. Add a Private Alibaba Cloud Region (Aliyun EBS)


Manage a Region

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. Then, the Region page is displayed.

The following lists the actions you can perform on a region.
Action Description
Add Region Add a region to ZStack Cloud Hybrid Cloud.
Delete Region Delete a region. After the deletion, the region is not managed on ZStack Cloud and its local record is deleted. You can synchronize the record by re-adding the region to local.

Add a Bucket

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. On the Region page, click a region to enter its details page. On the region details page, click Bucket > Add Bucket. Then, the Add Bucket dialog box is displayed.

On the displayed dialog box, set the following parameters:
  • Add Method: Choose Available Bucket or Create Bucket.
    If you choose Available Bucket, set these parameters:
    • Bucket: Select an available Bucket from the drop-down list.
    • Make Default: Set whether to make this Bucket the default Bucket in the region. You need to set one and only one default Bucket for a region. By default, the checkbox is selected.
    • Description: Optional. Enter a description for the Bucket.
    If you choose Create Bucket, set these parameters:
    • Bucket Name: Enter a name for the Bucket. The name cannot be used by other Buckets.
    • Make Default: Set whether to make the bucket the default Bucket in the region. You need to set one and only on default Bucket for a region. By default, the checkbox is selected.
    • Description: Optional. Enter a description for the Bucket.
Figure 35. Add a Bucket


Manage a Bucket

On the Region page, click the name of a region. On the displayed region details page, click Bucket. Then, the Bucket tab page is displayed.

The following lists the actions you can perform on a Bucket.
Action Description
Edit Bucket Edit the name and description of a Bucket.
Add Bucket Add a Bucket in a region.
Make Default Make a Bucket as the default bucket in a region.
Note: You can set one default Bucket per region. The default Bucket is used to upload local images to Alibaba Cloud.
Delete Bucket Delete a Bucket.
Note: By default, only the local record of the Bucket is deleted. If you want to delete the actual Bucket on OSS, select the checkbox of Delete Actual Resources on OSS.

Add Zone

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Zone. On the Zone page, click Add Zone. Then, the Add Zone page is displayed.

On displayed page, set the following parameters:
  • Region: Select a region can be accessed by the AccessKey.
  • Zone: Select an availability zone from the drop-down list.
  • Description: Enter a description for the zone. This is a required parameter.

Manage a Zone

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Zone. Then, the Zone page is displayed.

The following lists the actions you can perform on a zone.
Action Description
Add Zone Add a zone to a region.
Delete Zone Delete a zone. After the deletion, the zone is not managed on ZStack Cloud and its local record is deleted. You can synchronized the record by re-adding the zone to local.

What is AccessKey Management?

An AccessKey pair is an identity credential that has access to APIs of Alibaba Cloud or Private Alibaba Cloud. It has full access to the Cloud. An AccessKey pair consists of AccessKey ID and AccessKey secret.

You need to add an AccessKey on ZStack Cloud Hybrid Cloud to obtain Alibaba Cloud/Private Alibaba Cloud services with Alibaba Cloud/Private Alibaba Cloud APIs.
Note: AK is not an Alibaba Cloud account. Owning an AK does not represent that you own account resources. The resources are owned by the Alibaba Cloud account.

ZStack Cloud allows you to view the basic property of an AccessKey, such as its corresponding Alibaba Cloud root account ID and Alibaba Cloud Sub-Username.

Add an AccessKey

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > AccessKey Management. On the AccessKey Management page, click Add AccessKey. Then, the Add AccessKey page is displayed.

Add Alibaba Cloud AccessKey

On the displayed page, set the following parameters:
  • Addition Method: Choose Alibaba Cloud.
  • Name: Enter a name for the AccessKey.
  • Description: Optional. Enter a description for the AccessKey.
  • AccessKey ID: Enter the correct AccessKey ID of the Alibaba Cloud account.
  • AccessKey Secret: Enter the correct AccessKey Secret corresponding to the AccessKey ID.
Figure 36. Add Alibaba Cloud AccessKey


Add Private Alibaba Cloud AccessKey

On the displayed page, set the following parameters:
  • Addition Method: Choose Private Alibaba Cloud.
  • Name: Enter a name for the AccessKey.
  • Description: Optional. Enter a description for the AccessKey.
  • Type: Choose a Private Alibaba Cloud AccessKey type. Options: AliyunEBS and AliyunNAS.
  • AccessKey ID: Enter the AccessKey ID of a Private Alibaba Cloud account. Ensure the correctness of the AccessKey ID.
  • AccessKey Secret: Enter the AccessKey Secret corresponding to the AccessKey ID. Ensure the correctness of the AccessKey Secret.
Figure 37. Add a Private Alibaba Cloud AccessKey


Manage an AccessKey

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > AccessKey Management. Then, the AccessKey Management page is displayed.

The following lists the actions you can perform on an AccessKey.
Action Description
Edit AccessKey Edit the name and description of an AccessKey.
Add AccessKey Add an AccessKey.
Note:
  • The AccessKey added for the first time is automatically set as the default AccessKey.
  • AccessKey is not an Alibaba Cloud account. Owning an AccessKey does not represent that you own account resources. The resources are owned by the Alibaba Cloud account.
Set as Default Set an AccessKey as the default AccessKey.
Note: You can set only one AccessKey as the default AccessKey. The default AccessKey is used to call Alibaba Cloud/Private Alibaba Cloud APIs and control resources of the corresponding Alibaba Cloud account.
Cancel Default Setting No longer use an AccessKey as the default AccessKey.
Delete AccessKey Delete an AccessKey.

What is Hybrid Cloud Setting?

Global Setting allows you to configure settings that take effect on the whole platform.

On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > Hybrid Cloud Setting. Then, the Hybrid Cloud Setting is displayed.
Figure 38. Hybrid Cloud Setting


The following lists setting entries in Hybrid Cloud Setting.
Category Name Description
Alibaba Cloud EBS Garbage Collection Interval of Alibaba Cloud EBS Primary Storage Specifies the interval to clean up garbage data of Alibaba Cloud EBS primary storage. Default: 3600. Unit: second.
Timeout Period of Snapshot Import and Output The timeout period of importing and exporting snapshots in EBS primary storage. Default: 10800000. Unit: millisecond.
Rollback Imported Image Specifies whether to rollback related objects in OSS buckets if an error occurs when you upload custom images to Alibaba Cloud EBS Image Storage. Default: true. If set to false, the uploaded images are not rolled back if upload errors occur.
Alibaba Cloud NAS Garbage Collection Interval of Alibaba Cloud NAS Primary Storage The interval of collecting garbage data in NAS primary storage. Default: 3600. Unit: second.
NAS Primary Storage Ping Interval The interval that the management node pings NAS primary storages. Default: 180. Unit: second.
Alibaba Cloud ECS Alibaba Cloud Console Domain The access address of the Alibaba Cloud console. Default: ims.aliyuncs.com:443. When you add an AccesKey pair on the Hybrid Cloud, you need to check the connection of the management node to the Alibaba Cloud console.
Timeout Period of Alibaba Cloud Console Connection Test The timeout period of checking the connection of the management node to the Alibaba Cloud console. Default: 500. Unit: milliseconds. When you add an AccesKey pair on the Hybrid Cloud, you need to check the connection of the management node to the Alibaba Cloud console. If the management node does not connect to the Alibaba Cloud console, the addition fails.
Alibaba Cloud AccessKey Check User Info upon AccessKey Addition Specifies whether to check user information while adding an Alibaba Cloud AccessKey pair on the platform. Default: true.
Alibaba Cloud Image Custom Image Format The format of custom images uploaded to the Hybrid Cloud. Default: qcow2. Valid values: qcow2 and raw.
Alibaba Cloud Gateway Alibaba Cloud Gateway The custom gateway. Default: null. The gateway format is
oss::http://oss.api.com,ecs::ecs.api.com,nas::nas.endpoint.com
Alibaba Cloud Management Node Management Node Time Zone The time zone of the terminal address to which API requests are sent. Default: China.
Other Manageable Alibaba Cloud Regions The Alibaba Cloud regions that the cloud platform allows you to manage. Default: cn-shenzhen,cn-beijing,cn-shanghai,cn-hangzhou,cn-zhangjiakou,cn-qingdao,cn-huhehaote. Separate each region with a comma (,).
Advanced Features | Advanced Features · ZCF | ZStack Resource Center