What is Alibaba Cloud Hybrid Cloud Management?
Alibaba Cloud Hybrid Cloud Management provided by ZStack Cloud integrates the simple, strong, scalable, and smart (4S) features of ZStack Cloud Private Cloud and the advanced, secure, and stable features of Alibaba Cloud Public Cloud. It is a hybrid cloud management solution that seamlessly integrates cloud services and terminals, interconnecting the control panel and data panel.
Concepts
- ZStack Cloud Alibaba Cloud Hybrid Cloud Management
provides the following cloud computing products of Alibaba Cloud:
- ECS Instance: An elastic compute service (ECS) instance is a VM instance created on Alibaba Cloud.
- Disk: A disk provides storage space for an ECS instance created on Alibaba Cloud.
- Image: An image is a template file that is used to create ECS instances. Images are categorized into custom images and Alibaba Cloud images.
- Security Group: A security group provides security control services for ECS instances on the L3 network. It filters the inbound or outbound packets of ECS instances based on security rules.
- VPC: A virtual private cloud (VPC) is a private network dedicated for ECS instances created on Alibaba Cloud.
- EIP: An elastic IP address (EIP) is an IP address in Alibaba Cloud public networks. You can attach EIPs to ECS instances so that the ECS instances can access public networks by using the EIPs.
- VPN: Establishes a site-to-site IPsec VPN channel to enable communications
between private networks in a local data center and Alibaba Cloud VPC. This
section includes:
- VPN Gateway: A virtual private network (VPN) gateway establishes a secure connection between a local data center and Alibaba Cloud VPC by using an encrypted channel.
- VPN Customer Gateway: A VPN customer gateway provides services for a local data center.
- VPN Connection: A VPN connection is an encrypted communication channel established between a VPN gateway and VPN customer gateway.
- Express Connect: Express Connect uses physical circuits (electric cables or
optical fibers leased from operators) to connect local data centers with
Alibaba Cloud access points and Alibaba Cloud VPC. This way, private
networks on Alibaba Cloud and in local data centers can communicate with
each other in a fast, stable, and secure manner. This section includes:
- Router Interface: A router interface is a virtual device that is used to establish communication channels and control their status.
- Virtual Border Router: A virtual border router (VBR) is virtualized from a physical switch port on the access point of Alibaba Cloud. It forwards the data on the physical circuit to Alibaba Cloud VPC.
- Alibaba Cloud NAS: Alibaba Cloud NAS is a network-attached file storage
service. It provides highly reliable and available distributed file systems
that can be accessed by using standard file access protocols. In addition,
Alibaba Cloud NAS is scalable in storage space and performance and can be
managed in a namespace while shared with multiple users. ZStack Cloud seamlessly integrates with Alibaba Cloud NAS.
You can add primary storage of the AliyunNAS type on ZStack Cloud
Private Cloud so as to use the distributed
storage independently deployed on Alibaba Cloud. This section includes:
- File System: A file system is a backend storage system used for Alibaba Cloud NAS primary storage. Before you add an AliyunNAS primary storage, you need to add an NAS file system.
- Permission Group: A permission group is an allowlist of IP addresses or IP ranges which can access file systems according to specified permission rules.
- Data Center: Data centers are resources corresponding to Alibaba Cloud
regions and zones. These resources include:
- Region: A region is a physical data center. A region in ZStack Cloud Hybrid Cloud corresponds to a region in Alibaba Cloud.
- Zone: A zone is a physical area in a region that is independent from other zones in the region in terms of electricity and network supplies.
- Setting: ZStack Cloud Hybrid Cloud provides the
following basic settings:
- AccessKey Management: An AccessKey pair is an identity credential that has access to APIs of Alibaba Cloud or Private Alibaba Cloud. It has full access to the Cloud. An AccessKey pair consists of AccessKey ID and AccessKey secret.
- Hybrid Cloud Settings: Hybrid cloud settings allow you to configure settings that take effect on the whole platform.
Physical Deployment
ZStack Cloud Hybrid Cloud uses an in-process micro-service architecture and does not introduce a new module. ZStack Cloud management nodes need to access the Internet so that they can call Alibaba Cloud Public Cloud APIs.

Architecture
ZStack Cloud Hybrid Cloud includes the following sections:
- Identity Authentication:Alibaba Cloud AccessKey: integrates Resource Access Management of Alibaba Cloud Public Cloud / Private Cloud. A user authorized with an Alibaba Cloud AccessKey pair can access remote resources on Alibaba Cloud.
Figure 2. Identity Authentication 
- Network Interconnection:
You can use IPsec tunnels or Alibaba Cloud Express Connect to connect local Private Cloud with Alibaba Cloud Public Cloud. This way, local-remote L3 networks can access each other. The Local-remote network interconnection is the foundation of ZStack Cloud Hybrid Cloud.
ZStack Cloud Hybrid Cloud allows you to use IPsec tunnels or Alibaba Cloud Express Connect to establish interconnected networks.Figure 3. IPsec Tunnel 
Figure 4. Alibaba Cloud Express Connect 
- Resource Management:You can authorize a RAM user to manage Alibaba Cloud Public Cloud resources, including ECS instances, VBR, VPC, and virtual switches.
Resource Management

- Business Implementation:
The identity authentication, network interconnection, and resource management mechanisms help establish a flexible and elastic business system architecture. After the hybrid cloud platform is established, you can deploy flexible and multi-dimensional business modes on it.
Characteristics
- Seamless integration:
ZStack Cloud Hybrid Cloud seamlessly integrates Alibaba Cloud Public Cloud. Combined with the benefits of ZStack Cloud Private Cloud, it provides users a platform to manage both public clouds and private clouds in a unified way.
- Seamless upgrading:
ZStack Cloud Hybrid Cloud allows seamless upgrading without affecting business continuity.
- Easy to use:
ZStack Cloud Hybrid Cloud seamlessly integrates cloud services and terminals in a unified cloud platform. You can easily manage local private clouds and access resources on the public cloud as needed.
Scenarios
- Data backup on the Cloud
Financial, medical and some other industries have a high requirement for the compliance of long-term data storage. However, backing up data in local data centers is relatively risky, cost-consuming, and hard for O&M. To deal with these problems, ZStack Cloud Hybrid Cloud helps you back up the data to the Cloud, providing you with a stable data storage service at a lower cost.
- Data storage on Cloud
Enterprises and institutions need to store large amounts of data. In these scenarios, you can use ZStack Cloud Hybrid Cloud to store data on Cloud. This solution lowers your investment and management costs and allows data access from multiple regions and zones.
- Data migration on Cloud
High data negotiability is important to some enterprises and institutions whose works are finished based on multi-regional cooperation. In these scenarios, you can use ZStack Cloud Hybrid Cloud to migrate data to Cloud, thus ensuring a stable data transmission and data integrity.
Preparation
About this task
To use ZStack Cloud Hybrid Cloud Management, make the following preparations:Procedure
-
Purchase a license.
Purchase a license of Alibaba Cloud Hybrid Cloud Management and install it on ZStack Cloud.
-
Add the following items to your firewall allowlist so that the ZStack Cloud management node can access Alibaba Cloud
APIs:
- *.aliyuncs.com
-
Create an Alibaba Cloud account.
Create an Alibaba Cloud account. For more information, see Create an Alibaba Cloud Account.
If you are unfamiliar with the main account and sub-account system of Alibaba Cloud, see What is RAM. We recommend that you follow this process to finish the account creation:- Create a main account on Alibaba Cloud.
- Use the main account to log on to the Alibaba Cloud Console, and choose Access Control.
- On the navigation bar on the left, choose , and create a user named zstack-user.
- On the navigation bar, choose , and create a group named zstack-developer-group.
- Click the group you create, and click the
Permissions tab. On the displayed tab page,
click Grant Permission. Grant at least the
following permissions to the group:
- AliyunRAMFullAccess
- AliyunECSFullAccess
- AliyunEIPFullAccess
- AliyunVPCFullAccess
- AliyunOSSFullAccess
- AliyunExpressConnectFullAccess
- AliyunVPNGatewayFullAccess
- Click the Group Members tab and add the user you created to the group.
- On the navigation bar, click Users. On the User page, click the user you created. On the details page of the user, choose the Authentication tab page and click Create AccessKey. Then, an AccessKey pair is generated. Save the AccessKey ID and AccessKey Secret (AK) well for they will not be displayed again after you exist the creation page.
Note:
- ZStack Cloud does not record your Alibaba Cloud account information. It only uses the AK to call Alibaba Cloud APIs.
- We recommend that you comply with the RAM rules of Alibaba Cloud to improve the resource security.
- The most important security principle is Do not use the main account AK for any actions.
-
Apply for the permission to upload custom images.
On the main menu of Alibaba Cloud Console, click . On the Submit Ticket page, choose the question attribution as Elastic Compute Service. Choose question type as Image and Operating System. Then, choose Create/Delete Image and Import/Export Image. On the displayed page, enter a question description like "We are applying for your image import service. Please help add us to your image import allowlist." This ticket is proceeded manually, which takes quite some time.
-
Apply for the OSS service and create an OSS Bucket.
A ZStack Cloud image is stored in an Alibaba Cloud OSS before it is used to create an Alibaba Cloud ECS instance. You can use a Bucket in the OSS to upload ZStack Cloud images to Alibaba Cloud.
Note:
- Make sure that the ZStack Cloud images to be uploaded support Online Password Modification (Qemu-guest-agent).
- Make sure that the images do not use an EFI or LVM partitioning scheme.
- Make sure that the images encapsulate Linux or Windows operating systems.
-
Add Alibaba Cloud AccessKey to ZStack Cloud Hybrid
Cloud.
On the main menu of ZStack Cloud, choose . On the AccessKey Management page, click Add AccessKey, and add the Alibaba Cloud AccessKey you generated in the step3.
Note: The AccessKey added for the first
time is automatically set as the default AccessKey. -
Add a region.
On the main menu of Hybrid Cloud Management, choose and add an Alibaba Cloud region or a Private Alibaba Cloud region.
-
Synchronize data.
On the main menu of Hybrid Cloud Management, click Sync Data to synchronize data in the corresponding Alibaba Cloud data center to ZStack Cloud for a local management.
- Make sure that you have added a region and zone to ZStack Cloud Hybrid Cloud before you exercise the data synchronization.
- This action synchronizes the Alibaba Cloud resources that can be accessed with the AccessKey and in the added regions and zones, such as ECS instances, volumes, VPCs, vSwithes, security groups, images, EIPs, VPNs, virtual border routers, and router interfaces.
- ZStack Cloud automatically synchronized the resources in a region or zone when you add it to local for the first time.
- The data synchronization takes a relatively long time when you have added multiple regions and zones.
Getting Started
- Add AccessKey: Use the AccessKey to call the Alibaba Cloud APIs or Private Alibaba Cloud APIs.
- Add Region: After adding regions, you can specify regions to create ECS instances.
- Add Zone: After adding zones, you can specify zones to create ECS instances.
- Add Bucket: Use the Bucket to synchronize ZStack Cloud images to Alibaba Cloud OSS and upload the images to corresponding regions. If you only use Alibaba Cloud images instead of local images to create ECS instances, you do not need to add a Bucket.
- Create VPC: Create a VPC dedicated for ECS instances.
- Create Security Group: Create security groups for ECS instances.
- Create ECS Instance: Create ECS instances to provide compute services.
- Create VPC Network: Create a VPC network which is used to create VM instances on Private Cloud.
- Create VPN Connection: Use a VPN connection to enable the intercommunication between local Private Cloud VM instances and Alibaba Cloud ECS instances.
- Create Express Connect: Use an express connect to enable the intercommunication between Private Cloud VM instances and Alibaba Cloud ECS instances.
Practices
IPsec VPN Practice
About this task
ZStack Cloud allows you to create an IPsec VPN to enable the intercommunication between the VPC networks in the local data center and on Alibaba Cloud.
- In ZStack Cloud Hybrid Cloud Management, create the following resources in order: a region, a zone, a VPC, and a vSwitch associated with the VPC.
- Use a VPC network to create a Private Cloud VM instance.
- Create an ECS instance.
- Create a VPN connection.
- Check whether the Private Cloud VM instance can
pingthe ECS instance. If so, the IPsec tunnel is created successfully.

- Initialize ZStack CloudPrivate Cloud, adding basic resources like zones, clusters, hosts, backup storage, and primary storage.
- Purchase a VPN gateway on Alibaba Cloud Console.
- Local Public Network
Public Network Configuration NIC eth0 VLAN ID NoVLAN CIDR 192.168.25.0/24 Gateway 192.168.25.1 DHCP IP 192.168.25.2 - Management Network
Management Network Configuration NIC eth1 VLAN ID NoVLAN IP Address 172.20.58.50~172.20.58.59 Netmask 255.255.0.0 Gateway 172.20.0.1 - VPC Network
VPC Network Configuration NIC eth0 VLAN ID 1982 IP CIDR 10.10.224.0/24 DHCP IP 10.10.224.153 - Alibaba Cloud VPN customer gateway IP: 180.169.211.121
- Alibaba Cloud VPN gateway IP: 47.103.147.121
- The CIDR of the vSwitch associated with the VPN gateway: 172.31.0.0/16
The procedures are described in details as follows:
Procedure
- In ZStack Cloud Hybrid Cloud Management, create the following resources in order: a region, a zone, a VPC, and a vSwitch associated with the VPC.
- In ZStack CloudPrivate Cloud, create a VPC network and use the VPC network to create a VM instance on ZStack CloudPrivate Cloud.
- Create an ECS instance.
-
Create a VPN connection.
-
Check whether the local VM instance can
pingthe Alibaba Cloud ECS instance.On the main menu of Hybrid Cloud Management, choose . On the VPN Connection page, if the status of the VPN connection is Phase 2 negotiations succeeded, the IPsec VPN creation is finished. Then, you need to use the local VM instance to
pingthe ECS instance to check whether the creation is successful.
Note:
If the VPN connection is not created successfully, or the local VM instance and the ECS instance cannotpingeach other, check the following points before you reconfigure the VPN connection:- Check whether the local VIP used to create the IPsec connection is occupied. If it is occupied, delete this VIP.
- Check whether the Alibaba Cloud VPN connection exists. If so, delete the VPN connection both from local and from Alibaba Cloud.
- Check whether the Alibaba Cloud VPN customer gateway is allocated with a duplicated IP address. If so, delete the IP address both from local and from Alibaba Cloud.
- Check whether the Alibaba Cloud VPC virtual router is configured with a route rule corresponding to the VPC network of ZStack CloudPrivate Cloud. If so, delete the route rule.
What to do next
Now, you has established an IPsec VPN and enabled the intercommunication between the ZStack CloudPrivate Cloud VM instance and the Alibaba Cloud ECS instance.
Express Connect Practice
About this task
ZStack Cloud allows you to create an Alibaba Cloud express connect to enable the intercommunication between the VPC networks in local data center and on Alibaba Cloud.
- Prepare a physical circuit, a virtual border router, and router interfaces provided by an operator.
- Plan network CIDRs, including a public network CIDR, a management network CIDR, a physical circuit network CIDR, and a VPC network CIDR. The public network CIDR and the management network CIDR can be the same one.
- Use the local VPC network to create a VM instance on ZStack CloudPrivate Cloud.
- Attach the physical circuit network to a VPC vRouter.
- Prepare a VPC environment on Alibaba Cloud. Use the vSwitch associated with the Alibaba Cloud VPC to create an ECS instance.
- In ZStack Cloud Hybrid Cloud Management, add an AccessKey, regions, and zones, and synchronize corresponding resources.
- Use Quick Start Wizard to create an Alibaba Cloud express connect.
- Configure route rules for both Alibaba Cloud VPC virtual router and local VPC vRouter on the CPE device.
- Check whether the local VM instance and the Alibaba Cloud ECS instance can
pingeach other. If so, the express connect is created successfully.
Note: The CIDRs from the local VPC vRouter
to Alibaba Cloud VPC, which use the express connect to realize the
intercommunication, cannot overlap with each other.
- Public Network
Public Network Configuration NIC em01 VLAN ID NoVLAN IP Range 172.20.58.180~172.20.58.189 Netmask 255.255.0.0 Gateway 172.20.0.1 Note Private Cloud VM instance can use this network to access the Internet. - Physical Circuit Network
Physical Circuit Network Configuration NIC em02 VLAN ID NoVLAN IP Range 10.255.255.230~10.255.255.240 Netmask 255.255.255.0 Gateway 10.255.255.1 Note A new network. Private Cloud VM instances use this network to access Alibaba Cloud ECS instances. - Private Network
VPC Configuration NIC em01 VLAN ID 2984 IP CIDR 10.200.0.0/16 - The local IP address of the CPE device is 10.255.255.1
- The local IP address of the virtual border router is 10.240.1.1. The Alibaba Cloud IP address of the virtual border router is 10.240.1.2.
- The CIDR of Alibaba Cloud VPC is 192.168.0.0/16.
- Make local VM instance access Alibaba Cloud ECS instance.
- Configure the VPC route: On the VPC vRouter, set the route destination address as the ECS VPC CIDR, 192.168.0.0/16. Set the next hop as the IP address of the client CPE device, 10.255.255.1.
- Configure the CPE device custom route: On the CPE device, set the destination address as the ECS VPC CIDR, 192.168.0.0/16. Set the next hop as the address of the physical circuit.
- Configure VRB custom route 2: On the VRB, set the destination address as the ECS VPC CIDR, 192.168.0.0/16. Set the next hop as VRB interface2, which is the VRB interface on Alibaba Cloud.
- The Alibaba Cloud virtual router forwards the routes it receives to the ECS instance.
Figure 12. Route Configurations Enabling Local VM Instance to Ping Alibaba Cloud ECS Instance 
- Make Alibaba Cloud ECS instance access local VM instance.
- Configure the VPC custom route1: On the VPC virtual router on Alibaba Cloud, set the destination address as the CIDR of the ZStack Cloud VPC network, 10.200.0.0/16. Set the next hop as the VPC virtual router interface1.
- Configure the VBR custom route1: On the VBR, set the destination address as the CIDR of the ZStack Cloud VPC network, 10.200.0.0/16. Set the next hop as the VBR interface1, which is the VBR interface on ZStack Cloud.
- Configure the CPE custom route1: On the CPE device, set the destination address as the CIDR of the ZStack Cloud VPC network, 10.200.0.0/16. Set the next hop as the physical circuit IP address of the VPC vRouter, 10.255.255.240.
- The VPC vRouter forwards the routes it receives to the VM instance on ZStack CloudPrivate Cloud.
Figure 13. Route Configurations Enabling Alibaba Cloud ECS Instance Ping Local VM Instance 
Note:
- When you create an express connect, the following 4 routes are
automatically configured by ZStack Cloud:
- VPC Custom Route2 (Configured with Alibaba Cloud APIs)
- VBR Custom Route1 (Configured with Alibaba Cloud APIs)
- VBR Custom Route2 (Configured with Alibaba Cloud APIs)
- VPC Custom Route1 (Configured with local APIs)
- The following two routes on the CPE device need to be created
manually:
- CPE Custom Route1
- CPE Custom Route2
Note:
- This practice uses a same CIDR for both the public network and the management network.
- This practice enables VM instances on ZStack CloudPrivate Cloud access both the Internet and Alibaba Cloud ECS instances.
Procedure
- Create an L2 public network on ZStack CloudPrivate Cloud.
- Create an L3 public network on ZStack CloudPrivate Cloud.
- Create an L2 physical circuit network on ZStack CloudPrivate Cloud.
- Create an L3 physical circuit network on ZStack CloudPrivate Cloud.
- Create an L2 VPC network on ZStack CloudPrivate Cloud.
- Create an L3 VPC network on ZStack CloudPrivate Cloud.
- Use the VPC network to create a Private Cloud VM instance.
- Attach the physical circuit network to the VPC vRouter.
- Prepare the VPC environment on Alibaba Cloud, and use the vSwitch associated with the Alibaba Cloud VPC to create an ECS instance.
- In ZStack Cloud Hybrid Cloud Management, add an AccessKey, regions, and zones. Then, synchronize corresponding resources.
-
Use Quick Start Wizard to create an Alibaba Cloud express connect.
-
Manually configure 2 routes on the CPE device.
- Configure CPE custom route1: Set the destination address as the CIDR of ZStack Cloud VPC network. Set the next hop as the physical circuit IP of the VPC vRouter.
- Configure CPE custom route2: Set the destination address as the ECS VPC CIDR. Set the next hop as the physical circuit address.
-
Check whether the local VM instance and the ECS instance can
pingeach other.
What to do next
Now, you create an express connect successfully and can use it to enable the intercommunication between ZStack CloudPrivate Cloud VM instances and Alibaba Cloud ECS instances.
Hybrid Cloud Backup Practice
ZStack Cloud provides local backup, remote backup, and Public Cloud backup services in a separate module. You can choose a backup solution according to your business requirements.
For more information about backup services, see Backup Service Tutorial.
Hybrid Cloud Migration Practice
About this task
ZStack Cloud Hybrid Cloud Management allows you to migrate business VM instances on local Private Cloud to Alibaba Cloud Public Cloud.
- Create a local image based on the local VM instance.
- Upload the image to Alibaba Cloud.
- Use the image to create an ECS instance on Alibaba Cloud.
The procedures are described in details as follows:
Procedure
-
Create a local image based on the local VM instance.
On the main menu of ZStack CloudPrivate Cloud, choose . On the VM Instance page, locate the VM instance to be migrated. Click . On the Create Image page, set the following parameters:
- Name: Enter a name for the VM image.
- Description: Optional. Enter a description for the VM image.
- Image Type: Choose System Image.
- Backup Storage: Choose a backup storage to store the image.
Figure 16. Create Image 
Note: To ensure the application consistent, we recommend that you stop the VM
instance before you create the image. -
Upload the image to Alibaba Cloud.
- On Alibaba Cloud, use the image to create a business ECS instance. For more information, see Create an ECS instance by using a custom image.
What to do next
Now, you have finished the VM migration from ZStack Cloud Private Cloud to Alibaba Cloud Public Cloud.
AliyunNAS Primary Storage Deployment Practice
About this task
ZStack Cloud seamlessly integrates Alibaba Cloud NAS, restores the Alibaba Cloud centralized storage to distributed storage, and loads it to ZStack CloudPrivate Cloud as a primary storage type, AliyunNAS, for VM instances,.
A AliyunNAS primary storage works with an ImageStore backup storage.

- Prepare required resources in ZStack Cloud Hybrid
Cloud Management.
- Configure the Alibaba Cloud gateway.
- Add a private Alibaba Cloud AccessKey as well as the private Alibaba Cloud region where the NAS file system locates.
- Create an NAS file system as the backend storage of the AliyunNAS primary storage.
- Configure an allowlist for the file system by creating permission groups and permission group rules.
- Add an AliyunNAS primary storage on ZStack CloudPrivate Cloud.
- Manage the AliyunNAS primary storage.
The procedures of deploying an AliyunNAS primary storage are explained in details as follows:
Procedure
-
Prepare required resources in ZStack Cloud Hybrid Cloud
Management.
-
Add an AliyunNAS primary storage on ZStack CloudPrivate Cloud.
On the main menu of ZStack Cloud, choose . On the Primary Storage page, click Add Primary Storage. Then, the Add Primary Storage page is displayed.On the displayed page, set the following parameters:
- Zone: The current zone is displayed.
- Name: Enter a name for the primary storage.
- Description: Optional. Enter a description for the primary storage.
- Type: Choose AliyunNAS.
- File System: Choose an Alibaba Cloud NAS system file created in Hybrid Cloud Management.
- Permission Group: Choose a permission group created in Hybrid Cloud Management.
- Mount Path: The mount path is a host
directory used to mount Alibaba Cloud NAS file systems.
Note:
- If the entered path does not exist, the system will automatically create one.
- Do not use the following system directories. Otherwise,
an exception may occur to your host:
- /
- /dev/
- /proc/
- /sys/
- /usr/bin
- /bin
- Cluster: Choose a cluster to attach the primary storage.
-
Manage the AliyunNAS primary storage.
On the Primary Storage page, you can manage the added AliyunNAS primary storage, such as enabling, disabling, reconnecting, deleting, entering maintenance the primary storage, or attaching/detaching the primary storage to/from a cluster. On the details page of the primary storage, you can view visualized monitoring, alarm, and audit information of the primary storage, and centrally manage VM instances and volumes created on the primary storage.
What to do next
Now, you have successfully deployed an AliyunNAS primary storage.
AliyunEBS Primary Storage Deployment Practice
About this task
ZStack Cloud seamlessly integrates Alibaba Cloud elastic block storage service (EBS) and loads it to ZStack CloudPrivate Cloud as a new primary storage type, AliyunEBS, for business VM instances.

- If you add an AliyunEBS primary storage for the first time, finish
the following configurations in ZStack Cloud Hybrid
Cloud Management:
- Add a Private Alibaba Cloud AccessKey. Choose the AccessKey type as AliyunEBS.
- Add the Private Alibaba Cloud region where the EBS resides and the zones in this region.
- Add an OSS Bucket in the Private Alibaba Cloud region.
- Add an AliyunEBS primary storage on ZStack CloudPrivate Cloud.
- Manage the AliyunEBS primary storage.
The procedures are described in details as follows.
Procedure
-
Finish configurations in ZStack Cloud Hybrid CLoud
Management.
-
Add an AliyunEBS primary storage on ZStack CloudPrivate Cloud.
On the main menu of ZStack Cloud, choose . On the Primary Storage page, click Add Primary Storage. Then, the Add Primary Storage page is displayed.On the displayed page, set the following parameters:
- Zone: The current zone is displayed.
- Name: Enter a name for the primary storage.
- Description: Optional. Enter a description for the primary storage.
- Type: Choose AliyunEBS.
- URL: Enter the endpoint of the Ocean API.
Note:
- AliyunEBS uses the URL to sand requests to the Ocean Server.
- Syntax: http://Ocean_Server_Domain:Port/ocean/api.
- Zone: Choose a zone added in ZStack Cloud Hybrid Cloud Management.
Note:
- You can choose one zone for each AliyunEBS primary storage.
- A zone can be used to create multiple AliyunEBS primary storage.
- Volume Type: Optional. Enter the type of
physical volumes in AliyunEBS primary storage. Options: io7, io8,
and other allowed types.
Note: An AliyunEBS primary storage supports
one physical volume type. - TDC Configurations: Set TDC template parameters.
Note:
- TDC is an application installed on the compute node. It enables the compute node to communicate with the storage node on Alibaba Cloud (such as Nuwa). TDC configurations refers to the configurations for the access of the compute node to the storage node.
- TDC parameters include a port for the host to access the
TDC service, TDC Region, two sets of River Master
(including URL, Server IP, and agent IP), and the
cluster where the Aliyun EBS resides. Configure the
parameters according to actual requirements.Simple:
{ "tdcPort": "20120", "tdcRegion": "region1", "riverMaster": "nuwa://ECS-river/sys/houyi/river_master", "server": "192.168.0.1:10240,192.168.0.2:10240,192.168.0.3:10240", "proxy": "192.168.1.1:10240,192.168.1.2:10240,192.168.1.3:10240", "cluster": "ECS-river" }The edit box can be expanded.Figure 28. Expand Edit Box 
- Cluster: Specify a cluster for the primary storage.
Figure 29. Add an AliyunEBS Primary Storage 
-
Manage the AliyunEBS primary storage.
On the Primary Storage page, you can perform actions on the AliyunEBS primary storage. You can enable, disable, reconnect, attach/detach a cluster to/from, put into maintenance, or delete the primary storage. You can centrally manage the VM instances and volumes on the primary storage, and view the primary storage alarm messages, visualized monitoring, and audit information.
What to do next
Now, you have deployed an AliyunEBS primary storage successfully.
AliyunEBS Backup Storage Deployment Practice
About this task
ZStack Cloud seamlessly integrates the object storage service (OSS) provided by Alibaba Cloud, and loads it to ZStack CloudPrivate Cloud as a new backup storage type, AliyunEBS, which works with AliyunEBS primary storage and provides an image storage service.

- If you add an AliyunEBS backup storage for the first time, finish the
following parameters in ZStack Cloud Hybrid Cloud
Management.
- Add a Private Alibaba Cloud AccessKey. Set the AccessKey type as AliyunEBS.
- Add the Private Alibaba Cloud region where the EBS resides and the zones in the region.
- Add an OSS Bucket in the region.
- Add an AliyunEBS backup storage on ZStack CloudPrivate Cloud.
- Manage the AliyunEBS backup storage.
The deployment procedures are described in details as follows:
Procedure
-
Finish configurations in ZStack Cloud Hybrid Cloud
Management.
-
Add an AliyunEBS backup storage on ZStack CloudPrivate Cloud.
On the main menu of ZStack Cloud, choose . On the Backup Storage page, click Add Backup Storage. Then, the Add Backup Storage page is displayed.On the displayed page, set the following parameters:
- Zone: The current zone is displayed.
- Name: Enter a name for the backup storage.
- Description: Optional. Enter a description for the backup storage.
- Type: Choose AliyunEBS.
- Mount Path: Enter an Ocean API endpoint.
Note:
- The AliyunEBS backup storage uses the mount path to send requests to the Ocean Server.
- Syntax: http://Ocean_Server_Domain:Port/ocean/api.
- Bucket: Choose a Bucket added in ZStack Cloud Hybrid Cloud Management.
- Data Network: The network used for the data communication between the compute node and the backup storage. Setting an independent data network can avoid network congestion and improve transfer efficiencies. If not set, management networks will be used by default.
Figure 34. Add an AliyunEBS Backup Storage 
-
Manage the AliyunEBS bakup storage.
On the Backup Storage page, you can manage the AliyunEBS backup storage, such as enabling, disabling, reconnecting, and deleting the backup storage. You can centrally manage the images on the backup storage and view the back storage visualized monitoring, alarm messages, and audit information.
What to do next
Now, you have deployed an AliyunEBS backup storage successfully.















