Document navigation

What is Alibaba Cloud Hybrid Cloud Management?

Alibaba Cloud Hybrid Cloud Management provided by ZStack Cloud integrates the simple, strong, scalable, and smart (4S) features of ZStack Cloud Private Cloud and the advanced, secure, and stable features of Alibaba Cloud Public Cloud. It is a hybrid cloud management solution that seamlessly integrates cloud services and terminals, interconnecting the control panel and data panel.

Concepts

  • ZStack Cloud Alibaba Cloud Hybrid Cloud Management provides the following cloud computing products of Alibaba Cloud:
    • ECS Instance: An elastic compute service (ECS) instance is a VM instance created on Alibaba Cloud.
    • Disk: A disk provides storage space for an ECS instance created on Alibaba Cloud.
    • Image: An image is a template file that is used to create ECS instances. Images are categorized into custom images and Alibaba Cloud images.
    • Security Group: A security group provides security control services for ECS instances on the L3 network. It filters the inbound or outbound packets of ECS instances based on security rules.
    • VPC: A virtual private cloud (VPC) is a private network dedicated for ECS instances created on Alibaba Cloud.
    • EIP: An elastic IP address (EIP) is an IP address in Alibaba Cloud public networks. You can attach EIPs to ECS instances so that the ECS instances can access public networks by using the EIPs.
  • VPN: Establishes a site-to-site IPsec VPN channel to enable communications between private networks in a local data center and Alibaba Cloud VPC. This section includes:
    • VPN Gateway: A virtual private network (VPN) gateway establishes a secure connection between a local data center and Alibaba Cloud VPC by using an encrypted channel.
    • VPN Customer Gateway: A VPN customer gateway provides services for a local data center.
    • VPN Connection: A VPN connection is an encrypted communication channel established between a VPN gateway and VPN customer gateway.
  • Express Connect: Express Connect uses physical circuits (electric cables or optical fibers leased from operators) to connect local data centers with Alibaba Cloud access points and Alibaba Cloud VPC. This way, private networks on Alibaba Cloud and in local data centers can communicate with each other in a fast, stable, and secure manner. This section includes:
    • Router Interface: A router interface is a virtual device that is used to establish communication channels and control their status.
    • Virtual Border Router: A virtual border router (VBR) is virtualized from a physical switch port on the access point of Alibaba Cloud. It forwards the data on the physical circuit to Alibaba Cloud VPC.
  • Alibaba Cloud NAS: Alibaba Cloud NAS is a network-attached file storage service. It provides highly reliable and available distributed file systems that can be accessed by using standard file access protocols. In addition, Alibaba Cloud NAS is scalable in storage space and performance and can be managed in a namespace while shared with multiple users. ZStack Cloud seamlessly integrates with Alibaba Cloud NAS. You can add primary storage of the AliyunNAS type on ZStack Cloud Private Cloud so as to use the distributed storage independently deployed on Alibaba Cloud. This section includes:
    • File System: A file system is a backend storage system used for Alibaba Cloud NAS primary storage. Before you add an AliyunNAS primary storage, you need to add an NAS file system.
    • Permission Group: A permission group is an allowlist of IP addresses or IP ranges which can access file systems according to specified permission rules.
  • Data Center: Data centers are resources corresponding to Alibaba Cloud regions and zones. These resources include:
    • Region: A region is a physical data center. A region in ZStack Cloud Hybrid Cloud corresponds to a region in Alibaba Cloud.
    • Zone: A zone is a physical area in a region that is independent from other zones in the region in terms of electricity and network supplies.
  • Setting: ZStack Cloud Hybrid Cloud provides the following basic settings:
    • AccessKey Management: An AccessKey pair is an identity credential that has access to APIs of Alibaba Cloud or Private Alibaba Cloud. It has full access to the Cloud. An AccessKey pair consists of AccessKey ID and AccessKey secret.
    • Hybrid Cloud Settings: Hybrid cloud settings allow you to configure settings that take effect on the whole platform.

Physical Deployment

ZStack Cloud Hybrid Cloud uses an in-process micro-service architecture and does not introduce a new module. ZStack Cloud management nodes need to access the Internet so that they can call Alibaba Cloud Public Cloud APIs.

Physical connection-based deployment: uses physical connections to establish local-remote inter-connected networks, thereby connecting a local data center with Alibaba Cloud Public Cloud.
Figure 1. Physical Connection-based Deployment


Architecture

ZStack Cloud Hybrid Cloud includes the following sections:

  • Identity Authentication:
    Alibaba Cloud AccessKey: integrates Resource Access Management of Alibaba Cloud Public Cloud / Private Cloud. A user authorized with an Alibaba Cloud AccessKey pair can access remote resources on Alibaba Cloud.
    Figure 2. Identity Authentication


  • Network Interconnection:

    You can use IPsec tunnels or Alibaba Cloud Express Connect to connect local Private Cloud with Alibaba Cloud Public Cloud. This way, local-remote L3 networks can access each other. The Local-remote network interconnection is the foundation of ZStack Cloud Hybrid Cloud.

    ZStack Cloud Hybrid Cloud allows you to use IPsec tunnels or Alibaba Cloud Express Connect to establish interconnected networks.
    Figure 3. IPsec Tunnel


    Figure 4. Alibaba Cloud Express Connect


  • Resource Management:
    You can authorize a RAM user to manage Alibaba Cloud Public Cloud resources, including ECS instances, VBR, VPC, and virtual switches.

    Resource Management



  • Business Implementation:

    The identity authentication, network interconnection, and resource management mechanisms help establish a flexible and elastic business system architecture. After the hybrid cloud platform is established, you can deploy flexible and multi-dimensional business modes on it.

Characteristics

ZStack Cloud Hybrid Cloud have the following characteristics:
  • Seamless integration:

    ZStack Cloud Hybrid Cloud seamlessly integrates Alibaba Cloud Public Cloud. Combined with the benefits of ZStack Cloud Private Cloud, it provides users a platform to manage both public clouds and private clouds in a unified way.

  • Seamless upgrading:

    ZStack Cloud Hybrid Cloud allows seamless upgrading without affecting business continuity.

  • Easy to use:

    ZStack Cloud Hybrid Cloud seamlessly integrates cloud services and terminals in a unified cloud platform. You can easily manage local private clouds and access resources on the public cloud as needed.

Scenarios

  • Data backup on the Cloud

    Financial, medical and some other industries have a high requirement for the compliance of long-term data storage. However, backing up data in local data centers is relatively risky, cost-consuming, and hard for O&M. To deal with these problems, ZStack Cloud Hybrid Cloud helps you back up the data to the Cloud, providing you with a stable data storage service at a lower cost.

  • Data storage on Cloud

    Enterprises and institutions need to store large amounts of data. In these scenarios, you can use ZStack Cloud Hybrid Cloud to store data on Cloud. This solution lowers your investment and management costs and allows data access from multiple regions and zones.

  • Data migration on Cloud

    High data negotiability is important to some enterprises and institutions whose works are finished based on multi-regional cooperation. In these scenarios, you can use ZStack Cloud Hybrid Cloud to migrate data to Cloud, thus ensuring a stable data transmission and data integrity.

Preparation

About this task

To use ZStack Cloud Hybrid Cloud Management, make the following preparations:

Procedure

  1. Purchase a license.

    Purchase a license of Alibaba Cloud Hybrid Cloud Management and install it on ZStack Cloud.

  2. Add the following items to your firewall allowlist so that the ZStack Cloud management node can access Alibaba Cloud APIs:
    • *.aliyuncs.com
  3. Create an Alibaba Cloud account.

    Create an Alibaba Cloud account. For more information, see Create an Alibaba Cloud Account.

    If you are unfamiliar with the main account and sub-account system of Alibaba Cloud, see What is RAM. We recommend that you follow this process to finish the account creation:
    1. Create a main account on Alibaba Cloud.
    2. Use the main account to log on to the Alibaba Cloud Console, and choose Access Control.
    3. On the navigation bar on the left, choose Users > Create User, and create a user named zstack-user.
    4. On the navigation bar, choose Groups > Create Group, and create a group named zstack-developer-group.
    5. Click the group you create, and click the Permissions tab. On the displayed tab page, click Grant Permission. Grant at least the following permissions to the group:
      • AliyunRAMFullAccess
      • AliyunECSFullAccess
      • AliyunEIPFullAccess
      • AliyunVPCFullAccess
      • AliyunOSSFullAccess
      • AliyunExpressConnectFullAccess
      • AliyunVPNGatewayFullAccess
    6. Click the Group Members tab and add the user you created to the group.
    7. On the navigation bar, click Users. On the User page, click the user you created. On the details page of the user, choose the Authentication tab page and click Create AccessKey. Then, an AccessKey pair is generated. Save the AccessKey ID and AccessKey Secret (AK) well for they will not be displayed again after you exist the creation page.
    Note:
    • ZStack Cloud does not record your Alibaba Cloud account information. It only uses the AK to call Alibaba Cloud APIs.
    • We recommend that you comply with the RAM rules of Alibaba Cloud to improve the resource security.
    • The most important security principle is Do not use the main account AK for any actions.
  4. Apply for the permission to upload custom images.

    On the main menu of Alibaba Cloud Console, click Tickets > Submit Ticket. On the Submit Ticket page, choose the question attribution as Elastic Compute Service. Choose question type as Image and Operating System. Then, choose Create/Delete Image and Import/Export Image. On the displayed page, enter a question description like "We are applying for your image import service. Please help add us to your image import allowlist." This ticket is proceeded manually, which takes quite some time.

  5. Apply for the OSS service and create an OSS Bucket.
    A ZStack Cloud image is stored in an Alibaba Cloud OSS before it is used to create an Alibaba Cloud ECS instance. You can use a Bucket in the OSS to upload ZStack Cloud images to Alibaba Cloud.
    Note:
    • Make sure that the ZStack Cloud images to be uploaded support Online Password Modification (Qemu-guest-agent).
    • Make sure that the images do not use an EFI or LVM partitioning scheme.
    • Make sure that the images encapsulate Linux or Windows operating systems.
  6. Add Alibaba Cloud AccessKey to ZStack Cloud Hybrid Cloud.
    On the main menu of ZStack Cloud, choose Resource Center > Hybrid Cloud Management > Setting > AccessKey Management. On the AccessKey Management page, click Add AccessKey, and add the Alibaba Cloud AccessKey you generated in the step3.
    Note: The AccessKey added for the first time is automatically set as the default AccessKey.
  7. Add a region.

    On the main menu of Hybrid Cloud Management, choose Data Center > Region and add an Alibaba Cloud region or a Private Alibaba Cloud region.

  8. Synchronize data.
    On the main menu of Hybrid Cloud Management, click Sync Data to synchronize data in the corresponding Alibaba Cloud data center to ZStack Cloud for a local management.
    • Make sure that you have added a region and zone to ZStack Cloud Hybrid Cloud before you exercise the data synchronization.
    • This action synchronizes the Alibaba Cloud resources that can be accessed with the AccessKey and in the added regions and zones, such as ECS instances, volumes, VPCs, vSwithes, security groups, images, EIPs, VPNs, virtual border routers, and router interfaces.
    • ZStack Cloud automatically synchronized the resources in a region or zone when you add it to local for the first time.
    • The data synchronization takes a relatively long time when you have added multiple regions and zones.

Getting Started

To use the main functions of ZStack Cloud Hybrid Cloud Management, follow these steps:
  1. Add AccessKey: Use the AccessKey to call the Alibaba Cloud APIs or Private Alibaba Cloud APIs.
  2. Add Region: After adding regions, you can specify regions to create ECS instances.
  3. Add Zone: After adding zones, you can specify zones to create ECS instances.
  4. Add Bucket: Use the Bucket to synchronize ZStack Cloud images to Alibaba Cloud OSS and upload the images to corresponding regions. If you only use Alibaba Cloud images instead of local images to create ECS instances, you do not need to add a Bucket.
  5. Create VPC: Create a VPC dedicated for ECS instances.
  6. Create Security Group: Create security groups for ECS instances.
  7. Create ECS Instance: Create ECS instances to provide compute services.
  8. Create VPC Network: Create a VPC network which is used to create VM instances on Private Cloud.
  9. Create VPN Connection: Use a VPN connection to enable the intercommunication between local Private Cloud VM instances and Alibaba Cloud ECS instances.
  10. Create Express Connect: Use an express connect to enable the intercommunication between Private Cloud VM instances and Alibaba Cloud ECS instances.

Practices

IPsec VPN Practice

About this task

ZStack Cloud allows you to create an IPsec VPN to enable the intercommunication between the VPC networks in the local data center and on Alibaba Cloud.

To create an IPsec tunnel, follow these steps:
  1. In ZStack Cloud Hybrid Cloud Management, create the following resources in order: a region, a zone, a VPC, and a vSwitch associated with the VPC.
  2. Use a VPC network to create a Private Cloud VM instance.
  3. Create an ECS instance.
  4. Create a VPN connection.
  5. Check whether the Private Cloud VM instance can ping the ECS instance. If so, the IPsec tunnel is created successfully.
Figure 6. IPsec VPN Network Architecture


Preparations:
  • Initialize ZStack CloudPrivate Cloud, adding basic resources like zones, clusters, hosts, image storage, and primary storage.
  • Purchase a VPN gateway on Alibaba Cloud Console.
Assume that your environment is as follow:
  1. Local Public Network
    Public Network Configuration
    NIC eth0
    VLAN ID NoVLAN
    CIDR 192.168.25.0/24
    Gateway 192.168.25.1
    DHCP IP 192.168.25.2
  2. Management Network
    Management Network Configuration
    NIC eth1
    VLAN ID NoVLAN
    IP Address 172.20.58.50~172.20.58.59
    Netmask 255.255.0.0
    Gateway 172.20.0.1
  3. VPC Network
    VPC Network Configuration
    NIC eth0
    VLAN ID 1982
    IP CIDR 10.10.224.0/24
    DHCP IP 10.10.224.153
  4. Alibaba Cloud VPN customer gateway IP: 180.169.211.121
  5. Alibaba Cloud VPN gateway IP: 47.103.147.121
  6. The CIDR of the vSwitch associated with the VPN gateway: 172.31.0.0/16

The procedures are described in details as follows:

Procedure

  1. In ZStack Cloud Hybrid Cloud Management, create the following resources in order: a region, a zone, a VPC, and a vSwitch associated with the VPC.
  2. In ZStack CloudPrivate Cloud, create a VPC network and use the VPC network to create a VM instance on ZStack CloudPrivate Cloud.
  3. Create an ECS instance.
  4. Create a VPN connection.
    1. Use Quick Start Wizard to create a VPN connection.

      On the main menu of Hybrid Cloud Management, choose Quick Start > Quick Start Wizard. On the Quick Start Wizard page, click Establish VPN Connection.

    2. Select an Alibaba Cloud network.
      On the displayed Select Alibaba Cloud Network page, set the following parameters:
      • VPN Gateway (Alibaba Cloud): Select a purchased Alibaba Cloud VPN gateway.
        Note: If no VPN gateway is available in the selected region, you need to purchase one on Alibaba Cloud Console.
      Figure 7. Select an Alibaba Cloud Network


    3. Finish connection configurations.
      On the Connection Configuration page, set the following parameters:
      • Name: Enter a name for the VPN connection.
      • Description: Optional. Enter a description for the VPN connection.
      • IKE Preshared Key: We recommend that you set a strong key.
      • VPC vRouter (ZStack): Select a VPC vRouter for the VPN connection.
      • Public Network (ZStack): Select the public network the VPC vRouter attached to.
      • NAT Device: Choose whether an NAT device is used in your local network environment.
        • If an NAT device is used, set the following parameters:
          • Pre-NAT IP: A public network IP to create the IPsec tunnel. Enter an IP address that can be used to access the public network.
          • Post-NAT IP: The IP address of the VPN customer gateway used to create the IPsec tunnel. Enter an IP address that is transformed from the source IP address (Pre-NAT IP) and can access the Internet directly.
          Note: Make sure that the post-NAT IP is the definite transformation result of the pre-NAT IP (source IP address) in you local network environment.
        • If no NAT device is used, set the following parameters:
          • IP Address: Optional. An available public network IP for the IPsec tunnel. Enter an IP address of the public Internet. If you do not set it, the system allocates an available public network IP randomly to create the IPsec tunnel.
      • Private Network (ZStack): Select L3 networks attached to the VPC vRouter. You can select up to 3 L3 networks.
      • Advanced: We recommend that you do not modify the advanced parameters for the default values can ensure the IPsec connectivity.
        • SA Lifetime: 86400 (Default). Unit: second.
        • IPsec Encoding Algorithm: 3des (Default).
        • IPsec Authentication Algorithm:sha1 (Default).
        • IPsec DH Group: group2 (Default).
        • IKE Version: ikev1 (Default).
        • IKE Negotiation Mode: main (Default).
        • IKE Encoding Algorithm: 3des (Default).
        • IKE Authentication Algorithm: sha1 (Default).
        • IKE DH Group: group2 (Default).
      Figure 8. Connection Configuration




    4. Click OK to create the IPsec VPN connection. During the creation, the system automatically finishes the following operations:
      1. Chooses a VIP in the public network corresponding to the local VPC vRouter.
      2. Uses this VIP to create a VPN customer gateway on Alibaba Cloud.
      3. Creates a VPN connection on Alibaba Cloud.
      4. Configures routes for the VPC virtual router on Alibaba Cloud. The destination CIDR is the CIDR of the VPC network the local VPC vRouter attached to. The next hop is the VPN gateway.
      5. Creates an IPsec connection on ZStack CloudPrivate Cloud.
  5. Check whether the local VM instance can ping the Alibaba Cloud ECS instance.

    On the main menu of Hybrid Cloud Management, choose VPN > VPN Connection. On the VPN Connection page, if the status of the VPN connection is Phase 2 negotiations succeeded, the IPsec VPN creation is finished. Then, you need to use the local VM instance to ping the ECS instance to check whether the creation is successful.

    1. Log in to the local VM instance and ping the ECS instance.
      Figure 9. Local VM Instance ping ECS Instance


    2. Log in to the ECS instance and ping the local VM instance.
      Figure 10. ECS Instance ping Local VM Instance


    Note:
    If the VPN connection is not created successfully, or the local VM instance and the ECS instance cannot ping each other, check the following points before you reconfigure the VPN connection:
    • Check whether the local VIP used to create the IPsec connection is occupied. If it is occupied, delete this VIP.
    • Check whether the Alibaba Cloud VPN connection exists. If so, delete the VPN connection both from local and from Alibaba Cloud.
    • Check whether the Alibaba Cloud VPN customer gateway is allocated with a duplicated IP address. If so, delete the IP address both from local and from Alibaba Cloud.
    • Check whether the Alibaba Cloud VPC virtual router is configured with a route rule corresponding to the VPC network of ZStack CloudPrivate Cloud. If so, delete the route rule.

What to do next

Now, you has established an IPsec VPN and enabled the intercommunication between the ZStack CloudPrivate Cloud VM instance and the Alibaba Cloud ECS instance.

Express Connect Practice

About this task

ZStack Cloud allows you to create an Alibaba Cloud express connect to enable the intercommunication between the VPC networks in local data center and on Alibaba Cloud.

To create an Alibaba Cloud express, following these steps:
  1. Prepare a physical circuit, a virtual border router, and router interfaces provided by an operator.
  2. Plan network CIDRs, including a public network CIDR, a management network CIDR, a physical circuit network CIDR, and a VPC network CIDR. The public network CIDR and the management network CIDR can be the same one.
  3. Use the local VPC network to create a VM instance on ZStack CloudPrivate Cloud.
  4. Attach the physical circuit network to a VPC vRouter.
  5. Prepare a VPC environment on Alibaba Cloud. Use the vSwitch associated with the Alibaba Cloud VPC to create an ECS instance.
  6. In ZStack Cloud Hybrid Cloud Management, add an AccessKey, regions, and zones, and synchronize corresponding resources.
  7. Use Quick Start Wizard to create an Alibaba Cloud express connect.
  8. Configure route rules for both Alibaba Cloud VPC virtual router and local VPC vRouter on the CPE device.
  9. Check whether the local VM instance and the Alibaba Cloud ECS instance can ping each other. If so, the express connect is created successfully.
Express connect logic: Use a physical circuit to connect the local data center and the access point of Alibaba Cloud, thus realizing the intercommunication between the local VPC network and Alibaba Cloud VPC.
Note: The CIDRs from the local VPC vRouter to Alibaba Cloud VPC, which use the express connect to realize the intercommunication, cannot overlap with each other.
Figure 11. Express Connect Network Architecture


Assume that your environment is as follow:
  1. Public Network
    Public Network Configuration
    NIC em01
    VLAN ID NoVLAN
    IP Range 172.20.58.180~172.20.58.189
    Netmask 255.255.0.0
    Gateway 172.20.0.1
    Note Private Cloud VM instance can use this network to access the Internet.
  2. Physical Circuit Network
    Physical Circuit Network Configuration
    NIC em02
    VLAN ID NoVLAN
    IP Range 10.255.255.230~10.255.255.240
    Netmask 255.255.255.0
    Gateway 10.255.255.1
    Note A new network. Private Cloud VM instances use this network to access Alibaba Cloud ECS instances.
  3. Private Network
    VPC Configuration
    NIC em01
    VLAN ID 2984
    IP CIDR 10.200.0.0/16
  4. The local IP address of the CPE device is 10.255.255.1
  5. The local IP address of the virtual border router is 10.240.1.1. The Alibaba Cloud IP address of the virtual border router is 10.240.1.2.
  6. The CIDR of Alibaba Cloud VPC is 192.168.0.0/16.
Follow these steps to configure routes
  1. Make local VM instance access Alibaba Cloud ECS instance.
    1. Configure the VPC route: On the VPC vRouter, set the route destination address as the ECS VPC CIDR, 192.168.0.0/16. Set the next hop as the IP address of the client CPE device, 10.255.255.1.
    2. Configure the CPE device custom route: On the CPE device, set the destination address as the ECS VPC CIDR, 192.168.0.0/16. Set the next hop as the address of the physical circuit.
    3. Configure VRB custom route 2: On the VRB, set the destination address as the ECS VPC CIDR, 192.168.0.0/16. Set the next hop as VRB interface2, which is the VRB interface on Alibaba Cloud.
    4. The Alibaba Cloud virtual router forwards the routes it receives to the ECS instance.
    Figure 12. Route Configurations Enabling Local VM Instance to Ping Alibaba Cloud ECS Instance


  2. Make Alibaba Cloud ECS instance access local VM instance.
    1. Configure the VPC custom route1: On the VPC virtual router on Alibaba Cloud, set the destination address as the CIDR of the ZStack Cloud VPC network, 10.200.0.0/16. Set the next hop as the VPC virtual router interface1.
    2. Configure the VBR custom route1: On the VBR, set the destination address as the CIDR of the ZStack Cloud VPC network, 10.200.0.0/16. Set the next hop as the VBR interface1, which is the VBR interface on ZStack Cloud.
    3. Configure the CPE custom route1: On the CPE device, set the destination address as the CIDR of the ZStack Cloud VPC network, 10.200.0.0/16. Set the next hop as the physical circuit IP address of the VPC vRouter, 10.255.255.240.
    4. The VPC vRouter forwards the routes it receives to the VM instance on ZStack CloudPrivate Cloud.
    Figure 13. Route Configurations Enabling Alibaba Cloud ECS Instance Ping Local VM Instance


Note:
  1. When you create an express connect, the following 4 routes are automatically configured by ZStack Cloud:
    • VPC Custom Route2 (Configured with Alibaba Cloud APIs)
    • VBR Custom Route1 (Configured with Alibaba Cloud APIs)
    • VBR Custom Route2 (Configured with Alibaba Cloud APIs)
    • VPC Custom Route1 (Configured with local APIs)
  2. The following two routes on the CPE device need to be created manually:
    • CPE Custom Route1
    • CPE Custom Route2
The procedures are described in details as follows:
Note:
  • This practice uses a same CIDR for both the public network and the management network.
  • This practice enables VM instances on ZStack CloudPrivate Cloud access both the Internet and Alibaba Cloud ECS instances.

Procedure

  1. Create an L2 public network on ZStack CloudPrivate Cloud.
  2. Create an L3 public network on ZStack CloudPrivate Cloud.
  3. Create an L2 physical circuit network on ZStack CloudPrivate Cloud.
  4. Create an L3 physical circuit network on ZStack CloudPrivate Cloud.
  5. Create an L2 VPC network on ZStack CloudPrivate Cloud.
  6. Create an L3 VPC network on ZStack CloudPrivate Cloud.
  7. Use the VPC network to create a Private Cloud VM instance.
  8. Attach the physical circuit network to the VPC vRouter.
  9. Prepare the VPC environment on Alibaba Cloud, and use the vSwitch associated with the Alibaba Cloud VPC to create an ECS instance.
  10. In ZStack Cloud Hybrid Cloud Management, add an AccessKey, regions, and zones. Then, synchronize corresponding resources.
  11. Use Quick Start Wizard to create an Alibaba Cloud express connect.
    1. On the Quick Start Wizard, click Create Alibaba Cloud Express Connect.
    2. Configure ZStack Cloud network.
      Set the following parameters:
      • VPC vRouter: Select a local VPC vRouter.
      • Public Network: Select a dedicated network to connect local and the VBR interface.
      • VPC Network: Select a local VPC network.
    3. Configure Alibaba Cloud Network
      Set the following parameters:
      • VPC: Select a VPC.
      • VBR: Select a VBR. A VBR is created and configured with routes by an ISP.
      • CPE IP (ISP): The IP address of the client device provides by an ISP for the physical circuit to access the local environment.
  12. Manually configure 2 routes on the CPE device.
    • Configure CPE custom route1: Set the destination address as the CIDR of ZStack Cloud VPC network. Set the next hop as the physical circuit IP of the VPC vRouter.
    • Configure CPE custom route2: Set the destination address as the ECS VPC CIDR. Set the next hop as the physical circuit address.
  13. Check whether the local VM instance and the ECS instance can ping each other.
    1. Log in to the local VM instance and ping the ECS instance.
      Figure 14. Local VM Instance ping ECS Instance


    2. Log in to the ECS instance and ping the local VM instance.
      Figure 15. ECS Instance ping Local VM Instance


What to do next

Now, you create an express connect successfully and can use it to enable the intercommunication between ZStack CloudPrivate Cloud VM instances and Alibaba Cloud ECS instances.

Hybrid Cloud Backup Practice

ZStack Cloud provides local backup, remote backup, and Public Cloud backup services in a separate module. You can choose a backup solution according to your business requirements.

For more information about backup services, see Backup Service Tutorial.

Hybrid Cloud Migration Practice

About this task

ZStack Cloud Hybrid Cloud Management allows you to migrate business VM instances on local Private Cloud to Alibaba Cloud Public Cloud.

To migrate a VM instance from local Private Cloud to Alibaba Cloud Public Cloud, follow these steps:
  1. Create a local image based on the local VM instance.
  2. Upload the image to Alibaba Cloud.
  3. Use the image to create an ECS instance on Alibaba Cloud.

The procedures are described in details as follows:

Procedure

  1. Create a local image based on the local VM instance.
    On the main menu of ZStack CloudPrivate Cloud, choose Resource Center > Resource Pool > VM Instance. On the VM Instance page, locate the VM instance to be migrated. Click Actions > Snapshot and Image > Create Image. On the Create Image page, set the following parameters:
    • Name: Enter a name for the VM image.
    • Description: Optional. Enter a description for the VM image.
    • Image Type: Choose System Image.
    • Image Storage: Choose an image storage to store the image.
    Figure 16. Create Image


    Note: To ensure the application consistent, we recommend that you stop the VM instance before you create the image.
  2. Upload the image to Alibaba Cloud.
    1. Add a Bucket in the corresponding region and set it as the default Bucket.

      On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. On the Region page, click a region to enter its details page. On the region details page, click Bucket > Add Bucket. Then, the Add Bucket dialog box is displayed.

      On the displayed dialog box, set the following parameters:
      • Add Method: Choose Available Bucket or Create Bucket.
        If you choose Available Bucket, set these parameters:
        • Bucket: Select an available Bucket from the drop-down list.
        • Make Default: Set whether to make this Bucket the default Bucket in the region. You need to set one and only one default Bucket for a region. By default, the checkbox is selected.
        • Description: Optional. Enter a description for the Bucket.
        If you choose Create Bucket, set these parameters:
        • Bucket Name: Enter a name for the Bucket. The name cannot be used by other Buckets.
        • Make Default: Set whether to make the bucket the default Bucket in the region. You need to set one and only on default Bucket for a region. By default, the checkbox is selected.
        • Description: Optional. Enter a description for the Bucket.
      Figure 17. Add a Bucket


    2. Upload the local image to Alibaba Cloud
      1. On the main menu of ZStack Cloud Hybrid Cloud Management, choose Products > Image. On the Image page, click Upload Image. Then, the Upload Image is displayed.

        On the displayed page, set the following parameters:
        • Name: Enter a name for the image.
        • Description: Optional. Enter a description for the image.
        • OS: Select the image operating system.
        • OS Type: Select the image operating system type.
        • Image: Select an image in a local image storage.
        • Region: Select a region that the image is uploaded to.
        • Bucket: The default Bucket in the region is displayed automatically.
        Figure 18. Upload an Image


      2. You can view the image upload process on the Uploading tab page. The whole upload process consists of three steps:
        • (1/3) Export the image from ZStack Cloud.
        • (2/3) Upload the image to Alibaba Cloud OSS.
        • (3/3) Import the image to Alibaba Cloud.
      Note:

      Comply with the requirements of Alibaba Cloud on the custom image import. For more information, see Instruction for importing image.

    3. Log in to the Alibaba Cloud console to check the image uploaded.
      On the Alibaba Cloud console, choose ECS > Image, you can see that the image is uploaded to Alibaba Cloud.
  3. On Alibaba Cloud, use the image to create a business ECS instance. For more information, see Create an ECS instance by using a custom image.

What to do next

Now, you have finished the VM migration from ZStack Cloud Private Cloud to Alibaba Cloud Public Cloud.

AliyunNAS Primary Storage Deployment Practice

About this task

ZStack Cloud seamlessly integrates Alibaba Cloud NAS, restores the Alibaba Cloud centralized storage to distributed storage, and loads it to ZStack CloudPrivate Cloud as a primary storage type, AliyunNAS, for VM instances,.

A AliyunNAS primary storage works with an ImageStore image storage.

Figure 19. ZStack Seamlessly Integrates Alibaba Cloud NAS


To deploy an AliyunNAS primary storage, follow these steps:
  1. Prepare required resources in ZStack Cloud Hybrid Cloud Management.
    1. Configure the Alibaba Cloud gateway.
    2. Add a private Alibaba Cloud AccessKey as well as the private Alibaba Cloud region where the NAS file system locates.
    3. Create an NAS file system as the backend storage of the AliyunNAS primary storage.
    4. Configure an allowlist for the file system by creating permission groups and permission group rules.
  2. Add an AliyunNAS primary storage on ZStack CloudPrivate Cloud.
  3. Manage the AliyunNAS primary storage.

The procedures of deploying an AliyunNAS primary storage are explained in details as follows:

Procedure

  1. Prepare required resources in ZStack Cloud Hybrid Cloud Management.
    1. Configure the Alibaba Cloud gateway.

      On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > Hybrid Cloud Settings. On the Hybrid Cloud Setting page, set the Alibaba Cloud gateway according to actual requirements.

      Alibaba Cloud gateway syntax:
      oss::http://oss.api.com,ecs::ecs.api.com,nas::nas.endpoint.com
      In this practice, the endpoint of the Private Alibaba Cloud data center is cn-shanghai-nas.cloud.io. Set the Alibaba Cloud gateway as
      NAS::cn-shanghai-nas::cn-shanghai-nas.cloud.io

      cn-shanghai-nas is the ID of the region where the Private Alibaba Cloud data center locates.

    2. Add a Private Alibaba Cloud AccessKey and the Private Alibaba Cloud region where the NAS file system locates.
      1. Add a Private Alibaba Cloud AccessKey.

        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > AccessKey Management. On the AccessKey Management page, click Add AccessKey. Then, the Add AccessKey page is displayed.

        On the displayed page, set the following parameters:
        • Addition Method: Choose Private Alibaba Cloud.
        • Name: Enter a name for the AccessKey.
        • Description: Optional. Enter a description for the AccessKey.
        • Type: Choose AliyunNAS
        • AccessKeyID: Enter the AccessKey ID of the Private Alibaba Cloud account. Make sure the correctness of the AccessKey ID.
        • AccessKeySecret: Enter the AccessKEy Secret corresponding to the AccessKey ID. Make sure the correctness of the AccessKey Secret.
        Figure 20. Add Private Alibaba Cloud AccessKey


      2. Add a Private Alibaba Cloud region.
        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. On the Region page, click Add Region. Then, the Add Region page is displayed. On the displayed page, set the following parameters:
        • Region Type: Select Private Alibaba Cloud.
        • Region: Select a region corresponding to the Private Alibaba Cloud AccessKey.
        • Description: Enter a description for the region. The description is required.
        Figure 21. Add a Private Alibaba Cloud Region (AliyunNAS)


      Note:

      After you add the Private Alibaba Cloud AccessKey and corresponding regions, the NAS file system and related resources are automatically synchronized to local. You do not need to click Sync Data manually.

    3. Create an Alibaba Cloud NAS file system as the backend storage for the AliyunNAS primary storage.

      On the main menu of ZStack Cloud Hybrid Cloud Management, choose Alibaba Cloud NAS > File System. On the File System page, click Create File System. Then, the Create File System page is displayed.

      On the displayed page, set the following parameters:
      • Region: Choose a Private Alibaba Cloud region for the file system.
      • Creation Time: Choose to add an existing file system or create a file system.
        • Existing File System: If you have an NAS file system deployed on Alibaba Cloud, you can directly add it to ZStack Cloud.
          If you choose to add an existing file system, set the following parameters:
          • File System: Add the file system deployed on Alibaba Cloud to ZStack Cloud.
          • Name: Enter a name for the file system.
          • Description: Optional. Enter a description for the file system.
        • Create File System:

          You can also create a file system on ZStack Cloud.

          If you choose to create a file system, set the following parameters:
          • Name: Enter a name for the file system.
          • Description: Optional. Enter a description for the file system.
          • Storage Type: Choose a storage type. Valid values: Performance and Capacity.
          • Protocol Type: Choose a protocol type. Valid values: NFS and SMB.
    4. Create a permission group and configure permission group rule allow specified IP addresses to access the file system.
      1. Create a permission group.

        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Alibaba Cloud NAS > Permission Group. On the Permission Group page, click Create Permission Group. Then, the Create Permission Group page is displayed.

        On the displayed page, set the following parameters:
        • Region: Select the Private Alibaba Cloud region where the NAS file system resides.
        • Creation Method: You can choose to add an existing permission group or create a permission group.
          • Existing Permission Group: If you have a permission group on Private Alibaba Cloud, you can add the permission group to ZStack Cloud Hybrid Cloud.
            Note: You can add only a classic network permission group.
            If you choose to add an existing permission group, set the following parameters:
            • Permission Group: Add the existing permission group to ZStack Cloud Hybrid Cloud.
            • Name: Enter a name for the permission group.
            • Description: Optional. Enter a description for the permission group.
            Figure 22. Add an Existing Permission Group


          • Create Permission Group:
            You can also create a permission group on ZStack Cloud Hybrid Cloud.
            Note: You can create only a classic network permission group.
            If you choose to create a permission group, set the following parameters:
            • Name: Enter a name for the permission group.
            • Description: Optional. Enter a description for the permission group.
            • Network Type: Classic (Default).
            Figure 23. Create a Permission Group


      2. Configure permission group rules.
        • If you have a classic network permission group configured with permission rules on Private Alibaba Cloud, you can add the permission group to ZStack Cloud Hybrid Cloud and its permission rules are simultaneously synchronized to local.
        • You can also create permission group rules on ZStack Cloud Hybrid Cloud.

        On the Permission Group page, click the name of a permission group. On the displayed permission group details page, choose Permission Group Rule > Create Permission Group Rule. Then, the Create Permission Group Rule page is displayed.

        On the displayed page, set the following parameters:
        • Network CIDR: Specify an IP address or CIDR as the authorization object of the rule.
        • Priority: Valid values: 1-100. 1 represents the highest priority.
          Note: If you add more than one permission group rules to an authorization object, the rule with the highest priority takes effect.
        • Read/Write Rule: Choose to allow the authorization object to only read the file system (RDONLY) or to read and write in the file system (RDWR).
  2. Add an AliyunNAS primary storage on ZStack CloudPrivate Cloud.
    On the main menu of ZStack Cloud, choose > Resource Center > Hardware > Storage Facility > Primary Storage. On the Primary Storage page, click Add Primary Storage. Then, the Add Primary Storage page is displayed.
    On the displayed page, set the following parameters:
    • Zone: The current zone is displayed.
    • Name: Enter a name for the primary storage.
    • Description: Optional. Enter a description for the primary storage.
    • Type: Choose AliyunNAS.
    • File System: Choose an Alibaba Cloud NAS system file created in Hybrid Cloud Management.
    • Permission Group: Choose a permission group created in Hybrid Cloud Management.
    • Mount Path: The mount path is a host directory used to mount Alibaba Cloud NAS file systems.
      Note:
      • If the entered path does not exist, the system will automatically create one.
      • Do not use the following system directories. Otherwise, an exception may occur to your host:
        • /
        • /dev/
        • /proc/
        • /sys/
        • /usr/bin
        • /bin
    • Cluster: Choose a cluster to attach the primary storage.
  3. Manage the AliyunNAS primary storage.

    On the Primary Storage page, you can manage the added AliyunNAS primary storage, such as enabling, disabling, reconnecting, deleting, entering maintenance the primary storage, or attaching/detaching the primary storage to/from a cluster. On the details page of the primary storage, you can view visualized monitoring, alarm, and audit information of the primary storage, and centrally manage VM instances and volumes created on the primary storage.

What to do next

Now, you have successfully deployed an AliyunNAS primary storage.

AliyunEBS Primary Storage Deployment Practice

About this task

ZStack Cloud seamlessly integrates Alibaba Cloud elastic block storage service (EBS) and loads it to ZStack CloudPrivate Cloud as a new primary storage type, AliyunEBS, for business VM instances.

Figure 24. ZStack Seamlessly Integrates Alibaba Cloud EBS and OSS


To deploy an AliyunEBS primary storage, follow these steps:
  1. If you add an AliyunEBS primary storage for the first time, finish the following configurations in ZStack Cloud Hybrid Cloud Management:
    1. Add a Private Alibaba Cloud AccessKey. Choose the AccessKey type as AliyunEBS.
    2. Add the Private Alibaba Cloud region where the EBS resides and the zones in this region.
    3. Add an OSS Bucket in the Private Alibaba Cloud region.
  2. Add an AliyunEBS primary storage on ZStack CloudPrivate Cloud.
  3. Manage the AliyunEBS primary storage.

The procedures are described in details as follows.

Procedure

  1. Finish configurations in ZStack Cloud Hybrid CLoud Management.
    1. Add a Private Alibaba Cloud AccessKey. Choose the AccessKey type as AliyunEBS.

      On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > AccessKey Management. On the AccessKey Management page, click Add AccessKey. Then, the Add AccessKey page is displayed.

      On the displayed page, set the following parameters:
      • Addition Method: Choose Private Alibaba Cloud.
      • Name: Enter a name for the AccessKey.
      • Description: Optional. Enter a description for the AccessKey.
      • Type: Choose a Private Alibaba Cloud AccessKey type. Options: AliyunEBS and AliyunNAS.
      • AccessKey ID: Enter the AccessKey ID of a Private Alibaba Cloud account. Ensure the correctness of the AccessKey ID.
      • AccessKey Secret: Enter the AccessKey Secret corresponding to the AccessKey ID. Ensure the correctness of the AccessKey Secret.
      Figure 25. Add a Private Alibaba Cloud AccessKey


    2. Add the Private Alibaba Cloud region where the EBS resides and the zones in this region.
      1. Add the Private Alibaba Cloud region where the EBS resides.

        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. On the Region page, click Add Region. Then, the Add Region page is displayed.

        On the displayed page, set the following parameters:
        • Region Type: Choose Private Alibaba Cloud.
        • Type: Choose AliyunEBS.
        • Endpoint: Enter the domain name of the Ocean external service.
          Note:
          • Ocean provides an external service with HTTP RESTful APIs.
          • Syntax: http://Ocean_Server_Domain:Port/ocean/api;
          • Domain names varies according to regions.
        • Region: Enter a region can be accessed by the Private Alibaba Cloud AccessKey.
        • Description: Optional. Enter a description for the region.
        Figure 26. Add a Private Alibaba Cloud Region (Aliyun EBS)


      2. Add zones in the region.

        The zones in the region are automatically synchronized to local after you add the region. If the zones are not synchronized automatically, follow these method to manually add them:

        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Zone. On the Zone page, click Add Zone. Then, the Add Zone page is displayed.

        On displayed page, set the following parameters:
        • Region: Select a region can be accessed by the AccessKey.
        • Zone: Select an availability zone from the drop-down list.
        • Description: Enter a description for the zone. This is a required parameter.
    3. Add an OSS Bucket in the region.

      On the Region page, click the private Alibaba Cloud region to enter its details page. On the details page, click Bucket > Add Bucket. Then, the Add Bucket dialog box is displayed.

      On the displayed dialog box, set the following parameters:
      • Add Method: Choose Available Bucket or Create Bucket.
        If you choose Available Bucket, set these parameters:
        • Bucket: Select an available Bucket from the drop-down list.
        • Make Default: Set whether to make this Bucket the default Bucket in the region. You need to set one and only one default Bucket for a region. By default, the checkbox is selected.
        • Description: Optional. Enter a description for the Bucket.
        If you choose Create Bucket, set these parameters:
        • Bucket Name: Enter a name for the Bucket. The name cannot be used by other Buckets.
        • Make Default: Set whether to make the bucket the default Bucket in the region. You need to set one and only on default Bucket for a region. By default, the checkbox is selected.
        • Description: Optional. Enter a description for the Bucket.
      Figure 27. Add a Bucket


  2. Add an AliyunEBS primary storage on ZStack CloudPrivate Cloud.
    On the main menu of ZStack Cloud, choose Resource Center > Hardware > Storage Facility > Primary Storage. On the Primary Storage page, click Add Primary Storage. Then, the Add Primary Storage page is displayed.
    On the displayed page, set the following parameters:
    • Zone: The current zone is displayed.
    • Name: Enter a name for the primary storage.
    • Description: Optional. Enter a description for the primary storage.
    • Type: Choose AliyunEBS.
    • URL: Enter the endpoint of the Ocean API.
      Note:
      • AliyunEBS uses the URL to sand requests to the Ocean Server.
      • Syntax: http://Ocean_Server_Domain:Port/ocean/api.
    • Zone: Choose a zone added in ZStack Cloud Hybrid Cloud Management.
      Note:
      • You can choose one zone for each AliyunEBS primary storage.
      • A zone can be used to create multiple AliyunEBS primary storage.
    • Volume Type: Optional. Enter the type of physical volumes in AliyunEBS primary storage. Options: io7, io8, and other allowed types.
      Note: An AliyunEBS primary storage supports one physical volume type.
    • TDC Configurations: Set TDC template parameters.
      Note:
      • TDC is an application installed on the compute node. It enables the compute node to communicate with the storage node on Alibaba Cloud (such as Nuwa). TDC configurations refers to the configurations for the access of the compute node to the storage node.
      • TDC parameters include a port for the host to access the TDC service, TDC Region, two sets of River Master (including URL, Server IP, and agent IP), and the cluster where the Aliyun EBS resides. Configure the parameters according to actual requirements.
        Simple:
        {
          "tdcPort": "20120",
          "tdcRegion": "region1",
          "riverMaster": "nuwa://ECS-river/sys/houyi/river_master",
          "server": "192.168.0.1:10240,192.168.0.2:10240,192.168.0.3:10240",
          "proxy": "192.168.1.1:10240,192.168.1.2:10240,192.168.1.3:10240",
          "cluster": "ECS-river"
        }
        The edit box can be expanded.
        Figure 28. Expand Edit Box


    • Cluster: Specify a cluster for the primary storage.
    Figure 29. Add an AliyunEBS Primary Storage


  3. Manage the AliyunEBS primary storage.

    On the Primary Storage page, you can perform actions on the AliyunEBS primary storage. You can enable, disable, reconnect, attach/detach a cluster to/from, put into maintenance, or delete the primary storage. You can centrally manage the VM instances and volumes on the primary storage, and view the primary storage alarm messages, visualized monitoring, and audit information.

What to do next

Now, you have deployed an AliyunEBS primary storage successfully.

AliyunEBS Image Storage Deployment Practice

About this task

ZStack Cloud seamlessly integrates the object storage service (OSS) provided by Alibaba Cloud, and loads it to ZStack CloudPrivate Cloud as a new image storage type, AliyunEBS, which works with AliyunEBS primary storage and provides an image storage service.

Figure 30. ZStack Seamlessly Integrates Alibaba Cloud EBS and OSS


To deploy an AliyunEBS image storage, follow these steps:
  1. If you add an AliyunEBS image storage for the first time, finish the following parameters in ZStack Cloud Hybrid Cloud Management.
    1. Add a Private Alibaba Cloud AccessKey. Set the AccessKey type as AliyunEBS.
    2. Add the Private Alibaba Cloud region where the EBS resides and the zones in the region.
    3. Add an OSS Bucket in the region.
  2. Add an AliyunEBS image storage on ZStack CloudPrivate Cloud.
  3. Manage the AliyunEBS image storage.

The deployment procedures are described in details as follows:

Procedure

  1. Finish configurations in ZStack Cloud Hybrid Cloud Management.
    1. Add a Private Alibaba Cloud AccessKey. Set the AccessKey type as AliyunEBS.

      On the main menu of ZStack Cloud Hybrid Cloud Management, choose Set > AccessKey Management. On the AccessKey Management page, click Add AccessKey. Then, the Add AccessKey page is displayed.

      On the displayed page, set the following parameters:
      • Addition Method: Choose Private Alibaba Cloud.
      • Name: Enter a name for the AccessKey.
      • Description: Optional. Enter a description for the AccessKey.
      • Type: Choose a Private Alibaba Cloud AccessKey type. Options: AliyunEBS and AliyunNAS.
      • AccessKey ID: Enter the AccessKey ID of a Private Alibaba Cloud account. Ensure the correctness of the AccessKey ID.
      • AccessKey Secret: Enter the AccessKey Secret corresponding to the AccessKey ID. Ensure the correctness of the AccessKey Secret.
      Figure 31. Add a Private Alibaba Cloud AccessKey


    2. Add the Private Alibaba Cloud region where the EBS resides and the zones in the region.
      1. Add the Private Alibaba Cloud region where the EBS resides.

        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Region. On the Region page, click Add Region. Then, the Add Region page is displayed.

        On the displayed page, set the following parameters:
        • Region Type: Choose Private Alibaba Cloud.
        • Type: Choose AliyunEBS.
        • Endpoint: Enter the domain name of the Ocean external service.
          Note:
          • Ocean provides an external service with HTTP RESTful APIs.
          • Syntax: http://Ocean_Server_Domain:Port/ocean/api;
          • Domain names varies according to regions.
        • Region: Enter a region can be accessed by the Private Alibaba Cloud AccessKey.
        • Description: Optional. Enter a description for the region.
        Figure 32. Add a Private Alibaba Cloud Region (Aliyun EBS)


      2. Add the zones in the region.

        The zones in the region are automatically synchronized after you add the region to local. If the zones are not synchronized automatically, you can manually add them through the following method.

        On the main menu of ZStack Cloud Hybrid Cloud Management, choose Data Center > Zone. On the Zone page, click Add Zone. Then, the Add Zone page is displayed.

        On displayed page, set the following parameters:
        • Region: Select a region can be accessed by the AccessKey.
        • Zone: Select an availability zone from the drop-down list.
        • Description: Enter a description for the zone. This is a required parameter.
    3. Add an OSS Bucket in the region.

      On the Region page, click the Private Alibaba Cloud region to enter its details page. On the details page, click Bucket > Add Bucket. Then, the Add Bucket dialog box is displayed.

      On the displayed dialog box, set the following parameters:
      • Add Method: Choose Available Bucket or Create Bucket.
        If you choose Available Bucket, set these parameters:
        • Bucket: Select an available Bucket from the drop-down list.
        • Make Default: Set whether to make this Bucket the default Bucket in the region. You need to set one and only one default Bucket for a region. By default, the checkbox is selected.
        • Description: Optional. Enter a description for the Bucket.
        If you choose Create Bucket, set these parameters:
        • Bucket Name: Enter a name for the Bucket. The name cannot be used by other Buckets.
        • Make Default: Set whether to make the bucket the default Bucket in the region. You need to set one and only on default Bucket for a region. By default, the checkbox is selected.
        • Description: Optional. Enter a description for the Bucket.
      Figure 33. Add a Bucket


  2. Add an AliyunEBS image storage on ZStack CloudPrivate Cloud.
    On the main menu of ZStack Cloud, choose Resource Center > Hardware > Storage Facility > Image Storage. On the Image Storage page, click Add Image Storage. Then, the Add Image Storage page is displayed.
    On the displayed page, set the following parameters:
    • Zone: The current zone is displayed.
    • Name: Enter a name for the image storage.
    • Description: Optional. Enter a description for the image storage.
    • Type: Choose AliyunEBS.
    • Mount Path: Enter an Ocean API endpoint.
      Note:
      • The AliyunEBS image storage uses the mount path to send requests to the Ocean Server.
      • Syntax: http://Ocean_Server_Domain:Port/ocean/api.
    • Bucket: Choose a Bucket added in ZStack Cloud Hybrid Cloud Management.
    • Data Network: The network used for the data communication between the compute node and the image storage. Setting an independent data network can avoid network congestion and improve transfer efficiencies. If not set, management networks will be used by default.
    Figure 34. Add an AliyunEBS Image Storage


  3. Manage the AliyunEBS image storage.

    On the Image Storage page, you can manage the AliyunEBS image storage, such as enabling, disabling, reconnecting, and deleting the image storage. You can centrally manage the images on the image storage and view the back storage visualized monitoring, alarm messages, and audit information.

What to do next

Now, you have deployed an AliyunEBS image storage successfully.

Glossary

Instance

An instance is a virtual machine or server that runs the images of operating systems in Cloud, such as VM instance and elastic baremetal instance.

VM Instance

A VM instance is a virtual machine instance running on a host. A VM instance has its own IP address and can access public networks and run application services.

Volume

A volume provides storage space for a VM instance. Volumes are categorized into root volumes and data volumes.

Root Volume

A root volume provides support for the system operations of a VM instance.

Data Volume

A data volume provides extended storage space for a VM instance.

Image

An image is a template file used to create a VM instance or volume. Images are categorized into system images and volume images.

Instance Offering

An instance offering defines the number of vCPU cores, memory size, network bandwidth, and other configuration settings of VM instances.

Disk Offering

A disk offering defines the capacity and other configuration settings of volumes.

GPU Specification

A GPU specification defines the frame per second (FPS), video memory, resolution, and other configuration settings of a physical or virtual GPU. GPU specifications are categorized into physical GPU specifications and virtual GPU specifications.

vNUMA Configuration

vNUMA uses CPU pinning to passthrough the topology of associated host physical NUMA (pNUMA) nodes to a VM instance, generating a topology of virtual NUMA (vNUMA) nodes for the VM instance. This topology enables a vCPU on a vNUMA node to primarily access the local memory and thus improves VM performance.

NUMA (Non-Uniform Memory Access)

Non-uniform memory access (NUMA) is a computer memory design where the memory access time depends on the memory location relative to the CPU. Under NUMA, a processor can access its own local memory faster than non-local memory and thus improves VM performance.

pNUMA Node (physical NUMA Node)

A pNUMA node (physical NUMA node) is a host NUMA node predefined based on the host NUMA architecture. It is used to manage the CPUs and memory of the host.

pNUMA Topology (physical NUMA Topology)

A pNUMA topology (physical NUMA topology) is the topology of the host NUMA nodes predefined by the CPU vendor based on the host NUMA architecture.

vNUMA Node (virtual NUMA Node)

A vNUMA node (virtual NUMA node) is generated by passing-through associated pNUMA nodes via CPU pinning. It is used to manage the CPUs and memory of a VM instance.

vNUMA Topology (virtual NUMA Topology)

A vNUMA topology (virtual NUMA topology) is the topology of VM NUMA nodes generated by passing-through associated pNUMA nodes via CPU pinning.

Local Memory

Local memory is the memory that a CPU (pCPU or vCPU) accesses through the Uncore iMC (Integrated Memory Controller) of the same NUMA (pNUMA or vNUMA) node. Compared with accessing non-local memory, accessing local memory has lower latencies.

CPU Pinning

CPU pinning assigns the virtual CPUs (vCPUs) of a VM instance to specific physical CPUs (pCPUs) of the host, which improves VM performance.

EmulatorPin Configuration

EmulatorPin assigns all other threads than virtual CPU (vCPU) threads and IO threads of a VM instance to physical CPUs (pCPUs) of the host so that these threads run on assigned pCPUs.

Auto-Scaling Group

An auto-scaling group is a group of VM instances that are used for the same scenarios. An auto-scaling group can automatically scale out or in based on application workloads or health status of VM instances in the group.

Snapshot

A snapshot is a point-in-time capture of data status in a volume.

Affinity Group

A VM scheduling policy is a resource orchestration policy based on which VM instances are assigned hosts to achieve the high performance and high availability of businesses.

Zone

A zone is a logical group of resources such as clusters, L2 networks, and primary storage. Zone is the largest resource scope defined in the Cloud.

Cluster

A cluster is a logical group of hosts (compute nodes).

Host

A host provides compute, network, and storage resources for VM instances.

Primary Storage

A primary storage is one or more servers that store volume files of VM instances. These files include root volume snapshots, data volume snapshots, image caches, root volumes, and data volumes.

Image Storage

An image storage is a storage server that stores VM image templates, including ISO image files.

iSCSI Storage

iSCSI storage is an SAN storage that uses the iSCSI protocol for data transmission. You can add an iSCSI SAN block as a Shared Block primary storage or pass through the block to a VM instance.

FC Storage

FC storage is an SAN storage that uses the FC technology for data transmission. You can add an FC SAN block as a Shared Block primary storage or pass through the block to a VM instance.

NVMe Storage

A type of storage implemented via the NVMe-oF (NVMe over fabrics) protocol. You can add a block device configured from an NVMe storage as SharedBlock primary storage.

L2 Network

An L2 network is a layer 2 broadcast domain used for layer 2 isolation. Generally, L2 networks are identified by names of devices on the physical network.

VXLAN Pool

A VXLAN pool is a collection of VXLAN networks established based on VXLAN Tunnel Endpoints (VTEPs). The VNI of each VXLAN network in a VXLAN pool must be unique.

L3 Network

An L3 network includes IP ranges, gateway, DNS, and other network configurations that are used by VM instances.

Public Network

Generally, a public network is a logical network that is connected to the Internet. However, in an environment that has no access to the Internet, you can also create a public network.

Flat Network

A flat network is connected to the network where the host is located and has direct access to the Internet. VM instances in a flat network can access public networks by using elastic IP addresses.

VPC Network

A VPC network is a private network where VM instances can be created. A VM instance in a VPC network can access the Internet through a VPC vRouter.

Management Network

A management network is used to manage physical resources in the Cloud. For example, you can create a management network to manage access to hosts, primary storage, image storage, and VPC vRouters.

Flow Network

A flow network is a dedicated network for port mirror transmission. You can use a flow network to transmit the mirrors of data packets of NIC ports to the target ports.

VPC vRouter

A VPC vRouter is a dedicated VM instance that provides multiple network services.

VPC vRouter HA Group

A VPC vRouter HA group consists of two VPC vRouters. Either VPC vRouter can be a primary or secondary VPC vRouter for the group. If the primary VPC vRouter does not work as expected, the VPC vRouter becomes the secondary VPC vRouter in the group to ensure high availability of business.

vRouter Image

A vRouter image encapsulates network services and can be used to create VPC vRouters.

Dedicated-Performance LB Image

A dedicated-performance load balancer (LB) image encapsulates dedicated-performance load-balancing services and can be used to create load balancer instances. However, a dedicated-performance load balancer image cannot be used to create VM instances.

vRouter Offering

A vRouter offering defines the number of vCPU cores, memory size, image, management network, and public network configuration settings of VPC vRouters. You can use a vRouter offering to create VPC vRouters that can provide network services for public networks and VPC networks.

LB Instance Offering

A load balancer (LB) instance offering defines the CPU, memory, image, and management network configuration settings used to create LB instances. LB instances provide load balancing services for the public network, flat network, and VPC network.

SDN Controller

The SDN controller is the core of the SDN architecture, responsible for centralized management and control of network devices.

SDN Cluster

A cluster of dedicated VM instances designed to provide highly available SDN capabilities.

SDN Instance

A dedicated VM instance designed to provide SDN network capabilities.

SDN Image

An SDN image encapsulates an SDN software and can be used to create SDN instances.

SDN Instance Offering

An SDN instance offering defines the CPU, memory, SDN image, and management network configuration used for creating SDN instances.

Security Group

A security group provides security control services for VM NICs. It filters the ingress or egress TCP, UDP, and ICMP packets of VM NICs based on the specified security rules.

VIP

In bridged network environments, a virtual IP address (VIP) provides network services such as serving as an elastic IP address (EIP), port forwarding, load balancing, IPsec tunneling. When a VIP provides the preceding network services, packets are sent to the VIP and then routed to the destination network where VM instances are located.

EIP

An elastic IP address (EIP) functions based on the NAT technology. IP addresses in a private network are translated into an EIP that is in another network. This way, private networks can be accessed from other networks by using EIPs.

Port Forwarding

Port forwarding functions based on the layer-3 forwarding service of VPC vRouters. This service forwards traffic flows of the specified IP addresses and ports in a public network to specified ports of VM instances by using the specified protocol. If your public IP addresses are insufficient, you can configure port forwarding for multiple VM instances by using one public IP address and port.

Load Balancer

A load balancer distributes traffic flows of a virtual IP address to backend servers. It automatically inspects the availability of backend servers and isolates unavailable servers during traffic distribution. This way, the load balancer improves the availability and service capability of your business.

Listener

A listener monitors the frontend requests of a load balancer and distributes the requests to a backend server based on the specified policy. In addition, the listener performs health checks on backend servers.

Forwarding Rule

A forwarding rule forwards the requests from different domain names or URLs to different backend server groups.

Backend Server Group

A backend server group is a group of backend servers that handles requests distributed by load balancers. It is the basic unit for traffic distribution by load balancer instances.

Backend Server

A backend server handles requests distributed by a load balancer. You can add a VM instance on the Cloud or a server on a third-party cloud as a backend server.

Frontend Network

A frontend network is a type of network that is associated with a load balancer. Requests from the network are distributed by the load balancer to backend servers based on a specified policy.

Backend Network

A backend network is a type of network that is associated with a load balancer. Requests from frontend networks are distributed by the load balancer to servers in the backend network.

Load Balancer Instance

A load balancer instance is a custom VM instance used to provide load balancing services.

Certificate

If you select HTTPS for a listener, associate it with a certificate to make the listener take effect. You can upload either a certificate or certificate chain.

Firewall

A firewall is an access control policy that monitors ingress and egress traffic of VPC vRouters and decides whether to allow or block specific traffic based on the associated rule sets and rules.

Firewall Rule Set

A firewall rule set is a set of rules that a firewall uses to defend against network attacks. You need to associate a rule set with the egress or ingress flow direction of VPC vRouter NICs to make the rule set take effect.

Firewall Rule

A firewall rule is an access control entry associated with the egress or ingress flow direction of VPC vRouter NICs to defend against network attacks. A firewall rule includes rule priority, match condition, and behavior.

Rule Template

A rule template is a template that you can select when you add rules to a rule set or a firewall.

IP/Port Set

An IP or port set is a set of IP addresses or ports that you can select when you add rules to a rule set or a firewall.

IPsec Tunnel

An IPSec tunnel encrypts and verifies IP packets that transmit over a virtual private network (VPN) from one site to another.

OSPF Area

An Open Shortest Path First (OSPF) area is divided from an autonomous system based on the OSPF protocol. This simplifies the hierarchical management of vRouters.

NetFlow

A NetFlow monitors the ingress and egress traffic of the NICs of VPC vRouters. The supported versions of data flows are V5 and V9.

Port Mirroring

Port mirroring mirrors the traffic data of VM NICs and sends the traffic data to the target ports. This allows for the analysis of data packets of ports and simplifies the monitoring and management of data traffic and makes it easier to locate network errors and exceptions.

Route Table

A route table contains information about various routes that you configure. Route entries in a route table must include the destination network, next hop, and route priority.

CloudFormation

CloudFormation is a service that simplifies the management of cloud resources and automates deployment and O&S. You can create a stack template to configure cloud resources and their dependencies. This way, resources can be automatically configured and deployed in batches. CloudFormation provides easy management of the lifecycle of cloud resources and integrates automatic O&S into API and SDK.

Resource Stack

A resource stack is a stack of resources that are configured by using a stack template. The resources in the stack have dependencies with each other. You can manage resources in the stack by managing the resource stack.

Stack Template

A stack template is a UTF8-encoded file based on which you can create resource stacks. The stack template defines the resources that you want, the dependencies between the resources, and the configuration settings of the resources. When you use a stack template to create a resource stack, CloudFormation parses the template and the resources are automatically created and configured.

Sample Template

A sample template is a commonly used resource stack. You can use a sample template provide by the Cloud to create resource stacks.

Designer

A designer is a CloudFormation tool that allows you to orchestrate cloud resources. You can drag and drop resources on a canvas and use lines to establish dependencies between the resources.

Baremetal Cluster

A baremetal cluster consists of baremetal chassis. You can manage baremetal chassis by managing a baremetal cluster where the chassis reside.

Deployment Server

A deployment server is a server that provides PXE service and console proxy service for baremetal chassis.

Baremetal Chassis

A baremetal chassis is used to create a baremetal instance and is identified based on the BMC interface and IPMI configuration setting.

Preconfigured Template

A preconfigured template is used to create a preconfigured file that allows for unattended batch installation of an operating system for baremetal instances.

Baremetal Instance

A baremetal instance is an instantiated baremetal chassis.

Elastic Baremetal Management

Elastic Baremetal Management provides dedicated physical servers for your applications to ensure high performance and stability. In addition, this feature allows elastic scaling. You can apply for and scale resources based on your needs.

Provision Network

A provision network is a dedicated network for PXE boot and image downloads while creating elastic baremetal instances in a gateway proxy cluster.

Elastic Baremetal Cluster

Provides a separated cluster to manage baremetal nodes.

Gateway Node

A gateway node is a node where the ingress and egress traffic of the Cloud and elastic baremetal instances in gateway proxy clusters is forwarded.

Baremetal Node

A baremetal node is used to create a baremetal instance and is identified based on the BMC interface and IPMI configuration setting.

Elastic Baremetal Instance

An elastic baremetal instance has the same performance as physical servers and allows elastic scaling. You can apply for and scale resources based on your needs.

Elastic Baremetal Offering

An elastic baremetal offering defines the number of vCPU cores, memory size, CPU architecture, CPU model, and other configuration settings of elastic baremetal instances.

vCenter

The Cloud allows you to take over vCenter and manage resources on the vCenter.

VM Instance

A VM instance is an ESXi virtual machine instance running on a host. A VM instance has its own IP address to access public networks and can run application services.

Network

A vCenter network defines the network settings of VM instances on vCenter, such as IP range, gateway, DNS, and network services.

Volume

A volume provides storage space for a VM instance on vCenter. A volume attached to a VM instance can be used as a root volume or data volume. A root volume provides support for the system operations of a VM instance. A data volume provides extended storage space for a VM instance.

Image

An image is a template file used to create a VM instance or volume on vCenter. Images are categorized into system images and volume images.

Event Message

Event Message displays event alarm messages of vCenter that is took over by the Cloud. This feature allows you to locate errors and exceptions efficiently.

Network Topology

A network topology visualizes the network architecture of the Cloud. It allows for efficient planning, management, and improvement of network architecture. Network topologies can be categorized into global topologies and custom topologies.

Performance Analysis

Performance Analysis displays the performance metrics of key resources monitored externally or internally in the Cloud. You can view the performance analysis or export the analysis report as needed to improve the O&M efficiency.

Capacity Management

Capacity Management visualizes the capacities and usages of key resources in the Cloud. You can use this feature to improve O&S efficiency.

MN Monitoring

Management Node (MN) monitoring allows you to view the health status of each management node when you use multiple management nodes to achieve high availability.

Alarm

An alarm is used to monitor the status of time-series data and events and respond to the status change. Alarms can be categorized into resource alarm, event alarm, and extended alarm.

One-Click Alarm

A one-click alarm integrates multiple metrics of a resource. You can create one-click alarms for multiple resources to monitor these resources.

Alarm Template

An alarm template is a template of alarm rules. If you associate an alarm template with a resource group, an alarm is created to monitor the resources in the group.

Resource Group

A resource group consists of resources grouped based on your business needs. If you associate an alarm template with a resource group, the alarm rules specified by the template take effect on all the resources in the group.

Message Template

A message template specifies the text template of a resource alarm message or event alarm message sent to an SNS system.

Message Source

A message source is used to take over extended alarm messages. If you configure alarms for message sources, extended alarm messages can be sent to various endpoints.

Endpoint

An endpoint is a method that users obtain subscribed messages. Endpoints are categorized into system endpoints, email, DingTalk, HTTP application, short message service, and Microsoft Teams.

Alarm Message

An alarm message is a message sent the time when an alarm is triggered.

Current Task

A current task is an ongoing operation performed in the Cloud. You can perform centralized management over ongoing operations.

Operation Log

An operation log is a chronological record of operations on the specified objects and their operation results.

Audit

Audit monitors and records all activities on the Cloud. You can use this feature to implement operation tracking, cybersecurity classified protection compliance, security analysis, troubleshooting, and automatic O&M.

Log Collection

Allows you to collect with one click the log data from the Cloud and various nodes on the Cloud generated in the specified time period and download the log data.

One-Click Inspection

Comprehensively inspects the health status of key resources and services of the Cloud and scores their healthiness based on the inspection results. In addition, the one-click inspection service provides O&M suggestions and inspection reports.

Backup Management

Backup management integrates multiple disaster recovery technologies such as incremental backup and full backup that are suitable for multiple business scenarios. You can implement local backup and remote backup based on your business needs.

Backup Job

You can create a backup job to back up local VM instances, volumes, or databases to a specified storage server on a regular basis.

Local Backup Data

Local backup data of VM instances, volumes, and databases is stored in the local backup server.

Local Backup Server

A local backup server is located at the local data center and is used to store local backup data.

Remote Backup Server

A remote backup server is located at a remote data center or a public cloud and is used to store remote backup data.

Continuous Data Protection (CDP)

Continuous Data Protection (CDP) provides second-level and fine-grained continuous backups for important business systems in VM instances, allowing users to restore VM data to a specific time state, and retrieve files without restoring the system.

CDP Task

You can create a CDP task to continuously back up your VM data to a specified backup server to achieve continuous data protection and recovery.

CDP Data

The backup data generated from continuous data protection on VM instances is stored in local backup servers.

Recovery Point

A recovery point is a data point generated during continuous data protection. A recovery point corresponds to a data record within the recovery point interval specified by the user.

Locked Recovery Point

You can lock or unlock a recovery point as needed. After a recovery point is locked, data of the recovery point will not be automatically cleared or deleted.

Recovery Task

A recovery task helps you quickly restore data by specifying a CDP task and recovery point, and allows you to view the recovery progress and logs in a more friendly way.

Cryptography Security Compliance

The Cryptography Security Compliance service provides applications with cloud security capabilities based on commercial cryptography, meeting the requirements of commercial cryptography application security assessments.

HSM Pool

An HSM pool is a logical group of hardware security modules (HSMs) and is used to provide unified cryptography services such as signature validation and encryption.

HSM

A hardware security module (HSM) is a dedicated device that encrypts, decrypts, and authenticates information by using the cryptographic technology.

Platform Cryptography Security Compliance

Enables the Cloud to meet the requirements of Cryptography Security Compliance through the cryptography capabilities provided by HSM pools.

Certificate Login

Authenticates the identity of a user by using a UKey device.

Data Protection

Protects important data on the Cloud to ensure the data confidentiality and integrity.

Scheduled Job

A scheduled job defines that a specific action be implemented at a specified time based on a scheduler.

Scheduler

A scheduler is used to schedule jobs. It is suitable for business scenarios that last for a long time.

Tag

A tag is used to mark resources. You can use a tag to search for and aggregate resources.

Migration Service

The Cloud provides V2V migration service that allows you to migrate VM instances and data from other virtualized platform to the current cloud platform.

ZMigrate Migration Service

A migration service installed from Application Market that migrates VM instances and their data from VMware environments to the current cloud platform.

V2V Migration

V2V Migration allows you to migrate VM instances from the VMware or KVM platform to the current cloud platform.

V2V Conversion Host

A V2V conversion host is a host in the destination cluster that you need to specify during V2V migration to cache VM instances and data when you implement V2V migration. After the VM instances and data are cached in the V2Vconversion host, they are migrated to the destination primary storage.

User

A user is a natural person that constructs the most basic unit in Tenant Management.

User Group

A user group is a collection of natural persons or a collection of project members. You can use a user group to grant permissions.

Role

A role is a collection of permissions that can be granted to users. A user that assumes a role can call API operations based on the permissions specified by the role. Roles are categorized into platform roles and project roles.

Single Sign-On

The Single Sign-On service provided by the Cloud. It supports seamless access to SSO systems. Through the service, related users can directly log in to the Cloud and manage cloud resources.

Project

A project is a task that needs to be accomplished by specific personnel at a specified time. In Tenant Management, you can plan resources at the project granularity and allocate an independent resource pool to a project. The word Tenant in Tenant Management mainly refers to projects. A project is a tenant.

Project Member

A project member is a member in a project who is granted permissions on specific project resources and can use the resources to accomplish tasks. Project members include the project admin, project managers, and normal project members.

Process Management

Process management is part of ticket management that manages the processes related to the resources of projects. Processes can be categorized into default processes and custom processes.

My Approvals

In the Cloud, only the administrator and project administrators are granted approval permissions. the administrator and project administrators can approve or reject a ticket. If a ticket is approved, resources are automatically deployed and allocated to the specified project.

Bills

A bill is the expense of resources totaled at a specified time period. Billing is accurate to the second. Bills can be categorized into project bills, department bills, and account bills.

Pricing List

A pricing list is a list of unit prices of different resources. The unit price of a resource is set based on the specification and usage time of the resource.

Console Proxy

Console proxy allows you to log in to a VM instance by using the IP address of a proxy.

AccessKey Management

An AccessKey pair is a security credential that one party authorizes another party to call API operations and access its resources in the Cloud. AccessKey pairs shall be kept confidential.

IP Allowlist/Blocklist

An IP allowlist or blocklist identifies and filters IP addresses that access the Cloud. You can create an IP allowlist or blocklist to improve access control of the Cloud.

Application Center

Application Market allows you to add applications to the Cloud and then access the applications with one click. It extends the functionality of the Cloud. You can add default applications through the built-in installation package or add more applications through URLs.

Sub-Account Management

A sub-account can be created by the admin or synced from an SSO authentication system and is managed by the admin. Resources created under a sub-account are managed by the sub-account.

Theme and Appearance

You can customize the theme and appearance of the Cloud.

Email Server

If you select Email as the endpoint of an alarm, you need to set an email server. Then alarm messages are sent to the email server.

Log Server

A log server is used to collect management node logs or the platform operation logs. You can add a log server to the cloud and use the collected logs for operation trace or troubleshooting. This makes your O&M more efficient.

Global Setting

Global Setting allows you to configure settings that take effect on the whole platform.

Scenario Template

Scenario Template provides multiple templates that encapsulate scenario-based global settings. You can apply a template globally with one click based on your business needs. This improves your O&M efficiency.

HA Policy

HA Policy is a mechanism that ensures sustained and stable running of the business if VM instances are unexpectedly stopped or are errored because of errors occurring to compute, network, or storage resources associated with the VM instances. By enabling this feature, you can customize VM HA policies to ensure your business continuity and stability.

Time Management

Manages the Cloud system time and allows you to configure time servers for the Cloud. After you configure NTP time servers for the Cloud, the clock of the time servers is synced with all nodes of the Cloud.

GPU Device

A GPU device is a powerful microprocessor with high computational capabilities. You can use a GPU device to handle intricate graphics rendering and parallel computing jobs, thus improving the efficiency of businesses such as graphic production, video processing, and machine learning.

Script Library

The script library stores and manages script files centrally. By executing scripts on VM instances, you can complete complex O&M operations and automated jobs.

XML Hook

An XML Hook is a script that can flexibly insert or modify parameters in XML files of VM instances. By attaching an XML Hook to a VM instance, you can customize VM configurations and enable specialized functionalities.

Container Service

A simple and user-friendly container management service, providing features like GPU management & scheduling, multi-tenancy, multi-cluster, quota configuration, CI/CD. and microservice. The service reduces the container using complexity and aligns well with traditional user's habits, helping you easily manage and deploy your container cluster, and enjoy the benefits of cloud-native technologies in a quick and convenient way.

Advanced Monitoring Server

An advanced monitoring server is a dedicated VM instance used to receive advanced monitoring data of load balancers and other resources.

Advanced Monitoring Server Image

An advanced monitoring server image encapsulates the advanced monitoring service and can be used to create advanced monitoring server.

Advanced Monitoring Server Offering

An advanced monitoring server offering defines the CPU cores, memory size, image, management network, and public network configurations of advanced monitoring server. You can use an advanced monitoring server offering to create advanced monitoring servers.

Plugin Management

You can package extended resources or tools into standardized plugins for quick installation and integration, expanding the Cloud capabilities.

Region Management

A region is a self-contained cloud environment with independent management node(s), networks, hardware, and cloud resources. ZStack IAM enabled user synchronization and SSO across multiple regions.
Alibaba Cloud Hybrid Cloud Management Tutorial | 5.5.38 | ZStack Cloud · ZCF | ZStack Resource Center