Document navigation

Product Security Overview

ZStack Cloud Security provides the information that ensures the Cloud environment security. This paper introduces the core security features of ZStack Cloud.

Product Security Analysis

Compute Security

HTTPS-encrypted UI Login

The system supports HTTPS access to the management UI for enhanced security.
  • HTTPS is disabled by default.
  • When HTTPS is enabled, the system uses port 5443 by default and supports configuration of custom ports for access.
  • After enabling HTTPS, accessing the UI via HTTP on port 5000 will be automatically redirected to HTTPS. Currently, only automatic redirection from HTTP port 5000 is supported.
  • The system supports PKCS12 format certificates by default. Currently, only PKCS12 and JKS format certificates are supported. If you are using certificates in other formats, convert them to a supported format.

VM Instance Console

The VM instance console provides users with a streamlined entry point for monitoring and managing VM instances. You must have appropriate permissions to access the VM console. Two authentication methods are supported for console login: SSH key authentication and username/password.
  • SSH Key Authentication
    • You can use SSH key authentication to log in to Linux VM instances.
    • An SSH key is a pair of cryptographic keys generated by an algorithm: a public key, which is shared openly, and a private key, which is kept secure by the user.
    • After a public key is attached to a VM instance, you can use the corresponding private key to SSH into the VM instance from another VM instance without requiring a password.
    • To attach a public key during the VM instance creation, ensure that the VM image has cloud-init pre-installed. The recommended cloud-init versions are 0.7.9, 17.1, 19.4, or later.
    • To attach a public key after the VM instance creation, ensure that the VM instance is running and has QEMU Guest Agent (QGA) installed and running. You can install QGA by installing the GuestTool. If you install QGA by using other methods, install version 2.5 or later.
  • Username/Password
    • You can log into VM instances using a username and password.
    • The fixed username for Linux VM instances is root, and the fixed username for Windows VM instances is administrator.
    • After a password is injected into a VM instance, you can use the username or password to SSH into the VM instance from another VM instance.
    • Ensure that the VM image has cloud-init pre-installed. The recommended cloud-init versions are 0.7.9, 17.1, 19.4, or later.

High Availability

VM Instance HA

VM instances support the high availability (HA) mode. This policy can trigger automatic VM restart when a VM is stopped due to routine maintenance (planned) or unexpected failures (unplanned), thereby improving VM availability.

NeverStop VM HA Mechanism:
  • The system uses polling and trigger-based mechanisms to monitor the VM instance status. If the VM instance is confirmed to be stopped, a VM configured with HA will be automatically restarted.
  • The system uses polling and trigger-based mechanisms to monitor the VM instance status. If the VM status cannot be definitively determined, the following detection process is initiated:
    1. Based on the existing network configuration, select the most accurate method to probe the status of the host where the VM instance resides.
    2. If the status of the host is abnormal, the HA-enabled VM instance will attempt to restart automatically.

Load Balancing

Multiple VM instances can use the load balancing service to form a cluster, eliminating single points of failure and improving application availability.

IP/MAC/ARP Spoofing Protection

In traditional networks, IP/MAC/ARP spoofing has always been a severe challenge. Through IP/MAC/ARP spoofing, attackers can disrupt the network environment and intercept network secrets.

The system isolates abnormal protocol access initiated by VM instances at the host's data link layer and blocks VM instance MAC/ARP spoofing. It also prevents VM instance IP spoofing at the host's network layer.

Images and Snapshots

Images

You can create images from VM instances or volumes. An image contains a complete data information of a VM instance or volume. You can use images to quickly replicate corresponding resources.

ZStack Cloud provides protection for image integrity and security:
  • Security: Image files are stored in slices in the ImageStore. The segmented image files must be reassembled by ZStack Cloud before their specific content can be read, thereby protecting image data security.
  • Integrity: Images use cryptographic algorithms to protect integrity.
    • When you upload an image to the ImageStore, the system calculates the MD5 checksum of the uploaded image. You can compare this value to verify image integrity.
    • When an image is downloaded from the ImageStore to primary storage, it must pass a cryptographic verification check. The download only proceeds if the verification is successful.

Snapshots

You can create snapshots for VM instances or volumes. A snapshot is essentially a data state file of a disk at a specific time. Before performing important operations, creating a snapshot for a VM instance or volume can retain the data state (including the memory state) at that specific time, facilitating quick rollback in case of failures. For long-term backup, it is recommended that you use the backup service.

Snapshots include manual snapshots and automatic snapshots:
  • Manual Snapshots: You can manually create a snapshot for the root volume or data volume of a VM instance at any time.
  • Automatic Snapshots: The system creates snapshots through scheduled tasks or triggers one-time automatic snapshots in specific scenarios.
The snapshot feature is applied in the following scenarios:
  • Quick Failure Recovery: If an unexpected failure occurs in the production environment, you can use the snapshot rollback feature to quickly restore the environment to the normal state. This method is a temporary solution. For comprehensive long-term data protection, it is recommended that you use the backup service.
  • Data Development: By creating snapshots of production data, you can acquire near real-time authentic production data for applications such as data mining, report query, and development testing.
  • Improve Operation Fault Tolerance: Before major operations such as system upgrades or business data migration, we recommend that you create one or more snapshots. If any problem occurs during the upgrade or migration process, you can use snapshots to restore the normal system data state in time.

Encrypted Password Storage

ZStack Cloud supports encrypted storage of all plaintext passwords to protect the privacy and autonomy of user data.

Supported scenarios for encrypted password storage include, but are not limited to:
  • Host passwords: Not displayed in plaintext.
  • Primary storage passwords: Not displayed in plaintext.
  • Database passwords: Encrypted and stored by using keys and hidden from users directly.
  • Log passwords: All platform log passwords are either not displayed in plaintext or are hidden from users.

Resource Deletion Protection

Deletion Policy

ZStack Cloud supports configuring deletion policies for critical resources to reduce the risk of accidental deletion.

The current deletion policies include Direct, Delay, and Never.
  • Direct: Resources are physically deleted directly and removed from the database. Deleted resources cannot be recovered.
  • Delay: Resources are first marked as deleted in the database but are not physically deleted. Within a certain period, you can recover resources from the recycle bin in the UI or using APIs. During this period, resources still exist physically and occupy physical space (for example, disk space). After a certain period, resources are physically deleted and cannot be recovered.
  • Never: Resources are marked as deleted in the database but are never physically deleted. They occupy physical space all the time.
Resources that currently support deletion policy include VM instances, volumes, images, baremetal instances, and elastic baremetal instances.
  • VM Instance Deletion Policy: Direct, Delay, and Never. The default policy is Delay.
  • Volume Deletion Policy: Direct, Delay, and Never. The default policy is Delay.
  • Image Deletion Policy: Direct, Delay, and Never. The default policy is Delay.
  • Baremetal Instance Deletion Policy: Direct, Delay, and Never. The default policy is Delay.
  • Elastic Baremetal Instance Deletion Policy: Direct, Delay, and Never. The default policy is Delay.
    Note:

    An elastic baremetal instance is a customized VM instance. Elastic baremetal instances and VM instances are controlled by the same set of deletion policies. If the VM instance deletion policy changes, the elastic baremetal instance deletion policy changes accordingly.

UI Deletion Reminder

The UI provides a protection mechanism for deleting important resources. The system displays the consequences of deleting the resource and shows the number of directly associated VM instances and volumes. You must confirm the deletion to proceed, reducing the risk of accidental operation.

National Cryptographic Data Protection

The feature provides data protection based on national cryptographic algorithms (such as SM3, HMAC-SM3, and SM4). After you enable this feature, important data such as logs, passwords, and images can be encrypted to ensure data confidentiality and integrity.

To use this feature, ensure that you have installed the cryptography security compliance module license and enabled data protection.

Monitoring and Alarm

The monitoring and alarm feature is primarily delivered through an monitoring system and the notification system. The monitoring system monitors time-series data and events, and the notification system pushes alarms to specified endpoints.

The monitoring system provides monitoring data metrics, including system performance and resource utilization, in forms such as large-screen monitors, dashboards, graphical charts, and banner notifications, allowing you to fully understand platform resource utilization, operational status, and health indicators. You can also customize alarms and endpoints to achieve flexible and fine-grained monitoring, promptly discover and diagnose related issues.

Characteristics:
  • Time-Series Monitoring: The system currently supports monitoring two types of time-series data.
    • Resource Load Data: For example, VM instance CPU utilization and host memory utilization.
    • Resource Capacity Data: For example, the number of available IP addresses and the total number of running VM instances.
  • Event Collection: Collects predefined events that occur in ZStack Cloud, such as host disconnection and VM instance high availability activation.
  • Alerting: Generates alarms for time-series data or events and provides global notifications for important resources, such as available physical capacity of primary storage.
  • Auditing: Records all operations and provides search functionality.
  • Customization: Allows you to customize alarms and alert message templates.
Characteristics:
  • Pushes alarm messages to specified endpoints.
  • The system provides a system endpoint by default. You can set email, DingTalk, HTTP application, SMS, or Microsoft Teams endpoints.

Security Configuration Templates

ZStack Cloud provides one-click security configuration templates, enabling rapid deployment of standardized security settings across the environment to meet production security requirements.
Name Description
IP Allowlist/Blocklist Default: false. Specifies whether to enable IP allowlist or blocklist for logins. If set to true, the platform filters IP addresses of login clients based on the configured IP allowlist or blocklist entries.
Host Login Password Encrypted Storage
Default: None. Specifies whether and how to encrypt the login password of hosts in the database. Valid values: None, LocalEncryption.
  • None: Does not encrypt the login password of hosts.
  • LocalEncryption: Encrypts the login password of hosts by using the built-in encryption feature.
Note: If you enabled Platform Cryptography Security Compliance, the current effective value will change to SecurityResourceEncryption, indicating that the login password of hosts is encrypted by using HSMs. In this case, the encryption method cannot be changed.
Multiple Connection Session Disallowance of One User Default: false. Specifies whether to disallow simultaneous connection sessions established by one user. If set to true, one user can establish only one connection session with the platform. If a user establishes a new connection session, the previous session will be forcibly closed.
Session Timeout Period Default: 7200. Unit: second/minute/hour/day.
Note: If a session times out, the system becomes unavailable. You need to log in to the system again.
SSL Certificate Check Skipping Default: false. Determines whether to skip all checks for LDAP SSL certificates. If set to true, all checks for LDAP SSL certificates are skipped.
Platform Verification Code Policy Default: false. Specifies whether to enable verification by verification code if logins continuously fail. Default: false. If set to true, you can set the maximum number of continuous login failures that trigger verification by verification code. If the verification is triggered, you must enter the correct account name, password, and the verification code before you can log in to the platform.
Platform Login Password Update Policy Default: false. Determines whether to enable periodic password change. If set to true, after the password usage time reaches the set password update cycle, you are prompted to change the password upon re-login.
Lock Account Policy Upon Continuous Failed Login Default: false. Determines whether to enable user lockout due to consecutive login failures. If set to true, a user account is locked for a period of time after several consecutive login failures.
Password Strength Policy Default: false. If set to true, you can manually set the password length and choose whether to enable a policy combining digits, uppercase letters, lowercase letters, and special characters.
Two-factor Verification Default: false. Specifies whether to enable two-factor verification for platform login.
VNC Console Password Strength Policy Default: false. Determines whether to enable password login for the VNC console.
Note:

The VNC password length range follows the format m~n. The value range is an integer that ranges from 6 to 8 and the default value is 6 to 8. You can choose whether to enable a policy combining digits, uppercase letters, lowercase letters, and special characters.

VM Password Strength Policy Default: false. Determines whether to enable password login for VM instances.
Note:
  • The VM instance password length range follows the format m~n. The value range is an integer that ranges from 8 to 18 and the default value is 8 to 18. You can choose whether to enable a policy combining digits, uppercase letters, lowercase letters, and special characters.
  • To set a VM instance password, ensure that the VM image has cloud-init pre-installed. The recommended cloud-init versions are 0.7.9, 17.1, 19.4, and later versions.

Backup Service

The backup service is business-centric and integrates various backup technologies such as scheduled incremental and full backup into the platform. The backup service supports multiple disaster recovery solutions, including local, remote, and Public Cloud disaster recovery. You can choose an appropriate backup method based on your business characteristics. The backup service is provided as a separate functional module.

Typical Scenarios

Local Backup:
  • You can use a locally deployed ImageStore as a local backup server to store scheduled backups of local VM instances, volumes, and management node databases (hereinafter referred to as databases). The local backup server supports seamless active-standby failover, effectively ensuring business continuity.
  • If local data is accidentally deleted or data in the local primary storage is damaged, you can restore the data from the local backup server to the local environment.
  • If a disaster occurs in the local data center, you can rely entirely on the local backup server to rebuild the data center and restore services.
Remote Backup:
  • You can use a storage server in a remote computer room as a remote backup server to store scheduled backups of local VM instances, volumes, and databases. The backup data must be synchronized from a local backup server to the remote backup server.
  • If local data is accidentally deleted or data in the local primary storage is damaged, you can restore the data from the remote backup server to the local environment.
  • If a disaster occurs in the local data center, you can rely entirely on the remote backup server to rebuild the data center and restore services.
Public Cloud Backup:
  • You can use a storage server on a Public Cloud as a Public Cloud backup server to store scheduled backups of local VM instances, volumes, and databases. The backup data must be synchronized from a local backup server to the Public Cloud backup server.
  • If local data is accidentally deleted or data in the local primary storage is damaged, you can restore the data from the Public Cloud backup server to the local environment.
  • If a disaster occurs in the local data center, you can rely entirely on the Public Cloud backup server to rebuild the data center and restore services.

CDP Service

The CDP service delivers second-level, granular continuous data protection for critical business systems running on VM instances. The CDP service enables you to restore VM data to a specific point in time or retrieve files without performing a full system restoration. CDP recovery supports two strategies: creating a new VM instance and restoring to the original VM instance. You can choose an appropriate recovery method based on your business requirements. The CDP service is provided as a separate functional module.

Typical Scenarios

Local CDP Recovery | Restore to Original VM Instance
  • Supports using a locally deployed ImageStore as a local backup server to store local VM instance data.
  • Supports creating CDP tasks for multiple VM instances to provide unified CDP protection for VM instances. When creating a CDP task, you can set the RPO in seconds or minutes. During important business adjustments, you can mark and lock recovery points to preserve important recovery point data for a long time.
  • In scenarios involving accidental local data deletion or data damage caused by sudden failures, due to hardware-based licensing requirements of the business application, to quickly validate service availability, you can locate a locked recovery point and restore the data to the original VM instance to check if the application functions correctly. Recovery to the original VM instance by creating new volumes is supported. And the volumes before recovery can all be retained and reattached to the VM instance, maximizing data security.
  • During CDP recovery, the VM instance is rapidly restored with an RTO that can be as low as seconds, effectively ensuring business continuity.
Local CDP Recovery | Create New VM Instance
  • Supports using a locally deployed ImageStore as a local backup server to store local VM instance data.
  • Supports creating CDP tasks for multiple VM instances to provide unified CDP protection for VM instances. When creating a CDP task, you can set the RPO in seconds or minutes.
  • During important recovery tests, you can create a new VM instance based on the selected recovery point without affecting the normal operation of the current VM instance. After confirming that the data is correct, you can then restore to the original environment.
  • During CDP recovery, the VM instance is rapidly restored with an RTO that can be as low as seconds, effectively ensuring business continuity.

Advantages

Simple:
  • This service is software-defined, hardware-independent, and scalable.
  • Supports previewing and downloading backed up files without performing a full system restoration.
  • Guided workflows with intelligent parameter recommendations minimize operational complexity and error rates.
Powerful:
  • No agent installation is required for VM instances, eliminating OS dependencies and imposing no performance overhead on VM instances.
  • Delivers second-level, granular continuous data protection for VM instances with an RPO that can be as low as one second.
  • Instant VM instance recovery from any recovery point ensures business continuity with an RTO that can be as low as one second.
  • Streamlined backup intelligently identifies disk partitions and valid data, backing up valid data with a smaller consumed storage space and at a faster speed.
Flexible:
  • Supports flexible settings such as backup frequency, RPO, and retention policy to meet different needs.
  • Supports multiple recovery levels, such as full VM recovery and file-level recovery.
  • Full VM recovery supports multiple strategies, including creating a new VM instance and restoring to the original VM instance.
  • Not limited by the type of primary storage, meeting CDP requirements in different storage scenarios.
Reliable:
  • The UI provides a CDP overview, supporting unified viewing of CDP status and related alerts.
  • Data recovery supports retaining current volume data, maximizing data security and facilitating post-failure analysis.
  • Supports creating a new VM instance based on the selected recovery point and restoring to the original environment after confirming the data is correct, meeting recovery test requirements.
  • Supports marking and locking recovery points for long-term preservation of important recovery point data.
  • Provides a recovery task list and supports viewing recovery records and progress, facilitating subsequent auditing and tracing.

SE Device

SE (Security Element) is an embedded security IP core within the processor. It provides foundational software and application systems with secure, compliant, and standardized cryptographic support. ZStack Cloud can detect SE devices on hosts and allows you to virtualize and attach them to VM instances to deliver security and encryption services.
Note: Currently, only SE devices on Hygon and Loongarch hosts can be detected.

Network Security

Security Group

Security groups provide L3 network security control for VM instances, effectively filtering ingress and egress TCP/UDP/ICMP packets for NICs based on specified security rules.

VPC Firewall

You can configure firewalls for VPC vRouters. After a VPC firewall is created, the system automatically configures an ingress rule set for the VPC vRouter, and you can flexibly configure the egress rule set. Each interface direction on a VPC router can have one rule set applied. By filtering north-south traffic at the VPC vRouter interfaces, the VPC firewall effectively protects the communication security of the entire VPC and the VPC vRouter itself. The VPC firewall provides complementary protection to security groups. These security groups operate at the VM's virtual NICs, with primary focus on securing east-west traffic within the VPC.

VPC vRouter HA Group

ZStack Cloud supports the VPC vRouter high availability (HA) groups. You can deploy a pair of active-standby VPC vRouters in a VPC vRouter HA group. If the active VPC vRouter becomes abnormal, an HA failover is triggered within seconds, automatically switching to the standby VPC vRouter to ensure continuous and stable business operation.

Load Balancer HA

Dedicated-performance load balancers support HA. When the main instance fails, the backup instance can seamlessly switch over and quickly take over the service, which greatly reduces the risk of business interruption. ZStack Cloud supports an LB instance configuration detection mechanism, which triggers an auto-synchronization when the main and backup instance configurations are inconsistent. You can also perform a manual synchronization to ensure configuration consistency in case of auto-synchronization failure.

Netflow

The VPC vRouter supports directed Netflow export for network flow monitoring and analysis. By analyzing the ingress and egress traffic on VPC vRouter NICs through Netflow, you can ​quickly locate network-wide bottlenecks, optimize network topology and bandwidth, and mitigate malicious attacks, thereby enhancing overall network security. Currently, the supported versions of output data flows are V5 and V9.

Port Mirroring

ZStack Cloud supports port mirroring. Port mirroring forwards the ingress and egress traffic of a VM instance NIC to another VM instance. This enables you to capture and analyze packets from the source port without affecting its normal business throughput. Port mirroring facilitates internal network monitoring and management, allowing for rapid troubleshooting of network issues. Port mirroring requires a dedicated traffic network and this network cannot be shared with other networks to ensure transmission efficiency.

Access Control Security

Three-Role Separation

ZStack Cloud supports a Three-Role Separation model, which is an implementation of the Separation of Duties. This model decomposes the super administrator (admin) privileges and assigns them to three distinct roles: the System Administrator, the Security Administrator, and the Security Auditor. The System Administrator is responsible for managing platform resources. The Security Administrator is responsible for managing platform permissions. The Security Auditor is responsible for platform auditing ad compliance. These three roles operate independently and provide checks and balances on each other's authority.

By distributing the comprehensive privileges of the super administrator among three separate roles, this model effectively mitigates security risks associated with over-concentrated super-administrator access and significantly enhances the overall security posture of the platform.

Tenant Management Permissions

Tenant management provides enterprise users with organizational structure management, project-based resource access control, ticket management, independent zone management, and other functions. The tenant management module is offered as an independent feature, which requires a separate license.

Characteristics:
  • User-Role Separation: Roles, defined as collections of permissions, can be flexibly assigned to or removed from users in the tenant management.
  • Roles are categorized into system roles and custom roles. System roles are predefined by the platform with fixed permission scopes, while custom roles can be created by users to meet specific requirements.
  • The UI supports API-level permission control, enabling flexible adaptation to various permission configuration scenarios.

SM2 Certificate Login

The Cloud provides a certificate login feature based on the Shang Mi 2 (SM2) algorithm. After enable this feature, you must use a UKey for login authentication to ensure identity authenticity.

To use this feature, ensure that you have the module license of cryptography security compliance installed and certificate login enabled.

Certificate login can be enabled for the admin or tenants. To enable certificate login for tenants, ensure that the tenant management module license is installed on the Cloud.

Two-Factor Authentication

ZStack Cloud supports two-factor authentication (2FA) as an additional layer of security beyond static passwords. When 2FA is enabled, you must correctly enter a 6-digit dynamic security code from your authenticator app during each login attempt to gain access.

After 2FA is enabled and you successfully log in for the first time, the login QR code is no longer displayed. This helps prevent malicious login attempts and further enhances system security.

AccessKey Authentication

ZStack Cloud supports AccessKey authentication.

AccessKeys include:
  • Local AccessKey, consisting of AccessKey ID and AccessKey Secret, is a secure credential issued by ZStack Cloud. Local AccessKey authorizes third-party users to call the ZStack Cloud's APIs and access its resources. These credentials must be kept strictly confidential.
  • Third-Party AccessKey, consisting of AccessKey ID and AccessKey Secret, is a secure credential provided by a third-party service. Third-party AccessKey authorizes you to call the third-party's APIs and access resources within that external platform. These credentials must be kept strictly confidential.

Operation Auditing

ZStack Cloud provides unified operation log management, recording user logins and resource operations performed under various accounts. The logs capture details such as operation description, task result, operator, client IP, task creation and completion time, and operation return details. Through operation log auditing, you can meet requirements for security analysis, intrusion detection, resource change tracking, and compliance auditing.
Note: If operation requests are forwarded to ZStack Cloud through a load balancer, you need to correctly configure X-Forwarded-For forwarding on the load balancing device so that ZStack Cloud can obtain the actual client IP.

Glossary

Instance

An instance is a virtual machine or server that runs the images of operating systems in Cloud, such as VM instance and elastic baremetal instance.

VM Instance

A VM instance is a virtual machine instance running on a host. A VM instance has its own IP address and can access public networks and run application services.

Volume

A volume provides storage space for a VM instance. Volumes are categorized into root volumes and data volumes.

Root Volume

A root volume provides support for the system operations of a VM instance.

Data Volume

A data volume provides extended storage space for a VM instance.

Image

An image is a template file used to create a VM instance or volume. Images are categorized into system images and volume images.

Instance Offering

An instance offering defines the number of vCPU cores, memory size, network bandwidth, and other configuration settings of VM instances.

Disk Offering

A disk offering defines the capacity and other configuration settings of volumes.

GPU Specification

A GPU specification defines the frame per second (FPS), video memory, resolution, and other configuration settings of a physical or virtual GPU. GPU specifications are categorized into physical GPU specifications and virtual GPU specifications.

vNUMA Configuration

vNUMA uses CPU pinning to passthrough the topology of associated host physical NUMA (pNUMA) nodes to a VM instance, generating a topology of virtual NUMA (vNUMA) nodes for the VM instance. This topology enables a vCPU on a vNUMA node to primarily access the local memory and thus improves VM performance.

NUMA (Non-Uniform Memory Access)

Non-uniform memory access (NUMA) is a computer memory design where the memory access time depends on the memory location relative to the CPU. Under NUMA, a processor can access its own local memory faster than non-local memory and thus improves VM performance.

pNUMA Node (physical NUMA Node)

A pNUMA node (physical NUMA node) is a host NUMA node predefined based on the host NUMA architecture. It is used to manage the CPUs and memory of the host.

pNUMA Topology (physical NUMA Topology)

A pNUMA topology (physical NUMA topology) is the topology of the host NUMA nodes predefined by the CPU vendor based on the host NUMA architecture.

vNUMA Node (virtual NUMA Node)

A vNUMA node (virtual NUMA node) is generated by passing-through associated pNUMA nodes via CPU pinning. It is used to manage the CPUs and memory of a VM instance.

vNUMA Topology (virtual NUMA Topology)

A vNUMA topology (virtual NUMA topology) is the topology of VM NUMA nodes generated by passing-through associated pNUMA nodes via CPU pinning.

Local Memory

Local memory is the memory that a CPU (pCPU or vCPU) accesses through the Uncore iMC (Integrated Memory Controller) of the same NUMA (pNUMA or vNUMA) node. Compared with accessing non-local memory, accessing local memory has lower latencies.

CPU Pinning

CPU pinning assigns the virtual CPUs (vCPUs) of a VM instance to specific physical CPUs (pCPUs) of the host, which improves VM performance.

EmulatorPin Configuration

EmulatorPin assigns all other threads than virtual CPU (vCPU) threads and IO threads of a VM instance to physical CPUs (pCPUs) of the host so that these threads run on assigned pCPUs.

Auto-Scaling Group

An auto-scaling group is a group of VM instances that are used for the same scenarios. An auto-scaling group can automatically scale out or in based on application workloads or health status of VM instances in the group.

Snapshot

A snapshot is a point-in-time capture of data status in a volume.

Affinity Group

A VM scheduling policy is a resource orchestration policy based on which VM instances are assigned hosts to achieve the high performance and high availability of businesses.

Zone

A zone is a logical group of resources such as clusters, L2 networks, and primary storage. Zone is the largest resource scope defined in the Cloud.

Cluster

A cluster is a logical group of hosts (compute nodes).

Host

A host provides compute, network, and storage resources for VM instances.

Primary Storage

A primary storage is one or more servers that store volume files of VM instances. These files include root volume snapshots, data volume snapshots, image caches, root volumes, and data volumes.

Image Storage

An image storage is a storage server that stores VM image templates, including ISO image files.

iSCSI Storage

iSCSI storage is an SAN storage that uses the iSCSI protocol for data transmission. You can add an iSCSI SAN block as a Shared Block primary storage or pass through the block to a VM instance.

FC Storage

FC storage is an SAN storage that uses the FC technology for data transmission. You can add an FC SAN block as a Shared Block primary storage or pass through the block to a VM instance.

NVMe Storage

A type of storage implemented via the NVMe-oF (NVMe over fabrics) protocol. You can add a block device configured from an NVMe storage as SharedBlock primary storage.

L2 Network

An L2 network is a layer 2 broadcast domain used for layer 2 isolation. Generally, L2 networks are identified by names of devices on the physical network.

VXLAN Pool

A VXLAN pool is a collection of VXLAN networks established based on VXLAN Tunnel Endpoints (VTEPs). The VNI of each VXLAN network in a VXLAN pool must be unique.

L3 Network

An L3 network includes IP ranges, gateway, DNS, and other network configurations that are used by VM instances.

Public Network

Generally, a public network is a logical network that is connected to the Internet. However, in an environment that has no access to the Internet, you can also create a public network.

Flat Network

A flat network is connected to the network where the host is located and has direct access to the Internet. VM instances in a flat network can access public networks by using elastic IP addresses.

VPC Network

A VPC network is a private network where VM instances can be created. A VM instance in a VPC network can access the Internet through a VPC vRouter.

Management Network

A management network is used to manage physical resources in the Cloud. For example, you can create a management network to manage access to hosts, primary storage, image storage, and VPC vRouters.

Flow Network

A flow network is a dedicated network for port mirror transmission. You can use a flow network to transmit the mirrors of data packets of NIC ports to the target ports.

VPC vRouter

A VPC vRouter is a dedicated VM instance that provides multiple network services.

VPC vRouter HA Group

A VPC vRouter HA group consists of two VPC vRouters. Either VPC vRouter can be a primary or secondary VPC vRouter for the group. If the primary VPC vRouter does not work as expected, the VPC vRouter becomes the secondary VPC vRouter in the group to ensure high availability of business.

vRouter Image

A vRouter image encapsulates network services and can be used to create VPC vRouters.

Dedicated-Performance LB Image

A dedicated-performance load balancer (LB) image encapsulates dedicated-performance load-balancing services and can be used to create load balancer instances. However, a dedicated-performance load balancer image cannot be used to create VM instances.

vRouter Offering

A vRouter offering defines the number of vCPU cores, memory size, image, management network, and public network configuration settings of VPC vRouters. You can use a vRouter offering to create VPC vRouters that can provide network services for public networks and VPC networks.

LB Instance Offering

A load balancer (LB) instance offering defines the CPU, memory, image, and management network configuration settings used to create LB instances. LB instances provide load balancing services for the public network, flat network, and VPC network.

SDN Controller

The SDN controller is the core of the SDN architecture, responsible for centralized management and control of network devices.

SDN Cluster

A cluster of dedicated VM instances designed to provide highly available SDN capabilities.

SDN Instance

A dedicated VM instance designed to provide SDN network capabilities.

SDN Image

An SDN image encapsulates an SDN software and can be used to create SDN instances.

SDN Instance Offering

An SDN instance offering defines the CPU, memory, SDN image, and management network configuration used for creating SDN instances.

Security Group

A security group provides security control services for VM NICs. It filters the ingress or egress TCP, UDP, and ICMP packets of VM NICs based on the specified security rules.

VIP

In bridged network environments, a virtual IP address (VIP) provides network services such as serving as an elastic IP address (EIP), port forwarding, load balancing, IPsec tunneling. When a VIP provides the preceding network services, packets are sent to the VIP and then routed to the destination network where VM instances are located.

EIP

An elastic IP address (EIP) functions based on the NAT technology. IP addresses in a private network are translated into an EIP that is in another network. This way, private networks can be accessed from other networks by using EIPs.

Port Forwarding

Port forwarding functions based on the layer-3 forwarding service of VPC vRouters. This service forwards traffic flows of the specified IP addresses and ports in a public network to specified ports of VM instances by using the specified protocol. If your public IP addresses are insufficient, you can configure port forwarding for multiple VM instances by using one public IP address and port.

Load Balancer

A load balancer distributes traffic flows of a virtual IP address to backend servers. It automatically inspects the availability of backend servers and isolates unavailable servers during traffic distribution. This way, the load balancer improves the availability and service capability of your business.

Listener

A listener monitors the frontend requests of a load balancer and distributes the requests to a backend server based on the specified policy. In addition, the listener performs health checks on backend servers.

Forwarding Rule

A forwarding rule forwards the requests from different domain names or URLs to different backend server groups.

Backend Server Group

A backend server group is a group of backend servers that handles requests distributed by load balancers. It is the basic unit for traffic distribution by load balancer instances.

Backend Server

A backend server handles requests distributed by a load balancer. You can add a VM instance on the Cloud or a server on a third-party cloud as a backend server.

Frontend Network

A frontend network is a type of network that is associated with a load balancer. Requests from the network are distributed by the load balancer to backend servers based on a specified policy.

Backend Network

A backend network is a type of network that is associated with a load balancer. Requests from frontend networks are distributed by the load balancer to servers in the backend network.

Load Balancer Instance

A load balancer instance is a custom VM instance used to provide load balancing services.

Certificate

If you select HTTPS for a listener, associate it with a certificate to make the listener take effect. You can upload either a certificate or certificate chain.

Firewall

A firewall is an access control policy that monitors ingress and egress traffic of VPC vRouters and decides whether to allow or block specific traffic based on the associated rule sets and rules.

Firewall Rule Set

A firewall rule set is a set of rules that a firewall uses to defend against network attacks. You need to associate a rule set with the egress or ingress flow direction of VPC vRouter NICs to make the rule set take effect.

Firewall Rule

A firewall rule is an access control entry associated with the egress or ingress flow direction of VPC vRouter NICs to defend against network attacks. A firewall rule includes rule priority, match condition, and behavior.

Rule Template

A rule template is a template that you can select when you add rules to a rule set or a firewall.

IP/Port Set

An IP or port set is a set of IP addresses or ports that you can select when you add rules to a rule set or a firewall.

IPsec Tunnel

An IPSec tunnel encrypts and verifies IP packets that transmit over a virtual private network (VPN) from one site to another.

OSPF Area

An Open Shortest Path First (OSPF) area is divided from an autonomous system based on the OSPF protocol. This simplifies the hierarchical management of vRouters.

NetFlow

A NetFlow monitors the ingress and egress traffic of the NICs of VPC vRouters. The supported versions of data flows are V5 and V9.

Port Mirroring

Port mirroring mirrors the traffic data of VM NICs and sends the traffic data to the target ports. This allows for the analysis of data packets of ports and simplifies the monitoring and management of data traffic and makes it easier to locate network errors and exceptions.

Route Table

A route table contains information about various routes that you configure. Route entries in a route table must include the destination network, next hop, and route priority.

CloudFormation

CloudFormation is a service that simplifies the management of cloud resources and automates deployment and O&S. You can create a stack template to configure cloud resources and their dependencies. This way, resources can be automatically configured and deployed in batches. CloudFormation provides easy management of the lifecycle of cloud resources and integrates automatic O&S into API and SDK.

Resource Stack

A resource stack is a stack of resources that are configured by using a stack template. The resources in the stack have dependencies with each other. You can manage resources in the stack by managing the resource stack.

Stack Template

A stack template is a UTF8-encoded file based on which you can create resource stacks. The stack template defines the resources that you want, the dependencies between the resources, and the configuration settings of the resources. When you use a stack template to create a resource stack, CloudFormation parses the template and the resources are automatically created and configured.

Sample Template

A sample template is a commonly used resource stack. You can use a sample template provide by the Cloud to create resource stacks.

Designer

A designer is a CloudFormation tool that allows you to orchestrate cloud resources. You can drag and drop resources on a canvas and use lines to establish dependencies between the resources.

Baremetal Cluster

A baremetal cluster consists of baremetal chassis. You can manage baremetal chassis by managing a baremetal cluster where the chassis reside.

Deployment Server

A deployment server is a server that provides PXE service and console proxy service for baremetal chassis.

Baremetal Chassis

A baremetal chassis is used to create a baremetal instance and is identified based on the BMC interface and IPMI configuration setting.

Preconfigured Template

A preconfigured template is used to create a preconfigured file that allows for unattended batch installation of an operating system for baremetal instances.

Baremetal Instance

A baremetal instance is an instantiated baremetal chassis.

Elastic Baremetal Management

Elastic Baremetal Management provides dedicated physical servers for your applications to ensure high performance and stability. In addition, this feature allows elastic scaling. You can apply for and scale resources based on your needs.

Provision Network

A provision network is a dedicated network for PXE boot and image downloads while creating elastic baremetal instances in a gateway proxy cluster.

Elastic Baremetal Cluster

Provides a separated cluster to manage baremetal nodes.

Gateway Node

A gateway node is a node where the ingress and egress traffic of the Cloud and elastic baremetal instances in gateway proxy clusters is forwarded.

Baremetal Node

A baremetal node is used to create a baremetal instance and is identified based on the BMC interface and IPMI configuration setting.

Elastic Baremetal Instance

An elastic baremetal instance has the same performance as physical servers and allows elastic scaling. You can apply for and scale resources based on your needs.

Elastic Baremetal Offering

An elastic baremetal offering defines the number of vCPU cores, memory size, CPU architecture, CPU model, and other configuration settings of elastic baremetal instances.

vCenter

The Cloud allows you to take over vCenter and manage resources on the vCenter.

VM Instance

A VM instance is an ESXi virtual machine instance running on a host. A VM instance has its own IP address to access public networks and can run application services.

Network

A vCenter network defines the network settings of VM instances on vCenter, such as IP range, gateway, DNS, and network services.

Volume

A volume provides storage space for a VM instance on vCenter. A volume attached to a VM instance can be used as a root volume or data volume. A root volume provides support for the system operations of a VM instance. A data volume provides extended storage space for a VM instance.

Image

An image is a template file used to create a VM instance or volume on vCenter. Images are categorized into system images and volume images.

Event Message

Event Message displays event alarm messages of vCenter that is took over by the Cloud. This feature allows you to locate errors and exceptions efficiently.

Network Topology

A network topology visualizes the network architecture of the Cloud. It allows for efficient planning, management, and improvement of network architecture. Network topologies can be categorized into global topologies and custom topologies.

Performance Analysis

Performance Analysis displays the performance metrics of key resources monitored externally or internally in the Cloud. You can view the performance analysis or export the analysis report as needed to improve the O&M efficiency.

Capacity Management

Capacity Management visualizes the capacities and usages of key resources in the Cloud. You can use this feature to improve O&S efficiency.

MN Monitoring

Management Node (MN) monitoring allows you to view the health status of each management node when you use multiple management nodes to achieve high availability.

Alarm

An alarm is used to monitor the status of time-series data and events and respond to the status change. Alarms can be categorized into resource alarm, event alarm, and extended alarm.

One-Click Alarm

A one-click alarm integrates multiple metrics of a resource. You can create one-click alarms for multiple resources to monitor these resources.

Alarm Template

An alarm template is a template of alarm rules. If you associate an alarm template with a resource group, an alarm is created to monitor the resources in the group.

Resource Group

A resource group consists of resources grouped based on your business needs. If you associate an alarm template with a resource group, the alarm rules specified by the template take effect on all the resources in the group.

Message Template

A message template specifies the text template of a resource alarm message or event alarm message sent to an SNS system.

Message Source

A message source is used to take over extended alarm messages. If you configure alarms for message sources, extended alarm messages can be sent to various endpoints.

Endpoint

An endpoint is a method that users obtain subscribed messages. Endpoints are categorized into system endpoints, email, DingTalk, HTTP application, short message service, and Microsoft Teams.

Alarm Message

An alarm message is a message sent the time when an alarm is triggered.

Current Task

A current task is an ongoing operation performed in the Cloud. You can perform centralized management over ongoing operations.

Operation Log

An operation log is a chronological record of operations on the specified objects and their operation results.

Audit

Audit monitors and records all activities on the Cloud. You can use this feature to implement operation tracking, cybersecurity classified protection compliance, security analysis, troubleshooting, and automatic O&M.

Log Collection

Allows you to collect with one click the log data from the Cloud and various nodes on the Cloud generated in the specified time period and download the log data.

One-Click Inspection

Comprehensively inspects the health status of key resources and services of the Cloud and scores their healthiness based on the inspection results. In addition, the one-click inspection service provides O&M suggestions and inspection reports.

Backup Management

Backup management integrates multiple disaster recovery technologies such as incremental backup and full backup that are suitable for multiple business scenarios. You can implement local backup and remote backup based on your business needs.

Backup Job

You can create a backup job to back up local VM instances, volumes, or databases to a specified storage server on a regular basis.

Local Backup Data

Local backup data of VM instances, volumes, and databases is stored in the local backup server.

Local Backup Server

A local backup server is located at the local data center and is used to store local backup data.

Remote Backup Server

A remote backup server is located at a remote data center or a public cloud and is used to store remote backup data.

Continuous Data Protection (CDP)

Continuous Data Protection (CDP) provides second-level and fine-grained continuous backups for important business systems in VM instances, allowing users to restore VM data to a specific time state, and retrieve files without restoring the system.

CDP Task

You can create a CDP task to continuously back up your VM data to a specified backup server to achieve continuous data protection and recovery.

CDP Data

The backup data generated from continuous data protection on VM instances is stored in local backup servers.

Recovery Point

A recovery point is a data point generated during continuous data protection. A recovery point corresponds to a data record within the recovery point interval specified by the user.

Locked Recovery Point

You can lock or unlock a recovery point as needed. After a recovery point is locked, data of the recovery point will not be automatically cleared or deleted.

Recovery Task

A recovery task helps you quickly restore data by specifying a CDP task and recovery point, and allows you to view the recovery progress and logs in a more friendly way.

Cryptography Security Compliance

The Cryptography Security Compliance service provides applications with cloud security capabilities based on commercial cryptography, meeting the requirements of commercial cryptography application security assessments.

HSM Pool

An HSM pool is a logical group of hardware security modules (HSMs) and is used to provide unified cryptography services such as signature validation and encryption.

HSM

A hardware security module (HSM) is a dedicated device that encrypts, decrypts, and authenticates information by using the cryptographic technology.

Platform Cryptography Security Compliance

Enables the Cloud to meet the requirements of Cryptography Security Compliance through the cryptography capabilities provided by HSM pools.

Certificate Login

Authenticates the identity of a user by using a UKey device.

Data Protection

Protects important data on the Cloud to ensure the data confidentiality and integrity.

Scheduled Job

A scheduled job defines that a specific action be implemented at a specified time based on a scheduler.

Scheduler

A scheduler is used to schedule jobs. It is suitable for business scenarios that last for a long time.

Tag

A tag is used to mark resources. You can use a tag to search for and aggregate resources.

Migration Service

The Cloud provides V2V migration service that allows you to migrate VM instances and data from other virtualized platform to the current cloud platform.

ZMigrate Migration Service

A migration service installed from Application Market that migrates VM instances and their data from VMware environments to the current cloud platform.

V2V Migration

V2V Migration allows you to migrate VM instances from the VMware or KVM platform to the current cloud platform.

V2V Conversion Host

A V2V conversion host is a host in the destination cluster that you need to specify during V2V migration to cache VM instances and data when you implement V2V migration. After the VM instances and data are cached in the V2Vconversion host, they are migrated to the destination primary storage.

User

A user is a natural person that constructs the most basic unit in Tenant Management.

User Group

A user group is a collection of natural persons or a collection of project members. You can use a user group to grant permissions.

Role

A role is a collection of permissions that can be granted to users. A user that assumes a role can call API operations based on the permissions specified by the role. Roles are categorized into platform roles and project roles.

Single Sign-On

The Single Sign-On service provided by the Cloud. It supports seamless access to SSO systems. Through the service, related users can directly log in to the Cloud and manage cloud resources.

Project

A project is a task that needs to be accomplished by specific personnel at a specified time. In Tenant Management, you can plan resources at the project granularity and allocate an independent resource pool to a project. The word Tenant in Tenant Management mainly refers to projects. A project is a tenant.

Project Member

A project member is a member in a project who is granted permissions on specific project resources and can use the resources to accomplish tasks. Project members include the project admin, project managers, and normal project members.

Process Management

Process management is part of ticket management that manages the processes related to the resources of projects. Processes can be categorized into default processes and custom processes.

My Approvals

In the Cloud, only the administrator and project administrators are granted approval permissions. the administrator and project administrators can approve or reject a ticket. If a ticket is approved, resources are automatically deployed and allocated to the specified project.

Bills

A bill is the expense of resources totaled at a specified time period. Billing is accurate to the second. Bills can be categorized into project bills, department bills, and account bills.

Pricing List

A pricing list is a list of unit prices of different resources. The unit price of a resource is set based on the specification and usage time of the resource.

Console Proxy

Console proxy allows you to log in to a VM instance by using the IP address of a proxy.

AccessKey Management

An AccessKey pair is a security credential that one party authorizes another party to call API operations and access its resources in the Cloud. AccessKey pairs shall be kept confidential.

IP Allowlist/Blocklist

An IP allowlist or blocklist identifies and filters IP addresses that access the Cloud. You can create an IP allowlist or blocklist to improve access control of the Cloud.

Application Center

Application Market allows you to add applications to the Cloud and then access the applications with one click. It extends the functionality of the Cloud. You can add default applications through the built-in installation package or add more applications through URLs.

Sub-Account Management

A sub-account can be created by the admin or synced from an SSO authentication system and is managed by the admin. Resources created under a sub-account are managed by the sub-account.

Theme and Appearance

You can customize the theme and appearance of the Cloud.

Email Server

If you select Email as the endpoint of an alarm, you need to set an email server. Then alarm messages are sent to the email server.

Log Server

A log server is used to collect management node logs or the platform operation logs. You can add a log server to the cloud and use the collected logs for operation trace or troubleshooting. This makes your O&M more efficient.

Global Setting

Global Setting allows you to configure settings that take effect on the whole platform.

Scenario Template

Scenario Template provides multiple templates that encapsulate scenario-based global settings. You can apply a template globally with one click based on your business needs. This improves your O&M efficiency.

HA Policy

HA Policy is a mechanism that ensures sustained and stable running of the business if VM instances are unexpectedly stopped or are errored because of errors occurring to compute, network, or storage resources associated with the VM instances. By enabling this feature, you can customize VM HA policies to ensure your business continuity and stability.

Time Management

Manages the Cloud system time and allows you to configure time servers for the Cloud. After you configure NTP time servers for the Cloud, the clock of the time servers is synced with all nodes of the Cloud.

GPU Device

A GPU device is a powerful microprocessor with high computational capabilities. You can use a GPU device to handle intricate graphics rendering and parallel computing jobs, thus improving the efficiency of businesses such as graphic production, video processing, and machine learning.

Script Library

The script library stores and manages script files centrally. By executing scripts on VM instances, you can complete complex O&M operations and automated jobs.

XML Hook

An XML Hook is a script that can flexibly insert or modify parameters in XML files of VM instances. By attaching an XML Hook to a VM instance, you can customize VM configurations and enable specialized functionalities.

Container Service

A simple and user-friendly container management service, providing features like GPU management & scheduling, multi-tenancy, multi-cluster, quota configuration, CI/CD. and microservice. The service reduces the container using complexity and aligns well with traditional user's habits, helping you easily manage and deploy your container cluster, and enjoy the benefits of cloud-native technologies in a quick and convenient way.

Advanced Monitoring Server

An advanced monitoring server is a dedicated VM instance used to receive advanced monitoring data of load balancers and other resources.

Advanced Monitoring Server Image

An advanced monitoring server image encapsulates the advanced monitoring service and can be used to create advanced monitoring server.

Advanced Monitoring Server Offering

An advanced monitoring server offering defines the CPU cores, memory size, image, management network, and public network configurations of advanced monitoring server. You can use an advanced monitoring server offering to create advanced monitoring servers.

Plugin Management

You can package extended resources or tools into standardized plugins for quick installation and integration, expanding the Cloud capabilities.

Region Management

A region is a self-contained cloud environment with independent management node(s), networks, hardware, and cloud resources. ZStack IAM enabled user synchronization and SSO across multiple regions.
Security Whitepaper | 5.5.38 | ZStack Cloud · ZCF | ZStack Resource Center