Skip to main content

Alibaba Cloud Prerequisites

Cloudaware connects to Alibaba Cloud using either a cross‑account RAM role (recommended) or a RAM user with access keys. Before you start the setup steps, make sure the following prerequisites are in place.

Cloudaware Prerequisites

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).

Alibaba Cloud Account & Identity

  • An Alibaba Cloud account to onboard.
  • Permissions in that account to:
    • Use Resource Orchestration Service (ROS) to create stacks from templates.
    • Create RAM roles and trust policies, or
    • Create RAM users and manage their access keys and policies.

Identity & Authentication Choices

Decide which integration pattern you will use:

  • RAM Role (recommended):
    • A cross‑account RAM role whose trust policy allows the Cloudaware Alibaba account ID to assume it using an External ID.
    • Typically created via a Cloudaware‑provided ROS template.
  • Access Keys:
    • A dedicated RAM user with an access key ID and secret.
    • Read‑only policies attached to that user.

For new integrations and larger environments, prefer RAM roles for stronger isolation and easier rotation.

Network & Connectivity

  • Cloudaware connects to Alibaba Cloud public APIs over the internet; no inbound connectivity from Alibaba Cloud to Cloudaware is required.
  • Ensure that your security policies allow outbound access from Cloudaware to the Alibaba Cloud API endpoints for the regions you use.

Compliance & Approvals

  • Internal approval to grant the required read‑only RAM role or RAM user permissions described in Least-Privilege Policies.
  • Any change‑management tickets or reviews required to create ROS stacks, RAM roles, or RAM users for Cloudaware.

Once these prerequisites are met, continue with Setup to configure the RAM role or access keys and onboard Alibaba accounts into Cloudaware.