Connect Alibaba Cloud
Argus scans an Alibaba Cloud account read-only with static keys or a RAM role. Nothing is installed in the account, and Argus only ever reads.
Before you start
- Permission to create a read-only RAM user or RAM role for Argus.
- An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.
Provider-side setup
- Create a RAM user (or a RAM role) with a read-only policy scoped to what you want scanned. Argus only reads.
- For the user, create an AccessKey pair. For a role, note the role ARN the user can assume.
Required permissions
Give the scan identity read-only access to the services Argus scans. The simplest is to attach the managed read-only policies, for example:
AliyunRAMReadOnlyAccess,AliyunECSReadOnlyAccess,AliyunVPCReadOnlyAccess,AliyunOSSReadOnlyAccess,AliyunActionTrailReadOnlyAccess,AliyunLogReadOnlyAccess,AliyunRDSReadOnlyAccess,AliyunCSReadOnlyAccess,AliyunYundunSASReadOnlyAccess
For the RAM-role method, the calling identity also needs
AliyunSTSAssumeRoleAccess.
Connect in Argus
Go to Accounts and click Connect account. Pick Alibaba Cloud, then the recommended Static keys method. Enter:
| Field | Value |
|---|---|
| Account ID | the Alibaba Cloud account id |
| Access key ID | the AccessKey id |
| Access key secret | the AccessKey secret |
| Security token | optional, for temporary credentials |
RAM role
The RAM role method takes a Role ARN plus an Access key ID and Access key secret allowed to assume it.
Connection test
Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.