Skip to main content

Connect Alibaba Cloud

Argus scans an Alibaba Cloud account read-only with static keys or a RAM role. Nothing is installed in the account, and Argus only ever reads.

Before you start​

  • Permission to create a read-only RAM user or RAM role for Argus.
  • An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.

Provider-side setup​

  1. Create a RAM user (or a RAM role) with a read-only policy scoped to what you want scanned. Argus only reads.
  2. For the user, create an AccessKey pair. For a role, note the role ARN the user can assume.

Required permissions​

Give the scan identity read-only access to the services Argus scans. The simplest is to attach the managed read-only policies, for example:

  • AliyunRAMReadOnlyAccess, AliyunECSReadOnlyAccess, AliyunVPCReadOnlyAccess, AliyunOSSReadOnlyAccess, AliyunActionTrailReadOnlyAccess, AliyunLogReadOnlyAccess, AliyunRDSReadOnlyAccess, AliyunCSReadOnlyAccess, AliyunYundunSASReadOnlyAccess

For the RAM-role method, the calling identity also needs AliyunSTSAssumeRoleAccess.

Connect in Argus​

Go to Accounts and click Connect account. Pick Alibaba Cloud, then the recommended Static keys method. Enter:

FieldValue
Account IDthe Alibaba Cloud account id
Access key IDthe AccessKey id
Access key secretthe AccessKey secret
Security tokenoptional, for temporary credentials

RAM role​

The RAM role method takes a Role ARN plus an Access key ID and Access key secret allowed to assume it.

Connection test​

Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.

Official Alibaba Cloud documentation​