A new Bastionhost instance must be enabled before you can use it.
Prerequisites
A Bastionhost instance is purchased. Purchase an instance.
Procedure
Log on to the Bastionhost console.
On first login, create a service-linked role when prompted. This role grants Bastionhost access to other cloud resources for O&M security.
In the top navigation bar, select a region. Find the target instance and click Run.
In the panel that appears, configure the startup parameters.
Basic Edition
Parameter
Description
Select Network
Select the VPC and vSwitch for the Bastionhost instance.
Select a VPC:
The VPC cannot be changed after enablement.
For private network connectivity, place the instance in the same VPC as the ECS instances you manage.
A Basic Edition instance requires a vSwitch with at least three available IP addresses. If the vSwitch has insufficient IPs, enablement fails. Try a different vSwitch or create a new one. Create a vSwitch.
NoteFor Basic Edition, you can switch the instance to a vSwitch in a different zone after enablement. Configure a Bastionhost instance.
ECS Security Groups
Select the security group for your ECS instances.
Add the instance to at least one basic security group before enabling. An access rule is automatically generated to allow access to ECS assets in that group.
The instance cannot be added to an advanced security group. Manually configure access rules for advanced security groups.
The instance cannot be added to a security group managed by another cloud service. Create a new basic security group if needed.
NoteAfter enablement, you can change the security group. Configure a Bastionhost instance.
If a security group blocks access to an asset after enablement, manually configure an access rule. Add a security group rule.
Enterprise Edition
Parameter
Description
Select Network
Select the VPC for the Bastionhost instance.
The VPC cannot be changed after enablement.
For private network connectivity, place the instance in the same VPC as the ECS instances you manage.
Select vSwitch And Primary Zone
Enterprise Edition supports active-active deployment across a primary and secondary zone. Select a vSwitch in the primary zone.
An Enterprise Edition instance requires a vSwitch with at least four available IP addresses. If the vSwitch has insufficient IPs, enablement fails. Try a different vSwitch or create a new one. Create a vSwitch.
Select vSwitch And Secondary Zone
For disaster recovery, select a vSwitch in a secondary zone. If you purchase an Enterprise Edition instance without selecting a secondary zone, a dual-engine deployment runs in the primary zone.
Security Group
Select the security group for your ECS instances.
Add the instance to at least one basic security group before enabling. An access rule is automatically generated to allow access to ECS assets in that group.
The instance cannot be added to an advanced security group. Manually configure access rules for advanced security groups.
The instance cannot be added to a security group managed by another cloud service. Create a new basic security group if needed.
NoteAfter enablement, you can change the security group. Configure a Bastionhost instance.
If a security group blocks access to an asset after enablement, manually configure an access rule. Add a security group rule.
Private O&M Settings
Bastionhost uses Alibaba Cloud PrivateLink to establish a private connection between your VPC and Bastionhost, enabling secure web-based O&M over a private network.
After enabling, select an endpoint security group for the PrivateLink connection.
NoteYou can enable private O&M later if not configured during instance enablement. Configure a Bastionhost instance.
Click Next. After the startup check passes, click Enable.
Initialization typically takes 10 to 15 minutes. After completion, the instance status changes to Running.
What to do next
After enablement, find the instance and click Manage to open the management console. Log on to the Bastionhost management console.