All Products
Search
Document Center

Bastionhost:Enable a Bastionhost instance

Last Updated:Jun 04, 2026

A new Bastionhost instance must be enabled before you can use it.

Prerequisites

A Bastionhost instance is purchased. Purchase an instance.

Procedure

  1. Log on to the Bastionhost console.

    On first login, create a service-linked role when prompted. This role grants Bastionhost access to other cloud resources for O&M security.

  2. In the top navigation bar, select a region. Find the target instance and click Run.

  3. In the panel that appears, configure the startup parameters.

    1. Basic Edition

      Parameter

      Description

      Select Network

      Select the VPC and vSwitch for the Bastionhost instance.

      • Select a VPC:

        • The VPC cannot be changed after enablement.

        • For private network connectivity, place the instance in the same VPC as the ECS instances you manage.

      • A Basic Edition instance requires a vSwitch with at least three available IP addresses. If the vSwitch has insufficient IPs, enablement fails. Try a different vSwitch or create a new one. Create a vSwitch.

        Note

        For Basic Edition, you can switch the instance to a vSwitch in a different zone after enablement. Configure a Bastionhost instance.

      ECS Security Groups

      Select the security group for your ECS instances.

      Add the instance to at least one basic security group before enabling. An access rule is automatically generated to allow access to ECS assets in that group.

      • The instance cannot be added to an advanced security group. Manually configure access rules for advanced security groups.

      • The instance cannot be added to a security group managed by another cloud service. Create a new basic security group if needed.

      Note
    2. Enterprise Edition

      Parameter

      Description

      Select Network

      Select the VPC for the Bastionhost instance.

      • The VPC cannot be changed after enablement.

      • For private network connectivity, place the instance in the same VPC as the ECS instances you manage.

      Select vSwitch And Primary Zone

      Enterprise Edition supports active-active deployment across a primary and secondary zone. Select a vSwitch in the primary zone.

      An Enterprise Edition instance requires a vSwitch with at least four available IP addresses. If the vSwitch has insufficient IPs, enablement fails. Try a different vSwitch or create a new one. Create a vSwitch.

      Select vSwitch And Secondary Zone

      For disaster recovery, select a vSwitch in a secondary zone. If you purchase an Enterprise Edition instance without selecting a secondary zone, a dual-engine deployment runs in the primary zone.

      Security Group

      Select the security group for your ECS instances.

      Add the instance to at least one basic security group before enabling. An access rule is automatically generated to allow access to ECS assets in that group.

      • The instance cannot be added to an advanced security group. Manually configure access rules for advanced security groups.

      • The instance cannot be added to a security group managed by another cloud service. Create a new basic security group if needed.

      Note

      Private O&M Settings

      Bastionhost uses Alibaba Cloud PrivateLink to establish a private connection between your VPC and Bastionhost, enabling secure web-based O&M over a private network.

      After enabling, select an endpoint security group for the PrivateLink connection.

      Note

      You can enable private O&M later if not configured during instance enablement. Configure a Bastionhost instance.

  4. Click Next. After the startup check passes, click Enable.

    Initialization typically takes 10 to 15 minutes. After completion, the instance status changes to Running.

What to do next

After enablement, find the instance and click Manage to open the management console. Log on to the Bastionhost management console.