API standards and multilingual preset SDKs
The OpenAPI of this product (governance/2021-01-20) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.
Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.
Custom signature scenarios
If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.
Account and security preparation
Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.
Account factory
|
API |
Title |
Description |
| EnrollAccount | EnrollAccount | Creates a new resource account or enrolls an existing resource account in Account Factory. |
| BatchEnrollAccounts | BatchEnrollAccounts | Applies an account baseline to multiple existing resource accounts at a time. |
| ListEnrolledAccounts | ListEnrolledAccounts | Queries a list of accounts that are enrolled in the account factory. |
| GetEnrolledAccount | GetEnrolledAccount | Queries the details about an account that is enrolled in the account factory. |
| GetAccountFactoryBaseline | GetAccountFactoryBaseline | Obtains the details of an account factory baseline. |
| ListAccountFactoryBaselines | ListAccountFactoryBaselines | Obtains a list of baselines in the account factory. |
| CreateAccountFactoryBaseline | CreateAccountFactoryBaseline | Creates a baseline of the account factory. |
| DeleteAccountFactoryBaseline | DeleteAccountFactoryBaseline | Deletes an account factory baseline. |
| ListAccountFactoryBaselineItems | ListAccountFactoryBaselineItems | Queries a list of baseline items that are supported by the account factory of Cloud Governance Center (CGC). |
| UpdateAccountFactoryBaseline | UpdateAccountFactoryBaseline | Updates a baseline of the account factory. |
Governance maturity detection
|
API |
Title |
Description |
| RunEvaluation | Run governance check | Runs a Cloud Governance Center governance check. |
| ListEvaluationMetadata | Retrieve governance evaluation item information | Retrieves information about all available governance evaluation items, including names, IDs, descriptions, stages, resource detail metadata, and remediation guidance. |
| ListEvaluationScoreHistory | Retrieve historical governance detection scores | Retrieves the historical scores of governance detection. |
| ListEvaluationMetricDetails | Retrieve non-compliant resource information for a specified check item | Retrieves non-compliant resource information for a specified check item, including the name, ID, category, type, region, and related metadata of non-compliant resources. |
| ListEvaluationResults | Get governance evaluation results and status | Get governance evaluation results and status. |
| GenerateEvaluationReport | Generate Governance Evaluation Report | Generate Governance Evaluation Report |