All Products
Search
Document Center

Compute Nest:Create a fully managed service

Last Updated:Apr 16, 2026

In a fully managed service, all resources and software are deployed in your Alibaba Cloud account. This topic walks you through creating a fully managed service in the Compute Nest console.

How it works

Creating and publishing a fully managed service involves four stages:

  1. Create Service — Configure service information, deployment templates, O&M features, and advanced settings in the Compute Nest console.

  2. Test Service Now — Run a self-test or share the service with selected customers for pre-release testing.

  3. Publish the service — Submit the service for review. After approval, publish it so customers can find and deploy it.

  4. Manage service instances — Customers create service instances based on your published service. All resources are provisioned in your account.

Prerequisites

Before you begin, make sure you have:

Create a fully managed service

  1. Log on to the Compute Nest console.

  2. In the left navigation pane, choose My Services. On the My Services page, click the Created Services tab, then click Create Service.

  3. On the Create Service page, select a creation method:

    • Create Service from Featured Templates: Choose a pre-built template for your architecture or application. Compute Nest pre-fills the service name and icon from the template. You only need to configure basic information.

    • Build Custom Service: Configure all service settings yourself, including deployment templates, O&M features, and advanced options.

  4. For service type, select Fully Managed Service.

    If you selected Create Service from Featured Templates, select Fully Managed Service first, then choose a template. Click View Details to preview a template's deployment description and configuration files before selecting it.
  5. Click Next: Configure Settings.

  6. Configure the service settings. The sections you see depend on the creation method you selected.

Basic information

Configure the following fields. Required fields are noted.

Field Description
Service icon (Optional) Upload a JPG or PNG image. For best clarity, use 192 × 192 pixels.
Service name (Required) 3–200 characters. Letters, digits, and underscores (_) are allowed.
Service description (Required) 10–500 characters.
Service agreement document (Optional) Enter the name and URL of your service agreement document.
Version description (Required) 1–200 characters. Include a version number. Each version must have a unique description.
Default prefix for service instance name (Optional) Up to 40 characters. Letters, digits, hyphens (-), and underscores (_) are allowed. Must start with a letter. This prefix is pre-filled when customers create a service instance and can be changed.
Tag settings (Optional) Add up to 20 tags per resource. See Add a custom tag.
Resource group (Optional) Assign the service to a resource group. See Resource groups.
If you selected Create Service from Featured Templates, the service icon and name are pre-filled from the template. You can change them if needed.

Service deployment

Configure the resources and deployment settings for your service.

Field Description
Create a member in Resource Directory Specify whether Compute Nest automatically creates a member in your Resource Directory when a customer creates a service instance. A member acts as a resource container for physical isolation between service instances. See Fully managed services support account-level isolation.
User type Select Alibaba Cloud if customers can view service instances in their own Compute Nest console. Select Alibaba Cloud if customers don't have an Alibaba Cloud account, or if you don't want to expose Alibaba Cloud to them.
Template input Choose one of the following options: Manually Import Template, Scenario-based Template, or Custom Template. See below for details.
Add parameter mapping Map a dependency parameter to a corresponding parameter. After mapping, the corresponding parameter is hidden from customers. When a customer selects a value for the dependency parameter, the corresponding parameter is automatically set. See Configure parameter mappings.
Add package Define parameter sets. A parameter set groups template parameters with preset values. To let customers modify all values in a set, select Support Custom Parameter Set. See Configure parameter sets.
Hidden parameters Select template parameters to hide from customers during service instance creation. Parameters already set as corresponding parameters in a mapping are hidden automatically — no need to add them here again.
Deployment region Select one or more regions where your service can be deployed. If you select no regions, the service is available in all regions by default.
Role name Select the RAM role that Compute Nest uses to create resources.
Estimated time (Optional) Set the expected deployment time for a service instance. This is displayed on the deployment page so customers know how long to expect.
Deployment package association (Optional) Link deployment packages to your template: Set ECS Image Association replaces the ECS image in the template with the image from a distributed deployment package. Set Container Image Association is recommended when Docker container images are used for service deployment. Set File Association resolves issues with downloading software resources for script-based deployment (for example, when cloud resources are inaccessible over the Internet or the download source is unstable). Set Helm Association keeps your Helm Chart package private using a Helm Chart deployment artifact from Compute Nest.
Create application group (Optional) Group template resources into application groups. Customers can then view resources, monitoring data, logs, and O&M operations by group on their service instance details page. Each resource can belong to only one group.

Template input options:

  • Manually Import Template: Set Deployment Method and Template Name, then paste or upload your template content. ROS templates (JSON or YAML) and Terraform templates are supported. To support multiple deployment scenarios (for example, single-zone and multi-zone deployments), click the 添加 icon next to Template1 to add another template.

    Important

    For trial templates (used to create trial service instances): - Do not define VPC or vSwitch creation in the template. Define them as template parameters instead. - Define security group creation in the template. Do not define selection of an existing security group.

  • Scenario-based Template: Select a scenario from the Scenario drop-down list. The template content is filled in automatically.

  • Custom Template: Select a custom ROS template and version. The template content is filled in automatically. If no custom ROS template is available, create one in the ROS console.

Service O&M (optional)

Configure operations and maintenance (O&M) features for customers managing their service instances.

Field Description
Authorization required for users To let customers perform O&M operations on their service instances, select Grant Permissions to Customers and choose the permissions to grant.
Add O&M operation Define O&M operations that appear on the customer's O&M management page. See Custom O&M operations.
Resource monitoring Configure CloudMonitor alert templates for resources or application groups. To receive alert notifications, select Obtain Permissions, then select Monitoring Permissions. The per-application-group CloudMonitor option is available only if application groups are configured. See Overview of monitoring and alerting.
Prometheus service Enable Prometheus monitoring for services deployed in ACK clusters. See Configure business monitoring and alerting for a fully managed service deployed in an ACK cluster.
Application log Configure log collection. Click Add a Logstore and set the Logstore name, path, and file name. For ECS-based services, configure the file path and name. For pod-based services, configure Logstore settings in the pod's environment variables.
Service instance configuration change Enable configuration change operations for customers. Click Add Operation to define an operation with the following settings:

Configuration change operation settings:

Setting Description
Select template The template used to apply the configuration change. To enable instance type change, set the UpdatePolicy property of the ALIYUN::ECS::InstanceGroup resource to ForAllInstances in the template. To enable update of the ALIYUN::ECS::RunCommand resource, set the Syns property to true in the template; the updated resource is re-executed during configuration change.
Operation name The name of the configuration change operation.
Operation description A description of the operation.
Operation type Upgrade, Downgrade, or Custom. Select one type per operation.
Method Change Plan or Change Parameter.
Select parameters (Available when Method is Change Parameter) The parameters customers can modify. Parameters that cannot be changed are filtered out.

Operation type details:

  • Upgrade — With Change Plan: customers upgrade by switching to a parameter set with a higher serial number. With Change Parameter: customers must increase numeric parameter values. Custom parameter sets are not supported.

  • Downgrade — With Change Plan: customers downgrade by switching to a parameter set with a lower serial number. With Change Parameter: customers must decrease numeric parameter values. Custom parameter sets are not supported.

  • Custom — No restrictions on parameter sets or values. Custom parameter sets are supported.

Advanced configuration (optional)

Field Description
Deployment link permission Control who can access the service deployment link: Public (anyone with the link), Restricted (only users on the whitelist — see Modify service deployment permissions), or Hidden (the service details page is hidden; unauthorized users see a "service does not exist" message).
VPC private access Establish a private connection between your service and the customer's network using PrivateLink. Select the Server Load Balancer or endpoint service from the deployment template.
Payer selection Select whether the Service Consumer or Service Provider pays for resources. The Service Provider billing method is disabled by default. To enable it, request it in the Quota Center console.
VPC reverse private access Access resources in the customer's VPC through a reverse private connection.
Reverse endpoint service configuration Set the region and endpoint service for the reverse endpoint.
Custom domain name Let customers access your service over a private network using a custom domain name. Use a domain name consistent with your service's public domain name.
OAuth authentication Enable password-free login for customers. Connect to a RAM OAuth application through Compute Nest so customers can log on to your software using their Alibaba Cloud accounts without a password. After enabling, select the login address from Select Application and set Application logon address.
Allow service providers to apply for distribution authorization Let Compute Nest distributors request authorization to re-create and distribute your service. Review and approve requests as they come in. Settle payments with distributors separately.
Retention period after expiration Set how many days the service instance is retained after it expires.
Enable data security risk check within VPC Run a VPC-internal data breach check, for example when an ECS instance is moved in or out of a VPC.
  1. Click Create Service, then click OK in the confirmation dialog box.

After the service is created, click View Service to go to the My Services page, or click Test Service Now to start testing immediately.

View the service

After creation, the service appears on the My Services page.

lQLPKc3q5jF075nNAivNA5CwVSK50o9JHMAGOtdOqpkiAA_912_555

What's next

  1. Test Service Now Run a self-test, or pre-publish the service and share it with specific customers for testing. See Test a service.

  2. Publish the service. Submit the service for review. After it is approved, publish it online. See Publish a service.

  3. Deploy a service instance. Once your service is published, customers can create service instances where all resources are provisioned in your account. See Create a fully managed service instance.