All Products
Search
Document Center

:Account-based isolation in fully managed services

Last Updated:May 06, 2026

When you create a single-tenant fully managed service, you can enable the Resource Directory feature to simplify resource management, bill settlement, and log auditing for each service instance. When a user creates a service instance, Compute Nest automatically creates a dedicated member account within your Resource Directory to isolate that service instance's resources. This topic describes how to create and delete these member accounts.

Background

Resource Directory allows you to build an organizational structure that reflects your business needs. You can organize multiple accounts into this structure to create a hierarchy for your resources. This enables centralized management of accounts and resources, helping you meet unified governance requirements for network deployment, bill settlement, user permissions, security compliance, and log auditing. For more information, see What is Resource Directory?.

A member account in Resource Directory is a resource container that Compute Nest automatically creates when a user creates a service instance. This account physically isolates the service instance's cloud resources, creating an independent resource group.

Create member accounts and view resources

When a user creates a service instance, Compute Nest creates a dedicated member account for that instance within your Resource Directory. Compute Nest then deploys all resources required for the service instance into this member account.

  1. Create a service instance.

    For more information, see Create a fully managed service instance.

    After creating the service instance, you can go to Resource Directory to view the member account created for the instance.

  2. View the resources within the member account.

    1. On the details page of the service instance, click the link next to Member Logon URL to go to the Alibaba Cloud Management Console home page.

    2. Click the Resource Management tab to view the service instance's resources.

Delete a member account

Each member account has a one-to-one relationship with a service instance, and all of the instance's resources reside within the account. Therefore, when you delete a service instance, the corresponding member account is also deleted.

Enable member deletion

Before you can delete a member account, you must enable the Member Deletion in the Resource Management console.

  1. Log on to the Resource Management console.

  2. In the navigation pane on the left, choose Resource Directory > Configure.

  3. On the Configure page, click Enable Member Deletion.

Delete a service instance

  1. Log on to the Compute Nest console.

  2. In the navigation pane on the left, click Service Instance.

  3. On the Service Instance page, find the service instance that you want to delete. In the Actions column, click Delete.

  4. In the confirmation dialog box, select I confirm to delete the service instance and the cloud resources that are created for the service instance. and click Confirm Deletion.

Next steps

After deleting the service instance, go to the Resource Management console to verify that the corresponding member account has been removed from your Resource Directory. The account is considered deleted if it no longer appears in the list.

The figure below shows that the member account from the preceding steps is no longer listed, which confirms its deletion.