All Products
Search
Document Center

Compute Nest:File deployment packages

Last Updated:Jun 20, 2026

Compute Nest uses file deployment packages to address software download challenges during script-based deployments, such as when cloud resources lack public internet access or download sources are unstable. This topic describes the use cases and principles of file deployment packages, and explains how to create and use them.

Background

  • Why use file deployment packages?

    Compute Nest uses file deployment packages to address software download challenges caused by a lack of public internet access for cloud resources, large file sizes, or unstable sources. A service provider uploads a file to a specified OSS bucket. The system then automatically replicates the file to multiple regions. During deployment, it replaces a placeholder in the template with the private OSS URL of the deployment region, ensuring stable and secure data transfer.

  • What are the advantages of file deployment packages?

    Service providers only need to add a placeholder to a template and configure the file association in the Compute Nest console.

    1. File replication: Compute Nest copies the file uploaded by the service provider to a shared Compute Nest account. Within this account, the file is replicated to OSS buckets across multiple regions.

    2. File association: Compute Nest recognizes the placeholder ({{ computeneset::file::xxx}}) in a template and associates it with a file deployment package during service creation. When a user deploys the service, Compute Nest identifies the deployment region and automatically replaces the placeholder with the corresponding regional OSS URL, enabling dynamic URL substitution.

    3. Permission management: A deployment package inherits its permissions from the associated service. If a deployment package is not associated with any service, it is private. If it is associated with at least one public service, the deployment package becomes public. If it is associated with only private services, the deployment package remains private.

    4. Private network downloads: Compute Nest downloads file deployment packages over a private network. When replacing the placeholder, Compute Nest generates a private OSS HTTP URL by default, which ensures a stable and secure download.

Usage

Define a placeholder in the service's ROS template and associate it with a file deployment package. When a service instance is created, Compute Nest automatically identifies the placeholder in the template and replaces it with the file URL corresponding to the service instance's deployment region.

The fixed expressions for the file association placeholder are as follows:

  • (Recommended) If the file URL of the deployment package is a private URL, use the following expression: {{ computenest::file:: ${key}}}.

  • If the file URL of the deployment package is a public URL, use the following expression: {{ computenest::publicfile::${key}}}.

    Note

    In these expressions, ${key} can be any word but must not contain spaces.

The following YAML examples show how to use file deployment packages for deployment:

Important
  • When defining a file association placeholder in a template, we recommend that you enclose the placeholder in single ('') or double ("") quotation marks.

  • If you use the wget command to download a file, we recommend adding the -O parameter to specify the output filename.

  • Define a placeholder in a standard template.

    The following example shows how to define placeholders in the userData section to download files and rename them to TestFirst.txt and TestSecond.tar.

    TiDBServer:
        Type: ALIYUN::ECS::InstanceGroup
        Properties:
          ……
          UserData:
            Fn::Sub:
              - |
                #!/bin/sh
                sleep 10
                wget '{{ computenest::file::DemoFirst }}' -O TestFirst.txt
                wget '{{ computenest::file::DemoSecond }}' -O TestSecond.tar
                ……
  • The database type MigrateTask defines a flag.

    SQLDump:
        Type: ALIYUN::RDS::MigrateTask
        Properties:
            ……
          DBName: mytest
          DBInstanceId:
            Fn::GetAtt:
              - Database
              - DBInstanceId
          OssObjectPositions: {{ computenest::file::DemoFirst }}

Create and use file deployment packages

Prerequisites

Prepare the file that you want to upload.

Create a file deployment package

  1. Configure basic information for the deployment package.

    1. Log on to the Compute Nest console. In the left-side navigation pane, choose Service Deployment Package. On the Packages tab, click Create Deployment Package.

    2. In the Basic Information section, configure the following parameters.

      Parameter

      Description

      Deployment Package Name

      The name can contain Chinese characters, English letters, digits, and underscores (_). The name must be 3 to 128 characters long, where a Chinese character counts as two characters. The deployment package name cannot be changed after creation.

      Version Name

      The name can contain Chinese characters, English letters, digits, and underscores (_). The name must be 3 to 50 characters long, where a Chinese character counts as two characters.

      Description

      The description must be 10 to 500 characters long. A Chinese character counts as two characters.

      Resource Group

      Select the resource group to which the deployment package belongs.

      Resource groups allow you to group your cloud resources by usage, permissions, or ownership, enabling hierarchical resource management for multiple users and projects within an organization. For more information, see resource groups.

      Tag Settings

      Select or enter a complete tag key and tag value to add a tag to the deployment package. You can bind up to 20 tags to a resource. If no tag keys or values are available, you can create a custom tag. For more information, see Create and bind a custom tag.

  2. Configure the file deployment package.

    1. In the Deployment Package Content section, set Deployment Package Type to File.

    2. Select the region to which you want to upload the file. Then, depending on the file size, select Upload Local File or Upload Flie Larger Than 5 GB.

      (Optional) To upload a file larger than 5 GB, perform the following steps.

      1. Click Obtain Access Credential. A dialog box appears with upload commands for a local environment or an ECS internal network environment. Copy the appropriate command and replace <source_file> with your source filename and <target_file> with the target filename in Compute Nest.

      2. Run the upload command in the Alibaba Cloud CLI to upload the file.

        xxx oss://computenest-artifacts-draft-cn-beijing/1563457855438522/cn-beijing/2ddcfb2065f94e678ab4/cyxtest -e oss-cn-beijing.aliyuncs.com --region cn-beijing --mode StsToken --access-key-id STS.NU2iEZ4DdDQeajGyvfaUnMCeV --access-key-secret FAkZhpdf3x4JnwMaAQf3Eda7j5aLVobZAk1oMthwr4H --sts-token CAISoQR1q6ft5B2yfSjIr5aHIv/u2Zt8500Y0z2nXYzbdbpCoob0tDz2ZH1Le3NrBO8esfgymGFlU6v8d1o0oZ88rHWGbKRn4vv8OGtF79PKCEkeXosf1Z0LOLNTTOV2LQh5KK71ER.jmHKJmXcFnhunJZL9GYHGz0tzbHKLSNjZ14fM110iCzcTbAvpP0wrJms7V0HHDNNPGrQC+IS23LFxhpQxZbg2Fy4rjdscqH3Uj/i1zmyy+YJqqHaJoS1d82Kpn9Y0C30I4QcbHagnHI7x9D+Y9/1rAmiJDcpYO2BFxJ5xiaPs/J9sFuNAZjepUiH61NoIIX/J8egOHIkJntwBtgJPxCVz+1JLqt28zZAuikRN1beL/wICvcvdMu340gjZGOGKA5MdsE9b3Z2gFR0iQzrGMegr41nEfkKoTe2P3aa.A00JKx61Ay1o4HWegffHujFinZFYMV; xxx
        xxx :V6f8sjBRkR0HQaH3mDB;/Io7mHtGb4Fxz00aLso4q1n3cHJ5tG7LBvZ61j1jhiC0zBQWt2oRYE8sBAgB1Ler1eXZrm5JmNBI3CVP0gd6pT0IhqIIUeE3z0ncUxqAAUc8e5m4NgmE/g4.ZJzJh77WH8pnklUrh9I3bId7FhTuZQ8X0C6OYRXmS3cWAD2uLt1gVCbBoM51HDOQ9egrKagfIyc0waDNaVDOGW4t+ck8WaAnD5gfNMa.Q55+/7CQkQ0bJCWCYSU6ogoVfWUkrbp38iFh5kk2rLya3K0tkghc7s/IAA=
        Succeed: Total num: 1, size: 41,472. OK num: 1(upload 1 files).
        average speed 29000(byte/s)
        1.464391(s) elapsed
      3. In the File Upload URL field, enter the name of the uploaded file.

    3. (Optional) Use the Configure Script Command feature. Script commands are primarily used for service instance upgrades and are not required for file association.

      If you enable this feature, you must configure the following parameters.

      1. OS: Select the operating system that corresponds to your service.

      2. New Resource Download Directory: Specify the download directory on the ECS instance. If the directory does not exist, it is created before the download begins.

      3. Command Type: Set the type of command.

      4. Command: Specify the command to run after the file is downloaded.

        If you need to reference specific configuration parameters of the service instance, use commands to call them in the command content. For more information, see Parameter reference.

    4. In the Distribution Settings section, the file deployment package is distributed to all regions by default.

    5. Click Publish Deployment Package.

      After a deployment package is published, its current version cannot be modified. To make changes, you must create a new version or a new deployment package.

  3. View the deployment package.

    1. Return to the Service Deployment Packages page. Click the name of the deployment package to go to the Deployment Package Details page and view the deployment progress.

    2. When the status changes to Available, click View to get the Distribution Results for the file deployment package.

      The distribution results include the Distribution region and the corresponding distribution link, showing records for each region where the deployment package has been distributed, such as China (Beijing) and China (Ulanqab).

Use a file deployment package

This section uses creating a private service as an example to explain file deployment package configuration.

  1. Log on to the Compute Nest console.

  2. In the left-side navigation pane, click My Services. On the Created Services tab of the My Services page, click Create Service.

  3. On the Create New Service page, select Custom launch as the creation method, select Private Service as the service type, and click Next: Configure Settings.

  4. Enter the basic service information and select a ROS template.

    If the ROS template contains {{ computenest::file::test }} or {{ computenest::publicfile::test }}, you can Set File Association in the Deployment Package Association section.

    Sample template

    Note

    This sample template is for testing purposes only.

    ROSTemplateFormatVersion: '2015-09-01'
    Description:
      en: Create a new ACK deployment
      zh-cn: new ack
    Parameters:
      PayType:
        Type: String
        Label:
          en: ECS Instance Charge Type
          zh-cn: 付费类型
        Default: PostPaid
        AllowedValues:
          - PostPaid
          - PrePaid
        AssociationProperty: ChargeType
        AssociationPropertyMetadata:
          LocaleKey: InstanceChargeType
      PayPeriodUnit:
        Type: String
        Label:
          en: Pay Period Unit
          zh-cn: 购买资源时长周期
        Default: Month
        AllowedValues:
          - Month
          - Year
        AssociationProperty: PayPeriodUnit
        AssociationPropertyMetadata:
          Visible:
            Condition:
              Fn::Not:
                Fn::Equals:
                  - ${PayType}
                  - PostPaid
      PayPeriod:
        Type: Number
        Description:
          en: When the resource purchase duration is Month, the value of Period ranges from 1 to 9, 12, 24, 36, 48, or 60. <br><b><font color='red'> When ECS instance types are PrePaid valid </b></font>
          zh-cn: 当购买资源时长为Month时,Period取值:1~9 <br><b><font color='red'>当ECS实例类型为PrePaid有效</b></font>
        Label:
          en: Period
          zh-cn: 购买资源时长
        Default: 1
        AllowedValues:
          - 1
          - 2
          - 3
          - 4
          - 5
          - 6
          - 7
          - 8
          - 9
        AssociationProperty: PayPeriod
        AssociationPropertyMetadata:
          Visible:
            Condition:
              Fn::Not:
                Fn::Equals:
                  - ${PayType}
                  - PostPaid
      ZoneId:
        Type: String
        AssociationProperty: ALIYUN::ECS::Instance:ZoneId
        Label:
          en: Zone ID
          zh-cn: 可用区
        Default: cn-hangzhou-h
      VpcCidrBlock:
        Type: String
        Label:
          en: VPC CIDR IPv4 Block
          zh-cn: 专有网络IPv4网段
        Description:
          zh-cn: VPC的ip地址段范围,<br>您可以使用以下的ip地址段或其子网:<br><font color='green'>[10.0.0.0/8]</font><br><font color='green'>[172.16.0.0/12]</font><br><font color='green'>[192.168.0.0/16]</font>
          en: 'The ip address range of the VPC in the CidrBlock form; <br>You can use the following ip address ranges and their subnets: <br><font color=''green''>[10.0.0.0/8]</font><br><font color=''green''>[172.16.0.0/12]</font><br><font color=''green''>[192.168.0.0/16]</font>'
        Default: 192.168.0.0/16
        AssociationProperty: ALIYUN::VPC::VPC::CidrBlock
      VSwitchCidrBlock:
        Type: String
        Label:
          en: VSwitch CIDR Block
          zh-cn: 交换机子网网段
        Description:
          zh-cn: 必须属于VPC的子网段。
          en: Must belong to the subnet segment of VPC.
        Default: 192.168.1.0/24
        AssociationProperty: ALIYUN::VPC::VSwitch::CidrBlock
        AssociationPropertyMetadata:
          VpcCidrBlock: VpcCidrBlock
      LoginPassword:
        NoEcho: true
        Type: String
        Description:
          en: Server login password, Length 8-30, must contain three(Capital letters, lowercase letters, numbers, ()`~!@#$%^&*_-+=|{}[]:;<>,.?/ Special symbol in)
          zh-cn: 服务器登录密码,长度8-30,必须包含三项(大写字母、小写字母、数字、 ()`~!@#$%^&*_-+=|{}[]:;<>,.?/ 中的特殊符号)
        Label:
          en: Instance Password
          zh-cn: 实例密码
        ConstraintDescription:
          en: Length 8-30, must contain three(Capital letters, lowercase letters, numbers, ()`~!@#$%^&*_-+=|{}[]:;<>,.?/ Special symbol in)
          zh-cn: 长度 8-30,必须包含三项(大写字母、小写字母、数字、 ()`~!@#$%^&*_-+=|{}[]:;<>,.?/ 中的特殊符号)
        AssociationProperty: ALIYUN::ECS::Instance::Password
        AllowedPattern: ^[a-zA-Z0-9-\(\)\`\~\!\@\#\$\%\^\&\*\_\-\+\=\|\{\}\[\]\:\;\<\>\,\.\?\/]*$
        MinLength: 8
        MaxLength: 30
        Default: computenest*12345
      WorkerInstanceType:
        Type: String
        Label:
          en: Worker Nodes Types
          zh-cn: Worker节点规格
        AssociationProperty: ALIYUN::ECS::Instance::InstanceType
        AssociationPropertyMetadata:
          ZoneId: ${ZoneId}
        Default: ecs.g6.large
      WorkerSystemDiskCategory:
        Type: String
        AllowedValues:
          - cloud_efficiency
          - cloud_ssd
          - cloud_essd
        AssociationPropertyMetadata:
          LocaleKey: DiskCategory
          InstanceType: ${WorkerInstanceType}
        Label:
          en: Worker System Disk Category
          zh-cn: Worker 系统盘磁盘类型
        Default: cloud_essd
      WorkerSystemDiskSize:
        Type: Number
        Label:
          en: Worker System Disk Size(GB)
          zh-cn: Worker节点系统盘大小(GB)
        MinValue: 1
        Default: 120
      PodCidr:
        Type: String
        Description:
          zh-cn: 请填写有效的私有网段,即以下网段及其子网:10.0.0.0/8,172.16-31.0.0/12-16,192.168.0.0/16<br>不能与 VPC 及 VPC 内已有 Kubernetes 集群使用的网段重复。<font color='blue'><b>创建成功后不能修改</b></font>
          en: 'Please fill in a valid private segment, i.e. the following segments and their subnets: 10.0.0.0/8, 172.16-31.0.0/12-16, 192.168.0.0/16<br> which cannot duplicate the network segments already used by clusters in VPC and VPC Kunetberes. <font color=''blue''><b>Cannot be modified after successful creation</b></font>'
        Label:
          zh-cn: Pod 网络 CIDR
          en: Pod Network CIDR
        AssociationProperty: ALIYUN::CS::ManagedKubernetesCluster::PodCidr
        Default: 10.0.0.0/16
      ServiceCidr:
        Type: String
        Description:
          zh-cn: 可选范围:10.0.0.0/16-24,172.16-31.0.0/16-24,192.168.0.0/16-24<br>不能与 VPC 及 VPC 内已有 Kubernetes 集群使用的网段重复。<font color='blue'><b>创建成功后不能修改</b></font>
          en: 'Optional range: 10.0.0.0/16-24, 172.16-31.0.0/16-24, 192.168.0.0/16-24<br> cannot duplicate segments already used by existing Kubernetes clusters in VPC and VPC.<font color=''blue''><b>Cannot be modified after successful creation</b></font>'
        Label:
          zh-cn: Service CIDR
          en: Service CIDR
        AssociationProperty: ALIYUN::CS::ManagedKubernetesCluster::ServiceCidr
        Default: 172.16.0.0/16
    Resources:
      EcsVpc:
        Type: ALIYUN::ECS::VPC
        Properties:
          VpcName:
            Ref: ALIYUN::StackName
          CidrBlock:
            Ref: VpcCidrBlock
      EcsVSwitch:
        Type: ALIYUN::ECS::VSwitch
        Properties:
          VSwitchName:
            Ref: ALIYUN::StackName
          VpcId:
            Ref: EcsVpc
          ZoneId:
            Ref: ZoneId
          CidrBlock:
            Ref: VSwitchCidrBlock
      EcsSecurityGroup:
        Type: ALIYUN::ECS::SecurityGroup
        Properties:
          SecurityGroupName:
            Ref: ALIYUN::StackName
          VpcId:
            Ref: EcsVpc
          SecurityGroupEgress:
            - PortRange: '-1/-1'
              Priority: 1
              IpProtocol: all
              DestCidrIp: 0.0.0.0/0
              NicType: intranet
          SecurityGroupIngress:
            - PortRange: '-1/-1'
              Priority: 1
              IpProtocol: all
              SourceCidrIp:
                Ref: PodCidr
              Description: pod网络访问开放
              NicType: intranet
            - PortRange: '-1/-1'
              Priority: 1
              IpProtocol: all
              SourceCidrIp:
                Ref: VpcCidrBlock
              Description: vpc网络访问开放
              NicType: intranet
            - PortRange: '-1/-1'
              Priority: 1
              IpProtocol: icmp
              SourceCidrIp: 0.0.0.0/0
              Description: icmp协议端口放开
              NicType: intranet
      ManagedKubernetesCluster:
        Type: ALIYUN::CS::ManagedKubernetesCluster
        Properties:
          Name:
            Ref: ALIYUN::StackName
          ChargeType:
            Ref: PayType
          Period:
            Ref: PayPeriod
          PeriodUnit:
            Ref: PayPeriodUnit
          VSwitchIds:
            - Ref: EcsVSwitch
          VpcId:
            Ref: EcsVpc
          WorkerInstanceTypes:
            - Ref: WorkerInstanceType
          NumOfNodes: 3
          ClusterSpec: ack.pro.small
          ContainerCidr:
            Ref: PodCidr
          ServiceCidr:
            Ref: ServiceCidr
          ZoneIds:
            - Ref: ZoneId
          SecurityGroupId:
            Ref: EcsSecurityGroup
          WorkerSystemDiskCategory:
            Ref: WorkerSystemDiskCategory
          WorkerSystemDiskSize:
            Ref: WorkerSystemDiskSize
          LoginPassword:
            Ref: LoginPassword
          SnatEntry: true
          Addons:
            - Name: flannel
              Config: ''
      ComputenestHelmApplication:
        Type: MODULE::SHARE::1563457855438522::HelmDeploy
        Version: v5
        DependsOn:
          - ManagedKubernetesCluster
        Properties:
          ClusterId:
            Fn::GetAtt:
              - ManagedKubernetesCluster
              - ClusterId
          ChartIdentifier: '{{ computenest::helmpull::springBoot }}'
          ChartValues:
            image:
              fullname: '{{ computenest::acrimage::springBootDemo }}'
            dockerConfigJson: '{{ computenest::acr::dockerconfigjson }}'
            service:
              type: LoadBalancer
              port: 8080
          Namespace:
            Ref: ALIYUN::StackName
          ReleaseName: spring-boot-chart
      # Wait for 1 minute for the resources to be ready.
      HelmSleep:
        Type: ALIYUN::ROS::Sleep
        DependsOn:
          - ComputenestHelmApplication
        Properties:
          CreateDuration: 60
      # Get service information and output it.
      ClusterApplicationResources:
        Type: DATASOURCE::CS::ClusterApplicationResources
        DependsOn:
          - HelmSleep
        Properties:
          ClusterId:
           Fn::GetAtt:
            - ManagedKubernetesCluster
            - ClusterId
          Kind: Service
          Name: spring-boot-chart
          Namespace:
            Ref: ALIYUN::StackName
          JsonPath: $.status.loadBalancer.ingress[0].ip
          FirstMatch: true
    Outputs:
      # Display the public IP as the HTTP address in the console.
      Endpoint:
        Description:
          zh-cn: 对外暴露的公网IP地址
          en: Public IP Addresses
        Value:
          Fn::Sub:
            - "http://${ServerAddress}:8080"
            - ServerAddress:
                Fn::GetAtt:
                  - ClusterApplicationResources
                  - Response
    Metadata:
      ALIYUN::ROS::Interface:
        ParameterGroups:
          - Parameters:
              - PayType
              - PayPeriodUnit
              - PayPeriod
            Label:
              en: PayType Configuration
              zh-cn: 付费类型配置
          - Parameters:
              - ZoneId
              - VpcCidrBlock
              - VSwitchCidrBlock
              - LoginPassword
            Label:
              en: Basic Configuration
              zh-cn: 基础配置
          - Parameters:
              - WorkerInstanceType
              - WorkerSystemDiskCategory
              - WorkerSystemDiskSize
              - ServiceCidr
              - PodCidr
            Label:
              en: Kubernetes
              zh-cn: Kubernetes配置
  5. Click Deployment Package Association under Set File Association. In the dialog box that appears, select the deployment package and version, then click OK.

    In the dialog box, the Association identifier field shows a value such as {{ computenest::file::springboot }}, and only file-type deployment packages can be selected.

    After the configuration is complete, the Association identifier field displays the corresponding template variable (for example, {{ computenest::file::springboo…), and the Associated deployment package field displays the name of the selected deployment package.

  6. After you create and test the service, test the service against the Compute Nest review criteria, and then submit it for review. For more information, see Review criteria.

  7. After the service passes the review, publish the service. For more information, see Publish a service.

    When a user creates a service instance, Compute Nest automatically replaces the placeholders in the template with the file URLs for the service instance's deployment region.

    • The following code shows the replacement result for placeholders in a standard template.

      • If the deployment package uses a private URL, the result is as follows:

        Resources:
          ECSInstances:
            Type: 'ALIYUN::ECS::InstanceGroup'
            Properties:
              UserData: |
                #!/bin/sh
                mkdir /root/lzq
                cd /root/lzq
                wget 'https://computenest-artifacts-cn-wulanchabu.oss-cn-wulanchabu-internal.aliyuncs.com/xxx/cn-zhangjiakou/xxx/sample-text.txt'
                wget 'https://computenest-artifacts-cn-wulanchabu.oss-cn-wulanchabu-internal.aliyuncs.com/xxx/cn-guangzhou/xxx/changes.txt'
                wget {{DemoThird}}
              SystemDiskCategory:
      • If the deployment package uses a public URL, the result is as follows:

        Properties:
          UserData: |
            #!/bin/sh
            mkdir /root/lzq
            cd /root/lzq
            wget 'https://computenest-artifacts-cn-wulanchabu.oss-cn-wulanchabu.aliyuncs.com/xxx/cn-beijing/xxx/virtual-background-1976.jpg'
            wget {{DemoThird}}
          SystemDiskCategory:
            Ref: SystemDiskCategory
          VpcId:
    • In a MigrateTask of the database type, Compute Nest changes the URL of the file deployment package to the format of the OssObjectPositions parameter.

      Because the OssObjectPositions parameter is composed of three parts separated by a colon (:) (the OSS endpoint, the OSS bucket name, and the key of the backup file on OSS), Compute Nest converts the URL of a file deployment package into this format. For example: oss-ap-southeast-1.aliyuncs.com:rdsmssqlsingapore:autotest_2008R2_TestMigration_FULL.bak. For more information, see ALIYUN::RDS::MigrateTask.

      },
      "OssObjectPositions": "oss-cn-hangzhou-internal.aliyuncs.com:computenest-artifacts-cn-hangzhou:xxx/cn-zhangjiakou/xxx/sample-text.txt",
      "DBInstanceId": {
        ...
      }

Related topics

  • For more information about how to create a Compute Nest service, see Create a service.

  • If you no longer need a deployment package or a specific version, you can delete it. For more information, see Delete a deployment package.

  • To change the distribution regions or content of a deployment package, you can create a new version. For more information, see Create a version.

  • To configure upgrade settings for a deployment package, see Configure service update settings.