All Products
Search
Document Center

Serverless App Engine:Deploy an app using a cross-account ACR image

Last Updated:Sep 21, 2026

If your Serverless App Engine (SAE) application and Container Registry (ACR) instance are in different Alibaba Cloud accounts, first ensure network connectivity. Then, configure authorization to access the ACR instance. Finally, provide the image repository address to deploy the application.

Prerequisites

Ensure network connectivity for SAE and ACR

You must either establish cross-VPC connectivity or enable a public NAT gateway for your application's Virtual Private Cloud (VPC). For ACR Enterprise Edition instances, you must also add the CIDR block of the SAE application's VPC or the Elastic IP Address (EIP) bound to the NAT gateway to the ACR instance's whitelist.

How to view the VPC of an SAE application

Before you deploy an application, you must plan its region and namespace. This determines the VPC where the application is located.

  1. Log on to the SAE console, select a region in the top navigation bar, and select Namespaces in the left-side navigation pane.

  2. Click the target namespace in the list. In the left-side navigation pane, select Basic Information. Click the link in the VPC field to view details such as the VPC ID.

Configure ACR access authorization

You can use either Static Username and Password or a RAM Role.

Static username and password

Create a Secret to store the username and password for the image repository. On the Namespace page, select a region, click the target namespace, choose Secret in the left-side navigation pane, and then click Create.

  • Set Type to Private Image Repository Logon Key.

  • In the Image Repository Address field, enter the public domain of the ACR instance. For example, registry.cn-xx.aliyuncs.com for Container Registry Personal Edition or xx-registry.cn-xx.cr.aliyuncs.com for ACR Enterprise Edition. Enter the Username and Password to log on to the image repository.

How to find the username and password to log on to the image repository

  • For Container Registry Personal Edition, log on to the account that owns the ACR instance. On the ACR Personal Edition Instance - Access Credential page, select the instance's region to view the Username and modify the Password.

    This page contains the Get Credential and Log On To Instance sections. In the Get Credential section, click Set Fixed Password to set a permanent access credential. In the Log On To Instance section, select the access domain for your network environment (VPC, public network, or classic network). Then, run the command sudo docker login --username=<username> registry.cn-shenzhen.aliyuncs.com in a terminal to log on to the registry instance.

  • For ACR Enterprise Edition, log on to the account that owns the ACR instance and see Configure access credentials to find the username and password.

    In the left-side navigation pane, choose Instance Management > Access Credential. On the Account Access Credential Management tab, obtain credentials by either setting a fixed password or getting a temporary password. After obtaining the credentials, use the following command to log on to the instance: sudo docker login --username=<username> registry-vpc.cn-hangzhou.cr.aliyuncs.com. You can find the value for --username on this page.

RAM role

SAE can pull images from an ACR instance in another account by assuming a RAM role. For example, an application in Account A can assume a RAM role in Account B to pull images from an ACR instance owned by Account B.

  1. Create a RAM role: Use Account B to create a RAM role for Account A. For more information, see Create a RAM role for a trusted Alibaba Cloud account.

  2. Configure an access policy: Create a custom policy or modify a custom policy to include the following statements to allow operations on private images.

    {
      "Version": "1",
      "Statement": [
          {
              "Effect": "Allow",
              "Action": [
                  "cr:GetAuthorizationToken",
                  "cr:ListInstanceEndpoint",
                  "cr:PullRepository",
                  "cr:GetRepository",
                  "cr:ListRepositoryTag"
              ],
              "Resource": "*"
          }
      ]
    }
  3. Grant permissions to the RAM role: Grant the access policy from Step 2 to the RAM role from Step 1. For more information, see Manage RAM role permissions.

  4. Modify the trusted entity of the RAM role: Change the trusted entity of the RAM role from Step 1 to the SAE service account by modifying the trust policy. For more information, see Modify the trust policy of a RAM role.

    Before

    After

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::123456789012****:root"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    This RAM role can be assumed by any authorized RAM user or RAM role under the Alibaba Cloud account (AccountID=123456789012****).

    {
      "Statement": [
        {
          "Action": "sts:AssumeRole",
          "Effect": "Allow",
          "Principal": {
            "Service": [
              "123456789012****@sae.aliyuncs.com"
            ]
          }
        }
      ],
      "Version": "1"
    }

    This RAM role can only be assumed by the SAE service account (123456789012****@sae.aliyuncs.com) for the Alibaba Cloud account (AccountID=123456789012****).

    Note

    In this example, Service refers to the service that pulls the image.

  5. Copy the ARN: On the Basic Information page of the RAM role, copy the ARN. You will need this value for the acrAssumeRoleArn field when deploying the application.

Procedure

  1. On the SAE Application List page, select the target region and namespace in the top navigation bar, and then click Create Application.

  2. Select an application edition.

    Important

    The Lightweight Edition and Professional Edition are currently in an invite-only beta phase. For users not participating in the beta test, applications are created as the Standard Edition by default.

    • Lightweight Edition: Provides the minimum feature set required to run an application. It does not support the Application Monitoring and Microservices Governance features.

    • Standard Edition: Includes the Basic Application Monitoring feature. The Advanced Application Monitoring and Microservices Governance features must be enabled and purchased separately.

    • Professional Edition: Includes the Advanced Application Monitoring and Microservices Governance features, which do not need to be enabled or purchased separately.

  3. On the Create Application page, specify an Application Name and configure the following parameters.

    1. Select the namespace type for the application. A namespace is equivalent to a Kubernetes namespace and can be used to isolate resources in different environments. You cannot change the namespace of an application after it is created. Plan accordingly.

      • System Created: Use the default namespace, vSwitch, and security group created by the system in the current region.

      • Existing Namespace: Select a namespace, vSwitch, and security group that you created in advance.

    2. Set Application Deployment Method to Select Image Deployment, and then click Specify Image on the right. On the Private Images of Other Alibaba Cloud Account tab, configure the following parameters.

      • Select your ACR edition, and then choose an authorization method. For ACR Enterprise Edition, you must also enter the Enterprise Edition Instance ID.

        • Static Username and Password: Select the Secret for Username and Password of Image Repository that you created earlier.

        • RAM Role: Enter the acrAssumeRoleArn that you copied earlier.

      • Enter the Complete Image Repository Address in the format <image-repository-address>:<image-tag>. For example: registry.cn-xx.aliyuncs.com/xx/xx:1.0 for Container Registry Personal Edition, or xx-registry.cn-xx.cr.aliyuncs.com/xx/xx:1.0 for ACR Enterprise Edition.Note: Use the public or private image repository address that corresponds to your network configuration.

      • For ACR Enterprise Edition, you can enable image acceleration to speed up application startup.

    3. In the Capacity Settings section, set Resource Type, Single Instance Type, and Instances.

  4. (Optional) Click Next: Advanced Settings to configure desired features.

    • Startup command

      The startup command for an application is determined by the CMD or ENTRYPOINT set in the image. No additional configuration is required in SAE. If you have specific requirements, you can set a startup command to override the one set in the image.

    • Runtime environment and lifecycle management

    • Network access and service invocation

    • Data persistence

      Store application data in NAS, OSS, or a database to prevent data loss when an application is changed or stopped. Note: NAS, OSS, and databases incur additional charges.

    • Logging and monitoring

      • After you deploy an application, you can view real-time logs and view resource usage and load without additional configuration. You can also output logs to SLS or Kafka for centralized management and analysis. Note: SLS and Kafka incur additional charges.

      • ARMS helps you track application health, quickly find failed and slow APIs, identify performance bottlenecks, and reproduce call parameters, which improves production troubleshooting efficiency.

        • For Standard Edition applications, you can view ARMS Basic Edition monitoring data after deployment without additional configuration. You can also enable and purchase ARMS Premium Edition monitoring.

        • For Professional Edition applications, after you enable Application Monitoring in Advanced Settings and deploy the application, you can view ARMS Premium Edition monitoring data. No additional fees are required.

    • Other features

      • Microservices Governance provides Graceful Start and Shutdown, traffic protection, end-to-end canary release, and Intra-zone Provider First for Java applications.

        • For Standard Edition applications, go to the application details page after deployment to enable and purchase the MSE Microservices Governance feature.

        • For Professional Edition applications, after you enable Microservices Governance in Advanced Settings, you can configure Graceful Start and Shutdown. For more features, go to the application details page after deployment. No additional fees are required.

      • You can enable the CPU Burst feature to avoid wasting resources when CPU requirements are higher at startup than during normal operation.

      • You can decouple and standardize non-business features from the main container by adding a sidecar container.

  5. Click Create Application with One Click or Create Application.

    • Creating the application takes about 1 to 2 minutes. You can view change records to verify that the deployment was successful. If the deployment fails, no application instance is created. You can troubleshoot the issue based on the error message in Change Details.

    • You can view the created application on the page. To change the application configuration after deployment, click the target application to go to its details page. Then, click Deploy Application or Modify Application Configurations at the top. The application automatically restarts to apply the new configuration. Perform this operation during off-peak hours.

    • You can log on to an application instance by using Webshell and interact with the instance by using console commands.

    • After you create an application, you can manually adjust the number of instances and the instance specification, or automatically adjust the number of instances by configuring an auto scaling policy. You can also reduce costs by enabling idle mode.