All Products
Search
Document Center

Serverless App Engine:Manage distributed configurations (ACM)

Last Updated:Jul 17, 2026

Serverless App Engine (SAE) integrates with Application Configuration Management (ACM), allowing your applications to dynamically fetch configurations from a central source. ACM supports dynamic updates, environment separation, version control, data encryption, and fine-grained permission control.

The standalone ACM service is no longer available, but the ACM service integrated with SAE remains functional. For better security and stability, we recommend that you migrate from ACM to MSE Nacos and then use the MSE Nacos registry.

This topic does not cover configuration items for the container runtime environment. For that information, see Manage and use configuration items (K8s ConfigMap).

Create a configuration

In the SAE Application Configuration Management (ACM) console, select your target region and namespace. Then, click Configuration List and Create Configuration. To ensure your application can fetch the configuration, you must also integrate Application Configuration Management (ACM) into your application.

Parameters

Parameter

Description

Data ID

The ID of the configuration. Use a naming convention similar topackage.class (for example,com.taobao.tc.refund.log.level) to ensure global uniqueness. Define the class part based on the business purpose.

Group

The group for the configuration. Use the product or module name. The group name must be globally unique.

Data Encryption

Specifies whether to encrypt the configuration data. Enable this feature if your configuration contains sensitive data to reduce the risk of data leaks.

Important

The data encryption feature in ACM relies on Key Management Service (KMS). Before using this feature, activate KMS and grant ACM permission to use KMS for encryption and decryption. The Data ID of an encrypted configuration must start with cipher-. For more information, see Create an encrypted configuration.

Configuration Format

Select a configuration format.SAE validates the data based on your selection. The default format is TEXT.

Configuration Content

Enter the content of the configuration. The recommended size is 10 KB or less, and the maximum size is 100 KB.

Description

A description for the configuration.

More Configurations

applications,

The application to which the configuration belongs.

Tag

Tags for the configuration. Use tags to organize configurations by dimension. You can add up to five tags, each up to 64 characters long.

Integrate ACM into your application

In the SAE Application Configuration Management (ACM) console, select a region and namespace. Click Configuration List and then click a Data ID to open the configuration details page.Click the Sample Code tab and select your technology stack.

Refer to the sample code to integrate ACM into your application. For more information, see the ACM SDK documentation.

View configuration content

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. Click Configuration List and then click a Data ID to go to the configuration details page.Click the Configuration Content tab.

Export configurations

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. On the Configuration List page, select one or more configurations and click Export at the bottom of the page. In the dialog box that appears, click Export. The configurations are exported as a ZIP package.

Import a configuration

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. On the Configuration List page, click Import Configuration and then click Upload File. The imported file must be a ZIP package.

View and roll back historical versions

You can view historical versions of a configuration and roll back to a previous version if an update causes errors.

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. Click Configuration List and then click a Data ID to go to the configuration details page.Click the Historical Versions tab. In the Actions column, click View or Rollback for a specific version.

Query the push status

You can check whether a configuration has been pushed to its listening applications.

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. Click Configuration List and then click a Data ID to go to the configuration details page.Click the Listener Query tab to filter and query the push status.

Query the push track

You can query the push track of a configuration to troubleshoot issues such as push failures.

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. Click Configuration List and then click a Data ID to go to the configuration details page.Click the Push Track tab to filter and query the push track.

Create an encrypted configuration

Encrypted configurations protect sensitive information such as data sources, tokens, usernames, and passwords, reducing the risk of data leaks.

Prerequisites

  1. Purchase a dedicated KMS instance.

  2. Grant ACM permission to use Key Management Service (KMS).

  3. Grant permissions to a RAM user:AliyunACMFullAccess andAliyunKMSCryptoAdminAccess.

  4. Create an AccessKey for a RAM user, and then perform operations as the RAM user. Only the AccessKeys of RAM users are supported. AccessKeys specific to ACM are not supported.

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar, and then click Configuration List. Click Create Configuration. Enable Data Encryption and select an encryption method.

Parameters

Parameter

Description

Encryption method

  • KMS AES-128 (Recommended): Uses KMS envelope encryption. The maximum data size is 100 KB. Plaintext data is not transmitted to the KMS system, providing higher security.

  • KMS: Directly calls KMS to encrypt the configuration. The recommended data size is 4 KB or less, with a maximum of 6 KB. This method may fail to decrypt special characters such as&, and is not recommended.

Integrate an encrypted configuration

In the SAE Application Configuration Management (ACM) console, select the target region and namespace from the top navigation bar. Click Configuration List and then click a Data ID to go to the configuration details page.Click the Sample Code tab and select your technology stack.

Configure the AccessKey/SecretKey of a RAM user in your application to decrypt the data. The Java and Python SDKs have integrated the KMS SDK, so you can add a decryption filter for automatic decryption. For decryption in other languages, see Decrypt.