All Products
Search
Document Center

Security Center:Onboard Volcengine Assets Using an AccessKey

Last Updated:Jun 18, 2026

By configuring a Volcengine sub-account AccessKey (AK) in Alibaba Cloud Security Center, you can automatically synchronize Volcengine host assets into the Alibaba Cloud security protection system. This topic describes how to onboard Volcengine host assets using an AK, helping you achieve centralized security management across multi-cloud environments and reduce the complexity of managing security in a multi-cloud setup.

Configuration methods

Important

The Volcengine console operations described in this topic are for reference only. For exact steps, refer to the Volcengine documentation linked below.

Configuration method

Description

Supported Features

Quick configuration

After you submit the AK of your Volcengine main account, Security Center automatically creates a sub-account and completes the provisioning authorization.

Host

Manual configuration

Manually create a sub-account in Volcengine and grant the required permissions, then submit the sub-account AK in Security Center to complete the authorization.

Host, CSPM

Quick configuration

Step 1: Create a main account key

For more information, see API Access Key Management.

  1. Log on to the Volcengine console and go to the API Access Keys page. On the AK Leak Detection page, click Create AccessKey.

  2. In the Create AccessKey dialog box, click Continue and complete identity verification as prompted.

  3. In the Create AccessKey Successful dialog box, click Download Credentials.

    Save the AccessKey ID and SecretAccessKey from the downloaded file.

Step 2: Submit the main account AK

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, select System Settings > Feature Settings. In the upper-left corner of the console, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Multi-cloud Configuration Management > Multi-cloud Assets tab, click Grant Permission and select Volcano Engine from the drop-down list.

    Alternatively, on the Assets > Host page, move the pointer over the image icon in the Add Multi-cloud Asset section, and click Add below Volcano Engine to open the Add Assets Outside Cloud panel.

  4. In the Add Assets Outside Cloud panel, select Quick Configuration and click Next.

  5. On the Submit AccessKey Pair wizard page, enter the AccessKey ID, SecretAccessKey, and an account name, then click Next.

    The account name is used to distinguish assets from different accounts under the same cloud provider. We recommend that you set a meaningful name based on your use case.

Step 3: Complete the provisioning policy configuration

  1. In the Security Center console, on the Add Assets Outside Cloud panel, configure the region and data synchronization frequency for the Volcengine assets to be onboarded in the Policy Configuration wizard, and click OK.

    Parameter

    Description

    Select region

    Select the region where the assets to be onboarded reside. Security Center provisions the assets to the corresponding data management center based on your selection in the upper-left corner of the console (China or Outside China).

    Region Management

    If you select this option, Security Center automatically provisions asset data from any newly added regions under the current Volcengine account to the current data management center.

    If you clear this option, assets in newly added regions will not be provisioned to Security Center.

    Host Asset Synchronization Frequency

    Select the interval at which Security Center automatically synchronizes Volcengine host assets. If you select Close, synchronization is disabled.

    AK Service Status Check

    Select the interval at which Security Center automatically checks the validity of the Volcengine account AccessKey. If you select Close, the check is disabled.

  2. Click Synchronize Assets to synchronize all host assets from the Volcengine account to Security Center.

After you configure the provisioning policy, Security Center automatically creates a user with the prefix AlibabaSas_ in the Volcengine console to authorize asset provisioning. We recommend that you do not delete or disable this user or its credentials, as doing so may disrupt the onboarding of Volcengine assets. After configuration is complete, you can view the auto-created IAM user (for example, AlibabaCloud_202504) on the Users page in the Volcengine IAM console. The user belongs to the user group AlibabaCloudGroup_202504.

Step 4: Delete the main account key

After onboarding is complete, we recommend that you delete the main account AK from the Volcengine console to ensure main account security. For more information, see API Access Key Management.

  1. Log on to the Volcengine console and go to the API Access Keys page. Find the AccessKey that you submitted in Security Center and click Disable in the Actions column.

  2. In the Are you sure that the AccessKey pair is disabled? dialog box, click OK and complete identity verification as prompted.

  3. On the AccessKey Leak Detection page, click Delete in the Actions column of the target AccessKey and follow the prompts to complete the deletion.

Manual configuration

Step 1: Create a sub-account and obtain its AK

For more information, see User Management.

  1. Log on to the Volcengine console and go to the Users page. On the Users page, click Add.

  2. On the Create User page, click Create IAM user.

  3. On the Create IAM user page, enter a Username, set Access mode to Programmatic Access, and click Next.

  4. Configure access policies: On the Access Policy tab, select the permission policies required for the Security Center features you plan to use, then click Next.

    Feature

    Permission Policy

    Host

    IAMReadOnlyAccess
    ECSReadOnlyAccess

    CSPM (CSPM)

    ALBReadOnlyAccess

    AdvDefenceReadOnly

    CLBReadOnlyAccess

    CRReadOnlyAccess

    CloudFirewallReadOnlyAccess

    CloudIdentityReadOnlyAccess

    ECSReadOnlyAccess

    HBaseReadOnlyAccess

    IAMReadOnlyAccess

    KMSReadOnlyAccess

    MCDNReadOnlyAccess

    MongoDBReadOnlyAccess

    NATReadOnlyAccess

    RDSMSSQLReadOnlyAccess

    RDSMySQLReadOnlyAccess

    RDSPGReadOnlyAccess

    RedisReadOnlyAccess

    SecCenterReadOnlyAccess

    TOSReadOnlyAccess

    VBHReadOnlyAccess

    VKEReadOnlyAccess

    VPCReadOnlyAccess

    VedbMysqlReadOnlyAccess

    VeenReadOnlyAccess

    WafReadOnlyAccess

    AgentKitReadOnlyAccess

    IDReadOnlyAccess

    ArkReadOnlyAccess

    Note

    You can also configure the global read-only ReadOnlyAccess policy to avoid situations where newly added assets and properties cannot be detected by CSPM due to delayed permission configuration.

  5. After confirming the user information, click Bind Account and Go to Data Source Binding.

  6. In the User Information section, click Save and Download CSV or the image icon to save the AccessKey ID and SecretAccessKey.

Step 2: Submit the sub-account AK

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, select System Settings > Feature Settings. In the upper-left corner of the console, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Multi-cloud Configuration Management > Multi-cloud Assets tab, click Grant Permission and select Volcano Engine from the drop-down list.

    Alternatively, on the Assets > Host page, move the pointer over the image icon in the Add Multi-cloud Asset section, and click Add below Volcano Engine to open the Add Assets Outside Cloud panel.

  4. In the Add Assets Outside Cloud panel, keep Manual Configuration selected by default. In the Permission Description section, select Host and click Next.

  5. On the Submit AccessKey Pair wizard page, enter the sub-account AccessKey ID, SecretAccessKey, and an account name, then click Next.

    The account name is used to distinguish assets from different accounts under the same cloud provider. We recommend that you set a meaningful name based on your use case.

    Important

    Do not delete or disable the sub-account or its AccessKey, as doing so may disrupt the onboarding process.

Step 3: Complete the provisioning policy configuration

  1. In the Security Center console, on the Add Assets Outside Cloud panel, configure the region and data synchronization frequency for the Volcengine assets to be onboarded in the Policy Configuration wizard, and click OK.

    Parameter

    Description

    Select region

    Select the region where the assets to be onboarded reside. Security Center provisions the assets to the corresponding data management center based on your selection in the upper-left corner of the console (China or Outside China).

    Region Management

    If you select this option, Security Center automatically provisions asset data from any newly added regions under the current Volcengine account to the current data management center.

    If you clear this option, assets in newly added regions will not be provisioned to Security Center.

    Host Asset Synchronization Frequency

    Select the interval at which Security Center automatically synchronizes Volcengine host assets. If you select Close, synchronization is disabled.

    AK Service Status Check

    Select the interval at which Security Center automatically checks the validity of the Volcengine account AccessKey. If you select Close, the check is disabled.

  2. Click Synchronize Assets to synchronize all host assets from the Volcengine account to Security Center.

Manage onboarded assets

Host

Go to the Assets > Host page. In the Add Multi-cloud Asset section, click the image icon to view the list of onboarded Volcengine assets. You can follow the steps below to apply advanced protection and manage onboarded hosts.

Note

For more information, see Server assets

  1. Install the Security Center agent: Install the Security Center agent on your Volcengine hosts. When you run the installation command, set Service Provider to Volcengine. For more information, see Install the agent.

  2. Upgrade to a paid edition for advanced protection: The Free Edition provides only basic security detection. For comprehensive security capabilities such as antivirus, vulnerability remediation, and intrusion prevention, upgrade your Volcengine hosts to the Anti-virus Edition or a higher edition. For more information, see Manage host and container security quotas.

CSPM

In the Security Center console, go to the Assets > Overview > Cloud Product page. In the left-side All Alibaba Cloud Services navigation pane, click Volcengine to view your onboarded assets. The following CSPM features are available for onboarded Volcengine assets:

Note

For more information, see View cloud service information.

  1. Run a configuration risk check: Check for configuration risks in your Volcengine products. For more information, see Configure and run check policies.

  2. Address risk items: Review and remediate failed risk check items to improve the compliance and security of your cloud assets. For more information, see Handle failed check items.