By configuring a Volcengine sub-account AccessKey (AK) in Alibaba Cloud Security Center, you can automatically synchronize Volcengine host assets into the Alibaba Cloud security protection system. This topic describes how to onboard Volcengine host assets using an AK, helping you achieve centralized security management across multi-cloud environments and reduce the complexity of managing security in a multi-cloud setup.
Configuration methods
The Volcengine console operations described in this topic are for reference only. For exact steps, refer to the Volcengine documentation linked below.
|
Configuration method |
Description |
Supported Features |
|
After you submit the AK of your Volcengine main account, Security Center automatically creates a sub-account and completes the provisioning authorization. |
Host |
|
|
Manually create a sub-account in Volcengine and grant the required permissions, then submit the sub-account AK in Security Center to complete the authorization. |
Host, CSPM |
Quick configuration
Step 1: Create a main account key
For more information, see API Access Key Management.
-
Log on to the Volcengine console and go to the API Access Keys page. On the AK Leak Detection page, click Create AccessKey.
-
In the Create AccessKey dialog box, click Continue and complete identity verification as prompted.
-
In the Create AccessKey Successful dialog box, click Download Credentials.
Save the AccessKey ID and SecretAccessKey from the downloaded file.
Step 2: Submit the main account AK
-
Log on to the Security Center console.
-
In the navigation pane on the left, select . In the upper-left corner of the console, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
-
On the tab, click Grant Permission and select Volcano Engine from the drop-down list.
Alternatively, on the page, move the pointer over the
icon in the Add Multi-cloud Asset section, and click Add below Volcano Engine to open the Add Assets Outside Cloud panel. -
In the Add Assets Outside Cloud panel, select Quick Configuration and click Next.
-
On the Submit AccessKey Pair wizard page, enter the AccessKey ID, SecretAccessKey, and an account name, then click Next.
The account name is used to distinguish assets from different accounts under the same cloud provider. We recommend that you set a meaningful name based on your use case.
Step 3: Complete the provisioning policy configuration
-
In the Security Center console, on the Add Assets Outside Cloud panel, configure the region and data synchronization frequency for the Volcengine assets to be onboarded in the Policy Configuration wizard, and click OK.
Parameter
Description
Select region
Select the region where the assets to be onboarded reside. Security Center provisions the assets to the corresponding data management center based on your selection in the upper-left corner of the console (China or Outside China).
Region Management
If you select this option, Security Center automatically provisions asset data from any newly added regions under the current Volcengine account to the current data management center.
If you clear this option, assets in newly added regions will not be provisioned to Security Center.
Host Asset Synchronization Frequency
Select the interval at which Security Center automatically synchronizes Volcengine host assets. If you select Close, synchronization is disabled.
AK Service Status Check
Select the interval at which Security Center automatically checks the validity of the Volcengine account AccessKey. If you select Close, the check is disabled.
-
Click Synchronize Assets to synchronize all host assets from the Volcengine account to Security Center.
After you configure the provisioning policy, Security Center automatically creates a user with the prefix AlibabaSas_ in the Volcengine console to authorize asset provisioning. We recommend that you do not delete or disable this user or its credentials, as doing so may disrupt the onboarding of Volcengine assets. After configuration is complete, you can view the auto-created IAM user (for example, AlibabaCloud_202504) on the Users page in the Volcengine IAM console. The user belongs to the user group AlibabaCloudGroup_202504.
Step 4: Delete the main account key
After onboarding is complete, we recommend that you delete the main account AK from the Volcengine console to ensure main account security. For more information, see API Access Key Management.
-
Log on to the Volcengine console and go to the API Access Keys page. Find the AccessKey that you submitted in Security Center and click Disable in the Actions column.
-
In the Are you sure that the AccessKey pair is disabled? dialog box, click OK and complete identity verification as prompted.
-
On the AccessKey Leak Detection page, click Delete in the Actions column of the target AccessKey and follow the prompts to complete the deletion.
Manual configuration
Step 1: Create a sub-account and obtain its AK
For more information, see User Management.
-
Log on to the Volcengine console and go to the Users page. On the Users page, click Add.
-
On the Create User page, click Create IAM user.
-
On the Create IAM user page, enter a Username, set Access mode to Programmatic Access, and click Next.
-
Configure access policies: On the Access Policy tab, select the permission policies required for the Security Center features you plan to use, then click Next.
Feature
Permission Policy
Host
IAMReadOnlyAccessECSReadOnlyAccessCSPM (CSPM)
ALBReadOnlyAccessAdvDefenceReadOnlyCLBReadOnlyAccessCRReadOnlyAccessCloudFirewallReadOnlyAccessCloudIdentityReadOnlyAccessECSReadOnlyAccessHBaseReadOnlyAccessIAMReadOnlyAccessKMSReadOnlyAccessMCDNReadOnlyAccessMongoDBReadOnlyAccessNATReadOnlyAccessRDSMSSQLReadOnlyAccessRDSMySQLReadOnlyAccessRDSPGReadOnlyAccessRedisReadOnlyAccessSecCenterReadOnlyAccessTOSReadOnlyAccessVBHReadOnlyAccessVKEReadOnlyAccessVPCReadOnlyAccessVedbMysqlReadOnlyAccessVeenReadOnlyAccessWafReadOnlyAccessAgentKitReadOnlyAccessIDReadOnlyAccessArkReadOnlyAccessNoteYou can also configure the global read-only
ReadOnlyAccesspolicy to avoid situations where newly added assets and properties cannot be detected by CSPM due to delayed permission configuration. -
After confirming the user information, click Bind Account and Go to Data Source Binding.
-
In the User Information section, click Save and Download CSV or the
icon to save the AccessKey ID and SecretAccessKey.
Step 2: Submit the sub-account AK
-
Log on to the Security Center console.
-
In the navigation pane on the left, select . In the upper-left corner of the console, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
-
On the tab, click Grant Permission and select Volcano Engine from the drop-down list.
Alternatively, on the page, move the pointer over the
icon in the Add Multi-cloud Asset section, and click Add below Volcano Engine to open the Add Assets Outside Cloud panel. -
In the Add Assets Outside Cloud panel, keep Manual Configuration selected by default. In the Permission Description section, select Host and click Next.
-
On the Submit AccessKey Pair wizard page, enter the sub-account AccessKey ID, SecretAccessKey, and an account name, then click Next.
The account name is used to distinguish assets from different accounts under the same cloud provider. We recommend that you set a meaningful name based on your use case.
ImportantDo not delete or disable the sub-account or its AccessKey, as doing so may disrupt the onboarding process.
Step 3: Complete the provisioning policy configuration
-
In the Security Center console, on the Add Assets Outside Cloud panel, configure the region and data synchronization frequency for the Volcengine assets to be onboarded in the Policy Configuration wizard, and click OK.
Parameter
Description
Select region
Select the region where the assets to be onboarded reside. Security Center provisions the assets to the corresponding data management center based on your selection in the upper-left corner of the console (China or Outside China).
Region Management
If you select this option, Security Center automatically provisions asset data from any newly added regions under the current Volcengine account to the current data management center.
If you clear this option, assets in newly added regions will not be provisioned to Security Center.
Host Asset Synchronization Frequency
Select the interval at which Security Center automatically synchronizes Volcengine host assets. If you select Close, synchronization is disabled.
AK Service Status Check
Select the interval at which Security Center automatically checks the validity of the Volcengine account AccessKey. If you select Close, the check is disabled.
-
Click Synchronize Assets to synchronize all host assets from the Volcengine account to Security Center.
Manage onboarded assets
Host
Go to the page. In the Add Multi-cloud Asset section, click the
icon to view the list of onboarded Volcengine assets. You can follow the steps below to apply advanced protection and manage onboarded hosts.
For more information, see Server assets
-
Install the Security Center agent: Install the Security Center agent on your Volcengine hosts. When you run the installation command, set Service Provider to Volcengine. For more information, see Install the agent.
-
Upgrade to a paid edition for advanced protection: The Free Edition provides only basic security detection. For comprehensive security capabilities such as antivirus, vulnerability remediation, and intrusion prevention, upgrade your Volcengine hosts to the Anti-virus Edition or a higher edition. For more information, see Manage host and container security quotas.
CSPM
In the Security Center console, go to the page. In the left-side All Alibaba Cloud Services navigation pane, click Volcengine to view your onboarded assets. The following CSPM features are available for onboarded Volcengine assets:
For more information, see View cloud service information.
-
Run a configuration risk check: Check for configuration risks in your Volcengine products. For more information, see Configure and run check policies.
-
Address risk items: Review and remediate failed risk check items to improve the compliance and security of your cloud assets. For more information, see Handle failed check items.