The multi-application service provides a logical isolation solution for managing multiple environments (such as development, testing, and production) or multi-tenant businesses under an Alibaba Cloud account. It creates independent application spaces to achieve fine-grained isolation of data, configurations, and permissions, reducing management costs and enhancing security. This topic describes how the multi-application service works, its scenarios, activation and configuration, limits, application management, and authorization.
How it works
The multi-application architecture achieves logical isolation by adding an application ID (AppId) to the metadata of ApsaraVideo VOD. When you initiate API requests—such as uploading videos or retrieving playback URLs—the system uses the specified AppId parameter to restrict operations to the specified application.
Core concepts
Application (App): An independent logical space for isolating media resources, configurations, and permissions. Each application has a unique
AppId.Default Application (System App): After you enable the multi-application system, the system automatically creates a default application with the ID
app-1000000. All historical data under your account is automatically assigned to this application. If you do not specify anAppIdwhen you call an API, the operation targets this application by default.Custom App: An application that you create, such as
app-xxxxxxx, to isolate new services or environments.
Scenarios
Isolation of multiple environments:
In testing and online environments, resources such as videos and images, configurations, and data must be isolated. For example, different callback URL configurations must be isolated. Use the multi-application service to create an application for each environment. Associate different RAM users with these applications and grant permissions to the RAM users. This helps prevent impacts from applications that are being tested or developed on online applications.
Isolation of multiple business lines:
When your business has multiple business lines or multiple departments that need to use ApsaraVideo VOD, use the multi-application service to create an application for each business line or department for isolation.
Isolation of multiple channels:
If you want to build platform services based on the capabilities of ApsaraVideo VOD for multiple channels or users, use the multi-application service.
Activate and configure
Before using the feature, submit a ticket to activate it. After activation, the system automatically creates a default application and assigns historical data to it.
Submit a ticket to activate the feature.
Submit a ticket, and state in the application information: "I understand and accept the impact of activating the multi-application service, and I request to activate it." Also provide your Alibaba Cloud account UID.
Go to the ApsaraVideo VOD console. In the navigation pane on the left, go to the Overview page.
On the Overview page, in the Multi-Application Activation module in the top-right corner, click the Get Started button to activate the multi-application feature. After activation, this module is no longer displayed on the Overview page.
Create applications.
Go to the ApsaraVideo VOD console. In the navigation pane on the left, click Application Management.
On the Application Management page, click Create Application. Enter the application name and description, then click OK. After creation, you can edit, delete, or enter the application.
Click the application name or the Actions button in the **Actions** column to access the application. It supports media asset management, media processing, and video distribution.
NoteYou can retrieve the list of application IDs by calling the ListAppInfo API.
Authorize identity entities.
Call AttachAppPolicyToIdentity - Attach an application-level access policy to an identity to grant a RAM user or RAM role permissions to access a specific application. ApsaraVideo VOD provides three application-level access policies:
Policy Name
Authorization Scope
Operation Permissions
VODAppAdministratorAccessAll applications
Permissions to manage all applications under the Alibaba Cloud account and all resources within the applications
VODAppFullAccessSingle application
All resources in the specified application
VODAppReadOnlyAccessSingle application
Read-only access to all resources in the specified application, such as calling operations that start with Get, Describe, Search, or List to manage resources.
Manage applications.
You can use the APIs of the multi-application system to create, query, update, and delete applications. The console will support additional multi-application management features in the future.
Use the multi-application service
Services that support the multi-application feature will add support for the AppId parameter. You can specify this parameter when creating resources or new settings. When querying data, only resources in applications for which you have permissions are returned. When modifying or deleting, relevant permissions are checked.
Currently, only message callbacks and media asset services (upload, playback, and media asset management) support the multi-application feature.
Message callbacks
You can configure a unique message callback method and address for each application, used in conjunction with the API (Set Event Notification Configuration):
Specify an `AppId` to set message callbacks for that application.
If not specified, the system uses the default application.
After the settings are complete, callbacks are performed for event notifications generated by video and image uploads in different applications based on their settings. You can also use the query event notification configuration API to query the related configuration.
Media asset services
Media upload: Upload-related operations (such as obtaining video upload URLs and credentials, and obtaining image upload URLs and credentials) support specifying an `AppId`. The account entity must have permissions for the application; otherwise, the upload fails. If you do not specify an application ID, the content is uploaded to the system's default application.
Audio and video playback: You can only obtain playback information (such as playback credentials and playback URLs) from authorized applications.
Modify and delete: Media asset modification and deletion operations can only be performed on resources in applications for which you have permissions.
Media asset query: The query media asset details operation can only retrieve media asset information from applications for which you have permissions. For batch queries, only authorized media asset data is returned. Unauthorized `MediaId` values are placed in `NonExistMediaIds` (the field name may vary slightly).
Media asset search: When searching, only media asset data from applications for which you have permissions is returned. You can specify one or more `AppId` values in the search criteria.
Limits
The multi-application service supports the following regions: China (Shanghai), China (Beijing), China (Shenzhen), Singapore, Germany (Frankfurt), US (Silicon Valley), Japan (Tokyo), Indonesia (Jakarta), and SAU (Riyadh - Partner Region).
You can create up to 10 applications within the same account. If you need more, submit a ticket.
Only media upload, audio and video playback, media asset management, and message callbacks support multi-application isolation.
Billing
Currently, resource consumption (such as storage, traffic, and transcoding) for all applications is billed at the account level. Independent billing and bill generation at the application level are not yet supported.
FAQ
Will activation affect existing businesses?
No. All historical data is automatically assigned to the default application. Existing API calls and business logic continue to work normally without modification.
How do I migrate historical videos to a newly created application?
You can use the Migrate Resources to a New Application API to perform migration. This API supports single or batch migration, and the video's VideoId and playback URL remain unchanged during migration, without affecting online services.
Console Navigation Permissions
Primary Directory | Secondary Directory | Tertiary Directory | Default Version | Multi-application Version | |
Outside Application | Inside Application | ||||
Overview | — | — | ✔️ | ✔️ | — |
Application Management | — | — | — | ✔️ | — |
Media Library | Audio and Video | — | ✔️ | — | ✔️ |
Images | — | ✔️ | — | ✔️ | |
Short Video Materials | — | ✔️ | — | ✔️ | |
Production Center | Video Clip | — | ✔️ | — | ✔️ View within the application, only for the primary application |
Review Management | Video Review | — | ✔️ | — | ✔️ |
Review Settings | — | ✔️ | — | ✔️ | |
Configuration Management | Media Asset Management Configuration | Storage Management | ✔️ | — | ✔️ |
Storage Policy | ✔️ | — | ✔️ View within the application, only for the primary application | ||
Data Classification | ✔️ | — | ✔️ | ||
Media Processing Configuration | Transcoding Template Groups | ✔️ | — | ✔️ | |
Screenshot Templates | ✔️ | — | ✔️ | ||
Animated Image Templates | ✔️ | — | ✔️ | ||
Watermark Templates | ✔️ | — | ✔️ | ||
Workflow Management | ✔️ | — | ✔️ | ||
Callback Settings | ✔️ | — | ✔️ | ||
Digital Rights Management (DRM) Certificate Management | ✔️ | — | ✔️ | ||
Standard Encryption | ✔️ | — | ✔️ | ||
Distribution Acceleration Configuration | Domain Name Management | ✔️ | — | ✔️ | |
Refresh and Prefetch | ✔️ | — | ✔️ | ||
Download Settings | ✔️ | — | ✔️ | ||
SDK Management | SDK List | — | ✔️ | ✔️ | — |
My Authorizations | — | ✔️ | ✔️ | — | |
Tools | Video Playback Troubleshooting | — | ✔️ | ✔️ | — |
Digital Watermarking Extraction Tool | — | ✔️ | — | ✔️ | |
Activate Multi-application | — | ✔️ | ✔️ | — | |
Data Center | Playback Quality Monitoring | — | ✔️ | — | ✔️ |
Single Point Probe | — | ✔️ | — | ✔️ | |
Monitoring Statistics | Resource Monitoring | ✔️ | — | ✔️ | |
Real-time Monitoring | ✔️ | — | ✔️ | ||
Statistical Analysis | ✔️ | — | ✔️ | ||
Resource Plan Management | — | ✔️ | ✔️ | — | |
Usage Query | — | ✔️ | ✔️ | ✔️ | |
Log Management | — | ✔️ | ✔️ | ✔️ | |
Media Asset Data Exporting | — | ✔️ | — | ✔️ | |