All Products
Search
Document Center

Alibaba Cloud DevOps:Quick start for region-specific organizations

Last Updated:Aug 27, 2026

This topic describes how to quickly get started with a region-specific organization.

Benefits of region-specific organizations

  • Provides VPC domain names and allows you to associate your enterprise VPC and security groups. Both the Alibaba Cloud DevOps site and repository addresses can be made accessible only from within the VPC.

  • Builds and deployments (CI/CD) can be completed entirely within a VPC, delivering faster performance, stronger security, and lower costs.

  • Integrates enterprise identity providers (DingTalk or Lark) and supports single sign-on (SSO) for more standardized account management.

Activate Alibaba Cloud DevOps

Before you use Alibaba Cloud DevOps for the first time, you must activate the service. After activation, the system automatically creates a pay-as-you-go order, and you can then create an organization and use its features.

To support individual developers and startup teams, Alibaba Cloud DevOps offers a free tier of resources, including computing resources, storage space, and user licenses. New users can try the product within the free tier limits in Personal Use Mode.

When your actual usage exceeds the free tier, you are automatically billed according to the standard billing rules. You can flexibly adjust usage based on your business needs and upgrade to Enterprise Collaboration Mode at any time to unlock enterprise-grade features.

image

Create a region-specific organization

  1. Log on to the Alibaba Cloud DevOps console with your Alibaba Cloud account or a RAM user that has Alibaba Cloud DevOps management permissions.

    The RAM user must have the AliyunRDCFullAccess permission.
  2. In the left-side navigation pane, choose Instance management > Standard, and then select a region at the top of the page.

    If this is your first time using the service, click Activate Alibaba Cloud DevOps, follow the on-screen instructions to create a service-linked role, and then click Activate Now.
  3. Click Create Organization and configure the following parameters:

    For more information about purchasing permissions and billing, see Billing description (Region edition).
    • Region: Select the region of the organization. Supported regions: China East 2 (Shanghai), China South 1 (Shenzhen), China East 1 (Hangzhou), and China North 2 (Beijing).

    • Organization name: The name of the organization. You can change it after creation.

    • Organization identifier: The organization's access domain name and the suffix of member account IDs are automatically generated based on this identifier. It cannot be changed after creation.

    • Collaboration mode: Select Enterprise Collaboration Mode or Personal Use Mode based on your needs.

    • Administrator account password: The password for logging on to the organization with the initial root account. You can change it after creation.

  4. After you complete the configuration, click Create Organization to create the organization. Then, on the instance list page, click the organization name to go to the organization details page. On this page, you can view the basic information of the organization, such as the site address and egress IP address, and perform subsequent organization settings, such as member management and network configuration.

  5. Click Access Instance to go to the logon page of Alibaba Cloud DevOps. We recommend the logon-free method with your Alibaba Cloud account: click the Alibaba Cloud icon on the logon page to complete logon. You can also log on with the administrator account and password. The administrator account can be found on the organization details page, and the password is the one you entered when creating the organization.image

Create organization members

Alibaba Cloud DevOps supports multiple ways to add members. You can log on directly with Alibaba Cloud RAM users, manually add accounts that log on with an account and password, or integrate third-party identity providers (such as DingTalk, Lark, WeCom, SAML, and CAS).

Method 1: Direct logon with Alibaba Cloud RAM users

  1. On the organization details page in the Alibaba Cloud DevOps console, click Member management.

  2. In the Alibaba Cloud RAM user settings area, click Set Scope. On the RAM user settings page, click Select RAM users and select from your existing RAM users. The selected RAM users can then log on to Alibaba Cloud DevOps directly.

  3. Set the Default logon method to Alibaba Cloud RAM user.

  4. When users access the Alibaba Cloud DevOps site, they are automatically redirected to the Alibaba Cloud logon page. After they successfully log on with a RAM user, they can use Alibaba Cloud DevOps.

Method 2: Manually add accounts as the organization administrator

  1. On the organization details page in the Alibaba Cloud DevOps console, click Member management. In the Manual Account Management settings area, click Member Management to open the admin console of Alibaba Cloud DevOps.

  2. In the left-side navigation pane, choose Member management, and then click Create User. Enter the following required information, including Name, Account ID, Initial password, and Department, as well as other optional information.

  3. Click Confirm to create the member. For more information about member management features, see Member management.

Method 3: Sync from a third-party identity provider

Many enterprises use third-party identity providers to manage their organizational structure and employee onboarding and offboarding in a standardized way. Alibaba Cloud DevOps can integrate with these identity providers directly. Supported identity provider types:

  • DingTalk

  • Lark

  • WeCom

  • SAML

  • CAS

Configuration path: On the organization details page in the Alibaba Cloud DevOps console, click Member management, select the type that matches the identity system used by your enterprise, and complete the configuration. For detailed steps, see Identity provider management.

Collaboration mode overview and selection

Alibaba Cloud DevOps Region edition provides two collaboration modes. We recommend that you choose a mode based on your team size and security compliance requirements before creating an organization.

Mode comparison

Feature

Personal Mode

Enterprise Collaboration Mode

Target users

For startup development teams or individual developers.

For enterprise development teams with high requirements for data security and standardized development processes.

Logon method

Username and password

Username and password, or single sign-on (SSO)

Integration with corporate identity providers

Not supported.

Supports Alibaba Cloud RAM, SAML, Feishu, DingTalk, WeCom, and CAS.

Enterprise Collaboration Mode supports configuring multiple identity providers. Administrators can select and configure the identity provider type based on their enterprise's identity system.

Virtual Private Cloud (VPC) access

Not supported.

Supports private endpoints and integration with your enterprise VPC.

Development asset backup

Not supported.

Supports code repository backups.

IP address whitelist

Not supported.

Supports configuring an IP address whitelist.

Audit log

Not supported.

Supports pushing operation logs to ActionTrail.

How to choose a collaboration mode

Important

Personal Mode is free for up to five user accounts. Enterprise Collaboration Mode requires per-user licensing and unlocks advanced enterprise features.

  • If you are an individual developer or part of a small startup team and want to quickly try Alibaba Cloud DevOps without complex security controls and enterprise integrations, choose Personal Mode.

  • Choose Enterprise Collaboration Mode if your enterprise team requires the following features:

    • Unified logon with a corporate identity system (SSO)

    • VPC access for code management and pipelines

    • Operation auditing and security compliance

    • Development asset backup

Configure organization roles

After accounts are created, you need to assign roles to organization members. Roles of Alibaba Cloud DevOps are configured in admin console > Role management of Alibaba Cloud DevOps, rather than in Alibaba Cloud RAM account management. Alibaba Cloud DevOps provides several predefined roles and also allows organization administrators to create custom roles. Predefined roles include:

  • Global administrator: the administrator with the highest permissions.

  • Module administrators, such as the code administrator and the project collaboration administrator. These administrators have full permissions on the corresponding modules.

  • Member: has only standard user permissions and no administrative permissions.

You can select permission points for each role. A user can be associated with multiple roles, in which case the effective permissions are the union of the permission points of all assigned roles.

Important

The predefined Member role has permissions to create data, such as code repositories and projects. If your team has strict permission management requirements and standard members must not be allowed to create important data, create a new role and select the corresponding permission points.

Choose a site access mode

Alibaba Cloud DevOps provides two access methods: the public domain name and the VPC domain name. The public domain name is enabled by default, while the VPC domain name is disabled by default. If your enterprise has no special network access requirements, you can use the public domain name directly. If your enterprise has high requirements for the network security of development data, enable the VPC domain name. Common scenarios include:

  • Enterprise members must access the Alibaba Cloud DevOps site from the enterprise IDC or VPC network.

  • Developers must read from and write to code repositories and artifact repositories from the enterprise IDC or VPC network.

  • Code cloning and build processes in CI/CD workflows must be performed inside the VPC network.

In this case, activate the VPC domain name. This domain name can be accessed only through the associated VPC and is not accessible from the Internet. Perform the following steps:

  1. In the Alibaba Cloud DevOps console, go to the organization details page and click the Network configuration tab.

  2. Select the Enable VPC access mode checkbox, click Add VPC, and configure the following items:

    • Select an appropriate VPC.

    • Associate a security group and a vSwitch.

    You must associate at least one vSwitch. You can add multiple vSwitches to ensure network availability.
  3. After you complete the configuration, click OK.

After the VPC domain name is activated and a VPC is associated, all endpoints within the VPC can access the Alibaba Cloud DevOps VPC domain name.

Get started with code management

Alibaba Cloud DevOps Codeup is a self-developed Git code management platform of Alibaba Cloud. It supports features such as code hosting, branch policies, code detection, intelligent code review, code encryption, and scheduled backups, protecting your enterprise code assets in all aspects and helping you achieve secure, stable, and efficient development process management.

  1. From the workbench or the top menu, go to Code management. In the left-side navigation pane, click Repositories. Here, you can directly create a new repository.

  2. To migrate and import an existing repository, click Import repository. For more information, see Code migration and repository synchronization.

  3. After creating a repository, you can add developers and administrators for the repository in the member settings. A standard member of the organization role can also be set as an administrator of a specific repository here.

  4. Configure identity authentication in your local Git environment. Both HTTPS and SSH modes are provided.

    1. For HTTPS mode, the account and password can be obtained from the Personal settings page of Alibaba Cloud DevOps. The account name is on the Basic information page. If a user logs on with an account and password, they are exactly the same as the logon account and logon password. If a user logs on with an Alibaba Cloud RAM user or a third-party identity provider, a personal access token must be created and used as the password for the local Git configuration. For more information about how to create one, see Personal access tokens.

    2. For SSH mode, see Configure an SSH key.

  5. For the clone address of a repository, find it in the Clone/Download button on the repository details page in Codeup.

Get started with pipelines

Alibaba Cloud DevOps Flow is an enterprise-grade, automated continuous integration and continuous delivery tool that supports scenarios such as building, deployment, testing, and code detection.

  1. Unlike the Alibaba Cloud DevOps central site, the Alibaba Cloud DevOps Region site does not have a default build cluster. You must first initialize a VPC build cluster and associate it with your VPC before you can run pipeline builds. For a new build cluster, you must select an Alibaba Cloud DevOps site (endpoint). Because Alibaba Cloud DevOps provides two sites, the public domain name and the VPC domain name, pay special attention to the network configuration of the VPC associated with the build cluster:

    1. If the build cluster endpoint is the Alibaba Cloud DevOps public domain name, the VPC must have Internet access, and the egress IP addresses of Alibaba Cloud DevOps must be added to the IP address whitelist of the security group. You can find the Alibaba Cloud DevOps IP addresses on the organization details page: Organization overview.

    2. If the build cluster endpoint is the Alibaba Cloud DevOps VPC domain name, you only need to ensure that the network of the cluster VPC can communicate with the organization VPC of Alibaba Cloud DevOps.

  2. Initialize service connections for connecting to cloud resources. This typically includes code repositories (Codeup/GitLab), container registries (ACR), cloud servers (ECS), and Kubernetes clusters (ACK). This way, when you orchestrate pipelines, you can directly use service connections to configure specific resources for building and deployment. For more information, see Service connection management.

  3. Initialize host groups and Kubernetes clusters. Choose host deployment or Kubernetes deployment based on your actual deployment method. For more information, see Host group management and Kubernetes cluster management.

  4. Create a pipeline by using the pipeline template wizard and complete your first build and deployment. Create your first pipeline

Important

When you use pipelines for the first time, you may encounter runtime errors. The most common cause is that the VPC associated with the build cluster cannot connect to the specified endpoint. For example:

  • An error occurs when requesting the build runtime environment because the VPC cannot access the Alibaba Cloud DevOps site.

  • An error occurs during code cloning because the VPC cannot access the clone address of the repository.

  • An error occurs when pushing the image after the image build is complete because the VPC cannot access the address of the container registry.

In this case, check the network configuration of the VPC, the security group whitelist, Cloud Enterprise Network (CEN), and other related settings. If the problem cannot be resolved, submit a ticket on the Alibaba Cloud website for technical support.