An organization in Alibaba Cloud DevOps is a centralized workspace for managing code repositories, pipelines, and development assets. You can configure collaboration modes, security settings, and network access to match your team's requirements.
Prerequisites
Before you begin, make sure that you have:
-
An Alibaba Cloud account or a Resource Access Management (RAM) user with administrative permissions for Alibaba Cloud DevOps
-
The
AliyunRDCFullAccesspermission granted to the RAM user
Choose a collaboration mode
Alibaba Cloud DevOps offers two collaboration modes. Choose one based on your team size and security requirements.
| Feature | Personal Mode | Enterprise Collaboration Mode |
|---|---|---|
| Target users | Individual developers or small startup teams | Enterprise R&D teams with security and compliance requirements |
| User licenses | Free (up to 5 accounts) | Paid, based on the number of users |
| Logon method | Username and password | Username and password, or Single Sign-On (SSO) |
| Identity provider integration | Not supported | Alibaba Cloud RAM, SAML, and Feishu. Other integrations are under development. |
| Virtual Private Cloud (VPC) access | Not supported | Private endpoints with VPC integration |
| Development asset backup | Not supported | Code repository backups |
| IP whitelist | Not supported | Supported |
| Audit log | Not supported | Operation logs pushed to ActionTrail |
Personal Mode -- Choose this mode to get started quickly without enterprise-grade security controls. Personal Mode includes free user licenses and supports up to 5 accounts.
Enterprise Collaboration Mode -- Choose this mode if your team requires SSO integration, VPC access, audit logging, or development asset backup. User licenses are billed based on the actual number of users. For pricing details, see Billing rules for Alibaba Cloud DevOps (Region-based).
Create an organization
-
Log on to the Alibaba Cloud DevOps console.
-
In the left-side navigation pane, choose Instances > Standard.
-
Click Create Organization and configure the following parameters:
Parameter Description Region The region where the organization is hosted. Organization name A display name for the organization. You can change this after creation. Organization ID A unique identifier used to generate the access endpoint and member account ID suffix. You cannot change this after creation. Collaboration mode Select Personal Mode or Enterprise Collaboration Mode. For help choosing, see Choose a collaboration mode. Password The initial password for the root account. You can change this after creation. -
After the organization is created, go to the instance list page and click the organization name to open the details page.
-
Click Go to Instance to open the logon page. For more information, see Accounts and logon.
View organization details
View and manage your organization's information, resource usage, security settings, and network configuration on the organization details page.
Basic information
The Overview tab displays the following fields:
| Field | Description | Editable |
|---|---|---|
| Instance Name | The display name of the organization. | Yes |
| Instance ID | The unique ID of the organization. | No |
| Region | The region where the organization is hosted. | No |
| Description | A description of the organization. | Yes |
| Creation Time | The time the organization was created. | No |
| Collaboration mode | The current collaboration mode. | See Upgrade and downgrade collaboration modes |
Instance information
| Field | Description |
|---|---|
| Public Domain | The public access endpoint of the organization. |
| VPC Domain | The private access endpoint, available when VPC access mode is enabled. |
| Root Account Status | The root account name, which is automatically generated based on the Organization ID, and its enabled or disabled status. |
| IP Whitelist | The current status of the IP whitelist. |
| Domain Name IP | The domain name IP of the organization. |
| Outbound IP Address | The outbound IP address of the organization. |
Service information
Available only in Enterprise Collaboration Mode.
View DevOps service orders and license status.
Resource usage
View the resource usage of the current organization, including:
-
Core-minutes used this month
-
Git storage used
-
LFS storage used
-
Artifact storage used
Resource usage statistics are not real-time. Data is updated daily.
Configure security settings
Root account management
-
Enable or disable the root account.
-
Change the root account password. Password changes are available only when the root account is enabled.
IP whitelist
The IP whitelist restricts access to your organization to specific source IPs.
-
Enable or disable the IP whitelist.
-
Use group management to define IP ranges for different access scenarios.
-
When first enabled, the whitelist is automatically populated with
0.0.0.0/0, which allows access from all IP addresses. -
Edit the whitelist to include only the specific IP addresses or CIDR blocks that you want to allow.
Data backup
Available only in Enterprise Collaboration Mode.
Back up core data such as code repositories to Object Storage Service (OSS).
Audit log
Operation logs for your organization are automatically delivered to ActionTrail in the purchaser's Alibaba Cloud account. By default, the last 90 days of logs are available for query.
In ActionTrail, configure the following options:
-
Store logs in Simple Log Service (SLS) or Object Storage Service (OSS)
-
Set up long-term retention, query, analysis, and compliance auditing
Configure network access
Public access mode
Public access is enabled by default for new organizations. The system assigns a public endpoint accessible over the internet.
Enable VPC access mode
To access Alibaba Cloud DevOps through your enterprise VPC:
-
Go to the organization details page and switch to the Network Configuration tab.
-
Select Enable VPC access mode.
-
After you enable this mode, a private endpoint is assigned to your organization. This endpoint is not accessible from the public internet -- it can only be reached from an associated VPC.
-
Click Add VPC, select a VPC ID, and associate a security group and at least one vSwitch. You can optionally enable Reverse Access. Add multiple vSwitches to improve network availability.
Restrict access to VPC only
To block public internet access and allow connections only from within a VPC:
-
Go to the organization details page and switch to the Network Configuration tab.
-
Select Enable VPC access mode.
-
Click Add VPC, select a VPC ID, and associate a security group and a vSwitch.
-
Go to the VPC console and find the IP address of the VPC configured in step 3.
-
On the Security Settings tab of the organization details page, add the VPC IP address to the IP whitelist.
Upgrade and downgrade collaboration modes
Upgrade from Personal Mode to Enterprise Collaboration Mode
-
Log on to the Alibaba Cloud DevOps console.
-
In the left-side navigation pane, choose Instances > Standard.
-
On the instance list page, click the organization name to open the details page.
-
Click Upgrade collaboration mode.
Downgrade from Enterprise Collaboration Mode to Personal Mode
Before downgrading, make sure the following conditions are met:
-
The organization has 5 or fewer accounts. Delete extra accounts before proceeding.
-
All corporate identity provider integrations are removed.
-
VPC access mode is disabled and all associated VPCs are removed.
-
No other organization in the current region is using Personal Mode.
Procedure:
-
Log on to the Alibaba Cloud DevOps console.
-
In the left-side navigation pane, choose Instances > Standard.
-
On the instance list page, click the organization name to open the details page.
-
Click More > Downgrade collaboration mode. Confirm that all downgrade conditions are met, select the confirmation checkbox, and click OK.
Delete an organization
Deleting an organization permanently erases all data, including code repositories, pipelines, departments, and members. This action is irreversible.
Before you delete:
-
Active, paid subscriptions must be cancelled or expired before deletion. An organization with active subscriptions cannot be deleted.
-
Once subscriptions expire, the instance is stopped and inaccessible.
Procedure:
-
Log on to the Alibaba Cloud DevOps console. In the left-side navigation pane, choose Instances > Standard.
-
On the instance list page, click the organization name to open the details page.
-
Click More > Delete.
-
In the dialog box, enter the organization name and click OK.
Upgrade from the global edition to a region-specific edition
If your organization uses the Alibaba Cloud DevOps global edition and you want region-specific features such as VPC access and private network builds, submit a ticket to request an upgrade.
After the upgrade, note the following changes:
-
Region change: Only the Singapore region is supported for this upgrade. Before the upgrade, your organization is listed under "Global". After the upgrade, it appears under the Singapore region. Switch the region to Singapore in the console to find your organization.
-
Build cluster update: The global and Singapore region-specific editions use different build clusters. After the upgrade, update your pipeline's build cluster settings to associate the build cluster with your VPC. This enables your builds and deployments to connect to Alibaba Cloud resources such as Elastic Compute Service (ECS), Container Service for Kubernetes (ACK), Container Registry (ACR), and OSS through the VPC. For more information, see Build clusters.