FAQ about configuring VPC access control

Updated at:

If connectivity or domain resolution issues occur when you configure virtual private cloud (VPC) access control for a Container Registry (ACR) Enterprise Edition instance, this FAQ helps you troubleshoot them and manually configure private domain name resolution.

The VPC and the Enterprise Edition instance fail to connect

Symptom

The access IP address of the ACR Enterprise Edition instance is not found in the VPC. This means the VPC failed to connect to the Enterprise Edition instance.

Solution

Delete the VPC and add it again. If the issue persists, submit a ticket for troubleshooting.

VPC domain resolution errors

Symptom

After you enable VPC access control, ACR automatically configures private domain name resolution (PrivateZone) in the VPC. ACR then resolves the private domain name of the Enterprise Edition instance to the assigned access IP address. If the access IP address appears in the list but is marked with a red exclamation point, automatic resolution has failed. Troubleshoot the issue based on the error code, as described in the following table.

Common error codes and solutions

Error code

Solution

PRIVATE_ZONE_SERVICE_NOT_ENABLED

The Private Zone service is not enabled.

Log on to the Alibaba Cloud DNS-Private Zone console to enable the service, and then configure access control again for the target VPC. For more information, see Configure VPC access control.

PRIVATE_ZONE_REACH_SERVICE_FLOW_CONTROL

The Private Zone service has temporarily throttled your account.

After the throttling is lifted, add access control again for the VPC. Alternatively, see Manually configure VPC domain name resolution.

PRIVATE_ZONE_SERVICE_UNAVAILABLE

The Private Zone service encountered an error while resolution was being configured.

After the service recovers, add access control again for the VPC. Alternatively, see Manually configure VPC domain name resolution.

NO_PRIVATE_ZONE_AUTHORIZED

ACR has no service-linked role configured for Private Zone, or the role has insufficient permissions.

See Service-linked role for PrivateZone to complete the authorization.

PRIVATE_ZONE_CONFLICT_AT_{private_zone_id}

ACR detected that the target zone ({private_zone_id}) is already bound to multiple VPCs in Private Zone.

To avoid affecting existing workloads, perform the following steps:

  1. Log on to the Alibaba Cloud DNS-Private Zone console.

  2. Find the target zone and click Effective Scope in the Actions column.

  3. In the Effective Scope panel, hover over image for the target VPC, and then click image.

  4. Click OK.

After you remove the unnecessary VPCs, add access control again for the target VPC. Alternatively, see Manually configure VPC domain name resolution.

  • PRIVATE_ZONE_NOT_EXIST

  • PRIVATE_ZONE_VPC_NOT_EXIST

  • PRIVATE_ZONE_VPC_REPEATED_BINDED

The related domain name records changed while ACR was automatically configuring Private Zone.

Add access control again for the target VPC. For more information, see Configure VPC access control.

Manually configure VPC domain name resolution

Important

If you manually configured VPC domain name resolution for a VPC and later removed access control for that VPC from the Enterprise Edition instance, manually delete the corresponding resolution records in Alibaba Cloud DNS - Private Zone. Otherwise, the records may affect your workloads. Assess and resolve any resulting issues at your own discretion.

The following example points the private domain name test-vpc.cn-hangzhou.cr.aliyuncs.com of an Enterprise Edition instance to the IP address 192.168.0.1 in the target VPC.

  1. Log on to the Alibaba Cloud DNS-Private Zone console.

  2. On the User Defined Zones tab, click Add Zone.

  3. In the Add Zone sidebar, configure the following parameters and then click OK.

    Parameter

    Example value

    Authoritative Zone

    cn-hangzhou.cr.aliyuncs.com

    For example, if the private domain name is test-vpc.cn-hangzhou.cr.aliyuncs.com, its domain name suffix is cn-hangzhou.cr.aliyuncs.com.

    Subdomain Recursive Proxy

    Enabled

    Effective in VPCs

    Select the ID of the target VPC.

  4. On the User Defined Zones tab, find the zone you created and click Settings in the Actions column.

  5. Click Add Record. In the Add Record dialog box, configure the following parameters and click OK.

    Parameter

    Example value

    Record Type

    A

    Hostname

    test-vpc

    For example, if the private domain name is test-vpc.cn-hangzhou.cr.aliyuncs.com, its prefix is test-vpc.

    Record Value

    192.168.0.1

    The access IP address in the corresponding VPC.