Create a fully managed service

Updated at:

A fully managed service is a service in which all resources and software created by the service are deployed within the Alibaba Cloud account of the service creator. This topic describes how a service provider creates a fully managed service in the Compute Nest console.

Procedure

  1. Log on to the Compute Nest console.

  2. In the left-side navigation pane, choose My Services. On the My Services page, click Created Services, and then click Create Service.

  3. On the Create Service page, configure the service information.

    1. Select a method to create the service.

      You can select Create Service from Featured Templates or Build Custom Service.

      • Create a service from a featured template: Compute Nest provides service templates that are based on different architectures and applications to help you quickly create a service.

      • Create a service manually: Compute Nest provides the complete service creation process. You must configure the service information, service deployment, service O&M, and advanced settings.

    2. For the service type, select Fully Managed Service.

      If you select Create Service from Featured Templates, you must first select Fully Managed Service and then select the service template that you need below.

      Note

      After you select a service template, you can click View Details to view the deployment description and the configuration files of the service template.

    3. Click Next: Configure Settings.

    4. On the Configure Service page, configure the information about the service.

      • If you select Create Service from Featured Templates, you need to configure only the basic information of the service.

        Note

        The service icon and the service name are pre-filled with the icon and the name that are specified in the service template. You can modify the service icon and the service name based on your service plan.

      • If you select Build Custom Service, you must provide the complete service information.

        1. In the Basic Information section, enter the basic information about the service.

          Configuration item

          Description

          Service Icon

          The icon of the service. The JPG and PNG formats are supported. We recommend that you upload an image whose resolution is 192 × 192 pixels for optimal clarity.

          Service Name

          The name of the service. The name must be 3 to 200 characters in length, and can contain digits, letters, and underscores (_).

          Service Description

          The description of the service. The description must be 10 to 500 characters in length.

          Terms of service document

          Enter the name and the URL of the terms of service document that the service creator defines for the service.

          Version Description

          The description of the service version. The version description must be 1 to 200 characters in length. We recommend that you include a version number in the description. The description of each version of a service must be unique.

          Default Prefix for Service Instance Name

          The default prefix of service instance names. The prefix can be up to 40 characters in length, and can contain digits, letters, hyphens (-), and underscores (_). The prefix must start with a letter.

          After you specify the default prefix, the prefix is automatically entered in the Service Instance Name field when customers create a service instance. Customers can modify the prefix.

          Tag Settings

          The tag key and value. Select or enter a tag key and a tag value to add a tag to the service resources. You can add up to 20 tags to each resource. If no tag key or tag value is available, you can create a custom tag. For more information, see Add a custom tag.

          Resource group

          Select the resource group to which you want to add your resources.

          Resource groups allow you to group the cloud resources that you own by dimensions such as purpose, permissions, and ownership. This way, an enterprise can implement hierarchical resource management for multiple users and multiple projects. For more information, see Resource groups.

        2. In the Service Deployment section, configure the resources that the service requires.

          Configuration item

          Description

          Whether to create a member account in the resource directory

          You can select Whether to Create Member in Resource Directory based on the resource management requirements of the service instance.

          A member account in a resource directory is a resource container that Compute Nest automatically creates in the resource directory of the service creator when a service consumer creates a service instance. The member account physically isolates the resources of the service instance and forms an independent resource grouping unit. For more information, see Account-based isolation in fully managed services.

          User type

          Select the Alibaba Cloud or Third-party Cloud user type.

          • Alibaba Cloud: Select this option if service consumers can view service instances in their own Compute Nest console.

          • Third-party cloud: Select this option if service consumers do not have an Alibaba Cloud account, or if you do not want to expose Alibaba Cloud to service consumers.

          Add parameter mappings

          You can configure mappings and sub-dependency mappings for the parameters in the template.

          Select Dependency Parameter and Parameter, and then specify the values of Dependency Parameter and Parameter. After the values are specified, the corresponding parameter automatically becomes a hidden parameter. When a user creates a service instance, only the dependency parameter is displayed. After the user selects a value for the dependency parameter, the hidden parameter is automatically filled with the value that is specified for the corresponding parameter in the mapping. For more information, see Configure parameter mappings.

          Add packages

          The parameter sets. You can select a set of parameters in the template and specify the parameter values to create a parameter set. If you want to allow customers to modify all the parameters in a parameter set when they create a service instance, select Support Custom Parameter Set. Otherwise, clear this check box. For more information about parameter sets, see Parameter sets.

          Hidden parameters

          Select the parameters in the template that you want to hide.

          The selected parameters are invisible to users when they create a service instance.

          Note

          The corresponding parameters that are specified in the parameter mappings are automatically added as hidden parameters. If you have already configured the parameters in the parameter mappings, you do not need to select them again here.

          Deployment regions

          Select the regions in which deployment is allowed. You can select multiple regions. If you do not select a region, the service can be deployed in all regions by default.

          Role name

          Select a role that is trusted by Compute Nest. Compute Nest uses this role to create resources.

          • If you use Compute Nest with an Alibaba Cloud account, you must create a role and grant permissions to the role. For more information about how to create a role and grant permissions to the role, see Create a RAM role for Compute Nest service.

          • If you use Compute Nest with a RAM user, you must first create a role and grant permissions to the role, and then grant the PassRole permission to the RAM user. For more information about how to grant the PassRole permission to a RAM user, see Grant the PassRole permission to a RAM user.

          Deployed At

          Estimated Time

          The estimated time for deploying a service instance. If you configure this parameter, the specified value is displayed on the service instance deployment page to inform customers of the average time required to deploy a service instance.

          Deployment Package Association

          Set ECS Image Association

          You can set this parameter to replace the Elastic Compute Service (ECS) image specified in the template with the ECS image in the deployment package that has been distributed. For more information, see ECS image deployment package.

          Set Container Image Association

          We recommend that you use Container image deployment packages if Docker container images are used for service deployment. For more information, see Container image deployment package.

          Set File Association

          Compute Nest provides file deployment packages to resolve the issues that you may encounter when you download software resources for script-based deployment. For example, the cloud resources are inaccessible over the Internet, or the download source of the resources is not stable. For more information, see File deployment packages.

          Set Helm chart association

          If your chart package must remain private, we recommend that you use the Helm chart deployment package of Compute Nest. For more information, see Helm chart package.

          Application Group

          Create Application Group

          The application groups of resources in the template. You can add resources in the template to application groups. This facilitates resource check and management for customers. On the details page of service instances, customers can view resources, view monitoring data, perform O&M operations, and view logs by group. For more information, see Configure application groups.

          Note

          Each resource can be added to only one group.

        3. In the Service O&M (Optional) section, configure the O&M features of the service.

          Configuration item

          Description

          O&M

          Grant permissions to users

          • If service consumers need to perform O&M operations on service instances, select Grant Permissions to Customers and select the permissions that you want to grant to the users.

          • If service consumers do not need to perform O&M operations on service instances, do not select Grant Permissions to Customers.

          Add O&M operations

          Specify the O&M operations that you want to display on the O&M management page for users. For more information, see Custom O&M operations.

          Monitoring

          Resource Monitoring

          The monitoring configurations. If you want to receive alert notifications, you must select Obtain Permissions and then select Monitoring Permissions.

          • Configure CloudMonitor Alert Template for All Resources: Select a CloudMonitor alert template.

          • Configure CloudMonitor Alert Template for All Resources: Select a CloudMonitor alert template for each application group.

            Note

            This option is available only if application groups are configured.

          If no alert template is available, create one first. For more information, see Monitoring and alerting overview.

          Prometheus Service

          Specifies whether to enable the Prometheus monitoring feature. If you disable this feature, you do not need to configure the following parameters. For more information, see Configure monitoring and alerts for fully managed ACK.

          Log

          Application Log

          The Logstore information. Click Add a Logstore. In the Add Logstore dialog box, configure the Logstore Name, Path, and File Name parameters.

          Note
          • If a service is deployed on an ECS instance, you must configure the path and name of the file in a Logstore.

          • If a service is deployed in a pod, you must configure the Logstore information in the environment variables of the pod.

          Modify Configurations

          Service Instance Configuration Change

          Specifies whether to enable the configuration change feature. If you disable this feature, you do not need to configure the following parameters.

          Click Add Operation. In the dialog box that appears, configure the configuration change operation.

          • Select Template: the template that is used to implement the configuration change.

            Note
            • To enable instance type change, you must set the UpdatePolicy property of the ALIYUN::ECS::InstanceGroup resource to ForAllInstances in the template.

            • To enable the update of the ALIYUN::ECS::RunCommand resource, you must set the Syns property to true in the template. The updated ALIYUN::ECS::RunCommand resource is re-executed during the configuration change.

          • Operation Name: the name of the configuration change operation.

          • Operation Description: the description of the configuration change operation.

          • Operation Type: the type of the configuration change operation. Valid values: Upgrade, Downgrade, and Custom. You can select only one operation type.

            • Upgrade: If you select Change Plan as Method, customers can upgrade service instances by changing the current parameter set to a parameter set with a larger serial number. If you select Change Parameter as Method, customers must set parameters of a numeric type to larger values when they upgrade service instances. Custom parameter sets do not support upgrade operations.

            • Downgrade: If you select Change Plan as Method, customers can downgrade service instances by changing the current parameter set to a parameter set with a smaller serial number. If you select Change Parameter as Method, customers must set parameters of a numeric type to smaller values when they downgrade service instances. Custom parameter sets do not support downgrade operations.

            • Custom: No limits are set on the configurations of parameter sets and parameters, and custom parameter sets are supported.

          • Method: the configuration change method.

          • Select Parameters: the parameters that can be modified by customers. This parameter is available only if you select Change Parameter as Method. Parameters that cannot be changed are filtered out.

        4. In the Advanced Configuration (Optional) section, configure the advanced features of the service.

          Configuration item

          Description

          Permission settings

          Deployment link permissions

          You can configure this parameter based on your plan.

          • Public: All users who obtain the deployment link can use the deployment link to create service instances.

          • Restricted: Only users who are added to the whitelist of deployment link permissions can use the deployment link to access the service or create service instances. For more information about how to add users to the whitelist of deployment link permissions, see Modify service deployment permissions.

          • Hidden: The service details page is hidden from all users who are not on the permission list. If an unauthorized user clicks the link, a message appears to indicate that the service does not exist.

          Network settings

          VPC private access

          After you enable VPC private connections, the service and the network of the service consumer are connected over a private network, and your traffic is not exposed to the Internet.

          Based on the content of the template, select the load balancer or endpoint service information, and then select the corresponding load balancer or endpoint from the service deployment template.

          Payer

          Select the payment method for the service resources. You can select Service Consumer or Service Provider.

          The Service Provider payment feature is disabled by default. To enable the feature, go to the Quota Center console and apply to enable the Service Provider payment method.

          VPC private reverse access

          After you enable this feature, you can access the resources in the VPC of the user over a VPC private reverse connection.

          Reverse endpoint service configuration

          Specify the region and the endpoint service information of the reverse endpoint.

          Custom domain name

          When users create a service instance, they can choose to access your service over a private network by using this domain name. We recommend that you keep the custom domain name consistent with the public domain name of your service.

          Tenant settings

          OAuth authentication

          After OAuth authentication is enabled, service providers can connect a RAM OAuth application in the Compute Nest console to provide users with a password-free logon address. Users can use this address and their Alibaba Cloud account to log on to the software that is associated with the service created by the service provider without entering a password.

          Select application

          After you enable OAuth authentication, select the password-free logon address that you want to provide to users from the Select Application drop-down list.

          If you have not created an application, create and connect an application first. For more information, see Configure password-free logon with OAuth.

          Application logon address

          Specify the logon address of your application. After a user creates a service instance, the address is displayed to the user on the service instance details page.

          Distribution settings

          Allow service providers to apply for distribution authorization

          After you enable this feature, Compute Nest distributors can apply to you for the distribution authorization of the service, and you receive a review reminder message. If you approve the authorization, the distributor can re-create and distribute the service. In this case, you must settle payments with the distributor separately.

          Instance time settings

          Retention period after expiration

          Specify the retention period of the service instance after the instance expires. Unit: days.

          Compliance package check

          Enable data security risk check in the VPC

          Checks for data leaks in the VPC. For example, an ECS instance is migrated out of the VPC, or an ECS instance is added to the VPC.

  4. Click Create Service, and then click OK in the confirmation dialog box that appears.

    On the message page, you can click View Service or Test Service Now.

View the service

  1. After the service is created, you can view the service on the My Services page.

    The My Services page contains the Created Services and Used Services tabs. The page provides the Create Service button and allows you to filter services by tag, service name, and type. Created services are displayed as cards. Each card displays the service tag, the update time, and the version information, and provides action buttons such as Unpublish Service, Publish to Marketplace, Pre-release, and Edit Version.

Next steps

  1. Test the service.

    After the service is saved, you can test the service by yourself. You can also pre-release the service and share it with specific customers for testing. For more information, see Test a service.

  2. Publish the service.

    After the service passes the test, submit the service for review. After the review is approved, you can publish the service. For more information, see Publish a service.

  3. Deploy a service instance.

    A fully managed service instance is a service entity that a user creates based on a Compute Nest service and for which the service provider provides the resources and the software. For more information, see Create a fully managed service instance.