Publishing review standards

更新时间:
复制 MD 格式

Compute Nest connects partners and customers in the cloud. It helps partners reduce application delivery costs and improve operational efficiency. It also helps customers achieve efficient software deployment and a smooth user experience. This topic describes the review standards for publishing a Compute Nest service, covering security, design, performance, and legal compliance.

Before you submit

To help your Compute Nest service pass the publishing review, make sure that you have checked every item in the following list before you submit the service. Make sure that:

Security

When users deploy software using Compute Nest, they expect a secure experience. If your service does not meet the security guidelines, revise it before you submit it for review.

  • Service information review standards

    • The service name, icon, and description must not contain prohibited or sensitive content. This includes content related to violence, gore, politics, religion, discrimination, pornography, or privacy violations.

    • You must understand and agree that the state secrets of the People's Republic of China are protected by law and that you are obligated to protect them. The service information must comply with relevant confidentiality laws and regulations and must not jeopardize the security of state secrets of the People's Republic of China.

  • Template input parameter (Parameters) review standards

    • Template input parameters must not contain user credentials for Alibaba Cloud, such as passwords, public keys, private keys, or certificates.

    • Do not set default values for the passwords of remote services, CIDR blocks/IP addresses, or databases. These parameters must be provided by the user as input parameters. For sensitive inputs such as passwords, select the NoEcho input and enable a stricter regular expression. For other inputs, set the most common values and provide corresponding help text.

  • Template network and security parameter review standards

    • Make sure that the default Secure Shell (SSH) port (22) or Remote Desktop Protocol (RDP) port (3389) is not open to 0.0.0.0. For more information, see Elastic Computing Service security.

    • Private deployments do not support classic network instances.

    • Set RAM roles and policies to the minimum required permissions. In general, trust relationships cannot be granted to non-Alibaba Cloud services. To use the instance RAM role feature, see Instance RAM roles.

  • Image and deliverable review standards

    • The image cannot contain vulnerable system software. You can scan for vulnerabilities in Security Center.

    • Use key pair-based access for instance identity verification instead of password-based authentication.

    • The image must not contain passwords, authentication keys, key pairs, security keys, or other credentials for any reason.

    • The image must not request or use keys or private keys from users to access Alibaba Cloud resources.

    • Linux-based images must not allow SSH password authentication. To disable password authentication, set `PasswordAuthentication` to `NO` in the sshd_config file.

  • Data security review standards

    Service providers must implement appropriate security measures to ensure that collected user information is properly handled in accordance with the Compute Nest Service Agreement and the legal guidelines in this topic. These measures must prevent unauthorized use, disclosure, or third-party access to this information.

Performance

To ensure a good user experience during service instance deployment, make sure that your published Compute Nest service meets the following performance requirements.

  • Compute Nest service completeness

    The service that you submit to Alibaba Cloud for review must be the final version. This ensures that users receive a complete and usable service when they purchase it. Before you submit the service for review, you must test the stability of the deployment process. We will reject incomplete services or services with obvious errors.

  • Accurate metadata

    Make sure that your service information accurately reflects the core content of the service. This helps customers understand exactly what they will receive when they purchase the service. When you update the service version, also update the service information to keep the description current. Do not include hidden, hibernating, or undocumented features in the service. All features included in a Compute Nest service must be clearly visible.

  • Deployment time configuration

    When you create a service, you can set the estimated deployment time and the deployment timeout period. The estimated deployment time is displayed to users to set their expectations. The deployment timeout period defines the maximum time allowed for a deployment before it is considered abnormal. If a user's deployment exceeds this timeout period, the deployment fails.

  • Service stability

    The service must remain stable. This includes stability during upgrades. The upgrade process must not affect normal use of the service by users.

Design

Follow the design specifications for Compute Nest services to ensure service quality.

  • Service information specifications

    • Provide complete service information in both Chinese and English.

    • In the service description, clearly state the service limitations, applicable scenarios, and inapplicable scenarios.

  • Package usage specifications

    When you create a service, you can use package settings to simplify the process for users when many input parameters are required. After you define the required user input parameters in the template, select which of these parameters to include in a package. Then, configure the default values for each parameter in the package to complete the package setup.

  • Template content specifications

Legal

You must comply with all legal requirements of any region where your Compute Nest service is available to users. Ensure that you comply with the terms of the Compute Nest Service Agreement.

  • Data collection and storage specifications

    • Permission: Service providers must obtain user consent before collecting user data. Paid features must not depend on or require users to grant access to this data. Service providers must implement appropriate security measures to properly handle collected user information and prevent unauthorized use, disclosure, or third-party access to the information.

    • Access permissions: Service providers must adhere to the access permissions for user data as specified in the purchase agreement with the user. This includes data such as user contact information and data required for Alibaba Cloud Managed Services.

  • Data use and sharing specifications

    • Unless otherwise permitted by law, you must not use, transmit, or share user personal data without user consent. You must also clearly state how and where this data is used. Failure to comply with these requirements may result in the delisting of your service and your removal from the Compute Nest Program.

    • Data collected for one purpose cannot be used for another purpose without additional user consent, unless explicitly permitted by law.

  • Intellectual property specifications

    • The service provider owns the intellectual property rights to their brand, logo, services published through Compute Nest, other information displayed on Compute Nest, and any derivative works. The service provider agrees to grant the Compute Nest operator a free license to use, copy, reproduce, execute, and display (in whole or in part) their brand, logo, and other information displayed on Compute Nest.

    • The service provider must guarantee that they own the legal intellectual property rights (including copyrights, patents, and trademarks) for the services they publish in Compute Nest or have obtained legal and sufficient authorization. The service provider assumes all legal responsibilities and risks regarding the legality of their intellectual property. The Compute Nest operator has the right to request relevant intellectual property certificates from the service provider for verification at any time. You must ensure that the legal rights or interests of any third party are not infringed.

After you submit

After you create a service in the Compute Nest console and submit it for review, the review process begins. Keep the following points in mind:

  • Time: Alibaba Cloud will review your service as soon as possible and complete the review within three business days. If the service is complex or has new issues, a more in-depth review may be required.

  • Status updates: The current status of your submitted service is displayed in the review request in the Compute Nest console. You can check the status regularly.

  • Publishing date: After your Compute Nest service passes the review, you must publish the service yourself. You also need to create and associate an Alibaba Cloud Marketplace product. Therefore, you can control the publishing date.

  • Rejection: If your service review request is rejected and you have questions or want to provide additional information, contact your Alibaba Cloud account manager or Alibaba Cloud after-sales support.