Unified O&M solution for hosts across multiple accounts
Solution overview

This topic describes a unified operations and maintenance (O&M) solution that uses Bastionhost to manage hosts across multiple accounts. This solution provides a unified portal for enterprises to manage cloud hosts. It helps you meet basic O&M security needs and network security requirements for classified protection compliance. You can manage server assets, user accounts, and permissions more efficiently and flexibly.
Benefits
Unified portal for O&M operations
Administrators can import Alibaba Cloud Elastic Compute Service (ECS) instances and hosts from other sources to create hosts in Bastionhost. This provides a unified way to maintain assets and perform O&M operations.
Stable, cloud-native architecture
Bastionhost uses a cloud-native architecture. This architecture prevents service interruptions from a single point of failure. The underlying Alibaba Cloud services are highly stable and mature, which enhances the security of system resources. A cloud-native Bastionhost is more stable, flexible, and secure.
Secure and reliable O&M capabilities
Bastionhost provides stable and efficient O&M for Windows and Linux systems. O&M on Windows is smooth and fully audited. Bastionhost also enables unified management and centralized O&M for server assets in hybrid cloud scenarios, such as multicloud, on-premises data centers, and cross-VPC environments. In addition, the Bastionhost code is commercially packaged and closed-source, which makes it resistant to attacks and ensures stable, secure O&M.
Global deployment
Bastionhost supports global deployment in regions such as Asia-Pacific, the Americas, Europe, and the Middle East. It is optimized for use outside China and provides a full English interface. It also supports two-factor authentication for O&M using mobile numbers from many countries. This ensures secure O&M for assets worldwide.
Convenient and practical
Bastionhost is simple, efficient, and easy to use. It is available for immediate use after purchase. You can configure it flexibly as needed and enable it with a single click. It supports one-click synchronization of ECS instances and ApsaraDB for MyBase hosts from your Alibaba Cloud account. It also supports one-click import of users from Resource Access Management (RAM), Active Directory (AD), and LDAP accounts.
Customer scenarios
Efficient and unified management of hosts across multiple accounts
Scenario description
Unified portal management to resolve issues with scattered logons:
Manages account credentials, such as passwords or Secure Shell (SSH) keys, for ECS instances.
O&M engineers log on to Bastionhost and then to ECS instances without needing to know the ECS passwords.
Fine-grained permission management:
Implements the principle of least privilege for flexible and Accurate Access Control.
Requires secondary approval for access to important assets or commands.
Differentiates permissions based on location for remote work.
Applicable customers
Enterprise customers who need to perform unified O&M for hosts across multiple accounts.
Secure and traceable host O&M
Scenario description
Multi-factor authentication:
Uses strong, multi-factor authentication with technologies such as text message verification and dynamic tokens. This prevents identity theft and reuse.
Blocks illegal behavior:
Blocks dangerous commands in real time.
Interrupts risky sessions at any time.
Security event traceability:
Records detailed operation logs.
Provides full video playback of O&M sessions for traceability.
Applicable customers
Enterprise customers with requirements for O&M security and auditing.
Solution architecture
Deployment architecture

Based on the best practices for a multi-account architecture, the architecture is as follows:
Deploy Bastionhost in the shared service account or O&M management account. Place it in the virtual private cloud (VPC) of the inline O&M partition. Deploy business VPCs in business accounts. For more information about account structure planning, see enterprise multi-account unified architecture. For more information about cloud network partitions, see Cloud network partitions.
Use Cloud Enterprise Network (CEN) to grant cross-account authorization and connect the VPC where Bastionhost is located with the managed business VPCs.
Users can log on to Bastionhost using its public or private endpoint. If a user's network is not connected to the private network on the cloud, you can connect to the cloud's private network through a VPN Gateway. Then, you can use the Bastionhost private endpoint to log on for better security.
Bastionhost configuration flow

Note: The O&M engineer must set the user password on the host. The username and password in the Bastionhost user authorization must be the same.
Product billing and terms
Product billing
Product name |
Description |
Billing |
Bastionhost |
Bastionhost is a control platform provided by Alibaba Cloud for core system O&M and security auditing. It centrally manages asset permissions, controls all operations, and provides real-time playback of O&M scenarios. It ensures that identities are verifiable, permissions are controllable, and operations are auditable for cloud O&M. It solves problems such as difficulty in managing numerous assets, unclear O&M responsibilities and permissions, and difficulty in tracing O&M incidents. It helps enterprises meet classified protection compliance requirements. |
Paid. For more information, see Product Billing. |
Resource Access Management (RAM) |
Resource Access Management (RAM) is a service provided by Alibaba Cloud to manage user identities and resource access permissions. |
Free. |
Elastic Compute Service (ECS) |
Elastic Compute Service (ECS) is a simple and efficient computing service with elastic scaling capabilities. It helps you build more stable and secure applications, improve O&M efficiency, and reduce IT costs. This lets you focus on core business innovation. |
Paid. For more information, see Product Billing. |
Terms
Name |
Description |
Shared service account |
Enterprise shared services are deployed in this account, such as network deployments. The costs for this account should be borne by a unified team, such as the infrastructure team. |
Security
Stability and reliability
Bastionhost uses a cloud-native architecture. This stable architecture prevents O&M service interruptions caused by a single point of failure. The underlying Alibaba Cloud services are highly stable and mature, which enhances the security of system resources. A cloud-native Bastionhost is more stable, flexible, and secure. For more information, see Benefits.
O&M security
The Bastionhost Basic Edition provides basic O&M audit capabilities. These include two-factor authentication, O&M authorization, high-risk command blocking, and O&M auditing. It meets the basic O&M security and classified protection compliance requirements for small and medium-sized enterprises. The High-availability Edition is suitable for enterprises with high security requirements for O&M or large-scale operations. Examples include government, finance, gaming, online education, and technology development. In addition to the basic O&M security capabilities of the Basic Edition, the High-availability Edition meets higher business O&M security needs. For more information, see Features.
You can enable two-factor authentication for Bastionhost to improve security. For more information, see Enable two-factor authentication.
Cloud resource authorization
Before you use Bastionhost for the first time, you must grant it permission to access your cloud resources. Bastionhost needs to access resources of Alibaba Cloud services such as ECS and VPC. For more information, see Authorize Bastionhost to access cloud resources.
Operation audit and RAM integration
Bastionhost is integrated with Simple Log Service, ActionTrail, and RAM. This facilitates compliance auditing, security analytics, and access control. For more information, see Supported Alibaba Cloud services.
Notes
Bastionhost editions
Bastionhost is available in Basic and High-availability editions. You can select an edition based on your needs. For more information, see Features.
Terms of service
Before you use Bastionhost, you must read the corresponding terms of service. For more information, see Bastionhost Terms of Service.
Procedure
Preparations
The deployment is based on the recommended account structure for the landing zone. The following deployments have been completed:
Account type |
Deployment content |
Shared service account/O&M account |
|
Business account |
|
Implementation time
After you complete the preparations, the implementation of this solution takes about 30 minutes.
Steps
Enable Bastionhost
Log on to the shared service account. In the Bastionhost console, view the purchased Bastionhost instance and click Enable. Select a network and a security group, confirm your selection, and wait for the initialization to complete.
Import hosts
Click the Manage button for the Bastionhost instance to go to the management page. On the Assets -> Hosts page, you can import existing ECS instances from the current account. Because you cannot load cloud hosts from other accounts in the Bastionhost console, select Import Hosts from Other Sources.
Note: The network of the source host must be connected to the VPC where Bastionhost is located. For more information about how to establish the network connection, see Cloud Enterprise Network.
Create Bastionhost users
An administrator must create an account (a new user) in Bastionhost for an O&M engineer. The engineer can then use that account to log on to Bastionhost. On the Bastionhost instance management page, choose the Users menu to create a Bastionhost User. Bastionhost supports importing Alibaba Cloud RAM users, creating local Bastionhost users, and importing AD or LDAP users. For more information, see Create a user.
Create host accounts
Bastionhost needs to use a corresponding account to log on to the target host for O&M. This section describes how to add an existing host account on the Bastionhost page.
Note: The corresponding account must be created on the target host beforehand.
Add an account using a username and password.
Add an account using a private key.
For more configurations, see Create a host account.
Grant host permissions to users
Granting host permissions associates Bastionhost users with host assets. This feature lets you control which users can access which hosts. After the authorization is complete, you have specified which accounts on which hosts a user can access. The procedure is as follows:
On the user details page, click Grant Host.
On the Granted Hosts page, click Grant Host. Select the hosts for which to grant permissions and click OK.
In the list of granted hosts, click Grant Account.
Select the host accounts for which to grant permissions.
For more configuration details, see Grant host permissions to a user.
Perform O&M on hosts
Log on to a host through Bastionhost to perform O&M operations. The procedure is as follows:
Run the command
ssh xxxx.bastionhost.aliyuncs.com -p60022 -l yourUserNameto log on to Bastionhost. You can find the logon address on the Bastionhost instance page.After you log on, select the target host and user.
After you successfully log on to the target host, you can perform O&M operations.
For more information about O&M, see O&M user guide.
More features
For information about Bastionhost control policy management, see Control policies.
For information about Bastionhost approval management, see Approval commands.
For information about Bastionhost audit management, see Auditing.
Troubleshooting
Bastionhost issues
For more information about common Bastionhost issues, see Pre-sales FAQ and FAQ about features.