Implement cloud host risk inspections using Cloud Config and Function Compute

更新时间:
复制 MD 格式

Companies often have compliance requirements for their IT assets. For example, they must promptly fix system vulnerabilities on Elastic Compute Service (ECS) instances to prevent security attacks. They also need to maintain consistent system and software configuration baselines, such as host kernel parameters, time zones, and software versions. This requires a method to continuously and promptly detect security, compliance, and configuration risks on hosts.

This document describes a solution for enterprise customers to implement automated risk inspections for cloud hosts. This solution enables continuous risk inspection and unified monitoring across a multi-account environment.

Solution advantages

Comprehensive inspection dimensions

This solution uses Cloud Config and Function Compute to inspect cloud host configurations, patch baselines, and host processes or software configurations. This provides comprehensive resource inspection capabilities.

Fully managed inspection platform

Compared to self-built inspection platforms, this solution uses Cloud Config and Function Compute for resource inspections. It relies on the stability of the cloud platform, which eliminates the need for O&M. This lets you benefit from higher system stability.

Extendable inspection rules

This solution uses the custom rule feature of Cloud Config. You can define your own resource inspection rules and flexibly extend them as needed.

Observable inspection results

This solution uses Grafana to create a unified observability dashboard for multi-account inspection results. It integrates results from multiple accounts into a single dashboard for unified observation and alert configuration.

Customer scenarios

Unified enterprise monitoring and O&M

Scenario description

Enterprises need to maintain a unified security and compliance baseline for host resource configurations, operating systems, and system and software settings. To ensure all host instances have a consistent configuration baseline, enterprises must continuously perform risk inspections on host resources and have unified visual monitoring.

Applicable customers

  • Enterprise customers who use a resource directory to manage multiple Alibaba Cloud accounts.

  • Enterprise customers who use multiple Alibaba Cloud accounts.

  • Enterprise customers with a central O&M team or security team.

  • Alibaba Cloud accounts with multiple ECS instances.

Solution architecture

This solution uses Cloud Config and Function Compute to inspect and monitor host risks in a multi-account environment. First, in the log archive account, you can use official and custom Cloud Config rules to perform risk inspections on hosts for all member accounts in the resource directory. The custom rules are implemented using custom Function Compute functions. These functions call Cloud Assistant or CloudOps Orchestration Service (OOS) patch baseline APIs to check the operating system and software configurations within ECS instances (Steps 1 and 2 in the figure). You can also send notifications about inspection results through EventBridge or deliver the results to Simple Log Service (SLS) for unified query and analysis (Step 3). Finally, in the operations account, you can ingest the inspection logs from SLS and use Grafana to build a unified observability dashboard (Step 4). This dashboard provides real-time monitoring and alerting for ECS host resource configurations, operating system patches, and host process or software configurations.

Product billing and terminology

Product billing

Product Name

Product Description

Product Billing

Cloud Config

CloudConfig is a configuration management and IT governance service on Alibaba Cloud. It consolidates your resources from various regions into a global resource list, which lets you easily search for global resources. The service also records the configuration change history of your cloud IT resources and lets you continuously collect all resource configurations and configuration history files in a specified bucket. In addition, Cloud Config continuously and automatically evaluates the compliance of your cloud resource configurations to help you achieve IT compliance governance on the cloud.

During the public preview of Cloud Config, all valid Alibaba Cloud accounts can use it for free. However, if your usage involves other services, see the billing details.

Function Compute

Function Compute is a fully managed, event-driven compute service. With Function Compute, you can write and upload code without having to purchase and manage infrastructure, such as servers. Function Compute prepares computing resources for you, runs tasks elastically and reliably, and provides features such as log query, performance monitoring, and alerting.

Charges apply. For more information, see Product Billing.

Simple Log Service

Simple Log Service (SLS) is a cloud-native observability and analysis platform that provides large-scale, low-cost, and real-time platform services for data such as Logs, Metrics, and Traces. SLS provides a one-stop solution for data collection, processing, query and analysis, visualization, alerting, consumption, and delivery to comprehensively improve your digital capabilities in scenarios such as R&D, O&M, operations, and security. In this solution, Cloud Config pushes non-compliant issues that are found during compliance scans to SLS as logs. This lets you further ingest and distribute these non-compliance results.

Paid. For more information, see Product Billing.

CloudOps Orchestration Service (OOS)

CloudOps Orchestration Service (OOS) is a cloud-based automated O&M service from Alibaba Cloud that automatically manages and executes tasks.

Free. For more information, see Pricing.

Managed Service for Grafana

Managed Service for Grafana helps you efficiently analyze and view metrics, logs, and traces without having to manage complex tasks, such as server configuration or software updates. This service effectively reduces O&M complexity and workload and leverages the powerful cloud-native capabilities of Alibaba Cloud to improve the security and availability of Grafana.

This is a paid service. For more information, see Product Billing.

Elastic Compute Service (ECS)

Elastic Compute Service (ECS) is a simple, efficient, and elastically scalable computing service. It helps you build more stable and secure applications, improve O&M efficiency, reduce IT costs, and focus on your core business innovation.

Charged. For more information, see Product Billing.

Glossary

Name

Description

Management account

When an enterprise has multiple Alibaba Cloud accounts, this refers to the administrator account that has permissions to manage resources in other accounts. It is used for multi-account management, unified configuration of identity and permissions, unified viewing of bills for each cloud account, and unified configuration and deployment of audit rules to member accounts.

Log archive account

Aggregates logs from all member accounts for unified collection and management.

Operations account

Deploys O&M-related tools, such as a unified monitoring platform, CMP, or CMDB.

Cloud Config rule

A rule is a function used to determine whether a resource configuration is compliant. Cloud Config uses functions in Function Compute to host the rule code. After a rule is bound to a resource type, it is automatically triggered to evaluate compliance whenever a resource of that type undergoes a configuration change. You can also set rules to trigger periodically, and Cloud Config will regularly check the compliance of all your resources.

Cloud Config account group

An account group is a collection of members. In a resource directory, a management account can select all or some members to form a management unit for centralized compliance management. This management unit is the account group. From a resource perspective, an account group is a resource pool formed by aggregating resources from multiple members.

The management account can view the resource list, resource details, resource configuration timeline, resource compliance timeline, and associated resources for all members in the account group. It can also create rules and compliance packages within the account group. These rules and compliance packages will apply to the resources of all members in the account group for continuous compliance assessment.

Security

Cloud Config service-linked role

A service-linked role for Cloud Config is a RAM role that provides Cloud Config with the required permissions to access other Alibaba Cloud services. For more information, see Service-linked role for Cloud Config.

Simple Log Service security

Alibaba Cloud Simple Log Service (SLS) has robust security and protection capabilities. It supports features such as server-side encryption, fine-grained access control, and detailed service logs. It also provides a log auditing function that enables real-time, automated, and centralized collection and auditing of cloud product logs across multiple accounts. SLS provides you with rich data insight capabilities while meeting your enterprise's data security and compliance requirements.

Create and authorize a RAM user

In practical application scenarios, an Alibaba Cloud account may need to delegate the operation and maintenance (O&M) of Simple Log Service to a Resource Access Management (RAM) user. Alternatively, a RAM user may need to access Simple Log Service resources. In these cases, the Alibaba Cloud account must grant the RAM user permissions to access or manage Simple Log Service. To ensure data security, we recommend that you follow the principle of least privilege (PoLP) when you grant permissions to a RAM user. For more information about RAM users, see Getting Started.

Function Compute security

Alibaba Cloud Function Compute is an event-driven, fully managed compute service. Function Compute lets you focus on writing and uploading code without the need to manage infrastructure resources such as servers. Function Compute prepares compute resources for you, runs your code in an elastic and reliable manner, and provides features such as log queries, performance monitoring, and alerting. On the data plane, Function Compute uses TLS 1.2 or later to encrypt the transmission of invocation requests and responses. For internal communication, Function Compute uses proprietary protocols to prevent information leakage and tampering. On the control plane, you can use Alibaba Cloud Resource Access Management (RAM) for access control. For more information about the security of Function Compute, see Security Compliance.

Notes

Limits on Cloud Config account groups

The management account or a delegated administrator account in a resource directory can create account groups in the Cloud Config console to centrally manage resources, compliance packages, and rules for multiple members. Cloud Config supports two types of account groups:

Name

Description

Global account group

The members of a global account group are automatically synchronized with the resource directory. When the management account or delegated administrator account selects the global account group, the group automatically detects new members in the resource directory and adds them. This ensures that the scope of compliance management always remains consistent with the resource directory.

Custom account group

When creating a custom account group, the management account or delegated administrator account actively selects all or some members from the resource directory. When new members are added to the resource directory, the custom account group is not automatically synchronized. The management account or delegated administrator account must manually add the new members to the custom account group.

Note that you can only create one global account group. If you do not select the global account group option, Cloud Config defaults to a custom account group, even if you select all members of the resource directory when you create the account group.

Limits on Function Compute

Function Compute is subject to limits on the use of resources, such as service resources, function runtime resources, triggers, layers, regions, image size, and the number of GPU cards. For more information, see Limits.

Differences between Cloud Assistant and local command execution

There are differences between running commands with Cloud Assistant and running them locally on an ECS instance in terms of supported features, environment variables, and command execution results. Different operating systems have different variations and solutions. Before you use Cloud Assistant, read and confirm the details:

Limits on OOS patch baselines

The OOS Patch Management service provides a predefined default patch baseline for each operating system. You can set a custom patch baseline as the default for an operating system to apply custom patch scanning and installation rules. The following limits apply when you use patch baselines:

  • For a single operating system, there can be only one default patch baseline.

  • Patch scanning and installation are performed strictly according to the rules defined in the default patch baseline. You cannot specify other non-default patch baselines.

Procedure

Preparations

  • Ensure that you have enabled the resource directory in your management account. For more information, see Enable a resource directory.

  • Ensure that you have enabled the Function Compute service in the log archive account. For more information, see Quickly create a function.

Implementation time

After the preparations are complete, the estimated implementation time for this solution is 60 minutes.

Procedure

Create a delegated administrator

Using a delegated administrator account lets you separate organization management tasks from business management tasks. The management account performs organization management tasks for the resource directory, while the delegated administrator account performs management tasks for Cloud Config. This aligns with security best practices. You can set the log archive account of the resource directory as the delegated administrator account for Cloud Config. This account then acts as the administrator for Cloud Config and creates rules to perform risk inspections on member accounts.

  1. Log on to the Resource Management console using your management account.

  2. In the navigation pane on the left, choose Resource Directory > Trusted Services.

  3. On the Trusted Services page, find the CloudConfig service and click Manage in the Actions column.

  4. In the Delegated Administrator Account section, click Add.

  5. In the Add Delegated Administrator Account panel, select the member account (the log archive account).

  6. Click OK. After the account is added, you can use this delegated administrator account to access the corresponding trusted service and perform management operations within the scope of the resource directory.

Create a Cloud Config account group

  1. Log on to the log archive account and go to the Cloud Config console. In the navigation pane on the left, choose Account Group.

  2. On the Account Group page, click Create Account Group.

  3. On the Create Account Group page, set the account group name and description, and then select the account group type. Note that you can only create one global account group. If different business accounts require different compliance rules, you can create multiple account groups based on resource directory folders or by manually selecting member accounts. This allows for more fine-grained compliance management.

  4. Click Submit. In the account group list, if the status of the target account group is Created, the account group was created successfully. You can also view the name, description, number of members, type, and creation time of the target account group.

Inspect host resource configurations

You can use the compliance package templates in Cloud Config to quickly create compliance rules for ECS instances within an account group. This lets you continuously check the compliance of resource configurations for ECS instances, such as whether deletion protection is enabled for an ECS instance or a subscription ECS instance is about to expire.

Configure a compliance package
  1. Log on to the log archive account and go to the Cloud Config console.

  2. At the top of the navigation pane on the left, select the target account group.

  3. In the navigation pane on the left, choose Compliance Audit > Compliance Packages.

  4. On the Compliance Packages page, select Best Practices for ECS Compliance Management.

  5. Set the basic properties of the compliance package and select its effective scope, such as a specific region or resource group tag.

  6. Select the audit rules to apply.

  7. Set rule parameters, such as expiration checks or open ports. Then, click OK to create the compliance package.

View non-compliant resources
  1. Log on to the log archive account and go to the Cloud Config console. In the navigation pane on the left, choose Compliance Audit > Compliance Packages.

  2. On the Compliance Packages page, you can view the enabled compliance packages and the number of non-compliant resources for each package.

  3. Click the ID of the target compliance package or click Details in the Actions column.

  4. On the Rule Evaluation Results tab, you can view the number of non-compliant resources for each rule.

Inspect the host data plane

In addition to meeting compliance requirements for ECS host resource configurations, enterprises often have compliance requirements for the host data plane. For example, system vulnerabilities on ECS host instances must be fixed promptly to prevent security attacks, and a consistent system and software configuration baseline must be maintained for items such as host kernel parameters, time zones, and software versions.

You can use Function Compute and custom rules in Cloud Config to continuously inspect the data plane of your ECS host instances for compliance. For example, you can check if an ECS instance is missing necessary operating system patches or if the host's time zone is correct. This solution provides two methods for custom rule inspection:

  1. Host process and software configuration inspection: Use Cloud Assistant to run custom command scripts on target ECS instances to inspect system and software configurations, such as kernel parameters, time zones, and software versions.

  2. Operating system patch baseline inspection: Use OOS Patch Manager to scan the operating systems of ECS instances based on patch baselines to promptly discover missing patches.

First, you must create the required roles. The role assumption chain is shown in the figure below. You must create a service role in the log archive account that specifies Function Compute as the trusted entity. Function Compute assumes this service role to run your custom inspection logic. Your custom inspection logic then uses chained role assumption to assume roles in other member accounts to perform cross-account inspection operations.

Create a service role for Function Compute

First, create a service role in the log archive account and set Function Compute as the trusted entity. Function Compute will assume this service role to run your custom inspection logic.

  1. Log on to the log archive account and go to the RAM console. In the navigation pane on the left, choose Identities > Roles.

  2. On the Roles page, click Create Role.

  3. On the Create Role page, select Alibaba Cloud Service as the trusted entity type, and then click Next.

  4. Set the Role Type to Normal Service Role. Enter a role name, such as AliyunCustomConfigRuleRole. Select Function Compute as the trusted service, and then click OK.

Next, grant permissions to this role.

  1. Log on to the log archive account and go to the RAM console. In the navigation pane on the left, choose Permissions > Policies.

  2. On the Policies page, click Create Policy.

  3. In the Script editor, replace the existing script with the following content. This policy must grant at least the config:PutEvaluations and sts:AssumeRole permissions. Your custom Function Compute inspection logic uses chained role assumption to assume roles in other member accounts and perform cross-account inspection operations. The inspection results must be explicitly reported to Cloud Config using its API.

    {
        "Version": "1",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": "config:PutEvaluations",
                "Resource": "*"
            },
            {
                "Effect": "Allow",
                "Action": "sts:AssumeRole",
                "Resource": "*"
            }
        ]
    }
  4. Click Continue to edit basic information. Enter a name for the custom permission policy, such as AliyunCustomConfigRuleRolePolicy. Click OK to create the policy.

  5. After the policy is created, go to the Roles page and find the AliyunCustomConfigRuleRole role. Click the Add Permissions button.

  6. In the Custom Policy section, select the AliyunCustomConfigRuleRolePolicy policy that you created.

  7. Click OK to complete the process.

Create inspection roles in batches

You can use a Resource Orchestration Service (ROS) template to create a stack group that batch-creates RAM roles for the member accounts in your resource directory. You can also enable automatic deployment for the stack group. When this feature is enabled, stacks are automatically deployed when member accounts in the target folder change. This simplifies the management of stacks across member accounts. You can also change the automatic deployment settings as needed.

Create a delegated administrator for ROS

Next, set the shared service account or operations account of the resource directory as the delegated administrator account. This account then acts as the ROS administrator to deploy stacks for member accounts.

  1. Log on to the Resource Management console using your management account.

  2. In the navigation pane on the left, choose Resource Directory > Trusted Services.

  3. On the Trusted Services page, find Resource Orchestration Service (ROS) and click Manage in the Actions column.

  4. In the Delegated Administrator Account section, click Add.

  5. In the Add Delegated Administrator Account panel, select the member account (the shared service account).

  6. Click OK. After the account is added, use this delegated administrator account to access the multi-account management module of the trusted service and perform management operations within the resource directory.

Enable trusted access for ROS

If you have enabled a resource directory, you must enable trusted access before you can use the management account or a delegated administrator account to create a stack group with service-managed permissions.

  1. Separately log on to the ROS console using the management account and the shared service account (delegated administrator).

  2. In the navigation pane on the left, click Stack Groups.

  3. On the Stack Groups page, click Enable Trusted Access in the upper-right corner.

Use a stack group to create inspection roles
  1. Log on to the shared service account and go to the ROS console.

  2. In the navigation pane on the left, click Stack Groups.

  3. From the Region drop-down list in the top menu bar, select the region where the stack group is located.

  4. On the Stack Groups page, click Create Stack Group.

  5. In the Select Template section, select Use Existing Template.

  6. Set Template Source to Enter Template and Template Content to ROS > YAML.

  7. This solution provides ROS templates for two scenarios: operating system patch baseline inspection and host process and software configuration inspection. Copy the content of the appropriate template into the text box, and then click Next.

    1. ROS template for host process and software configuration inspection

    2. ROS template for operating system patch baseline inspection

  8. Enter a Stack Group Name and Stack Group Description. On the Configure Template Parameters page, you can keep the default parameter values or modify them as required, and then click Next.

    Parameter Name

    Example Value

    Description

    RoleName

    EcsCommandInspectionRole

    The name of the new inspection role to be created.

    PolicyName

    EcsCommandInspectionRolePolicy

    The name of the new inspection policy to be created. This policy will be attached to the inspection role.

    Trusted account

    1002504xxxxxxx

    The ID of the account that the new inspection role will trust. The default is the current account. Here, you need to enter the ID of the log archive account.

    Roles that the trusted account can assume

    AliyunCustomConfigRuleRole

    The role in the trusted account that is allowed to assume the inspection role. Here, you need to enter the service role for Function Compute.

  9. On the Configure Stack Group page, select Service-managed permissions, and then click Next.

  10. On the Set Deployment Options page, set Deployment targets to the folder of the target accounts in the resource directory, and enable Automatic deployment.

  11. Set parameters such as Region, Resource Group, Tag, and Deployment Options as required. For more information, see Parameters. Then, click Next.

  12. On the Review page, verify that the stack group information is correct, and then click Create Stack Group.

  13. After the stack group is created, you can view the instance status on the Instances tab of the stack group details page. A status of Latest indicates that the roles have been successfully created in the business accounts.

Inspect host processes and software configurations

You can use Cloud Assistant to run custom command scripts on target ECS instances to check system and software configurations, such as kernel parameters, time zones, and software versions. This topic provides an example of how to check the time zone of an ECS instance.

Create a Function Compute function
  1. Log on to the log archive account, go to the Function Compute console, and in the navigation pane on the left, click Services & Functions.

  2. Click Create Service. You can group custom rules under the same service to simplify management. In the Create Service sidebar, click the Show Advanced Options button. For Service Role, select the service role that you created in the log archive account, AliyunCustomConfigRule. For Allow Function to Access Public Network, select Yes.

  3. After the service is created, go to the Services page and click the target service. On the Functions page, click Create Function. On the Create Function page, select Use Built-in Runtimes. Enter a name for the function that is related to the rule, such as ecs-timezone for checking the ECS host time zone. Because the sample code provided in this solution is written in NodeJS, select the NodeJS runtime environment. You can choose a different runtime environment as needed. Upload the sample code and then click Create.

Create an inspection rule
  1. Go to the Cloud Config console. At the top of the navigation pane on the left, select the target account group.

  2. In the navigation pane on the left, choose Compliance Audit > Rules. On the Rules page, click Create Rule.

  3. On the Create Rule page, for Creation Method, select Custom with Function Compute. Select the function service and function instance that you created.

  4. Click Next. On the Set Basic Properties page, enter a rule name and click Add Rule Parameter to configure the rule parameters. For example, to check the ECS host time zone, configure the rule parameters as follows. Then, configure the rule trigger. Make sure to select both Configuration Change and Periodic Execution.

    Parameter Name

    Example Value

    Description

    configFcExecutionRoleName

    EcsCommandInspectionRole

    Required. This parameter is passed to the Function Compute instance. Function Compute assumes this role to inspect resources in other member accounts. Enter the name of the inspection role created for the host process & software configuration scenario.

    timezone

    Asia/Shanghai (CST, +0800)

    Required. This parameter is passed to the Function Compute instance to verify if the time zone is correct.

    tagScopes

    [{"TagKey":"InspectionType","TagValue":"TimeZone"}]

    Optional. Filters inspection resources based on tags. Enter a valid JSON string. Resources that match any of the tag key-value pairs in the array will be inspected. Otherwise, they will be ignored. If this parameter is not configured, all resources will be inspected.

  5. Click Next. On the Set Scope page, set Resource Type to ECS Instance.

  6. Click Next. On the Set Remediation page, click Submit. The rule is created.

  7. Wait for the rule to scan the resources. You can also trigger a scan by clicking Re-evaluate on the rule details page. You can then view the non-compliant resources.

Inspect operating system patch baselines

You can use the Patch Management feature of OOS to scan the operating systems of ECS instances for patches against a patch baseline and quickly identify missing patches. The procedure for this inspection rule is almost identical to that of the preceding Host Process & Software Configuration Inspection, except for the Function Compute code and the rule's input parameters.

Create a Function Compute function
  1. Log on to the log archive account, go to the Function Compute console, and in the navigation pane on the left, choose Services & Functions.

  2. Click Create Service. If you have already created a service, you can skip this step. You can place other custom rules under the same service for easier management. In the Create Service sidebar, click the Show Advanced Options button. For Service Role, select the service role that you created in the log archive account, AliyunCustomConfigRule. For Allow Function to Access Public Network, select Yes.

  3. After the service is created, go to the Services page and click the target service. On the Functions page, click Create Function. On the Create Function page, select Use Built-in Runtimes. Name the function based on the rule. Because the sample code provided in this solution is written in NodeJS, select the NodeJS runtime. You can choose a different runtime environment as needed.

  4. Upload the sample code, and then click Advanced Configuration. Configure the execution timeout. Because patch baseline scanning can take a long time, set a longer execution timeout, such as 3600 seconds.

Create an inspection rule
  1. Go to the Cloud Config console. In the upper-left navigation pane, select the target account group.

  2. In the navigation pane on the left, choose Compliance Audit > Rules. On the Rules page, click Create Rule.

  3. On the Create Rule page, set Creation Method to Custom with Function Compute, and then select the function service and function instance that you created.

  4. Click Next. On the Set Basic Properties page, enter a rule name and click Add Rule Parameter. Configure the rule parameters as follows. Then, configure the rule trigger by selecting both Configuration Change and Periodic Execution.

    Parameter Name

    Example Value

    Description

    configFcExecutionRoleName

    EcsPatchBaselineInspectionRole

    Required. This parameter is passed to the Function Compute instance. Function Compute assumes this role to inspect resources in other member accounts. Enter the name of the inspection role created for the operating system patch baseline scenario.

    tagScopes

    [{"TagKey":"InspectionType","TagValue":"PatchBaseline"}]

    Optional. Filters inspection resources based on tags. Enter a valid JSON string. Resources that match any of the tag key-value pairs in the array will be inspected. Otherwise, they will be ignored. If this parameter is not configured, all resources will be inspected.

  5. Click Next. On the Set Scope page, set Resource Type to ECS Instance.

  6. Click Next. On the Set Remediation page, click Submit. The rule is created.

  7. Wait for the rule to scan the resources. You can also trigger a scan by clicking Re-evaluate on the rule details page. After the scan is complete, the non-compliant resources are displayed.

  8. On the rule details page, in the Evaluation Results list, click a resource ID to go to the Resource Details page. On the Resource Details page, select the rule from the Latest Audit Results list. Then, hover your mouse over More in the Compliance Result column to view the number of missing patches for the ECS instance.

Deliver Cloud Config logs

Configure log delivery
  1. Log on to the log archive account and go to the Cloud Config console.

  2. Switch to the corresponding account group.

  3. In the navigation pane on the left, click Delivery.

  4. On the Delivery page, click Create Delivery in the upper-left corner.

  5. On the New Delivery page, enter a Delivery Name, select Simple Log Service (SLS) as the Delivery Channel, and then configure the parameters for SLS. You can create a new project in the current management account or select an existing project that belongs to the management account or a member account. The specified project stores the resource data of the management account and its member accounts. For more information, see Product Link.

  6. Enable SLS log indexing for the destination Logstore. To facilitate the configuration of the observability dashboard later, enable statistics for all inspection-related fields.

Configure a Grafana observability dashboard (Optional)

Create a RAM user
  1. Log on to the log archive account and go to the RAM console. On the Policies page, create a permission policy named, for example, GrafanaEcsTimeZoneLogStoreAccess. This policy grants permissions to read the specified SLS Logstore. The policy content is as follows:

    {
      "Version": "1",
      "Statement": [
        {
          "Action": [
            "log:ListProject"
          ],
          "Resource": "acs:log:*:*:project/*",
          "Effect": "Allow"
        },
        {
          "Action": [
            "log:List*"
          ],
          "Resource": "acs:log:*:*:project/<your-project-name>/logstore/*",
          "Effect": "Allow"
        },
        {
          "Action": [
            "log:Get*",
            "log:List*"
          ],
          "Resource": [
            "acs:log:*:*:project/<your-project-name>/logstore/<your-logstore-name>"
          ],
          "Effect": "Allow"
        }
      ]
    }
  2. In the RAM console, create a RAM user that Grafana can use to read SLS logs.

  3. Record the AccessKey ID and AccessKey secret of the created RAM user.

  4. Attach the permission policy GrafanaEcsTimeZoneLogStoreAccess to the RAM user.

Add a data source

Add a Simple Log Service (SLS) data source and enter the AccessKey ID and AccessKey secret of the log archive account that you use to access logs delivered by Cloud Config. For more information, see the official documentation.

Troubleshooting

Why can't I use the service-managed permission model in ROS?

  • If you use a member account from a resource directory to perform management tasks in ROS, you must set the member account as a delegated administrator account. This allows the account to act as an ROS administrator and deploy stacks to other member accounts. For more information about ROS delegated administrators, see Set a Delegated Administrator Account.

  • When you use the management account or a delegated administrator account of a resource directory to create a service-managed stack group, you must enable trusted access to grant the required service-managed permissions to the account. For more information about trusted access, see Enable trusted access.

Why doesn't my custom Cloud Config rule push resource information to Function Compute?

When you create a custom Cloud Config rule, you must select the Configuration Change trigger. This causes the Cloud Config rule to push the corresponding resource information when it invokes Function Compute. Otherwise, the rule will only trigger a resource-agnostic push at the account level.