NAPal: Your cloud digital network engineer
NAPal (Network AI Pal) is a cloud-based intelligent network O&M service launched by Alibaba Cloud for enterprise customers. Positioned as your Cloud Digital Network Engineer, NAPal is equipped with network expert-level knowledge, supports scheduled triggering, and can autonomously respond online 24/7, helping enterprise customers move from "manual response" to "AI-driven intelligent O&M".
NAPal covers the full Alibaba Cloud network product line, including VPC, EIP, SLB (ALB/CLB/NLB), CEN, EC, NAT, VPN, GA, and PVL. Through a rich skill library of vertical-domain network expert experience and intelligent orchestration capabilities, it helps enterprise customers achieve cost reduction and efficiency improvement across the full network lifecycle scenarios such as cloud migration planning, resource management, configuration operations, traffic insights, diagnostic analysis, and alert response.
Try it now: Go to the console to use NAPal.
NAPal: So you can nap. —— Let AI safeguard your network so you can rest easy.
Core values
NAPal encapsulates vast Alibaba Cloud network operations data and expert experience into an interactive, intelligent service. It reduces the cost and complexity of network troubleshooting and shortens the Mean Time to Resolution (MTTR) for network failures.
Core values of NAPal:
Consolidated expert network knowledge: Integrates the extensive knowledge and best practices of network operations experts. This covers official documentation, SA solutions, best practices, and standard operating procedures (SOPs) for troubleshooting complex network scenarios to achieve rapid issue resolution.
Full network data foundation: For the first time, Alibaba Cloud makes network engineer-level network O&M data, probing data, and expert troubleshooting experience SOPs built into the NAPal Agent available to customers. It provides unified access to Alibaba Cloud's most comprehensive network data foundation, covering network configuration information, monitoring metrics, activity logs, link probing data, and more.
Full network O&M lifecycle coverage: From cloud migration planning, resource inventory, and configuration management to traffic insights, fault localization, and architecture inspection, it covers the complete network O&M workflow.
Inherited RAM permission management: Based on the RAM permission control policy of the Alibaba Cloud account, it accesses cloud services through the standard Alibaba Cloud OpenAPI MCP component.
Product architecture

Data foundation
NAPal aggregates six core data categories as its analytical foundation:
Data category | Description |
Network configuration information | Complete network configurations, including route tables, security groups, and VPC/vSwitch settings. |
Network monitoring metrics | Instance-level network monitoring metric data. |
Network log information | Layer 4 Flowlog activity logs and Layer 7 ALB/GA access logs. |
Link probing data | Data from Alibaba Cloud's proprietary probe clusters, covering intra-cloud traffic paths and global links for public network access. |
Network infrastructure data | Alibaba Cloud engineer-level infrastructure link diagnostics and operations data, made accessible by injecting expert knowledge into the AI model for interpretation. |
Network expert knowledge base | Covers network product Q&A, network solutions, and best practices for network architecture. |
Agent runtime layer
Powered by the Qwen model series, NAPal features a proprietary agent runtime foundation tailored for cloud network operations. Its core capabilities include multi-agent collaboration and orchestration, ReAct (Reasoning and Acting) thought-action loops, a sandboxed execution environment, long-term context management, expert knowledge bases and skill libraries, and a toolset of MCP and proprietary scripts.
User access layer
NAPal supports three access methods to meet different scenario requirements:
Access method | Description |
An embedded conversational interface in the Alibaba Cloud console that supports real-time Q&A and context-aware interactions. | |
Integrates with major IM platforms like DingTalk, Feishu, WeCom, and Webhook URLs, allowing you to receive analysis reports and alert notifications via bots. | |
Provides a standard A2A-based OpenAPI that allows you to integrate NAPal's capabilities into your own agents or O&M systems. |
Work mode layer
NAPal supports three work modes:
Work mode | Description |
Conversation-triggered | Use natural language in the console or an IM channel to invoke skills for queries, diagnostics, and analysis. |
Scheduled task | Automatically perform recurring tasks like inspections, resource inventories, and report generation at set intervals without manual intervention. |
Event-triggered response | Integrates with CloudMonitor alerts. Network-related alerts automatically trigger an agent to perform Root Cause Analysis (RCA) for unattended operations. |
Features
NAPal builds an intelligent network operations system with six core capabilities, divided into two main areas:
Area one: Effective network usage
From cloud adoption to resource inventory, NAPal helps you quickly get started with your cloud network.
AI product consultation
Solves the initial challenge of network design for cloud adoption. Based on Alibaba Cloud product documentation, best practices, and SA solutions, NAPal provides network product recommendations, architecture suggestions, and cost estimates to help you plan your cloud deployment quickly.
Typical scenarios:
Recommending network solutions for new services moving to the cloud
Consulting on cross-region and cross-availability zone network architecture design
Comparing network products and estimating costs
AI resource management
Manages and inventories your cloud network resources. It supports multi-dimensional resource search and visualization, identifies idle resources and suggests cleanup, monitors quota usage with alerts, and analyzes resource utilization for cost optimization.
Typical scenarios:
Automating network-wide resource inventory to identify underutilized and idle resources for cost reduction
Aggregating and visualizing cross-region resource distribution
Quota bottleneck alerts and increase recommendations
Area two: Network perception and protection
This area provides visibility into your network, helping you understand traffic and pinpoint issues.
AI traffic insight
Provides fine-grained traffic analysis based on Flowlog and Layer 7 access logs. Capabilities include traffic insight reports down to the vport level, anomalous traffic detection and source tracing, analysis of public network access by provider, identification of inter-cloud public traffic, and analysis of microburst traffic growth.
Typical scenarios:
Flowlog traffic insights for VPC, CEN Transit Router, NAT Gateway, VPN Gateway, ALB, and NLB
Public-facing exposure analysis and security auditing
Provider quality insights and link anomaly detection
Microburst traffic growth analysis, calculating growth volume and rate at the 5-tuple flow level to precisely pinpoint burst sources
Top IP analysis to distinguish between normal traffic and burst trends
AI diagnostic analysis
Pinpoints the blast radius of network-level issues and provides root cause analysis and remediation suggestions. Capabilities include instance diagnostics, path connectivity analysis, basic performance queries and analysis, and interpretation of monitoring metrics.
Typical scenarios:
VBR packet drop detection and RCA for rate-limiting packet loss
Diagnostics for abnormal optical signals on physical ports
End-to-end path connectivity analysis and fault localization
In a hybrid cloud scenario, input any two IP addresses (one from an on-premises IDC and one from a cloud ECS instance) to visualize the path and detect issues like congestion or packet loss
Task center
NAPal provides a Task Center that allows you to configure scheduled tasks and event-driven RCA tasks for autonomous network fault response, enabling unattended intelligent network operations:
Scheduled tasks
NAPal provides a template framework for scheduled inspection tasks. You can select product types, inspection skills, and resource scopes. Tasks are triggered on a schedule across all network instances in your account, covering resource inventory, quota management, health checks, stability analysis, network quality, and traffic insights. The service generates comprehensive inspection reports that can be pushed to IM channels.
Six inspection perspectives:
Inspection perspective | Description |
Resource inventory | Automatically inventories network resource usage, identifies idle resources, analyzes utilization, detects waste, and provides statistics on cross-region resource distribution. |
Quota management | Scans quota usage, identifies bottlenecks, provides recommendations and warnings for quota increases, and analyzes quota usage across multiple accounts. |
Health check | Scans instance health status, checks backend server health, verifies port connectivity, and pinpoints the root cause of health check failures. |
Stability analysis | Analyzes network high availability, identifies stability risks like single points of failure, insufficient redundancy, and disaster recovery gaps, and assesses multi-availability zone redundancy. |
Network quality root cause analysis | Combines instance-level link probing, provider quality probing, and cross-domain PingMesh to provide network quality root cause analysis. |
Traffic insight report | Generates traffic insight reports down to the vport level, and detects and traces anomalous traffic by using Flowlog and Layer 7 access logs. |
Event RCA tasks
Integrates with CloudMonitor alerts to automatically orchestrate skills like topology blast radius analysis, resource health diagnostics, and anomalous traffic localization to perform root cause analysis. It then generates an RCA report and sends it to an IM channel, enabling unattended response to network alerts.
Automatic analysis workflow:
Subscribe to alerts: Forward CloudMonitor alerts to NAPal.
NAPal responds automatically: NAPal matches the alert to a built-in handling SOP.
Analyze topology blast radius: Analyzes the network topology and dependent resources affected by the alert (for example, the EIP → NAT Gateway → SLB impact chain).
Diagnose related resource health: Performs health checks and stability assessments on affected resources.
Locate and analyze anomalous traffic: Pinpoints abnormal traffic patterns and attack behaviors based on Flowlog and Layer 7 logs.
Output RCA report: Generates an event RCA report and pushes it to an IM channel (DingTalk, Feishu, or WeCom).
Skill center
NAPal continuously releases expert skills for network operations that cover Alibaba Cloud's core network product lines. You can follow updates in the NAPal Skill Center to stay informed about its evolving capability matrix.
Access methods
Console chatbox
In the right sidebar of the Alibaba Cloud network console (for example, VPC console), click the
icon to enter the embedded conversational interface. You can instantly invoke NAPal through natural language, with support for instant Q&A, resource queries, troubleshooting, and more.
IM channel
NAPal integrates with major enterprise IM platforms, allowing you to use bots to interact with NAPal and receive inspection reports and alert RCA reports:
DingTalk: Pushes notifications via a DingTalk bot.
Feishu: Pushes notifications via a Feishu bot.
WeCom: Pushes notifications via a WeCom bot.
IM channels support managing information flows by Agent, allowing you to set up different push groups by team or business line. For details, see IM channels.
OpenAPI
Provides a standard OpenAPI protocol call interface, allowing customers to integrate NAPal capabilities into their own Agents, O&M platforms, or automation workflows.
To get raw data analysis results without AI interpretation, you can call the standard API directly.
To get intelligent analysis conclusions, call the agent to invoke AI capabilities, which generate insights based on the underlying data.
Use cases
Scenario 1: Daily conversational Q&A
Use natural language in the console or an IM channel to query resource information or get assistance with troubleshooting. Most queries are completed within minutes.
Examples:
"Show me how many ENIs are in VPC-123."
"What's the traffic trend for this EIP over the last hour?"
"Analyze why NAT Gateway nat-456 is dropping packets."
Scenario 2: Periodic intelligent inspections
Configure scheduled tasks to have an agent periodically inspect your entire network across six perspectives (Resource inventory, Quota management, Health check, Stability analysis, Network quality root cause analysis, and Traffic insight report). The agent generates a comprehensive inspection report and pushes it to your IM channel.
Examples:
Automatically run a full network resource inventory and health scan every Monday at 9:00 AM.
Identify underutilized and idle resources for cost reduction.
Proactively identify scaling needs to prevent alerts.
Periodically assess architectural health and stability to identify single points of failure and disaster recovery risks.
Scenario 3: Unattended event response
The NAPal agent integrates with CloudMonitor, allowing network-related alerts to automatically trigger root cause analysis. The analysis is fully automated, from alert to root cause. The analysis report can be sent back to CloudMonitor for delivery to your existing contact groups or pushed to specific groups via an IM bot.
Examples:
When shared bandwidth is saturated, automatically identify the IP address or 5-tuple causing the issue and provide a resolution plan.
After a physical port on a leased line fails, automatically analyze the blast radius and determine the root cause.
Identify the root cause of saturated NAT Gateway public bandwidth using top traffic sources
Billing
NAPal currently offers prepaid monthly subscriptions. The base subscription fee includes an AI Credit quota and a base number of concurrent sessions. You can add AI capacity packages to increase the AI Credit quota and the number of concurrent sessions.
Free AI Credit benefits
The free AI Credit benefits of NAPal, your cloud digital network engineer, follow a "stop-on-depletion" policy. After you use up all the quota in your benefit package or your benefit package expires, if you have not subscribed to the monthly commercial version of NAPal, the service is terminated by default to help you avoid unexpected charges.
Benefit type | Quota | Applicable to | Validity period |
New user trial benefit | 100 AI Credits | Alibaba Cloud account - first use of the NAPal service | Valid for 31 days from the first claim |
Monthly free quota | 25 AI Credits | Alibaba Cloud account - NAPal service activated | Automatically issued on the 1st of each month, valid within the current month, and not carried over to the next month. |
Monthly subscription
Includes a base AI Credit quota and 5 concurrent sessions, suitable for the daily operational needs of small to medium-sized environments.
AI capacity package (Add-on)
When the base subscription capacity is insufficient, you can purchase AI capacity packages to expand it. Each AI capacity package provides an additional 8 concurrent sessions and includes extra AI Credits.
Value of an AI capacity package:
More AI Credits to support more frequent analysis calls.
Allows more team members to work online simultaneously.
Enables more frequent scheduled tasks and denser inspection cycles.
Higher concurrent alert response capacity to support large-scale alert scenarios.
Billing details
Item | Includes | Fees | Validity period |
Monthly subscription package | 5,000 AI Credits, 5 concurrent sessions | CNY 8,000/month | Calendar month |
AI capacity package | Each add-on AI capacity package provides:
| CNY 10,000/month | Calendar month |
FAQ
What network products does NAPal support?
NAPal covers the full range of Alibaba Cloud network products, including VPC, EIP, the SLB product family (ALB/CLB/NLB), CEN, Express Connect, NAT Gateway, VPN Gateway, GA, and PVL.
How fast does NAPal respond?
Most query and analysis tasks can be completed at the minute level (average response time within about 3 minutes); second-level response is not guaranteed.
Integration with existing systems
NAPal provides a standard OpenAPI that can be integrated into your own agents or operations systems. It also integrates with major IM channels like DingTalk, Feishu, WeCom, and Webhooks, allowing you to receive analysis reports via bots.
Does NAPal support custom skills?
This feature is not yet supported. In the future, we plan to enable custom skills, allowing you to build on pre-set SOPs with your own operational logic to create a personalized network operations agent.
How are inspection reports delivered?
Inspection reports can be pushed to IM channels (DingTalk, Feishu, or WeCom). You can configure different push groups for different teams or business lines to manage information flow on a per-agent basis.
CloudMonitor integration for event RCA
The NAPal Agent is integrated with CloudMonitor. After you subscribe to network-related alerts and connect them to the NAPal Agent, CloudMonitor automatically pushes triggered alerts to NAPal. The agent then automatically performs blast radius analysis, health diagnostics, and root cause localization. The analysis report can be sent back to CloudMonitor for delivery to your existing contact groups.