Functions and features

Updated at:

Resource Management helps you organize and govern cloud resources through tags, resource groups, resource directories, and resource sharing.

Tag

Category

Feature

Description

References

Tag management

Create a predefined tag

A predefined tag is created during tag planning and applies to resources across all regions.

Create a predefined tag

Delete a predefined tag

Deleting a predefined tag removes only the predefined tag. Custom tags on resources are not affected.

Delete a predefined tag

Add a custom tag

Add custom tags to resources for categorization and centralized management.

Add a custom tag

Remove and delete a custom tag

After you remove a custom tag from a resource, the system automatically deletes the tag within 24 hours if it is not added to other resources.

Remove or delete a custom tag

Export resources to which a tag is added

You can export resources to which a custom tag, predefined tag, or system tag is added.

Add a predefined tag to a resource

After a predefined tag is created, you can add the tag to resources.

Add a predefined tag

Remove a predefined tag

After you remove a predefined tag from resources, the system retains the tag if it is not added to other resources.

Remove a predefined tag

View and search for tags

You can view and search for custom tags, predefined tags, and system tags.

ListTagResources

Enable or disable createdby tags

When enabled, the system auto-tags newly created resources with createdby tags. Existing resources are not affected. Disabling stops new tagging but retains existing createdby tags.

Enable or disable createdby tags

View and search for resources to which a tag is added

You can view and search for resources to which a custom tag, predefined tag, or system tag is added.

Use the Associated Resource Tagging feature

You can enable or disable the Associated Resource Tagging feature or configure, view, or modify an associated resource tagging rule.

Use the Associated Resource Tagging feature

Tag policy management

Create a tag policy

Create a tag policy to standardize resource tags. Configure policy details from built-in scenarios or in JSON format.

Create a tag policy

Delete a tag policy

Delete a tag policy that is no longer needed. Deleted tag policies cannot be recovered.

Delete a tag policy

Attach a tag policy

You can attach a tag policy to the current account or an object of a resource directory.

Attach a tag policy

Detach a tag policy

You can detach a tag policy from the current account or an object of a resource directory.

Detach a tag policy

Modify a tag policy

Modify the name, description, or details of a tag policy. Changes take effect immediately for all attached objects.

Modify a tag policy

View tag policies

You can view the tag policies within the current account or your resource directory.

View the details of a tag policy

Enable or disable the Tag Policy feature

Tag Policy supports single-account and resource directory modes. Choose a mode based on your scenario and account type. Disabling Tag Policy automatically detaches all attached policies.

View and download non-compliance detection results

The system automatically checks tag compliance after a tag policy is attached. Generate, view, and download reports for non-compliant resources.

View and download non-compliance detection results

View an effective tag policy

View the effective tag policy for the current account or resource directory, derived from tag policy inheritance.

View an effective tag policy

Resource Group

Category

Feature

Description

References

Resource group management

Create a resource group

Create resource groups with an Alibaba Cloud account or authorized RAM identity to manage resources by department or project.

Create a resource group

Modify the basic information of a resource group

You can change the name of a resource group.

Change the name of a resource group

Delete a resource group

A resource group must be empty before deletion. Transfer or release its resources first. The system verifies the group is empty over three days, during which the group stays in the Deleting state. The default resource group cannot be deleted.

Delete a resource group

View and search for a resource group

You can view the basic information about a resource group, including the ID, name, identifier, and tags of the resource group.

View the basic information about a resource group

Resource management in a resource group

Transfer resources between resource groups

You can transfer resources across resource groups to adjust the resource groups to which the resources belong.

Transfer resources across resource groups

View and search for resources in a group

Query accessible resources in a resource group by using one or more filter fields.

Search for resources in a resource group

Export resources in a resource group

Export all resources in a resource group as a CSV file for local viewing.

Export resources in a resource group

Use the Transfer Associated Resources feature

You can enable or disable the Transfer Associated Resources feature and view or modify transfer rules.

Use the Transfer Associated Resources feature

Resource Center

Resource Center provides a global view of resources across accounts, services, and regions. Query resources in the console or by calling API operations. From the console, navigate to related service consoles for further operations.

Category

Feature

Description

References

Service management

Activate or deactivate Resource Center

Resource Center is free. After activation, the service is available immediately. Deactivating it disables resource visibility.

View the status of Resource Center

You can view the status of Resource Center.

GetResourceCenterServiceStatus

Resource search within the current account

Search for resources within the current account

View and search for all resources in your account across services and regions.

Search for resources within the current account

Query the number of resources within the current account

Query the number of accessible resources in the current account. Only resource types supported by Resource Center are included.

GetResourceCounts

View the details of a resource

You can view the basic information, configuration change history, and operation records of resources within your Alibaba Cloud account.

View the details of a resource

Search for resources based on specific conditions

Filter resources by type, region, tag, or other conditions. Search for a specific resource by ID, name, or IP address.

Search for resources based on specific conditions

View tag keys

You can view the tag keys of resources within the current account.

ListTagKeys

View tag values

You can view the tag values of resources within the current account.

ListTagValues

View the resource types supported by Resource Center

You can view the resource types supported by Resource Center.

Resource search across accounts

Enable or disable cross-account resource search

By default, Resource Center searches only the current account. If you have a resource directory, enable cross-account search with the management account or a delegated administrator account to view resources across members. Disabling this feature removes cross-account visibility.

View the status of the cross-account resource search feature

You can view the status of the cross-account resource search feature.

GetMultiAccountResourceCenterServiceStatus

Search for resources across accounts

View and search for resources across accounts, services, and regions. Use the management account to access all member resources in the resource directory.

Search for resources across accounts

View the details of a resource

View resource details across members in your resource directory, including IDs, names, types, regions, resource groups, tags, and configurations.

View the details of a resource

Search for resources based on specific conditions

Filter resources by type, region, tag, or other conditions. Search for a specific resource by ID, name, or IP address.

Search for resources based on specific conditions

Query the resource groups within the management account or a member of a resource directory

You can query the resource groups within the management account or a member of your resource directory.

ListMultiAccountResourceGroups

Query the tag keys of resources within the management account or a member of a resource directory

You can query the tag keys of resources within the management account or a member of your resource directory.

ListMultiAccountTagKeys

Query the tag values of resources within the management account or a member of a resource directory

You can query the tag values of resources within the management account or a member of your resource directory.

ListMultiAccountTagValues

Advanced search

Execute an SQL statement to query the resources within the current account

Execute SQL to query accessible resources in the current account. Only resource types supported by Resource Center are included.

ExecuteSQLQuery

Execute an SQL statement to query resources across accounts

Execute SQL to query resources across the management account or members of your resource directory. Only resource types supported by Resource Center are included.

ExecuteMultiAccountSQLQuery

Query all sample query templates

You can query all sample query templates.

ListExampleQueries

Query the information about a sample query template

You can query the information about a sample query template.

Modify a custom query template

You can modify a custom query template.

Manage query templates

Delete a custom query template

You can delete a custom query template.

Manage query templates

Query the information about a custom query template

View details of a custom query template, including ID, expression, name, description, creation time, and update time.

GetSavedQuery

Query all custom query templates

List all custom query templates in the current account with their IDs, expressions, names, descriptions, and timestamps.

ListSavedQueries

Resource delivery

Create a resource delivery task

You can create resource delivery tasks to deliver resource change events and scheduled resource snapshots to Object Storage Service (OSS) or Simple Log Service.

Modify a resource delivery task

You can modify the information about a resource delivery task.

Manage resource delivery tasks

Delete a resource delivery task

You can delete a resource delivery task.

Manage resource delivery tasks

View the information about a resource delivery task

You can view the basic information and configurations of a resource delivery task.

Manage resource delivery tasks

View all resource delivery tasks

You can view all resource delivery tasks.

Manage resource delivery tasks

Resource Directory

Category

Feature

Description

References

Resource directory management

Enable or disable a resource directory

You can enable or disable a resource directory.

Manage folders

You can create, modify, delete, and query folders in your resource directory.

Member management

Create a member

You can create a member in a resource directory.

Create a member

Invite an Alibaba Cloud account to join a resource directory

You can invite an Alibaba Cloud account to join your resource directory.

Invite an Alibaba Cloud account to join a resource directory

Delete a member

You can delete members of the resource account type from your resource directory.

Delete a member of the resource account type

Add a tag to a member

You can add tags to members in your resource directory.

Add a tag to a member

Enable or disable the root user of a member

You can enable the root user of a member of the resource account type or disable the root user of a member of the cloud account type.

View and search for members

You can view the information about a member and search for a member.

View the detailed information about a member

Policy management

Create an access control policy

You can create an access control policy.

Create a custom access control policy

Modify an access control policy

You can modify the document of an access control policy.

Modify a custom access control policy

View and search for an access control policy

View the basic information and configurations of an access control policy.

View custom access control policies

Delete an access control policy

You can delete an access control policy.

Delete a custom access control policy

Attach an access control policy and view the effective scope of an access control policy

Attach an access control policy to the Root folder, another folder, or a member. View the effective scope of the policy.

Attach a custom access control policy

Trusted service management

Add a delegated administrator account

You can specify a member in your resource directory as a delegated administrator account of a trusted service.

Manage a delegated administrator account

Remove a delegated administrator account

You can remove a delegated administrator account for a trusted service.

Manage a delegated administrator account

View delegated administrator accounts

You can view all delegated administrator accounts.

ListDelegatedAdministrators

Contact management

Add a contact

You can add a contact for a resource directory.

Manage contacts for a member

Modify a contact

You can modify the basic information and message preferences of a contact.

Manage contacts for a member

Delete a contact

You can delete a contact for a resource directory.

Manage contacts for a member

View and search for contacts

You can view all contacts for a resource directory and search for a contact.

Manage contacts for a member

Bind a contact

Bind a contact to a resource directory, a folder, or a member in the resource directory.

Manage contacts for a member

Resource Sharing

Category

Feature

Description

References

Resource share management

Manage a resource share

You can create, modify, query, and delete a resource share.

Manage a resource share

Enable resource sharing

When enabled, the management account or a member of your resource directory can share resources with all members, all members in a specific folder, or individual members in the resource directory.

Enable resource sharing

Add a resource or principal

You can add resources or principals to a resource share.

Modify a resource share

Remove a resource or principal

You can remove resources or principals from a resource share.

Modify a resource share

View resources or principals

You can view resources or principals added to a resource share.

Resource sharing invitation management

Accept a resource sharing invitation

A principal can accept a resource sharing invitation. Then, the principal can view and use the shared resources specified in the invitation.

Accept a resource sharing invitation

Reject a resource sharing invitation

A principal can reject a resource sharing invitation.

Reject a resource sharing invitation

View the information about resource shares

You can view the details of resource shares to which your account is added.

View the details of resource shares

Permission management

Add permissions to a resource share

You can add permissions to resource shares.

Permissions for resource sharing

Remove permissions from a resource share

You can remove permissions from resource shares.

Permissions for resource sharing

View the permissions added to a resource share

You can view the permissions that are added to a resource share.

Permissions for resource sharing

View the information about a permission

You can view the information about a permission related to a resource type that supports resource sharing.

Permissions for resource sharing