In a resource directory, a member (resource owner) can share the vSwitches in a virtual private cloud (VPC) with another member (principal).
Limits
Before you begin, review the limits on shared VPCs. For more information, see Limits on use.
Step 1: Use a resource directory to manage multiple accounts
Alibaba Cloud Resource Directory lets you centrally manage enterprise accounts by creating or inviting members. Use the management account of your resource directory to complete the following steps. For more information, see Resource management best practices.
-
Enable a resource directory.
For more information, see Enable a resource directory.
-
Use the management account of the resource directory to create folders based on the organizational structure of your enterprise.
For more information, see Create a folder.
-
Use the management account of the resource directory to create members in the resource directory or invite accounts to join the resource directory as members.
For more information, see Create a member or Invite an account to a resource directory.
Step 2: Enable resource sharing
-
Log on to the Resource Management console with the management account of your resource directory.
-
In the left-side navigation pane, choose Resource Sharing > Settings.
-
Click Enable.
-
In the Service-linked Role for Resource Sharing dialog box, click OK.
The system creates the Service-linked role for Resource Sharing (AliyunServiceRoleForResourceSharing) to obtain the resource directory organizational structure.
Step 3: Create a resource share as the resource owner
Create a resource share in the Resource Management console, and then add the VPC resources and the target accounts to the resource share.
-
Create a resource share. Then, add the VPC resources that you want to share and the accounts you want to use to share the resources to the resource share.
-
Log on to the Resource Management console.
-
In the navigation pane on the left, choose .
-
In the top navigation bar, select the region where the VPC resources that you want to share are deployed.
-
Click Create Resource Share.
-
On the Configure Basic Information and Add Resources page, enter a name for the resource share (for example,
Finance_VPC), add the resources to share (for example, the vSwitchvsw-bp183p93qs667muql****), and then click Next. -
On the Add Permissions page, select permissions for principals on the shared resources (for example,
AliyunRSDefaultPermissionVSwitch), and then click Next. -
On the Add Principals page, add principals, and then click Next.
For more information about how to add principals, see Create a resource share.
-
On the Submit page, click OK.
-
-
View the details about the resource share.
-
In the resource share list, view the Resource Share ID/Name, Status, and Created At.
If the status of the resource share is Enabled, the resource share is successfully created.
-
Click the ID of the resource share to view its detailed information.
A status of Associated for the Shared Resources and Principals confirms successful association. On the details page, verify that the resource share status is Active and the principal scope is Allow sharing with any account. On the Resources tab, the vSwitch status is Associated. On the Principals tab, the target account status is also Associated, confirming that resource sharing is established.
-
-
(Optional) Modify the information of the resource share.
On the details page of the resource share, you can click Edit Resource Share to change its name, or add or remove shared resources and principals. For more information, see Modify a resource share.
Step 4: View and use the shared vSwitches as a principal
By default, after the resource owner shares a vSwitch, a principal can use it without confirmation. Principals can view shared vSwitches and create cloud resources in them, such as Elastic Compute Service (ECS) instances, Server Load Balancer (SLB) instances, and ApsaraDB RDS instances.
-
Log on to the console by using the principal's account (for example, member
177242285274**) and view the shared vSwitch (for example,vsw-bp183p93qs667muql**).NoteA principal can log on to the Resource Management or VPC console to view shared vSwitches. For more information about how to view shared vSwitches, see View shared vSwitches.
In the left-side navigation pane of the VPC console, you can view sharing records. A Shared tag below the vSwitch instance name indicates that it is shared.
NoteWhen a resource owner shares vSwitches, the VPC console generates records of shared VPCs, route tables, and vSwitches due to network requirements.
-
In the VPC console, change the name and description of the shared VPC, route table, and vSwitch.
NoteThe preceding information is exclusive to you and cannot be viewed or changed by the resource owner.
On the vSwitch details page, the principal can modify the Name and Description by clicking the Edit link for each field.
-
Create a cloud resource in the shared vSwitch.
-
On the vSwitch page, find the target shared vSwitch, hover over Add Cloud Service in the Actions column, and then select a cloud resource to create.
NoteYou can also create cloud resources in the consoles of the related Alibaba Cloud services. When you configure networks for the resources, select the shared vSwitch.
-
View the cloud resource that is created in the shared vSwitch.
The principal can view created resources in the VPC console or the respective cloud service consoles. For example, on the vSwitch details page in the VPC console, the Cloud Resource Management tab shows three ECS instances under Basic Cloud Resources and three elastic network interfaces under Network Cloud Resources.
-