This document answers frequently asked questions about Alibaba Cloud DevOps.
Application FAQs
General questions
DingTalk personal operations
Find registered Alibaba Cloud accounts
-
Go to the Alibaba Cloud login page and click Forgot Account Name.
-
Enter your phone number to receive a verification code and click Retrieve Now. Alternatively, you can recover your account by using other information, such as your ID card or domain name.
Install the DingTalk app
As an organization administrator or sub-administrator, open the DingTalk app, select Workbench at the bottom, click App Market in the upper right corner, enter Alibaba Cloud DevOps in the search bar, select the Alibaba Cloud DevOps application, and click Activate for Free.
Bind a personal account to an organization
You must bind your account to both a DingTalk organization and an Alibaba Cloud DevOps organization.
-
DingTalk organization: See How to install the DingTalk app on your phone in this topic.
-
Alibaba Cloud DevOps organization: See the answer to Why does a member's status show as inactive after I invite them? in the Organization operations section of this topic.
After the binding is successful, in DingTalk, go to Console, search for and open the Alibaba Cloud DevOps app to view your current binding status.
The page displays a list of currently bound Alibaba Cloud DevOps enterprises, with functions such as Synchronize Organization Structure and Send DingTalk Messages.
Accept an organization invitation
After you receive an invitation message in DingTalk or a shared invitation link, click the message or link to start the initial login setup and select Authorize and create a new account. Click Agree at the bottom to proceed to the next step.
Resolve the "account already joined" error
-
Symptom:
When you try to join or switch organizations, you receive a permission error: "Your DingTalk account has already joined the organization with another account [***]."
-
Resolution:
Within a single Alibaba Cloud DevOps organization, each DingTalk member can only be associated with one Alibaba Cloud account. If you have multiple Alibaba Cloud accounts bound to DingTalk, you must first decide which Alibaba Cloud account you want to use for your work in Alibaba Cloud DevOps, and then choose the appropriate option below.
-
If you want to use the Alibaba Cloud account that was previously bound to DingTalk, follow these steps:
Log out and then log back in to Alibaba Cloud DevOps using the "other account [*]" mentioned in the error message.
NoteIf the account name starts with
dingtalk_, it was registered via DingTalk QR code login, and you can log in by scanning the QR code with DingTalk. If it does not start withdingtalk_, it is likely an Alibaba Cloud account you registered yourself or a RAM account assigned to you by your organization. If you have forgotten the password for your Alibaba Cloud account, see What to do if you forget your username or login password. -
If you want to use your current login account to join the Alibaba Cloud DevOps organization, you must change the bound account. Depending on the prompt you receive, choose one of the following methods.
-
Prompt Type 1:
The page displays a message Unable to join this organization, indicating that your DingTalk account has already joined the organization with another account. You are given three options: log in with the original account mentioned in the prompt, Change the bound account, or Create a new organization.
If you see this prompt, you can choose one of the following:
Option 2: On the "Unable to join organization" page, click Change. After confirming the change, you can access the organization with your current login account.
ImportantPermissions, task assignments, and other data associated with the previous Alibaba Cloud account will not be transferred to the new account. Once you change the binding, the previous account (the "other account [*]" from the prompt) will be deactivated and can no longer access this organization.
Option 3: Create a new organization.
-
Prompt Type 2:
If the page displays a No permission message, this indicates that the DingTalk information bound to the current Alibaba Cloud DevOps account does not match the DingTalk information bound to the Alibaba Cloud account.
If you see this prompt, your Alibaba Cloud DevOps and Alibaba Cloud accounts have inconsistent bindings. To change the account, proceed as follows:
Log out, and then use the "other account [*]" from the prompt to access the personal settings > third-party binding page in Alibaba Cloud DevOps. Based on the number of records you see under "Alibaba Cloud DevOps has been bound to DingTalk", follow the corresponding steps:
-
If there is only one record under "Alibaba Cloud DevOps has been bound to DingTalk", follow these steps:
NotePermissions, task assignments, and other data associated with the previous Alibaba Cloud account will not be transferred to the new account. Once you change the binding, the previous account (the "other account [*]" from the prompt) will be deactivated and can no longer access this organization.
-
Click Unbind.
-
Log in to Alibaba Cloud DevOps with the account you want to use. You will now be able to access the Alibaba Cloud DevOps organization.
-
-
If you change the binding when multiple records are present, you will no longer be able to use a single account to access all the corresponding DingTalk-bound organizations.
ImportantPermissions, task assignments, and other data associated with the previous Alibaba Cloud account will not be transferred to the new account. Once you change the binding, the previous account (the "other account [*]" from the prompt) will be deactivated and can no longer access this organization.
-
Click Unbind.
-
You must bind a unique Alibaba Cloud account to each organization listed. As a result, each Alibaba Cloud account can only access its corresponding organization, whereas previously, a single account could access multiple organizations.
-
-
-
-
Unbind a personal account
An organization owner cannot unbind their personal account. To unbind, you must first transfer ownership of the organization. The transfer option is located in Organization Admin Backend > Basic Information.
-
Log in to Alibaba Cloud DevOps at https://devops.aliyun.com.
-
Click the profile picture in the upper-right corner and select Personal Settings.
-
In personal settings, unbind your account. If the DingTalk organization you belong to is bound to an Alibaba Cloud DevOps organization, unbinding will automatically remove you from that Alibaba Cloud DevOps organization. To rejoin the organization, bind your Alibaba Cloud DevOps account again.
View account information and change password
Open the Alibaba Cloud Account Center in a web browser on your computer. Your logged-in account is displayed in the top-right corner of the page. Click Change Password to change the password for the current account. The page also displays information such as Account ID, Registration Time, and Last Login Time, as well as the Login Method Management section.
DingTalk organization operations
Bind a DingTalk organization to Alibaba Cloud DevOps
Open the Alibaba Cloud DevOps platform, enter your organization's name and size, and click Create. Click your profile picture in the upper-right corner, select Organization Admin Backend, then navigate to Member Configuration > Third-party Platform Management.
On the Third-party Binding page, find the DingTalk item, and click the Bind button on the right.
Sync a DingTalk organization structure
As an organization administrator or sub-administrator, open DingTalk. Tap Console at the bottom, tap App Market in the upper-right corner, tap My in the lower-right corner, select Apps & Templates, find the Alibaba Cloud DevOps app, tap the options icon on the right, and then tap Settings.
Configure a DingTalk organization structure
Refer to the "How to sync the DingTalk organization structure to Alibaba Cloud DevOps" section in this topic to access the Settings options: Scope of Use and Belongs to Group.
Scope of Use: You can set the scope to all employees or specific employees. Configure this based on the departments and users in your organization that use Alibaba Cloud DevOps.
Invite members to Alibaba Cloud DevOps
Open the Alibaba Cloud DevOps platform and log in with an organization administrator account. Go to the Organization Admin Backend, select Member Configuration > Members, click the Add Member button on the right to invite members, and then click Send DingTalk Notification.
Handle inactive member status
Open the Alibaba Cloud DevOps platform and click Bind Personal DingTalk Account at the bottom of the page. The member must then scan the QR code with their DingTalk app to log in.
DingTalk notification triggers
-
You will not receive work notifications for your own actions.
-
Work notifications are sent only to task participants. If you are not a participant in a specific task, you will not receive notifications for that task, even if you are the project owner.
DingTalk notifications are sent for the following events:
-
Projex:
-
Basic events: Task creation, movement, and moving to the recycle bin.
-
Update events: Notifications for comments, status changes, content updates, assignee changes, due date changes, priority changes, and more.
-
Linked content events: Notifications related to linked content.
-
-
Codeup:
-
Third-party library import event notifications.
-
Merge request operation notifications.
-
Member permission change notifications.
-
Repository or group transfer or path change notifications.
-
Repository or group deletion event notifications.
-
Repository or group visibility adjustment notifications.
-
Alert notifications.
-
-
pipeline:
-
Manual approval notifications
-
Adding, removing, or modifying pipeline members
-
Run failure or cancellation
-
Pipeline deletion
-
Pipeline owner transfer
-
Check your DingTalk organization
To see which DingTalk organization your current login account is bound to, you can check during the login process. If you are already logged in to Alibaba Cloud, log out first.
-
For primary accounts
-
Log out of Alibaba Cloud, then click to log in and use the DingTalk QR code method to log in to Alibaba Cloud.
-
Scan the QR code with your mobile DingTalk app. The name of the DingTalk organization to which your account belongs will be displayed on the login page.
-
-
For RAM accounts
-
Log out of Alibaba Cloud, then click to log in and use the DingTalk QR code method to log in to Alibaba Cloud.
-
Scan the QR code with your mobile DingTalk app, and then tap Log In on your phone.
-
The name of the DingTalk organization to which your account belongs will be displayed on the browser page.
-
DingTalk binding errors
Alibaba Cloud account not bound to DingTalk
On the personal settings > third-party binding page, the Alibaba Cloud account not yet bound to DingTalk section shows a Go to Bind button. Below this, the Alibaba Cloud DevOps has been bound to DingTalk section displays information about the bound DingTalk organization and Alibaba Cloud DevOps organization.
Procedure
-
Click Go to Bind. When binding, select the DingTalk organization displayed under "Alibaba Cloud DevOps has been bound to DingTalk". If no organization information is displayed, choose the DingTalk organization corresponding to the Alibaba Cloud DevOps organization you want to join.
-
You will be redirected to different binding pages depending on your account type.
-
If you are using a primary account, you will see the following page. For binding instructions, see Steps to bind a primary account to a DingTalk account.
This page is the Alibaba Cloud Account Center > Basic Information > Third-party Account Binding page. It shows binding options for platforms like Taobao, 1688, DingTalk, Alipay, and Weibo. Click the Bind Now button for DingTalk to proceed.
-
If you are using a RAM account, you will see the following page. For binding instructions, see Steps to bind a RAM account to a DingTalk account.
This is the RAM User and DingTalk Binding page. Use the DingTalk App on your phone to scan the QR code on the page to complete the binding.
-
Alibaba Cloud account already bound to DingTalk
If your Alibaba Cloud account is already bound to DingTalk but the binding is inconsistent, there are two possible scenarios:
-
Possible cause 1: The two DingTalk accounts belong to different organizations.
A red prompt on the third-party binding page states: "Both Alibaba Cloud DevOps and Alibaba Cloud are bound to DingTalk accounts, but the two DingTalk accounts belong to different organizations." The Alibaba Cloud account has been bound to DingTalk section shows the currently bound DingTalk organization information, but it is not yet bound to an Alibaba Cloud DevOps organization, and provides a Go to Modify button.
-
Possible cause 2: The two DingTalk accounts are not the same.
We recommend modifying the binding on your Alibaba Cloud account to match the one used by Alibaba Cloud DevOps. Click Go to Modify to be redirected to the appropriate page based on your account type.
-
If you are using a primary account, click Unbind first, then re-bind. When re-binding, select the DingTalk organization shown under "Alibaba Cloud DevOps has been bound to DingTalk". For binding instructions, see Steps to bind a primary account to a DingTalk account.
-
If you are using a RAM account, click Unbind first, then re-bind. When re-binding, select the DingTalk organization shown under "Alibaba Cloud DevOps has been bound to DingTalk". For binding instructions, see Steps to bind a RAM account to a DingTalk account.
-
Impact of unbinding a DingTalk account
If your Alibaba Cloud account is bound to a DingTalk account that is also bound to an Alibaba Cloud DevOps organization, unbinding the account will deactivate your permissions and prevent you from accessing that Alibaba Cloud DevOps organization.
If you have already unbound your account, you can rejoin the Alibaba Cloud DevOps organization and restore your permissions by binding your DingTalk account again.
To check if unbinding will affect your use of Alibaba Cloud DevOps, follow these steps:
-
Check the binding information in third-party binding.
-
If the binding information only shows that the Alibaba Cloud account is bound to DingTalk, with a message like: "The DingTalk organization [DingTalk Organization DA] to which account [User A] belongs has been bound to the Alibaba Cloud DevOps organization [Alibaba Cloud DevOps Organization YA]", then unbinding the DingTalk account will affect your use of Alibaba Cloud DevOps. The impacts of unbinding are:
-
Your permissions for the Alibaba Cloud DevOps organization, [Alibaba Cloud DevOps Organization YA], will be deactivated for your current Alibaba Cloud account, and you will lose access.
-
If you are the organization owner of this Alibaba Cloud DevOps organization (indicated by the organization owner icon in the display), unbinding will leave the organization without an owner. If you must unbind, we recommend that you first transfer organization ownership (see how to transfer organization ownership) before proceeding.
In the binding information under Alibaba Cloud DevOps has been bound to DingTalk, if the organization owner icon is displayed next to the Bound Alibaba Cloud DevOps Organization name, it means the current account is the owner of that organization.
-
Accounts and plans
Register an account
Go to the Alibaba Cloud DevOps login page and click Register for free in the lower-right corner. If you have an Alibaba, Taobao, 1688, or DingTalk account, you can log in directly.
Reset a forgotten password
Go to the Alibaba Cloud DevOps login page, click Forgot Password in the lower-right corner, and follow the prompts to reset your password.
Retrieve a forgotten username
Go to the Alibaba Cloud DevOps login page, click Forgot Password, and then click Retrieve Login Name.
Complete real-name authentication
After registration, follow the prompts to click Real-name Authentication. There are currently three types of authentication. Choose one and submit the required information.
Modify personal information
Click personal settings to open a pop-up window where you can view your personal information.
You can change your avatar, modify your name, and bind an email address. After verification, the bound email will be used for notifications and for matching commit authors in Codeup.
This section shows your current organization name and your member name within that organization, which is your identifier across various product features. This name is maintained by the organization administrator. Please contact your administrator if you need to change it.
Manage your login account and password
Alibaba Cloud DevOps uses Alibaba Cloud accounts. To make changes, manage your account information on the official Alibaba Cloud website.
To manage your Alibaba Cloud account, go to the Alibaba Cloud website, click your profile picture in the upper-right corner, and select Account.
Manage invitation permissions to avoid exceeding member limits
You can control the Add Organization Member and Add External Organization Member permissions for a role in Organization Admin Backend > Permission Management > Organization Permissions.
-
If you revoke the Add Organization Member permission, members with this role can no longer add new organization members.
-
If you revoke the Add External Organization Member permission, members with this role can no longer add external members to the organization.
-
A role with the Add Organization Member permission also has the Add External Organization Member permission by default.
To fully control member invitations, revoke the Add Organization Member and Add External Organization Member permissions. You should also revoke the Modify Organization Member Role permission to prevent members from re-granting themselves invitation rights.
Handle exceeded member limits from external invitations
You have two options. Option 1: In Organization Admin Backend > Permission Management > Project Permissions, revoke the Add Project Member/Invite Project Member permission. However, this will also prevent the role from inviting internal organization members to projects.
Option 2: In Organization Admin Backend > Permission Management > Project Permissions, keep the Add Project Member/Invite Project Member permission, but in Organization Admin Backend > Permission Management > Organization Permissions, revoke the Add External Organization Member permission. This allows the role to invite only internal members to projects.
To fully control project member invitations, revoke the Add Project Member/Invite Project Member permission. You should also revoke the Modify Project Member Role permission to prevent members from re-granting themselves invitation rights.
Purchase and activate a plan
Alibaba Cloud DevOps offers a free version for you to try. If you exceed the free quota, you can choose to purchase the all-in-one DevOps plan or individual products. Go to the Alibaba Cloud DevOps activation page to get started.
Free plan limits
The free plan is available to organizations that meet the criteria for the Small and Micro Business Support Program. The limits are: up to 29 members for Projex, Docs, and Test Management; 3 concurrent pipeline tasks; up to 5,400 minutes of pipeline runtime per month; and an unlimited number of pipeline runs.
Paid plans and differences
Alibaba Cloud DevOps offers two billing models: a plan-based model and a pay-as-you-go model. You can choose the one that best suits your business needs.
The Enterprise Edition plan is priced at ¥818 per person per year. The Product + Service plan is available in three tiers: ¥38,800/year for 60 people (includes Customer Success Functionality Package, 60-person quota, 2 hours with a dedicated consultant), ¥68,800/year for 100 people (includes Business Consulting Package, 1 day with a dedicated consultant), and ¥188,000/year for 300 people (includes Advanced Business Consulting Package, 3 days of expert services). Each tier includes different user quotas, expert services, and levels of DingTalk group support.
Authentication, AD support, and registration
Alibaba Cloud DevOps uses the Alibaba Cloud account authentication system. It supports Active Directory authentication and can be integrated with Alibaba Cloud RAM accounts, eliminating the need for separate registration.
Accessing Alibaba Cloud DevOps through a proxy or firewall
If you can access major websites like Baidu, you can access Alibaba Cloud DevOps directly. However, Alibaba Cloud DevOps may need to communicate with your internal resources, such as code repositories and deployment machines. For this, Alibaba Cloud DevOps requires access to your resources. Secure solutions are available, and details can be discussed based on your specific scenario.
Integrate accounts
For integrating organization accounts with Alibaba Cloud DevOps, refer to Enterprise single sign-on (SSO). Alternatively, you can connect to LDAP. For details, see this document: Use AD/LDAP authentication to log in to third-party applications.
-
General integration guide for IDaaS: Use cases
-
For single sign-on (SSO) to Alibaba Cloud DevOps or Quick BI using an IDaaS account, we recommend using the user SSO template: Alibaba Cloud User SSO
-
Syncing OA accounts to IDaaS: Account data synchronization
-
Syncing IDaaS accounts to RAM: Synchronize accounts from Alibaba Cloud IDaaS to Alibaba Cloud RAM via SCIM
Join an organization
To use Alibaba Cloud DevOps, you must create or join at least one organization. An Alibaba Cloud account can create or join multiple organizations. Each organization is independent, and information is not shared between them.
To join an organization, you can be added by an administrator or join via an invitation link. The method for joining depends on how the organization is configured:
-
If the Alibaba Cloud DevOps organization is not bound to a DingTalk organization:
-
Join via an invitation link: Get an organization invitation link from an administrator. Open the link to join the organization.
-
Be added by an administrator as an Alibaba Cloud RAM user: The administrator can add RAM users from their account to the organization through automatic or manual synchronization (Add RAM users).
-
-
If the Alibaba Cloud DevOps organization is bound to a DingTalk organization:
-
You can join the Alibaba Cloud DevOps organization by binding your personal account to a DingTalk account. The binding method depends on your account type:
-
If you are using a primary account, go to Third-party Account Binding. For instructions, see Bind a primary account to a DingTalk account.
-
If you are using a RAM account, for instructions, see Bind a RAM account to a DingTalk account.
-
-
If you are still unable to join the organization after binding your DingTalk account, check for the following possible reasons:
-
You are not within the scope of the DingTalk application. To check, go to the DingTalk Console and search for the "Alibaba Cloud DevOps" app. If you cannot open the app, you are outside its configured scope.
-
You have been deactivated in the Alibaba Cloud DevOps organization. If you are within the DingTalk app's scope but still cannot access the organization, you may have been deactivated. Contact your Alibaba Cloud DevOps organization administrator to be re-enabled.
-
Your DingTalk account has already joined the organization with another Alibaba Cloud account. To check, go to Personal Settings > Third-party Binding.
-
-
If you are not part of the DingTalk organization, you can join by using an external member invitation link. Get the link from an administrator and access it to join the organization.
-
Delete an organization
Once an organization is deleted, all its content is permanently removed. Deleting an organization is an irreversible action. Please proceed with caution.
If your organization is on an Advanced plan, the Delete Organization button is not available to prevent accidental deletion. If you need to delete the organization, please contact technical support.
Only the organization owner has the permission to delete or request the deletion of an organization.
-
The organization owner must go to the organization's admin backend. Click your profile picture in the upper-right corner and select Admin Backend.
-
In the admin backend, go to Basic Configuration > Basic Information. You will find the Delete Organization button at the bottom of the page.
Troubleshooting information
Find the organization ID
In the upper-left dock, go to Organization Admin Backend > Basic Information. The organization ID is displayed on this page.
Find the user ID
Go to flow.aliyun.com, right-click and view the page source, then search for userid. Provide the tbuserid value to technical support.
// Search for tbuserid in the page source code
window.g_config = {
env: "PRODUCTION",
...
tbuserid: "xxx", // Copy this value and provide it to technical support
...
}
Other questions
Set the login session validity
The duration of an Alibaba Cloud DevOps login session is determined by its expiration time. When the session expires, you must log in again. The default session expiration time is 3 hours, but it can be modified.
The method for setting the expiration time depends on whether you are using a primary account or a RAM account. For instructions, see Set the login session validity for Alibaba Cloud DevOps.
Handle dependency package builds
If you have different services in different code repositories—for example, services A, B, C, and D each have their own repository—and service A depends on a package from service B during its build, you can use one of the following approaches:
-
Upload the package built from service B to an Alibaba Cloud DevOps private repository. You can do this by running a deploy command to the private repository or by manually uploading it to Packages.
-
Use the Git submodule feature. However, Option 1 is the recommended approach.