Skip to content

Alibaba Cloud Reference

What this page holds

Look-up facts for Alibaba Cloud (Aliyun): region IDs and footprint, recent region launches and closures, service-name mappings to AWS and Google Cloud, tooling versions, credential modes, published limits, security-product names, and compliance facts. Why the services work the way they do is in Explanation. Commands are in How-to Guides.

Tooling Versions (September 2026)

Tool Latest version Date Notes
Terraform provider aliyun/alicloud 1.293.0 2026-09-17 Releases roughly weekly. 1.292.0 on 2026-09-08, 1.291.0 on 2026-09-01 (CHANGELOG)
Alibaba Cloud CLI (aliyun) v3.5.1 2026 (release date not in the changelog) v3.5.0 added a unified OpenAPI runtime, kebab-case commands, and an AI/agent mode. Homebrew formula tracks v3.5.1 (CHANGELOG)
Resource Orchestration Service (ROS) managed service n/a Native IaC. Uses CloudFormation-style JSON/YAML templates and also runs Terraform templates
ACK (Container Service for Kubernetes) managed service n/a Supported Kubernetes minors: TBD. Check the ACK release notes. Clusters can auto-upgrade on the patch, stable or rapid channel

CLI v3.5.0 breaking change

v3.5.0 removed retired products (acm, aigen, Ddi, scdn, scsp, viapi-regen, WebPlus) from the catalog. It also moved the Domain and Qualitycheck PascalCase commands to newer API versions. Scripts that call those products need to be migrated.

Global Footprint

Metric Value Source date
Regions 31 2026-09-23 (Apsara Conference 2026)
Availability zones 107 2026-09-23
Previous count 29 regions / 91 AZs 2025-09 (Apsara Conference 2025)
Announced next First regions in Turkey, Finland, and the Netherlands within 12 months (the Netherlands reportedly as early as 2026-10). Capacity expansion in Malaysia, Germany, UAE, France, and Hong Kong 2026-09-23
Long-range target More than 20 GW of global data-center capacity by 2032 (Alibaba group AI roadmap) 2026-09

Region IDs

Region IDs come from the Terraform provider's region list (connectivity/regions.go) and from Alibaba Cloud's region documentation. The data-center column counts facilities the press reported at launch. It is not an authoritative zone list. Run aliyun ecs DescribeZones --RegionId <id> for the live zones.

International Regions

Region Region ID Data centers / AZs (reported) Notes
China (Hong Kong) cn-hongkong TBD Sold on the international site. Expansion announced 2026-09
Singapore ap-southeast-1 TBD Main APAC hub for international accounts. Default migration target for the closed Sydney and Mumbai regions
Malaysia (Kuala Lumpur) ap-southeast-3 3 (5 in Malaysia in total)
Malaysia (Johor) TBD 2 Launched 2026-06 as the second Malaysian region
Indonesia (Jakarta) ap-southeast-5 3 DCs opened in 2018, 2019, and 2021
Philippines (Manila) ap-southeast-6 TBD
Thailand (Bangkok) ap-southeast-7 2 First DC 2022-05, second DC 2025-02
Japan (Tokyo) ap-northeast-1 TBD Further Tokyo expansion reported 2026-06
South Korea (Seoul) ap-northeast-2 3 Second DC 2025-06, third DC 2026-08-18
US (Silicon Valley) us-west-1 TBD
US (Virginia) us-east-1 TBD
Mexico (Querétaro) na-south-1 1 AZ at launch Launched 2025-02-18. First Latin American region
Brazil (São Paulo) sa-east-1 2 Launched 2026-08-27. First South American region
Germany (Frankfurt) eu-central-1 TBD Expansion announced 2026-09
UK (London) eu-west-1 TBD
France (Paris) eu-west-2 2 AZs Launched 2026-06-17. Third European region
UAE (Dubai) me-east-1 2 Second DC began operating 2025-10
Saudi Arabia (Riyadh) me-central-1 TBD Operated with a local partner

Closed regions

India (Mumbai, ap-south-1) stopped operating after 2024-07-15, and Australia (Sydney, ap-southeast-2) after 2024-09-30. Alibaba told customers to migrate to Singapore or another region (notice). Old templates and provider code still list these IDs.

Mainland China Regions

Mainland regions are sold through aliyun.com (China site). They need a China business entity, and public websites need ICP filing.

Region Region ID
China (Hangzhou) cn-hangzhou
China (Shanghai) cn-shanghai
China (Beijing) cn-beijing
China (Qingdao) cn-qingdao
China (Zhangjiakou) cn-zhangjiakou
China (Hohhot) cn-huhehaote
China (Ulanqab) cn-wulanchabu
China (Shenzhen) cn-shenzhen
China (Heyuan) cn-heyuan
China (Guangzhou) cn-guangzhou
China (Chengdu) cn-chengdu
China (Nanjing, local region) cn-nanjing
China (Fuzhou, local region) cn-fuzhou

Finance-cloud (cn-*-finance-*) and government-cloud (cn-north-2-gov-1) regions also exist. They are isolated, compliance-scoped regions and are not generally available.

Service Mapping: Alibaba Cloud to AWS and Google Cloud

Category Alibaba Cloud AWS Google Cloud
Multi-account hierarchy Resource Directory (folders, members) AWS Organizations (OUs, accounts) Resource Manager (org, folders, projects)
Guardrails Control Policies Service Control Policies Organization Policy
Landing zone Agentic Cloud Governance Center (formerly Cloud Governance Center) AWS Control Tower Cloud Foundation / Fabric FAST blueprints
IAM RAM (users, groups, roles, policies) + STS IAM + STS Cloud IAM
Workforce SSO CloudSSO IAM Identity Center Cloud Identity / Workforce Identity Federation
Audit log ActionTrail CloudTrail Cloud Audit Logs
Config compliance Cloud Config AWS Config Security Command Center / Asset Inventory
Virtual network VPC + vSwitch (zonal subnet) VPC + subnet (zonal) VPC (global) + subnet (regional)
Transit hub CEN + Transit Router (Enterprise Edition) Transit Gateway / Cloud WAN Network Connectivity Center
Peering VPC Peering Connection VPC Peering VPC Network Peering
Dedicated line Express Connect (+ VBR, Express Connect Router) Direct Connect (+ DX Gateway) Cloud Interconnect
NAT NAT Gateway (Internet / VPC NAT) NAT Gateway Cloud NAT
Load balancing SLB family: ALB (L7), NLB (L4), CLB (legacy L4/L7) ALB / NLB / CLB Cloud Load Balancing
Global acceleration Global Accelerator (GA) Global Accelerator Premium Tier network + global LB
DNS / traffic manager Alibaba Cloud DNS (Alidns) + GTM Route 53 Cloud DNS
Compute ECS EC2 Compute Engine
Serverless containers ECI, ACS Fargate Cloud Run
Kubernetes ACK (Basic, Pro, Serverless, Edge), ACK One (multi-cluster) EKS GKE
Container registry Container Registry (ACR) ECR Artifact Registry
Functions Function Compute Lambda Cloud Run functions
Object storage OSS S3 Cloud Storage
Managed RDBMS ApsaraDB RDS (MySQL, PostgreSQL, SQL Server, MariaDB) RDS Cloud SQL
Cloud-native RDBMS PolarDB (MySQL / PostgreSQL / Oracle-compatible) Aurora AlloyDB
Distributed SQL PolarDB-X Aurora DSQL (nearest) Spanner
Cache Tair (Redis OSS-compatible), formerly ApsaraDB for Redis ElastiCache / MemoryDB Memorystore
Data replication DTS DMS Datastream / Database Migration Service
Logs Simple Log Service (SLS) CloudWatch Logs Cloud Logging
Metrics / alarms CloudMonitor (CMS) CloudWatch Cloud Monitoring
Keys and secrets KMS (incl. Secrets Manager) KMS + Secrets Manager Cloud KMS + Secret Manager
Firewalls Cloud Firewall, WAF Network Firewall, WAF Cloud NGFW, Cloud Armor
DDoS Anti-DDoS Basic / Origin / Pro / Premium Shield Cloud Armor
Threat detection Security Center GuardDuty + Security Hub Security Command Center
Backup Cloud Backup (formerly Hybrid Backup Recovery, HBR) AWS Backup Backup and DR
Native IaC ROS CloudFormation Infrastructure Manager
AI model platform Model Studio (Qwen models), PAI Bedrock, SageMaker Vertex AI

Service Naming Quick Reference

Alibaba Cloud services often have different marketing names and console names. This table maps common architecture concepts to the exact Alibaba Cloud service names and the CLI product code.

Concept Alibaba Cloud service Abbreviation CLI product code
Virtual network Virtual Private Cloud VPC vpc
Subnet vSwitch vSW vpc
Load balancer (legacy L4/L7) Classic Load Balancer CLB (formerly "SLB") slb
Load balancer (L7) Application Load Balancer ALB alb
Load balancer (L4) Network Load Balancer NLB nlb
NAT NAT Gateway NAT GW vpc
Cloud-native firewall Cloud Firewall CFW cloudfw
WAF Web Application Firewall WAF waf-openapi
Dedicated line Express Connect EC vpc
WAN / transit Cloud Enterprise Network CEN cbn
Transit hub Transit Router TR cbn
Edge router for Express Connect Virtual Border Router VBR vpc
Global routing for Express Connect Express Connect Router ECR expressconnectrouter
Multi-account management Resource Directory RD resourcemanager
Governance / landing zone Agentic Cloud Governance Center CGC governance
IAM Resource Access Management RAM ram, ims
Temporary credentials Security Token Service STS sts
Workforce SSO CloudSSO — cloudsso
IaC (native) Resource Orchestration Service ROS ros
Object storage Object Storage Service OSS oss
Managed RDBMS ApsaraDB RDS RDS rds
Cloud-native DB PolarDB — polardb
Distributed DB PolarDB-X — polardbx
In-memory cache Tair (Redis OSS-compatible) KVStore r-kvstore
Data replication Data Transmission Service DTS dts
DNS (managed) Alibaba Cloud DNS Alidns alidns
Global traffic failover Global Traffic Manager GTM alidns
Backup Cloud Backup (formerly Hybrid Backup Recovery) HBR hbr
Logging Simple Log Service SLS sls
Metrics / alarms CloudMonitor CMS cms
Audit trail ActionTrail — actiontrail
Compliance Cloud Config Config config
Key management Key Management Service KMS kms
Security operations Security Center SAS sas
Container registry Container Registry ACR cr
Kubernetes Container Service for Kubernetes ACK cs

CLI product codes

The codes above follow the OpenAPI product names that aliyun <product> accepts. ecs, vpc, cbn, resourcemanager, ims, sts, cms, rds, dts, slb, and actiontrail appear in the commands on How-to Guides. Treat the others as unverified until aliyun <code> --help resolves them on your CLI version.

Connectivity Comparison Matrix

Criteria CEN (Transit Router) VPC Peering Express Connect
Topology Hub-and-spoke Point-to-point Point-to-point (physical)
Scalability Large number of VPC attachments per TR (quota-bound, see limits) O(n^2) links for full mesh Limited by circuit capacity
Cross-region Yes (TR peer attachments over the backbone) Yes (inter-region peering, Gold default or Platinum link type) Circuit to one access point; reach other regions through ECR or CEN
Routing Centralized, custom route tables, route maps Manual per-VPC routes BGP via VBR/ECR, or static
Isolation policy Fine-grained (route tables) All-or-nothing All-or-nothing
Provisioning Minutes (cloud) Minutes (cloud) Days to weeks (physical circuit)
Cost model TR attachment + processing fees. Inter-region either bandwidth plan (BandwidthPackage) or pay-by-data-transfer (DataTransfer) Inter-region peering billed by traffic. Same-region: verify current pricing Port + circuit + bandwidth
Best for Enterprise multi-VPC and multi-account Small, simple setups (2-4 VPCs) Hybrid cloud, compliance

Published Limits and Defaults

Quotas change and many can be raised in Quota Center. Rows marked "unverified" come from the pre-2026-09 note and were not re-checked against current docs.

Item Value Status
Resource Directory folder depth 5 levels below Root Verified (RD docs)
Control policy document size Up to 4,096 characters Verified (Terraform provider docs)
Control policy effect scope All (Alibaba Cloud accounts, RAM users, RAM roles) or RAM (RAM users and roles only) Verified (Terraform provider docs)
RAM role max session duration Default 3,600 s. Configurable 3,600-43,200 s Verified (Terraform provider docs)
STS AssumeRole DurationSeconds Minimum 900 s, maximum = role's max session duration Minimum from CLI docs. Maximum verified
Security group rule priority 1-100 (1 = highest), default 1 Verified (Terraform provider docs)
RAM users per account 1,000 (default quota) Unverified (2026-04)
VPC attachments per Enterprise TR Up to 1,000 VPCs per region Unverified (2026-04)
PolarDB cluster read-only nodes Up to 15 Unverified (2026-04)
Express Connect dedicated port Up to 100 Gbit/s per port. ECMP across circuits for more Unverified (2026-04)
Enhanced Internet NAT Gateway Auto-scaling. 2026-04 note claimed ~100K new conn/s, 15 Gbit/s, 2M concurrent sessions Unverified. Check NAT Gateway specs
NAT Gateway type Only Enhanced can be created. Normal was retired from the API/provider (Terraform v1.137.0+) Verified (Terraform provider docs)
OSS redundancy LRS (default) or ZRS (multi-zone, selected regions) Verified (Terraform provider docs)

Credential Modes (CLI and Terraform)

Mode (aliyun configure --mode) Use Terraform provider equivalent
OAuth Interactive local sign-in, no stored AccessKey n/a
CloudSSO Workforce sign-in through CloudSSO portal profile pointing to a CLI CloudSSO profile
AK Static AccessKey. Use only when nothing better exists access_key / secret_key or ALIBABA_CLOUD_ACCESS_KEY_ID / ALIBABA_CLOUD_ACCESS_KEY_SECRET
StsToken Pre-issued temporary AK + token, no refresh security_token / ALIBABA_CLOUD_SECURITY_TOKEN
RamRoleArn Assume a RAM role from an AK identity assume_role { role_arn = ... } / ALIBABA_CLOUD_ROLE_ARN
ChainableRamRoleArn Assume a role using another profile as the source profile
EcsRamRole Instance RAM role from ECS metadata ecs_role_name / ALIBABA_CLOUD_ECS_METADATA
OIDC Exchange an OIDC token for role credentials (CI, ACK RRSA) assume_role_with_oidc { ... }
External, CredentialsURI Credential process or HTTP credential endpoint profile (External) / ALIBABA_CLOUD_CREDENTIALS_URI

The legacy provider variables ALICLOUD_ACCESS_KEY, ALICLOUD_SECRET_KEY, and ALICLOUD_SECURITY_TOKEN are deprecated since provider v1.228.0 in favour of the ALIBABA_CLOUD_* names.

ACK Cluster Types

cluster_spec / profile Meaning
ack.standard ACK Basic managed cluster
ack.pro.small ACK Pro managed cluster (SLA-backed control plane, cluster management fee)
ack.pro.xlarge / 2xlarge / 4xlarge ACK Pro Provisioned Control Plane tiers (4xlarge needs allowlisting)
profile = Edge ACK Edge (Basic / Pro)
profile = Serverless ACK Serverless (Basic / Pro), pods on ECI
profile = Acs ACS (Container Compute Service) cluster

Source: Terraform alicloud_cs_managed_kubernetes.

Security Products at a Glance

Cloud Firewall Boundaries

Mode Scope Use case
Internet Border North-south traffic on EIPs, SLBs, NAT Gateways Block external attacks, IPS/IDS
VPC Border East-west traffic between VPCs over CEN/TR or Express Connect Inter-VPC isolation and inspection
NAT Border Outbound traffic through NAT Gateway Egress control for private workloads
Internal Firewall East-west traffic between ECS instances in a VPC Micro-segmentation by instance tags/security groups

Anti-DDoS Family

Product Protection Scope
Anti-DDoS Basic Free basic mitigation. Threshold depends on region and instance (2026-04 note: up to 5 Gbit/s, unverified) On by default for all Alibaba Cloud public IPs
Anti-DDoS Origin (Terraform ddosbgp, mapping unverified) Paid protection applied directly to origin public IPs, no traffic redirection Resources with EIPs/public IPs in supported regions
Anti-DDoS Pro (Terraform ddoscoo) Proxy-mode high-capacity scrubbing (2026-04 note: up to 1.5 Tbit/s, unverified) Resources in mainland China
Anti-DDoS Premium (Terraform ddoscoo) Anycast proxy scrubbing outside mainland China, hides origin IP. "Unlimited" mitigation plans exist, check current plans Resources outside mainland China

KMS Features

Feature Detail
Key types Symmetric (AES-256, SM4), asymmetric (RSA, EC, SM2)
Hardware protection HSM-backed keys. The HSMs are described as FIPS 140-2 Level 3 validated (unverified 2026-09)
Key rotation Automatic rotation with configurable interval
Envelope encryption Generate data keys locally, encrypt them with a KMS key
Native integrations OSS (SSE-KMS), RDS/PolarDB (TDE), ECS (disk encryption), SLS, ActionTrail, ACK (Secret encryption)

Compliance Facts

Item Fact
China Cybersecurity Law In force 2017-06-01. Network log retention at least 6 months. Data localization for personal information and important data collected by CII operators. Amendment raising penalties took effect 2026-01-01 (verify details)
Data Security Law / PIPL In force 2021-09-01 / 2021-11-01. Cross-border transfer needs a CAC security assessment, standard contract, or certification. Relaxations under the 2024-03 cross-border data-flow provisions
MLPS 2.0 GB/T 22239-2019, levels 1-5. Alibaba provides compliance packages for levels 2 and 3. Level 4 support claims in the 2026-04 note are unverified
Certifications (per Alibaba Trust Center, unverified 2026-09) ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, CSA STAR, Singapore MTCS Level 3, Germany C5
Site split aliyun.com (mainland China, China entity) and alibabacloud.com (international). Accounts, pricing, and some product features differ

Sources