Alibaba Cloud Reference¶
What this page holds
Look-up facts for Alibaba Cloud (Aliyun): region IDs and footprint, recent region launches and closures, service-name mappings to AWS and Google Cloud, tooling versions, credential modes, published limits, security-product names, and compliance facts. Why the services work the way they do is in Explanation. Commands are in How-to Guides.
Tooling Versions (September 2026)¶
| Tool | Latest version | Date | Notes |
|---|---|---|---|
Terraform provider aliyun/alicloud |
1.293.0 | 2026-09-17 | Releases roughly weekly. 1.292.0 on 2026-09-08, 1.291.0 on 2026-09-01 (CHANGELOG) |
Alibaba Cloud CLI (aliyun) |
v3.5.1 | 2026 (release date not in the changelog) | v3.5.0 added a unified OpenAPI runtime, kebab-case commands, and an AI/agent mode. Homebrew formula tracks v3.5.1 (CHANGELOG) |
| Resource Orchestration Service (ROS) | managed service | n/a | Native IaC. Uses CloudFormation-style JSON/YAML templates and also runs Terraform templates |
| ACK (Container Service for Kubernetes) | managed service | n/a | Supported Kubernetes minors: TBD. Check the ACK release notes. Clusters can auto-upgrade on the patch, stable or rapid channel |
CLI v3.5.0 breaking change
v3.5.0 removed retired products (acm, aigen, Ddi, scdn, scsp, viapi-regen, WebPlus) from the
catalog. It also moved the Domain and Qualitycheck PascalCase commands to newer API versions. Scripts
that call those products need to be migrated.
Global Footprint¶
| Metric | Value | Source date |
|---|---|---|
| Regions | 31 | 2026-09-23 (Apsara Conference 2026) |
| Availability zones | 107 | 2026-09-23 |
| Previous count | 29 regions / 91 AZs | 2025-09 (Apsara Conference 2025) |
| Announced next | First regions in Turkey, Finland, and the Netherlands within 12 months (the Netherlands reportedly as early as 2026-10). Capacity expansion in Malaysia, Germany, UAE, France, and Hong Kong | 2026-09-23 |
| Long-range target | More than 20 GW of global data-center capacity by 2032 (Alibaba group AI roadmap) | 2026-09 |
Region IDs¶
Region IDs come from the Terraform provider's region list
(connectivity/regions.go)
and from Alibaba Cloud's region documentation. The data-center column counts facilities the press reported at
launch. It is not an authoritative zone list. Run aliyun ecs DescribeZones --RegionId <id> for the live zones.
International Regions¶
| Region | Region ID | Data centers / AZs (reported) | Notes |
|---|---|---|---|
| China (Hong Kong) | cn-hongkong |
TBD | Sold on the international site. Expansion announced 2026-09 |
| Singapore | ap-southeast-1 |
TBD | Main APAC hub for international accounts. Default migration target for the closed Sydney and Mumbai regions |
| Malaysia (Kuala Lumpur) | ap-southeast-3 |
3 (5 in Malaysia in total) | |
| Malaysia (Johor) | TBD | 2 | Launched 2026-06 as the second Malaysian region |
| Indonesia (Jakarta) | ap-southeast-5 |
3 | DCs opened in 2018, 2019, and 2021 |
| Philippines (Manila) | ap-southeast-6 |
TBD | |
| Thailand (Bangkok) | ap-southeast-7 |
2 | First DC 2022-05, second DC 2025-02 |
| Japan (Tokyo) | ap-northeast-1 |
TBD | Further Tokyo expansion reported 2026-06 |
| South Korea (Seoul) | ap-northeast-2 |
3 | Second DC 2025-06, third DC 2026-08-18 |
| US (Silicon Valley) | us-west-1 |
TBD | |
| US (Virginia) | us-east-1 |
TBD | |
| Mexico (Querétaro) | na-south-1 |
1 AZ at launch | Launched 2025-02-18. First Latin American region |
| Brazil (São Paulo) | sa-east-1 |
2 | Launched 2026-08-27. First South American region |
| Germany (Frankfurt) | eu-central-1 |
TBD | Expansion announced 2026-09 |
| UK (London) | eu-west-1 |
TBD | |
| France (Paris) | eu-west-2 |
2 AZs | Launched 2026-06-17. Third European region |
| UAE (Dubai) | me-east-1 |
2 | Second DC began operating 2025-10 |
| Saudi Arabia (Riyadh) | me-central-1 |
TBD | Operated with a local partner |
Closed regions
India (Mumbai, ap-south-1) stopped operating after 2024-07-15, and Australia (Sydney,
ap-southeast-2) after 2024-09-30. Alibaba told customers to migrate to Singapore or another region
(notice).
Old templates and provider code still list these IDs.
Mainland China Regions¶
Mainland regions are sold through aliyun.com (China site). They need a China business entity, and public websites need ICP filing.
| Region | Region ID |
|---|---|
| China (Hangzhou) | cn-hangzhou |
| China (Shanghai) | cn-shanghai |
| China (Beijing) | cn-beijing |
| China (Qingdao) | cn-qingdao |
| China (Zhangjiakou) | cn-zhangjiakou |
| China (Hohhot) | cn-huhehaote |
| China (Ulanqab) | cn-wulanchabu |
| China (Shenzhen) | cn-shenzhen |
| China (Heyuan) | cn-heyuan |
| China (Guangzhou) | cn-guangzhou |
| China (Chengdu) | cn-chengdu |
| China (Nanjing, local region) | cn-nanjing |
| China (Fuzhou, local region) | cn-fuzhou |
Finance-cloud (cn-*-finance-*) and government-cloud (cn-north-2-gov-1) regions also exist. They are
isolated, compliance-scoped regions and are not generally available.
Service Mapping: Alibaba Cloud to AWS and Google Cloud¶
| Category | Alibaba Cloud | AWS | Google Cloud |
|---|---|---|---|
| Multi-account hierarchy | Resource Directory (folders, members) | AWS Organizations (OUs, accounts) | Resource Manager (org, folders, projects) |
| Guardrails | Control Policies | Service Control Policies | Organization Policy |
| Landing zone | Agentic Cloud Governance Center (formerly Cloud Governance Center) | AWS Control Tower | Cloud Foundation / Fabric FAST blueprints |
| IAM | RAM (users, groups, roles, policies) + STS | IAM + STS | Cloud IAM |
| Workforce SSO | CloudSSO | IAM Identity Center | Cloud Identity / Workforce Identity Federation |
| Audit log | ActionTrail | CloudTrail | Cloud Audit Logs |
| Config compliance | Cloud Config | AWS Config | Security Command Center / Asset Inventory |
| Virtual network | VPC + vSwitch (zonal subnet) | VPC + subnet (zonal) | VPC (global) + subnet (regional) |
| Transit hub | CEN + Transit Router (Enterprise Edition) | Transit Gateway / Cloud WAN | Network Connectivity Center |
| Peering | VPC Peering Connection | VPC Peering | VPC Network Peering |
| Dedicated line | Express Connect (+ VBR, Express Connect Router) | Direct Connect (+ DX Gateway) | Cloud Interconnect |
| NAT | NAT Gateway (Internet / VPC NAT) | NAT Gateway | Cloud NAT |
| Load balancing | SLB family: ALB (L7), NLB (L4), CLB (legacy L4/L7) | ALB / NLB / CLB | Cloud Load Balancing |
| Global acceleration | Global Accelerator (GA) | Global Accelerator | Premium Tier network + global LB |
| DNS / traffic manager | Alibaba Cloud DNS (Alidns) + GTM | Route 53 | Cloud DNS |
| Compute | ECS | EC2 | Compute Engine |
| Serverless containers | ECI, ACS | Fargate | Cloud Run |
| Kubernetes | ACK (Basic, Pro, Serverless, Edge), ACK One (multi-cluster) | EKS | GKE |
| Container registry | Container Registry (ACR) | ECR | Artifact Registry |
| Functions | Function Compute | Lambda | Cloud Run functions |
| Object storage | OSS | S3 | Cloud Storage |
| Managed RDBMS | ApsaraDB RDS (MySQL, PostgreSQL, SQL Server, MariaDB) | RDS | Cloud SQL |
| Cloud-native RDBMS | PolarDB (MySQL / PostgreSQL / Oracle-compatible) | Aurora | AlloyDB |
| Distributed SQL | PolarDB-X | Aurora DSQL (nearest) | Spanner |
| Cache | Tair (Redis OSS-compatible), formerly ApsaraDB for Redis | ElastiCache / MemoryDB | Memorystore |
| Data replication | DTS | DMS | Datastream / Database Migration Service |
| Logs | Simple Log Service (SLS) | CloudWatch Logs | Cloud Logging |
| Metrics / alarms | CloudMonitor (CMS) | CloudWatch | Cloud Monitoring |
| Keys and secrets | KMS (incl. Secrets Manager) | KMS + Secrets Manager | Cloud KMS + Secret Manager |
| Firewalls | Cloud Firewall, WAF | Network Firewall, WAF | Cloud NGFW, Cloud Armor |
| DDoS | Anti-DDoS Basic / Origin / Pro / Premium | Shield | Cloud Armor |
| Threat detection | Security Center | GuardDuty + Security Hub | Security Command Center |
| Backup | Cloud Backup (formerly Hybrid Backup Recovery, HBR) | AWS Backup | Backup and DR |
| Native IaC | ROS | CloudFormation | Infrastructure Manager |
| AI model platform | Model Studio (Qwen models), PAI | Bedrock, SageMaker | Vertex AI |
Service Naming Quick Reference¶
Alibaba Cloud services often have different marketing names and console names. This table maps common architecture concepts to the exact Alibaba Cloud service names and the CLI product code.
| Concept | Alibaba Cloud service | Abbreviation | CLI product code |
|---|---|---|---|
| Virtual network | Virtual Private Cloud | VPC | vpc |
| Subnet | vSwitch | vSW | vpc |
| Load balancer (legacy L4/L7) | Classic Load Balancer | CLB (formerly "SLB") | slb |
| Load balancer (L7) | Application Load Balancer | ALB | alb |
| Load balancer (L4) | Network Load Balancer | NLB | nlb |
| NAT | NAT Gateway | NAT GW | vpc |
| Cloud-native firewall | Cloud Firewall | CFW | cloudfw |
| WAF | Web Application Firewall | WAF | waf-openapi |
| Dedicated line | Express Connect | EC | vpc |
| WAN / transit | Cloud Enterprise Network | CEN | cbn |
| Transit hub | Transit Router | TR | cbn |
| Edge router for Express Connect | Virtual Border Router | VBR | vpc |
| Global routing for Express Connect | Express Connect Router | ECR | expressconnectrouter |
| Multi-account management | Resource Directory | RD | resourcemanager |
| Governance / landing zone | Agentic Cloud Governance Center | CGC | governance |
| IAM | Resource Access Management | RAM | ram, ims |
| Temporary credentials | Security Token Service | STS | sts |
| Workforce SSO | CloudSSO | — | cloudsso |
| IaC (native) | Resource Orchestration Service | ROS | ros |
| Object storage | Object Storage Service | OSS | oss |
| Managed RDBMS | ApsaraDB RDS | RDS | rds |
| Cloud-native DB | PolarDB | — | polardb |
| Distributed DB | PolarDB-X | — | polardbx |
| In-memory cache | Tair (Redis OSS-compatible) | KVStore | r-kvstore |
| Data replication | Data Transmission Service | DTS | dts |
| DNS (managed) | Alibaba Cloud DNS | Alidns | alidns |
| Global traffic failover | Global Traffic Manager | GTM | alidns |
| Backup | Cloud Backup (formerly Hybrid Backup Recovery) | HBR | hbr |
| Logging | Simple Log Service | SLS | sls |
| Metrics / alarms | CloudMonitor | CMS | cms |
| Audit trail | ActionTrail | — | actiontrail |
| Compliance | Cloud Config | Config | config |
| Key management | Key Management Service | KMS | kms |
| Security operations | Security Center | SAS | sas |
| Container registry | Container Registry | ACR | cr |
| Kubernetes | Container Service for Kubernetes | ACK | cs |
CLI product codes
The codes above follow the OpenAPI product names that aliyun <product> accepts. ecs, vpc, cbn,
resourcemanager, ims, sts, cms, rds, dts, slb, and actiontrail appear in the commands on
How-to Guides. Treat the others as unverified until
aliyun <code> --help resolves them on your CLI version.
Connectivity Comparison Matrix¶
| Criteria | CEN (Transit Router) | VPC Peering | Express Connect |
|---|---|---|---|
| Topology | Hub-and-spoke | Point-to-point | Point-to-point (physical) |
| Scalability | Large number of VPC attachments per TR (quota-bound, see limits) | O(n^2) links for full mesh | Limited by circuit capacity |
| Cross-region | Yes (TR peer attachments over the backbone) | Yes (inter-region peering, Gold default or Platinum link type) |
Circuit to one access point; reach other regions through ECR or CEN |
| Routing | Centralized, custom route tables, route maps | Manual per-VPC routes | BGP via VBR/ECR, or static |
| Isolation policy | Fine-grained (route tables) | All-or-nothing | All-or-nothing |
| Provisioning | Minutes (cloud) | Minutes (cloud) | Days to weeks (physical circuit) |
| Cost model | TR attachment + processing fees. Inter-region either bandwidth plan (BandwidthPackage) or pay-by-data-transfer (DataTransfer) |
Inter-region peering billed by traffic. Same-region: verify current pricing | Port + circuit + bandwidth |
| Best for | Enterprise multi-VPC and multi-account | Small, simple setups (2-4 VPCs) | Hybrid cloud, compliance |
Published Limits and Defaults¶
Quotas change and many can be raised in Quota Center. Rows marked "unverified" come from the pre-2026-09 note and were not re-checked against current docs.
| Item | Value | Status |
|---|---|---|
| Resource Directory folder depth | 5 levels below Root | Verified (RD docs) |
| Control policy document size | Up to 4,096 characters | Verified (Terraform provider docs) |
| Control policy effect scope | All (Alibaba Cloud accounts, RAM users, RAM roles) or RAM (RAM users and roles only) |
Verified (Terraform provider docs) |
| RAM role max session duration | Default 3,600 s. Configurable 3,600-43,200 s | Verified (Terraform provider docs) |
STS AssumeRole DurationSeconds |
Minimum 900 s, maximum = role's max session duration | Minimum from CLI docs. Maximum verified |
| Security group rule priority | 1-100 (1 = highest), default 1 | Verified (Terraform provider docs) |
| RAM users per account | 1,000 (default quota) | Unverified (2026-04) |
| VPC attachments per Enterprise TR | Up to 1,000 VPCs per region | Unverified (2026-04) |
| PolarDB cluster read-only nodes | Up to 15 | Unverified (2026-04) |
| Express Connect dedicated port | Up to 100 Gbit/s per port. ECMP across circuits for more | Unverified (2026-04) |
| Enhanced Internet NAT Gateway | Auto-scaling. 2026-04 note claimed ~100K new conn/s, 15 Gbit/s, 2M concurrent sessions | Unverified. Check NAT Gateway specs |
| NAT Gateway type | Only Enhanced can be created. Normal was retired from the API/provider (Terraform v1.137.0+) |
Verified (Terraform provider docs) |
| OSS redundancy | LRS (default) or ZRS (multi-zone, selected regions) |
Verified (Terraform provider docs) |
Credential Modes (CLI and Terraform)¶
Mode (aliyun configure --mode) |
Use | Terraform provider equivalent |
|---|---|---|
OAuth |
Interactive local sign-in, no stored AccessKey | n/a |
CloudSSO |
Workforce sign-in through CloudSSO portal | profile pointing to a CLI CloudSSO profile |
AK |
Static AccessKey. Use only when nothing better exists | access_key / secret_key or ALIBABA_CLOUD_ACCESS_KEY_ID / ALIBABA_CLOUD_ACCESS_KEY_SECRET |
StsToken |
Pre-issued temporary AK + token, no refresh | security_token / ALIBABA_CLOUD_SECURITY_TOKEN |
RamRoleArn |
Assume a RAM role from an AK identity | assume_role { role_arn = ... } / ALIBABA_CLOUD_ROLE_ARN |
ChainableRamRoleArn |
Assume a role using another profile as the source | profile |
EcsRamRole |
Instance RAM role from ECS metadata | ecs_role_name / ALIBABA_CLOUD_ECS_METADATA |
OIDC |
Exchange an OIDC token for role credentials (CI, ACK RRSA) | assume_role_with_oidc { ... } |
External, CredentialsURI |
Credential process or HTTP credential endpoint | profile (External) / ALIBABA_CLOUD_CREDENTIALS_URI |
The legacy provider variables ALICLOUD_ACCESS_KEY, ALICLOUD_SECRET_KEY, and ALICLOUD_SECURITY_TOKEN are
deprecated since provider v1.228.0 in favour of the ALIBABA_CLOUD_* names.
ACK Cluster Types¶
cluster_spec / profile |
Meaning |
|---|---|
ack.standard |
ACK Basic managed cluster |
ack.pro.small |
ACK Pro managed cluster (SLA-backed control plane, cluster management fee) |
ack.pro.xlarge / 2xlarge / 4xlarge |
ACK Pro Provisioned Control Plane tiers (4xlarge needs allowlisting) |
profile = Edge |
ACK Edge (Basic / Pro) |
profile = Serverless |
ACK Serverless (Basic / Pro), pods on ECI |
profile = Acs |
ACS (Container Compute Service) cluster |
Source: Terraform alicloud_cs_managed_kubernetes.
Security Products at a Glance¶
Cloud Firewall Boundaries¶
| Mode | Scope | Use case |
|---|---|---|
| Internet Border | North-south traffic on EIPs, SLBs, NAT Gateways | Block external attacks, IPS/IDS |
| VPC Border | East-west traffic between VPCs over CEN/TR or Express Connect | Inter-VPC isolation and inspection |
| NAT Border | Outbound traffic through NAT Gateway | Egress control for private workloads |
| Internal Firewall | East-west traffic between ECS instances in a VPC | Micro-segmentation by instance tags/security groups |
Anti-DDoS Family¶
| Product | Protection | Scope |
|---|---|---|
| Anti-DDoS Basic | Free basic mitigation. Threshold depends on region and instance (2026-04 note: up to 5 Gbit/s, unverified) | On by default for all Alibaba Cloud public IPs |
Anti-DDoS Origin (Terraform ddosbgp, mapping unverified) |
Paid protection applied directly to origin public IPs, no traffic redirection | Resources with EIPs/public IPs in supported regions |
Anti-DDoS Pro (Terraform ddoscoo) |
Proxy-mode high-capacity scrubbing (2026-04 note: up to 1.5 Tbit/s, unverified) | Resources in mainland China |
Anti-DDoS Premium (Terraform ddoscoo) |
Anycast proxy scrubbing outside mainland China, hides origin IP. "Unlimited" mitigation plans exist, check current plans | Resources outside mainland China |
KMS Features¶
| Feature | Detail |
|---|---|
| Key types | Symmetric (AES-256, SM4), asymmetric (RSA, EC, SM2) |
| Hardware protection | HSM-backed keys. The HSMs are described as FIPS 140-2 Level 3 validated (unverified 2026-09) |
| Key rotation | Automatic rotation with configurable interval |
| Envelope encryption | Generate data keys locally, encrypt them with a KMS key |
| Native integrations | OSS (SSE-KMS), RDS/PolarDB (TDE), ECS (disk encryption), SLS, ActionTrail, ACK (Secret encryption) |
Compliance Facts¶
| Item | Fact |
|---|---|
| China Cybersecurity Law | In force 2017-06-01. Network log retention at least 6 months. Data localization for personal information and important data collected by CII operators. Amendment raising penalties took effect 2026-01-01 (verify details) |
| Data Security Law / PIPL | In force 2021-09-01 / 2021-11-01. Cross-border transfer needs a CAC security assessment, standard contract, or certification. Relaxations under the 2024-03 cross-border data-flow provisions |
| MLPS 2.0 | GB/T 22239-2019, levels 1-5. Alibaba provides compliance packages for levels 2 and 3. Level 4 support claims in the 2026-04 note are unverified |
| Certifications (per Alibaba Trust Center, unverified 2026-09) | ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, CSA STAR, Singapore MTCS Level 3, Germany C5 |
| Site split | aliyun.com (mainland China, China entity) and alibabacloud.com (international). Accounts, pricing, and some product features differ |
Sources¶
- Terraform provider CHANGELOG, regions.go, resource docs in
website/docs/r - Alibaba Cloud CLI README and CHANGELOG
- ECS regions and zones
- Alibaba Cloud global locations
- Notice: ceasing operation in Australia and India
- Mexico region launch (press room)
- France region, two AZs (press room)
- Brazil region launch (press room)
- Johor region (press room)
- Third South Korea data center (press room)
- Second Thailand data center (press room)
- Apsara 2026 expansion: Turkey, Finland, Netherlands (heise)
- Resource Management limits
- Control policy overview