Skip to content

Tencent Cloud Reference

What this page holds

Look-up facts for Tencent Cloud (international site): tooling versions, region IDs and footprint, service-name mappings to AWS, Google Cloud, and Alibaba Cloud, multi-account (TCO) features and their API/Terraform names, CCN billing rules, security-product tiers, published limits, and compliance facts. Why the services work the way they do is in Explanation. Commands are in How-to Guides.

Tooling Versions (September 2026)

Tool Latest version Date Notes
Terraform provider tencentcloudstack/tencentcloud 1.83.33 2026-09-21 Releases several times a week. MPL-2.0 (CHANGELOG)
tccli (Tencent Cloud CLI) 3.1.174.1 2026-09-24 Python, installs with pip install tccli. Apache-2.0 (PyPI)
tencentcloud-sdk-python 3.1.181 2026-09-24 tccli depends on it and upgrades it automatically (PyPI)
Landing-zone Terraform modules tencentcloud-landing-zone-booster 2025-2026 Terraform modules and components for a network hub, a logging account, and CAM/SSO baselines. Apache-2.0 (repo)

Provider authentication modes (from the provider docs): static keys, environment variables (TENCENTCLOUD_SECRET_ID, TENCENTCLOUD_SECRET_KEY, TENCENTCLOUD_REGION), assume_role (1.33.1+), assume_role_with_saml and assume_role_with_web_identity (1.81.111+), cam_role_name for a CVM instance role and enable_pod_oidc for TKE pods (1.81.117+), and shared credentials from ~/.tccli. The default region is ap-guangzhou.

Global Footprint

Tencent's own count changes with each announcement. The figures differ in whether they include AZs announced but not yet open.

Date Regions AZs Source statement
2025-04-15 21 56 Osaka announcement ("service network covering 21 geographical regions and 56 availability zones")
2026-03-02 22 64 Frankfurt AZ-3 announcement at MWC 2026
2026-08-18 23 66 Malaysia (Johor) region announcement. "Tencent Cloud International's existing global network"

Conflicting counts

Some secondary sources quote "70 availability zones across 25 (or 26) regions". That figure dates from 2023 and appears to include partner-operated locations. Use the dated Tencent statements above and check the live Global Infrastructure page before you quote a number.

Region IDs

Region IDs come from the SDK region constants (tencentcloud-sdk-go-intl-en). That list is not updated for every launch. Newer regions have no confirmed ID here. Run tccli cvm DescribeRegions against your account for the authoritative list.

Mainland China

Region Region ID Notes
Beijing ap-beijing
Shanghai ap-shanghai
Shanghai Finance ap-shanghai-fsi Isolated financial-services zone, needs approval
Guangzhou ap-guangzhou Default region of tccli examples and the Terraform provider
Shenzhen Finance ap-shenzhen-fsi Isolated financial-services zone, needs approval
Nanjing ap-nanjing
Chengdu ap-chengdu
Chongqing ap-chongqing

International

Region Region ID AZs Status / notes
Hong Kong (China) ap-hongkong TBD Separate from mainland regulation
Singapore ap-singapore TBD Main Southeast Asia hub
Jakarta ap-jakarta 3 Third AZ added in 2025 (Tencent statement, 2026-03-02)
Bangkok ap-bangkok TBD
Johor (Malaysia) TBD 2, third planned First Malaysian region. Two AZs live in the week of 2026-08-18
Seoul ap-seoul TBD
Tokyo ap-tokyo 2 Second AZ added in 2021
Osaka TBD 1 planned Announced 2025-04-15 as Japan's third AZ, launch scheduled for 2026. Live status TBD
Mumbai ap-mumbai TBD In the SDK list. Availability to new customers TBD
Riyadh area (Saudi Arabia) TBD 2 First Middle East region, announced 2025-02-10 at LEAP 2025. Over USD 150M investment planned
Frankfurt eu-frankfurt 3 AZ-3 announced 2026-03-02, open to customers from Q2 2026
Moscow eu-moscow TBD In the SDK list. Availability to new customers TBD
Silicon Valley na-siliconvalley TBD
Virginia (Ashburn) na-ashburn TBD Shown as "Virginia" in the console
Toronto na-toronto TBD
Sao Paulo sa-saopaulo TBD Only South America region

AZ IDs follow the <region-id>-<n> pattern (for example ap-guangzhou-3). Numbers are not contiguous. tccli cvm DescribeZones --region <id> lists the zones your account can use.

Service Name Mapping

The table gives the closest equivalent, not feature parity. The Tencent abbreviation is the name you see in API namespaces (tccli <namespace> ...) and Terraform resource prefixes.

Category Tencent Cloud (abbrev.) AWS Google Cloud Alibaba Cloud
VM Cloud Virtual Machine (CVM) EC2 Compute Engine ECS
Simple VPS Lighthouse Lightsail -- Simple Application Server
Bare metal Cloud Physical Machine (CPM) EC2 bare metal Bare Metal Solution ECS Bare Metal
Auto scaling Auto Scaling (AS) EC2 Auto Scaling Managed instance groups Auto Scaling (ESS)
Functions Serverless Cloud Function (SCF) Lambda Cloud Run functions Function Compute
Kubernetes Tencent Kubernetes Engine (TKE) EKS GKE ACK
Container registry Tencent Container Registry (TCR) ECR Artifact Registry ACR
Virtual network VPC VPC VPC VPC
Transit / WAN Cloud Connect Network (CCN) Transit Gateway / Cloud WAN Network Connectivity Center CEN + Transit Router
VPC peering Peering Connection VPC Peering VPC Network Peering VPC peering connection
Dedicated line Direct Connect (DC) Direct Connect Cloud Interconnect Express Connect
VPN VPN Gateway Site-to-Site VPN Cloud VPN VPN Gateway
Load balancer Cloud Load Balancer (CLB) ELB (ALB/NLB) Cloud Load Balancing ALB / NLB / CLB
NAT NAT Gateway NAT Gateway Cloud NAT NAT Gateway
Global acceleration Global Application Acceleration Platform (GAAP) Global Accelerator Premium Tier network Global Accelerator
DNS DNSPod / Private DNS Route 53 Cloud DNS Alibaba Cloud DNS
CDN + edge security EdgeOne, CDN CloudFront + Shield + WAF Cloud CDN + Cloud Armor CDN / ESA
Object storage Cloud Object Storage (COS) S3 Cloud Storage OSS
Block storage Cloud Block Storage (CBS) EBS Persistent Disk / Hyperdisk Block storage (ESSD)
File storage Cloud File Storage (CFS) EFS Filestore NAS
Managed MySQL TencentDB for MySQL (CDB) RDS for MySQL Cloud SQL for MySQL ApsaraDB RDS for MySQL
Cloud-native MySQL/PG TDSQL-C (formerly CynosDB) Aurora AlloyDB (PostgreSQL) PolarDB
Distributed MySQL TDSQL for MySQL (API namespace dcdb) -- Spanner (loosely) PolarDB-X
MariaDB TencentDB for MariaDB (API namespace mariadb) RDS for MariaDB -- --
Redis TencentDB for Redis ElastiCache Memorystore Tair (Redis-compatible)
Kafka Cloud Kafka (CKafka) MSK Managed Service for Apache Kafka ApsaraMQ for Kafka
DB migration/sync Data Transmission Service (DTS) DMS Database Migration Service / Datastream DTS
IAM Cloud Access Management (CAM) IAM IAM RAM
Organization Tencent Cloud Organization (TCO) Organizations Resource Manager (organization, folders) Resource Directory
Workforce SSO TCO Identity Center (CIC) IAM Identity Center Workforce Identity Federation CloudSSO
Landing zone Control Center Control Tower Fabric FAST / Google Cloud Setup Agentic Cloud Governance Center
Config compliance Config AWS Config Cloud Asset Inventory Cloud Config
API audit CloudAudit CloudTrail Cloud Audit Logs ActionTrail
Metrics / alarms Cloud Monitor (API namespace monitor) CloudWatch Cloud Monitoring CloudMonitor
Logs Cloud Log Service (CLS) CloudWatch Logs Cloud Logging Simple Log Service (SLS)
Event bus EventBridge EventBridge Eventarc EventBridge
Key management Key Management Service (KMS) KMS Cloud KMS KMS
Network firewall Cloud Firewall (CFW) Network Firewall Cloud NGFW Cloud Firewall
WAF Web Application Firewall (WAF) WAF Cloud Armor WAF
DDoS Anti-DDoS Basic / Pro / Advanced Shield / Shield Advanced Cloud Armor Anti-DDoS Origin / Pro
Posture / threats Cloud Security Center Security Hub + GuardDuty Security Command Center Security Center
Data security Data Security Governance Center (DSGC) Macie (partly) Sensitive Data Protection Data Security Center
ML platform TI Platform (TI) SageMaker Vertex AI PAI
Foundation models Hunyuan models, Agent Development Platform (ADP) Bedrock Vertex AI / Gemini Model Studio (Qwen)

Tencent Cloud Organization (TCO) Feature Reference

Feature What it does API (tccli organization ...) Terraform resource
Organization and departments (OUs) Tree of department nodes under a root CreateOrganization, AddOrganizationNode, DescribeOrganizationNodes tencentcloud_organization_instance, tencentcloud_organization_org_node
Member accounts Create new or invite existing accounts. Financial relationship (PolicyType=Financial) with permission IDs such as view bills and view balance CreateOrganizationMember, InviteOrganizationMember, MoveOrganizationNodeMembers tencentcloud_organization_org_member
Member access identities Roles the management account uses to log in to members CreateOrganizationIdentity, CreateOrganizationMemberAuthIdentity tencentcloud_organization_org_identity, tencentcloud_organization_org_member_auth_identity_attachment
Service control policies (SCP) Allow-list guardrails on departments or members. CAM policy syntax EnablePolicyType, CreatePolicy, AttachPolicy (Type=SERVICE_CONTROL_POLICY) tencentcloud_organization_org_manage_policy, ..._policy_config, ..._policy_target
Tag policies Standardize tag keys and values. Report non-compliant resources Same calls with Type=TAG_POLICY, plus ListNonCompliantResource Same resources
Identity Center (CIC) Workforce users and groups, SAML 2.0 IdP, SCIM sync, permission sets ("role configurations") assigned to member accounts OpenIdentityCenter, CreateUser, CreateGroup, SetExternalSAMLIdentityProvider, CreateSCIMCredential, CreateRoleConfiguration, CreateRoleAssignment tencentcloud_identity_center_*
Resource sharing Share resources (for example VPC subnets) to members through share units AddShareUnit, AddShareUnitMembers, AddShareUnitResources tencentcloud_organization_org_share_unit*
Trusted-service admins Delegate a member as administrator of an integrated service CreateOrgServiceAssign, ListOrganizationService tencentcloud_organization_service_assign
Consolidated finance Bills by member, product, and month DescribeOrganizationFinancialByMember, ...ByProduct, ...ByMonth tencentcloud_organization_org_financial_by_* (data sources)

SCP evaluation facts (Enabling Service Control Policy):

  • The root, every department, and every member start with the system FullAccess policy attached.
  • SCPs are default deny. An action is allowed only when an allow exists at every level from the root to the member.
  • A deny attached at any level is inherited downward and cannot be overridden below.
  • SCPs only limit what CAM can grant inside a member account. They never grant permissions.

CAM Reference

Identity Description
Root account Owns all resources and billing. Use it only for account-level tasks
Sub-user Created and fully owned by the root account. Console login and/or API keys. Most common identity for people and tools
Collaborator An existing Tencent Cloud root account added to another account. Keeps its own identity
Message recipient Receives notifications only. No console or API access
Role Virtual identity with temporary credentials. Assumed by services, sub-users, other accounts, SAML or OIDC IdPs
Policy element Values / notes
version "2.0"
statement[].effect allow or deny. An explicit deny wins
statement[].action <service>:<Action>, for example cvm:DescribeInstances. Wildcards allowed
statement[].resource Six-segment resource description: qcs::<service>:<region>:uin/<uin>:<resource-type>/<id>
statement[].condition Operators such as string_equal, ip_equal, for_any_value:string_equal, with keys such as qcs:resource_tag/<key> and qcs:ip
Federation Role SSO with SAML 2.0 or OIDC IdPs. User SSO (SAML) for sub-users. Multi-account SSO through TCO Identity Center

Networking Facts

Item Value Source / caveat
VPC CIDR ranges 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 sub-ranges. Mask 12-28 (16-28 for 192.168) VPC docs. CIDR cannot be changed after creation. Add a secondary CIDR to grow
Reserved subnet IPs First two and last address of each subnet VPC docs, as of 2026-04
Security group rules 100 inbound + 100 outbound per group (default quota) As of 2026-04, not re-verified. Check the VPC "Limits" page
CCN same-region bandwidth First 5 Gbps free (same account or cross-account). Ticket for more CCN Billing Overview
CCN cross-region billing Pay-as-you-go by monthly 95th percentile of peak bandwidth x valid-day ratio x tiered unit price. Billed on the 1st of the next month Same page
CCN service levels Platinum, Gold, Silver (quality tiers for cross-region traffic) Same page
CCN instance and traffic fees Hourly "connected network instance fee" per attached VPC/DC/VPN gateway, plus an inbound traffic processing fee. Billed since 2023-07-03 Same page. Check current unit prices before you budget
Cross-border CCN (mainland China to overseas) Separate cross-border billing. Prices for links between regions outside mainland China come from sales Same page
GAAP 50+ nodes (product page), up to 10 Gbps and 1 million concurrent requests per connection. TCP/UDP/HTTP/HTTPS GAAP product page

Security Product Tiers

Anti-DDoS

Tier Protection Scope Pricing
Anti-DDoS Basic 2 Gbps free (the earlier note said "up to 10 Gbps" in some regions, unverified) Auto-enabled on Tencent Cloud public IPs Free
Anti-DDoS Pro Base + elastic protection Tencent Cloud resources only (CVM, CLB, WAF, NAT Gateway, Lighthouse). No IP change Base monthly + elastic
Anti-DDoS Advanced Over 900 Gbps per node in China, up to 400 Gbps per node outside China Any Internet service. Hides the origin IP behind a high-defense IP Base monthly + elastic + service bandwidth
EdgeOne 25 Tbps dedicated mitigation (vendor figure), Anycast outside mainland China Sites and apps behind EdgeOne Plans from Free upward (pricing)

Cloud Firewall (CFW) Editions

Edition Capabilities
Premium Internet (perimeter) firewall ACLs, IPS, virtual patching, NAT firewall with integrated NAT
Enterprise Premium + inter-VPC firewall (east-west between VPCs over CCN or peering)
Ultimate Enterprise + advanced threat tracing. Network logs kept up to six months

Other Security Services

Service Key facts
WAF SaaS (CNAME) mode or CLB-integrated mode. OWASP Top 10, CC (HTTP flood) protection, bot management, API protection
KMS Keys held in FIPS 140-2 Level 3 validated HSMs. Symmetric (AES-256, SM4) and asymmetric (RSA-2048, SM2) keys. Automatic rotation. Integrates with COS, CBS, CDB (TDE), TDSQL, CLS
CloudAudit Event history covers the last 90 days. Tracking sets deliver events to COS, CLS, or CKafka. TrackForAllMembers=1 on a tracking set in the TCO management (or delegated) account collects member-account events. Free. You pay only for the destination storage
Config Resource recorder, managed and custom rules, compliance packs, remediation. Terraform resources tencentcloud_config_* since provider 1.82.86 (2026-04-14)

Database HA Facts

Product HA / DR facts
CDB (TencentDB for MySQL) Two-node (source + replica, async or semi-sync), three-node (two replicas, can span AZs), Cluster Edition. TXSQL kernel. Vendor figures: 99.9996% data reliability, 99.95% availability. Remote DR instances synced over the private network
TDSQL-C Compute-storage separation. MySQL and PostgreSQL editions, serverless compute, multi-AZ storage
TDSQL for MySQL Sharded distributed MySQL. Strong sync replication (MAR). 1-region-2-DC and 2-region-3-DC deployments
TencentDB for Redis Multi-AZ replica placement (up to 6 AZs, as of 2026-04, unverified). Read-local routing
COS Multi-AZ (MAZ) storage classes. Cross-region replication needs versioning on both buckets

Kubernetes (TKE) Facts

Item Value
Version policy Only even-numbered Kubernetes minor versions since 2018-09-24. Version string x.y.z-tke.n
Support window Up to 27 months per minor version (18 + 6 + 3) (maintenance mechanism)
Newest version The TKE major-version update notes cover versions up to 1.34 (checked 2026-09). Confirm with tccli tke DescribeVersions
Upgrades One minor version at a time. Control plane first, then nodes
Node types CVM nodes in node pools, native nodes, super nodes (serverless AZ-level capacity), serverless node pools. TKE Serverless clusters have no nodes to manage

Compliance Facts

Item Detail
Certifications (vendor claims) ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, CSA STAR, China MLPS Level 3, Singapore MTCS Level 3, Korea CSAP. Check the Compliance Center for current scope per region
China Cybersecurity Law Effective 2017-06-01. Network logs kept at least six months. Data localization for CII operators
PIPL / DSL Personal Information Protection Law and Data Security Law govern cross-border transfers from mainland regions
MLPS 2.0 GB/T 22239-2019 baseline
MLPS level Scope Tencent Cloud services commonly used
Level 2 General business systems Cloud Firewall, CAM, CloudAudit, security-group hardening
Level 3 Important business systems Level 2 + KMS/TDE, WAF, Anti-DDoS Pro, Bastion Host, logs kept 180 days or more
Level 4 Critical systems Level 3 + dedicated or isolated infrastructure and third-party audit support. Specific Tencent offering TBD

Sources