Tencent Cloud Reference
What this page holds
Look-up facts for Tencent Cloud (international site): tooling versions, region IDs and footprint, service-name
mappings to AWS, Google Cloud, and Alibaba Cloud, multi-account (TCO) features and their API/Terraform names,
CCN billing rules, security-product tiers, published limits, and compliance facts. Why the services work the
way they do is in Explanation. Commands are in How-to Guides.
| Tool |
Latest version |
Date |
Notes |
Terraform provider tencentcloudstack/tencentcloud |
1.83.33 |
2026-09-21 |
Releases several times a week. MPL-2.0 (CHANGELOG) |
tccli (Tencent Cloud CLI) |
3.1.174.1 |
2026-09-24 |
Python, installs with pip install tccli. Apache-2.0 (PyPI) |
tencentcloud-sdk-python |
3.1.181 |
2026-09-24 |
tccli depends on it and upgrades it automatically (PyPI) |
| Landing-zone Terraform modules |
tencentcloud-landing-zone-booster |
2025-2026 |
Terraform modules and components for a network hub, a logging account, and CAM/SSO baselines. Apache-2.0 (repo) |
Provider authentication modes (from the provider docs): static keys, environment variables
(TENCENTCLOUD_SECRET_ID, TENCENTCLOUD_SECRET_KEY, TENCENTCLOUD_REGION), assume_role (1.33.1+),
assume_role_with_saml and assume_role_with_web_identity (1.81.111+), cam_role_name for a CVM instance role
and enable_pod_oidc for TKE pods (1.81.117+), and shared credentials from ~/.tccli. The default region is
ap-guangzhou.
Tencent's own count changes with each announcement. The figures differ in whether they include AZs announced but not
yet open.
| Date |
Regions |
AZs |
Source statement |
| 2025-04-15 |
21 |
56 |
Osaka announcement ("service network covering 21 geographical regions and 56 availability zones") |
| 2026-03-02 |
22 |
64 |
Frankfurt AZ-3 announcement at MWC 2026 |
| 2026-08-18 |
23 |
66 |
Malaysia (Johor) region announcement. "Tencent Cloud International's existing global network" |
Conflicting counts
Some secondary sources quote "70 availability zones across 25 (or 26) regions". That figure dates from 2023 and
appears to include partner-operated locations. Use the dated Tencent statements above and check the live
Global Infrastructure page before you quote a number.
Region IDs
Region IDs come from the SDK region constants
(tencentcloud-sdk-go-intl-en).
That list is not updated for every launch. Newer regions have no confirmed ID here. Run tccli cvm DescribeRegions
against your account for the authoritative list.
Mainland China
| Region |
Region ID |
Notes |
| Beijing |
ap-beijing |
|
| Shanghai |
ap-shanghai |
|
| Shanghai Finance |
ap-shanghai-fsi |
Isolated financial-services zone, needs approval |
| Guangzhou |
ap-guangzhou |
Default region of tccli examples and the Terraform provider |
| Shenzhen Finance |
ap-shenzhen-fsi |
Isolated financial-services zone, needs approval |
| Nanjing |
ap-nanjing |
|
| Chengdu |
ap-chengdu |
|
| Chongqing |
ap-chongqing |
|
International
| Region |
Region ID |
AZs |
Status / notes |
| Hong Kong (China) |
ap-hongkong |
TBD |
Separate from mainland regulation |
| Singapore |
ap-singapore |
TBD |
Main Southeast Asia hub |
| Jakarta |
ap-jakarta |
3 |
Third AZ added in 2025 (Tencent statement, 2026-03-02) |
| Bangkok |
ap-bangkok |
TBD |
|
| Johor (Malaysia) |
TBD |
2, third planned |
First Malaysian region. Two AZs live in the week of 2026-08-18 |
| Seoul |
ap-seoul |
TBD |
|
| Tokyo |
ap-tokyo |
2 |
Second AZ added in 2021 |
| Osaka |
TBD |
1 planned |
Announced 2025-04-15 as Japan's third AZ, launch scheduled for 2026. Live status TBD |
| Mumbai |
ap-mumbai |
TBD |
In the SDK list. Availability to new customers TBD |
| Riyadh area (Saudi Arabia) |
TBD |
2 |
First Middle East region, announced 2025-02-10 at LEAP 2025. Over USD 150M investment planned |
| Frankfurt |
eu-frankfurt |
3 |
AZ-3 announced 2026-03-02, open to customers from Q2 2026 |
| Moscow |
eu-moscow |
TBD |
In the SDK list. Availability to new customers TBD |
| Silicon Valley |
na-siliconvalley |
TBD |
|
| Virginia (Ashburn) |
na-ashburn |
TBD |
Shown as "Virginia" in the console |
| Toronto |
na-toronto |
TBD |
|
| Sao Paulo |
sa-saopaulo |
TBD |
Only South America region |
AZ IDs follow the <region-id>-<n> pattern (for example ap-guangzhou-3). Numbers are not contiguous.
tccli cvm DescribeZones --region <id> lists the zones your account can use.
Service Name Mapping
The table gives the closest equivalent, not feature parity. The Tencent abbreviation is the name you see in API
namespaces (tccli <namespace> ...) and Terraform resource prefixes.
| Category |
Tencent Cloud (abbrev.) |
AWS |
Google Cloud |
Alibaba Cloud |
| VM |
Cloud Virtual Machine (CVM) |
EC2 |
Compute Engine |
ECS |
| Simple VPS |
Lighthouse |
Lightsail |
-- |
Simple Application Server |
| Bare metal |
Cloud Physical Machine (CPM) |
EC2 bare metal |
Bare Metal Solution |
ECS Bare Metal |
| Auto scaling |
Auto Scaling (AS) |
EC2 Auto Scaling |
Managed instance groups |
Auto Scaling (ESS) |
| Functions |
Serverless Cloud Function (SCF) |
Lambda |
Cloud Run functions |
Function Compute |
| Kubernetes |
Tencent Kubernetes Engine (TKE) |
EKS |
GKE |
ACK |
| Container registry |
Tencent Container Registry (TCR) |
ECR |
Artifact Registry |
ACR |
| Virtual network |
VPC |
VPC |
VPC |
VPC |
| Transit / WAN |
Cloud Connect Network (CCN) |
Transit Gateway / Cloud WAN |
Network Connectivity Center |
CEN + Transit Router |
| VPC peering |
Peering Connection |
VPC Peering |
VPC Network Peering |
VPC peering connection |
| Dedicated line |
Direct Connect (DC) |
Direct Connect |
Cloud Interconnect |
Express Connect |
| VPN |
VPN Gateway |
Site-to-Site VPN |
Cloud VPN |
VPN Gateway |
| Load balancer |
Cloud Load Balancer (CLB) |
ELB (ALB/NLB) |
Cloud Load Balancing |
ALB / NLB / CLB |
| NAT |
NAT Gateway |
NAT Gateway |
Cloud NAT |
NAT Gateway |
| Global acceleration |
Global Application Acceleration Platform (GAAP) |
Global Accelerator |
Premium Tier network |
Global Accelerator |
| DNS |
DNSPod / Private DNS |
Route 53 |
Cloud DNS |
Alibaba Cloud DNS |
| CDN + edge security |
EdgeOne, CDN |
CloudFront + Shield + WAF |
Cloud CDN + Cloud Armor |
CDN / ESA |
| Object storage |
Cloud Object Storage (COS) |
S3 |
Cloud Storage |
OSS |
| Block storage |
Cloud Block Storage (CBS) |
EBS |
Persistent Disk / Hyperdisk |
Block storage (ESSD) |
| File storage |
Cloud File Storage (CFS) |
EFS |
Filestore |
NAS |
| Managed MySQL |
TencentDB for MySQL (CDB) |
RDS for MySQL |
Cloud SQL for MySQL |
ApsaraDB RDS for MySQL |
| Cloud-native MySQL/PG |
TDSQL-C (formerly CynosDB) |
Aurora |
AlloyDB (PostgreSQL) |
PolarDB |
| Distributed MySQL |
TDSQL for MySQL (API namespace dcdb) |
-- |
Spanner (loosely) |
PolarDB-X |
| MariaDB |
TencentDB for MariaDB (API namespace mariadb) |
RDS for MariaDB |
-- |
-- |
| Redis |
TencentDB for Redis |
ElastiCache |
Memorystore |
Tair (Redis-compatible) |
| Kafka |
Cloud Kafka (CKafka) |
MSK |
Managed Service for Apache Kafka |
ApsaraMQ for Kafka |
| DB migration/sync |
Data Transmission Service (DTS) |
DMS |
Database Migration Service / Datastream |
DTS |
| IAM |
Cloud Access Management (CAM) |
IAM |
IAM |
RAM |
| Organization |
Tencent Cloud Organization (TCO) |
Organizations |
Resource Manager (organization, folders) |
Resource Directory |
| Workforce SSO |
TCO Identity Center (CIC) |
IAM Identity Center |
Workforce Identity Federation |
CloudSSO |
| Landing zone |
Control Center |
Control Tower |
Fabric FAST / Google Cloud Setup |
Agentic Cloud Governance Center |
| Config compliance |
Config |
AWS Config |
Cloud Asset Inventory |
Cloud Config |
| API audit |
CloudAudit |
CloudTrail |
Cloud Audit Logs |
ActionTrail |
| Metrics / alarms |
Cloud Monitor (API namespace monitor) |
CloudWatch |
Cloud Monitoring |
CloudMonitor |
| Logs |
Cloud Log Service (CLS) |
CloudWatch Logs |
Cloud Logging |
Simple Log Service (SLS) |
| Event bus |
EventBridge |
EventBridge |
Eventarc |
EventBridge |
| Key management |
Key Management Service (KMS) |
KMS |
Cloud KMS |
KMS |
| Network firewall |
Cloud Firewall (CFW) |
Network Firewall |
Cloud NGFW |
Cloud Firewall |
| WAF |
Web Application Firewall (WAF) |
WAF |
Cloud Armor |
WAF |
| DDoS |
Anti-DDoS Basic / Pro / Advanced |
Shield / Shield Advanced |
Cloud Armor |
Anti-DDoS Origin / Pro |
| Posture / threats |
Cloud Security Center |
Security Hub + GuardDuty |
Security Command Center |
Security Center |
| Data security |
Data Security Governance Center (DSGC) |
Macie (partly) |
Sensitive Data Protection |
Data Security Center |
| ML platform |
TI Platform (TI) |
SageMaker |
Vertex AI |
PAI |
| Foundation models |
Hunyuan models, Agent Development Platform (ADP) |
Bedrock |
Vertex AI / Gemini |
Model Studio (Qwen) |
Tencent Cloud Organization (TCO) Feature Reference
| Feature |
What it does |
API (tccli organization ...) |
Terraform resource |
| Organization and departments (OUs) |
Tree of department nodes under a root |
CreateOrganization, AddOrganizationNode, DescribeOrganizationNodes |
tencentcloud_organization_instance, tencentcloud_organization_org_node |
| Member accounts |
Create new or invite existing accounts. Financial relationship (PolicyType=Financial) with permission IDs such as view bills and view balance |
CreateOrganizationMember, InviteOrganizationMember, MoveOrganizationNodeMembers |
tencentcloud_organization_org_member |
| Member access identities |
Roles the management account uses to log in to members |
CreateOrganizationIdentity, CreateOrganizationMemberAuthIdentity |
tencentcloud_organization_org_identity, tencentcloud_organization_org_member_auth_identity_attachment |
| Service control policies (SCP) |
Allow-list guardrails on departments or members. CAM policy syntax |
EnablePolicyType, CreatePolicy, AttachPolicy (Type=SERVICE_CONTROL_POLICY) |
tencentcloud_organization_org_manage_policy, ..._policy_config, ..._policy_target |
| Tag policies |
Standardize tag keys and values. Report non-compliant resources |
Same calls with Type=TAG_POLICY, plus ListNonCompliantResource |
Same resources |
| Identity Center (CIC) |
Workforce users and groups, SAML 2.0 IdP, SCIM sync, permission sets ("role configurations") assigned to member accounts |
OpenIdentityCenter, CreateUser, CreateGroup, SetExternalSAMLIdentityProvider, CreateSCIMCredential, CreateRoleConfiguration, CreateRoleAssignment |
tencentcloud_identity_center_* |
| Resource sharing |
Share resources (for example VPC subnets) to members through share units |
AddShareUnit, AddShareUnitMembers, AddShareUnitResources |
tencentcloud_organization_org_share_unit* |
| Trusted-service admins |
Delegate a member as administrator of an integrated service |
CreateOrgServiceAssign, ListOrganizationService |
tencentcloud_organization_service_assign |
| Consolidated finance |
Bills by member, product, and month |
DescribeOrganizationFinancialByMember, ...ByProduct, ...ByMonth |
tencentcloud_organization_org_financial_by_* (data sources) |
SCP evaluation facts (Enabling Service Control Policy):
- The root, every department, and every member start with the system
FullAccess policy attached.
- SCPs are default deny. An action is allowed only when an allow exists at every level from the root to the member.
- A deny attached at any level is inherited downward and cannot be overridden below.
- SCPs only limit what CAM can grant inside a member account. They never grant permissions.
CAM Reference
| Identity |
Description |
| Root account |
Owns all resources and billing. Use it only for account-level tasks |
| Sub-user |
Created and fully owned by the root account. Console login and/or API keys. Most common identity for people and tools |
| Collaborator |
An existing Tencent Cloud root account added to another account. Keeps its own identity |
| Message recipient |
Receives notifications only. No console or API access |
| Role |
Virtual identity with temporary credentials. Assumed by services, sub-users, other accounts, SAML or OIDC IdPs |
| Policy element |
Values / notes |
version |
"2.0" |
statement[].effect |
allow or deny. An explicit deny wins |
statement[].action |
<service>:<Action>, for example cvm:DescribeInstances. Wildcards allowed |
statement[].resource |
Six-segment resource description: qcs::<service>:<region>:uin/<uin>:<resource-type>/<id> |
statement[].condition |
Operators such as string_equal, ip_equal, for_any_value:string_equal, with keys such as qcs:resource_tag/<key> and qcs:ip |
| Federation |
Role SSO with SAML 2.0 or OIDC IdPs. User SSO (SAML) for sub-users. Multi-account SSO through TCO Identity Center |
Networking Facts
| Item |
Value |
Source / caveat |
| VPC CIDR ranges |
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 sub-ranges. Mask 12-28 (16-28 for 192.168) |
VPC docs. CIDR cannot be changed after creation. Add a secondary CIDR to grow |
| Reserved subnet IPs |
First two and last address of each subnet |
VPC docs, as of 2026-04 |
| Security group rules |
100 inbound + 100 outbound per group (default quota) |
As of 2026-04, not re-verified. Check the VPC "Limits" page |
| CCN same-region bandwidth |
First 5 Gbps free (same account or cross-account). Ticket for more |
CCN Billing Overview |
| CCN cross-region billing |
Pay-as-you-go by monthly 95th percentile of peak bandwidth x valid-day ratio x tiered unit price. Billed on the 1st of the next month |
Same page |
| CCN service levels |
Platinum, Gold, Silver (quality tiers for cross-region traffic) |
Same page |
| CCN instance and traffic fees |
Hourly "connected network instance fee" per attached VPC/DC/VPN gateway, plus an inbound traffic processing fee. Billed since 2023-07-03 |
Same page. Check current unit prices before you budget |
| Cross-border CCN (mainland China to overseas) |
Separate cross-border billing. Prices for links between regions outside mainland China come from sales |
Same page |
| GAAP |
50+ nodes (product page), up to 10 Gbps and 1 million concurrent requests per connection. TCP/UDP/HTTP/HTTPS |
GAAP product page |
Security Product Tiers
Anti-DDoS
| Tier |
Protection |
Scope |
Pricing |
| Anti-DDoS Basic |
2 Gbps free (the earlier note said "up to 10 Gbps" in some regions, unverified) |
Auto-enabled on Tencent Cloud public IPs |
Free |
| Anti-DDoS Pro |
Base + elastic protection |
Tencent Cloud resources only (CVM, CLB, WAF, NAT Gateway, Lighthouse). No IP change |
Base monthly + elastic |
| Anti-DDoS Advanced |
Over 900 Gbps per node in China, up to 400 Gbps per node outside China |
Any Internet service. Hides the origin IP behind a high-defense IP |
Base monthly + elastic + service bandwidth |
| EdgeOne |
25 Tbps dedicated mitigation (vendor figure), Anycast outside mainland China |
Sites and apps behind EdgeOne |
Plans from Free upward (pricing) |
Cloud Firewall (CFW) Editions
| Edition |
Capabilities |
| Premium |
Internet (perimeter) firewall ACLs, IPS, virtual patching, NAT firewall with integrated NAT |
| Enterprise |
Premium + inter-VPC firewall (east-west between VPCs over CCN or peering) |
| Ultimate |
Enterprise + advanced threat tracing. Network logs kept up to six months |
Other Security Services
| Service |
Key facts |
| WAF |
SaaS (CNAME) mode or CLB-integrated mode. OWASP Top 10, CC (HTTP flood) protection, bot management, API protection |
| KMS |
Keys held in FIPS 140-2 Level 3 validated HSMs. Symmetric (AES-256, SM4) and asymmetric (RSA-2048, SM2) keys. Automatic rotation. Integrates with COS, CBS, CDB (TDE), TDSQL, CLS |
| CloudAudit |
Event history covers the last 90 days. Tracking sets deliver events to COS, CLS, or CKafka. TrackForAllMembers=1 on a tracking set in the TCO management (or delegated) account collects member-account events. Free. You pay only for the destination storage |
| Config |
Resource recorder, managed and custom rules, compliance packs, remediation. Terraform resources tencentcloud_config_* since provider 1.82.86 (2026-04-14) |
Database HA Facts
| Product |
HA / DR facts |
| CDB (TencentDB for MySQL) |
Two-node (source + replica, async or semi-sync), three-node (two replicas, can span AZs), Cluster Edition. TXSQL kernel. Vendor figures: 99.9996% data reliability, 99.95% availability. Remote DR instances synced over the private network |
| TDSQL-C |
Compute-storage separation. MySQL and PostgreSQL editions, serverless compute, multi-AZ storage |
| TDSQL for MySQL |
Sharded distributed MySQL. Strong sync replication (MAR). 1-region-2-DC and 2-region-3-DC deployments |
| TencentDB for Redis |
Multi-AZ replica placement (up to 6 AZs, as of 2026-04, unverified). Read-local routing |
| COS |
Multi-AZ (MAZ) storage classes. Cross-region replication needs versioning on both buckets |
Kubernetes (TKE) Facts
| Item |
Value |
| Version policy |
Only even-numbered Kubernetes minor versions since 2018-09-24. Version string x.y.z-tke.n |
| Support window |
Up to 27 months per minor version (18 + 6 + 3) (maintenance mechanism) |
| Newest version |
The TKE major-version update notes cover versions up to 1.34 (checked 2026-09). Confirm with tccli tke DescribeVersions |
| Upgrades |
One minor version at a time. Control plane first, then nodes |
| Node types |
CVM nodes in node pools, native nodes, super nodes (serverless AZ-level capacity), serverless node pools. TKE Serverless clusters have no nodes to manage |
Compliance Facts
| Item |
Detail |
| Certifications (vendor claims) |
ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, CSA STAR, China MLPS Level 3, Singapore MTCS Level 3, Korea CSAP. Check the Compliance Center for current scope per region |
| China Cybersecurity Law |
Effective 2017-06-01. Network logs kept at least six months. Data localization for CII operators |
| PIPL / DSL |
Personal Information Protection Law and Data Security Law govern cross-border transfers from mainland regions |
| MLPS 2.0 |
GB/T 22239-2019 baseline |
| MLPS level |
Scope |
Tencent Cloud services commonly used |
| Level 2 |
General business systems |
Cloud Firewall, CAM, CloudAudit, security-group hardening |
| Level 3 |
Important business systems |
Level 2 + KMS/TDE, WAF, Anti-DDoS Pro, Bastion Host, logs kept 180 days or more |
| Level 4 |
Critical systems |
Level 3 + dedicated or isolated infrastructure and third-party audit support. Specific Tencent offering TBD |
Sources