Discovery for Alibaba Cloud

  • Release version: Zurich
  • Updated February 1, 2024
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Discovery for Alibaba Cloud

    Discovery for Alibaba Cloud is an automated process within the IT Operations Management (ITOM) Visibility framework that scans and identifies Alibaba Cloud resources in your organization’s cloud infrastructure. It helps maintain an accurate Configuration Management Database (CMDB), which is essential for reliable cloud resource management and operational visibility.

    Show full answer Show less

    This discovery uses pattern-based cloud discovery techniques, leveraging Discovery and Service Mapping Patterns to detect and map cloud resources such as service accounts, datacenters, availability zones, hardware types, and operating system images. It also identifies relationships between resources, enabling comprehensive infrastructure mapping.

    Key Features

    • Pattern-based Discovery: Uses predefined patterns to create configuration items (CIs) and discover relationships across Alibaba Cloud resources.
    • REST API Permissions Verification: A downloadable spreadsheet helps assign the required permissions to users running discovery patterns, listing pattern details and vendor documentation links.
    • Quarterly Pattern Updates: New discovery patterns are released regularly to keep up with Alibaba Cloud changes.
    • Flexible User Permissions: Supports discovery using Alibaba Cloud Root Account, RAM users, and RAM roles with appropriate access levels, typically requiring at least read-only permissions.
    • ServiceNow Integration: Requires installation of specific plugins, credential setup with discoveryadmin roles, and configuration of MID Servers to enable cloud communication and discovery execution.

    Configuration and Roles

    Proper configuration involves steps on both ServiceNow and Alibaba Cloud:

    • ServiceNow Side: Install Discovery and related plugins, assign discoveryadmin roles for API credential creation, configure MID Servers for connectivity, and schedule discovery runs.
    • Alibaba Cloud Side: Set up Identity and Access Management (RAM) roles and assign appropriate permissions (read-only or higher) to users or roles used by the discovery process.

    Different user personas are involved in the configuration and operation:

    • ServiceNow Administrators: Responsible for installing plugins, MID Server setup, validation, and role assignments.
    • Cloud or Discovery Administrators: Manage Alibaba Cloud service accounts and API credentials necessary for discovery.
    • Discovery Administrators: Operate discovery patterns and schedules to collect and update cloud resource data.

    Practical Benefits for ServiceNow Customers

    • Gain an accurate and up-to-date inventory of Alibaba Cloud resources automatically within the CMDB.
    • Understand relationships between cloud components to improve impact analysis and service mapping.
    • Streamline cloud visibility with automated discovery patterns and scheduled scans.
    • Ensure compliance and governance by managing discovery permissions aligned with Alibaba Cloud IAM best practices.
    • Leverage regular pattern updates to stay current with Alibaba Cloud platform changes without manual intervention.

    Alibaba Cloud discovery is one of the overall Cloud discovery offerings within the IT Operations Management (ITOM) Visibility framework. It’s an automated process used to scan and identify Alibaba Cloud resources within your organization's cloud infrastructure. This discovery process is critical for maintaining an accurate and trustworthy data foundation—the Configuration Management Database (CMDB).

    Pattern-based cloud discovery

    Using Discovery and Service Mapping Patterns to perform horizontal discovery enables you to find and map your organization's Alibaba Cloud resources. You can discover Alibaba Cloud metadata including: Cloud service accounts, datacenters, availability zones, and hardware types. Patterns also support OS level discovery, for example OS images.

    Discovery and Service Mapping Patterns create configuration items (CIs) for your Alibaba Cloud resources. Additionally, patterns discover the relationships between your organization's Alibaba Cloud resources, such as Hosted On :: Hosts.

    See Alibaba Cloud discovery using patterns to learn about all Alibaba Cloud resources you can discover using Patterns.

    Verify the REST API Permissions

    Download the Cloud Discovery patterns spreadsheet so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available quarterly, so check periodically to be sure you have the latest version of the spreadsheet.

    Alibaba Cloud discovery configuration

    The basic steps to configure pattern-based discovery for Alibaba Cloud involve preparation on the ServiceNow side like installing necessary plugins and setting up credentials. The discovery_admin role in ServiceNow is required for creating Alibaba Cloud API credentials and service accounts.

    The discovery process requires configuration within Alibaba Cloud, like setting up Identity and Access Management roles. The discovery permissions of Alibaba Cloud users are determined by their access levels within Alibaba Cloud.

    To promote proper discovery, the Alibaba Cloud user must have at least read-only access to the necessary Alibaba Cloud services.

    Table 1. Alibaba Cloud user discovery permissions
    Alibaba Cloud user Discovery permissions
    Root Account (Master Account) Full access to all Alibaba Cloud resources and services, including Elastic Compute Service (ECS), Object Storage Service (OSS), Relational Database Service (RDS), and Resource Access Management (RAM). Can create and manage RAM users, assign permissions, and perform billing operations.
    RAM user Access to specific Alibaba Cloud resources and services based on assigned policies. Can be granted read-only access for discovery purposes.
    RAM Role (AssumedRoleUser) Temporary access to Alibaba Cloud resources and services based on assumed role policies. Useful for cross-account access, temporary access, or access by ECS instances.
    Table 2. Alibaba Cloud discovery users and tasks
    Typical persona Roles and permissions Responsibility Link to detailed documentation
    ServiceNow administrator or IT Implementation Specialist admin Install the store applications and update them on every store release:
    • Discovery
    • Discovery and Service Mapping Patterns
    • Visibility content.
    • CMDB CI Class Models
    • Discovery Admin Workspace
    ITOM Store upgrades
    ServiceNow administrator admin
    • Create a MID Server user.
    • Assign the MID Server role to the user.
    Create the MID Server user and grant the role
    ServiceNow administrator admin, mid_server Install a MID Server.
    ServiceNow administrator admin Validate that the MID Server is installed correctly. Validate the MID Server
    ServiceNow administrator admin Assigning users with discovery_admin roles and giving them permission for discovery. Managing roles
    Cloud administrator or Discovery administrator discovery_admin Creating Alibaba Cloud service accounts Set up Alibaba Cloud service accounts
    Cloud administrator or Discovery administrator The person configuring the API credentials must have the discovery_admin role in ServiceNow and must have access to the Alibaba Cloud Access Key ID and Access Key Secret. Configuring Alibaba Cloud API credentials Create Alibaba Cloud API Credentials
    Discovery administrator discovery_admin Use Discovery and Service Mapping Patterns Alibaba Cloud discovery using patterns
    Discovery administrator discovery_admin Set up a discovery schedule for Alibaba Cloud