For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Alibaba Cloud resource inventory

Understand how Cortex Cloud discovers and inventories Alibaba Cloud resources for security visibility.

The onboarding process creates resources in the customer's Alibaba Cloud account using the Terraform authentication template. All resources are created at the account level.

Resource type
Resource name
Purpose

alicloud_ram_role

CortexPlatformRole

RAM role that Cortex Cloud assumes via OIDC federation. Configured with a trust policy that accepts GCP OIDC tokens with the configured audience.

alicloud_ram_policy

Custom Policy

RAM policy with 46 read-only permissions across ECS, OSS, RAM, RDS, VPC, SLB, ActionTrail, CEN, and NAS services.

alicloud_ram_role_policy_attachment

Policy Attachment

Attaches the custom read-only policy to the CortexPlatformRole.

(OIDC Provider)

OIDC Identity Provider

Alibaba Cloud OIDC identity provider that trusts GCP OIDC tokens issued by Cortex Cloud with the audience alibaba-cortex-wif-<tenantID>.

Last updated

Was this helpful?