Skip to content

Tenant-Cloud Auth ​

Feature Overview ​

ItemContent
Applicable RolesOperators
Navigation PathAI Infra(On-Cloud) > Authorization Management > Tenant-Cloud Auth
Page Route/infrahub/op/auth/platform-auth
Managed ObjectsUsage authorization between tenants and cloud platforms

Beginner Explanation ​

Tenant-Cloud Auth grants a tenant access to a cloud platform. Authorized tenants can become eligible to see platform resources; removing authorization withdraws that scope.

Terminology ​

TermDescription
Single-Tenant AuthorizationGrants the selected cloud platform to one tenant.
Authorize All TenantsGrants the selected cloud platform to all tenants.
Authorization RelationshipA saved availability relationship between a tenant and a cloud platform.

Review existing relationships, add authorization, edit when scope changes, and check tenant deployments and business dependencies before deletion.

Beginner Checklist ​

ScenarioDo FirstDo Not Do Directly
First visitReview existing objects, states, and available actionsChange an unknown object
Before a changeVerify upstream dependencies, impact scope, and target objectSkip dependency and impact checks
After completionValidate the current and downstream pages with Result ValidationRely only on a success message
Page errorRecord the redacted object, time, and page messageSubmit repeatedly or record real credentials

Prerequisites ​

  1. The current account has the permission required for Tenant-Cloud Auth.
  2. The target cloud platform and tenant exist, and the authorization boundary is approved.
  3. Before changing authorization, confirm tenant deployments, business visibility, and revocation arrangements.

Page Description ​

The page shows tenant names, authorized cloud platforms, and add, edit, and delete actions.

Page screenshots:

Tenant-Cloud Auth page

The image shows the Tenant-Cloud Authorization list page, listing tenant names, tenant IDs, authorized cloud platforms, with tenant search, add authorization, and row-level edit/delete actions.

Main Operations ​

Add Tenant-Cloud Authorization ​

  1. Click "Add Tenant-Cloud Auth".
  2. Select a cloud platform.
  3. Select Single-Tenant Authorization or Authorize All Tenants; select the target tenant for single-tenant mode.
  4. Verify the scope and click "Confirm".

Add tenant authorization

The image shows the Add Tenant-Cloud Authorization dialog, where you select the cloud platform, authorization mode (single tenant or all tenants), and pick the target tenant.

Edit Tenant-Cloud Authorization ​

  1. Click "Edit" on the target record.
  2. Verify the cloud platform, authorization mode, and tenant scope.
  3. Save and verify the updated relationship in the list.

Edit tenant authorization

The image shows the Edit Tenant-Cloud Authorization dialog, where you can verify or adjust the cloud platform authorization scope for the selected tenant.

Delete Tenant-Cloud Authorization ​

  1. Confirm that the tenant no longer depends on the cloud platform.
  2. Click "Delete" and verify the target record.
  3. After confirmation, check the list and tenant-side visibility.

Delete tenant authorization

The image shows the secondary confirmation dialog for deleting a tenant-cloud authorization, which revokes the tenant's access permissions to the specified cloud platform.

Parameter Reference ​

Field NameRequiredField TypeExampleDescription
Tenant NameNoTextSample TenantFilters authorization records by tenant name. Do not enter a real customer name in examples.
Tenant IDNoText/Number1000000000000000Filters authorization records by tenant identifier. The example value is for documentation only.
Authorized Cloud PlatformsYesList/Multiple valuesAlibaba CloudDisplays or selects the cloud platform scope available to the tenant.
Select Cloud PlatformYesDropdownAlibaba CloudSelects the cloud platform to authorize when adding authorization.
Authorization ModeYesRadioAuthorize a Single TenantSelects whether to authorize one tenant or all tenants.
Select TenantConditionally requiredDropdownSample TenantRequired when Authorize a Single Tenant is selected.
SearchNoButtonSearchQueries authorization records with the current filters.
ResetNoButtonResetClears filters and restores the list display.
PaginationNoPage control10/pageOpens additional list pages without modifying authorization records.
EditNoAction entryEditModifies an existing authorization. Confirm the impact scope before editing.
DeleteNoAction entryDeleteDeletes authorization and may affect tenant resource availability. Use with caution.
CancelNoButtonCancelCloses the dialog without saving the current configuration.
ConfirmYesButtonConfirmSubmits the authorization configuration. Review carefully before clicking.

Pitfalls ​

  • Do not skip the upstream dependency check: The target cloud platform and tenant exist, and the authorization boundary is approved.
  • Confirm impact before a configuration change: Before changing authorization, confirm tenant deployments, business visibility, and revocation arrangements.
  • A success message does not prove downstream synchronization. Use Result Validation afterward.
  • Use only <API_KEY>, <PERSONAL_KEY>, <ACCESS_KEY_ID>, <ACCESS_KEY_SECRET>, <BASE_URL>, and <ENDPOINT_PATH> for credential and endpoint examples.

Result Validation ​

Check ItemSuccess SignalIf Abnormal
Page is accessibleTitle, navigation, and main content display correctlyCheck role permission and navigation path
Managed objects are visibleUsage authorization between tenants and cloud platforms display as expectedClear filters and verify upstream dependencies
Operation result is savedThe expected state or new record appearsReview page messages, required fields, and dependencies
Downstream result is consistentAssociated pages show the changeWait for synchronization, refresh, and return to the responsible object

FAQ ​

Target Object Is Missing in Tenant-Cloud Auth ​

Symptom:

The expected object is missing from the list or selector.

Possible Causes:

  • Active query criteria filter out the target object.
  • An upstream object is disabled, or the current role lacks visibility.

Resolution:

  1. Clear filters and refresh the page.
  2. Verify the prerequisite object: The target cloud platform and tenant exist, and the authorization boundary is approved.
  3. Confirm the current role and data scope, then locate the object again.

Tenant-Cloud Auth Action Is Unavailable ​

Symptom:

An expected button, menu, or state switch is unavailable.

Possible Causes:

  • The current account lacks the required action permission.
  • Object state, references, or prerequisites block the action.

Resolution:

  1. Verify the permission for the action and the current object state.
  2. Check references and prerequisites identified by the page message.
  3. Remove the blocker, refresh the page, and perform the action once.

Tenant-Cloud Auth Change Does Not Reach Downstream ​

Symptom:

The page reports success, but a downstream page still shows the old state.

Possible Causes:

  • An associated page has stale cache or synchronization delay.
  • The current and downstream pages use different roles, tenants, or data scopes.

Resolution:

  1. Wait for synchronization and refresh both pages.
  2. Confirm that both pages use the same role, tenant, and object scope.
  3. If they still differ, return to the responsible object and verify the saved result.

Tenant-Cloud Auth Data Differs from Another Page ​

Symptom:

Counts or states differ from an associated page.

Possible Causes:

  • The pages use different filters, aggregation rules, or update times.
  • The change is still synchronizing, or role-based data scopes differ.

Resolution:

  1. Align filters and aggregation rules on both pages.
  2. Check update times and wait for synchronization.
  3. Compare object details instead of summary counts only.

How to Troubleshoot a Tenant-Cloud Auth Failure ​

Symptom:

Submission fails or the state does not change for an extended period.

Possible Causes:

  • Required fields, field combinations, or object state do not meet submission rules.
  • An upstream dependency is invalid, the request failed, or the same action is already processing.

Resolution:

  1. Record the redacted object, time, and complete page message.
  2. Verify required fields, object state, and upstream dependencies.
  3. Confirm that no identical job is processing before one retry.

Notes ​

  • Before changing authorization, confirm tenant deployments, business visibility, and revocation arrangements.
  • Do not put real accounts, credentials, internal locations, or customer data in documentation, screenshots, tickets, or chat records.
  • Authorization, deployment, deletion, publication, state, or billing changes require an auditable record and recovery plan.

Next Steps ​

  1. Continue confirming tenant-available regions on the business-region authorization page.
  2. Check the model deployment or resource selection page from the tenant perspective.
  3. Regularly review configurations such as Authorize All Tenants to avoid overly broad authorization.