---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Discovery for Alibaba Cloud

# Discovery for Alibaba Cloud {#ariaid-title1}

* Release version: Yokohama
* 
* Updated February 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Discovery for Alibaba Cloud

Alibaba Cloud discovery is an automated process within the IT Operations Management (ITOM) Visibility framework that scans and identifies resources in your organization's Alibaba Cloud infrastructure.
This process is essential for maintaining an accurate Configuration Management Database (CMDB).
Show full answer Show less  

## Key Features

* **Pattern-based Cloud Discovery:** Utilizes Discovery and Service Mapping Patterns to identify and map Alibaba Cloud resources, including service accounts, datacenters, availability zones, and OS images.
* **Configuration Items Creation:** Automatically generates configuration items (CIs) for discovered resources, establishing relationships between them, such as the "Hosted On" relationship.
* **REST API Permissions:** A spreadsheet is available for managing user permissions necessary for running discovery patterns, including pattern names, types, and CI classes.
* **Quarterly Updates:** New discovery patterns are released quarterly, ensuring you have the latest capabilities for resource identification.

## Key Outcomes

To configure Alibaba Cloud discovery, follow these steps:

* **Platform Preparation:** Install necessary plugins on the ServiceNow AI Platform and set up API credentials. A discoveryadmin role is required for these tasks.
* **Alibaba Cloud Configuration:** Set up Identity and Access Management roles, ensuring users have at least read-only access to relevant services.
* **User Roles and Responsibilities:** Various roles are outlined, including ServiceNow administrators, cloud administrators, and discovery administrators, each tasked with specific responsibilities like installing MID Servers and managing service accounts.
* **Discovery Schedule:** Establish a discovery schedule in the Discovery Admin Workspace to facilitate ongoing scanning and identification of Alibaba Cloud resources.  
Alibaba Cloud discovery is one of the overall Cloud discovery offerings within the IT Operations Management (ITOM) Visibility framework. It's an automated process used to scan and identify Alibaba Cloud resources within your organization's cloud infrastructure. This discovery process is critical for maintaining an accurate and trustworthy data foundation---the Configuration Management Database
(CMDB).

## Pattern-based cloud discovery {#alibaba-cloud-discovery__supported-resources}

Using Discovery and Service Mapping Patterns to perform horizontal discovery enables you to find and map your organization's Alibaba Cloud resources. You can discover Alibaba Cloud metadata including:

* Cloud service accounts.
* Datacenters.
* Availability zones.
* Hardware types.
{#alibaba-cloud-discovery__ul_zhj_h4t_ghc} Patterns also support OS level discovery, for example OS images.

Discovery and Service Mapping Patterns create configuration items (CIs) for your Alibaba Cloud resources. Additionally, patterns discover the relationships between your organization's Alibaba Cloud resources, such as Hosted On :: Hosts.

See [Alibaba Cloud discovery using patterns](https://servicenow-prod.fluidtopics.net/grY1iKldcbJ4pcPdZKTkyw "Discovery and Service Mapping Patterns uses patterns to discover components of the Alibaba Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.") to learn about all Alibaba Cloud resources you can discover using Patterns.

## Verify the REST API Permissions {#alibaba-cloud-discovery__id_wxp_lh3_chc}

Download the [Cloud Discovery patterns spreadsheet](https://downloads.docs.servicenow.com/resource/enus/api/servicenow-discovery-patterns-api-details.xlsx) so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available
quarterly, so check periodically to be sure you have the latest version of the spreadsheet.{#alibaba-cloud-discovery__cloud-discovery-api-paragraph}

## Alibaba Cloud discovery configuration {#alibaba-cloud-discovery__users}

The basic steps to configure pattern-based discovery for Alibaba Cloud involve preparation on the ServiceNow AI Platform side like installing necessary plugins and setting up credentials. The discovery_admin role in ServiceNow AI Platform is required for creating Alibaba Cloud API credentials and service accounts.

The discovery process requires configuration within Alibaba Cloud, like setting up Identity and Access Management roles. The discovery permissions of Alibaba Cloud users are determined by their access levels within Alibaba Cloud.

To promote proper discovery, the Alibaba Cloud user must have at least read-only access to the necessary Alibaba Cloud services.  
{#alibaba-cloud-discovery__users__entry__2}

| Alibaba Cloud user | Discovery permissions |
|-|-|
| Root Account (Master Account) | Full access to all Alibaba Cloud resources and services, including Elastic Compute Service (ECS), Object Storage Service (OSS), Relational Database Service (RDS), and Resource Access Management (RAM). Can create and manage RAM users, assign permissions, and perform billing operations. |
| RAM user | Access to specific Alibaba Cloud resources and services based on assigned policies. Can be granted read-only access for discovery purposes. |
| RAM Role (AssumedRoleUser) | Temporary access to Alibaba Cloud resources and services based on assumed role policies. Useful for cross-account access, temporary access, or access by ECS instances. |
[Table 1. Alibaba Cloud user discovery permissions]

{#alibaba-cloud-discovery__users__entry__12}

| Typical persona | Roles and permissions | Responsibility | Link to detailed documentation |
|-|-|-|-|
| ServiceNow administrator or IT Implementation Specialist | admin | Install the store applications and update them on every store release: * Discovery * Discovery and Service Mapping Patterns * Visibility content. * CMDB CI Class Models * Discovery Admin Workspace {#alibaba-cloud-discovery__ul_v1n_t4k_dhc} | [ITOM Store upgrades](https://servicenow-prod.fluidtopics.net/KWnGq_ZnxOBhPKBLkb6C7w "To be able to use ITOM at its full capacity, you can deploy the latest out-of-band upgrades from the ServiceNow Store. Learn about features and enhancements available out-of-band.") |
| ServiceNow administrator | admin | * Create a MID Server user. * Assign the MID Server role to the user. {#alibaba-cloud-discovery__ul_nz5_hcn_2hc} | [Create the MID Server user and grant the role](https://www.servicenow.com/docs/access?context=t_SetupMIDServerRole&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US) |
| ServiceNow administrator | admin, mid_server | Install a MID Server. | * [Install a MID Server on Linux](https://www.servicenow.com/docs/access?context=t_InstallAMIDServerOnLinux&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US) * [Install a MID Server on Windows](https://www.servicenow.com/docs/access?context=mid-server-install-prereqs&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US) * [Install and configure MID Servers to access cloud environments](https://servicenow-prod.fluidtopics.net/J5R6fEzDsXUAwkST18d7jg "Install and configure the MID Servers correctly to enable ITOM products to access to the cloud resources.") {#alibaba-cloud-discovery__ul_x1p_lcn_2hc} |
| ServiceNow administrator | admin | Validate that the MID Server is installed correctly. | [Validate the MID Server](https://www.servicenow.com/docs/access?context=t_ValidateAMIDServer&version=yokohama&pubname=yokohama-servicenow-platform&ft:locale=en-US) |
| ServiceNow administrator | admin | Assigning users with discovery_admin roles and giving them permission for discovery. | [Managing roles](https://www.servicenow.com/docs/access?context=ua-creating-roles&version=yokohama&pubname=yokohama-platform-administration&ft:locale=en-US) |
| Cloud administrator or Discovery administrator | discovery_admin | Creating Alibaba Cloud service accounts | [Set up Alibaba Cloud service accounts](https://servicenow-prod.fluidtopics.net/8NjTdVLXmyGm6MEKEZ8~NA "Create Alibaba Cloud infrastructure service accounts on the ServiceNow AI Platform to access your Alibaba Cloud account during Alibaba Cloud discovery.") |
| Cloud administrator or Discovery administrator | The person configuring the API credentials must have the discovery_admin role in ServiceNow and must have access to the Alibaba Cloud Access Key ID and Access Key Secret. | Configuring Alibaba Cloud API credentials | [Create Alibaba Cloud API Credentials](https://servicenow-prod.fluidtopics.net/Zw~78mJfgYcSfUaomD~nNw "Create Alibaba Cloud API credentials on the ServiceNow AI Platform to enable access to your Alibaba Cloud resources during Alibaba Cloud discovery.") |
| Discovery administrator | discovery_admin | Use Discovery and Service Mapping Patterns | [Alibaba Cloud discovery using patterns](https://servicenow-prod.fluidtopics.net/grY1iKldcbJ4pcPdZKTkyw "Discovery and Service Mapping Patterns uses patterns to discover components of the Alibaba Cloud deployment during horizontal discovery. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.") |
| Discovery administrator | discovery_admin | Set up a discovery schedule for Alibaba Cloud | * [Create a Discovery schedule for Alibaba Cloud](https://servicenow-prod.fluidtopics.net/tsAM545EznQMNQjXbcTcVg "Create a Discovery schedule to run Alibaba Cloud discovery.") * [Create an Alibaba Cloud Discovery schedule in Discovery Admin Workspace](https://servicenow-prod.fluidtopics.net/nT5qRqTq7Oqqge7V2M8ivA "Use the Discovery Admin Workspace dashboard to create an Alibaba Cloud Discovery schedule.") {#alibaba-cloud-discovery__ul_u2v_5kz_j3c} |
[Table 2. Alibaba Cloud discovery users and tasks]


