Purchasing a CBH Instance
Context
A Cloud Bastion Host (CBH) instance corresponds to an independently running CBH O&M management system. To perform real-time, remote, and efficient O&M on your resources, create a CBH account on the CBH instance you purchased, log in to the CBH system mapped to the CBH instance, and configure the O&M system.
Prerequisites
- You have obtained the information about the resources to be managed in the CBH system, and the resources are in the region where CBH is available.
- You have obtained credentials for logging in to the management console.
- You have purchased at least one elastic IP address (EIP).
Procedure
- Log in to the management console.
- Go to the page for purchasing CBH instances by following the steps shown in Figure 1.
- Select CBH Instance for Service Type and specify other parameters as required. For more information, see Table 1.
Table 1 Parameters for purchasing a CBH instance Parameter
Description
Billing Mode
The billing mode of the CBH instance. Currently, only Yearly/Monthly is available.
Yearly/Monthly is a prepaid billing mode in which a CBH instance is billed based on the service duration. This cost-effective mode is ideal when the duration of CBH instance usage is predictable.
Region
The region and AZ where the CBH instance is located.
For more information about regions and AZs where CBH is available, see Supported Regions and AZs.
Select a region nearest to your ECSs, RDS instances, BMSs to reduce network latency and accelerate service access.
AZ
Instance Name
Name of the CBH instance.
Edition
Specifications of your CBH instance.
CBH provides the standard and professional editions. Each edition has 100, 200, 500, 1000, 2000, and 5000 asset specifications.
For more details, see What Are the Editions Available in CBH?
VPC
The Virtual Private Cloud (VPC) where your instance is located. Select a VPC in the current region.
If no VPC is available in the current region, click View VPC and create one.
NOTE:- By default, networks in VPCs in different regions or even in the same region are not connected. The network communications on these different networks are isolated from each other. This is not the case for different AZs on the same VPC. Two networks on the same VPC should be able to communicate with each other even if they are in different AZs.
- A CBH instance directly manages and allows access from resources, such as ECSs, in the same VPC in the same region. To manage resources such as ECSs in different VPCs in the same region, establish a VPC peering connection or use a VPN to connect networks. For details, see Creating a VPC Peering Connection. Managing ECSs across regions is not recommended.
- After a CBH instance is created, its VPC cannot be changed. If an incorrect VPC is configured, unsubscribe from the instance and purchase a new one and configure a correct VPC.
For more information, see VPC Planning.
Security Group
The security group for your CBH instance. The default security group is Sys-default in the current region.
If no security group is available, click Manage Security Groups to create a security group or configure a new one.
NOTE:- A security group provides access rules for the CBH instances and resources that have the same security protection requirements and are mutually trusted in the same VPC. CBH instances are protected by these access rules after being added the security group. For details, see Security Group Overview.
- CBH instances and ECSs can be added to the same security groups. They do not affect each other when implementing security group rules.
- After a CBH instance is created, its security group cannot be changed, but rules in the security group can be modified. To change the security group for your instance, unsubscribe from the instance and then purchase a new one.
For more information about security groups, see How Do I Configure a Security Group for a CBH Instance?
Subnet
The subnet in the current VPC for your CBH instance.
NOTE:The selected subnet must be in the VPC network segment.
For more information, see Creating a VPC.
EIP
The EIP in the current region for your CBH instance.
If no EIP is available in the current region, click Purchase EIP to create one.
NOTE:- An EIP can be bound to only one cloud resource. A CBH instance cannot share an EIP with other cloud resources. After you created a CBH instance, you are required to bind an EIP to the instance for logging in to the CBH system. You need to create at least one EIP for a CBH instance.
- To meet the requirements of the CBH system, set the EIP bandwidth to 5 Mbit/s or higher.
- After the CBH instance is created, you can unbind the original EIP from the instance and bind a new EIP to it.
For more information about EIPs, see EIP Overview.
Username
The default username admin is used.
admin is the system administrator account. This account has the highest operation permissions. Keep the account information secure.
Password
User-defined password of the admin user.
NOTE:- The password must:
- Contain 8 to 32 characters.
- Contain at least three of the following types of characters: uppercase letters (A to Z), lowercase letters (a to z), digits (0 to 9), and following special characters: !@$%^-_=+[{}]:,./?~#*
- Cannot contain the username or the username spelled backwards.
- Enter the same password in the Password and Confirm Password text boxes.
- Your CBH system cannot obtain the password of the system administrator admin. Keep the account information secure.
- When you log in to your CBH system as admin for the first time, change the password and configure mobile phone number as prompted. Otherwise, you cannot log in to the CBH system.
- If you forget the password of user admin after a CBH instance is purchased, you can reset the password.
Required Duration
Required duration of the instance
You can buy a CBH instance on a monthly or yearly basis.
- Confirm details in the Current Configuration area and click Next.
When receiving a network restriction notification, click Enable to eliminate the network restrictions so that the instance can be issued after purchase.
You can view the rules in the security group and firewall ACL.
- Access to port 9443 is allowed in the outbound direction of the security group to which your CBH instance belongs.
- The subnet where the instance locates is not associated with the firewall ACL, or the ACL rule of the associated firewall allows the instance to access port 9443 in the outbound direction.
- On the Confirm page, confirm the details, read the privacy statement, select Privacy Statement, and click Submit.
- Make your purchase and return to the CBH console. Check the newly purchased instance in the CBH instance list.
After a CBH instance is purchased, a mapped CBH system is automatically created for you, which takes about 10 minutes.
Do not unbind an EIP from a CBH instance before the mapped CBH system is created. If you unbind an EIP from an instance before its status changes to Running, the mapped CBH system may fail to be created.
Follow-up Procedure
- If the instance Status is Running, the CBH system is successfully created. Then, you can log in to the CBH system.
- If the instance Status is Failed to creation, view the failure cause in the displayed dialog box. Then, click Service Ticket in the upper right corner of the management console, fill in the service ticket, and submit the service ticket.
- If a CBH instance is about to expire or has expired, locate the row where the instance resides, click More > Renew in the Operation column, and complete required configuration to renew it. For details, see Renewing a CBH Instance.
- If the VPC or security group information configured for the purchased instance is incorrect, you can click More > Unsubscribe in the Operation column to unsubscribe from it, and repurchase it again. For details, see Unsubscribing from a CBH Instance.
Last Article: CBH Instance Permissions and Supported Actions
Next Article: Viewing CBH Instance Details

Did this article solve your problem?
Thank you for your score!Your feedback would help us improve the website.