Updated on 2025-11-17 GMT+08:00

Concepts

  • Domain

    A domain has full access permissions for all of its cloud services and resources. It can be used to reset user passwords and grant user permissions. The domain is a payment entity and should not be used directly to perform routine management. For security purposes, create users and grant them permissions for routine management.

  • User

    A user is created by a domain to use cloud services. Each user has its own identity credentials (password and access keys).

    The domain name, username, and password will be required for API authentication.

  • Region

    Regions are geographic areas isolated from each other. Resources are region-specific and cannot be used across regions through internal network connections. For low network latency and quick resource access, select the nearest region.

  • AZ

    AZs are physically isolated locations in a region, but are interconnected through an internal network for enhanced application availability.

  • Project

    Projects group and isolate compute, storage, and network resources across physical regions. A default project is provided for each region, and subprojects can be created under each default project. Users can be granted permissions to access all resources in a specific project. For more refined access control, create subprojects under a project and create resources in the subprojects. Users can then be assigned permissions to access only specific resources in the subprojects.

    Figure 1 Project isolating model