Updated on 2026-09-24 GMT+08:00

Shared VPC

Scenario

Ensure the VPC of the database audit instance is the same as that of the node (application side or database side) where you plan to install the database audit agent. Otherwise, the instance will be unable to connect to the agent or perform audit.

Creating a VPC

  1. Log in to the management console.
  2. Click in the upper left corner, choose Management & Governance > Resource Access Manager, and go to the resource access management page.
  3. Choose Shared by Me > Resource Shares.
  4. Click Create Resource Share in the upper right corner.

    Figure 1 Specifying shared resources

  5. Set resource type to vpc:subnet, choose the corresponding region, and select VPCs to be shared. Click Next: Associate Permissions.

    Figure 2 Specifying shared resources

  6. Associate a RAM managed permission with each resource type on the displayed page. Then, click Next: Grant Access to Principals in the lower right corner.

    Figure 3 Configuring permissions

  7. Specify the principals that you want to have access to the resources on the displayed page. Then, click Next: Confirm in the lower right corner.

    Figure 4 Specifying principals
    Table 1 Parameter descriptions

    Parameter

    Description

    Principal Type

  8. Check the configurations and click OK.

    Figure 5 Confirming configurations

Using a VPC

  1. Log in to the DBSS console.
  2. Click in the upper left corner on the displayed page and select a region.
  3. Select Region, AZ Type, AZ, and Edition Configuration.

    Select an enterprise project. The DBSS you purchase will be put under this project. Billing and permissions management are performed based on enterprise projects.

    For details about the differences between editions, see Edition Differences.

  4. Select the VPC and subnet for database audit. For details about related parameters, see Table 2.

    Figure 6 Setting database audit parameters
    Table 2 Database audit parameters

    Parameter

    Description

    Basic Settings

    Service Type

    Select a service type. Only Database Audit Service is supported currently.

    Billing Mode

    Select a billing mode for the instance. Currently, only Yearly/Monthly is available.

    Region

    Select the region where the database audit instance is located. For details, see Selecting a Region.

    AZ Type

    Select an AZ type. Only General is supported.

    AZ

    Select an AZ. For details, see Selecting an AZ

    Edition Configuration

    Edition

    DBAS provides four editions: starter, basic, professional, and advanced. For details, see Edition Differences.

    Network Configuration

    VPC

    You can select an existing VPC, or click View VPC to create one on the VPC console.

    NOTE:
    • Select the VPC of the node (application or database side) where you plan to install the agent. For more information, see How Do I Determine Where to Install an Agent?
    • To change the VPC of a DBSS instance, unsubscribe from it and purchase a new one.

    For more information about VPC, see Virtual Private Cloud User Guide.

    Subnet

    You can select a subnet configured in the VPC or create a subnet on the VPC console.

    Security Group

    You can select an existing security group in the region or create a security group on the VPC console. Once a security group is selected for an instance, the instance is protected by the access rules of this security group.

    For more information about security groups, see Virtual Private Cloud User Guide.

    Advanced Settings

    Name

    You can enter a custom instance name.

    The name can contain a maximum of 64 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

    Remarks (Optional)

    You can add instance remarks.

    The remarks can contain a maximum of 225 characters. Only letters, digits, spaces, underscores (_), and hyphens (-) are allowed.

    Enterprise Project

    This parameter is provided for enterprise users.

    An enterprise project groups cloud resources, so you can manage resources and members by project. The default project is default.

    Select an enterprise project from the drop-down list. For more information about enterprise projects, see Enterprise Management User Guide.

    Tag

    (Optional) Identifier of the database audit instance. Adding tags helps you better identify and manage your database instances. A maximum of 50 tags for each instance

    If you have configured tag policies for DBSS, you need to add tags to your DBSS instances based on the tag policies. If you add a tag that does not comply with the tag policies, the database audit instance may fail to be created. Contact your organization administrator to learn more about tag policies.

    Required Duration

    Select a required duration for the instance.

    You can purchase DBSS by month or year.

    Auto-renew

    After you select Auto-renew, the system automatically renews the instance upon expiry if your account balance is sufficient. You can continue to use the instance. Table 2 describes the auto-renewal period.