Skip to content

Commit a13fa0e

Browse files
authored
feat: add aliyun private link (#2962)
1 parent 472ed21 commit a13fa0e

File tree

25 files changed

+78
-26
lines changed

25 files changed

+78
-26
lines changed

docs/cn/guides/20-cloud/30-advanced/01-iam-role/01-aws.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ sidebar_label: "AWS IAM 角色"
4141

4242
点击 `Create role`,在 `Trusted entity type` 中选择 `Custom trust policy`
4343

44-
![创建角色](/img/cloud/iam/create-role.png)
44+
![创建角色](/img/cloud/iam/aws/create-role.png)
4545

4646
输入信任策略文档:
4747

docs/cn/guides/20-cloud/30-advanced/02-private-link/01-aws.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ sidebar_label: "AWS PrivateLink"
1111

1212
2. 验证您的 VPC 设置
1313

14-
![VPC 设置](/img/cloud/privatelink/vpc-settings.png)
14+
![VPC 设置](/img/cloud/privatelink/aws/vpc-settings.png)
1515

1616
确保选中 `启用 DNS 解析``启用 DNS 主机名`
1717

@@ -21,47 +21,47 @@ sidebar_label: "AWS PrivateLink"
2121

2222
4. 准备一个打开 tcp 443 端口的安全组:
2323

24-
![安全组](/img/cloud/privatelink/security-group.png)
24+
![安全组](/img/cloud/privatelink/aws/security-group.png)
2525

2626
5. 转到 AWS 控制台:
2727

2828
https://us-east-2.console.aws.amazon.com/vpcconsole/home?region=us-east-2#Endpoints:
2929

3030
单击 `创建终端节点`
3131

32-
![创建终端节点按钮](/img/cloud/privatelink/create-endpoint-1.png)
32+
![创建终端节点按钮](/img/cloud/privatelink/aws/create-endpoint-1.png)
3333

34-
![创建终端节点表单](/img/cloud/privatelink/create-endpoint-2.png)
34+
![创建终端节点表单](/img/cloud/privatelink/aws/create-endpoint-2.png)
3535

3636
选择先前创建的安全组 `HTTPS`
3737

38-
![创建终端节点 SG](/img/cloud/privatelink/create-endpoint-3.png)
38+
![创建终端节点 SG](/img/cloud/privatelink/aws/create-endpoint-3.png)
3939

40-
![创建终端节点完成](/img/cloud/privatelink/create-endpoint-4.png)
40+
![创建终端节点完成](/img/cloud/privatelink/aws/create-endpoint-4.png)
4141

4242
6. 等待云管理员批准您的连接请求:
4343

44-
![请求](/img/cloud/privatelink/request.png)
44+
![请求](/img/cloud/privatelink/aws/request.png)
4545

4646
7. 等待 PrivateLink 创建:
4747

48-
![创建](/img/cloud/privatelink/creation.png)
48+
![创建](/img/cloud/privatelink/aws/creation.png)
4949

5050
8. 修改私有 DNS 名称设置:
5151

52-
![DNS 菜单](/img/cloud/privatelink/dns-1.png)
52+
![DNS 菜单](/img/cloud/privatelink/aws/dns-1.png)
5353

5454
启用私有 DNS 名称:
5555

56-
![DNS 表单](/img/cloud/privatelink/dns-2.png)
56+
![DNS 表单](/img/cloud/privatelink/aws/dns-2.png)
5757

5858
等待更改生效。
5959

6060
9. 验证通过 PrivateLink 访问 Databend Cloud:
6161

62-
![验证 DNS](/img/cloud/privatelink/verify-1.png)
62+
![验证 DNS](/img/cloud/privatelink/aws/verify-1.png)
6363

64-
![验证响应](/img/cloud/privatelink/verify-2.png)
64+
![验证响应](/img/cloud/privatelink/aws/verify-2.png)
6565

6666
网关域名已解析为 VPC 内部 IP 地址。
6767

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
---
2+
title: "通过阿里云私网连接连接到 Databend Cloud"
3+
sidebar_label: "阿里云私网连接"
4+
---
5+
6+
# 如何设置阿里云私网连接
7+
8+
1. 提供计划使用 PrivateLink 的 AccountID(主账号 ID)
9+
10+
![AccountID](/img/cloud/privatelink/aliyun/accountid.png)
11+
12+
2. 等待 Databend Cloud 将 AccountID 加入到白名单
13+
14+
3. Databend Cloud 提供终端节点服务名称
15+
16+
例如: `com.aliyuncs.privatelink.cn-beijing.epsrv-2zelaf38jasnuv54go9j`
17+
18+
4. 准备一个开放 443 端口的安全组
19+
20+
![Security Group](/img/cloud/privatelink/aliyun/security-group.png)
21+
22+
5. 到 aliyun 控制台创建终端节点
23+
24+
https://vpc.console.aliyun.com/endpoint/cn-beijing/endpoints/new
25+
输入第三步 Databend Cloud 提供的终端节点服务名称并点击验证
26+
![Create Endpoint](/img/cloud/privatelink/aliyun/create-endpoint.png)
27+
点击最下方的【确定创建】
28+
29+
6. 通知 Databend Cloud 并等待通过连接请求
30+
31+
![Request](/img/cloud/privatelink/aliyun/request.png)
32+
33+
7. 获取终端连接的内网 IP
34+
35+
![Endpoint IP](/img/cloud/privatelink/aliyun/endpoint-ip.png)
36+
37+
8. 验证终端连接可用
38+
39+
```bash
40+
curl -v https://gw.aliyun-cn-beijing.default.databend.cn/status --resolve gw.aliyun-cn-beijing.default.databend.cn:443:10.0.1.222 | jq
41+
```
42+
43+
如果返回结果中包含 `"status": "ok"`,则表示终端连接可用
44+
45+
![Verify Endpoint Request](/img/cloud/privatelink/aliyun/verify-endpoint-request.png)
46+
47+
![Verify Endpoint Response](/img/cloud/privatelink/aliyun/verify-endpoint-response.png)
48+
49+
50+
:::info
51+
恭喜!您已成功通过阿里云私网连接连接到 Databend Cloud。
52+
:::

docs/en/guides/20-cloud/30-advanced/01-iam-role/01-aws.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ sidebar_label: "AWS IAM Role"
4141

4242
Click `Create role`, and select `Custom trust policy` in `Trusted entity type`:
4343

44-
![Create Role](/img/cloud/iam/create-role.png)
44+
![Create Role](/img/cloud/iam/aws/create-role.png)
4545

4646
Input the the trust policy document:
4747

docs/en/guides/20-cloud/30-advanced/02-private-link/01-aws.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ sidebar_label: "AWS PrivateLink"
1111

1212
2. Verify your VPC settings
1313

14-
![VPC Settings](/img/cloud/privatelink/vpc-settings.png)
14+
![VPC Settings](/img/cloud/privatelink/aws/vpc-settings.png)
1515

1616
Ensure `Enable DNS resolution` and `Enable DNS hostnames` are checked.
1717

@@ -21,47 +21,47 @@ sidebar_label: "AWS PrivateLink"
2121

2222
4. Prepare a security group with tcp 443 port open:
2323

24-
![Security Group](/img/cloud/privatelink/security-group.png)
24+
![Security Group](/img/cloud/privatelink/aws/security-group.png)
2525

2626
5. Goto AWS Console:
2727

2828
https://us-east-2.console.aws.amazon.com/vpcconsole/home?region=us-east-2#Endpoints:
2929

3030
Click `Create endpoint`:
3131

32-
![Create Endpoint Button](/img/cloud/privatelink/create-endpoint-1.png)
32+
![Create Endpoint Button](/img/cloud/privatelink/aws/create-endpoint-1.png)
3333

34-
![Create Endpoint Sheet](/img/cloud/privatelink/create-endpoint-2.png)
34+
![Create Endpoint Sheet](/img/cloud/privatelink/aws/create-endpoint-2.png)
3535

3636
Select the previously created security group `HTTPS`
3737

38-
![Create Endpoint SG](/img/cloud/privatelink/create-endpoint-3.png)
38+
![Create Endpoint SG](/img/cloud/privatelink/aws/create-endpoint-3.png)
3939

40-
![Create Endpoint Done](/img/cloud/privatelink/create-endpoint-4.png)
40+
![Create Endpoint Done](/img/cloud/privatelink/aws/create-endpoint-4.png)
4141

4242
6. Wait for cloud admin approving your connect request:
4343

44-
![Request](/img/cloud/privatelink/request.png)
44+
![Request](/img/cloud/privatelink/aws/request.png)
4545

4646
7. Wait for the PrivateLink creation:
4747

48-
![Creation](/img/cloud/privatelink/creation.png)
48+
![Creation](/img/cloud/privatelink/aws/creation.png)
4949

5050
8. Modify private DNS name setting:
5151

52-
![DNS Menu](/img/cloud/privatelink/dns-1.png)
52+
![DNS Menu](/img/cloud/privatelink/aws/dns-1.png)
5353

5454
Enable private DNS names:
5555

56-
![DNS Sheet](/img/cloud/privatelink/dns-2.png)
56+
![DNS Sheet](/img/cloud/privatelink/aws/dns-2.png)
5757

5858
Wait for changes to apply.
5959

6060
9. Verify accessing Databend Cloud via PrivateLink:
6161

62-
![Verify DNS](/img/cloud/privatelink/verify-1.png)
62+
![Verify DNS](/img/cloud/privatelink/aws/verify-1.png)
6363

64-
![Verify Response](/img/cloud/privatelink/verify-2.png)
64+
![Verify Response](/img/cloud/privatelink/aws/verify-2.png)
6565

6666
Gateway domain is resolved to VPC internal IP address.
6767

50 KB
Loading
142 KB
Loading
80 KB
Loading
102 KB
Loading

0 commit comments

Comments
 (0)