Alibaba Cloud resource inventory

The onboarding process creates resources in the customer's Alibaba Cloud account using the Terraform authentication template. All resources are created at the account level.

Resource typeResource namePurpose
alicloud_ram_roleCortexPlatformRoleRAM role that Cortex XSIAM assumes via OIDC federation. Configured with a trust policy that accepts GCP OIDC tokens with the configured audience.
alicloud_ram_policyCustom PolicyRAM policy with 46 read-only permissions across ECS, OSS, RAM, RDS, VPC, SLB, ActionTrail, CEN, and NAS services.
alicloud_ram_role_policy_attachmentPolicy AttachmentAttaches the custom read-only policy to the CortexPlatformRole.
(OIDC Provider)OIDC Identity ProviderAlibaba Cloud OIDC identity provider that trusts GCP OIDC tokens issued by Cortex XSIAM with the audience alibaba-cortex-wif-<tenantID>.