Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Discovery for Alibaba Cloud

Alibaba Cloud discovery is one of the overall Cloud discovery offerings within the IT Operations Management (ITOM) Visibility framework. It’s an automated process used to scan and identify Alibaba Cloud resources within your organization's cloud infrastructure. This discovery process is critical for maintaining an accurate and trustworthy data foundation—the Configuration Management Database (CMDB).

Pattern-based cloud discovery

Using Discovery and Service Mapping Patterns to perform horizontal discovery enables you to find and map your organization's Alibaba Cloud resources. You can discover Alibaba Cloud metadata including:

  • Cloud service accounts.
  • Datacenters.
  • Availability zones.
  • Hardware types.

Patterns also support OS level discovery, for example OS images.

Discovery and Service Mapping Patterns create configuration items (CIs) for your Alibaba Cloud resources. Additionally, patterns discover the relationships between your organization's Alibaba Cloud resources, such as Hosted On :: Hosts.

See Alibaba Cloud discovery using patterns to learn about all Alibaba Cloud resources you can discover using Patterns.

Verify the REST API Permissions

Download the Cloud Discovery patterns spreadsheet so you can grant user permissions required for running the Discovery patterns. In addition to permissions, the spreadsheet also includes useful information such as pattern names, types, CI Classes, and links to vendor documentation. New patterns are available quarterly, so check periodically to be sure you have the latest version of the spreadsheet.

Alibaba Cloud discovery configuration

The basic steps to configure pattern-based discovery for Alibaba Cloud involve preparation on the ServiceNow AI Platform side like installing necessary plugins and setting up credentials. The discovery_admin role in ServiceNow AI Platform is required for creating Alibaba Cloud API credentials and service accounts.

The discovery process requires configuration within Alibaba Cloud, like setting up Identity and Access Management roles. The discovery permissions of Alibaba Cloud users are determined by their access levels within Alibaba Cloud.

To promote proper discovery, the Alibaba Cloud user must have at least read-only access to the necessary Alibaba Cloud services.

Alibaba Cloud userDiscovery permissions
Root Account (Master Account)Full access to all Alibaba Cloud resources and services, including Elastic Compute Service (ECS), Object Storage Service (OSS), Relational Database Service (RDS), and Resource Access Management (RAM). Can create and manage RAM users, assign permissions, and perform billing operations.
RAM userAccess to specific Alibaba Cloud resources and services based on assigned policies. Can be granted read-only access for discovery purposes.
RAM Role (AssumedRoleUser)Temporary access to Alibaba Cloud resources and services based on assumed role policies. Useful for cross-account access, temporary access, or access by ECS instances.
Typical personaRoles and permissionsResponsibilityLink to detailed documentation
ServiceNow administrator or IT Implementation SpecialistadminInstall the store applications and update them on every store release:- Discovery - Discovery and Service Mapping Patterns - Visibility content. - CMDB CI Class Models - Discovery Admin WorkspaceITOM Store upgrades
ServiceNow administratoradmin- Create a MID Server user. - Assign the MID Server role to the user.Create the MID Server user and grant the role
ServiceNow administratoradmin, mid\_serverInstall a MID Server.- Install a MID Server on Linux - Install a MID Server on Windows - Install and configure MID Servers to access cloud environments
ServiceNow administratoradminValidate that the MID Server is installed correctly.Validate the MID Server
ServiceNow administratoradminAssigning users with discovery\_admin roles and giving them permission for discovery.Managing roles
Cloud administrator or Discovery administratordiscovery\_adminCreating Alibaba Cloud service accountsSet up Alibaba Cloud service accounts
Cloud administrator or Discovery administratorThe person configuring the API credentials must have the discovery_admin role in ServiceNow and must have access to the Alibaba Cloud Access Key ID and Access Key Secret.Configuring Alibaba Cloud API credentialsCreate Alibaba Cloud API Credentials
Discovery administratordiscovery\_adminUse Discovery and Service Mapping PatternsAlibaba Cloud discovery using patterns
Discovery administratordiscovery\_adminSet up a discovery schedule for Alibaba Cloud- Create a Discovery schedule for Alibaba Cloud - Create an Alibaba Cloud Discovery schedule in Discovery Admin Workspace

Parent Topic:Discovery for cloud environment