China Cloud Overview & Support
After Cloud Security (InsightCloudSec) is successfully installed, you’re ready to start harvesting resources from your target cloud accounts. This documentation combines information for configuring your China Cloud environments to “talk” with Cloud Security (InsightCloudSec) securely. Review the sections below to determine the best starting point for your environment.
China Cloud in Cloud Security (InsightCloudSec): Frequently Asked Questions (FAQ)
What does Cloud Security (InsightCloudSec) support for China Clouds?
How do I start seeing my China environments in Cloud Security (InsightCloudSec)?
How do I start seeing my China environments in Cloud Security (InsightCloudSec)?
Cloud Security (InsightCloudSec) relies on a process called “harvesting” to pull data from various CSPs. Currently, Cloud Security (InsightCloudSec) only offers onboarding for an individual cloud account in AWS China via our universal onboarding experience.
Can customers running Cloud Security (InsightCloudSec) in China Cloud (self-hosted) harvest commercial account data/resources?
Can customers running Cloud Security (InsightCloudSec) in China Cloud (self-hosted) harvest commercial account data/resources?
AWS China:
Yes, however, customers must use an STS assume role operation instead of a traditional assume role. API calls cannot be made between AWS partitions (commercial/GovCloud/China) until a cross-partition STS assume role operation has been performed.
Can customers running Cloud Security (InsightCloudSec) in commercial cloud environments (SaaS and self-hosted) harvest China Cloud account data/resources?
Can customers running Cloud Security (InsightCloudSec) in commercial cloud environments (SaaS and self-hosted) harvest China Cloud account data/resources?
AWS China:
Yes, however, customers must use a STS assume role operation instead of a traditional assume role. API calls cannot be made between AWS partitions (commercial/GovCloud/China) until a cross-partition STS assume role operation has been performed.
AWS China Support
AWS China Policies
AWS China Policies
Cloud Security (InsightCloudSec) offers several different AWS policies for harvesting resource information found in your AWS accounts and enabling Cloud Security (InsightCloudSec) features. Our universal onboarding experience will implement the appropriate policies automatically, so there’s no need for AWS China-specific policies. Review AWS Policies for details.
AWS China Supported Deployment Regions
AWS China Supported Services
AWS China Supported Services
Listed below are all of the AWS China services (and their components) supported by Cloud Security (InsightCloudSec). In general if a service is supported by Cloud Security (InsightCloudSec), we support it in any region in which the CSP provides the service. If you have questions related to AWS or specific services and their support, contact us through the Customer Support Portal .
Amazon API Gateway (Domain, Key, Stage, Usage Plans)
Amazon DocumentDB
Amazon Keyspaces
Amazon SageMaker (Notebook, Training job)
Amazon Redshift (Serverless Namespace, Serverless Workgroup, Snapshot)
Amazon Transcription
Athena (Workgroup)
AWS Auto Scaling (Group, Launch Configurations)
AWS Backup (gateway, Vault)
AWS Glue (Connection, Crawler, Data Catalog, Database, Job, Security Configuration)
AWS Health Dashboard
AWS Organizations (Consolidated Bill, Service Control Policy)
AWS Systems Manager (Association, Parameter Store (Parameter), Document)
AWS Transfer Family (SFTP Server)
Batch (Compute Environment)
Certificate Manager (Private Certificate Authority)
CloudFormation (Templates)
CloudFront
CloudSearch (Cluster)
CloudTrail
CloudWatch (Alarm, Log Group, Rule, EventBridge event bus)
CodeBuild (Project)
Database Migration Service (Endpoint, Replication Instance)
Direct Connect
Directory Service
DynamoDB (Accelerator (DAX))
EC2 (Amazon EBS Snapshot, Amazon EBS Volume, Dedicated Instance, Instance, Launch Template, Reserved Instance, Resource/Service Limit/Quota, Savings Plans, SSH Key Pairs)
EFS
Elastic Beanstalk (Application, Environment)
Elastic Container Registry (Container Image, Container Registry)
Elastic Container Service/Fargate (Cluster, Container, Container Task)
Elastic Kubernetes Service (Cluster, Container Instance, Node Group)
Elastic Load Balancer (Application Load Balancer, Gateway Load Balancer, Network Load Balancer)
ElastiCache (Snapshot)
EMR
FSx
GuardDuty
IAM (Access Analyzer, Cloud Account, Group, Policy (Customer Managed), Role, IAM/ACM SSL Certificate, User, User Access Key)
Key Management Service
Kinesis (Data Firehose)
Kinesis Video Stream
Lambda (Layer)
MSK (Instance)
Neptune
OpenSearch Service
RDS (Aurora, Cluster, Event Subscription, Instance, Snapshot)
Region
Resource Access Manager (Resource shares, Shared resources)
Route 53 (DNS Zone, Domain)
S3 (Access Point, Multi-Region Access Point)
S3 Glacier
SAML Identity Provider
Secrets Manager (Secret)
Serverless Application Repository
Simple Queue Service
Simple Notification Service (Subscription, Topic)
Step Function State Machine
Storage Gateway
Systems Manager (Document)
Trusted Advisor
VPC (Elastic IP, Elastic Network Interface (ENI), Endpoint Service, Endpoint/PrivateLink, Flow Log, Internet Gateway, Managed Prefix List, NACL/Security Group, NACL/Security Group Rules, NAT Gateway, Network Firewall (Rules, Rule Groups), Peer, Route, Route Table, Site-to-Site VPN, Subnet, Traffic Mirror Target, Transit Gateway, Virtual Private Gateway)
WAF (Rules, Rule Groups)
WorkSpaces (Instances)