China Cloud Overview & Support

After InsightCloudSec is successfully installed, you're ready to start harvesting resources from your target cloud accounts. This documentation combines information for configuring your China Cloud environment(s) to "talk" with InsightCloudSec securely. Review the sections below to determine the best starting point for your environment.

New Onboarding Experience

Beginning with InsightCloudSec version 23.4.11, a new AWS onboarding experience is available. This experience replaces our previous onboarding process.

China Cloud in InsightCloudSec: Frequently Asked Questions (FAQ)

What does InsightCloudSec support for China Clouds?

What does InsightCloudSec support for China Clouds?

Review the full list of China-specific supported services on the China Cloud Support Reference page.

How do I start seeing my China environment(s) in InsightCloudSec?

How do I start seeing my China environment(s) in InsightCloudSec?

InsightCloudSec relies on a process called "harvesting" to pull data from various CSPs. Currently, InsightCloudSec only offers onboarding for an individual cloud account in AWS China via our universal onboarding experience.

Can customers running InsightCloudSec in China Cloud (self-hosted) harvest commercial account data/resources?

Can customers running InsightCloudSec in China Cloud (self-hosted) harvest commercial account data/resources?

AWS China Support

Yes, however, customers must use an STS assume role operation instead of a traditional assume role. API calls cannot be made between AWS partitions (commercial/GovCloud/China) until a cross-partition STS assume role operation has been performed.

Can customers running InsightCloudSec in commercial cloud environments (SaaS and self-hosted) harvest China Cloud account data/resources?

Can customers running InsightCloudSec in commercial cloud environments (SaaS and self-hosted) harvest China Cloud account data/resources?

AWS China

Yes, however, customers must use a STS assume role operation instead of a traditional assume role. API calls cannot be made between AWS partitions (commercial/GovCloud/China) until a cross-partition STS assume role operation has been performed.

AWS China Support

AWS China Policies

AWS China Policies

InsightCloudSec offers several different AWS policies for harvesting resource information found in your AWS accounts and enabling InsightCloudSec features. Our universal onboarding experience will implement the appropriate policies automatically, so there's no need for AWS China-specific policies. Review AWS Policies for details.

AWS China Supported Deployment Regions

AWS China Supported Deployment Regions

InsightCloudSec can only be deployed in AWS. For self-hosted customers, InsightCloudSec can be exclusively deployed/hosted in AWS China, if you so choose.

AWS China Supported Services

AWS China Supported Services

Listed below are all of the AWS China services (and their components) supported by InsightCloudSec. In general if a service is supported by InsightCloudSec, we support it in any region in which the CSP provides the service. If you have questions related to AWS or specific services and their support, contact us through the Customer Support Portal.

text
1
Amazon API Gateway (Domain, Key, Stage, Usage Plans)
2
Amazon DocumentDB
3
Amazon Keyspaces
4
Amazon SageMaker (Notebook, Training job)
5
Amazon Redshift (Serverless Namespace, Serverless Workgroup, Snapshot)
6
Amazon Transcription
7
Athena (Workgroup)
8
AWS Auto Scaling (Group, Launch Configurations)
9
AWS Backup (gateway, Vault)
10
AWS Glue (Data Catalog, Database, Security Configuration)
11
AWS Health Dashboard
12
AWS Organizations (Consolidated Bill, Service Control Policy)
13
AWS Transfer Family (SFTP Server)
14
Batch (Compute Environment)
15
Certificate Manager (Private Certificate Authority)
16
CloudFormation (Templates)
17
CloudFront
18
CloudSearch (Cluster)
19
CloudTrail
20
CloudWatch (Alarm, Log Group, Rule, EventBridge event bus)
21
CodeBuild (Project)
22
Database Migration Service (Endpoint, Replication Instance)
23
Direct Connect
24
Directory Service
25
DynamoDB (Accelerator (DAX))
26
EC2 (Amazon EBS Snapshot, Amazon EBS Volume, Dedicated Instance, Instance, Launch Template, Reserved Instance, Resource/Service Limit/Quota, Savings Plans, SSH Key Pairs)
27
EFS
28
Elastic Beanstalk (Application, Environment)
29
Elastic Container Registry (Container Image, Container Registry)
30
Elastic Container Service/Fargate (Cluster, Container, Container Task)
31
Elastic Kubernetes Service (Cluster, Container Instance, Node Group)
32
Elastic Load Balancer (Application Load Balancer, Gateway Load Balancer, Network Load Balancer)
33
ElastiCache (Snapshot)
34
EMR
35
FSx
36
IAM (Access Analyzer, Cloud Account, Group, Policy (Customer Managed), Role, IAM/ACM SSL Certificate, User, User Access Key)
37
Key Management Service
38
Kinesis (Data Firehose)
39
Kinesis Video Stream
40
Lambda (Layer)
41
MSK (Instance)
42
Neptune
43
OpenSearch Service
44
RDS (Aurora, Cluster, Event Subscription, Instance, Snapshot)
45
Region
46
Route 53 (DNS Zone, Domain)
47
S3 (Access Point, Multi-Region Access Point)
48
S3 Glacier
49
SAML Identity Provider
50
Secrets Manager (Secret)
51
Serverless Application Repository
52
Simple Queue Service
53
Simple Notification Service (Subscription, Topic)
54
Step Function State Machine
55
Storage Gateway
56
Systems Manager (Document)
57
Trusted Advisor
58
VPC (Elastic IP, Elastic Network Interface (ENI), Endpoint Service, Endpoint/PrivateLink, Flow Log, Internet Gateway, Managed Prefix List, NACL/Security Group, NACL/Security Group Rules, NAT Gateway, Peer, Route, Route Table, Site-to-Site VPN, Subnet, Traffic Mirror Target, Transit Gateway, Virtual Private Gateway)
59
WAF
60
WorkSpaces (Instances)