Service Release Point
The service publishing point allows users to make services built with BLB accessible to specified users within Baidu AI Cloud intranet. Users can utilize the service publishing point without exposing IP addresses and ports on the public network. All access traffic is securely accessed through Baidu AI Cloud intranet. Service users can mount the service domain generated by the service publishing point via Service Network Interface Card (SNIC) to realize secure access to the service on the Baidu AI Cloud intranet.
Before Configuration, you should know:
- Each region can create up to 10 service publishing points;
- A single BLB can be bound to multiple service publishing points;
- A service publishing point can mount 1,000 SNICs;
- The maximum number of permission entries allowed for service publishing points is 50.
Create a service distribution point
- Log in to the Baidu AI Cloud Platform, go to Product Services > Baidu Load Balancer (BLB) > Service Publishing Points, and access the Service Publishing Point Instance page.
- Click on Create Service Publishing Point to open the corresponding pop-up box.
- Fill in the following configuration information:
| ConfigMap | Description |
|---|---|
| Publishing point name | Required, name of user custom service publishing point |
| Service name | Required, used for building Domain Name. It must be uppercase and lowercase English letters and numbers. Once it is created and published, it cannot be changed. |
| Associate BLB | Required, select the associated BLB instance |
| Publish permission | Required. All users are allowed by default, with custom permissions |
| Description | Edit the description information related to the service publishing point |
Description:
- Each service publishing point is associated with a specific region, and the publishing point can only be tied to a BLB within the same region.
- A service publishing point in the "In-Service" status cannot be released. To release it, you must unbind it from the BLB and trigger the release when the publishing point status changes to "unavailable," or disassociate all associated SNICs, triggering the release when the status changes to "available."
- Click OK to finalize the creation of the service publishing point.
Manage publishing permissions
On the operations section to the right of the service publishing point instance, click Manage Publishing Permissions to access the publishing permissions page.
- Click Add Permission to open the Add Permission pop-up box, where you can customize authorizations.
- Click Modify to adjust an existing permission entry.
- Click Delete to remove a permission entry.
Description:
- Custom permissions are supported, allowing you to configure allow or deny permissions for specific users or all users. If there is a conflict between permissions for all users and single users, deny permissions take precedence.
- If a user repeatedly adds permission policies, the previous policy will be overwritten, and the most recent one added will apply.
- By default, users are allowed to associate their own service publishing points with their SNIC. If no permissions are configured, only the current user's SNIC is permitted by default to associate with the publishing point.
- If permissions for other users (excluding the current user) are revoked or denied, their associated SNICs will be automatically unbound.
- The owner of the service publishing point is unaffected by the permission configuration on the publishing point and is always permitted to associate their SNIC with their own service publishing point. Even if deny permissions are set up for the owner, those rules will not apply.
View the SNIC
In the operations menu on the right side of the service publishing point instance, click on "View Associated SNIC" to navigate to the associated records page, where you can review the SNICs in the service along with their historical records.
Description:
- If a user's authorization is revoked, the SNICs under their account will be automatically disassociated and logged in the associated history.
