All pages
Powered by GitBook
1 of 8

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Setup Password Lifetime

Overview

Password Lifetime is the duration for which a password is valid. This duration will be extended whenever the password is reset.

  • This function allows users (Provider/Tenant) to set the lifetime of password of tenant user and all members in a tenant will have the same password lifetime.

  • The lifetime can be Unlimited and Limited:

o Unlimited: the password will not expire.

o Limited: The password will expire based on the value of the setting.

  • Whenever the password is updated, the password lifetime will start over again.

  • Emails will be sent to tenant users if their password is:

It will expire in the next 30 days ⇒ to remind users to change their password.

It will expire in the next 7 days ⇒ to remind users to change their password.

It will expire in the next day ⇒ to remind users to change their password.

It expired last day ⇒ To inform users that they cannot log in to the system anymore, they need to contact the administrator to reset the password.

Besides, there is an email to send to the administrator/owner of the tenant to inform the list of their members that have passwords to expire the next day.

If the password lifetime is updated, the administrator/owner of tenant must reset the password for all members to make sure the system running correctly.

Procedure

Step 1: Login to the Tenant site by the role that has permission to change password lifetime.

Step 2: Access the Tenant setting page: General > Setting tab.

Step 3: Click on the Edit button.

Step 4: Choose Limited or Unlimited from the select box.

Step 5: If you choose Limited, the user must input the duration by days.

Step 6: Click the button to Save.

Step 1: Email to remind users to change their password.

Step 2: Email to inform users that their password is not valid anymore >> please contact the Administrator or HI GIO support to reset the password.

Step 3: Email to inform administrators/owners of the list of members.

HI GIO Portal – Tenant User Guide

Procedure

1

Step 1: Log in to HI GIO IAM portal with domain https://iam.higiocloud.vn

  • Enter Organization Name NEXT

  • Enter user name /password SIGN IN

  • Login Success

2

Step 2: Create a new user

  • Select tab User ADD NEW

  • Fill information: please select the properties role for Portal Role. If you want to use MFA, you need to enable MFA TOTP.

3

Step 3: Log in with MFA TOTP.

  • You can enable/disable the function MFA TOTP on the IAM portal. We recommend using the MFA function for more security for your HI GIO account.

  • After enabling MFA TOTP, you need to Verify.

4

Step 4: Go to vCD portal.

HI GIO Cloud includes 2 portals: the IAM portal & vCD portal.

  • IAM portal: user management, billing

  • vCD portal: resource management, VMs…

How to go vCD portal:

HI GIO's VM monitoring

Overview

This function aims to provide tenant users/service providers a visual look at the status of each VM based on its metrics:

o CPU Usage.

o Memory Usage.

o Disk used Space.

o Disk Average number of bytes read.

o Disk Average number of bytes written.

o Network utilization on interfaces.

In this guide, we will help you:

  • How to enable Monitor Zones

  • How to view monitor items on your organization.

Procedure

1

Step 1: Enable Monitor Zones

This page lists out all managed regions of your account and lets you enable monitoring for them.

Log on to the IAM portal. Select Monitor > Manage

Select Zone > Change to Active

2

Step 2: View monitor items on your organization:

Setup Passkey

Overview

HIGIO supports tenant users setting the Passkey factor to log in IAM portal.

Passkey 2 MFA simplifies secure login to the IAM portal. Users authenticate using biometrics or device PIN, with credentials stored securely on their device. This enhances both security and convenience.

1. IAM Portal

Overview

This guide is designed to help you navigate the Identity and Access Management (IAM) Portal, a critical component of HI GIO Cloud that enables you to manage user identities, permissions, and access controls effectively.

The IAM Portal provides a user-friendly interface for administrators and users, allowing you to create and manage user accounts, assign roles, and enforce security policies to protect your cloud resources. Whether setting up new users, configuring access rights, or monitoring activity logs, this manual offers step-by-step instructions and best practices to ensure a secure and efficient experience.

Explore the features of the HI GIO IAM Portal and empower your organization with robust identity management and access control capabilities!

  • vCDs role = IaaS Admin

  • Click NEXT. Verify user information and SAVE

  • Successfully created a new user.

The user will receive an email to activate account IAM (Please see file Activate HI GIO account)

  • Log out your account on the IAM portal. Please install one of the following applications on your mobile:

    • Microsoft Authenticator

    • Google Authenticator

    • FreeOTP

  • Log in again after entering a user name/password SIGN IN. Please Open the application and scan the barcode display on the screen.

    • Enter the one-time code provided by the application (Device name - optional) and click Submit to finish the setup.

    • Successfully activate and login with MFA TOTP

    On the top right corner of HI GIO IAM portal, click your name.

    • Click “Open VCD Portal hcmc01” (or another site)

    • Click “SIGN IN WITH SAML” (No need enter user name & password)

    • Successfully Linked to vCD Portal.

    Log on IAM portal. Select Monitor > View.

    In Monitor View window, you can select: IaaS Zone [3], oVDC [4] which one you want to view.

    Select VM name from list [5] to open monitor items of VMs.

    On this page, you can select:

    [1] oVDC

    [2] VM

    [3] Network (if VM have multiple NIC)

    [4] Disk (if VM have multiple disk)

    Once Passkey is set, it will be the default factor when logging in.

    Procedure

    Step 1: Log in to the HI GIO IAM portal with domain https://iam.higiocloud.vn

    • Enter Organization Name then click NEXT

    • Enter user name /password SIGN IN

    • Login success

    Step 2. Setup Passkey

    • Go to the User Profile -> Passkeys -> ADD NEW

    • It will open a new Passkey Registration page, click REGISTER, can verify with your PIN, FaceID or Fingerprint, then click OK.

    • Successfully create Passkey

    Step 3. Log in with passkey.

    Go to the IAM portal https://iam.higiocloud.vn , input Organization Name and login.

    After entering your Username/Password, you will be asked for the Passkey. Choose your verification method and then click OK.

    • Successfully logged in.

    NOTE: After registering, Passkey is required by default, but you can also use the TOTP option.

    • Choose VERIFY WITH TOTP

    Step 4. Delete Passkey.

    Log in to the IAM portal, go to the User Profile tab and choose DELETE under the Passkeys tab.

    Guideline
    • Activate HI GIO - IAM account

    • HI GIO Portal – Tenant User Guide

    • Setup Password Lifetime

    • HI GIO's VM monitoring

    HI GIO's Monitoring Alert - Email notification channel

    Overview

    This function is designed to enable users to create rules for receiving notifications if the statuses of VMs exceed or fall below specific thresholds. The resources that can be monitored and notified are:

    - CPU Usage.

    - Memory Usage.

    - Free Disk Space.

    Procedure

    The recipients will receive notifications when the alert is triggered.

    • Log in to HI GIO cloud > Monitor

    • Select Manage, and Select NEW below the Alert Contact Destination section.

    HI GIO's Monitoring Alert - Telegram notification channel

    Overview

    This function allows users to create rules for receiving notifications via Telegram channels when the statuses of VMs exceed or fall below specific thresholds.

    HI GIO's Monitoring Alert - Email notification channel
    HI GIO's Monitoring Alert - Telegram notification channel
    A new Alert Contact Destination will open. Fill up contact information to this window> SAVE

    ** Please add [email protected] to the email whitelist.

    Requirement fields explanation:

    Name: The name of the contact destination.

    Integration: The channel where users can receive alerts. In this version, there is only 1 channel available: Email.

    Email Address:

    • The email address of the persons who will receive the alert email.

    • We can add multiple email addresses but only add 1 email at a time. After inputting a correct email address and pressing the Enter key, the email address will be added to the text area below, and then we can add another one.

    Email Subject: The alert email’s subject.

    Send a single email to all recipients check box:

    • If checked, 1 email will be sent to all recipients. All recipients will be displayed in “To“ field.

    • If not checked, each recipient will receive a separate email >> We don’t know who gets the notify email.

    An alert rule is a configuration that defines conditions under which an alert should be triggered.

    • Log in to HI GIO cloud > Monitor

    • Select Manage, and Select NEW below the Alert Rules section.

    • New Alert Rule window will open. Fill up the information in this window> SAVE

    Requirement fields explanation:

    Name: The name of the rule.

    Item: The resource that triggers the alert. For example, CPU.

    • After it is completed, the alert rule will show as below:

    We also can activate\deactivate the rules directly from this list.

    Update the VM field If you rename the VM’s name on the porta

    Alert Rule will not automatically update the VM’s name on the VM field.

    Every threshold reaches the defined in the alert rule. we will get the email notification - Firing Instance\Resolved Instances.

    Sample email - Firing Instance.

    Sample email - Resolved Instances.

    Procedure

    Please view this link to learn how to obtain the BOT API TOKEN and Chat ID

    Step 1: Login HI GIO cloud > Monitor

    Step 2: Select Manage, and Select NEW below Alert Contact Destination section

    • New Alert Contact Destination will open

    • Select Integration in Telegram

    • Fill up contact information to this window> SAVE

    Fields explanation:

    Name: The name of the contact destination.

    Integration: The channel where users can receive alerts. In this version, there are 3 channels available: Email and telegram.

    BOT API Token: Token to access the BOT API

    Chat ID: Group Chat ID of Telegram

    Optional Webhook Settings:

    + Disable Web Page Preview: If this option is checked, a Web Page Preview will be hidden on the notification content.

    + Disable resolve message: A "resolved" notification will not be sent if this option is checked.

    • After completed, the Alert Contact Destination will show as below:

    Step 1: Login HI GIO cloud > Monitor

    Step 2: Select Manage, and Select NEW below the Alert Rules section.

    • A New Alert Rule window will open.

    • Fill up the information in this window and select Alert Contact Destination using the Telegram notification channel > SAVE

    Whenever the threshold defined in the alert rule is reached, we will receive a Telegram notification indicating the Firing Instances or Resolved Instances.

    • Sample Telegram – Firing Instance

    • Sample Telegram – Resolved Instance

    Activate HI GIO - IAM account

    Overview

    You will receive an activation email after you request your HI GIO account. You need to activate it in the first use.

    Procedure

    1

    Step 1: Check activate email, subject: no-reply-iam from [email protected]

    2

    Step 2: Follow the link in the email. Click “Link to account update.”

    3

    Threshold: Specify specific values or ranges that activate the alert. For example, 90% (meaning that if CPU usage exceeds 90%, the alert will be triggered).

    oVDC: Specify the oVDC.

    VM: Specify the VM that triggers the alert. The select box will contain all VMs in the oVDC and /.*/ option indicates the selection of all VMs.

    Pending Period:

    • The duration for which an alert remains pending after being triggered.

    • During this pending period, Grafana allows time for conditions to potentially resolve on their own before considering the alert fully triggered or resolved.

    • This feature helps avoid unnecessary alert notifications for transient issues.

    • The default value is 3m.

    For example, Pending Period = 3m → means that if the CPU exceeds 90%, the system will wait 3 minutes. Within 03 minutes, if the CPU falls behind 90%, no alert will be fired. The alert will only be fired if the CPU exceeds 90% after a 3-minute.

    Repeat Interval:

    • It specifies how frequently the system checks whether the conditions for triggering the alert are still met after the initial alert firing.

    • If the conditions remain true during these intervals, the system continues to send notifications at the specified repeat interval until the alert condition is no longer met or resolved.

    • For example, Repeat Interval = 4h and the condition is CPU exceeds 90% → meaning that after an alert is first fired, the system will continue to fire the alert every 4 hours as long as the CPU still exceeds 90%.

    Annotation – Summary, Description: The alert email’s content.

    Alert Contact Destination: The destination where the alert will be sent. The select box contains all the created contact destinations.

    Data of BOT API Token will be hidden on the Edit form

  • After it is completed, the alert rule will show as below:

  • Step 3: Click “Click here to proceed.”

    You need to change your password in the first login.

    4

    Step 4: Click “Submit” to complete.

    5

    Step 5: Click “Back to Application” to log on HI GIO.

    6

    Step 6: Enter user name/password to log on to HI GIO Cloud

    From the second login, you can use this information.

    HI GIO’s URL: https://iam.higiocloud.vn

    Organization name: (The HI GIO team provided it via email, or you can get it through the activate email).

    Password: that you changed in the activate steps.

    If you get the notification below from an active email.

    It’s a safe link. This notice is due to AWS SES.

    -

    REF
    Monitoring your Amazon SES sending activity - Amazon Simple Email Service
    Activate email with tenant name