You need to enable JavaScript to run this app.
Copy page
Download PDF
Quick Start
Preparations
Copy page
Download PDF
Preparations

This article describes the preparations that O&M administrators usually need to complete before new users use AI Data Lake Service Lake AI Service (hereinafter referred to as LAS), such as preparing a Volcengine account and enabling services. This article introduces the key steps for these preparations.

Browser recommendations

We recommend using a supported browser version: Google Chrome 100.0 or later.

Prepare a Volcengine account

Before new users use AI Data Lake Service LAS for the first time, you need to prepare a Volcengine account. This article introduces operations related to Volcengine account registration, verification, and sub-user creation.

Preparations

Details

Notes

Register a Volcengine primary account

  • If your enterprise has never registered a Volcengine account before, you need to register a Volcengine account first and complete real-name verification. For operation details, see: Register a Volcengine account.
  • If you already have a Volcengine account with enterprise real-name verification, you can proceed directly to subsequent steps.
  • We recommend completing enterprise real-name verification for the Volcengine account used with LAS. For details, see: Enterprise verification.
  • Users with individual real-name verification cannot fully experience LAS features by default (for example, they cannot use operator service features). If users with individual real-name verification want to experience more features, they need to submit a ticket separately.

Create a sub-account

After the primary account is registered, you can log in to the Volcengine access console. On the Identity Management > Users page, create sub-users based on actual business scenarios, and grant different permission policies to different sub-users. This helps finely distinguish role permissions and ensure the security and privacy of business data.

  • To learn the difference between a primary account and a sub-account, see Access control.
  • When managing permissions for sub-accounts in the LAS product, you can:
    • Add permission policies to a sub-account, such as LASAIFullAccess, LASAIReadOnlyAccess. To learn the detailed permission scope of each preset policy, see LAS system preset permission policy description.

      Image=284x
    • Add sub-accounts to user groups: A user group is a collection of sub-users. The same sub-user can belong to multiple user groups. After a policy is associated with a user group, users in the user group also have the corresponding policy permissions. For operations, see User group management.

(Optional) Create an IAM role

LAS currently also supports logging in with an IAM role and using the LAS Catalog feature. You can create an IAM role as needed. You can log in to the Volcengine access console and create it on the Role Management page.

  • To learn about IAM roles, see the IAM role management documentation. When creating a role for LAS:
    • You can select "Account" as the trusted identity type.
    • You can also create a custom permission policy for the role to manage role permissions. For details, see Create a custom role.
  • When using a role to log in to LAS, such as SSO login, you can use the role after login to connect to EMR Serverless, DataLeap, and many other services. This enables read and write operations on databases and tables in Catalog. For details about SSO login operations, see: IAM official documentation.

    Caution

    Granting permissions for Catalog through a role is not supported yet. If you have related requirements, you can perform the operations through DataLeap.

Enable the LAS service

Cautions

  1. Only the Volcengine primary account and IAM sub-users with the LASAIFullAccess permission can enable the LAS service.
  2. The Volcengine primary account has completed enterprise real-name verification. Users with individual real-name verification cannot fully experience LAS features by default, such as operator services, data processing, online services, and resource management. If users with individual real-name verification want to experience more features, they need to submit a ticket separately.
  3. After the LAS service is enabled, fees will be charged for billable items based on your usage. No fees are charged when the service is only enabled but not used. You can go to product billing in advance to view billable items and billing details. For more information, see Billing description.

Enable the service

  1. Log in to the LAS console.​If the current account is enabling the service for the first time, the service enablement page appears when you log in to the LAS console.

  2. Service authorization. When you log in for the first time, follow the on-screen prompts and click "Go to authorize" to complete cross-service access authorization. This grants the LAS service account access permissions to other products that the product depends on.

    Image=1603x
  3. On the right side of the page, select the region where you want to enable the service based on actual business requirements. LAS currently supports enabling the service in North China 2 (Beijing), East China 2 (Shanghai), South China 1 (Guangzhou), and Asia Pacific Southeast (Johor). Only North China 2 (Beijing) supports enabling full Data Lake AI capabilities.

  4. Select the corresponding region, read and select "I have read and agree to AI Data Lake Service LAS Terms of Service LAS Service Level Agreement", and click Enable now to complete enablement of the AI Data Lake Service product.

  5. (Optional) After enabling the service, if you log in to the LAS console and cannot see the entrances to the following features on the console page, your current operating account may be an account with "individual real-name verification". You can switch to an account with "enterprise real-name verification" to enable the service, or submit a ticket to apply for the corresponding features based on business requirements.

    Feature

    Description

    Data processing

    Provides workflow orchestration capabilities for built-in unstructured data processing operators to accelerate data cleansing.

    Dataset management

    Provides dataset management capabilities, including data query, data editing, version management, and data export.

    Resource management

    Manages various resources provided by LAS, including:

    • Compute queues: Support compute engines such as Spark and Ray, and are used for data computing and processing in RAG workflows.
    • Online service queues: Used for online service deployment to ensure high real-time performance and normal service operation.
    • Managed queues: Used for information hosting of other cloud product resources such as Kafka and VikingDB.

    Online services

    LAS provides one-stop service/model deployment capabilities. It supports deploying models or services as online services with one click, and allows users to access them from the public network, VPC private network, or bound CLB. Online services deployed on LAS support scaling, O&M monitoring, logs, and other capabilities.

Last updated: 2026.09.21 19:57:32