diff --git a/docs/iam/permissions/ALL_META.TXT.json b/docs/iam/permissions/ALL_META.TXT.json index 52341cbfb..8aa9a9edd 100644 --- a/docs/iam/permissions/ALL_META.TXT.json +++ b/docs/iam/permissions/ALL_META.TXT.json @@ -5,15 +5,16 @@ { "uri":"permissions.html", "node_id":"permissions.xml", - "product_code":"", + "product_code":"iam", "code":"1", - "des":"Permissions are user management and cloud service management permissions. User management involves creating, deleting, and modifying users and granting permissions to use", - "doc_type":"", + "des":"By default, new IAM users do not have permissions assigned. You need to add a user to one or more groups, and attach permissions policies or roles to these groups. Users ", + "doc_type":"permissions", "kw":"Permissions", "search_title":"", "metedata":[ { - + "prodname":"iam", + "documenttype":"permissions" } ], "title":"Permissions", diff --git a/docs/iam/permissions/CLASS.TXT.json b/docs/iam/permissions/CLASS.TXT.json index 808b7620b..3eaae1f83 100644 --- a/docs/iam/permissions/CLASS.TXT.json +++ b/docs/iam/permissions/CLASS.TXT.json @@ -1,10 +1,10 @@ [ { - "desc":"Permissions are user management and cloud service management permissions. User management involves creating, deleting, and modifying users and granting permissions to use", - "product_code":"", + "desc":"By default, new IAM users do not have permissions assigned. You need to add a user to one or more groups, and attach permissions policies or roles to these groups. Users ", + "product_code":"iam", "title":"Permissions", "uri":"permissions.html", - "doc_type":"", + "doc_type":"permissions", "p_code":"", "code":"1" } diff --git a/docs/iam/permissions/en-us_image_0000001655594621.png b/docs/iam/permissions/en-us_image_0000002264517658.png similarity index 100% rename from docs/iam/permissions/en-us_image_0000001655594621.png rename to docs/iam/permissions/en-us_image_0000002264517658.png diff --git a/docs/iam/permissions/permissions.html b/docs/iam/permissions/permissions.html index cacb27b1b..02037b235 100644 --- a/docs/iam/permissions/permissions.html +++ b/docs/iam/permissions/permissions.html @@ -1,503 +1,1464 @@

Permissions

-

Permission Description

Permissions are user management and cloud service management permissions. User management involves creating, deleting, and modifying users and granting permissions to users. Cloud service management involves creating, viewing, modifying, and deleting resources of cloud services. After granting user management and cloud service management permissions to a user group, the users added to the user group can inherit permissions of the user group. User group-specific permissions simplify permission management.

+

Permission Description

By default, new IAM users do not have permissions assigned. You need to add a user to one or more groups, and attach permissions policies or roles to these groups. Users inherit permissions from the groups to which they are added and can perform specified operations on cloud services based on the permissions.

+
Scope: The projects for which permissions granted to a user group will be applied.
  • Global services: Services deployed without specifying physical regions, such as Object Storage Service (OBS) , are called global services. Permissions for these services must be assigned globally.
  • Region-specific projects: Services deployed in specific regions, such as Elastic Cloud Server (ECS) and Bare Metal Server (BMS), are called project-level services. Permissions for these services must be assigned in region-specific projects and will be applied only for specific regions.
    • All resources: Permissions will be applied for both global services and region-specific projects, including projects created later.
    • Region-specific projects: Permissions will be applied for the region-specific projects you select.
    +
-

Permission Relationship

+

Type: You can grant users permissions by using roles and policies. Policies are a type of fine-grained authorization mechanism that defines permissions required to perform operations on specific cloud resources under certain conditions. For details, see Permission.

+
  • For services that provide both policies and roles, preferentially use policies to assign permissions.
  • For services that support policy-based access control, you can create custom policies to supplement system-defined policies to allow or deny access to specific types of resources under certain conditions.
-

Default Permissions

The system provides two types of default permissions: user management and cloud service management.

- -
Table 1 User management permissions

Node Name

+

Permission Relationship

+
+

BASE

+
- - + + - - - + + - - - - - -

Service

Permission Name

+

Scope

Description

+

Policy/Role Name

+

Type

+

Description

Base

+

BASE

+

Security Administrator

+

Global services

Users with this permission can: Create, delete, and modify users. Grant permissions to users.

+

FullAccess

+

Policy

+

Full permissions for all services that support policy-based authorization.

IAM

+

All resources

Agent Operator

+

Tenant Guest

Users with this permission can switch to an entrusted user for processing services.

+

Role

-
-

Currently, policies only support fine-grained authorizationof ECS, EVS, and VPC. ECS Admin, ECS User, ECS Viewer, EVS Admin, EVS Viewer,VPC Admin, and VPC Viewer are preset fine-grained authorization policies.

+

Read-only permissions for all services except IAM.

+
NOTE:
  • If the permission scope is Global services, they will be applied for global services.
  • If the permission scope is All resources, they will be applied for both global services and all region-specific projects, including projects created later.
  • If the permission scope is Region-specific projects, they will be applied only for specific projects.
- -
+ + + + + + + + + +
Table 2 User group for cloud service management

Permission Name

+ +

All resources

+

Tenant Administrator

+

Full permissions for all services except IAM.

+
NOTE:
  • If the permission scope is Global services, they will be applied for global services.
  • If the permission scope is All resources, they will be applied for both global services and all region-specific projects, including projects created later.
  • If the permission scope is Region-specific projects, they will be applied only for specific projects.
+
+

Global services

+

Agent Operator

+

Permissions for switching roles to access resources of delegating accounts.

+
+
+ +

Compute

+
- - + + - - - + + - - - - - - - - - - - - + + - - - + + - - - - - - - - - + + - - - + + - - - - - - - - - - - - - - - + + - - - - - - - +

Service

Managed Cloud Resource

+

Scope

Description

+

Policy/Role Name

+

Type

+

Description

Agent Operator

+

Elastic Cloud Server (ECS)

+

(Project-level service)

Identity and Access Management

+

Region-specific projects

Permissions for switching roles to access resources of delegating accounts.

+

ECS FullAccess

+

Policy

+

Full permissions for ECS.

IAM ReadOnlyAccess

+

ECS ReadOnlyAccess

Identity and Access Management

-

Read-only permissions for IAM.

+

Read-only permissions for ECS.

CBR Administrator

+

ECS CommonOperations

Cloud Backup and Recovery

-

Administrator permissions for CBR. Users granted these permissions can operate and use all vaults, backups, and policies.

+

Permissions for starting, stopping, restarting, and querying ECSs.

CBR User

+

Server Administrator

Cloud Backup and Recovery

+

Role

Common user permissions for CBR. Users granted these permissions can create, view, and delete vaults and backups, but cannot create, update, or delete policies.

+

Full permissions for ECS. This role must be used together with the Tenant Guest role in the same project.

+

If a user needs to create, delete, or change resources of other services, the user must also be granted administrator permissions of the corresponding services in the same project.

+

For example, if a user needs to create a new VPC when creating an ECS, the user must also be granted permissions with the VPC Administrator role.

CBR Viewer

+

Bare Metal Server (BMS)

+

(Project-level service)

Cloud Backup and Recovery

+

Region-specific projects

Read-only permissions for CBR. Users granted these permissions can only view CBR data.

+

BMS FullAccess

+

Policy

+

Full permissions for BMS.

CCE Admin

+

Auto Scaling (AS)

+

(Project-level service)

Cloud Container Engine

+

Region-specific projects

Read and write permissions for CCE clusters, including creating, deleting, and updating a cluster.

+

AutoScaling FullAccess

+

Policy

+

Full permissions for the Auto Scaling service.

CCE Administrator

+

AutoScaling ReadOnlyAccess

Cloud Container Engine

-

All permissions related to CCE service resources. Users who use this permission must have Tenant Guest, Server Administrator, OBS Tenant Administrator, and ELB Administrator permissions.

+

Read-only permissions for AS.

CCE Viewer

+

AutoScaling Administrator

Cloud Container Engine

+

Role

Read-only permissions for CCE clusters.

+

Full permissions for all AS resources.

+

This role must be used together with the ELB Administrator, CES Administrator, Server Administrator, and Tenant Administrator roles in the same project.

CES Administrator

+

Image Management Service (IMS)

+

(Project-level service)

Cloud Eye

+

Region-specific projects

Permissions to view monitoring metrics as well as add, modify, and delete alarm rules. Users granted permissions of this policy must also be granted permissions of the Tenant Guest policy.

+

IMS FullAccess

+

Policy

+

Full permissions for IMS.

CSBS Administrator

+

FunctionGraph

+

(Project-level service)

Cloud Server Backup Service

+

Region-specific projects

Permissions to create, restore, and delete backups of ECSs, and manage backup policies. The creation, restoration, and management permissions depend on the Server Administrator permission. If the Server Administrator permission is unavailable, ECS information cannot be obtained when users create and restore backups. If the Server Administrator permission is unavailable, ECS information cannot be obtained when users associate ECSs with backup policies..

+

FunctionGraph FullAccess

+

Policy

+

Full permissions for FunctionGraph.

CSS Administrator

+

FunctionGraph ReadOnlyAccess

Cloud Search Service

-

Management permissions on all CSS resources.The permissions depend on the Tenant Guest and Server Administrator permissions. CSS cannot run properly if either of the permissions is unavailable.

+

Read-only permissions for FunctionGraph.

CTS Administrator

+

FunctionGraph CommonOperations

Cloud Trace Service

-

Full permissions for CTS. This policy depends on the Tenant Guest policy in the same project and the Tenant Administrator policy in the OBS project.

+

Common operation permissions for FunctionGraph, including permissions for querying functions and triggers and invoking functions.

DCS Administrator

+

FunctionGraph Administrator

Distributed Cache Service

+

Role

Permissions to: Create, start, stop, restart, and delete DCS instances. Change passwords of DCS instances. Configure DCS instance parameters.

+

Permissions for managing FunctionGraph functions and triggers.

+

This role must be used together with the Tenant Guest role in the same project.

DDS Administrator

+

FunctionGraph Invoker

Document Database Service

-

Users who have this right, plus Tenant Guest and Server Administrator rights, can perform any operations on DDS, including creating, deleting, rebooting, or scaling up DB instances, configuring database parameters, and restoring DB instances. Users who have this right but not the Tenant Guest or Server Administrator right cannot use DDS. Users who have the VPC Administrator right can create VPCs or subnets. Users who have the CES Administrator right can add or modify alarm rules for DB instances.

+

Permissions for querying FunctionGraph functions and triggers.

DIS Administrator

+

Dedicated Host (DeH)

+

(Project-level service)

Data Ingestion Service

+

Region-specific projects

Permissions to: Create, delete, query, and list DIS streams. Push data to DIS streams or pull data from them. Query stream monitoring metrics.

+

DeH FullAccess

+

Policy

+

Full permissions for DeH.

DMS Administrator

+

DeH CommonOperations

Distributed Message Service

-

Administrator permissions for DMS. Users granted these permissions can perform all operations on DMS queues.

+

Basic operation permissions for DeH.

DNS Administrator

+

DeH ReadOnlyAccess

Domain Name Service

-

Permissions to create, query, and delete zones and record sets.

+

Read-only permissions for DeH. Users with these permissions can only query DeHs.

DWS Administrator

+
+
+
+

Storage

+
+ + + + + + + - - + + - - - - - - - - - - - - + + - - - - - - + + - - - - - - - - - + + - - - + + - - - - - - - - - + + - - - + + - +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Object Storage Service (OBS)

+

(Global service)

Data Warehouse Service

+

Global services

Management permissions on all DWS resources. The permissions depend on the Tenant Guest and Server Administrator permissions. DWS cannot run properly if either of the permissions is unavailable. If DWS users are to create a VPC or a subnet, the VPC Administrator permission is required. If DWS users are to view monitoring metrics of data warehouse clusters, the CES Administrator permission is required.

+

OBS OperateAccess

+

Policy

+

Users with this permission can perform all operations specified by OBS ReadOnlyAccess and perform basic object operations, such as uploading objects, downloading objects, deleting objects, and obtaining object ACLs.

DWS Database Access

+

OBS Administrator

Data Warehouse Service

-

DWS Database Access permission. Users with this permission can generate temporary database user credentials based on IAM users to connect to the DWS cluster database.

+

Allows you to perform any operation on all OBS resources under the account.

ECS Admin

+

OBS ReadOnlyAccess

Elastic Cloud Server

-

All ECS operation permissions, including creating, deleting, and viewing ECSs and modifying ECS specifications.

+

Users with this permission can list buckets, obtain basic bucket information, obtain bucket metadata, and list objects.

ECS User

+

OBS Buckets Viewer

Elastic Cloud Server

+

Role

General operation permissions on ECSs (such as viewing and restarting ECSs), but not advanced operation permissions (such as creating or deleting ECSs, or reinstalling/changing ECS OSs).

+

Users with this permission can list buckets, obtain basic bucket information, and obtain bucket metadata.

ECS Viewer

+

Elastic Volume Service (EVS)

+

(Project-level service)

Elastic Cloud Server

+

Region-specific projects

ECS read-only permissions, such as viewing ECSs.

+

EVS Admin

+

Role

+

All EVS operation permissions, including creating, deleting, and viewing EVS disks and modifying EVS disk specifications.

ELB Administrator

+

EVS Viewer

Elastic Load Balancing

-

Permissions on all ELB resources. This permission depends on the VPC Administrator, Server Administrator, CES Administrator, and OBS Administrator permissions. Users who use the ELB Administrator permission cannot use some functions provided by the ELB service if they do not have the preceding permissions. If users who use this permission do not have the VPC Administrator and Server Administrator permissions, they cannot create or delete load balancers and backend servers. If users who use this permission do not have the CES Administrator permission, monitoring data cannot be reported to Cloud Eye. If users who use this permission do not have the OBS Administrator permission, data backups cannot be stored in OBS buckets.

+

EVS read-only permission, such as viewing EVS disks and EVS disk details.

EVS Admin

+

Cloud Backup and Recovery (CBR)

+

(Project-level service)

Elastic Volume Service

+

Region-specific projects

All EVS operation permissions, including creating, deleting, and viewing EVS disks and modifying EVS disk specifications.

+

CBR FullAccess

+

Policy

+

Administrator permissions for using all vaults and policies on CBR.

EVS Viewer

+

CBR BackupsAndVaultsFullAccess

Elastic Volume Service

-

EVS read-only permission, such as viewing EVS disks and EVS disk details.

+

Common user permissions for creating, viewing, and deleting vaults on CBR.

GaussDB FullAccess

+

CBR ReadOnlyAccess

GaussDB(for MySQL)

-

Full permissions for GaussDB

+

Read-only permissions for viewing data on CBR.

GaussDB ReadOnlyAccess

+

Storage Disaster Recovery Service (SDRS)

+

(Project-level service)

GaussDB(for MySQL)

+

Region-specific projects

Read-only permissions for GaussDB

+

SDRS Administrator

+

Role

+

Full permissions for SDRS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.

IAM ReadOnlyAccess

+

Scalable File Service (SFS)

+

(Project-level service)

Identity and Access Management

+

Region-specific projects

Read-only permissions for IAM.

+

SFS Turbo FullAccess

+

Policy

+

All permissions of Scalable File Service (SFS Turbo).

IMS Administrator

+

SFS Turbo ReadOnlyAccess

Image Management Service

-

Permissions to create, modify, delete, and share images. The permissions depend on the Server Administrator and OBS Tenant Administrator permissions. To create an image using an ECS, users need to configure this permission as well as the Server Administrator permission. To create an image using an image file, users need to configure this permission as well as the OBS Tenant Guest permission. To export an image, users need to configure this permission as well as the OBS Tenant Administrator permission. To query predefined tags when adding a tag to an image or searching for an image by tag, users need to configure this permission as well as the TMS Administrator permission.

+

The read-only permissions to all Scalable File Service (SFS Turbo) resources.

KMS Administrator

+

SFS Administrator

Key Management Service

+

Role

Permissions to: Create, enable, disable, schedule the deletion of, and cancel the scheduled deletion of CMKs. Query the list of CMKs and information about CMKs. Create random numbers. Create DEKs. Create DEKs without plaintext. Encrypt and decrypt DEKs. Change the aliases and description of CMKs. Create, revoke, and query grants on CMKs. Import, delete CMK material. Add, delete, and query CMK tags.

+

Scalable File Service Administrator.

LTS Administrator

+

Cloud Server Backup Service (CSBS)

+

(Project-level service)

Log Tank Service

+

Region-specific projects

Permissions to create log groups, query log groups, delete log groups, create log topics, query log topics, and delete log topics.

+

CSBS Administrator

+

Role

+

Full permissions for CSBS.

+

This role must be used together with the Server Administrator role in the same project.

ModelArts CommonOperations

+

Volume Backup Service (VBS)

+

(Project-level service)

ModelArts

+

Region-specific projects

Common user permissions for ModelArts. Users granted these permissions can operate and use ModelArts, but cannot manage dedicated resource pools.

+

VBS Administrator

+

Role

+

Full permissions for VBS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.

ModelArts FullAccess

+
+
+
+

Network

+
+ + + + + + + - - + + - - - - - - - - - - - - + + - - - - - - - - - + + - - - - - - - - - + + - - - - - - - - - + + - - - - - - - - - + + - - - - - - - - - + + - - - + + - - - - +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Virtual Private Cloud (VPC)

+

(Project-level service)

ModelArts

+

Region-specific projects

Administrator permissions for ModelArts. Users granted these permissions can operate and use ModelArts.

+

VPC FullAccess

+

Policy

+

Full permissions for VPC.

MRS Administrator

+

VPC ReadOnlyAccess

MapReduce Service

-

Permissions to view MRS overview information, operation logs, cluster information, job information, HDFS file operation information, alarm list, and MRS Manager portal.

+

Read-only permissions for VPC.

NAT Gateway Administrator

+

VPC Administrator

NAT Gateway

+

Role

Permissions to create, delete, modify, and query all resources of the NAT Gateway service. The permissions depend on the Tenant Guest permission. If a NAT user needs resources, including VPCs, subnets, and EIPs, to create NAT gateways, the VPC Administrator and Server Administrator permissions are required.

+

Permissions for VPC, excluding permissions for creating, modifying, deleting, and viewing security groups and security group rules.

+

This role must be used together with the Tenant Guest role in the same project.

OBS Buckets Viewer

+

Server Administrator

Object Storage Service

-

Operation permissions: listing buckets, obtaining basic bucket information, obtaining bucket metadata, and listing objects.

+

Permissions for performing operations on EIPs, security groups, and ports.

+

This role must be used together with the Tenant Guest role in the same project.

RDS Administrator

+

Elastic Load Balance (ELB)

+

(Project-level service)

Relational Database Service

+

Region-specific projects

Users who have this right, plus Tenant Guest and Server Administrator rights, can perform any operations on RDS and DDS, including creating, deleting, rebooting, or scaling up DB instances, configuring database parameters, and restoring DB instances. Users who have this right but not the Tenant Guest or Server Administrator right cannot use RDS and DDS. NOTE Users who have the VPC Administrator right can create VPCs or subnets. Users who have the CES Administrator right can add or modify alarm rules for DB instances.

+

ELB FullAccess

+

Policy

+

Full permissions for ELB.

RDS ManageAccess

+

ELB ReadOnlyAccess

Relational Database Service

-

Database administrator permissions for all operations except deleting RDS resources.

+

Read-only permissions for ELB.

RDS FullAccess

+

ELB Administrator

Relational Database Service

+

Role

Full permissions for Relational Database Service.

+

Full permissions for ELB.

+

This role must be used together with the Tenant Guest role in the same project.

RDS ReadOnlyAccess

+

NAT Gateway

+

(Project-level service)

Relational Database Service

+

Region-specific projects

Read-only permissions for Relational Database Service.

+

NAT FullAccess

+

Policy

+

Full permissions for NAT Gateway.

RTS Administrator

+

NAT ReadOnlyAccess

Resource Template Service

-

Operation permissions: All operations on RTS. To orchestrate a resource, users with this permission must also have the Administrator permission. For example: Users with this permission and the Server Administrator permission can create stacks for ECS, VPC, EVS, and IMS resources. Users with this permission and the ELB Administrator permission can create an ELB resource stack.

+

Read-only permissions for NAT Gateway.

SDRS Administrator

+

NAT GatewayAdministrator

Storage Disaster Recovery Service

+

Role

Users with this permission can create, modify, delete, and query SDRS resources.

+

Full permissions for NAT Gateway.

+

This role must be used together with the Tenant Guest role in the same project.

Security Administrator

+

Direct Connect

+

(Project-level service)

Base

+

Region-specific projects

Full permissions for IAM.

+

Direct Connect Administrator

+

Role

+

Has all permissions for Direct Connect resources.

+

For permissions of this role to take effect, users must also have the Tenant Guest and VPC Administrator permissions.

Server Administrator

+

DCAAS FullAccess

Base

+

Policy

For the EVS service, users with this permission can create, modify, and delete EVS disks. For the ECS service, users with this permission can create, modify, and delete ECSs.This role must be used together with the Tenant Guest role in the same project. For the VPC service, users with this permission and the Tenant Guest permission can perform all operations on security groups, security group rules, ports, firewalls, elastic IP addresses (EIPs), and bandwidth. For the IMS service, users with this permission can create, delete, query, and modify images.This role must be used together with the IMS Administrator role in the same project.

+

Full permissions for Direct Connect.

SFS Administrator

+

DCAAS ReadOnlyAccess

Scalable File Service

-

Users with both this permission and the Tenant Guest permission can create, delete, query, expand, and downsize the file system.

+

Read-only permissions for Direct Connect.

SFS Turbo Administrator

+

Virtual Private Network (VPN)

+

(Project-level service)

Scalable File Service

+

Region-specific projects

Users with both this permission and the Tenant Guest permission can create, delete, query, and expand the SFS Turbo file system.

+

VPN Administrator

+

Role

+

Administrator permissions for VPN.

+

This role must be used together with the Tenant Guest and VPC Administrator roles in the same project.

SFS Turbo Viewer

+

VPN FullAccess

Scalable File Service

+

Policy

Read-only permissions. Users granted these permissions can only view file system data.

+

Full permissions for VPN.

SMN Administrator

+

VPN ReadOnlyAccess

Simple Message Notification

-

Permissions to: Create, modify, delete, and view topics. Create, delete, and view subscriptions. Create, modify, delete, and view message templates.

+

Read-only permissions for VPN.

SWR Administrator

+

Domain Name Service (DNS)

+

(Project-level service)

Software Repository for Container

+

Region-specific projects

All SWR operation permissions, including pushing and pulling images, and granting permissions.

+

DNS Administrator

+

Role

+

Full permissions for DNS.

+

This role must be used together with the Tenant Guest and VPC Administrator roles in the same project.

Tenant Administrator

+

DNS FullAccess

Base

+

Policy

Administrator permissions for all services except IAM.

+

Full permissions for DNS.

Tenant Guest

+

DNS ReadOnlyAccess

Base

-

Read-only permissions for all services except IAM.

+

Read-only permissions for DNS. Users granted these permissions can only view DNS resources.

TMS Administrator

+

VPC Endpoint (VPCEP)

+

(Project-level service)

Tag Management Service

+

Region-specific projects

Users with this permission can create, modify, and delete predefined tags.

+

VPCEndpoint Administrator

+

Role

+

Full permissions for VPCEP.

+

This role must be used together with the Server Administrator, VPC Administrator, and DNS Administrator roles in the same project.

VBS Administrator

+

Enterprise Router

+

(Project-level service)

Volume Backup Service

+

Region-specific projects

Permissions to create backups, delete backups, and restore data using backups. This permission depends on the ServerAdministrator and Tenant Guest permissions. The VBS administrator must have permissions to manage EVS disks and read images.

+

ER FullAccess

+

Policy

+

Full permissions for ER.

VPC Admin

+

ER ReadOnlyAccess

Virtual Private Cloud

-

All VPC operation permissions, including creating, querying, modifying, and deleting VPCs, subnets, and security groups.

+

Read-only permissions for ER.

VPC Administrator

+
+
+
+

Containers

+
+ + + + + + + - - + + - - - - - - - - - + + - - - - - - - - - - - - + + - +
Table 1 User management permissions

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Cloud Container Engine (CCE)

+

(Project-level service)

Virtual Private Cloud

+

Region-specific projects

All operation permissions on VPCs, subnets, ports, VPNs, and Direct Connect resources. A user with the VPC Administrator permission must have the Tenant Guest permission.

+

CCE FullAccess

+

Policy

+

Full permissions for CCE.

VPC Viewer

+

CCE ReadOnlyAccess

Virtual Private Cloud

-

VPC real-only permission, such as querying VPCs.

+

Permissions to view CCE cluster resources, excluding namespace-level permissions for clusters that have Kubernetes RBAC enabled.

VPCEndpoint Administrator

+

CCE Administrator

VPC Endpoint

+

Role

Full permissions for VPCEP. This role must be used together with the Server Administrator, VPC Administrator, and DNS Administrator roles in the same project.

+

Read and write permissions for CCE clusters and all resources (including workloads and services) in the clusters.

+

This role depends on the following permissions:

+

Global services: OBS Buckets Viewer.

+

Region-specific projects (same projects): Tenant Guest, Server Administrator, ELB Administrator, SFS Administrator, SWR Admin, and APM FullAccess.

+
NOTE:

Users also granted permissions with the NAT Gateway Administrator role can use NAT Gateway functions for clusters.

+

WAF Administrator

+

Cloud Container Instance (CCI)

+

(Project-level service)

Web Application Firewall

+

Region-specific projects

Permissions to: Create and delete WAF instances. Configure, enable, disable WAF instances. Modify the protection policies of WAF instances. Configure alarm notification for WAF instances. Query the WAF instance list and details. Authenticate the domain name of a WAF instance.

+

CCI FullAccess

+

Policy

+

Full permissions for CCI. Users granted these permissions can create, delete, query, and update all CCI resources.

Anti-DDoS Administrator

+

CCI ReadOnlyAccess

Anti-DDoS

-

Permissions to enable, disable, and modify configurations. This permission depends on the Tenant Guest permission and must have permission to query EIPs in VPCs.

+

Read-only permissions for CCI. Users granted these permissions can only view CCI resources.

DRS Administrator

+

CCI CommonOperations

Data Replication Service

-

Basic permission, which must be added when DRS is used.Dependent on the Tenant Guest, Server Administrator, and RDS Administrator policies.

+

Common user permissions for CCI. Users granted these permissions can perform all operations except creating, deleting, and modifying role-based access control (RBAC) policies, networks, and namespaced resources.

DRS FullAccess

+

CCI Administrator

Data Replication Service

+

Role

Dependent on the VPC FullAccess, RDS ReadOnlyAccess, and SMN Administrator, OBS Administrator, and EPS ReadOnlyAccess policies.

+

Administrator permissions for CCI. Users granted these permissions can create, delete, query, and update all CCI resources.

DRS FullWithOutDeletePermission

+

Software Repository for Container (SWR)

+

(Project-level service)

Data Replication Service

+

Region-specific projects

Dependent on the VPC FullAccess, RDS ReadOnlyAccess, and SMN Administrator, and OBS Administrator policies.

+

SWR Administrator

+

Role

+

All SWR operation permissions, including pushing and pulling images, and granting permissions.

DRS ReadOnlyAccess

+
+
+
+

Security & Compliance

+
+ + + + + + + - - + + - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Anti-DDoS

+

(Project-level service)

+

+

Data Replication Service

+

Region-specific projects

+

+

Configure the following policies as required:

-

RDS ReadOnlyAccess: This parameter needs to be configured when RDS is selected.

-

SMN Administrator: This parameter needs to be configured when SMN is selected.

+

Anti-DDoS Administrator

+

Role

+

Full permissions for Anti-DDoS.

+

This role must be used together with the Tenant Guest role in the same project.

GeminiDB FullAccess

+

Anti-DDoS FullAccess

GeminiDB

+

Policy

+

Full permissions for GeminiDB.

+

All permissions for Anti-DDoS.

GeminiDB ReadOnlyAccess

+

Anti-DDoS ReadOnlyAccess

GeminiDB

+

Read-only permissions for Anti-DDoS.

Read-only permissions for GeminiDB.

+

Host Security Service (HSS)

+

(Project-level service)

+

Region-specific projects

+

+

+

HSS Administrator

+

Role

+

Full permissions for HSS.

+

HSS FullAccess

+

Policy

+

Full permissions for HSS.

+

HSS ReadOnlyAccess

+

Read-only permissions for HSS.

+

Database Security Service (DBSS)

+

(Project-level service)

+

Region-specific projects

+

DBSS System Administrator

+

Role

+

Full permissions for DBSS.

+

DBSS Audit Administrator

+

Security auditing permissions for DBSS.

+

DBSS Security Administrator

+

Security protection permissions for DBSS.

+

DBSS FullAccess

+

Policy

+

Full permissions for DBSS.

+

DBSS ReadOnlyAccess

+

Read-only permissions for DBSS. Users granted these permissions can only view this service and cannot configure resources in it.

+

Web Application Firewall (WAF)

+

(Project-level service)

+

+

Region-specific projects

+

WAF Administrator

+

Role

+

Permissions to: Create and delete WAF instances. Configure, enable, disable WAF instances. Modify the protection policies of WAF instances. Configure alarm notification for WAF instances. Query the WAF instance list and details. Authenticate the domain name of a WAF instance.

+

Cloud Firewall (CFW)

+

(Project-level service)

+

Region-specific projects

+

CFW FullAccess

+

Policy

+

Full permissions for CFW.

+
+
+
+

Management & Governance

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Identity and Access Management (IAM)

+

(Global service)

+

Global service

+

IAM ReadOnlyAccess

+

Policy

+

Read-only permissions for IAM.

+

Agent Operator

+

Role

+

Permissions for switching roles to access services of a delegating account.

+

Cloud Eye

+

(Project-level service)

+

Region-specific projects

+

CES Administrator

+

Role

+

Administrator permissions for Cloud Eye

+

CES FullAccess

+

Policy

+

Administrator permissions for Cloud Eye. Users granted these permissions can perform all operations on Cloud Eye.

+

CES ReadOnlyAccess

+

Read-only permissions for Cloud Eye. Users granted these permissions can only view Cloud Eye data.

+

Application Operations Management (AOM)

+

(Project-level service)

+

Region-specific projects

+

AOM Admin

+

Policy

+

+

Administrator permissions for AOM. Users granted these permissions can operate and use AOM.

+

AOM Viewer

+

Read-only permissions for AOM. Users granted these permissions can only view AOM data.

+

Application Performance Management (APM)

+

(Project-level service)

+

+

Region-specific projects

+

+

APM FullAccess

+

Policy

+

+

All permissions for APM.

+

APM ReadOnlyAccess

+

Read-only permissions for APM.

+

APM Administrator

+

Role

+

Administrator for APM.All permissions of APM.

+

Cloud Trace Service (CTS)

+

(Project-level service)

+

Region-specific projects

+

CTS FullAccess

+

Policy

+

Full permissions for CTS.

+

CTS ReadOnlyAccess

+

Read-only permissions for CTS.

+

Log Tank Service (LTS)

+

(Project-level service)

+

Region-specific projects

+

LTS Administrator

+

Role

+

Permissions to create log groups, query log groups, delete log groups, create log topics, query log topics, and delete log topics.

+

Tag Management Service (TMS)

+

(Global service)

+

Global services

+

TMS Administrator

+

Role

+

Users with this permission can create, modify, and delete predefined tags.

+

Resource Template Service (RTS)

+

(Project-level service)

+

Region-specific projects

+

RTS Administrator

+

Role

+

Operation permissions: All operations on RTS. To orchestrate a resource, users with this permission must also have the Administrator permission. For example: Users with this permission and the Server Administrator permission can create stacks for ECS, VPC, EVS, and IMS resources. Users with this permission and the ELB Administrator permission can create an ELB resource stack.

+

Config

+

(Global service)

+

Global services

+

Config FullAccess

+

Policy

+

Full permissions for Config

+

Config ReadOnlyAccess

+

Read-only permissions for Config.

+
+
+
+

Application

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Cloud Service Engine (CSE)

+

Region-specific projects

+

CES Administrator

+

Role

+

Permissions to view monitoring metrics as well as add, modify, and delete alarm rules. Users granted permissions of this policy must also be granted permissions of the Tenant Guest policy.

+

Distributed Cache Service (DCS)

+

(Project-level service)

+

Region-specific projects

+

DCS FullAccess

+

Policy

+

Full permissions for DCS.

+

DCS UserAccess

+

Common user permissions for DCS operations except creating, modifying, deleting, and scaling instances.

+

DCS ReadOnlyAccess

+

Read-only permissions for DCS.

+

DCS Administrator

+

Role

+

Full permissions for DCS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.

+

Distributed Message Service (DMS)

+

(Project-level service)

+

+

+

+

+

Region-specific projects

+

+

+

+

+

DMS UserAccess

+

Policy

+

+

+

+

+

+

Common user permissions for DMS (DMS for Kafka and DMS for RabbitMQ), excluding permissions for creating, modifying, deleting, scaling up instances and dumping.

+

DMS ReadOnlyAccess

+

Read-only permissions for DMS (DMS for Kafka and DMS for RabbitMQ). Users granted these permissions can only view DMS data.

+

DMS FullAccess

+

Administrator permissions for DMS (DMS for Kafka and DMS for RabbitMQ). Users granted these permissions can perform all operations on DMS.

+

DMS VPCAccess

+

VPC operation permissions to assign to DMS agencies.

+

DMS KMSAccess

+

KMS operation permissions to assign to DMS agencies.

+

DMS ELBAccess

+

ELB operation permissions to assign to DMS agencies.

+

DMSAgencyCheckAccessPolicy

+

IAM operation permissions to assign to DMS agencies.

+

Simple Message Notification (SMN)

+

(Project-level service)

+

Region-specific projects

+

SMN Administrator

+

Role

+

Full permissions for SMN.

+

This role must be used together with the Tenant Guest role in the same project.

+

SMN FullAccess

+

Policy

+

Full permissions for SMN.

+

SMN ReadOnlyAccess

+

Read-only permissions for SMN.

+

API Gateway (APIG)

+

(Project-level service)

+

Region-specific projects

+

APIG Administrator

+

Role

+

Administrator permissions for API Gateway. Users granted these permissions can use all functions of the shared and dedicated gateways.

+

To use VPC channels, the user must also be assigned the VPC Administrator role.

+

To use custom authentication, the user must also be assigned the FunctionGraph Administrator role.

+

APIG FullAccess

+

Policy

+

+

Full permissions for API Gateway. Users granted these permissions can use all functions of dedicated API gateways.

+

APIG ReadOnlyAccess

+

Read-only permissions for API Gateway. Users granted these permissions can only view dedicated API gateways.

+
+
+
+

Database

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

Relational Database Service (RDS)

+

(Project-level service)

+

Region-specific projects

+

RDS FullAccess

+

Policy

+

Full permissions for RDS.

+

RDS ReadOnlyAccess

+

Read-only permissions for RDS.

+

RDS ManageAccess

+

Database administrator permissions for all operations except deleting RDS resources.

+

RDS Administrator

+

Role

+

Full permissions for RDS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.

+

Document Database Service (DDS)

+

(Project-level service)

+

Region-specific projects

+

DDS Administrator

+

Role

+

Users who have this right, plus Tenant Guest and Server Administrator rights, can perform any operations on DDS, including creating, deleting, rebooting, or scaling up DB instances, configuring database parameters, and restoring DB instances. Users who have this right but not the Tenant Guest or Server Administrator right cannot use DDS. Users who have the VPC Administrator right can create VPCs or subnets. Users who have the CES Administrator right can add or modify alarm rules for DB instances.

+

Data Replication Service (DRS)

+

(Project-level service)

+

Region-specific projects

+

DRS FullAccess

+

Policy

+

+

Full permissions for DRS.

+

DRS ReadOnlyAccess

+

Read-only permissions for DRS.

+

DRS Administrator

+

Role

+

Full permissions for DRS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.

+

Data Admin Service (DAS)

+

(Project-level service)

+

+

Region-specific projects

+

+

DAS Administrator

+

Role

+

DAS administrator with full permissions.

+

This role must be used together with the Tenant Guest role in the same project.

+

DAS FullAccess

+

Policy

+

Full permissions for DAS.

+

Distributed Database Middleware (DDM)

+

(Project-level service)

+

+

+

Region-specific projects

+

+

+

DDM FullAccess

+

Policy

+

+

+

Full permissions for DDM.

+

DDM CommonOperations

+

Common permissions for DDM.

+

Users with common permissions cannot perform the following operations:

+
  • Buying DDM instances
  • Deleting DDM instances
  • Scaling up instances
  • Rolling back instances or clearing data when scale-up fails
+

DDM ReadOnlyAccess

+

Read-only permissions for DDM.

+

GeminiDB

+

(Project-level service)

+

Region-specific projects

+

GeminiDB FullAccess

+

Policy

+

Full permissions for multi-model NoSQL databases.

+

GeminiDB ReadOnlyAccess

+

Read-only permissions for multi-model NoSQL databases.

+

GaussDB

+

(Project-level service)

+

Region-specific projects

+

GaussDB FullAccess

+

Policy

+

Full permissions for GaussDB.

+

GaussDB ReadOnlyAccess

+

Read-only permissions for GaussDB.

+
+
+
+

Enterprise Intelligence

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

Service

+

Scope

+

Policy/Role Name

+

Type

+

Description

+

ModelArts

+

(Project-level service)

+

Region-specific projects

+

ModelArts FullAccess

+

Policy

+

Administrator permissions for performing all operations on ModelArts.

+

ModelArts CommonOperations

+

Permissions for performing all operations except managing dedicated resource pools on ModelArts.

+

DataArts Studio

+

(Project-level service)

+

Region-specific projects

+

DARTS Administrator

+

Role

+

Instance administrator who has all management permissions on a DataArts Studio instance and its workspaces, permissions of dependent services, and service operation permissions in all workspaces.

+

DARTS User

+

Common user who has permissions to view a DataArts Studio instance and its workspaces, and the permissions of dependent services. After assigned a role, a common user has permissions of the role to perform service operations.

+

MapReduce Service (MRS)

+

(Project-level service)

+

Region-specific projects

+

+

+

+

MRS FullAccess

+

Policy

+

+

+

Full permissions for MRS.

+

MRS CommonOperations

+

Common user permissions for MRS operations except creating and deleting resources.

+

MRS ReadOnlyAccess

+

Read-only permissions for MRS.

+

MRS Administrator

+

Role

+

Full permissions for MRS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.

+

GaussDB(DWS)

+

(Project-level service)

+

+

+

+

Region-specific projects

+

+

+

+

DWS FullAccess

+

Policy

+

+

Database administrator permissions for GaussDB(DWS). Users granted these permissions can perform all operations on GaussDB(DWS).

+

DWS ReadOnlyAccess

+

Read-only permissions for GaussDB(DWS). Users granted these permissions can only view GaussDB(DWS) data.

+

DWS Administrator

+

Role

+

+

Database administrator permissions for GaussDB(DWS). Users granted these permissions can perform operations on all GaussDB(DWS) resources.

+

Users granted permissions of the VPC Administrator policy can create VPCs and subnets.

+

Users granted permissions of the Cloud Eye Administrator policy can view monitoring information of data warehouse clusters.

+

If you need to create an agency, you also need to configure the Security Administrator permission.

+

DWS Database Access

+

GaussDB(DWS) database access permission. Users with this permission can generate the temporary database user credentials based on IAM users to connect to the database in the GaussDB(DWS) cluster.

+

Data Lake Insight (DLI)

+

(Project-level service)

+

Region-specific projects

+

DLI Service Admin

+

Role

+

+

Full permissions for DLI.

+

DLI FullAccess

+

Policy

+

Full permissions for DLI. Users granted these permissions can perform all operations on DLI.

+

DLI ReadOnlyAccess

+

Users granted these permissions can only view the queue list, job list, job details, database list, table list, table creation statements, table fields, and job metadata such as job creation, update, and deletion.

+

Cloud Search Service (CSS)

+

(Project-level service)

+

Region-specific projects

+

CSS Administrator

+

Role

+

Full permissions for CSS.

+

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.