Policy | Description | Required | Notes |
QcloudCamSubaccountsAuthorizeRoleFullAccess | Permission required for CAM sub-users to obtain permissions granted by service roles | No | |
QcloudCamRoleFullAccess | Full access to CAM roles | No | Permission to custom service roles to control access to data across services. For more information, see Custom Service Roles. |
QcloudEMRFullAccess | Full access to EMR | No | Full permission to use all EMR features. For more information, see Purchasing and managing EMR clusters. |
QcloudEMRReadOnlyAccess | Read-only access to EMR | No | Permission to view EMR features |
QcloudEMRPurchaseAccess | EMR finance permission | No | For more information, see Purchasing and managing EMR clusters. This permission is not required if you don't need to purchase EMR clusters or adjust their configurations. |
QcloudEMRPurchaseAccess
preset policy allows you to manage all users' permission to purchase EMR instances. It grants users the finance permissions of CVM, TencentDB, and EMR at the same time. To restrict users from purchasing CVM or TencentDB instances, do not grant the permission to place orders for the corresponding product.QcloudCamSubaccountsAuthorizeRoleFullAccess
permission can access other cloud services after being authorized.EMR_QCSRole
service role and grant the QcloudAccessForEMRRole
permission (for EMR to read CVM, CBS, TencentDB, COS, and other services) to the first EMR instance you purchase.EMR_QCSRole
service role and grant the QcloudAccessForEMRRoleInApplicationDataAccess
permission (for EMR big data applications to access other data services, such as COS) to EMR.QcloudCamSubaccountsAuthorizeRoleFullAccess
permission to sub-users or collaborators via the following steps:QcloudCamSubaccountsAuthorizeRoleFullAccess
policy, and then click Confirm.
QcloudAccessForEMRRoleInApplicationDataAccess
and QcloudAccessForEMRRole
policies with the root account, sub-user, or collaborator. The process is the same as step 2.QcloudEMRFullAccess
and the custom TencentDB purchase policy. In cases not involving resource purchase, such as service configuration management, only the QcloudEMRFullAccess
policy is required.Policy Type | Policy Name | Description |
Preset EMR policy | QcloudEMRFullAccess | Full access to EMR |
Preset EMR policy | QcloudEMRReadOnlyAccess | Read-only access to EMR |
Preset EMR policy | QcloudEMRPurchaseAccess | EMR finance permission |
QcloudEMRFullAccess
policy is used as an example in the following figure:QcloudEMRPurchaseAccess
is the same as step 2.QcloudCamRoleFullAccess
permission can precisely control COS bucket permissions and other cloud resource permissions. For more information see Custom Service Roles.
A root account can grant the QcloudCamRoleFullAccess
permission to a sub-user or collaborator via the following steps:QcloudCamRoleFullAccess
policy, and then click Confirm.
Was this page helpful?