tencent cloud

All product documents
CAM Examples
Last updated: 2024-10-23 10:24:14
CAM Examples
Last updated: 2024-10-23 10:24:14

Overview

You can grant a user the permission to view and use specific resources in the ENI console by using a Cloud Access Management (CAM) policy. This document describes how to grant the permission to view and use specified resources.

Examples

This example grants a sub-user the permission DeleteNetworkInterface to delete the ENI eni-abcdefgh.

Solution 1. Generating a policy by policy generator

With a policy created by the policy generator, you can create policy syntax automatically by selecting a service and operations, and defining resources. This method is highly recommended for its simplicity and flexibility.
1. Log in to the CAM console. Click Create custom policy in the upper-left corner.
2. In the pop-up window, click Create by policy generator to go to the Edit policy page.
3. Select the service in the Visual policy generator, enter the following information, and edit an authorization statement. (You can also choose JSON to use the policy syntax method to edit the policy, and the authorization effect is the same as the Visual policy generator).
Effect (required): You can select "Allow" or "Deny". Select "Allow" in this example.
Service (required): Select the desired product. Select "VPC" in this example.
Action (required): Select the desired operation. Select DeleteNetworkInterface in this example.
Resource (required): Select all resources or the desired resource. In this example, we use six-piece format, that is, qcs::vpc:$region:$account:eni/$networkInterfaceId, where the "$region", "$account:eni" and "$networkInterfaceId" are set to the actual region, account and ENI instance ID respectively.
4. After editing the policy authorization statement, click Next to enter the Associate with user/user group page.
Note:
The policy name is policygen by default, which is generated automatically in the console. The suffix number is generated based on the creation date. This is customizable.
You can also associate the policy with a user/user group after creation of the policy.
5. Click Complete.

Solution 2: Generating policy by policy syntax

The following policy allows you to delete the ENI instance eni-abcdefgh. You can associate the policy with a user or user group.
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"vpc:DeleteNetworkInterface"
],
"resource": [
"qcs::vpc::uin/10000xxxxxxx:eni/eni-abcdefgh"
]
}
]
}

Was this page helpful?
You can also Contact Sales or Submit a Ticket for help.
Yes
No

Feedback

Contact Us

Contact our sales team or business advisors to help your business.

Technical Support

Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

7x24 Phone Support
Hong Kong, China
+852 800 906 020 (Toll Free)
United States
+1 844 606 0804 (Toll Free)
United Kingdom
+44 808 196 4551 (Toll Free)
Canada
+1 888 605 7930 (Toll Free)
Australia
+61 1300 986 386 (Toll Free)
EdgeOne hotline
+852 300 80699
More local hotlines coming soon