tencent cloud

Feedback

Cloud Data Warehouse

Last updated: 2024-11-26 09:51:52

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    Cloud Data Warehouse ClickHouse cdwch Supported Supported Resource level Partially supported

    Note:

    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    ActionAlterCkUser ActionAlterCkUser Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    ActionDmsAuthority dms authority Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    AddNewDictionary add dictionary Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    AuthorizedCNSql AuthorizedCNSql Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    ClosePublicCloudClb ClosePublicCloudClb Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    CreateBackUpSchedule CreateBackUpSchedule Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    CreateCNRegularPlan create regular plan Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    CreateEsLog CreateEsLog Resource level qcs::cdwch:${region}:uin/:cdwchInstance/${InstanceId} Supported
    CreateInstanceNew Create Instance Operation level * Supported
    CreatePublicCloudClb CreatePublicCloudClb Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DeleteBackUpData DeleteBackUpData Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DeleteCNRegularPlan delete regular plan Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DeleteCNUserConfig DeleteCNUserConfig Resource level qcs::cdwch:${Region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    ExecuteCNSql ExecuteCNSql Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    KillCNQueries KillCNQueries Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyCNCkUserPrivileges ModifyCNCkUserPrivileges Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyCNUserConfig ModifyCNUserConfig Resource level qcs::cdwch:${Region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyClusterConfigs ModifyClusterConfigs Resource level qcs::cdwch:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    ModifyDictionary modify dictionary Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyInstance Modify Information for Instance Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    ModifyInstanceConfigs Modify Instance Configs Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    ModifyInstanceDetails modify instance details Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyInstanceKeyValConfigs ModifyInstanceKeyValConfigs Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    ModifySecurityGroups ModifySecurityGroups Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyUserNewPrivilege ModifyUserNewPrivilege Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyZookeeperRestartSchedule ModifyZookeeperRestartSchedule Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    OpenBackUp OpenBackUp Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    OperateCNClusterStatus OperateCNClusterStatus Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    RebootInstances RebootInstances Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    RecoverBackUpJob RecoverBackUpJob Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    ScaleCNOutUpInstance scal out up instance Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    ScaleOutInstance scaleout instance Resource level qcs::cdwch:${Region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    TerminateInstance Terminate Instance Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    UpdateSparkJob UpdateSparkJob Operation level * Supported

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    CheckDictionarySourceConnection check dictionary Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeAvailableRegion DescribeAvailableRegion Operation level * Supported
    DescribeBackUpJob DescribeBackUpJob Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeBackUpJobDetail DescribeBackUpJobDetail Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeBackUpSchedule DescribeBackUpSchedule Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeBackUpTables DescribeBackUpTables Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeCNCkSql DescribeCNCkSql Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeCNCosSpec DescribeCNCosSpec Operation level * Supported
    DescribeCNDmsSqlHistory DescribeCNDmsSqlHistory Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeCNGoodsDetail Generate the GoodsDetail structure of the accounting-related interface Operation level * Supported
    DescribeCNInstances Get Instances List Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/* not supported
    DescribeCNRunningQuery DescribeCNRunningQuery Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeCNSlowQueryRecords DescribeCNSlowQueryRecords Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeCNSlowQueryTrend DescribeCNSlowQueryTrend Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeClusterConfigs DescribeClusterConfigs Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/$InstanceId not supported
    DescribeDictionarySourceDatabases describe db list Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeDictionarySourceTables describe dictionary source tables Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeFederationToken describe federation token Resource level qcs::cdwch:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeGoodsDetail Describe GoodsDetail Operation level * Supported
    DescribeInstance Get Instance Details Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeInstanceClusters DescribeInstanceClusters Operation level * Supported
    DescribeInstanceCommonNodes DescribeInstanceCommonNodes Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} not supported
    DescribeInstanceConfigs Describe Instance Configs Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    DescribeInstanceKeyValConfigs DescribeInstanceKeyValConfigs Operation level * Supported
    DescribeInstanceMonitorPort DescribeInstanceMonitorPort Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeInstanceNodes Get Node Information for Instance Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchinstanceId Supported
    DescribeInstanceOperations Describe Instance Operations Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    DescribeInstanceShards DescribeInstanceShards Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeInstanceState Describe Instance State Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    DescribeInstances Get Instances List Resource level qcs::cdwch:$region:$account:cdwchInstance/* Supported
    DescribeInstancesNew DescribeInstancesNew Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/* Supported
    DescribeInstancesV2 Get Instances List Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/* Supported
    DescribeMetricData Get Metric Data Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeMetricMeta Get MetaData about monitoring Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeOverviewData Get Metric Data for OverviewPage Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeRunningQuery DescribeRunningQuery Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeSlowQueryRecords DescribeSlowQueryRecords Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeSlowQueryTrend DescribeSlowQueryTrend Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceID} Supported
    DescribeSpec Describe Spec Operation level * Supported
    DescribeZookeeperRestartJob DescribeZookeeperRestartJob Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeZookeeperRestartSchedule DescribeZookeeperRestartSchedule Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} Supported
    ModifyCNInstance ModifyCNInstance Resource level qcs::cdwch::uin/${uin}:cdwchInstance/${InstanceId} not supported

    List Operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeAreaRegion DescribeAreaRegion Operation level * Supported
    DescribeCNSql DescribeCNSql Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    DescribeCkSqlApis DescribeCkSqlApis Resource level qcs::cdwch:${region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeInstanceForMonitor DescribeInstanceForMonitor Operation level * Supported
    DescribeRegionZone DescribeRegionZone Operation level * Supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support