tencent cloud

이 페이지는 현재 영어 만 지원하며보고있는 언어를 준비 중입니다.
关闭
전체 제품 문서
TDMQ for CKafka
문서TDMQ for CKafkaGetting StartedObtaining Access PermissionGranting Resource-Level Permissions to Sub-Accounts
Granting Resource-Level Permissions to Sub-Accounts
마지막 업데이트 시간:2024-01-09 14:45:02
Granting Resource-Level Permissions to Sub-Accounts
마지막 업데이트 시간: 2024-01-09 14:45:02

Overview

This document describes how to use the root account to authorize sub-accounts at the resource level. After successful authorization, the sub-accounts will have the capability to control a certain resource.

Prerequisites

You must have a Tencent Cloud root account and have activated the Cloud Access Management (CAM) service.
Your root account must have at least one sub-account, and you have completed the authorization as instructed in Getting Access Authorization.
You must have at least one CKafka instance.

Directions

By using the policy feature in the CAM console, you can grant a sub-account access to the CKafka resources owned by the root account. Taking cluster resource as an example, the following describes the detailed steps for granting the sub-account access to CKafka resources, which also apply to other types of resources.

Step 1. Obtain the CKafka cluster ID

1. Log in to the CKafka console with root account, select an existing cluster instance, and click it to enter the details page.



2. In Basic Info, the field ID indicates the ID of the current CKafka cluster.


Step 2. Create a new authorization policy

1. Log in to the CAM console and click Policies on the left sidebar.
2. Click Create Custom Policy > Create by Policy Generator.
3. In the visual policy generator, select Allow for Effect, enter CKafka in Service to filter, and select CKafka (ckafka).



4. Select All actions in Action, and you can also select the action type as needed.

5. In the Resource field, select Specific resources, find the ckafkaId resource type, and you can select Any resource of this type on the right to authorize all cluster resources, or click Add a six-segment resource description to authorize specific cluster resources.
6. If you click Add a six-segment resource description, enter the cluster ID for Resource in the pop-up dialog box. For how to obtain the cluster ID, see Step 1.

7. Click Next and enter a policy name as needed.
8. Click Select Users or Select User Groups to select the users or user groups that need to be granted resource permissions.

9. Click Complete. The sub-account with granted resource permissions will have the capability to access related resources.

Other authorization methods

문제 해결에 도움이 되었나요?
더 자세한 내용은 문의하기 또는 티켓 제출 을 통해 문의할 수 있습니다.
아니오

피드백

문의하기

고객의 업무에 전용 서비스를 제공해드립니다.

기술 지원

더 많은 도움이 필요하시면, 티켓을 통해 연락 바랍니다. 티켓 서비스는 연중무휴 24시간 제공됩니다.

연중무휴 24시간 전화 지원
중국 홍콩
+852 800 906 020 (무료)
캐나다
+1 888 605 7930 (무료)
영국
+44 808 196 4551 (무료)
미국
+1 844 606 0804 (무료)
호주
+61 1300 986 386 (무료)
EdgeOne 전화 번호
+852 300 80699
현지 서비스 핫라인은 지속적으로 추가 중입니다