Overview
CAM is a web-based Tencent Cloud service that helps you securely manage and control access to your Tencent Cloud resources. Using CAM, you can create, manage, and terminate users (user groups), and control who can access and use your Tencent Cloud resources through identity and policy management. For more information on CAM policies and how to use them, see Concepts. A root account can grant a sub-account or collaborator access to specified CLS resources.
Preset access policies
CLS offers two preset access policies to meet your basic access management demand.
QcloudCLSFullAccess: access to all CLS resources and actions, including creating log topics, modifying index configuration, deleting log topics, searching for logs, uploading logs, etc.
QcloudCLSReadOnlyAccess: only read access to CLS data; no CRUD access
Custom access policies
You can use a custom access policy to grant access at a finer granularity, for example, to allow a specific user to view the data of a specific log topic.
A custom access policy consists of two parts:
Action: The action a user is allowed to perform, such as searching for logs, modifying index configuration, uploading logs, and creating alarm policies.
Resource: The resources a user is allowed to operate on, such as a specific log topic, dashboard, and data processing task.
Configuring custom access policies can be a demanding process. The examples we offer in Access Policy Templates should meet most access management needs. You can also modify the examples based on your requirements. Detailed directions are as follows: 1. Log in to the console with the root account (or an account with CAM access). On the Policies page, click Create Custom Policy. 2. In the pop-up window, click Create by Policy Syntax.
3. On the Select Policy Template page, select Blank Template and click Next.
4. On the Edit Policy page, enter a policy name and policy content. For the latter, you can copy the content from Access Policy Templates. For example, to grant the sub-account permission to use LogListener, copy the policy as shown below: 5. Click Complete to save the policy. Then, you can associate it with a user/user group to grant the user/user group the corresponding operation permissions as instructed in Authorization Management.
문제 해결에 도움이 되었나요?