CAM中产品名 | 角色名称 | 角色类型 | 角色载体 |
---|---|---|---|
云原生数据库 TDSQL-C | CynosDB_QCSLinkedRoleInDBLog | 服务相关角色 | DBLog.cynosdb.cloud.tencent.com |
云原生数据库 TDSQL-C | CynosDBMysql_QCSLinkedRoleInKms | 服务相关角色 | kms.cynosdb.cloud.tencent.com |
云原生数据库 TDSQL-C | CynosDBMysql_QCSLinkedRoleInClslog | 服务相关角色 | clslog.cynosdb.cloud.tencent.com |
使用场景: 当前角色为云原生数据库(TDSQL-C)服务相关角色,该角色将在已关联策略的权限范围内访问您的其他云服务资源。
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"cls:ModifyKafkaRecharge",
"cls:DescribeKafkaRecharges",
"cls:DeleteKafkaRecharge",
"cls:CreateKafkaRecharge",
"cls:DeleteCloudProductLogTask"
],
"resource": "*"
}
]
}
使用场景: 当前角色为云原生数据库TDSQL-C(cynosdb)服务相关角色,该角色将在已关联策略的权限范围内访问您的其他云服务资源。
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"kms:GetServiceStatus",
"kms:ListKeyDetail",
"kms:CreateKey",
"kms:GenerateDataKey",
"kms:Decrypt",
"kms:BindCloudResource",
"kms:UnbindCloudResource"
],
"resource": [
"*"
]
}
]
}
使用场景: 当前角色为云原生数据库 TDSQL-C (CYNOSDB )服务相关角色,该角色将在已关联策略的权限范围内访问您的其他云服务资源。
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"cls:DescribeIndexs",
"cls:DescribeTopics",
"cls:DescribeIndex",
"cls:CreateIndex",
"cls:DeleteIndex",
"cls:ModifyIndex",
"cls:pushLog",
"cls:CreateLogset",
"cls:CreateTopic",
"cls:DescribeLogsets",
"cls:DeleteTopic",
"cls:DeleteLogset"
],
"resource": [
"*"
]
}
]
}
本页内容是否解决了您的问题?