How to set the permission of VPC

举报
Huawei Cloud is Cool 发表于 2020/03/13 19:27:40 2020/03/13
【摘要】 How to set the permission of VPC How to set the permission of IAM to meet the customer’s requirement? Customer needs a sub-user, which has all permission except the VPC (can’t change ...

How to set the permission of VPC

       How to set the permission of IAM to meet the customer’s requirement?

         Customer needs a sub-user, which has all permission except the VPC (can’t change the security group).

         Now this is the best practice on Huawei cloud, you can follow this guide to realize it.

1.         Login in —— console —— IAM —— create s sub-user:

1584098036415140.png

2.         Create a user group

1584097929416103.png

3.         Add the new sub-user to this group

1584098054550838.png

4.         Click the permissions to create the custom policy. (Apply the permission first)

1584098069657918.png

         After you have the permission, you can have some default permission and also can create new one by yourself.

1584098086124169.png

5.         Create new policy——set name ——choose project-level services——choose deny

1584098100135746.png

6.         Search “VPC”

1584098114567718.png

7.         Choose the actions you want to deny:

For this requirement , choose “readwrite” ,then the sub-user can’t read & write the VPC configuration.

1584098127412777.png

         All permissions are listed here:

1584098139729438.png

8.         Back to user group ,click “more”——“manage permissions”

1584098152429293.png

9.         Ensure that you already added the user:

1584098168679753.png

10.     Add the permissions for sub-user

1584098179927326.png

11.     Assign the 1st permission: Scope(Bangkok region)——search “Tenant”——choose “Tenant administrator”

1584098192823148.png

12.     Assign the 2nd permission (the most important permission to forbid sub-user change VPC configuration): Choose the custom policy we just created.

1584098224270791.png

13.     Now we can test the permissions we set:

Use the link to login in as a sub-user:

1584098252554079.png

1584098270203785.png

14.     Login in as a sub-user, and choose some services to test the permissions:

1584098288397516.png

15.     Click “VPC” ,try to create a new VPC

1584098300273640.png

16.     It will show that you don’t have the permission:

1584098312538647.png

17.     Try to change the existing VPC, it will show that you don’t have the permission:

1584098329876145.png

         You even can’t change the name of VPC:

1584098344891090.png

Now you already set the permission you need, let’s try more

1)       How to set the permission that only have the permission of VPC?

2)       How to set the permission that have all permission?


【版权声明】本文为华为云社区用户原创内容,转载时必须标注文章的来源(华为云社区)、文章链接、文章作者等基本信息, 否则作者和本社区有权追究责任。如果您发现本社区中有涉嫌抄袭的内容,欢迎发送邮件进行举报,并提供相关证据,一经查实,本社区将立刻删除涉嫌侵权内容,举报邮箱: cloudbbs@huaweicloud.com
  • 点赞
  • 收藏
  • 关注作者

评论(0

0/1000
抱歉,系统识别当前为高风险访问,暂不支持该操作

全部回复

上滑加载中

设置昵称

在此一键设置昵称,即可参与社区互动!

*长度不超过10个汉字或20个英文字符,设置后3个月内不可修改。

*长度不超过10个汉字或20个英文字符,设置后3个月内不可修改。