检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Creating an ECS/BMS Agency Log in to Huawei Cloud management console and go to the Identity and Access Management console page. In the navigation pane on the left, choose Agencies. Click Create Agency in the upper right corner, set related parameters, and click Next.
LakeFormation authenticates the IAM token in the HTTPS request delivered by the console to identify the delegating tenant (local tenant), agency, delegated tenant (ECS account), and delegated IAM user (built-in user of ECS). If the authentication fails, the request is rejected.
Agency Select Configure next to Set Advanced Options, select Available agencies for Agency, and select the agency created in Creating an ECS/BMS Agency. For example, the following figure shows an example configuration. The configuration may vary depending on the cluster version.
For example, if an IAM user wants to query ECSs using an API, the user must have been granted permissions that allow the ecs:servers:list action. Actions LakeFormation provides system-defined policies that can be directly used in IAM.