检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Reducing the Agency Permissions of ASM Users Background ASM permission management is implemented through IAM agencies. However, users authorized prior to July 2024 may have excessive agency permissions. For security purposes, you are advised to reduce the agency permissions.
For example, if you want to obtain an IAM token in CN North-Beijing1, use the endpoint of IAM (iam.cn-north-1.myhuaweicloud.com) for this region and resource-path (/v3/auth/tokens) in the URI of the API used to obtain a user token.
You can go to the IAM console, choose > Agencies and click asm_admin_trust to view the permissions of each region. When you create the asm_admin_trust agency, a custom policy named asm admin trust policy will be automatically created. Do not delete this policy.