检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Creating an IAM User and Granting SFS Permissions This section describes how to use IAM to implement fine-grained permissions control for your SFS resources. With IAM, you can: Create IAM users for employees based on your enterprise's organizational structure.
For security purposes, create Identity and Access Management (IAM) users and grant them permissions for routine management. User An IAM user is created by an account in IAM to use cloud services. Each IAM user has its own identity credentials (password and access keys).
Table 1 SFS access control Method Description Reference Permissions control IAM permissions IAM permissions define which actions on your cloud resources are allowed or denied.
When employees in your enterprise need to use SFS, the enterprise administrator can use IAM to create users and control these users' permissions on enterprise resources.
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.
General-Purpose File System Management Permission API Action IAM Project (Project) Enterprise Project (Enterprise Project) Creating a General-Purpose File System PUT /{file-system-name} sfs3:fileSystem:createFileSystem × √ Listing General-Purpose File Systems GET / sfs3:fileSystem
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.
Permissions Management SFS uses IAM for permissions management. You can control the read and write permissions of file systems by granting IAM users fine-grained SFS permissions using IAM custom policies. For more information, see Permissions.
Obtaining Access Keys (AK/SK) To access SFS using access keys as an IAM user, the programmatic access must be enabled. For details, see Viewing or Modifying IAM User Information. When calling an API, you need to use the AK/SK to verify the signature.
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.
Virtual Private Cloud (VPC) Creating a File System IAM is an enterprise-level self-help cloud resource management system. It provides user identity management and access control functions.
Creating an IAM User If you want to allow multiple users to manage your resources without sharing your password or private key, you can create users using IAM and grant permissions to the users.
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.
Creating a User and Granting SFS Permissions This chapter describes how to use IAM to implement fine-grained permissions control for your SFS resources. With IAM, you can: Create IAM users for employees based on your enterprise's organizational structure.
Policies that contain actions for both IAM and enterprise projects can be used and applied for both IAM and Enterprise Management. Policies that only contain actions for IAM projects can be used and applied to IAM only.
IAM provides identity authentication, permissions management, and access control, helping you to securely access your cloud resources. With IAM, you can use your cloud account to create IAM users, and assign permissions to the users to control their access to specific resources.
IAM can be used free of charge. You pay only for the resources in your account. For more information about IAM, see IAM Service Overview. SFS Permissions By default, new IAM users do not have permissions assigned.
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.
Authorization Each account has all of the permissions required to call all APIs, but IAM users must have the required permissions specifically assigned. For the specific permissions required, see Permissions Policies and Supported Actions.