检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
The IAM permissions of an IAM user are configured by their tenants. If a tenant does not grant the OBS putObjectAcl permission to their IAM users, this issue occurs.
In this mode, IAM users must be authorized to use ModelArts functions. In this way, the permission scope of IAM users can be accurately controlled, minimizing permissions granted to IAM users.
In this mode, IAM users must be authorized to use ModelArts functions. In this way, the permission scope of IAM users can be accurately controlled, minimizing permissions granted to IAM users.
Log in to the ModelArts management console as an IAM user in user_group. On the login page, ensure that IAM User Login is selected. Change the password as prompted upon the first login.
Configuring ModelArts Standard Permissions Sample Function Scenario Description ModelArts Standard Permission Management IAM permission configuration and management Permission assignment for IAM users Assign specific ModelArts operation permissions to the IAM users under a Huawei
Error 404 If this error is reported when an IAM user creates an instance, the IAM user does not have the permission to access the OBS bucket. Solution Log in to the OBS console using the tenant account and grant access permissions for the OBS bucket to the IAM user.
In this case, create an IAM user and use it for authentication.
-a, --account TEXT Account of an IAM user. -u, --username TEXT Username of an IAM user. -p, --password TEXT Password of an IAM user -ak, --access-key TEXT User access key. -sk, --secret-key TEXT User secret key.
For security purposes, create IAM users and grant them permissions for routine management. IAM user An IAM user is created using an account to use cloud services. Each IAM user has its own identity credentials (password and access keys).
If no SWR operation permissions are configured, go to the IAM console and grant the permissions to the target agency.
When Authorization Type is set to INTERNAL, specify one or more accessible IAM user accounts. A default workspace is allocated to each IAM project of each account. The access control of the default workspace is PUBLIC.
For better permission control over IAM users, you shall grant agency permissions to each IAM user individually on the ModelArts global configuration page. The same agency credential shall not be shared by multiple IAM users.
Preparation: Assigning the Cloud Shell Permission to an IAM User Log in to the Huawei Cloud management console as a tenant user, hover the cursor over your username in the upper right corner, and choose Identity and Access Management from the drop-down list to switch to the IAM management
Set ****d80fb058844ae8b82aa66d9fe**** to the IAM user ID of the specified user.
Create a user on the IAM console and add the user to the group created in 3. Log in as the IAM user and verify permissions.
To do so, ModelArts provides IAM permission control, agency authorization, and workspace. IAM permission control To use ModelArts functions, you need to grant permissions through IAM.
Table 4 grants Parameter Mandatory Type Description user_id No String IAM user ID. Either this parameter or user_name must be configured. If both of them are available, user_id will be used preferentially. user_name No String IAM username.
Team labeling IAM iam:projects:listProjects (Obtaining tenant projects) iam:users:listUsers (Obtaining users) iam:agencies:createAgency (Creating an agency) iam:quotas:listQuotasForProject (Obtaining the quotas of a project) Manage labeling teams.
Table 1 Common best practices Practice Description Assigning permissions for using ModelArts Assigning Basic Permissions for Using ModelArts Assign specific ModelArts operation permissions to the IAM users under a Huawei Cloud account.
If user_id is set to all, all IAM users are authorized. If some IAM users have been authorized, the authorization setting will be updated. This parameter is mandatory only if the authorization method is set to Agency.