检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Minimum length: 1 Maximum length: 47 Table 4 member_id Parameter Type Description user_id String Globally unique ID of an IAM Identity Center user in the identity source.
Table 4 member_id Parameter Mandatory Type Description user_id Yes String Globally unique ID of an IAM Identity Center user in the identity source.
If you use an IAM user, ensure that the user has been added to a user group that has the permissions required to use OBS. For details about how to create buckets, upload objects, and perform operations on buckets and objects on OBS, see Managing Buckets and Managing Objects.
IAM Identity and Access Management (IAM) authenticates access to DLV.
Symptoms When I click Pay to submit an order as an IAM user, the message "Policy doesn't allow bss:order:update to be performed." is displayed. Figure 1 Error message Cause Analysis You do not have permission to create, pay for, and view orders in the Billing Center.
Click in the upper left corner of the page and choose Management & Governance > IAM Identity Center. In the navigation pane, choose Multi-Account Permissions > Permission Sets. In the permission set list, locate the permission set and click Delete in the Operation column.
Verification You can use a secret of an IAM user to mount an OBS volume. Assume that a workload named obs-secret is created, the mount path in the container is /temp, and the IAM user has the CCE ReadOnlyAccess and Tenant Guest permissions.
Logging In to a Bastion Host Through the Service Console You can select Local Login, IAM Login (available in V3.3.44.0 or later), or Admin Login (available in V3.3.52.1 or later, but not supported by Kunpeng bastion hosts).
If Condition is configured in the IAM permission or bucket policy, check whether the specified rules are met.
calc ak sk signature fail:signature expired When an API is called, the "Incorrect IAM authentication information: calc ak sk signature fail:signature expired" error is reported. It indicates that the AK or SK has expired.
Click in the upper left corner of the page and choose Management & Governance > IAM Identity Center. In the navigation pane, choose Applications. Click the name of the application to which you want to remove access.
If you use an IAM user account, check if you are in the admin user group. If not, grant relevant permissions to your account and complete the following preparations.
Currently, the GaussDB(DWS) cluster supports two login modes: custom (username + password) and IAM account. Custom login is the default login mode. With IAM account login, you create an IAM user in the database and use a token to log in.
If you use an IAM user account, check if you are in the admin user group. If not, grant relevant permissions to your account and complete the following preparations.
Preparing a Huawei Account Before using MgC, prepare a HUAWEI ID or an IAM user that can access MgC and obtain an AK/SK pair for the account or IAM user. For details, see Preparations.
URI GET /v1/instances/{instance_id}/account-assignments Table 1 Path parameters Parameter Mandatory Type Description instance_id Yes String Globally unique ID of an IAM Identity Center instance.
Before configuring an IAM policy, you need to understand what permissions are required. An IAM user only has the permissions defined by the policy. In this example, user APPServer only has full permissions on objects in the APPClient folder.
Symptom You have set an API access control policy, but IAM users who do not meet the policy requirements can still access Huawei Cloud using APIs. Solution The API access control policy has not taken effect yet. API access control policies take effect within 2 hours once set.
Preparing a Huawei Account Before using MgC, prepare a HUAWEI ID or an IAM user that can access MgC and obtain an AK/SK pair for the account or IAM user. For details, see Making Preparations.
Table 6 group_memberships.member_id Parameter Type Description user_id String Globally unique ID of an IAM Identity Center user in the identity source.