Cloud Access Management (CAM) policy:
{
"version":"2.0",
"statement":
[
{
"effect":"effect",
"action":["action"],
"resource":["resource"],
"condition":{"key":{"value"}}
}
]
}
version: Required. Currently, only the value 2.0 is allowed.
statement: This element describes the detailed information of one or more permissions and covers permissions or permission sets of several other elements such as effect, action, resource, and condition. A policy has only one statement element.
effect: Required. This element describes the result of the statement. Valid values include allow and deny (explicit deny).
action: Required. This element describes the allowed or denied operation. An operation can be an API, which is described with the cdb: prefix.
resource: Required. This element describes the specific data of authorization. The resources are described in a six-segment format and the resource definition details vary by product.
condition: A required field that describes the constraints under which the policy takes effect. Conditions include operators, condition keys, and condition values. Condition values can include information such as time and IP addresses, and some services allow you to specify other values in conditions.
Cloud database operations
In cloud database policy statements, you can specify any API operation from any service that supports cloud databases. For cloud databases, use APIs prefixed with cdb:, for example, cdb:CreateDBInstance or cdb:CreateAccounts.
If you need to specify multiple actions in a single statement, separate them with commas, as shown below:
"action":["cdb:action1","cdb:action2"]
You can also use wildcards to specify multiple actions. For example, you can specify all actions that start with the word Describe, as shown below:
"action":["cdb:Describe*"]
If you want to specify all operations in the cloud database, use the * wildcard, as shown below:
Each CAM policy statement applies to its own resources.
Resources are generally specified in the following format:
qcs:project_id:service_type:region:account:resource
project_id: the project information. It is only for compatibility with early CAM logic and does not need to be filled in.
service_type: The product abbreviation, such as cdb.
region: region information. Example: ap-guangzhou.
account: The root account information of the resource owner, such as uin/65xxx763.
resource: specific resource details of each product. Example: instanceId/instance_id1 or instanceId/*.
For example, you can specify a specific instance (cdb-k05xdcta) in the statement, as shown below:
"resource":["qcs::cdb:ap-guangzhou:uin/65xxx763:instanceId/cdb-k05xdcta"]
You can also use the * wildcard character to specify all instances belonging to a specific account, as shown below:
"resource":["qcs::cdb:ap-guangzhou:uin/65xxx763:instanceId/*"]
If you want to specify all resources, or if a specific API operation does not support resource-level permissions, use the * wildcard in the resource element, as shown below:
To specify multiple resources in one instruction, separate them with a comma. The following is an example of specifying two resources:
"resource":["resource1","resource2"]
The following table describes the resources that can be used in the cloud database and their corresponding specification methods. Words prefixed with $ are placeholders, where region refers to the region and account refers to the account ID.
|
| qcs::cdb:$region:$account:instanceId/$instanceId
|
| qcs::vpc:$region:$account:vpc/$vpcId
|
| qcs::cvm:$region:$account:sg/$sgId
|