任务说明:
1、根据文档创建华为云IAM账号并分配相应的权限,并提供相应的Access Key ID和Access Secret Key
说明:华为云IAM账号用于容灾时调用容灾目标云API接口
(创建访问云资源,存放容灾数据),开通IAM账号时下载对应AccessKey和AccessSecretKey,请将账号信息及AK/SK通过邮件发送给我们。参考权限问题:
备注:
内容不全,需要补充华为云创建IAM账号的截图示例,包含自定义权限如何配置,用户如何创建,创建用户时如何关联设定的自定义权限、以及是否具备编程权限和控制台访问权限,中间过程截图,可以依照我们的华为云账号来进行补充。(英文界面)
以下为文档正文,注意格式:
华为云IAM账号用于容灾时调用容灾目标云API接口
(创建访问云资源,存放容灾数据),开通IAM账号时下载对应AccessKey和AccessSecretKey,请将账号信息及AK/SK通过邮件发送给我们。参考权限问题:
创建IAM用户
:::tips 华为云官方文档链接:
https://support.huaweicloud.com/intl/en-us/usermanual-iam/iam_02_0001.html
:::
给IAM用户授权
:::tips 华为云官方文档链接:
https://support.huaweicloud.com/intl/en-us/usermanual-iam/iam_01_0652.html
:::
管理IAM用户访问密钥
:::tips 华为云官方文档链接:
https://support.huaweicloud.com/intl/en-us/usermanual-iam/iam_02_0003.html
:::
Huawei Cloud IAM requirements
#ecs/vpc/evs/ims
{
"Version": "1.1",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ecs:serverPasswords:manage",
"ecs:serverKeypairs:delete",
"ecs:cloudServers:reboot",
"ecs:diskConfigs:use",
"ecs:cloudServers:start",
"ecs:cloudServers:vnc",
"ecs:servers:lock",
"ecs:servers:rebuild",
"ecs:cloudServers:attach",
"ecs:serverInterfaces:get",
"ecs:cloudServers:detachVolume",
"ecs:servers:unlock",
"ecs:cloudServers:delete",
"ecs:serverKeypairs:get",
"ecs:cloudServers:updateMetadata",
"ecs:cloudServers:stop",
"ecs:servers:setMetadata",
"ecs:serverVolumes:use",
"ecs:cloudServers:create",
"ecs:serverKeypairs:create",
"ecs:servers:get",
"ecs:serverInterfaces:use",
"ecs:serverGroups:manage",
"ecs:securityGroups:use",
"ecs:*:get*",
"ecs:*:list*"
]
},
{
"Effect": "Allow",
"Action": [
"evs:snapshots:rollback",
"evs:volumes:use",
"evs:snapshots:delete",
"evs:volumes:create",
"evs:snapshots:create",
"evs:volumes:update",
"evs:backups:get",
"evs:volumes:get",
"evs:snapshots:get",
"evs:volumes:delete",
"evs:*:get*",
"evs:*:list*"
]
},
{
"Effect": "Allow",
"Action": [
"vpc:securityGroups:create",
"vpc:vpcs:delete",
"vpc:subnets:update",
"vpc:routers:update",
"vpc:subnets:delete",
"vpc:vpcs:create",
"vpc:networks:get",
"vpc:publicIps:create",
"vpc:ports:get",
"vpc:ports:update",
"vpc:ports:create",
"vpc:securityGroupRules:get",
"vpc:subnets:create",
"vpc:securityGroups:delete",
"vpc:publicIps:delete",
"vpc:subnets:get",
"vpc:securityGroups:update",
"vpc:routers:get",
"vpc:securityGroups:get",
"vpc:networks:create",
"vpc:networks:update",
"vpc:*:list*",
"vpc:*:get*"
]
},
{
"Effect": "Allow",
"Action": [
"ims:images:get",
"ims:*:list*"
]
}
]
}
#obs
{
"Version": "1.1",
"Statement": [
{
"Effect": "Allow",
"Action": [
"OBS:*:*"
]
}
]
}