任务说明:
1、根据文档创建华为云IAM账号并分配相应的权限,并提供相应的Access Key ID和Access Secret Key
说明:华为云IAM账号用于容灾时调用容灾目标云API接口
(创建访问云资源,存放容灾数据),开通IAM账号时下载对应AccessKey和AccessSecretKey,请将账号信息及AK/SK通过邮件发送给我们。参考权限问题:
备注:
内容不全,需要补充华为云创建IAM账号的截图示例,包含自定义权限如何配置,用户如何创建,创建用户时如何关联设定的自定义权限、以及是否具备编程权限和控制台访问权限,中间过程截图,可以依照我们的华为云账号来进行补充。(英文界面)
以下为文档正文,注意格式:
华为云IAM账号用于容灾时调用容灾目标云API接口
(创建访问云资源,存放容灾数据),开通IAM账号时下载对应AccessKey和AccessSecretKey,请将账号信息及AK/SK通过邮件发送给我们。参考权限问题:
创建IAM用户
:::tips 华为云官方文档链接:
https://support.huaweicloud.com/intl/en-us/usermanual-iam/iam_02_0001.html
:::
给IAM用户授权
:::tips 华为云官方文档链接:
https://support.huaweicloud.com/intl/en-us/usermanual-iam/iam_01_0652.html
:::
管理IAM用户访问密钥
:::tips 华为云官方文档链接:
https://support.huaweicloud.com/intl/en-us/usermanual-iam/iam_02_0003.html
:::
Huawei Cloud IAM requirements
#ecs/vpc/evs/ims
{"Version": "1.1","Statement": [{"Effect": "Allow","Action": ["ecs:serverPasswords:manage","ecs:serverKeypairs:delete","ecs:cloudServers:reboot","ecs:diskConfigs:use","ecs:cloudServers:start","ecs:cloudServers:vnc","ecs:servers:lock","ecs:servers:rebuild","ecs:cloudServers:attach","ecs:serverInterfaces:get","ecs:cloudServers:detachVolume","ecs:servers:unlock","ecs:cloudServers:delete","ecs:serverKeypairs:get","ecs:cloudServers:updateMetadata","ecs:cloudServers:stop","ecs:servers:setMetadata","ecs:serverVolumes:use","ecs:cloudServers:create","ecs:serverKeypairs:create","ecs:servers:get","ecs:serverInterfaces:use","ecs:serverGroups:manage","ecs:securityGroups:use","ecs:*:get*","ecs:*:list*"]},{"Effect": "Allow","Action": ["evs:snapshots:rollback","evs:volumes:use","evs:snapshots:delete","evs:volumes:create","evs:snapshots:create","evs:volumes:update","evs:backups:get","evs:volumes:get","evs:snapshots:get","evs:volumes:delete","evs:*:get*","evs:*:list*"]},{"Effect": "Allow","Action": ["vpc:securityGroups:create","vpc:vpcs:delete","vpc:subnets:update","vpc:routers:update","vpc:subnets:delete","vpc:vpcs:create","vpc:networks:get","vpc:publicIps:create","vpc:ports:get","vpc:ports:update","vpc:ports:create","vpc:securityGroupRules:get","vpc:subnets:create","vpc:securityGroups:delete","vpc:publicIps:delete","vpc:subnets:get","vpc:securityGroups:update","vpc:routers:get","vpc:securityGroups:get","vpc:networks:create","vpc:networks:update","vpc:*:list*","vpc:*:get*"]},{"Effect": "Allow","Action": ["ims:images:get","ims:*:list*"]}]}
#obs
{"Version": "1.1","Statement": [{"Effect": "Allow","Action": ["OBS:*:*"]}]}
