Creating a User and Granting CS Permissions
This section describes how to use Identity and Access Management (IAM) to implement fine-grained permissions control for your CS resources. With IAM, you can:
- Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials, providing access to CS resources.
- Grant only the permissions required for users to perform a specific task.
- Entrust a HUAWEI CLOUD account or cloud service to perform efficient O&M on your CS resources.
If your HUAWEI CLOUD account does not require individual IAM users, skip this chapter.
Prerequisites
- CS ReadOnlyAccess is a policy.
- Learn about the permissions (see Permissions Management.) supported by CS and choose policies or roles according to your requirements.
Process Flow
This section describes how to use a group to grant permissions to a user. Figure 1 shows the process for granting permissions.
- Create a user group and assign permissions to it.
Create a user group on the IAM console, and attach the CS ReadOnlyAccess policy to the group.
- Create an IAM user.
Create a user on the IAM console and add the user to the group created in 1.
- Log in and verify permissions.
Log in to the console by using the user created, and verify that the user has the granted permissions.
- Choose Service List > Cloud Stream Service. Then click Create Cluster on the CS console. If a message appears indicating that you have insufficient permissions to perform the operation, the CS ReadOnlyAccess policy has already taken effect.
- Choose any other service in Service List. If a message appears indicating that you have insufficient permissions to access the service, the CS ReadOnlyAccess permission has already taken effect.
Last Article: Permissions Management
Next Article: CS Custom Policies

Did this article solve your problem?
Thank you for your score!Your feedback would help us improve the website.