Creating a User and Granting CDM Permissions
This chapter describes how to use Identity and Access Management (IAM) to implement fine-grained permissions control for your CDM resources. With IAM, you can:
- Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing CDM resources.
- Grant only the permissions required for users to perform a specific task.
- Entrust a Huawei Cloud account or cloud service to perform efficient O&M on your CDM resources.
If your Huawei Cloud account does not require individual IAM users, skip this chapter.
This section describes the procedure for granting permissions (see Figure 1).
Process Flow
- Create a user group and assign permissions
Create a user group on the IAM console, and attach the CDM ReadOnlyAccess policy to the group.
- Create an IAM user.
Create a user on the IAM console and add the user to the group created in 1.
- Log in and verify permissions.
Log in to the CDM console by using the user created, and verify that the user only has read permissions for CDM.
- Choose Service List > Cloud Data Migration. On the CDM console, view clusters. If no message appears indicating insufficient permissions to perform the operation, the CDM ReadOnlyAccess policy has already taken effect.
- Choose any other service in Service List. If a message appears indicating that you have insufficient permissions to access the service, the CDM ReadOnlyAccess policy has already taken effect.
