Creating a User and Granting EIP Permissions
Currently, the EIP service permissions are included in the VPC permissions. For details, see Permissions Management.
- Create IAM users for personnel based on your enterprise's organizational structure. Each IAM user has their own identity credentials for accessing VPC resources.
- Grant users only the permissions required to perform a given task based on their job responsibilities.
- Entrust a cloud account or cloud service to perform efficient O&M on your VPC resources.
If your cloud account meets your permissions requirements, you can skip this section.
Figure 1 shows the process flow for granting permissions.
Prerequisites
Before granting permissions to user groups, learn about EIP permissions.
To grant permissions for other services, learn about all system-defined permissions supported by IAM.
Process Flow
- On the IAM console, create a user group and grant it permissions.
Create a user group on the IAM console and assign the EIP ReadOnlyAccess permissions to the group.
- Create an IAM user and add it to the created user group.
Create a user on the IAM console and add the user to the group created in 1.
- Log in as the IAM user and verify permissions.
In the authorized region, perform the following operations:
- Choose Service List > Elastic IP. Then click Buy EIP on the EIP console. If a message appears indicating that you have insufficient permissions to perform the operation, the EIP ReadOnlyAccess policy is in effect.
- Choose another service from Service List. If a message appears indicating that you have insufficient permissions to access the service, the EIP ReadOnlyAccess policy is in effect.
