How Do I Handle the Error 403 "Insufficient permissions. Contact your account administrator to assign you a policy with the codearts:monthlyPackage:subscribe action."?
Symptom
When you enable CodeArts Agent packages or pay-per-use billing as an IAM user, the error message "Insufficient permissions. Contact your account administrator to assign you a policy with the codearts:monthlyPackage:subscribe action." is displayed in the upper right corner.
Cause Analysis
The current IAM user has not been granted the fine-grained permission to purchase CodeArts Agent.
Solution
- Log in to the new Identity and Access Management (IAM) console using your HUAWEI ID.
- Create and configure a custom identity policy for enabling CodeArts Agent packages or pay-per-use billing.
- In the navigation pane on the left, click Identity Policies. The identity policy page is displayed.
- Click Create Identity Policy in the upper right corner.
- Set the custom identity policy by referring to Table 1. Figure 1 Creating a custom identity policy
Table 1 Custom identity policy parameters Parameter
Description
Policy Name
Enter a policy name. Only letters, digits, and the following special characters are allowed: +=_.@-
Policy View
Select Visual editor.
Policy Content
Configure the CodeArts permission as follows. Only this permission is required for enabling or disabling pay-per-use billing.
- Select Allow.
- Cloud service: Enter codearts in the search box and select CodeArts (codearts).
- Actions: Enter monthly in the search box and select codearts:monthlyPackage:subscribe and codearts:monthlyPackage:listResourceDetail.
- Skip Select resource.
- Skip (Optional) Add request condition.
To enable CodeArts Agent packages, you also need to configure the billing permission as follows:
- Click Add Permissions.
- Select Allow.
- Cloud service: Enter billing in the search box and select billing (billing).
- Actions: Enter order in the search box and select billing:order:pay and billing:order:view.
- Skip Select resource.
- Skip (Optional) Add request condition.
Description
Optional. Enter a brief description for the policy.
- Click OK.
The new policy is displayed on the Identity Policies page.
- Grant the custom identity policy to the IAM user who needs to enable CodeArts Agent packages or pay-per-use billing.
- In the navigation pane, choose Users to go to the Users page.
- Locate the target IAM user and click Authorize in the Operation column.
- Authorize the IAM user by referring to Table 2.
Table 2 Authorization parameters Parameter
Description
Assign By
Select Identity policy.
Identity Policy
Enter the identity policy created in 2 in the search box, press Enter, and select the identity policy.
- Click OK. The Information dialog box is displayed.
- Click OK. A message is displayed, indicating that the authorization is successful. Click Finish.
It takes 15 to 30 minutes for the authorization to take effect.
- Log in to the CodeArts Agent console as the authorized IAM user and enable CodeArts Agent packages or pay-per-use billing again.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot