Managing Database Rules
Scenarios
You can enable, modify, disable, or delete a database rule you configure, or associate a database rule with a rule set, user, user group, resource account, or account group.
Prerequisites
Your role has the management permission for the DB Rules module. For details about the permissions of each role, see Role.
Querying and Editing a Database Rule
This topic describes how to view and edit a database rule. You can view and edit rule configurations, including basic settings, related regulation sets, users, user groups, accounts, and account groups.
- A modified database rule takes effect the instant its status changes to Enabled.
- If related users have logged in to resources before the modification, those users need to log out and log in again for the modified database rule to take effect.
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
- View the rule list.
Table 1 Database rule list parameters Parameter
Description
Rule Name
Name of a database rule.
Status
Status of a database rule.
- Enabled: The rule has been enabled.
- Disabled: The rule has been disabled. To enable it, see Enabling or Disabling a Database Rule.
- Ineffective: The rule has not taken effect because the current time is earlier than the effective time configured for the rule. You can change its Period of validity to make it take effect.
- Expired: The rule has expired. You can change its Period of validity to make it take effect.
- Incomplete: The rule has not been associated with any rule set, user, user group, resource account, or account group. For details, see Associating a Rule Set with a Database Rule, Associating a Database Rule with a User or User Group and Associating a Database Rule with a Resource Account or Account Group.
Action
Action of a rule.
- Disconnect: After a database rule is triggered, the system rejects executing the operation and disconnects the O&M session. The system displays a message indicating that the connection is forcibly disconnected by the administrator.
- Reject: After a database rule is triggered, the system rejects executing the operation and displays a message indicating that the operation has been intercepted.
- Dynamic approval: After a database rule is triggered, the system reject executing the operation. The system displays a message indicating that the operation has been intercepted and asking you to submit a database approval ticket. A database approval ticket is automatically generated. The command can be executed only after the ticket is submitted and approved.
- Permit: By default, all operations are allowed. After a database rule is triggered, operations in the related regulation set are allowed.
Rule Set
Rule set associated with the rule.
User
Users and user groups associated with the rule.
Account
Resource accounts and account groups associated with the rule.
Operation
Operations you can perform for the rule.
- Locate the row that contains the target rule, and click the rule name or Manage in the Operation column to go to the details page.
- View and edit basic rule information.
- In the Basic Info area, view basic rule information, such as the department and status.
- In the Basic Info area, click Edit on the right. In the displayed dialog box, modify the Rule Name, Action, Period of validity, and Time Limit settings of the rule. For details about the parameters, see Table 1.
- View and edit regulation sets related to the rule.
- In the RegSet area, view the rule sets associated with the rule.
- In the RegSet area, click Edit on the right. In the displayed dialog box, add a rule set to be associated with the rule.
- In the row containing the target rule set, click Remove to delete the associated rule set.
- View and edit users or user groups associated with the rule.
- In the User and UserGroup areas, view the users or user groups associated with the rule.
- In the User or User Group area, click Edit on the right. In the displayed dialog box, associate users or user groups with the rule.
- In the list, locate the row that contains the target user or user group, and click Remove to delete the associated user or user group and cancel the authorization.
- View and edit resource accounts and account groups associated with the rule.
- In the Account and AccountGroup areas, view the resource accounts or account groups associated with the rule.
- In the Account or Account Group area, click Edit on the right. In the displayed configuration window, add a resource account or account group to be associated.
- To remove a resource account or account group, click Remove in the row of the resource account or account group.
Associating a Rule Set with a Database Rule
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
- In the Operation column of the target rule, click Relate and select RegSet.
- In the displayed dialog box, associate the rule with a rule set.
- You can associate a rule with multiple rule sets at once. For details about how to create a rule set, see Creating and Managing a Rule Set.
- Selecting rule sets: Select rule sets in the Selectable RegSets area and click
to move them to the Selected RegSets area. - Removing rule sets: Select rule sets in the Selected RegSets area and click
to move them back to the Selectable RegSets area.
- Selecting rule sets: Select rule sets in the Selectable RegSets area and click
- After a rule set is associated with a rule, rules added to the rule set automatically inherit the permissions of that rule.
- You can associate a rule with multiple rule sets at once. For details about how to create a rule set, see Creating and Managing a Rule Set.
- Click OK.
Associating a Database Rule with a User or User Group
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
- In the row containing the target rule, click Relate in the Operation column and select User or UserGroup.
- In the displayed dialog box, associate the rule with a user or user group. Make sure the associated users or users in the associated user groups have the permissions for the DB Tickets module. Otherwise, after they log in to the system, the DB Tickets module will be unavailable to them. This means they cannot submit tickets to obtain approval during operation. For details about the permissions of each role, see Role.
- You can associate a rule with multiple users or user groups at once.
- Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click
to move them to the Selected users or Selected user groups box. - Remove users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selected users or Selected user groups box, and click
to move them back to the Selectable users or Selectable user groups box.
- Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click
- After a user group is associated with a rule, users automatically obtain the permissions of the rule the instant they are added to the user group.
- You can associate a rule with multiple users or user groups at once.
- Click OK.
Associating a Database Rule with a Resource Account or Account Group
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
- In the Operation column of the target rule, click Relate and select Account or Account Group.
- In the displayed dialog box, associate the rule with a resource account or account group.
- You can associate a rule with multiple managed resource accounts or account groups at once.
- Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click
to move it to the Selected accounts or Selected account groups box. - Remove a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selected accounts or Selected account groups box, and click
to remove it back to the Selectable accounts or Selectable account groups box.
- Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click
- After an account group is associated with a rule, accounts automatically obtain the permissions of the rule the instant they are added to the account group.
- You can associate a rule with multiple managed resource accounts or account groups at once.
- Click OK.
Enabling or Disabling a Database Rule
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
- Enable or disable a database rule.
- Enabling a rule
- In the rule list, select all the target rules and click Enable in the lower left corner.
- In the displayed dialog box, click OK.
- Disabling a rule
- In the rule list, select all the target rules and click Disable in the lower left corner.
- In the displayed dialog box, click OK.
- Enabling a rule
Deleting a Database Rule
- Log in to your bastion host system.
- In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
- Delete a database rule.
- Deleting a single rule
- In the row containing the target rule, click Delete in the Operation column.
- In the displayed dialog box, click OK.
- Batch deleting rules
- On the ACL rule list page, select all the target rules.
- Click Delete in the lower left corner.
- In the displayed dialog box, click OK.
- Deleting a single rule
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot