Updated on 2026-09-17 GMT+08:00

Actions Supported by Policy-based Authorization

This section describes the actions supported by DDM in policy-based authorization.

Supported Actions

DDM provides system-defined policies that can be directly used in IAM. You can also create custom policies to supplement system-defined policies for more refined access control. Operations supported by policies are specific to APIs. The following are common concepts related to policies:

  • Permissions: statements that allow or deny certain operations.
  • APIs: REST APIs that can be called by a user who has been granted specific permissions
  • Actions: specific operations that are allowed or denied in a custom policy
  • Dependencies: actions which a specific action depends on. When allowing an action for a user, you also need to allow any existing action dependencies for that user.
  • IAM projects/Enterprise projects: the authorization scope of a custom policy. A custom policy can be applied to IAM projects or enterprise projects or both. Policies that contain actions for both IAM and enterprise projects can be used and applied for both IAM and Enterprise Management. Policies that contain actions only for IAM projects can be used and applied to IAM only. Administrators can check whether an action supports IAM projects or enterprise projects in the action list. For details about the differences between IAM and enterprise management, see Differences Between IAM and Enterprise Management.

DDM supports the following actions in custom policies.

Table 1 Instance management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Creating an instance

POST /v1/{project_id}/instances

ddm:instance:create

√

√

Querying instances

GET /v1/{project_id}/instances?offset={offset}&limit={limit}

ddm:instance:list

√

√

Querying details of an instance

GET /v1/{project_id}/instances/{instance_id}

ddm:instance:get

√

√

Changing an instance name

PUT /v1/{project_id}/instances/{instance_id}/modify-name

ddm:instance:modify

√

√

Changing the security group of an instance

PUT /v1/{project_id}/instances/{instance_id}/modify-security-group

ddm:instance:modify

√

√

Deleting an instance

DELETE /v1/{project_id}/instances/{instance_id}?delete_rds_data=true

ddm:instance:delete

√

√

Restarting an instance

POST /v1/{project_id}/instances/{instance_id}/action

ddm:instance:reboot

√

√

Reloading table data

POST /v1/{project_id}/instances/{instance_id}/reload-config

ddm:instance:modify

√

√

Scaling out an instance

POST /v2/{project_id}/instances/{instance_id}/action/enlarge

ddm:instance:extendNode

√

√

Scaling in an instance

POST /v2/{project_id}/instances/{instance_id}/action/reduce

ddm:instance:extendNode

√

√

Modifying the read policy of the associated DB instance

PUT /v2/{project_id}/instances/{instance_id}/action/read-write-strategy

ddm:rds:modifyReadPolicy

√

√

Synchronizing data node information

POST /v1/{project_id}/instances/{instance_id}/rds/sync

ddm:rds:synchro

√

√

Querying nodes of an instance

GET /v1/{project_id}/instances/{instance_id}/nodes?offset={offset}&limit={limit}

ddm:instance:list

√

√

Querying details of an instance node

GET /v1/{project_id}/instances/{instance_id}/nodes/{node_id}

ddm:instance:get

√

√

Querying engine information

GET /v2/{project_id}/engines?offset={offset}&limit={limit}

ddm:product:list

√

√

Querying node classes available in an AZ

GET /v2/{project_id}/flavors?engine_id={engine_id}&offset={offset}&limit={limit}

ddm:product:list

√

√

Changing the node class of an instance

PUT /v3/{project_id}/instances/{instance_id}/flavor

ddm:instance:resize

√

√

Obtaining the instance group information

GET /v3/{project_id}/instances/{instance_id}/groups?offset={offset}&limit={limit}

ddm:instance:list

√

√

Creating an instance group

POST /v3/{project_id}/instances/{instance_id}/groups

ddm:instance:extendNode

√

√

Deleting an instance group

DELETE /v3/{project_id}/instances/{instance_id}/groups/{group_id}

ddm:instance:extendNode

√

√

Querying engine information (V3)

GET /v3/{project_id}/engines?offset={offset}&limit={limit}

ddm:product:list

√

√

Querying node classes available in an AZ (V3)

GET /v3/{project_id}/flavors?engine_id={engine_id}&offset={offset}&limit={limit}&engine_version={engine_version}&available_zones={available_zones}

ddm:product:list

√

√

Querying parameters of a specified instance

GET /v3/{project_id}/instances/{instance_id}/configurations?offset={offset}&limit={limit}

ddm:param:list

√

√

Modifying parameters of an instance (V3.1)

PUT /v3.1/{project_id}/instances/{instance_id}/configurations

ddm::updateParamGroup

√

√

Scaling out an instance (V3)

POST /v3/{project_id}/instances/{instance_id}/nodes

ddm:instance:extendNode

√

√

Deleting an instance (V3)

DELETE /v3/{project_id}/instances/{instance_id}

ddm:instance:delete

√

√

Enabling or disabling SSL (V3)

POST /v3/{project_id}/instances/{instance_id}/switch-ssl

ddm:instance:modifySsl

√

√

Changing an instance port

PUT /v3/{project_id}/instances/{instance_id}/port

ddm:instance:modify

√

√

Restarting an instance (V3)

POST /v3/{project_id}/instances/{instance_id}/restart

ddm:instance:reboot

√

√

Restarting a node (V3)

POST /v3/{project_id}/instances/{instance_id}/nodes/{node_id}/restart

ddm:instance:reboot

√

√

Binding an EIP (V3)

POST /v3/{project_id}/instances/{instance_id}/eip

ddm:instance:modifyPublicAccess

√

√

Unbinding an EIP (V3)

DELETE /v3/{project_id}/instances/{instance_id}/eip

ddm:instance:modifyPublicAccess

√

√

Changing the ELB load balancer IP address of an instance (V3)

PUT /v3/{project_id}/instances/{instance_id}/elb/ip

ddm:instance:modify

√

√

Deleting instance nodes (V3)

DELETE /v3/{project_id}/instances/{instance_id}/nodes

ddm:instance:extendNode

√

√

Deleting instance nodes in batches (V3)

POST /v3/{project_id}/instances/{instance_id}/nodes/batch-delete

ddm:instance:extendNode

√

√

Querying details of an instance node (V3)

GET /v3/{project_id}/instances/{instance_id}/nodes/{node_id}

ddm:instance:get

√

√

Buying an instance (V3)

POST /v3/{project_id}/instances

ddm:instance:create

√

√

Obtaining information about the EIP bound to an instance (V3)

GET /v3/{project_id}/instances/{instance_id}/public-ips

ddm:instance:get

√

√

Synchronizing data node information (V3)

POST /v3/{project_id}/instances/{instance_id}/data-nodes/sync

ddm:rds:synchro

√

√

Changing an instance name (V3)

PUT /v3/{project_id}/instances/{instance_id}/name

ddm:instance:modify

√

√

Changing the security group of an instance (V3)

PUT /v3/{project_id}/instances/{instance_id}/security-group

ddm:instance:modify

√

√

Reloading table data (V3)

POST /v3/{project_id}/instances/{instance_id}/reload-config

ddm:instance:modify

√

√

Checking RDS connectivity (V3)

POST /v3/{project_id}/instances/{instance_id}/rds/connection

ddm:instance:list

√

√

Setting an instance to read-only

PUT /v3/{project_id}/instances/{instance_id}/readonly-status

ddm:instance:modify

√

√

Querying TMLog information

GET /v3/{project_id}/instances/{instance_id}/tmlogs

ddm:instance:getTmlogs

√

√

Moving a TMLog file

POST /v3/{project_id}/instances/{instance_id}/tmlogs

ddm:instance:modify

√

√

Querying details of an instance (V3)

GET /v3/{project_id}/instances/{instance_id}

ddm:instance:get

√

√

Querying instances (V3)

GET /v3/{project_id}/instances

ddm:instance:list

√

√

Creating an access control group (V3)

POST /v3/{project_id}/instances/{instance_id}/ip-group

ddm:instance:modify

√

√

Querying an access control group (V3)

GET /v3/{project_id}/instances/{instance_id}/ip-group

ddm:instance:get

√

√

Table 2 Schema management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Creating a schema

POST /v1/{project_id}/instances/{instance_id}/databases

ddm:database:create

√

√

Querying schemas

GET /v1/{project_id}/instances/{instance_id}/databases?offset={offset}&limit={limit}

ddm:database:list

√

√

Querying details of a schema

GET /v1/{project_id}/instances/{instance_id}/databases/{ddm_dbname}

ddm:database:get

√

√

Deleting a schema

DELETE /v1/{project_id}/instances/{instance_id}/databases/{ddm_dbname}?delete_rds_data=true

ddm:database:delete

√

√

Querying DB instances available for creating a schema

GET /v1/{project_id}/instances/{instance_id}/rds?offset={offset}&limit={limit}

ddm:rds:list

√

√

Creating a schema (V3)

POST /v3/{project_id}/instances/{instance_id}/databases

ddm:database:create

√

√

Deleting a schema (V3)

DELETE /v3/{project_id}/instances/{instance_id}/databases/{database_name}

ddm:database:delete

√

√

Querying details about a schema (V3)

GET /v3/{project_id}/instances/{instance_id}/databases/{database_name}

ddm:database:get

√

√

Exporting schema metadata (V3)

GET /v3/{project_id}/instances/{instance_id}/schema-metadata

ddm:database:get

√

√

Importing schema metadata (V3)

POST /v3/{project_id}/instances/{instance_id}/schema-metadata

ddm:database:create

√

√

Querying data nodes available for creating a schema (V3)

GET /v3/{project_id}/instances/{instance_id}/available-data-nodes

ddm:rds:list

√

√

Querying data nodes available for shard configuration (V3)

GET /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/available-data-nodes

ddm:rds:list

√

√

Pre-checking shard configuration (V3)

POST /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/precheck

ddm:database:migrate

√

√

Querying the asynchronous pre-check result of shard configuration (V3)

GET /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/precheck/{job_id}

ddm:instance:list

√

√

Configuring shards (V3)

POST /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration

ddm:database:migrate

√

√

Querying details about a shard configuration task (V3)

GET /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}

ddm:task:list

√

√

Canceling shard configuration (V3)

PUT /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}/cancel

ddm:database:migrate

√

√

Rolling back shard configuration (V3)

PUT /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}/rollback

ddm:database:migrateRollback

√

√

Clearing shard configuration data (V3)

PUT /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}/clean

ddm:database:migrate

√

√

Retrying shard configuration (V3)

PUT /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}/retry

ddm:database:migrate

√

√

Changing a route switching policy (V3)

PUT /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}/route-switch-strategy

ddm:database:migrate

√

√

Switching a route (V3)

PUT /v3/{project_id}/instances/{instance_id}/databases/{db_name}/migration/jobs/{job_id}/route-switch

ddm:database:migrate

√

√

Unbinding a schema (V3)

POST /v3/{project_id}/instances/{instance_id}/databases/{logic_db_name}/unbind

ddm:database:unbind

√

√

Table 3 Account management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Creating a DDM account

POST /v1/{project_id}/instances/{instance_id}/users

ddm:user:create

√

√

Querying DDM accounts

GET /v1/{project_id}/instances/{instance_id}/users?offset={offset}&limit={limit}

ddm:user:list

√

√

Modifying a DDM account

PUT /v1/{project_id}/instances/{instance_id}/users/{username}

ddm:user:modify

√

√

Deleting a DDM account

DELETE /v1/{project_id}/instances/{instance_id}/users/{username}

ddm:user:delete

√

√

Resetting the password of a DDM account

POST /v2/{project_id}/instances/{instance_id}/users/{username}/password

ddm:user:modify

√

√

Managing an administrator password (V3)

PUT /v3/{project_id}/instances/{instance_id}/admin-user

ddm:user:modify

√

√

Validating password strength (V3)

POST /v3/{project_id}/weak-password-verification

ddm:user:list

√

√

Creating an account (V3)

POST /v3/{project_id}/instances/{instance_id}/users

ddm:user:create

√

√

Querying accounts (V3)

GET /v3/{project_id}/instances/{instance_id}/users

ddm:user:list

√

√

Modifying an account (V3)

PUT /v3/{project_id}/instances/{instance_id}/users/{username}

ddm:user:modify

√

√

Deleting an account (V3)

DELETE /v3/{project_id}/instances/{instance_id}/users/{username}

ddm:user:delete

√

√

Resetting the password of an account (V3)

POST /v3/{project_id}/instances/{instance_id}/users/{username}/password

ddm:user:modify

√

√

Table 4 Task management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Obtaining task information

GET /v1/{project_id}/jobs/{job_id}

ddm:task:list

√

√

Obtaining information about a task with a specified ID

GET /v3/{project_id}/jobs/{job_id}

ddm:task:get

√

√

Querying tasks (V3)

GET /v3/{project_id}/jobs

ddm:task:list

√

√

Table 5 Monitoring

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Monitoring slow query logs

GET /v2/{project_id}/instances/{instance_id}/slowlog?curPage={curPage}&perPage={perPage}&startDate={startDate}&endDate={endDate}

ddm:instance:listSlowSqlInfo

√

√

Table 6 Session management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Querying logical sessions (V3)

GET /v3/{project_id}/instances/{instance_id}/logical-processes?offset={offset}&limit={limit}

ddm:instance:queryProcessList

√

√

Killing logical sessions (V3)

DELETE /v3/{project_id}/instances/{instance_id}/logical-processes

ddm:instance:killProcessList

√

√

Querying physical sessions (V3)

GET /v3/{project_id}/instances/{instance_id}/physical-processes?offset={offset}&limit={limit}

ddm:instance:queryProcessList

√

√

Killing physical sessions (V3)

DELETE /v3/{project_id}/instances/{instance_id}/physical-processes

ddm:instance:killProcessList

√

√

Querying audit logs of killing sessions (V3)

GET /v3/{project_id}/instances/{instance_id}/processes-audit-log?offset={offset}&limit={limit}&start_time={start_time}&end_time={end_time}

ddm:instance:queryProcessList

√

√

Table 7 Version management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Querying the DDM kernel versions that can be changed (V3)

GET /v3/{project_id}/instances/{instance_id}/database-version/available-versions

ddm:instance:get

√

√

Changing a DDM kernel version (V3)

POST /v3/{project_id}/instances/{instance_id}/database-version/change-version

ddm:instance:changeVersion

√

√

Rolling back a DDM kernel version (V3)

POST /v3/{project_id}/instances/{instance_id}/database-version/rollback-version

ddm:instance:changeVersion

√

√

Reminding users of risks for a DDM kernel version (V3)

GET /v3/{project_id}/instances/{instance_id}/show-risk-info

ddm:instance:get

√

√

Table 8 Backup management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Obtaining backups

GET /v3/{project_id}/backups

ddm:backup:list

√

√

Deleting a backup

DELETE /v3/{project_id}/backups/{backup_id}

ddm:backup:delete

√

√

Querying backup details (V3)

GET /v3/{project_id}/instances/{instance_id}/backups/{backup_id}

ddm:backup:get

√

√

Querying data nodes associated with an instance at a restoration time point (V3)

GET /v3/{project_id}/instances/{instance_id}/backups/related-dn

ddm:backup:get

√

√

Querying the restoration time range (V3)

GET /v3/{project_id}/instances/{instance_id}/backups/restorable-time-interval

ddm:backup:get

√

√

Querying data nodes available to restore data to a point in time (V3)

GET /v3/{project_id}/instances/{instance_id}/backups/restorable-data-node

ddm:rds:list

√

√

Querying instances that can be used for restoration (V3)

GET /v3/{project_id}/instances/{instance_id}/backups/restorable-instances

ddm:instance:list

√

√

Restoring metadata (V3)

POST /v3/{project_id}/instances/{instance_id}/backups/metadata-recovery

ddm:backup:restore

√

√

Restoring data to a new instance (V3)

POST /v3/{project_id}/instances/{instance_id}/backups/recovery

ddm:backup:restore

√

√

Table 9 Parameter management

Description

API

Action

IAM Project

(Project)

Enterprise Project

(Enterprise Project)

Obtaining parameter templates

GET /v3/{project_id}/configurations

ddm:param:list

√

√

Obtaining parameters of a specified parameter template

GET /v3/{project_id}/configurations/{config_id}

ddm:param:list

√

√

Creating a parameter template (V3)

POST /v3/{project_id}/configurations

ddm:param:create

√

√

Deleting a parameter template (V3)

DELETE /v3/{project_id}/configurations/{config_id}

ddm:param:delete

√

√

Querying parameter template application records (V3)

GET /v3/{project_id}/configurations/{config_id}/apply-histories

ddm:param:list

√

√

Replicating a parameter template (V3)

POST /v3/{project_id}/configurations/{config_id}/copy

ddm:param:create

√

√

Updating a parameter template (V3)

PUT /v3/{project_id}/configurations/{config_id}

ddm:param:update

√

√

Querying instances that a parameter template can be applied to (V3)

GET /v3/{project_id}/configurations/{config_id}/query-instances

ddm:instance:list

√

√

Comparing two parameter templates (V3)

PUT /v3/{project_id}/configurations/diff

ddm:param:list

√

√