Delegating CPH to Operate OBS Buckets
The administrator can create custom policies on IAM, assign custom policies to OBS buckets for refined access control, and delegate the policies to CPH to back up and restore cloud phone data and install applications.
- Log in to the management console.
- On the Service List page, choose Management & Governance > Identity and Access Management.
- On the IAM console, choose Permissions > Policies/Roles from the navigation pane, and click Create Custom Policy in the upper right corner.
- Enter a policy name.
Select Visual editor for Policy View.
- Set the policy content.
- Select Allow.
- Click Select service and select Object Storage Service (OBS).
- For Actions, select actions as required. For details about the actions, see Object-Related Actions.
To delegate CPH to perform operations on OBS buckets, at least the following four actions must be selected:
obs:object:GetObject
obs:object:PutObject
obs:object:PutObjectVersionAcl
obs:object:PutObjectAcl
- Select All for Resources. For details about how to select specific resources, see descriptions of specific resources in Creating a Custom Policy.
- Click OK.
- Create an agency.
- Log in to the IAM console.
In the navigation pane on the left, choose Agencies and click Create Agency in the upper right corner.
- Configure parameters shown in the following figure and click Next.
The agency name must be cph_obs_agency.
- Select the custom policy created in Create a custom policy and click Next.
- Select Global services and click OK.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot