How Do I Handle the Error 403 "Insufficient permissions. Contact your account administrator to assign you a policy with the devcloud:monthlyPackage:subscribe action."?
Symptom
When you enable CodeArts Agent packages or pay-per-use billing as an IAM user, the error message "Insufficient permissions. Contact your account administrator to assign you a policy with the devcloud:monthlyPackage:subscribe action." is displayed in the upper right corner.
Cause Analysis
The current IAM user has not been granted the fine-grained permission to purchase CodeArts Agent.
Solution
- Log in to the Identity and Access Management (IAM) console using your HUAWEI ID.
- Create and configure a custom policy for enabling CodeArts Agent packages or pay-per-use billing.
- In the navigation pane on the left, choose Permissions > Policies/Roles. The Policies/Roles page is displayed.
- Click Create Custom Policy in the upper right corner.
- Set the custom policy by referring to Table 1. Figure 1 Creating a custom policy
Table 1 Custom policy parameters Parameter
Description
Policy Name
Enter a policy name. Only letters, digits, spaces, and the following special characters are allowed: -_.,
Policy View
Select Visual editor.
Policy Content
Configure the DevCloud permission as follows. Only this permission is required for enabling or disabling pay-per-use billing.
- Select Allow.
- Cloud service: Enter devcloud in the search box and select CodeArts (DevCloud).
- Actions: Enter monthly in the search box and select devcloud:monthlyPackage:subscribe and devcloud:monthlyPackage:listResourceDetail.
- Skip Select resource.
- Skip (Optional) Add request condition.
To enable CodeArts Agent packages, you also need to configure the BSS permission as follows:
- Click Add Permissions.
- Select Allow.
- Cloud service: Enter bss in the search box and select BSS (BSS).
- Actions: Enter order in the search box and select bss:order:pay and bss:order:view.
- Skip Select resource.
- Skip (Optional) Add request condition.
Description
Optional. Enter a brief description for the policy.
- Click OK. The custom policy is created.
On the Policies/Roles page, view the new policy.
- Add the IAM user who needs to enable CodeArts Agent packages or pay-per-use billing to a user group. If the user has been added to a user group, skip this step and go to 4.
- In the navigation pane on the left, choose User Groups.
- Click Create User Group in the upper right corner.
- Set the user group name and click OK.
The user group name consists of letters, digits, spaces, hyphens (-), and underscores (_).
- On the User Groups page, locate the target user group, and click Manage User in the Operation column.
- Select the target IAM user, and click OK.
- Assign the permissions of the custom policy to the user group.
- On the User Groups page, locate the target user group, and click Authorize in the Operation column.
- In the search box, enter the custom policy name configured in 2. Locate and select the policy. Click Next.
- Click OK. An information dialog box is displayed.
- Click OK. A message is displayed, indicating that the authorization is successful. Click Finish.
- Log in to the CodeArts Agent console as the authorized IAM user and enable CodeArts Agent packages or pay-per-use billing again.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot