Updated on 2023-01-09 GMT+08:00

Granting an IAM Account the DWS Database Access Permission

The IAM account you use to access a database must be granted with the DWS Database Access permission. Only users with both the DWS Administrator and DWS Database Access permissions can connect to GaussDB(DWS) databases using the temporary database user credentials generated based on IAM users. Using the DWS Database Access permission helps to control access to databases.

The DWS Database Access permission can only be granted to user groups. Ensure that your IAM account is in a user group with this permission.

On IAM, only users in the admin group have the permissions to manage users. This requires that your IAM account be in the admin user group. Otherwise, contact the IAM account administrator to grant your IAM account this permission.

Procedure

  1. Log in to the Huawei Cloud management console and choose Service List > Management & Governance > Identity and Access Management to enter the IAM management console.
  2. Modify the user group to which your IAM user belongs. Set a policy for, grant the DWS Database Access permission to, and add your IAM user to it.

    Only users in the admin user group of IAM can perform this step. In IAM, only users in the admin user group can manage users, including creating user groups and users and setting user group rights.

    For details, see "User and User Group Management > Viewing or Modifying User Group Information" in the Identity and Access Management User Guide.

    You can also create an IAM user group, and set a policy for, grant the DWS Administrator and DWS Database Access permissions to, and add your IAM user to it. For details, see "User and User Group Management > Creating a User Group" in the Identity and Access Management User Guide.