Help Center/ Cloud Application Engine/ User Guide/ Permissions Management/ Creating a User and Granting Permissions
Updated on 2024-05-25 GMT+08:00

Creating a User and Granting Permissions

This section describes how to use Identity and Access Management (IAM) for fine-grained permissions management on your CAE resources. With IAM, you can:

  • Create IAM users for employees from different departments of your enterprise. In this way, each IAM user has a unique security credential to use CAE resources.
  • Grant only the permissions required for users to perform a specific task.
  • Entrust a Huawei account or cloud service to perform efficient O&M on your CAE resources.

If your Huawei account does not require individual IAM users, skip this section.

This section describes the procedure for granting permissions, as shown in Figure 1.

Prerequisites

Learn about the permissions (see Permissions Management) supported by CAE and choose policies or roles according to your requirements.

For details about the permissions of other services, see System Permissions.

Process Flow

Figure 1 Process for granting CAE permissions
  1. Create a user group and grant permissions to it.

    Create a user group on the CAE console, and grant the CAE ReadOnlyAccess policy to the group.

  2. Create an IAM user.

    Create a user on the IAM console and add the user to the group created in 1.

  3. Log in and verify permissions.

    Log in to the CAE console as the created user, and verify that the user only has read permissions for CAE.

    • In Service List, choose Cloud Application Engine. On the CAE console, choose Components > Create Component. If a message appears indicating insufficient permissions after you click Create and Deploy Component, the CAE ReadOnlyAccess policy has taken effect.
    • Choose any other service in Service List. If a message appears indicating insufficient permissions, the CAE ReadOnlyAccess policy has taken effect.