Updated on 2026-07-30 GMT+08:00

Managing Database Rules

Scenarios

You can enable, modify, disable, or delete a database rule you configure, or associate a database rule with a rule set, user, user group, resource account, or account group.

Prerequisites

Your role has the management permission for the DB Rules module. For details about the permissions of each role, see Role.

Querying and Editing a Database Rule

This topic describes how to view and edit a database rule. You can view and edit rule configurations, including basic settings, related regulation sets, users, user groups, accounts, and account groups.

  • A modified database rule takes effect the instant its status changes to Enabled.
  • If related users have logged in to resources before the modification, those users need to log out and log in again for the modified database rule to take effect.
  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
  3. View the rule list.

    Table 1 Database rule list parameters

    Parameter

    Description

    Rule Name

    Name of a database rule.

    Status

    Status of a database rule.

    Action

    Action of a rule.

    • Disconnect: After a database rule is triggered, the system rejects executing the operation and disconnects the O&M session. The system displays a message indicating that the connection is forcibly disconnected by the administrator.
    • Reject: After a database rule is triggered, the system rejects executing the operation and displays a message indicating that the operation has been intercepted.
    • Dynamic approval: After a database rule is triggered, the system reject executing the operation. The system displays a message indicating that the operation has been intercepted and asking you to submit a database approval ticket. A database approval ticket is automatically generated. The command can be executed only after the ticket is submitted and approved.
    • Permit: By default, all operations are allowed. After a database rule is triggered, operations in the related regulation set are allowed.

    Rule Set

    Rule set associated with the rule.

    User

    Users and user groups associated with the rule.

    Account

    Resource accounts and account groups associated with the rule.

    Operation

    Operations you can perform for the rule.

  4. Locate the row that contains the target rule, and click the rule name or Manage in the Operation column to go to the details page.
  5. View and edit basic rule information.

    • In the Basic Info area, view basic rule information, such as the department and status.
    • In the Basic Info area, click Edit on the right. In the displayed dialog box, modify the Rule Name, Action, Period of validity, and Time Limit settings of the rule. For details about the parameters, see Table 1.

  6. View and edit regulation sets related to the rule.

    • In the RegSet area, view the rule sets associated with the rule.
    • In the RegSet area, click Edit on the right. In the displayed dialog box, add a rule set to be associated with the rule.
    • In the row containing the target rule set, click Remove to delete the associated rule set.

  7. View and edit users or user groups associated with the rule.

    • In the User and UserGroup areas, view the users or user groups associated with the rule.
    • In the User or User Group area, click Edit on the right. In the displayed dialog box, associate users or user groups with the rule.
    • In the list, locate the row that contains the target user or user group, and click Remove to delete the associated user or user group and cancel the authorization.

  8. View and edit resource accounts and account groups associated with the rule.

    • In the Account and AccountGroup areas, view the resource accounts or account groups associated with the rule.
    • In the Account or Account Group area, click Edit on the right. In the displayed configuration window, add a resource account or account group to be associated.
    • To remove a resource account or account group, click Remove in the row of the resource account or account group.

Associating a Rule Set with a Database Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
  3. In the Operation column of the target rule, click Relate and select RegSet.
  4. In the displayed dialog box, associate the rule with a rule set.

    • You can associate a rule with multiple rule sets at once. For details about how to create a rule set, see Creating and Managing a Rule Set.
      • Selecting rule sets: Select rule sets in the Selectable RegSets area and click to move them to the Selected RegSets area.
      • Removing rule sets: Select rule sets in the Selected RegSets area and click to move them back to the Selectable RegSets area.
    • After a rule set is associated with a rule, rules added to the rule set automatically inherit the permissions of that rule.

  5. Click OK.

Associating a Database Rule with a User or User Group

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
  3. In the row containing the target rule, click Relate in the Operation column and select User or UserGroup.
  4. In the displayed dialog box, associate the rule with a user or user group.

    Make sure the associated users or users in the associated user groups have the permissions for the DB Tickets module. Otherwise, after they log in to the system, the DB Tickets module will be unavailable to them. This means they cannot submit tickets to obtain approval during operation. For details about the permissions of each role, see Role.
    • You can associate a rule with multiple users or user groups at once.
      • Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click to move them to the Selected users or Selected user groups box.
      • Remove users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selected users or Selected user groups box, and click to move them back to the Selectable users or Selectable user groups box.
    • After a user group is associated with a rule, users automatically obtain the permissions of the rule the instant they are added to the user group.

  5. Click OK.

Associating a Database Rule with a Resource Account or Account Group

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
  3. In the Operation column of the target rule, click Relate and select Account or Account Group.
  4. In the displayed dialog box, associate the rule with a resource account or account group.

    • You can associate a rule with multiple managed resource accounts or account groups at once.
      • Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click to move it to the Selected accounts or Selected account groups box.
      • Remove a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selected accounts or Selected account groups box, and click to remove it back to the Selectable accounts or Selectable account groups box.
    • After an account group is associated with a rule, accounts automatically obtain the permissions of the rule the instant they are added to the account group.

  5. Click OK.

Enabling or Disabling a Database Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
  1. Enable or disable a database rule.

    • Enabling a rule
      1. In the rule list, select all the target rules and click Enable in the lower left corner.
      2. In the displayed dialog box, click OK.
    • Disabling a rule
      1. In the rule list, select all the target rules and click Disable in the lower left corner.
      2. In the displayed dialog box, click OK.

Deleting a Database Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > DB Rules > DB Rules.
  1. Delete a database rule.

    • Deleting a single rule
      1. In the row containing the target rule, click Delete in the Operation column.
      2. In the displayed dialog box, click OK.
    • Batch deleting rules
      1. On the ACL rule list page, select all the target rules.
      2. Click Delete in the lower left corner.
      3. In the displayed dialog box, click OK.