Help Center> Cloud Bastion Host> User Guide> Instances> Allowing Access to Cloud Assets
Updated on 2024-06-28 GMT+08:00

Allowing Access to Cloud Assets

In CBH, you can use the secrets managed by Cloud Secret Management Service (CSMS).

After you authorize CBH to access CSMS secrets and KMS keys, it takes about 10 minutes before the bastion host can obtain the delegation token.

For details about how to create a secret, see Data Encryption Workshop - Credential Management.

For secrets invoked through the bastion host, the account and password must comply with Key specifications.

Example:

username:root

password:*****

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, click and choose Security & Compliance > Cloud Bastion Host to go to the CBH console.

    Figure 1 Instances

  4. Click Cloud Asset Authorization in the upper right corner.
  5. In the displayed dialog box, switch to in the Operation column. Enable CSMS and KMS authorization.

    Figure 2 Cloud asset authorization

  6. For details about how to add a resource account, see Adding Accounts of Managed Host or Application Resources into CBH.