Sharing KMS Resources
Scenarios
To share your KMS resources with other accounts, create a resource share first. During the creation, you need to specify resources to be shared, configure permissions, specify users to be shared with, and confirm the configuration.
You can use shared KMS to encrypt the secrets and key pairs in DEW, and create an encryption task for instances in Relational Database Service (RDS), Document Database Service (DDS), and Object Storage Service (OBS).
Creating Shared KMS Resources
- Log in to the management console.
- Click
in the upper left corner and choose .
- In the navigation pane on the left, choose .
- Click Create Resource Share in the upper right corner.
Figure 1 Specifying shared resources
- Set resource type to kms:KeyId, choose the corresponding region, and select keys to be shared. Click Next: Associate Permissions.
- Associate a RAM managed permission with each resource type on the displayed page. Then, click Next: Specify Principals in the lower right corner.
- Specify the target principals and click Next: Confirm in the lower right corner.
- Check the configurations and click Submit in the lower right corner.
After a shared instance is created, the organization accepts the instance automatically, while Huawei cloud accounts need to perform certain operations. For details, see .
Viewing Shared KMS Resources
- Log in to the management console.
- Click
in the upper left corner of the management console and select a region or project.
- Click
on the left. Choose .
- Check the shared key resources in the Shared Key tab.
Figure 2 Shared keys
In the Shared Key tab, you can choose a scenario by entering the copied KMS encryption key ID.
Using Shared KMS Resources
- Log in to the management console.
- Click
in the upper left corner of the management console and select a region or project.
- Click
on the left. Choose .
- In the navigation pane on the left, choose Cloud Secret Management Service.
- Click Create Secret. On the displayed page, select or enter a shared key for KMS Encryption Key.
Figure 3 Selecting a shared key
- When creating a key pair, you can select shared KMS keys.
- When creating an RDS, DDS, or OBS instance, you can choose shared KMS keys.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot