- Service Overview
- User Guide
- Best Practices
-
FAQs
-
Technologies
- How Do I Enable Cluster Protection?
- How Do I Disable Cluster Protection?
- What Should I Do If the Shield on a Node Is Offline?
- What Should I Do If I Have No Service Authorization Permissions or Fail to Create an Agency as an IAM User?
- How Often Are CGS Vulnerability Libraries Updated?
- When Does CGS Update and Back Up Logs?
- Where Can I Find My CGS Logs?
- Does the Shield Plug-in of CGS Affect My Services?
- Product Consultation
- Pricing
- Regions and AZs
- Change History
-
Technologies
- General Reference
Show all
Copied.
Service Authorization
CGS requires access permissions for Cloud Container Engine (CCE) to protect its clusters and Software Repository for Container (SWR) to scan its images.
Authorize CGS to access these services the first time you use it.
Constraints
- CGS cannot be used across regions. The images to be scanned and the clusters to be protected must be in the same region as CGS.
- You have obtained the account (with the global Security Administrator permission) and password for logging in to the management console.
Procedure
- Log in to the management console.
- In the upper part of the page, select a region, click
, and choose Security & Compliance > Container Guard Service.
- Click Approve.
Once service authorization has succeeded, an agency named cgs_admin_trust on CGS will be created and you can start to use CGS.
NOTE:
After authorization, if the agency fails to be created for CGS, it is probably because the number of agencies already reaches the upper limit. In this case, log in to the IAM console and delete unnecessary agencies, or contact the system administrator to increase the agency quota.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot