CodeArts Console Permissions
If you need to assign different permissions to employees in your enterprise to access CodeArts, use Identity and Access Management (IAM) for fine-grained permissions management. IAM provides identity authentication, permissions management, and access control, helping you securely access your Huawei Cloud resources. If your Huawei Cloud account does not require individual IAM users for permissions management, you can skip this section.
IAM can be used free of charge. You pay only for the resources in your account.
With IAM, you can control access to specific Huawei Cloud resources. For example, some software developers need to use the CodeArts console but should not be allowed to unsubscribe from CodeArts or perform any other high-risk operations. In this scenario, you can create IAM users for the software developers and grant them only the permissions required for viewing basic information about purchased CodeArts packages.
IAM supports role/policy-based authorization and identity policy-based authorization.
The following table describes the differences between these two authorization models.
| Model | Core Relationship | Permissions | Authorization Method | Scenario |
|---|---|---|---|---|
| Role/Policy | User-permission-authorization scope |
| Granting roles or policies to principals | To authorize a user, you need to add it to a user group first and then specify the scope of authorization. It provides a limited number of condition keys and cannot meet the requirements of fine-grained permissions control. This method is suitable for small- and medium-sized enterprises. |
| Identity policy | Users - Policies |
|
| You can authorize a user by attaching an identity policy to it. User-specific authorization and a variety of key conditions allow for more fine-grained permissions control. However, this model can be hard to set up. It requires a certain amount of expertise and is suitable for medium- and large-sized enterprises. |
Assume that you want to grant IAM users permission to create ECSs in CN North-Beijing4 and OBS buckets in CN South-Guangzhou. With role/policy-based authorization, the administrator needs to create two custom policies and assign both to the IAM users. With ABAC, the administrator only needs to create one custom policy and configure the condition key g:RequestedRegion for the policy, and then attach the policy to the users or grant the users the access permissions to the specified regions. ABAC is more flexible than RBAC.
Policies and actions in the two authorization models are not interoperable. You are advised to use ABAC. For details about system-defined permissions of the two models, see Role/Policy-based Permissions Management and Identity Policy-based Permissions Management.
For more details, see IAM Service Overview.
Role/Policy-based Permissions Management
The CodeArts console supports role/policy-based authorization. By default, new IAM users do not have any permissions. You need to add them to one or more groups, and then attach policies or roles to these groups. The users inherit permissions from their groups and can then perform specified operations on cloud services.
CodeArts is a project-level service deployed and accessed in specific physical regions. If you set Scope to All resources, users have permissions for CodeArts resources in all region-specific projects. When accessing the CodeArts console, the users need to switch to a region where they have been authorized.
Table 2 lists all system-defined permissions for the CodeArts console. System-defined policies in RBAC and ABAC are not interoperable.
| Role/Policy Name | Description | Type | Dependency |
|---|---|---|---|
| CodeArts Console FullAccess | All permissions for the CodeArts console. Users with these permissions can buy CodeArts packages and authorize enterprise accounts. | System-defined policy | None |
| CodeArts Console ReadOnlyAccess | Read-only permissions for the CodeArts console. Users with these permissions can only view the usage of CodeArts services. | System-defined policy | None |
Table 3 lists the common operations supported by system-defined permissions for the CodeArts console. Select the permissions as required.
| Operation | Console Console FullAccess | Console Console ReadOnlyAccess |
|---|---|---|
| Check CodeArts Req resource usage | √ | √ |
| Check CodeArts Repo resource usage | √ | √ |
| Check CodeArts Check resource usage | √ | √ |
| Check CodeArts Build resource usage | √ | √ |
| Check CodeArts Artifact resource usage | √ | √ |
| Check CodeArts TestPlan resource usage | √ | √ |
| Check CodeArts IDE Online resource usage | √ | √ |
| Purchase CodeArts packages | √ | × |
| Change CodeArts package specifications | √ | × |
| View CodeArts package resource details | √ | √ |
| View the authorization list | √ | √ |
| Authorize an enterprise account | √ | × |
| Cancel the authorization granted to an enterprise account | √ | × |
| Accept or reject authorization to an enterprise account | √ | × |
Role/Policy Dependencies of the CodeArts Console
| Console Function | Dependent Service | Role/Policy Required |
|---|---|---|
| Purchasing CodeArts | Billing Center (BSS) | An IAM user with the CodeArts Console FullAccess permission can purchase CodeArts only after the user is granted one of the following permissions:
|
Identity Policy-based Permissions Management
The CodeArts console supports identity policy-based authorization. Table 5 lists all system-defined policies for the CodeArts console with ABAC. System-defined policies in RBAC and ABAC are not interoperable.
| Identity Policy Name | Description | Type |
|---|---|---|
| CODEARTSFullAccessPolicy | All permissions for the CodeArts console. Users with these permissions can buy CodeArts packages and authorize enterprise accounts. | System-defined identity policy |
| CODEARTSReadOnlyPolicy | Read-only permissions for the CodeArts console. Users with these permissions can only view the usage of CodeArts services. | System-defined identity policy |
Table 6 lists the common operations supported by system-defined policies for the CodeArts console.
| Operation | CODEARTSFullAccessPolicy | CODEARTSReadOnlyPolicy |
|---|---|---|
| Check CodeArts Req resource usage | √ | √ |
| Check CodeArts Repo resource usage | √ | √ |
| Check CodeArts Check resource usage | √ | √ |
| Check CodeArts Build resource usage | √ | √ |
| Check CodeArts Artifact resource usage | √ | √ |
| Check CodeArts TestPlan resource usage | √ | √ |
| Check CodeArts IDE Online resource usage | √ | √ |
| Purchase CodeArts packages | √ | × |
| Change CodeArts package specifications | √ | × |
| View CodeArts package resource details | √ | √ |
| View the authorization list | √ | √ |
| Authorize an enterprise account | √ | × |
| Cancel the authorization granted to an enterprise account | √ | × |
| Accept or reject authorization to an enterprise account | √ | × |
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot