Help Center/ Log Tank Service/ User Guide/ Permissions Management
Updated on 2024-07-23 GMT+08:00

Permissions Management

You can use Identity and Access Management (IAM) for fine-grained permissions control for your LTS. With IAM, you can:

  • Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing LTS resources.
  • Grant only the permissions required for users to perform a specific task.
  • Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing LTS resources.

If your Huawei Cloud account does not require individual IAM users, skip this chapter.

This section describes the procedure for granting permissions (see Figure 1).

Prerequisites

Before granting permissions to user groups, learn about the permissions supported by LTS and select the permissions as required. For details, see Permissions Management.

Process Flow

Figure 1 Process of granting permissions to a user
  1. Log in to the IAM console. Create a user group on the IAM console and grant the LTS FullAccess permission to the user group. For details, see Creating a User Group and Assigning Permissions.

    If you select the LTS FullAccess permissions, the Tenant Guest policy that the permission depends on is automatically selected. You also need to grant the Tenant Administrator policy for the global service project to the user group.

  2. Create a user on the IAM console and add the user to the user group created in 1. For details, see Creating an IAM User.
  3. Log in to the console by using the created user and verify permissions in the authorized region. For details, see Logging In as an IAM User and verify permissions.