Updated on 2026-04-16 GMT+08:00

System Agency

UCS works closely with other container services. When you log in to the UCS console for the first time, UCS automatically requests permission to access those services. Specifically:

Access to container services: To support CCE clusters in container clusters, UCS requires permission to access Cloud Container Engine (CCE).

After you agree to the authorization, UCS automatically creates an agency named ucs_admin_trust in IAM to delegate other resource operation permissions in your account to Huawei Cloud UCS. For details, see Delegating Another Account for Resource Management.

ucs_admin_trust

The ucs_admin_trust agency has permission to call other cloud services that UCS depends on, for example, to obtain the cluster status.

UCS depends on many other cloud services. If the ucs_admin_trust agency is not created, UCS functions may be affected due to insufficient permissions on a service. Do not delete or modify the ucs_admin_trust agency in IAM while using UCS.

To improve agency security, the ucs_admin_trust permissions are redesigned based on the dependencies of UCS on other cloud services. The new permissions do not include the Tenant Administrator permissions. The console will display a message indicating that the permissions have changed and a re-authorization is required. After re-authorization, the permissions of the cloud services that UCS depends on will be added to the ucs_admin_trust agency.

When creating the ucs_admin_trust agency, UCS creates a custom policy named UCS admin policies. Do not delete this policy.