Updated on 2024-05-28 GMT+08:00

Creating a User and Granting Permissions

This section describes how to use IAM to implement fine-grained permissions control for your UGO resources. With IAM, you can:

  • Create IAM users for employees based on your enterprise's organizational structure. Each IAM user will have their own security credentials for accessing UGO resources.
  • Grant only the permissions required for users to perform specific tasks.
  • Entrust a Huawei Cloud account or cloud service to perform efficient O&M on your UGO resources.

If your Huawei Cloud account does not require individual IAM users, skip this section.

Figure 1 describes the process for granting permissions.

Prerequisites

Before assigning permissions to user groups, you should learn about the system-defined roles and policies listed in Supported system roles. For the system policies of other services, see System Permissions.

Process Flow

Figure 1 Process for granting UGO permissions
  1. Create a user group and assign permissions.

    Create a user group on the IAM console, and assign the UGO ReadOnlyAccess policy to the group.

  2. Create an IAM user.

    Create a user on the IAM console and add the user to the group created in 1.

  3. Log in as an IAM user and verify permissions.

    Log in to the management console using the newly created user, and verify that the user only has read permissions for UGO.

    In the service list, choose Databases > Database and Application Migration UGO. On the UGO page, choose Schema Migration > Database Evaluation, and click Create Project to create an evaluation project. If the evaluation project can be created (assume that the current permission contains only UGO Administrator), the evaluation project is UGO Administrator. The permission has taken effect.