Help Center/ Cloud Bastion Host/ User Guide/ Instances/ Allowing Access to Cloud Assets
Updated on 2024-09-24 GMT+08:00

Allowing Access to Cloud Assets

CBH has been interconnected with Cloud Secret Management Service (CSMS), Elastic Cloud Server (ECS), Relational Database Service (RDS), and Key Management Service (KMS), making it easier for you to use managed credentials on CBH.

After you authorize CBH to access CSMS, ECS, RDS, and KMS, it takes about 10 minutes before the bastion host can obtain the delegation token.

For details about how to create a secret, see Data Encryption Workshop - Credential Management.

For secrets invoked through the bastion host, the account and password must comply with Key specifications.

Example:

username:root

password:*****

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner and select a region or project. In the upper left corner of the page, click and select a region. Choose Security & Compliance > Cloud Bastion Host to go to the CBH instance management page.

    Figure 1 Instances
    Table 1 Instance parameters

    Parameter

    Description

    Instance Name

    Instance name you specify. It cannot be modified after the instance is created.

    Status

    Status of the instance, including the status of the standby node.

    Instance Type

    Instance type you select.

    Login Address

    Private IP address of an instance.

    EIP

    EIP of the instance.

    Billing Mode

    Billing mode of the current instance.

    Enterprise Project

    Enterprise project that the instance belongs to.

  3. Click Cloud Asset Authorization in the upper right corner.
  4. In the displayed dialog box, switch to in the Operation column to enable the authorization.

    Figure 2 Cloud asset authorization

  5. For details about how to add a resource account, see Adding Accounts of Managed Host or Application Resources into Your Bastion Host.