Performing Operations on DWS Users and Permissions
This section describes how to perform operations on users, roles, and permissions. The operations include Creating a User/Role, Managing Permissions, Configuring the Export Permission for IAM Users, Sharing a Custom Data Source with Other IAM Users of the Same Tenant, and Exporting Permissions.
Creating a User/Role
- Log in to the DWS console.
- In the navigation pane on the left, choose Data > SQL Editor.
- Click the Data Source tab. After connecting to a data source, right-click Users/Roles and select Create User. Figure 1 Creating a user
- On the Create User page, set parameters based on Table 1.
Table 1 Parameters for creating a user Parameter
Description
User/Role
Select one option. If you select User, you can log in to the database and need to set a password. If you select Role, you cannot log in to the database by default and do not need to set a password. This option is usually used for permission group management.
Password
Regular expression verification is required. This parameter is mandatory only for a user. The password must meet the DWS password complexity requirements.
Permissions
Basic permissions of the user or role. You can select multiple options.
Maximum Connections
Maximum number of concurrent connections allowed for the user or role. The value cannot be less than -1. Value -1 indicates that there is no limit.
Start Time
Time when the user or role takes effect. The user or role is unavailable before it takes effect.
End Time
Time when the user or role expires. When the user or role expires, it cannot log in to the database. If this parameter is not set, the user is permanently valid.
Role Group
Grants the permissions of existing users and roles to this user or role. That is, the user or role will inherit the permissions of the selected role group.
Member Group
Adds the user or group to be created to the member group that contains existing users and roles so that they inherit the permissions of the user or group to be created.
Description
Description of the user to be created. The description makes it easy to identify and maintain the user.
SQL Preview
Click Preview to display the SQL syntax for creating a user.
- Confirm the information and click OK.
Managing Permissions
- Log in to the DWS console.
- In the navigation pane on the left, choose Data > SQL Editor.
- Click the Data Source tab. After connecting to a data source, right-click the name of a user or role and select Permissions Management. Figure 2 Managing permissions
- On the displayed user permissions list page, you can view, add, modify, delete, and batch delete permissions of the user. Table 2 lists the operations. Figure 3 Permissions

Table 2 Permissions management operations Operation
Description
Add
Click Add to add a permission configuration. Select the database object type and the corresponding objects. Then, select permissions. For details about the permissions, see "DCL Syntax > GRANT" in GRANT.
Modify
Click Modify in the Operation column, and then click Modify in the Permissions column to add or remove permissions.
Delete
Click Delete in the Operation column to delete a specified permission. The deletion takes effect immediately. Confirm the impact before performing this operation.
Delete
Select multiple permissions and click Delete to delete them.
- After operating the permissions, click Submit.
Configuring the Export Permission for IAM Users
You can configure whether to disable the export function for the IAM users of a cluster. If the export function is disabled for an IAM user of a cluster, the Export button is unavailable for the IAM user.
- Log in to the DWS console.
- In the navigation pane on the left, choose Data > SQL Editor.
- Choose Data Source > Custom and create a custom data source based on the required cluster.
- Right-click the custom data source name and select Export file permissions (this function is available only for clusters). You can view the list of IAM users for whom the export function is disabled.
- Click Add Forbidden Permission above the list. You can disable the export function for other IAM users of the same tenant and set an end time for disabling the export function.
- Click Revoke Permission in the Operation column of an IAM user for whom the export function is disabled.
- Click Modify in the Operation column of an IAM user for whom the export function is disabled to change the expiration time and IAM username.
Figure 4 Disabling the export function for a cluster
- Confirm the information and click OK. When you log in to the system as the IAM user for whom the export function is disabled, create a custom data source in the cluster, and query data, the Export button is unavailable. Figure 5 Unavailable Export
Sharing a Custom Data Source with Other IAM Users of the Same Tenant
IAM users can share a custom data source with other IAM users of the same tenant. Other users can log in to the cluster database through the shared data source. If the shared data source does not contain a saved password, other users must enter the password when logging in to the database. Shared data sources cannot be shared again.
- Log in to the DWS console.
- In the navigation pane on the left, choose Data > SQL Editor.
- Click Data Source and click Custom to create a custom data source. Remember the password you set during the creation.
- Right-click the name of the custom data source to be shared and choose Shared datasource to view the list of IAM users with whom this data source has been shared.
- Click Add share to share the data source with other IAM users of the same tenant and set the sharing expiration time.
- To cancel the sharing, click Unshare in the Operation column of the row that contains the target IAM user.
- Click Modify in the Operation column of the row that contains the target IAM user to change the sharing expiration time and username.
Figure 6 Sharing a data source
- IAM users can easily access the data sources shared with them by viewing the custom data source list and clicking the respective data source name to log in to the system. Figure 7 Shared data source
Exporting Permissions
- Log in to the DWS console.
- In the navigation pane on the left, choose Data > SQL Editor.
- Click the Data Source tab. After connecting to a data source, right-click Users/Roles and select Export Permissions. Figure 8 Exporting permissions
- In the displayed Export Permissions dialog box, set the following parameters.
Table 3 Parameters for exporting permissions Parameter
Description
Database
Databases whose permissions you want to export. You can select a maximum of 10 databases.
User
Users or roles whose permissions you want to export. You can select a maximum of 100 users or roles.
OBS Bucket
OBS bucket to which you want to export the permissions file. Select an available OBS bucket of the current tenant.
Path
Path in the OBS bucket for storing the exported permissions file
Remarks
Description of the exported permissions
- Confirm the information and click OK.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot