Help Center/ Cloud Bastion Host/ User Guide/ Authorizing Access to Cloud Assets
Updated on 2026-07-30 GMT+08:00

Authorizing Access to Cloud Assets

CBH has been interconnected with Key Management Service (KMS), Cloud Secret Management Service (CSMS), Simple Message Notification (SMN), Elastic Cloud Server (ECS), and Relational Database Service (RDS), making it easier for you to use credentials managed by your bastion host.

Asset Authorization

Table 1 Asset authorization description

Asset Module

Authorization Description

CSMS

After your authorization, CBH has the permissions needed to query your credential list in CSMS. You can select credentials as resource accounts on your CBH instance.

NOTE:

For secrets invoked through the bastion host, the account and password must comply with Key specifications. For details about how to create a credential, see Cloud Secret Management Service in DEW.

Example:

username:root

password:*****

KMS

After your authorization, CBH has the permissions needed to use KMS APIs to obtain credentials in CSMS. You can use obtained credentials to log in to the hosts managed by your CBH instance.

ECS

After your authorization, CBH will have the permissions to query your ECS list. You can synchronize your ECS list to the host list in CBH in just a few clicks.

RDS

After your authorization, CBH will have the permissions to query your RDS instance list. You can synchronize your RDS instance list to the host list in CBH in just a few clicks.

SMN

After your authorization, CBH has the permissions to query your SMN instance list. You can create SMN topics on CBH instances and synchronize the topics to your SMN instance.

How to Use

After your authorization, it takes about 10 minutes for your bastion host to obtain the delegation tokens.

Enabling or Disabling Authorization

  1. Log in to the CBH console.
  2. Click in the upper left corner on the displayed page and select a region.
  3. Click Cloud Asset Authorization in the upper right corner.
  4. On the configuration page, enable or disable the corresponding authorization.

    • Enabling authorization
      1. In the Operation column of the target resource module, click Enable.
      2. In the displayed dialog box, click OK.
    • Disabling authorization
      1. In the Operation column of the target resource module, click Disable.
      2. In the displayed dialog box, click OK.