How Do I Use VPC Sharing to Process GaussDB(DWS) Resources?
Context
With VPC sharing, multiple accounts can create cloud resources such as GaussDB(DWS) clusters, ELBs, and ECSs within a single, centrally managed VPC. It empowers the VPC owner to distribute access to subnets within the VPC across various accounts. Through VPC sharing, you can easily configure and manage multiple accounts' resources at low costs. For more information, see VPC Sharing.
Constraints and Limitations
- The subnets of the owner and those of the principals are in the same VPC, so resources in these subnets can communicate with each other by default. The owner and principals can create resources in a shared subnet. If the resources are associated with different security groups, they are isolated from each other. If you want the resources to communicate with each other, you need to add security group rules. For details, see Adding a Security Group Rule.
For example, to allow mutual access between accounts A and B's GaussDB(DWS) security groups, add inbound rules to each group with the other group specified as the source.
- A principal can receive a maximum of 100 subnet shares.
- A subnet can be shared with a maximum of 100 principals.
Operation Permissions of the Owner and Principles in a Shared VPC
The owner and principals of a shared subnet have different operation permissions on the subnet and associated resources. For details, see Table 1.
Role |
When a Share Is Accepted |
When a Share Is Stopped |
When the Principals Leave a Share |
---|---|---|---|
Owner |
|
|
|
Principal |
|
Principals can use the existing resources created by themselves, but cannot create resources in the shared subnet. |
Principals can use the existing resources created by themselves, but cannot create resources in the shared subnet. |
Using GaussDB(DWS) Resources in a Shared VPC
- Share a subnet on the RAM console or VPC console. For details, see Table 2.
- When creating a GaussDB(DWS) cluster, select shared VPC resources on the Configure Network > VPC page after the share is created.
Method |
Description |
Operation |
---|---|---|
Method A |
|
|
Method B |
|
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot