更新时间:2024-09-06 GMT+08:00

数据仓库服务 GaussDB(DWS)

Organizations服务中的服务控制策略(Service Control Policy,以下简称SCP)可以使用以下授权项元素设置访问控制策略。

SCP不直接进行授权,只划定权限边界。将SCP绑定到组织单元或者成员账号时,并没有直接对组织单元或成员账号授予操作权限,而是规定了成员账号或组织单元包含的成员账号的授权范围。

本章节介绍组织服务中SCP使用的元素,这些元素包含了操作(Action)、资源(Resource)和条件(Condition)。

如何使用这些元素编辑SCP自定义策略,请参考创建SCP

操作(Action)

操作(Action)即为SCP中支持的授权项。

  • “访问级别”列描述如何对操作进行分类(list、read和write等)。此分类可帮助您了解在SCP中相应操作对应的访问级别。
  • “资源类型”列指每个操作是否支持资源级权限。
    • 资源类型支持通配符号*表示所有。如果此列没有值(-),则必须在SCP语句的Resource元素中指定所有资源类型(“*”)。
    • 如果该列包含资源类型,则必须在具有该操作的语句中指定该资源的URN。
    • 资源类型列中必需资源在表中用星号(*)标识,表示使用此操作必须指定该资源类型。

    关于GaussDB(DWS)定义的资源类型的详细信息请参见资源类型(Resource)

  • “条件键”列包括了可以在SCP语句的Condition元素中支持指定的键值。
    • 如果该授权项资源类型列存在值,则表示条件键仅对列举的资源类型生效。
    • 如果该授权项资源类型列没有值(-),则表示条件键对整个授权项生效。
    • 如果此列条件键没有值(-),表示此操作不支持指定条件键。

    关于GaussDB(DWS)定义的条件键的详细信息请参见条件(Condition)

您可以在SCP语句的Action元素中指定以下GaussDB(DWS)的相关操作。

表1 GaussDB(DWS)支持的授权项

授权项

描述

访问级别

资源类型(*为必须)

条件键

dws:cluster:list

授予集群列表查询权限。

list

-

-

dws:cluster:getDetail

授予集群详情查看权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:create

授予DWS集群创建权限。

write

-

  • g:RequestTag/<tag-key>
  • g:TagKeys
  • g:EnterpriseProjectId

dws:cluster:delete

授予DWS集群删除权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:scaleIn

授予DWS集群缩容权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listRing

授予获得合适的缩容环列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:restore

授予就地恢复集群权限。

write

cluster *

-

-

  • g:RequestTag/<tag-key>
  • g:TagKeys
  • g:EnterpriseProjectId

dws:cluster:scaleOut

授予集群扩容权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:resize

授予集群扩容和调整大小权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:expandDisk

授予DWS集群磁盘扩容权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:restart

授予DWS集群重启权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:resetPassword

授予DWS集群重置密码权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listAuditLog

授予查看审计日志列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:setMaintainceWindow

授予维护时间窗修改权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:switchover

授予集群主备恢复权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:cancelReadonly

授予集群解除只读权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addCN

授予集群增加CN节点权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listCN

授予获取集群CN列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteCN

授予删除CN节点权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:redistribution

授予集群数据重分布权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createDataSource

授予创建MRS数据源权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateDataSource

授予更新MRS数据源权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteDataSource

授予删除MRS数据源权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:alarm:listDetail

授予查询告警详情列表权限。

list

-

-

dws:alarm:report

授予上报告警权限。

write

-

-

dws:event:createSpec

授予创建事件配置权限。

write

-

-

dws:event:deleteSpec

授予删除事件配置权限。

write

-

-

dws:event:report

授予上报事件权限。

write

-

-

dws:cluster:createConnection

授予创建DWS集群连接权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteConnection

授予删除DWS集群连接权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateConnection

授予更新DWS集群连接权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:bindEIP

授予公网IP绑定权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:unbindEIP

授予公网IP解绑权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listELB

授予获得弹性负载均衡列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:bindELB

授予绑定弹性负载均衡权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:unbindELB

授予解绑弹性负载均衡权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createSnapshotPolicy

授予设置自动快照策略权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSnapshotStatistics

授予查询快照空间容量权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSnapshot

授予查看集群快照列表权限。

list

cluster

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getSnapshotDetail

授予查看集群快照详情权限。

list

cluster

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createSnapshot

授予使用API创建快照权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteSnapshotPolicy

授予删除快照策略权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSnapshotPolicy

授予查询快照策略权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:copySnapshot

授予复制快照权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteSnapshot

授予删除快照权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:restoreSnapshot

授予恢复快照权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteDisasterRecovery

授予删除容灾权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createDisasterRecovery

授予创建备份容灾权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:restoreDisaster

授予容灾恢复权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws::listTagsForProject

授予查询该项目下的标签列表权限。

list

-

-

dws:cluster:listConfig

授予查看集群配置参数权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:service:listSpec

授予查看服务规格列表权限。

list

-

-

dws:cluster:listDataSource

授予查看集群数据源权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:service:listJobDetail

授予查看任务进度详情权限。

list

-

-

dws:service:listStatistics

授予查看当前可用资源数量权限。

list

-

-

dws:service:listQuotas

授予查看用户配额权限。

list

-

-

dws:cluster:updateConfig

授予更新集群配置参数权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:service:listAZ

授予查看服务可用区列表权限。

list

-

-

dws:service:listDssPools

授予查看专属存储池列表权限。

list

-

-

dws:service:listEps

授予查看eps列表权限。

list

-

-

dws:service:authorize

授予获取用户授权权限。

write

-

-

dws:service:checkAuthorize

授予检查用户授权权限。

read

-

-

dws::updateTag

授予更新标签权限。

tagging

cluster *

-

-

  • g:RequestTag/<tag-key>
  • g:TagKeys
  • g:EnterpriseProjectId

dws:cluster:getSnapshotPolicy

授予查看快照策略权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:bindOrUnbindELB

授予绑定或解绑弹性负载均衡权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:bindOrUnbindEIP

授予绑定或解绑弹性IP权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteNode

授予删除节点权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listConnection

授予查询DWS集群连接列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:checkConnection

授予检查DWS集群连接权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDN

授予获取集群DN列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listBucket

授予获取桶列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listScaleInNode

授予获取缩容待删除节点列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listFlavorForResize

授予查询支持变更的规格列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listFlavorForRestore

授予查询支持恢复的规格列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws::countResourceByTag

授予使用标签查询集群权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateSnapshotPolicy

授予更新快照策略权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws::listResourceByTag

授予根据标签查询集群列表权限。

list

cluster *

-

-

  • g:RequestTag/<tag-key>
  • g:TagKeys
  • g:EnterpriseProjectId

dws:cluster:assessRisk

授予评估调整大小风险权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:checkRestoreTable

授予恢复表检查权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:checkSupportFineGrainedBackup

授予检测集群是否支持细粒度备份权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:configureNetwork

授予配置集群网络权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:expandWithExistedNodes

授予集群从空闲节点扩容权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getAntiAffinity

授予查询反亲和性状态权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getCnCount

授予查询集群CN数量权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getCredential

授予获取集群JDBC连接凭证权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDiskExpandScope

授予获取磁盘扩容范围权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getEncryptInfo

授予查看集群加密信息权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listHistoryConfig

授予查询参数修改历史权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getHistoryConfigDetail

授予查询参数修改历史详情权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getInstanceDetail

授予实例详情查看权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getProcessTopo

授予查询集群节点进程拓扑权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getRedistribution

授予查询重分布详情权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getRestoreDatabase

授予获取用户恢复数据库权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getRoachConfig

授予获取roach参数配置权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getSnapshotEncryptInfo

授予查看快照加密信息权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getSnapshotStorage

授予查询快照空间容量使用情况权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getTaskDetail

授予查询集群任务详情权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getVolumeInfo

授予查询磁盘信息权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listNode

授予查询节点列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSchema

授予获取用户结构列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listTable

授予获取用户表列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDatabase

授予获取用户数据库列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:recoverRedistribution

授予恢复重分布权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:resizeFlavor

授予执行规格变更权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:resizeRetry

授予调整大小重试权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:restoreTable

授予表恢复权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:retryELBSwitch

授予重试ELB切换任务权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listRingForScaleIn

授予获得缩容环列表权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:stopSnapshot

授予停止快照权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:suspendRedistribution

授予暂停重分布权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateInstanceAliasName

授予更新节点别名权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateRoachConfig

授予更新roach参数配置权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateScheduleConfig

授予更新调度配置权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:service:getClusterSum

授予查询集群数量权限。

read

-

-

dws:service:getResourceStatistics

授予查询资源统计权限。

read

-

-

dws:service:getStorageStatistics

授予查询存储统计信息权限。

read

-

-

dws:cluster:listDisasterRecovery

授予容灾列表查询操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:checkDisasterRecoveryName

授予容灾名称检查操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateDisasterRecoveryConfig

授予更新容灾配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addOperationalTask

授予新增调度任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:bindManageIp

授予绑定管理面IP操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:checkAccessLts

授予检查LTS服务是否正常操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:checkLogicalClusterData

授予逻辑集群-检查集群有无业务数据操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:closeAccessLts

授予关闭云服务日志操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createLogicalCluster

授予逻辑集群-创建逻辑集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createApplicationForDM

授予数据迁移-增加作业任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createClusterForDM

授予数据迁移-创建集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createConnectionForDM

授予数据迁移-增加指定连接信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createMappingForDM

授予数据迁移-增加指定映射信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteApplicationForDM

授予数据迁移-删除作业任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteClusterForDM

授予数据迁移-删除集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteConnectionForDM

授予数据迁移-删除指定连接信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteMappingForDM

授予数据迁移-删除指定映射信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:dialsConnectionForDM

授予数据迁移-连接信息探活操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getApplicationForDM

授予数据迁移-查询作业任务详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listApplicationConfigForDM

授予数据迁移-作业任务参数配置信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listApplicationForDM

授予数据迁移-查询集群内所有作业任务操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterForDM

授予数据迁移-查询集群信息详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listClusterForDM

授予数据迁移-查询集群信息列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listConfigurationTemplateForDM

授予数据迁移-查询参数模板操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getConnectionForDM

授予数据迁移-查询连接信息详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listConnectionForDM

授予数据迁移-查询所有连接信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDependApplicationForDM

授予数据迁移-查询所有依赖作业任务操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMappingForDM

授予数据迁移-查询映射信息详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listMappingForDM

授予数据迁移-查询所有映射信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listProductForDM

授予GDS-Kafka-查询产品信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateConnectionForDM

授予数据迁移-修改指定连接信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateMappingForDM

授予数据迁移-修改指定映射信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:startApplicationForDM

授予数据迁移-启动作业任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:stopApplicationForDM

授予数据迁移-停止作业任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteCrossRegionSnapshotPolicy

授予删除跨区域备份配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteLogicalCluster

授予逻辑集群-删除逻辑集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteOperationalTask

授予调度器-删除调度任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:operateDisasterRecovery

授予容灾-容灾操作,启/停/切换等操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateLogicalCluster

授予逻辑集群-更新逻辑集群权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listAllCrossRegionSnapshotConfig

授予查询所有跨区域快照配置操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDisasterRecoveryProject

授予容灾-查询可用project操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDisasterRecoveryRegion

授予容灾-查询可用region操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getLastOperationalTask

授予调度器-查询上次构建任务操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getLogicalClusterRings

授予逻辑集群-查询集群环信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getLogicalClusterVolume

授予逻辑集群-查询集群磁盘信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getOperationalTaskConfig

授予调度器-获取调度器运维任务公共配置操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getOperationalTaskDetail

授予调度器-获取运维任务详情列表操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getOperationalTaskStatus

授予调度器-获取调度器状态操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSnapshotRegion

授予获取跨区域快照可用region操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getTargetAllCrossRegionSnapshotConfig

授予查询所有跨区域快照配置操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:initLogicalClusterSwitch

授予逻辑集群-切换逻辑集群开关操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listAccessLts

授予查询LTS列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listLogicalCluster

授予逻辑集群-查询逻辑集群列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listLogicalClusterTask

授予逻辑集群-查询任务信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listOperationalTask

授予调度器-获取运维任务列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:openAccessLts

授予开启云服务日志操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:pauseOperationalTask

授予调度器-暂停调度任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDisasterRecoveryDetail

授予容灾-查询容灾详情操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:refreshOperationalTask

授予调度器-远程刷新当前集群运维任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:restartLogicalCluster

授予逻辑集群-重启逻辑集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:resumeOperationalTask

授予调度器-恢复调度任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:setCrossRegionSnapshotPolicy

授予设置跨区域备份配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:startOperationalTask

授予调度器-打开调度器操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:stopOperationalTask

授予调度器-关闭调度器操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:switchLogicalCluster

授予逻辑集群-转换到逻辑集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:syncCrossRegionBackupClusterInfo

授予同步跨region备份集群信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:syncCrossRegionBackupConfig

授予同步跨区域快照配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:syncCrossRegionBackupInfo

授予同步跨region快照信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:syncLogicalCluster

授予逻辑集群-逻辑集群从后台同步操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateOperationalTaskConfig

授予调度器-修改调度器运维任务公共配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateOperationalTask

授予调度器-修改调度任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addPlanForWLM

授予工作负载管理-添加工作负载计划操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addPlanStageForWLM

授予工作负载管理-添加工作负载计划阶段操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addQueueForWLM

授予工作负载管理-添加工作负载队列操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addQueueUserForWLM

授予工作负载管理-添加工作负载队列的绑定用户操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deletePlanForWLM

授予工作负载管理-删除工作负载计划操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deletePlanStageForWLM

授予工作负载管理-删除工作负载计划阶段操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteQueueForWLM

授予工作负载管理-删除工作负载队列操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteQueueUserForWLM

授予工作负载管理-删除工作负载队列的绑定用户操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:exportPlanForWLM

授予工作负载管理-导出工作负载计划操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPlanDetailForWLM

授予工作负载管理-查询某个工作负载计划详细信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPlanLogForWLM

授予工作负载管理-查看计划执行日志操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPlanQueueForWLM

授予工作负载管理-查询某个队列是否在计划中操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPlanStageForWLM

授予工作负载管理-查询工作负载计划阶段操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listQueueForWLM

授予工作负载管理-获得当前集群的工作负载队列的名称列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getQueueDetailForWLM

授予工作负载管理-获得工作负载队列信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getQueueRuleForWLM

授予工作负载管理-获得工作负载队列异常规则信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:importPlanForWLM

授予工作负载管理-导入工作负载计划操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listPlanQueueForWLM

授予工作负载管理-查询所有工作负载计划可用的队列信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listPlanForWLM

授予工作负载管理-查询工作负载计划操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listQueueUserForWLM

授予工作负载管理-获得工作负载队列的绑定用户列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listUserForWLM

授予工作负载管理-获得集群中所有未绑定工作负载队列的用户列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterDBInfoForWLM

授予工作负载管理-查询集群数据库信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listClusterPlanForWLM

授予工作负载管理-查询集群中所有工作负载计划操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterSchemaInfoForWLM

授予工作负载管理-查询集群模式空间信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterVersionForWLM

授予工作负载管理-获得当前集群后台数据库的版本操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getFunctionStatusForWLM

授予工作负载管理-获得工作负载功能开关状态操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:setFunctionStatusForWLM

授予工作负载管理-设置工作负载功能开关状态操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:startPlanForWLM

授予工作负载管理-启动工作负载计划操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:stopPlanForWLM

授予工作负载管理-停止工作负载计划操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:switchPlanStageForWLM

授予工作负载管理-切换工作负载阶段操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updatePlanStageForWLM

授予工作负载管理-修改工作负载计划阶段操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateQueueBaseForWLM

授予工作负载管理-更新工作负载队列基础信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateQueueResourceForWLM

授予工作负载管理-更新工作负载队列资源配置信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateQueueRuleForWLM

授予工作负载管理-更新工作负载队列异常规则信息操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateSchemaLimitForWLM

授予工作负载管理-更新模式空间限额操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMonitorConfigForDMS

授予DMS-查询采集配置或存储配置额操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:listClusterOverview

授予DMS-获取集群概览操作权限。

list

-

-

dws:cluster:listClusterInstanceForDMS

授予DMS-获取集群实例列表操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDDLExamineDetailForDMS

授予DMS-查询审核结果详细信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterDnStreamForDMS

授予DMS-查询dn数据流监控信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listClusterAlarmRuleForDMS

授予DMS-查询租户侧告警规则列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterInstanceForDMS

授予DMS-查询实例信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getHostNetMetricsForDMS

授予DMS-查询网络状态操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:getHistoryMetrics

授予DMS-查询历史监控数据操作权限。

read

-

-

dws:cluster:getMonitoringInfoForDMS

授予DMS-查询监控数据操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listAlarmRuleForDMS

授予DMS-租户侧根据告警id查询告警规则操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateCollectionItemForDMS

授予DMS-更新采集配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:doDDLExamineActionForDMS

授予DMS-手动触发审核操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:downloadDDLExamineDetailForDMS

授予DMS-DDL审核详情下载操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listInstanceDiskIOForDMS

授予DMS-查询磁盘IO操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:resetCollectionItemForDMS

授予DMS-重置采集配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getQueryRangeForDMS

授予DMS-查询时间句柄操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:getAlarmConfig

授予DMS-租户侧查询所有集群和告警配置信息操作权限。

read

-

-

dws:cluster:switchoverCollectionItemForDMS

授予DMS-切换采集开关操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:getOSMetrics

授予DMS-查询DWS硬件资源使用情况操作权限。

read

-

-

dws:cluster:listPerfDashboardForDMS

授予DMS-查询当前用户所有性能监控面板操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:disableCollectionItemForDMS

授予DMS-关闭采集开关操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:getAggregationOSMetrics

授予DMS-查询DWS集群硬件资源使用情况操作权限。

read

-

-

dws:cluster:terminateSessionForDMS

授予DMS-终止会话操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPerfDashboardDetailForDMS

授予DMS-通过面板id获取面板信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:createAlarmRule

授予DMS-租户侧添加告警规则操作权限。

write

-

-

dws:cluster:enableCollectionItemForDMS

授予DMS-开启采集开关操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listInstanceNetworkMetricsForDMS

授予DMS-查询DWS集群节点各网卡流量操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createPerfDashboardForDMS

授予DMS-创建用户面板操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMonitorMetricsForDMS

授予DMS-获取首页监控项操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createSQLProbeForDMS

授予DMS-新增SQL探针操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listInstanceIOStatusForDMS

授予DMS-查询DWS集群各节点磁盘IO使用情况操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMonitorMetricsByDimensionForDMS

授予DMS-按维度获取指标操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateStorageConfigForDMS

授予DMS-更新存储配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:updateAlarmRule

授予DMS-租户侧修改告警规则操作权限。

write

-

-

dws:cluster:getInstanceIOAggResultForDMS

授予DMS-查询DWS集群各节点磁盘IO汇聚使用情况操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updatePerfDashboardForDMS

授予DMS-修改用户面板操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMonitorHistoryMetricsCost

授予DMS-查询队列历史消耗操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:deleteAlarmRule

授予DMS-租户侧删除规则操作权限。

write

-

-

dws:cluster:updateSQLProbeForDMS

授予DMS-修改SQL探针操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:startMonitorMetricsCollectionForDMS

授予DMS-开始采集操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listInstanceStorageForDMS

授予DMS-查询DWS集群各节点文件系统使用情况操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deletePerfDashboardForDMS

授予DMS-删除用户监控面板操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMonitorMetricsDetailForDMS

授予DMS-查询指标数据操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteSQLProbeForDMS

授予DMS-删除SQL探针操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:stopAlarmRule

授予DMS-租户侧停用规则操作权限。

write

-

-

dws:cluster:stopMonitorMetricsCollectionForDMS

授予DMS-停止采集操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listExceptionTableForDMS

授予DMS-查询表倾斜或脏页率信息操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getInstanceStorageAggForDMS

授予DMS-查询DWS集群各节点文件系统使用情况操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getWDRSnapShotForDMS

授予DMS-获取快照记录操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPerfMetricsDataForDMS

授予DMS-获取所有监控指标操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listQueryForDMS

授予DMS-获取当前所有的查询操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getInstanceIOMetricsForDMS

授予DMS-查询网卡IO数据操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getSQLProbeDetailForDMS

授予DMS-查询SQL探针详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:switchoverMonitorMetricStatusForDMS

授予DMS-切换采集开关操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:startAlarmRule

授予DMS-租户侧启用规则操作权限。

write

-

-

dws:monitor:getClusterStatus

授予DMS-查询DWS集群状态操作权限。

read

-

-

dws:cluster:getPerfMetricsDetailForDMS

授予DMS-通过pmid获取监控项操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSlowInstanceForDMS

授予DMS-查询慢节点操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDDLExamineConfigForDMS

授予DMS-查询采集配置操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMonitoringViewStatusForDMS

授予DMS-获取DMS视图状态操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:enableAlarm

授予DMS-租户侧集群启用告警功能操作权限。

write

-

-

dws:cluster:createWDRSnapShotForDMS

授予DMS-新增快照操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listExecuteStatusForDMS

授予DMS-查询DWS集群查询执行情况操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getSlowInstanceDetailForDMS

授予DMS-查询慢节点详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:enableSQLProbeForDMS

授予DMS-更新SQL探针启用状态操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getWDRConfigForDMS

授予DMS-查询集群WDR配置操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:disableAlarm

授予DMS-租户侧集群停用告警功能操作权限。

write

-

-

dws:cluster:getMonitoringViewForDMS

授予DMS-获取可用菜单操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDatabaseUsageForDMS

授予DMS-查询DWS集群中数据库使用情况操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listSQLProbeForDMS

授予DMS-分页查询SQL探针操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:getAlarmMetrics

授予DMS-租户侧查询告警指标操作权限。

read

-

-

dws:monitor:listMetricStatus

授予DMS-获取功能状态操作权限。

list

-

-

dws:cluster:listSessionStatusForDMS

授予DMS-查询DWS集群会话执行情况操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:downloadPerfHistoryForDMS

授予DMS-下载历史监控趋势操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:addPerfItemForDMS

授予DMS-添加监控项操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listClusterSessionForDMS

授予DMS-获取当前所有的会话操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getSQLDiagnosticsForDMS

授予DMS-查询SQL诊断详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateWDRSnapShotForDMS

授予DMS-更新集群WDR配置操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:clearAlarm

授予DMS-租户侧告警清除操作权限。

write

-

-

dws:cluster:executeSQLProbeForDMS

授予DMS-执行SQL探针操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listQueryStatusForDMS

授予DMS-获取查询的当前状态操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getWDRReportForDMS

授予DMS-获取报告记录操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listWLMQueueForDMS

授予DMS-查询当前的工作负载队列操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updatePerfItemForDMS

授予DMS-更新监控项操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getQueryCostForDMS

授予DMS-获取历史资源消耗操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createWDRReportForDMS

授予DMS-新增WDR报告操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:downloadWDRReportForDMS

授予DMS-WDR报告下载操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDatabaseForDMS

授予DMS-查询当前集群所有数据库操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listUserWLMQueueForDMS

授予DMS-查询用户工作负载队列操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deletePerfItemForDMS

授予DMS-删除监控项操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:monitor:getExceptionAlarmRule

授予DMS-查询异常告警规则操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getWDRHostForDMS

授予DMS-查询节点信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getHistoryPerfDataForDMS

授予DMS-查询历史监控数据操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteWDRReportForDMS

授予DMS-删除WDR报告操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getPerfDetailByDimensionForDMS

授予DMS-通过集群id,维度获取监控对象操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:downloadPerfHistoryByIdForDMS

授予DMS-下载历史监控趋势操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listWaitingWLMForDMS

授予DMS-获取当前等待的查询操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getQueryPropertyForDMS

授予DMS-获取查询属性操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listBucketForDMS

授予DMS-获取OBS桶列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getHistoryQueryPropertyForDMS

授予DMS-获取历史查询属性操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listExceptionWLMForDMS

授予DMS-查询当前异常任务操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:terminateQueryForDMS

授予DMS-终止查询操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateTaskForDMS

授予DMS-更新任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:retryTaskForDMS

授予DMS-重试任务操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listTaskForDMS

授予DMS-任务查询操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getDatabaseOmUserStatus

授予获取运维用户状态操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:executeDatabaseOmUserAction

授予执行运维用户操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getClusterInstancesInfo

授予查询集群实例逻辑集群详情操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getMetadataSyncStatus

授予dataArts元数据同步开启状态查询操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:startMetadataSync

授予开启dataArts元数据同步操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:stopMetadataSync

授予关闭dataArts元数据同步操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updatePeriodCluster

授予更新包周期集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createPeriodCluster

授予创建包周期集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteConfigTemplate

授予删除配置模板操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getCountDown

授予获取倒计时信息操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:getObsHotStorage

授予查询存算分离集群OBS数据使用情况操作权限。

read

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listConfigTemplate

授予查询配置参数模板操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDwsResource

授予获取集群实例资源列表操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDiscountNode

授予查询折扣套餐包节点操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:changeToPeriod

授予按需转包周期操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:rotateKey

授予密钥轮转操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:operateCluster

授予集群操作,修复集群、解除只读等操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:doUpgrade

授予升级集群操作权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listUpgradePath

授予获取集群升级路径操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listUpgradeRecord

授予获取集群升级记录操作权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listLogicalClusterPlans

授予查询定时增删计划权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:createLogicalClusterPlan

授予添加定时增删计划权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:deleteLogicalClusterPlan

授予删除定时增删计划权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:listDatabaseUsers

授予查询所有数据库用户权限。

list

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:switchLogicalClusterPlan

授予启停定时增删计划权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

dws:cluster:updateLogicalClusterPlan

授予编辑定时增删计划权限。

write

cluster *

  • g:ResourceTag/<tag-key>
  • g:EnterpriseProjectId

GaussDB(DWS)的API通常对应着一个或多个授权项。表2展示了API与授权项的关系,以及该API需要依赖的授权项。

表2 API与授权项的关系

API

对应的授权项

依赖的授权项

POST /v2/{project_id}/alarm-subs

dws:alarm:createSubscription

-

DELETE /v2/{project_id}/alarm-subs/{alarm_sub_id}

dws:alarm:deleteSubscription

-

POST /v1.0/{project_id}/clusters/{cluster_id}/cns/batch-create

dws:cluster:addCN

-

PUT /v2/{project_id}/clusters/{cluster_id}/workload/queues

dws:cluster:addQueueForWLM

-

dws:cluster:assessRisk

-

POST /v2/{project_id}/clusters/{cluster_id}/eips/{eip_id}

dws:cluster:bindEIP

-

dws:cluster:bindOrUnbindEIP

  

POST /v2/{project_id}/clusters/{cluster_id}/elbs/{elb_id}

dws:cluster:bindELB

-

dws:cluster:bindOrUnbindELB

-

POST /v1.0/{project_id}/clusters/{cluster_id}/cancel-readonly

dws:cluster:cancelReadonly

-

GET /v2/{project_id}/disaster-recovery/check-name

dws:cluster:checkConnection

-

dws:cluster:checkDisasterRecoveryName

-

POST /v1/{project_id}/clusters/{cluster_id}/check-instance-storage

dws:cluster:expandDisk

-

dws:cluster:resize

-

dws:cluster:checkRestoreTable

-

dws:cluster:scaleIn

-

dws:cluster:checkSupportFineGrainedBackup

-

dws:cluster:configureNetwork

-

POST /v1.0/{project_id}/snapshots/{snapshot_id}/linked-copy

dws:cluster:copySnapshot

-

POST /v1.0/{project_id}/clusters

dws:cluster:create

  • ecs:cloudServerQuotas:get
  • ecs:cloudServerFlavors:get
  • bms:serverQuotas:get
  • bms:serverFlavors:get
  • vpc:subnets:get
  • vpc:vpcs:list
  • vpc:ports:get
  • vpc:ports:create
  • vpc:ports:update
  • vpc:securityGroups:get
  • vpc:securityGroups:create
  • vpc:securityGroups:delete
  • vpc:securityGroupRules:create
  • vpc:securityGroupRules:delete
  • vpc:quotas:list
  • eip:publicIps:list
  • eip:publicIps:get
  • eip:publicIps:create
  • evs:quotas:get

POST /v2/{project_id}/clusters

dws:cluster:create

-

POST /v2/{project_id}/cluster-precheck

dws:cluster:create

-

POST /v1.0/{project_id}/clusters/{cluster_id}/dns

dws:cluster:createConnection

-

dws:cluster:createDataSource

-

POST /v2/{project_id}/clusters/{cluster_id}/workload

dws:cluster:setFunctionStatusForWLM

-

POST /v1.0/{project_id}/snapshots

dws:cluster:createSnapshot

-

PUT /v2/{project_id}/clusters/{cluster_id}/snapshot-policies

dws:cluster:createSnapshotPolicy

-

DELETE /v1.0/{project_id}/clusters/{cluster_id}

dws:cluster:delete

-

POST /v1.0/{project_id}/clusters/{cluster_id}/cns/batch-delete

dws:cluster:deleteCN

-

DELETE /v1.0/{project_id}/clusters/{cluster_id}/dns

dws:cluster:deleteConnection

-

DELETE /v1.0/{project_id}/clusters/{cluster_id}/ext-data-sources/{ext_data_source_id}

dws:cluster:deleteDataSource

-

POST /v2/{project_id}/clusters/{cluster_id}/nodes/delete

dws:cluster:deleteNode

-

DELETE /v1.0/{project_id}/snapshots/{snapshot_id}

dws:cluster:deleteSnapshot

-

DELETE /v1.0/{project_id}/clusters/{cluster_id}/snapshot-policies/{id}

dws:cluster:deleteSnapshotPolicy

-

DELETE /v2/{project_id}/clusters/{cluster_id}/workload/queues

dws:cluster:deleteQueueForWLM

-

POST /v1.0/{project_id}/clusters/{cluster_id}/expand-instance-storage

dws:cluster:expandDisk

-

dws:cluster:expandWithExistedNodes

-

dws:cluster:getAntiAffinity

-

dws:cluster:getCnCount

-

dws:cluster:listConfig

-

dws:cluster:getCredential

-

GET /v1.0/{project_id}/clusters/{cluster_id}

dws:cluster:getDetail

-

GET /v2/{project_id}/disaster-recoveries

dws:cluster:getDisasterRecovery

-

dws:cluster:getDiskExpandScope

-

dws:cluster:getEncryptInfo

-

dws:cluster:getHistoryConfigDetail

-

dws:cluster:getInstanceDetail

-

GET /v2/{project_id}/disaster-recovery/{disaster_recovery_id}

dws:cluster:getDisasterRecovery

-

dws:cluster:getInstanceDetail

-

dws:cluster:getProcessTopo

-

dws:cluster:getRedistribution

-

dws::listResourceByTag

-

dws::countResourceByTag

-

dws:cluster:getRestoreDatabase

-

dws:cluster:getRoachConfig

-

dws:cluster:getSnapshotEncryptInfo

-

dws:cluster:getSnapshotPolicy

-

dws:cluster:getSnapshotStorage

-

dws:cluster:getTaskDetail

-

dws:cluster:getVolumeInfo

-

GET /v1.0/{project_id}/clusters

dws:cluster:list

-

GET /v1.0/{project_id}/clusters/{cluster_id}/audit-log-records

dws:cluster:listAuditLog

-

dws:cluster:listBucket

-

GET /v1.0/{project_id}/clusters/{cluster_id}/cns

dws:cluster:listCN

-

GET /v1.0/{project_id}/clusters/{cluster_id}/configurations

dws:cluster:listConfig

-

GET /v1.0/{project_id}/clusters/{cluster_id}/configurations/{configuration_id}

dws:cluster:listConfig

-

dws:cluster:listConnection

-

dws:cluster:listDatabase

-

GET /v1.0/{project_id}/clusters/{cluster_id}/ext-data-sources

dws:cluster:listDataSource

-

GET /v2/{project_id}/clusters/{cluster_id}/elbs

dws:cluster:listDN

-

dws:cluster:listELB

-

dws:cluster:listFlavorForResize

-

dws:cluster:listFlavorForRestore

-

dws:cluster:listHistoryConfig

-

dws:cluster:listNode

-

dws::listResourceByTag

-

dws:cluster:listRing

-

GET /v1.0/{project_id}/clusters/{cluster_id}/shrink-numbers

dws:cluster:listRingForScaleIn

-

dws:cluster:listSchema

-

dws:cluster:listScaleInNode

-

GET /v1.0/{project_id}/clusters/{cluster_id}/snapshots

dws:cluster:listSnapshot

-

GET /v1.0/{project_id}/snapshots

dws:cluster:listSnapshot

-

GET /v1.0/{project_id}/snapshots/{snapshot_id}

dws:cluster:getSnapshotDetail

-

GET /v2/{project_id}/clusters/{cluster_id}/snapshot-policies

dws:cluster:listSnapshotPolicy

-

GET /v1.0/{project_id}/clusters/{cluster_id}/snapshots/statistics

dws:cluster:listSnapshotStatistics

-

dws:cluster:listTable

-

GET /v2/{project_id}/clusters/{cluster_id}/workload

dws:cluster:getFunctionStatusForWLM

-

GET /v2/{project_id}/clusters/{cluster_id}/workload/queues

dws:cluster:listQueueForWLM

-

POST /v2/{project_id}/disaster-recovery/{disaster_recovery_id}/pause

dws:cluster:pauseDisasterRecovery

-

dws:cluster:recoverRedistribution

-

POST /v2/{project_id}/clusters/{cluster_id}/redistribution

dws:cluster:redistribution

-

POST /v1.0/{project_id}/clusters/{cluster_id}/reset-password

dws:cluster:resetPassword

-

POST /v1.0/{project_id}/clusters/{cluster_id}/resize

dws:cluster:resize

-

dws:cluster:resizeFlavor

-

dws:cluster:resizeRetry

-

POST /v1.0/{project_id}/clusters/{cluster_id}/restart

dws:cluster:restart

-

POST /v2/{project_id}/disaster-recovery/{disaster_recovery_id}/recovery

dws:cluster:restore

-

dws:cluster:restoreDisaster

-

POST /v1.0/{project_id}/snapshots/{snapshot_id}/actions

dws:cluster:restoreSnapshot

-

dws:cluster:restoreTable

-

dws:cluster:retryELBSwitch

-

PUT /v1.0/{project_id}/clusters/{cluster_id}/maintenance-window

dws:cluster:scaleOut

-

dws:cluster:setMaintainceWindow

-

POST /v1.0/{project_id}/clusters/{cluster_id}/cluster-shrink

dws:cluster:scaleIn

-

POST /v1/{project_id}/snapshots/{snapshot_id}/stop

dws:cluster:stopSnapshot

-

dws:cluster:suspendRedistribution

-

POST /v1.0/{project_id}/clusters/{cluster_id}/switchover

dws:cluster:switchover

-

DELETE /v2/{project_id}/clusters/{cluster_id}/eips/{eip_id}

dws:cluster:unbindEIP

-

DELETE /v2/{project_id}/clusters/{cluster_id}/elbs/{elb_id}

dws:cluster:unbindELB

-

PUT /v2/{project_id}/clusters/{cluster_id}/configurations/{configuration_id}

dws:cluster:updateConfig

-

PUT /v1.0/{project_id}/clusters/{cluster_id}/dns

dws:cluster:updateConnection

-

PUT /v1.0/{project_id}/clusters/{cluster_id}/ext-data-sources/{ext_data_source_id}

dws:cluster:updateDataSource

-

dws:cluster:updateInstanceAliasName

-

dws:cluster:updateRoachConfig

-

dws:cluster:updateScheduleConfig

-

dws:cluster:updateSnapshotPolicy

-

dws::updateTag

-

POST /v2/{project_id}/event-subs

dws::updateTag

-

dws:event:createSpec

-

dws:event:createSubscription

-

DELETE /v2/{project_id}/event-subs/{event_sub_id}

dws:event:deleteSpec

-

dws:event:deleteSubscription

-

GET /v2/{project_id}/event-subs

dws:event:listSubscription

-

dws:event:report

-

PUT /v2/{project_id}/event-subs/{event_sub_id}

dws:event:updateSubscription

-

dws:service:authorize

-

dws:service:checkAuthorize

-

dws:service:getClusterSum

-

dws:service:getResourceStatistics

-

dws:service:getStorageStatistics

-

GET /v1.0/{project_id}/dss-pools

dws:service:listDssPools

-

dws:service:listEps

-

GET /v2/{project_id}/node-types

dws:service:listSpec

-

GET /v1.0/{project_id}/statistics

dws:service:listStatistics

-

GET /v1.0/{project_id}/tags

dws::listTagsForProject

-

dws:cluster:addOperationalTask

-

dws:cluster:bindManageIp

-

dws:cluster:checkAccessLts

-

dws:cluster:checkDisasterRecoveryName

-

dws:cluster:checkLogicalClusterData

-

dws:cluster:closeAccessLts

-

dws:cluster:createDisasterRecovery

-

POST /v2/{project_id}/clusters/{cluster_id}/logical-clusters

dws:cluster:createLogicalCluster

-

dws:cluster:createApplicationForDM

-

dws:cluster:createClusterForDM

-

dws:cluster:createConnectionForDM

-

dws:cluster:createMappingForDM

-

dws:cluster:deleteApplicationForDM

-

dws:cluster:deleteClusterForDM

-

dws:cluster:deleteConnectionForDM

-

dws:cluster:deleteMappingForDM

-

dws:cluster:dialsConnectionForDM

-

dws:cluster:getApplicationForDM

-

dws:cluster:listApplicationConfigForDM

-

dws:cluster:listApplicationForDM

-

dws:cluster:getClusterForDM

-

dws:cluster:listClusterForDM

-

dws:cluster:listConfigurationTemplateForDM

-

dws:cluster:getConnectionForDM

-

dws:cluster:listConnectionForDM

-

dws:cluster:listDependApplicationForDM

-

dws:cluster:getMappingForDM

-

dws:cluster:listMappingForDM

-

dws:cluster:listProductForDM

-

dws:cluster:updateConnectionForDM

-

dws:cluster:updateMappingForDM

-

dws:cluster:startApplicationForDM

-

dws:cluster:stopApplicationForDM

-

dws:cluster:deleteCrossRegionSnapshotPolicy

-

dws:cluster:deleteDisasterRecovery

-

DELETE /v2/{project_id}/clusters/{cluster_id}/logical-clusters/{logical_cluster_id}

dws:cluster:deleteLogicalCluster

-

dws:cluster:deleteOperationalTask

-

dws:cluster:operateDisasterRecovery

-

PUT /v2/{project_id}/clusters/{cluster_id}/logical-clusters/{logical_cluster_id}

dws:cluster:updateLogicalCluster

-

dws:cluster:listAllCrossRegionSnapshotConfig

-

dws:cluster:getDisasterRecoveryProject

-

dws:cluster:getDisasterRecoveryRegion

-

dws:cluster:getLastOperationalTask

-

dws:cluster:getLogicalClusterRings

-

dws:cluster:getLogicalClusterVolume

-

dws:cluster:getOperationalTaskConfig

-

dws:cluster:getOperationalTaskDetail

-

dws:cluster:getOperationalTaskStatus

-

dws:cluster:listSnapshotRegion

-

dws:cluster:getTargetAllCrossRegionSnapshotConfig

-

dws:cluster:initLogicalClusterSwitch

-

dws:cluster:listAccessLts

-

dws:cluster:listDisasterRecovery

-

dws:cluster:listLogicalCluster

-

dws:cluster:listLogicalClusterTask

-

dws:cluster:listOperationalTask

-

dws:cluster:openAccessLts

-

dws:cluster:pauseOperationalTask

-

dws:cluster:getDisasterRecoveryDetail

-

dws:cluster:refreshOperationalTask

-

POST /v2/{project_id}/clusters/{cluster_id}/logical-clusters/{logical_cluster_id}/restart

dws:cluster:restartLogicalCluster

-

dws:cluster:resumeOperationalTask

-

dws:cluster:setCrossRegionSnapshotPolicy

-

dws:cluster:startOperationalTask

-

dws:cluster:stopOperationalTask

-

dws:cluster:switchLogicalCluster

-

dws:cluster:syncCrossRegionBackupClusterInfo

-

dws:cluster:syncCrossRegionBackupConfig

-

dws:cluster:syncCrossRegionBackupInfo

-

dws:cluster:syncLogicalCluster

-

dws:cluster:updateDisasterRecoveryConfig

-

dws:cluster:updateOperationalTaskConfig

-

dws:cluster:updateOperationalTask

-

dws:cluster:addPlanForWLM

-

dws:cluster:addPlanStageForWLM

-

dws:cluster:addQueueForWLM

-

dws:cluster:addQueueUserForWLM

-

dws:cluster:deletePlanForWLM

-

dws:cluster:deletePlanStageForWLM

-

dws:cluster:deleteQueueForWLM

-

dws:cluster:deleteQueueUserForWLM

-

dws:cluster:exportPlanForWLM

-

dws:cluster:getPlanDetailForWLM

-

dws:cluster:getPlanDetailForWLM

-

dws:cluster:getPlanLogForWLM

-

dws:cluster:getPlanQueueForWLM

-

dws:cluster:getPlanStageForWLM

-

dws:cluster:listQueueForWLM

-

dws:cluster:getQueueDetailForWLM

-

dws:cluster:getQueueRuleForWLM

-

dws:cluster:importPlanForWLM

-

dws:cluster:listPlanQueueForWLM

-

dws:cluster:listPlanForWLM

-

dws:cluster:listQueueUserForWLM

-

dws:cluster:listUserForWLM

-

dws:cluster:getClusterDBInfoForWLM

-

dws:cluster:listClusterPlanForWLM

-

dws:cluster:getClusterSchemaInfoForWLM

-

dws:cluster:getClusterVersionForWLM

-

dws:cluster:getFunctionStatusForWLM

-

dws:cluster:setFunctionStatusForWLM

-

dws:cluster:startPlanForWLM

-

dws:cluster:startPlanForWLM

-

dws:cluster:stopPlanForWLM

-

dws:cluster:stopPlanForWLM

-

dws:cluster:switchPlanStageForWLM

-

dws:cluster:switchPlanStageForWLM

-

dws:cluster:updatePlanStageForWLM

-

dws:cluster:updateQueueBaseForWLM

-

dws:cluster:updateQueueResourceForWLM

-

dws:cluster:updateQueueRuleForWLM

-

dws:cluster:updateSchemaLimitForWLM

-

dws:cluster:getMonitorConfigForDMS

-

dws:monitor:listClusterOverview

-

dws:cluster:listClusterInstanceForDMS

-

dws:cluster:getDDLExamineDetailForDMS

-

dws:cluster:getClusterDnStreamForDMS

-

dws:cluster:listClusterAlarmRuleForDMS

-

dws:cluster:getClusterInstanceForDMS

-

dws:cluster:getDDLExamineDetailForDMS

-

dws:cluster:getHostNetMetricsForDMS

-

dws:monitor:getHistoryMetrics

-

dws:cluster:getMonitoringInfoForDMS

-

dws:cluster:listAlarmRuleForDMS

-

dws:cluster:updateCollectionItemForDMS

-

dws:cluster:doDDLExamineActionForDMS

-

dws:cluster:downloadDDLExamineDetailForDMS

-

dws:cluster:listInstanceDiskIOForDMS

-

dws:cluster:resetCollectionItemForDMS

-

dws:monitor:listClusterOverview

-

dws:monitor:listClusterOverview

-

dws:cluster:getQueryRangeForDMS

-

dws:monitor:getAlarmConfig

-

dws:cluster:switchoverCollectionItemForDMS

-

dws:monitor:listClusterOverview

-

dws:monitor:listClusterOverview

-

dws:monitor:getOSMetrics

-

dws:cluster:listPerfDashboardForDMS

-

dws:cluster:disableCollectionItemForDMS

-

dws:monitor:listClusterOverview

-

dws:monitor:getAggregationOSMetrics

-

dws:cluster:terminateSessionForDMS

-

dws:cluster:getPerfDashboardDetailForDMS

-

dws:monitor:createAlarmRule

-

dws:cluster:enableCollectionItemForDMS

-

dws:monitor:listClusterOverview

-

dws:cluster:listInstanceNetworkMetricsForDMS

-

dws:cluster:createPerfDashboardForDMS

-

dws:cluster:getMonitorMetricsForDMS

-

dws:monitor:listClusterOverview

-

dws:cluster:createSQLProbeForDMS

-

dws:cluster:listInstanceIOStatusForDMS

-

dws:cluster:getMonitorMetricsByDimensionForDMS

-

dws:cluster:updateStorageConfigForDMS

-

dws:monitor:listClusterOverview

-

dws:monitor:updateAlarmRule

-

dws:cluster:getInstanceIOAggResultForDMS

-

dws:cluster:updatePerfDashboardForDMS

-

dws:cluster:getMonitorHistoryMetricsCost

-

dws:monitor:deleteAlarmRule

-

dws:cluster:updateSQLProbeForDMS

-

dws:cluster:startMonitorMetricsCollectionForDMS

-

dws:cluster:listInstanceStorageForDMS

-

dws:cluster:deletePerfDashboardForDMS

-

dws:cluster:getMonitorMetricsDetailForDMS

-

dws:cluster:deleteSQLProbeForDMS

-

dws:monitor:stopAlarmRule

-

dws:cluster:stopMonitorMetricsCollectionForDMS

-

dws:cluster:listExceptionTableForDMS

-

dws:cluster:getInstanceStorageAggForDMS

-

dws:cluster:getWDRSnapShotForDMS

-

dws:cluster:getPerfMetricsDataForDMS

-

dws:cluster:listQueryForDMS

-

dws:cluster:getInstanceIOMetricsForDMS

-

dws:cluster:getSQLProbeDetailForDMS

-

dws:cluster:switchoverMonitorMetricStatusForDMS

-

dws:monitor:startAlarmRule

-

dws:monitor:getClusterStatus

-

dws:cluster:getPerfMetricsDetailForDMS

-

dws:cluster:listSlowInstanceForDMS

-

dws:cluster:getDDLExamineConfigForDMS

-

dws:cluster:getMonitoringViewStatusForDMS

-

dws:monitor:enableAlarm

-

dws:cluster:createWDRSnapShotForDMS

-

dws:cluster:listExecuteStatusForDMS

-

dws:cluster:listQueryForDMS

-

dws:cluster:getSlowInstanceDetailForDMS

-

dws:cluster:enableSQLProbeForDMS

-

dws:cluster:getWDRConfigForDMS

-

dws:monitor:disableAlarm

-

dws:cluster:getMonitoringViewForDMS

-

dws:cluster:createWDRSnapShotForDMS

-

dws:cluster:getDatabaseUsageForDMS

-

dws:cluster:listSQLProbeForDMS

-

dws:monitor:getAlarmMetrics

-

dws:monitor:listMetricStatus

-

dws:cluster:listSessionStatusForDMS

-

dws:cluster:downloadPerfHistoryForDMS

-

dws:cluster:addPerfItemForDMS

-

dws:cluster:listClusterSessionForDMS

-

dws:cluster:getSQLDiagnosticsForDMS

-

dws:cluster:updateWDRSnapShotForDMS

-

dws:monitor:clearAlarm

-

dws:cluster:executeSQLProbeForDMS

-

dws:cluster:listQueryStatusForDMS

-

dws:cluster:getWDRReportForDMS

-

dws:cluster:listWLMQueueForDMS

-

dws:cluster:updatePerfItemForDMS

-

dws:cluster:executeSQLProbeForDMS

-

dws:cluster:getQueryCostForDMS

-

dws:cluster:createWDRReportForDMS

-

dws:cluster:downloadWDRReportForDMS

-

dws:cluster:listDatabaseForDMS

-

dws:cluster:listUserWLMQueueForDMS

-

dws:cluster:deletePerfItemForDMS

-

dws:cluster:createWDRReportForDMS

-

dws:cluster:getQueryCostForDMS

-

dws:monitor:getExceptionAlarmRule

-

dws:cluster:getWDRHostForDMS

-

dws:cluster:getHistoryPerfDataForDMS

-

dws:cluster:deleteWDRReportForDMS

-

dws:cluster:getQueryCostForDMS

-

dws:cluster:getPerfDetailByDimensionForDMS

-

dws:cluster:downloadPerfHistoryByIdForDMS

-

dws:cluster:listWaitingWLMForDMS

-

dws:cluster:downloadWDRReportForDMS

-

dws:cluster:getQueryPropertyForDMS

-

dws:cluster:listBucketForDMS

-

dws:cluster:getHistoryQueryPropertyForDMS

-

dws:cluster:listExceptionWLMForDMS

-

dws:cluster:addPerfItemForDMS

-

dws:cluster:terminateQueryForDMS

-

dws:cluster:updateTaskForDMS

-

dws:cluster:retryTaskForDMS

-

dws:cluster:listTaskForDMS

-

GET /v1/{project_id}/clusters/{cluster_id}/db-manager/om-user/status

dws:cluster:getDatabaseOmUserStatus

-

POST /v1/{project_id}/clusters/{cluster_id}/db-manager/om-user/action

dws:cluster:executeDatabaseOmUserAction

-

GET /v2/{project_id}/clusters/{cluster_id}/instances

dws:cluster:getClusterInstancesInfo

-

dws:cluster:getMetadataSyncStatus

-

dws:cluster:startMetadataSync

-

dws:cluster:stopMetadataSync

-

dws:cluster:updatePeriodCluster

-

dws:cluster:createPeriodCluster

-

dws:cluster:deleteConfigTemplate

-

dws:cluster:getCountDown

-

dws:cluster:getObsHotStorage

-

dws:cluster:listConfigTemplate

-

dws:cluster:listDwsResource

-

dws:cluster:listDiscountNode

-

dws:cluster:changeToPeriod

-

dws:cluster:rotateKey

-

dws:cluster:operateCluster

-

dws:cluster:setMaintainceWindow

-

dws:cluster:doUpgrade

-

dws:cluster:listUpgradePath

-

dws:cluster:listUpgradeRecord

-

dws:cluster:delete

-

GET /v1/{project_id}/clusters/{cluster_id}/db-manager/objects

dws:cluster:getDatabaseObjects

-

dws:cluster:listLogicalClusterPlans

-

dws:cluster:createLogicalClusterPlan

-

dws:cluster:deleteLogicalClusterPlan

-

dws:cluster:listDatabaseUsers

-

dws:cluster:switchLogicalClusterPlan

-

dws:cluster:updateLogicalClusterPlan

-

dws:cluster:getAccessWhitelistStatus

-

POST /v1/{project_id}/clusters/{cluster_id}/access-whitelist

dws:cluster:addAccessWhitelist

-

dws:cluster:getAccessWhitelist

-

PUT /v1/{project_id}/clusters/{cluster_id}/access-whitelist/{whitelist_id}

dws:cluster:getAccessWhitelistDetail

-

dws:cluster:setAccessWhitelistDetail

-

DELETE /v2/{project_id}/clusters/{cluster_id}

dws:cluster:delete

-

资源类型(Resource)

资源类型(Resource)表示SCP所作用的资源。如表3中的某些操作指定了可以在该操作指定的资源类型,则必须在具有该操作的SCP语句中指定该资源的URN,SCP仅作用于此资源;如未指定,Resource默认为“*”,则SCP将应用到所有资源。您也可以在SCP中设置条件,从而指定资源类型。

GaussDB(DWS)定义了以下可以在SCP的Resource元素中使用的资源类型。

表3 GaussDB(DWS)支持的资源类型

资源类型

URN

cluster

dws:<region>:<account-id>:cluster:<cluster-id>

条件(Condition)

GaussDB(DWS)服务不支持在SCP中的条件键中配置服务级的条件键。

GaussDB(DWS)可以使用适用于所有服务的全局条件键,请参考全局条件键