CAM Overview
Features
Scenarios
Basic Concepts
Use Limits
User Types
cvmtest01 only to manage the resource-level APIs of ins-duglsqg0.
For more information, see overview >>{"version": "2.0","statement": [{"effect": "allow","action": ["cvm:*"],"resource": ["qcs::cvm::uin/12345678:instance/ins-duglsqg0",// `12345678` is `UIN` of the root account"qcs::cvm::uin/12345678:image/img-eb30mz89"]},{"effect": "allow","action": ["vpc:DescribeVpcEx","vpc:DescribeNetworkInterfaces","cvm:DescribeCbsStorages"],"resource": ["*"]}]}

instance and image and resource IDs ins-duglsqg0 and img-eb30mz89 respectively.cvm-test01, and grant it to the sub-account cvmtest01.
DescribeVpcEx and relevant resource permissions of VPC are missing.DescribeVpcEx API in the list of CAM APIs supported by VPC and verify that the API is at the operation level.cvm-test01 policy and click its name to enter the policy details page.


cvmtest01 to verify permissions again, and you can see that DescribeNetworkInterfaces and relevant resource access permissions of VPC are still missing. View the list of CAM APIs supported by VPC and verify that the DescribeNetworkInterfaces API is at the operation level. 
cvmtest01 to verify the policy again, and the expected effect is achieved.
At this point, the sub-user cvmtest01 can start, shut down, restart, rename, and reset the password of the CVM instance.

Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback