tencent cloud

Feedback

Cloud Data Warehouse

Last updated: 2024-03-02 09:01:37

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    Cloud Data Warehouse ClickHouse cdwch Supported Supported Resource level Partially supported

    Note:

    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    ActionAlterCkUser add or modify user Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${isntsanceId} Supported
    CreateBackUpSchedule CreateBackUpSchedule Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    CreateEsLog CreateEsLog Resource level qcs::cdwch:${region}:uin/:cdwchInstance/${InstanceId} Supported
    DeleteBackUpData DeleteBackUpData Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    ModifyInstance Modify Information for Instance Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    ModifyInstanceConfigs Modify Instance Configs Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    ModifyInstanceKeyValConfigs ModifyInstanceKeyValConfigs Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    ModifyUserNewPrivilege add or modify user cluster Privilege Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/${InstanceId} Supported
    OpenBackUp OpenBackUp Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    RecoverBackUpJob RecoverBackUpJob Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    TerminateInstance Terminate Instance Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeBackUpJob DescribeBackUpJob Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeBackUpJobDetail DescribeBackUpJobDetail Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeBackUpSchedule DescribeBackUpSchedule Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeBackUpTables DescribeBackUpTables Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeCNGoodsDetail Generate the GoodsDetail structure of the accounting-related interface Operation level * Supported
    DescribeCNInstances Get Instances List Resource level qcs::cdwch:${region}:uin/${uin}:cdwchInstance/* not supported
    DescribeGoodsDetail Describe GoodsDetail Operation level * Supported
    DescribeInstance Get Instance Details Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeInstanceConfigs Describe Instance Configs Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    DescribeInstanceMonitorPort DescribeInstanceMonitorPort Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceId} Supported
    DescribeInstanceNodes Get Node Information for Instance Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchinstanceId Supported
    DescribeInstanceOperations Describe Instance Operations Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    DescribeInstanceState Describe Instance State Resource level qcs::cdwch:$region:$account:cdwchInstance/$InstanceId Supported
    DescribeInstances Get Instances List Resource level qcs::cdwch:$region:$account:cdwchInstance/* not supported
    DescribeInstancesNew DescribeInstancesNew Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/$InstanceId Supported
    DescribeMetricData Get Metric Data Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeMetricMeta Get MetaData about monitoring Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeOverviewData Get Metric Data for OverviewPage Resource level qcs::cdwch:$region:$account:cdwchInstance/$cdwchInstanceId Supported
    DescribeSlowQueryTrend slow query trend Resource level qcs::${ApiModule}:${Region}:uin/:cdwchInstance/${InstanceID} not supported
    DescribeSpec Describe Spec Operation level * Supported

    List Operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeCkSqlApis DescribeCkSqlApis Resource level qcs::cdwch::uin/${uin}:cdwchInstance/$InstanceId not supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support