tencent cloud

Feedback

Message Queue CKafka

Last updated: 2024-03-02 09:01:56

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    CKafka ckafka Supported Supported Resource level Partially supported

    Note:

    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    AddPartition AddPartition Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    AddRoute AddRoute Operation level * not supported
    AddTopicIpwhitelist AddTopicIpwhitelist Operation level * not supported
    BatchCreateAcl BatchCreateAcl Operation level * not supported
    BatchDeleteAcl BatchDeleteAcl Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    BatchModifyGroupOffsets BatchModifyGroupOffsets Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    BatchModifyTopicAttributes BatchModifyTopicAttributes Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    BurnCPU BurnCPU Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    BurnDiskIO BurnDiskIO Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    CreateAcl CreateAcl Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    CreateAclRule create Acl rule Resource level qcs::ckafka::uin/${uin}:ckafkaId/${instanceId} not supported
    CreateConnectResource create dip connect resource Operation level * not supported
    CreateDatahubGroup create dip consumer group Operation level * not supported
    CreateDatahubTask create dip task Operation level * not supported
    CreateDatahubTopic create dip topic Operation level * not supported
    CreateInstance CreateInstance Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    CreateInstancePost CreateInstancePost Operation level * Supported
    CreateInstancePre CreateInstancePre Operation level * Supported
    CreatePartition CreatePartition Operation level * not supported
    CreatePostPaidInstance CreatePostPaidInstance Operation level * Supported
    CreatePrometheus CreatePrometheus Resource level qcs::ckafka::uin/${uin}:ckafkaId/${instanceId} not supported
    CreateRoute CreateRoute Operation level * not supported
    CreateSystemMaintenanceTime CreateSystemMaintenanceTime Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    CreateTopic CreateTopic Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    CreateTopicIpWhiteList CreateTopicIpWhiteList Operation level * not supported
    CreateUser CreateUser Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DelayMessage DelayMessage Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DelayMessageRollback DelayMessageRollback Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DeleteAcl DeleteAcl Operation level * not supported
    DeleteConnectResource delete dip connect resource Resource level qcs::ckafka:${region}:uin/${uin}:dipConnectResource/${ResourceId} not supported
    DeleteDatahubGroup delete dip consumer group Resource level qcs::ckafka:${region}:uin/${uin}:dipGroup/${Group} not supported
    DeleteDatahubTask delete dip task Resource level qcs::ckafka:${region}:uin/${uin}:dipTask/${TaskId} not supported
    DeleteDatahubTopic delete dip Topic Resource level qcs::ckafka:${region}:uin/${uin}:dipTopic/${Name} not supported
    DeleteGroup Delete consumer group Operation level * not supported
    DeleteInstance DeleteInstance Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DeleteInstancePost DeleteInstancePost Operation level * Supported
    DeleteInstancePre DeleteInstancePre Operation level * not supported
    DeletePrometheus DeletePrometheus Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DeleteRoute DeleteRoute Operation level * not supported
    DeleteTopic DeleteTopic Operation level * not supported
    DeleteTopicIpwhitelist DeleteTopicIpwhitelist Operation level * not supported
    DeleteUser DeleteUser Operation level * not supported
    DownAttackRollback DownAttackRollback Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    InjectDownAttack shutdown Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    InstanceScalingDown InstanceScalingDown Operation level * Supported
    IsolateResource Isolate Resource Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ModifyConnectResource modify dip connect resource attributes Resource level qcs::ckafka:${region}:uin/${uin}:dipConnectResource/${ResourceId} not supported
    ModifyConsumerGroupConfig ModifyConsumerGroupConfig Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ModifyDatahubGroupOffsets modify dip group offset Resource level qcs::ckafka:${region}:uin/${uin}:dipGroup/${Group} not supported
    ModifyDatahubPartition add dip topic partition Resource level qcs::ckafka:${region}:uin/${uin}:dipTopic/${Name} not supported
    ModifyDatahubPassword modify dip topic password Resource level qcs::ckafka:${region}:uin/${uin}:dipTopic/${Name} not supported
    ModifyDatahubResource ModifyDatahubResource Resource level qcs::ckafka:${Region}:uin/:dipTask/${TaskId} not supported
    ModifyDatahubTopic modify dip topic attributes Resource level qcs::ckafka:${region}:uin/${uin}:dipTopic/${Name} not supported
    ModifyForward Set ckafka to forward messages to cos Operation level * not supported
    ModifyGroupOffsets ModifyGroupOffsets Operation level * not supported
    ModifyInstance ModifyInstance Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ModifyInstanceAttributes ModifyInstanceAttributes Operation level * not supported
    ModifyInstanceMultiZone ModifyInstanceMultiZone Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ModifyInstancePre ModifyInstancePre Operation level * not supported
    ModifyPassword ModifyPassword Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ModifyRoutineMaintenanceTask ModifyRoutineMaintenanceTask Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ModifyTopicAttributes ModifyTopicAttributes Operation level * not supported
    PauseDatahubTask pause dip task Resource level qcs::ckafka:${region}:uin/${uin}:dipTask/${TaskId} not supported
    RenewCkafkaInstance Renew Ckafka instance Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    ResumeDatahubTask resume dip task Resource level qcs::ckafka:${region}:uin/${uin}:dipTask/${TaskId} not supported
    SendMessage HTTP send message Resource level qcs::ckafka:${region}:uin/${uin}:DataHub/${DataHubId} not supported
    SetForward Set ckafka to forward messages to cos Operation level * not supported
    SetInstanceAttributes SetInstanceAttributes Operation level * not supported
    SetTopicAttributes SetTopicAttributes Operation level * not supported

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeACL DescribeACL Operation level * not supported
    DescribeAclRule DescribeAclRule Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeAppInfo DescribeAppInfo Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeAsyncResult DescribeAsyncResult Resource level qcs::ckafka::uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeAttackAsyncRequestResult DescribeAttackAsyncRequestResult Resource level qcs::ckafka::uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeBrokerIpInfo DescribeBrokerIpInfo Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} Supported
    DescribeCkafkaZone DescribeCkafkaZone Operation level * not supported
    DescribeConnectResource describe dip connect resource attributes Resource level qcs::ckafka:${region}:uin/${uin}:dipConnectResource/${ResourceId} not supported
    DescribeDatahubGroup describe dip group list Resource level qcs::ckafka:${region}:uin/${uin}:dipGroup/${Group} not supported
    DescribeDatahubGroupOffsets describe dip group offset Resource level qcs::ckafka:${region}:uin/${uin}:dipGroup/${Group} not supported
    DescribeDatahubTask describe dip task attributes Resource level qcs::ckafka:${region}:uin/${uin}:dipTask/${TaskId} not supported
    DescribeDatahubTopic describe dip topic attributes Resource level qcs::ckafka:${region}:uin/${uin}:dipTopic/${Name} not supported
    DescribeGroup DescribeGroup Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeGroupInfo DescribeGroupInfo Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeGroupOffsets DescribeGroupOffsets Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeInstanceAttributes DescribeInstanceAttributes Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeMigrationTask DescribeMigrationTask Operation level * Supported
    DescribeRollbackAsyncRequestResult DescribeRollbackAsyncRequestResult Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeRunningEventIds DescribeRunningEventIds Operation level * Supported
    DescribeTopicAttributes DescribeTopicAttributes Operation level * not supported
    DescribeTopicDetail DescribeTopicDetail Operation level * not supported
    DescribeTopicDistribute DescribeTopicDistribute Operation level * Supported
    DescribeTopicFlowRanking describe some topics in the cluster. and get flow metric about the nodes in the cluster, using the default options. Operation level * not supported
    DescribeUser DescribeUser Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    GetInstanceAttributes GetInstanceAttributes Operation level * not supported
    GetTopicAttributes GetTopicAttributes Operation level * not supported
    InquireCkafkaPrice Inquire ckafka instance price Operation level * not supported

    List Operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeConnectResources describe dip connect resource list Resource level qcs::ckafka:${region}:uin/${uin}:dipConnectResource/${ResourceId} not supported
    DescribeConsumerGroup DescribeConsumerGroup Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeDatahubTasks describe dip task list Resource level qcs::ckafka:${region}:uin/${uin}:dipTask/${TaskId} not supported
    DescribeDatahubTopics describe dip topic list Resource level qcs::ckafka:${region}:uin/${uin}:dipTopic/${Name} not supported
    DescribeInstances DescribeInstances Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeInstancesDetail DescribeInstancesDetail Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeRoute DescribeRoute Resource level qcs::ckafka:${region}:uin/${uin}:ckafkaId/${instanceId} not supported
    DescribeTopic DescribeTopic Operation level * not supported
    ListConsumerGroup ListConsumerGroup Operation level * not supported
    ListInstance ListInstance Operation level * not supported
    ListRoute ListRoute Operation level * not supported
    ListTopic ListTopic Operation level * not supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support