tencent cloud

Feedback

TencentDB for MongoDB

Last updated: 2024-05-26 09:25:56

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    Cloud MongoDB mongodb Supported Supported Resource level Partially supported

    Note:

    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    BackupDBInstance Backup DB Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    CreateAccountUser Create Account User Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    CreateBackupDBInstance CreateBackupDBInstance Operation level * Supported
    CreateBackupDownloadTask Create Backup Download Task Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    CreateDBInstance Create DB Instance Operation level * not supported
    CreateDBInstanceHour Create DB Instance Hour Operation level * Supported
    CreateLogDownloadTask CreateLogDownloadTask Resource level qcs::mongodb:${Region}:uin/${uin}:instance/$instance Supported
    DeleteAccountUser Delete Account User Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DeleteBackupDownloadTask DeleteBackupDownloadTask Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    ExchangeInstance Exchange Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    FlashBackDBInstance Execute flashback by key Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    FlushInstanceRouterConfig FlushInstanceRouterConfig Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    IsolateDBInstance IsolateDBInstance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    KillOps KillOps Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    MigrateInstanceAdjustReverseRunTime migrate instance to the cloudbase and adjust the reverse runtime Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} not supported
    MigrateInstanceSwitchSignal migrate instance to cloudbase and initiate switch Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} not supported
    MigrateInstanceToCloudBase migrate instance to cloudbase Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} not supported
    ModifyDBInstanceNodeProperty modify DB instance node property Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    ModifyDBInstanceSecurityGroup ModifyDBInstanceSecurityGroup Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    ModifyDBInstanceSpec Modify DB Instance Spec Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    ModifyDBInstancesChargeType ModifyDBInstancesChargeType Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    ModifyInstanceParams ModifyInstanceParams Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    OfflineIsolatedDBInstance Offline Isolated DB Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    OpenDBInstanceNodeIp open node Ip Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    ReleaseIsolatedDBInstances ReleaseIsolatedDBInstances Operation level * not supported
    RemoveCloneInstance Remove Clone Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    RenameCollection RenameCollection Operation level * not supported
    RenameInstance Rename Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    RenewDBInstances RenewDBInstances Operation level * Supported
    RenewInstance Renew Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    ResetDBInstancePassword ResetDBInstancePassword Operation level * Supported
    ResizeOplog Resize Oplog Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    RestartInstance Restart Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    RestartNodes restart nodes Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    RestoreDBInstance Restore DB Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    RestoreDatabases RestoreDatabases Operation level * not supported
    SetAccountUserPrivilege SetAccountUserPrivilege Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetAutoRenew Set Auto Renew Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetBackupRules SetBackupRules Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetInstanceFormal Set Instance Formal Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetInstanceMaintenance Set Instance Maintenance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetMultiRegionBackup SetMultiRegionBackup Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    SetPassword Set Password Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetReadOnlyToNormal Set ReadOnly to Normal Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SetUserDesc SetUserDesc Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    SwitchDBInstancePrimary Switch Primary Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    TerminateDBInstance Terminate DB Instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    TerminateDBInstanceHour Terminate DB Instance Hour Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    TerminateDBInstances TerminateDBInstances Operation level * not supported
    UpgradeDBInstance UpgradeDBInstance Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    UpgradeDBInstanceHour Upgrade DB Instance Hour Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    UpgradeDBInstanceKernelVersion This interface (UpgradeDBInstanceKernelVersion) is used to upgrade the database instance kernel version. Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    UpgradeDbInstanceVersion This interface upgrades the database version. Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    CheckMigrateInstanceToCloudBase check whether the migration instance can be migrated to the cloudbase Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} not supported
    CheckMongoDBLinkedKmsRole Determine whether the current user already has the cam role required by the cloud product mongo to call kms Operation level * not supported
    CheckWhiteListRecordExist CheckWhiteListRecordExist Operation level * not supported
    DeleteLogDownloadTask DeleteLogDownloadTask Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    DescribeAccountUsers Describe Account Users Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeAsyncRequestInfo DescribeAsyncRequestInfo Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeAuditInstanceList This API (DescribeAuditInstanceList) can query the list of audit instances that are activated and deactivated Operation level * not supported
    DescribeBackupAccess Describe Backup Access Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeBackupDownloadTask Describe Backup Download Task Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeBackupRules Describe Backup Rules Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeClientConnections Describe Client Connections Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeCurrentOp DescribeCurrentOp Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeDBInstanceDeal DescribeDBInstanceDeal Operation level * not supported
    DescribeDBInstanceNodeProperty describe DB instance node property Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    DescribeDBInstanceURL describe DB Instance URL Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    DescribeDBInstanceVersion This interface is used to obtain the kernel version information of the MongoDB instance Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    DescribeFlashbackFilters Obtain database table information that supports flashback by key Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} Supported
    DescribeInstanceDB Describe Instance DB Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeInstanceDatabases DescribeInstanceDatabases Operation level * not supported
    DescribeInstanceParamRecords DescribeInstanceParamRecords Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    DescribeInstanceParams DescribeInstanceParams Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    DescribeInstanceRestoreInfo DescribeInstanceRestoreInfo Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeLogDownloadTasks DescribeLogDownloadTasks Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    DescribeMigrateInstanceDetail migrate instance to the cloudbase, describe migration details Resource level qcs::mongodb:${region}:uin/${uin}:instance/${instance} not supported
    DescribeMongoDBLinkedClbRole Describe MongoDB Linked ClbRole Operation level * not supported
    DescribeMongodbLogs DescribeMongodbLogs Operation level * Supported
    DescribeSecurityGroup DescribeSecurityGroup Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    DescribeSlowLogPatterns DescribeSlowLogPatterns Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    DescribeSlowLogs DescribeSlowLogs Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    GetPublicKey GetPublicKey Operation level * not supported
    InquirePriceCreateDBInstances Inquire Price Create DBInstances Operation level * not supported
    InquirePriceModifyDBInstanceSpec InquirePriceModifyDBInstanceSpec Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported
    InquirePriceRenewDBInstances InquirePriceRenewDBInstances Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance Supported

    List Operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeDBBackups Describe DB Backups Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeDBInstances Describe DB Instances Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeInstanceTaskInfo Describe Instance Task Infomation Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeSlowLog Describe Slow Log Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeSlowLogPattern Describe SlowLog Parttern Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    DescribeSpecInfo Describe Spec Info Resource level qcs::mongodb:${region}:uin/${uin}:instance/$instance not supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support