tencent cloud

Feedback

Tencent Cloud Mesh

Last updated: 2024-04-22 09:21:14

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    Tencent Cloud Mesh tcm Supported Supported Resource level Partially supported

    Note:

    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    CheckClusterList CheckClusterList Resource level qcs::tcm::uin/${uin}:- not supported
    DescribeAutoInjectionNamespaceList DescribeAutoInjectionNamespaceList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeConfig DescribeConfig Operation level * not supported
    DescribeEgressGateway get egressgateway workload Resource level qcs::${ApiModule}:${Region}:uin/:mesh/${MeshId} Supported
    DescribeGatewayWorkloadList get gateway workload list Resource level qcs::${ApiModule}:${Region}:uin/:mesh/${MeshId} Supported
    DescribeIngressGateway get ingressgateway workload Resource level qcs::${ApiModule}:${Region}:uin/:mesh/${MeshId} Supported
    DescribeIngressGatewayList DescribeIngressGatewayList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    DescribeIstioResourceList DescribeIstioResourceList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeMesh Describe Mesh Resource level qcs:tcm:gz:uin/12345678:* Supported
    DescribeMeshList DescribeMeshList Resource level qcs::tcm:${region}:uin/${uin}:- not supported
    DescribeMeshOperation DescribeMeshOperation Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeMeshStatistics DescribeMeshStatistics Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeMetaClusterID DescribeMetaClusterID Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeNamespaceList DescribeNamespaceList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeNodeRegionList DescribeNodeRegionList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeServiceDashboard DescribeServiceDashboard Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeServiceList DescribeServiceList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeServiceListDashboard DescribeServiceListDashboard Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DescribeTopology DescribeTopology Resource level qcs::tcm:${region}:uin/${uin}:DescribeTopology not supported
    DescribeWorkloadDashboard DescribeWorkloadDashboard Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    ForwardRequestRead ForwardRequestRead Operation level * Supported
    ListIstioIngresses ListIstioIngresses Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    ListMeshes ListMeshes Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    ConvertIstioIngress ConvertIstioIngress Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    CreateEgressGateway CreateEgressGateway Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    CreateIngressGateway CreateIngressGateway Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    CreateIstioResource CreateIstioResource Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    CreateMesh CreateMesh Resource level qcs:tcm:gz:uin/12345678:* Supported
    CreateTrial Create TCM sample deployment Operation level * Supported
    DeleteEgressGateway DeleteEgressGateway Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DeleteIngressGateway DeleteIngressGateway Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    DeleteIstioResource DeleteIstioResource Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    DeleteMesh DeleteMesh Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    DeleteTrial Delete TCM sample deployment Operation level * Supported
    EnableAccessLogConfig EnableAccessLogConfig Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    ForwardRequestWrite ForwardRequestWrite Operation level * Supported
    LinkClusterList link clusters Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    LinkNamespaceList LinkNamespaceList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    LinkPrometheus LinkPrometheus Resource level qcs::${ApiModule}:${Region}:uin/:mesh/${MeshId} Supported
    ModifyAccessLogConfig ModifyAccessLogConfig Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    ModifyIngressGateway ModifyIngressGateway Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    ModifyIstioResource ModifyIstioResource Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    ModifyMesh Modify mesh Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    ModifyMeshCanaryUpgradingPhase ModifyMeshCanaryUpgradingPhase Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    ModifyTracingConfig ModifyTracingConfig Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    RelinkCluster RelinkCluster Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    RetryTrialTask Retry TCM sample deployment creation Operation level * Supported
    UnlinkCluster unlink cluster Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    UnlinkNamespaceList UnlinkNamespaceList Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} not supported
    UnlinkPrometheus UnlinkPrometheus Resource level qcs::${ApiModule}:${Region}:uin/:mesh/${MeshId} Supported
    UpgradeGateway UpgradeGateway Resource level qcs::${ApiModule}:${Region}:uin/:mesh/${MeshId} Supported
    UpgradeMesh UpgradeMesh Resource level qcs::tcm:${region}:uin/${uin}:mesh/${MeshId} Supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support