Overview
When creating shipping to COS/CKafka tasks, you need to grant the CLS service role the permissions to access COS/CKafka/DLC. perform operations in the console, the system will guide you through the authorization process.
Directions
If this is the first time you create a task to ship logs to COS/CKafka/DLC in the CLS console, follow the instructions in the console to create the required role and policies:
1. In the pop-up window that reads This feature requires creating a service role, click Go to Cloud Access Management.
2. On the Role Management page, click Grant.
At this point, you have authorized the CLS service role to access COS/CKafka/DLC. If you are using a root account, you can directly ship logs. If you are using a sub-account or collaborator account, you need to be authorized by the root account. For more information on granting permissions, see CAM Access Management. For more information on copying authorization policies, see Examples of Custom Access Policies.