tencent cloud

TencentDB for PostgreSQL

Release Notes and Announcements
Release Notes
Product Announcements
Product Introduction
Overview
Features
Strengths
Scenarios
Information Security
Regions and AZs
Product Feature List
Large version lifecycle description
MSSQL Compatible Version
Billing
Billing Overview
Instance Type and Specification
Purchase Methods
Refund
Overdue Payments
Backup Space Billing
Database Audit Billing Overview
Getting Started
Creating TencentDB for PostgreSQL Instance
Connecting to TencentDB for PostgreSQL Instance
Managing TencentDB for PostgreSQL Instance
Importing Data
Migrating Data with DTS
Kernel Version Introduction
Kernel Version Overview
Kernel Version Release Notes
Viewing Kernel Version
Proprietary Kernel Features
Database Audit
Audit Service Description
Activating Audit Service
View Audit Logs
Modify audit services
Audit Performance Description
User Guide
Instance Management
Upgrading Instance
CPU Elastic Scaling
Read-Only Instance
Account Management
Database Management
Parameter Management
Log Management and Analysis
Backup and Restoration
Data Migration
Extension Management
Network Management
Access Management
Data Security
Tenant and Resource Isolation
Security Groups
Monitoring and Alarms
Tag
AI Practice
Using the Tencentdb_ai Plug-In to Call Large Models
Building Ai Applications with the Tencentdb Ai Plug-In
Combining Supabase to Quickly Build Backend Service Based on TencentDB for PostgreSQL
Use Cases
postgres_fdw Extension for Cross-database Access
Automatically Creating Partition in PostgreSQL
Searching in High Numbers of Tags Based on pg_roaringbitmap
Querying People Nearby with One SQL Statement
Configuring TencentDB for PostgreSQL as GitLab's External Data Source
Supporting Tiered Storage Based on cos_fdw Extension
Implement Read/Write Separation via pgpool
Implementing Slow SQL Analysis Using the Auto_explain Plugin
Using pglogical for Logical Replication
Using Debezium to Collect PostgreSQL Data
Set Up a Remote Disaster Recovery Environment for PostgreSQL Locally on CVM
Read-Only Instance and Read-Only Group Practical Tutorial
How to Use SCF for Scheduled Database Operations
Fix Table Bloat
Performance White Paper
Test Methods
Test Results
API Documentation
History
Introduction
API Category
Making API Requests
Instance APIs
Read-only Replica APIs
Backup and Recovery APIs
Parameter Management APIs
Security Group APIs
Performance Optimization APIs
Account APIs
Specification APIs
Network APIs
Data Types
Error Codes
FAQs
Service Agreement
Service Level Agreement
Terms of Service
Glossary
Contact Us

Authorizable Resource Types

PDF
Mode fokus
Ukuran font
Terakhir diperbarui: 2024-01-24 11:16:51

Resource-Level Permission Overview

Resource-level permissions specify resources a user can operate. TencentDB for PostgreSQL supports specific resource-level permissions, i.e., allowing the user to perform operations or use specific resources. In Cloud Access Management (CAM), the types of PostgreSQL resources that can be authorized are as follows:
Resource Type
Resource Description Method in Access Policies
qcs::postgres:$region:$account:DBInstanceId/$DBInstanceId
qcs::postgres:$region:$account:DBInstanceId/*
The PostgreSQL instance APIs section in this document describes PostgreSQL API operations that currently support resource-level permissions as well as resources and condition keys supported by each operation. When configuring the resource path, you need to replace values of the parameters such as $region and $account with your actual values. You can also use the wildcard (*) in the path. For more information, please see Console Examples.
Note:
For a PostgreSQL API operation that does not support authorization at the resource level, you can still authorize a user to perform the operation. In this case, you must specify * as the resource element in the policy statement.

List of APIs Not Supporting Resource-Level Permissions

API Operation
API Description
CreateDBInstances
Creates an instance
CreateServerlessDBInstance
Creates a PostgreSQL for Serverless instance
DescribeOrders
Obtains order information
DescribeRegions
Queries available regions
DescribeZones
Queries available availability zones
DescribeProductConfig
Queries product specifications
InquiryPriceCreateDBInstances
Queries prices
DescribeServerlessDBInstances
Queries the list of PostgreSQL for Serverless instances

List of APIs Supporting Resource-Level Permissions

[PostgreSQL instance APIs]

PostgreSQL for Serverless instance APIs
API Name
API Description
CloseServerlessDBExtranetAccess
Disables the public network access for a PostgreSQL for Serverless instance
DeleteServerlessDBInstance
Deletes a PostgreSQL for Serverless instance
OpenServerlessDBExtranetAccess
Enables the public network access for a PostgreSQL for Serverless instance
Backup and restoration APIs
API Name
API Description
DescribeDBBackups
Queries the list of instance backups
DescribeDBErrlogs
Obtains error logs
DescribeDBSlowlogs
Obtains slow query logs
DescribeDBXlogs
Obtains the Xlog list
Instance APIs
API Name
API Description
CloseDBExtranetAccess
Disables the public network address for an instance
DescribeDBInstanceAttribute
Queries instance details
DescribeDatabases
Pulls the instance list
DestroyDBInstance
Terminates an instance
InitDBInstances
Initializes an instance
InquiryPriceRenewDBInstance
Queries the instance renewal price
InquiryPriceUpgradeDBInstance
Queries the instance upgrade price
ModifyDBInstanceName
Modifies the instance name
ModifyDBInstancesProject
Transfers an instance to another project
OpenDBExtranetAccess
Enables public network access
RenewInstance
Renews an instance
RestartDBInstance
Restarts an instance
SetAutoRenewFlag
Sets auto-renewal
UpgradeDBInstance
Upgrades an instance
DescribeDBInstances
Queries the instance list
Account APIs
API Name
API Description
DescribeAccounts
Obtains the list of instance users
ModifyAccountRemark
Modifies the account password
ResetAccountPassword
Resets the account password


Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan