tencent cloud

Tencent Cloud Smart Advisor

Release Notes
Product Introduction
Overview
Features
Product Strengths
Scenarios
Customer Cases
Purchase Guide
Getting Started
Using TSA to Perform a Cloud Risk Assessment
Using TSA to Execute a Chaos Experiment on CFG
Operation Guide
Operation Guide to TSA-Cloud Architecture
Operation Guide to TSA-Cloud Risk Assessment
Operation Guide to TSA-Chaotic Fault Generator
Operation Guide to TSA-Digital Assets
Permission Management
API Documentation
History
Introduction
API Category
Making API Requests
Other APIs
Task APIs
Cloud Architecture Console APIs
Data Types
Error Codes
FAQs
FAQs: TSA
FAQs: TSA-Cloud Risk Assessment
FAQs: TSA-Cloud Architecture
FAQs: TSA-Chaotic Fault Generator
Related Protocol
Tencent Cloud Smart Advisor Service Level Agreement
PRIVACY POLICY MODULE CHAOTIC FAULT GENERATOR
DATA PRIVACY AND SECURITY AGREEMENT MODULE CHAOTIC FAULT GENERATOR
Contact Us

Service Authorization and Role Permissions

PDF
포커스 모드
폰트 크기
마지막 업데이트 시간: 2026-03-31 22:07:27
When using TSA-Chaotic Fault Generator (TSA-CFG), you may encounter various scenarios that require service authorization to access relevant cloud resources. Each scenario usually corresponds to the preset policies for different roles, mainly involving the CFG_QCSLinkedRoleInChaos role. This document presents the details of the authorization policy, authorization scenarios, and authorization steps.

Role Permissions (CFG_QCSLinkedRoleInChaos)

After you activate the TSA-CFG service, Tencent Cloud will grant your account the permissions of a CFG_QCSLinkedRoleInChaos role. This service role is associated with multiple preset policies by default. To obtain relevant permissions, you must perform authorization operations on the corresponding preset policies in specific authorization scenarios. Upon completion, these preset policies are included in the authorized policy list of this role. The preset policies associated with the CFG_QCSLinkedRoleInChaos role include permissions for the TSA-CFG service to access cloud resources.

Preset Policy (QcloudAccessForCFGLinkedRoleInChaos)

Authorization Scenario

When you log in to the Tencent Cloud Smart Advisor (TSA) console and select Chaotic Fault Generator for the first time after registering and logging in with a Tencent Cloud account, you need to go to the Cloud Access Management page to authorize CFG to access cloud resources such as Cloud Virtual Machine (CVM), Cloud Load Balancer (CLB), Tencent Cloud Automation Tools (TAT), CloudDB for Redis® (Redis®), TencentDB for MySQL, Tencent Cloud Observability Platform (TCOP), and Virtual Private Cloud (VPC) under the account.

Authorization Steps

1. Log in to the TSA console and choose Chaotic Fault Generator > Experiment Management in the left sidebar. The Service Authorization window is displayed.
2. Click Go to Authorize to go to the Role Management page.
3. Click Agree to Authorize. The authorization is successful upon authentication completion.

Permissions

CLB

Permission
Description
clb:DescribeTargets
Queries a list of application CLB-related CVM instances
clb:BatchModifyTargetWeight
Modifies the forwarding weights of backend servers associated with listeners in batches
clb:DescribeLoadBalancers
Queries a list of CLB instances
clb:SetLoadBalancerSecurityGroups
Associates security groups with the load balancer

TAT

Permission
Description
tat:DescribeAutomationAgentStatus
Checks the client status
tat:DescribeCommands
Queries commands
tat:InvokeCommand
Triggers a command
tat:DescribeInvocations
Queries the execution results
tat:RunCommand
Runs a temporary command
tat:DescribeInvocationTasks
Queries the execution tasks

Redis®

Permission
Description
redis:DescribeInstances
Displays the instance details
redis:KillMasterGroup
Simulates failures

TencentDB for MySQL

Permission
Description
cdb:DescribeDBInstances
Queries the instance list
cdb:SwitchDBInstanceMasterSlave
Allows users to actively switch between primary and secondary roles of TencentDB for MySQL instances
cdb:DescribeTasks
Queries a task list of TencentDB for MySQL instances
cdb:ModifyInstanceParam
Modifies the instance parameters
cdb:DescribeInstanceParams
Queries a list of configurable parameters for a TencentDB for MySQL instance
cdb:DescribeInstanceParamRecords
Queries the parameter modification history of a TencentDB for MySQL instance

CVM

Permission
Description
cvm:DescribeInstances
Queries CVM instances (V3)
cvm:RebootInstances
Restarts CVM instances (V3)
cvm:StopInstances
Stops CVM instances (V3)
cvm:StartInstances
Starts CVM instances (V3)
cvm:CreateSecurityGroup
Creates a security group
cvm:DeleteSecurityGroup
Deletes a security group

TCOP

Permission
Description
monitor:CreateAlarmNotice
Creates an alarm notification
monitor:DescribeAlarmHistories
Queries the alarm records (V2.0)
monitor:DescribeAlarmPolicies
Queries a list of alarm policies (V2.0)
monitor:DescribeBaseMetrics
Pulls a list of monitoring metrics
monitor:GetMonitorData
Pulls the monitoring data

VPC

Permission
Description
vpc:ResetNatGatewayConnection
Adjusts the maximum concurrent connections to an NAT gateway (V3)
vpc:DescribeNatGateways
Queries NAT gateways (V3)
vpc:ModifyNatGatewayAttribute
Modifies the attribute of an NAT gateway (V3)


도움말 및 지원

문제 해결에 도움이 되었나요?

피드백