Issues
If you have multiple users managing different Tencent Cloud services such as CVM, VPC, and TencentDB, and they all share your Tencent Cloud account access key, you may face the following problems:
Your key will be easily compromised because it is shared by several users.
Your users might introduce security risks from misoperations due to the lack of user access control.
Solution
You can avoid the above problems by using sub-accounts to allow different individuals to manage different services. By default, sub-accounts have no access to cloud services or related resources. You need to create policies to grant sub-accounts the required resources or permissions. CAM (Cloud Access Management) supports creating sub-users, user groups, and roles, and allows controlling their access scope through policies. You can configure customized access to Tencent Cloud services for enterprise users based on specific management scenarios. Note:
The Tencent Cloud root account you initially created has full access to all services and resources under the account. It is recommended to protect the credentials of the root account, use sub-users or roles for daily access, enable multi-factor authentication, and periodically rotate keys.
Getting started
CAM policies must grant permissions for one or more Distributed Cache operations or deny permissions for one or more Distributed Cache operations. They must also specify the resources (which may include all resources or partial resources for certain operations) that can be used for the operations, and may include conditions set for the operations on these resources.
Note:
It is recommended that users use CAM policies to manage Distributed Cache resources and authorize Distributed Cache operations. For existing users with project-based permissions, the experience remains consistent; however, it is not recommended to continue using project-based permissions for resource management and operation authorization.
Distributed Cache currently does not support the configuration of effective conditions.
|
Operation definition in a policy | |
Resource definition in a policy | |
Resource-level permissions | |