| CAM中产品名 | 角色名称 | 角色类型 | 角色载体 |
|---|---|---|---|
| 对象存储 | COS_QCSLinkedRoleInCOSAcc | 服务相关角色 | COSAcc.COS.cloud.tencent.com |
| 对象存储 | COS_QCSLinkedRoleInCLSAccess | 服务相关角色 | cosoclsr.cos.cloud.tencent.com |
| 对象存储 | COS_QCSLinkedRoleVectorBucket | 服务相关角色 | vector.cos.cloud.tencent.com |
| 对象存储 | COS_QCSLinkedRoleInLighthouseMounting | 服务相关角色 | lhmounting.cos.cloud.tencent.com |
使用场景: 当前角色为对象存储(COS)服务相关角色,该角色将在已关联策略的权限范围内访问您的其他云服务资源。
权限策略
{
"statement": [
{
"action": [
"cos:*"
],
"effect": "allow",
"resource": "*"
}
],
"version": "2.0"
}
使用场景: 对象存储服务(COS)操作权限包括但不限于以下权限:增删查改日志服务(CLS)日志集、日志主题、日志,增删查改机器组,增删查改索引以及投递日志等
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"cls:CreateIndex",
"cls:ModifyIndex",
"cls:DescribeIndex",
"cls:CreateTopic",
"cls:ModifyTopic",
"cls:DeleteTopic",
"cls:DescribeTopics",
"cls:ModifyLogset",
"cls:DeleteLogset",
"cls:CreateLogset",
"cls:DescribeLogsets",
"tag:DescribeResourceTagsByResourceIds",
"tag:DescribeTagKeys",
"tag:DescribeTagValues",
"tag:DescribeResourceTags",
"tag:TagResources",
"tag:DescribeTags"
],
"resource": "*"
}
]
}
使用场景: 当前角色为COS的向量存储桶服务角色,该角色将在已关联策略的权限范围内访问您的其他云服务资源。
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"cos:PutBucketEncryption",
"cos:GetBucketEncryption",
"cos:DeleteBucketEncryption",
"cos:PutObject",
"cos:PutObjectCopy",
"cos:PostObject",
"cos:GetObject",
"cos:HeadObject",
"cos:DeleteObject",
"cos:DeleteMultipleObjects",
"cos:PutObjectTagging",
"cos:GetObjectTagging",
"cos:DeleteObjectTagging",
"cos:InitiateMultipartUpload",
"cos:UploadPart",
"cos:UploadPartCopy",
"cos:CompleteMultipartUpload",
"cos:AbortMultipartUpload",
"cos:ListMultipartUploads",
"cos:ListParts",
"cos:PutBucket",
"cos:GetBucket",
"cos:HeadBucket",
"cos:DeleteBucket"
],
"resource": "*"
}
]
}
使用场景: 当前角色为对象存储 (COS)服务相关角色,该角色将在已关联策略的权限范围内访问您的其他云服务资源。
权限策略
{
"statement": [
{
"action": [
"tat:DescribeCommands",
"tat:RunCommand",
"tat:InvokeCommand",
"tat:DescribeInvocations",
"tat:DescribeInvocationTasks",
"tat:DescribeAutomationAgentStatus",
"tat:CancelInvocation",
"tat:DescribeInstancesFeatureStatus"
],
"effect": "allow",
"resource": "*"
}
],
"version": "2.0"
}
文档反馈