检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
IAM This section describes the IAM permission configurations for all ModelArts functions.
Viewing the Notebook Instances of All IAM Users Under One Tenant Account Any IAM user granted with the listAllNotebooks and listUsers permissions can click View all on the notebook page to view the instances of all IAM users in the current IAM project.
How Do I View an Account ID and IAM User ID? Use your IAM account to log in to Huawei Cloud. In the upper right corner of the page, click Console. The HUAWEI CLOUD management console is displayed.
Figure 1 Modifying permissions in IAM On the IAM console, choose Agencies from the navigation pane on the left, and choose Permissions > Authorize. Search for IAM ReadOnlyAccess, enable it, and click Next and OK. Figure 2 IAM ReadOnlyAccess Verify that the permission is granted.
The IAM permissions of an IAM user are configured by their tenants. If a tenant does not grant the OBS putObjectAcl permission to their IAM users, this issue occurs.
Viewing the Notebook Instances of All IAM Users Under One Tenant Account Any IAM user granted with the listAllNotebooks and listUsers permissions can click View all on the notebook page to view the instances of all users in the current IAM project.
After creating a user group on the IAM console, grant the custom policy created in 1 to the user group. Create a user on the IAM console and add the user to the group created in 3.
What Do I Do If Error ModelArts.0010 Occurred When I Use ExeML to Start Training as an IAM User? Use the ACL permission assigned by the tenant account for the OBS bucket used by ModelArts. Parent topic: Training Models
Creating a User and Granting Permissions This section describes how to use IAM to implement fine-grained permissions control for your ModelArts resources. With IAM, you can: Create IAM users for employees based on the organizational structure of your enterprise.
Step 1 Create a User Group and Add Users to the User Group Multiple IAM users can be created under a tenant user, and the permissions of the IAM users are managed by group. This section describes how to create a user group and IAM users and add the IAM users to the user group.
In agent-based ModelArts access authorization, only tenant users are allowed to configure for their IAM users. Therefore, in this example, the administrator needs to configure access authorization for all the IAM users.
IAM ModelArts uses Identity and Access Management (IAM) for authentication and authorization. For more information about IAM, see Identity and Access Management User Guide.
Related Services IAM ModelArts uses Identity and Access Management (IAM) for authentication and authorization. For more information about IAM, see Identity and Access Management User Guide.
IAM user: Select an IAM user and configure an agency for the IAM user. Figure 1 Selecting an IAM user Federated user: Enter the username or user ID of the target federated user. Figure 2 Selecting a federated user Agency: Select an agency name.
Assigning the Required Permissions Any IAM user granted with the listAllNotebooks and listUsers permissions can click View all on the notebook page to view the instances of all IAM users in the current IAM project.
Table 1 Service authorization Target Service Description IAM Permission Mandatory ModelArts Assign permissions to IAM users for using ModelArts.
This section describes how to assign the permissions to use cloud services to all IAM users in a user group. On the user group list page of IAM, click Authorize of the target user group. The Authorize User Group page is displayed.
IAM or enterprise projects: Type of projects for which an action will take effect. Policies that contain actions for both IAM and enterprise projects can be used and take effect for both IAM and Enterprise Management.
For example, the endpoint of IAM in the CN-Hong Kong region is iam.ap-southeast-1.myhuaweicloud.com. resource-path Access path of an API for performing a specified operation. Obtain the path from the URI of an API.
Only the sub-users (IAM users) of the account can register and use the SWR images if the image type is Private. Other users can register and use SWR images only when the image type is Public.