检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
With IAM, you can: Create IAM users for employees based on the organizational structure of your enterprise. Each IAM user has their own security credentials for accessing DDM resources. Grant users only the permissions required to perform a specific task.
Ensure that you have the IAM permission to modify DDM accounts. An expired account cannot be used to log in to the system. You need to reset the password and log in again. Figure 1 Account expired Procedure Log in to the DDM console.
Policies that contain actions for both IAM and enterprise projects can be used and take effect for both IAM and Enterprise Project Management Service (EPS). Policies that only contain actions supporting IAM projects can be assigned to user groups and only take effect for IAM.
For example, you can grant IAM users only the permissions for managing a certain type of DDM resources.
For example, to obtain an IAM token in the CN-Hong Kong region, obtain the endpoint of IAM (iam.ap-southeast-1.myhuaweicloud.com) for this region and the resource-path (/v3/auth/tokens) in the URI of the API used to obtain a user token.
IAM user An IAM user is created using an account to use cloud services. Each IAM user has its own identity credentials (password and access keys). An IAM user can view the account ID and user ID on the API Credentials page of the management console.
Reloading Table Data Table 1 Permissions for managing logical tables Permission API Action IAM Project Enterprise Project Reloading table data POST /v1/{project_id}/instances/{instance_id}/reload-config ddm:instance:modify √ √ Parent topic: Permissions Policies and Supported Actions
Schema Management Table 1 Schema management actions Permission API Actions IAM Project Enterprise Project Creating a Schema POST /v1/{project_id}/instances/{instance_id}/databases ddm:database:create √ √ Querying Schemas GET /v1/{project_id}/instances/{instance_id}/databases?
Account Management Table 1 Account management permissions Permission API Actions IAM Project Enterprise Project Creating a DDM Account POST /v1/{project_id}/instances/{instance_id}/users ddm:user:create √ √ Querying DDM Accounts GET /v1/{project_id}/instances/{instance_id}/users?
You can obtain the token by calling the IAM API used to obtain a user token. Table 3 Request body parameters Parameter Mandatory Type Description process_ids Yes String Session ID set. Value range: 1 to 100. Example Request Delete a physical session of a DDM instance.
You can obtain the token by calling the IAM API used to obtain a user token. Table 3 Request body parameters Parameter Mandatory Type Description process_ids Yes String Session ID set. Value range: 1 to 100.
Request Parameters Table 2 Request header parameters Parameter Mandatory Type Description x-auth-token Yes String User token You can obtain the token by calling the IAM API used to obtain a user token.
You can obtain the token by calling the IAM API used to obtain a user token.
ID of a tenant in a region To obtain this value, see Obtaining a Project ID. instance_id Yes String DDM instance ID Request Parameters Table 2 Request header parameters Parameter Mandatory Type Description x-auth-token Yes String User token You can obtain the token by calling the IAM
{Endpoint} is the IAM endpoint and can be obtained from Regions and Endpoints. For details about API authentication, see Authentication.
You can obtain the token by calling the IAM API used to obtain a user token. Table 3 Request body parameters Parameter Mandatory Type Description security_group_id Yes String Security group ID. The default value is the original security group ID.
a Project ID. instance_id Yes String DDM instance ID username Yes String Username of the DDM account to be deleted Request Parameters Table 2 Request header parameters Parameter Mandatory Type Description X-Auth-Token Yes String User token You can obtain the token by calling the IAM
You can obtain the token by calling the IAM API used to obtain a user token.
Project ID. instance_id Yes String DDM instance ID username Yes String Username of the DDM account to be modified Request Parameters Table 2 Request header parameters Parameter Mandatory Type Description X-Auth-Token Yes String User token You can obtain the token by calling the IAM
You can obtain the token by calling the IAM API used to obtain a user token. Table 3 Request body parameters Parameter Mandatory Type Description name Yes String Name of a DDM instance, which: Can include 4 to 64 characters. Must start with a letter.