recreating obs_umn_0414 PR due to bug in gitea
Before Width: | Height: | Size: 32 KiB |
BIN
docs/obs/umn/en-us_image_0000001523534634.png
Normal file
After Width: | Height: | Size: 52 KiB |
Before Width: | Height: | Size: 31 KiB After Width: | Height: | Size: 33 KiB |
Before Width: | Height: | Size: 26 KiB After Width: | Height: | Size: 33 KiB |
Before Width: | Height: | Size: 27 KiB After Width: | Height: | Size: 33 KiB |
Before Width: | Height: | Size: 22 KiB After Width: | Height: | Size: 33 KiB |
@ -26,7 +26,7 @@
|
||||
</table>
|
||||
</div>
|
||||
</li><li id="en-us_topic_0045853504__li11906947104610">The latest objects in a bucket are returned by default after a GET Object request.</li><li id="en-us_topic_0045853504__li5044213017308">Objects can be downloaded by version IDs. By default, the latest object is downloaded if the version ID is not specified. For details, see <a href="obs_03_0327.html#obs_03_0327__section29772226">Related Operations</a> in <a href="obs_03_0327.html">Configuring Versioning</a>.</li><li id="en-us_topic_0045853504__li1922972904812">You can select an object and click <strong id="en-us_topic_0045853504__b1439112892814">Delete</strong> on the right to delete the object. After the object is deleted, OBS generates a <strong id="en-us_topic_0045853504__b887102583116">Delete Marker</strong> with a unique version ID for the deleted object, and the deleted object is displayed in the <strong id="en-us_topic_0045853504__b982755722818">Deleted Objects</strong> list. For details, see <a href="en-us_topic_0045853756.html">Deleting a File or Folder</a>. The 404 error will be returned if attempts are made to access this deleted object.<div class="fignone" id="en-us_topic_0045853504__fig12513111686"><span class="figcap"><b>Figure 3 </b>Object with a delete marker</span><br><span><img id="en-us_topic_0045853504__image106810213564" src="en-us_image_0135698309.png"></span></div>
|
||||
</li><li id="en-us_topic_0045853504__li16974139482">You can recover a deleted object by deleting the object version that has the <strong id="en-us_topic_0045853504__b9737126133818">Delete Marker</strong>. For details, see <a href="en-us_topic_0066176932.html#en-us_topic_0066176932__section27691114163422">Related Operations</a> in <a href="en-us_topic_0066176932.html">Undeleting a File</a>.</li><li id="en-us_topic_0045853504__li65671427483">After an object is deleted, you can specify the version number in <strong id="en-us_topic_0045853504__b202463427396">Deleted Objects</strong> to permanently delete the object of the specified version. For details, see <a href="en-us_topic_0045853756.html#en-us_topic_0045853756__section089519314196">Related Operations</a> in <a href="en-us_topic_0045853756.html">Deleting a File or Folder</a>.</li><li id="en-us_topic_0045853504__li185772028101011">An object is displayed either in the object list or the list of deleted objects. It will never be displayed in both the lists at the same time.<p id="en-us_topic_0045853504__p11578112817100"><a name="en-us_topic_0045853504__li185772028101011"></a><a name="li185772028101011"></a>For example, after object <strong id="en-us_topic_0045853504__b153159177404">A</strong> is uploaded and deleted, it will be displayed in the <strong id="en-us_topic_0045853504__b113718469401">Deleted Objects</strong> list. If you upload an object named <strong id="en-us_topic_0045853504__b109891246104011">A</strong> again, the object <strong id="en-us_topic_0045853504__b1991114619403">A</strong> will be displayed in the <strong id="en-us_topic_0045853504__b92871340114115">Objects</strong> list, and the previously deleted object <strong id="en-us_topic_0045853504__b149921646144011">A</strong> will no longer be displayed in the <strong id="en-us_topic_0045853504__b585482374119">Deleted Objects</strong> list. For details, see <a href="#en-us_topic_0045853504__fig1469714544377">Figure 4</a>.</p>
|
||||
</li><li id="en-us_topic_0045853504__li16974139482">You can recover a deleted object by deleting the delete marker. For details, see <a href="en-us_topic_0066176932.html#en-us_topic_0066176932__section27691114163422">Related Operations</a> in <a href="en-us_topic_0066176932.html">Undeleting a File</a>.</li><li id="en-us_topic_0045853504__li65671427483">After an object is deleted, you can specify the version number in <strong id="en-us_topic_0045853504__b202463427396">Deleted Objects</strong> to permanently delete the object of the specified version. For details, see <a href="en-us_topic_0045853756.html#en-us_topic_0045853756__section089519314196">Related Operations</a> in <a href="en-us_topic_0045853756.html">Deleting a File or Folder</a>.</li><li id="en-us_topic_0045853504__li185772028101011">An object is displayed either in the object list or the list of deleted objects. It will never be displayed in both the lists at the same time.<p id="en-us_topic_0045853504__p11578112817100"><a name="en-us_topic_0045853504__li185772028101011"></a><a name="li185772028101011"></a>For example, after object <strong id="en-us_topic_0045853504__b153159177404">A</strong> is uploaded and deleted, it will be displayed in the <strong id="en-us_topic_0045853504__b113718469401">Deleted Objects</strong> list. If you upload an object named <strong id="en-us_topic_0045853504__b109891246104011">A</strong> again, the object <strong id="en-us_topic_0045853504__b1991114619403">A</strong> will be displayed in the <strong id="en-us_topic_0045853504__b92871340114115">Objects</strong> list, and the previously deleted object <strong id="en-us_topic_0045853504__b149921646144011">A</strong> will no longer be displayed in the <strong id="en-us_topic_0045853504__b585482374119">Deleted Objects</strong> list. For details, see <a href="#en-us_topic_0045853504__fig1469714544377">Figure 4</a>.</p>
|
||||
<div class="fignone" id="en-us_topic_0045853504__fig1469714544377"><a name="en-us_topic_0045853504__fig1469714544377"></a><a name="fig1469714544377"></a><span class="figcap"><b>Figure 4 </b>Uploading a namesake object after the original one is deleted</span><br><span><img id="en-us_topic_0045853504__image7901510165611" src="en-us_image_0135706002.png"></span></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
|
@ -14,7 +14,7 @@
|
||||
</thead>
|
||||
<tbody><tr id="en-us_topic_0045853662__obs_03_0306_row721018185364"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="en-us_topic_0045853662__obs_03_0306_p12210111812361">Region</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="79.78%" headers="mcps1.3.3.2.2.2.1.2.3.1.2 "><p id="en-us_topic_0045853662__obs_03_0306_p480613549419">Geographic area where a bucket resides. For low network latency and quick resource access, select the nearest region. Once the bucket is created, its region cannot be changed.</p>
|
||||
<td class="cellrowborder" valign="top" width="79.78%" headers="mcps1.3.3.2.2.2.1.2.3.1.2 "><p id="en-us_topic_0045853662__obs_03_0306_p480613549419">Geographic area where a bucket resides. For low latency and faster access, select the region nearest to you. Once the bucket is created, its region cannot be changed.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="en-us_topic_0045853662__obs_03_0306_row321061820361"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="en-us_topic_0045853662__obs_03_0306_p6210181823616">Bucket Name</p>
|
||||
@ -36,7 +36,7 @@
|
||||
<tr id="en-us_topic_0045853662__obs_03_0306_row162107185362"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="en-us_topic_0045853662__obs_03_0306_p1621051833618">Bucket Policy</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="79.78%" headers="mcps1.3.3.2.2.2.1.2.3.1.2 "><p id="en-us_topic_0045853662__obs_03_0306_p13250952104514">Controls read and write permissions for buckets.</p>
|
||||
<ul id="en-us_topic_0045853662__obs_03_0306_ul1118618569194"><li id="en-us_topic_0045853662__obs_03_0306_li13186185612196"><strong id="en-us_topic_0045853662__obs_03_0306_b5921165812225">Private</strong>: Only users granted permissions by the ACL can access the bucket.</li><li id="en-us_topic_0045853662__obs_03_0306_li181131478206"><strong id="en-us_topic_0045853662__obs_03_0306_b116813342311">Public Read</strong>: Anyone can read objects in the bucket.</li><li id="en-us_topic_0045853662__obs_03_0306_li147015152013"><strong id="en-us_topic_0045853662__obs_03_0306_b1492156122319">Public Read and Write</strong>: Anyone can read, write, or delete objects in the bucket.</li></ul>
|
||||
<ul id="en-us_topic_0045853662__obs_03_0306_ul1118618569194"><li id="en-us_topic_0045853662__obs_03_0306_li13186185612196"><strong id="en-us_topic_0045853662__obs_03_0306_b929114841213">Private</strong>: No access beyond the bucket ACL settings is granted.</li><li id="en-us_topic_0045853662__obs_03_0306_li181131478206"><strong id="en-us_topic_0045853662__obs_03_0306_b116813342311">Public Read</strong>: Anyone can read objects in the bucket.</li><li id="en-us_topic_0045853662__obs_03_0306_li147015152013"><strong id="en-us_topic_0045853662__obs_03_0306_b1492156122319">Public Read and Write</strong>: Anyone can read, write, or delete objects in the bucket.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="en-us_topic_0045853662__obs_03_0306_row521061883619"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="en-us_topic_0045853662__obs_03_0306_p6210111812361">Default Encryption</p>
|
||||
|
@ -6,20 +6,20 @@
|
||||
</div>
|
||||
<div class="section" id="en-us_topic_0045853663__section1750515815466"><h4 class="sectiontitle">Prerequisites</h4><ul id="en-us_topic_0045853663__obs_03_0307_ul13735132573913"><li id="en-us_topic_0045853663__obs_03_0307_li16735122520395">At least one bucket has been created.</li><li id="en-us_topic_0045853663__obs_03_0307_li167391276399">If you want to classify files, you can create folders and upload files to different folders. For details about how to create a folder, see <a href="obs_03_0316.html">Creating a Folder</a></li></ul>
|
||||
</div>
|
||||
<div class="section" id="en-us_topic_0045853663__section64292661113931"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0045853663__obs_03_0307_ol658192291912"><li id="en-us_topic_0045853663__obs_03_0307_li1596440151221"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0045853663__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0045853663__obs_03_0307_li123641720664"><span>In the navigation pane, click <strong id="en-us_topic_0045853663__obs_03_0307_b47118221194931">Objects</strong>.</span></li><li id="en-us_topic_0045853663__obs_03_0307_li46803166594"><span>Go to the folder to which objects are uploaded. Click <strong id="en-us_topic_0045853663__obs_03_0307_b0882125105511">Upload Object</strong>. The <strong id="en-us_topic_0045853663__obs_03_0307_b6293181115555">Upload Object</strong> dialog box is displayed.</span><p><div class="note" id="en-us_topic_0045853663__obs_03_0307_note186461450113113"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0045853663__obs_03_0307_p14504161520198">If the files that you want to upload to OBS are stored in Microsoft OneDrive, it is recommended that the names of these files contain a maximum of 32 characters to ensure compatibility.</p>
|
||||
<div class="section" id="en-us_topic_0045853663__section64292661113931"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0045853663__obs_03_0307_ol658192291912"><li id="en-us_topic_0045853663__obs_03_0307_li1596440151221"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0045853663__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0045853663__obs_03_0307_li123641720664"><span>In the navigation pane, choose <strong id="en-us_topic_0045853663__obs_03_0307_b51941856151917">Objects</strong>.</span></li><li id="en-us_topic_0045853663__obs_03_0307_li46803166594"><span>Go to the folder to which objects are uploaded. Click <strong id="en-us_topic_0045853663__obs_03_0307_b0882125105511">Upload Object</strong>. The <strong id="en-us_topic_0045853663__obs_03_0307_b6293181115555">Upload Object</strong> dialog box is displayed.</span><p><div class="note" id="en-us_topic_0045853663__obs_03_0307_note186461450113113"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0045853663__obs_03_0307_p14504161520198">If the files that you want to upload to OBS are stored in Microsoft OneDrive, it is recommended that the names of these files contain a maximum of 32 characters to ensure compatibility.</p>
|
||||
</div></div>
|
||||
<div class="fignone" id="en-us_topic_0045853663__obs_03_0307_fig188654349118"><span class="figcap"><b>Figure 1 </b>Uploading objects</span><br><span><img id="en-us_topic_0045853663__obs_03_0307_image10536191814483" src="en-us_image_0153827167.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
<p id="en-us_topic_0045853663__obs_03_0307_p739115241316"></p>
|
||||
<p id="en-us_topic_0045853663__obs_03_0307_p1430017260138"></p>
|
||||
</p></li><li id="en-us_topic_0045853663__obs_03_0307_li8341913385"><span>Select a storage class. If you do not specify a storage class, the object you upload inherits the default storage class of the bucket.</span><p><div class="note" id="en-us_topic_0045853663__obs_03_0307_note27281163408"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0045853663__obs_03_0307_p15728186194013">An object can have a different storage class from its bucket. You can specify a storage class for an object when uploading it, or you can change the object storage class after the object is uploaded.</p>
|
||||
</div></div>
|
||||
</p></li><li id="en-us_topic_0045853663__obs_03_0307_li43271656164119"><span>Add a file or folder to be uploaded by dragging it to the <strong id="en-us_topic_0045853663__obs_03_0307_b120411138146">Upload Object</strong> area.</span><p><p id="en-us_topic_0045853663__obs_03_0307_p5316155610415">You can also click <strong id="en-us_topic_0045853663__obs_03_0307_b9948174410266">add file</strong> in the <strong id="en-us_topic_0045853663__obs_03_0307_b064791710146">Upload Object</strong> area to select files.</p>
|
||||
</p></li><li id="en-us_topic_0045853663__obs_03_0307_li74481344102111"><span><strong id="en-us_topic_0045853663__obs_03_0307_b4955291917530">Optional</strong>: Select <strong id="en-us_topic_0045853663__obs_03_0307_b16368281536">KMS encryption</strong> to encrypt the uploaded file. For details, see <a href="obs_03_0322.html">Uploading a File with Server-Side Encryption</a>.</span><p><div class="note" id="en-us_topic_0045853663__obs_03_0307_note610818411894"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0045853663__obs_03_0307_obs_03_0306_p062133814520">If the default encryption has been enabled for the bucket, uploaded objects are automatically encrypted.</p>
|
||||
</p></li><li id="en-us_topic_0045853663__obs_03_0307_li74481344102111"><span>(Optional) Select <strong id="en-us_topic_0045853663__obs_03_0307_b16368281536">KMS encryption</strong> to encrypt the uploaded file. For details, see <a href="obs_03_0322.html">Uploading a File in Server-Side Encryption Mode</a>.</span><p><div class="note" id="en-us_topic_0045853663__obs_03_0307_note610818411894"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0045853663__obs_03_0307_obs_03_0306_p062133814520">If the default encryption has been enabled for the bucket, uploaded objects are automatically encrypted.</p>
|
||||
</div></div>
|
||||
</p></li><li id="en-us_topic_0045853663__obs_03_0307_li12125192695311"><span>Click <strong id="en-us_topic_0045853663__obs_03_0307_b1918611133719">Upload</strong>.</span></li></ol>
|
||||
</div>
|
||||
<div class="section" id="en-us_topic_0045853663__section2680481145652"><h4 class="sectiontitle">Related Operations</h4><p id="en-us_topic_0045853663__p61538082105347">When uploading an object, you can specify a storage class for it. After the object is uploaded, you can also change its storage class. The procedure is as follows:</p>
|
||||
<ol id="en-us_topic_0045853663__ol54196626"><li id="en-us_topic_0045853663__li94697228416"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0045853663__obs_03_0307_b1395123914108_1">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0045853663__li33462878175550"><span>In the navigation pane, click <strong id="en-us_topic_0045853663__b4277252771182">Objects</strong>.</span></li><li id="en-us_topic_0045853663__li45807892175717"><span>Select the target object and choose <strong id="en-us_topic_0045853663__b16331938401184">More</strong> > <strong id="en-us_topic_0045853663__b4308642191184">Change Storage Class</strong> on the right.</span></li><li id="en-us_topic_0045853663__li65518593175554"><span>Select the desired storage class and click <strong id="en-us_topic_0045853663__b6082718214515">OK</strong>.</span></li></ol>
|
||||
<ol id="en-us_topic_0045853663__ol54196626"><li id="en-us_topic_0045853663__li94697228416"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0045853663__obs_03_0307_b1395123914108_1">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0045853663__li33462878175550"><span>In the navigation pane, click <strong id="en-us_topic_0045853663__b4277252771182">Objects</strong>.</span></li><li id="en-us_topic_0045853663__li45807892175717"><span>Select the target object and choose <strong id="en-us_topic_0045853663__b16331938401184">More</strong> > <strong id="en-us_topic_0045853663__b4308642191184">Change Storage Class</strong> on the right.</span><p><p id="en-us_topic_0045853663__p7418134211011"></p>
|
||||
</p></li><li id="en-us_topic_0045853663__li65518593175554"><span>Select the desired storage class and click <strong id="en-us_topic_0045853663__b6082718214515">OK</strong>.</span></li></ol>
|
||||
<div class="note" id="en-us_topic_0045853663__note49933437105659"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><ul id="en-us_topic_0045853663__ul48955806162444"><li id="en-us_topic_0045853663__li18917418162447">Objects can be changed from Standard to Warm or Cold storage class, or from Warm to Standard or Cold storage class, but objects in Cold storage class must be restored before being changed to Standard or Warm storage class. Changing from Warm or Cold to other storage classes incurs restore fees. Select an appropriate change option based on your actual needs.</li><li id="en-us_topic_0045853663__li377814260432">When the storage class is changed to Cold, the object restore status changes to <strong id="en-us_topic_0045853663__b478316619">Unrestored</strong>.</li><li id="en-us_topic_0045853663__li20206156162444">You can also configure a lifecycle rule to change the storage class of an object. For details, see <a href="obs_03_0335.html">Configuring a Lifecycle Rule</a>.</li></ul>
|
||||
</div></div>
|
||||
</div>
|
||||
|
@ -1,8 +1,8 @@
|
||||
<a name="en-us_topic_0045853816"></a><a name="en-us_topic_0045853816"></a>
|
||||
|
||||
<h1 class="topictitle1">SMN-Enabled Event Notification</h1>
|
||||
<div id="body1499758606807"><p class="MsoNormal" id="en-us_topic_0045853816__p14144781513">Simple Message Notification (SMN) is a reliable and extensible message notification service that can handle a huge number of messages. SMN significantly simplifies system coupling. It can automatically push messages to subscribers through emails and text messages.</p>
|
||||
<p class="MsoNormal" id="en-us_topic_0045853816__p52332551694">OBS leverages SMN to provide the event notification function. In OBS, you can use SMN to send event notifications to specified subscribers, so that you will be informed of any critical operations (such as upload and deletion) that occur on specified buckets in real time. For example, you can configure an event notification rule to send messages through SMN to the specified email address whenever an upload operation occurs on the specified bucket.</p>
|
||||
<h1 class="topictitle1">SMN-Enabled Event Notifications</h1>
|
||||
<div id="body1499758606807"><p class="MsoNormal" id="en-us_topic_0045853816__p14144781513">Simple Message Notification (SMN) is a reliable and extensible message notification service that can handle a huge number of messages. It significantly simplifies system coupling and can automatically push messages to endpoints via email or text message.</p>
|
||||
<p class="MsoNormal" id="en-us_topic_0045853816__p52332551694">OBS leverages SMN to provide event notifications. In OBS, you can use SMN to send event notifications to specified subscribers, so that you will be informed of any critical operations (such as upload and deletion) that occur on specified buckets in real time. For example, you can configure an event notification rule to send messages through SMN to the specified email address whenever an upload operation occurs on the specified bucket.</p>
|
||||
<p class="MsoNormal" id="en-us_topic_0045853816__p30617153">You can configure the event notification rule to filter objects by the object name prefix or suffix. For example, you can add an event notification rule to send notifications whenever an object with the <strong id="en-us_topic_0045853816__b5249621124716">.jpg</strong> suffix is uploaded to the specified bucket. You can also add an event notification rule to send notifications whenever an object with the <strong id="en-us_topic_0045853816__b182751715538">images/</strong> prefix is uploaded to the specified bucket.</p>
|
||||
<p id="en-us_topic_0045853816__p148813132915">For details about events supported by SMN and how to configure an SMN-enabled event notification rule, see <a href="en-us_topic_0066088963.html">Configuring SMN-Enabled Event Notification</a>.</p>
|
||||
<div class="fignone" id="en-us_topic_0045853816__fig9778481781"><span class="figcap"><b>Figure 1 </b>SMN-enabled event notification</span><br><span><img id="en-us_topic_0045853816__image14512421491" src="en-us_image_0136295107.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
@ -49,7 +49,7 @@
|
||||
</div>
|
||||
<div>
|
||||
<div class="familylinks">
|
||||
<div class="parentlink"><strong>Parent topic:</strong> <a href="obs_03_0332.html">Event Notification</a></div>
|
||||
<div class="parentlink"><strong>Parent topic:</strong> <a href="obs_03_0332.html">Event Notifications</a></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
@ -4,7 +4,7 @@
|
||||
<div id="body1557123327164"><div class="section" id="en-us_topic_0045853821__section654711404519"><h4 class="sectiontitle">Prerequisites</h4><p id="en-us_topic_0045853821__p131591575457">You are the object owner or you have the permission to write the object ACL.</p>
|
||||
<p id="en-us_topic_0045853821__p14538134016468">An object owner is the account that uploads the object, but may not be the owner of the bucket that stores the object. For example, account <strong id="en-us_topic_0045853821__b131031122538">B</strong> is granted the permission to access a bucket of account <strong id="en-us_topic_0045853821__b10109529531">A</strong>, and account <strong id="en-us_topic_0045853821__b1111017255312">B</strong> uploads a file to the bucket. In that case, account <strong id="en-us_topic_0045853821__b1911016216538">B</strong>, instead of the bucket owner account <strong id="en-us_topic_0045853821__b111101821537">A</strong>, is the owner of the object. By default, account A is not allowed to access this object and cannot read or modify the object ACL.</p>
|
||||
</div>
|
||||
<div class="section" id="en-us_topic_0045853821__section125891538184018"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0045853821__ol3653067817298"><li id="en-us_topic_0045853821__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0045853821__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0045853821__li2931491252"><span>In the navigation pane, click <strong id="en-us_topic_0045853821__obs_03_0307_b47118221194931">Objects</strong>.</span></li><li id="en-us_topic_0045853821__li27180413161423"><span>Click the object to be operated.</span></li><li id="en-us_topic_0045853821__li30113624141859"><span>On the <strong id="en-us_topic_0045853821__b51051121169">Object ACL</strong> tab, click <strong id="en-us_topic_0045853821__b12752165594317">Edit</strong> to set ACL permissions of the <strong id="en-us_topic_0045853821__b1250210194412">Owner</strong>, <strong id="en-us_topic_0045853821__b999571984411">Registered User</strong>, and <strong id="en-us_topic_0045853821__b12376141564415">Anonymous User</strong> for the target object.</span><p><div class="note" id="en-us_topic_0045853821__note32759916"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p class="NotesText" id="en-us_topic_0045853821__p26403792">If the object is encrypted, the ACL permission cannot be configured for registered users and anonymous users.</p>
|
||||
<div class="section" id="en-us_topic_0045853821__section125891538184018"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0045853821__ol3653067817298"><li id="en-us_topic_0045853821__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0045853821__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0045853821__li2931491252"><span>In the navigation pane, choose <strong id="en-us_topic_0045853821__obs_03_0307_b51941856151917">Objects</strong>.</span></li><li id="en-us_topic_0045853821__li27180413161423"><span>Click the object to be operated.</span></li><li id="en-us_topic_0045853821__li30113624141859"><span>On the <strong id="en-us_topic_0045853821__b51051121169">Object ACL</strong> tab, click <strong id="en-us_topic_0045853821__b12752165594317">Edit</strong> to set ACL permissions of the <strong id="en-us_topic_0045853821__b1250210194412">Owner</strong>, <strong id="en-us_topic_0045853821__b999571984411">Registered User</strong>, and <strong id="en-us_topic_0045853821__b12376141564415">Anonymous User</strong> for the target object.</span><p><div class="note" id="en-us_topic_0045853821__note32759916"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p class="NotesText" id="en-us_topic_0045853821__p26403792">If the object is encrypted, the ACL permission cannot be configured for registered users and anonymous users.</p>
|
||||
</div></div>
|
||||
</p></li><li id="en-us_topic_0045853821__li1325219548272"><span>Click <strong id="en-us_topic_0045853821__b139855243117">Add</strong> to set the ACL permissions of a specific account. For details, see <a href="#en-us_topic_0045853821__fig3474335195326">Figure 1</a>.</span><p><p id="en-us_topic_0045853821__p271280205114">Enter an account ID or account name and set ACL permissions for the account. You can obtain the account ID or account name on the <strong id="en-us_topic_0045853821__b13462053113017">My Credentials</strong> page. The account ID and account name correspond to the <strong id="en-us_topic_0045853821__b439115211314">Domain ID</strong> and <strong id="en-us_topic_0045853821__b1139272116111">Domain Name</strong> respectively on the <strong id="en-us_topic_0045853821__b9392102115112">My Credentials</strong> page.</p>
|
||||
<div class="fignone" id="en-us_topic_0045853821__fig3474335195326"><a name="en-us_topic_0045853821__fig3474335195326"></a><a name="fig3474335195326"></a><span class="figcap"><b>Figure 1 </b>Adding ACL permissions for objects</span><br><span><img id="en-us_topic_0045853821__image1665582616554" src="en-us_image_0168396382.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
|
@ -26,7 +26,7 @@
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="65.41%" headers="mcps1.3.4.2.3.1.2 "><p id="en-us_topic_0049066876__en-us_topic_0047496338_p297677011524">Redirects an object to another object or an external URL. The redirection function is implemented using static website hosting.</p>
|
||||
<p id="en-us_topic_0049066876__p293004410328">For example, you can perform the following operations to implement object redirection:</p>
|
||||
<ol id="en-us_topic_0049066876__ol64035022103214"><li id="en-us_topic_0049066876__li34498184103354">Set metadata of object <strong id="en-us_topic_0049066876__b3403178165515">testobject.html</strong> in the root directory of bucket <strong id="en-us_topic_0049066876__b144046825515">testbucket</strong>. Select <strong id="en-us_topic_0049066876__b18405585550">WebsiteRedirectLocation</strong> for <strong id="en-us_topic_0049066876__b54061586550">Name</strong> and enter <strong id="en-us_topic_0049066876__b18407128155519">http://www.example.com</strong> for <strong id="en-us_topic_0049066876__b34091884557">Value</strong>.<div class="note" id="en-us_topic_0049066876__note66951730103627"><span class="notetitle"> NOTE: </span><div class="notebody"><p id="en-us_topic_0049066876__p65694662103627">OBS only supports redirection for objects in the root directory of a bucket. It does not support redirection for objects in folders in a bucket.</p>
|
||||
<ol id="en-us_topic_0049066876__ol64035022103214"><li id="en-us_topic_0049066876__li34498184103354">Set metadata of object <strong id="en-us_topic_0049066876__b3403178165515">testobject.html</strong> in the root directory of bucket <strong id="en-us_topic_0049066876__b144046825515">testbucket</strong>. Select <strong id="en-us_topic_0049066876__b18405585550">WebsiteRedirectLocation</strong> for <strong id="en-us_topic_0049066876__b54061586550">Name</strong> and enter <strong id="en-us_topic_0049066876__b18407128155519">http://www.example.com</strong> for <strong id="en-us_topic_0049066876__b34091884557">Value</strong>.<div class="note" id="en-us_topic_0049066876__note66951730103627"><span class="notetitle"> NOTE: </span><div class="notebody"><p id="en-us_topic_0049066876__p65694662103627">OBS only supports redirection for objects in the root directory of a bucket. Redirection for objects located in folders of a bucket is not supported.</p>
|
||||
</div></div>
|
||||
</li><li id="en-us_topic_0049066876__li45119609103541">Configure static website hosting for bucket <strong id="en-us_topic_0049066876__b20224317114715">testbucket</strong>, and set the object <strong id="en-us_topic_0049066876__b4226191704715">testobject.html</strong> in the bucket as the default home page of the hosted static website.</li><li id="en-us_topic_0049066876__li39834343103214">If you access object <strong id="en-us_topic_0049066876__b537162135512">testobject.html</strong> through the URL link provided on the <strong id="en-us_topic_0049066876__b1337312105510">Configure Static Website Hosting</strong> page, the access request is redirected to <strong id="en-us_topic_0049066876__b1437682125516">http://www.example.com</strong>.</li></ol>
|
||||
</td>
|
||||
|
@ -4,7 +4,7 @@
|
||||
<div id="body1499753333227"><p id="en-us_topic_0066036542__p55351642">This section describes how to use CORS in HTML5 to implement cross-origin access.</p>
|
||||
<div class="section" id="en-us_topic_0066036542__section48948668114148"><h4 class="sectiontitle">Prerequisites</h4><p id="en-us_topic_0066036542__p5419211114148">Static website hosting has been configured. For details, see <a href="en-us_topic_0045853755.html">Configuring Static Website Hosting</a>.</p>
|
||||
</div>
|
||||
<div class="section" id="en-us_topic_0066036542__section54298028"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0066036542__ol23319874"><li id="en-us_topic_0066036542__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0066036542__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0066036542__li18830181855820"><span>On the right of the <strong id="en-us_topic_0066036542__b3277199132716">Overview</strong> page, select <strong id="en-us_topic_0066036542__b6556172482718">CORS Rules</strong> in the <strong id="en-us_topic_0066036542__b2562175252319">Basic Configurations</strong> area. The <strong id="en-us_topic_0066036542__b763811488279">CORS Rules</strong> page is displayed.</span><p><p id="en-us_topic_0066036542__p471425117139">Alternatively, you can choose <strong id="en-us_topic_0066036542__b1898818329375">Basic Configurations</strong> > <strong id="en-us_topic_0066036542__b18988132103714">CORS Rules</strong> in the navigation pane.</p>
|
||||
<div class="section" id="en-us_topic_0066036542__section54298028"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0066036542__ol23319874"><li id="en-us_topic_0066036542__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0066036542__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0066036542__li18830181855820"><span>On the right of the <strong id="en-us_topic_0066036542__b3277199132716">Overview</strong> page, click <strong id="en-us_topic_0066036542__b6556172482718">CORS Rules</strong> in the <strong id="en-us_topic_0066036542__b2562175252319">Basic Configurations</strong> area. The <strong id="en-us_topic_0066036542__b763811488279">CORS Rules</strong> page is displayed.</span><p><p id="en-us_topic_0066036542__p471425117139">Alternatively, you can choose <strong id="en-us_topic_0066036542__b1898818329375">Basic Configurations</strong> > <strong id="en-us_topic_0066036542__b18988132103714">CORS Rules</strong> in the navigation pane.</p>
|
||||
</p></li><li id="en-us_topic_0066036542__li45993918325"><span>Click <strong id="en-us_topic_0066036542__b15332124463218">Create</strong>. The <strong id="en-us_topic_0066036542__b08802053113218">Create CORS Rule</strong> dialog box is displayed. See <a href="#en-us_topic_0066036542__fig2425430173411">Figure 1</a> for details.</span><p><div class="note" id="en-us_topic_0066036542__note714561653618"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0066036542__p61451516193620">You can set a maximum of 100 CORS rules for one bucket.</p>
|
||||
</div></div>
|
||||
<div class="fignone" id="en-us_topic_0066036542__fig2425430173411"><a name="en-us_topic_0066036542__fig2425430173411"></a><a name="fig2425430173411"></a><span class="figcap"><b>Figure 1 </b>Creating a CORS rule</span><br><span><img id="en-us_topic_0066036542__image154545112510" src="en-us_image_0145420855.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Configuring SMN-Enabled Event Notification</h1>
|
||||
<div id="body1499758606807"><p id="en-us_topic_0066088963__p1195915314414">This topic describes how to configure an SMN-enabled event notification rule on OBS Console.</p>
|
||||
<div class="section" id="en-us_topic_0066088963__section72855457345"><h4 class="sectiontitle">Background Information</h4><p id="en-us_topic_0066088963__p76811548103411">For details, see <a href="en-us_topic_0045853816.html">SMN-Enabled Event Notification</a>.</p>
|
||||
<div class="section" id="en-us_topic_0066088963__section72855457345"><h4 class="sectiontitle">Background Information</h4><p id="en-us_topic_0066088963__p76811548103411">For details, see <a href="en-us_topic_0045853816.html">SMN-Enabled Event Notifications</a>.</p>
|
||||
</div>
|
||||
<div class="section" id="en-us_topic_0066088963__section4422459618019"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0066088963__ol6247704518019"><li id="en-us_topic_0066088963__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="en-us_topic_0066088963__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="en-us_topic_0066088963__li18830181855820"><span>In the right <strong id="en-us_topic_0066088963__b52421745173018">Basic Configurations</strong> area, click <strong id="en-us_topic_0066088963__b16528417163113">Event Notification</strong>. The <strong id="en-us_topic_0066088963__b14368192511314">Event Notification</strong> page is displayed.</span><p><p id="en-us_topic_0066088963__p471425117139">Alternatively, you can choose <strong id="en-us_topic_0066088963__b37321058164212">Basic Configurations</strong> > <strong id="en-us_topic_0066088963__b167381858114211">Event Notification</strong> in the navigation pane.</p>
|
||||
</p></li><li id="en-us_topic_0066088963__li108481812202814"><span>Click <strong id="en-us_topic_0066088963__b10410184615474">Create</strong>. The <strong id="en-us_topic_0066088963__b5197637481">Create Event Notification</strong> dialog box is displayed. See <a href="#en-us_topic_0066088963__fig17847723015">Figure 1</a> for details.</span><p><div class="fignone" id="en-us_topic_0066088963__fig17847723015"><a name="en-us_topic_0066088963__fig17847723015"></a><a name="fig17847723015"></a><span class="figcap"><b>Figure 1 </b>Creating an event notification rule</span><br><span><img id="en-us_topic_0066088963__image1754618155260" src="en-us_image_0145117970.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
@ -65,7 +65,7 @@
|
||||
</div>
|
||||
<div>
|
||||
<div class="familylinks">
|
||||
<div class="parentlink"><strong>Parent topic:</strong> <a href="obs_03_0332.html">Event Notification</a></div>
|
||||
<div class="parentlink"><strong>Parent topic:</strong> <a href="obs_03_0332.html">Event Notifications</a></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
@ -1,10 +1,9 @@
|
||||
<a name="obs_03_0032"></a><a name="obs_03_0032"></a>
|
||||
|
||||
<h1 class="topictitle1">Configuring a User-Defined Domain Name</h1>
|
||||
<div id="body0000001508343717"><div class="section" id="obs_03_0032__section16552733193411"><h4 class="sectiontitle">Prerequisites</h4><p id="obs_03_0032__p52272611352">You have created a bucket and uploaded your website file to it.</p>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0032__section541719774011"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0032__ol7482417101117"><li id="obs_03_0032__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0032__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0032__li13225103917434"><span>In the navigation pane, choose <strong id="obs_03_0032__b112571336227">Domain Name Mgmt</strong>.</span></li><li id="obs_03_0032__li1780214214274"><span>Click <strong id="obs_03_0032__b12674133062813">Bind User Domain Name</strong> and enter the domain name to be configured, as shown in <a href="#obs_03_0032__fig53010339108">Figure 1</a>.</span><p><p id="obs_03_0032__p7863173592419">The suffix of a user-defined domain name can contain 2 to 6 uppercase or lowercase letters.</p>
|
||||
<div id="body0000001508343717"><div class="section" id="obs_03_0032__section541719774011"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0032__ol7482417101117"><li id="obs_03_0032__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0032__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0032__li13225103917434"><span>In the navigation pane, choose <strong id="obs_03_0032__b112571336227">Domain Name Mgmt</strong>.</span></li><li id="obs_03_0032__li1780214214274"><span>Click <strong id="obs_03_0032__b1833051191011">Bind User Domain Name</strong>. In the displayed dialog box, enter the domain name to configure, as shown in <a href="#obs_03_0032__fig53010339108">Figure 1</a>.</span><p><p id="obs_03_0032__p7863173592419">The suffix of a user-defined domain name can contain 2 to 6 uppercase or lowercase letters.</p>
|
||||
<div class="fignone" id="obs_03_0032__fig53010339108"><a name="obs_03_0032__fig53010339108"></a><a name="fig53010339108"></a><span class="figcap"><b>Figure 1 </b>Binding a user domain name</span><br><span><img id="obs_03_0032__image1886212815184" src="en-us_image_0000001458743966.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
<p id="obs_03_0032__p1030020111556"></p>
|
||||
</p></li><li id="obs_03_0032__li417413617312"><span>Click <strong id="obs_03_0032__b514602912318">OK</strong>.</span></li><li id="obs_03_0032__li313135810364"><span>Configure a CNAME record on the DNS, and map the user-defined domain name (for example, <strong id="obs_03_0032__b148053833110">example.com</strong>) to the domain name of the bucket. </span><p><p id="obs_03_0032__p161095613225">The CNAME configuration varies depending on DNS providers. For details, contact your DNS provider.</p>
|
||||
</p></li></ol>
|
||||
</div>
|
||||
|
@ -2,15 +2,15 @@
|
||||
|
||||
<h1 class="topictitle1">Configuring User Permissions</h1>
|
||||
<div id="body8662426"><p id="obs_03_0035__obs_03_0304_p77331243113019">If your cloud service account does not need individual IAM users, then you may skip this section. Your permissions to use OBS functions are not affected.</p>
|
||||
<p id="obs_03_0035__obs_03_0304_p783465223215">If IAM users are required, you need to grant OBS access permissions to the users, because OBS is separately deployed from other cloud resources.</p>
|
||||
<p id="obs_03_0035__obs_03_0304_p783465223215">If IAM users are required, you need to grant them access permissions on OBS, because OBS is separately deployed from other cloud resources.</p>
|
||||
<div class="section" id="obs_03_0035__obs_03_0304_section12521716448"><h4 class="sectiontitle">Process</h4><div class="fignone" id="obs_03_0035__obs_03_0304_obs_03_0122_fig292324264713"><span class="figcap"><b>Figure 1 </b>Process of granting an IAM user the OBS permissions</span><br><span><img id="obs_03_0035__obs_03_0304_obs_03_0122_image12924124212474" src="en-us_image_0170301902.png"></span></div>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0035__obs_03_0304_section1056019017457"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0035__obs_03_0304_obs_03_0122_ol63831030102"><li id="obs_03_0035__obs_03_0304_obs_03_0122_li35354147174321"><span>Log in to the management console using a cloud service account.</span></li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li5853192561010"><span>On the top navigation menu, choose <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b19603113671814">Service List</strong> > <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b3603103615186">Management & Deployment</strong> > <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b460310368184">Identity and Access Management</strong>. The IAM console page is displayed.</span></li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li257313485116"><span>Create a user group and grant the OBS permissions to the user group.</span><p><div class="p" id="obs_03_0035__obs_03_0304_obs_03_0122_p371751915195">User groups facilitate centralized user management and streamlined permissions management. Users in the same user group have the same permissions. Users created in IAM inherit permissions from the groups to which they belong.<ol type="a" id="obs_03_0035__obs_03_0304_obs_03_0122_ol28671118201912"><li id="obs_03_0035__obs_03_0304_obs_03_0122_li78661718151913">In the navigation pane on the left, click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b17624165682216">User Groups</strong>. The <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b4625115617224">User Groups</strong> page is displayed.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li286617189195">Click <span class="uicontrol" id="obs_03_0035__obs_03_0304_obs_03_0122_uicontrol230942777211457"><b>Create User Group</b></span>.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li1886641801917">On the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1190011522266">Create User Group</strong> page, enter a name for the user group and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b7542112222713">OK</strong>.<p id="obs_03_0035__obs_03_0304_obs_03_0122_p3866171841910">The user group is displayed in the user group list once the creation completes.</p>
|
||||
</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li19866191819199">Click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1406172416567">Modify</strong> in the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b12813112718562">Operation</strong> column of the row where the created user group resides.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li1286721818193">In the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1813981018595">Group Permissions</strong> area, locate <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b166361281309">OBS (S3)</strong>, click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b145811817302">Attach Policy</strong> in the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b151884218015">Operation</strong> column, select the policy name, and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b112537337019">OK</strong>.<div class="note" id="obs_03_0035__obs_03_0304_obs_03_0122_note12867161811198"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0035__obs_03_0304_obs_03_0122_p128671018121916">In the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1318212383618">Policy Information</strong> area, you can view the details about the policy.</p>
|
||||
<div class="section" id="obs_03_0035__obs_03_0304_section1056019017457"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0035__obs_03_0304_obs_03_0122_ol63831030102"><li id="obs_03_0035__obs_03_0304_obs_03_0122_li35354147174321"><span>Log in to the management console with your account.</span></li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li5853192561010"><span>On the top menu bar, choose <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b149371518121613">Service List</strong> > <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b29379189163">Management & Deployment</strong> > <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1293761819168">Identity and Access Management</strong>. The IAM console is displayed.</span></li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li257313485116"><span>Create a user group and assign OBS permissions to it.</span><p><div class="p" id="obs_03_0035__obs_03_0304_obs_03_0122_p371751915195">A user group is a collection of users. By assigning permissions to a user group, you assign permissions to the users in this group. After you create an IAM user, add it to one or more user groups, so that it can inherit the permissions from the groups.<ol type="a" id="obs_03_0035__obs_03_0304_obs_03_0122_ol28671118201912"><li id="obs_03_0035__obs_03_0304_obs_03_0122_li78661718151913">In the navigation pane, choose <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b0624202611174">User Groups</strong>. The <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b8624112618178">User Groups</strong> page is displayed.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li286617189195">Click <span class="uicontrol" id="obs_03_0035__obs_03_0304_obs_03_0122_uicontrol230942777211457"><b>Create User Group</b></span>.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li1886641801917">Enter a user group name and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b779483571714">OK</strong>.<p id="obs_03_0035__obs_03_0304_obs_03_0122_p3866171841910">The user group is displayed in the user group list once the creation is complete.</p>
|
||||
</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li19866191819199">Locate the user group you created and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b834625118178">Modify</strong> in the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b19346105117174">Operation</strong> column of the row.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li1286721818193">In the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1813981018595">Group Permissions</strong> area, locate <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b166361281309">OBS (S3)</strong>, click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b145811817302">Attach Policy</strong> in the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b151884218015">Operation</strong> column, select the policy name, and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b112537337019">OK</strong>.<div class="note" id="obs_03_0035__obs_03_0304_obs_03_0122_note12867161811198"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0035__obs_03_0304_obs_03_0122_p128671018121916">In the <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1318212383618">Policy Information</strong> area, you can view the details about the policy.</p>
|
||||
</div></div>
|
||||
</li></ol>
|
||||
</div>
|
||||
</p></li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li17712194912"><span>Create a user.</span><p><ol type="a" id="obs_03_0035__obs_03_0304_obs_03_0122_ol6893174016015"><li id="obs_03_0035__obs_03_0304_obs_03_0122_li84578140715">In the navigation pane on the left, click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b332175483617">Users</strong>. The <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b832320546366">Users</strong> page is displayed.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li75875232719">Click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b16239139183714">Create User</strong>.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li08941740305">Set user information and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b897712100378">Next</strong>.
|
||||
</p></li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li17712194912"><span>Create a user.</span><p><ol type="a" id="obs_03_0035__obs_03_0304_obs_03_0122_ol6893174016015"><li id="obs_03_0035__obs_03_0304_obs_03_0122_li84578140715">In the navigation pane, choose <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b1645363019241">Users</strong>. The <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b174541830102416">Users</strong> page is displayed.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li75875232719">Click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b16239139183714">Create User</strong>.</li><li id="obs_03_0035__obs_03_0304_obs_03_0122_li08941740305">Set user information and click <strong id="obs_03_0035__obs_03_0304_obs_03_0122_b897712100378">Next</strong>.
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0035__obs_03_0304_obs_03_0122_table127131345071" frame="border" border="1" rules="all"><caption><b>Table 1 </b>User parameters</caption><thead align="left"><tr id="obs_03_0035__obs_03_0304_obs_03_0122_row4714144517714"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.4.2.1.3.2.2.3.1.1"><p id="obs_03_0035__obs_03_0304_obs_03_0122_p137145451578">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.4.2.1.3.2.2.3.1.2"><p id="obs_03_0035__obs_03_0304_obs_03_0122_p1071417451679">Description</p>
|
||||
|
33
docs/obs/umn/obs_03_0046.html
Normal file
@ -0,0 +1,33 @@
|
||||
<a name="obs_03_0046"></a><a name="obs_03_0046"></a>
|
||||
|
||||
<h1 class="topictitle1">Sharing a File</h1>
|
||||
<div id="body1532571182532"><div class="section" id="obs_03_0046__section10566111319376"><h4 class="sectiontitle">Scenarios</h4><p id="obs_03_0046__p14712175511">You can allow anyone to access your file stored in OBS by sharing the temporary URL of the file.</p>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0046__section11953161812519"><h4 class="sectiontitle">Background Information</h4><p id="obs_03_0046__p817605994513">File sharing is temporary. All shared URLs are temporary with a validity period.</p>
|
||||
<p id="obs_03_0046__p722415488219">A temporary URL consists of the access domain name and the temporary authentication information of a file. </p>
|
||||
<p id="obs_03_0046__p936175214325">The temporary authentication information contains the <strong id="obs_03_0046__b191581710133314">AccessKeyId</strong>, <strong id="obs_03_0046__b11743171313331">Expires</strong>, <strong id="obs_03_0046__b1536761914331">x-obs-security-token</strong>, and <strong id="obs_03_0046__b139019248332">Signature</strong> parameters. <strong id="obs_03_0046__b17853173373317">AccessKeyId</strong>, <strong id="obs_03_0046__b3580542183317">x-obs-security-token</strong>, and <strong id="obs_03_0046__b910504711334">Signature</strong> are used for authentication. The <strong id="obs_03_0046__b275917572338">Expires</strong> parameter specifies the validity period of the authentication. </p>
|
||||
<p id="obs_03_0046__p6131231352">After an object is shared on OBS Console, the system will generate a URL that contains the temporary authentication information, valid for five minutes since its generation by default. Each time you change the validity period of a URL, OBS obtains the authentication information again to generate a new URL for sharing, which takes effect since the time when the validity period is changed.</p>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0046__section1524379204718"><h4 class="sectiontitle">Limitations and Constraints</h4><ul id="obs_03_0046__ul1476864319553"><li id="obs_03_0046__li19768743155510">An object shared from OBS Console can be valid for one minute to 18 hours. If you need a longer validity period for a shared object, use the client tool OBS Browser+ that supports a validity period from one minute to 30 days. Or, you can configure a <a href="en-us_topic_0045853745.html">bucket policy or object policy</a> to grant the access permissions of an object to other users permanently.</li><li id="obs_03_0046__li176586246567">Only buckets of version 3.0 support file sharing. You can view the bucket version in the <strong id="obs_03_0046__b137583459531">Basic Information</strong> area on the <strong id="obs_03_0046__b14463156155413">Overview</strong> page of a bucket.</li><li id="obs_03_0046__li15991193655713">Encrypted objects cannot be shared.</li><li id="obs_03_0046__li31603935010">To share a cold object, restore it first.</li></ul>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0046__section2745155111154"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0046__ol165136117163"><li id="obs_03_0046__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0046__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0046__li33462878175550"><span>In the navigation pane, click <strong id="obs_03_0046__b87911144516">Objects</strong>.</span></li><li id="obs_03_0046__en-us_topic_0066036523_li55598663"><span>Locate the file to be shared and click <strong id="obs_03_0046__b71183914283">Share</strong> under the <strong id="obs_03_0046__b4398656122919">Operation</strong> column. The dialog box as given in <a href="#obs_03_0046__fig125731684458">Figure 1</a> is displayed.</span><p><p id="obs_03_0046__p654141612312">Once the <strong id="obs_03_0046__b17315125693317">Share File</strong> dialog box is opened, the URL is effective and valid for five minutes by default. If you change the validity period, the authentication information in the URL changes accordingly, and the URL's new validity period starts upon the change.</p>
|
||||
<div class="fignone" id="obs_03_0046__fig125731684458"><a name="obs_03_0046__fig125731684458"></a><a name="fig125731684458"></a><span class="figcap"><b>Figure 1 </b>Sharing a file</span><br><span><img id="obs_03_0046__image6573188144512" src="en-us_image_0000001523534634.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
</p></li><li id="obs_03_0046__li113111832018"><span>Operate the URL as follows:</span><p><ul id="obs_03_0046__ul36691545182112"><li id="obs_03_0046__li1167044516212">Click <strong id="obs_03_0046__b26901743105011">Open URL</strong> to preview the file on a new page or directly download it to your default download path.</li><li id="obs_03_0046__li475872122213">Click <strong id="obs_03_0046__b13582131814211">Copy Link</strong> to share the link to others for them to access this file using a browser.</li><li id="obs_03_0046__li18612549152314">Click <strong id="obs_03_0046__b10298451165318">Copy Path</strong> to share the file path to users who have access permissions to the bucket. The users then can search for the file by pasting the shared path to the search box of the bucket.</li></ul>
|
||||
<div class="note" id="obs_03_0046__note27664672718"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0046__p57734614276">Within the validity period of a URL, any user who has the URL can access the file.</p>
|
||||
</div></div>
|
||||
</p></li></ol>
|
||||
</div>
|
||||
</div>
|
||||
<div>
|
||||
<div class="familylinks">
|
||||
<div class="parentlink"><strong>Parent topic:</strong> <a href="obs_03_0315.html">Managing Objects</a></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
||||
<script language="JavaScript">
|
||||
<!--
|
||||
image_size('.imgResize');
|
||||
var msg_imageMax = "view original image";
|
||||
var msg_imageClose = "close";
|
||||
//--></script>
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Principals</h1>
|
||||
<div id="body1557026128761"><p id="obs_03_0049__p28805261528">The principals indicate the users which the bucket policies apply to. These users can be accounts, federated users or federated user groups, and IAM users. Target users can be specified in either of the following ways:</p>
|
||||
<ul id="obs_03_0049__ul108801826115212"><li id="obs_03_0049__li7880926165213"><strong id="obs_03_0049__b9396124819353">Include</strong>: Specifies the user on whom the bucket policy statement takes effect.</li><li id="obs_03_0049__li1488092635210"><strong id="obs_03_0049__b13188853163520">Exclude</strong>: Specifies that on all users except the specified user the bucket policy statement takes effect.</li></ul>
|
||||
<ul id="obs_03_0049__ul108801826115212"><li id="obs_03_0049__li7880926165213"><strong id="obs_03_0049__b1043613214332">Include</strong>: The policy takes effect on specified users.</li><li id="obs_03_0049__li1488092635210"><strong id="obs_03_0049__b1890962511336">Exclude</strong>: The policy takes effect on all users except the specified ones.</li></ul>
|
||||
<div class="section" id="obs_03_0049__section1896613422547"><h4 class="sectiontitle">Cloud Service User</h4><ul id="obs_03_0049__ul10202322105519"><li id="obs_03_0049__li20202822135510">IAM users in the current account<p id="obs_03_0049__p1350312548559"><a name="obs_03_0049__li20202822135510"></a><a name="li20202822135510"></a>With <strong id="obs_03_0049__b15586161432114">Principal</strong> set to <strong id="obs_03_0049__b195861514192116">Current account</strong>, you can select one or more IAM users under this account, so the bucket policy applies to the selected IAM users.</p>
|
||||
</li><li id="obs_03_0049__li697612394557">Other account<p id="obs_03_0049__p1584215477567"><a name="obs_03_0049__li697612394557"></a><a name="li697612394557"></a>When the <strong id="obs_03_0049__b12296181019114">Principal</strong> is set to <strong id="obs_03_0049__b629711061111">Other account</strong>, you can enter the ID of other accounts. If you want to apply the bucket policy to IAM users under that account, you need to enter the user IDs, and use commas (,) to separate one from another.</p>
|
||||
<div class="note" id="obs_03_0049__note8951376579"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0049__p145818142578">An authorized user can go to the <strong id="obs_03_0049__b5232132317110">My Credential</strong> page to obtain the domain ID and user ID after login.</p>
|
||||
|
@ -3,7 +3,7 @@
|
||||
<h1 class="topictitle1">Actions</h1>
|
||||
<div id="body1557026128761"><p id="obs_03_0051__p205313416552">Actions are related to resources. When the resource is the current bucket, actions configured in the bucket policy must be bucket related actions. When objects are specified as resources, actions configured in the bucket policy must be object related actions.</p>
|
||||
<p id="obs_03_0051__p77695354145">Actions can be specified in either of the following ways:</p>
|
||||
<ul id="obs_03_0051__ul80324181519"><li id="obs_03_0051__li100102451519"><strong id="obs_03_0051__b125261325103613">Include</strong>: Specifies the actions on which the bucket policy takes effect.</li><li id="obs_03_0051__li73441302154"><strong id="obs_03_0051__b2084382816362">Exclude</strong>: Specifies that on all except the specified actions the bucket policy takes effect.</li></ul>
|
||||
<ul id="obs_03_0051__ul80324181519"><li id="obs_03_0051__li100102451519"><strong id="obs_03_0051__b856171514343">Include</strong>: The policy takes effect on specified actions.</li><li id="obs_03_0051__li73441302154"><strong id="obs_03_0051__b881411181346">Exclude</strong>: The policy takes effect on all actions except the specified ones.</li></ul>
|
||||
<div class="section" id="obs_03_0051__section88267409555"><h4 class="sectiontitle">Actions Related to Buckets</h4>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0051__table13827194016555" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Actions related to buckets</caption><thead align="left"><tr id="obs_03_0051__row85334118557"><th align="left" class="cellrowborder" valign="top" width="16.16%" id="mcps1.3.4.2.2.4.1.1"><p id="obs_03_0051__p195334120552">Type</p>
|
||||
</th>
|
||||
|
@ -16,7 +16,7 @@
|
||||
</tr>
|
||||
<tr id="obs_03_0054__row2742419211311"><td class="cellrowborder" valign="top" width="34%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0054__p676711911311"><a href="obs_03_0315.html">Basic object operations</a></p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="66%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0054__p1979955161418">Allow you to manage objects, including uploads, multipart uploads, downloads, storage class change, restore of archived objects, and deletion.</p>
|
||||
<td class="cellrowborder" valign="top" width="66%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0054__p1979955161418">Allow you to manage objects, including uploads, multipart uploads, downloads, storage class change, restore of Cold objects, and deletion.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0054__row275312461116"><td class="cellrowborder" valign="top" width="34%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0054__p73666084410"><a href="obs_03_0321.html">Server-side encryption</a></p>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Configuring an Object Policy</h1>
|
||||
<div id="body1557123327164"><p id="obs_03_0075__p18416184972615">Object policies are applied to the objects in a bucket. With an object policy, you can configure conditions and actions for objects in a bucket.</p>
|
||||
<div class="section" id="obs_03_0075__section1427668152517"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0075__ol3653067817298"><li id="obs_03_0075__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0075__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0075__li51927620"><span>In the navigation pane, click <strong id="obs_03_0075__obs_03_0307_b47118221194931">Objects</strong>.</span></li><li id="obs_03_0075__li27180413161423"><span>On the right of the object to be operated, choose <strong id="obs_03_0075__b622031814208">More</strong> > <strong id="obs_03_0075__b156481323142016">Configure Object Policy</strong>. The <strong id="obs_03_0075__b1787252862012">Configure Object Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0075__li141801159171718"><span>Select a proper policy mode as required. Valid options are as follows:</span><p><ul id="obs_03_0075__ul1974615162010"><li id="obs_03_0075__li97411532015">Read-only mode: The authorized user has the read permission to the object. For follow-up procedure, see <a href="#obs_03_0075__li3552175452220">5</a>.</li><li id="obs_03_0075__li390172213204">Read and write mode: The authorized user has the read and write permissions to the object. For follow-up procedure, see <a href="#obs_03_0075__li3552175452220">5</a>.</li><li id="obs_03_0075__li4483132516202">Customized: The authorized user will be granted with customized permissions to the object. For detailed configuration, see <a href="#obs_03_0075__li588503161565">6</a>.</li></ul>
|
||||
<div class="section" id="obs_03_0075__section1427668152517"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0075__ol3653067817298"><li id="obs_03_0075__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0075__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0075__li51927620"><span>In the navigation pane, choose <strong id="obs_03_0075__obs_03_0307_b51941856151917">Objects</strong>.</span></li><li id="obs_03_0075__li27180413161423"><span>On the right of the object to be operated, choose <strong id="obs_03_0075__b622031814208">More</strong> > <strong id="obs_03_0075__b156481323142016">Configure Object Policy</strong>. The <strong id="obs_03_0075__b1787252862012">Configure Object Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0075__li141801159171718"><span>Select a proper policy mode as required. Valid options are as follows:</span><p><ul id="obs_03_0075__ul1974615162010"><li id="obs_03_0075__li97411532015">Read-only mode: The authorized user has the read permission to the object. For follow-up procedure, see <a href="#obs_03_0075__li3552175452220">5</a>.</li><li id="obs_03_0075__li390172213204">Read and write mode: The authorized user has the read and write permissions to the object. For follow-up procedure, see <a href="#obs_03_0075__li3552175452220">5</a>.</li><li id="obs_03_0075__li4483132516202">Customized: The authorized user will be granted with customized permissions to the object. For detailed configuration, see <a href="#obs_03_0075__li588503161565">6</a>.</li></ul>
|
||||
<div class="note" id="obs_03_0075__note3389183318244"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0075__p6390333192416">You can configure only one object policy at a time.</p>
|
||||
</div></div>
|
||||
</p></li><li id="obs_03_0075__li3552175452220"><a name="obs_03_0075__li3552175452220"></a><a name="li3552175452220"></a><span>For read-only and read and write modes, enter information about the authorized user in the following format and click <strong id="obs_03_0075__b1320965261618">OK</strong>.</span><p><div class="fignone" id="obs_03_0075__fig17275162821520"><span class="figcap"><b>Figure 1 </b>Parameter settings of an object policy in the read-only or read and write mode</span><br><span><img id="obs_03_0075__image127510288156" src="en-us_image_0189257108.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
@ -17,12 +17,11 @@
|
||||
</thead>
|
||||
<tbody><tr id="obs_03_0075__row8783617122317"><td class="cellrowborder" valign="top" width="15.151515151515152%" headers="mcps1.3.2.2.5.2.2.2.4.1.1 "><p id="obs_03_0075__p478519172231">Principal</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="37.37373737373738%" headers="mcps1.3.2.2.5.2.2.2.4.1.2 "><ul id="obs_03_0075__ul278810179232"><li id="obs_03_0075__li1578941718233"><strong id="obs_03_0075__b1499114720199">Include</strong> or <strong id="obs_03_0075__b195001647151916">Exclude</strong></li><li id="obs_03_0075__li4287125223917">Cloud service user, Federated user<ul id="obs_03_0075__ul103531411807"><li id="obs_03_0075__li162698114912">If you select <strong id="obs_03_0075__b12681481385">Cloud service user</strong>, you can specify the user to be the <strong id="obs_03_0075__b1826984853817">Current account</strong> or <strong id="obs_03_0075__b52702048203815">Other account</strong>.<p id="obs_03_0075__p119889201618">If you select <strong id="obs_03_0075__b12744659724">Other account</strong>, enter the account ID, which is the <strong id="obs_03_0075__b574555913216">Domain ID</strong> on the <strong id="obs_03_0075__b5745159926">My Credential</strong> page.</p>
|
||||
</li><li id="obs_03_0075__li869675384816">If you select <strong id="obs_03_0075__b452255323811">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0075__b1252315303814">Identity provider</strong> or a <strong id="obs_03_0075__b15523155393814">User group</strong>.</li></ul>
|
||||
<td class="cellrowborder" valign="top" width="37.37373737373738%" headers="mcps1.3.2.2.5.2.2.2.4.1.2 "><ul id="obs_03_0075__ul278810179232"><li id="obs_03_0075__li1578941718233"><strong id="obs_03_0075__b1499114720199">Include</strong> or <strong id="obs_03_0075__b195001647151916">Exclude</strong></li><li id="obs_03_0075__li4287125223917">Cloud service user, Federated user<ul id="obs_03_0075__ul103531411807"><li id="obs_03_0075__li869675384816">If you select <strong id="obs_03_0075__b452255323811">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0075__b1252315303814">Identity provider</strong> or a <strong id="obs_03_0075__b15523155393814">User group</strong>.</li></ul>
|
||||
</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="47.474747474747474%" headers="mcps1.3.2.2.5.2.2.2.4.1.3 "><p id="obs_03_0075__p19808171717235">Indicates the user that the object policy applies to.</p>
|
||||
<ul id="obs_03_0075__ul25601236173218"><li id="obs_03_0075__obs_03_0049_li7880926165213"><strong id="obs_03_0075__obs_03_0049_b9396124819353">Include</strong>: Specifies the user on whom the bucket policy statement takes effect.</li><li id="obs_03_0075__obs_03_0049_li1488092635210"><strong id="obs_03_0075__obs_03_0049_b13188853163520">Exclude</strong>: Specifies that on all users except the specified user the bucket policy statement takes effect.</li></ul>
|
||||
<ul id="obs_03_0075__ul25601236173218"><li id="obs_03_0075__obs_03_0049_li7880926165213"><strong id="obs_03_0075__obs_03_0049_b1043613214332">Include</strong>: The policy takes effect on specified users.</li><li id="obs_03_0075__obs_03_0049_li1488092635210"><strong id="obs_03_0075__obs_03_0049_b1890962511336">Exclude</strong>: The policy takes effect on all users except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0075__row081741752319"><td class="cellrowborder" valign="top" width="15.151515151515152%" headers="mcps1.3.2.2.5.2.2.2.4.1.1 "><p id="obs_03_0075__p15821617102320">Resources</p>
|
||||
@ -30,7 +29,7 @@
|
||||
<td class="cellrowborder" valign="top" width="37.37373737373738%" headers="mcps1.3.2.2.5.2.2.2.4.1.2 "><p id="obs_03_0075__p882465163013"><strong id="obs_03_0075__b5961111282010">Include</strong> or <strong id="obs_03_0075__b796319127204">Exclude</strong></p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="47.474747474747474%" headers="mcps1.3.2.2.5.2.2.2.4.1.3 "><p id="obs_03_0075__p2084119170234">Resources on which the object policy takes effect.</p>
|
||||
<ul id="obs_03_0075__ul1441045823718"><li id="obs_03_0075__obs_03_0118_li1620132355317"><strong id="obs_03_0075__obs_03_0118_b184419873610">Include</strong>: Indicates that the policy takes effect only on the specified OBS resources.</li><li id="obs_03_0075__obs_03_0118_li152011423195316"><strong id="obs_03_0075__obs_03_0118_b171841311113612">Exclude</strong>: Indicates that the bucket policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
<ul id="obs_03_0075__ul1441045823718"><li id="obs_03_0075__obs_03_0118_li1620132355317"><strong id="obs_03_0075__obs_03_0118_b184419873610">Include</strong>: The policy takes effect on specified OBS resources.</li><li id="obs_03_0075__obs_03_0118_li152011423195316"><strong id="obs_03_0075__obs_03_0118_b171841311113612">Exclude</strong>: The policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
@ -51,17 +50,16 @@
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.2.2.6.2.2.2.4.1.2 "><p id="obs_03_0075__p616717174717"><strong id="obs_03_0075__b0711135462019">Allow</strong> or <strong id="obs_03_0075__b1771213544202">Deny</strong></p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.2.2.6.2.2.2.4.1.3 "><p id="obs_03_0075__p1615161923718">Effect of the object policy.</p>
|
||||
<ul id="obs_03_0075__ul415919103710"><li id="obs_03_0075__obs_03_0115_li19191705526"><strong id="obs_03_0075__obs_03_0115_b1391852611270">Allow</strong>: Indicates that access requests are allowed, if they match the configurations of the bucket policy.</li><li id="obs_03_0075__obs_03_0115_li1919150175216"><strong id="obs_03_0075__obs_03_0115_b1037794816276">Deny</strong>: Indicates that access requests are denied, if they match the configurations of the bucket policy.</li></ul>
|
||||
<ul id="obs_03_0075__ul415919103710"><li id="obs_03_0075__obs_03_0115_li19191705526"><strong id="obs_03_0075__obs_03_0115_b71561349173317">Allow</strong>: The policy allows the matched requests.</li><li id="obs_03_0075__obs_03_0115_li1919150175216"><strong id="obs_03_0075__obs_03_0115_b164762542339">Deny</strong>: The policy denies the matched requests.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0075__row46881427144542"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.2.2.6.2.2.2.4.1.1 "><p id="obs_03_0075__p39299241144542">Principal</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.2.2.6.2.2.2.4.1.2 "><ul id="obs_03_0075__ul19561211185417"><li id="obs_03_0075__li7956181185413"><strong id="obs_03_0075__b57446226218">Include</strong> or <strong id="obs_03_0075__b1745222142115">Exclude</strong></li><li id="obs_03_0075__li18810122551811">Cloud service user, Federated user<ul id="obs_03_0075__ul16810162511812"><li id="obs_03_0075__li6810225191815">If you select <strong id="obs_03_0075__b664717160398">Cloud service user</strong>, you can specify the user to be the <strong id="obs_03_0075__b1064741663914">Current account</strong> or <strong id="obs_03_0075__b1164861613399">Other account</strong>.<p id="obs_03_0075__p17218630181616">If you select <strong id="obs_03_0075__b1024981319313">Other account</strong>, enter the account ID, which is the <strong id="obs_03_0075__b1024916132316">Domain ID</strong> on the <strong id="obs_03_0075__b32507131339">My Credential</strong> page.</p>
|
||||
</li><li id="obs_03_0075__li14810625191813">If you select <strong id="obs_03_0075__b9859208399">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0075__b286102013393">Identity provider</strong> or a <strong id="obs_03_0075__b168619207395">User group</strong>.</li></ul>
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.2.2.6.2.2.2.4.1.2 "><ul id="obs_03_0075__ul19561211185417"><li id="obs_03_0075__li7956181185413"><strong id="obs_03_0075__b57446226218">Include</strong> or <strong id="obs_03_0075__b1745222142115">Exclude</strong></li><li id="obs_03_0075__li18810122551811">Cloud service user, Federated user<ul id="obs_03_0075__ul16810162511812"><li id="obs_03_0075__li14810625191813">If you select <strong id="obs_03_0075__b9859208399">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0075__b286102013393">Identity provider</strong> or a <strong id="obs_03_0075__b168619207395">User group</strong>.</li></ul>
|
||||
</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.2.2.6.2.2.2.4.1.3 "><p id="obs_03_0075__p1715111933716">Specifies users on whom this object policy takes effect, including cloud service users and federated users. A cloud service user is the one who accesses the cloud services through registration with the cloud services. A federated user is the one who accesses the cloud services through federated identity authentication.</p>
|
||||
<ul id="obs_03_0075__ul119112314313"><li id="obs_03_0075__obs_03_0049_li7880926165213_1"><strong id="obs_03_0075__obs_03_0049_b9396124819353_1">Include</strong>: Specifies the user on whom the bucket policy statement takes effect.</li><li id="obs_03_0075__obs_03_0049_li1488092635210_1"><strong id="obs_03_0075__obs_03_0049_b13188853163520_1">Exclude</strong>: Specifies that on all users except the specified user the bucket policy statement takes effect.</li></ul>
|
||||
<ul id="obs_03_0075__ul119112314313"><li id="obs_03_0075__obs_03_0049_li7880926165213_1"><strong id="obs_03_0075__obs_03_0049_b1043613214332_1">Include</strong>: The policy takes effect on specified users.</li><li id="obs_03_0075__obs_03_0049_li1488092635210_1"><strong id="obs_03_0075__obs_03_0049_b1890962511336_1">Exclude</strong>: The policy takes effect on all users except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0075__row26311294144542"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.2.2.6.2.2.2.4.1.1 "><p id="obs_03_0075__p50840088144542">Resources</p>
|
||||
@ -69,7 +67,7 @@
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.2.2.6.2.2.2.4.1.2 "><ul id="obs_03_0075__ul151711055754"><li id="obs_03_0075__li151719551252"><strong id="obs_03_0075__b188441334211">Include</strong> or <strong id="obs_03_0075__b19845133132113">Exclude</strong></li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.2.2.6.2.2.2.4.1.3 "><p id="obs_03_0075__p1016819183718">Resources on which the object policy takes effect.</p>
|
||||
<ul id="obs_03_0075__ul98281632306"><li id="obs_03_0075__obs_03_0118_li1620132355317_1"><strong id="obs_03_0075__obs_03_0118_b184419873610_1">Include</strong>: Indicates that the policy takes effect only on the specified OBS resources.</li><li id="obs_03_0075__obs_03_0118_li152011423195316_1"><strong id="obs_03_0075__obs_03_0118_b171841311113612_1">Exclude</strong>: Indicates that the bucket policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
<ul id="obs_03_0075__ul98281632306"><li id="obs_03_0075__obs_03_0118_li1620132355317_1"><strong id="obs_03_0075__obs_03_0118_b184419873610_1">Include</strong>: The policy takes effect on specified OBS resources.</li><li id="obs_03_0075__obs_03_0118_li152011423195316_1"><strong id="obs_03_0075__obs_03_0118_b171841311113612_1">Exclude</strong>: The policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0075__row461371117754"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.2.2.6.2.2.2.4.1.1 "><p id="obs_03_0075__p420595051780">Actions</p>
|
||||
@ -77,7 +75,7 @@
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.2.2.6.2.2.2.4.1.2 "><ul id="obs_03_0075__ul732518295298"><li id="obs_03_0075__li93251529122910"><strong id="obs_03_0075__b4794124413212">Include</strong> or <strong id="obs_03_0075__b479513445217">Exclude</strong></li><li id="obs_03_0075__li17137153782916">For details about the actions, see <a href="obs_03_0051.html#obs_03_0051__section387654045518">Actions Related to Objects</a>.</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.2.2.6.2.2.2.4.1.3 "><p id="obs_03_0075__p1916419183710">Operation stated in the object policy.</p>
|
||||
<ul id="obs_03_0075__ul13161219203711"><li id="obs_03_0075__obs_03_0051_li100102451519"><strong id="obs_03_0075__obs_03_0051_b125261325103613">Include</strong>: Specifies the actions on which the bucket policy takes effect.</li><li id="obs_03_0075__obs_03_0051_li73441302154"><strong id="obs_03_0075__obs_03_0051_b2084382816362">Exclude</strong>: Specifies that on all except the specified actions the bucket policy takes effect.</li></ul>
|
||||
<ul id="obs_03_0075__ul13161219203711"><li id="obs_03_0075__obs_03_0051_li100102451519"><strong id="obs_03_0075__obs_03_0051_b856171514343">Include</strong>: The policy takes effect on specified actions.</li><li id="obs_03_0075__obs_03_0051_li73441302154"><strong id="obs_03_0075__obs_03_0051_b881411181346">Exclude</strong>: The policy takes effect on all actions except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0075__row8998688144542"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.2.2.6.2.2.2.4.1.1 "><p id="obs_03_0075__p57805116144542">Conditions</p>
|
||||
|
@ -3,7 +3,7 @@
|
||||
<h1 class="topictitle1">Granting an IAM User with the Operation Permissions for a Specified Bucket</h1>
|
||||
<div id="body1557026128761"><p id="obs_03_0080__p1919519475574">Create an IAM user under in an account. The IAM user has no permission to any resource before it is added to any user group. The bucket owner (root account) or other accounts and IAM users, who have the permission to set bucket policies, can configure bucket policies to grant the bucket operation permissions to IAM users.</p>
|
||||
<p id="obs_03_0080__p2058382155214">The following is an example about how to authorize an IAM user with the bucket access and object upload permissions.</p>
|
||||
<div class="section" id="obs_03_0080__section13279211683"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0080__ol549119194012"><li id="obs_03_0080__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0080__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0080__li2836319145514"><span>In the navigation pane on the left, click <strong id="obs_03_0080__obs_03_0142_b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0080__li8120153165517"><span>Choose <strong id="obs_03_0080__b19801124353">Bucket Policies</strong> > <strong id="obs_03_0080__b880311214357">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0080__li81441540133419"><span>Click <strong id="obs_03_0080__b17165141553511">Create Bucket Policy</strong>. The <strong id="obs_03_0080__b61661215173517">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0080__li17931032163517"><span>Set the following parameters to authorize the IAM user with the permission to access the bucket (listing objects in the bucket).</span><p>
|
||||
<div class="section" id="obs_03_0080__section13279211683"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0080__ol549119194012"><li id="obs_03_0080__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0080__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0080__li2836319145514"><span>In the navigation pane, choose <strong id="obs_03_0080__obs_03_0142_b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0080__li8120153165517"><span>Choose <strong id="obs_03_0080__b19801124353">Bucket Policies</strong> > <strong id="obs_03_0080__b880311214357">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0080__li81441540133419"><span>Click <strong id="obs_03_0080__b17165141553511">Create Bucket Policy</strong>. The <strong id="obs_03_0080__b61661215173517">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0080__li17931032163517"><span>Set the following parameters to authorize the IAM user with the permission to access the bucket (listing objects in the bucket).</span><p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0080__table7531653104420" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameters for authorizing the permission to access a specified bucket</caption><thead align="left"><tr id="obs_03_0080__row2532105311447"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.3.2.5.2.1.2.3.1.1"><p id="obs_03_0080__p16532195364414">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.3.2.5.2.1.2.3.1.2"><p id="obs_03_0080__p15532145310443">Value</p>
|
||||
|
@ -7,7 +7,7 @@
|
||||
<ol id="obs_03_0081__ol7853716103516"><li id="obs_03_0081__li685301693514">Configure a bucket policy to allow IAM users to access the bucket.</li><li id="obs_03_0081__li888244323516">Configure <span id="obs_03_0081__ph135373523355">IAM policies</span> for the account to which the authorized IAM user belongs, to allow the IAM user to access the bucket.</li></ol>
|
||||
<p id="obs_03_0081__p1345162763720">Only permissions that are allowed by both the bucket policy and <span id="obs_03_0081__ph5939236183712">IAM policies</span> can take effect.</p>
|
||||
</div></div>
|
||||
<div class="section" id="obs_03_0081__section435994418812"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0081__ol549119194012"><li id="obs_03_0081__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0081__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0081__li13508181724617"><span>In the navigation pane on the left, click <strong id="obs_03_0081__obs_03_0142_b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0081__li8120153165517"><span>Choose <strong id="obs_03_0081__b942110816513">Bucket Policies</strong> > <strong id="obs_03_0081__b7422287515">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0081__li81441540133419"><span>Click <strong id="obs_03_0081__b111286107515">Create Bucket Policy</strong>. The <strong id="obs_03_0081__b14129191013513">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0081__li17931032163517"><span>Set the following parameters to authorize another account with the permission to access the bucket:</span><p>
|
||||
<div class="section" id="obs_03_0081__section435994418812"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0081__ol549119194012"><li id="obs_03_0081__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0081__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0081__li13508181724617"><span>In the navigation pane, choose <strong id="obs_03_0081__obs_03_0142_b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0081__li8120153165517"><span>Choose <strong id="obs_03_0081__b942110816513">Bucket Policies</strong> > <strong id="obs_03_0081__b7422287515">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0081__li81441540133419"><span>Click <strong id="obs_03_0081__b111286107515">Create Bucket Policy</strong>. The <strong id="obs_03_0081__b14129191013513">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0081__li17931032163517"><span>Set the following parameters to authorize another account with the permission to access the bucket:</span><p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0081__table7531653104420" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameters for authorizing the permission to access a specified bucket</caption><thead align="left"><tr id="obs_03_0081__row2532105311447"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.5.2.1.2.3.1.1"><p id="obs_03_0081__p16532195364414">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.5.2.1.2.3.1.2"><p id="obs_03_0081__p15532145310443">Value</p>
|
||||
|
@ -2,12 +2,12 @@
|
||||
|
||||
<h1 class="topictitle1">Bucket Default Encryption</h1>
|
||||
<div id="body1551323631371"><p id="obs_03_0088__p725032142814">OBS enables you to configure default encryption for a bucket. After the configuration, objects uploaded to the bucket are automatically encrypted using the specified KMS key, improving data storage security.</p>
|
||||
<p id="obs_03_0088__p855995918245">You can enable the default encryption when creating a bucket. For details, see <a href="en-us_topic_0045853662.html">Creating a Bucket</a>. You can also enable or disable the default encryption after a bucket is created.</p>
|
||||
<p id="obs_03_0088__p4926171015014">OBS encrypts only the objects uploaded after the default encryption function is enabled, and does not encrypt those uploaded before. After default encryption is disabled, the encryption status of existing objects keeps unchanged, and you can still manually encrypt objects upon upload.</p>
|
||||
<div class="section" id="obs_03_0088__section3892114117330"><h4 class="sectiontitle">Enabling Default Encryption for a Bucket</h4><ol id="obs_03_0088__ol93829311363"><li id="obs_03_0088__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0088__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0088__li18830181855820"><span>In the right <strong id="obs_03_0088__b26567116474">Basic Configurations</strong> area, click <strong id="obs_03_0088__b188978911477">Default Encryption</strong>. The <strong id="obs_03_0088__b87694251478">Default Encryption</strong> dialog box is displayed.</span></li><li id="obs_03_0088__li185861427134716"><span>Select <strong id="obs_03_0088__b158241243144713">Enable</strong>.</span><p><p id="obs_03_0088__p181834121475">Key <strong id="obs_03_0088__b309598757">obs/default</strong> is selected by default for KMS encryption. You can also click <strong id="obs_03_0088__b42672114811">Create KMS Key</strong> to switch to the management console of KMS and create customer master keys. Then back to OBS Console and select the key from the drop-down list box for KMS encryption.</p>
|
||||
<p id="obs_03_0088__p855995918245">You can enable default encryption when creating a bucket (see <a href="en-us_topic_0045853662.html">Creating a Bucket</a>), or enable or disable default encryption after a bucket is created.</p>
|
||||
<p id="obs_03_0088__p4926171015014">OBS encrypts only the objects uploaded after the default encryption is enabled, and does not encrypt those uploaded before. After default encryption is disabled, the encryption status of existing objects keeps unchanged, and you can still manually encrypt objects upon upload.</p>
|
||||
<div class="section" id="obs_03_0088__section3892114117330"><h4 class="sectiontitle">Enabling Default Encryption for a Bucket</h4><ol id="obs_03_0088__ol93829311363"><li id="obs_03_0088__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0088__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0088__li18830181855820"><span>In the right <strong id="obs_03_0088__b26567116474">Basic Configurations</strong> area, click <strong id="obs_03_0088__b188978911477">Default Encryption</strong>. The <strong id="obs_03_0088__b87694251478">Default Encryption</strong> dialog box is displayed.</span></li><li id="obs_03_0088__li185861427134716"><span>Select <strong id="obs_03_0088__b158241243144713">Enable</strong>.</span><p><p id="obs_03_0088__p181834121475">Key <strong id="obs_03_0088__b316857542">obs/default</strong> is selected by default for KMS encryption. You can also click <strong id="obs_03_0088__b42672114811">Create KMS Key</strong> to switch to the management console of KMS and create customer master keys. Then back to OBS Console and select the key from the drop-down list box for KMS encryption.</p>
|
||||
</p></li><li id="obs_03_0088__li950544814498"><span>Click <strong id="obs_03_0088__b74262294910">OK</strong>.</span></li></ol>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0088__section1434134116310"><h4 class="sectiontitle">Disabling Default Encryption for a Bucket</h4><ol id="obs_03_0088__ol03353441319"><li id="obs_03_0088__li1933611448318"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0088__obs_03_0307_b1395123914108_1">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0088__li11336244153118"><span>In the right <strong id="obs_03_0088__b1365043122112">Basic Configurations</strong> area, click <strong id="obs_03_0088__b5651153142118">Default Encryption</strong>. The <strong id="obs_03_0088__b26513319217">Default Encryption</strong> dialog box is displayed.</span></li><li id="obs_03_0088__li18336114433120"><span>Select <strong id="obs_03_0088__b842352706195129">Disable</strong>.</span></li><li id="obs_03_0088__li93366443315"><span>Click <strong id="obs_03_0088__b1845125900">OK</strong>.</span></li></ol>
|
||||
<div class="section" id="obs_03_0088__section1434134116310"><h4 class="sectiontitle">Disabling Default Encryption for a Bucket</h4><ol id="obs_03_0088__ol03353441319"><li id="obs_03_0088__li1933611448318"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0088__obs_03_0307_b1395123914108_1">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0088__li11336244153118"><span>In the right <strong id="obs_03_0088__b1365043122112">Basic Configurations</strong> area, click <strong id="obs_03_0088__b5651153142118">Default Encryption</strong>. The <strong id="obs_03_0088__b26513319217">Default Encryption</strong> dialog box is displayed.</span></li><li id="obs_03_0088__li18336114433120"><span>Select <strong id="obs_03_0088__b711113614154">Disable</strong>.</span></li><li id="obs_03_0088__li93366443315"><span>Click <strong id="obs_03_0088__b931448065">OK</strong>.</span></li></ol>
|
||||
</div>
|
||||
</div>
|
||||
<div>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Authorizing Folder Access Permissions to Anonymous Users</h1>
|
||||
<div id="body1557026128762"><p id="obs_03_0096__p517314258104">If all objects in a folder need to be accessible to anonymous users, you can configure a bucket policy or an object policy to grant anonymous users the permission to access the folder. In this example, a bucket policy is used. If you want to use an object policy to authorize the permission, select the target folder and configure the object policy directly. Parameters are the same as those in the bucket policy.</p>
|
||||
<div class="section" id="obs_03_0096__section17557163019204"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0096__en-us_topic_0056349953_ol62991470"><li id="obs_03_0096__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0096__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0096__li19853957175612"><span>In the navigation pane on the left, click <strong id="obs_03_0096__obs_03_0142_b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0096__li8120153165517"><span>Choose <strong id="obs_03_0096__b23113213129">Bucket Policies</strong> > <strong id="obs_03_0096__b19512328126">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0096__li81441540133419"><span>Click <strong id="obs_03_0096__b4839432131212">Create Bucket Policy</strong>. The <strong id="obs_03_0096__b984273212127">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0096__li17931032163517"><span>Configure parameters according to the following table, so that you can grant anonymous users the permission to access the folder and objects in it:</span><p>
|
||||
<div class="section" id="obs_03_0096__section17557163019204"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0096__en-us_topic_0056349953_ol62991470"><li id="obs_03_0096__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0096__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0096__li19853957175612"><span>In the navigation pane, choose <strong id="obs_03_0096__obs_03_0142_b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0096__li8120153165517"><span>Choose <strong id="obs_03_0096__b23113213129">Bucket Policies</strong> > <strong id="obs_03_0096__b19512328126">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0096__li81441540133419"><span>Click <strong id="obs_03_0096__b4839432131212">Create Bucket Policy</strong>. The <strong id="obs_03_0096__b984273212127">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0096__li17931032163517"><span>Configure parameters according to the following table, so that you can grant anonymous users the permission to access the folder and objects in it:</span><p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0096__table7531653104420" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameters for authorizing the permission to access a specified bucket</caption><thead align="left"><tr id="obs_03_0096__row2532105311447"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.5.2.1.2.3.1.1"><p id="obs_03_0096__p16532195364414">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.5.2.1.2.3.1.2"><p id="obs_03_0096__p15532145310443">Value</p>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Effect</h1>
|
||||
<div id="body1557026128761"><p id="obs_03_0115__p01900020523">A bucket policy can either allow or deny the access requests that match the configuration.</p>
|
||||
<ul id="obs_03_0115__ul13190140125211"><li id="obs_03_0115__li19191705526"><strong id="obs_03_0115__b1391852611270">Allow</strong>: Indicates that access requests are allowed, if they match the configurations of the bucket policy.</li><li id="obs_03_0115__li1919150175216"><strong id="obs_03_0115__b1037794816276">Deny</strong>: Indicates that access requests are denied, if they match the configurations of the bucket policy.</li></ul>
|
||||
<ul id="obs_03_0115__ul13190140125211"><li id="obs_03_0115__li19191705526"><strong id="obs_03_0115__b71561349173317">Allow</strong>: The policy allows the matched requests.</li><li id="obs_03_0115__li1919150175216"><strong id="obs_03_0115__b164762542339">Deny</strong>: The policy denies the matched requests.</li></ul>
|
||||
<p id="obs_03_0115__p81913025212">When a bucket policy contains both the allow and deny effects, the deny effect prevails. The following figure shows the judgment process.</p>
|
||||
<div class="fignone" id="obs_03_0115__fig15111849151"><span class="figcap"><b>Figure 1 </b>Determining a bucket policy when the allow and deny statements conflict</span><br><span><img id="obs_03_0115__image16657105175215" src="en-us_image_0168267011.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
<ol id="obs_03_0115__ol1419115017523"><li id="obs_03_0115__li1819140165214">A user initiates an access request.</li><li id="obs_03_0115__li5191130145215">OBS preferentially searches for deny (explicit deny) effects from bucket policies. If a deny statement is found, OBS directly rejects the access. The access request ends.</li><li id="obs_03_0115__li171912001523">If there is no deny statement, OBS searches for allow statements.<ul id="obs_03_0115__ul91915075212"><li id="obs_03_0115__li1919160165214">If an allow statement is found, OBS allows the access.</li><li id="obs_03_0115__li1719119025211">If no allow statement is found, OBS rejects the access. The access request ends.</li></ul>
|
||||
|
@ -3,7 +3,7 @@
|
||||
<h1 class="topictitle1">Resources</h1>
|
||||
<div id="body1557026128761"><p id="obs_03_0118__p27361558140">The resource can be the current entire bucket, an object, or a set of objects in the bucket.</p>
|
||||
<p id="obs_03_0118__p3201152310539">Resources can be specified in either of the following ways:</p>
|
||||
<ul id="obs_03_0118__ul18201323125311"><li id="obs_03_0118__li1620132355317"><strong id="obs_03_0118__b184419873610">Include</strong>: Indicates that the policy takes effect only on the specified OBS resources.</li><li id="obs_03_0118__li152011423195316"><strong id="obs_03_0118__b171841311113612">Exclude</strong>: Indicates that the bucket policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
<ul id="obs_03_0118__ul18201323125311"><li id="obs_03_0118__li1620132355317"><strong id="obs_03_0118__b184419873610">Include</strong>: The policy takes effect on specified OBS resources.</li><li id="obs_03_0118__li152011423195316"><strong id="obs_03_0118__b171841311113612">Exclude</strong>: The policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
<div class="section" id="obs_03_0118__section530512714414"><h4 class="sectiontitle">Specifying Bucket Resources</h4><p id="obs_03_0118__p7692111610414">To specify the current bucket as the resource, keep the resource text box empty. When configuring actions for the policy, select bucket related actions.</p>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0118__section20650152864119"><h4 class="sectiontitle">Specifying Object Resources</h4><p id="obs_03_0118__p1020118236532">When objects in the bucket are specified as the resources, actions configured in the bucket policy must be object related actions. The following are examples of how to specify objects as resources.</p>
|
||||
|
@ -1,14 +1,14 @@
|
||||
<a name="obs_03_0122"></a><a name="obs_03_0122"></a>
|
||||
|
||||
<h1 class="topictitle1">Creating a User and Granting OBS Permissions</h1>
|
||||
<h1 class="topictitle1">Creating an IAM User and Granting OBS Permissions</h1>
|
||||
<div id="body1558061572625"><div class="section" id="obs_03_0122__section35143124418"><h4 class="sectiontitle">Process</h4><div class="fignone" id="obs_03_0122__fig292324264713"><span class="figcap"><b>Figure 1 </b>Process of granting an IAM user the OBS permissions</span><br><span><img id="obs_03_0122__image12924124212474" src="en-us_image_0170301902.png"></span></div>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0122__section2074420567337"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0122__ol63831030102"><li id="obs_03_0122__li35354147174321"><span>Log in to the management console using a cloud service account.</span></li><li id="obs_03_0122__li5853192561010"><span>On the top navigation menu, choose <strong id="obs_03_0122__b19603113671814">Service List</strong> > <strong id="obs_03_0122__b3603103615186">Management & Deployment</strong> > <strong id="obs_03_0122__b460310368184">Identity and Access Management</strong>. The IAM console page is displayed.</span></li><li id="obs_03_0122__li257313485116"><span>Create a user group and grant the OBS permissions to the user group.</span><p><div class="p" id="obs_03_0122__p371751915195">User groups facilitate centralized user management and streamlined permissions management. Users in the same user group have the same permissions. Users created in IAM inherit permissions from the groups to which they belong.<ol type="a" id="obs_03_0122__ol28671118201912"><li id="obs_03_0122__li78661718151913">In the navigation pane on the left, click <strong id="obs_03_0122__b17624165682216">User Groups</strong>. The <strong id="obs_03_0122__b4625115617224">User Groups</strong> page is displayed.</li><li id="obs_03_0122__li286617189195">Click <span class="uicontrol" id="obs_03_0122__uicontrol230942777211457"><b>Create User Group</b></span>.</li><li id="obs_03_0122__li1886641801917">On the <strong id="obs_03_0122__b1190011522266">Create User Group</strong> page, enter a name for the user group and click <strong id="obs_03_0122__b7542112222713">OK</strong>.<p id="obs_03_0122__p3866171841910">The user group is displayed in the user group list once the creation completes.</p>
|
||||
</li><li id="obs_03_0122__li19866191819199">Click <strong id="obs_03_0122__b1406172416567">Modify</strong> in the <strong id="obs_03_0122__b12813112718562">Operation</strong> column of the row where the created user group resides.</li><li id="obs_03_0122__li1286721818193">In the <strong id="obs_03_0122__b1813981018595">Group Permissions</strong> area, locate <strong id="obs_03_0122__b166361281309">OBS (S3)</strong>, click <strong id="obs_03_0122__b145811817302">Attach Policy</strong> in the <strong id="obs_03_0122__b151884218015">Operation</strong> column, select the policy name, and click <strong id="obs_03_0122__b112537337019">OK</strong>.<div class="note" id="obs_03_0122__note12867161811198"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0122__p128671018121916">In the <strong id="obs_03_0122__b1318212383618">Policy Information</strong> area, you can view the details about the policy.</p>
|
||||
<div class="section" id="obs_03_0122__section2074420567337"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0122__ol63831030102"><li id="obs_03_0122__li35354147174321"><span>Log in to the management console with your account.</span></li><li id="obs_03_0122__li5853192561010"><span>On the top menu bar, choose <strong id="obs_03_0122__b149371518121613">Service List</strong> > <strong id="obs_03_0122__b29379189163">Management & Deployment</strong> > <strong id="obs_03_0122__b1293761819168">Identity and Access Management</strong>. The IAM console is displayed.</span></li><li id="obs_03_0122__li257313485116"><span>Create a user group and assign OBS permissions to it.</span><p><div class="p" id="obs_03_0122__p371751915195">A user group is a collection of users. By assigning permissions to a user group, you assign permissions to the users in this group. After you create an IAM user, add it to one or more user groups, so that it can inherit the permissions from the groups.<ol type="a" id="obs_03_0122__ol28671118201912"><li id="obs_03_0122__li78661718151913">In the navigation pane, choose <strong id="obs_03_0122__b0624202611174">User Groups</strong>. The <strong id="obs_03_0122__b8624112618178">User Groups</strong> page is displayed.</li><li id="obs_03_0122__li286617189195">Click <span class="uicontrol" id="obs_03_0122__uicontrol230942777211457"><b>Create User Group</b></span>.</li><li id="obs_03_0122__li1886641801917">Enter a user group name and click <strong id="obs_03_0122__b779483571714">OK</strong>.<p id="obs_03_0122__p3866171841910">The user group is displayed in the user group list once the creation is complete.</p>
|
||||
</li><li id="obs_03_0122__li19866191819199">Locate the user group you created and click <strong id="obs_03_0122__b834625118178">Modify</strong> in the <strong id="obs_03_0122__b19346105117174">Operation</strong> column of the row.</li><li id="obs_03_0122__li1286721818193">In the <strong id="obs_03_0122__b1813981018595">Group Permissions</strong> area, locate <strong id="obs_03_0122__b166361281309">OBS (S3)</strong>, click <strong id="obs_03_0122__b145811817302">Attach Policy</strong> in the <strong id="obs_03_0122__b151884218015">Operation</strong> column, select the policy name, and click <strong id="obs_03_0122__b112537337019">OK</strong>.<div class="note" id="obs_03_0122__note12867161811198"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0122__p128671018121916">In the <strong id="obs_03_0122__b1318212383618">Policy Information</strong> area, you can view the details about the policy.</p>
|
||||
</div></div>
|
||||
</li></ol>
|
||||
</div>
|
||||
</p></li><li id="obs_03_0122__li17712194912"><span>Create a user.</span><p><ol type="a" id="obs_03_0122__ol6893174016015"><li id="obs_03_0122__li84578140715">In the navigation pane on the left, click <strong id="obs_03_0122__b332175483617">Users</strong>. The <strong id="obs_03_0122__b832320546366">Users</strong> page is displayed.</li><li id="obs_03_0122__li75875232719">Click <strong id="obs_03_0122__b16239139183714">Create User</strong>.</li><li id="obs_03_0122__li08941740305">Set user information and click <strong id="obs_03_0122__b897712100378">Next</strong>.
|
||||
</p></li><li id="obs_03_0122__li17712194912"><span>Create a user.</span><p><ol type="a" id="obs_03_0122__ol6893174016015"><li id="obs_03_0122__li84578140715">In the navigation pane, choose <strong id="obs_03_0122__b1645363019241">Users</strong>. The <strong id="obs_03_0122__b174541830102416">Users</strong> page is displayed.</li><li id="obs_03_0122__li75875232719">Click <strong id="obs_03_0122__b16239139183714">Create User</strong>.</li><li id="obs_03_0122__li08941740305">Set user information and click <strong id="obs_03_0122__b897712100378">Next</strong>.
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0122__table127131345071" frame="border" border="1" rules="all"><caption><b>Table 1 </b>User parameters</caption><thead align="left"><tr id="obs_03_0122__row4714144517714"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.4.2.1.3.2.2.3.1.1"><p id="obs_03_0122__p137145451578">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.4.2.1.3.2.2.3.1.2"><p id="obs_03_0122__p1071417451679">Description</p>
|
||||
|
@ -3,7 +3,7 @@
|
||||
<h1 class="topictitle1">Configuring a Custom Bucket Policy (Common Mode)</h1>
|
||||
<div id="body1499753333226"><p class="MsoNormal" id="obs_03_0123__p398813105457">If you want to grant special permissions to specific users, you can configure custom bucket policies. If a standard bucket policy conflicts with a custom bucket policy, the authorization priority is given to the custom bucket policy and then the standard bucket policy.</p>
|
||||
<p class="MsoNormal" id="obs_03_0123__p3712241">This topic describes how to configure a custom bucket policy in common mode (GUI).</p>
|
||||
<div class="section" id="obs_03_0123__section1761505716442"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0123__ol2431779016442"><li id="obs_03_0123__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0123__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0123__li13508181724617"><span>In the navigation pane on the left, click <strong id="obs_03_0123__obs_03_0142_b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0123__li1568715376490"><span>On the <strong id="obs_03_0123__b25185174103">Bucket Policies</strong> tab page, configure a custom bucket policy according to your needs.</span><p><p id="obs_03_0123__p173901896189">On the right of <strong id="obs_03_0123__b9368111971014">Custom Bucket Policies</strong>, select <strong id="obs_03_0123__b536961911101">Common mode</strong> to configure the policy in the GUI mode.</p>
|
||||
<div class="section" id="obs_03_0123__section1761505716442"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0123__ol2431779016442"><li id="obs_03_0123__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0123__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0123__li13508181724617"><span>In the navigation pane, choose <strong id="obs_03_0123__obs_03_0142_b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0123__li1568715376490"><span>On the <strong id="obs_03_0123__b25185174103">Bucket Policies</strong> tab page, configure a custom bucket policy according to your needs.</span><p><p id="obs_03_0123__p173901896189">On the right of <strong id="obs_03_0123__b9368111971014">Custom Bucket Policies</strong>, select <strong id="obs_03_0123__b536961911101">Common mode</strong> to configure the policy in the GUI mode.</p>
|
||||
</p></li><li id="obs_03_0123__li1948691455110"><span>Click <strong id="obs_03_0123__b19810858145319">Create Bucket Policy</strong>. Select a proper policy mode as required. Valid values are as follows:</span><p><ul id="obs_03_0123__ul6489914125113"><li id="obs_03_0123__li194921514175111"><strong id="obs_03_0123__b125231032193417">Read-only</strong>: The authorized user will be granted with the read permission on the bucket and objects. For subsequent operations, see <a href="#obs_03_0123__li3552175452220">5</a>.</li><li id="obs_03_0123__li1949713143512"><strong id="obs_03_0123__b8639102763418">Read and write</strong>: The authorized user will be granted with read and write permissions on the bucket and objects. For subsequent operations, see <a href="#obs_03_0123__li3552175452220">5</a>.</li><li id="obs_03_0123__li17501101418511"><strong id="obs_03_0123__b15554073410">Customized</strong>: The authorized user will be granted with customized permissions on the bucket and objects. For detailed configuration, see <a href="#obs_03_0123__li588503161565">6</a>.</li></ul>
|
||||
<div class="note" id="obs_03_0123__note650419148512"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0123__p20506131415113">Only one bucket policy mode can be configured at a time.</p>
|
||||
</div></div>
|
||||
@ -19,12 +19,11 @@
|
||||
</thead>
|
||||
<tbody><tr id="obs_03_0123__row8783617122317"><td class="cellrowborder" valign="top" width="15.151515151515152%" headers="mcps1.3.3.2.5.2.2.2.4.1.1 "><p id="obs_03_0123__p478519172231">Principal</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="37.37373737373738%" headers="mcps1.3.3.2.5.2.2.2.4.1.2 "><ul id="obs_03_0123__ul278810179232"><li id="obs_03_0123__li1578941718233"><strong id="obs_03_0123__b8700129123916">Include</strong> or <strong id="obs_03_0123__b13701149143915">Exclude</strong></li><li id="obs_03_0123__li14773155954215"><strong id="obs_03_0123__b20217128143219">Cloud service user</strong>, <strong id="obs_03_0123__b3946133123218">Federated user</strong><ul id="obs_03_0123__ul15575185754819"><li id="obs_03_0123__li162698114912">If you select <strong id="obs_03_0123__b1719003851715">Cloud service user</strong>, you can specify the user to be the <strong id="obs_03_0123__b13691182461815">Current account</strong> or <strong id="obs_03_0123__b811012284185">Other account</strong>.<p id="obs_03_0123__p6813111014299">If you select <strong id="obs_03_0123__b19285104818530">Other account</strong>, enter the account ID, which is the <strong id="obs_03_0123__b1854913415546">Domain ID</strong> on the <strong id="obs_03_0123__b314165115542">My Credential</strong> page.</p>
|
||||
</li><li id="obs_03_0123__li869675384816">If you select <strong id="obs_03_0123__b10799136191814">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0123__b14629912194">Identity provider</strong> or a <strong id="obs_03_0123__b1312311791912">User group</strong>.</li></ul>
|
||||
<td class="cellrowborder" valign="top" width="37.37373737373738%" headers="mcps1.3.3.2.5.2.2.2.4.1.2 "><ul id="obs_03_0123__ul278810179232"><li id="obs_03_0123__li1578941718233"><strong id="obs_03_0123__b8700129123916">Include</strong> or <strong id="obs_03_0123__b13701149143915">Exclude</strong></li><li id="obs_03_0123__li14773155954215"><strong id="obs_03_0123__b20217128143219">Cloud service user</strong>, <strong id="obs_03_0123__b3946133123218">Federated user</strong><ul id="obs_03_0123__ul15575185754819"><li id="obs_03_0123__li869675384816">If you select <strong id="obs_03_0123__b10799136191814">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0123__b14629912194">Identity provider</strong> or a <strong id="obs_03_0123__b1312311791912">User group</strong>.</li></ul>
|
||||
</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="47.474747474747474%" headers="mcps1.3.3.2.5.2.2.2.4.1.3 "><p id="obs_03_0123__p19808171717235">Specifies users on whom this bucket policy takes effect, including cloud service users and federated users. A cloud service user is the one who accesses the cloud services through registration with the cloud services. A federated user is the one who accesses the cloud services through federated identity authentication.</p>
|
||||
<ul id="obs_03_0123__ul20673512167"><li id="obs_03_0123__li9670511619"><strong id="obs_03_0123__b1104616143714">Include</strong>: Specifies the user on whom the bucket policy statement takes effect.</li><li id="obs_03_0123__li479685931620"><strong id="obs_03_0123__b970317196371">Exclude</strong>: Specifies that on all users except the specified user the bucket policy statement takes effect.</li></ul>
|
||||
<ul id="obs_03_0123__ul20673512167"><li id="obs_03_0123__li9670511619"><strong id="obs_03_0123__b494418244">Include</strong>: The policy takes effect on specified users.</li><li id="obs_03_0123__li479685931620"><strong id="obs_03_0123__b16400068242">Exclude</strong>: The policy takes effect on all users except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0123__row081741752319"><td class="cellrowborder" valign="top" width="15.151515151515152%" headers="mcps1.3.3.2.5.2.2.2.4.1.1 "><p id="obs_03_0123__p15821617102320">Resources</p>
|
||||
@ -34,7 +33,7 @@
|
||||
</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="47.474747474747474%" headers="mcps1.3.3.2.5.2.2.2.4.1.3 "><p id="obs_03_0123__p2084119170234">Indicates the resource that a bucket policy applies to. With the read-only mode and read and write mode, the policy can only apply to objects.</p>
|
||||
<ul id="obs_03_0123__ul7274173411710"><li id="obs_03_0123__li7274634171715"><strong id="obs_03_0123__b24951819019">Include</strong>: Specifies the OBS resources on which the bucket policy statement takes effect.</li><li id="obs_03_0123__li260555313171"><strong id="obs_03_0123__b172155361308">Exclude</strong>: Specifies that on all OBS resources except the specified ones the bucket policy statement takes effect.</li></ul>
|
||||
<ul id="obs_03_0123__ul7274173411710"><li id="obs_03_0123__li7274634171715"><strong id="obs_03_0123__b24951819019">Include</strong>: The policy takes effect on the specified OBS resources.</li><li id="obs_03_0123__li260555313171"><strong id="obs_03_0123__b172155361308">Exclude</strong>: The policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
@ -55,17 +54,16 @@
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.2 "><p id="obs_03_0123__p616717174717"><strong id="obs_03_0123__b97561137113311">Allow</strong> or <strong id="obs_03_0123__b135788406338">Deny</strong></p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.3 "><p id="obs_03_0123__p04354171543">Effect of a bucket policy.</p>
|
||||
<ul id="obs_03_0123__ul1835191314190"><li id="obs_03_0123__li159861027191911"><strong id="obs_03_0123__b1391852611270">Allow</strong>: Indicates access requests are allowed, if they match the configurations of this bucket policy.</li><li id="obs_03_0123__li18986102701916"><strong id="obs_03_0123__b1037794816276">Deny</strong>: Indicates access requests are denied, if they match the configurations of this bucket policy.</li></ul>
|
||||
<ul id="obs_03_0123__ul1835191314190"><li id="obs_03_0123__li159861027191911"><strong id="obs_03_0123__b17812850122611">Allow</strong>: The policy allows the matched requests.</li><li id="obs_03_0123__li18986102701916"><strong id="obs_03_0123__b170015412269">Deny</strong>: The policy denies the matched requests.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0123__row46881427144542"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.1 "><p id="obs_03_0123__p39299241144542">Principal</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.2 "><ul id="obs_03_0123__ul19561211185417"><li id="obs_03_0123__li7956181185413"><strong id="obs_03_0123__b830025419431">Include</strong> or <strong id="obs_03_0123__b030075414316">Exclude</strong></li><li id="obs_03_0123__li4287125223917"><strong id="obs_03_0123__b19619115514331">Cloud service user</strong>, <strong id="obs_03_0123__b1769811573338">Federated user</strong><ul id="obs_03_0123__ul3534111145812"><li id="obs_03_0123__li762319816581">If you select <strong id="obs_03_0123__b12105540112018">Cloud service user</strong>, you can specify the user to be the <strong id="obs_03_0123__b15106124020204">Current account</strong> or <strong id="obs_03_0123__b19107540182019">Other account</strong>.<p id="obs_03_0123__p27327479313">If you select <strong id="obs_03_0123__b22846587544">Other account</strong>, enter the account ID, which is the <strong id="obs_03_0123__b429005865414">Domain ID</strong> on the <strong id="obs_03_0123__b1529085812541">My Credential</strong> page.</p>
|
||||
</li><li id="obs_03_0123__li8623685589">If you select <strong id="obs_03_0123__b11332843172011">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0123__b18332134322012">Identity provider</strong> or a <strong id="obs_03_0123__b1133313438201">User group</strong>.</li></ul>
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.2 "><ul id="obs_03_0123__ul19561211185417"><li id="obs_03_0123__li7956181185413"><strong id="obs_03_0123__b830025419431">Include</strong> or <strong id="obs_03_0123__b030075414316">Exclude</strong></li><li id="obs_03_0123__li4287125223917"><strong id="obs_03_0123__b19619115514331">Cloud service user</strong>, <strong id="obs_03_0123__b1769811573338">Federated user</strong><ul id="obs_03_0123__ul3534111145812"><li id="obs_03_0123__li8623685589">If you select <strong id="obs_03_0123__b11332843172011">Federated user</strong>, you can specify the user to be an <strong id="obs_03_0123__b18332134322012">Identity provider</strong> or a <strong id="obs_03_0123__b1133313438201">User group</strong>.</li></ul>
|
||||
</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.3 "><p id="obs_03_0123__p243601717416">Specifies users on whom this bucket policy takes effect, including cloud service users and federated users. A cloud service user is the one who accesses the cloud services through registration with the cloud services. A federated user is the one who accesses the cloud services through federated identity authentication.</p>
|
||||
<ul id="obs_03_0123__ul101874512014"><li id="obs_03_0123__li121871259206"><strong id="obs_03_0123__b5139722814">Include</strong>: Specifies the user on whom the bucket policy statement takes effect.</li><li id="obs_03_0123__li61876510206"><strong id="obs_03_0123__b148526316218">Exclude</strong>: Specifies that on all users except the specified user the bucket policy takes effect.</li></ul>
|
||||
<ul id="obs_03_0123__ul101874512014"><li id="obs_03_0123__li121871259206"><strong id="obs_03_0123__b1024293172719">Include</strong>: The policy takes effect on specified users.</li><li id="obs_03_0123__li61876510206"><strong id="obs_03_0123__b119859613272">Exclude</strong>: The policy takes effect on all users except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0123__row26311294144542"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.1 "><p id="obs_03_0123__p50840088144542">Resources</p>
|
||||
@ -76,7 +74,7 @@
|
||||
</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.3 "><p id="obs_03_0123__p144361117943">Indicates the resource that a bucket policy applies to.</p>
|
||||
<ul id="obs_03_0123__ul1243923162015"><li id="obs_03_0123__li114312316201"><strong id="obs_03_0123__b865918341216">Include</strong>: Specifies the OBS resources on which the bucket policy statement takes effect.</li><li id="obs_03_0123__li1943152318208"><strong id="obs_03_0123__b944620361117">Exclude</strong>: Specifies that on all OBS resources except the specified ones the bucket policy statement takes effect.</li></ul>
|
||||
<ul id="obs_03_0123__ul1243923162015"><li id="obs_03_0123__li114312316201"><strong id="obs_03_0123__b71952054152719">Include</strong>: The policy takes effect on the specified OBS resources.</li><li id="obs_03_0123__li1943152318208"><strong id="obs_03_0123__b137062594278">Exclude</strong>: The policy takes effect on all OBS resources except the specified ones.</li></ul>
|
||||
<p id="obs_03_0123__p24361917944">Relationship between resource types and actions:</p>
|
||||
<ul id="obs_03_0123__ul1943618171341"><li id="obs_03_0123__li94361117243">When a resource is an object or an object set, only the actions related to the object can be configured.</li><li id="obs_03_0123__li144361817143">When the resource is a bucket, only the actions related to the bucket can be configured.</li></ul>
|
||||
</td>
|
||||
@ -86,7 +84,7 @@
|
||||
<td class="cellrowborder" valign="top" width="34.343434343434346%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.2 "><ul id="obs_03_0123__ul732518295298"><li id="obs_03_0123__li93251529122910"><strong id="obs_03_0123__b2283202443">Include</strong> or <strong id="obs_03_0123__b1929620114413">Exclude</strong></li><li id="obs_03_0123__li17137153782916">For details, see <a href="obs_03_0051.html">Actions</a>.</li></ul>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="45.45454545454546%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.3 "><p id="obs_03_0123__p114369173413">Operations stated in the bucket policy.</p>
|
||||
<ul id="obs_03_0123__ul172495822013"><li id="obs_03_0123__li7724458102010"><strong id="obs_03_0123__b6426853183718">Include</strong>: Specifies the actions on which the bucket policy takes effect.</li><li id="obs_03_0123__li47248585207"><strong id="obs_03_0123__b10431155616372">Exclude</strong>: Specifies that on all actions except the specified ones the bucket policy takes effect.</li></ul>
|
||||
<ul id="obs_03_0123__ul172495822013"><li id="obs_03_0123__li7724458102010"><strong id="obs_03_0123__b23784148281">Include</strong>: The policy takes effect on specified actions.</li><li id="obs_03_0123__li47248585207"><strong id="obs_03_0123__b41061220162820">Exclude</strong>: The policy takes effect on all actions except the specified ones.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0123__row8998688144542"><td class="cellrowborder" valign="top" width="20.202020202020204%" headers="mcps1.3.3.2.6.2.2.2.2.4.1.1 "><p id="obs_03_0123__p57805116144542">Conditions</p>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Restricting Bucket Access to a Specified Address </h1>
|
||||
<div id="body1557026128761"><p id="obs_03_0130__p5170135082114">You can configure a bucket policy to authorize a specified address the permission to access the bucket. This example shows how to deny a client access whose source IP address is within the range of 114.115.1.0/24.</p>
|
||||
<div class="section" id="obs_03_0130__section17557163019204"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0130__en-us_topic_0056349953_ol62991470"><li id="obs_03_0130__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0130__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0130__li077741015611"><span>In the navigation pane on the left, click <strong id="obs_03_0130__obs_03_0142_b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0130__li8120153165517"><span>Choose <strong id="obs_03_0130__b21707295505">Bucket Policies</strong> > <strong id="obs_03_0130__b317132914502">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0130__li81441540133419"><span>Click <strong id="obs_03_0130__b41911130175020">Create Bucket Policy</strong>. The <strong id="obs_03_0130__b8192230125013">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0130__li17931032163517"><span>Configure the parameters according to the following table:</span><p>
|
||||
<div class="section" id="obs_03_0130__section17557163019204"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0130__en-us_topic_0056349953_ol62991470"><li id="obs_03_0130__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0130__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0130__li077741015611"><span>In the navigation pane, choose <strong id="obs_03_0130__obs_03_0142_b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0130__li8120153165517"><span>Choose <strong id="obs_03_0130__b21707295505">Bucket Policies</strong> > <strong id="obs_03_0130__b317132914502">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0130__li81441540133419"><span>Click <strong id="obs_03_0130__b41911130175020">Create Bucket Policy</strong>. The <strong id="obs_03_0130__b8192230125013">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0130__li17931032163517"><span>Configure the parameters according to the following table:</span><p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0130__table7531653104420" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameters for authorizing the permission to access a specified bucket</caption><thead align="left"><tr id="obs_03_0130__row2532105311447"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.5.2.1.2.3.1.1"><p id="obs_03_0130__p16532195364414">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.5.2.1.2.3.1.2"><p id="obs_03_0130__p15532145310443">Value</p>
|
||||
@ -36,7 +36,7 @@
|
||||
</tr>
|
||||
<tr id="obs_03_0130__row3328954204119"><td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.2.2.5.2.1.2.3.1.1 "><p id="obs_03_0130__p2329115416419">Conditions</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.2.2.5.2.1.2.3.1.2 "><ul id="obs_03_0130__ul4774185114612"><li id="obs_03_0130__li177741358462"><strong id="obs_03_0130__b871608476">Conditional Operator</strong>: <strong id="obs_03_0130__b282076241">IpAddress</strong></li><li id="obs_03_0130__li1764818167461"><strong id="obs_03_0130__b1088670443">Key</strong>: <strong id="obs_03_0130__b1865513592">SourceIP</strong></li><li id="obs_03_0130__li295412744610"><strong id="obs_03_0130__b1912124816313">Value</strong>: <strong id="obs_03_0130__b158527333177">114.115.1.0/24</strong></li></ul>
|
||||
<td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.2.2.5.2.1.2.3.1.2 "><ul id="obs_03_0130__ul4774185114612"><li id="obs_03_0130__li177741358462"><strong id="obs_03_0130__b252267374">Conditional Operator</strong>: <strong id="obs_03_0130__b1317813735">IpAddress</strong></li><li id="obs_03_0130__li1764818167461"><strong id="obs_03_0130__b502935696">Key</strong>: <strong id="obs_03_0130__b545707728">SourceIP</strong></li><li id="obs_03_0130__li295412744610"><strong id="obs_03_0130__b1912124816313">Value</strong>: <strong id="obs_03_0130__b158527333177">114.115.1.0/24</strong></li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Configuring the Start Time and End Time of Access to Objects in a Bucket</h1>
|
||||
<div id="body1557026128762"><p id="obs_03_0131__p13527855125217">You can configure the bucket policy to limit the time when objects in a bucket are accessible. In the following example, the access time window is from 2019-03-26T12:00:00Z to 2019-03-26T15:00:00Z.</p>
|
||||
<div class="section" id="obs_03_0131__section17557163019204"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0131__en-us_topic_0056349953_ol62991470"><li id="obs_03_0131__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0131__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0131__li141322034115610"><span>In the navigation pane on the left, click <strong id="obs_03_0131__obs_03_0142_b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0131__li8120153165517"><span>Choose <strong id="obs_03_0131__b07801117125512">Bucket Policies</strong> > <strong id="obs_03_0131__b1778211712552">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0131__li81441540133419"><span>Click <strong id="obs_03_0131__b69922018185512">Create Bucket Policy</strong>. The <strong id="obs_03_0131__b17993141811550">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0131__li17931032163517"><span>Configure the parameters according to the following table:</span><p>
|
||||
<div class="section" id="obs_03_0131__section17557163019204"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0131__en-us_topic_0056349953_ol62991470"><li id="obs_03_0131__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0131__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0131__li141322034115610"><span>In the navigation pane, choose <strong id="obs_03_0131__obs_03_0142_b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0131__li8120153165517"><span>Choose <strong id="obs_03_0131__b07801117125512">Bucket Policies</strong> > <strong id="obs_03_0131__b1778211712552">Custom Bucket Policies</strong>.</span></li><li id="obs_03_0131__li81441540133419"><span>Click <strong id="obs_03_0131__b69922018185512">Create Bucket Policy</strong>. The <strong id="obs_03_0131__b17993141811550">Create Bucket Policy</strong> dialog box is displayed.</span></li><li id="obs_03_0131__li17931032163517"><span>Configure the parameters according to the following table:</span><p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0131__table7531653104420" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameters for authorizing the permission to access a specified bucket</caption><thead align="left"><tr id="obs_03_0131__row2532105311447"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.5.2.1.2.3.1.1"><p id="obs_03_0131__p16532195364414">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.2.2.5.2.1.2.3.1.2"><p id="obs_03_0131__p15532145310443">Value</p>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Configuring a Standard Bucket Policy</h1>
|
||||
<div id="body1559010359272"><p id="obs_03_0142__p8060118">For standard bucket policy, OBS offers three options, namely the Private, Public Read, and Public Read and Write policies. These policies are pre-defined and can be applied with a few clicks.</p>
|
||||
<div class="section" id="obs_03_0142__section11176714193111"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0142__ol642412246319"><li id="obs_03_0142__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0142__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0142__li13508181724617"><span>In the navigation pane on the left, click <strong id="obs_03_0142__b63882047163712">Permissions</strong> to go to the permission management page.</span></li><li id="obs_03_0142__li10943173416311"><span>On the <strong id="obs_03_0142__b3956213131911">Bucket Policies</strong> tab page, select a policy from the <strong id="obs_03_0142__b189570135198">Standard Bucket Policies</strong> area.</span><p><ul id="obs_03_0142__ul15740133433513"><li id="obs_03_0142__li4740103420354"><strong id="obs_03_0142__b1707153134118">Private</strong>: No access beyond the bucket ACL settings is granted.</li><li id="obs_03_0142__li377138153513"><strong id="obs_03_0142__b15687153323119">Public Read</strong>: Anyone can read objects in the bucket.</li><li id="obs_03_0142__li66641044203514"><strong id="obs_03_0142__b8546440113113">Public Read and Write</strong>: Anyone can read, write, or delete objects in the bucket.</li></ul>
|
||||
<div class="section" id="obs_03_0142__section11176714193111"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0142__ol642412246319"><li id="obs_03_0142__li99821455306"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0142__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0142__li13508181724617"><span>In the navigation pane, choose <strong id="obs_03_0142__b2055212481903">Permissions</strong>.</span></li><li id="obs_03_0142__li10943173416311"><span>On the <strong id="obs_03_0142__b3956213131911">Bucket Policies</strong> tab page, select a policy from the <strong id="obs_03_0142__b189570135198">Standard Bucket Policies</strong> area.</span><p><ul id="obs_03_0142__ul15740133433513"><li id="obs_03_0142__li4740103420354"><strong id="obs_03_0142__b1707153134118">Private</strong>: No access beyond the bucket ACL settings is granted.</li><li id="obs_03_0142__li377138153513"><strong id="obs_03_0142__b15687153323119">Public Read</strong>: Anyone can read objects in the bucket.</li><li id="obs_03_0142__li66641044203514"><strong id="obs_03_0142__b8546440113113">Public Read and Write</strong>: Anyone can read, write, or delete objects in the bucket.</li></ul>
|
||||
<div class="note" id="obs_03_0142__note81761083713"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0142__p12185190153719">For your data security, the <strong id="obs_03_0142__b1544014421288">Public Read</strong> and <strong id="obs_03_0142__b12442142384">Public Read and Write</strong> policies are not recommended.</p>
|
||||
</div></div>
|
||||
<div class="fignone" id="obs_03_0142__fig1077518154818"><span class="figcap"><b>Figure 1 </b>Standard bucket policies</span><br><span><img id="obs_03_0142__image163392417374" src="en-us_image_0172132522.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
|
@ -4,7 +4,7 @@
|
||||
<div id="body1559715596438"></div>
|
||||
<div>
|
||||
<ul class="ullinks">
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0122.html">Creating a User and Granting OBS Permissions</a></strong><br>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0122.html">Creating an IAM User and Granting OBS Permissions</a></strong><br>
|
||||
</li>
|
||||
</ul>
|
||||
|
||||
|
@ -1,7 +1,7 @@
|
||||
<a name="obs_03_0152"></a><a name="obs_03_0152"></a>
|
||||
|
||||
<h1 class="topictitle1">Endpoints and Domain Names</h1>
|
||||
<div id="body1569566812932"><p id="obs_03_0152__p1441895318321"><strong id="obs_03_0152__b144159163517">Endpoint:</strong> OBS provides an endpoint for each region. An endpoint is a domain name to access OBS in a region and is used to process access requests of that region. For details about regions and endpoints, see <a href="https://docs.otc.t-systems.com/en-us/endpoint/index.html" target="_blank" rel="noopener noreferrer">Regions and Endpoints</a>.</p>
|
||||
<div id="body1569566812932"><p id="obs_03_0152__p1441895318321"><strong id="obs_03_0152__b144159163517">Endpoint:</strong> OBS provides an endpoint for each region. An endpoint is considered a domain name to access OBS in a region and is used to process requests of that region. For details about regions and endpoints, see <a href="https://docs.otc.t-systems.com/en-us/endpoint/index.html" target="_blank" rel="noopener noreferrer">Regions and Endpoints</a>.</p>
|
||||
<p id="obs_03_0152__p685617162213"></p>
|
||||
<p id="obs_03_0152__p482595520328"><strong id="obs_03_0152__b185781611173920">Bucket domain name</strong>: Each bucket in OBS has a domain name. A domain name is the address of a bucket and can be used to access the bucket over the Internet. It is applicable to cloud application development and data sharing.</p>
|
||||
<p id="obs_03_0152__p17160176182817">An OBS bucket domain name is in the format of <em id="obs_03_0152__i2588163811507">BucketName.Endpoint</em>, where <em id="obs_03_0152__i625493165116">BucketName</em> indicates the name of the bucket, and <em id="obs_03_0152__i19997159195117">Endpoint</em> indicates the domain name of the region where the bucket is located.</p>
|
||||
|
@ -3,30 +3,30 @@
|
||||
<h1 class="topictitle1">Using OBS</h1>
|
||||
<div id="body1501486129846"><p id="obs_03_0203__p1762410753419">You can use the following tools to access and manage OBS resources:</p>
|
||||
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0203__table95276448493" frame="border" border="1" rules="all"><caption><b>Table 1 </b>OBS resource management tools</caption><thead align="left"><tr id="obs_03_0203__row1527844104914"><th align="left" class="cellrowborder" valign="top" width="23.48%" id="mcps1.3.2.2.3.1.1"><p id="obs_03_0203__p352713445495">Tool</p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0203__table95276448493" frame="border" border="1" rules="all"><caption><b>Table 1 </b>OBS resource management tools</caption><thead align="left"><tr id="obs_03_0203__row1527844104914"><th align="left" class="cellrowborder" valign="top" width="23.46%" id="mcps1.3.2.2.3.1.1"><p id="obs_03_0203__p352713445495">Tool</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="76.52%" id="mcps1.3.2.2.3.1.2"><p id="obs_03_0203__p1652794404910">Description</p>
|
||||
<th align="left" class="cellrowborder" valign="top" width="76.53999999999999%" id="mcps1.3.2.2.3.1.2"><p id="obs_03_0203__p1652794404910">Description</p>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody><tr id="obs_03_0203__row452724410491"><td class="cellrowborder" valign="top" width="23.48%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p15271447490">OBS Console</p>
|
||||
<tbody><tr id="obs_03_0203__row452724410491"><td class="cellrowborder" valign="top" width="23.46%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p15271447490">OBS Console</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="76.52%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p155276441494">OBS Console is a web-based GUI for you to easily manage OBS resources.</p>
|
||||
<td class="cellrowborder" valign="top" width="76.53999999999999%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p155276441494">OBS Console is a web-based GUI for you to easily manage OBS resources.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0203__row752744464920"><td class="cellrowborder" valign="top" width="23.48%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p752784416490">OBS Browser</p>
|
||||
<tr id="obs_03_0203__row752744464920"><td class="cellrowborder" valign="top" width="23.46%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p752784416490">OBS Browser</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="76.52%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p75271144204914">OBS Browser is an OBS client running on Windows operating systems. You can use OBS Browser to manage the storage of objects on your PC.</p>
|
||||
<td class="cellrowborder" valign="top" width="76.53999999999999%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p75271144204914">OBS Browser is a Windows client that lets you easily manage OBS resources from your desktop.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0203__row17528444194913"><td class="cellrowborder" valign="top" width="23.48%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p1852824444918">SDKs</p>
|
||||
<tr id="obs_03_0203__row17528444194913"><td class="cellrowborder" valign="top" width="23.46%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p1852824444918">SDKs</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="76.52%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p11528134416497">OBS SDKs encapsulate APIs provided by OBS to simplify user development. Users can directly use API functions provided by the OBS SDKs to obtain the OBS service capabilities.</p>
|
||||
<td class="cellrowborder" valign="top" width="76.53999999999999%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p11528134416497">OBS SDKs encapsulate the REST API provided by OBS to simplify development. You can call API functions provided by the OBS SDKs to enjoy OBS capabilities.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0203__row1152810445492"><td class="cellrowborder" valign="top" width="23.48%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p13528174418494">APIs</p>
|
||||
<tr id="obs_03_0203__row1152810445492"><td class="cellrowborder" valign="top" width="23.46%" headers="mcps1.3.2.2.3.1.1 "><p id="obs_03_0203__p13528174418494">API</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="76.52%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p652811441496">With APIs, you can easily access OBS from web applications. By making API calls, you can upload and download data anytime, anywhere, or through any Internet device.</p>
|
||||
<td class="cellrowborder" valign="top" width="76.53999999999999%" headers="mcps1.3.2.2.3.1.2 "><p id="obs_03_0203__p652811441496">OBS offers the REST API for you to access it from web applications with ease. By making API calls, you can upload and download data anytime, anywhere, over the Internet.</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
|
@ -30,7 +30,7 @@
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="42%" headers="mcps1.3.1.2.4.1.2 "><p id="obs_03_0204__p13409104010269">Simple Message Notification (SMN)</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="21%" headers="mcps1.3.1.2.4.1.3 "><p id="obs_03_0204__p10410144062617"><a href="en-us_topic_0045853816.html">SMN-Enabled Event Notification</a></p>
|
||||
<td class="cellrowborder" valign="top" width="21%" headers="mcps1.3.1.2.4.1.3 "><p id="obs_03_0204__p10410144062617"><a href="en-us_topic_0045853816.html">SMN-Enabled Event Notifications</a></p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0204__row042764019267"><td class="cellrowborder" valign="top" width="37%" headers="mcps1.3.1.2.4.1.1 "><p id="obs_03_0204__p166219531432">Tags are used to label and classify buckets in OBS.</p>
|
||||
|
@ -3,7 +3,7 @@
|
||||
<h1 class="topictitle1">Buckets</h1>
|
||||
<div id="body1499753333225"><p id="obs_03_0207__p8060118">Buckets are containers for storing objects. OBS provides flat storage in the form of buckets and objects. Unlike the conventional multi-layer directory structure of file systems, all objects in a bucket are stored at the same logical layer.</p>
|
||||
<p id="obs_03_0207__p18442164011176">Each bucket has its own attributes, such as access permissions, storage class, and the region. You can specify access permissions, storage class, and regions when creating buckets. You can also configure advanced attributes to meet storage requirements in different scenarios.</p>
|
||||
<p id="obs_03_0207__p4544930811379">OBS provides the following storage classes for buckets: Standard, Warm, and Cold. With diverse storage classes, OBS caters to both storage performance and cost requirements. When creating a bucket, you can set a storage class for the bucket. The storage class of a bucket can be changed as needed.</p>
|
||||
<p id="obs_03_0207__p4544930811379">OBS provides the following storage classes for buckets: Standard, Warm, and Cold. With diverse storage classes, OBS caters to both storage performance and cost requirements. When creating a bucket, you can specify a storage class for the bucket. The storage class of a bucket can be changed as needed.</p>
|
||||
<p id="obs_03_0207__p145061250114416">Each bucket name in OBS is globally unique and cannot be changed after the bucket has been created. The region where a bucket resides cannot be changed once the bucket is created. When you create a bucket, OBS creates a default access control list (ACL) that grants users permissions (such as read and write permissions) on the bucket. Only authorized users can perform operations such as creating, deleting, viewing, and configuring buckets.</p>
|
||||
<p id="obs_03_0207__p22208171">An account (including all IAM users under this account) can create a maximum of 100 buckets and parallel file systems. However, there is no restriction on the number and total size of objects in a bucket.</p>
|
||||
<p id="obs_03_0207__p65655818">OBS adopts the REST architectural style, and is based on HTTP and HTTPS. You can use URLs to locate resources.</p>
|
||||
|
@ -1,13 +1,13 @@
|
||||
<a name="obs_03_0208"></a><a name="obs_03_0208"></a>
|
||||
|
||||
<h1 class="topictitle1">Access Keys (AK/SK)</h1>
|
||||
<div id="body1499753333225"><p id="obs_03_0208__p52592197">OBS supports AK/SK authentication. The AK/SK encryption method is used to authenticate a request sender. When you use OBS APIs for secondary development and use the AK and SK for authentication, the signature must be computed based on the algorithm defined by OBS and added to the request.</p>
|
||||
<p id="obs_03_0208__p3139131403119">OBS supports authentication using a permanent AK/SK pair, or using a temporary AK/SK pair and a security token.</p>
|
||||
<div id="body1499753333225"><p id="obs_03_0208__p52592197">OBS uses an access key ID (AK) and secret access key (SK) to authenticate the identity of a requester. When you use OBS APIs for secondary development and use the AK and SK for authentication, the signature must be calculated based on the algorithm defined by OBS and added to the request.</p>
|
||||
<p id="obs_03_0208__p3139131403119">The authentication can be based on a permanent AK and SK pair, or based on a temporary AK/SK pair and security token.</p>
|
||||
<p id="obs_03_0208__p2396184515319"><strong id="obs_03_0208__b41846336393">Permanent AK/SK Pair</strong></p>
|
||||
<p id="obs_03_0208__p15291241">You can create a pair of permanent AK and SK on the <strong id="obs_03_0208__b18786137102311">My Credentials</strong> page.</p>
|
||||
<ul id="obs_03_0208__ul36784332"><li id="obs_03_0208__li32558606">Access key ID (AK): indicates the ID of the access key. It is the unique ID associated with the SK. The AK and SK are used together to obtain an encrypted signature for a request.</li><li id="obs_03_0208__li24592002">Secret access key (SK): indicates the private key used together with its associated AK to cryptographically sign requests. The AK and SK are used together to identify a request sender to prevent the request from being modified.</li></ul>
|
||||
<p id="obs_03_0208__p11982124418368"><strong id="obs_03_0208__b1848794564015">Temporary AK/SK Pair</strong></p>
|
||||
<p id="obs_03_0208__p16519181820419">A temporary AK/SK pair and the security token are temporary access tokens granted by the system to users. The validity period of the tokens ranges from 15 minutes to 24 hours. After the tokens expire, you need to obtain the tokens again. A temporary AK/SK pair and the security token comply with the least privilege principle and can only be used to temporarily access OBS. A 403 error will be returned if the security token is not available.</p>
|
||||
<p id="obs_03_0208__p16519181820419">A temporary AK/SK pair and security token assigned by OBS comply with the principle of least privilege and are for temporarily accessing OBS. They are valid from 15 minutes to 24 hours, and need to be obtained again once they expire. If the security token is missing from your request, a 403 error will be returned.</p>
|
||||
<ul id="obs_03_0208__ul14493111816456"><li id="obs_03_0208__li15131041194414">Temporary AK: indicates the ID of a temporary access key. It is the unique ID associated with the SK. The AK and SK are used together to obtain an encrypted signature for a request.</li><li id="obs_03_0208__li134941318104514">Temporary SK: indicates the temporary private key used together with its associated temporary AK. The AK and SK are used together to identify a request sender to prevent the request from being modified.</li><li id="obs_03_0208__li9725287468">Security token: indicates the token used together with the temporary AK and SK to access all resources of a specified account.</li></ul>
|
||||
<p id="obs_03_0208__p31525188">When using the following tools to access OBS resources, you need to use the AK/SK pair for security authentication.</p>
|
||||
|
||||
|
@ -28,7 +28,7 @@
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0330.html">Tags</a></strong><br>
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0332.html">Event Notification</a></strong><br>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0332.html">Event Notifications</a></strong><br>
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0334.html">Lifecycle Management</a></strong><br>
|
||||
</li>
|
||||
|
@ -1,7 +1,8 @@
|
||||
<a name="obs_03_0303"></a><a name="obs_03_0303"></a>
|
||||
|
||||
<h1 class="topictitle1">Process Description</h1>
|
||||
<div id="body1501728369277"><p id="obs_03_0303__p11721694142328">The follow-up sections describe how to complete the tasks illustrated in <a href="#obs_03_0303__fig22289233142328">Figure 1</a>.</p>
|
||||
<div id="body1501728369277"><p id="obs_03_0303__p3216135818497">OBS basic operations include bucket creation, object upload and object download.</p>
|
||||
<p id="obs_03_0303__p11721694142328">The follow-up sections describe how to complete the tasks illustrated in <a href="#obs_03_0303__fig22289233142328">Figure 1</a>.</p>
|
||||
<div class="fignone" id="obs_03_0303__fig22289233142328"><a name="obs_03_0303__fig22289233142328"></a><a name="fig22289233142328"></a><span class="figcap"><b>Figure 1 </b>OBS Console quick start</span><br><span><img id="obs_03_0303__image1946974614590" src="en-us_image_0129289009.png"></span></div>
|
||||
</div>
|
||||
<div>
|
||||
|
@ -2,15 +2,15 @@
|
||||
|
||||
<h1 class="topictitle1">Configuring User Permissions</h1>
|
||||
<div id="body1499753333225"><p id="obs_03_0304__p77331243113019">If your cloud service account does not need individual IAM users, then you may skip this section. Your permissions to use OBS functions are not affected.</p>
|
||||
<p id="obs_03_0304__p783465223215">If IAM users are required, you need to grant OBS access permissions to the users, because OBS is separately deployed from other cloud resources.</p>
|
||||
<p id="obs_03_0304__p783465223215">If IAM users are required, you need to grant them access permissions on OBS, because OBS is separately deployed from other cloud resources.</p>
|
||||
<div class="section" id="obs_03_0304__section12521716448"><h4 class="sectiontitle">Process</h4><div class="fignone" id="obs_03_0304__obs_03_0122_fig292324264713"><span class="figcap"><b>Figure 1 </b>Process of granting an IAM user the OBS permissions</span><br><span><img id="obs_03_0304__obs_03_0122_image12924124212474" src="en-us_image_0170301902.png"></span></div>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0304__section1056019017457"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0304__obs_03_0122_ol63831030102"><li id="obs_03_0304__obs_03_0122_li35354147174321"><span>Log in to the management console using a cloud service account.</span></li><li id="obs_03_0304__obs_03_0122_li5853192561010"><span>On the top navigation menu, choose <strong id="obs_03_0304__obs_03_0122_b19603113671814">Service List</strong> > <strong id="obs_03_0304__obs_03_0122_b3603103615186">Management & Deployment</strong> > <strong id="obs_03_0304__obs_03_0122_b460310368184">Identity and Access Management</strong>. The IAM console page is displayed.</span></li><li id="obs_03_0304__obs_03_0122_li257313485116"><span>Create a user group and grant the OBS permissions to the user group.</span><p><div class="p" id="obs_03_0304__obs_03_0122_p371751915195">User groups facilitate centralized user management and streamlined permissions management. Users in the same user group have the same permissions. Users created in IAM inherit permissions from the groups to which they belong.<ol type="a" id="obs_03_0304__obs_03_0122_ol28671118201912"><li id="obs_03_0304__obs_03_0122_li78661718151913">In the navigation pane on the left, click <strong id="obs_03_0304__obs_03_0122_b17624165682216">User Groups</strong>. The <strong id="obs_03_0304__obs_03_0122_b4625115617224">User Groups</strong> page is displayed.</li><li id="obs_03_0304__obs_03_0122_li286617189195">Click <span class="uicontrol" id="obs_03_0304__obs_03_0122_uicontrol230942777211457"><b>Create User Group</b></span>.</li><li id="obs_03_0304__obs_03_0122_li1886641801917">On the <strong id="obs_03_0304__obs_03_0122_b1190011522266">Create User Group</strong> page, enter a name for the user group and click <strong id="obs_03_0304__obs_03_0122_b7542112222713">OK</strong>.<p id="obs_03_0304__obs_03_0122_p3866171841910">The user group is displayed in the user group list once the creation completes.</p>
|
||||
</li><li id="obs_03_0304__obs_03_0122_li19866191819199">Click <strong id="obs_03_0304__obs_03_0122_b1406172416567">Modify</strong> in the <strong id="obs_03_0304__obs_03_0122_b12813112718562">Operation</strong> column of the row where the created user group resides.</li><li id="obs_03_0304__obs_03_0122_li1286721818193">In the <strong id="obs_03_0304__obs_03_0122_b1813981018595">Group Permissions</strong> area, locate <strong id="obs_03_0304__obs_03_0122_b166361281309">OBS (S3)</strong>, click <strong id="obs_03_0304__obs_03_0122_b145811817302">Attach Policy</strong> in the <strong id="obs_03_0304__obs_03_0122_b151884218015">Operation</strong> column, select the policy name, and click <strong id="obs_03_0304__obs_03_0122_b112537337019">OK</strong>.<div class="note" id="obs_03_0304__obs_03_0122_note12867161811198"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0304__obs_03_0122_p128671018121916">In the <strong id="obs_03_0304__obs_03_0122_b1318212383618">Policy Information</strong> area, you can view the details about the policy.</p>
|
||||
<div class="section" id="obs_03_0304__section1056019017457"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0304__obs_03_0122_ol63831030102"><li id="obs_03_0304__obs_03_0122_li35354147174321"><span>Log in to the management console with your account.</span></li><li id="obs_03_0304__obs_03_0122_li5853192561010"><span>On the top menu bar, choose <strong id="obs_03_0304__obs_03_0122_b149371518121613">Service List</strong> > <strong id="obs_03_0304__obs_03_0122_b29379189163">Management & Deployment</strong> > <strong id="obs_03_0304__obs_03_0122_b1293761819168">Identity and Access Management</strong>. The IAM console is displayed.</span></li><li id="obs_03_0304__obs_03_0122_li257313485116"><span>Create a user group and assign OBS permissions to it.</span><p><div class="p" id="obs_03_0304__obs_03_0122_p371751915195">A user group is a collection of users. By assigning permissions to a user group, you assign permissions to the users in this group. After you create an IAM user, add it to one or more user groups, so that it can inherit the permissions from the groups.<ol type="a" id="obs_03_0304__obs_03_0122_ol28671118201912"><li id="obs_03_0304__obs_03_0122_li78661718151913">In the navigation pane, choose <strong id="obs_03_0304__obs_03_0122_b0624202611174">User Groups</strong>. The <strong id="obs_03_0304__obs_03_0122_b8624112618178">User Groups</strong> page is displayed.</li><li id="obs_03_0304__obs_03_0122_li286617189195">Click <span class="uicontrol" id="obs_03_0304__obs_03_0122_uicontrol230942777211457"><b>Create User Group</b></span>.</li><li id="obs_03_0304__obs_03_0122_li1886641801917">Enter a user group name and click <strong id="obs_03_0304__obs_03_0122_b779483571714">OK</strong>.<p id="obs_03_0304__obs_03_0122_p3866171841910">The user group is displayed in the user group list once the creation is complete.</p>
|
||||
</li><li id="obs_03_0304__obs_03_0122_li19866191819199">Locate the user group you created and click <strong id="obs_03_0304__obs_03_0122_b834625118178">Modify</strong> in the <strong id="obs_03_0304__obs_03_0122_b19346105117174">Operation</strong> column of the row.</li><li id="obs_03_0304__obs_03_0122_li1286721818193">In the <strong id="obs_03_0304__obs_03_0122_b1813981018595">Group Permissions</strong> area, locate <strong id="obs_03_0304__obs_03_0122_b166361281309">OBS (S3)</strong>, click <strong id="obs_03_0304__obs_03_0122_b145811817302">Attach Policy</strong> in the <strong id="obs_03_0304__obs_03_0122_b151884218015">Operation</strong> column, select the policy name, and click <strong id="obs_03_0304__obs_03_0122_b112537337019">OK</strong>.<div class="note" id="obs_03_0304__obs_03_0122_note12867161811198"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0304__obs_03_0122_p128671018121916">In the <strong id="obs_03_0304__obs_03_0122_b1318212383618">Policy Information</strong> area, you can view the details about the policy.</p>
|
||||
</div></div>
|
||||
</li></ol>
|
||||
</div>
|
||||
</p></li><li id="obs_03_0304__obs_03_0122_li17712194912"><span>Create a user.</span><p><ol type="a" id="obs_03_0304__obs_03_0122_ol6893174016015"><li id="obs_03_0304__obs_03_0122_li84578140715">In the navigation pane on the left, click <strong id="obs_03_0304__obs_03_0122_b332175483617">Users</strong>. The <strong id="obs_03_0304__obs_03_0122_b832320546366">Users</strong> page is displayed.</li><li id="obs_03_0304__obs_03_0122_li75875232719">Click <strong id="obs_03_0304__obs_03_0122_b16239139183714">Create User</strong>.</li><li id="obs_03_0304__obs_03_0122_li08941740305">Set user information and click <strong id="obs_03_0304__obs_03_0122_b897712100378">Next</strong>.
|
||||
</p></li><li id="obs_03_0304__obs_03_0122_li17712194912"><span>Create a user.</span><p><ol type="a" id="obs_03_0304__obs_03_0122_ol6893174016015"><li id="obs_03_0304__obs_03_0122_li84578140715">In the navigation pane, choose <strong id="obs_03_0304__obs_03_0122_b1645363019241">Users</strong>. The <strong id="obs_03_0304__obs_03_0122_b174541830102416">Users</strong> page is displayed.</li><li id="obs_03_0304__obs_03_0122_li75875232719">Click <strong id="obs_03_0304__obs_03_0122_b16239139183714">Create User</strong>.</li><li id="obs_03_0304__obs_03_0122_li08941740305">Set user information and click <strong id="obs_03_0304__obs_03_0122_b897712100378">Next</strong>.
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="obs_03_0304__obs_03_0122_table127131345071" frame="border" border="1" rules="all"><caption><b>Table 1 </b>User parameters</caption><thead align="left"><tr id="obs_03_0304__obs_03_0122_row4714144517714"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.4.2.1.3.2.2.3.1.1"><p id="obs_03_0304__obs_03_0122_p137145451578">Parameter</p>
|
||||
</th>
|
||||
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.4.2.1.3.2.2.3.1.2"><p id="obs_03_0304__obs_03_0122_p1071417451679">Description</p>
|
||||
|
@ -14,7 +14,7 @@
|
||||
</thead>
|
||||
<tbody><tr id="obs_03_0306__row721018185364"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="obs_03_0306__p12210111812361">Region</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="79.78%" headers="mcps1.3.3.2.2.2.1.2.3.1.2 "><p id="obs_03_0306__p480613549419">Geographic area where a bucket resides. For low network latency and quick resource access, select the nearest region. Once the bucket is created, its region cannot be changed.</p>
|
||||
<td class="cellrowborder" valign="top" width="79.78%" headers="mcps1.3.3.2.2.2.1.2.3.1.2 "><p id="obs_03_0306__p480613549419">Geographic area where a bucket resides. For low latency and faster access, select the region nearest to you. Once the bucket is created, its region cannot be changed.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0306__row321061820361"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="obs_03_0306__p6210181823616">Bucket Name</p>
|
||||
@ -36,7 +36,7 @@
|
||||
<tr id="obs_03_0306__row162107185362"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="obs_03_0306__p1621051833618">Bucket Policy</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="79.78%" headers="mcps1.3.3.2.2.2.1.2.3.1.2 "><p id="obs_03_0306__p13250952104514">Controls read and write permissions for buckets.</p>
|
||||
<ul id="obs_03_0306__ul1118618569194"><li id="obs_03_0306__li13186185612196"><strong id="obs_03_0306__b5921165812225">Private</strong>: Only users granted permissions by the ACL can access the bucket.</li><li id="obs_03_0306__li181131478206"><strong id="obs_03_0306__b116813342311">Public Read</strong>: Anyone can read objects in the bucket.</li><li id="obs_03_0306__li147015152013"><strong id="obs_03_0306__b1492156122319">Public Read and Write</strong>: Anyone can read, write, or delete objects in the bucket.</li></ul>
|
||||
<ul id="obs_03_0306__ul1118618569194"><li id="obs_03_0306__li13186185612196"><strong id="obs_03_0306__b929114841213">Private</strong>: No access beyond the bucket ACL settings is granted.</li><li id="obs_03_0306__li181131478206"><strong id="obs_03_0306__b116813342311">Public Read</strong>: Anyone can read objects in the bucket.</li><li id="obs_03_0306__li147015152013"><strong id="obs_03_0306__b1492156122319">Public Read and Write</strong>: Anyone can read, write, or delete objects in the bucket.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="obs_03_0306__row521061883619"><td class="cellrowborder" valign="top" width="20.22%" headers="mcps1.3.3.2.2.2.1.2.3.1.1 "><p id="obs_03_0306__p6210111812361">Default Encryption</p>
|
||||
|
@ -8,15 +8,14 @@
|
||||
</div></div>
|
||||
<div class="section" id="obs_03_0307__sd7d65d851f1c4a2d8a507d1689a5d358"><h4 class="sectiontitle">Prerequisites</h4><ul id="obs_03_0307__ul13735132573913"><li id="obs_03_0307__li16735122520395">At least one bucket has been created.</li><li id="obs_03_0307__li167391276399">If you want to classify files, you can create folders and upload files to different folders. For details about how to create a folder, see <a href="obs_03_0316.html">Creating a Folder</a></li></ul>
|
||||
</div>
|
||||
<div class="section" id="obs_03_0307__section1567551415194"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0307__ol658192291912"><li id="obs_03_0307__li1596440151221"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0307__b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0307__li123641720664"><span>In the navigation pane, click <strong id="obs_03_0307__b47118221194931">Objects</strong>.</span></li><li id="obs_03_0307__li46803166594"><span>Go to the folder to which objects are uploaded. Click <strong id="obs_03_0307__b0882125105511">Upload Object</strong>. The <strong id="obs_03_0307__b6293181115555">Upload Object</strong> dialog box is displayed.</span><p><div class="note" id="obs_03_0307__note186461450113113"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0307__p14504161520198">If the files that you want to upload to OBS are stored in Microsoft OneDrive, it is recommended that the names of these files contain a maximum of 32 characters to ensure compatibility.</p>
|
||||
<div class="section" id="obs_03_0307__section1567551415194"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0307__ol658192291912"><li id="obs_03_0307__li1596440151221"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0307__b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0307__li123641720664"><span>In the navigation pane, choose <strong id="obs_03_0307__b51941856151917">Objects</strong>.</span></li><li id="obs_03_0307__li46803166594"><span>Go to the folder to which objects are uploaded. Click <strong id="obs_03_0307__b0882125105511">Upload Object</strong>. The <strong id="obs_03_0307__b6293181115555">Upload Object</strong> dialog box is displayed.</span><p><div class="note" id="obs_03_0307__note186461450113113"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0307__p14504161520198">If the files that you want to upload to OBS are stored in Microsoft OneDrive, it is recommended that the names of these files contain a maximum of 32 characters to ensure compatibility.</p>
|
||||
</div></div>
|
||||
<div class="fignone" id="obs_03_0307__fig188654349118"><span class="figcap"><b>Figure 1 </b>Uploading objects</span><br><span><img id="obs_03_0307__image10536191814483" src="en-us_image_0153827167.png" title="Click to enlarge" class="imgResize"></span></div>
|
||||
<p id="obs_03_0307__p739115241316"></p>
|
||||
<p id="obs_03_0307__p1430017260138"></p>
|
||||
</p></li><li id="obs_03_0307__li8341913385"><span>Select a storage class. If you do not specify a storage class, the object you upload inherits the default storage class of the bucket.</span><p><div class="note" id="obs_03_0307__note27281163408"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0307__p15728186194013">An object can have a different storage class from its bucket. You can specify a storage class for an object when uploading it, or you can change the object storage class after the object is uploaded.</p>
|
||||
</div></div>
|
||||
</p></li><li id="obs_03_0307__li43271656164119"><span>Add a file or folder to be uploaded by dragging it to the <strong id="obs_03_0307__b120411138146">Upload Object</strong> area.</span><p><p id="obs_03_0307__p5316155610415">You can also click <strong id="obs_03_0307__b9948174410266">add file</strong> in the <strong id="obs_03_0307__b064791710146">Upload Object</strong> area to select files.</p>
|
||||
</p></li><li id="obs_03_0307__li74481344102111"><span><strong id="obs_03_0307__b4955291917530">Optional</strong>: Select <strong id="obs_03_0307__b16368281536">KMS encryption</strong> to encrypt the uploaded file. For details, see <a href="obs_03_0322.html">Uploading a File with Server-Side Encryption</a>.</span><p><div class="note" id="obs_03_0307__note610818411894"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0307__obs_03_0306_p062133814520">If the default encryption has been enabled for the bucket, uploaded objects are automatically encrypted.</p>
|
||||
</p></li><li id="obs_03_0307__li74481344102111"><span>(Optional) Select <strong id="obs_03_0307__b16368281536">KMS encryption</strong> to encrypt the uploaded file. For details, see <a href="obs_03_0322.html">Uploading a File in Server-Side Encryption Mode</a>.</span><p><div class="note" id="obs_03_0307__note610818411894"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0307__obs_03_0306_p062133814520">If the default encryption has been enabled for the bucket, uploaded objects are automatically encrypted.</p>
|
||||
</div></div>
|
||||
</p></li><li id="obs_03_0307__li12125192695311"><span>Click <strong id="obs_03_0307__b1918611133719">Upload</strong>.</span></li></ol>
|
||||
</div>
|
||||
|
@ -1,8 +1,8 @@
|
||||
<a name="obs_03_0309"></a><a name="obs_03_0309"></a>
|
||||
|
||||
<h1 class="topictitle1">Deleting a File</h1>
|
||||
<div id="body1499758606806"><p id="obs_03_0309__p23374247205629">You can delete unnecessary files one by one or in a batch to save space and costs.</p>
|
||||
<div class="section" id="obs_03_0309__sbce25240b91d49e2a0d7b514a73a7da9"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0309__en-us_topic_0066036524_ol36405904"><li id="obs_03_0309__li1421405614294"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0309__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0309__li123641720664"><span>In the navigation pane, click <strong id="obs_03_0309__b49917419145">Objects</strong>.</span></li><li id="obs_03_0309__li1463890417452"><span>Select the file you want to delete, and choose <strong id="obs_03_0309__b152019501616">More</strong> > <strong id="obs_03_0309__b873616741617">Delete</strong> on the right.</span><p><p id="obs_03_0309__en-us_topic_0066036524_p18694614">You can select multiple files and click <strong id="obs_03_0309__b1919669813155639">Delete</strong> above the file list to batch delete the files.</p>
|
||||
<div id="body1499758606806"><p id="obs_03_0309__p23374247205629">You can delete unnecessary files one by one or in a batch on OBS Console to save space and money.</p>
|
||||
<div class="section" id="obs_03_0309__sbce25240b91d49e2a0d7b514a73a7da9"><h4 class="sectiontitle">Procedure</h4><ol id="obs_03_0309__en-us_topic_0066036524_ol36405904"><li id="obs_03_0309__li1421405614294"><span>In the bucket list, click the bucket you want to operate. The <strong id="obs_03_0309__obs_03_0307_b1395123914108">Overview</strong> page of the bucket is displayed.</span></li><li id="obs_03_0309__li123641720664"><span>In the navigation pane, choose <strong id="obs_03_0309__b12531423200">Objects</strong>.</span></li><li id="obs_03_0309__li1463890417452"><span>Select the file you want to delete, and choose <strong id="obs_03_0309__b152019501616">More</strong> > <strong id="obs_03_0309__b873616741617">Delete</strong> on the right.</span><p><p id="obs_03_0309__en-us_topic_0066036524_p18694614">You can select multiple files and click <strong id="obs_03_0309__b1919669813155639">Delete</strong> above the file list to batch delete the files.</p>
|
||||
</p></li><li id="obs_03_0309__en-us_topic_0066036524_li34033799"><span>Click <strong id="obs_03_0309__b187788533819">Yes</strong> to confirm the deletion.</span><p><p id="obs_03_0309__p667144781316">The object deletion task is displayed in the <strong id="obs_03_0309__b1117816723919">Task Management</strong> window.</p>
|
||||
</p></li></ol>
|
||||
</div>
|
||||
|
@ -10,6 +10,8 @@
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0317.html">Downloading a File</a></strong><br>
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0046.html">Sharing a File</a></strong><br>
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0318.html">Searching for a File or Folder</a></strong><br>
|
||||
</li>
|
||||
<li class="ulchildlink"><strong><a href="obs_03_0319.html">Accessing an Object Using Its URL</a></strong><br>
|
||||
|
@ -32,7 +32,7 @@
|
||||
</div>
|
||||
</p></li><li id="obs_03_0320__li1972912351264"><span>Click <strong id="obs_03_0320__b842352706183323">OK</strong>.</span><p><p id="obs_03_0320__p10132153742618">The <strong id="obs_03_0320__b335265113369">Restoration Status</strong> column in the object list displays the restore statuses of objects.</p>
|
||||
<p id="obs_03_0320__p1285581315719">You can click <span><img id="obs_03_0320__image0359833184910" src="en-us_image_0148639825.png"></span> to manually refresh the restore status.</p>
|
||||
<div class="note" id="obs_03_0320__note32356781143931"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0320__p15686904143943">The system checks the file restore status at UTC 00:00 everyday. The system starts counting down the expiration time from the time when the latest check is complete.</p>
|
||||
<div class="note" id="obs_03_0320__note32356781143931"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="obs_03_0320__p15686904143943">The system checks the file restore status at UTC 00:00 every day. The system starts counting down the expiration time from the time when the latest check is complete.</p>
|
||||
</div></div>
|
||||
</p></li></ol>
|
||||
</div>
|
||||
|