forked from laiweijian4/doc-exports
ER API 20240206 version
Reviewed-by: Sarda, Priya <prsarda@noreply.gitea.eco.tsi-dev.otc-service.com> Co-authored-by: Qin Ying, Fan <fanqinying@huawei.com> Co-committed-by: Qin Ying, Fan <fanqinying@huawei.com>
This commit is contained in:
parent
3bc19c4f14
commit
ce373ee855
@ -1163,7 +1163,7 @@
|
||||
"node_id":"er_02_0016.xml",
|
||||
"product_code":"er",
|
||||
"code":"59",
|
||||
"des":"This section describes fine-grained permissions management for your Enterprise Router resources. If your account does not need individual IAM users, you may skip this sec",
|
||||
"des":"This topic describes fine-grained permissions management for your Enterprise Router resources. If your account does not need individual IAM users, you may skip this topic",
|
||||
"doc_type":"api",
|
||||
"kw":"Introduction,Permissions Policies and Supported Actions,API Reference",
|
||||
"search_title":"",
|
||||
|
@ -8,7 +8,19 @@
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody><tr id="APIChangeHistory__row1718161012571"><td class="cellrowborder" valign="top" width="33.58%" headers="mcps1.3.1.1.3.1.1 "><p id="APIChangeHistory__p51817107575">2023-12-06</p>
|
||||
<tbody><tr id="APIChangeHistory__row19772175210164"><td class="cellrowborder" valign="top" width="33.58%" headers="mcps1.3.1.1.3.1.1 "><p id="APIChangeHistory__p7693956111612">2024-03-05</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="66.42%" headers="mcps1.3.1.1.3.1.2 "><p id="APIChangeHistory__p1969365641612">This release incorporates the following changes:</p>
|
||||
<p id="APIChangeHistory__p769385651610">Modified the description of the <strong id="APIChangeHistory__b153071325142120">asn</strong> parameter in "Creating an Enterprise Router".</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="APIChangeHistory__row191531010173"><td class="cellrowborder" valign="top" width="33.58%" headers="mcps1.3.1.1.3.1.1 "><p id="APIChangeHistory__p540819107468">2024-02-05</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="66.42%" headers="mcps1.3.1.1.3.1.2 "><p id="APIChangeHistory__p10444827204610">This release incorporates the following changes:</p>
|
||||
<p id="APIChangeHistory__p4759192514910">Modified the description of the <strong id="APIChangeHistory__b14331817111314">auto_create_vpc_routes</strong> parameter in "Creating a VPC Attachment."</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="APIChangeHistory__row1718161012571"><td class="cellrowborder" valign="top" width="33.58%" headers="mcps1.3.1.1.3.1.1 "><p id="APIChangeHistory__p51817107575">2023-12-06</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="66.42%" headers="mcps1.3.1.1.3.1.2 "><p id="APIChangeHistory__p161819108572">This release incorporates the following changes:</p>
|
||||
<ul id="APIChangeHistory__ul12434202045710"><li id="APIChangeHistory__li184341120175714">Modified the descriptions of the tag key and value in the document.</li><li id="APIChangeHistory__li597341255814">Modified the description of the status code in "Querying AZs."</li></ul>
|
||||
|
@ -522,7 +522,7 @@
|
||||
"code":"58"
|
||||
},
|
||||
{
|
||||
"desc":"This section describes fine-grained permissions management for your Enterprise Router resources. If your account does not need individual IAM users, you may skip this sec",
|
||||
"desc":"This topic describes fine-grained permissions management for your Enterprise Router resources. If your account does not need individual IAM users, you may skip this topic",
|
||||
"product_code":"er",
|
||||
"title":"Introduction",
|
||||
"uri":"er_02_0016.html",
|
||||
|
@ -115,7 +115,7 @@
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="20%" headers="mcps1.3.3.4.2.5.1.3 "><p>Long</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="40%" headers="mcps1.3.3.4.2.5.1.4 "><p>Enterprise router BGP ASN</p>
|
||||
<td class="cellrowborder" valign="top" width="40%" headers="mcps1.3.3.4.2.5.1.4 "><p>Enterprise router BGP ASN. Specify a dedicated ASN in the range of 64512-65534 or 4200000000-4294967294. ASN can only be set during enterprise router creation.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr><td class="cellrowborder" valign="top" width="20%" headers="mcps1.3.3.4.2.5.1.1 "><p>enterprise_project_id</p>
|
||||
|
@ -142,7 +142,7 @@
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="20%" headers="mcps1.3.3.4.2.5.1.3 "><p>Boolean</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="40%" headers="mcps1.3.3.4.2.5.1.4 "><p>The default value is false. If the value is set to true, a route with the enterprise router as the next hop will be automatically added to the route tables of the VPC.</p>
|
||||
<td class="cellrowborder" valign="top" width="40%" headers="mcps1.3.3.4.2.5.1.4 "><p>The default value is false. If the value is set to true, a route with the enterprise router as the next hop will be automatically added to the route tables of the VPC. This parameter can only be enabled when a VPC attachment is created.</p>
|
||||
<p>Default: <strong>false</strong></p>
|
||||
</td>
|
||||
</tr>
|
||||
|
@ -1,9 +1,9 @@
|
||||
<a name="er_02_0016"></a><a name="er_02_0016"></a>
|
||||
|
||||
<h1 class="topictitle1">Introduction</h1>
|
||||
<div id="body0000001150607954"><p id="er_02_0016__en-us_topic_0166806405_p8060118">This section describes fine-grained permissions management for your Enterprise Router resources. If your account does not need individual IAM users, you may skip this section.</p>
|
||||
<div id="body0000001150607954"><p id="er_02_0016__en-us_topic_0166806405_p8060118">This topic describes fine-grained permissions management for your Enterprise Router resources. If your account does not need individual IAM users, you may skip this topic.</p>
|
||||
<p id="er_02_0016__a1f386e3a1c8c4ff381a0c29cc5cc9eaf">By default, new IAM users do not have any permissions assigned. You need to add a user to one or more groups, and assign policies or roles to these groups. The user then inherits permissions from the groups. After authorization, the user can perform specified operations on cloud services based on the permissions.</p>
|
||||
<p id="er_02_0016__ae91c77fbfe6247faa6db52521a7971ee">An account has all of the permissions required to call all APIs, but IAM users must be assigned the required permissions. The permissions required for calling an API are determined by the actions supported by the API. Only users who have been granted permissions can call the API successfully. For example, if an IAM user wants to query enterprise routers using an API, the user must have been granted permissions that allow the <strong id="er_02_0016__b91541911141817">er:instances:list</strong> action.</p>
|
||||
<p id="er_02_0016__ae91c77fbfe6247faa6db52521a7971ee">An account has all of the permissions required to call all APIs, but IAM users must be assigned the required permissions. The permissions required for calling an API are determined by the actions supported by the API. Only users who have been granted permissions can call the API successfully. For example, if an IAM user wants to query the enterprise router list using an API, the user must have been granted permissions that allow the <strong id="er_02_0016__b91541911141817">er:instances:list</strong> action.</p>
|
||||
<div class="section" id="er_02_0016__s0c7a9b31e4de44d2b6f9a2d280a7f414"><h4 class="sectiontitle">Supported Actions</h4><p id="er_02_0016__en-us_topic_0166806405_p52064552499">IAM provides system-defined policies that can be directly used. You can also create custom policies to work with system-defined policies for more refined access control. Actions supported by policies are specific to APIs. Common concepts related to policies include:</p>
|
||||
<ul id="er_02_0016__u8d9007de06234085928a29ef0c6e58e0"><li id="er_02_0016__l04fdc83678e447f49aff210d2949b242">Permissions: allow or deny operations on specified resources under specific conditions.</li><li id="er_02_0016__li84151023147">APIs: REST APIs that can be called by a user who has been granted specific permissions</li><li id="er_02_0016__en-us_topic_0166806405_li84486140474">Actions: specific operations that are allowed or denied</li><li id="er_02_0016__li6132171512144">Related actions: actions on which a specific action depends. When assigning permissions for the action to a user, you also need to assign permissions for the dependent actions.</li><li id="er_02_0016__li61351453151518">IAM projects or enterprise projects: type of projects for which an action will take effect. For example, if you set the authorization scope of a custom policy to both IAM projects and enterprise projects, the policy takes effect for user groups in either IAM or enterprise projects. If the authorization scope is set to IAM projects only, the custom policy will take effect only for user groups in IAM projects. Administrators can check whether an action supports IAM projects or enterprise projects in the action list. "√" indicates that the action supports the project and "×" indicates that the action does not support the project. </li></ul>
|
||||
<div class="p" id="er_02_0016__p17404162120396">Enterprise Router supports the following actions that can be defined in custom policies:<ul id="er_02_0016__u79a4719ae58248a9b6a9cac462ec0fc6"><li id="er_02_0016__lfe0e194a7f4f454e88ae9a07f0bc9ec3"><a href="er_02_0017.html">Enterprise Routers</a></li><li id="er_02_0016__li862543317242"><a href="er_02_0018.html">VPC Attachments</a></li><li id="er_02_0016__li1169838112415"><a href="er_02_0019.html">Attachments</a></li><li id="er_02_0016__li193243427242"><a href="er_02_0020.html">Route Tables</a></li><li id="er_02_0016__li126372470246"><a href="er_02_0021.html">Associations</a></li><li id="er_02_0016__li675805182418"><a href="er_02_0022.html">Propagations</a></li><li id="er_02_0016__li9999155620243"><a href="er_02_0023.html">Routes</a></li><li id="er_02_0016__li19745143771916"><a href="er_02_0024.html">Flow Logs</a></li><li id="er_02_0016__li59121233183311"><a href="er_02_0033.html">Tags</a></li><li id="er_02_0016__li193451341143319"><a href="er_02_0034.html">Quota Management</a></li></ul>
|
||||
|
Loading…
x
Reference in New Issue
Block a user