Data Lake Compute has a complete access control mechanism and divides permissions into operation permissions and data permissions. The former is managed by CAM, while the latter is managed by the permission module of Data Lake Compute.
A root account has all the operation and data permissions of Data Lake Compute by default.
If a sub-user is granted the operation permissions of Data Lake Compute, the sub-user can grant the data permissions to other sub-users and can be regarded as an "admin" of this type of sub-users.
If a sub-user is granted the data read/write permissions, the sub-user can query data as permitted. The data permissions are granted by an "admin".
The data permissions of all sub-users other than root accounts are granted by an "admin". They cannot query data which they don't have permissions on.
A root account has all the operation permissions of Data Lake Compute by default and can grant sub-users the access permissions of Data Lake Compute through CAM, so that the sub-users can have corresponding operation permissions of Data Lake Compute. This document primarily explains operation permissions.
CAM Permission Policy
DLC's current operation permissions are implemented through CAM. They support two permission control methods: preset policies provided by the DLC product and custom policies managed by customers themselves.
Preset policies:
DLC currently defines two preset policies:
QcloudDLCFullAccess: Full read/write access to Data Lake Compute (DLC). This policy includes read and write permissions for all APIs that DLC integrates with CAM. Users can directly grant this policy to sub-accounts. However, this may result in excessive permissions. Please proceed with caution.
QcloudDLCReadOnlyAccess: Read-only access to Data Lake Compute (DLC). This policy includes permissions for all read-only APIs that DLC integrates with CAM. Users can directly grant this policy to sub-accounts. However, it does not include any modification permissions.
Note:
1. To view the specific APIs included in QcloudDLCFullAccess and QcloudDLCReadOnlyAccess, navigate to Access Management > Policies in the left-side menu > QcloudDLCFullAccess / QcloudDLCReadOnlyAccess details page > Service > Data Lake Compute (DLC).
2. QcloudDLCFullAccess and QcloudDLCReadOnlyAccess only include API permissions for the DLC product itself. Some DLC capabilities rely on other cloud products. When using these capabilities, you must additionally grant sub-accounts the corresponding API permissions for those products. For the required API permissions and authorization operations for each product, see the appendix of this document.
CAM custom policies:
Users can create custom permission policies through the CAM console to achieve flexible permission management. CAM provides three methods for authorizing custom policies. Taking the policy generator method as an example, you can refer to Creating a Custom Policy via the Policy Generator. Operation Permission Classification
Data Lake Compute operation permissions are categorized by API as follows. For details, see the API documentation. |
Metadata Management | Manipulate the metadata information of databases and data tables managed in Data Lake Compute. |
Task Management | Submit and view tasks in Data Lake Compute. |
Permission Management | Manage users' data access permissions. |
System Configuration | Perform basic configurations of the Data Lake Compute service. |
Preset Policy Authorization Operations
This procedure uses <Granting QcloudDLCFullAccess to a Sub-account> as an example. The operation steps are as follows:
1. Create a sub-user.
3. The sub-user logs into the DLC console and verifies permissions. If the sub-user successfully logs into the console and performs the data permission authorization operation, the CAM permission authorization takes effect.
Custom Policy Authorization Operations
If you access Data Lake Compute as a root account, skip this step. Sub-accounts must be authorized before the DLC service can be enabled. The authorization process is as follows:
2. Create a custom policy.
On the Policies page in the CAM console, click Create Custom Policy. In the pop-up window, click Create by Policy Syntax.
On the Create by Policy Syntax page, select Blank Template and click Next.
In the template, enter the Policy Name (e.g., DLCDataAccess) and Description, copy the following policy, paste it into Policy Content, and click Complete. A sub-user bound to the custom policy can log in to the Data Lake Compute console to run SQL tasks but cannot manage data permissions.
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"dlc:DescribeStoreLocation",
"dlc:DescribeTable",
"dlc:DescribeViews",
"dlc:CancelTask",
"dlc:CreateDatabase",
"dlc:CreateScript",
"dlc:CreateTable",
"dlc:CreateTask",
"dlc:DeleteScript",
"dlc:DescribeDatabases",
"dlc:DescribeScripts",
"dlc:DescribeTables",
"dlc:DescribeTasks",
"dlc:DescribeQueue",
"dlc:DescribeTaskResult"
],
"resource": [
"*"
]
}
]
}
3. Bind the custom policy DLCDataAccess to the sub-account that accesses DLC. Then the sub-account can log into and access DLC. For details, see Sub-user Permission Settings. Appendix
Some DLC capabilities are implemented by other cloud products, such as Cloud Monitor and Tag. When using these capabilities, you must additionally grant sub-accounts the corresponding API permissions for those products. Root accounts can grant the corresponding operation permissions to sub-accounts as needed. The related operation APIs are listed in the following table:
|
Data jobs/Storage management | COS | GetService | |
SuperSQL Engine > Cluster Monitoring Standard Engine > Cluster Monitoring Resource Group > Resource Group Monitoring | Monitor | DescribeDashboardMetrics | Queries the Dashboard2.0 metric list. |
|
| DescribeMonitorProductByIds | Queries the monitoring product list by ID. |
|
| DescribeDashboardMetricData | Queries Dashboard2.0 metric monitoring data. |
SuperSQL Engine Standard Engine Storage management | TAG | DescribeTagKeys | Queries tag keys. |
|
| AttachResourcesTag | Binds tags to resources in batches. |
|
| DetachResourcesTag | Unbinds tags from resources in batches. |
Network Connection Configuration / Metadata Management | MySQL | DescribeDBInstances | Queries the list. |
| TencentDB for PostgreSQL | DescribeDBInstances | Queries the instance list |
| TencentDB for SQL Server | DescribeDBInstances | Queries the instance list |
This section uses the permissions required to view monitoring data on the DLC console page as an example to describe the process for a root account to grant TCOP permissions to a sub-account.
2. Create a custom policy. This example uses the Create a Custom Policy via the Policy Generator method. The operation flow is: Access Management > Policies > Create Custom Policy > Create by Policy Generator. The creation details are shown in the following figure. For other creation processes, see the official CAM documentation. You can configure additional items such as API permissions, policy names, Tag settings, and associated users/user groups/roles as needed. This document only demonstrates the minimum configuration required to enable monitoring view in the DLC console.
3. Grant the policy defined in Step 2 to the sub-account. This step can be performed either when the policy is created or after the full policy creation is completed on the User, User Group, and Role Authorization page.