tencent cloud

Application Load Balancer

Overview

Download
Focus Mode
Font Size
Last updated: 2026-09-28 16:39:10
AI-Translated & Reviewed
If you use services such as Application Load Balancer (ALB), Cloud Virtual Machine (CVM), and TencentDB, these services are managed by different personnel but all share your cloud account key, which causes the following issues:
Your key is shared among multiple personnel, leading to a high risk of leakage.
You are unable to restrict others' access permissions, which easily leads to accidental operations causing security risks.
Cloud Access Management (CAM) is used to manage resource access permissions under Tencent Cloud accounts. You can use CAM's identity management and policy management to control which sub-accounts have operation permissions on which resources.
For example, your account has multiple ALB instances deployed in different projects. To strengthen permission control and authorize resources, you can bind an authorization policy to the administrator of project A. The policy stipulates that only the administrator can operate the ALB resources under project A.
If you do not need to manage access to ALB-related resources for sub-accounts, you can skip this section. Skipping these parts does not affect your understanding and use of the rest of the document.

Basic Concepts of CAM

The root account grants permissions by binding policies to sub-accounts. Policy settings can be precise to the dimensions of Effect, Service, Action, Resource, and Condition.
1. Accounts
Root account
The basic entity for Tencent Cloud resource ownership and resource usage metering and billing. It can be used to log in to Tencent Cloud services.
Sub-account
An account created by the root account. It has a unique identity ID and identity credentials and can be used to log in to the Tencent Cloud console. A root account can create multiple sub-accounts (users). Sub-accounts do not own resources by default and must be authorized by their root account.
Identity credential
Login credentials and access certificates. Login credentials refer to the user login name and password, and access certificates refer to TencentCloud API keys (SecretId and SecretKey).
2. Resources and Permissions
Resource
An object in cloud services that can be operated on, such as a CVM instance or a Virtual Private Cloud (VPC) instance.
Permission
A permission that defines whether to allow or deny certain users to perform certain operations. By default, the root account has the permission to access all resources under its name, while sub-accounts do not have the permission to access any resources under the root account.
Policy
A syntax specification that defines and describes one or more permissions. The root account grants permissions by associating policies with users/user groups.
For more information, see CAM Overview.

References

Target
Link
Understand the relationship between policies and users.
Understand the policy syntax.
Learn about which other products support CAM.


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback