Sub-Account Authorization for Backup Download

Last updated: 2020-07-14 14:52:17

    Overview

    To download a backup with a sub-account, you need to first authorize the sub-account with the root account. This document describes how to grant a sub-account permissions on the CAM console.

    Directions

    1. Log in to the CAM Console, go to Policies from the left sidebar and click Create Custom Policy.
    2. Click Create by Policy Syntax in the pop-up dialog box.
    3. Select Blank Template and click Next.
    4. Set the policy content by referring to the following custom policy syntax, and click Done.
      • uid: the value is fixed to 1257588757.
      • COS bucket path: it can be obtained from Backup and Rollback tab on the instance details page in the MongoDB Console.

        Policy syntax (we are using cmongo-gz-backup-1257588757 for the COS bucket path in the following example):
        {
        "version": "2.0",
        "statement": [
           {
               "action": "cos:*",
               "effect": "allow",
               "resource": "qcs::cos::uid/1257588757:cmongo-gz-backup-1257588757/*"
           }
        ]
        }
    5. Return to Policies, locate the new policy, and click Associate in the "Operation" column to associate with the sub-account.
    6. After association, see Download Backup File for instructions on how to configure COSCMD for downloading backup files.

    Was this page helpful?

    Was this page helpful?

    • Not at all
    • Not very helpful
    • Somewhat helpful
    • Very helpful
    • Extremely helpful
    Send Feedback
    Help