Help & DocumentationCloud Access ManagementBusiness Use CaseCOS-related CasesAuthorizing Sub-account Read-only Access to COS Resources

Authorizing Sub-account Read-only Access to COS Resources

Last updated: 2019-12-04 10:44:16

PDF

A sub-account Developer under the enterprise account CompanyExample (ownerUin is 12345678) requires read-only permission (accessing COS buckets or objects and object list) of the COS service under the enterprise account CompanyExample.

Solution A:

The enterprise account CompanyExample directly authorizes the preset policy QcloudCOSReadOnlyAccess to the sub-account Developer. For more information on authorization, please see Authorization Management.

Solution B:

Step 1: Create the following policy using policy syntax

 {
    "version": "2.0",
    "statement":[
     {
         "effect": "allow",
         "action":  [
                    "cos:List*",
                    "cos:Get*",
                    "cos:Head*",
                    "cos:OptionsObject"
                ],
         "resource": "*"
     }
   ]
}

Step 2: Authorize the policy to the sub-account. For more information on authorization, please see Authorization Management.