tencent cloud

Feedback

Direct Connect

Last updated: 2024-05-02 09:05:39

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    Physical Direct Connect dc Supported Supported Resource level Partially supported

    Note:

    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    AcceptDirectConnectTunnel This interface used to accept DirectConnectTunnel Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    CreateDirectConnect CreateDirectConnect Operation level * Supported
    CreateDirectConnectTunnel This interface used to create DirectConnectTunnel Operation level * Supported
    CreateDirectConnectTunnelDetectionTask This interface is used to create Direct Connect Tunnel Detection task Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    CreateLetterOfAuthorization CreateLetterOfAuthorization Operation level * Supported
    CreatePublicDirectConnectTunnel This interface is used to create Public Direct Connect Tunnel Operation level * Supported
    DeleteDirectConnect DeleteDirectConnect Operation level * Supported
    DeleteDirectConnectTunnel This interface used to delete DirectConnectTunnel Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    DeleteDirectConnectTunnelDetectionTask This interface is used to delete Direct Connect Tunnel Detection task Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    ModifyDirectConnectAttribute ModifyDirectConnectAttribute Operation level * Supported
    ModifyDirectConnectTunnelAttribute This interface used to modify DirectConnectTunnle\\\'s attribute Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    ModifyDirectConnectTunnelExtra This interface is used to modify Direct Connect Tunnel\\\'s extra attributes Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    ModifyDirectConnectTunnelUpOrDown This interface is used to modify Direct Connect Tunnel\\\'s up down status Resource level qcs::dc::uin/:dcx/${DirectConnectTunnelId} Supported
    ModifyLetterOfAuthorization ModifyLetterOfAuthorization Operation level * Supported
    RejectDirectConnectTunnel This interface used to reject DirectConnectTunnle Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeAccessPoints DescribeAccessPoints Operation level * Supported
    DescribeDirectConnectTunnelDetectionTasks This interface is used to query Direct Connect Tunnel Detection tasks Resource level qcs::dc::uin/${Uin}/:dcx/${InstanceId} Supported
    DescribeDirectConnectTunnelExtra This interface is used to query Direct Connect Tunnel\\\'s extra attributes Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    DescribeDirectConnects DescribeDirectConnects Operation level * Supported
    DescribeLetterOfAuthorizations DescribeLetterOfAuthorizations Operation level * Supported
    DescribePublicDirectConnectTunnelRoutes This interface is used to query Public Direct Connect Tunnel\\\'s routes Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
    IsDirectConnectUplinkAccess IsDirectConnectUplinkAccess Operation level * Supported
    IsNonStandardTunnel This interface is used to check Direct Connect Tunnel Operation level * Supported
    IsSameRegion This interface is used to check access points is same region Operation level * Supported

    List Operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    DescribeDirectConnectTunnels This interface used to query DirectConnectTunnel Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} not supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support