tencent cloud

Feedback

Viewing and Configuring Shipping Permissions

Last updated: 2022-04-18 15:45:03

    Overview

    When creating a task for shipping logs to COS/CKafka, perform authorization in a corresponding way:

    • Via CLS console: Configure permissions according to the permission process provided in the console.
    • Via API call: Manually create the permissions to ship logs to COS/CKafka.
      Note

      If you do not configure the required permissions before making an API call, log shipping will fail. Check and configure the required permissions by referring to this document.

    This document describes how to check if you have the permissions to ship logs to COS/CKafka and how to create a log shipping task. If you do not have the permissions, create a log shipping task before configuring the permissions.

    Directions

    Checking whether you have the permissions to ship logs to COS/CKafka

    1. Log in to the CAM console, and select Roles on the left sidebar.

    2. On the Role page, check whether you have the CLS_QcsRole role. You can use the search box in the top-right corner of the role list to search for the role.

    3. Click the role name to go to the role details page.

    • Select the Permission tab to see if the role has the QcloudCOSAccessForCLSRole and QcloudCKAFKAAccessForCLSRole permissions.

    • Select the Role Entity tab to see if the role entity is cls.cloud.tencent.com.

    After confirming that you have the required role and permissions, you can create a task to ship logs to COS/CKafka. If you do not have the required role or permissions, create them as follows.

    Creating the permissions to ship logs to COS/CKafka

    You can use either of the following methods to create the permissions to ship logs to COS/CKafka:

    If this is the first time you create a task to ship logs to COS/CKafka in the CLS console, follow the instructions in the console to create the required role and policies:

    1. In the pop-up window that reads This feature requires creating a service role, click Go to Cloud Access Management.

    2. On the Role Management page, click Grant.

    Now you have created the permissions to ship logs to COS/CKafka. If you are using the root account, you can perform shipping operations directly. If you need to use a sub-account or collaborator for shipping, use the root account to grant the sub-account or collaborator with related shipping policies by referring to Shipping Authorization before performing shipping operations.

    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support