| CAM中产品名 | 角色名称 | 角色类型 | 角色载体 |
|---|---|---|---|
| TokenHub | TokenHub_QCSLinkedRoleInBatchInference | 服务相关角色 | batchinference.tokenhub.cloud.tencent.com |
| TokenHub | TokenHub_QCSLinkedRoleInInternalAccess | 服务相关角色 | internalaccess.tokenhub.cloud.tencent.com |
使用场景: 当前角色为 TokenHub 服务相关角色,用于授权 TokenHub 访问 COS ,无需用户托管密钥,操作更高效、更安全。该角色将在已关联策略的权限范围内访问您的 COS 资源
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"cos:AbortMultipartUpload",
"cos:DeleteMultipleObjects",
"cos:DeleteObject",
"cos:GetBucket",
"cos:GetObject",
"cos:HeadBucket",
"cos:HeadObject",
"cos:ListMultipartUploads",
"cos:PutBucket",
"cos:PutObject",
"cos:ListParts",
"cos:UploadPart",
"cos:UploadPartCopy",
"cos:PutObjectCopy",
"cos:InitiateMultipartUpload",
"cos:CompleteMultipartUpload"
],
"resource": "*"
}
]
}
使用场景: 当前角色为 TokenHub 服务相关角色,用于授权 TokenHub 访问 VPC,无需用户托管密钥,操作更高效、更安全。该角色将在已关联策略的权限范围内访问您的 VPC 资源
权限策略
{
"version": "2.0",
"statement": [
{
"effect": "allow",
"action": [
"privatedns:ModifyPrivateZoneVpc",
"privatedns:ModifyPrivateZone",
"privatedns:DeletePrivateZoneRecord",
"privatedns:ModifyPrivateZoneRecord",
"privatedns:CreatePrivateZoneRecord",
"privatedns:CreatePrivateZone",
"vpc:CreateVpcEndPoint",
"vpc:DeleteVpcEndPoint",
"vpc:CheckVpcEndPointServiceExist",
"privatedns:AddSpecifyPrivateZoneVpc",
"privatedns:DescribePrivateZoneList",
"privatedns:DeletePrivateZone",
"privatedns:DescribePrivateZoneRecordList",
"privatedns:DeleteSpecifyPrivateZoneVpc",
"vpc:DescribeVpcEndPoint",
"vpc:DescribeVpcs",
"vpc:DescribeSubnets"
],
"resource": "*"
}
]
}
文档反馈