tencent cloud

访问管理

大模型服务平台 TokenHub

PDF
聚焦模式
字号
最后更新时间: 2026-04-29 10:03:05

服务(相关)角色是由腾讯云服务预定义,经用户授权后相应服务即可通过扮演服务相关角色对用户资源进行访问操作。本文档介绍具体服务相关角色的使用场景及相关权限策略信息。

CAM中产品名 角色名称 角色类型 角色载体
TokenHub TokenHub_QCSLinkedRoleInBatchInference 服务相关角色 batchinference.tokenhub.cloud.tencent.com
TokenHub TokenHub_QCSLinkedRoleInInternalAccess 服务相关角色 internalaccess.tokenhub.cloud.tencent.com

TokenHub_QCSLinkedRoleInBatchInference

使用场景: 当前角色为 TokenHub 服务相关角色,用于授权 TokenHub 访问 COS ,无需用户托管密钥,操作更高效、更安全。该角色将在已关联策略的权限范围内访问您的 COS 资源
权限策略

  • 策略名称: QcloudAccessForTokenhubRoleInBatchInference
  • 策略内容:
    {
      "version": "2.0",
      "statement": [
          {
              "effect": "allow",
              "action": [
                  "cos:AbortMultipartUpload",
                  "cos:DeleteMultipleObjects",
                  "cos:DeleteObject",
                  "cos:GetBucket",
                  "cos:GetObject",
                  "cos:HeadBucket",
                  "cos:HeadObject",
                  "cos:ListMultipartUploads",
                  "cos:PutBucket",
                  "cos:PutObject",
                  "cos:ListParts",
                  "cos:UploadPart",
                  "cos:UploadPartCopy",
                  "cos:PutObjectCopy",
                  "cos:InitiateMultipartUpload",
                  "cos:CompleteMultipartUpload"
              ],
              "resource": "*"
          }
      ]
    }
    

TokenHub_QCSLinkedRoleInInternalAccess

使用场景: 当前角色为 TokenHub 服务相关角色,用于授权 TokenHub 访问 VPC,无需用户托管密钥,操作更高效、更安全。该角色将在已关联策略的权限范围内访问您的 VPC 资源
权限策略

  • 策略名称: QcloudAccessForTokenhubRoleInInternalAccess
  • 策略内容:
    {
      "version": "2.0",
      "statement": [
          {
              "effect": "allow",
              "action": [
                  "privatedns:ModifyPrivateZoneVpc",
                  "privatedns:ModifyPrivateZone",
                  "privatedns:DeletePrivateZoneRecord",
                  "privatedns:ModifyPrivateZoneRecord",
                  "privatedns:CreatePrivateZoneRecord",
                  "privatedns:CreatePrivateZone",
                  "vpc:CreateVpcEndPoint",
                  "vpc:DeleteVpcEndPoint",
                  "vpc:CheckVpcEndPointServiceExist",
                  "privatedns:AddSpecifyPrivateZoneVpc",
                  "privatedns:DescribePrivateZoneList",
                  "privatedns:DeletePrivateZone",
                  "privatedns:DescribePrivateZoneRecordList",
                  "privatedns:DeleteSpecifyPrivateZoneVpc",
                  "vpc:DescribeVpcEndPoint",
                  "vpc:DescribeVpcs",
                  "vpc:DescribeSubnets"
              ],
              "resource": "*"
          }
      ]
    }
    

帮助和支持

本页内容是否解决了您的问题?

填写满意度调查问卷,共创更好文档体验。

文档反馈