TCR Permissions Overview
The address format for Tencent Cloud container images is:
ccr.ccs.tencentyun.com/${namespace}/${name}:${tag}.
Permissions for image repositories are configured around the following two fields:${namespace}: The namespace to which the image repository belongs.${name}: The name of the image repository.Note
The namespace
${namespace} and image name ${name} must not contain a forward slash "/".
The ${tag} field currently only supports authorization for deletion operations. Please refer to Image Tag Permissions.Using the
${namespace} and ${name} fields, administrators can create detailed permission schemes for collaborators, enabling flexible permission management. For example:Permit collaborator A to pull images
Forbid collaborator A from deleting images
Forbid collaborator B from pulling the images in the namespace ns1
If you do not require detailed management of image repository permissions, you can use Preset Policy Authorization.
For more granular control over collaborator permissions, use Custom Policy Authorization.
TCR permissions are managed through Tencent Cloud CAM. You can learn more about using CAM in the following sections: User Management, Policy Management, and Authorization Management.
Preset Policy Authorization
To simplify TCR permissions management, two preset policies are configured in TCR:
Full Read/Write Access to Container Registry (CCR)
This preset policy configures all permissions for the container image service. If a collaborator is associated with this preset policy, they will have the same image repository permissions as the administrator. For more information, see Permission List.
Image Repository (CCR) Read-Only Access
This preset policy includes read-only permissions for the container image service. If a collaborator is only associated with this preset policy in the container image service, the following actions will be prohibited:
docker push Pushing an imageCreate a namespace of image registry
Delete a namespace of image registry
Create an image repository
Delete an image repository
Delete an image tag
If you do not know how to associate a collaborator with a preset policy, please see Policy and Authorization Management.
Custom Policy Authorization
With custom policies, administrators can associate different permissions for various collaborators.
When assigning permissions, please consider the following factors:
Resource: Which image repositories are associated with this permission policy, for example, all image repositories are described as
qcs::ccr:::repo/*. For more information, see CAM Resource Description Method.Action: The operations that the permission policy performs on the resource, such as deletion, creation, etc., usually described using an API.
Effect: The effect the permission policy has on the collaborator (Allow/Deny)
When you have planned the permission settings, you can assign the permissions. The following example shows how to "permit collaborators to create an image repository":
Step 1. Creating a custom policy
1. On the Policies page of the CAM console, click Create Custom Policy in the upper left corner.
2. In the pop-up window for selecting the creation method, click Create by Policy Syntax to proceed to the Select Policy Template page.
3. On the policy template selection page, choose Create by Policy Syntax > Blank Template.
4. Click Next to proceed to the Edit Policy page.
5. On the Edit Policy page, set the policy name to
ccr-policy-demo and enter the following content into the "Edit Policy Content" input box.{"version": "2.0","statement": [{"action": "ccr:CreateRepository","resource": "qcs::ccr:::repo/*","effect": "allow"}]}
6. Click Complete.
Step 2: Associate a Custom Policy
Upon completing the policy creation (ccr-policy-demo) in Step 1, you can associate it with any collaborator. For more information, see Authorization Management. Once the policy is associated, the collaborator will have the permission to create image repositories in any namespace.
"resource": "qcs::ccr:::repo/*" format explanation:qcs::ccr::: is a fixed format, indicating the developer's TCR service.repo is a fixed prefix, representing the resource type, which is an image repository here.The
* following the slash (/) represents a match for all image repositories.Authorizing by resource
You can grant permissions for multiple resources at a time. For example, to "permit the deletion of the image repositories in namespaces
foo and bar", you can create the following custom policy:{"version": "2.0","statement": [{"action": ["ccr:BatchDeleteRepository","ccr:DeleteRepository"],"resource": ["qcs::ccr:::repo/foo/*","qcs::ccr:::repo/bar/*"],"effect": "allow"}]}
Note
foo/* in qcs::ccr:::repo/foo/* means all images in the image repository namespace foo.bar/* in qcs::ccr:::repo/bar/* means all images in the image repository namespace bar.Authorizing by action (API)
You can configure multiple
actions for a single resource to achieve unified management of resource permissions. For example, to "allow creation, deletion, and push of image repositories in namespace foo," you can create the following custom policy:{"version": "2.0","statement": [{"action": ["ccr:CreateRepository","ccr:BatchDeleteRepository","ccr:DeleteRepository","ccr:push"],"resource": "qcs::ccr:::repo/foo/*","effect": "allow"}]}
Permission List
docker client permissions
resource:
qcs::ccr:::repo/${namespace}/${name}action:
ccr:pull: Use the docker command line to pull an imageccr:push: Use the docker command line to push an imageNamespace permissions
resource:
qcs::ccr:::repo/${namespace}action:
ccr:CreateCCRNamespace Create an image repository namespaceccr:DeleteUserNamespace Delete an image repository namespaceImage repository permissions
resource:
qcs::ccr:::repo/${namespace}/${name}action:
ccr:CreateRepository Create an image repositoryccr:DeleteRepository Delete an image repositoryccr:BatchDeleteRepository Batch delete image repositoriesccr:GetUserRepositoryList View the list of image repositoriesNote
To prevent a collaborator from deleting certain images, configure multiple actions.
For example, to prohibit deleting any image repository:
{"version": "2.0","statement": [{"action": ["ccr:BatchDeleteRepository","ccr:DeleteRepository"],"resource": "qcs::ccr:::repo/*","effect": "deny"}]}
Image Tag Permissions
resource:
qcs::ccr:::repo/${namespace}/${name}:${tag}action:
ccr:DeleteTag Delete image tag permissions