Under the corporate account CompanyExample (ownerUin 12345678), there is a sub-account named Developer. This sub-account requires the permission to view the elastic IP addresses in the CVM console, and to use the elastic IP addresses under the CVM service of the corporate account CompanyExample.
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"action": ["cvm:AllocateAddresses","cvm:AssociateAddress","cvm:DescribeAddresses","cvm:DisassociateAddress","cvm:ModifyAddressAttribute","cvm:ReleaseAddresses"],"resource": "*","effect": "allow"}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.
The following policy allows the sub-account to view elastic IP addresses, assign it to instances, and associate it with them. The sub-account can modify the properties of elastic IP addresses, disassociate elastic IP addresses, or release elastic IP addresses.
1. Create a policy through policy syntax.
{"version": "2.0","statement": [{"action": ["cvm:DescribeAddresses","cvm:AllocateAddresses","cvm:AssociateAddress"],"resource": "*","effect": "allow"}]}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.