Help & Documentation>Cloud Access Management>Business Use Cases>VPC>Granting operational permissions for a specific VPC to the sub-account

Granting operational permissions for a specific VPC to the sub-account

Last updated: 2024-09-30 16:59:47
Under the corporate account CompanyExample (with ownerUin 12345678), there is a sub-account named Developer. This sub-account requires operation permissions for a specific VPC (with ID vpc-id1) under the VPC service of the corporate account CompanyExample, as well as the network resources under this VPC (such as subnets, routing tables, and so on, excluding CVM, databases, and so on).
1. Create a policy through policy syntax.
{
"version": "2.0",
"statement": [
{
"action": "vpc:*",
"resource": "*",
"effect": "allow",
"condition": {
"string_equal_if_exist": {
"vpc:vpc": [
"vpc-id1"
],
"vpc:accepter_vpc": [
"vpc-id1"
],
"vpc:requester_vpc": [
"vpc-id1"
]
}
}
}
]
}
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.