Help & Documentation>Cloud Access Management>Business Use Cases>TencentDB for MySQL>Granting a sub-account the operational permissions for CDB in a specific region

Granting a sub-account the operational permissions for CDB in a specific region

Last updated: 2024-09-20 10:10:29
Under the corporate account CompanyExample (with ownerUin as 12345678), there is a sub-account named cdb. This sub-account has been granted full operation permissions (*) for all CDB instances within a specific region (gz). Specifically, this sub-account has the permission to execute any operation on these CDB instances.
1. Create a policy through policy syntax.
{
"version": "2.0"
"statement": [
{
"action": "cdb:*",
"resource": "qcs::cdb:gz::*",
"effect": "allow"
}
]
}
action: Indicates the permitted operation. cdb:* signifies that all CDB operations are allowed.
effect: Indicates whether the permission described in the statement is allowed or denied. allow signifies that the permission is allowed.
resource: Indicates the scope of resources applicable to this statement. qcs::cdb:gz::* signifies that the sub-account is granted full operation permissions for all CDB instances within a specific region (gz). * represents a wildcard, indicating permissions for all instances.
2. Grant this policy to the sub-account. For the authorization method, please see Authorization Management.