公網IP策略示例
當您需要授權(quan)某個子用戶(hu)“云主機綁(bang)定/解(jie)綁(bang)公網IP”的(de)操(cao)作權(quan)限時,您可以(yi)這樣編(bian)輯(ji)策略:
例1:公網(wang)IP綁定默認私網(wang)下的云主機
{
"Version": "1",
"Statement": [
{
"Effect": "Allow",
"Action": [
"vpc:DescribeEip*",
"vpc:*ssociateEip*",
"cec:DescribeInstance*",
"vpc:AssociateEip",
"vpc:DescribeNetworks"
],
"Resource": [
"ccs:vpc:cn-test-suzhou1:*:eip-rv180h4obpg13u",
"ccs:cec:cn-test-suzhou1:*:i-ay180h4ob3k20t",
"ccs:vpc:cn-test-suzhou1:*:n-sc180h4nfc348e"
]
},
{
"Effect": "Allow",
"Action": [
"vpc:DescribeEips",
"cec:DescribeInstance*"
],
"Resource": [
"ccs:vpc:cn-test-suzhou1:*:eip-1",
"ccs:cec:cn-test-suzhou1:*:-1"
]
}
]
}
例2:公網IP綁定(ding)(ding)自(zi)(zi)定(ding)(ding)義(yi)私(si)網下的云主機(此(ci)時需(xu)要把自(zi)(zi)定(ding)(ding)義(yi)私(si)網連接的路由器的相關權限也給到子(zi)用(yong)戶)
{
"Version": "1",
"Statement": [
{
"Effect": "Allow",
"Action": [
"vpc:*ssociateEip*",
"cec:DescribeInstance*"
],
"Resource": [
"ccs:vpc:cn-test-suzhou1:*:eip-rv180h4obpg13u",
"ccs:vpc:cn-test-suzhou1:*:n-3u180h4h9wa89",
"ccs:vpc:cn-test-suzhou1:*:r-g5180h4h9tv93x",
"ccs:cec:cn-test-suzhou1:*:-1"
]
},
{
"Effect": "Allow",
"Action": [
"vpc:DescribeEip*",
"vpc:*ssociateEip*",
"vpc:DescribeNetworks",
"vpc:DescribeRouter*"
],
"Resource": [
"ccs:vpc:cn-test-suzhou1:*:eip-rv180h4obpg13u",
"ccs:vpc:cn-test-suzhou1:*:n-3u180h4h9wa89",
"ccs:vpc:cn-test-suzhou1:*:r-g5180h4h9tv93x",
"ccs:vpc:cn-test-suzhou1:*:eip-1",
"ccs:vpc:cn-test-suzhou1:*:r-1"
]
}
]
}