tencent cloud

Cloud Access Management

Product Introduction
CAM Overview
Features
Scenarios
Basic Concepts
Use Limits
User Types
Purchase Guide
Getting Started
Creating Admin User
Creating and Authorizing Sub-account
Logging In to Console with Sub-account
User Guide
Overview
Users
Access Key
User Groups
Role
Identity Provider
Policies
Permissions Boundary
Troubleshooting
Downloading Security Analysis Report
CAM-Enabled Role
Overview
Compute
Container
Microservice
Essential Storage Service
Data Process and Analysis
Data Migration
Relational Database
Enterprise Distributed DBMS
NoSQL Database
Database SaaS Tool
Database SaaS Service
Networking
CDN and Acceleration
Network Security
Data Security
Application Security
Domains & Websites
Big Data
Middleware
Interactive Video Services
Real-Time Interaction
Media On-Demand
Media Process Services
Media Process
Cloud Real-time Rendering
Game Services
Cloud Resource Management
Management and Audit Tools
Developer Tools
Monitor and Operation
More
CAM-Enabled API
Overview
Compute
Edge Computing
Container
Distributed cloud
Microservice
Serverless
Essential Storage Service
Data Process and Analysis
Data Migration
Relational Database
Enterprise Distributed DBMS
NoSQL Database
Database SaaS Tool
Networking
CDN and Acceleration
Network Security
Endpoint Security
Data Security
Business Security
Application Security
Domains & Websites
Office Collaboration
Big Data
Voice Technology
Image Creation
Tencent Big Model
AI Platform Service
Natural Language Processing
Optical Character Recognition
Middleware
Communication
Interactive Video Services
Real-Time Interaction
Stream Services
Media On-Demand
Media Process Services
Media Process
Cloud Real-time Rendering
Game Services
Education Sevices
Medical Services
Cloud Resource Management
Management and Audit Tools
Developer Tools
Monitor and Operation
More
Use Cases
Security Practical Tutorial
Multi-Identity Personnel Permission Management
Authorizing Certain Operations by Tag
Supporting Isolated Resource Access for Employees
Enterprise Multi-Account Permissions Management
Reviewing Employee Operation Records on Tencent Cloud
Implementing Attribute-Based Access Control for Employee Resource Permissions Management
During tag-based authentication, only tag key matching is supported
Business Use Cases
TencentDB for MySQL
CLB
CMQ
COS
CVM
VPC
VOD
Others
API Documentation
History
Introduction
API Category
Making API Requests
User APIs
Policy APIs
Role APIs
Identity Provider APIs
Data Types
Error Codes
FAQs
Role
Key
Others
CAM Users and Permissions
Glossary

Direct Connect

PDF
포커스 모드
폰트 크기
마지막 업데이트 시간: 2026-04-03 09:42:26

Fundamental information

Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
Physical Direct Connect dc Supported Supported Resource level Partially supported

Note:

The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

  • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
  • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
  • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

API authorization granularity

Two authorization granularity levels of API are supported: resource level, and operation level.

  • Resource level: It supports the authorization of a specific resource.
  • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

Write operations

API API Description Authorization Granularity Six-segment Resource Description IP Restriction
AcceptDirectConnectTunnel This interface is used to accept Direct Connect Tunnel Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
ApplyInternetAddress Apply Internet Address Operation level * not supported
ApproveCloudAttachServiceBandwidthChange ApproveCloudAttachServiceBandwidthChange Operation level * Supported
CancelCloudAttachServiceBandwidthChange CancelCloudAttachServiceBandwidthChange Operation level * Supported
ConfirmCloudAttachServiceBandwidthChange Confirm the completion of the high-speed cloud instance configuration change acceptance Operation level * Supported
CreateCloudAttachService Create Cloud Attach Service Operation level * Supported
CreateCloudAttachServiceGateway Create a high-speed cloud gateway Operation level * Supported
CreateDirectConnect Create Direct Connect Resource level qcs::dc::uin/${uin}:dc/${DirectConnectId} Supported
CreateDirectConnectMacSecKey Create Direct Connect MACsec Key Operation level * Supported
CreateDirectConnectTunnel This interface is used to create Direct Connect Tunnel Resource level qcs::dc::uin/${uin}:dcx/${DirectConnectTunnelId} Supported
CreateDirectConnectTunnelDetectionTask This interface is used to create Direct Connect Tunnel Detection task Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
CreateLetterOfAuthorization CreateLetterOfAuthorization Operation level * Supported
CreatePublicDirectConnectTunnel This interface is used to create Public Direct Connect Tunnel Resource level qcs::dc::uin/${uin}:dcx/${DirectConnectTunnelId} Supported
CreateTcapIpCertificate Create tcap ip certificate Operation level * Supported
CreateTcapIps Create tcap ip network segment Operation level * Supported
CreateTcapVif Create tcap channel Operation level * Supported
CreateUnderlayAclRule Create Underlay Acl Rule Operation level * Supported
CreateUnderlayIpWhitelistIntranetChange Create Underlay IpWhitelist Intranet Change Operation level * Supported
DeleteCloudExchange Delete Cloud Exchange Service Operation level * Supported
DeleteDirectConnect Delete Direct Connect Resource level qcs::dc::uin/${uin}:dc/${DeleteDirectConnect} Supported
DeleteDirectConnectMacSecKey Delete Direct Connect MACsec Key Operation level * Supported
DeleteDirectConnectTunnel This interface is used to delete Direct Connect Tunnel Resource level qcs::dc::uin/${Uin}:dcx/${DirectConnectTunnelId} Supported
DeleteDirectConnectTunnelDetectionTask This interface is used to delete Direct Connect Tunnel Detection task Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
DeleteTcapIpCertificate delete tcap ip certificate Operation level * Supported
DeleteTcapIps Delete tcap ip network segment Operation level * Supported
DeleteTcapVif Delete tcap channel Operation level * Supported
DeleteUnderlayAclRule Delete Underlay Acl Rule Operation level * Supported
DisableDirectConnectMacSec Disable Direct Connect MACsec Operation level * Supported
DisableInternetAddress Disable Internet Address Operation level * not supported
EnableDirectConnectMacSec Enable Direct Connect MACsec Operation level * Supported
EnableInternetAddress Enable Internet Address Operation level * not supported
ModifyDirectConnectAttribute Modify Direct Connect Attribute Resource level qcs::dc::uin/${uin}:dc/${DirectConnectId} Supported
ModifyDirectConnectTunnelAttribute This interface is used to modify Direct Connect Tunnel Resource level qcs::dc::uin/${Uin}:dcx/${DirectConnectTunnelId} Supported
ModifyDirectConnectTunnelExtra This interface is used to modify Direct Connect Tunnels extra attributes Resource level qcs::dc::uin/${Uin}:dcx/${DirectConnectTunnelId} Supported
ModifyDirectConnectTunnelUpOrDown This interface is used to modify Direct Connect Tunnel\\\\\\\'s up down status Resource level qcs::dc::uin/:dcx/${DirectConnectTunnelId} Supported
ModifyLetterOfAuthorization ModifyLetterOfAuthorization Operation level * Supported
RejectCloudAttachServiceBandwidthChange Reject high-speed cloud instance changes Operation level * Supported
RejectCloudExchange Reject cloud exchange service Operation level * Supported
RejectDirectConnectTunnel This interface is used to reject Direct Connect Tunnel Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
ReleaseInternetAddress Release Internet Address Operation level * not supported
SplitInternetAddress Split Internet public addresses Operation level * Supported
UpdateCloudAttachServiceGateway Update high-speed cloud service gateway information Operation level * Supported
UpdateTcapVif Update tcap channel Operation level * Supported
UpdateVifNetDetect Update private channel network probe Operation level * Supported

Read operations

API API Description Authorization Granularity Six-segment Resource Description IP Restriction
ApplyCloudAttachServiceBandwidthChange ApplyCloudAttachServiceBandwidthChange Operation level * Supported
CheckWhiteList Check Whitelist Operation level * Supported
DescribeCloudExchangePrice Describe Cloud Exchange Price Operation level * Supported
DescribeDirectConnectAlarms Query all alarm information related to Directconnect Operation level * Supported
DescribeDirectConnectGatewaysOverView Get overview information of directconnect gateway Operation level * Supported
DescribeDirectConnectMacSec Describe Direct Connect MACsec Operation level * Supported
DescribeDirectConnectOverView Obtain directconnect overview information Operation level * Supported
DescribeDirectConnectTunnelDetectionTasks This interface is used to query Direct Connect Tunnel Detection tasks Resource level qcs::dc::uin/${Uin}/:dcx/${InstanceId} Supported
DescribeDirectConnectTunnelExtra This interface is used to query Direct Connect Tunnel\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'s extra attributes Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
DescribeDirectConnectTunnelOverView Describe DirectConnect Tunnel OverView Operation level * Supported
DescribeDirectConnectTunnelRouteLimit Describe Direct Connect Tunnel Route Limit Operation level * Supported
DescribeDirectConnectTunnelRoutes Describe Direct Connect Route List Operation level * Supported
DescribeDirectConnects query Direct Connect Resource level qcs::dc::uin/${uin}:dc/${InstanceId} Supported
DescribeDirectConnectsAdmin Describe Direct Connects Admin Operation level * Supported
DescribeGroupAgileOntoClouds Describe Group Agile Onto Cloud List Operation level * Supported
DescribeInternetAddress Describe Internet IP Address Operation level * not supported
DescribeInternetAddressQuota Get Internet IP Address Quota Operation level * Supported
DescribeInternetAddressStatistics Describe Internet IP Address Statistics Operation level * Supported
DescribeLetterOfAuthorizations DescribeLetterOfAuthorizations Operation level * Supported
DescribePublicDirectConnectTunnelRoutes This interface is used to query Public Direct Connect Tunnel\\\\\\\\\\\\\\\'s routes Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} Supported
DescribeQosQueueStatisticsByDCID Query QOS queue statistics based on dedicated line ID Operation level * Supported
DoDcHealthInspection DoDcHealthInspection Operation level * Supported
InquirePriceCloudAttachServiceBandwidthChange High-speed cloud configuration inquiry Operation level * Supported
InquiryPriceDirectConnectPort Get the monthly rental price of the dedicated line port Operation level * Supported
IsDirectConnectUplinkAccess IsDirectConnectUplinkAccess Operation level * Supported
IsNonStandardTunnel This interface is used to check Direct Connect Tunnel Operation level * Supported
IsSameRegion This interface is used to check access points is same region Operation level * Supported
ModifyManagedDeviceStatusNotification Modify Managed Device Status Notification Operation level * Supported

List Operations

API API Description Authorization Granularity Six-segment Resource Description IP Restriction
DescribeAccessPointList Retrieve information about the carrier and port type under the access point. Operation level * Supported
DescribeAccessPoints This interface is used to query Direct Connect access point Operation level * Supported
DescribeAccessRegions Query access region list Operation level * Supported
DescribeDirectConnectAlarmsAdmin Query all alarm information related to Directconnect Operation level * Supported
DescribeDirectConnectTunnels This interface is used to query Direct Connect Tunnel information Resource level qcs::dc::uin/${Uin}:dcx/${InstanceId} not supported
DescribeUnderlayAclRules Describe Underlay Acl Rules Operation level * Supported
DescribeUnderlayIpWhitelist Describe Underlay IpWhitelist Operation level * Supported

도움말 및 지원

문제 해결에 도움이 되었나요?

피드백