tencent cloud

Cloud Access Management

Data Accelerator Goose FileSystem

Download
Modo Foco
Tamanho da Fonte
Última atualização: 2026-08-06 09:54:07

Service roles and service-linked roles are predefined by Tencent Cloud services and, upon user authorization, the corresponding services can access and use resources by assuming these service-linked roles. This document provides detailed information on the use cases and associated authorization policies of these specific service-linked roles.

Product Role Name Role Types Role Entity
Data Accelerator Goose File System GooseFS_QCSLinkedRoleInManageCloudService Service-Related Roles managecloudservice.goosefs.cloud.tencent.com
Data Accelerator Goose File System GooseFSMountPoint_QCSLinkedRoleInManageCloudServic Service-Related Roles GooseFSMountPoint.GooseFS.cloud.tencent.com

GooseFS_QCSLinkedRoleInManageCloudService

Use Cases: The current role is the GooseFS service linked role, which will access your other service resources within the scope of the permissions of the associated policy.
Authorization Polices

  • Policy Name: QcloudAccessForGooseFSLinkedRoleInManageCloudService
  • Policy Information:
    {
        "version": "2.0",
        "statement": [
            {
                "action": [
                    "vpc:DescribeVpcEx",
                    "vpc:DescribeVpcPrivateIpAddresses",
                    "vpc:DescribeSubnetEx",
                    "cvm:RunInstances",
                    "cvm:TerminateInstances",
                    "cvm:DescribeInstancesStatus",
                    "cvm:DescribeInstances",
                    "cvm:DescribeImages",
                    "tat:RunCommand",
                    "tat:DescribeInvocations",
                    "tat:DescribeAutomationAgentStatus",
                    "cos:GetBucket",
                    "cos:GetBucketObjectVersions",
                    "cos:PutObject",
                    "cos:PutObjectCopy",
                    "cos:PostObject",
                    "cos:AppendObject",
                    "cos:GetObject",
                    "cos:HeadBucket",
                    "cos:HeadObject",
                    "cos:DeleteObject",
                    "cos:OptionsObject",
                    "cos:PostObjectRestore",
                    "cos:InitiateMultipartUpload",
                    "cos:UploadPart",
                    "cos:UploadPartCopy",
                    "cos:CompleteMultipartUpload",
                    "cos:AbortMultipartUpload",
                    "cos:ListMultipartUploads",
                    "cos:ListParts",
                    "tat:DescribeInvocationTasks",
                    "cvm:DeleteSecurityGroup",
                    "cvm:CreateSecurityGroupWithPolicies",
                    "cvm:DescribeSecurityGroups",
                    "cvm:DescribeSecurityGroupAssociationStatistics",
                    "cvm:DescribeDisasterRecoverGroups",
                    "cvm:DescribeDisasterRecoverGroupQuota",
                    "cvm:CreateDisasterRecoverGroup",
                    "cvm:ModifyDisasterRecoverGroupAttribute",
                    "cvm:DeleteDisasterRecoverGroups",
                    "cvm:CreateSecurityGroup",
                    "cvm:CreateSecurityGroupPolicy",
                    "cvm:DeleteSecurityGroupPolicy",
                    "cos:PostBucketInventory",
                    "cos:GetBucketNotification",
                    "cos:PutBucketNotification"
                ],
                "resource": "*",
                "effect": "allow"
            },
            {
                "effect": "allow",
                "action": "finance:*",
                "resource": "qcs::cvm:::*"
            }
        ]
    }

GooseFSMountPoint_QCSLinkedRoleInManageCloudServic

Use Cases: The current role is the GooseFS MountPoint service linked role, which will access your other service resources within the scope of the permissions of the associated policy.
Authorization Polices

  • Policy Name: QcloudAccessForGooseFSMountPointLinkedRoleInManageCloudService
  • Policy Information:
    {
        "version": "2.0",
        "statement": [
            {
                "effect": "allow",
                "action": [
                    "vpc:DescribeVpcEx",
                    "vpc:DescribeVpcPrivateIpAddresses",
                    "vpc:DescribeSubnetEx",
                    "tat:DescribeInvocationTasks",
                    "tat:RunCommand",
                    "tat:DescribeInvocations",
                    "tat:DescribeAutomationAgentStatus",
                    "cvm:RunInstances",
                    "cvm:TerminateInstances",
                    "cvm:DescribeInstancesStatus",
                    "cvm:DescribeInstances",
                    "cvm:DescribeImages",
                    "cos:GetBucket",
                    "cos:HeadBucket",
                    "cos:HeadObject"
                ],
                "resource": "*"
            }
        ]
    }

Ajuda e Suporte

Esta página foi útil?

comentários