建立備份服務的服務對服務授權

為「IBM Cloud Backup for VPC」設定服務對服務授權及 使用者角色,以便偵測資源標籤,並建立區塊卷宗和檔案共用資料夾的備份快照。

概觀

為了讓IBM Cloud Backup for VPC服務正常運作,您需要提供該服務的授權。 在授權過程中,來源服務將被授予存取目標服務的權限。 您所選取的角色將決定來源服務的存取權限層級。 目標服務是指您根據所指派的角色,允許來源服務存取的服務。 來源服務可以在建立授權的相同帳戶中,或在另一個帳戶中。 目標服務一律位於建立授權的帳戶中。

若要建立備份策略並使備份作業正確運行,需要授權備份服務與Block Storage for VPC、VPC 快照,以及Virtual Server for VPC服務。

企業帳戶管理員若要為其企業帳戶及子帳戶建立備份政策,同樣需要獲得授權。 具體而言,企業帳戶中的「備份」服務必須獲得授權,才能與子帳戶中的「備份」服務進行協作。

若要建立備份策略並使備份作業針對檔案共用正確執行,需要授權備份服務使用 File Storage for VPC。

如需授權的相關資訊,請參閱 使用授權來授與服務之間的存取權

如果您不正確地設定服務授權,則備份服務無法建立備份原則。 如需詳細資訊,請參閱疑難排解主題 當我嘗試建立備份原則時,什麼會導致服務授權錯誤?

在控制台建立授權策略

在帳戶層級建立磁碟區備份授權

若要建立服務對服務授權原則,請遵循下列程序:

  1. 在IBM Cloud控制台中,前往管理 > 存取 (IAM)
  2. 從側邊畫面中,選取 授權
  3. 在「管理授權」頁面上,按一下 建立
  4. 來源 區段中,選取 來源帳戶。 在您設定帳戶中「備份」服務的授權時,請選取 此帳戶。 按下一步
  5. 對於來源服務,從清單中選取 VPC 基礎架構服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 從清單中,選取 資源類型
    4. 在下一個欄位中,選擇 IBM Cloud Backup for VPC
    5. 下一步
  6. 對於目標服務,從清單中選取 VPC 基礎架構服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 按一下 資源類型。 請從以下服務中選擇一項。 您需要為所有使用者建立授權。
服務間授權
來源服務 - 資源類型 目標服務 - 資源類型 相依服務使用者角色
IBM Cloud Backup for VPC Block Storage for VPC 操作員
IBM Cloud Backup for VPC Block Storage Snapshots for VPC 編輯者
IBM Cloud Backup for VPC VPC 的多重磁區 Snapshot 編輯者
IBM Cloud Backup for VPC Virtual Server for VPC 操作員

(可選)若要將授權範圍限制在特定的虛擬伺服器執行個體上,請按一下「新增條件」,並從屬性清單中選取「執行個體 ID」。 接著,請從選單中選取一個特定的實例。

若將授權範圍限制在特定執行個體上,會導致連接至其他執行個體的卷宗發生備份失敗。 若要為「Virtual Server for VPC」新增條件,您必須針對每個需要備份其儲存卷的執行個體,分別建立獨立的授權政策。 如需更多資訊,請參閱「授權範圍問題的疑難排解」。

  1. 下一步
  2. 選取角色。 如需更多資訊,請參閱對應角色的表格。
  3. 按一下 檢閱,並檢查您的選項。
  4. 按一下授權
  5. 當您回到「管理授權」頁面時,請再次按一下 建立,並遵循相同的步驟來設定其餘服務的授權。

在帳戶層級建立檔案共用備份授權

若要建立服務對服務授權原則,請遵循下列程序:

  1. 在IBM Cloud控制台中,前往管理 > 存取 (IAM)
  2. 從側邊畫面中,選取 授權
  3. 在「管理授權」頁面上,按一下 建立
  4. 來源 區段中,選取 來源帳戶。 在您設定帳戶中「備份」服務的授權時,請選取 此帳戶。 按下一步
  5. 對於來源服務,從清單中選取 VPC 基礎架構服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 從清單中,選取 資源類型
    4. 在下一個欄位中,選擇 IBM Cloud Backup for VPC
    5. 下一步
  6. 對於目標服務,從清單中選取 VPC 基礎架構服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 按一下 資源類型。 請選擇 File Storage for VPC
  7. 下一步
  8. 選擇角色:編輯器共用快照操作員
  9. 按一下 檢閱,並檢查您的選項。
  10. 按一下授權

從子帳戶為企業帳戶管理的備份建立跨帳戶授權

為了讓企業管理員能夠集中管理備份,子帳戶必須授權企業帳戶的「備份」服務與其資源進行互動。 子帳戶管理員可依照以下步驟,在其帳戶中本地建立授權。

  1. 在IBM Cloud控制台中,前往管理 > 存取 (IAM)
  2. 從側邊畫面中,選取 授權
  3. 在「管理授權」頁面上,按一下 建立
  4. 來源 區段中,選取 來源帳戶。 當您設定企業帳戶的「備份」服務授權時,請選取 特定帳戶,然後輸入企業帳戶的 ID。 按下一步
  5. 對於來源服務,從清單中選取 VPC 基礎架構服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 從清單中,選取 資源類型
    4. 在下一個欄位中,選擇 IBM Cloud Backup for VPC
    5. 下一步
  6. 對於目標服務,從清單中選取 VPC 基礎架構服務
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 按一下 資源類型。 在表格 2 中選取其中一個服務。
企業的服務到服務授權
來源服務 - 資源類型 目標服務 - 資源類型 相依服務使用者角色
IBM Cloud Backup for VPC Block Storage for VPC 操作員
IBM Cloud Backup for VPC Block Storage Snapshots for VPC 編輯者
IBM Cloud Backup for VPC VPC 的多重磁區 Snapshot 編輯者
IBM Cloud Backup for VPC Virtual Server for VPC 操作員
IBM Cloud Backup for VPC IBM Cloud Backup for VPC 編輯者
IBM Cloud Backup for VPC File Storage for VPC 編輯、分享快照操作員
  1. 下一步
  2. 選取角色。 如需更多資訊,請參閱表 2 以了解相應的角色。
  3. 按一下 檢閱,並檢查您的選項。
  4. 按一下授權
  5. 當您回到「管理授權」頁面時,請再次按一下 建立,並遵循相同的步驟來設定其餘服務的授權。

為企業管理的備份建立跨帳戶授權模板

透過 授權範本,企業帳戶管理員可以建立授權政策,並將其指派給子帳戶。 此授權將自動套用至這些帳戶,無需管理員逐一登入每個子帳戶。

  1. 在 IBM Cloud 控制台中,前往管理 > 存取 (IAM) > 企業 > 範本
  2. 選取「授權」,然後按一下「建立」。
  3. 輸入授權範本的名稱和描述,描述其對企業使用者的用途。
  4. 輸入企業管理的授權策略的說明,描述其對兒童帳戶使用者的用途。
  5. 按一下建立

接下來,完成以下步驟來建立授權規則:

  1. 進入授權,指定授權策略的詳細資訊。
  2. 選擇來源服務請求存取其他服務的帳戶。 選擇已分配的帳戶。 當您稍後將授權範本指派給子帳戶時,「來源帳戶」欄位會自動設定為與持有該存取資源的子帳戶相符。
  3. 接下來,選擇來源服務和資源。
    1. 從清單中選擇 VPC 基礎設施服務。 按下一步
    2. 按一下 特定資源來選取範圍。
    3. 點擊「選取一項屬性」。
    4. 從清單中,選取 資源類型
    5. 在下一個欄位中,選擇 IBM Cloud Backup for VPC
  4. 對於目標服務,從清單中選取 VPC 基礎架構服務
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 從清單中,選取 資源類型。 選擇下表中的一項服務。 您需要為所有使用者建立授權。
企業的服務到服務授權
來源服務 - 資源類型 目標服務 - 資源類型 相依服務使用者角色
IBM Cloud Backup for VPC Block Storage for VPC 操作員
IBM Cloud Backup for VPC Block Storage Snapshots for VPC 編輯者
IBM Cloud Backup for VPC VPC 的多重磁區 Snapshot 編輯者
IBM Cloud Backup for VPC Virtual Server for VPC 操作員
IBM Cloud Backup for VPC IBM Cloud Backup for VPC 編輯者
IBM Cloud Backup for VPC File Storage for VPC 編輯、分享快照操作員
  1. 下一步
  2. 選取角色。 如需更多資訊,請參閱對應角色的表格。
  3. 按一下 檢閱,並檢查您的選項。 然後,按一下儲存
  4. 提交並將該範本指派給子帳戶。 重複這些步驟為所有服務建立授權範本。

為Event Notifications建立授權

若要為Event Notifications建立服務到服務授權策略,請依照下列程序操作:

  1. 在IBM Cloud控制台中,前往管理 > 存取 (IAM)
  2. 從側邊畫面中,選取 授權
  3. 在「管理授權」頁面上,按一下 建立
  4. 來源 區段中,選取 來源帳戶。 在您設定帳戶中「備份」服務的授權時,請選取 此帳戶。 按下一步
  5. 對於來源服務,從清單中選取 VPC 基礎架構服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 按一下選擇屬性,然後從清單中選擇資源類型
    3. 在下一個欄位中,選擇 IBM Cloud Backup for VPC
    4. 下一步
  6. 選擇 Event Notifications 作為目標服務。 按下一步
    1. 按一下 特定資源來選取範圍。
    2. 點擊「選取一項屬性」。
    3. 按一下 serviceInstance
    4. 在下一個欄位中,選擇字串 equals
    5. 在下一個欄位中,選擇您要授權的Event Notifications服務實例。
  7. 選擇事件來源管理員角色。
  8. 按一下 檢閱,並檢查您的選項。
  9. 按一下授權

從 CLI 建立授權原則

在帳戶層級建立磁碟區備份授權

若要在您的帳戶中使用「VPC 備份」來建立政策與計畫,並執行區塊儲存卷的備份工作,請建立以下「服務對服務」授權:

  • backup-policy (來源) 至 instance (目標),具有 操作員 角色
  • backup-policy (來源) 至 volume (目標),具有 操作員 角色
  • backup-policy (來源) 至 snapshot (目標),具有 編輯者 角色
  • backup-policy (來源) 至 snapshot-consistency-group (目標),具有 編輯者 角色
  1. 使用下列授權原則資訊來建立四個 JSON 檔案。

請保留範例中的萬用字元值("*" )。 將萬用字元替換為特定的資源 ID 會限制授權範圍,並導致備份失敗。 如需更多資訊,請參閱「授權範圍問題的疑難排解」。

  • 實例服務:
    {
      "type": "authorization",
      "subject": {
          {"attributes": [
               {"name": "accountId", "value": "ACCOUNT_ID"},
               {"name": "serviceName", "value": "is"},
               {"name": "resourceType", "value": "backup-policy"}]}},
      "roles": [
          {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}],
      "resources": [
          {"attributes": [
               {"name": "accountId", "value": "ACCOUNT_ID"},
               {"name": "serviceName", "operator": "stringEquals", "value": "is"},
               {"name": "instanceId", "operator": "stringEquals", "value": "*"}]}]
      }
    
  • Block Storage 音量服務:
    {
      "type": "authorization",
      "subject": {
          {"attributes": [
               {"name": "accountId", "value": "ACCOUNT_ID"},
               {"name": "serviceName", "value": "is"},
               {"name": "resourceType", "value": "backup-policy"}]}},
      "roles": [
          {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}],
      "resources": [
          {"attributes": [
               {"name": "accountId", "value": "ACCOUNT_ID"},
               {"name": "serviceName", "operator": "stringEquals", "value": "is"},
               {"name": "volumeId", "operator": "stringEquals", "value": "*"}]}]
    }
    
  • Block Storage 快照服務:
    {
      "type": "authorization",
      "subject": {
          {"attributes": [
               {"name": "accountId", "value": "ACCOUNT_ID"},
               {"name": "serviceName", "value": "is"},
               {"name": "resourceType", "value": "backup-policy"}]}},
      "roles": [
          {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}],
      "resources": [
          {"attributes": [
               {"name": "accountId", "value": "ACCOUNT_ID"},
               {"name": "serviceName", "operator": "stringEquals", "value": "is"},
               {"name": "snapshotId", "operator": "stringEquals", "value": "*"}]}]
    }
    
  • Snapshot 一致性群組:
    {
     "type": "authorization",
     "subject": {
         {"attributes": [
              {"name": "accountId", "value": "ACCOUNT_ID"},
              {"name": "serviceName", "value": "is"},
              {"name": "resourceType", "value": "backup-policy"}]}},
     "roles": [
         {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}],
     "resources": [
         {"attributes": [
              {"name": "accountId", "value": "ACCOUNT_ID"},
              {"name": "serviceName", "operator": "stringEquals", "value": "is"},
              {"name": "snapshotConsistencyGroupId", "operator": "stringEquals", "value": "*"}]}]
    }
    
  1. 然後,使用 JSON 檔案來執行下列 CLI 指令。
    ibmcloud iam authorization-policy-create --file ~/Documents/policy.json
    

如需此指令可用的所有參數的相關資訊,請參閱 ibmcloud iam authorization-policy-create

在帳戶層級建立檔案共用備份授權

若要為 File Storage for VPC 共用備份建立服務到服務授權策略,請使用 authorization-policy-create 命令。

ibmcloud iam authorization-policy-create is is "Share Snapshot Operator",Editor --source-resource-type backup-policy --target-resource-type share

如需此指令可用的所有參數的相關資訊,請參閱 ibmcloud iam authorization-policy-create

為企業管理的備份建立跨帳戶授權模板

企業帳戶管理員可以 建立授權政策範本,並將其指派 給子帳戶,以集中管理授權。 若要建立一個授權政策範本,供企業旗下所有子帳戶的備份政策使用,請完成以下步驟。

  1. 若要取得企業root帳號ID,可以執行下列指令。
ibmcloud enterprise show
  1. 建立提供授權策略範本定義的 JSON 檔案。 有關可在 JSON 檔案中使用的屬性的更多信息,請參閱 IAM 策略管理 API
  • 實例服務:

    {
     "name": "Centralized authorization for Backup service to work with Instances",
     "description": "Grant Operator Role for the Backup service to work with Instances",
     "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
     "policy":{
       "type": "authorization",
       "description": "Grant Operator on VPC Instances",
       "control":{
           "grant":{
             "roles":[
               {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}]
             }},
       "subject":{
           "attributes":[
               {"key": "serviceName", "operator": "stringEquals", "value": "is"},
               {"key": "resourceType", "operator": "stringEquals", "value": "backup-policy"}
             ]},
       "resource":{
           "attributes":[
               {"key": "serviceName", "operator": "stringEquals", "value": "is"},
               {"key": "instanceId", "operator": "stringExists", "value": true}
             ]}}
    }
    
    • Block Storage 音量服務:
    {
         "name": "Centralized authorization for Backup service to work with Block Storage service",
         "description": "Grant Operator Role for the Backup service to work with Block Storage volumes",
         "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
         "policy":{
           "type": "authorization",
           "description": "Grant Operator on Block Storage for VPC volumes",
           "control": {
               "grant": {
                 "roles": [
                   {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}]
               }},
           "subject": {
             "attributes": [
               {"key": "serviceName", "value": "is"},
               {"key": "resourceType", "value": "backup-policy"}
               ]},
           "resource": {
             "attributes": [
                {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                {"key": "volumeId", "operator": "stringExists", "value": "true"}
               ]}}
    }
    
    • Block Storage 快照服務:
    {
         "name": "Centralized authorization for Backup service to work with Block Storage snapshots",
         "description": "Grant Editor Role for the Backup service to work with Block Storage snapshots",
         "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
         "policy": {
           "type": "authorization",
           "description": "Grant Editor on Block Storage for VPC snapshots",
           "control": {
               "grant": {
                 "roles": [
                   {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}]
               }},
           "subject": {
             "attributes": [
               {"key": "serviceName", "value": "is"},
               {"key": "resourceType", "value": "backup-policy"}
               ]},
           "resource": {
             "attributes": [
               {"key": "serviceName", "operator": "stringEquals", "value": "is"},
               {"key": "snapshotId", "operator": "stringExists", "value": "true"}
               ]}}
    }
    
    • Snapshot 一致性群組:
     {
          "name": "Centralized authorization for Backup service to work with snapshot consistency groups",
          "description": "Grant Editor Role for the Backup service to work with snapshot consistency groups",
          "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
          "policy": {
            "type": "authorization",
            "description": "Grant Editor on snapshot consistency groups",
            "control": {
                "grant": {
                  "roles": [
                    {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}]
                }},
            "subject": {
              "attributes": [
                {"key": "serviceName", "value": "is"},
                {"key": "resourceType", "value": "backup-policy"}
                ]},
            "resource": {
              "attributes": [
                {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                {"key": "snapshotConsistencyGroupId", "operator": "stringExists", "value": "true"}
                ]}}
     }
    
    • 檔案共用:
      {
           "name": "Centralized authorization for Backup service to work with File shares",
           "description": "Grant Editor Role for the Backup service to work with File shares",
           "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
           "policy": {
             "type": "authorization",
             "description": "Grant Editor, and Share Snapshot Operator roles on File shares",
             "control": {
                 "grant": {
                   "roles": [
                     {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"},{"role_id": "crn:v1:bluemix:public:iam::::role:ShareSnapshotOperator"}]
             },
             "subject": {
               "attributes": [
                 {"key": "serviceName", "value": "is"},
                 {"key": "resourceType", "value": "backup-policy"}]
             },
             "resource": {
               "attributes": [
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "shareId", "operator": "stringExists", "value": "true"}]
             }
           }
      }
    
  1. 運行 authorization-policy-template-create 帶有 JSON 檔案的命令,如以下範例請求所示:

    ibmcloud iam authorization-policy-template-create --file /path/to/vpc-share-authorization-template.json
    
  2. 對所有 JSON 檔案重複此操作。 完成後,模板即可提交並指派給子帳戶。

  3. 執行以下命令,提交模板版本並將模板指派給目標帳戶。

    ibmcloud iam authorization-policy-template-version-commit (TEMPLATE_ID | TEMPLATE_NAME) TEMPLATE_VERSION [-q, --quiet]
    
    ibmcloud iam authorization-policy-assignment-create (TEMPLATE_ID | TEMPLATE_NAME) TEMPLATE_VERSION --target-type TYPE --target TARGET [-q, --quiet] [-o, --output FORMAT]
    

有關此命令可用的所有參數的更多信息,請參閱 ibmcloud iamauthorization-policy-template-create

為Event Notifications建立授權

若要為Event Notifications建立服務到服務授權策略,請使用 authorization-policy-create 指令。

ibmcloud iam authorization-policy-create is event-notification EventSourceManager --source-resource-type backup-policy --target-resource-instance $en-instance-ID

如需此指令可用的所有參數的相關資訊,請參閱 ibmcloud iam authorization-policy-create

使用 API 建立授權原則

在帳戶層級建立磁碟區備份授權

若要在您的帳戶中使用「VPC 備份」來建立政策與計畫,並執行區塊儲存卷的備份工作,請建立以下「服務對服務」授權:

  • is.backup-policy (來源) 至 is.instance (目標),具有 operator 角色。
  • is.backup-policy (來源) 至 is.volume (目標),具有 operator 角色。
  • is.backup-policy (來源) 至 is.snapshot (目標),具有 編輯者 角色。
  • is.backup-policy (來源) 至 is.snapshot-consistency-group,具有 編輯者 角色

IAM 原則管理 API 提出要求,類似下列範例。

請保留範例中的萬用字元值("*" )。 將萬用字元替換為特定的資源 ID 會限制授權範圍,並導致備份失敗。 如需更多資訊,請參閱「授權範圍問題的疑難排解」。

curl -X POST 'https://iam.cloud.ibm.com/v1/policies'
-H 'Authorization: Bearer $TOKEN'
-H 'Content-Type: application/json'
-d '{
   "type": "access",
   "description": "Operator role for the Backup service to the Virtual Server service",
   "subjects": [
    {"attributes": [
       {"name": "serviceName", "value": "is"},
       {"name": "accountId", "value": "$ACCOUNT_ID"},
       {"name": "resourceType", "value": "backup-policy"}]
    }
   ],
  "roles":[
    {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}
   ],
   "resources":[
    {"attributes":[
      {"name": "accountId", "value": "$ACCOUNT_ID"},
      {"name": "serviceName", "operator": "stringEquals", "value": "is"},
      {"name": "instanceId", "operator": "stringEquals", "value": "*"}]
    }
  ]
}'
curl -X POST 'https://iam.cloud.ibm.com/v1/policies' \
-H 'Authorization: Bearer $TOKEN' \
-H 'Content-Type: application/json' \
-d '{
   "type": "access",
   "description": "Operator role for the Backup service to the Cloud Block Storage",
   "subjects":[
    {"attributes":[
      {"name": "serviceName", "value": "is"},
      {"name": "accountId", "value": "$ACCOUNT_ID"},
      {"name": "resourceType", "value": "backup-policy"}]
    }],
   "roles":[
    {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}
    ],
   "resources":[
    {"attributes": [
      {"name": "accountId", "value": "$ACCOUNT_ID"},
      {"name": "serviceName", "operator": "stringEquals", "value": "is.volume"},
      {"name": "volumeId", "operator": "stringEquals", "value": "*"}
     ]
    }
   ]
}'
curl -X POST 'https://iam.cloud.ibm.com/v1/policies' \
-H 'Authorization: Bearer $TOKEN' \
-H 'Content-Type: application/json' \
-d '{
   "type": "access",
   "description": "Editor role for the Backup service to Block Storage Snapshots",
   "subjects": [
    {"attributes": [
      {"name": "serviceName", "value": "is"},
      {"name": "accountId", "value": "$ACCOUNT_ID"},
      {"name": "resourceType", "value": "backup-policy"}]
    }
   ],
   "roles":[
    {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}
   ],
   "resources":[
    {"attributes": [
      {"name": "accountId", "value": "$ACCOUNT_ID"},
      {"name": "serviceName", "operator": "stringEquals", "value": "is"},
      {"name": "snapshotId", "operator": "stringEquals", "value": "*"}]
    }
   ]
}'
curl -X POST 'https://iam.cloud.ibm.com/v1/policies' \
-H 'Authorization: Bearer $TOKEN' \
-H 'Content-Type: application/json' \
-d '{
   "type": "access",
   "description": "Editor role for the Backup service to the Snapshot consistency groups",
   "subjects": [
    {"attributes": [
       {"name": "serviceName", "value": "is"},
       {"name": "accountId", "value": "$ACCOUNT_ID"},
       {"name": "resourceType", "value": "backup-policy"}]
    }
   ],
  "roles":[
    {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}
   ],
   "resources":[
    {"attributes":[
      {"name": "accountId", "value": "$ACCOUNT_ID"},
      {"name": "serviceName", "operator": "stringEquals", "value": "is"},
      {"name": "snapshotConsistencyGroupId", "operator": "stringEquals", "value": "*"}]
    }
  ]
}'

如需相關資訊,請參閱 IAM 原則管理 的 API 規格。

從子帳戶為企業管理的磁碟區備份建立跨帳戶授權

若要容許「企業」管理者集中管理備份,子帳戶必須提供授權給「企業」帳戶的「備份」服務,以與子帳戶的資源互動。

  1. 企業管理 API 提出 API 要求,以取得上層企業帳戶的帳戶 ID。

    curl -X GET "https://enterprise.cloud.ibm.com/v1/enterprises"
    -H "Authorization: Bearer <IAM_Token>"
    -H 'Content-Type: application/json'
    
  2. 然後,向 IAM 原則管理 API 提出要求,以建立企業帳戶 is.backup-policy 的服務對服務授權,以與子帳戶的 is.backupis.snapshotis.volumeis.snapshot-consistency-groupis.instance 服務互動。

    • 授權 is.backup-policy (來源) 以 編輯者 角色與 is.backup-policy (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policies' -H
    'Authorization: Bearer $TOKEN' -H
    'Content-Type: application/json' -d
    '{
      "type": "access",
      "description": "Editor role for the Enterprise account's backup service to interact with this account's backup service.",
      "subjects": [
        {"attributes": [
           {"name": "serviceName", "value": "is"},
           {"name": "accountId", "value": "$ENTERPRISE_ACCOUNT_ID"},
           {"name": "resourceType", "value": "backup-policy"}]
         }
       ],
      "roles":[
        {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}
      ],
      "resources":[
        {"attributes":[
           {"name": "accountId", "value": "$SUB_ACCOUNT_ID", "operator": "stringEquals"},
           {"name": "serviceName", "operator": "stringEquals", "value": "is"},
           {"name": "backupPolicyId", "operator": "stringEquals", "value": "*"}]
        }
       ]
      }'
    
    • 授權 is.backup-policy (來源) 與具有 操作員 角色的 is.volume (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policies' -H
    'Authorization: Bearer $TOKEN' -H
    'Content-Type: application/json' -d
    '{
      "type": "access",
      "description": "Operator role for the Enterprise account's backup service to interact with this account's volume service",
      "subjects": [
        {
         "attributes": [
           {"name": "serviceName", "value": "is"},
           {"name": "accountId", "value": "$ENTERPRISE_ACCOUNT_ID"},
           {"name": "resourceType", "value": "backup-policy"}]
         }
       ],
      "roles":[
        {"role_id" "crn:v1:bluemix:public:iam::::role:Operator"}
       ],
      "resources":[
        {"attributes": [
           {"name": "accountId", "value": "$SUB_ACCOUNT_ID"},
           {"name": "serviceName", "operator": "stringEquals", "value": "is.volume"},
           {"name": "volumeId", "operator": "stringEquals", "value": "*"}]
        }
       ]
    }'
    
    • 授權 is.backup-policy (來源) 以 編輯者 角色與 is.snapshot (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policies' -H
    'Authorization: Bearer $TOKEN' -H
    'Content-Type: application/json' -d
     '{
       "type": "access",
       "description": "Editor role for the Enterprise account's backup service to interact with this account's snapshots",
       "subjects":[
        {
         "attributes":[
           {"name": "serviceName", "value": "is"},
           {"name": "accountId", "value": "$ENTERPRISE_ACCOUNT_ID"},
           {"name": "resourceType", "value": "backup-policy"}]
         }
        ],
       "roles":[
          {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}
        ],
       "resources":[
          {"attributes": [
           {"name": "accountId", "value": "$SUB_ACCOUNT_ID"},
           {"name": "serviceName", "operator": "stringEquals", "value": "is"},
           {"name": "snapshotId", "operator": "stringEquals", "value": "*"}]
        }
       ]
     }'
    
    • 授權 is.backup-policy (來源) 與具有 操作員 角色的 is.instance (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policies' -H
    'Authorization: Bearer $TOKEN' -H
    'Content-Type: application/json' -d
    '{
      "type": "access",
      "description": "Operator role for the Enterprise account's backup service to interact with this account's virtual server instance service",
      "subjects": [
        {"attributes": [
           {"name": "serviceName", "value": "is"},
           {"name": "accountId", "value": "$ENTERPRISE_ACCOUNT_ID"},
           {"name": "resourceType", "value": "backup-policy"}]
         }
       ],
      "roles":[
        {"role_id" "crn:v1:bluemix:public:iam::::role:Operator"}
       ],
      "resources":[
        {"attributes": [
           {"name": "accountId", "value": "$SUB_ACCOUNT_ID"},
           {"name": "serviceName", "operator": "stringEquals", "value": "is.volume"},
           {"name": "instanceId", "operator": "stringEquals", "value": "*"}]
        }
       ]
    }'
    

如需相關資訊,請參閱 IAM 原則管理 的 API 規格。

建立檔案共享備份授權

若要在您的帳戶中使用「VPC 備份」來建立政策與方案,並執行檔案共用資料夾的備份工作,請提出以下請求以建立所需的服務對服務授權。

curl -X POST 'https://iam.cloud.ibm.com/v2/policies'
-H 'Authorization: Bearer $TOKEN'
-H 'Content-Type: application/json'
-d '{
     "type": "authorization",
     "description": "IAM roles for the Backup service to Cloud File Storage",
     "subject": {
        "attributes": [
            {"key": "serviceName","operator": "stringEquals","value": "is"},
            {"key": "accountId","operator": "stringEquals","value": "a1234567"},
            {"key": "resourceType","operator": "stringEquals","value": "backup-policy"}]
     },
     "control": {
        "grant": {
            "roles": [
                {"role_id":"crn:v1:bluemix:public:is::::serviceRole:ShareSnapshotOperator"},
                {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}]}
     },
     "resource": {
        "attributes": [
            {"key": "accountId","operator": "stringEquals","value": "a1234567"},
            {"key": "serviceName","operator": "stringEquals","value": "is"},
            {"key": "shareId","operator": "stringExists","value": true}]
     }
    }'

為企業管理的備份建立跨帳戶授權模板

企業帳戶管理員可透過程式化方式 建立授權政策範本,並將其指派 給子帳戶,以集中管理授權。 若要建立一個授權政策範本,供企業旗下所有子帳戶的備份政策使用,請完成以下步驟。

  1. 企業管理 API 提出 API 要求,以取得上層企業帳戶的帳戶 ID。

    curl -X GET `https://enterprise.cloud.ibm.com/v1/enterprises`
    -H "Authorization: Bearer <IAM_Token>"
    -H 'Content-Type: application/json'
    
  2. 然後,向 IAM 策略管理 API 發出請求以建立服務到服務授權 is.backup-policy 企業帳戶的與分配的子帳戶的交互 is.backup, is.snapshot, is.volume, is.snapshot-consistency-group,和 is.instance 服務。

    • 授權 is.backup-policy (來源) 以 編輯者 角色與 is.backup-policy (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policy_templates'
    -H 'Authorization: Bearer $TOKEN'
    -H 'Content-Type: application/json'
    -d '{
       "name": "Centralized authorization for Backup service to work with Instances",
       "description": "Grant Operator Role for the Backup service to work with Instances",
       "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
       "policy":{
         "type": "authorization",
         "description": "Grant Operator on VPC Instances",
         "control":{
             "grant":{
               "roles":[
                 {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}]
               }},
         "subject":{
             "attributes":[
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "resourceType", "operator": "stringEquals", "value": "backup-policy"}
               ]},
         "resource":{
             "attributes":[
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "instanceId", "operator": "stringExists", "value": true}
               ]}}
      }
    
    • 授權 is.backup-policy (來源) 與具有 操作員 角色的 is.volume (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policy_templates'
    -H 'Authorization: Bearer $TOKEN'
    -H 'Content-Type: application/json'
    -d '{
           "name": "Centralized authorization for Backup service to work with Block Storage service",
           "description": "Grant Operator Role for the Backup service to work with Block Storage volumes",
           "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
           "policy":{
             "type": "authorization",
             "description": "Grant Operator on Block Storage for VPC volumes",
             "control": {
                 "grant": {
                   "roles": [
                     {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}]
                 }},
             "subject": {
               "attributes": [
                 {"key": "serviceName", "value": "is"},
                 {"key": "resourceType", "value": "backup-policy"}
                 ]},
             "resource": {
               "attributes": [
                  {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                  {"key": "volumeId", "operator": "stringExists", "value": "true"}
                 ]}}
      }'
    
    • 授權 is.backup-policy (來源) 以 編輯者 角色與 is.snapshot (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policy_templates'
    -H 'Authorization: Bearer $TOKEN'
    -H 'Content-Type: application/json'
    -d '{
           "name": "Centralized authorization for Backup service to work with Block Storage snapshots",
           "description": "Grant Editor Role for the Backup service to work with Block Storage snapshots",
           "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
           "policy": {
             "type": "authorization",
             "description": "Grant Editor on Block Storage for VPC snapshots",
             "control": {
                 "grant": {
                   "roles": [
                     {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}]
                 }},
             "subject": {
               "attributes": [
                 {"key": "serviceName", "value": "is"},
                 {"key": "resourceType", "value": "backup-policy"}
                 ]},
             "resource": {
               "attributes": [
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "snapshotId", "operator": "stringExists", "value": "true"}
                 ]}}
      }'
    
    • 授權 is.backup-policy (來源) 與具有 操作員 角色的 is.instance (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policy_templates'
    -H 'Authorization: Bearer $TOKEN'
    -H 'Content-Type: application/json'
    -d '{
       "name": "Centralized authorization for Backup service to work with Instances",
       "description": "Grant Operator Role for the Backup service to work with Instances",
       "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
       "policy":{
         "type": "authorization",
         "description": "Grant Operator on VPC Instances",
         "control":{
             "grant":{
               "roles":[
                 {"role_id": "crn:v1:bluemix:public:iam::::role:Operator"}]
               }},
         "subject":{
             "attributes":[
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "resourceType", "operator": "stringEquals", "value": "backup-policy"}
               ]},
         "resource":{
             "attributes":[
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "instanceId", "operator": "stringExists", "value": true}
               ]}}
      }`
    
    • 授權 is.backup-policy (來源) 以 編輯者 角色與 is.snapshotConsistencyGroup (目標) 互動。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policy_templates'
    -H 'Authorization: Bearer $TOKEN'
    -H 'Content-Type: application/json'
    -d '{
           "name": "Centralized authorization for Backup service to work with snapshot consistency groups",
           "description": "Grant Editor Role for the Backup service to work with snapshot consistency groups",
           "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
           "policy": {
             "type": "authorization",
             "description": "Grant Editor on snapshot consistency groups",
             "control": {
                 "grant": {
                   "roles": [
                     {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"}]
                 }},
             "subject": {
               "attributes": [
                 {"key": "serviceName", "value": "is"},
                 {"key": "resourceType", "value": "backup-policy"}
                 ]},
             "resource": {
               "attributes": [
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "snapshotConsistencyGroupId", "operator": "stringExists", "value": "true"}
                 ]}}
      }`
    
    • 授權 is.backup-policy (來源) 使用_編輯器_與 is.share (目標) 互動,並_共享快照操作員_角色。
    curl -X POST 'https://iam.cloud.ibm.com/v1/policy_templates'
    -H 'Authorization: Bearer $TOKEN'
    -H 'Content-Type: application/json'
    -d '{
           "name": "Centralized authorization for Backup service to work with File shares",
           "description": "Grant Editor Role for the Backup service to work with File shares",
           "account_id": "ENTERPRISE_ROOT_ACCOUNT_ID",
           "policy": {
             "type": "authorization",
             "description": "Grant Editor, and Share Snapshot Operator roles on File shares",
             "control": {
                 "grant": {
                   "roles": [
                     {"role_id": "crn:v1:bluemix:public:iam::::role:Editor"},
                     {"role_id": "crn:v1:bluemix:public:iam::::role:ShareSnapshotOperator"}]}
             },
             "subject": {
               "attributes": [
                 {"key": "serviceName", "value": "is"},
                 {"key": "resourceType", "value": "backup-policy"}]
             },
             "resource": {
               "attributes": [
                 {"key": "serviceName", "operator": "stringEquals", "value": "is"},
                 {"key": "shareId", "operator": "stringExists", "value": "true"}]
             }
           }
      }'
    
  3. 建立授權範本後,您必須 提交 它們並將 其指派 給帳戶。

如需相關資訊,請參閱 IAM 原則管理 的 API 規格。

為Event Notifications建立授權

若要為 Event Notifications 建立服務對服務授權政策,請發送 API 請求,授予 is.backup-policy (來源)以 EventSourceManager 角色存取 event-notification (目標)的權限。

curl -X POST 'https://iam.cloud.ibm.com/v2/policies' -H
'Authorization: Bearer $TOKEN' -H
'Content-Type: application/json' -d
'{
  "type": "access",
  "description": "Event Source Manager role for the backup service to interact with the Event notification service",
  "subjects": [
       {"attributes": [
          {"name": "serviceName", "value": "is"},
          {"name": "resourceType", "value": "backup-policy"}]
        }
  ],
  "roles":[
       {"role_id" "crn:v1:bluemix:public:iam::::role:EventSourceManager"}
  ],
  "resource":[
       {"attributes": [
          {"name": "serviceName", "operator": "stringEquals", "value": "event-notification"},
          {"name": "instanceId", "operator": "stringEquals", "value": "<en-instance-ID>"}]
       }
  ]
}'

使用 Terraform 建立授權原則

在帳戶層級建立磁碟區備份授權

使用 main.tf 檔案中的 ibm_iam_authorization_policy 資源引數,在服務之間建立授權原則。

請將資源屬性的 operator = "stringExists" 設定為 value = "true" 。 若將資源 ID 改為 "stringEquals",將限制授權範圍,並導致備份失敗。 如需更多資訊,請參閱「授權範圍問題的疑難排解」。

resource "ibm_iam_authorization_policy" "policy1" {
  subject_attributes {
    name  = "accountId"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  subject_attributes {
    name  = "serviceName"
    value = "is"
  }
  subject_attributes {
    name  = "resourceType"
    value = "backup-policy"
  }
  resource_attributes {
    name  = "accountId"
    operator = "stringEquals"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  resource_attributes {
    name  = "serviceName"
    operator = "stringEquals"
    value = "is"
  }
  resource_attributes {
    name  = "volumeId"
    operator = "stringExists"
    value = "true"
  }
  roles   = ["Operator"]
}
resource "ibm_iam_authorization_policy" "policy2" {
  subject_attributes {
    name  = "accountId"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  subject_attributes {
    name  = "serviceName"
    value = "is"
  }
  subject_attributes {
    name  = "resourceType"
    value = "backup-policy"
  }
  resource_attributes {
    name  = "accountId"
    operator = "stringEquals"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  resource_attributes {
    name  = "serviceName"
    operator = "stringEquals"
    value = "is"
  }
  resource_attributes {
    name  = "snapshotId"
    operator = "stringExists"
    value = "true"
  }
  roles   = ["Editor"]
}
resource "ibm_iam_authorization_policy" "policy3" {
  subject_attributes {
    name  = "accountId"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  subject_attributes {
    name  = "serviceName"
    value = "is"
  }
  subject_attributes {
    name  = "resourceType"
    value = "backup-policy"
  }
  resource_attributes {
    name  = "accountId"
    operator = "stringEquals"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  resource_attributes {
    name  = "serviceName"
    operator = "stringEquals"
    value = "is"
  }
  resource_attributes {
    name  = "snapshotConsistencyGroupId"
    operator = "stringExists"
    value = "true"
  }
  roles   = ["Editor"]
}
resource "ibm_iam_authorization_policy" "policy4" {
  subject_attributes {
    name  = "accountId"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  subject_attributes {
    name  = "serviceName"
    value = "is"
  }
  subject_attributes {
    name  = "resourceType"
    value = "backup-policy"
  }
  resource_attributes {
    name  = "accountId"
    operator = "stringEquals"
    value = data.ibm_iam_account_settings.iam.account_id
  }
  resource_attributes {
    name  = "serviceName"
    operator = "stringEquals"
    value = "is"
  }
  resource_attributes {
    name  = "instanceId"
    operator = "stringExists"
    value = "true"
  }
  roles   = ["Operator"]
}

如需引數及屬性的相關資訊,請參閱 授權資源的 Terraform 文件

建立檔案共享備份授權

使用 main.tf 檔案中的 ibm_iam_authorization_policy 資源引數,在服務之間建立授權原則。

resource "ibm_iam_authorization_policy" "policy1" {
   source_service_name  = "is"
   source_resource_type = "backup-policy"
   target_service_name  = "is"
   target_resource_type = "share"
   roles                = ["ShareSnapshotOperator,Editor"]
}

如需引數及屬性的相關資訊,請參閱 授權資源的 Terraform 文件

為Event Notifications建立授權

若要為Event Notifications建立服務到服務授權策略,請在 main.tf 檔案中使用 ibm_iam_authorization_policy 資源參數。

resource "ibm_iam_authorization_policy" "en-policy" {
   source_service_name         = "is"
   source_resource_type        = "backup-policy"
   source_resource_instance_id = ibm_backup-policy_instance.instance.guid
   target_service_name         = "event-notification"
   target_resource_instance_id = ibm_event-notification_instance.instance.guid
   roles                       = ["EventSourceManager"]
}

如需引數及屬性的相關資訊,請參閱 授權資源的 Terraform 文件

後續步驟