授予访问权限 Workload Protection
对 Workload Protection 的访问由 IBM Cloud® Identity and Access Management (IAM)进行控制。 您账户中访问 Workload Protection 服务的每位用户,都必须被分配一个包含 IAM 角色的访问策略。 该策略用于确定用户在 Workload Protection 环境中可以执行哪些操作。
必须为账户中的用户分配平台角色,才能管理实例以及通过 IBM Cloud 启动 Workload Protection。 此外,用户必须拥有一个服务角色,该角色需定义了操作 Workload Protection 的权限。
要将一组用户和服务 ID 组织成一个单一实体,以便您轻松管理 IAM 权限,请使用访问组。 您可以将单个策略分配给该组,而无需为每个用户或服务 ID 多次分配相同的访问权限。 如需了解更多信息,请参阅 “IAM 访问原理”。
使用访问组管理访问权
要管理访问组,您必须是该账户中所有已启用“身份与访问”功能的服务的所有者、管理员或编辑者,或者IAM访问组服务的指定管理员或编辑者。
使用以下操作来管理 IBM Cloud中的 IAM 访问组:
通过将策略直接分配给用户来管理访问权
若要使用 IAM 策略管理访问权限或为用户分配新的访问权限,您必须是账户所有者、该账户中所有服务的管理员,或是特定服务或服务实例的管理员。
使用以下操作来管理 IBM Cloud中的 IAM 策略:
IBM Cloud 平台角色
必须为用户授予平台角色,才能使其能够查看和管理您账户中的 Workload Protection 服务。 您可以授予许可权以使用 IBM Cloud 帐户中的所有实例,也可以限制对个别实例的访问权。
下表标识可在 IBM Cloud 中授予用户以运行指定平台操作的平台角色:
| 平台操作 | 管理员 | 编辑者 | 运算符 | 查看者 |
|---|---|---|---|---|
Grant other account members access to work with the service |
||||
Provision a service instance |
||||
Delete a service instance |
||||
Create a service ID |
||||
View details of a service instance |
||||
View service instances in the Observability Monitoring dashboard |
IBM Cloud 服务角色
下表标识可在 IBM Cloud 中授予用户以运行指定操作的服务角色:
| 操作 | 管理者 | 写入者 | 读取者 |
|---|---|---|---|
Manage access keys |
|||
Manage Secure API Tokens |
|||
Create, configure, and delete teams |
|||
Configure and remove notifications channels |
|||
Configure and remove agents |
|||
Create, delete, and edit content in the UI |
|||
Manage runtime policies |
|||
Manage image scanning policies |
|||
Manage Activity Audit |
|||
Send container images to the scanning queue |
|||
Create, update and remove alerts |
|||
View reports and image scanning results |
|||
View platforms, frameworks, rules and policies |
|||
View events |
IAM 操作
下表列出了分配给“Workload Protection”服务的平台角色和服务角色的 IAM 操作:
| 角色类型 | 角色 | IAM 操作 |
|---|---|---|
| 平台 | administrator |
sysdig-secure.launch.admin sysdig-secure.launch.user sysdig-secure.launch.viewer |
| 服务 | manager |
sysdig-secure.launch.admin sysdig-secure.launch.user sysdig-secure.launch.viewer |
| 服务 | writer |
sysdig-secure.launch.user sysdig-secure.launch.viewer |
| 服务 | reader |
sysdig-secure.launch.viewer |
我该如何了解为我设置了哪些访问策略?
您可以在 IBM Cloud 控制台中查看为您设置了哪些访问策略。
- 转至 访问 IAM 用户。
- 单击用户表中您的名称。
- 单击访问策略选项卡以查看您的访问策略。
- 单击 访问组 选项卡以查看您所属的访问组。 检查每个组的策略。