授予存取權限至 Workload Protection

對 Workload Protection 的存取權限由 IBM Cloud® Identity and Access Management (IAM)進行管控。 您帳戶中每位存取 Workload Protection 服務的使用者,都必須被指派一項包含 IAM 角色的存取政策。 此政策決定使用者在 Workload Protection 的環境下可執行的操作。

帳戶中的使用者必須被指派一個平台角色,才能管理實例,並從 IBM Cloud 啟動 Workload Protection。 此外,使用者必須具備一個服務角色,該角色需定義了操作 Workload Protection 的權限。

若要將一組使用者與服務識別碼組織成單一實體,以便您輕鬆管理 IAM 權限 ,請使用存取群組。 您可以將單一政策指派給該群組,而非針對每位使用者或服務識別碼分別多次指派相同的存取權限。 如需更多資訊,請參閱「IAM 存取機制如何運作」。

使用存取群組來管理存取權

若要管理存取群組,您必須是該帳戶中所有已啟用「身分與存取」功能之服務的帳戶擁有者、管理員或編輯者,或是 IAM 存取群組服務的指定管理員或編輯者。

使用下列動作來管理 IBM Cloud中的 IAM 存取群組:

將原則直接指派給使用者來管理存取權

若要透過 IAM 政策來管理存取權限或為使用者指派新的存取權限,您必須是帳戶擁有者、該帳戶中所有服務的管理員,或是特定服務或服務實例的管理員。

使用下列動作來管理 IBM Cloud中的 IAM 原則:

IBM Cloud 平台角色

必須授予使用者平台角色,才能讓他們檢視及管理您帳戶中的「Workload Protection」服務。 您可以授與許可權來使用 IBM Cloud 帳戶中的所有實例,也可以限制個別實例的存取權。

下表識別您可以在 IBM Cloud 中授與使用者執行指定平台動作的平台角色:

IAM 使用者角色和操作
平台動作 管理者 編輯者 操作員 檢視者
Grant other account members access to work with the service 勾號圖示
Provision a service instance 勾號圖示 勾號圖示
Delete a service instance 勾號圖示 勾號圖示
Create a service ID 勾號圖示 勾號圖示
View details of a service instance 勾號圖示 勾號圖示 勾號圖示 勾號圖示
View service instances in the Observability Monitoring dashboard 勾號圖示 勾號圖示 勾號圖示 勾號圖示

IBM Cloud 服務角色

下表識別您可以在 IBM Cloud 中授與使用者執行指定動作的服務角色:

服務角色和操作
動作 管理員 撰寫者 讀者
Manage access keys 勾號圖示
Manage Secure API Tokens 勾號圖示
Create, configure, and delete teams 勾號圖示
Configure and remove notifications channels 勾號圖示
Configure and remove agents 勾號圖示
Create, delete, and edit content in the UI 勾號圖示 勾號圖示
Manage runtime policies 勾號圖示 勾號圖示
Manage image scanning policies 勾號圖示 勾號圖示
Manage Activity Audit 勾號圖示 勾號圖示
Send container images to the scanning queue 勾號圖示 勾號圖示
Create, update and remove alerts 勾號圖示 勾號圖示
View reports and image scanning results 勾號圖示 勾號圖示
View platforms, frameworks, rules and policies 勾號圖示 勾號圖示 勾號圖示
View events 勾號圖示 勾號圖示 勾號圖示

IAM 動作

下表列出了指派給「Workload Protection」服務之平台角色與服務角色的 IAM 操作:

指派給平台和服務角色的 IAM 操作
角色類型 角色 IAM 動作
平台 administrator sysdig-secure.launch.admin
sysdig-secure.launch.user
sysdig-secure.launch.viewer
服務 manager sysdig-secure.launch.admin
sysdig-secure.launch.user
sysdig-secure.launch.viewer
服務 writer sysdig-secure.launch.user
sysdig-secure.launch.viewer
服務 reader sysdig-secure.launch.viewer

我該如何知道為我設定了哪些存取政策?

您可以在 IBM Cloud 控制台中查看為您設定了哪些存取政策。

  1. 移至 存取 IAM 使用者
  2. 按一下使用者表格中您的名稱。
  3. 按一下存取原則標籤以查看您的存取原則。
  4. 按一下 存取群組 標籤,以查看您所屬的存取群組。 請檢查每一個群組的原則。