授予存取權限至 Workload Protection
對 Workload Protection 的存取權限由 IBM Cloud® Identity and Access Management (IAM)進行管控。 您帳戶中每位存取 Workload Protection 服務的使用者,都必須被指派一項包含 IAM 角色的存取政策。 此政策決定使用者在 Workload Protection 的環境下可執行的操作。
帳戶中的使用者必須被指派一個平台角色,才能管理實例,並從 IBM Cloud 啟動 Workload Protection。 此外,使用者必須具備一個服務角色,該角色需定義了操作 Workload Protection 的權限。
若要將一組使用者與服務識別碼組織成單一實體,以便您輕鬆管理 IAM 權限 ,請使用存取群組。 您可以將單一政策指派給該群組,而非針對每位使用者或服務識別碼分別多次指派相同的存取權限。 如需更多資訊,請參閱「IAM 存取機制如何運作」。
使用存取群組來管理存取權
若要管理存取群組,您必須是該帳戶中所有已啟用「身分與存取」功能之服務的帳戶擁有者、管理員或編輯者,或是 IAM 存取群組服務的指定管理員或編輯者。
使用下列動作來管理 IBM Cloud中的 IAM 存取群組:
將原則直接指派給使用者來管理存取權
若要透過 IAM 政策來管理存取權限或為使用者指派新的存取權限,您必須是帳戶擁有者、該帳戶中所有服務的管理員,或是特定服務或服務實例的管理員。
使用下列動作來管理 IBM Cloud中的 IAM 原則:
IBM Cloud 平台角色
必須授予使用者平台角色,才能讓他們檢視及管理您帳戶中的「Workload Protection」服務。 您可以授與許可權來使用 IBM Cloud 帳戶中的所有實例,也可以限制個別實例的存取權。
下表識別您可以在 IBM Cloud 中授與使用者執行指定平台動作的平台角色:
| 平台動作 | 管理者 | 編輯者 | 操作員 | 檢視者 |
|---|---|---|---|---|
Grant other account members access to work with the service |
||||
Provision a service instance |
||||
Delete a service instance |
||||
Create a service ID |
||||
View details of a service instance |
||||
View service instances in the Observability Monitoring dashboard |
IBM Cloud 服務角色
下表識別您可以在 IBM Cloud 中授與使用者執行指定動作的服務角色:
| 動作 | 管理員 | 撰寫者 | 讀者 |
|---|---|---|---|
Manage access keys |
|||
Manage Secure API Tokens |
|||
Create, configure, and delete teams |
|||
Configure and remove notifications channels |
|||
Configure and remove agents |
|||
Create, delete, and edit content in the UI |
|||
Manage runtime policies |
|||
Manage image scanning policies |
|||
Manage Activity Audit |
|||
Send container images to the scanning queue |
|||
Create, update and remove alerts |
|||
View reports and image scanning results |
|||
View platforms, frameworks, rules and policies |
|||
View events |
IAM 動作
下表列出了指派給「Workload Protection」服務之平台角色與服務角色的 IAM 操作:
| 角色類型 | 角色 | IAM 動作 |
|---|---|---|
| 平台 | administrator |
sysdig-secure.launch.admin sysdig-secure.launch.user sysdig-secure.launch.viewer |
| 服務 | manager |
sysdig-secure.launch.admin sysdig-secure.launch.user sysdig-secure.launch.viewer |
| 服務 | writer |
sysdig-secure.launch.user sysdig-secure.launch.viewer |
| 服務 | reader |
sysdig-secure.launch.viewer |
我該如何知道為我設定了哪些存取政策?
您可以在 IBM Cloud 控制台中查看為您設定了哪些存取政策。
- 移至 存取 IAM 使用者。
- 按一下使用者表格中您的名稱。
- 按一下存取原則標籤以查看您的存取原則。
- 按一下 存取群組 標籤,以查看您所屬的存取群組。 請檢查每一個群組的原則。