Huawei

This section provides information about creating a user with policies, which is required for the DSPM product to connect to a customers' Huawei Cloud accounts.

Create a Policy

  1. Sign in to the Huawei Cloud Console and open the IAM console with an appropriate admin-level account.

  2. In the navigation pane on the left, choose Permissions > Policies/Roles, and then choose Create Custom Policy in the upper-right corner.

  3. In the Policy Content section, allow the following actions.

  4. In Actions allowed, choose the following actions to add to the policy.
    • For scanning
      • Object Storage Service
        • obs:bucket:ListAllMyBuckets
        • obs:bucket:GetBucketLocation
        • obs:bucket:ListBucket
        • obs:object:GetObject
        • obs:object:GetObjectAcl
      • Identity and Access Management
        • iam:users:listUsers
        • iam:users:getUser
        • iam:groups:listGroupsForUser
        • iam:groups:listGroups
        • iam:credentials:listCredentials
        • iam:permissions:listRolesForGroup
        • iam:permissions:listRolesForGroupOnDomain
    • For revoke permissions
      • Object Storage Service
        • obs:object:PutObjectAcl
    • For cloud tagging
      • Object Storage Service
        • obs:object:PutObject
    • For persistent tagging and move files
      • Object Storage Service
        • obs:object:DeleteObject
        • obs:object:PutObject

Create a User Group

  1. In the navigation pane on the left, choose User Groups, and then choose Create User Group in the upper-right corner.

  2. On the displayed page, enter a user group name.
  3. Click OK.

Assigning Permissions to a User Group

  1. In the user group list, click Authorize in the row that contains the created user group.

  2. On the Authorize User Group page, select the previously created policy to be assigned to the user group and click Next.

  3. Select All resources in the scope.

  4. Select OK.

Create a User

  1. In the navigation pane on the left, choose Users, and then choose Create User in the upper-right corner.

  2. On the Set User Details page, under User details, in User name, enter the name for the new user (for example, Huawei-connector-user) and select Next.

  3. Fill in the required fields and submit the changes.
  4. In the user list, click Authorize in the row that contains the created user.
  5. On the Authorize User page, select an authorization mode as Inherit permissions from user groups and select the previously created group.

  6. Click OK.

Create Access Key

  1. Choose Security Settings in the row containing the IAM user, then scroll to the Access Keys section and click the Create Access Key button.

  2. Give a meaningful description and click OK.

    Note: Save the generated access key, as it cannot be viewed later.