Obtain an O&M token from Bastionhost to perform O&M operations on a host or a database. This topic describes how to obtain an O&M token, how to renew a token before it expires, and what to check when an O&M connection fails.
Token validity and usage
An O&M token for a host or a database in Bastionhost is subject to the following rules:
Validity period — Your administrator sets the validity period of a token in the O&M token settings on the O&M settings page in Bastionhost.
Number of uses — You can use a token an unlimited number of times within its validity period.
O&M review — If your administrator enables O&M review, the validity period and the number of uses that your administrator approves prevail.
Prerequisites
Before you obtain or renew an O&M token, make sure that the following requirements are met:
Host O&M token — A host account is hosted in Bastionhost, the host account is configured for the host that you want to manage, and the account is granted to you. For instructions, see Configure a host account.
Database O&M token — A database account is hosted in Bastionhost, the database account is configured for the database that you want to manage, and the account is granted to you. For instructions, see Database management.
Token renewal — Your administrator has enabled token renewal in the O&M token settings and has not enabled O&M review. If either condition is not met, you cannot renew a token. Request a new token instead.
Choose an operation path
Every procedure in this topic provides two paths, one for RAM users and one for non-RAM users. The two paths differ in the page that you start from:
RAM user — Start from the Host O&M page for a host or from the Database O&M page for a database.
Non-RAM user — Start from the Hosts page for a host or from the Databases page for a database.
Obtain an O&M token
Obtain a host O&M token
RAM user
Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.
In the list of Bastionhost instances, find the target instance and click Manage.
In the navigation pane on the left, choose .
On the Host O&M page, find the host that you want to manage and click Log On.
In the Remote Connection dialog box, select a Host Account and click Obtain O&M Token.
Non-RAM user
Log on to the O&M portal. For more information, see Log on to the O&M portal.
In the navigation pane on the left, click Hosts.
On the Hosts page, find the host that you want to manage and click Remote Connection.
In the Remote Connection dialog box, select a Host Account and click Obtain O&M Token.
Obtain a database O&M token
RAM user
Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.
In the list of Bastionhost instances, find the target instance and click Manage.
In the navigation pane on the left, choose .
On the Database O&M page, find the database that you want to manage and click the O&M Token button in the Log On column.
In the O&M Token dialog box, select a Database Account and click Obtain O&M Token.
Non-RAM user
Log on to the O&M portal. For more information, see Log on to the O&M portal.
In the navigation pane on the left, click Databases.
On the Databases page, find the database that you want to manage and click the O&M Token button in the O&M Token column.
In the O&M Token dialog box, select a Database Account and click Obtain O&M Token.
Renew an O&M token
Renewal rules and limits
Token renewal in Bastionhost is subject to the following rules:
Renewal window — Renew a token before it expires. After a token expires, request a new token.
Validity extension — Each renewal extends the validity period of the token by one hour. Your administrator sets the total number of renewals that you can perform.
Settings changes — After your administrator modifies the O&M token settings, request a new token or update the existing token before the changed settings take effect.
Renew a host O&M token
RAM user
Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.
In the list of Bastionhost instances, find the target instance and click Manage.
In the navigation pane on the left, choose .
On the Host O&M page, find the host that you want to manage and click Log On.
In the Remote Connection dialog box, select a Host Account and click View O&M Token.
On the O&M Token page, click Renew Token.
Non-RAM user
Log on to the O&M portal. For more information, see Log on to the O&M portal.
In the navigation pane on the left, click Hosts.
On the Hosts page, find the host that you want to manage and click Remote Connection.
In the Remote Connection dialog box, select a Host Account and click View O&M Token.
On the O&M Token page, click Renew Token.
Renew a database O&M token
RAM user
Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.
In the list of Bastionhost instances, find the target instance and click Manage.
In the navigation pane on the left, choose .
On the Database O&M page, find the database that you want to manage and click the View O&M Token button in the Log On column.
On the O&M Token page, click Renew Token.
Non-RAM user
Log on to the O&M portal. For more information, see Log on to the O&M portal.
In the navigation pane on the left, click Databases.
On the Databases page, find the database that you want to manage and click the O&M Token button in the O&M Token column.
In the O&M Token dialog box, select a Database Account and click View O&M Token.
On the O&M Token page, click Renew Token.
Troubleshoot O&M connection failures
If your O&M token is still within its validity period but the O&M connection fails, check the following causes:
Concurrent connection limit — The number of concurrent O&M connections may have reached the upper limit. Contact your administrator to upgrade the specifications of the Bastionhost instance or to release idle connections.
Source IP address and time period restrictions — Your administrator may have restricted the source IP address and the time period, which prevents O&M operations. Contact your administrator to remove the restrictions.
Next steps
After you obtain an O&M token, use the token to perform O&M operations on the asset:
To run O&M operations from a client, see Client-based O&M.
To run O&M operations from the O&M portal, see Portal-based O&M.