Overview
To grant a RAM user full permissions for Cloud Architect Design Tools (CADT) and related resources, attach the following policies:
-
AliyunCADTFullAccess
-
AliyunConfigFullAccess
-
AliyunResourceDirectoryReadOnlyAccess
-
AliyunRAMReadOnlyAccess
-
AliyunQuotasReadOnlyAccess
-
Full permissions for the required products
NoteFor subscription resources, you must also attach the AliyunBSSRefundAccess policy.
Grant permissions
-
In the RAM console, go to the Users page, find the target user, and click Add Permissions.
-
On the Grant Permission page, attach the following policies, and then click Grant permissions.
In this example, a test application named CADT-Test contains VPC, ECS, and EIP resources. In addition to the AliyunCADTFullAccess and AliyunConfigFullAccess policies, you must grant the RAM user full permissions for these products.
-
AliyunCADTFullAccess
-
AliyunConfigFullAccess
-
AliyunResourceDirectoryReadOnlyAccess
-
AliyunRAMReadOnlyAccess
-
AliyunQuotasReadOnlyAccess
-
AliyunVPCFullAccess
-
AliyunECSFullAccess
-
AliyunEIPFullAccess
-
-
The specified policies are now attached to the user.
Verify permissions
After you grant the permissions, verify that the RAM user can manage CADT and related resources as expected.
-
Open a browser in incognito mode and sign in to the CADT console as the RAM user. To obtain the logon URL, sign in to the RAM console, click Overview in the left-side navigation pane, find the User Logon URL in the Account Management area, and then click Copy. After you sign in as the RAM user cadt-user, click your profile picture in the upper-right corner to confirm the identity.
-
In the top navigation bar, choose Application > My Applications. Find the sample application, hover over it, and click Copy Architecture to create a new application with the same architecture.
-
Click Save in the upper-right corner. In the Save Application dialog box, enter an application name, such as
CADT-Test-1, and then click OK. -
Click Deploy Application to start the deployment.
-
Complete Resource Validation, the Price List, and deployment. The Resource Validation window displays the validation results for resources such as vSwitch, region, security group, EIP, and VPC. After the status shows Validation successful, click Next: Price List. On the Price List page, review the costs and click Next: Confirm Order. In the Confirm Order dialog box, select the pay-as-you-go tab, verify that the resource list includes the ECS (instance type ecs.c6.large) and EIP (BGP) resources to be created, select the Cloud Architect Design Tools Service Terms checkbox, and then click Pay and Create.
-
Wait for the deployment to complete. The Resource Deployment Status window shows a status of Deployment successful, and all five created resources (VPC, vSwitch, EIP, ECS, and security group) are in the Running state.
-
At the bottom of the screen, open the resource list and click Release all resources to verify the release permission.
In the Resource Deployment Status window, confirm that the status of all resources is Deleted and that the status in the deployment summary shows Release successful.
-
You can use the same method to verify permissions for other CADT features. After all resources are released, the CADT console home page displays a menu bar with items such as New, Application, Resource, Management, Export, Migration, Intelligent Monitoring, Disaster Recovery Management Service, and Help Documentation. The tabs at the bottom of the page include Application Panorama, All Applications, Deployment Successful, Offline Applications, and Deleted Applications.