A Resource Access Management (RAM) user must be granted the AliyunClickHouseFullAccess permission before the RAM user follows instructions in the Quick Start tutorial to perform operations in the ApsaraDB ClickHouse console, such as creating a cluster and a database account. This topic describes how to use an Alibaba Cloud account to grant permissions to a RAM user. If you use an Alibaba Cloud account to log on to ApsaraDB ClickHouse, skip this topic.

Prerequisites

An Alibaba Cloud account is created. If you do not have an Alibaba Cloud account, visit the Alibaba Cloud official website to create an account.

Procedure

  1. Log on to the RAM console by using your Alibaba Cloud account.
  2. In the left-side navigation pane, choose Identities > Users.
  3. On the Users page, find the RAM user to which you want to grant permissions and click Add Permissions in the Actions column.
  4. In the Add Permissions panel, grant the required permissions to the RAM user. The following table describes the parameters.
    Parameter Description Example
    Authorized Scope
    • Alibaba Cloud Account: The permissions take effect on the current Alibaba Cloud account.
    • Specific Resource Group: The permissions take effect in a specific resource group.
    Alibaba Cloud Account
    Principal The RAM user to which you want to grant permissions. The system automatically sets this parameter to the current RAM user. You can also specify a different RAM user. test@cores.onaliyun.com
    Select Policy Policies are classified into system policies and custom policies.
    • System policy: Alibaba Cloud provides various default policies for different management purposes. ApsaraDB ClickHouse uses the following system policies:
      • AliyunClickHouseFullAccess: the permission to manage ApsaraDB ClickHouse. The account that is granted this permission can perform all operations on all resources in ApsaraDB ClickHouse.
      • AliyunClickHouseReadOnlyAccess: the read-only permission of ApsaraDB ClickHouse resources. The account that is granted this permission can view a list of ApsaraDB ClickHouse clusters and database accounts.
    • Custom policy: You can customize policies based on your business requirements. Custom policies are suitable for users who are familiar with the APIs of Alibaba Cloud services and require fine-grained control.
    Note You can attach a maximum of five policies to a RAM user at the same time. If you want to attach more than five policies to a RAM user, repeat the operation.
    AliyunClickHouseFullAccess
  5. Click OK.
  6. Click Complete.

What to do next

Create a cluster