When you use E-MapReduce (EMR), properly managing member permissions helps prevent security risks such as data leakage and misoperations.
Permission management system
|
Item |
Description |
|
Principals |
EMR supports the following principals:
|
|
Objects |
EMR supports fine-grained permission management on objects such as Elastic Compute Service (ECS) instances, virtual private clouds (VPCs), Object Storage Service (OSS) buckets, and Data Lake Formation (DLF) metadata. |
|
User group authorization |
To grant the same permissions to multiple users, assign a role to the users as a group. For more information, see Grant permissions to a RAM user group. |
|
User authorization |
You can grant permissions to users by using one of the following methods:
|
References
-
Before you use EMR for the first time, use your Alibaba Cloud account to assign the required roles to EMR. For more information, see Assign roles to an Alibaba Cloud account.
-
To manage permissions for different roles such as developers and O&M engineers, see Grant permissions to RAM users.
-
EMR service roles allow EMR to access other Alibaba Cloud services when you configure resources or perform service-level operations. For more information, see EMR service roles.
-
EMR application roles allow applications running on an EMR cluster to access other Alibaba Cloud resources. For more information, see ECS application role (used in a minor version later than EMR V3.32.0 or EMR V4.5.0 and EMR 5.X series).
-
To use a custom ECS application role, see Use a custom ECS application role to access other cloud resources in your Alibaba Cloud account.