This topic describes how to grant permissions to an Alibaba Cloud account or a RAM user to perform operations such as draft development.

Background information

  • Fully managed Flink allows you to authorize other Alibaba Cloud accounts or RAM users to use the fully managed Flink service. If an Alibaba Cloud account or a RAM user is not granted the permissions to use fully managed Flink by the Alibaba Cloud account that purchases the fully managed Flink service, the Namespace List page is empty after you log on to the console of fully managed Flink by using the Alibaba Cloud account or as a RAM user. As a result, you cannot perform operations such as draft development. Error 403
  • The features that an Alibaba Cloud account or a RAM user can use vary based on the role that is assigned to the Alibaba Cloud account or RAM user. The following table describes the features that are supported by different roles.
    FeatureOwnerEditorviewer
    View deploymentsYYY
    Start and cancel a deploymentYYN
    Modify deployment configurationsYYN
    View resourcesYYY
    Upload resourcesYYN
    Write SQL statementsYYN
    Create a user-defined function (UDF)YYN
    Register metadataYYN
    View a deployment templateYYY
    Add, delete, and modify a deployment templateYNN
    Manage members of a workspaceYNN

Grant permissions to the synchronization account

  1. Create an Alibaba Cloud account or a RAM user.
  2. Grant permissions to the Alibaba Cloud account or RAM user in the console of fully managed Flink.
    1. Log on to the Realtime Compute for Apache Flink console.
    2. On the Fully Managed Flink tab, find the workspace that you want to manage and click Console in the Actions column.
    3. In the left-side navigation pane, click Security.
    4. On the Members tab, click Add Member.
    5. In the Add Member dialog box, configure the Role and Member Information parameters.
      Add Member
      • Role: For more information about the features that are supported by different roles, see Background information.
      • Member Information: The RAM users of your Alibaba Cloud account in the current instance are displayed after you click the Member Information field. You can select the required RAM user of your Alibaba Cloud account or enter the ID of another Alibaba Cloud account in the Member Information field.
        Note You can enter the ID of an Alibaba Cloud account or a RAM user for a fuzzy match.
    6. Click OK.
  3. Log on to the console of fully managed Flink by using the newly created Alibaba Cloud account or as a RAM user.
    For more information about how to log on to the Alibaba Cloud Management Console as a RAM user, see Log on to the Alibaba Cloud Management Console as a RAM user.
    Important If you have logged on to the console of fully managed Flink by using the newly created Alibaba Cloud account or as a RAM user, you must log on to the console again by using the Alibaba Cloud account or as a RAM user after the Alibaba Cloud account or RAM user is authorized to use fully managed Flink. Otherwise, you cannot view project information.