Adds multi-cloud asset configuration information.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:AddCloudVendorAccountAK |
create |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Vendor |
string |
Yes |
The cloud asset vendor. Valid values:
|
AWS |
| AkType |
string |
Yes |
The AccessKey (AK) type. Valid values:
|
primary |
| SecretId |
string |
Yes |
The AK parameter ID. Valid values:
Note
If AkType is set to primary, this value is the SecretID of the primary account on the third-party cloud. If AkType is set to sub, this value is the Access Key ID of the sub-account on the third-party cloud. For Azure, no distinction is made. This value is the appId in the authentication information. Google Cloud is connected through a service account. AkType defaults to sub, and this value is the private_key_id property value from the JSON-formatted service key file. |
45GLRV4SOT0YFB**** |
| SecretKey |
string |
Yes |
The AK parameter secret. Valid values:
Note
If AkType is set to primary, this value is the Secret Access Key of the primary account on the third-party cloud. If AkType is set to sub, this value is the Secret Access Key of the sub-account on the third-party cloud. For Azure, no distinction is made. This value is the password in the authentication information. Google Cloud is connected through a service account. AkType defaults to sub, and this value is the private_key property value from the JSON-formatted service key file. |
AE6SLd**** |
| Regions |
array |
No |
The list of regions used for AK information verification. This parameter is valid only when Vendor is set to AWS. Note
Call the ListCloudVendorRegions operation to obtain this parameter. |
|
|
string |
No |
The region used for AK information verification. |
ap-south-1 |
|
| SubscriptionIds |
array |
No |
The list of subscription IDs. Note
This parameter is no longer valid. |
|
|
string |
No |
The subscription ID. Note
This parameter is no longer valid. |
9b41e7ae-fcbf-4983-aa32-6fb2e***** |
|
| TenantId |
string |
No |
The tenant ID. This parameter is valid only when Vendor is set to Azure. |
95304a97-339b-4de5-9a7d-cdbffaf**** |
| Domain |
string |
No |
The account domain for connection. Valid values:
Note
This parameter is valid only when Vendor is set to HUAWEICLOUD, Azure, AWS, VOLCENGINE, KingsoftCloud, UCloud, or BaiduCloud, and is required. For KingsoftCloud and BaiduCloud, set this parameter to china. For UCloud, set this parameter to global. |
global |
| AuthModules |
array |
No |
The list of AK-associated modules. If AkType is set to ctdr, this parameter is required. Specify at least one module, such as SIEM, HOST, or CSPM. If this parameter is not specified, the API returns HTTP 400 with error code -101. |
|
|
string |
No |
The AK-associated module code. Valid values:
|
HOST |
|
| Lang |
string |
No |
The language type for the request and response messages. Default value: zh. Valid values:
|
zh |
| VendorAuthAlias |
string |
No |
The AK account name. Note
Used to identify the account to which third-party host assets belong. |
test |
| ExtendInfo |
string |
No |
The extended information. Note
Used to store extended information for different vendors. Google Cloud is connected through a service account. ExtendInfo stores the JSON-formatted service key file, excluding the private_key_id and private_key fields. The file contains the following fields: type, project_id, client_email, client_id, auth_uri, token_uri, auth_provider_x509_cert_url, client_x509_cert_url, and universe_domain. |
{\"product\":\"webFirewall\",\"remark\":\"remark\"} |
| CtdrCloudUserId |
string |
No |
The account ID. Note
The account ID of the connected cloud vendor. This parameter is required when the permission description includes Cloud Threat Detection and Response (CTDR). |
azure_demo_1 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
A60DA4EC-7CD8-577D-AD73-*** |
| Data |
object |
The AK information that is added. |
|
| Status |
integer |
The AK status. Valid values:
|
0 |
| AuthId |
integer |
The unique ID of the AK. |
2158 |
| AkType |
string |
The AK type. Valid values:
|
sub |
| SecretId |
string |
The AK parameter ID. |
AE6SLd**** |
| ServiceStatus |
integer |
The AK usage status. Valid values:
|
0 |
| Vendor |
string |
The cloud asset vendor. Valid values:
|
Tencent |
| Message |
string |
The AK exception information. |
The IAM user is forbidden in the currently selected region |
| AuthModules |
array<object> |
The list of AK-associated modules. |
|
|
object |
|||
| ModuleDisp |
string |
The display name of the module. |
Host Assets |
| ModuleStatement |
string |
The associate permission description for the module. |
Read permission of the cloud server or virtual machine |
| Module |
string |
The module code. Valid values:
|
HOST |
| ModuleAssetType |
string |
The cloud asset description associated with the module. |
Cloud server or virtual machine |
| ModuleServiceStatus |
integer |
The module status. Valid values:
|
0 |
| Message |
string |
The module exception information. |
ak_domain_error |
| VendorAuthAlias |
string |
The AK account name. Note
Used to identify the account to which third-party host assets belong. |
test |
| CtdrCloudUserId |
string |
The account ID. Note
The account ID of the connected cloud vendor. |
azure_demo_1 |
Examples
Success response
JSON format
{
"RequestId": "A60DA4EC-7CD8-577D-AD73-***",
"Data": {
"Status": 0,
"AuthId": 2158,
"AkType": "sub",
"SecretId": "AE6SLd****",
"ServiceStatus": 0,
"Vendor": "Tencent",
"Message": "The IAM user is forbidden in the currently selected region",
"AuthModules": [
{
"ModuleDisp": "Host Assets",
"ModuleStatement": "Read permission of the cloud server or virtual machine",
"Module": "HOST",
"ModuleAssetType": "Cloud server or virtual machine",
"ModuleServiceStatus": 0,
"Message": "ak_domain_error"
}
],
"VendorAuthAlias": "test",
"CtdrCloudUserId": "azure_demo_1"
}
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | CreateAkError | Failed to create an AK. | Failed to create an AK. |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.