Tenant Cloud Network Virtual Private Cloud Operation Guide Resource-level Permissions Supported by VPC API Operations

Resource-level Permissions Supported by VPC API Operations

Last Updated At: 2025-10-21 09:10:00

In CAM, the following API operations can be performed on VPC resources. The corresponding relationship between resources and conditions supported by specific APIs is as follows:

Note: If the VPC API does not support resource-level permissions in the table, you can grant users access to VPC APIs that are not in this list but must specify * for resource elements of policy statements.

API Operation Resources Condition Remarks
AcceptVpcPeeringConnection VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc:region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId</
vpc:accepter_vpc
vpc:region
vpc:requester_vpc
The value of vpc: accepter_vpcq is the accepter VPC.
vpc: Region indicates the region where it is located.
The value of vpc: requester_vpc is the requester VPC.
VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId (accepter vpcId)
vpc:region vpc: Region indicates the region where the VPC is located.
AcceptVpcPeeringConnectionEx Peering connection resources
qcs::vpc:$region:$account:pcx/* qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:accepter_vpc_region
vpc:requester_vpc
vpc:requester_vpc_region
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: accepter_vpc_region indicates the accepter region.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: requester_vpc_region indicates the requester region.
VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
AddVpnConnEx VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
VPN gateway resources
qcs::vpc:$region:$account:vpngw/*
qcs::vpc:$region:$account:vpngw/$vpnGwId
vpc:vpc
vpc:region
vpc:vpc represents the developer's VPC. vpc:region represents the region of the vpc.
Customer gateway resources
qcs::vpc:$region:$account:cgw/*
vpc:region vpc: Region indicates the region where the VPC is located.
VPN channel resources
qcs::vpc:$region:$account:vpnx/*
vpc:vpc
vpc:vpngw
vpc:region
vpc: vpc indicates the developer's VPC.
vpc:vpngw indicates the VPN gateway under the developer.
vpc: Region indicates the region where the VPC is located.
AssignPrivateIpAddresses ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
AssociateVip VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc:vpc
AssociateRouteTable Subnet resource
qcs::vpc:$region:$account:subnet/*
qcs::vpc:$region:$account:subnet/$subnetId
vpc:vpc vpc:region vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
Routing table resources
qcs::vpc:$region:$account:rtb/*
qcs::vpc:$region:$account:rtb/$routeTableId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
AttachClassicLinkVpc VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
CVM resources
qcs::cvm:$region:$account:instance/*
qcs::cvm:$region:$account:instance/$instanceId
cvm:region cvm: region indicates the area where the CVM is located.
AttachNetworkInterface ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
CVM resources
qcs::cvm:$region:$account:instance/*
qcs::cvm:$region:$account:instance/$instanceId
cvm:region cvm: region indicates the area where the CVM is located
CreateAndAttachNetworkInterface VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
CVM resources
qcs::cvm:$region:$account:instance/*
qcs::cvm:$region:$account:instance/$instanceId
cvm:region cvm: region indicates the area where the CVM is located
ENI resources
qcs::vpc:$region:$account:eni/*
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
CreateDirectConnectGateway VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateLocalDestinationIPPortTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateLocalIPTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateLocalIPTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateLocalSourceIPPortTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateLocalSourceIPPortTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreatePeerIPTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateNatGateway VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
NAT gateway resources
qcs::vpc:$region:$account:nat/*
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateNetworkAcl VPC resource qcs::vpc:$region:$account:vpc/* qcs::vpc:$region:$account:vpc/$vpcId vpc:region vpc: Region indicates the region where the VPC is located.
Network ACL resources
qcs::vpc:$region:$account:acl/*
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateNetworkInterface VPC Resources qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Subnet resource
qcs::vpc:$region:$account:subnet/*
qcs::vpc:$region:$account:subnet/$subnetId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ENI Resources qcs::vpc:$region:$account:eni/* vpc:vpc
vpc:subnet
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: subnet indicates the developer's subnet.
vpc: Region indicates the region where the VPC is located.
CreateRoute Routing table resources
qcs::vpc:$region:$account:rtb/*
qcs::vpc:$region:$account:rtb/$routeTableId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateRouteTable VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Routing table resources
qcs::vpc:$region:$account:rtb/*
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateSubnet VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Subnet gateway resources
qcs::vpc:$region:$account:subnet/*
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateSubnetAclRule Network ACL resources
qcs::vpc:$region:$account:acl/*
qcs::vpc:$region:$account:acl/$networkAclId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
Subnet gateway resources
qcs::vpc:$region:$account:subnet/*
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
CreateVpcPeeringConnection VPC resource (requester)
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
vpc:accepter_vpc
vpc:requester_vpc
vpc:region
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: Region indicates the region where the VPC is located.
CreateVpcPeeringConnectionEx VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resource qcs::vpc:$region:$account:pcx/* vpc:accepter_vpc
vpc:accepter_vpc_region
vpc:requester_vpc
vpc:requester_vpc_region
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: accepter_vpc_region indicates the accepter region.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: requester_vpc_region indicates the requester region.
DeleteDirectConnectGateway Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteLocalDestinationIPPortTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteLocalIPTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc vpc:region vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteLocalIPTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteLocalSourceIPPortTranslationAclRule< Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeletePeerIPTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteLocalSourceIPPortTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteNatGatewaynat Gateway resources
qcs::vpc:$region:$account:nat/*
qcs::vpc:$region:$account:nat/$natId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteNetworkAcl Network ACL resources

qcs::vpc:$region:$account:acl/*
qcs::vpc:$region:$account:acl/$networkAclId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteNetworkInterface ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
DeleteRoute Routing table resources
qcs::vpc:$region:$account:rtb/*
qcs::vpc:$region:$account:rtb/$routeTableId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteRouteTable Routing table resources
qcs::vpc:$region:$account:rtb/*
qcs::vpc:$region:$account:rtb/$routeTableId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteSubnet Subnet resource
qcs::vpc:$region:$account:subnet/*
qcs::vpc:$region:$account:subnet/$subnetId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
DeleteUserGw Customer gateway resources
qcs::vpc:$region:$account:cgw/*
qcs::vpc:$region:$account:cgw/$userGwId
vpc:region vpc: Region indicates the region where the VPC is located.
DeleteVpc VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region
vpc:vpc
vpc: Region indicates the region where the VPC is located.
DeleteVpcPeeringConnection Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:region
vpc:requester_vpc
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: Region indicates the region where the VPC is located.
DeleteVpcPeeringConnectionEx Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:accepter_vpc_region
vpc:requester_vpc
vpc:requester_vpc_region
DeleteVpnConn VPN channel resources
qcs::vpc:$region:$account:vpnx/*
qcs::vpc:$region:$account:vpnx/$vpnConnId
vpc:vpc
vpc:vpngw
vpc:usergw
vpc:region
vpc: vpc represents the developer's VPC.
vpc:vpngw indicates the gateway under the developer.
vpc:usergw indicates the customer gateway under the developer.
vpc: Region indicates the region where the VPC is located.
DetachClassicLinkVpc VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region
vpc:vpc
vpc: Region indicates the region where the VPC is located.
CVM resources
qcs::cvm:$region:$account:instance/*
qcs::cvm:$region:$account:instance/$instanceId
cvm:region cvm: region indicates the area where the CVM is located
DetachNetworkInterface CVM resources
qcs::cvm:$region:$account:instance/*
qcs::cvm:$region:$account:instance/$instanceId
cvm:region cvm: region indicates the area where the CVM is located
ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
DeteleSubnetAclRule Subnet resource
qcs::vpc:$region:$account:subnet/*
qcs::vpc:$region:$account:subnet/$subnetId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
Network ACL resources
qcs::vpc:$region:$account:acl/*
qcs::vpc:$region:$account:acl/$networkAclId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
EipBindNatGateway NAT gateway resources
qcs::vpc:$region:$account:nat/*
qcs::vpc:$region:$account:nat/$natId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
EipUnBindNatGateway NAT gateway resources
qcs::vpc:$region:$account:nat/*
qcs::vpc:$region:$account:nat/$natId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
EnableVpcPeeringConnection VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc:region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:region
vpc:requester_vpc
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: Region indicates the region where the VPC is located.
EnableVpcPeeringConnectionEx VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resources

qcs::vpc:$region:$account:pcx/*

qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc

vpc:accepter_vpc_region

vpc:requester_vpc

pc:requester_vpc_region
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: accepter_vpc_region indicates the accepter region.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: requester_vpc_region indicates the requester region.
MigrateNetworkInterface ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
CVM resources
qcs::cvm:$region:$account:instance/*
qcs::cvm:$region:$account:instance/$instanceId (authorization is required before and after migration)
cvm:region cvm: region indicates the area where the CVM is located.
MigratePrivateIpAddress ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
ModifyDirectConnectGateway Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyLocalDestinationIPPortTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyLocalIPTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyLocalIPTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyLocalSourceIPPortTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyPeerIPTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyLocalSourceIPPortTranslationNatRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyNatGateway NAT gateway resources
qcs::vpc:$region:$account:nat/*
qcs::vpc:$region:$account:nat/nat-dc7cdf
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyNetworkAcl Network ACL resources
qcs::vpc:$region:$account:acl/*
qcs::vpc:$region:$account:acl/$networkAclId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyNetworkAclEntry Network ACL resources
qcs::vpc:$region:$account:acl/*
qcs::vpc:$region:$account:acl/$networkAclId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyNetworkInterface ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
ModifyPrivateIpAddress ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.
ModifyRouteTableAttribute Routing table resources
qcs::vpc:$region:$account:rtb/*
qcs::vpc:$region:$account:rtb/$routeTableId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifySubnetAttribute Subnet resource
qcs::vpc:$region:$account:subnet/*
qcs::vpc:$region:$account:subnet/$subnetId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
ModifyUserGw Customer gateway resources
qcs::vpc:$region:$account:cgw/*
qcs::vpc:$region:$account:cgw/$userGwId
vpc:region vpc: Region indicates the region where the VPC is located.
ModifyVpcAttribute VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:Region vpc: Region indicates the region where the VPC is located.
ModifyVpcPeeringConnection VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:region
vpc:requester_vpc
vpc:accepter_vpc
ModifyVpcPeeringConnectionEx VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:accepter_vpc_region
vpc:requester_vpc
vpc:requester_vpc_region
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: accepter_vpc_region indicates the accepter region.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: requester_vpc_region indicates the requester region.
ModifyVpnConnEx VPN channel resources
qcs::vpc:$region:$account:vpnx/*
qcs::vpc:$region:$account:vpnx/$vpnConnId
vpc:vpc
vpc:vpngw
vpc:usergw
vpc:region
vpc: vpc represents the developer's VPC.
vpc:vpngw indicates the gateway under the developer.
vpc:usergw indicates the customer gateway under the developer.
vpc: Region indicates the region where the VPC is located.
ModifyVpnGw VPN gateway resources
qcs::vpc:$region:$account:vpngw/*
qcs::vpc:$region:$account:vpngw/$vpnGwId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
RejectVpcPeeringConnection VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:region
vpc:requester_vpc
vpc: accepter_vpc indicates the accepter VPC, and the value is taken as the accepter VPC.
vpc: requester_vpc indicates the requester VPC, and the value is taken as the requester VPC.
vpc: Region indicates the region where the VPC is located.
RejectVpcPeeringConnectionEx VPC resources
qcs::vpc:$region:$account:vpc/*
qcs::vpc:$region:$account:vpc/$vpcId
vpc:region vpc: Region indicates the region where the VPC is located.
Peering connection resources
qcs::vpc:$region:$account:pcx/*
qcs::vpc:$region:$account:pcx/$peeringConnectionId
vpc:accepter_vpc
vpc:accepter_vpc_region
vpc:requester_vpc
vpc:requester_vpc_region
ResetVpnConnSA VPN channel resources
qcs::vpc:$region:$account:vpnx/*
qcs::vpc:$region:$account:vpnx/$vpnConnId
vpc:vpc
vpc:vpngw
vpc:usergw
vpc:region
vpc: vpc represents the developer's VPC.
vpc:vpngw indicates the gateway under the developer.
vpc:usergw indicates the customer gateway under the developer.
vpc: Region indicates the region where the VPC is located.
SetLocalIPTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
\vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
SetLocalSourceIPPortTranslationAclRule Direct connect gateway resources
qcs::vpc:$region:$account:dcg/*
qcs::vpc:$region:$account:dcg/$directConnectGatewayId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
SetSSLVpnDomain VPN gateway resources
qcs::vpc:$region:$account:vpngw/*
qcs::vpc:$region:$account:vpngw/$vpnGwId
vpc:vpc
vpc:region
vpc: vpc indicates the developer's VPC.
vpc: Region indicates the region where the VPC is located.
UnassignPrivateIpAddresses ENI resources
qcs::vpc:$region:$account:eni/*
qcs::vpc:$region:$account:eni/$networkInterfaceId
vpc:vpc
vpc:subnet
vpc:region
vpc: vpc represents the developer's VPC.
vpc: subnet indicates the subnet under the developer.
vpc: Region indicates the region where the VPC is located.