Creating Policy Based on Fault Report
Overview
This document describes how to create a policy for troubleshooting through fault reports. After the fault is cleared, sub-accounts will manage resources under the root account within the newly set permission range.
Example
When a sub-account with QcloudCVMReadOnlyAccess policy tries to reinstall the CVM, an error message will be displayed as follows:
If you wish to authorize a sub-account to continue operations, you can create and associate a custom policy for it based on the current error information.
Directions
Enter the Policies page in the CAM console, click Create Definition Policy.
In the pop-up window for selecting a creation method, click Create by Policy Builder to enter the page of selecting service and operation.
On the page of selecting service and operation, add the following information,
- Effect (required): According to the authorization effect, choose to 'Allow' or 'Deny'. In this example, select Allow.
- Service (required): Select the product to be authorized according to its English abbreviation. In this example, for cvm in the operation of the error message, you will select Cloud Virtual Machin from the product list.
- Operation (required): select the operation you want to authorize. In this example, it corresponds to "ResetInstance" in the error message operation.
- Resources (required): Fill in the six-segment resource of the resources you want to authorize.
- Condition (optional): Set the effective conditions for the above authorization of sub-accounts, such as access by specified IP. In this example, it does not need to be filled in.
Click Add Statement > Next to go to the policy editing page.
On the policy editing page, add the policy name and remarks and confirm the content of the policy. The policy name and content are automatically generated by the console.
- The policy name defaults to policygen, with a numerical suffix generated based on the creation date. You can also customize this as needed.
- The content of the policy corresponds to the services and operations in step 3. You can modify it according to your actual needs
Click Create Policy to complete the operation of creating a custom policy by policy builder.
Authorize the sub-account. After successful authorization, the sub-account will obtain corresponding permissions and remove the fault.
SMS Verification Failure
Symptom Description
When binding or changing mobile numbers, resetting passwords, etc., no verification information is received on the mobile.
Possible Causes
The main reasons for not receiving verification information on the mobile include:
- Incorrect mobile phone number and area code.
- The phone system automatically hides the content based on keywords.
- Abnormal reception caused by the mobile phone number itself, such as arrears and network failure.
Steps
- Confirm whether the mobile phone number is correct.
- If yes, go to the next step.
- If no, change the mobile number.
- Verify whether the mobile phone is out of service.
- If yes, make a payment or change your mobile phone number.
- If no, go to the next step.
- Confirm whether the authentication SMS is blocked as spam.
- If yes, disable the SMS Interception in the application software.
- If no, go to the next step.
- Abnormal network communication may cause SMS loss. Confirm whether the network communication is abnormal.
Email Verification Failure
Symptom Description
When binding or changing emails, resetting passwords, etc., the email does not receive verification information.
Possible Causes
The main reasons for not receiving verification information in the email include:
- The email address is incorrect.
- The email system automatically hides the content based on keywords.
- The email system has special restrictions that cause reception to fail. For example, a company's in-house email system prohibits receiving third-party emails.
Steps
- Confirm whether the email address is correct.
- If yes, go to the next step.
- If no, change the email address.
- Confirm whether the authentication information is regarded as spam and stored in the trash can.
- Yes, set the Cloud's email to the allowlist.
- If no, go to the next step.
- Abnormal network communication may cause email loss. Please confirm whether the network communication is abnormal.
- If yes, obtain it again or try again later.
- If no, go to the next step.
- Confirm whether you are using a company's in-house email system with third-party mail restrictions.