How to Use the TLS Authorization File to Grant Permissions to an IAM Account¶
Background¶
This guide starts from scratch to create an IAM account and grant permissions. If you have already performed related operations, you can skip this section.
Steps¶
-
On the page for binding a Volcengine TLS external index in TrueWatch (see Binding Volcengine TLS External Index), click Download Authorization File, open the file, copy the JSON content, and save it as a backup. This will be used later.
-
Log in to your Volcengine primary account and complete real-name authentication.
Note: If no prompt appears, you have already completed authentication.
- Click the avatar in the top-right corner, select API Access Key from the dropdown.
- Click Create Key to create a new sub-user.
- Create a user. You can create one using the current username, or invite other accounts to create one.
The following image shows creation by username:
- Enter the required information for the sub-user, then click Next.
Note: Under Login Settings, you must select Programmatic Access.
- In the Permission Settings section, do not select any permission policy; set the Scope of Action to Global.
- After the review and mobile phone verification, you can view the AK and AKS information and download them.
- Click Policy Management and create a custom policy.
- Click JSON Editor, enter a policy name, paste the JSON you copied in Step 1, and click Submit.
-
After successful submission, click Add Authorization to assign the permission policy to the sub-user you created.
-
Enable the Log Service for your Volcengine account.








