Request cross-account authorization

Updated at:

Data Transmission supports data migration and data synchronization between different Alibaba Cloud accounts. This process requires authorization from the other account. This topic describes how to request cross-account authorization.

Background information

Before you can purchase and use Alibaba Cloud products and services, you must create an Alibaba Cloud account. After you set up and verify this account, which can be a personal or enterprise account, you can purchase and use cloud resources such as ECS and database services. While using these resources, you may need to grant resource authorization, migrate data, or synchronize data between different Alibaba Cloud accounts. Therefore, Data Transmission Service supports data migration and data synchronization between different Alibaba Cloud accounts.

For example, consider Account A and Account B. If Account A wants to access an OceanBase instance or a Virtual Private Cloud (VPC) that belongs to Account B, Account A can request authorization from Account B. Follow the steps in this topic to make the request.

Submit an authorization request

  1. Go to the Cross-account Authorization Information page.

    image

    1. Log on to the OceanBase Management Console .

    2. In the navigation pane on the left, click Data Transmission > System Administration.

    3. On the System Administration page, click the Cross-account Authorization Information tab. The My Requests page appears by default.

  2. On the My Requests page, click Request Cross-account Authorization in the upper-right corner.

  3. In the Request Cross-account Authorization dialog box, configure the parameters.

    image

    Parameter

    Description

    Peer Account UID

    Enter the user identifier (UID) of the account that you want to access. For more information about how to obtain the UID, see Obtain the UID of the peer account.

    Authorized Role

    The default value is AliyunOceanBaseMigrationServiceRole.

    Reason for Request (Optional)

    Enter the reason for the authorization request.

  4. Click Request.

  5. After you submit the request, notify the owner of the peer account to log on to the System Administration > Cross-account Authorization Information > Requests from Others page to approve the request.

    image

    You can view the approval progress on the System Administration > Cross-account Authorization Information > My Requests page.

Cancel an authorization request

You can cancel a request that is in the Pending Authorization state.

  1. Go to the Cross-account Authorization Information > My Requests page.

  2. On the My Requests page, find the request that is pending authorization and click Cancel in the Actions column.

    image

  3. In the dialog box, click Cancel Request.

    After the operation is complete, the status of the request changes to Canceled.

Revoke an authorization request

You can revoke a request that is in the Authorized state.

  1. Go to the Cross-account Authorization Information > My Requests page.

  2. On the My Requests page, find the authorized request and click Revoke in the Actions column.

    image

  3. (Optional) Before revoking the authorization, release any associated data migration or data synchronization tasks that are displayed in the dialog box. Then, go to the My Requests page to perform the revocation.

    Note

    If no unreleased tasks exist, skip this step.

    image

  4. In the Revoke Authorization dialog box, enter revoke and click Revoke Authorization.

    After the operation is complete, the status of the request changes to Revoked.

Resubmit an authorization request

You can resubmit a request that is in the Canceled, Revoked, or Rejected state.

  1. Go to the Cross-account Authorization Information > My Requests page.

  2. On the My Requests page, find the canceled, revoked, or rejected request and click Resubmit in the Actions column.

    image

  3. In the Resubmit Request dialog box, enter a Reason for Request.

    Note

    The peer account UID and authorized role cannot be modified. Entering a reason for the request is optional.

  4. Click Request.

  5. After you submit the request, notify the owner of the peer account to log on to the System Administration > Cross-account Authorization Information > Requests from Others page to approve the request.

References

Approve a cross-account authorization request

View cross-account authorization information