SchedulerX supports permission management at the namespace and application levels. For access control, you can use Resource Access Management (RAM) to assign access policies. SchedulerX is compatible with existing application-based permission configurations. This topic describes how to manage application permissions.
Manage permissions on namespaces
If no namespace exists in your Alibaba Cloud account after you activate SchedulerX and access a region, the system automatically creates a default namespace. You can change the name of the default namespace or create a new one.
Namespaces are typically used to isolate environments. Different RAM users may be responsible for different applications that run in the same environment. Therefore, SchedulerX does not isolate namespace permissions for each RAM user. All RAM users that belong to the same Alibaba Cloud account can view all namespaces created within that account, regardless of who created them. For example, if an Alibaba Cloud account PrimaryAccount-A has two RAM users, subAccount-B and subAccount-C, any namespace created by one of these three accounts is visible to the other two.
Manage permissions on applications
Different RAM users are typically responsible for different applications. An application created by a RAM user is not visible to other RAM users, but it is visible to the parent Alibaba Cloud account. The Alibaba Cloud account can grant other RAM users access to the application. A RAM user can also grant other RAM users access to their applications.
-
Log on to the EDAS console.
-
In the left-side navigation pane, click Task Scheduling (SchedulerX).
-
In the top navigation bar, select a region.
-
In the left-side navigation pane, click Application Management.
On the Application Management page, select a namespace from the list next to Namespace.
On the Application Management page, find the target application and click Authorize in the Actions column.
On the Authorization Management page, select the RAM users that you want to authorize from the Unauthorized list, click
to add them to the Authorized list, and then click OK.