The management account or a member of a resource directory can share resources with the entire resource directory, a specific folder, or a specific member.
Background information
In this example, a resource owner (the management account of a resource directory) shares one or more vSwitches in a virtual private cloud (VPC) with a member in the resource directory.
Step 1: Enable resource sharing
-
Log on to the Resource Management console with the management account of your resource directory.
-
In the left-side navigation pane, choose Resource Sharing > Settings.
-
Click Enable.
-
In the Service-linked Role for Resource Sharing dialog box, click OK.
The system creates the Service-linked role for Resource Sharing (AliyunServiceRoleForResourceSharing) to obtain the resource directory organizational structure.
Step 2: Create a resource share
-
Log on to the Resource Management console as a resource owner.
-
In the navigation pane on the left, choose Resource Sharing > Resources I Share.
-
In the top navigation bar, select the region where the resources to be shared reside.
ImportantIf you want to share global resources, such as templates in Resource Orchestration Service (ROS), you must select the China (Shanghai) region to create resource shares.
-
Click Create Resource Share, and then configure the resource share.
-
Configure basic information and add resources.
Enter a resource share name, add tags based on your business requirements, and then select the resources to share. In this example, vSwitches are selected.
-
Add permissions.
Permissions specify the operations that principals can perform on shared resources. In this example, select AliyunRSDefaultPermissionVSwitch. Click the permission name to view details.
-
Add principals.
Set Principal Scope to Objects Within Resource Directory, set Method to Add from Resource Directory , and then select a folder or member from the resource directory. In this example, a member is selected.
-
Confirm the configurations and click OK.
-
Step 3: Verify the result
You can verify whether resources are shared successfully by using one of the following methods:
-
Resource owner
On the details page of the resource share in the Resource Management console, check the sharing status. If the status of both the resource and the principal is Associated, the resource is shared.
-
Principal
In the console of the Alibaba Cloud service to which the resources belong, view and manage the shared resources. In this example, log on to the VPC console as the member and view the shared vSwitches.
In the list of vSwitches, a blue Shared label appears under the name of the shared vSwitch (such as vs3). The vSwitch belongs to the VPC owned by the resource owner (such as test3).