{"componentChunkName":"component---src-templates-acg-portal-new-template-tsx","path":"/Cmotjbzvi","result":{"data":{"markdownRemark":{"html":"<p>百舸提供了对接资源池和资源队列 RBAC的授权模式，便于对子用户进行细粒度的访问权限控制。本文介绍如何为子用户配置RBAC权限，实现对百舸资源池和资源队列的权限控制。</p>\n<h2 id=\"声明\"><a href=\"#%E5%A3%B0%E6%98%8E\" aria-label=\"声明 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>声明</h2>\n<p>百舸AI计算平台对RBAC 权限管理声明如下：</p>\n<ul>\n<li>\n<p>禁止未完成RBAC权限授予的子用户访问资源池资源，请及时联系主账号完成RBAC授权，以免带来生产上的不便。</p>\n<ul>\n<li>除AIHCAssetFullControPolicy权限策略外，被授予该权限的用户可以查看平台的公共资产（如公共数据集、预置镜像等），用户自定义资产（自定义数据集、用户上传模型等）受具体授予权限管控。</li>\n</ul>\n</li>\n<li>子用户将只拥有被指定授予的资源池或者资源队列的访问权限。</li>\n</ul>\n<h2 id=\"授权说明\"><a href=\"#%E6%8E%88%E6%9D%83%E8%AF%B4%E6%98%8E\" aria-label=\"授权说明 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>授权说明</h2>\n<ul>\n<li>\n<p>只有如下账号/用户/角色，才能配置百舸的 RBAC 权限：</p>\n<ul>\n<li>百度智能云主账号。</li>\n<li>具有 AIHCFullControlPolicy 权限的 IAM 用户。</li>\n<li>某具体资源池的管理员对资源池下所属队列拥有配置RBAC 权限的能力。</li>\n</ul>\n</li>\n</ul>\n<h2 id=\"前提条件\"><a href=\"#%E5%89%8D%E6%8F%90%E6%9D%A1%E4%BB%B6\" aria-label=\"前提条件 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>前提条件</h2>\n<ul>\n<li>IAM 用户已完成 百舸侧的相关权限配置。</li>\n</ul>\n<h2 id=\"权限说明\"><a href=\"#%E6%9D%83%E9%99%90%E8%AF%B4%E6%98%8E\" aria-label=\"权限说明 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>权限说明</h2>\n<p>百舸内置了三种级别的RBAC权限，如下所示：</p>\n<table>\n<thead>\n<tr>\n<th>角色名称</th>\n<th>角色说明</th>\n<th>依赖成员具备的IAM系统策略</th>\n<th>权限范围</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>资源池管理员</td>\n<td>运维管理资源池和队列的权限（不能创建/删除资源池和节点）</td>\n<td>AIHCResourceOperatorPolicy</td>\n<td>资源池全局配置<br>查看资源池监控/工作负载/资源报表/变更记录等详情信息<br>关联绑定相关依赖产品（Cprom、PFS、子网等）<br>封锁资源池节点<br>创建队列<br>删除队列<br>编辑队列（调度策略、队列状态等）<br>管理队列（添加节点/移出节点/转让节点/封锁节点）<br>资源池成员管理（添加/移出资源池管理员）<br>队列成员管理（添加/移出队列管理员/队列算法开发成员）</td>\n</tr>\n<tr>\n<td>队列管理员</td>\n<td>具备队列的管理权限以及添加队列成员（不支持创建/删除队列，不支持修改队列的配额）</td>\n<td>AIHCDevelopPolicy</td>\n<td>查看队列详情/队列资源视图/队列节点列表/工作负载/队列成员/队列监控<br><strong>使用队列的资源，</strong>在指定的队列进行算法开发（管理开发机、分布式训练以及推理服务等）</td>\n</tr>\n<tr>\n<td>队列内算法开发成员</td>\n<td>具备在本队列内开发的权限，支持在队列内创建开发机、提交训练任务和部署推理服务</td>\n<td>AIHCDevelopPolicy</td>\n<td><strong>使用队列的资源，</strong>在指定的队列进行算法开发（管理开发机、分布式训练以及推理服务等）</td>\n</tr>\n</tbody>\n</table>\n<blockquote>\n<p>需要同时配置IAM系统策略和百舸内部角色，权限才能生效。如需要设置用户A为资源池1的管理员，则首先需要在IAM系统中授予用户A <code>AIHCResourceOperatorPolicy</code> 系统策略，然后在资源池1中为用户A分配<code>资源池管理员</code>的角色.</p>\n</blockquote>\n<h2 id=\"配置iam用户的rbac授权\"><a href=\"#%E9%85%8D%E7%BD%AEiam%E7%94%A8%E6%88%B7%E7%9A%84rbac%E6%8E%88%E6%9D%83\" aria-label=\"配置iam用户的rbac授权 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>配置IAM用户的RBAC授权</h2>\n<ul>\n<li>\n<p><strong>操作步骤</strong></p>\n<ul>\n<li>登陆百舸平台->进入资源池详情->成员管理->配置资源池管理员。</li>\n<li>登陆百舸平台->进入队列详情->成员管理->配置队列管理员 &#x26; 队列内算法开发成员。</li>\n</ul>\n</li>\n</ul>\n<p>具体操作流程<a href=\"https://cloud.baidu.com/doc/AIHC/s/Rm5zi945p#%E7%99%BE%E8%88%B8%E7%9A%84-rbac-%E6%8E%88%E6%9D%83%EF%BC%88%E8%B5%84%E6%BA%90%E6%B1%A0%E8%B5%84%E6%BA%90%E9%98%9F%E5%88%97%E7%BA%A7%E5%88%AB%EF%BC%89\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">详情见文档</a></p>","fields":{"slug":"Cmotjbzvi","title":"配置预置RBAC权限策略","date":"2026-05-06","extractedHeadings":[]},"headings":[{"value":"声明","depth":2},{"value":"授权说明","depth":2},{"value":"前提条件","depth":2},{"value":"权限说明","depth":2},{"value":"配置IAM用户的RBAC授权","depth":2}]}},"pageContext":{"isCreatedByStatefulCreatePages":false,"slug":"Cmotjbzvi","prev":{"id":"7motign9d","name":"配置IAM预置权限策略","path":"7motign9d","filePath":"操作指南/权限管理/配置IAM预置权限策略.md","seo":null,"parentIds":["ilib2qygp","Cm5zi8b8e"],"parents":[{"id":"ilib2qygp","documentId":"bfa43a8b-968a-41a1-8c9d-906507eeaed9","name":"操作指南","repoName":"AIHC","filePath":"操作指南","disabled":false,"path":"ilib2qygp","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":null},{"id":"Cm5zi8b8e","documentId":"e67d1395-2f3c-4efe-b715-0fb196dced68","name":"权限管理","repoName":"AIHC","filePath":"操作指南/权限管理","disabled":false,"path":"Cm5zi8b8e","lastMergeTime":"2025-01-16 23:47:39","isApiDoc":null,"httpMethod":null,"seo":{"title":null,"keywords":null,"description":null,"serviceType":null},"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":null}]},"next":{"id":"Emmk9ygy0","name":"预留实例劵","path":"Emmk9ygy0","filePath":"操作指南/预留实例劵/预留实例券概述.md","seo":{"title":"","keywords":"","description":"","serviceType":null},"parentIds":["ilib2qygp","Mmmk9w93m"],"parents":[{"id":"ilib2qygp","documentId":"bfa43a8b-968a-41a1-8c9d-906507eeaed9","name":"操作指南","repoName":"AIHC","filePath":"操作指南","disabled":false,"path":"ilib2qygp","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":null},{"id":"Mmmk9w93m","documentId":"01fd593b-24ce-46fb-941c-b26a7f40edd5","name":"预留实例劵","repoName":"AIHC","filePath":"操作指南/预留实例劵","disabled":false,"path":"Mmmk9w93m","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":""}]},"parents":[{"id":"ilib2qygp","documentId":"bfa43a8b-968a-41a1-8c9d-906507eeaed9","name":"操作指南","repoName":"AIHC","filePath":"操作指南","disabled":false,"path":"ilib2qygp","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":null},{"id":"Cm5zi8b8e","documentId":"e67d1395-2f3c-4efe-b715-0fb196dced68","name":"权限管理","repoName":"AIHC","filePath":"操作指南/权限管理","disabled":false,"path":"Cm5zi8b8e","lastMergeTime":"2025-01-16 23:47:39","isApiDoc":null,"httpMethod":null,"seo":{"title":null,"keywords":null,"description":null,"serviceType":null},"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":null}],"specificSeo":null}}}