Access Control

2024-11-07 06:47:33

Configuring Access Credentials

Overview

Before pulling private images or uploading images, you need to use docker login to enter your username / password as access credentials. The Cloud Container Repository supports resetting the password for your access credentials.

Reset Password

1.      Access the Cloud Container Repository console.

2.      Click on the name of the activated Enterprise Edition instance.

3.      In the left navigation pane, select Instance Management - Access Credentials to go to the Access Credentials page.

4.      Click the Reset Password button on the page.

5.      Enter the new password and click Set to complete the password reset process.

Configuring Internet Trustlist

To ensure the security of the image artifacts and the Enterprise Edition instances, it is necessary to configure an Internet access control policy to restrict access to the Enterprise Edition instances via the Internet.

Before You Begin

This feature can only be used with an Enterprise Edition instance and is not supported for Personal Edition instances.

Note: Upon activating an Enterprise Edition instance, a default "127.0.0.1/32" Internet trustlist is created to restrict all access from the Internet.

Procedure

1.      Log in to the Container Image Console;

2.      On the top menu bar, select the resource pool required.

3.      In the instance page, select the specified Enterprise Edition instance.

4.      On the left menu of the Enterprise Edition instance management page, select " Instance Management " > " Access Control ". Then, click the " Add Trustlist for Public Network Access " button on the upper-left corner of the interface.

5.      In the pop-up " Add Trustlist for Public Network Access " tab, enter the address segment and notes, then click the Confirm button.

After adding, hosts with IPs included in the trustlist CIDR block can access the instance normally.

Note: After all trustlists are deleted, nodes on the Internet can access the Enterprise Edition instance using credentials. Please be aware that an Enterprise Edition instance fully exposed to the Internet is at risk of being attacked. Proceed with caution.


4Rc9macyO7ip