YI-MapReduce

Create YI-MapReduce Operation User

2025-07-21 11:02:18

If detailed permission management for your YI-MapReduce service is required, you can use the Identity and Access Management (IAM). This can be achieved by creating IAM sub-users and assigning them different role permissions in the YI-MapReduce console.

If your cloud account meets your requirements and there is no need to create separate IAM users, you can skip this section. It will not affect your use of other YI-MapReduce service functions.

This section guides you through the user authorization process. The procedure is shown as follows.

Procedure

 

1.      Create an IAM sub-user. Go to the User Management page of the YI-MapReduce console. Click on the "?" next to the IAM Sync button. Then, click on Access IAM to enter the IAM user page. Click on Create User in the upper right corner and follow the instructions to create a sub-user.

        

        

2.      Click IAM Sync on the User Management page of the YI-MapReduce console to sync IAM sub-user information with the LDAP User in the YI-MapReduce console and YI-MapReduce Manager.

3.      Add roles on the Role Management page of the YI-MapReduce console. Assign the appropriate menu function permissions to the role.

        

4.      Add users on the User Permission page of the YI-MapReduce console. Assign the appropriate role permissions to the user.

        

5.      Then, IAM sub-users can log in to the YI-MapReduce console, access the authorized cluster, and verify permissions.

²  Description

By default, IAM users created by the administrator do not have any permissions. They need to be assigned role permissions to obtain corresponding cluster permissions. This process is known as authorization. After authorization, users can operate cloud services based on the granted permissions.

IAM User Sync

IAM user synchronization involves syncing the created IAM sub-users into the YI-MapReduce system: one part is syncing IAM user information to the User Management service, including details such as IAM username, email, user status, add time, etc.; another part is syncing IAM users into the LDAP User service in the YI-MapReduce Manager, where LDAP usernames are denoted as "emr_email prefix". However, for the second part, the deployment, configuration, and start-up of the OpenLDAP cluster service under that cluster need to be completed; otherwise, it is not possible to sync into the LDAP User service.

Procedure

1.      Click on the "?" button next to IAM Sync on the User Management page. Then, click Access IAM to go to the Master Account and Member Accounts and Authorization Center in IAM.

        

        

2.      Click on Create User and follow the instructions to create an IAM user.

        

3.      After creation, return to the User Management page in the YI-MapReduce console, click on IAM Sync to sync the IAM user information to the User Management page.

        

        


V36bPgLRUmnH