This topic describes how to manage AccessKeys in OceanBase Cloud and how to obtain access keys for Alibaba Cloud OSS, AWS S3, and Azure Blob Storage.
OceanBase Cloud allows you to manage AccessKey IDs (AKs) and AccessKey Secrets (SKs). You can use an AccessKey ID and an AccessKey Secret to access the API of OceanBase Cloud with full privileges.
Prerequisites
You have the project owner, project admin, and organization admin permissions.
Procedure
- Log in to the OceanBase Cloud console.
In the left-side navigation pane, click the AccessKey. You can view the AccessKey ID, status, last usage time, and creation time. In the Actions column, you can disable, enable, or delete an AccessKey.
In the upper-right corner of the page, click Create AccessKey. The system randomly generates an AccessKey. Click Copy and properly save your AccessKey ID and AccessKey Secret. You can generate up to two AccessKeys for one account.
You can use an AccessKey ID and an AccessKey Secret to access the API of OceanBase Cloud with full privileges on the account. For more information, refer to Authorization information.
curl --digest -u 'AccessKey ID:AccessKey Secret' \ --request GET \ --url https://api-cloud.oceanbase.com/api/v2/<Open API name> -H 'X-Ob-Project-Id: <Project ID>'Note
- A project ID uniquely identifies a project. For information about how to obtain the project ID of an instance, see Manage projects.
- Make sure that the project ID corresponding to the specified instanceId is consistent with the specified project ID.
On the AccessKey page, you can view the created AccessKeys and disable or delete them.
Prerequisites
- You have the permissions to log in to the Alibaba Cloud console.
- You have the permissions to create an AccessKey in the Alibaba Cloud console.
Procedure
Click Log in to Alibaba Cloud console. Obtain the primary account ID.
Navigate to the AccessKey page of the RAM console. Use an existing AccessKey or create a new AccessKey. Save your AccessKey ID and AccessKey Secret, and fill them into the corresponding OceanBase Cloud console page.
Prerequisites
- You have access to an AWS account.
- You have permission to create an IAM user, or you have access keys for an existing IAM user.
- The IAM user has read and write permissions on the target S3 bucket. We recommend that you grant only the permissions required for the target bucket, following the principle of least privilege.
Reference procedure
The following steps are for reference only. For the latest instructions, see Manage access keys for IAM users in the AWS documentation.
Log in to the AWS Management Console.
Search for IAM in the search bar at the top and open the IAM console.
In the left-side navigation pane, click Users. Select an existing user, or click Create user in the upper-right corner to create a user.
Note
We recommend that you create a dedicated IAM user for OceanBase Cloud log delivery and grant only the permissions required for the target bucket.
On the user details page, click the Security credentials tab.
In the Access keys section, click Create access key.
Select Other or Application running outside AWS as the use case. Click Next, optionally enter a description, and then click Create access key.
AWS generates an Access Key ID and a Secret Access Key. Click Show to view the Secret Access Key, or click Download .csv file to save the credentials. Store the Access Key ID and Secret Access Key securely.
Note
The Secret Access Key is displayed only when it is created. After you close the page, you cannot view it again. Save it securely when you create the access key.
Enter the Access Key ID and Secret Access Key on the corresponding object storage configuration page in OceanBase Cloud.
OceanBase Cloud object storage configurations currently use Shared Key authorization for Azure Blob Storage. SAS tokens are not supported. The Access Key ID corresponds to the storage account name, and the Access Key Secret corresponds to the storage account key.
Prerequisites
- You have access to an Azure account.
- You have created an Azure storage account.
Reference procedure
The following steps are for reference only. For the latest instructions, see Manage storage account access keys in Microsoft Learn.
Log in to the Azure portal.
Search for Storage accounts in the search bar at the top and open the storage account list.
Click the name of the target storage account to open its details page.
In the left-side navigation pane, under Security + networking, click Access keys.
The page displays the storage account name and two keys, key1 and key2. Click Show keys at the top of the page to display the complete key values and connection strings and enable the copy buttons.
Note
Either key1 or key2 can be used for authentication. We recommend that you use one key and reserve the other for key rotation. During rotation, switch to the reserved key before regenerating the original key to avoid service interruption.
Under key1 or key2, locate the Key value and click Copy.
On the corresponding object storage configuration page in OceanBase Cloud, enter the storage account name as the Access Key ID and the copied key as the Access Key Secret.
