Skip to main content
此產品有較新版本可以使用。
本繁體中文版使用機器翻譯,譯文僅供參考,若與英文版本牴觸,應以英文版本為準。

以最低權限建立SVM角色

貢獻者

在這個功能中為新的SVM使用者建立角色時、您必須執行幾ONTAP 個SfCLI命令ONTAP 。如果您將SVM設定ONTAP 為搭配SnapCenter 使用、但不想使用vsadmin角色、則需要此角色。

步驟

  1. 在儲存系統上、建立角色並將所有權限指派給該角色。

    security login role create –vserver <svm_name\>- role <SVM_Role_Name\> -cmddirname <permission\>

    註 您應該針對每個權限重複此命令。
  2. 建立使用者並將角色指派給該使用者。

    security login create -user <user_name\> -vserver <svm_name\> -application ontapi -authmethod password -role <SVM_Role_Name\>

  3. 解除鎖定使用者。

    security login unlock -user <user_name\> -vserver <svm_name\>

用於建立SVM角色和指派權限的CLI命令ONTAP

您應該執行幾ONTAP 個SVM命令來建立SVM角色並指派權限。

註 從 SnapCenter 5.0 開始、只有 REST API 支援 vserver 管理使用者。如果您想要使用非 vserver admin 建立角色、請使用 ZAPI 。
  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "snapmirror list-destinations" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "event generate-autosupport-log" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "job history show" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "job stop" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "lun" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun igroup add" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun igroup create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun igroup delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun igroup rename" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun igroup show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun mapping add-reporting-nodes" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "lun mapping create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun mapping delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun mapping remove-reporting-nodes" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun mapping show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun modify" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun move-in-volume" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun offline" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun online" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun resize" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun serial" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "lun show" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "network interface" -access readonly

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror policy add-rule" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror policy modify-rule" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror policy remove-rule" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror policy show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror restore" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror show" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "snapmirror show-history" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror update" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "snapmirror update-ls-set" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "version" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume clone create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume clone show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume clone split start" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume clone split stop" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume destroy" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume file clone create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume file show-disk-usage" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume modify" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume offline" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume online" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume qtree create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume qtree delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume qtree modify" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume qtree show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume restrict" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot modify" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot rename" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot restore" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot restore-file" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume snapshot show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume unmount" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver cifs share create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver cifs share delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver cifs share show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver cifs show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver export-policy create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver export-policy delete" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver export-policy rule create" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver export-policy rule show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver export-policy show" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "vserver iscsi connection show" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver" -access readonly

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver export-policy" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "vserver iscsi" -access all

  • security login role create -vserver SVM_Name -role SVM_Role_Name -cmddirname "volume clone split status" -access all

  • security login role create -vserver SVM_name -role SVM_Role_Name -cmddirname "volume managed-feature" -access all