Assign a role to KCE

Last updated:2021-05-11 10:41:43

When you activate the Kingsoft Cloud Container Engine (KCE) service, you must assign the default role KsyunKCEDefaultRolePolicy to KCE so that KCE can access related services, such as Server Load Balancing (SLB), Elastic IP (EIP), and Elastic Block Storage (EBS). This ensures normal operation of the KCE service.

Authorization process

  1. Log in to the KCE console.
    If the default role has not been assigned to KCE, the page shown in the following figure appears.


  1. Click Go to IAM for Authorization to assign the role to KCE.
    After you assign the role to KCE, you can perform related operations in the KCE console.


  • You can log in to the Identity and Access Management (IAM) console to view the detailed policy information of the default role.
  • You can go to the Roles page to edit role permissions. Note that wrong configurations may cause KCE to fail to obtain required permissions and result in unavailability of the KCE service.

Permissions of the KsyunKCEDefaultRolePolicy role

The KsyunKCEDefaultRolePolicy role grants the permissions on the following services:

  • SLB
  • EBS
  • EIP
  • Elastic Physical Compute (EPC)
  • Virtual Private Cloud (VPC)
  • Kingsoft Cloud Monitor Service (CMS)

The following table describes the permissions on CMS.

Action Description
Create* Creates monitoring metrics.
Delete* Deletes monitoring metrics.
GetMetricStatistics Obtains monitoring data.

Did you find the above information helpful?

Mostly Unhelpful
A little helpful
Very helpful

What might be the problems?

Unclear or awkward
Redundant or clumsy
Lack of context for the complex system or functionality

More suggestions


Please give us your feedback.


Thank you for your feedback.