service overview - huawei cloud€¦ · (evs), object storage service (obs), virtual private cloud...

26
Scalable File Service Service Overview Issue 04 Date 2020-08-07 HUAWEI TECHNOLOGIES CO., LTD.

Upload: others

Post on 05-Oct-2020

6 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Scalable File Service

Service Overview

Issue 04

Date 2020-08-07

HUAWEI TECHNOLOGIES CO., LTD.

Page 2: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Copyright © Huawei Technologies Co., Ltd. 2020. All rights reserved.

No part of this document may be reproduced or transmitted in any form or by any means without priorwritten consent of Huawei Technologies Co., Ltd. Trademarks and Permissions

and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.All other trademarks and trade names mentioned in this document are the property of their respectiveholders. NoticeThe purchased products, services and features are stipulated by the contract made between Huawei andthe customer. All or part of the products, services and features described in this document may not bewithin the purchase scope or the usage scope. Unless otherwise specified in the contract, all statements,information, and recommendations in this document are provided "AS IS" without warranties, guaranteesor representations of any kind, either express or implied.

The information in this document is subject to change without notice. Every effort has been made in thepreparation of this document to ensure accuracy of the contents, but all statements, information, andrecommendations in this document do not constitute a warranty of any kind, express or implied.

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. i

Page 3: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Contents

1 SFS............................................................................................................................................... 1

2 Region and AZ.......................................................................................................................... 3

3 Application Scenarios............................................................................................................. 5

4 File System Types.................................................................................................................... 7

5 Related Services....................................................................................................................... 9

6 Basic Concepts........................................................................................................................11

7 Restrictions and Limitations...............................................................................................12

8 Billing....................................................................................................................................... 14

9 Permissions Management................................................................................................... 17

10 Supported Operating Systems......................................................................................... 22

11 Change History.................................................................................................................... 23

Scalable File ServiceService Overview Contents

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. ii

Page 4: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

1 SFS

What Is SFS?

Scalable File Service (SFS) provides scalable, high-performance file storage. Withthe service, shared file access can be achieved among multiple Elastic CloudServers (ECSs), Bare Metal Servers (BMSs), and containers created on CloudContainer Engine (CCE). See Figure 1-1.

Figure 1-1 Accessing SFS

Compared with traditional file sharing storage, SFS has the following advantages:● File sharing

Scalable File ServiceService Overview 1 SFS

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 1

Page 5: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

ECSs in multiple availability zones (AZs) of a same region can access thesame file system concurrently and share files.

● Elastic scalingStorage can be scaled up or down on demand to dynamically adapt to servicechanges without interrupting applications. You can complete resizing with afew clicks.

● Superior performance and reliabilityThe service enables file system performance to increase as capacity grows,and delivers a high data durability to support rapid service growth.

● Seamless integrationSFS supports Network File System (NFS). With this standard protocol, a broadrange of mainstream applications can read and write data in the file system.

● Easy operation and low costsIn an intuitive graphical user interface (GUI), you can create and manage filesystems with ease. SFS slashes the cost as it is charged on a pay-per-use basis.

Accessing SFSYou can access SFS on the management console or through APIs by sendingHTTPS requests.

● APIsCall APIs if you need to integrate SFS on the cloud service platform into athird-party system for secondary development. For detailed operations, seeScalable File Service API Reference.

● Management consoleYou can access SFS on the management console.

Scalable File ServiceService Overview 1 SFS

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 2

Page 6: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

2 Region and AZ

Concept

A region and availability zone (AZ) identify the location of a data center. You cancreate resources in a specific region and AZ.

● Regions are divided based on geographical location and network latency.Public services, such as Elastic Cloud Server (ECS), Elastic Volume Service(EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP(EIP), and Image Management Service (IMS), are shared within the sameregion. Regions are classified into universal regions and dedicated regions. Auniversal region provides universal cloud services for common tenants. Adedicated region provides specific services for specific tenants.

● An AZ contains one or more physical data centers. Each AZ has independentcooling, fire extinguishing, moisture-proof, and electricity facilities. Within anAZ, computing, network, storage, and other resources are logically dividedinto multiple clusters. AZs within a region are interconnected using high-speed optical fibers to support cross-AZ high-availability systems.

Figure 2-1 shows the relationship between regions and AZs.

Figure 2-1 Regions and AZs

HUAWEI CLOUD provides services in many regions around the world. Select aregion and AZ based on requirements. For more information, see HUAWEI CLOUDGlobal Regions.

Scalable File ServiceService Overview 2 Region and AZ

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 3

Page 7: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Selecting a RegionWhen selecting a region, consider the following factors:

● LocationIt is recommended that you select the closest region for low network latencyand quick access. Regions within the Chinese mainland provide the sameinfrastructure, BGP network quality, as well as resource operations andconfigurations. Therefore, if your target users are on the Chinese mainland,you do not need to consider the network latency differences when selecting aregion.– If your target users are in Asia Pacific (excluding the Chinese mainland),

select the AP-Hong Kong, AP-Bangkok, or AP-Singapore region.– If your target users are in Africa, select the AF-Johannesburg region.– If your target users are in Europe, select the EU-Paris region.– If your target users are in Latin America, select the LA-Santiago region.

NO TE

The LA-Santiago region is located in Chile.

● Resource priceResource prices may vary in different regions. For details, see Product PricingDetails.

Selecting an AZWhen deploying resources, consider your applications' requirements on disasterrecovery (DR) and network latency.

● For high DR capability, deploy resources in different AZs within the sameregion.

● For low network latency, deploy resources in the same AZ.

Regions and EndpointsBefore you use an API to call resources, specify its region and endpoint. For moredetails, see Regions and Endpoints.

Scalable File ServiceService Overview 2 Region and AZ

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 4

Page 8: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

3 Application Scenarios

SFS Capacity-Oriented

Expandable to petabytes, SFS Capacity-Oriented provides fully hosted shared filestorage. It features high availability and durability, and seamlessly handles data-intensive and bandwidth-intensive applications. It is suitable for multiple scenarios,including high-performance computing (HPC), media processing, file sharing, aswell as content management and web services.

● HPCIn industries that require HPC, such as simulation experiments, biopharmacy,gene sequencing, image processing, and weather forecast, SFS providessuperb compute and storage capabilities, as well as high bandwidth and lowlatency.

● Media processingServices of TV stations and new media are more likely to be deployed oncloud platforms than before. Such services include streaming media, archiving,editing, transcoding, content distribution, and video on demand (VoD). Insuch scenarios, a large number of workstations are involved in the wholeprogram production process. Different operating systems may be used bydifferent workstations, requiring file systems to share materials. In addition,HD/4K videos have become a major trend in the broadcasting and TVindustry. Taking video editing as an example, to improve audiences'audiovisual experience, HD editing is being transformed to 30- to 40-layerediting. Therefore, a single editing client may require a file system with abandwidth up to hundreds of MB per second. Usually, producing a single TVprogram needs several editing clients to process a lot of video materialsconcurrently. To meet such requirement, SFS provides customers with stable,bandwidth-intensive, and latency-sensitive performance.

● File sharingFor an organization with a large number of staff, SFS can create shared filesystems that are accessible to all staff, to facilitate file sharing among staff.

● Content management and web serviceSFS can be used in various content management systems to store and provideinformation for websites, home directories, online releases, and archiving.

● Big data and analytic applications

Scalable File ServiceService Overview 3 Application Scenarios

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 5

Page 9: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

SFS delivers an aggregate bandwidth of over 10 GB/s, capable of handlingultra-large data files such as satellite images. In addition, SFS has robustreliability to prevent service interruptions due to system failures.

SFS TurboExpandable to 320 TB, SFS Turbo provides a fully hosted shared file storage. Itfeatures high availability and durability to support massive small files andapplications requiring low latency and high IOPS. SFS Turbo is perfect to scenariossuch as high-performance websites, log storage, compression and decompression,DevOps, enterprise offices, and container applications.

● High-performance websitesFor I/O-intensive website services, SFS Turbo can provide shared websitesource code directories for multiple web servers, enabling low-latency andhigh-IOPS concurrent share access.

● Log storageSFS Turbo can provide multiple service nodes for shared log outputdirectories, facilitating log collection and management of distributedapplications.

● DevOpsThe development directory can be shared to multiple VMs or containers,simplifying the configuration process and improving R&D experience.

● Enterprise officesOffice documents of enterprises or organizations can be saved in an SFSTurbo file system for high-performance shared access.

Scalable File ServiceService Overview 3 Application Scenarios

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 6

Page 10: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

4 File System Types

SFS provides two types of file systems: SFS Capacity-Oriented and SFS Turbo. SFSTurbo is classified into SFS Turbo Standard and SFS Turbo Performance.

The following table describes the features, advantages, and application scenariosof these file system types.

Table 4-1 Comparison of file system types

FileSystemType

StorageClass

Feature Advantage ApplicationScenario

SFSCapacity-Oriented

- ● Maximumbandwidth:20 GB/s;maximumIOPS: 10,000

● Latency: 3to 20 ms;maximumcapacity: 4PB

● Withoptimizedfeatures, it issuitable forservices thatrequire largecapacity andhighbandwidth.

Largecapacity,highbandwidth,and lowcost

Cost-sensitiveservices whichrequire large-capacity scalability,such as mediaprocessing, filesharing, HPC, anddata backup

Scalable File ServiceService Overview 4 File System Types

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 7

Page 11: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

FileSystemType

StorageClass

Feature Advantage ApplicationScenario

SFS Turbo SFS TurboStandard

● Maximumbandwidth:150 MB/s;maximumIOPS: 5,000

● Latency: 2to 5 ms;maximumcapacity: 32TB

● It is suitablefor serviceswithmassivesmall filesand servicesthat requirelow latency.

Low latencyand tenantexclusive

Services withmassive small files,such as code storage,log storage, webservices, and virtualdesktop

SFS TurboPerformance

● Maximumbandwidth:350 MB/s;maximumIOPS: 20,000

● Latency: 1to 2 ms;maximumcapacity: 32TB

● Withoptimizedfeatures, it issuitable forservices withmassivesmall filesand servicesthat requirelow latencyand highIOPS.

Lowlatency,high IOPS,and tenantexclusive

Services withmassive small files,random I/O-intensive andlatency-sensitiveservices, such ashigh-performancewebsites, filesharing, and contentmanagement

Scalable File ServiceService Overview 4 File System Types

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 8

Page 12: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

5 Related Services

Table 5-1 lists the relationship between SFS and other cloud services.

Table 5-1 Related services

Function Related Service Reference

A file system and theassociated ECSs mustbelong to the sameproject. File systems aremounted to shared pathsfor data sharing.

Elastic Cloud Server(ECS)

Mounting an NFS FileSystem to ECSs (Linux)

VPC provisions anisolated virtual networkenvironment defined andmanaged by yourself,improving the security ofcloud resources andsimplifying networkdeployment.An ECS cannot access filesystems in a differentVPC. Before using SFS,assign the file systemand the associated ECSsto the same VPC.

Virtual Private Cloud(VPC)

Creating a File System

Scalable File ServiceService Overview 5 Related Services

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 9

Page 13: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Function Related Service Reference

IAM is an enterprise-level self-help cloudresource managementsystem. It provides useridentity managementand access controlfunctions. When anenterprise needs toprovide SFS for multipleusers within theenterprise, the enterpriseadministrator can useIAM to create users andcontrol these users'permissions onenterprise resources.

Identity and AccessManagement (IAM)

PermissionsManagement

Once you havesubscribed to SFS, youcan monitor itsperformance, such as theread bandwidth, writebandwidth, and readwrite bandwidth onCloud Eye, which doesnot require any plug-ins.

Cloud Eye Monitoring

Scalable File ServiceService Overview 5 Related Services

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 10

Page 14: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

6 Basic Concepts

Before you start, understand the following concepts.

● NFSNetwork File System (NFS) is a distributed file system protocol that allowsdifferent computers and operating systems to share data over a network.

● File systemA file system provides users with shared file storage service through NFS. It isused for accessing network files remotely. After a user creates a mount pointon the management console, the file system can be mounted to multiple ECSsand is accessible through the standard POSIX.

● POSIXPortable Operating System Interface (POSIX) is a set of interrelated standardsspecified by Institute of Electrical and Electronics Engineers (IEEE) to definethe application programming interface (API) for software compatible withvariants of the Unix operating system. POSIX is intended to achieve softwareportability at the source code level. That is, a program written for a POSIXcompatible operating system may be compiled and executed on any otherPOSIX operating system.

● DHCPDynamic Host Configuration Protocol (DHCP) is a LAN network protocol. Theserver controls an IP address range, and a client can automatically obtain theIP address and subnet mask allocated by the server when logging in to theserver. By default, DHCP is not automatically installed as a service componentof Windows Server. Manual installation and configuration are required.

● ProjectA project is used to group and isolate OpenStack resources, such as compute,storage, and network resources. A project can be a department or a projectteam. More than one project can be created for an account.

Scalable File ServiceService Overview 6 Basic Concepts

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 11

Page 15: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

7 Restrictions and Limitations

Constraints:

● SFS supports the NFSv3 protocol only. The default export options are rw,no_root_squash, no_all_squash, and sync.

● To obtain better performance, you are advised to use the operating systemslisted in Supported Operating Systems, which have passed the compatibilitytest.

● Currently, SFS does not support replication.● Currently, SFS does not support cross-region access.● A file system cannot be mounted to multiple accounts.

Restrictions on specifications of SFS Capacity-Oriented file systems:

● Currently, NFSv3 protocol is supported (NFSv4 is not supported).● A maximum of 10,000 compute nodes can be mounted to and access a single

file system at the same time.● The maximum capacity of a single file system is 4 PB, and the maximum

capacity of a single file is 240 TB.● Multiple VPCs are supported. You can add a maximum of 20 VPCs for each

file system. A maximum of 400 ACL rules for added VPCs can be created.

Restrictions on specifications of SFS Turbo file systems:

● SFS Turbo supports access on the Internet. It can be used off the cloud(through the VPN, private line, or other methods).

● You are not advised to mount SFS Turbo file systems to ECSs runningWindows.

● Only the NFSv3 protocol is supported (NFSv4 is not supported).● A maximum of 500 compute nodes can be mounted to and access a single

file system at the same time.● The maximum capacity of a single file system is 320 TB, and the maximum

capacity of a single file is 16 TB.● A maximum of 100 million files are supported in a single file system.● By default, a single directory contains a maximum of 2 million files.

Scalable File ServiceService Overview 7 Restrictions and Limitations

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 12

Page 16: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

● The maximum full path is 1024 bytes, and the maximum file name length is255 bytes.

● The maximum soft link length is 1024 bytes.● The maximum number of hard links is 255.● The maximum directory depth is 100 layers.

Scalable File ServiceService Overview 7 Restrictions and Limitations

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 13

Page 17: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

8 Billing

Billing Items of SFS Capacity-OrientedThe default billing mode is pay-per-use. With this billing mode, creating filesystems is free of charge and your service account is only billed for the amount oftime (hours) resources used for. There is no minimum billing threshold. A durationof less than one hour is rounded up to an hour. For details about SFS billing, seeTable 8-1.

Table 8-1 SFS billing

Category Billing Item Billing Formula Description

Storage space Storage spaceoccupied by thefile system andusage duration

Fees = Price of each GBper hour x Storagespace used x Hours ofuse

With tiered pricing,you pay even lessper GB by usinglonger or more.

NO TE

The price is calculated based on the amount of resources you use and the pricing basis. Theprice is accurate to two decimal places.

Billing Items of SFS TurboThe default billing mode is pay-per-use. With this billing mode, your serviceaccount is billed based on the storage capacity that you select (instead of the usedcapacity) and the amount of time that you use the capacity. Usage duration iscalculated at the top of every hour. A duration of less than one hour is rounded upto an hour. For details about SFS Turbo billing, see Table 8-2.

Table 8-2 SFS Turbo billing

Category Billing Item

SFS Turbo Storage space

Scalable File ServiceService Overview 8 Billing

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 14

Page 18: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Billing ModesSFS provides two billing modes: pay-per-use and yearly/monthly. For details abouthow to purchase SFS, see How Do I Purchase SFS?

For details about the billing, see Product Pricing Details.

In addition, you can use the Price Calculator to quickly calculate an estimatedprice for the resources that you select.

Changing Billing Mode● Yearly/monthly is a prepaid billing mode. You will be billed based on the

subscription duration you specify. This mode provides a favorable price and isideal when the resource use duration is predictable.

● Pay-per-use is a postpaid billing mode. You will be billed based on the billingitems of specific file systems and can purchase or delete file systems at anytime. Fees are deducted from the account balance.

SFS Capacity-Oriented file systems support the change from pay-per-use billing toyearly/monthly billing while SFS Turbo file systems do not. For details, see Yearly/Monthly Subscription. Currently, the billing mode cannot be changed fromyearly/monthly to pay-per-use.

The purchased SFS resource packages cannot be viewed on SFS Console. Fordetails about how to view the resource packages, see How Do I View the Usageof a Resource Package? The capacity of the resource packages is preferentiallyused when you use the file systems.

RenewalFor more information about renewal, including auto-renewal, exporting therenewal list, and changing subscriptions, see Renewal Management.

ExpirationAfter a yearly/monthly file system expires, you will be billed for subsequently usedresources on a pay-per-use basis. If your account is in arrears, you need to pay offthe arrears in a timely manner. For details about how to repay the arrears, seeRepaying Arrears. If you do not pay off the arrears in a timely manner, thesystem processes the resource based on the Service Suspension and ResourceRelease. If the resource package is not renewed before the retention periodexpires, the system automatically deletes the resource.

Overdue PaymentPossible causes of overdue payment:

● You have purchased an SFS Capacity-Oriented resource package, but theusage of the SFS Capacity-Oriented file system exceeds the quota of theresource package. In addition, your account balance is insufficient to deductthe pay-per-use fees generated when the quota is exceeded.

● You have purchased an SFS Capacity-Oriented resource package but created apay-per-use SFS Turbo file system. In addition, your account balance isinsufficient to deduct the generated pay-per-use fees.

Scalable File ServiceService Overview 8 Billing

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 15

Page 19: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

● You have purchased a yearly/monthly SFS Turbo file system but created apay-per-use SFS Capacity-Oriented file system. In addition, your accountbalance is insufficient to deduct the generated pay-per-use fees.

● You have not purchased any SFS Capacity-Oriented resource package andyour account balance is insufficient after you create a pay-per-use SFSCapacity-Oriented file system.

● You have created a pay-per-use SFS Turbo file system and your accountbalance is insufficient to deduct the generated pay-per-use fees.

Service status and operation restrictions when an account is in arrears:

If an account is in arrears, the retention period varies depending on the customertier. If your account is in the retention period, your file system will be retained butyou cannot continue to use the file system. For details about arrears payment, seeRepaying Arrears. If you do not pay off the outstanding fees within the retentionperiod, your data will be automatically released and cannot be restored.

For details about the retention period, see Retention Period.

Scalable File ServiceService Overview 8 Billing

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 16

Page 20: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

9 Permissions Management

If you need to assign different permissions to employees in your enterprise toaccess your SFS resources on , Identity and Access Management (IAM) is a goodchoice for fine-grained permissions management. IAM provides identityauthentication, permissions management, and access control, helping you secureaccess to your resources.

With IAM, you can use your account to create IAM users, and assign permissionsto the users to control their access to specific resources. For example, somesoftware developers in your enterprise need to use SFS resources but should notbe allowed to delete the resources or perform any other high-risk operations. Inthis scenario, you can create IAM users for the software developers and grantthem only the permissions required for using SFS resources.

If your account does not require individual IAM users for permissionsmanagement, skip this section.

IAM can be used free of charge. You pay only for the resources in your account.For more information about IAM, see IAM Service Overview.

SFS Permissions

By default, new IAM users do not have permissions assigned. You need to add auser to one or more groups, and attach permissions policies or roles to thesegroups. Users inherit permissions from the groups to which they are added andcan perform specified operations on cloud services based on the permissions.

SFS is a project-level service deployed and accessed in specific physical regions. Toassign SFS permissions to a user group, specify the scope as region-specificprojects and select projects for the permissions to take effect. If All projects isselected, the permissions will take effect for the user group in all region-specificprojects. When accessing SFS, the users need to switch to a region where theyhave been authorized to use this service.

You can grant users permissions by using roles and policies.

● Roles: A type of coarse-grained authorization mechanism that definespermissions related to user responsibilities. This mechanism provides only alimited number of service-level roles for authorization. When using roles togrant permissions, you need to also assign other roles on which the

Scalable File ServiceService Overview 9 Permissions Management

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 17

Page 21: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

permissions depend to take effect. However, roles are not an ideal choice forfine-grained authorization and secure access control.

● Policies: A type of fine-grained authorization mechanism that definespermissions required to perform operations on specific cloud resources undercertain conditions. This mechanism allows for more flexible policy-basedauthorization, meeting requirements for secure access control. For example,you can grant ECS users only the permissions for managing a certain type ofECSs. Most policies define permissions based on APIs. For the API actionssupported by SFS, see Permissions Policies and Supported Actions.

Table 9-1 lists all the system-defined roles and policies supported by SFS.

Table 9-1 System permissions for SFS Capacity-Oriented

Role/PolicyName

Description Type Dependency

SFS FullAccess Administratorpermissions forSFS. Usersgranted thesepermissions canperform alloperations on filesystems.

System-definedpolicy

None

SFSReadOnlyAccess

Read-onlypermissions. Usersgranted thesepermissions canonly view filesystem data.

System-definedpolicy

None

Scalable File ServiceService Overview 9 Permissions Management

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 18

Page 22: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Role/PolicyName

Description Type Dependency

SFS Administrator Permissionsinclude:● Creating,

deleting,querying, andmodifying filesystems

● Adding,modifying, anddeleting accessrules of filesystems

● Creating,querying, anddeleting filesystem tags

● Expanding andshrinking thecapacity of afile system

● Queryingavailabilityzones

● Read-onlypermissions onall cloudservices if theTenant Guestpolicy isassigned

System-definedrole

Tenant Guest roleneeds to beassigned in thesame project.

Table 9-2 lists all the system-defined roles and policies supported by SFS Turbo.

Scalable File ServiceService Overview 9 Permissions Management

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 19

Page 23: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Table 9-2 System-defined roles and policies supported by SFS Turbo

Role/PolicyName

Description Type Dependency

SFS TurboFullAccess

Administratorpermissions forSFS Turbo. Usersgranted thesepermissions canperform alloperations on SFSTurbo filesystems.

System-definedpolicy

None

SFS TurboReadOnlyAccess

Read-onlypermissions forSFS Turbo. Usersgranted thesepermissions canonly view SFSTurbo file systemdata.

System-definedpolicy

None

Table 9-3 lists the common operations supported by each system-defined policyor role of SFS. Select the policies or roles as required.

Table 9-3 Common operations supported by each system-defined policy or role ofSFS

Operation SFS FullAccess SFSReadOnlyAccess

SFSAdministrator

Creating a filesystem

√ x √

Querying a filesystem

√ √ √

Modifying a filesystem

√ x √

Deleting a filesystem

√ x √

Adding an accessrule of a filesystem(Adding a VPC oradding anauthorized addressto a file system)

√ x √

Scalable File ServiceService Overview 9 Permissions Management

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 20

Page 24: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

Operation SFS FullAccess SFSReadOnlyAccess

SFSAdministrator

Modifying anaccess rule of a filesystem (Modifyingthe VPC orauthorized addressof a file system).

√ x √

Deleting an accessrule of a filesystem (Deletingthe VPC orauthorized addressof a file system).

√ x √

Expanding thecapacity of a filesystem

√ x √

Shrinking thecapacity of a filesystem

√ x √

Creating filesystem tags

√ x √

Querying filesystem tags

√ √ √

Deleting filesystem tags

√ x √

Queryingavailability zones

√ √ √

Helpful Links● IAM Service Overview● Creating a User and Granting SFS Permissions● Permissions Policies and Supported Actions

Scalable File ServiceService Overview 9 Permissions Management

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 21

Page 25: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

10 Supported Operating Systems

Table 10-1 lists the operating systems that have passed the compatibility test.

Table 10-1 Supported operating systems

Type Version

CentOS CentOS 5, 6, and 7 for x86

Debian Debian GNU/Linux 6, 7, 8, and 9 for x86

Oracle Oracle Enterprise Linux 5, 6, and 7 for x86

Red Hat Red Hat Enterprise Linux 5, 6, and 7 for x86

SUSE SUSE Linux Enterprise Server 10, 11, and 12 for x86

Ubuntu Ubuntu 10, 11, 12, 13, 14, and 15 LTS for x86

Euler Euler OS 2

Fedora Fedora 24 and 25

OpenSUSE OpenSUSE 42

Scalable File ServiceService Overview 10 Supported Operating Systems

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 22

Page 26: Service Overview - HUAWEI CLOUD€¦ · (EVS), Object Storage Service (OBS), Virtual Private Cloud (VPC), Elastic IP (EIP), and Image Management Service (IMS), are shared within the

11 Change History

ReleaseDate

What's New

2020-08-07 This issue is the fourth official release.Updated the following content:Added the description of arrears in section "Billing."

2019-05-30 This issue is the third official release.Updated the following content:● Added the description of the SFS Turbo file system.● Added section "Regions and AZs."● Updated section "Limitations and Constraints."

2019-02-15 This issue is the second official release.Updated the following content:● Optimized the "Related Services" section.● Adjusted the structure of the document.● Merged section "Permissions" into section "Accessing SFS."● Deleted section "Pricing."

2018-11-15 This issue is the first official release.

Scalable File ServiceService Overview 11 Change History

Issue 04 (2020-08-07) Copyright © Huawei Technologies Co., Ltd. 23