首页 VMware服务 访问控制 VMware服务关联角色

VMware服务关联角色

本文为您介绍VMware服务关联角色(AliyunServiceRoleForACVS)的应用场景以及如何删除服务关联角色。

背景信息

VMware服务关联角色(AliyunServiceRoleForACVS)是在某些情况下,为了完成VMware服务自身的某个功能,需要获取其他云服务的访问权限,而提供的RAM角色。更多关于服务关联角色的信息请参见服务关联角色

应用场景

VMware服务的创建专属VMware环境功能需要访问云服务器ECS、专有网络VPC、云企业网CEN、资源编排云服务的资源时,通过服务关联角色功能获取访问权限。

AliyunServiceRoleForACVS介绍

角色名称:AliyunServiceRoleForACVS

角色权限策略:AliyunServiceRolePolicyForACVS

权限说明:

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "vpc:DescribeVpcs",
                "vpc:DescribeVSwitches",
                "vpc:CreateVSwitch",
                "vpc:DeleteVSwitch",
                "vpc:ConfirmPhysicalConnection",
                "vpc:CreateVirtualBorderRouter",
                "vpc:DeleteVirtualBorderRouter",
                "vpc:DescribeVirtualBorderRouters",
                "vpc:CreateBgpGroup",
                "vpc:DeleteBgpGroup",
                "vpc:DescribeBgpGroups",
                "vpc:CreateBgpPeer",
                "vpc:DeleteBgpPeer",
                "vpc:DescribeBgpPeers",
                "vpc:CreateRouteEntry",
                "vpc:DeleteRouteEntry",
                "vpc:DescribeRouteTables",
                "vpc:DescribeVRouters",
                "vpc:DescribeRouteEntryList",
                "vpc:AddBgpNetwork",
                "vpc:DeleteBgpNetwork",
                "vpc:DescribeBgpNetworks",
                "vpc:AssociateEipAddress",
                "vpc:UnassociateEipAddress",
                "vpc:DescribeEipAddresses",
                "vpc:CreateForwardEntry",
                "vpc:DeleteForwardEntry",
                "vpc:DescribeForwardTableEntries",
                "vpc:CreateSnatEntry",
                "vpc:DeleteSnatEntry",
                "vpc:DescribeSnatTableEntries",
                "vpc:DescribeNatGateways",
                "vpc:TerminatePhysicalConnection",
                "vpc:RecoverPhysicalConnection",
                "vpc:DeletePhysicalConnection",
                "vpc:OpenPhysicalConnectionService",
                "vpc:GetPhysicalConnectionServiceStatus",
                "vpc:DescribeGrantRulesToCen",
                "vpc:GrantInstanceToCen",
                "vpc:DescribeRouteTableList"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "cen:ResolveAndRouteServiceInCen",
                "cen:DeleteRouteServiceInCen",
                "cen:DescribeRouteServicesInCen",
                "cen:DescribeCenAttachedChildInstances",
                "cen:AttachCenChildInstance",
                "cen:DetachCenChildInstance",
                "cen:DescribeCenAttachedChildInstanceAttribute",
                "cen:DescribeCens",
                "cen:ListTransitRouters",
                "cen:ListTransitRouterAvailableResource",
                "cen:CreateTransitRouterVpcAttachment",
                "cen:ListTransitRouterVpcAttachments",
                "cen:DeleteTransitRouterVpcAttachment",
                "cen:CreateTransitRouterVbrAttachment",
                "cen:ListTransitRouterVbrAttachments",
                "cen:DeleteTransitRouterVbrAttachment",
                "cen:CreateCenChildInstanceRouteEntryToAttachment",
                "cen:DescribeCenChildInstanceRouteEntries",
                "cen:DeleteCenChildInstanceRouteEntryToAttachment",
                "cen:CreateTransitRouterRouteTable",
                "cen:ListTransitRouterRouteTables",
                "cen:DeleteTransitRouterRouteTable",
                "cen:CreateTransitRouterRouteEntry",
                "cen:ListTransitRouterRouteEntries",
                "cen:DeleteTransitRouterRouteEntry",
                "cen:AssociateTransitRouterAttachmentWithRouteTable",
                "cen:ListTransitRouterRouteTableAssociations",
                "cen:DissociateTransitRouterAttachmentFromRouteTable",
                "cen:EnableTransitRouterRouteTablePropagation",
                "cen:ListTransitRouterRouteTablePropagations",
                "cen:DisableTransitRouterRouteTablePropagation",
                "cen:DescribeGrantRulesToCen"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "bssapi:CreateInstance"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "ecs:CreateSecurityGroup",
                "ecs:DeleteSecurityGroup",
                "ecs:DescribeSecurityGroups",
                "ecs:DescribeSecurityGroupAttribute",
                "ecs:AuthorizeSecurityGroup",
                "ecs:RevokeSecurityGroup",
                "ecs:CreateNetworkInterface",
                "ecs:DeleteNetworkInterface",
                "ecs:DescribeNetworkInterfaces"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "nas:DescribeFileSystems"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "ros:ListStacks",
                "ros:GetStack",
                "ros:ListStackEvents",
                "ros:ListStackResources",
                "ros:GetStackResource",
                "ros:CreateStack",
                "ros:DeleteStack",
                "ros:PreviewStack"
            ],
            "Resource": [
                "*"
            ],
            "Effect": "Allow"
        },
        {
            "Action": "ram:PassRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "acs:Service": [
                        "ros.aliyuncs.com"
                    ]
                }
            }
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "acvs.aliyuncs.com"
                }
            }
        }
    ]
}

删除服务关联角色

如果您需要删除AliyunServiceRoleForACVS(服务关联角色),需要先释放依赖这个服务关联角色的专属VMware环境。

阿里云首页 VMware服务 相关技术圈