文档

授权信息

更新时间:
访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍关系型数据库(RDS)为RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。关系型数据库(RDS)的RAM代码(RamCode)为rds,支持的授权粒度为RESOURCE

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是关系型数据库(RDS)定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用背景高亮的方式表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
rds:ActivateMigrationTargetInstanceActivateMigrationTargetInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AddTagsToResourceAddTagsToResourceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AllocateInstancePublicConnectionAllocateInstancePublicConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AllocateReadWriteSplittingConnectionAllocateReadWriteSplittingConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AttachWhitelistTemplateToInstanceAttachWhitelistTemplateToInstanceWrite
全部资源
*
rds:CalculateDBInstanceWeightCalculateDBInstanceWeightRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckAccountNameAvailableCheckAccountNameAvailableRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckCloudResourceAuthorizedCheckCloudResourceAuthorizedRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckCreateDdrDBInstanceCheckCreateDdrDBInstanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CheckDBNameAvailableCheckDBNameAvailableRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckInstanceExistCheckInstanceExistRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckServiceLinkedRoleCheckServiceLinkedRoleRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#dbinstanceId}
rds:CloneDBInstanceCloneDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CloneParameterGroupCloneParameterGroupWrite
全部资源
*
rds:ResourceTag
rds:CopyDatabaseBetweenInstancesCopyDatabaseBetweenInstancesWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CreateAccountCreateAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateBackupCreateBackupWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateCloudMigrationPrecheckTaskCreateCloudMigrationPrecheckTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateCloudMigrationTaskCreateCloudMigrationTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDBInstanceCreateDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDBInstanceEndpointCreateDBInstanceEndpointWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDBInstanceEndpointAddressCreateDBInstanceEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDBInstanceForRebuildCreateDBInstanceForRebuildWrite
全部资源
*
rds:CreateDBNodesCreateDBNodesWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDBProxyEndpointAddressCreateDBProxyEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DBProxyConnectStringNetType
rds:CreateDatabaseCreateDatabaseWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDdrInstanceCreateDdrInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CreateDiagnosticReportCreateDiagnosticReportWrite
全部资源
*
rds:CreateGADInstanceCreateGADInstanceWrite
全部资源
*
rds:CreateGadInstanceMemberCreateGadInstanceMemberWrite
全部资源
*
rds:CreateMigrateTaskCreateMigrateTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateOnlineDatabaseTaskCreateOnlineDatabaseTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateParameterGroupCreateParameterGroupWrite
全部资源
*
rds:CreatePostgresExtensionsCreatePostgresExtensionsWrite
全部资源
*
rds:CreateReadOnlyDBInstanceCreateReadOnlyDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateServiceLinkedRoleCreateServiceLinkedRoleWrite
全部资源
*
rds:CreateTempDBInstanceCreateTempDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteADSettingDeleteADSettingWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:DeleteAccountDeleteAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteBackupDeleteBackupWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteBackupFileDeleteBackupFileWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteDBInstanceDeleteDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteDBInstanceEndpointDeleteDBInstanceEndpointWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteDBInstanceEndpointAddressDeleteDBInstanceEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteDBNodesDeleteDBNodesWrite
DBInstance
acs:rds:{#Region}:{#AccountId}:dbinstance/{#DbInstanceId}
rds:DeleteDBProxyEndpointAddressDeleteDBProxyEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteDatabaseDeleteDatabaseWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteGadInstanceDeleteGadInstanceWrite
全部资源
*
rds:DeleteParameterGroupDeleteParameterGroupWrite
全部资源
*
rds:DeletePostgresExtensionsDeletePostgresExtensionsWrite
全部资源
*
rds:DeleteSlotDeleteSlotWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteUserBackupFileDeleteUserBackupFileWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:DescibeImportsFromDatabaseDescibeImportsFromDatabaseList
全部资源
*
rds:DescribeADInfoDescribeADInfoRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeAccountsDescribeAccountsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeActionEventPolicyDescribeActionEventPolicyRead
全部资源
*
rds:DescribeActiveOperationTasksDescribeActiveOperationTasksRead
全部资源
*
rds:DescribeAllWhitelistTemplateDescribeAllWhitelistTemplateRead
全部资源
*
rds:DescribeAnalyticdbByPrimaryDBInstanceDescribeAnalyticdbByPrimaryDBInstanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeAvailableClassesDescribeAvailableClassesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeAvailableCrossRegionDescribeAvailableCrossRegionRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeAvailableMetricsDescribeAvailableMetricsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeAvailableRecoveryTimeDescribeAvailableRecoveryTimeRead
全部资源
*
rds:DescribeBackupDatabaseDescribeBackupDatabaseRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeBackupPolicyDescribeBackupPolicyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeBackupTasksDescribeBackupTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeBackupsDescribeBackupsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeBinlogFilesDescribeBinlogFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeCloudMigrationPrecheckResultDescribeCloudMigrationPrecheckResultRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeCloudMigrationResultDescribeCloudMigrationResultRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeCrossBackupMetaListDescribeCrossBackupMetaListRead
全部资源
*
rds:DescribeCrossRegionBackupDBInstanceDescribeCrossRegionBackupDBInstanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeCrossRegionBackupsDescribeCrossRegionBackupsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeCrossRegionLogBackupFilesDescribeCrossRegionLogBackupFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceAttributeDescribeDBInstanceAttributeRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeDBInstanceByTagsDescribeDBInstanceByTagsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeDBInstanceDetailDescribeDBInstanceDetailRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeDBInstanceEncryptionKeyDescribeDBInstanceEncryptionKeyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceEndpointsDescribeDBInstanceEndpointsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceHAConfigDescribeDBInstanceHAConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceIPArrayListDescribeDBInstanceIPArrayListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceIpHostnameDescribeDBInstanceIpHostnameRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceMetricsDescribeDBInstanceMetricsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceMonitorDescribeDBInstanceMonitorRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceNetInfoDescribeDBInstanceNetInfoRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceNetInfoForChannelDescribeDBInstanceNetInfoForChannelRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancePerformanceDescribeDBInstancePerformanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceProxyConfigurationDescribeDBInstanceProxyConfigurationRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceSSLDescribeDBInstanceSSLRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceTDEDescribeDBInstanceTDERead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesDescribeDBInstancesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesAsCsvDescribeDBInstancesAsCsvRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesByExpireTimeDescribeDBInstancesByExpireTimeRead
全部资源
*
rds:ResourceTag
rds:DescribeDBInstancesByPerformanceDescribeDBInstancesByPerformanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeDBInstancesForCloneDescribeDBInstancesForCloneRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:DescribeDBMiniEngineVersionsDescribeDBMiniEngineVersionsRead
DBInstance
acs:rds:{#Region}:{#AccountId}:dbinstance/{#DbInstanceId}
rds:DescribeDBProxyDescribeDBProxyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBProxyEndpointDescribeDBProxyEndpointRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBProxyPerformanceDescribeDBProxyPerformanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDTCSecurityIpHostsForSQLServerDescribeDTCSecurityIpHostsForSQLServerRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDatabasesDescribeDatabasesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDedicatedHostGroupsDescribeDedicatedHostGroupsRead
全部资源
*
rds:DescribeDetachedBackupsDescribeDetachedBackupsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeErrorLogsDescribeErrorLogsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeEventsDescribeEventsRead
全部资源
*
rds:DescribeGadInstancesDescribeGadInstancesRead
全部资源
*
rds:DescribeHADiagnoseConfigDescribeHADiagnoseConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeHASwitchConfigDescribeHASwitchConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeHistoryTasksDescribeHistoryTasksRead
全部资源
*
rds:DescribeHostWebShellDescribeHostWebShellRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeInstanceAutoRenewalAttributeDescribeInstanceAutoRenewalAttributeRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeInstanceCrossBackupPolicyDescribeInstanceCrossBackupPolicyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeInstanceKeywordsDescribeInstanceKeywordsRead
全部资源
*
rds:DescribeInstanceLinkedWhitelistTemplateDescribeInstanceLinkedWhitelistTemplateRead
全部资源
*
rds:DescribeLocalAvailableRecoveryTimeDescribeLocalAvailableRecoveryTimeRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeLogBackupFilesDescribeLogBackupFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeMetaListDescribeMetaListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeMigrateTaskByIdDescribeMigrateTaskByIdRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeMigrateTasksDescribeMigrateTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeModifyPGHbaConfigLogDescribeModifyPGHbaConfigLogRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeModifyParameterLogDescribeModifyParameterLogRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeOssDownloadsDescribeOssDownloadsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribePGHbaConfigDescribePGHbaConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeParameterGroupDescribeParameterGroupRead
全部资源
*
rds:DescribeParameterGroupsDescribeParameterGroupsRead
全部资源
*
rds:DescribeParametersDescribeParametersRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribePostgresExtensionsDescribePostgresExtensionsRead
全部资源
*
rds:DescribeRdsResourceSettingsDescribeRdsResourceSettingsRead
全部资源
*
rds:DescribeReadDBInstanceDelayDescribeReadDBInstanceDelayRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeResourceUsageDescribeResourceUsageRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLCollectorPolicyDescribeSQLCollectorPolicyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLCollectorRetentionDescribeSQLCollectorRetentionRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeSQLLogFilesDescribeSQLLogFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLLogRecordsDescribeSQLLogRecordsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLLogReportListDescribeSQLLogReportListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSecurityGroupConfigurationDescribeSecurityGroupConfigurationRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSlotsDescribeSlotsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeSlowLogRecordsDescribeSlowLogRecordsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSlowLogsDescribeSlowLogsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSupportOnlineResizeDiskDescribeSupportOnlineResizeDiskRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:DescribeTagsDescribeTagsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeTasksDescribeTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeUpgradeMajorVersionPrecheckTaskDescribeUpgradeMajorVersionPrecheckTaskRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeUpgradeMajorVersionTasksDescribeUpgradeMajorVersionTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeWhitelistTemplateDescribeWhitelistTemplateRead
全部资源
*
rds:DescribeWhitelistTemplateLinkedInstanceDescribeWhitelistTemplateLinkedInstanceRead
全部资源
*
rds:DestroyDBInstanceDestroyDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DetachGadInstanceMemberDetachGadInstanceMemberWrite
全部资源
*
rds:DetachWhitelistTemplateToInstanceDetachWhitelistTemplateToInstanceWrite
全部资源
*
rds:GetDBInstanceTopologyGetDBInstanceTopologyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:GetDbProxyInstanceSslGetDbProxyInstanceSslRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:GrantAccountPrivilegeGrantAccountPrivilegeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:GrantOperatorPermissionGrantOperatorPermissionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ImportUserBackupFileImportUserBackupFileWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:ListTagResourcesListTagResourcesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:LockAccountLockAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:MigrateConnectionToOtherZoneMigrateConnectionToOtherZoneWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:MigrateDBInstanceMigrateDBInstanceWrite
全部资源
*
rds:MigrateSecurityIPModeMigrateSecurityIPModeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:MigrateToOtherZoneMigrateToOtherZoneWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyADInfoModifyADInfoWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:ModifyAccountDescriptionModifyAccountDescriptionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyActionEventPolicyModifyActionEventPolicyWrite
全部资源
*
rds:EnableEventLog
rds:ModifyActiveOperationTasksModifyActiveOperationTasksWrite
全部资源
*
rds:ModifyBackupPolicyModifyBackupPolicyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:EnableBackupLog
rds:BackupLog
rds:ModifyCollationTimeZoneModifyCollationTimeZoneWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyDBDescriptionModifyDBDescriptionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceAutoUpgradeMinorVersionModifyDBInstanceAutoUpgradeMinorVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceConfigModifyDBInstanceConfigWrite
全部资源
*
rds:ModifyDBInstanceConnectionModeModifyDBInstanceConnectionModeWrite
全部资源
*
rds:ModifyDBInstanceConnectionStringModifyDBInstanceConnectionStringWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceDelayedReplicationTimeModifyDBInstanceDelayedReplicationTimeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceDeletionProtectionModifyDBInstanceDeletionProtectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceDescriptionModifyDBInstanceDescriptionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceEndpointModifyDBInstanceEndpointWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyDBInstanceEndpointAddressModifyDBInstanceEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceHAConfigModifyDBInstanceHAConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceMaintainTimeModifyDBInstanceMaintainTimeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceMetricsModifyDBInstanceMetricsWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceMonitorModifyDBInstanceMonitorWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceNetworkExpireTimeModifyDBInstanceNetworkExpireTimeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceNetworkTypeModifyDBInstanceNetworkTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:InstanceNetworkType
rds:ModifyDBInstancePayTypeModifyDBInstancePayTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceSSLModifyDBInstanceSSLWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:SSLEnabled
rds:ModifyDBInstanceSpecModifyDBInstanceSpecWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceTDEModifyDBInstanceTDEWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:TDEStatus
rds:ModifyDBNodeModifyDBNodeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:ModifyDBProxyModifyDBProxyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:InstanceNetworkType
rds:ModifyDBProxyEndpointModifyDBProxyEndpointWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBProxyEndpointAddressModifyDBProxyEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DBProxyConnectStringNetType
rds:ModifyDBProxyInstanceModifyDBProxyInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDTCSecurityIpHostsForSQLServerModifyDTCSecurityIpHostsForSQLServerWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyDasInstanceConfigModifyDasInstanceConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDatabaseConfigModifyDatabaseConfigWrite
全部资源
*
rds:ModifyDbProxyInstanceSslModifyDbProxyInstanceSslWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DbProxySslEnabled
rds:ModifyHADiagnoseConfigModifyHADiagnoseConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyHASwitchConfigModifyHASwitchConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyInstanceAutoRenewalAttributeModifyInstanceAutoRenewalAttributeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyInstanceCrossBackupPolicyModifyInstanceCrossBackupPolicyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:BackupEnabled
rds:LogBackupEnabled
rds:ModifyPGHbaConfigModifyPGHbaConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyParameterModifyParameterWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:TLSVersion
rds:ModifyParameterGroupModifyParameterGroupWrite
全部资源
*
rds:ModifyReadWriteSplittingConnectionModifyReadWriteSplittingConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyResourceGroupModifyResourceGroupWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifySQLCollectorPolicyModifySQLCollectorPolicyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifySQLCollectorRetentionModifySQLCollectorRetentionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifySecurityGroupConfigurationModifySecurityGroupConfigurationWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifySecurityIpsModifySecurityIpsWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyWhitelistTemplateModifyWhitelistTemplateWrite
全部资源
*
rds:PurgeDBInstanceLogPurgeDBInstanceLogWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ReceiveDBInstanceReceiveDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:RecoveryDBInstanceRecoveryDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ReleaseInstanceConnectionReleaseInstanceConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ReleaseInstancePublicConnectionReleaseInstancePublicConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ReleaseReadWriteSplittingConnectionReleaseReadWriteSplittingConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RemoveTagsFromResourceRemoveTagsFromResourceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
DatabaseInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DBInstanceId}
rds:RenewInstanceRenewInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ResetAccountResetAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ResetAccountPasswordResetAccountPasswordWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RestartDBInstanceRestartDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RestoreDdrTableRestoreDdrTableWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:RestoreTableRestoreTableWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RevokeAccountPrivilegeRevokeAccountPrivilegeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RevokeOperatorPermissionRevokeOperatorPermissionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:StartDBInstanceStartDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:StopDBInstanceStopDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:SwitchDBInstanceHASwitchDBInstanceHAWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:SwitchDBInstanceNetTypeSwitchDBInstanceNetTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:SwitchDBInstanceVpcSwitchDBInstanceVpcWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:TagResourcesTagResourcesWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:TerminateMigrateTaskTerminateMigrateTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:TransformDBInstancePayTypeTransformDBInstancePayTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UnlockAccountUnlockAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UntagResourcesUntagResourcesWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpdatePostgresExtensionsUpdatePostgresExtensionsWrite
全部资源
*
rds:UpdateUserBackupFileUpdateUserBackupFileWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
rds:UpgradeDBInstanceEngineVersionUpgradeDBInstanceEngineVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpgradeDBInstanceKernelVersionUpgradeDBInstanceKernelVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpgradeDBInstanceMajorVersionUpgradeDBInstanceMajorVersionWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:UpgradeDBInstanceMajorVersionPrecheckUpgradeDBInstanceMajorVersionPrecheckRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpgradeDBProxyInstanceKernelVersionUpgradeDBProxyInstanceKernelVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag

资源(Resource)

下表是关系型数据库(RDS)定义的资源,这些资源可以在RAM权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源ARN是资源在阿里云上的唯一标识。具体说明如下:
  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。
  • *表示全部。例如:
    • {#resourceType}*时:表示全部资源。
    • {#regionId}*时:表示全部地域。
    • {#accountId}*时:表示全部阿里云账号。
资源类型资源ARN
DBInstanceacs:rds:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
GadInstanceacs:{#ramcode}:*:{#accountId}:gadinstance/{#GadInstanceName}

条件(Condition)

下表是关系型数据库(RDS)定义的产品级条件关键字,这些条件关键字可以在RAM权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的通用条件关键字也同样适用关系型数据库(RDS)
其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型
条件关键字描述类型
rds:ResourceTag资源标签,与标签键组成条件关键字rds:ResourceTag/<tag-key>。示例值:假设标签为team:dev, 则此处条件关键字和值的写法 "rds:ResourceTag/team": "dev"。STRING
rds:DiskEncryptionRequired磁盘是否加密。String
rds:SSLEnabledSSL是否开启String
rds:TDEStatusTDE状态。String
rds:BackupEnabled是否开启跨地域备份总开关。String
rds:DBProxyConnectStringNetType独享代理连接地址的网络类型。String
rds:EnableEventLog是否开启历史事件记录。String
rds:InstanceNetworkType实例的网络类型。String
rds:LogBackupEnabled是否开启跨地域日志备份开关。String
rds:DbProxySslEnabledSSL加密配置。String
rds:EnableBackupLog是否开启日志备份。String
rds:BackupLog是否开启日志备份。String
rds:TLSVersionTLS版本,示例:TLSv1,TLSv1.1,TLSv1.2。String

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下:
  • 本页导读 (1)
文档反馈