授权信息

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍关系型数据库(RDS)为RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。关系型数据库(RDS)的RAM代码(RamCode)为rds,支持的授权粒度为RESOURCE

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是关系型数据库(RDS)定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用背景高亮的方式表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
rds:ActivateMigrationTargetInstanceActivateMigrationTargetInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AddTagsToResourceAddTagsToResourceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AllocateInstancePublicConnectionAllocateInstancePublicConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:AllocateReadWriteSplittingConnectionAllocateReadWriteSplittingConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CalculateDBInstanceWeightCalculateDBInstanceWeightWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CancelImportCancelImportWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CheckAccountNameAvailableCheckAccountNameAvailableRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckCloudResourceAuthorizedCheckCloudResourceAuthorizedRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckCreateDdrDBInstanceCheckCreateDdrDBInstanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CheckDBNameAvailableCheckDBNameAvailableRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckInstanceExistCheckInstanceExistRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CheckServiceLinkedRoleCheckServiceLinkedRoleRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#dbinstanceId}
rds:CloneDBInstanceCloneDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CloneParameterGroupCloneParameterGroupWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:ConfirmNotifyConfirmNotifyWrite
rds:CopyDatabaseCopyDatabaseWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CopyDatabaseBetweenInstancesCopyDatabaseBetweenInstancesWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:CreateAccountCreateAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateBackupCreateBackupWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateCloudMigrationPrecheckTaskCreateCloudMigrationPrecheckTaskRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateCloudMigrationTaskCreateCloudMigrationTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDBInstanceCreateDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
rds:ResourceTag
rds:CreateDBInstanceEndpointCreateDBInstanceEndpointWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:ResourceTag
rds:CreateDBInstanceEndpointAddressCreateDBInstanceEndpointAddressWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:ResourceTag
rds:CreateDBProxyEndpointAddressCreateDBProxyEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CreateDatabaseCreateDatabaseWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateDdrInstanceCreateDdrInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
rds:CreateDiagnosticReportCreateDiagnosticReportWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:CreateGADInstanceCreateGADInstanceWrite
全部资源
acs:rds::{#accountId}:*
rds:CreateGadInstanceMemberCreateGadInstanceMemberWrite
全部资源
acs:rds::{#accountId}:*
rds:CreateMigrateTaskCreateMigrateTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateOnlineDatabaseTaskCreateOnlineDatabaseTaskWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateParameterGroupCreateParameterGroupWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:CreateReadOnlyDBInstanceCreateReadOnlyDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:CreateServiceLinkedRoleCreateServiceLinkedRoleWrite
rds:CreateTempDBInstanceCreateTempDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteAccountDeleteAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteBackupDeleteBackupWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteBackupFileDeleteBackupFileWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteDBInstanceDeleteDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteDBInstanceEndpointDeleteDBInstanceEndpointWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ResourceTag
rds:DeleteDBInstanceEndpointAddressDeleteDBInstanceEndpointAddressWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ResourceTag
rds:DeleteDBProxyEndpointAddressDeleteDBProxyEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DeleteDatabaseDeleteDatabaseWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DeleteGadInstanceDeleteGadInstanceWrite
全部资源
acs:rds::{#accountId}:*
rds:DeleteUserBackupFileDeleteUserBackupFileWrite
BackupFile
acs:rds:*:{#accountId}:backupfile/{#BackupId}
rds:DescribeADInfoDescribeADInfoRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeAccountsDescribeAccountsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeActionEventPolicyDescribeActionEventPolicyRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeActiveOperationTasksDescribeActiveOperationTasksRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:DescribeAnalyticdbByPrimaryDBInstanceDescribeAnalyticdbByPrimaryDBInstanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeAvailableClassesDescribeAvailableClassesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
rds:ResourceTag
rds:DescribeAvailableCrossRegionDescribeAvailableCrossRegionRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeAvailableMetricsDescribeAvailableMetricsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeAvailableRecoveryTimeDescribeAvailableRecoveryTimeRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeAvailableZonesDescribeAvailableZonesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
rds:DescribeBackupDatabaseDescribeBackupDatabaseRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeBackupPolicyDescribeBackupPolicyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeBackupTasksDescribeBackupTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeBackupsDescribeBackupsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeBinlogFilesDescribeBinlogFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeCharacterSetNameDescribeCharacterSetNameRead
rds:DescribeCloudMigrationPrecheckResultDescribeCloudMigrationPrecheckResultRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeCrossBackupMetaListDescribeCrossBackupMetaListRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeCrossRegionBackupDBInstanceDescribeCrossRegionBackupDBInstanceRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:ResourceTag
rds:DescribeCrossRegionBackupsDescribeCrossRegionBackupsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeCrossRegionLogBackupFilesDescribeCrossRegionLogBackupFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceAttributeDescribeDBInstanceAttributeRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceByTagsDescribeDBInstanceByTagsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceDetailDescribeDBInstanceDetailRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeDBInstanceEncryptionKeyDescribeDBInstanceEncryptionKeyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceEndpointsDescribeDBInstanceEndpointsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ResourceTag
rds:DescribeDBInstanceHAConfigDescribeDBInstanceHAConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceIPArrayListDescribeDBInstanceIPArrayListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceIpHostnameDescribeDBInstanceIpHostnameRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceMetricsDescribeDBInstanceMetricsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceMonitorDescribeDBInstanceMonitorRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceNetInfoDescribeDBInstanceNetInfoRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceNetInfoForChannelDescribeDBInstanceNetInfoForChannelRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancePerformanceDescribeDBInstancePerformanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceProxyConfigurationDescribeDBInstanceProxyConfigurationRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceSSLDescribeDBInstanceSSLRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstanceTDEDescribeDBInstanceTDERead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesDescribeDBInstancesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesAsCsvDescribeDBInstancesAsCsvRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesByExpireTimeDescribeDBInstancesByExpireTimeRead
全部资源
acs:rds:*:*:*
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesByPerformanceDescribeDBInstancesByPerformanceRead
全部资源
acs:rds:*:*:*
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBInstancesForCloneDescribeDBInstancesForCloneRead
rds:DescribeDBMiniEngineVersionsDescribeDBMiniEngineVersionsRead
rds:DescribeDBProxyDescribeDBProxyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBProxyEndpointDescribeDBProxyEndpointRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDBProxyPerformanceDescribeDBProxyPerformanceRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDTCSecurityIpHostsForSQLServerDescribeDTCSecurityIpHostsForSQLServerRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDatabasesDescribeDatabasesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeDedicatedHostGroupsDescribeDedicatedHostGroupsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeDedicatedHostsDescribeDedicatedHostsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeDetachedBackupsDescribeDetachedBackupsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeDiagnosticReportListDescribeDiagnosticReportListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeErrorLogsDescribeErrorLogsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeEventsDescribeEventsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeGadInstancesDescribeGadInstancesList
全部资源
acs:rds::{#accountId}:*
rds:DescribeHADiagnoseConfigDescribeHADiagnoseConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeHASwitchConfigDescribeHASwitchConfigRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeInstanceAutoRenewalAttributeDescribeInstanceAutoRenewalAttributeRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeInstanceCrossBackupPolicyDescribeInstanceCrossBackupPolicyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeInstanceKeywordsDescribeInstanceKeywordsRead
rds:DescribeLocalAvailableRecoveryTimeDescribeLocalAvailableRecoveryTimeRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeLogBackupFilesDescribeLogBackupFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeMetaListDescribeMetaListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeMigrateTaskByIdDescribeMigrateTaskByIdRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeMigrateTasksDescribeMigrateTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeModifyParameterLogDescribeModifyParameterLogRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeOssDownloadsDescribeOssDownloadsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeParameterGroupDescribeParameterGroupRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeParameterGroupsDescribeParameterGroupsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
ResourceOwner
rds:DescribeParametersDescribeParametersRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeRdsResourceSettingsDescribeRdsResourceSettingsRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeReadDBInstanceDelayDescribeReadDBInstanceDelayRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:DescribeRenewalPriceDescribeRenewalPriceRead
rds:DescribeResourceUsageDescribeResourceUsageRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLCollectorPolicyDescribeSQLCollectorPolicyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLCollectorRetentionDescribeSQLCollectorRetentionRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:DescribeSQLLogFilesDescribeSQLLogFilesRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLLogRecordsDescribeSQLLogRecordsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSQLLogReportListDescribeSQLLogReportListRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSecurityGroupConfigurationDescribeSecurityGroupConfigurationRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSlowLogRecordsDescribeSlowLogRecordsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeSlowLogsDescribeSlowLogsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeTagsDescribeTagsRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeTasksDescribeTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeUpgradeMajorVersionPrecheckTaskDescribeUpgradeMajorVersionPrecheckTaskRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DescribeUpgradeMajorVersionTasksDescribeUpgradeMajorVersionTasksRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DestroyDBInstanceDestroyDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:DetachGadInstanceMemberDetachGadInstanceMemberWrite
全部资源
acs:rds::{#accountId}:*
rds:GetDBInstanceTopologyGetDBInstanceTopologyRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:GetDbProxyInstanceSslGetDbProxyInstanceSslWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:GrantAccountPrivilegeGrantAccountPrivilegeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:GrantOperatorPermissionGrantOperatorPermissionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ImportDatabaseBetweenInstancesImportDatabaseBetweenInstancesWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ImportUserBackupFileImportUserBackupFileRead
rds:ListClassesListClassesRead
rds:ListTagResourcesListTagResourcesRead
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ListUserBackupFilesListUserBackupFilesRead
rds:LockAccountLockAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:MigrateDBInstanceMigrateDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:MigrateSecurityIPModeMigrateSecurityIPModeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:MigrateToOtherZoneMigrateToOtherZoneWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyAccountDescriptionModifyAccountDescriptionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyActionEventPolicyModifyActionEventPolicyWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyActiveOperationTasksModifyActiveOperationTasksWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ModifyBackupPolicyModifyBackupPolicyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyCollationTimeZoneModifyCollationTimeZoneWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyDBDescriptionModifyDBDescriptionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceAutoUpgradeMinorVersionModifyDBInstanceAutoUpgradeMinorVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceConnectionModeModifyDBInstanceConnectionModeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyDBInstanceConnectionStringModifyDBInstanceConnectionStringWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceDelayedReplicationTimeModifyDBInstanceDelayedReplicationTimeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceDeletionProtectionModifyDBInstanceDeletionProtectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceDescriptionModifyDBInstanceDescriptionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceEndpointModifyDBInstanceEndpointWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ResourceTag
rds:ModifyDBInstanceEndpointAddressModifyDBInstanceEndpointAddressWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ResourceTag
rds:ModifyDBInstanceHAConfigModifyDBInstanceHAConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceMaintainTimeModifyDBInstanceMaintainTimeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceMetricsModifyDBInstanceMetricsWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceMonitorModifyDBInstanceMonitorWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceNetworkExpireTimeModifyDBInstanceNetworkExpireTimeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceNetworkTypeModifyDBInstanceNetworkTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstancePayTypeModifyDBInstancePayTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceProxyConfigurationModifyDBInstanceProxyConfigurationWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceSSLModifyDBInstanceSSLWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceSpecModifyDBInstanceSpecWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBInstanceTDEModifyDBInstanceTDEWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBProxyModifyDBProxyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBProxyEndpointModifyDBProxyEndpointWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBProxyEndpointAddressModifyDBProxyEndpointAddressWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDBProxyInstanceModifyDBProxyInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDTCSecurityIpHostsForSQLServerModifyDTCSecurityIpHostsForSQLServerWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifyDasInstanceConfigModifyDasInstanceConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyDbProxyInstanceSslModifyDbProxyInstanceSslWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyHADiagnoseConfigModifyHADiagnoseConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyHASwitchConfigModifyHASwitchConfigWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyInstanceAutoRenewalAttributeModifyInstanceAutoRenewalAttributeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyInstanceCrossBackupPolicyModifyInstanceCrossBackupPolicyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyParameterModifyParameterWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyParameterGroupModifyParameterGroupWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
rds:ModifyReadWriteSplittingConnectionModifyReadWriteSplittingConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifyReadonlyInstanceDelayReplicationTimeModifyReadonlyInstanceDelayReplicationTimeWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:ModifyResourceGroupModifyResourceGroupWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifySQLCollectorPolicyModifySQLCollectorPolicyWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifySQLCollectorRetentionModifySQLCollectorRetentionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ModifySecurityGroupConfigurationModifySecurityGroupConfigurationWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ModifySecurityIpsModifySecurityIpsWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:PurgeDBInstanceLogPurgeDBInstanceLogWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RebuildDBInstanceRebuildDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ReceiveDBInstanceReceiveDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:RecoveryDBInstanceRecoveryDBInstanceWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ReleaseInstanceConnectionReleaseInstanceConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ReleaseInstancePublicConnectionReleaseInstancePublicConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ReleaseReadWriteSplittingConnectionReleaseReadWriteSplittingConnectionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RemoveTagsFromResourceRemoveTagsFromResourceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RenewInstanceRenewInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ResetAccountResetAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:ResetAccountPasswordResetAccountPasswordWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RestartDBInstanceRestartDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RestoreDdrTableRestoreDdrTableWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:RestoreTableRestoreTableWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RevokeAccountPrivilegeRevokeAccountPrivilegeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:RevokeOperatorPermissionRevokeOperatorPermissionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:StartDBInstanceStartDBInstanceWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:StopDBInstanceStopDBInstanceWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:SwitchDBInstanceHASwitchDBInstanceHAWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:SwitchDBInstanceNetTypeSwitchDBInstanceNetTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:SwitchDBInstanceVpcSwitchDBInstanceVpcWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:TagResourcesTagResourcesWrite
全部资源
acs:rds:{#regionId}:{#accountId}:*
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:TerminateMigrateTaskTerminateMigrateTaskWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:TransformDBInstancePayTypeTransformDBInstancePayTypeWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UnlockAccountUnlockAccountWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UntagResourcesUntagResourcesWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpdateUserBackupFileUpdateUserBackupFileWrite
BackupFile
acs:rds:*:{#accountId}:backupfile/{#BackupId}
rds:UpgradeDBInstanceEngineVersionUpgradeDBInstanceEngineVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpgradeDBInstanceKernelVersionUpgradeDBInstanceKernelVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpgradeDBInstanceMajorVersionUpgradeDBInstanceMajorVersionWrite
DBInstance
acs:rds:*:{#accountId}:dbinstance/{#DBInstanceId}
rds:UpgradeDBInstanceMajorVersionPrecheckUpgradeDBInstanceMajorVersionPrecheckRead
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag
rds:UpgradeDBProxyInstanceKernelVersionUpgradeDBProxyInstanceKernelVersionWrite
DBInstance
acs:rds:{#regionId}:{#accountId}:dbinstance/{#dbinstanceId}
rds:ResourceTag

资源(Resource)

下表是关系型数据库(RDS)定义的资源,这些资源可以在RAM权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源ARN是资源在阿里云上的唯一标识。具体说明如下:
  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。
  • *表示全部。例如:
    • {#resourceType}*时:表示全部资源。
    • {#regionId}*时:表示全部地域。
    • {#accountId}*时:表示全部阿里云账号。
资源类型资源ARN
DBInstanceacs:{#ramcode}:{#regionId}:{#accountId}:dbinstance/{#DbInstanceId}
BackupFileacs:{#ramcode}:*:{#accountId}:backupfile/{#BackupId}

条件(Condition)

下表是关系型数据库(RDS)定义的产品级条件关键字,这些条件关键字可以在RAM权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的通用条件关键字也同样适用关系型数据库(RDS)
其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型
条件关键字描述类型
rds:ResourceTag资源 tab 标签STRING

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下:
阿里云首页 关系型数据库 相关技术圈