授权信息

更新时间:2025-03-18 07:09:24
访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍云解析DNS(Alidns)RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。云解析DNS(Alidns)RAM代码(RamCode)为 alidns、pubdns、pvtz,支持的授权粒度为资源级

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是云解析DNS(Alidns)定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用前面加 * 表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
操作API访问级别资源类型条件关键字关联操作
alidns:AddCustomLineAddCustomLinecreate
*domain
acs:alidns::{#accountId}:domain/{#domainId}
alidns:AddDnsCacheDomainAddDnsCacheDomaincreate
*CacheDomain
acs:alidns::{#accountId}:dnscache/*
alidns:AddDnsGtmAccessStrategyAddDnsGtmAccessStrategycreate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:AddDnsGtmAddressPoolAddDnsGtmAddressPoolcreate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:AddDnsGtmMonitorAddDnsGtmMonitorcreate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:AddDomainAddDomaincreate
*全部资源
*
alidns:AddDomainBackupAddDomainBackupcreate
*domain
acs:alidns::{#accountId}:domain/{#domainId}
alidns:AddDomainGroupAddDomainGroupcreate
*全部资源
*
alidns:AddDomainRecordAddDomainRecordcreate
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:AddGtmAccessStrategyAddGtmAccessStrategycreate
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#gtminstanceId}
alidns:AddGtmAddressPoolAddGtmAddressPoolcreate
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#gtminstanceId}
alidns:AddGtmMonitorAddGtmMonitorcreate
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#gtminstanceId}
alidns:AddGtmRecoveryPlanAddGtmRecoveryPlancreate
*全部资源
*
alidns:BindInstanceDomainsBindInstanceDomainsWRITE
*全部资源
*
alidns:ChangeDomainGroupChangeDomainGroupupdate
*domain
acs:alidns::{#accountId}:domain/{#domainName}
*group
acs:alidns::{#accountId}:group/{#groupId}
alidns:CopyGtmConfigCopyGtmConfigWRITE
*全部资源
*
alidns:CreateCloudGtmAddressCreateCloudGtmAddresscreate
*全部资源
*
alidns:CreateCloudGtmAddressPoolCreateCloudGtmAddressPoolcreate
*全部资源
*
alidns:CreateCloudGtmInstanceConfigCreateCloudGtmInstanceConfigupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:CreateCloudGtmMonitorTemplateCreateCloudGtmMonitorTemplatecreate
*全部资源
*
alidns:DeleteCloudGtmAddressDeleteCloudGtmAddressdelete
*全部资源
*
alidns:DeleteCloudGtmAddressPoolDeleteCloudGtmAddressPooldelete
*全部资源
*
alidns:DeleteCloudGtmInstanceConfigDeleteCloudGtmInstanceConfigdelete
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DeleteCloudGtmMonitorTemplateDeleteCloudGtmMonitorTemplatedelete
*全部资源
*
alidns:DeleteCustomLinesDeleteCustomLinesdelete
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:DeleteDnsCacheDomainDeleteDnsCacheDomaindelete
*CacheDomain
acs:alidns::{#accountId}:dnscache/{#DomainName}
alidns:DeleteDnsGtmAccessStrategyDeleteDnsGtmAccessStrategydelete
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DeleteDnsGtmAddressPoolDeleteDnsGtmAddressPooldelete
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DeleteDomainDeleteDomaindelete
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:DeleteDomainGroupDeleteDomainGroupdelete
*group
acs:alidns::{#accountId}:group/{#groupId}
alidns:DeleteDomainRecordDeleteDomainRecorddelete
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:DeleteGtmAccessStrategyDeleteGtmAccessStrategydelete
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DeleteGtmAddressPoolDeleteGtmAddressPooldelete
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DeleteGtmRecoveryPlanDeleteGtmRecoveryPlandelete
*全部资源
*
alidns:DeleteSubDomainRecordsDeleteSubDomainRecordsdelete
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:DescribeBatchResultCountDescribeBatchResultCountget
*全部资源
*
alidns:DescribeBatchResultDetailDescribeBatchResultDetailget
*全部资源
*
alidns:DescribeCloudGtmAddressDescribeCloudGtmAddressget
*全部资源
*
alidns:DescribeCloudGtmAddressPoolDescribeCloudGtmAddressPoolget
*全部资源
*
alidns:DescribeCloudGtmAddressPoolReferenceDescribeCloudGtmAddressPoolReferenceget
*全部资源
*
alidns:DescribeCloudGtmAddressReferenceDescribeCloudGtmAddressReferenceget
*全部资源
*
alidns:DescribeCloudGtmGlobalAlertDescribeCloudGtmGlobalAlertget
*全部资源
*
alidns:DescribeCloudGtmInstanceConfigAlertDescribeCloudGtmInstanceConfigAlertget
*全部资源
*
alidns:DescribeCloudGtmInstanceConfigFullInfoDescribeCloudGtmInstanceConfigFullInfoget
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeCloudGtmMonitorTemplateDescribeCloudGtmMonitorTemplateget
*全部资源
*
alidns:DescribeCloudGtmSummaryDescribeCloudGtmSummaryget
*全部资源
*
alidns:DescribeCloudGtmSystemLinesDescribeCloudGtmSystemLineslist
*全部资源
*
alidns:DescribeCustomLineDescribeCustomLineget
*Domain
acs:alidns:*:{#accountId}:domain/{#DomainName}
alidns:DescribeCustomLinesDescribeCustomLinesget
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:DescribeDNSSLBSubDomainsDescribeDNSSLBSubDomainsget
*domain
acs:alidns::{#accountId}:domain/{#domainId}
alidns:DescribeDnsCacheDomainsDescribeDnsCacheDomainsget
*CacheDomain
acs:alidns::{#accountId}:dnscache/*
alidns:DescribeDnsGtmAccessStrategiesDescribeDnsGtmAccessStrategiesget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmAccessStrategyDescribeDnsGtmAccessStrategyget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmAccessStrategyAvailableConfigDescribeDnsGtmAccessStrategyAvailableConfigget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmAddrAttributeInfoDescribeDnsGtmAddrAttributeInfoget
*全部资源
*
alidns:DescribeDnsGtmAddressPoolAvailableConfigDescribeDnsGtmAddressPoolAvailableConfigget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmAvailableAlertGroupDescribeDnsGtmAvailableAlertGroupget
*全部资源
*
alidns:DescribeDnsGtmInstanceDescribeDnsGtmInstanceget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmInstanceAddressPoolDescribeDnsGtmInstanceAddressPoolget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmInstanceAddressPoolsDescribeDnsGtmInstanceAddressPoolsget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmInstanceStatusDescribeDnsGtmInstanceStatusget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmInstanceSystemCnameDescribeDnsGtmInstanceSystemCnameget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmInstancesDescribeDnsGtmInstancesget
*全部资源
*
alidns:DescribeDnsGtmLogsDescribeDnsGtmLogsget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsGtmMonitorAvailableConfigDescribeDnsGtmMonitorAvailableConfigget
*全部资源
*
alidns:DescribeDnsGtmMonitorConfigDescribeDnsGtmMonitorConfigget
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:DescribeDnsProductInstanceDescribeDnsProductInstanceget
*instance
acs:alidns::{#accountId}:instance/{#instanceId}
alidns:DescribeDnsProductInstancesDescribeDnsProductInstancesget
*Instance
acs:alidns:*:{#accountId}:instance/*
alidns:DescribeDohAccountStatisticsDescribeDohAccountStatisticsget
*全部资源
*
alidns:DescribeDohDomainStatisticsDescribeDohDomainStatisticsget
*全部资源
*
alidns:test
alidns:DescribeDohDomainStatisticsSummaryDescribeDohDomainStatisticsSummaryget
*全部资源
*
alidns:DescribeDohSubDomainStatisticsDescribeDohSubDomainStatisticsget
*全部资源
*
alidns:DescribeDohSubDomainStatisticsSummaryDescribeDohSubDomainStatisticsSummaryget
*全部资源
*
alidns:DescribeDohUserInfoDescribeDohUserInfoget
*全部资源
*
alidns:DescribeDomainDnssecInfoDescribeDomainDnssecInfoget
*domain
acs:alidns::{#accountId}:domain/{#domainName}
alidns:DescribeDomainGroupsDescribeDomainGroupsget
*全部资源
*
alidns:DescribeDomainInfoDescribeDomainInfoget
*全部资源
*
alidns:DescribeDomainLogsDescribeDomainLogsget
*全部资源
*
alidns:DescribeDomainNsDescribeDomainNsget
*domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:DescribeDomainRecordInfoDescribeDomainRecordInfoget
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:DescribeDomainRecordsDescribeDomainRecordsget
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:DescribeDomainResolveStatisticsSummaryDescribeDomainResolveStatisticsSummary
*全部资源
*
alidns:DescribeDomainStatisticsDescribeDomainStatisticsget
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:DescribeDomainStatisticsSummaryDescribeDomainStatisticsSummaryget
*全部资源
*
alidns:DescribeDomainsDescribeDomainsget
*全部资源
*
alidns:DescribeGtmAccessStrategiesDescribeGtmAccessStrategiesget
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmAccessStrategyDescribeGtmAccessStrategyget
*全部资源
*
alidns:DescribeGtmAccessStrategyAvailableConfigDescribeGtmAccessStrategyAvailableConfigget
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmAvailableAlertGroupDescribeGtmAvailableAlertGroupget
*全部资源
*
alidns:DescribeGtmInstanceDescribeGtmInstanceget
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmInstanceAddressPoolDescribeGtmInstanceAddressPoolget
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmInstanceAddressPoolsDescribeGtmInstanceAddressPoolsget
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmInstanceStatusDescribeGtmInstanceStatusget
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmInstanceSystemCnameDescribeGtmInstanceSystemCnameget
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmInstancesDescribeGtmInstancesget
*全部资源
*
alidns:DescribeGtmLogsDescribeGtmLogsget
*全部资源
*
alidns:DescribeGtmMonitorAvailableConfigDescribeGtmMonitorAvailableConfigget
*全部资源
*
alidns:DescribeGtmMonitorConfigDescribeGtmMonitorConfigget
*gtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:DescribeGtmRecoveryPlanDescribeGtmRecoveryPlanget
*全部资源
*
alidns:DescribeGtmRecoveryPlanAvailableConfigDescribeGtmRecoveryPlanAvailableConfigget
*全部资源
*
alidns:DescribeGtmRecoveryPlansDescribeGtmRecoveryPlansget
*全部资源
*
alidns:DescribeInstanceDomainsDescribeInstanceDomainsget
*instance
acs:alidns::{#accountId}:instance/{#instanceId}
alidns:DescribeInternetDnsLogsDescribeInternetDnsLogsget
*全部资源
*
alidns:DescribeRecordLogsDescribeRecordLogsget
*Domain
acs:alidns:*:{#accountId}:domain/{#DomainName}
alidns:DescribeRecordResolveStatisticsSummaryDescribeRecordResolveStatisticsSummary
*Domain
acs:alidns:*:{#accountId}:domain/{#DomainName}
alidns:DescribeRecordStatisticsDescribeRecordStatisticsget
*Domain
acs:alidns:*:{#accountId}:domain/{#DomainName}
alidns:DescribeRecordStatisticsSummaryDescribeRecordStatisticsSummaryget
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:DescribeSubDomainRecordsDescribeSubDomainRecordsget
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:DescribeSupportLinesDescribeSupportLinesget
*全部资源
*
alidns:DescribeTagsDescribeTagsget
*全部资源
*
alidns:DescribeTransferDomainsDescribeTransferDomainsget
*全部资源
*
alidns:ExecuteGtmRecoveryPlanExecuteGtmRecoveryPlanWRITE
*全部资源
*
alidns:GetMainDomainNameGetMainDomainNameget
*全部资源
*
alidns:GetTxtRecordForVerifyGetTxtRecordForVerifyget
*全部资源
*
alidns:ListCloudGtmAddressPoolsListCloudGtmAddressPoolslist
*全部资源
*
alidns:ListCloudGtmAddressesListCloudGtmAddresseslist
*全部资源
*
alidns:ListCloudGtmAlertLogsListCloudGtmAlertLogslist
*全部资源
*
alidns:ListCloudGtmAvailableAlertGroupsListCloudGtmAvailableAlertGroupslist
*全部资源
*
alidns:ListCloudGtmInstanceConfigsListCloudGtmInstanceConfigslist
*全部资源
*
alidns:ListCloudGtmInstancesListCloudGtmInstanceslist
*全部资源
*
alidns:ListCloudGtmMonitorNodesListCloudGtmMonitorNodeslist
*全部资源
*
alidns:ListCloudGtmMonitorTemplatesListCloudGtmMonitorTemplateslist
*全部资源
*
alidns:ListTagResourcesListTagResourcesget
*全部资源
*
alidns:ModifyHichinaDomainDNSModifyHichinaDomainDNSupdate
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:MoveDomainResourceGroupMoveDomainResourceGroupWRITE
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:MoveGtmResourceGroupMoveGtmResourceGroupWRITE
*gtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:OperateBatchDomainOperateBatchDomainWRITE
*全部资源
*
alidns:PreviewGtmRecoveryPlanPreviewGtmRecoveryPlanget
*全部资源
*
alidns:ReplaceCloudGtmAddressPoolAddressReplaceCloudGtmAddressPoolAddressupdate
*全部资源
*
alidns:ReplaceCloudGtmInstanceConfigAddressPoolReplaceCloudGtmInstanceConfigAddressPoolupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:RetrieveDomainRetrieveDomainnone
*全部资源
*
alidns:RollbackGtmRecoveryPlanRollbackGtmRecoveryPlanWRITE
*全部资源
*
alidns:SearchCloudGtmAddressPoolsSearchCloudGtmAddressPoolslist
*全部资源
*
alidns:SearchCloudGtmAddressesSearchCloudGtmAddresseslist
*全部资源
*
alidns:SearchCloudGtmInstanceConfigsSearchCloudGtmInstanceConfigslist
*全部资源
*
alidns:SearchCloudGtmInstancesSearchCloudGtmInstancesget
*全部资源
*
alidns:SearchCloudGtmMonitorTemplatesSearchCloudGtmMonitorTemplateslist
*全部资源
*
alidns:SetDNSSLBStatusSetDNSSLBStatusupdate
*domain
acs:alidns::{#accountId}:domain/{#domainId}
alidns:SetDnsGtmAccessModeSetDnsGtmAccessModeupdate
*AccessStrategy
acs:alidns:*:{#accountId}:gtminstance/{#InstanceId}
alidns:SetDnsGtmMonitorStatusSetDnsGtmMonitorStatusupdate
*MonitorConfig
acs:alidns:*:{#accountId}:gtminstance/{#InstanceId}
alidns:SetDomainDnssecStatusSetDomainDnssecStatusupdate
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:SetDomainRecordStatusSetDomainRecordStatusupdate
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:SetGtmAccessModeSetGtmAccessModeupdate
*gtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:SetGtmMonitorStatusSetGtmMonitorStatusupdate
*gtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:SwitchDnsGtmInstanceStrategyModeSwitchDnsGtmInstanceStrategyModeWRITE
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:TagResourcesTagResources
*全部资源
*
alidns:TransferDomainTransferDomainWRITE
*全部资源
*
alidns:UnbindInstanceDomainsUnbindInstanceDomainsWRITE
*Instance
acs:alidns:*:{#accountId}:instance/{#InstanceId}
*Domain
acs:alidns:*:{#accountId}:domain/{#DomainName}
alidns:UntagResourcesUntagResources
*全部资源
*
alidns:UpdateCloudGtmAddressUpdateCloudGtmAddressupdate
*全部资源
*
alidns:UpdateCloudGtmAddressEnableStatusUpdateCloudGtmAddressEnableStatusupdate
*全部资源
*
alidns:UpdateCloudGtmAddressManualAvailableStatusUpdateCloudGtmAddressManualAvailableStatusupdate
*全部资源
*
alidns:UpdateCloudGtmAddressPoolBasicConfigUpdateCloudGtmAddressPoolBasicConfigupdate
*全部资源
*
alidns:UpdateCloudGtmAddressPoolEnableStatusUpdateCloudGtmAddressPoolEnableStatusupdate
*全部资源
*
alidns:UpdateCloudGtmAddressPoolLbStrategyUpdateCloudGtmAddressPoolLbStrategyupdate
*全部资源
*
alidns:UpdateCloudGtmAddressPoolRemarkUpdateCloudGtmAddressPoolRemarkupdate
*全部资源
*
alidns:UpdateCloudGtmAddressRemarkUpdateCloudGtmAddressRemarkupdate
*全部资源
*
alidns:UpdateCloudGtmGlobalAlertUpdateCloudGtmGlobalAlertupdate
*全部资源
*
alidns:UpdateCloudGtmInstanceConfigAlertUpdateCloudGtmInstanceConfigAlertupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateCloudGtmInstanceConfigBasicUpdateCloudGtmInstanceConfigBasicupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateCloudGtmInstanceConfigEnableStatusUpdateCloudGtmInstanceConfigEnableStatusupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateCloudGtmInstanceConfigLbStrategyUpdateCloudGtmInstanceConfigLbStrategyupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateCloudGtmInstanceConfigRemarkUpdateCloudGtmInstanceConfigRemarkupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateCloudGtmInstanceNameUpdateCloudGtmInstanceNameupdate
*GtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateCloudGtmMonitorTemplateUpdateCloudGtmMonitorTemplateupdate
*全部资源
*
alidns:UpdateCloudGtmMonitorTemplateRemarkUpdateCloudGtmMonitorTemplateRemarkupdate
*全部资源
*
alidns:UpdateCustomLineUpdateCustomLineupdate
*Domain
acs:alidns:*:{#accountId}:domain/{#DomainName}
alidns:UpdateDNSSLBWeightUpdateDNSSLBWeightupdate
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:UpdateDnsCacheDomainUpdateDnsCacheDomainupdate
*CacheDomain
acs:alidns::{#accountId}:dnscache/{#DomainName}
alidns:UpdateDnsCacheDomainRemarkUpdateDnsCacheDomainRemarkupdate
*CacheDomain
acs:alidns::{#accountId}:dnscache/{#DomainName}
alidns:UpdateDnsGtmAccessStrategyUpdateDnsGtmAccessStrategyupdate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:UpdateDnsGtmAddressPoolUpdateDnsGtmAddressPoolupdate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:UpdateDnsGtmInstanceGlobalConfigUpdateDnsGtmInstanceGlobalConfigupdate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:UpdateDnsGtmMonitorUpdateDnsGtmMonitorupdate
*MonitorConfig
acs:alidns:*:{#accountId}:gtminstance/{#InstanceId}
alidns:UpdateDomainGroupUpdateDomainGroupupdate
*group
acs:alidns::{#accountId}:group/{#groupId}
alidns:UpdateDomainRecordUpdateDomainRecordupdate
*domain
acs:alidns::{#accountId}:domain/{#domainId}
alidns:UpdateDomainRecordRemarkUpdateDomainRecordRemarkupdate
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:UpdateDomainRemarkUpdateDomainRemarkupdate
*Domain
acs:alidns::{#accountId}:domain/{#DomainName}
alidns:UpdateGtmAccessStrategyUpdateGtmAccessStrategyupdate
*gtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateGtmAddressPoolUpdateGtmAddressPoolupdate
*gtminstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateGtmInstanceGlobalConfigUpdateGtmInstanceGlobalConfigupdate
*gtmInstance
acs:alidns::{#accountId}:gtminstance/{#instanceId}
alidns:UpdateGtmMonitorUpdateGtmMonitorupdate
*gtmInstance
acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
alidns:UpdateGtmRecoveryPlanUpdateGtmRecoveryPlanupdate
*全部资源
*
pubdns:DescribePdnsRequestStatisticDescribePdnsRequestStatisticget
*全部资源
*
pubdns:DescribePdnsRequestStatisticsDescribePdnsRequestStatisticsget
*全部资源
*

资源(Resource)

下表是云解析DNS(Alidns)定义的资源,这些资源可以在RAM权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源ARN是资源在阿里云上的唯一标识。具体说明如下:
  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。
  • *表示全部。例如:
    • {#resourceType}*时:表示全部资源。
    • {#regionId}*时:表示全部地域。
    • {#accountId}*时:表示全部阿里云账号。
资源类型资源ARN
资源类型资源ARN
AccessStrategy
  • acs:alidns:*:{#accountId}:gtminstance/{#InstanceId}
CacheDomain
  • acs:alidns::{#accountId}:dnscache/{#DomainName}
  • acs:alidns::{#accountId}:dnscache/*
Domain
  • acs:alidns::{#accountId}:domain/{#DomainName}
  • acs:alidns:*:{#accountId}:domain/{#DomainName}
  • acs:alidns::{#accountId}:domain/*
  • acs:eiam:{#regionId}:{#accountId}:flushcache/*
  • acs:alidns:*:{#accountId}:domain/*
  • acs:alidns:*:{#accountId}:doh/*
  • acs:alidns:*:{#accountId}:flushcache/*
Fusion
  • acs:alidns::{#accountId}:fusion/*
GtmInstance
  • acs:alidns::{#accountId}:gtminstance/{#instanceId}
  • acs:alidns::{#accountId}:gtminstance/*
  • acs:alidns:*:{#accountId}:gtminstance/{#InstanceId}
Instance
  • acs:alidns:*:{#accountId}:instance/{#InstanceId}
  • acs:alidns:*:{#accountId}:instance/*
MonitorConfig
  • acs:alidns:*:{#accountId}:gtminstance/{#InstanceId}
PdnsAppKey
  • acs:pubdns::{#accountId}:*
cloudGtmAddress
  • acs:alidns::{#accountId}:*
  • acs:alidns::{#accountId}:cloudGtmAddress/{#addressId}
  • acs:alidns::{#accountId}:*/*
  • acs:alidns::{#accountId}:cloudGtmAddress/*
cloudGtmAddressPool
  • acs:alidns::{#accountId}:cloudGtmAddressPool/{#addressPoolId}
  • acs:alidns::{#accountId}:cloudGtmAddressPool/{#addressId}
cloudGtmMonitorTemplate
  • acs:alidns::{#accountId}:cloudGtmMonitorTemplate/{#templateId}
  • acs:alidns::{#accountId}:cloudGtmMonitorTemplate/*
doh
  • acs:alidns::{#accountId}:doh/*
domain
  • acs:alidns::{#accountId}:domain/{#$domainName}
  • acs:alidns::{#accountId}:domain/*
  • acs:alidns::{#accountId}:domain/{#domainName}
  • acs:alidns::{#accountId}:domain/{#domainId}
  • acs:alidns:*:{#accountId}:domain/*
group
  • acs:alidns::{#accountId}:group/{#groupId}
  • acs:alidns:*:{#accountId}:group/*
  • acs:alidns::{#accountId}:group/*
gtmInstance
  • acs:alidns::{#accountId}:gtmInstance/{#gtmInstanceId}
  • acs:alidns::{#accountId}:gtmInstance/*
  • acs:alidns::{#accountId}:gtminstance/{#instanceId}
gtmInstnace
  • acs:alidns:*:{#accountId}:gtmInstnace/*
gtminstance
  • acs:alidns::{#accountId}:gtminstance/*
  • acs:alidns::{#accountId}:gtminstance/{#instanceId}
  • acs:alidns::{#accountId}:gtminstance/{#gtminstanceId}
instance
  • acs:alidns::{#accountId}:instance/*
  • acs:alidns::{#accountId}:instance/{#instanceId}

条件(Condition)

云解析DNS(Alidns)未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下:
  • 本页导读 (1)
  • 权限策略通用结构
  • 操作(Action)
  • 资源(Resource)
  • 条件(Condition)
  • 相关操作
AI助理

点击开启售前

在线咨询服务

你好,我是AI助理

可以解答问题、推荐解决方案等