Repository access control
Use Resource Access Management (RAM) to grant different levels of image permissions to RAM users, or Security Token Service (STS) to grant temporary image permissions.
Prerequisites
A RAM user has been created by using your Alibaba Cloud account. For more information, see Create a RAM user.
Background information
Resource Access Management (RAM) and Security Token Service (STS) provide flexible, secure access control for image repositories. By default, an Alibaba Cloud account has full permissions on the resources it owns. Use RAM and STS to grant different permissions on image resources to different RAM users and to provide temporary access. Before you configure authorization policies, read .
After you configure authorization policies for a RAM user, use that RAM user to log on to the Container Registry console, create a Personal Edition instance, and set a registry password. You can then view the images that the RAM user has permissions on.
Grant permissions to a RAM user
When granting permissions to a RAM user, follow the principle of least privilege to avoid granting excessive permissions.
If you grant a RAM user the AdministratorAccess permission, which includes management permissions on all Alibaba Cloud resources, the RAM user has all permissions on Container Registry, regardless of any previously granted Container Registry permissions.
Attach system policies to a RAM user
By default, the AliyunContainerRegistryFullAccess and AliyunContainerRegistryReadOnlyAccess policies are created for Container Registry. These policies can be attached directly to a RAM user. The following list describes the system policies:
AliyunContainerRegistryFullAccess
This policy grants a RAM user the same permissions on image resources as the Alibaba Cloud account. The RAM user can perform all operations on image resources.
{ "Statement": [ { "Action": "cr:*", "Effect": "Allow", "Resource": "*" } ], "Version": "1" }AliyunContainerRegistryReadOnlyAccess
This policy grants a RAM user read-only permissions on all image resources. For example, the RAM user can view the repository list and pull images.
{ "Statement": [ { "Action": [ "cr:Get*", "cr:List*", "cr:PullRepository" ], "Effect": "Allow", "Resource": "*" } ], "Version": "1" }
This section describes how to grant the AliyunContainerRegistryReadOnlyAccess policy to a RAM user.
Log on to the RAM console.
In the left-side navigation pane, choose .
On the Users page, find the RAM user and click Actions in the Attach Policy column.
Alternatively, you can select multiple RAM users and click Attach Policy at the bottom of the list to grant permissions to them all at once.
Authorize
Select an authorization scope.
Account: The permissions apply within the current Alibaba Cloud account.
resource: The permissions apply within the specified resource group.
NoteTo grant permissions at the resource group level, the cloud service must support resource groups. For more information, see Services that support resource groups.
Specify the principal.
The principal is the user who will receive the permissions. The RAM user you selected is automatically specified as the principal.
In the Policies search box, search for AliyunContainerRegistryReadOnlyAccess, and then click AliyunContainerRegistryReadOnlyAccess in the results list.
Click OK.
Click Off.
Attach custom policies to a RAM user
To enforce fine-grained permission control, create custom policies and attach them to RAM users.
Policy configurations in typical scenarios
The following sections describe how to configure custom policies for typical scenarios:
Scenario 1: Grant a RAM user the read permission on a namespace. In this example, the namespace is named juzhong.
After the RAM user logs on to the Container Registry instance, the RAM user can pull all images in the juzhong namespace. The RAM user can also call API operations to view information about the namespace and all repositories in it.
{ "Statement": [ { "Action": [ "cr:Get*", "cr:List*", "cr:PullRepository" ], "Effect": "Allow", "Resource": [ "acs:cr:*:*:repository/juzhong/*" ] } ], "Version": "1" }ImportantIf you want to allow the RAM user to view all namespaces in the Container Registry console, add the following authorization configurations. The RAM user can then view all namespaces and repositories, but can pull images only from repositories in the juzhong namespace.
{ "Statement": [ { "Action": [ "cr:Get*", "cr:List*", "cr:PullRepository" ], "Effect": "Allow", "Resource": [ "acs:cr:*:*:repository/juzhong/*" ] }, { "Action": [ "cr:ListNamespace", "cr:ListRepository" ], "Effect": "Allow", "Resource": [ "*" ] } ], "Version": "1" }Scenario 2: Grant a RAM user all permissions on a repository. In this example, the repository is named nginx, belongs to the juzhong namespace, and is located in the China (Hangzhou) region.
ImportantIf you want to allow the RAM user to manage repositories in the Container Registry console, add the configurations described in scenario 1.
{ "Statement": [ { "Action": [ "cr:*" ], "Effect": "Allow", "Resource": [ "acs:cr:cn-hangzhou:*:repository/juzhong/nginx" ] }, { "Action": [ "cr:Get*", "cr:List*" ], "Effect": "Allow", "Resource": [ "acs:cr:*:*:repository/juzhong" ] } ], "Version": "1" }Scenario 3: Allow a RAM user to only push images to a specific repository.
The following policy allows a RAM user to only push images to the specified repository:
{ "Statement": [ { "Effect": "Allow", "Action": [ "cr:PushRepository", "cr:GetAuthorizationToken" ], "Resource": [ "acs:cr:*:*:repository/<namespace>/<repository>" ] } ], "Version": "1" }cr:GetAuthorizationTokenis used bydocker loginto obtain an access credential, which is required before you can push images. Replace<namespace>and<repository>with actual values. To grant push permissions on all repositories in a namespace, useacs:cr:*:*:repository/<namespace>/*.Scenario 4: Grant all permissions on a namespace to a RAM user.
ImportantThis scenario is supported only through API calls. If you want to allow the user to view all repositories in the Container Registry console, add the configurations described in scenario 1.
{ "Statement": [ { "Action": [ "cr:*" ], "Effect": "Allow", "Resource": [ "acs:cr:cn-hangzhou:*:repository/juzhong", "acs:cr:cn-hangzhou:*:repository/juzhong/*" ] } ], "Version": "1" }
Create a custom policy using one of the preceding scripts, then attach it to the RAM user as follows:
Create a custom policy.
Log on to the RAM console by using your Alibaba Cloud account.
In the left-side navigation pane, choose .
On the Policies page, click Create Policy.
On the Create Policy page, click the JSON Editor tab and edit the policy document in the code editor. For more information about the policy syntax, see Policy structure and syntax.
For more information about configuring the Action and Resource parameters in the policy document, see Authentication rules for Container Registry.
Click Confirm. In the Create Policy dialog box, configure the Policy Name and Notes parameters.
Attach the custom policy to a RAM user.
Log on to the RAM console by using your Alibaba Cloud account.
In the left-side navigation pane, choose .
On the User page, find the RAM user to which you want to attach the custom policy, and click Add Permission in the Actions column.
In the Authorize panel, grant permissions to the RAM user.
Select the authorization scope.
Account: The permissions apply within the current Alibaba Cloud account.
resource: The permissions apply within the specified resource group.
If you select ResourceGroup for the Resource Scope parameter, make sure that the cloud service supports resource groups. For more information, see Services that work with Resource Group.
Specify a principal.
The principal is the RAM user to which you want to grant permissions. By default, the current RAM user is specified. You can also specify another RAM user.
Click Custom Policy below All Types from the drop-down list, enter a custom policy name in the search box to search for the custom policy, and then click the name of the custom policy.
Click OK.
Click Off.
Authentication rules for Container Registry
The following table describes the Alibaba Cloud Resource Name (ARN) format in an authorization policy when you use RAM to grant permissions to users.
Resource | ARN format |
repository | acs:cr:$regionid:$accountid:repository/$namespacename/$repositoryname |
The following table describes the parameters in the ARN format.
Parameter | Description |
regionid | The region ID. Use an asterisk (*) to specify all regions. |
accountid | The numeric ID of the Alibaba Cloud account. Use an asterisk (*) to specify all accounts. |
namespacename | The name of the namespace. |
repositoryname | The name of the image repository. |