Before a Resource Access Management (RAM) user can call an Alibaba Cloud API, the Alibaba Cloud account must grant permissions to the RAM user by creating an authorization policy.
Resource authorization
By default, RAM users cannot call Alibaba Cloud APIs to create or modify cloud resources. To grant these permissions, you must create an authorization policy and attach it to the RAM user.
When you create an authorization policy, you must specify the resources to authorize using an Aliyun Resource Name (ARN). An ARN is a globally unique name that Alibaba Cloud defines for each resource.
The ARN format is as follows:
acs:
service-name:
region:
account-id:
resource-relative-id:Where:
acs: An acronym for Alibaba Cloud Service. It indicates the Alibaba Cloud public platform.
service-name: The name of the Alibaba Cloud service, such as OceanBase, ECS, OSS, or SLB.
region: The region of the resource. If this field is not supported, use an asterisk (*) as a wildcard character.
account-id: The ID of the Alibaba Cloud account, such as 123456789***.
resource-relative-id: A description of the specific resource. The format of this description varies by Alibaba Cloud product. For more information, see the developer documentation for each product.
For example,
acs:oceanbase:cn-shanghai:123456789***:instance/obtestid**indicates an OceanBase resource where the object name isinstance/obtestid**and the owner's UID is123456789***.
Authorizable OceanBase resource types
Permissions are hierarchical. From highest to lowest, the levels are instance, tenant, and database. A higher-level permission includes all lower-level permissions.
An asterisk (*) can be used as a wildcard character to match all values in a field.
Resource type | Resource description method in an authorization policy |
INSTANCE | acs:oceanbase:{region}:{accountId}:instance/{instanceId} |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:* | |
acs:oceanbase:{region}:*:* | |
acs:oceanbase:*:*:* | |
TENANT | acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId}/* |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:* | |
acs:oceanbase:{region}:*:* | |
acs:oceanbase:*:*:* | |
DATABASE | acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId}/database/{databaseName} |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId}/database/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId}/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:* | |
acs:oceanbase:{region}:*:* | |
acs:oceanbase:*:*:* |
Authorizable OceanBase service APIs
The following tables list the authorizable APIs for the OceanBase service and how they are specified in an authorization policy:
Cluster operations
API | Resource description |
None. The result is passed to the PayOrderCallBack callback. | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* |
Tenant operations
API | Resource description |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* |
Database operations
API | Resource description |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
cs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId}/database/{databaseName} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId}/database/* | |
acs:oceanbase:{region}: {accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* |
Account operations
API | Resource description |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/{tenantId} | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId}/tenant/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* |
Parameter management
API | Resource description |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* |
Security
API | Resource description |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* | |
acs:oceanbase:{region}:{accountId}:instance/{instanceId} | |
acs:oceanbase:{region}:{accountId}:instance/* |