Service-Linked Role

Updated at:

The service-linked role (SLR) AliyunServiceRoleForECAgent grants Elastic Compute Agent the permissions required to call other cloud services when executing scheduled tasks such as health checks and resource queries.

Common scenarios

When you create a scheduled task in Elastic Compute Agent, the system automatically creates the service-linked roleAliyunServiceRoleForECAgent for scheduled task scenarios such as GPU cluster health checks and ECS resource trend analysis. Elastic Compute Agent assumes this role to call the OpenAPIs of ECS, Cloud Monitor, Resource Center, and other services.

Role information

ItemDescription
Role nameAliyunServiceRoleForECAgent
Permission policy nameAliyunServiceRolePolicyForECAgent
Trusted cloud serviceecagent.aliyuncs.com
Applicable scenariosElastic Compute Agent scheduled tasks (health checks, resource queries, etc.)

Create a service-linked role

When you create a scheduled task in the Elastic Compute Agent console for the first time, the system automatically creates the service-linked role AliyunServiceRoleForECAgent. No manual creation is required.

To verify that the role has been created:

  1. Log on to the RAM console.

  2. Choose

    Identity Management > Roles, and search for AliyunServiceRoleForECAgent.

  3. If the role appears in the search results, the service-linked role has been successfully created.

Delete a service-linked role

If you no longer use the Scheduled Tasks feature of Elastic Compute Agent, you can delete the service-linked role AliyunServiceRoleForECAgent.

Note

Resource queries and anomaly diagnostics in sessions use the identity of the logged-in user to call APIs and do not depend on this service-linked role. These capabilities are not affected after the role is deleted.

Pre-deletion check: The system automatically checks whether any scheduled tasks exist in the current account. If scheduled tasks exist (regardless of whether they are running), the deletion is rejected with an error message. Delete all tasks on the Scheduled Tasks page in the Elastic Compute Agent console before deleting the service-linked role.

After the role is deleted, if you need to restore it, create a scheduled task in the console again. The system automatically recreates the role.

To delete the service-linked role:

  1. Log on to the Elastic Compute Agent console. In the left-side navigation pane, click Scheduled Tasks and delete all configured scheduled tasks.

  2. Log on to the RAM console.

  3. On the

    Identity Management > Roles page, search for AliyunServiceRoleForECAgent.

  4. In the Actions column, click Delete Role. The system automatically checks whether any scheduled tasks still exist in the current account. If tasks exist, the deletion fails with a prompt to clean up the scheduled tasks first.

  5. In the deletion dialog box, confirm and click Delete Role.

Permissions

The permission policy AliyunServiceRolePolicyForECAgent includes the following permissions:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ecs:CreateDiagnosticReport",
        "ecs:AcceptInquiredSystemEvent",
        "ecs:DescribeAccountAttributes",
        "ecs:DescribeActivations",
        "ecs:DescribeAutoProvisioningGroupHistory",
        "ecs:DescribeAutoProvisioningGroupInstances",
        "ecs:DescribeAutoProvisioningGroups",
        "ecs:DescribeAutoSnapshotPolicyAssociations",
        "ecs:DescribeAutoSnapshotPolicyEx",
        "ecs:DescribeAvailableResource",
        "ecs:DescribeBandwidthLimitation",
        "ecs:DescribeBandwidthPackages",
        "ecs:DescribeCapacityReservationInstances",
        "ecs:DescribeCapacityReservations",
        "ecs:DescribeClassicLinkInstances",
        "ecs:DescribeCloudAssistantSettings",
        "ecs:DescribeCloudAssistantStatus",
        "ecs:DescribeCommands",
        "ecs:DescribeDedicatedHostAutoRenew",
        "ecs:DescribeDedicatedHostClusters",
        "ecs:DescribeDedicatedHosts",
        "ecs:DescribeDedicatedHostTypes",
        "ecs:DescribeDeploymentSets",
        "ecs:DescribeDeploymentSetSupportedInstanceTypeFamily",
        "ecs:DescribeDiagnosticMetrics",
        "ecs:DescribeDiagnosticMetricSets",
        "ecs:DescribeDiagnosticReportAttributes",
        "ecs:DescribeDiagnosticReports",
        "ecs:DescribeDiskDefaultKMSKeyId",
        "ecs:DescribeDiskMonitorData",
        "ecs:DescribeDisks",
        "ecs:DescribeDisksFullStatus",
        "ecs:DescribeElasticityAssuranceAutoRenewAttribute",
        "ecs:DescribeElasticityAssuranceInstances",
        "ecs:DescribeElasticityAssurances",
        "ecs:DescribeEniMonitorData",
        "ecs:DescribeHpcClusters",
        "ecs:DescribeImageComponents",
        "ecs:DescribeImageFromFamily",
        "ecs:DescribeImagePipelineExecutions",
        "ecs:DescribeImagePipelines",
        "ecs:DescribeImages",
        "ecs:DescribeImageSharePermission",
        "ecs:DescribeImageSupportInstanceTypes",
        "ecs:DescribeInstanceAttachmentAttributes",
        "ecs:DescribeInstanceAttribute",
        "ecs:DescribeInstanceAutoRenewAttribute",
        "ecs:DescribeInstanceHistoryEvents",
        "ecs:DescribeInstanceMaintenanceAttributes",
        "ecs:DescribeInstanceModificationPrice",
        "ecs:DescribeInstanceMonitorData",
        "ecs:DescribeInstanceRamRole",
        "ecs:DescribeInstances",
        "ecs:DescribeInstancesFullStatus",
        "ecs:DescribeInstanceStatus",
        "ecs:DescribeInstanceTypeFamilies",
        "ecs:DescribeInstanceTypes",
        "ecs:DescribeInstanceVncUrl",
        "ecs:DescribeInvocationResults",
        "ecs:DescribeInvocations",
        "ecs:DescribeKeyPairs",
        "ecs:DescribeLaunchTemplates",
        "ecs:DescribeLaunchTemplateVersions",
        "ecs:DescribeLockedSnapshots",
        "ecs:DescribeManagedInstances",
        "ecs:DescribeNetworkInterfaceAttribute",
        "ecs:DescribeNetworkInterfacePermissions",
        "ecs:DescribeNetworkInterfaces",
        "ecs:DescribePlanMaintenanceWindows",
        "ecs:DescribePortRangeListAssociations",
        "ecs:DescribePortRangeListEntries",
        "ecs:DescribePortRangeLists",
        "ecs:DescribePrefixListAssociations",
        "ecs:DescribePrefixListAttributes",
        "ecs:DescribePrefixLists",
        "ecs:DescribePrice",
        "ecs:DescribeRecommendInstanceType",
        "ecs:DescribeRegions",
        "ecs:DescribeRenewalPrice",
        "ecs:DescribeReservedInstanceAutoRenewAttribute",
        "ecs:DescribeReservedInstances",
        "ecs:DescribeResourcesModification",
        "ecs:DescribeSecurityGroupAttribute",
        "ecs:DescribeSecurityGroupReferences",
        "ecs:DescribeSecurityGroups",
        "ecs:DescribeSendFileResults",
        "ecs:DescribeSnapshotGroups",
        "ecs:DescribeSnapshotLinks",
        "ecs:DescribeSnapshotMonitorData",
        "ecs:DescribeSnapshotPackage",
        "ecs:DescribeSnapshots",
        "ecs:DescribeSnapshotsUsage",
        "ecs:DescribeStorageCapacityUnits",
        "ecs:DescribeTaskAttribute",
        "ecs:DescribeTasks",
        "ecs:DescribeTerminalSessions",
        "ecs:DescribeUserData",
        "ecs:DescribeVscs",
        "ecs:DescribeZones",
        "ecs:GetInstanceConsoleOutput",
        "ecs:GetInstanceScreenshot",
        "ecs:ListPluginStatus",
        "ecs:ListTagResources",
        "ecs:ReportInstancesStatus"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "resourcecenter:ExecuteSQLQuery",
        "resourcecenter:GetResourceType"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "resourcemanager:ListResourceGroups"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ecagent:DescribeAgentService",
        "ecagent:DescribeAgentCreditUsage"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": ["appflow:InvokeAction"],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Condition": {
        "StringEquals": { "ram:ServiceName": "ecagent.aliyuncs.com" }
      }
    },
    {
      "Effect": "Allow",
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Condition": {
        "StringEquals": { "ram:ServiceName": "selfservice.ecs.aliyuncs.com" }
      }
    }
  ]
}

The last two statements grant ram:CreateServiceLinkedRole and ram:DeleteServiceLinkedRole permissions, allowing the agent to automatically create and clean up downstream service-linked roles (such as the ECS self-service role selfservice.ecs.aliyuncs.com) during scheduled task execution.

FAQ

Why can a RAM user not automatically create the service-linked role?

RAM users need the ram:CreateServiceLinkedRole permission. Contact the Alibaba Cloud account administrator to add the following access policy to the RAM user:

{
  "Version": "1",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["ram:CreateServiceLinkedRole"],
    "Resource": "acs:ram:*:*:role/*",
    "Condition": {
      "StringEquals": { "ram:ServiceName": ["ecagent.aliyuncs.com"] }
    }
  }]
}

Why does an "insufficient permissions" error appear when creating the service-linked role?

This is usually caused by missing the ram:CreateServiceLinkedRole permission. Contact the Alibaba Cloud account administrator to add the permission, or use the Alibaba Cloud account to use the scheduled task feature for the first time in the Elastic Compute Agent console, which triggers automatic creation.

Can I delete the service-linked role when scheduled tasks exist?

No. When you delete the service-linked role, the system automatically checks whether any scheduled tasks exist in the current account. If tasks exist (regardless of whether they are running), the deletion is rejected with an error message. Delete all tasks on the Scheduled Tasks page in the Elastic Compute Agent console before deleting the service-linked role.