Service-linked role for the Tag service

更新时间:
复制 MD 格式

The Tag service provides a service-linked role that enables cross-service authorized access. You can create, view, and delete this role as needed.

Overview

A service-linked role is a RAM role whose trusted entity is an Alibaba Cloud service, enabling authorized access across services. The following table lists the service-linked role provided by the Tag service.

Service-linked role for Tag

Service identifier

Permission policy

AliyunServiceRoleForTag

tag.aliyuncs.com

AliyunServiceRolePolicyForTag

For more information, see Service-linked roles.

Scenarios

  • The Tag service assumes this role to access resource creation events in ActionTrail, obtain resource creator information, and add createdby tags to resources.

  • The Tag service assumes this role to access operation records and resources in ActionTrail and Cloud Config, monitor resource changes in real time, and check the compliance of resource configurations such as tags.

Create the service-linked role

The Tag service automatically creates the service-linked role when you perform the following operations:

View information about the service-linked role

After the service-linked role is created, you can view its details in the RAM console. Go to the Roles page, find the role, and click its name.

  • Basic information

    On the role details page, the Basic Information section displays the role's name, creation time, ARN, and description.

  • Permission policy

    On the role details page, on the Permissions tab, click the policy name to view the policy content.

    Note

    You can view the permission policy of a service-linked role only from the role's details page. You cannot view the policy directly from the Permission Policy page in the RAM console.

  • Trust policy

    On the Trust Policy tab, you can view the trust policy attached to the role. A trust policy specifies which entities can assume the RAM role. For a service-linked role, the trusted entity is a cloud service. Check the Service field to identify the trusted entity.

For more information, see View a RAM role.

Delete the service-linked role

Warning

After the service-linked role is deleted, the features that depend on the role cannot be used. Proceed with caution.

If you do not use the Tag service for a long period of time or you want to delete your Alibaba Cloud account, you may need to manually delete the service-linked role.

To delete the service-linked role, you can submit a ticket.