授权信息

更新时间:
复制为 MD 格式

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 容器服务Kubernetes 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 容器服务Kubernetes 的 RAM 代码(RamCode)为 cs ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是容器服务Kubernetes定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

cs:DescribeTaskInfo DescribeTaskInfo get

*全部资源

*

cs:UpdateKMSEncryption UpdateKMSEncryption none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ListAutoRepairPolicies ListAutoRepairPolicies none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CancelClusterUpgrade CancelClusterUpgrade delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpdateUserPermissions UpdateUserPermissions none

*全部资源

*

cs:ListClusterChecks ListClusterChecks list

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterDetail DescribeClusterDetail get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DeleteClusterInspectConfig DeleteClusterInspectConfig delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DeleteKubernetesTrigger DeleteKubernetesTrigger delete

*全部资源

*

cs:DescribeClusterNodePools DescribeClusterNodePools get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeUserClusterNamespaces DescribeUserClusterNamespaces get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:MigrateCluster MigrateCluster update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:TagResources TagResources update

*全部资源

*

cs:ListClusterInspectReports ListClusterInspectReports list

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CancelComponentUpgrade CancelComponentUpgrade none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DeleteTrigger DeleteTrigger delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:PauseComponentUpgrade PauseComponentUpgrade none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CheckControlPlaneLogEnable CheckControlPlaneLogEnable get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeAutoRepairPolicy DescribeAutoRepairPolicy none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CreateClusterNodePool CreateClusterNodePool create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterResources DescribeClusterResources get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CreateAutoRepairPolicy CreateAutoRepairPolicy none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusters DescribeClusters get

*Cluster

acs:cs:*:{#accountId}:cluster/*

cs:SyncClusterNodePool SyncClusterNodePool update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UntagResources UntagResources delete

*全部资源

*

cs:DescribeNodePoolVuls DescribeNodePoolVuls get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#cluster_id}

cs:DeployPolicyInstance DeployPolicyInstance get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusterInspectReportDetail GetClusterInspectReportDetail get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ListClusterKubeconfigStates ListClusterKubeconfigStates none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:RevokeK8sClusterKubeConfig RevokeK8sClusterKubeConfig none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpdateControlPlaneLog UpdateControlPlaneLog update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:EnableCoreControlPlaneComponentsLog

cs:DescribeTrigger DescribeTrigger get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:InstallClusterAddons InstallClusterAddons create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:AddonNames

cs:DescribeClusterTasks DescribeClusterTasks get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#cluster_id}

cs:GetUpgradeStatus GetUpgradeStatus get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribePolicyGovernanceInCluster DescribePolicyGovernanceInCluster get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterAddonInstance DescribeClusterAddonInstance get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CleanClusterUserPermissions CleanClusterUserPermissions none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:QueryK8sComponentUpgradeStatus DescribeClusterAddonUpgradeStatus get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpdateNodePoolComponent UpdateNodePoolComponent update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CancelOperationPlan CancelOperationPlan delete

*全部资源

*

cs:DescribeClusterNodePoolDetail DescribeClusterNodePoolDetail get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeExternalAgent DescribeExternalAgent get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeResourcesDeleteProtection DescribeResourcesDeleteProtection get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribePolicies DescribePolicies get

*全部资源

*

cs:RunClusterCheck RunClusterCheck none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeAddons DescribeAddons get

*全部资源

*

cs:ListTagResources ListTagResources get

*全部资源

*

cs:DescribeKubernetesVersionMetadata DescribeKubernetesVersionMetadata get

*全部资源

*

cs:ListUserKubeConfigStates ListUserKubeConfigStates none

*全部资源

*

cs:DeleteTemplate DeleteTemplate delete

*全部资源

*

cs:DeleteClusterNodepool DeleteClusterNodepool delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ScanClusterVuls ScanClusterVuls update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribePolicyDetails DescribePolicyDetails get

*全部资源

*

cs:DescribeClustersForRegion DescribeClustersForRegion list

*全部资源

*

cs:ListClusterAddonInstances ListClusterAddonInstances list

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetKubernetesTrigger GetKubernetesTrigger get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ModifyClusterAddon ModifyClusterAddon update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:AddonName

cs:AddonNames

cs:ModifyClusterNodePool ModifyClusterNodePool update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CancelTask CancelTask update

*全部资源

*

cs:ModifyNodePoolNodeConfig ModifyNodePoolNodeConfig update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusterDiagnosisCheckItems GetClusterDiagnosisCheckItems get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeUserQuota DescribeUserQuota get

*全部资源

*

cs:UpdateClusterInspectConfig UpdateClusterInspectConfig update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetUserPermissions DescribeUserPermission get

*全部资源

*

cs:ListAddons ListAddons list

*全部资源

*

cs:CreateTemplate CreateTemplate create

*全部资源

*

cs:UpdateContactGroupForAlert UpdateContactGroupForAlert update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeRegions DescribeRegions get

*全部资源

*

cs:UpdateTemplate UpdateTemplate update

*全部资源

*

cs:CreateKubernetesTrigger CreateKubernetesTrigger create

*全部资源

*

cs:ResumeUpgradeCluster ResumeUpgradeCluster update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpdateResourcesDeleteProtection UpdateResourcesDeleteProtection update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ModifyClusterTags ModifyClusterTags update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterAddonMetadata DescribeClusterAddonMetadata get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:OpenAckService OpenAckService update

*全部资源

*

cs:DescribeClusterVuls DescribeClusterVuls get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:AttachInstancesToNodePool AttachInstancesToNodePool update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ListOperationPlans ListOperationPlans list

*全部资源

*

cs:GetClusterAuditProject GetClusterAuditProject get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpgradeClusterNodepool UpgradeClusterNodepool update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusters DescribeClustersV1 get

*Cluster

acs:cs:*:{#accountId}:cluster/*

cs:DescribeClusterV2UserKubeconfig DescribeClusterV2UserKubeconfig get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#clusterId}

cs:KubeConfigDurationMinutes

cs:DescribeClusterEvents DescribeClusterEvents get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DeletePolicyInstance DeletePolicyInstance delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CleanUserPermissions CleanUserPermissions none

*全部资源

*

cs:DescribePolicyInstances DescribePolicyInstances get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:PauseTask PauseTask update

*全部资源

*

cs:DescribeEventsForRegion DescribeEventsForRegion list

*全部资源

*

cs:DescribeClusterNodes DescribeClusterNodes get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpdateClusterAuditLogConfig UpdateClusterAuditLogConfig none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ResumeTask ResumeTask update

*全部资源

*

cs:DeleteClusterNodes DeleteClusterNodes delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GrantPermission GrantPermissions update

*全部资源

*

cs:StopAlert StopAlert update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeSubaccountK8sClusterUserConfig DescribeSubaccountK8sClusterUserConfig get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CreateClusterDiagnosis CreateClusterDiagnosis create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeTemplateAttribute DescribeTemplateAttribute get

*全部资源

*

cs:CreateTrigger CreateTrigger create

*全部资源

*

cs:CreateAutoscalingConfig CreateAutoscalingConfig create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:RunClusterInspect RunClusterInspect create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:RepairClusterNodePool RepairClusterNodePool update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#cluster_id}

cs:DescribeAddon DescribeAddon get

*全部资源

*

cs:ScaleClusterNodePool ScaleClusterNodePool update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusterDiagnosisResult GetClusterDiagnosisResult get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusterAddonInstance GetClusterAddonInstance get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpgradeCluster UpgradeCluster update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CheckServiceRole CheckServiceRole none

*全部资源

*

cs:ListOperationPlansForRegion ListOperationPlansForRegion none

*全部资源

*

cs:DescribeEvents DescribeEvents get

*全部资源

*

cs:ListClusterAddonInstanceResources ListClusterAddonInstanceResources list

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusterInspectConfig GetClusterInspectConfig get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:CreateClusterInspectConfig CreateClusterInspectConfig create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:GetClusterCheck GetClusterCheck list

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterLogs DescribeClusterLogs get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DeleteAutoRepairPolicy DeleteAutoRepairPolicy none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ModifyCluster ModifyCluster update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:EnableApiServerEip

cs:ApiServerEipId

cs:InstallNodePoolComponents InstallNodePoolComponents none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ModifyAutoRepairPolicy ModifyAutoRepairPolicy none

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterUserKubeconfig DescribeClusterUserKubeconfig get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:KubeConfigDurationMinutes

cs:DeleteAlertContactGroup DeleteAlertContactGroup delete

*全部资源

*

cs:UnInstallClusterAddons UnInstallClusterAddons delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:EnableAddonLogtailDs

cs:StartAlert StartAlert update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:ModifyPolicyInstance ModifyPolicyInstance update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpgradeK8sComponents UpgradeClusterAddons update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:RemoveNodePoolNodes RemoveNodePoolNodes update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeTemplates DescribeTemplates get

*全部资源

*

cs:DeleteAlertContact DeleteAlertContact delete

*全部资源

*

cs:CreateCluster CreateCluster create

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/*

cs:ClusterType

cs:ClusterSpec

cs:ClusterProfile

cs:EnableSecretEncryption

cs:EnableApiServerEip

cs:EnableAddonLogtailDs

cs:EnableCoreControlPlaneComponentsLog

cs:AddonNames

cs:EnableSNAT

cs:EnableNodePoolPublicIP

cs:DescribeClusterAttachScripts DescribeClusterAttachScripts update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:AttachInstances AttachInstances update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:FixNodePoolVuls FixNodePoolVuls update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#cluster_id}

cs:ResumeComponentUpgrade ResumeComponentUpgrade update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DeleteCluster DeleteCluster delete

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:Queryk8sComponentsUpdateVersion DescribeClusterAddonsVersion get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:UpdateK8sClusterUserConfigExpire UpdateK8sClusterUserConfigExpire update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:PauseClusterUpgrade PauseClusterUpgrade update

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribePolicyInstancesStatus DescribePolicyInstancesStatus get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

cs:DescribeClusterAddonsUpgradeStatus DescribeClusterAddonsUpgradeStatus get

*Cluster

acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}

资源(Resource)

下表是容器服务Kubernetes定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

Unrestricted
  • acs:cs:{#regionId}:{#accountId}:*
  • acs:cs:*:{#accountId}:cluster/*
Cluster
  • acs:cs:{#regionId}:{#accountId}:cluster/{#ClusterId}
  • acs:cs:*:{#accountId}:cluster/*
  • acs:cs:{#regionId}:{#accountId}:cluster/{#cluster_id}
  • acs:cs:{#regionId}:{#accountId}:cluster/*

条件(Condition)

下表是容器服务Kubernetes 定义的产品级条件关键字,这些条件关键字可以在 RAM 权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的通用条件关键字也同样适用容器服务Kubernetes

其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型

条件关键字

描述

类型

cs:EnableAddonLogtailDs 集群是否开启日志组件logtail-ds Boolean
cs:EnableApiServerEip 集群是否开启API Server公网访问 Boolean
cs:EnableSNAT 是否允许为集群专有网络配置 SNAT Boolean
cs:AddonNames 集群组件操作的对象,示例值:[\\\\\\\\\\"metrics-server\\\\\\\\\\",\\\\\\\\\\"terway-eniip\\\\\\\\\\"] Array
cs:ClusterType 集群类型 String
cs:ClusterSpec 托管版集群规格 String
cs:AddonName 集群组件名称,示例值:aliyun-acr-credential-helper,metrics-server String
cs:EnableSecretEncryption ACK集群是否开启Secret落盘加密 Boolean
cs:ClusterProfile 托管版集群子类型标识 String
cs:ApiServerEipId 集群API Server绑定的EIP实例ID,示例值:eip-2zep1n4o1ic48m3m**** String
cs:EnableNodePoolPublicIP 是否允许为集群每个节点分配一个公网 IPv4 地址 Boolean
cs:EnableCoreControlPlaneComponentsLog 集群是否开启控制面核心组件日志功能 Boolean
cs:KubeConfigDurationMinutes 集群KubeConfig凭证的有效期(分钟) Numeric

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: