授权信息

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍API 网关(CloudAPI)RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。API 网关(CloudAPI)RAM代码(RamCode)为 apigateway、cloudapi,支持的授权粒度为资源级

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是API 网关(CloudAPI)定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用前面加 * 表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
apigateway:AbolishApiAbolishApiupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:AddAccessControlListEntryAddAccessControlListEntryupdate
*AccessControlList
acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/{#AclId}
apigateway:AddIpControlPolicyItemAddIpControlPolicyItemcreate
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#IpControlId}
apigateway:AddTrafficSpecialControlAddTrafficSpecialControlcreate
*TrafficControl
acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/{#TrafficControlId}
apigateway:AssociateInstanceWithPrivateDNSAssociateInstanceWithPrivateDNSupdate
*全部资源
*
apigateway:AttachApiProductAttachApiProductcreate
*全部资源
*
apigateway:AttachGroupPluginAttachGroupPluginnone
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:AttachPluginAttachPluginupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:BatchAbolishApisBatchAbolishApisupdate
*全部资源
*
apigateway:BatchDeployApisBatchDeployApisupdate
*全部资源
*
apigateway:CreateAccessControlListCreateAccessControlListcreate
*全部资源
*
apigateway:CreateApiCreateApicreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:CreateApiGroupCreateApiGroupcreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/*
apigateway:CreateApiStageVariableCreateApiStageVariablecreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:CreateAppCreateAppcreate
*App
acs:apigateway:{#regionId}:{#accountId}:app/*
apigateway:CreateAppCodeCreateAppCodecreate
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:CreateAppKeyCreateAppKeycreate
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:CreateBackendCreateBackendcreate
*全部资源
*
apigateway:CreateBackendModelCreateBackendModelcreate
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
apigateway:CreateDatasetCreateDatasetcreate
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/*
apigateway:CreateDatasetItemCreateDatasetItemcreate
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:CreateInstanceCreateInstancecreate
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/*
apigateway:CreateIpControlCreateIpControlcreate
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/*
apigateway:CreateLogConfigCreateLogConfigcreate
*全部资源
*
apigateway:CreateModelCreateModelcreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:CreateMonitorGroupCreateMonitorGroupcreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:CreatePluginCreatePlugincreate
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/*
apigateway:CreatePrivateDNSCreatePrivateDNScreate
*全部资源
*
apigateway:CreateSignatureCreateSignaturecreate
*全部资源
*
apigateway:CreateTrafficControlCreateTrafficControlcreate
*TrafficControl
acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/*
apigateway:DeleteAccessControlListDeleteAccessControlListdelete
*全部资源
*
apigateway:DeleteAllTrafficSpecialControlDeleteAllTrafficSpecialControldelete
*全部资源
*
apigateway:DeleteApiDeleteApidelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeleteApiGroupDeleteApiGroupdelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeleteApiProductDeleteApiProductdelete
*全部资源
*
apigateway:DeleteApiStageVariableDeleteApiStageVariabledelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeleteAppDeleteAppdelete
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DeleteAppCodeDeleteAppCodedelete
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DeleteAppKeyDeleteAppKeydelete
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DeleteBackendDeleteBackenddelete
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
apigateway:DeleteBackendModelDeleteBackendModeldelete
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
apigateway:DeleteDatasetDeleteDatasetdelete
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:DeleteDatasetItemDeleteDatasetItemdelete
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:DeleteDomainDeleteDomaindelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeleteDomainCertificateDeleteDomainCertificatedelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeleteInstanceDeleteInstancedelete
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DeleteIpControlDeleteIpControldelete
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#IpControlId}
apigateway:DeleteLogConfigDeleteLogConfigdelete
*LogConfig
acs:apigateway:{#regionId}:{#accountId}:logconfig/{#LogType}
apigateway:DeleteModelDeleteModeldelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeleteMonitorGroupDeleteMonitorGroupdelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DeletePluginDeletePlugindelete
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:DeletePrivateDNSDeletePrivateDNSdelete
*全部资源
*
apigateway:DeleteSignatureDeleteSignaturedelete
*全部资源
*
apigateway:DeleteTrafficControlDeleteTrafficControldelete
*TrafficControl
acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/{#TrafficControlId}
apigateway:DeleteTrafficSpecialControlDeleteTrafficSpecialControldelete
*全部资源
*
apigateway:DeployApiDeployApiget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeAbolishApiTaskDescribeAbolishApiTaskget
*全部资源
*
apigateway:DescribeAccessControlListAttributeDescribeAccessControlListAttributeget
*全部资源
*
apigateway:DescribeAccessControlListsDescribeAccessControlListsget
*全部资源
*
apigateway:DescribeApiDescribeApiget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiDocDescribeApiDocget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiGroupDescribeApiGroupget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiGroupVpcWhitelistDescribeApiGroupVpcWhitelistget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiGroupsDescribeApiGroupsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/*
apigateway:DescribeApiHistoriesDescribeApiHistoriesget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiHistoryDescribeApiHistoryget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiIpControlsDescribeApiIpControlsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiLatencyDataDescribeApiLatencyDataget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiMarketAttributesDescribeApiMarketAttributesget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiProductApisDescribeApiProductApisget
*全部资源
*
apigateway:DescribeApiProductsByAppDescribeApiProductsByAppget
*全部资源
*
apigateway:DescribeApiQpsDataDescribeApiQpsDataget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiSignaturesDescribeApiSignaturesget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiTrafficControlsDescribeApiTrafficControlsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApiTrafficDataDescribeApiTrafficDataget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApisDescribeApisget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeApisByAppDescribeApisByAppget
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DescribeApisByBackendDescribeApisByBackendget
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
apigateway:DescribeApisByIpControlDescribeApisByIpControlget
*全部资源
*
apigateway:DescribeApisBySignatureDescribeApisBySignatureget
*全部资源
*
apigateway:DescribeApisByTrafficControlDescribeApisByTrafficControlget
*全部资源
*
apigateway:DescribeApisByVpcAccessDescribeApisByVpcAccesslist
*全部资源
*
apigateway:DescribeApisWithStageNameIntegratedByAppDescribeApisWithStageNameIntegratedByAppget
*全部资源
*
apigateway:DescribeAppDescribeAppget
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DescribeAppAttributesDescribeAppAttributesget
*App
acs:apigateway:{#regionId}:{#accountId}:app/*
apigateway:DescribeAppSecuritiesDescribeAppSecuritiesget
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DescribeAppSecurityDescribeAppSecurityget
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DescribeAppsDescribeAppsget
*App
acs:apigateway:{#regionId}:{#accountId}:app/*
apigateway:DescribeAppsByApiProductDescribeAppsByApiProductget
*全部资源
*
apigateway:DescribeAuthorizedApisDescribeAuthorizedApisget
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:DescribeAuthorizedAppsDescribeAuthorizedAppsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeBackendInfoDescribeBackendInfoget
*全部资源
*
apigateway:DescribeBackendListDescribeBackendListget
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/*
apigateway:DescribeDatasetInfoDescribeDatasetInfoget
*全部资源
*
apigateway:DescribeDatasetItemInfoDescribeDatasetItemInfoget
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:DescribeDatasetItemListDescribeDatasetItemListget
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:DescribeDatasetListDescribeDatasetListget
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/*
apigateway:DescribeDeployApiTaskDescribeDeployApiTaskget
*全部资源
*
apigateway:DescribeDeployedApiDescribeDeployedApiget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeDeployedApisDescribeDeployedApisget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeDomainDescribeDomainget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeGroupLatencyDescribeGroupLatencyget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeGroupQpsDescribeGroupQpsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeGroupTrafficDescribeGroupTrafficget
*全部资源
*
apigateway:DescribeHistoryApisDescribeHistoryApisget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeImportOASTaskDescribeImportOASTaskget
*全部资源
*
apigateway:DescribeInstanceClusterInfoDescribeInstanceClusterInfoget
*全部资源
*
apigateway:DescribeInstanceClusterListDescribeInstanceClusterListlist
*全部资源
*
apigateway:DescribeInstanceDropConnectionsDescribeInstanceDropConnectionsget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceDropPacketDescribeInstanceDropPacketget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceHttpCodeDescribeInstanceHttpCodeget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceLatencyDescribeInstanceLatencyget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceNewConnectionsDescribeInstanceNewConnectionsget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstancePacketsDescribeInstancePacketsget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceQpsDescribeInstanceQpsget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceSlbConnectDescribeInstanceSlbConnectget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstanceTrafficDescribeInstanceTrafficget
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:DescribeInstancesDescribeInstancesget
*全部资源
*
apigateway:DescribeIpControlPolicyItemsDescribeIpControlPolicyItemsget
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#IpControlId}
apigateway:DescribeIpControlsDescribeIpControlsget
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/*
apigateway:DescribeLogConfigDescribeLogConfigget
*LogConfig
acs:apigateway:{#regionId}:{#accountId}:logconfig/{#LogType}
apigateway:DescribeMarketRemainsQuotaDescribeMarketRemainsQuotaget
*全部资源
*
apigateway:DescribeModelsDescribeModelsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribePluginApisDescribePluginApisget
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:DescribePluginGroupsDescribePluginGroupsget
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:DescribePluginSchemasDescribePluginSchemasget
*全部资源
*
apigateway:DescribePluginTemplatesDescribePluginTemplatesget
*全部资源
*
apigateway:DescribePluginsDescribePluginsget
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/*
apigateway:DescribePluginsByApiDescribePluginsByApiget
*全部资源
*
apigateway:DescribePluginsByGroupDescribePluginsByGroupget
*全部资源
*
apigateway:DescribePurchasedApiGroupDescribePurchasedApiGroupget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribePurchasedApiGroupsDescribePurchasedApiGroupsget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/*
apigateway:DescribePurchasedApisDescribePurchasedApisget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeSignaturesDescribeSignaturesget
*Signature
acs:apigateway:{#regionId}:{#accountId}:secretkey/*
apigateway:DescribeSignaturesByApiDescribeSignaturesByApiget
*全部资源
*
apigateway:DescribeSummaryDataDescribeSummaryDataget
*全部资源
*
apigateway:DescribeSystemParametersDescribeSystemParametersget
*全部资源
*
apigateway:DescribeTrafficControlsDescribeTrafficControlsget
*TrafficControl
acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/{#TrafficControlId}
apigateway:DescribeTrafficControlsByApiDescribeTrafficControlsByApiget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:DescribeUpdateBackendTaskDescribeUpdateBackendTaskget
*全部资源
*
apigateway:DescribeUpdateVpcInfoTaskDescribeUpdateVpcInfoTaskget
*全部资源
*
apigateway:DescribeVpcAccessesDescribeVpcAccessesget
*全部资源
*
apigateway:DetachApiProductDetachApiProductdelete
*全部资源
*
apigateway:DetachGroupPluginDetachGroupPluginnone
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:DetachPluginDetachPluginupdate
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:DisableInstanceAccessControlDisableInstanceAccessControlupdate
*AccessControlList
acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/{#AclId}
apigateway:DissociateInstanceWithPrivateDNSDissociateInstanceWithPrivateDNSupdate
*全部资源
*
apigateway:DryRunSwaggerDryRunSwaggernone
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:EnableInstanceAccessControlEnableInstanceAccessControlupdate
*AccessControlList
acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/{#AclId}
apigateway:ExportOASExportOASget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ImportOASImportOAScreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ImportSwaggerImportSwaggercreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ListPrivateDNSListPrivateDNSlist
*全部资源
*
apigateway:ListTagResourcesListTagResourcesget
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#ResourceId}
apigateway:ModifyApiModifyApiupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyApiConfigurationModifyApiConfigurationupdate
*全部资源
*
apigateway:ModifyApiGroupModifyApiGroupupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyApiGroupInstanceModifyApiGroupInstanceupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyApiGroupNetworkPolicyModifyApiGroupNetworkPolicyupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyApiGroupVpcWhitelistModifyApiGroupVpcWhitelistupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyAppModifyAppupdate
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:ModifyBackendModifyBackendupdate
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
apigateway:ModifyBackendModelModifyBackendModelupdate
*Backend
acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
apigateway:ModifyDatasetModifyDatasetupdate
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:ModifyDatasetItemModifyDatasetItemupdate
*Dataset
acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
apigateway:ModifyInstanceAttributeModifyInstanceAttributeupdate
*Instance
acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
apigateway:ModifyInstanceSpecModifyInstanceSpecupdate
*全部资源
*
apigateway:ModifyInstanceVpcAttributeForConsoleModifyInstanceVpcAttributeForConsoleupdate
*全部资源
*
apigateway:ModifyIntranetDomainPolicyModifyIntranetDomainPolicyupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyIpControlModifyIpControlupdate
*全部资源
*
apigateway:ModifyIpControlPolicyItemModifyIpControlPolicyItemupdate
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#IpControlId}
apigateway:ModifyLogConfigModifyLogConfigupdate
*全部资源
*
apigateway:ModifyModelModifyModelupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:ModifyPluginModifyPluginupdate
*Plugin
acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
apigateway:ModifySignatureModifySignatureupdate
*全部资源
*
apigateway:ModifyTrafficControlModifyTrafficControlupdate
*TrafficControl
acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/{#TrafficControlId}
apigateway:ModifyVpcAccessAndUpdateApisModifyVpcAccessAndUpdateApisupdate
*全部资源
*
apigateway:OpenApiGatewayServiceOpenApiGatewayServicenone
*全部资源
*
apigateway:QueryRequestLogsQueryRequestLogsget
*全部资源
*
apigateway:ReactivateDomainReactivateDomainupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:RemoveAccessControlListEntryRemoveAccessControlListEntryupdate
*AccessControlList
acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/{#AclId}
apigateway:RemoveApiProductsAuthoritiesRemoveApiProductsAuthoritiesdelete
*全部资源
*
apigateway:RemoveApisAuthoritiesRemoveApisAuthoritiesdelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:RemoveAppsAuthoritiesRemoveAppsAuthoritiesdelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppIds}
apigateway:RemoveIpControlApisRemoveIpControlApisdelete
*全部资源
*
apigateway:RemoveIpControlPolicyItemRemoveIpControlPolicyItemdelete
*IpControl
acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#IpControlId}
apigateway:RemoveSignatureApisRemoveSignatureApisdelete
*全部资源
*
apigateway:RemoveTrafficControlApisRemoveTrafficControlApisdelete
*全部资源
*
apigateway:RemoveVpcAccessRemoveVpcAccessdelete
*全部资源
*
apigateway:RemoveVpcAccessAndAbolishApisRemoveVpcAccessAndAbolishApisdelete
*全部资源
*
apigateway:ResetAppCodeResetAppCodeupdate
*全部资源
*
apigateway:ResetAppSecretResetAppSecretupdate
*全部资源
*
apigateway:SdkGenerateByAppSdkGenerateByAppcreate
*全部资源
*
apigateway:SdkGenerateByAppForRegionSdkGenerateByAppForRegionget
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
apigateway:SdkGenerateByGroupSdkGenerateByGroupcreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetAccessControlListAttributeSetAccessControlListAttributeupdate
*AccessControlList
acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/{#AclId}
apigateway:SetApiProductsAuthoritiesSetApiProductsAuthoritiescreate
*全部资源
*
apigateway:SetApisAuthoritiesSetApisAuthoritiesupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetAppsAuthToApiProductSetAppsAuthToApiProductcreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apiproduct/{#ApiProductId}
apigateway:SetAppsAuthoritiesSetAppsAuthoritiesupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#AppIds}
apigateway:SetDomainSetDomainupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetDomainCertificateSetDomainCertificateupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetDomainWebSocketStatusSetDomainWebSocketStatusupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetIpControlApisSetIpControlApisupdate
*全部资源
*
apigateway:SetSignatureApisSetSignatureApisupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetTrafficControlApisSetTrafficControlApisupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SetVpcAccessSetVpcAccessupdate
*Vpc
acs:apigateway:{#regionId}:{#accountId}:vpcaccess/*
apigateway:SetWildcardDomainPatternsSetWildcardDomainPatternsupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:SwitchApiSwitchApiupdate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
apigateway:TagResourcesTagResourcescreate
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#ResourceId}
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#ResourceId}
apigateway:UntagResourcesUntagResourcesdelete
*ApiGroup
acs:apigateway:{#regionId}:{#accountId}:apigroup/{#ResourceId}
*App
acs:apigateway:{#regionId}:{#accountId}:app/{#ResourceId}
apigateway:UpdatePrivateDNSUpdatePrivateDNSupdate
*全部资源
*
apigateway:ValidateVpcConnectivityValidateVpcConnectivityget
*全部资源
*

资源(Resource)

下表是API 网关(CloudAPI)定义的资源,这些资源可以在RAM权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源ARN是资源在阿里云上的唯一标识。具体说明如下:
  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。
  • *表示全部。例如:
    • {#resourceType}*时:表示全部资源。
    • {#regionId}*时:表示全部地域。
    • {#accountId}*时:表示全部阿里云账号。
资源类型资源ARN
AccessControl
  • acs:apigateway:{#regionId}:{#accountId}:accesscontrol/*
  • acs:apigateway:{#regionId}:{#accountId}:accesscontrol/{#AclId}
  • acs:cloudapi:{#regionId}:{#accountId}:accesscontrol/{#AclId}
AccessControlList
  • acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/{#AclId}
  • acs:apigateway:{#regionId}:{#accountId}:accesscontrollist/*
ApiGroup
  • acs:apigateway:{#regionId}:{#accountId}:apigroup/*
  • acs:apigateway:{#regionId}:{#accountId}:apigroup/{#GroupId}
  • acs:apigateway:{#regionId}:{#accountId}:apigroup/{#ResourceId}
  • acs:apigateway:{#regionId}:{#accountId}:apiproduct/{#ApiProductId}
  • acs:apigateway:{#Region}:{#accountId}:apigroup/{#SourceGroupId}
  • acs:apigateway:{#regionId}:{#accountId}:apigroup/{#TargetGroupId}
  • acs:apigateway::{#accountId}:apigroup/*
  • acs:apigateway:{#regionId}:{#accountId}:apigroup/{#SourceGroupId}
App
  • acs:apigateway:{#regionId}:{#accountId}:app/{#AppId}
  • acs:apigateway:{#regionId}:{#accountId}:app/*
  • acs:apigateway:{#regionId}:{#accountId}:app/{#AppIds}
  • acs:apigateway:{#regionId}:{#accountId}:app/{#ResourceId}
Backend
  • acs:apigateway:{#regionId}:{#accountId}:backend/{#BackendId}
  • acs:apigateway:{#regionId}:{#accountId}:backend/*
Dataset
  • acs:apigateway:{#regionId}:{#accountId}:dataset/{#DatasetId}
  • acs:apigateway:{#regionId}:{#accountId}:dataset/*
Instance
  • acs:apigateway:{#regionId}:{#accountId}:instance/{#InstanceId}
  • acs:apigateway:{#regionId}:{#accountId}:instance/*
  • acs:apigateway:{#Region}:{#accountId}:instance/*
IpControl
  • acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#IpControlId}
  • acs:apigateway:{#regionId}:{#accountId}:ipcontrol/{#RuleId}
  • acs:apigateway:{#regionId}:{#accountId}:ipcontrol/*
LogConfig
  • acs:apigateway:{#regionId}:{#accountId}:logconfig/*
  • acs:apigateway:{#regionId}:{#accountId}:logconfig/{#LogType}
Plugin
  • acs:apigateway:{#regionId}:{#accountId}:plugin/{#PluginId}
  • acs:apigateway:{#regionId}:{#accountId}:plugin/*
Signature
  • acs:apigateway:{#regionId}:{#accountId}:secretkey/*
  • acs:apigateway:{#regionId}:{#accountId}:signature/*
  • acs:apigateway:{#regionId}:{#accountId}:signature/{#SignatureId}
TrafficControl
  • acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/*
  • acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/{#RuleId}
  • acs:apigateway:{#regionId}:{#accountId}:trafficcontrol/{#TrafficControlId}
Vpc
  • acs:apigateway:{#regionId}:{#accountId}:vpcaccess/*
  • acs:apigateway:{#regionId}:{#accountId}:vpcaccess/{#VpcAccessId}
VpcAccess
  • acs:apigateway:{#regionId}:{#accountId}:vpcaccess/*
  • acs:apigateway:{#regionId}:{#accountId}:vpcaccess/{#VpcAccessId}

条件(Condition)

API 网关(CloudAPI)未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下: