授权信息

更新时间:2025-02-07 03:03:36
访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍运维安全中心(堡垒机)RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。运维安全中心(堡垒机)RAM代码(RamCode)为 yundun-bastionhost,支持的授权粒度为操作级

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是运维安全中心(堡垒机)定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用前面加 * 表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
操作API访问级别资源类型条件关键字关联操作
yundun-bastionhost:AcceptApproveCommandAcceptApproveCommand
*全部资源
*
yundun-bastionhost:AcceptOperationTicketAcceptOperationTicketupdate
*全部资源
*
yundun-bastionhost:AddDatabasesToGroupAddDatabasesToGroup
*全部资源
*
yundun-bastionhost:AddHostsToGroupAddHostsToGroupcreate
*全部资源
*
yundun-bastionhost:AddUsersToGroupAddUsersToGroupcreate
*全部资源
*
yundun-bastionhost:AttachDatabaseAccountsToUserAttachDatabaseAccountsToUser
*全部资源
*
yundun-bastionhost:AttachDatabaseAccountsToUserGroupAttachDatabaseAccountsToUserGroup
*全部资源
*
yundun-bastionhost:AttachHostAccountsToHostShareKeyAttachHostAccountsToHostShareKeyWrite
*全部资源
*
yundun-bastionhost:AttachHostAccountsToUserAttachHostAccountsToUserupdate
*全部资源
*
yundun-bastionhost:AttachHostAccountsToUserGroupAttachHostAccountsToUserGroupupdate
*全部资源
*
yundun-bastionhost:AttachHostGroupAccountsToUserAttachHostGroupAccountsToUserupdate
*全部资源
*
yundun-bastionhost:AttachHostGroupAccountsToUserGroupAttachHostGroupAccountsToUserGroupupdate
*全部资源
*
yundun-bastionhost:ConfigInstanceSecurityGroupsConfigInstanceSecurityGroupsnone
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:ConfigInstanceWhiteListConfigInstanceWhiteListupdate
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:CreateDatabaseCreateDatabase
*全部资源
*
yundun-bastionhost:CreateDatabaseAccountCreateDatabaseAccount
*全部资源
*
yundun-bastionhost:CreateExportConfigJobCreateExportConfigJobcreate
*全部资源
*
yundun-bastionhost:CreateHostCreateHostcreate
*全部资源
*
yundun-bastionhost:CreateHostAccountCreateHostAccountcreate
*全部资源
*
yundun-bastionhost:CreateHostGroupCreateHostGroupcreate
*全部资源
*
yundun-bastionhost:CreateHostShareKeyCreateHostShareKeyWrite
*全部资源
*
yundun-bastionhost:CreateNetworkDomainCreateNetworkDomaincreate
*全部资源
*
yundun-bastionhost:CreateOperationTicketCreateOperationTicketcreate
*全部资源
*
yundun-bastionhost:CreatePolicyCreatePolicy
*全部资源
*
yundun-bastionhost:CreateRuleCreateRule
*全部资源
*
yundun-bastionhost:CreateUserCreateUsercreate
*全部资源
*
yundun-bastionhost:CreateUserGroupCreateUserGroupcreate
*全部资源
*
yundun-bastionhost:CreateUserPublicKeyCreateUserPublicKeycreate
*全部资源
*
yundun-bastionhost:DeleteDatabaseDeleteDatabase
*全部资源
*
yundun-bastionhost:DeleteDatabaseAccountDeleteDatabaseAccount
*全部资源
*
yundun-bastionhost:DeleteHostDeleteHostdelete
*全部资源
*
yundun-bastionhost:DeleteHostAccountDeleteHostAccountdelete
*全部资源
*
yundun-bastionhost:DeleteHostGroupDeleteHostGroupdelete
*全部资源
*
yundun-bastionhost:DeleteHostShareKeyDeleteHostShareKeyWrite
*全部资源
*
yundun-bastionhost:DeleteNetworkDomainDeleteNetworkDomain
*全部资源
*
yundun-bastionhost:DeletePolicyDeletePolicy
*全部资源
*
yundun-bastionhost:DeleteRuleDeleteRule
*全部资源
*
yundun-bastionhost:DeleteUserDeleteUserdelete
*全部资源
*
yundun-bastionhost:DeleteUserGroupDeleteUserGroupdelete
*全部资源
*
yundun-bastionhost:DeleteUserPublicKeyDeleteUserPublicKeydelete
*全部资源
*
yundun-bastionhost:DescribeInstanceAttributeDescribeInstanceAttributeget
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:DescribeInstanceBastionhostDescribeInstancesget
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:DetachDatabaseAccountsFromUserDetachDatabaseAccountsFromUser
*全部资源
*
yundun-bastionhost:DetachDatabaseAccountsFromUserGroupDetachDatabaseAccountsFromUserGroup
*全部资源
*
yundun-bastionhost:DetachHostAccountsFromHostShareKeyDetachHostAccountsFromHostShareKeyWrite
*全部资源
*
yundun-bastionhost:DetachHostAccountsFromUserDetachHostAccountsFromUserupdate
*全部资源
*
yundun-bastionhost:DetachHostAccountsFromUserGroupDetachHostAccountsFromUserGroupupdate
*全部资源
*
yundun-bastionhost:DetachHostGroupAccountsFromUserDetachHostGroupAccountsFromUserupdate
*全部资源
*
yundun-bastionhost:DetachHostGroupAccountsFromUserGroupDetachHostGroupAccountsFromUserGroupupdate
*全部资源
*
yundun-bastionhost:DisableInstancePublicAccessDisableInstancePublicAccessupdate
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:DisableRuleDisableRule
*全部资源
*
yundun-bastionhost:EnableInstancePublicAccessEnableInstancePublicAccessupdate
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:EnableRuleEnableRule
*全部资源
*
yundun-bastionhost:GenerateAssetOperationTokenGenerateAssetOperationTokencreate
*全部资源
*
yundun-bastionhost:GetDatabaseGetDatabase
*全部资源
*
yundun-bastionhost:GetDatabaseAccountGetDatabaseAccount
*全部资源
*
yundun-bastionhost:GetExportConfigJobGetExportConfigJobget
*全部资源
*
yundun-bastionhost:GetHostGetHostget
*全部资源
*
yundun-bastionhost:GetHostAccountGetHostAccountget
*全部资源
*
yundun-bastionhost:GetHostGroupGetHostGroupget
*全部资源
*
yundun-bastionhost:GetHostShareKeyGetHostShareKeyget
*全部资源
*
yundun-bastionhost:GetInstanceADAuthServerGetInstanceADAuthServerget
*全部资源
*
yundun-bastionhost:GetInstanceLDAPAuthServerGetInstanceLDAPAuthServerget
*全部资源
*
yundun-bastionhost:GetInstanceStoreInfoGetInstanceStoreInfoget
*全部资源
*
yundun-bastionhost:GetInstanceTwoFactorGetInstanceTwoFactorget
*全部资源
*
yundun-bastionhost:GetNetworkDomainGetNetworkDomainget
*全部资源
*
yundun-bastionhost:GetPolicyGetPolicy
*全部资源
*
yundun-bastionhost:GetPolicyAssetScopeGetPolicyAssetScope
*全部资源
*
yundun-bastionhost:GetPolicyUserScopeGetPolicyUserScope
*全部资源
*
yundun-bastionhost:GetRuleGetRule
*全部资源
*
yundun-bastionhost:GetUserGetUserget
*全部资源
*
yundun-bastionhost:GetUserGroupGetUserGroupget
*全部资源
*
yundun-bastionhost:ListApproveCommandsListApproveCommandsget
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:ListDatabaseAccountsListDatabaseAccounts
*全部资源
*
yundun-bastionhost:ListDatabaseAccountsForUserListDatabaseAccountsForUser
*全部资源
*
yundun-bastionhost:ListDatabaseAccountsForUserGroupListDatabaseAccountsForUserGroup
*全部资源
*
yundun-bastionhost:ListDatabasesListDatabases
*全部资源
*
yundun-bastionhost:ListDatabasesForUserListDatabasesForUser
*全部资源
*
yundun-bastionhost:ListDatabasesForUserGroupListDatabasesForUserGroup
*全部资源
*
yundun-bastionhost:ListHostAccountsListHostAccountsget
*全部资源
*
yundun-bastionhost:ListHostAccountsForHostShareKeyListHostAccountsForHostShareKeyget
*全部资源
*
yundun-bastionhost:ListHostAccountsForUserListHostAccountsForUserget
*全部资源
*
yundun-bastionhost:ListHostAccountsForUserGroupListHostAccountsForUserGroupget
*全部资源
*
yundun-bastionhost:ListHostGroupAccountNamesForUserListHostGroupAccountNamesForUserget
*全部资源
*
yundun-bastionhost:ListHostGroupAccountNamesForUserGroupListHostGroupAccountNamesForUserGroupget
*全部资源
*
yundun-bastionhost:ListHostGroupsListHostGroupsget
*全部资源
*
yundun-bastionhost:ListHostGroupsForUserListHostGroupsForUserget
*全部资源
*
yundun-bastionhost:ListHostGroupsForUserGroupListHostGroupsForUserGroupget
*全部资源
*
yundun-bastionhost:ListHostShareKeysListHostShareKeyslist
*全部资源
*
yundun-bastionhost:ListHostsListHostsget
*全部资源
*
yundun-bastionhost:ListHostsForUserListHostsForUserget
*全部资源
*
yundun-bastionhost:ListHostsForUserGroupListHostsForUserGroupget
*全部资源
*
yundun-bastionhost:ListNetworkDomainsListNetworkDomainslist
*全部资源
*
yundun-bastionhost:ListOperationDatabaseAccountsListOperationDatabaseAccounts
*全部资源
*
yundun-bastionhost:ListOperationDatabasesListOperationDatabaseslist
*全部资源
*
yundun-bastionhost:ListOperationHostAccountsListOperationHostAccounts
*全部资源
*
yundun-bastionhost:ListOperationHostsListOperationHostslist
*全部资源
*
yundun-bastionhost:ListOperationTicketsListOperationTicketslist
*全部资源
*
yundun-bastionhost:ListPoliciesListPolicies
*全部资源
*
yundun-bastionhost:ListRulesListRules
*全部资源
*
yundun-bastionhost:ListTagKeysListTagKeysget
*全部资源
*
yundun-bastionhost:ListTagResourcesListTagResourcesget
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:ListUserGroupsListUserGroupsget
*全部资源
*
yundun-bastionhost:ListUserPublicKeysListUserPublicKeysget
*全部资源
*
yundun-bastionhost:ListUsersListUsersget
*全部资源
*
yundun-bastionhost:LockUsersLockUsersWrite
*全部资源
*
yundun-bastionhost:ModifyDatabaseModifyDatabase
*全部资源
*
yundun-bastionhost:ModifyDatabaseAccountModifyDatabaseAccount
*全部资源
*
yundun-bastionhost:ModifyHostModifyHostupdate
*全部资源
*
yundun-bastionhost:ModifyHostAccountModifyHostAccountupdate
*全部资源
*
yundun-bastionhost:ModifyHostGroupModifyHostGroupupdate
*全部资源
*
yundun-bastionhost:ModifyHostShareKeyModifyHostShareKeyWrite
*全部资源
*
yundun-bastionhost:ModifyHostsActiveAddressTypeModifyHostsActiveAddressTypeupdate
*全部资源
*
yundun-bastionhost:ModifyHostsPortModifyHostsPortupdate
*全部资源
*
yundun-bastionhost:ModifyInstanceADAuthServerModifyInstanceADAuthServerWrite
*全部资源
*
yundun-bastionhost:ModifyInstanceAttributeModifyInstanceAttributeupdate
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:ModifyInstanceLDAPAuthServerModifyInstanceLDAPAuthServerWrite
*全部资源
*
yundun-bastionhost:ModifyInstanceTwoFactorModifyInstanceTwoFactorWrite
*全部资源
*
yundun-bastionhost:ModifyNetworkDomainModifyNetworkDomainupdate
*全部资源
*
yundun-bastionhost:ModifyPolicyModifyPolicy
*全部资源
*
yundun-bastionhost:ModifyRuleModifyRule
*全部资源
*
yundun-bastionhost:ModifyUserModifyUserupdate
*全部资源
*
yundun-bastionhost:ModifyUserGroupModifyUserGroupupdate
*全部资源
*
yundun-bastionhost:ModifyUserPublicKeyModifyUserPublicKeyWrite
*全部资源
*
yundun-bastionhost:MoveDatabasesToNetworkDomainMoveDatabasesToNetworkDomain
*全部资源
*
yundun-bastionhost:MoveHostsToNetworkDomainMoveHostsToNetworkDomain
*全部资源
*
yundun-bastionhost:MoveResourceGroupMoveResourceGroupupdate
*全部资源
*
yundun-bastionhost:RejectApproveCommandRejectApproveCommand
*全部资源
*
yundun-bastionhost:RejectOperationTicketRejectOperationTicketupdate
*全部资源
*
yundun-bastionhost:RemoveDatabasesFromGroupRemoveDatabasesFromGroup
*全部资源
*
yundun-bastionhost:RemoveHostsFromGroupRemoveHostsFromGroupdelete
*全部资源
*
yundun-bastionhost:RemoveUsersFromGroupRemoveUsersFromGroupdelete
*全部资源
*
yundun-bastionhost:RenewAssetOperationTokenRenewAssetOperationToken
*全部资源
*
yundun-bastionhost:ResetHostAccountCredentialResetHostAccountCredentialupdate
*全部资源
*
yundun-bastionhost:SetPolicyAccessTimeRangeConfigSetPolicyAccessTimeRangeConfig
*全部资源
*
yundun-bastionhost:SetPolicyApprovalConfigSetPolicyApprovalConfig
*全部资源
*
yundun-bastionhost:SetPolicyAssetScopeSetPolicyAssetScope
*全部资源
*
yundun-bastionhost:SetPolicyCommandConfigSetPolicyCommandConfig
*全部资源
*
yundun-bastionhost:SetPolicyIPAclConfigSetPolicyIPAclConfig
*全部资源
*
yundun-bastionhost:SetPolicyProtocolConfigSetPolicyProtocolConfig
*全部资源
*
yundun-bastionhost:SetPolicyUserScopeSetPolicyUserScope
*全部资源
*
yundun-bastionhost:StartInstanceStartInstanceupdate
*Instance
acs:yundun-bastionhost:{#regionId}:{#accountId}:instance/{#InstanceId}
yundun-bastionhost:TagResourcesTagResourcesWrite
*全部资源
*
yundun-bastionhost:UnlockUsersUnlockUsersWrite
*全部资源
*
yundun-bastionhost:UntagResourcesUntagResourcesnone
*全部资源
*

资源(Resource)

运维安全中心(堡垒机)不支持在RAM权限策略语句的Resource中指定资源ARN。如果要允许对运维安全中心(堡垒机)的访问权限,请在策略语句中指定"Resource": "*"

条件(Condition)

运维安全中心(堡垒机)未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下:
  • 本页导读 (1)
  • 权限策略通用结构
  • 操作(Action)
  • 资源(Resource)
  • 条件(Condition)
  • 相关操作
AI助理

点击开启售前

在线咨询服务

你好,我是AI助理

可以解答问题、推荐解决方案等