授权信息

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 云企业网 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 云企业网 的 RAM 代码(RamCode)为 cen ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是云企业网定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

cen:DescribeTransitRouteTableAggregationDetail DescribeTransitRouteTableAggregationDetail get

*全部资源

*

cen:ListTransitRouterPeerAttachments ListTransitRouterPeerAttachments get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/*

TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:CreateCenBandwidthPackage CreateCenBandwidthPackage create

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/*

cen:ListTransitRouterMulticastDomains ListTransitRouterMulticastDomains list

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/*

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:UpdateTrafficMarkingPolicyAttribute UpdateTrafficMarkingPolicyAttribute update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#CenId}

cen:ListTransitRouterVbrAttachments ListTransitRouterVbrAttachments list

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouterVbrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/*

TransitRouterVbrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:AssociateCenBandwidthPackage AssociateCenBandwidthPackage create

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:GrantInstanceToTransitRouter GrantInstanceToTransitRouter create

*全部资源

*

cen:DescribeCenVbrHealthCheck DescribeCenVbrHealthCheck get

*全部资源

*

cen:RegisterTransitRouterMulticastGroupMembers RegisterTransitRouterMulticastGroupMembers create

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:DescribeGrantRulesToResource DescribeGrantRulesToResource get

*VPC

acs:vpc:*:{#accountId}:vpc/{#VpcId}

cen:DeleteCenBandwidthPackage DeleteCenBandwidthPackage delete

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

cen:CreateCen CreateCen create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/*

cen:CreateTransitRouteTableAggregation CreateTransitRouteTableAggregation create

*全部资源

*

cen:ListTrafficMarkingPolicies ListTrafficMarkingPolicies list

*全部资源

*

cen:ModifyTrafficMatchRuleToTrafficMarkingPolicy ModifyTrafficMatchRuleToTrafficMarkingPolicy update

*全部资源

*

cen:DeleteTransitRouterVpnAttachment DeleteTransitRouterVpnAttachment delete

*TransitRouterVpnAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:AssociateTransitRouterMulticastDomain AssociateTransitRouterMulticastDomain update

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:ListCenInterRegionTrafficQosQueues ListCenInterRegionTrafficQosQueues get

*全部资源

*

cen:CreateTransitRouterVpnAttachment CreateTransitRouterVpnAttachment create

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}

cen:AssociateTransitRouterAttachmentWithRouteTable AssociateTransitRouterAttachmentWithRouteTable create

*TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:RevokeInstanceFromTransitRouter RevokeInstanceFromTransitRouter delete

*全部资源

*

cen:DeleteTransitRouterCidr DeleteTransitRouterCidr delete

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:UpdateTransitRouterRouteTable UpdateTransitRouterRouteTable update

*TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}

cen:TempUpgradeCenBandwidthPackageSpec TempUpgradeCenBandwidthPackageSpec update

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

cen:CreateTransitRouterPeerAttachment CreateTransitRouterPeerAttachment create

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}

cen:AddTraficMatchRuleToTrafficMarkingPolicy AddTraficMatchRuleToTrafficMarkingPolicy create

*全部资源

*

cen:DeleteTransitRouteTableAggregation DeleteTransitRouteTableAggregation delete

*全部资源

*

cen:CreateTransitRouterVpcAttachment CreateTransitRouterVpcAttachment create

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}

cen:DetachCenChildInstance DetachCenChildInstance update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*virtualborderrouter

acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}

*VPC

acs:vpc:*:{#accountId}:vpc/{#vpcId}

cen:DescribeFlowlogs DescribeFlowlogs get

*Flowlog

acs:cbn:{#regionId}:{#accountId}:flowlog/*

*Flowlog

acs:cbn:{#regionId}:{#accountId}:flowlog/{#FlowLogId}

cen:CreateCenInterRegionTrafficQosPolicy CreateCenInterRegionTrafficQosPolicy create

*全部资源

*

cen:OpenTransitRouterService OpenTransitRouterService none

*全部资源

*

cen:DescribeTransitRouteTableAggregation DescribeTransitRouteTableAggregation get

*全部资源

*

cen:DeleteTransitRouterRouteTable DeleteTransitRouterRouteTable delete

*TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}

cen:CreateTransitRouterRouteEntry CreateTransitRouterRouteEntry create

*TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}

cen:CreateCenRouteMap CreateCenRouteMap create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DeleteTransitRouterVbrAttachment DeleteTransitRouterVbrAttachment delete

*TransitRouterVbrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:ListCenChildInstanceRouteEntriesToAttachment ListCenChildInstanceRouteEntriesToAttachment get

*TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:DeleteCenInterRegionTrafficQosQueue DeleteCenInterRegionTrafficQosQueue delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#CenId}

cen:CreateCenChildInstanceRouteEntryToCen CreateCenChildInstanceRouteEntryToCen create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTagResources ListTagResources get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTransitRouters ListTransitRouters get

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/*

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:UpdateTransitRouter UpdateTransitRouter update

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:ListTransitRouterCidr ListTransitRouterCidr get

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:DescribeGrantRulesToCen DescribeGrantRulesToCen get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:CreateTransitRouterRouteTable CreateTransitRouterRouteTable create

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/*

cen:UpdateTransitRouterVpcAttachmentZones UpdateTransitRouterVpcAttachmentZones update

*TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:PublishRouteEntries PublishRouteEntries update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*virtualborderrouter

acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}

*VPC

acs:vpc:*:{#accountId}:vpc/{#vpcId}

cen:CreateTransitRouterMulticastDomain CreateTransitRouterMulticastDomain create

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/*

cen:CreateCenChildInstanceRouteEntryToAttachment CreateCenChildInstanceRouteEntryToAttachment create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:UpdateTransitRouterEcrAttachmentAttribute UpdateTransitRouterEcrAttachmentAttribute update

*TransitRouterEcrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}

cen:DeleteTransitRouterVpcAttachment DeleteTransitRouterVpcAttachment delete

*TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:CreateTransitRouterPrefixListAssociation CreateTransitRouterPrefixListAssociation create

*全部资源

*

cen:DeregisterTransitRouterMulticastGroupMembers DeregisterTransitRouterMulticastGroupMembers delete

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:UpdateTransitRouterRouteEntry UpdateTransitRouterRouteEntry update

*TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}

cen:CreateFlowlog CreateFlowlog create

*全部资源

*

cen:ListTransitRouterMulticastDomainAssociations ListTransitRouterMulticastDomainAssociations get

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:UpdateTransitRouterVbrAttachmentAttribute UpdateTransitRouterVbrAttachmentAttribute update

*TransitRouterVbrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:DescribeCenPrivateZoneRoutes DescribeCenPrivateZoneRoutes get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DisassociateTransitRouterMulticastDomain DisassociateTransitRouterMulticastDomain delete

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:DisableTransitRouterRouteTablePropagation DisableTransitRouterRouteTablePropagation update

*TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:UnroutePrivateZoneInCenToVpc UnroutePrivateZoneInCenToVpc delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTransitRouterRouteTables ListTransitRouterRouteTables get

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/*

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:DeleteTransitRouterRouteEntry DeleteTransitRouterRouteEntry delete

TransitRouterRouteEntry

acs:cen:*:{#accountId}:centransitrouterroutentry/{#centransitrouterroutentryId}

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutentry/{#transitrouterroutetableId}

cen:ReplaceTransitRouterRouteTableAssociation ReplaceTransitRouterRouteTableAssociation update

*TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:CheckTransitRouterService CheckTransitRouterService none

*全部资源

*

cen:DeleteCenRouteMap DeleteCenRouteMap delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:UntagResources UntagResources update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DescribeCens DescribeCens get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/*

cen:CreateTransitRouterEcrAttachment CreateTransitRouterEcrAttachment create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}

cen:UpdateCenInterRegionTrafficQosQueueAttribute UpdateCenInterRegionTrafficQosQueueAttribute update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#CenId}

cen:DescribeCenChildInstanceRouteEntries DescribeCenChildInstanceRouteEntries get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTransitRouterVpcAttachments ListTransitRouterVpcAttachments list

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/*

TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:DeleteTrafficMarkingPolicy DeleteTrafficMarkingPolicy delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#CenId}

cen:DeleteTransitRouterPeerAttachment DeleteTransitRouterPeerAttachment delete

*TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:ModifyCenBandwidthPackageSpec ModifyCenBandwidthPackageSpec update

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

cen:DeleteTransitRouterMulticastDomain DeleteTransitRouterMulticastDomain delete

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:CreateCenInterRegionTrafficQosQueue CreateCenInterRegionTrafficQosQueue create

*全部资源

*

cen:DeleteFlowlog DeleteFlowlog delete

*Flowlog

acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}

cen:ListTransitRouterMulticastDomainVSwitches ListTransitRouterMulticastDomainVSwitches get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DeregisterTransitRouterMulticastGroupSources DeregisterTransitRouterMulticastGroupSources delete

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:CreateTransitRouter CreateTransitRouter create

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/*

cen:MoveResourceGroup MoveResourceGroup update

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:CreateTrafficMarkingPolicy CreateTrafficMarkingPolicy create

*全部资源

*

cen:UpdateCenInterRegionTrafficQosPolicyAttribute UpdateCenInterRegionTrafficQosPolicyAttribute update

*全部资源

*

cen:DescribeCenGeographicSpanRemainingBandwidth DescribeCenGeographicSpanRemainingBandwidth get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DescribeRouteServicesInCen DescribeRouteServicesInCen get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DeleteRouteServiceInCen DeleteRouteServiceInCen delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:EnableTransitRouterRouteTablePropagation EnableTransitRouterRouteTablePropagation update

*TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:ListTransitRouterMulticastGroups ListTransitRouterMulticastGroups get

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:CreateTransitRouterCidr CreateTransitRouterCidr create

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:RefreshTransitRouteTableAggregation RefreshTransitRouteTableAggregation update

*全部资源

*

cen:DescribePublishedRouteEntries DescribePublishedRouteEntries get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*virtualborderrouter

acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}

*VPC

acs:vpc:*:{#accountId}:vpc/{#vpcId}

cen:DescribeRouteConflict DescribeRouteConflict get

*VPC

acs:vpc:*:{#accountId}:vpc/{#vpcId}

cen:ListTransitRouterRouteTableAssociations ListTransitRouterRouteTableAssociations get

TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}

cen:ListGrantVSwitchesToCen ListGrantVSwitchesToCen get

*全部资源

*

cen:ModifyCenBandwidthPackageAttribute ModifyCenBandwidthPackageAttribute update

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

cen:DeleteCenChildInstanceRouteEntryToCen DeleteCenChildInstanceRouteEntryToCen delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTransitRouterCidrAllocation ListTransitRouterCidrAllocation get

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:DeleteCen DeleteCen delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTransitRouterRouteEntries ListTransitRouterRouteEntries get

TransitRouterRouteEntry

acs:cen:*:{#accountId}:centransitrouterroutentry/{#centransitrouterroutentryId}

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}

TransitRouterRouteEntry

acs:cen:*:{#accountId}:centransitrouterroutentry/*

cen:DeleteTransitRouterEcrAttachment DeleteTransitRouterEcrAttachment delete

*TransitRouterEcrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}

cen:DescribeCenAttachedChildInstances DescribeCenAttachedChildInstances get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:AttachCenChildInstance AttachCenChildInstance update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*virtualborderrouter

acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}

*VPC

acs:vpc:*:{#accountId}:vpc/{#vpcId}

cen:WithdrawPublishedRouteEntries WithdrawPublishedRouteEntries update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*VPC

acs:vpc:*:{#accountId}:vpc/{#vpcId}

cen:DescribeCenInterRegionBandwidthLimits DescribeCenInterRegionBandwidthLimits get

CenInstance

acs:cen:*:{#accountId}:ceninstance/*

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ModifyFlowLogAttribute ModifyFlowLogAttribute update

*Flowlog

acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}

cen:ModifyTransitRouterCidr ModifyTransitRouterCidr update

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:ListTransitRouterVpnAttachments ListTransitRouterVpnAttachments list

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouterVpnAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/*

TransitRouterVpnAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:RegisterTransitRouterMulticastGroupSources RegisterTransitRouterMulticastGroupSources create

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}

cen:DescribeCenRegionDomainRouteEntries DescribeCenRegionDomainRouteEntries get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:RemoveTrafficMatchRuleFromTrafficMarkingPolicy RemoveTrafficMatchRuleFromTrafficMarkingPolicy update

*全部资源

*

cen:DeleteCenChildInstanceRouteEntryToAttachment DeleteCenChildInstanceRouteEntryToAttachment delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:UpdateTransitRouterVpcAttachmentAttribute UpdateTransitRouterVpcAttachmentAttribute update

*TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:DeleteCenInterRegionTrafficQosPolicy DeleteCenInterRegionTrafficQosPolicy delete

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#CenId}

cen:DescribeCenAttachedChildInstanceAttribute DescribeCenAttachedChildInstanceAttribute get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:UpdateTransitRouterPeerAttachmentAttribute UpdateTransitRouterPeerAttachmentAttribute update

*TransitRouterPeerAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:SetCenInterRegionBandwidthLimit SetCenInterRegionBandwidthLimit update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DeactiveFlowLog DeactiveFlowLog update

*Flowlog

acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}

cen:DescribeCenRouteMaps DescribeCenRouteMaps get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ListTransitRouterRouteTablePropagations ListTransitRouterRouteTablePropagations get

TransitRouterPeerAttachment

acs:cen:*:{#accountid}:centransitrouterattachment/{#TransitRouterAttachmentId}

TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}

cen:CreateTransitRouterVbrAttachment CreateTransitRouterVbrAttachment create

CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}

cen:DeleteTransitRouterPrefixListAssociation DeleteTransitRouterPrefixListAssociation delete

*全部资源

*

cen:ActiveFlowLog ActiveFlowLog update

*Flowlog

acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}

cen:EnableCenVbrHealthCheck EnableCenVbrHealthCheck update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*virtualborderrouter

acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}

cen:ModifyCenAttribute ModifyCenAttribute update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DeleteTransitRouter DeleteTransitRouter delete

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

cen:DescribeCenBandwidthPackages DescribeCenBandwidthPackages get

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/*

cen:ListGrantVSwitchEnis ListGrantVSwitchEnis get

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:UpdateTransitRouterVpnAttachmentAttribute UpdateTransitRouterVpnAttachmentAttribute update

*TransitRouterVpnAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:ListTransitRouterEcrAttachments ListTransitRouterEcrAttachments list

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*TransitRouterEcrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/*

TransitRouterEcrAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}

cen:ListCenInterRegionTrafficQosPolicies ListCenInterRegionTrafficQosPolicies list

*全部资源

*

cen:DissociateTransitRouterAttachmentFromRouteTable DissociateTransitRouterAttachmentFromRouteTable delete

*TransitRouterVpcAttachment

acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}

cen:ResolveAndRouteServiceInCen ResolveAndRouteServiceInCen create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ModifyCenRouteMap ModifyCenRouteMap update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:DisableCenVbrHealthCheck DisableCenVbrHealthCheck update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

*virtualborderrouter

acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}

cen:ListTransitRouterPrefixListAssociation ListTransitRouterPrefixListAssociation get

*TransitRouterRouteTable

acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}

cen:UnassociateCenBandwidthPackage UnassociateCenBandwidthPackage delete

*CenBandwidthPackage

acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ModifyTransitRouteTableAggregation ModifyTransitRouteTableAggregation create

*全部资源

*

cen:RemoveTraficMatchRuleFromTrafficMarkingPolicy RemoveTraficMatchRuleFromTrafficMarkingPolicy delete

*全部资源

*

cen:TagResources TagResources update

*全部资源

*

cen:RoutePrivateZoneInCenToVpc RoutePrivateZoneInCenToVpc create

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

cen:ModifyTransitRouterMulticastDomain ModifyTransitRouterMulticastDomain update

*TransitRouterMulticastDomain

acs:cen:*:{#accountId}:centransitroutermulticast/{#TransitRouterMulticastDomainId}

cen:AddTrafficMatchRuleToTrafficMarkingPolicy AddTrafficMatchRuleToTrafficMarkingPolicy create

*全部资源

*

资源(Resource)

下表是云企业网定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

TransitRouterRouteTable
  • acs:cen:*:{#accountId}:centransitrouterroutetable/{#transitrouterroutetableId}
  • acs:cen:*:{#accountId}:transitrouterroutetable/{#TransitRouteTableId}
  • acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
  • acs:cen:*:{#accountId}:transitrouterroutetable/{#TransitRouterRouteTableId}
  • acs:cen:*:{#accountId}:centransitrouterroutetable/*
  • acs:cen:*:{#accountId}:centransitrouterroutentry/{#transitrouterroutetableId}
TransitRouterRouteEntry
  • acs:cen:*:{#accountId}:centransitrouterroutentry/*
  • acs:cen:*:{#accountId}:transitrouterrouteentry/*
  • acs:cen:*:{#accountId}:transitrouterrouteentry/{#TransitRouterRouteEntryId}
  • acs:cen:*:{#accountId}:centransitrouterroutentry/{#centransitrouterroutentryId}
CenInstance
  • acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
  • acs:cen:*:{#accountId}:ceninstance/{#CenId}
  • acs:cen:*:{#accountId}:ceninstance/*
TransitRouterPeerAttachment
  • acs:cen:*:{#accountId}:centransitrouterattachment/*
  • acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
  • acs:cen:*:{#accountid}:centransitrouterattachment/{#TransitRouterAttachmentId}
CenBandwidthPackage
  • acs:cen:*:{#accountId}:cenbandwidthpackage/*
  • acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
TransitRouterMulticastDomain
  • acs:cen:*:{#accountId}:centransitroutermulticast/*
  • acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
  • acs:cen:*:{#accountId}:centransitroutermulticast/{#TransitRouterMulticastDomainId}
TransitRouterVbrAttachment
  • acs:cen:*:{#accountId}:centransitrouterattachment/*
  • acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
virtualborderrouter
  • acs:vpc:*:{#accountId}:virtualborderrouter/*
  • acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
VPC
  • acs:vpc:*:{#accountId}:vpc/{#VpcId}
TransitRouterVpnAttachment
  • acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
  • acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouter
  • acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
  • acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
  • acs:cen:*:{#accountId}:centransitrouter/*
Flowlog
  • acs:cbn:{#regionId}:{#accountId}:flowlog/*
  • acs:cbn:{#regionId}:{#accountId}:flowlog/{#FlowLogId}
TransitRouterVpcAttachment
  • acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
  • acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterEcrAttachment
  • acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
  • acs:cen:*:{#accountId}:centransitrouterattachment/*

条件(Condition)

云企业网未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: