授权信息

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 云企业网 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 云企业网 的 RAM 代码(RamCode)为 cen ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是云企业网定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

cen:DeregisterTransitRouterMulticastGroupMembers DeregisterTransitRouterMulticastGroupMembers delete
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:ListCenInterRegionTrafficQosPolicies ListCenInterRegionTrafficQosPolicies list
*全部资源
*
cen:CreateFlowlog CreateFlowlog create
*全部资源
*
cen:ListTransitRouterRouteTableAssociations ListTransitRouterRouteTableAssociations get
TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}
cen:CreateTransitRouterRouteEntry CreateTransitRouterRouteEntry create
*TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
cen:ReplaceTransitRouterRouteTableAssociation ReplaceTransitRouterRouteTableAssociation update
*TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DeleteTransitRouterCcnAttachment DeleteTransitRouterCcnAttachment delete
*全部资源
*
cen:DescribeTransitRouteTableAggregationDetail DescribeTransitRouteTableAggregationDetail get
*全部资源
*
cen:ListTransitRouterVpnAttachments ListTransitRouterVpnAttachments list
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouterVpnAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterVpnAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DisableCenVpcFlowStatistic DisableCenVpcFlowStatistic
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:RevokeInstanceFromTransitRouter RevokeInstanceFromTransitRouter delete
*全部资源
*
cen:DissociateTransitRouterAttachmentFromRouteTable DissociateTransitRouterAttachmentFromRouteTable delete
*TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:UpdateCenInterRegionTrafficQosPolicyAttribute UpdateCenInterRegionTrafficQosPolicyAttribute update
*全部资源
*
cen:ModifyCenRouteMap ModifyCenRouteMap update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DeleteTransitRouterConnectPeer DeleteTransitRouterConnectPeer delete
*全部资源
*
cen:DeactiveFlowLog DeactiveFlowLog update
*Flowlog
acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}
cen:UpdateTransitRouterRouteTable UpdateTransitRouterRouteTable update
*TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
cen:DeleteCenChildInstanceRouteEntryToAttachment DeleteCenChildInstanceRouteEntryToAttachment delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateCenRouteMap CreateCenRouteMap create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DescribeUpgradeTrPublishIpv6RouteEntries DescribeUpgradeTrPublishIpv6RouteEntries list
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:ListGrantVSwitchesToCen ListGrantVSwitchesToCen get
*全部资源
*
cen:ListTransitRouterAttachments ListTransitRouterAttachments list
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateCenBondVbr CreateCenBondVbr create
*全部资源
*
cen:UpdateTransitRouterVbrAttachmentAttribute UpdateTransitRouterVbrAttachmentAttribute
*TransitRouterVbrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:GetTransitRouterUpgradeApplicationDetail GetTransitRouterUpgradeApplicationDetail get
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:ListTransitRouterCidrAllocation ListTransitRouterCidrAllocation get
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:CreateTransitRouterCidr CreateTransitRouterCidr create
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:PublishRouteEntries PublishRouteEntries update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*virtualborderrouter
acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
*VPC
acs:vpc:*:{#accountId}:vpc/{#vpcId}
cen:ListTransitRouterMulticastDomainVSwitches ListTransitRouterMulticastDomainVSwitches get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DeleteTransitRouterMulticastDomain DeleteTransitRouterMulticastDomain delete
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:DescribeCenBandwidthPackage95Metric DescribeCenBandwidthPackage95Metric get
*全部资源
*
cen:UpdateTransitRouterPeerAttachmentAttribute UpdateTransitRouterPeerAttachmentAttribute update
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ModifyCenBandwidthPackageAttribute ModifyCenBandwidthPackageAttribute update
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
cen:CreateTransitRouterMulticastDomain CreateTransitRouterMulticastDomain create
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/*
cen:UnassociateCenBondVbrFromGateway UnassociateCenBondVbrFromGateway update
*全部资源
*
cen:DescribeTags DescribeTags get
*全部资源
*
cen:UpdateTransitRouterCcnAttachmentAttribute UpdateTransitRouterCcnAttachmentAttribute update
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
cen:CancelTransitRouterUpgradeApplication CancelTransitRouterUpgradeApplication delete
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:AssociateCenBandwidthPackage AssociateCenBandwidthPackage create
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:UpdateTransitRouterVpcAttachmentAttribute UpdateTransitRouterVpcAttachmentAttribute update
*TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:CheckTransitRouterService CheckTransitRouterService none
*全部资源
*
cen:EnableCenVpcFlowStatistic EnableCenVpcFlowStatistic
*全部资源
*
cen:CreateTransitRouterEcrAttachment CreateTransitRouterEcrAttachment create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:ListTransitRouterVpcAttachments ListTransitRouterVpcAttachments list
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:UnroutePrivateZoneInCenToVpc UnroutePrivateZoneInCenToVpc delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListTransitRouterMulticastGroups ListTransitRouterMulticastGroups get
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:ListTransitRouterPeerAttachments ListTransitRouterPeerAttachments get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:UpdateTransitRouterCcnAttachmentTransitRegion UpdateTransitRouterCcnAttachmentTransitRegion update
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DescribeCenBandwidthPackage95Traffic DescribeCenBandwidthPackage95Traffic get
*全部资源
*
cen:DeleteTrafficMarkingPolicy DeleteTrafficMarkingPolicy delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:AddTraficMatchRuleToTrafficMarkingPolicy AddTraficMatchRuleToTrafficMarkingPolicy create
*全部资源
*
cen:UpgradeTransitRouter UpgradeTransitRouter update
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:RegisterTransitRouterMulticastGroupMembers RegisterTransitRouterMulticastGroupMembers create
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:ListTagResources ListTagResources get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListGrantVSwitchEnis ListGrantVSwitchEnis get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DeleteTransitRouteTableAggregation DeleteTransitRouteTableAggregation delete
*全部资源
*
cen:DetachCenChildInstance DetachCenChildInstance update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*virtualborderrouter
acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
*VPC
acs:vpc:*:{#accountId}:vpc/{#vpcId}
cen:EnableCenChildInstanceIpv6 EnableCenChildInstanceIpv6 update
*全部资源
*
cen:ModifyTrafficMatchRuleToTrafficMarkingPolicy ModifyTrafficMatchRuleToTrafficMarkingPolicy update
*全部资源
*
cen:ModifyFlowLogAttribute ModifyFlowLogAttribute update
*Flowlog
acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}
cen:DisableCenVbrHealthCheck DisableCenVbrHealthCheck update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*virtualborderrouter
acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
cen:EnableCenVbrHealthCheck EnableCenVbrHealthCheck update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*virtualborderrouter
acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
cen:ModifyTransitRouteTableAggregation ModifyTransitRouteTableAggregation create
*全部资源
*
cen:DescribeCenChildInstanceRouteEntries DescribeCenChildInstanceRouteEntries get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:QueryTransitRouterAttachmentPrice QueryTransitRouterAttachmentPrice get
*全部资源
*
cen:DescribeFlowlogs DescribeFlowlogs get
*Flowlog
acs:cbn:{#regionId}:{#accountId}:flowlog/*
*Flowlog
acs:cbn:{#regionId}:{#accountId}:flowlog/{#FlowLogId}
cen:DescribeCenBondVbrAttribute DescribeCenBondVbrAttribute get
*全部资源
*
cen:RemoveTraficMatchRuleFromTrafficMarkingPolicy RemoveTraficMatchRuleFromTrafficMarkingPolicy delete
*全部资源
*
cen:UntagResources UntagResources update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:AddTrafficMatchRuleToTrafficMarkingPolicy AddTrafficMatchRuleToTrafficMarkingPolicy create
*全部资源
*
cen:CreateTransitRouteTableAggregation CreateTransitRouteTableAggregation create
*全部资源
*
cen:DeleteCenInterRegionTrafficQosPolicy DeleteCenInterRegionTrafficQosPolicy
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:ListCrossBorderCdtUsageDetailForCenInstance ListCrossBorderCdtUsageDetailForCenInstance get
*全部资源
*
cen:DeleteTransitRouter DeleteTransitRouter delete
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:ListTransitRouterPrefixListAssociation ListTransitRouterPrefixListAssociation get
*TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
cen:DeleteCenRouteMap DeleteCenRouteMap delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListTransitRouterRouteTables ListTransitRouterRouteTables get
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/*
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:ListTransitRouterAttachmentPropagations ListTransitRouterAttachmentPropagations get
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DescribeRouteServicesInCen DescribeRouteServicesInCen get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListSupportTransitRegions ListSupportTransitRegions list
*全部资源
*
cen:CreateTransitRouter CreateTransitRouter create
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/*
cen:WithdrawPublishedRouteEntries WithdrawPublishedRouteEntries update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*VPC
acs:vpc:*:{#accountId}:vpc/{#vpcId}
cen:SetCenInterRegionBandwidthLimit SetCenInterRegionBandwidthLimit update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DeleteFlowlog DeleteFlowlog delete
*Flowlog
acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}
cen:DescribeCenAttachedChildInstanceAttribute DescribeCenAttachedChildInstanceAttribute get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateCen CreateCen create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/*
cen:ListTransitRouterCcnAttachments ListTransitRouterCcnAttachments list
*全部资源
*
cen:DeleteCenChildInstanceRouteEntryToCen DeleteCenChildInstanceRouteEntryToCen delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:RemoveVbrFromCenBondVbr RemoveVbrFromCenBondVbr update
*全部资源
*
cen:DescribeRouteConflict DescribeRouteConflict get
*VPC
acs:vpc:*:{#accountId}:vpc/{#vpcId}
cen:DescribeTransitRouteTableAggregation DescribeTransitRouteTableAggregation get
*全部资源
*
cen:AttachCenChildInstance AttachCenChildInstance update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*virtualborderrouter
acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
*VPC
acs:vpc:*:{#accountId}:vpc/{#vpcId}
cen:ListTransitRouters ListTransitRouters get
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/*
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:DescribeCenAttachedChildInstanceRegions DescribeCenAttachedChildInstanceRegions get
*全部资源
*
cen:ListTransitRouterConnectAttachments ListTransitRouterConnectAttachments get
*全部资源
*
cen:CreateTrafficMarkingPolicy CreateTrafficMarkingPolicy create
*全部资源
*
cen:ListTransitRouterAttachmentSummary ListTransitRouterAttachmentSummary list
*全部资源
*
cen:MoveResourceGroup MoveResourceGroup update
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateTransitRouterCcnAttachment CreateTransitRouterCcnAttachment update
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:AssociateTransitRouterAttachmentWithRouteTable AssociateTransitRouterAttachmentWithRouteTable create
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ListVbrRelatedTransitRouterAttachments ListVbrRelatedTransitRouterAttachments list
*全部资源
*
cen:GetCenVbrRoutePriority GetCenVbrRoutePriority get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:DeleteCen DeleteCen delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateCenChildInstanceRouteEntryToCen CreateCenChildInstanceRouteEntryToCen create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListTrafficMarkingPolicies ListTrafficMarkingPolicies list
*全部资源
*
cen:DeleteTransitRouterEcrAttachment DeleteTransitRouterEcrAttachment delete
*TransitRouterEcrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
cen:ListDataTransferBandwidthLimit ListDataTransferBandwidthLimit get
*全部资源
*
cen:DisableTransitRouterRouteTablePropagation DisableTransitRouterRouteTablePropagation update
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ListTransitRouterConnectPeers ListTransitRouterConnectPeers get
*全部资源
*
cen:CreateTransitRouterConnectPeer CreateTransitRouterConnectPeer create
*全部资源
*
cen:ModifyTransitRouterCidr ModifyTransitRouterCidr update
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:ListCenCrossBorderPackageForComplianceCheck ListCenCrossBorderPackageForComplianceCheck get
*全部资源
*
cen:CreateCenChildInstanceRouteEntryToAttachment CreateCenChildInstanceRouteEntryToAttachment create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DisableCenCrossBorderPackage DisableCenCrossBorderPackage none
*全部资源
*
cen:DeleteCenBandwidthPackage DeleteCenBandwidthPackage delete
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
cen:DescribeTagKeys DescribeTagKeys get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#CenBandwidthPackageId}
cen:UpdateTransitRouterVpcAttachmentZones UpdateTransitRouterVpcAttachmentZones update
*TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DescribeCenPrivateZoneRoutes DescribeCenPrivateZoneRoutes get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListTransitRouterEcrAttachments ListTransitRouterEcrAttachments list
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*TransitRouterEcrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterEcrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
cen:ListCenBandwidthPackageAllocationSummary ListCenBandwidthPackageAllocationSummary list
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:ListTransitRouterAttachmentsForUpgrade ListTransitRouterAttachmentsForUpgrade get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DescribeGrantRulesToCen DescribeGrantRulesToCen get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DeleteTransitRouterVbrAttachment DeleteTransitRouterVbrAttachment
*TransitRouterVbrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ModifyTransitRouterMulticastDomain ModifyTransitRouterMulticastDomain update
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#TransitRouterMulticastDomainId}
cen:DescribePublishedRouteEntries DescribePublishedRouteEntries get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
*virtualborderrouter
acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
*VPC
acs:vpc:*:{#accountId}:vpc/{#vpcId}
cen:ListVpcRelatedTransitRouterAttachments ListVpcRelatedTransitRouterAttachments list
*全部资源
*
cen:SubmitTransitRouterUpgradeApplication SubmitTransitRouterUpgradeApplication get
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:OpenTransitRouterService OpenTransitRouterService none
*全部资源
*
cen:DeleteCenBondVbr DeleteCenBondVbr delete
*全部资源
*
cen:UnassociateCenBandwidthPackage UnassociateCenBandwidthPackage delete
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateTransitRouterVpcAttachment CreateTransitRouterVpcAttachment create
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:DeleteTransitRouterConnectAttachment DeleteTransitRouterConnectAttachment update
*全部资源
*
cen:RoutePrivateZoneInCenToVpc RoutePrivateZoneInCenToVpc create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DescribeCenBondVbrs DescribeCenBondVbrs get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:RemoveTrafficMatchRuleFromTrafficMarkingPolicy RemoveTrafficMatchRuleFromTrafficMarkingPolicy update
*全部资源
*
cen:ModifyCenUserQuota ModifyCenUserQuota update
*全部资源
*
cen:CreateCenInterRegionTrafficQosQueue CreateCenInterRegionTrafficQosQueue create
*全部资源
*
cen:AssociateCenBondVbrToGateway AssociateCenBondVbrToGateway update
*全部资源
*
cen:DisassociateTransitRouterMulticastDomain DisassociateTransitRouterMulticastDomain delete
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:DescribeCenGeographicSpanRemainingBandwidth DescribeCenGeographicSpanRemainingBandwidth get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:UpdateTransitRouterRouteEntry UpdateTransitRouterRouteEntry update
*TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}
cen:DeleteTransitRouterRouteEntry DeleteTransitRouterRouteEntry delete
TransitRouterRouteEntry
acs:cen:*:{#accountId}:centransitrouterroutentry/{#centransitrouterroutentryId}
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutentry/{#transitrouterroutetableId}
cen:VerifyCenCrossBorderPackageForCompliance VerifyCenCrossBorderPackageForCompliance get
*全部资源
*
cen:DeleteTransitRouterVpnAttachment DeleteTransitRouterVpnAttachment delete
*TransitRouterVpnAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:CreateTransitRouterPeerAttachment CreateTransitRouterPeerAttachment create
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:ListTransitRouterMulticastDomainAssociations ListTransitRouterMulticastDomainAssociations get
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:ListTransitRouterRouteTablePropagations ListTransitRouterRouteTablePropagations get
TransitRouterPeerAttachment
acs:cen:*:{#accountid}:centransitrouterattachment/{#TransitRouterAttachmentId}
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}
cen:DescribeGrantRulesToResource DescribeGrantRulesToResource get
*VPC
acs:vpc:*:{#accountId}:vpc/{#VpcId}
cen:UpdateTransitRouterEcrAttachmentAttribute UpdateTransitRouterEcrAttachmentAttribute update
*TransitRouterEcrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
cen:CreateTransitRouterPrefixListAssociation CreateTransitRouterPrefixListAssociation create
*全部资源
*
cen:DescribeCenVbrHealthCheck DescribeCenVbrHealthCheck get
*全部资源
*
cen:DeleteTransitRouterPeerAttachment DeleteTransitRouterPeerAttachment delete
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ListCenChildInstanceRouteEntriesToAttachment ListCenChildInstanceRouteEntriesToAttachment get
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ListTransitRegionBandwidthLimits ListTransitRegionBandwidthLimits list
*全部资源
*
cen:AddVbrToCenBondVbr AddVbrToCenBondVbr update
*全部资源
*
cen:DeleteTransitRouterPrefixListAssociation DeleteTransitRouterPrefixListAssociation delete
*全部资源
*
cen:ListTransitRouterRouteEntries ListTransitRouterRouteEntries get
TransitRouterRouteEntry
acs:cen:*:{#accountId}:centransitrouterroutentry/{#centransitrouterroutentryId}
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
TransitRouterRouteEntry
acs:cen:*:{#accountId}:centransitrouterroutentry/*
cen:UpdateCenVbrRoutePriority UpdateCenVbrRoutePriority update
*全部资源
*
cen:DescribeCenRouteMaps DescribeCenRouteMaps get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:RefreshTransitRouteTableAggregation RefreshTransitRouteTableAggregation update
*全部资源
*
cen:DeregisterTransitRouterMulticastGroupSources DeregisterTransitRouterMulticastGroupSources delete
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:DeleteTransitRouterRouteTable DeleteTransitRouterRouteTable delete
*TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
cen:ListTransitRouterMulticastDomains ListTransitRouterMulticastDomains list
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/*
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:ListTransitRouterCidr ListTransitRouterCidr get
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:EnableTransitRouterRouteTablePropagation EnableTransitRouterRouteTablePropagation update
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:ActiveFlowLog ActiveFlowLog update
*Flowlog
acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}
cen:DescribeCenInterRegionBandwidthLimits DescribeCenInterRegionBandwidthLimits get
CenInstance
acs:cen:*:{#accountId}:ceninstance/*
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ModifyCenBandwidthPackageSpec ModifyCenBandwidthPackageSpec update
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
cen:ListCenInterRegionTrafficQosQueues ListCenInterRegionTrafficQosQueues get
*全部资源
*
cen:DeleteCenInterRegionTrafficQosQueue DeleteCenInterRegionTrafficQosQueue delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:UpdateTransitRouter UpdateTransitRouter update
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:CreateTransitRouterRouteTable CreateTransitRouterRouteTable create
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
TransitRouterRouteTable
acs:cen:*:{#accountId}:centransitrouterroutetable/*
cen:TempUpgradeCenBandwidthPackageSpec TempUpgradeCenBandwidthPackageSpec update
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
cen:UpdateTransitRouterVpnAttachmentAttribute UpdateTransitRouterVpnAttachmentAttribute update
*TransitRouterVpnAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DeleteTransitRouterCidr DeleteTransitRouterCidr delete
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
cen:DescribeCenBandwidthPackages DescribeCenBandwidthPackages get
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/*
cen:DeleteTransitRouterVpcAttachment DeleteTransitRouterVpcAttachment delete
*TransitRouterVpcAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:DeleteRouteServiceInCen DeleteRouteServiceInCen delete
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ResolveAndRouteServiceInCen ResolveAndRouteServiceInCen create
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ListTransitRouterVbrAttachments ListTransitRouterVbrAttachments list
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouterVbrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterVbrAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
cen:CreateTransitRouterVbrAttachment CreateTransitRouterVbrAttachment create
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:UpdateTransitRouterConnectAttachmentAttribute UpdateTransitRouterConnectAttachmentAttribute update
*TransitRouterPeerAttachment
acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
cen:AssociateTransitRouterMulticastDomain AssociateTransitRouterMulticastDomain update
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:CreateTransitRouterConnectAttachment CreateTransitRouterConnectAttachment create
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:DescribeCenAttachedChildInstances DescribeCenAttachedChildInstances get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:ModifyCenAttribute ModifyCenAttribute update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:RegisterTransitRouterMulticastGroupSources RegisterTransitRouterMulticastGroupSources create
*TransitRouterMulticastDomain
acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
cen:CreateCenBandwidthPackage CreateCenBandwidthPackage create
*CenBandwidthPackage
acs:cen:*:{#accountId}:cenbandwidthpackage/*
cen:DescribeCenRegionDomainRouteEntries DescribeCenRegionDomainRouteEntries get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
cen:CreateCenInterRegionTrafficQosPolicy CreateCenInterRegionTrafficQosPolicy create
*全部资源
*
cen:ModifyCenBondVbrAttribute ModifyCenBondVbrAttribute update
*全部资源
*
cen:CreateTransitRouterVpnAttachment CreateTransitRouterVpnAttachment create
CenInstance
acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:EnableCenCrossBorderPackage EnableCenCrossBorderPackage get
*全部资源
*
cen:ListCenCrossBorderPackageUsageDetail ListCenCrossBorderPackageUsageDetail get
*全部资源
*
cen:UpdateCenInterRegionTrafficQosQueueAttribute UpdateCenInterRegionTrafficQosQueueAttribute update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:DescribeUpgradeTrRecvIpv6RouteEntries DescribeUpgradeTrRecvIpv6RouteEntries list
*TransitRouter
acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
cen:DescribeCens DescribeCens get
*CenInstance
acs:cen:*:{#accountId}:ceninstance/*
cen:ListCenCrossBorderPackageForCompliance ListCenCrossBorderPackageForCompliance get
*全部资源
*
cen:TagResources TagResources update
*全部资源
*
cen:UpdateTrafficMarkingPolicyAttribute UpdateTrafficMarkingPolicyAttribute update
*CenInstance
acs:cen:*:{#accountId}:ceninstance/{#CenId}
cen:GrantInstanceToTransitRouter GrantInstanceToTransitRouter create
*全部资源
*

资源(Resource)

下表是云企业网定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

TransitRouterMulticastDomain acs:cen:*:{#accountId}:centransitroutermulticast/{#centransitroutermulticastId}
CenInstance acs:cen:*:{#accountId}:ceninstance/*
Flowlog acs:cbn:{#regionId}:{#accountId}:flowlog/*
CenInstance acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}
TransitRouterPeerAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
TransitRouterRouteTable acs:cen:*:{#accountId}:centransitrouterroutetable/{#TransitRouterRouteTableId}
TransitRouterRouteTable acs:cen:*:{#accountId}:centransitrouterroutetable/{#centransitrouterroutetableId}
TransitRouterVpcAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
TransitRouter acs:cen:*:{#accountId}:centransitrouter/{#TransitRouterId}
TransitRouterRouteEntry acs:cen:*:{#accountId}:centransitrouterroutentry/*
TransitRouterVpnAttachment acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterVpnAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
CenInstance acs:cen:*:{#accountId}:ceninstance/{#CenId}
Flowlog acs:cbn:{#regionId}:{#accountId}:flowlog/{#flowlogId}
CenInstance acs:cen::{#accountId}:ceninstance/{#CenId}
TransitRouterVbrAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#centransitrouterattachmentId}
TransitRouter acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}
virtualborderrouter acs:vpc:*:{#accountId}:virtualborderrouter/{#virtualborderrouterId}
VPC acs:vpc:*:{#accountId}:vpc/{#vpcId}
CenBandwidthPackage acs:cen::{#accountId}:cenbandwidthpackage/{#CenBandwidthPackageId}
CenBandwidthPackage acs:cen:*:{#accountId}:cenbandwidthpackage/{#cenbandwidthpackageId}
TransitRouterMulticastDomain acs:cen:*:{#accountId}:centransitroutermulticast/*
TransitRouterPeerAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
TransitRouterVpcAttachment acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterPeerAttachment acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterRouteEntry acs:cen:*:{#accountId}:transitrouterrouteentry/{#TransitRouterRouteEntryId}
TransitRouterRouteTable acs:cen:*:{#accountId}:transitrouterroutetable/{#TransitRouterRouteTableId}
TransitRouterRouteEntry acs:cen:*:{#accountId}:transitrouterrouteentry/*
TransitRouterRouteTable acs:cen:*:{#accountId}:transitrouterroutetable/{#TransitRouteTableId}
CenInstance acs:cen::{#accountId}:ceninstance/*
TransitRouterRouteTable acs:cen:*:{#accountId}:centransitrouterroutetable/*
TransitRouter acs:cen:*:{#accountId}:centransitrouter/*
TransitRouterVbrAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
TransitRouterEcrAttachment acs:cen:*:{#accountId}:centransitrouterattachment/{#TransitRouterAttachmentId}
CenBandwidthPackage acs:cen:*:{#accountId}:cenbandwidthpackage/*
TransitRouterEcrAttachment acs:cen:*:{#accountId}:centransitrouterattachment/*
TransitRouterMulticastDomain acs:cen:*:{#accountId}:centransitroutermulticast/{#TransitRouterMulticastDomainId}
TransitRouterVpcAttachment acs:cen:{#regionId}:{#accountId}:centransitrouterattachment/*
TransitRouterRouteEntry acs:cen:*:{#accountId}:centransitrouterroutentry/{#centransitrouterroutentryId}
TransitRouterRouteTable acs:cen:*:{#accountId}:centransitrouterroutentry/{#transitrouterroutetableId}
virtualborderrouter acs:vpc:*:{#accountId}:virtualborderrouter/*
TransitRouterVbrAttachment acs:cen:*:{#accountId}:centransitrouterattachment/*

条件(Condition)

云企业网未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: