授权信息

更新时间:
复制为 MD 格式

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 企业级分布式应用服务 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 企业级分布式应用服务 的 RAM 代码(RamCode)为 edas ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是企业级分布式应用服务定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

edas:ReadApplication GetWebContainerConfig get

*全部资源

*

edas:ReadApplication GetJvmConfiguration get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageCluster UpdateK8sIngressRule update

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageApplication UpdateK8sService update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadApplication QuerySlsLogStoreList get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster ListK8sConfigMaps get

*全部资源

*

edas:ManageApplication UnbindK8sSlb none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadApplication ListDeployGroup get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication AbortChangeOrder update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageTraffic DeleteSwimmingLane delete

*全部资源

*

edas:UntagResources UntagResources update

*全部资源

*

edas:ManageApplication CreateApplicationScalingRule create

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ListSlb ListSlb list

*全部资源

*

edas:ReadService ListConsumedServices get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NamespaceId}/application/{#AppId}

edas:ConfigApplication UpdateApplicationBaseInfo update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster ListCluster list

*全部资源

*

edas:ManageApplication UpdateHealthCheckUrl update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ListTagResources ListTagResources list

*全部资源

*

edas:ManageCluster CreateK8sConfigMap create

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ReadApplication GetContainerConfiguration get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ListVpc ListVpc list

*全部资源

*

edas:AuthorizeRole AuthorizeRole none

*全部资源

*

edas:DeleteCluster DeleteCluster delete

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:GetPackageStorageCredential GetPackageStorageCredential get

*全部资源

*

edas:ConfigApplication BindEcsSlb none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication DeployK8sApplication update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:DeleteServiceGroup DeleteServiceGroup delete

*全部资源

*

edas:ManageCluster UpdateK8sSecret update

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ReadApplication GetAppDeployment get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster GetCluster get

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageApplication DeleteK8sService delete

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageCluster CreateK8sIngressRule create

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ListResourceGroup ListResourceGroup list

*全部资源

*

edas:ReadApplication ListRecentChangeOrder get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageCluster UpdateK8sConfigMap update

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageCluster CreateK8sSecret create

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:CreateApplication InsertK8sApplication create

*全部资源

*

edas:ReadApplication DescribeApplicationScalingRules get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication BindSlb none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageAppLog DeleteLogPath delete

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication RollbackApplication get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadNamespace GetSecureToken get

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:ManageCluster DeleteK8sIngressRule delete

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageApplication RollbackChangeOrder none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ECSPurchase ScaleoutApplicationWithNewInstances update

*全部资源

*

edas:ManageCluster TransformClusterMember none

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:InsertSwimmingLaneGroup InsertSwimmingLaneGroup create

*全部资源

*

edas:AuthorizeResourceGroup AuthorizeResourceGroup none

*全部资源

*

edas:ReadCluster ListConvertableEcu get

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageApplication UpdateLocalitySetting update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NamespaceId}/application/{#AppId}

edas:ManageApplication UpdateContainer update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:DeleteConfigTemplate DeleteConfigTemplate delete

*全部资源

*

edas:ReadService ListPublishedServices get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageCluster DeleteK8sConfigMap delete

*全部资源

*

edas:ReadApplication ListHistoryDeployVersion get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadService GetServiceConsumersPage get

*全部资源

*

edas:ManageApplication ScaleInApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication ContinuePipeline none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication ScaleK8sApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster GetK8sCluster get

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ListConfigTemplates ListConfigTemplates get

*全部资源

*

edas:ReadApplication GetK8sServices get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ConfigApplication UpdateK8sApplicationBaseInfo update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadService ListMethods get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:MigrateEcu MigrateEcu update

*全部资源

*

edas:ManageApplication InsertDeployGroup create

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster ListK8sSecrets get

*全部资源

*

edas:DeleteApplication DeleteK8sApplication delete

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication SwitchAdvancedMonitoring none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:InsertRole InsertRole create

*全部资源

*

edas:ListServiceGroups ListServiceGroups get

*全部资源

*

edas:ReadCluster ListScaleOutEcu get

*全部资源

*

edas:ManageApplication StopApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication UpdateHookConfiguration update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ListEcsNotInCluster ListEcsNotInCluster get

*全部资源

*

edas:ListSwimmingLaneGroup ListSwimmingLaneGroup get

*全部资源

*

edas:ReadApplication GetK8sApplication get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster GetK8sAppPrecheckResult get

*全部资源

*

edas:DeleteEcu DeleteEcu delete

*全部资源

*

edas:CreateNamespace InsertOrUpdateRegion update

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:CreateApplication InsertApplication create

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:ListRole ListRole get

*全部资源

*

edas:ReadCluster ListK8sIngressRules get

*全部资源

*

edas:ReadApplication GetJavaStartUpConfig get

*全部资源

*

edas:ManageCluster DeleteK8sSecret delete

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageTraffic UpdateSwimmingLaneGroup update

*全部资源

*

edas:ManageApplication RestartK8sApplication get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:tag

edas:QueryMigrateRegionList QueryMigrateRegionList none

*全部资源

*

edas:ListEcuByRegion ListEcuByRegion list

*全部资源

*

edas:ManageApplication DeleteApplicationScalingRule delete

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:DeleteRole DeleteRole delete

*全部资源

*

edas:ReadService GetServiceMethodPage get

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:ReadApplication GetApplication get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication ChangeDeployGroup none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication RestartApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:CreateCluster ImportK8sCluster none

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:UpdateAccountInfo UpdateAccountInfo update

*全部资源

*

edas:ReadApplication GetScalingRules get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadApplication QueryEccInfo get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NamespaceId}/application/{#AppId}

edas:ManageCluster DeleteClusterMember delete

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageApplication StartK8sApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication StopK8sApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication UpdateK8sSlb update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication StartApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication UpdateApplicationScalingRule update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:SynchronizeResource SynchronizeResource none

*全部资源

*

edas:ConfigApplication UpdateJvmConfiguration update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageCluster InsertClusterMember create

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:DeleteNamespace DeleteUserDefineRegion get

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:ManageCluster CreateIDCImportCommand create

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ReadApplication QueryApplicationStatus get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ListAuthority ListAuthority list

*全部资源

*

edas:ReadApplication GetChangeOrderInfo get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication DisableApplicationScalingRule update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadApplication DescribeAppInstanceList get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadApplication DescribeLocalitySetting get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NamespaceId}/application/{#AppId}

edas:ReadCluster ListK8sNamespaces

*全部资源

*

edas:CreateCluster InsertCluster create

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:ListUserDefineRegion ListUserDefineRegion list

*全部资源

*

edas:ConfigApplication UpdateK8sApplicationConfig

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageTraffic UpdateSwimmingLane update

*全部资源

*

edas:ReadService GetServiceListPage get

*NameSpace

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

edas:ManageAppLog AddLogPath create

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageTraffic InsertSwimmingLane create

*全部资源

*

edas:ReadApplication ListApplicationEcu get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication AbortAndRollbackChangeOrder get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication DeployApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication EnableApplicationScalingRule update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:InsertServiceGroup InsertServiceGroup create

*全部资源

*

edas:ListSwimmingLane ListSwimmingLane list

*全部资源

*

edas:ManageApplication ResetApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ListSubAccount ListSubAccount get

*全部资源

*

edas:ManageCluster ConvertK8sResource get

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageCluster InstallAgent none

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:ManageApplication UpdateContainerConfiguration update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadService GetServiceDetail get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageAppLog UpdateSlsLogStore update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadService GetServiceProvidersPage get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageCluster UpdateK8sResource update

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:CreateConfigTemplate CreateConfigTemplate create

*全部资源

*

edas:QueryMigrateEcuList QueryMigrateEcuList list

*全部资源

*

edas:ReadApplication ListApplication

*全部资源

*

edas:ReadCluster ListClusterMembers get

*Cluster

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}

edas:UpdateConfigTemplate UpdateConfigTemplate update

*全部资源

*

edas:ManageApplication ModifyScalingRule update

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:UpdateRole UpdateRole update

*全部资源

*

edas:ManageApplication CreateK8sService create

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NamespaceId}/application/{#AppId}

edas:TagResources TagResources update

*全部资源

*

edas:DeleteApplication DeleteApplication delete

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication UnbindSlb none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:SLBPurchase BindK8sSlb get

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ReadCluster StartK8sAppPrecheck none

*全部资源

*

edas:ManageApplication DeleteDeployGroup delete

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:ManageApplication ScaleOutApplication none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

edas:AuthorizeApplication AuthorizeApplication none

*全部资源

*

edas:ManageApplication RetryChangeOrderTask none

*Application

acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}

资源(Resource)

下表是企业级分布式应用服务定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

Application
  • acs:edas:{#regionId}:{#accountId}:application/{#AppId}
  • acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/application/{#AppId}
Cluster
  • acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}/cluster/{#ClusterId}
  • acs:edas:{#regionId}:{#accountId}:cluster/{#ClusterId}
  • acs:edas:{#regionId}:{#accountId}:cluster/*
NameSpace
  • acs:edas:{#regionId}:{#accountId}:namespace/{#NameSpaceId}

条件(Condition)

下表是企业级分布式应用服务 定义的产品级条件关键字,这些条件关键字可以在 RAM 权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的通用条件关键字也同样适用企业级分布式应用服务

其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型

条件关键字

描述

类型

edas:tag String

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: