授权信息

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 边缘安全加速 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 边缘安全加速 的 RAM 代码(RamCode)为 dcdn ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是边缘安全加速定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

dcdn:DeleteDcdnDomain DeleteDcdnDomain delete

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafGeoInfo DescribeDcdnWafGeoInfo get

*全部资源

*

dcdn:DescribeDcdnL2Ips DescribeDcdnL2Ips get

*全部资源

*

dcdn:BatchSetDcdnDomainConfigs BatchSetDcdnDomainConfigs update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DeleteDcdnIpaSpecificConfig DeleteDcdnIpaSpecificConfig delete

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:StartDcdnDomain StartDcdnDomain update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeRoutineRelatedDomains DescribeRoutineRelatedDomains get

*全部资源

*

dcdn:BatchStopDcdnDomain BatchStopDcdnDomain update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnIpaUserDomains DescribeDcdnIpaUserDomains get

*IpaDomain

acs:dcdn:*:{#accountId}:domain/*

dcdn:DescribeDcdnRefreshQuota DescribeDcdnRefreshQuota get

*全部资源

*

dcdn:DescribeDcdnWafPolicy DescribeDcdnWafPolicy get

*全部资源

*

dcdn:StopDcdnIpaDomain StopDcdnIpaDomain update

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:CreateDcdnSLSRealTimeLogDelivery CreateDcdnSLSRealTimeLogDelivery create

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:BatchDeleteDcdnKvWithHighCapacity BatchDeleteDcdnKvWithHighCapacity none

*全部资源

*

dcdn:DescribeDcdnIpInfo DescribeDcdnIpInfo get

*全部资源

*

dcdn:DescribeDcdnUserResourcePackage DescribeDcdnUserResourcePackage get

*全部资源

*

dcdn:BatchDeleteDcdnWafRules BatchDeleteDcdnWafRules delete

*全部资源

*

dcdn:DescribeDcdnDdosService DescribeDcdnDdosService none

*全部资源

*

dcdn:DescribeDcdnKvNamespace DescribeDcdnKvNamespace get

*全部资源

*

dcdn:DeleteDcdnWafGroup DeleteDcdnWafGroup delete

*全部资源

*

dcdn:DescribeDcdnDomainMultiUsageData DescribeDcdnDomainMultiUsageData none

*全部资源

*

dcdn:DescribeDcdnWafScenes DescribeDcdnWafScenes get

*全部资源

*

dcdn:DescribeDcdnRealTimeDeliveryField DescribeDcdnRealTimeDeliveryField get

*全部资源

*

dcdn:DescribeDcdnIpaDomainCidr DescribeDcdnIpaDomainCidr none

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:PreloadDcdnObjectCaches PreloadDcdnObjectCaches none

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:PutDcdnKv PutDcdnKv update

*全部资源

*

dcdn:DescribeDcdnDomainStagingConfig DescribeDcdnDomainStagingConfig get

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDeletedDomains DescribeDcdnDeletedDomains get

*全部资源

*

dcdn:DeleteDcdnUserConfig DeleteDcdnUserConfig delete

*全部资源

*

dcdn:DescribeRDDomainConfig DescribeRDDomainConfig get

*全部资源

*

dcdn:DescribeDcdnDomainHttpCodeDataByLayer DescribeDcdnDomainHttpCodeDataByLayer get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafDomains DescribeDcdnWafDomains get

*全部资源

*

dcdn:DescribeDcdnStagingIp DescribeDcdnStagingIp get

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeReqHitRateData DescribeDcdnDomainRealTimeReqHitRateData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeKvUsageData DescribeKvUsageData get

*全部资源

*

dcdn:DescribeDcdnDomainBpsDataByLayer DescribeDcdnDomainBpsDataByLayer get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainCcActivityLog DescribeDcdnDomainCcActivityLog get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainTopUrlVisit DescribeDcdnDomainTopUrlVisit get

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchModifyDcdnWafRules BatchModifyDcdnWafRules update

*全部资源

*

dcdn:DescribeDcdnBlockedRegions DescribeDcdnBlockedRegions get

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeHttpCodeData DescribeDcdnDomainRealTimeHttpCodeData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDdosAllEventList DescribeDdosAllEventList get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:CreateSlrAndSlsProject CreateSlrAndSlsProject create

*全部资源

*

dcdn:DescribeDcdnWafGroup DescribeDcdnWafGroup get

*全部资源

*

dcdn:DescribeDcdnBgpTrafficData DescribeDcdnBgpTrafficData get

*全部资源

*

dcdn:BatchAddDcdnDomain BatchAddDcdnDomain create

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:ModifyDcdnWafPolicyDomains ModifyDcdnWafPolicyDomains update

*全部资源

*

dcdn:CheckDcdnProjectExist CheckDcdnProjectExist none

*全部资源

*

dcdn:SetDcdnDomainStagingConfig SetDcdnDomainStagingConfig update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:PublishDcdnStagingConfigToProduction PublishDcdnStagingConfigToProduction none

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchPutDcdnKvWithHighCapacity BatchPutDcdnKvWithHighCapacity none

*全部资源

*

dcdn:VerifyDcdnDomainOwner VerifyDcdnDomainOwner get

*全部资源

*

dcdn:AddDcdnDomain AddDcdnDomain create

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:UpdateDcdnIpaDomain UpdateDcdnIpaDomain update

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:StartDcdnIpaDomain StartDcdnIpaDomain update

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchPutDcdnKv BatchPutDcdnKv none

*全部资源

*

dcdn:DeleteDcdnIpaDomain DeleteDcdnIpaDomain delete

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainUsageData DescribeDcdnDomainUsageData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnUserBillHistory DescribeDcdnUserBillHistory get

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeSrcHttpCodeData DescribeDcdnDomainRealTimeSrcHttpCodeData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnUserRealTimeDeliveryField DescribeDcdnUserRealTimeDeliveryField get

*全部资源

*

dcdn:DescribeDcdnDomainCname DescribeDcdnDomainCname get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainPvData DescribeDcdnDomainPvData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:SetDcdnFullDomainsBlockIP SetDcdnFullDomainsBlockIP update

*全部资源

*

dcdn:DescribeDcdnSecSpecInfo DescribeDcdnSecSpecInfo get

*全部资源

*

dcdn:DescribeDcdnDomainWebsocketTrafficData DescribeDcdnDomainWebsocketTrafficData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnIpaDomainDetail DescribeDcdnIpaDomainDetail get

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchStartDcdnDomain BatchStartDcdnDomain update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchDeleteDcdnKv BatchDeleteDcdnKv delete

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeSrcTrafficData DescribeDcdnDomainRealTimeSrcTrafficData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UpdateDcdnUserRealTimeDeliveryField UpdateDcdnUserRealTimeDeliveryField update

*全部资源

*

dcdn:DescribeDcdnUserSecDrop DescribeDcdnUserSecDrop get

*全部资源

*

dcdn:DescribeDcdnDomainOriginTrafficData DescribeDcdnDomainOriginTrafficData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnKvAccountStatus DescribeDcdnKvAccountStatus get

*全部资源

*

dcdn:DescribeUserLogserviceStatus DescribeUserLogserviceStatus get

*全部资源

*

dcdn:CreateRoutine CreateRoutine update

*全部资源

*

dcdn:DescribeEncryptRoutineUid DescribeEncryptRoutineUid get

*全部资源

*

dcdn:DescribeDcdnTagResources DescribeDcdnTagResources get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnErUsageData DescribeDcdnErUsageData get

*全部资源

*

dcdn:DescribeDcdnDomainProperty DescribeDcdnDomainProperty get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnUserDomainsByFunc DescribeDcdnUserDomainsByFunc get

Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnVerifyContent DescribeDcdnVerifyContent get

*全部资源

*

dcdn:DescribeHighlightInfo DescribeHighlightInfo get

*全部资源

*

dcdn:DescribeDcdnUserQuota DescribeDcdnUserQuota get

*全部资源

*

dcdn:DeleteDcdnKvNamespace DeleteDcdnKvNamespace delete

*全部资源

*

dcdn:ModifyDcdnWafPolicy ModifyDcdnWafPolicy update

*全部资源

*

dcdn:RefreshDcdnObjectCaches RefreshDcdnObjectCaches none

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafLogs DescribeDcdnWafLogs get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeRoutine DescribeRoutine get

*全部资源

*

dcdn:DescribeKvRealTimeQpsData DescribeKvRealTimeQpsData get

*全部资源

*

dcdn:DescribeDcdnDomainHttpCodeData DescribeDcdnDomainHttpCodeData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnUserVipsByDomain DescribeDcdnUserVipsByDomain none

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnDomainOriginBpsData DescribeDcdnDomainOriginBpsData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnSecFuncInfo DescribeDcdnSecFuncInfo get

*全部资源

*

dcdn:GetDcdnKvStatus GetDcdnKvStatus get

*全部资源

*

dcdn:DescribeDcdnDomainCertificateInfo DescribeDcdnDomainCertificateInfo get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnBgpBpsData DescribeDcdnBgpBpsData get

*全部资源

*

dcdn:DescribeRoutineSpec DescribeRoutineSpec get

*全部资源

*

dcdn:SetDcdnDomainCSRCertificate SetDcdnDomainCSRCertificate update

*全部资源

*

dcdn:DescribeDcdnWafRule DescribeDcdnWafRule get

*全部资源

*

dcdn:DescribeDcdnDomainByCertificate DescribeDcdnDomainByCertificate get

*全部资源

*

dcdn:DescribeDcdnHttpsDomainList DescribeDcdnHttpsDomainList get

*全部资源

*

dcdn:DescribeDcdnDomainHitRateData DescribeDcdnDomainHitRateData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeRoutineCodeRevision DescribeRoutineCodeRevision get

*全部资源

*

dcdn:StopDcdnDomain StopDcdnDomain update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainQpsData DescribeDcdnDomainQpsData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnsecService DescribeDcdnsecService get

*全部资源

*

dcdn:PutDcdnKvWithHighCapacity PutDcdnKvWithHighCapacity get

*全部资源

*

dcdn:DeleteDcdnRealTimeLogProject DeleteDcdnRealTimeLogProject delete

*全部资源

*

dcdn:DescribeDcdnWafDomain DescribeDcdnWafDomain get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchDeleteDcdnDomainConfigs BatchDeleteDcdnDomainConfigs update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDeliverList DescribeDcdnDeliverList get

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeQpsData DescribeDcdnDomainRealTimeQpsData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:RollbackDcdnStagingConfig RollbackDcdnStagingConfig update

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnDomainIspData DescribeDcdnDomainIspData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnCertificateDetail DescribeDcdnCertificateDetail get

*全部资源

*

dcdn:DescribeDcdnWafService DescribeDcdnWafService get

*全部资源

*

dcdn:DescribeDcdnFullDomainsBlockIPConfig DescribeDcdnFullDomainsBlockIPConfig none

*全部资源

*

dcdn:DescribeDcdnAclFields DescribeDcdnAclFields get

*全部资源

*

dcdn:DescribeDcdnDomainUvData DescribeDcdnDomainUvData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainRealTimeDetailData DescribeDcdnDomainRealTimeDetailData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UploadRoutineCode UploadRoutineCode update

*全部资源

*

dcdn:DescribeDcdnSMCertificateDetail DescribeDcdnSMCertificateDetail get

*全部资源

*

dcdn:DescribeDcdnDomainIpaTrafficData DescribeDcdnDomainIpaTrafficData get

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:GetDcdnKvDetail GetDcdnKvDetail get

*全部资源

*

dcdn:GetDcdnKv GetDcdnKv get

*全部资源

*

dcdn:AddDcdnIpaDomain AddDcdnIpaDomain create

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeUserDcdnIpaStatus DescribeUserDcdnIpaStatus get

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeByteHitRateData DescribeDcdnDomainRealTimeByteHitRateData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainTrafficData DescribeDcdnDomainTrafficData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:CreateDcdnSubTask CreateDcdnSubTask create

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnSubList DescribeDcdnSubList get

*全部资源

*

dcdn:DescribeDcdnCertificateList DescribeDcdnCertificateList get

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnSSLCertificateList DescribeDcdnSSLCertificateList get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UpdateDcdnDeliverTask UpdateDcdnDeliverTask update

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainWebsocketHttpCodeData DescribeDcdnDomainWebsocketHttpCodeData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UpdateDcdnSubTask UpdateDcdnSubTask update

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafPolicyValidDomains DescribeDcdnWafPolicyValidDomains get

*全部资源

*

dcdn:DeleteRoutineCodeRevision DeleteRoutineCodeRevision update

*全部资源

*

dcdn:BatchSetDcdnIpaDomainConfigs BatchSetDcdnIpaDomainConfigs update

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnService DescribeDcdnService get

*全部资源

*

dcdn:DescribeDcdnDomainIpaConnData DescribeDcdnDomainIpaConnData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnReportList DescribeDcdnReportList get

*全部资源

*

dcdn:DescribeDcdnDomainBpsData DescribeDcdnDomainBpsData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnUserBillType DescribeDcdnUserBillType get

*全部资源

*

dcdn:DescribeDcdnSLSRealtimeLogDelivery DescribeDcdnSLSRealtimeLogDelivery get

*全部资源

*

dcdn:PublishRoutineCodeRevision PublishRoutineCodeRevision update

*全部资源

*

dcdn:DescribeDcdnWafDomainDetail DescribeDcdnWafDomainDetail get

*WafDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UpdateDcdnDomain UpdateDcdnDomain update

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:RefreshErObjectCaches RefreshErObjectCaches none

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnWafRules DescribeDcdnWafRules get

*全部资源

*

dcdn:DescribeDcdnDomainRegionData DescribeDcdnDomainRegionData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:CreateDcdnWafGroup CreateDcdnWafGroup get

*全部资源

*

dcdn:DeleteDcdnSpecificConfig DeleteDcdnSpecificConfig delete

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnTopDomainsByFlow DescribeDcdnTopDomainsByFlow none

*全部资源

*

dcdn:DescribeRoutineUserInfo DescribeRoutineUserInfo get

*全部资源

*

dcdn:SetDcdnUserConfig SetDcdnUserConfig update

*全部资源

*

dcdn:DeleteDcdnSubTask DeleteDcdnSubTask delete

*全部资源

*

dcdn:DeleteDcdnWafPolicy DeleteDcdnWafPolicy delete

*全部资源

*

dcdn:DescribeDcdnRegionAndIsp DescribeDcdnRegionAndIsp get

*全部资源

*

dcdn:DescribeDcdnWafSpecInfo DescribeDcdnWafSpecInfo get

*全部资源

*

dcdn:CreateDcdnCertificateSigningRequest CreateDcdnCertificateSigningRequest create

*全部资源

*

dcdn:DeleteDcdnDeliverTask DeleteDcdnDeliverTask delete

*全部资源

*

dcdn:OpenDcdnService OpenDcdnService get

*全部资源

*

dcdn:DescribeDcdnDomainLog DescribeDcdnDomainLog get

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafBotAppKey DescribeDcdnWafBotAppKey get

*全部资源

*

dcdn:DescribeRoutineCanaryEnvs DescribeRoutineCanaryEnvs get

*全部资源

*

dcdn:DescribeDcdnDomainsBySource DescribeDcdnDomainsBySource none

*全部资源

*

dcdn:SetRoutineSubdomain SetRoutineSubdomain update

*全部资源

*

dcdn:DescribeDcdnSLSRealTimeLogType DescribeDcdnSLSRealTimeLogType get

*全部资源

*

dcdn:ModifyDcdnWafRule ModifyDcdnWafRule update

*全部资源

*

dcdn:ListDcdnRealTimeDeliveryProject ListDcdnRealTimeDeliveryProject list

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

*RealTimeLogDelivery

acs:dcdn:*:{#accountId}:domain/*

dcdn:RefreshDcdnObjectCacheByCacheTag RefreshDcdnObjectCacheByCacheTag none

*全部资源

*

dcdn:DescribeDcdnIpaDomainConfigs DescribeDcdnIpaDomainConfigs get

*IpaDomain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:ModifyDCdnDomainSchdmByProperty ModifyDCdnDomainSchdmByProperty update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeUserDcdnStatus DescribeUserDcdnStatus get

*全部资源

*

dcdn:EditRoutineConf EditRoutineConf update

*全部资源

*

dcdn:DescribeDcdnUserDomains DescribeDcdnUserDomains list

*Domain

acs:dcdn:*:{#accountId}:domain/*

dcdn:DescribeDcdnWafPolicyDomains DescribeDcdnWafPolicyDomains get

*全部资源

*

dcdn:DescribeDcdnWafUsageData DescribeDcdnWafUsageData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnDomainRealTimeBpsData DescribeDcdnDomainRealTimeBpsData get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnDomainTopReferVisit DescribeDcdnDomainTopReferVisit get

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:SetDcdnDomainSMCertificate SetDcdnDomainSMCertificate update

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DeleteDcdnSpecificStagingConfig DeleteDcdnSpecificStagingConfig delete

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:BatchCreateDcdnWafRules BatchCreateDcdnWafRules create

*全部资源

*

dcdn:DescribeDcdnWafGroups DescribeDcdnWafGroups get

*全部资源

*

dcdn:ModifyDcdnWafGroup ModifyDcdnWafGroup update

*全部资源

*

dcdn:DeleteRoutineConfEnvs DeleteRoutineConfEnvs update

*全部资源

*

dcdn:DescribeDcdnRefreshTasks DescribeDcdnRefreshTasks get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnUserConfigs DescribeDcdnUserConfigs get

*全部资源

*

dcdn:DescribeDcdnDomainWebsocketBpsData DescribeDcdnDomainWebsocketBpsData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UpdateDcdnSLSRealtimeLogDelivery UpdateDcdnSLSRealtimeLogDelivery update

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnRefreshTaskById DescribeDcdnRefreshTaskById get

*全部资源

*

dcdn:DescribeDcdnUserSecDropByMinute DescribeDcdnUserSecDropByMinute get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnUserTags DescribeDcdnUserTags get

*全部资源

*

dcdn:DescribeDcdnDomainDetail DescribeDcdnDomainDetail get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnDomainConfigs DescribeDcdnDomainConfigs get

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnFullDomainsBlockIPHistory DescribeDcdnFullDomainsBlockIPHistory none

*全部资源

*

dcdn:CreateDcdnDeliverTask CreateDcdnDeliverTask create

*DeliverTask

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnOriginSiteHealthStatus DescribeDcdnOriginSiteHealthStatus none

*全部资源

*

dcdn:DescribeDcdnDdosSpecInfo DescribeDcdnDdosSpecInfo get

*全部资源

*

dcdn:DescribeDcdnL2Vips DescribeDcdnL2Vips get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:UploadStagingRoutineCode UploadStagingRoutineCode update

*全部资源

*

dcdn:SetDcdnDomainSSLCertificate SetDcdnDomainSSLCertificate none

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafFilterInfo DescribeDcdnWafFilterInfo get

*全部资源

*

dcdn:UntagDcdnResources UntagDcdnResources update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:PutDcdnKvNamespace PutDcdnKvNamespace update

*全部资源

*

dcdn:DeleteRoutine DeleteRoutine update

*全部资源

*

dcdn:DescribeDcdnDomainIpaBpsData DescribeDcdnDomainIpaBpsData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnUserCertificateExpireCount DescribeDcdnUserCertificateExpireCount get

*全部资源

*

dcdn:ListDcdnKv ListDcdnKv get

*全部资源

*

dcdn:CreateDcdnWafPolicy CreateDcdnWafPolicy create

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeSrcBpsData DescribeDcdnDomainRealTimeSrcBpsData get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnReport DescribeDcdnReport get

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DescribeDcdnSMCertificateList DescribeDcdnSMCertificateList get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeUserErStatus DescribeUserErStatus get

*全部资源

*

dcdn:DescribeDcdnKvAccount DescribeDcdnKvAccount get

*全部资源

*

dcdn:BatchSetDcdnWafDomainConfigs BatchSetDcdnWafDomainConfigs create

*Domain

acs:dcdn:*:{#accountId}:domain/{#DomainName}

dcdn:DeleteDcdnKv DeleteDcdnKv delete

*全部资源

*

dcdn:DescribeDcdnWafPolicies DescribeDcdnWafPolicies get

*全部资源

*

dcdn:DescribeDcdnDomainRealTimeTrafficData DescribeDcdnDomainRealTimeTrafficData none

domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnWafDefaultRules DescribeDcdnWafDefaultRules get

*全部资源

*

dcdn:TagDcdnResources TagDcdnResources update

*domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:CommitStagingRoutineCode CommitStagingRoutineCode update

*全部资源

*

dcdn:DescribeDcdnDomainQpsDataByLayer DescribeDcdnDomainQpsDataByLayer get

*Domain

acs:dcdn:*:{#accountId}:domain/{#domainName}

dcdn:DescribeDcdnIpaService DescribeDcdnIpaService get

*全部资源

*

资源(Resource)

下表是边缘安全加速定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

domain
  • acs:dcdn:*:{#accountId}:domain/{#domainName}
  • acs:dcdn:*:{#accountId}:domain/*
Domain
  • acs:dcdn:*:{#accountId}:domain/{#domainName}
  • acs:dcdn::{#accountId}:domain/{#DomainName}
  • acs:dcdn:*:{#accountId}:domain/*
IpaDomain
  • acs:dcdn:*:{#accountId}:domain/*
  • acs:dcdn:*:{#accountId}:domain/{#domainName}
WafDomain
  • acs:dcdn:*:{#accountId}:domain/{#domainName}
RealTimeLogDelivery
  • acs:dcdn:*:{#accountId}:domain/*
DeliverTask
  • acs:dcdn:*:{#accountId}:domain/{#domainName}

条件(Condition)

下表是边缘安全加速 定义的产品级条件关键字,这些条件关键字可以在 RAM 权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的通用条件关键字也同样适用边缘安全加速

其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型

条件关键字

描述

类型

dcdn:tag dcdn标签授权 STRING

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: