权限命令集

更新时间:
复制 MD 格式

本文介绍MaxCompute项目中的权限管理命令全集,包含用户管理、角色管理、用户或角色授权、权限查看等命令。

角色管理

用户管理

角色授权

为角色授予对象的操作权限

  • 为角色授予项目的操作权限

    • 命令

      • ACL授权

        GRANT Read|Write|List|CreateTable|CreateInstance|CreateFunction|CreateResource|All 
              ON project <project_name> 
              TO ROLE <role_name> [privilegeproperties("conditions" = "<conditions>", "expires"="<days>")];
      • 通过ACL语法实现Policy授权

        GRANT Read|Write|List|CreateTable|CreateInstance|CreateFunction|CreateResource|All 
              ON project <project_name> 
              TO ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}"[, "conditions"= "<conditions>", "expires"="<days>"]);
    • 示例

      --ACL授权。
      grant CreateTable, CreateFunction, CreateInstance, List on project test_project_a to ROLE Worker;
      --Policy授权。
      grant CreateTable, CreateFunction, CreateInstance, List 
            on project test_project_a  
            to ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 为角色授予表的操作权限

    • 命令

      • ACL授权

        GRANT Describe|Select|Alter|Update|Drop|ShowHistory|All 
              ON TABLE <table_name> [(<column_list>)] 
              TO ROLE <role_name> [privilegeproperties("conditions" = "<conditions>", "expires"="<days>")];
      • 通过ACL语法实现Policy授权

        GRANT Describe|Select|Alter|Update|Drop|ShowHistory|All 
              ON TABLE <table_name> [(<column_list>)] 
              TO ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}"[, "conditions"= "<conditions>", "expires"="<days>"]);
    • 示例

      --ACL授权。
      grant Describe, Select on table sale_detail to ROLE Worker;
      --Policy授权。
      grant Describe, Select  
            on table sale_detail   
            to ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 为角色授予模型的操作权限

    • 命令

      • ACL授权

        GRANT Describe|Execute|Alter|Drop|All 
              ON MODEL <model_name> 
              TO ROLE <role_name> [privilegeproperties("conditions" = "<conditions>", "expires"="<days>")];
      • 通过ACL语法实现Policy授权

        GRANT Describe|Execute|Alter|Drop|All 
              ON MODEL <model_name> 
              TO ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}"[, "conditions"= "<conditions>", "expires"="<days>"]);
    • 示例

      -- Bob进入test_project_a项目。
      use test_project_a;
      -- ACL授权。
      GRANT All ON MODEL my_model TO ROLE Worker;
      -- 通过ACL语法实现Policy授权。
      GRANT All  
            ON MODEL my_model  
            TO ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 为角色授予资源的操作权限

    • 命令

      • ACL授权

        GRANT Read|Write|Delete|All 
              ON resource <resource_name> 
              TO ROLE <role_name> [privilegeproperties("conditions" = "<conditions>", "expires"="<days>")];
      • 通过ACL语法实现Policy授权

        GRANT Read|Write|Delete|All 
              ON resource <resource_name> 
              TO ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}"[, "conditions"= "<conditions>", "expires"="<days>"]);
    • 示例

      --ACL授权。
      grant Read, Write on resource udtf.jar to ROLE Worker;
      --Policy授权。
      grant Read, Write   
            on resource udtf.jar  
            to ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 为角色授予函数的操作权限

    • 命令

      GRANT Read|Write|Delete|Execute|All 
            ON FUNCTION <function_name> 
            TO ROLE <role_name> [privilegeproperties("conditions" = "<conditions>", "expires"="<days>")];
    • 示例

      --ACL授权。
      grant Read, Write on function udf_test to ROLE Worker;
      --Policy授权。
      grant Read, Write   
            on function udf_test  
            to ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 为角色授予实例的操作权限

    • 命令

      • ACL授权

        GRANT Read|Write|All 
              ON instance <instance_id> 
              TO ROLE <role_name> [privilegeproperties("conditions" = "<conditions>", "expires"="<days>")];
      • 通过ACL语法实现Policy授权

        GRANT Read|Write|All  
              ON instance <instance_id>   
              TO ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}"[, "conditions"= "<conditions>", "expires"="<days>"]);
    • 示例

      --ACL授权。
      grant All on instance 202112300224**** to ROLE Worker;
      --Policy授权。
      grant All    
            on instance 202112300224****   
            to ROLE Worker privilegeproperties("policy" = "true", "allow"="true");

撤销为角色授予的对象的操作权限

  • 撤销为角色授予的项目操作权限

    • 命令

      • 撤销ACL授权

        REVOKE Read|Write|List|CreateTable|CreateInstance|CreateFunction|CreateResource|All 
              ON project <project_name> 
              FROM ROLE <role_name>;
      • 撤销Policy授权

        REVOKE Read|Write|List|CreateTable|CreateInstance|CreateFunction|CreateResource|All 
              ON project <project_name> 
              FROM ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}");
    • 示例

      --撤销ACL授权。
      revoke CreateTable, CreateFunction, CreateInstance, List on project test_project_a from ROLE Worker;
      --撤销Policy授权。
      revoke CreateTable, CreateFunction, CreateInstance, List 
            on project test_project_a  
            from ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 撤销为角色授予的表操作权限

    • 命令

      • 撤销ACL授权

        REVOKE Describe|Select|Alter|Update|Drop|ShowHistory|All 
              ON TABLE <table_name> [(<column_list>)] 
              FROM ROLE <role_name>;
      • 撤销Policy授权

        REVOKE Describe|Select|Alter|Update|Drop|ShowHistory|All 
              ON TABLE <table_name> [(<column_list>)] 
              FROM ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}");
    • 示例

      --撤销ACL授权。
      revoke Describe, Select on table sale_detail from ROLE Worker;
      --撤销Policy授权。
      revoke Describe, Select  
            on table sale_detail   
            from ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 撤销为角色授予的模型的操作权限

    • 命令

      • 撤销ACL授权

        REVOKE Describe|Execute|Alter|Drop|All 
              ON MODEL <model_name>
              FROM ROLE <role_name>;
      • 撤销Policy授权

        REVOKE Describe|Execute|Alter|Drop|All 
              ON MODEL <model_name> 
              FROM ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}");
    • 示例

      -- Bob进入test_project_a项目。
      use test_project_a;
      -- 撤销ACL授权。
      REVOKE All ON MODEL my_model FROM ROLE Worker;
      -- 撤销Policy授权。
      REVOKE All  
            ON MODEL my_model  
            FROM ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 撤销为角色授予的资源操作权限

    • 命令

      • 撤销ACL授权

        REVOKE Read|Write|Delete|All 
              ON resource <resource_name> 
              FROM ROLE <role_name>;
      • 撤销Policy授权

        REVOKE Read|Write|Delete|All 
              ON resource <resource_name> 
              FROM ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}");
    • 示例

      --撤销ACL授权。
      revoke Read, Write on resource udtf.jar from ROLE Worker;
      --撤销Policy授权。
      revoke Read, Write   
            on resource udtf.jar  
            from ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 撤销为角色授予的函数操作权限

    • 命令

      • 撤销ACL授权

        REVOKE Read|Write|Delete|Execute|All 
              ON FUNCTION <function_name> 
              FROM ROLE <role_name>;
      • 撤销Policy授权

        REVOKE Read|Write|Delete|Execute|All 
              ON FUNCTION <function_name>  
              FROM ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}");
    • 示例

      --撤销ACL授权。
      revoke Read, Write on function udf_test from ROLE Worker;
      --撤销Policy授权。
      revoke Read, Write   
            on function udf_test  
            from ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
  • 撤销为角色授予的实例操作权限

    • 命令

      REVOKE Read|Write|All  
            ON instance <instance_id>   
            FROM ROLE <role_name> privilegeproperties("policy" = "true", "{allow}"="{true|false}");
    • 示例

      --撤销ACL授权。
      revoke All on instance 202112300224**** from ROLE Worker;
      --撤销Policy授权。
      revoke All    
            on instance 202112300224****   
            from ROLE Worker privilegeproperties("policy" = "true", "allow"="true");

为角色授予Download权限

  • 命令

    GRANT Download ON {Table|Resource|Function|Instance} <object_name> TO ROLE <role_name>;
  • 示例

    grant download on table sale_detail to ROLE Worker;

撤销为角色授予的Download权限

  • 命令

    REVOKE Download ON {Table|Resource|Function|Instance} <object_name> FROM ROLE <role_name>;
  • 示例

    revoke download on table sale_detail from ROLE Worker;

为角色授予访问高敏感等级数据的权限

  • 命令

    GRANT Label <number> ON TABLE <table_name> [(<column_list>)] TO ROLE <role_name> [WITH exp <days>];
  • 示例

    grant Label 4 on table sale_detail to ROLE Worker;

撤销为角色授予的访问高敏感等级数据的权限

  • 命令

    REVOKE Label ON TABLE <table_name> [(<column_list>)] FROM ROLE <role_name>;
  • 示例

    revoke Label on table sale_detail from ROLE Worker;

将角色赋予用户

  • 命令

    GRANT <role_name> TO <user_name>;
  • 示例

    grant Worker to ALIYUN$Ka**@aliyun.com;
    grant Worker to RAM$Bo*@aliyun.com:Allen;

收回赋予用户的角色

  • 命令

    REVOKE <role_name> FROM <user_name>;
  • 示例

    revoke Worker from ALIYUN$Ka**@aliyun.com;
    revoke Worker from RAM$Bo*@aliyun.com:Allen;

用户授权

为用户赋予操作权限

  • 为用户授予项目的操作权限

    • 命令

      grant Read|Write|List|CreateTable|CreateInstance|CreateFunction|CreateResource|All
            on project <project_name>
            to USER <user_name> [privilegeproperties("conditions" = "<conditions>",
    • 示例

      grant CreateTable, CreateFunction, CreateInstance, List on project test_project_a to user RAM$Ka**@aliyun.com:Lily;
  • 为用户授予表的操作权限

    • 命令

      grant Describe|Select|Alter|Update|Drop|ShowHistory|All
            on table <table_name> [(<column_list>)]
            to USER <user_name> [privilegeproperties("conditions" = "<conditions>"
    • 示例

      grant Describe, Select on table sale_detail to USER RAM$Bo*@aliyun.com:Allen;
  • 为用户授予资源的操作权限

    • 命令

      grant Read|Write|Delete|All
            on resource <resource_name>
            to USER <user_name> [privilegeproperties("conditions" = "<conditions>",
    • 示例

      grant Read, Write on resource udtf.jar to USER RAM$Bo*@aliyun.com:Alice;
  • 为用户授予函数的操作权限

    • 命令

      grant Read|Write|Delete|Execute|All
            on function <function_name>
            to USER <user_name> [privilegeproperties("conditions" = "<conditions>"
    • 示例

      grant Read, Write on function udf_test to USER RAM$Bo*@aliyun.com:Tom;
  • 为用户授予实例的操作权限

    • 命令

      grant Read|Write|All
            on instance <instance_id>
            to USER <user_name> [privilegeproperties("conditions" = "<conditions>"
    • 示例

      grant All on instance 202112300224**** to USER RAM$Bo*@aliyun.com:Tom;

撤销用户操作权限

  • 撤销为用户授予的项目的操作权限

    • 命令

      revoke Read|Write|List|CreateTable|CreateInstance|CreateFunction|CreateResource|All
            on project <project_name>
            from USER <user_name>;
    • 示例

      revoke CreateTable, CreateFunction, CreateInstance, List on project test_project_a from user RAM$Ka**@aliyun.com:Lily;
  • 撤销为用户授予的表的操作权限

    • 命令

      revoke Describe|Select|Alter|Update|Drop|ShowHistory|All
            on table <table_name> [(<column_list>)]
            from USER <user_name>;
    • 示例

      revoke Describe, Select on table sale_detail from USER RAM$Bo*@aliyun.com:Allen;
  • 撤销为用户授予的资源的操作权限

    • 命令

      revoke Read|Write|Delete|All
            on resource <resource_name>
            from USER <user_name>;
    • 示例

      revoke Read, Write on resource udtf.jar from USER RAM$Bo*@aliyun.com:Alice;
  • 撤销为用户授予的函数的操作权限

    • 命令

      revoke Read|Write|Delete|Execute|All
            on function <function_name>
            from USER <user_name>;
    • 示例

      revoke Read, Write on function udf_test from USER RAM$Bo*@aliyun.com:Tom;
  • 撤销为用户授予的实例的操作权限

    • 命令

      revoke Read|Write|All
            on instance <instance_id>
            from USER <user_name>;
    • 示例

      revoke All on instance 202112300224**** from USER RAM$Bo*@aliyun.com:Tom;

为角色授予对象的操作权限并将角色赋予用户

--为角色Worker授权。
   --ACL授权。
grant CreateTable, CreateFunction, CreateInstance, List on project test_project_a to ROLE Worker;
   --Policy授权。
grant CreateTable, CreateFunction, CreateInstance, List 
      on project test_project_a  
      to ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
--将角色Worker赋予用户。
grant Worker to RAM$Bo*@aliyun.com:Allen;
grant Worker to RAM$Bo*@aliyun.com:Alice;
grant Worker to RAM$Bob@aliyun.com:Tom;

撤销为角色授予的对象的操作权限或收回赋予用户的角色

--为角色Worker撤销授权。
   --撤销ACL授权。
revoke CreateTable, CreateFunction, CreateInstance, List on project test_project_a from ROLE Worker;
   --撤销Policy授权。
revoke CreateTable, CreateFunction, CreateInstance, List 
      on project test_project_a  
      from ROLE Worker privilegeproperties("policy" = "true", "allow"="true");
--或
--收回赋予用户的角色Worker。
revoke Worker from RAM$Bo*@aliyun.com:Allen;

为用户授予Download权限

  • 命令

    grant Download on {Table|Resource|Function|Instance} <object_name> to USER <user_name>;
  • 示例

    grant Download on table sale_detail to USER RAM$Bo*@aliyun.com:Allen;

收回为用户授予的Download权限

  • 命令

    revoke Download on {Table|Resource|Function|Instance} <object_name> from USER <user_name>;
  • 示例

    revoke Download on table sale_detail from USER RAM$Bo*@aliyun.com:Allen;

为角色授予Download权限并将角色赋予用户

--创建角色Worker。
create role Worker;
--为角色Worker授权。
grant download on table sale_detail to ROLE Worker;
--将角色Worker赋予用户。
grant Worker to RAM$Bo*@aliyun.com:Allen;
grant Worker to RAM$Bo*@aliyun.com:Alice;
grant Worker to RAM$Bob@aliyun.com:Tom;

撤销为角色授予的Download权限或收回赋予用户的角色

-为角色Worker撤销授权。
revoke download on table sale_detail from ROLE Worker;
--或
--收回赋予用户的角色Worker。
revoke Worker from RAM$Bo*@aliyun.com:Allen;

为用户授予访问高敏感等级数据的权限

  • 命令

    grant Label <number> on table <table_name> [(<column_list>)] to USER <user_name> [with exp <days>];
  • 示例

    grant Label 4 on table sale_detail to USER RAM$Bo*@aliyun.com:Allen;

撤销为用户授予的访问高敏感等级数据的权限

  • 命令

    revoke Label on table <table_name> [(<column_list>)] from USER <user_name>;
  • 示例

    revoke Label on table sale_detail from ROLE Worker;

为角色授予访问高敏感等级数据的权限并将角色赋予用户

--创建角色Worker。
create role Worker;
--为角色Worker授权。
grant Label 4 on table * to ROLE Worker;
--将角色Worker赋予用户。
grant Worker to RAM$Bo*@aliyun.com:Allen;
grant Worker to RAM$Bo*@aliyun.com:Alice;
grant Worker to RAM$Bob@aliyun.com:Tom;

撤销为角色授予的访问高敏感等级数据的权限或收回赋予用户的角色

-为角色Worker撤销授权。
revoke Label on table * from ROLE Worker;
--或
--收回赋予用户的角色Worker。
revoke Worker from RAM$Bo*@aliyun.com:Allen;

彻底清除被删除用户遗留的权限信息

  • 命令

    purge privs from user <user_name>;
  • 示例

    purge privs from user RAM$Bo*@aliyun.com:Allen;

查询权限信息

查询指定角色的权限及绑定的用户信息

查询指定角色的权限及绑定的用户信息详情请参见查询指定角色的权限及绑定的用户信息。

  • 命令

    describe role <role_name>;
  • 示例

    describe role Worker;

查询用户的权限信息

查询对象的ACL授权信息

查询对象的ACL授权信息详情请参见查询指定对象的ACL授权信息。

  • 命令

    show acl for <object_name> [on type <object_type>];
  • 示例

    show acl for test_project_a on type project;

查询Label权限信息

查询Package授权信息

  • 查询指定Package的授权信息

    • 命令

      show acl for <project_name>.<package_name> on type package;
    • 示例

      show acl for test_project_b.datashare on type package;
  • 查询指定Package内资源的授权信息

    • 命令

      show grants on <object_type> <object_name> privilegeproperties ("refobject"="true", "refproject"="<project_name>", "package"="<package
      _name>");
    • 示例

      show grants on Table sale_detail privilegeproperties ("refobject"="true", "refproject"="test_project_a", "package"="datashare");
  • 查询指定Package内表的Label授权信息

    • 命令

      show label grants on table <table_name> privilegeproperties ("refobject"="true", "refproject"="<project_name>", "package"="<package_name>");
    • 示例

      show label grants on table sale_detail privilegeproperties ("refobject"="true", "refproject"="test_project_a", "package"="datashare");

查看项目空间安全配置信息

  • 项目空间数据保护

    • 开启或关闭项目空间数据保护机制

      set ProjectProtection=true|false;
    • 查看项目空间的安全配置

      show SecurityConfiguration;

      返回结果中有ProjectProtection=true|false,对应项目空间数据保护机制已开启或关闭。

  • 查看已添加的可信的项目空间

    list trustedprojects;
  • LabelSecurity权限控制策略

    • 开启或关闭LabelSecurity权限控制策略

      set LabelSecurity=true|false;
    • 查看项目空间的安全配置

      show SecurityConfiguration;

      返回结果中有LabelSecurity=true|false,对应项目空间LabelSecurity权限控制策略已开启或关闭。

  • Download权限控制功能

    • 开启或关闭Download权限控制功能

      setproject odps.security.enabledownloadprivilege=true|false;
    • 查看项目空间属性

      setproject;

      返回结果中有odps.security.enabledownloadprivilege = true|false,对应项目空间Download权限控制功能已开启或关闭。