PolarDB服务关联角色

本文为您介绍PolarDB服务关联角色(AliyunServiceRoleForPolarDB)的应用场景以及如何删除服务关联角色。

背景信息

PolarDB服务关联角色(AliyunServiceRoleForPolarDB)是在某些情况下,为了完成PolarDB自身的某个功能,需要获取其他云服务的访问权限,而提供的RAM角色。更多关于服务关联角色的信息请参见服务关联角色

应用场景

AliyunServiceRoleForPolarDB介绍

角色名称:AliyunServiceRoleForPolarDB

角色权限策略:AliyunServiceRolePolicyForPolarDB

权限说明:

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "pvtz:DescribeUserServiceStatus",
                "pvtz:DescribeZones",
                "pvtz:DescribeZoneInfo",
                "pvtz:DescribeZoneRecords",
                "pvtz:CheckZoneName",
                "pvtz:AddZone",
                "pvtz:BindZoneVpc",
                "pvtz:DeleteZone",
                "pvtz:AddZoneRecord",
                "pvtz:UpdateZoneRecord",
                "pvtz:DeleteZoneRecord",
                "dts:CreateDtsInstance",
                "dts:ConfigureDtsJob",
                "dts:StartDtsJob",
                "dts:DescribePreCheckStatus",
                "dts:DescribeDtsJobDetail",
                "dts:DescribeDtsJobs",
                "dts:ModifyDtsJob",
                "dts:SuspendDtsJob",
                "dts:StopDtsJob",
                "dts:DeleteDtsJob",
                "dts:CheckDefaultRole",
                "dts:ReverseTwoWayDirection",
                "dts:ModifyDtsJobEndpoint",
                "privatelink:ListVpcEndpointServicesByEndUser",
                "privatelink:CreateVpcEndpoint",
                "privatelink:ListVpcEndpoints",
                "privatelink:UpdateVpcEndpointAttribute",
                "privatelink:GetVpcEndpointAttribute",
                "privatelink:ListVpcEndpointSecurityGroups",
                "privatelink:AttachSecurityGroupToVpcEndpoint",
                "privatelink:DetachSecurityGroupFromVpcEndpoint",
                "privatelink:AddZoneToVpcEndpoint",
                "privatelink:RemoveZoneFromVpcEndpoint",
                "privatelink:ListVpcEndpointZones",
                "privatelink:DeleteVpcEndpoint",
                "ecs:CreateNetworkInterface",
                "ecs:DeleteNetworkInterface",
                "ecs:DeleteNetworkInterfacePermission",
                "ecs:AttachNetworkInterface",
                "ecs:DetachNetworkInterface",
                "ecs:DescribeNetworkInterfaceAttribute",
                "ecs:DescribeNetworkInterfaces",
                "ecs:ModifyNetworkInterfaceAttribute",
                "ecs:CreateNetworkInterfacePermission",
                "ecs:DescribeNetworkInterfacePermissions",
                "ecs:DescribeSecurityGroupAttribute",
                "ecs:DescribeSecurityGroups",
                "vpc:DescribeVSwitches",
                "vpc:DescribeVpcs",
                "dms:AddInstance",
                "dms:ListInstances",
                "dms:GetInstance"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "polardb.aliyuncs.com"
                }
            }
        },
        {
            "Action": "ram:CreateServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "privatelink.aliyuncs.com"
                }
            }
        }
    ]
}

删除服务关联角色

如果您需要删除AliyunServiceRoleForPolarDB(服务关联角色),需要先释放依赖这个服务关联角色的PolarDB集群。