AliyunAdcpServerlessKubernetesRolePolicy

AliyunAdcpServerlessKubernetesRolePolicy 是专用于服务角色的授权策略,通常会在创建对应的服务角色时同步完成授权,以允许服务角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2024-02-26 17:27:13

  • 更新时间:2024-12-13 10:40:53

  • 当前版本:v2

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Action": [
        "arms:GetManagedPrometheusStatus",
        "arms:InstallManagedPrometheus",
        "arms:UninstallManagedPrometheus"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "vpc:DescribeVSwitches",
        "vpc:DescribeVpcs",
        "vpc:AssociateEipAddress",
        "vpc:DescribeEipAddresses",
        "vpc:AllocateEipAddress",
        "vpc:ReleaseEipAddress",
        "vpc:AddCommonBandwidthPackageIp",
        "vpc:RemoveCommonBandwidthPackageIp"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ecs:DescribeSecurityGroups",
        "ecs:CreateNetworkInterface",
        "ecs:CreateNetworkInterfacePermission",
        "ecs:DescribeNetworkInterfaces",
        "ecs:AttachNetworkInterface",
        "ecs:DetachNetworkInterface",
        "ecs:DeleteNetworkInterface",
        "ecs:DeleteNetworkInterfacePermission"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "pvtz:AddZone",
        "pvtz:DeleteZone",
        "pvtz:DescribeZones",
        "pvtz:DescribeZoneInfo",
        "pvtz:BindZoneVpc",
        "pvtz:AddZoneRecord",
        "pvtz:DeleteZoneRecord",
        "pvtz:DeleteZoneRecordsByRR",
        "pvtz:DescribeZoneRecordsByRR",
        "pvtz:DescribeZoneRecords"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cr:Get*",
        "cr:List*",
        "cr:PullRepository"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "eci:CreateContainerGroup",
        "eci:DeleteContainerGroup",
        "eci:DescribeContainerGroups",
        "eci:DescribeContainerGroupStatus",
        "eci:DescribeContainerGroupEvents",
        "eci:DescribeContainerLog",
        "eci:UpdateContainerGroup",
        "eci:UpdateContainerGroupByTemplate",
        "eci:CreateContainerGroupFromTemplate",
        "eci:RestartContainerGroup",
        "eci:ExportContainerGroupTemplate",
        "eci:DescribeContainerGroupMetric",
        "eci:DescribeMultiContainerGroupMetric",
        "eci:ResizeContainerGroupVolume",
        "eci:ExecContainerCommand",
        "eci:CreateImageCache",
        "eci:DescribeImageCaches",
        "eci:DeleteImageCache"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "log:CreateProject",
        "log:GetProject",
        "log:DeleteProject",
        "log:CreateLogStore",
        "log:GetLogStore",
        "log:UpdateLogStore",
        "log:DeleteLogStore",
        "log:CreateConfig",
        "log:UpdateConfig",
        "log:GetConfig",
        "log:DeleteConfig",
        "log:CreateMachineGroup",
        "log:UpdateMachineGroup",
        "log:GetMachineGroup",
        "log:DeleteMachineGroup",
        "log:ApplyConfigToGroup",
        "log:GetAppliedMachineGroups",
        "log:GetAppliedConfigs",
        "log:RemoveConfigFromMachineGroup",
        "log:CreateIndex",
        "log:GetIndex",
        "log:UpdateIndex",
        "log:DeleteIndex",
        "log:CreateSavedSearch",
        "log:GetSavedSearch",
        "log:UpdateSavedSearch",
        "log:DeleteSavedSearch",
        "log:CreateDashboard",
        "log:GetDashboard",
        "log:UpdateDashboard",
        "log:DeleteDashboard",
        "log:CreateJob",
        "log:GetJob",
        "log:DeleteJob",
        "log:PostLogStoreLogs",
        "log:UpdateJob"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
        {
            "Action": [
                "acc:DescribeZones",
                "acc:CreateInstance",
                "acc:UpdateInstance",
                "acc:DeleteInstance",
                "acc:RestartInstance",
                "acc:DescribeInstances",
                "acc:DescribeInstanceStatus",
                "acc:DescribeInstanceEvents",
                "acc:DescribeInstanceDetail",
                "acc:DescribeMultiInstanceMetric",
                "acc:DescribeContainerLog",
                "acc:ResizeInstanceVolume",
                "acc:CreateCustomResource",
                "acc:UpdateCustomResource",
                "acc:DeleteCustomResource",
                "acc:DescribeCustomResources",
                "acc:DescribeCustomResourceDetail"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },    
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "eci.aliyuncs.com"
        }
      }
    }
  ]
}

相关文档