AliyunGovernanceFullAccess

AliyunGovernanceFullAccess 是阿里云管理的产品系统策略,您可以将 AliyunGovernanceFullAccess 授权给 RAM 身份(RAM 用户、RAM 用户组和 RAM 角色),本策略定义了管理云治理中心(Governance)的权限。

策略详情

  • 类型:系统策略

  • 创建时间:2021-07-08 09:31:36

  • 更新时间:2023-08-08 06:17:29

  • 当前版本:v11

策略内容

{
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "governance:*",
      "Resource": "*"
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "governance.aliyuncs.com"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "resourcemanager:GetResourceDirectory",
        "resourcemanager:ListResources",
        "resourcemanager:ListFoldersForParent",
        "resourcemanager:InviteAccountToResourceDirectory",
        "resourcemanager:GetAccount",
        "resourcemanager:GetPayerForAccount",
        "resourcemanager:GetFolder",
        "resourcemanager:ListAccountRecordsForParent",
        "resourcemanager:ListChildrenForParent",
        "resourcemanager:ListAccounts",
        "resourcemanager:ListAccountsForParent",
        "resourcemanager:ListAncestors",
        "resourcemanager:ListDelegatedAdministrators"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ram:GetAccountSummary",
        "ram:ListSAMLProviders"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "config:DescribeDeliveryChannels",
        "config:GetAggregateConfigRuleComplianceByPack",
        "config:ListSupportedProducts",
        "config:ListAggregateConfigRuleEvaluationResults",
        "config:ListCompliancePackTemplates",
        "config:GetManagedRule",
        "config:GetConfigRule",
        "config:ListAggregators",
        "config:DescribeConfigurationRecorder",
        "config:GetAggregateDiscoveredResource",
        "config:ListAggregateResourceEvaluationResults",
        "config:ListAggregateConfigDeliveryChannels",
        "actiontrail:DescribeTrails",
        "config:GetAggregateResourceComplianceByConfigRule"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "cloudsso:GetServiceStatus",
        "cloudsso:ListDirectories",
        "cloudsso:GetExternalSAMLIdentityProvider",
        "cloudsso:GetDirectorySAMLServiceProviderInfo",
        "cloudsso:GetMFAAuthenticationStatus",
        "cloudsso:ListUsers",
        "cloudsso:ListAccessConfigurations",
        "cloudsso:ListGroups"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "cen:ListTransitRouterAvailableResource"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "ram:ListPolicies",
      "Resource": "acs:ram:*:system:policy/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ecs:DescribeImages",
        "ecs:DescribeImageSharePermission",
        "ecs:DescribeRegions"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "log:ListProject",
      "Resource": "acs:log:*:*:project/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "quotas:GetProductQuota"
      ],
      "Resource": "*"
    }
  ],
  "Version": "1"
}

相关文档