AliyunServiceRolePolicyForCas

更新时间:
复制 MD 格式

AliyunServiceRolePolicyForCas 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForCas 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2026-08-17 15:01:49

  • 更新时间:2026-08-17 15:01:49

  • 当前版本:v1

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Action": [
        "yundun-ddoscoo:DescribeWebRules",
        "yundun-ddoscoo:DescribeDomains",
        "yundun-ddoscoo:AssociateWebCert",
        "yundun-ddoscoo:DescribeCerts"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "live:DescribeLiveUserDomains",
        "live:SetLiveDomainCertificate",
        "live:DescribeLiveDomainCertificateInfo"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cdn:DescribeUserDomains",
        "cdn:SetDomainServerCertificate",
        "cdn:DescribeDomainCertificateInfo",
        "cdn:BatchSetCdnDomainServerCertificate",
        "cdn:SetCdnDomainSSLCertificate"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "slb:UploadServerCertificate",
        "slb:DeleteServerCertificate",
        "slb:DescribeServerCertificates",
        "slb:DescribeLoadBalancers",
        "slb:DescribeLoadBalancerAttribute",
        "slb:DescribeLoadBalancerHTTPSListenerAttribute",
        "slb:SetLoadBalancerHTTPSListenerAttribute",
        "slb:SetDomainExtensionAttribute",
        "slb:DescribeLoadBalancerSummaryForGlobal"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "scdn:DescribeScdnUserDomains",
        "scdn:SetScdnDomainCertificate",
        "scdn:DescribeScdnDomainCertificateInfo"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "dcdn:DescribeDcdnUserDomains",
        "dcdn:SetDcdnDomainCertificate",
        "dcdn:DescribeDcdnDomainCertificateInfo",
        "dcdn:SetDcdnDomainSSLCertificate"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "alb:ListListenerCertificates",
        "alb:ListListeners",
        "alb:ListLoadBalancers",
        "alb:AssociateAdditionalCertificatesWithListener",
        "alb:DissociateAdditionalCertificatesFromListener",
        "alb:UpdateListenerAttribute",
        "alb:ListAsynJobs",
        "alb:GetGlobalLoadBalancerSummary"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "alidns:AddDomainRecord",
        "alidns:DescribeDomainNs",
        "alidns:GetMainDomainName",
        "alidns:DeleteSubDomainRecords",
        "alidns:DescribeDomains",
        "alidns:DescribeDomainRecords"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "oss:ListBuckets",
        "oss:ListCname",
        "oss:PutCname"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "vod:SetVodDomainCertificate",
        "vod:DescribeVodDomainCertificateInfo",
        "vod:DescribeVodUserDomains"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "apigateway:DescribeApiGroups",
        "apigateway:DescribeApiGroup",
        "apigateway:SetDomainCertificate",
        "apigateway:ModifyApiGroup"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-cert:DescribeSSLCertificatePrivateKey",
        "yundun-cert:DescribeSSLCertificatePublicKeyDetail"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ga:ListAccelerators",
        "ga:DescribeAccelerator",
        "ga:DescribeListener",
        "ga:ListListeners",
        "ga:UpdateListener",
        "ga:AssociateAdditionalCertificatesWithListener",
        "ga:DissociateAdditionalCertificatesFromListener",
        "ga:UpdateAdditionalCertificateWithListener",
        "ga:ListListenerCertificates",
        "ga:DescribeRegions"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "fc:ListCustomDomains",
        "fc:GetCustomDomain",
        "fc:UpdateCustomDomain"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cr:UpdateInstanceCustomizedDomain",
        "cr:ListInstanceDomain",
        "cr:ListInstance",
        "cr:ListInstanceRegion"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "mse:QueryBusinessLocations",
        "mse:ListGatewayDomainSSL",
        "mse:UpdateSSLCertSSL",
        "mse:ListGateway",
        "mse:ListGatewayDomain",
        "mse:UpdateSSLCert",
        "mse:AddSSLCert"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "nlb:ListLoadBalancers",
        "nlb:ListListeners",
        "nlb:UpdateListenerAttribute",
        "nlb:GetGlobalLoadBalancerSummary",
        "nlb:AssociateAdditionalCertificatesWithListener",
        "nlb:DisassociateAdditionalCertificatesWithListener",
        "nlb:ListListenerCertificates",
        "nlb:GetJobStatus"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "webhosting:DeployCert",
        "webhosting:DescribeUserDomains"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "swas:CreateInstances",
        "swas:ListInstanceStatus",
        "swas:UpdateInstanceAttribute",
        "swas:ListInstances",
        "swas:UpgradeInstance"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "swas-open:ListInstanceStatus",
        "swas-open:ListInstances",
        "swas-open:RebootInstance",
        "swas-open:InvokeCommand",
        "swas-open:InstallCloudAssistant",
        "swas-open:DescribeCloudAssistantStatus",
        "swas-open:DescribeInvocationResult",
        "swas-open:RunCommand",
        "swas-open:DescribeInvocations",
        "swas-open:UploadFile",
        "swas-open:DescribeUploadFileResults",
        "swas-open:DescribeCommandInvocations"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ecs:DescribeRegions",
        "ecs:DescribeInstanceStatus",
        "ecs:DescribeInstances",
        "ecs:DescribeCloudAssistantStatus",
        "ecs:DescribeInvocationResults",
        "ecs:DescribeResourceByTags"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-cert:ListPcaCaCertificate"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "eas:AttachGatewayDomain",
        "eas:ListGatewayDomains",
        "eas:ListGateway"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "pai:ListProducts"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "apig:ListDomains",
        "apig:UpdateDomain",
        "apig:GetDomain"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cs:DescribeRegions",
        "cs:DescribeClustersV1",
        "cs:GetClusters",
        "cs:DescribeUserClusterNamespaces",
        "cs:DescribeTaskInfo"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "esa:ListSites",
        "esa:ListHttpsBasicConfigurations",
        "esa:ListCertificates",
        "esa:GetCertificate",
        "esa:SetCertificate",
        "esa:ListInstanceQuotasWithUsage"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "privatelink:ListVpcEndpoints",
        "privatelink:CreateVpcEndpoint",
        "privatelink:GetVpcEndpointAttribute"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ecs:CreateSecurityGroup",
        "ecs:AuthorizeSecurityGroup"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "vpc:CreateVSwitch",
        "vpc:DescribeVSwitches",
        "vpc:DescribeVpcAttribute"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-hsm:GetCluster",
        "yundun-hsm:GetInstance",
        "yundun-hsm:DownloadClusterManagedCert",
        "yundun-hsm:ConfigClusterWhitelist"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "actiontrail:CreateServiceTrail",
        "actiontrail:DeleteServiceTrail",
        "actiontrail:GetServiceTrail",
        "actiontrail:GetServiceTrailDeliveryStatus"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-waf:DescribeCloudResources",
        "yundun-waf:DescribeInstance",
        "yundun-waf:DescribeDomains",
        "yundun-waf:DescribeCloudResourceAccessPortDetails",
        "yundun-waf:ModifyCloudResourceCert",
        "yundun-waf:ModifyDomainCert",
        "yundun-waf:DescribeDomainDetail",
        "yundun-waf:CreateCloudResourceExtensionCert",
        "yundun-waf:DeleteCloudResourceExtensionCert",
        "yundun-waf:ModifyCloudResourceDefaultCert"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "privatelink.aliyuncs.com"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": "yundun-cert:SelfApplyCert",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "yundun-cert:GetPcaTypeByInstanceUuid",
      "Resource": "*"
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "cas.aliyuncs.com"
        }
      }
    }
  ]
}

相关文档