AliyunServiceRolePolicyForCas 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForCas 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。
策略详情
类型:系统策略
创建时间:2026-08-17 15:01:49
更新时间:2026-08-17 15:01:49
当前版本:v1
策略内容
{
"Version": "1",
"Statement": [
{
"Action": [
"yundun-ddoscoo:DescribeWebRules",
"yundun-ddoscoo:DescribeDomains",
"yundun-ddoscoo:AssociateWebCert",
"yundun-ddoscoo:DescribeCerts"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"live:DescribeLiveUserDomains",
"live:SetLiveDomainCertificate",
"live:DescribeLiveDomainCertificateInfo"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"cdn:DescribeUserDomains",
"cdn:SetDomainServerCertificate",
"cdn:DescribeDomainCertificateInfo",
"cdn:BatchSetCdnDomainServerCertificate",
"cdn:SetCdnDomainSSLCertificate"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"slb:UploadServerCertificate",
"slb:DeleteServerCertificate",
"slb:DescribeServerCertificates",
"slb:DescribeLoadBalancers",
"slb:DescribeLoadBalancerAttribute",
"slb:DescribeLoadBalancerHTTPSListenerAttribute",
"slb:SetLoadBalancerHTTPSListenerAttribute",
"slb:SetDomainExtensionAttribute",
"slb:DescribeLoadBalancerSummaryForGlobal"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"scdn:DescribeScdnUserDomains",
"scdn:SetScdnDomainCertificate",
"scdn:DescribeScdnDomainCertificateInfo"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"dcdn:DescribeDcdnUserDomains",
"dcdn:SetDcdnDomainCertificate",
"dcdn:DescribeDcdnDomainCertificateInfo",
"dcdn:SetDcdnDomainSSLCertificate"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"alb:ListListenerCertificates",
"alb:ListListeners",
"alb:ListLoadBalancers",
"alb:AssociateAdditionalCertificatesWithListener",
"alb:DissociateAdditionalCertificatesFromListener",
"alb:UpdateListenerAttribute",
"alb:ListAsynJobs",
"alb:GetGlobalLoadBalancerSummary"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"alidns:AddDomainRecord",
"alidns:DescribeDomainNs",
"alidns:GetMainDomainName",
"alidns:DeleteSubDomainRecords",
"alidns:DescribeDomains",
"alidns:DescribeDomainRecords"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"oss:ListBuckets",
"oss:ListCname",
"oss:PutCname"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"vod:SetVodDomainCertificate",
"vod:DescribeVodDomainCertificateInfo",
"vod:DescribeVodUserDomains"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"apigateway:DescribeApiGroups",
"apigateway:DescribeApiGroup",
"apigateway:SetDomainCertificate",
"apigateway:ModifyApiGroup"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"yundun-cert:DescribeSSLCertificatePrivateKey",
"yundun-cert:DescribeSSLCertificatePublicKeyDetail"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"ga:ListAccelerators",
"ga:DescribeAccelerator",
"ga:DescribeListener",
"ga:ListListeners",
"ga:UpdateListener",
"ga:AssociateAdditionalCertificatesWithListener",
"ga:DissociateAdditionalCertificatesFromListener",
"ga:UpdateAdditionalCertificateWithListener",
"ga:ListListenerCertificates",
"ga:DescribeRegions"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"fc:ListCustomDomains",
"fc:GetCustomDomain",
"fc:UpdateCustomDomain"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"cr:UpdateInstanceCustomizedDomain",
"cr:ListInstanceDomain",
"cr:ListInstance",
"cr:ListInstanceRegion"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"mse:QueryBusinessLocations",
"mse:ListGatewayDomainSSL",
"mse:UpdateSSLCertSSL",
"mse:ListGateway",
"mse:ListGatewayDomain",
"mse:UpdateSSLCert",
"mse:AddSSLCert"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"nlb:ListLoadBalancers",
"nlb:ListListeners",
"nlb:UpdateListenerAttribute",
"nlb:GetGlobalLoadBalancerSummary",
"nlb:AssociateAdditionalCertificatesWithListener",
"nlb:DisassociateAdditionalCertificatesWithListener",
"nlb:ListListenerCertificates",
"nlb:GetJobStatus"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"webhosting:DeployCert",
"webhosting:DescribeUserDomains"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"swas:CreateInstances",
"swas:ListInstanceStatus",
"swas:UpdateInstanceAttribute",
"swas:ListInstances",
"swas:UpgradeInstance"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"swas-open:ListInstanceStatus",
"swas-open:ListInstances",
"swas-open:RebootInstance",
"swas-open:InvokeCommand",
"swas-open:InstallCloudAssistant",
"swas-open:DescribeCloudAssistantStatus",
"swas-open:DescribeInvocationResult",
"swas-open:RunCommand",
"swas-open:DescribeInvocations",
"swas-open:UploadFile",
"swas-open:DescribeUploadFileResults",
"swas-open:DescribeCommandInvocations"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"ecs:DescribeRegions",
"ecs:DescribeInstanceStatus",
"ecs:DescribeInstances",
"ecs:DescribeCloudAssistantStatus",
"ecs:DescribeInvocationResults",
"ecs:DescribeResourceByTags"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"yundun-cert:ListPcaCaCertificate"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"eas:AttachGatewayDomain",
"eas:ListGatewayDomains",
"eas:ListGateway"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"pai:ListProducts"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"apig:ListDomains",
"apig:UpdateDomain",
"apig:GetDomain"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"cs:DescribeRegions",
"cs:DescribeClustersV1",
"cs:GetClusters",
"cs:DescribeUserClusterNamespaces",
"cs:DescribeTaskInfo"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"esa:ListSites",
"esa:ListHttpsBasicConfigurations",
"esa:ListCertificates",
"esa:GetCertificate",
"esa:SetCertificate",
"esa:ListInstanceQuotasWithUsage"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"privatelink:ListVpcEndpoints",
"privatelink:CreateVpcEndpoint",
"privatelink:GetVpcEndpointAttribute"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"ecs:CreateSecurityGroup",
"ecs:AuthorizeSecurityGroup"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"vpc:CreateVSwitch",
"vpc:DescribeVSwitches",
"vpc:DescribeVpcAttribute"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"yundun-hsm:GetCluster",
"yundun-hsm:GetInstance",
"yundun-hsm:DownloadClusterManagedCert",
"yundun-hsm:ConfigClusterWhitelist"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"actiontrail:CreateServiceTrail",
"actiontrail:DeleteServiceTrail",
"actiontrail:GetServiceTrail",
"actiontrail:GetServiceTrailDeliveryStatus"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"yundun-waf:DescribeCloudResources",
"yundun-waf:DescribeInstance",
"yundun-waf:DescribeDomains",
"yundun-waf:DescribeCloudResourceAccessPortDetails",
"yundun-waf:ModifyCloudResourceCert",
"yundun-waf:ModifyDomainCert",
"yundun-waf:DescribeDomainDetail",
"yundun-waf:CreateCloudResourceExtensionCert",
"yundun-waf:DeleteCloudResourceExtensionCert",
"yundun-waf:ModifyCloudResourceDefaultCert"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:CreateServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "privatelink.aliyuncs.com"
}
}
},
{
"Effect": "Allow",
"Action": "yundun-cert:SelfApplyCert",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "yundun-cert:GetPcaTypeByInstanceUuid",
"Resource": "*"
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "cas.aliyuncs.com"
}
}
}
]
}相关文档
该文章对您有帮助吗?