AliyunServiceRolePolicyForCloudMonitor

更新时间:
复制 MD 格式

AliyunServiceRolePolicyForCloudMonitor 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForCloudMonitor 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2025-10-29 10:40:57

  • 更新时间:2026-09-09 18:54:59

  • 当前版本:v184

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "cloudmonitor.aliyuncs.com"
        }
      }
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": [
            "ess.aliyuncs.com",
            "fc.aliyuncs.com",
            "privatelink.aliyuncs.com",
            "arms.aliyuncs.com",
            "xtrace.aliyuncs.com",
            "rmc.resourcemanager.aliyuncs.com",
            "audit.log.aliyuncs.com",
            "cloudmonitor.aliyuncs.com",
            "middlewarelens.log.aliyuncs.com",
            "securitylens.log.aliyuncs.com",
            "ai-lens.log.aliyuncs.com",
            "storagelens.log.aliyuncs.com",
            "sysom.aliyuncs.com",
            "secretsmanager-polardb.kms.aliyuncs.com",
            "operation-platform.aliyuncs.com",
            "agentidentity.aliyuncs.com"
          ]
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "ecs:RunCommand",
        "ecs:DescribeInvocations",
        "ecs:DescribeCloudAssistantStatus"
      ],
      "Resource": [
        "acs:ecs:*:*:instance/*",
        "acs:ecs:*:*:command/*"
      ]
    },
    {
      "Effect": "Allow",
      "Action": [
        "actiontrail:LookupEvents",
        "adb:Describe*",
        "adb:List*",
        "adcp:Describe*",
        "adcp:GrantUserPermission",
        "agentloop:GetAgentSpace",
        "ahas:Query*",
        "ahas:Search*",
        "aire:List*",
        "airec:List*",
        "airec:Describe*",
        "alb:List*",
        "alidns:Describe*",
        "alikafka:Get*",
        "alikafka:List*",
        "amqp:List*",
        "apig:Get*",
        "apig:List*",
        "apigateway:Describe*",
        "arms:AddAliClusterIdsToPrometheusGlobalView",
        "arms:AddPrometheusGlobalViewByAliClusterIds",
        "arms:Check*",
        "arms:createAliYunRecordingRuleYaml",
        "arms:CreateEnvironment",
        "arms:CreatePrometheusAlertRules",
        "arms:CreatePrometheusInstance",
        "arms:CreateTimingSyntheticTask",
        "arms:DeleteAddonRelease",
        "arms:DeleteEnvironmentFeature",
        "arms:DeletePrometheusAlertRules",
        "arms:DeletePrometheusGlobalView",
        "arms:DeleteTimingSyntheticTask",
        "arms:Describe*",
        "arms:EnableGraphResource",
        "arms:Get*",
        "arms:InitEnvironment",
        "arms:InstallAddon",
        "arms:InstallEnvironmentFeature",
        "arms:List*",
        "arms:Query*",
        "arms:RemoveAliClusterIdsFromPrometheusGlobalView",
        "arms:Search*",
        "arms:TagResourcesSystemTags",
        "arms:UninstallPromCluster",
        "arms:UntagResourcesSystemTags",
        "arms:UpdateDeliverTask",
        "arms:UpdateTimingSyntheticTask",
        "arms:UpgradeAddonRelease",
        "arms:UpgradeEnvironmentFeature",
        "arms:CreateDispatchRule",
        "arms:DeleteDispatchRule",
        "arms:UpdateDispatchRule",
        "asi:Describe*",
        "asi:Get*",
        "bbebo:List*",
        "bd:Describe*",
        "bss:ModifyInstance",
        "bssapi:QueryCostUnit",
        "bssapi:QueryCostUnitResource",
        "bssapi:QueryRelationList",
        "cd:Describe*",
        "cdd:Describe*",
        "cdn:Describe*",
        "cdn:StopCdnDomain",
        "cen:Describe*",
        "cen:List*",
        "clickhouse:Describe*",
        "cloudphon:List*",
        "cms:BatchExport",
        "cms:BatchGet",
        "cms:CreateAddonRelease",
        "cms:CreateAggTaskGroup*",
        "cms:CreateAlertEventIntegrationPolicy",
        "cms:CreateApplicationInsightsInstance",
        "cms:CreateChat",
        "cms:CreateCloudResource",
        "cms:CreateDataset",
        "cms:CreateEntityStore",
        "cms:CreateEvaluationTask",
        "cms:CreateExperimentTask",
        "cms:CreateInstantSiteMonitor",
        "cms:CreateIntegrationPolicy",
        "cms:CreatePrometheus*",
        "cms:CreateService",
        "cms:CreateServiceObservability",
        "cms:CreateSiteMonitor",
        "cms:CreateThread",
        "cms:CreateTicket",
        "cms:CreateUmodel",
        "cms:Cursor",
        "cms:DeleteAddonRelease",
        "cms:DeleteAggTaskGroup*",
        "cms:DeleteAlertEventIntegrationPolicy",
        "cms:DeleteCloudResource",
        "cms:DeleteDataset",
        "cms:DeleteMetricRules",
        "cms:DeletePrometheus*",
        "cms:DeleteService",
        "cms:DeleteSiteMonitor",
        "cms:DeleteSiteMonitors",
        "cms:DeleteUmodelCommonSchemaRef",
        "cms:DeleteUmodelData",
        "cms:Describe*",
        "cms:DisableAlertEventIntegrationPolicy",
        "cms:DisableHighResolutionMonitor",
        "cms:DisableSiteMonitor",
        "cms:DisableSiteMonitors",
        "cms:EnableActiveMetricRule",
        "cms:EnableAlertEventIntegrationPolicy",
        "cms:EnableHighResolutionMonitor",
        "cms:EnableSiteMonitor",
        "cms:EnableSiteMonitors",
        "cms:ExecuteQuery",
        "cms:Get*",
        "cms:InstallMonitoringAgent",
        "cms:List*",
        "cms:Check*",
        "cms:PutResourceMetricRule",
        "cms:PutWorkspace",
        "cms:Query*",
        "cms:SubscribeRcaEvents",
        "cms:SyncAlertRulesByGroup",
        "cms:UninstallMonitoringAgent",
        "cms:UpdateAddonRelease",
        "cms:UpdateAggTaskGroup*",
        "cms:UpdateAlertEventIntegrationPolicy",
        "cms:UpdateAlertRuleKvs",
        "cms:UpdateDataset",
        "cms:UpdatePrometheus*",
        "cms:UpdateService",
        "cms:UpdateServiceObservability",
        "cms:UpdateSiteMonitor",
        "cms:UpdateUmodel",
        "cms:UpsertUmodelCommonSchemaRef",
        "cms:UpsertUmodelData",
        "cms:UpdateMission",
        "cms:CreateAlertRule",
        "cms:UpdateAlertRule",
        "cms:DeleteAlertRules",
        "cms:SyncAlertRuleTemplatesByRunbook",
        "cms:UnapplyAlertRuleTemplate",
        "cms:ApplyAlertRuleTemplate",
        "cms:*ObserveGroup",
        "cms:PatchAlertRule",
        "cms:ManageAlertRules",
        "cms:RunOneResourceReport",
        "cms:*ResourceReportSchedule",
        "cms:DeleteEntityHealthRules",
        "cms:CreateEntityHealthRules",
        "cms:UpdateEntityHealthRules",
        "cms:ListEntityHealthRules",
        "cms:CreateAlertRuleTemplate",
        "cms:UpdateAlertRuleTemplate",
        "cms:DeleteAlertRuleTemplate",
        "cms:CreateEntityBundleInstance",
        "cms:TriggerEntitySync",
        "clickhouse:Describe*",
        "cs:AttachInstances",
        "cs:CheckKritisInstall",
        "cs:DeleteClusterNode",
        "cs:DeleteClusterNodes",
        "cs:DeleteKritisAttestationAuthority",
        "cs:DeleteKritisGenericAttestationPolicy",
        "cs:Describe*",
        "cs:Get*",
        "cs:InstallClusterAddons",
        "cs:InstallKritis",
        "cs:InstallKritisAttestationAuthority",
        "cs:InstallKritisGenericAttestationPolicy",
        "cs:List*",
        "cs:RevokeClusterInnerServiceKubeconfig",
        "cs:ScaleCluster",
        "cs:UnInstallClusterAddons",
        "cs:UninstallKritis",
        "cs:UpdateClusterAuditLogConfig",
        "cs:UpdateClusterTags",
        "cs:UpdateKritisAttestationAuthority",
        "cs:UpdateKritisGenericAttestationPolicy",
        "cs:UpgradeCluster",
        "cs:UpgradeClusterAddons",
        "dataworks:List*",
        "dbf:List*",
        "dcdn:Describe*",
        "dd:List*",
        "dds:Describe*",
        "dlf:Get*",
        "dlf:List*",
        "domain:Query*",
        "drds:Describe*",
        "drds:List*",
        "dts:Describe*",
        "ea:List*",
        "eas:Describe*",
        "eas:Get*",
        "eas:List*",
        "ecd:Describe*",
        "eci:Describe*",
        "ecs:AttachNetworkInterface",
        "ecs:AuthorizeSecurityGroup",
        "ecs:AuthorizeSecurityGroupEgress",
        "ecs:CreateCommand",
        "ecs:CreateNetworkInterface",
        "ecs:CreateNetworkInterfacePermission",
        "ecs:CreateSecurityGroup",
        "ecs:DeleteCommand",
        "ecs:DeleteNetworkInterfacePermission",
        "ecs:Describe*",
        "ecs:DetachNetworkInterface",
        "ecs:InstallCloudAssistant",
        "ecs:InvokeCommand",
        "ecs:List*",
        "ecs:ModifyCommand",
        "ecs:ModifyNetworkInterfaceAttribute",
        "ecs:RevokeSecurityGroup",
        "ecs:StopInvocation",
        "sysom:InitialSysom",
        "sysom:InvokeDiagnosis",
        "sysom:GetDiagnosisResult",
        "sysom:InstallAgent",
        "sysom:GetAgentTask",
        "sysom:ListInstanceStatus",
        "sysom:UninstallAgent",
        "sysom:UninstallAgentWithType",
        "sysom:InstallAgentWithType",
        "eflo:List*",
        "ehpc:List*",
        "eipanycas:List*",
        "elasticsearch:List*",
        "emr-serverless-spark:List*",
        "emr:List*",
        "ens:Describe*",
        "es:Describe*",
        "esa:List*",
        "ess:Describe*",
        "ess:ExecuteScalingRule",
        "eventbridge:CheckRoleForProduct",
        "eventbridge:CheckServiceLinkedRoleForProduct",
        "eventbridge:CreateEventBus",
        "eventbridge:CreateRule",
        "eventbridge:CreateTargets",
        "eventbridge:DeleteEventBus",
        "eventbridge:DeleteRule",
        "eventbridge:DeleteTargets",
        "eventbridge:DisableRule",
        "eventbridge:EnableRule",
        "eventbridge:Get*",
        "eventbridge:List*",
        "eventbridge:PutEvents",
        "eventbridge:PutTargets",
        "eventbridge:*EventStreaming",
        "eventbridge:UpdateRule",
        "expressconnectrouter:Describe*",
        "fc:Get*",
        "fc:InvokeFunction",
        "fc:List*",
        "featurestore:Get*",
        "featurestore:List*",
        "ga:List*",
        "gdb:Describe*",
        "graphcompute:List*",
        "gwlb:List*",
        "hbase:Describe*",
        "hbr_vaul:Describe*",
        "hcs-sgw:describe*",
        "hd:Describe*",
        "hdf:List*",
        "hdm:CreateRequestDiagnosis",
        "hdm:Describe*",
        "hdm:Get*",
        "hitsdb:Describe*",
        "hitsdb:Get*",
        "hologram:List*",
        "im:List*",
        "io:Query*",
        "kms:Decrypt",
        "kms:DescribeKey",
        "kms:Encrypt",
        "kms:GenerateDataKey",
        "kms:GenerateDataKeyWithoutPlaintext",
        "kms:List*",
        "kms:TagResource",
        "kms:UntagResource",
        "kvstore:Describe*",
        "lindorm:Describe*",
        "lindorm:Get*",
        "lindorm:List*",
        "lindorm:UpdateInstanceIpWhiteList",
        "log:*MetricStore*",
        "log:*ScheduledSQL*",
        "log:ApplyConfigToGroup",
        "log:BatchGet*",
        "log:BatchPostLogStoreLogs",
        "log:CallAiTools",
        "log:CloseProductDataCollection",
        "log:ConsumerGroupHeartBeat",
        "log:ConsumerGroupUpdateCheckPoint",
        "log:CreateAgentInstanceConfig",
        "log:CreateApp",
        "log:CreateConsumerGroup",
        "log:CreateDashboard",
        "log:CreateEtlMeta",
        "log:CreateIndex",
        "log:CreateJob",
        "log:CreateLogging",
        "log:CreateLogStore",
        "log:CreateLogtailPipelineConfig",
        "log:CreateMachineGroup",
        "log:CreateMetricsConfig",
        "log:CreateProject",
        "log:CreateResourceRecord",
        "log:CreateScheduledSQL",
        "log:CreateStoreView",
        "log:DeleteAgentInstanceConfig",
        "log:DeleteConsumerGroup",
        "log:DeleteEtlMeta",
        "log:DeleteIndex",
        "log:DeleteJob",
        "log:DeleteLogging",
        "log:DeleteLogStore",
        "log:DeleteLogtailPipelineConfig",
        "log:DeleteMachineGroup",
        "log:DeleteProject",
        "log:DeleteProjectPolicy",
        "log:DeleteProjectQuery",
        "log:DeleteScheduledSQL",
        "log:DeleteStoreView",
        "log:Describe*",
        "log:Get*",
        "log:List*",
        "log:ModifyJobInstance",
        "log:OpenProductDataCollection",
        "log:PostLogStoreLogs",
        "log:PostProjectQuery",
        "log:PullLogs",
        "log:PutLogStoreMultimodalConfiguration",
        "log:PutProjectPolicy",
        "log:PutProjectQuery",
        "log:Query*",
        "log:RemoveConfigFromGroup",
        "log:SplitShard",
        "log:TagResources",
        "log:UntagResources",
        "log:UpdateAgentInstanceConfig",
        "log:UpdateApp",
        "log:UpdateCheckPoint",
        "log:UpdateConsumerGroup",
        "log:UpdateConsumerGroupCheckPoint",
        "log:UpdateDashboard",
        "log:UpdateEtlMeta",
        "log:UpdateIndex",
        "log:UpdateJob",
        "log:UpdateLogging",
        "log:UpdateLogStore",
        "log:UpdateLogtailPipelineConfig",
        "log:UpdateMachineGroup",
        "log:UpdateMachineGroupMachine",
        "log:UpdateMetricsConfig",
        "log:UpdateProject",
        "log:UpdateResourceRecord",
        "log:UpdateScheduledSQL",
        "log:UpdateStoreView",
        "log:UpdateSubStore",
        "log:UpdateSubStoreTTL",
        "log:PutConsumeProcessor",
        "log:DeleteConsumeProcessor",
        "log:PutObject",
        "milvus:List*",
        "mns:List*",
        "mns:PublishMessage",
        "mns:SendMessage",
        "mongodb:Describe*",
        "modelstudio:List*",
        "mq:List*",
        "mq:OnsInstanceBaseInfo",
        "mq:OnsInstanceInServiceList",
        "mq:Query*",
        "mse:Get*",
        "mse:List*",
        "nas:Describe*",
        "netgateway:Describe*",
        "nlb:List*",
        "oceanbase:Describe*",
        "ocs:Describe*",
        "odps:List*",
        "ons:List*",
        "ons:OnsInstanceInServiceList",
        "opensearc:List*",
        "opensearch:List*",
        "ordere:Describe*",
        "oss:GetBucketInfo",
        "oss:ListBuckets",
        "oss:ListResourcePools",
        "ots:List*",
        "pai:Get*",
        "pai:List*",
        "paidlc:Get*",
        "paidlc:List*",
        "paidsw:Get*",
        "paidsw:List*",
        "paieas:Describe*",
        "paiworkspace:Get*",
        "paiworkspace:List*",
        "pee:Describe*",
        "polardb:Describe*",
        "polardb:List*",
        "polardbx:Describe*",
        "privatelink:List*",
        "pts:ApplicationGranted",
        "pts:Check*",
        "pts:CompareReport",
        "pts:Describe*",
        "pts:Get*",
        "pts:List*",
        "pts:PreviewJmxParser",
        "pts:Query*",
        "pts:Search*",
        "ram:GetRole",
        "ram:GetRole",
        "ram:ListRoles",
        "ram:PassRole",
        "rds:Describe*",
        "rds:List*",
        "resourcecenter:CreateServiceDeliveryChannel",
        "resourcecenter:DeleteServiceDeliveryChannel",
        "resourcecenter:DeliverResourceSnapshot",
        "resourcecenter:EnableResourceCenter",
        "resourcecenter:ExecuteGraphQLQuery",
        "resourcecenter:Get*",
        "resourcecenter:List*",
        "resourcecenter:SearchResources",
        "resourcemanager:Get*",
        "resourcemanager:List*",
        "rocketmq:List*",
        "rt:Describe*",
        "sa:Describe*",
        "sae:Describe*",
        "sae:List*",
        "searchengine:List*",
        "selectdb:Describe*",
        "slb:DeleteAccessLogsDownloadAttribute",
        "slb:Describe*",
        "slb:SetAccessLogsDownloadAttribute",
        "slb:SetLoadbalancerListenerAttributeEx",
        "starops:List*",
        "starops:Get*",
        "starops:CreateDigitalEmployee",
        "starops:UpdateDigitalEmployee",
        "starops:UpdateMission",
        "starops:CreateMission",
        "starops:CreateDigitalEmployeeSkill",
        "starops:DeleteDigitalEmployeeSkill",
        "starops:UpdateDigitalEmployeeSkill",
        "starops:DeleteDigitalEmployeeSkillMount",
        "starops:UpdateSkillDraft",
        "starops:MountDigitalEmployeeSkill",
        "starops:MountDigitalEmployeeSkills",
        "starops:DeleteSkillDraft",
        "starops:UpdateDigitalEmployeeSkillMount",
        "starops:*Skill",
        "starops:CreateChat",
        "starops:CreateThread",
        "agentidentity:GetIdentityProvider",
        "agentidentity:ListIdentityProviders",
        "agentidentity:CreateIdentityProvider",
        "agentidentity:UpdateIdentityProvider",
        "agentidentity:GetWorkloadIdentity",
        "agentidentity:ListWorkloadIdentities",
        "agentidentity:CreateWorkloadIdentity",
        "agentidentity:UpdateWorkloadIdentity",
        "agentidentitydata:GetWorkloadAccessTokenForJWT",
        "stream:ActOnBehalfOfAnotherUser",
        "stream:Describe*",
        "stream:Get*",
        "stream:List*",
        "swa:List*",
        "tag:DescribeRegions",
        "tag:ListTagKeys",
        "tag:ListTagResources",
        "tag:ListTagValues",
        "tai:Describe*",
        "vp:Describe*",
        "vpc:Describe*",
        "vpc:List*",
        "vpc:ModifyBypassToaAttribute",
        "vpcpee:List*",
        "waf-openapi:Describe*",
        "waf-openapi:Get*",
        "waf-openapi:List*",
        "xtrace:Get*",
        "yundun-antiddosbag:Describe*",
        "yundun-cloudfirewall:Describe*",
        "yundun-ddoscoo:Describe*",
        "yundun-hsm:Get*",
        "yundun-hsm:List*",
        "yundun-sas:InstallCloudMonitor",
        "yundun-waf:Describe*",
        "grace:GetFile",
        "grace:FetchFileAnalysis",
        "grace:ListFiles",
        "grace:CleanFile",
        "grace:DeleteFile",
        "grace:TransferFile",
        "grace:UpdateFile",
        "grace:UploadFileByOSS",
        "grace:UploadFileByURL",
        "openapiexplorer:ListApiMcpServers"
      ],
      "Resource": "*"
    },
    {
      "Action": [
        "ecs:DeleteSecurityGroup"
      ],
      "Effect": "Allow",
      "Resource": [
        "*"
      ],
      "Condition": {
        "StringEquals": {
          "ecs:tag/serverless/sg-creator": "containernetworking"
        }
      }
    },
    {
      "Action": [
        "ecs:DeleteNetworkInterface"
      ],
      "Effect": "Allow",
      "Resource": [
        "*"
      ],
      "Condition": {
        "StringEquals": {
          "ecs:tag/eni-creator": "function-compute"
        }
      }
    },
    {
      "Action": [
        "ecs:DeleteNetworkInterface"
      ],
      "Effect": "Allow",
      "Resource": [
        "*"
      ],
      "Condition": {
        "StringEquals": {
          "ecs:tag/serverless/eni-creator": "asi-cni-service"
        }
      }
    },
    {
      "Action": [
        "ecs:DeleteNetworkInterface"
      ],
      "Effect": "Allow",
      "Resource": [
        "*"
      ],
      "Condition": {
        "StringEqualsIgnoreCase": {
          "acs:ResourceTag/acs:eci:Product": [
            "CloudMonitor",
            "ARMS"
          ]
        }
      }
    },
    {
      "Action": [
        "fc:CreateService"
      ],
      "Resource": "acs:fc:*:*:services/*",
      "Effect": "Allow"
    },
    {
      "Effect": "Allow",
      "Action": [
        "kms:CreateSecret",
        "kms:DeleteSecret",
        "kms:DescribeSecret",
        "kms:PutSecretValue",
        "kms:UpdateSecret",
        "kms:UpdateSecretVersionStage",
        "kms:ListSecretVersionIds",
        "kms:GetSecretValue"
      ],
      "Resource": [
        "acs:kms:*:*:secret/agentloop!*"
      ]
    },
    {
      "Effect": "Allow",
      "Action": [
        "kms:DescribeSecret",
        "kms:ListSecretVersionIds",
        "kms:GetSecretValue"
      ],
      "Resource": [
        "acs:kms:*:*:secret/*"
      ],
      "Condition": {
        "StringEqualsIgnoreCase": {
          "kms:tag/acs:cms:agentloop": "true"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "airegistry:Read",
        "airegistry:List*",
        "airegistry:Get*",
        "airegistry:CreatePrompt",
        "airegistry:CreatePromptVersion",
        "airegistry:UpdatePrompt",
        "airegistry:UpdatePromptVersion",
        "airegistry:SubmitPromptVersion",
        "airegistry:DeletePromptVersion",
        "airegistry:DeletePrompt",
        "airegistry:InvokePromptDebugStream",
        "airegistry:InvokePromptOptimizeStream",
        "airegistry:CreateNamespace",
        "airegistry:CreateNamespaceWithSource",
        "airegistry:UpdateNamespace",
        "airegistry:DeleteNamespace"
      ],
      "Resource": "acs:airegistry:*:*:instance/saas/*"
    }
  ]
}

相关文档