AliyunServiceRolePolicyForCloudMonitor 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForCloudMonitor 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。
策略详情
类型:系统策略
创建时间:2025-10-29 10:40:57
更新时间:2026-09-09 18:54:59
当前版本:v184
策略内容
{
"Version": "1",
"Statement": [
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "cloudmonitor.aliyuncs.com"
}
}
},
{
"Action": "ram:CreateServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": [
"ess.aliyuncs.com",
"fc.aliyuncs.com",
"privatelink.aliyuncs.com",
"arms.aliyuncs.com",
"xtrace.aliyuncs.com",
"rmc.resourcemanager.aliyuncs.com",
"audit.log.aliyuncs.com",
"cloudmonitor.aliyuncs.com",
"middlewarelens.log.aliyuncs.com",
"securitylens.log.aliyuncs.com",
"ai-lens.log.aliyuncs.com",
"storagelens.log.aliyuncs.com",
"sysom.aliyuncs.com",
"secretsmanager-polardb.kms.aliyuncs.com",
"operation-platform.aliyuncs.com",
"agentidentity.aliyuncs.com"
]
}
}
},
{
"Effect": "Allow",
"Action": [
"ecs:RunCommand",
"ecs:DescribeInvocations",
"ecs:DescribeCloudAssistantStatus"
],
"Resource": [
"acs:ecs:*:*:instance/*",
"acs:ecs:*:*:command/*"
]
},
{
"Effect": "Allow",
"Action": [
"actiontrail:LookupEvents",
"adb:Describe*",
"adb:List*",
"adcp:Describe*",
"adcp:GrantUserPermission",
"agentloop:GetAgentSpace",
"ahas:Query*",
"ahas:Search*",
"aire:List*",
"airec:List*",
"airec:Describe*",
"alb:List*",
"alidns:Describe*",
"alikafka:Get*",
"alikafka:List*",
"amqp:List*",
"apig:Get*",
"apig:List*",
"apigateway:Describe*",
"arms:AddAliClusterIdsToPrometheusGlobalView",
"arms:AddPrometheusGlobalViewByAliClusterIds",
"arms:Check*",
"arms:createAliYunRecordingRuleYaml",
"arms:CreateEnvironment",
"arms:CreatePrometheusAlertRules",
"arms:CreatePrometheusInstance",
"arms:CreateTimingSyntheticTask",
"arms:DeleteAddonRelease",
"arms:DeleteEnvironmentFeature",
"arms:DeletePrometheusAlertRules",
"arms:DeletePrometheusGlobalView",
"arms:DeleteTimingSyntheticTask",
"arms:Describe*",
"arms:EnableGraphResource",
"arms:Get*",
"arms:InitEnvironment",
"arms:InstallAddon",
"arms:InstallEnvironmentFeature",
"arms:List*",
"arms:Query*",
"arms:RemoveAliClusterIdsFromPrometheusGlobalView",
"arms:Search*",
"arms:TagResourcesSystemTags",
"arms:UninstallPromCluster",
"arms:UntagResourcesSystemTags",
"arms:UpdateDeliverTask",
"arms:UpdateTimingSyntheticTask",
"arms:UpgradeAddonRelease",
"arms:UpgradeEnvironmentFeature",
"arms:CreateDispatchRule",
"arms:DeleteDispatchRule",
"arms:UpdateDispatchRule",
"asi:Describe*",
"asi:Get*",
"bbebo:List*",
"bd:Describe*",
"bss:ModifyInstance",
"bssapi:QueryCostUnit",
"bssapi:QueryCostUnitResource",
"bssapi:QueryRelationList",
"cd:Describe*",
"cdd:Describe*",
"cdn:Describe*",
"cdn:StopCdnDomain",
"cen:Describe*",
"cen:List*",
"clickhouse:Describe*",
"cloudphon:List*",
"cms:BatchExport",
"cms:BatchGet",
"cms:CreateAddonRelease",
"cms:CreateAggTaskGroup*",
"cms:CreateAlertEventIntegrationPolicy",
"cms:CreateApplicationInsightsInstance",
"cms:CreateChat",
"cms:CreateCloudResource",
"cms:CreateDataset",
"cms:CreateEntityStore",
"cms:CreateEvaluationTask",
"cms:CreateExperimentTask",
"cms:CreateInstantSiteMonitor",
"cms:CreateIntegrationPolicy",
"cms:CreatePrometheus*",
"cms:CreateService",
"cms:CreateServiceObservability",
"cms:CreateSiteMonitor",
"cms:CreateThread",
"cms:CreateTicket",
"cms:CreateUmodel",
"cms:Cursor",
"cms:DeleteAddonRelease",
"cms:DeleteAggTaskGroup*",
"cms:DeleteAlertEventIntegrationPolicy",
"cms:DeleteCloudResource",
"cms:DeleteDataset",
"cms:DeleteMetricRules",
"cms:DeletePrometheus*",
"cms:DeleteService",
"cms:DeleteSiteMonitor",
"cms:DeleteSiteMonitors",
"cms:DeleteUmodelCommonSchemaRef",
"cms:DeleteUmodelData",
"cms:Describe*",
"cms:DisableAlertEventIntegrationPolicy",
"cms:DisableHighResolutionMonitor",
"cms:DisableSiteMonitor",
"cms:DisableSiteMonitors",
"cms:EnableActiveMetricRule",
"cms:EnableAlertEventIntegrationPolicy",
"cms:EnableHighResolutionMonitor",
"cms:EnableSiteMonitor",
"cms:EnableSiteMonitors",
"cms:ExecuteQuery",
"cms:Get*",
"cms:InstallMonitoringAgent",
"cms:List*",
"cms:Check*",
"cms:PutResourceMetricRule",
"cms:PutWorkspace",
"cms:Query*",
"cms:SubscribeRcaEvents",
"cms:SyncAlertRulesByGroup",
"cms:UninstallMonitoringAgent",
"cms:UpdateAddonRelease",
"cms:UpdateAggTaskGroup*",
"cms:UpdateAlertEventIntegrationPolicy",
"cms:UpdateAlertRuleKvs",
"cms:UpdateDataset",
"cms:UpdatePrometheus*",
"cms:UpdateService",
"cms:UpdateServiceObservability",
"cms:UpdateSiteMonitor",
"cms:UpdateUmodel",
"cms:UpsertUmodelCommonSchemaRef",
"cms:UpsertUmodelData",
"cms:UpdateMission",
"cms:CreateAlertRule",
"cms:UpdateAlertRule",
"cms:DeleteAlertRules",
"cms:SyncAlertRuleTemplatesByRunbook",
"cms:UnapplyAlertRuleTemplate",
"cms:ApplyAlertRuleTemplate",
"cms:*ObserveGroup",
"cms:PatchAlertRule",
"cms:ManageAlertRules",
"cms:RunOneResourceReport",
"cms:*ResourceReportSchedule",
"cms:DeleteEntityHealthRules",
"cms:CreateEntityHealthRules",
"cms:UpdateEntityHealthRules",
"cms:ListEntityHealthRules",
"cms:CreateAlertRuleTemplate",
"cms:UpdateAlertRuleTemplate",
"cms:DeleteAlertRuleTemplate",
"cms:CreateEntityBundleInstance",
"cms:TriggerEntitySync",
"clickhouse:Describe*",
"cs:AttachInstances",
"cs:CheckKritisInstall",
"cs:DeleteClusterNode",
"cs:DeleteClusterNodes",
"cs:DeleteKritisAttestationAuthority",
"cs:DeleteKritisGenericAttestationPolicy",
"cs:Describe*",
"cs:Get*",
"cs:InstallClusterAddons",
"cs:InstallKritis",
"cs:InstallKritisAttestationAuthority",
"cs:InstallKritisGenericAttestationPolicy",
"cs:List*",
"cs:RevokeClusterInnerServiceKubeconfig",
"cs:ScaleCluster",
"cs:UnInstallClusterAddons",
"cs:UninstallKritis",
"cs:UpdateClusterAuditLogConfig",
"cs:UpdateClusterTags",
"cs:UpdateKritisAttestationAuthority",
"cs:UpdateKritisGenericAttestationPolicy",
"cs:UpgradeCluster",
"cs:UpgradeClusterAddons",
"dataworks:List*",
"dbf:List*",
"dcdn:Describe*",
"dd:List*",
"dds:Describe*",
"dlf:Get*",
"dlf:List*",
"domain:Query*",
"drds:Describe*",
"drds:List*",
"dts:Describe*",
"ea:List*",
"eas:Describe*",
"eas:Get*",
"eas:List*",
"ecd:Describe*",
"eci:Describe*",
"ecs:AttachNetworkInterface",
"ecs:AuthorizeSecurityGroup",
"ecs:AuthorizeSecurityGroupEgress",
"ecs:CreateCommand",
"ecs:CreateNetworkInterface",
"ecs:CreateNetworkInterfacePermission",
"ecs:CreateSecurityGroup",
"ecs:DeleteCommand",
"ecs:DeleteNetworkInterfacePermission",
"ecs:Describe*",
"ecs:DetachNetworkInterface",
"ecs:InstallCloudAssistant",
"ecs:InvokeCommand",
"ecs:List*",
"ecs:ModifyCommand",
"ecs:ModifyNetworkInterfaceAttribute",
"ecs:RevokeSecurityGroup",
"ecs:StopInvocation",
"sysom:InitialSysom",
"sysom:InvokeDiagnosis",
"sysom:GetDiagnosisResult",
"sysom:InstallAgent",
"sysom:GetAgentTask",
"sysom:ListInstanceStatus",
"sysom:UninstallAgent",
"sysom:UninstallAgentWithType",
"sysom:InstallAgentWithType",
"eflo:List*",
"ehpc:List*",
"eipanycas:List*",
"elasticsearch:List*",
"emr-serverless-spark:List*",
"emr:List*",
"ens:Describe*",
"es:Describe*",
"esa:List*",
"ess:Describe*",
"ess:ExecuteScalingRule",
"eventbridge:CheckRoleForProduct",
"eventbridge:CheckServiceLinkedRoleForProduct",
"eventbridge:CreateEventBus",
"eventbridge:CreateRule",
"eventbridge:CreateTargets",
"eventbridge:DeleteEventBus",
"eventbridge:DeleteRule",
"eventbridge:DeleteTargets",
"eventbridge:DisableRule",
"eventbridge:EnableRule",
"eventbridge:Get*",
"eventbridge:List*",
"eventbridge:PutEvents",
"eventbridge:PutTargets",
"eventbridge:*EventStreaming",
"eventbridge:UpdateRule",
"expressconnectrouter:Describe*",
"fc:Get*",
"fc:InvokeFunction",
"fc:List*",
"featurestore:Get*",
"featurestore:List*",
"ga:List*",
"gdb:Describe*",
"graphcompute:List*",
"gwlb:List*",
"hbase:Describe*",
"hbr_vaul:Describe*",
"hcs-sgw:describe*",
"hd:Describe*",
"hdf:List*",
"hdm:CreateRequestDiagnosis",
"hdm:Describe*",
"hdm:Get*",
"hitsdb:Describe*",
"hitsdb:Get*",
"hologram:List*",
"im:List*",
"io:Query*",
"kms:Decrypt",
"kms:DescribeKey",
"kms:Encrypt",
"kms:GenerateDataKey",
"kms:GenerateDataKeyWithoutPlaintext",
"kms:List*",
"kms:TagResource",
"kms:UntagResource",
"kvstore:Describe*",
"lindorm:Describe*",
"lindorm:Get*",
"lindorm:List*",
"lindorm:UpdateInstanceIpWhiteList",
"log:*MetricStore*",
"log:*ScheduledSQL*",
"log:ApplyConfigToGroup",
"log:BatchGet*",
"log:BatchPostLogStoreLogs",
"log:CallAiTools",
"log:CloseProductDataCollection",
"log:ConsumerGroupHeartBeat",
"log:ConsumerGroupUpdateCheckPoint",
"log:CreateAgentInstanceConfig",
"log:CreateApp",
"log:CreateConsumerGroup",
"log:CreateDashboard",
"log:CreateEtlMeta",
"log:CreateIndex",
"log:CreateJob",
"log:CreateLogging",
"log:CreateLogStore",
"log:CreateLogtailPipelineConfig",
"log:CreateMachineGroup",
"log:CreateMetricsConfig",
"log:CreateProject",
"log:CreateResourceRecord",
"log:CreateScheduledSQL",
"log:CreateStoreView",
"log:DeleteAgentInstanceConfig",
"log:DeleteConsumerGroup",
"log:DeleteEtlMeta",
"log:DeleteIndex",
"log:DeleteJob",
"log:DeleteLogging",
"log:DeleteLogStore",
"log:DeleteLogtailPipelineConfig",
"log:DeleteMachineGroup",
"log:DeleteProject",
"log:DeleteProjectPolicy",
"log:DeleteProjectQuery",
"log:DeleteScheduledSQL",
"log:DeleteStoreView",
"log:Describe*",
"log:Get*",
"log:List*",
"log:ModifyJobInstance",
"log:OpenProductDataCollection",
"log:PostLogStoreLogs",
"log:PostProjectQuery",
"log:PullLogs",
"log:PutLogStoreMultimodalConfiguration",
"log:PutProjectPolicy",
"log:PutProjectQuery",
"log:Query*",
"log:RemoveConfigFromGroup",
"log:SplitShard",
"log:TagResources",
"log:UntagResources",
"log:UpdateAgentInstanceConfig",
"log:UpdateApp",
"log:UpdateCheckPoint",
"log:UpdateConsumerGroup",
"log:UpdateConsumerGroupCheckPoint",
"log:UpdateDashboard",
"log:UpdateEtlMeta",
"log:UpdateIndex",
"log:UpdateJob",
"log:UpdateLogging",
"log:UpdateLogStore",
"log:UpdateLogtailPipelineConfig",
"log:UpdateMachineGroup",
"log:UpdateMachineGroupMachine",
"log:UpdateMetricsConfig",
"log:UpdateProject",
"log:UpdateResourceRecord",
"log:UpdateScheduledSQL",
"log:UpdateStoreView",
"log:UpdateSubStore",
"log:UpdateSubStoreTTL",
"log:PutConsumeProcessor",
"log:DeleteConsumeProcessor",
"log:PutObject",
"milvus:List*",
"mns:List*",
"mns:PublishMessage",
"mns:SendMessage",
"mongodb:Describe*",
"modelstudio:List*",
"mq:List*",
"mq:OnsInstanceBaseInfo",
"mq:OnsInstanceInServiceList",
"mq:Query*",
"mse:Get*",
"mse:List*",
"nas:Describe*",
"netgateway:Describe*",
"nlb:List*",
"oceanbase:Describe*",
"ocs:Describe*",
"odps:List*",
"ons:List*",
"ons:OnsInstanceInServiceList",
"opensearc:List*",
"opensearch:List*",
"ordere:Describe*",
"oss:GetBucketInfo",
"oss:ListBuckets",
"oss:ListResourcePools",
"ots:List*",
"pai:Get*",
"pai:List*",
"paidlc:Get*",
"paidlc:List*",
"paidsw:Get*",
"paidsw:List*",
"paieas:Describe*",
"paiworkspace:Get*",
"paiworkspace:List*",
"pee:Describe*",
"polardb:Describe*",
"polardb:List*",
"polardbx:Describe*",
"privatelink:List*",
"pts:ApplicationGranted",
"pts:Check*",
"pts:CompareReport",
"pts:Describe*",
"pts:Get*",
"pts:List*",
"pts:PreviewJmxParser",
"pts:Query*",
"pts:Search*",
"ram:GetRole",
"ram:GetRole",
"ram:ListRoles",
"ram:PassRole",
"rds:Describe*",
"rds:List*",
"resourcecenter:CreateServiceDeliveryChannel",
"resourcecenter:DeleteServiceDeliveryChannel",
"resourcecenter:DeliverResourceSnapshot",
"resourcecenter:EnableResourceCenter",
"resourcecenter:ExecuteGraphQLQuery",
"resourcecenter:Get*",
"resourcecenter:List*",
"resourcecenter:SearchResources",
"resourcemanager:Get*",
"resourcemanager:List*",
"rocketmq:List*",
"rt:Describe*",
"sa:Describe*",
"sae:Describe*",
"sae:List*",
"searchengine:List*",
"selectdb:Describe*",
"slb:DeleteAccessLogsDownloadAttribute",
"slb:Describe*",
"slb:SetAccessLogsDownloadAttribute",
"slb:SetLoadbalancerListenerAttributeEx",
"starops:List*",
"starops:Get*",
"starops:CreateDigitalEmployee",
"starops:UpdateDigitalEmployee",
"starops:UpdateMission",
"starops:CreateMission",
"starops:CreateDigitalEmployeeSkill",
"starops:DeleteDigitalEmployeeSkill",
"starops:UpdateDigitalEmployeeSkill",
"starops:DeleteDigitalEmployeeSkillMount",
"starops:UpdateSkillDraft",
"starops:MountDigitalEmployeeSkill",
"starops:MountDigitalEmployeeSkills",
"starops:DeleteSkillDraft",
"starops:UpdateDigitalEmployeeSkillMount",
"starops:*Skill",
"starops:CreateChat",
"starops:CreateThread",
"agentidentity:GetIdentityProvider",
"agentidentity:ListIdentityProviders",
"agentidentity:CreateIdentityProvider",
"agentidentity:UpdateIdentityProvider",
"agentidentity:GetWorkloadIdentity",
"agentidentity:ListWorkloadIdentities",
"agentidentity:CreateWorkloadIdentity",
"agentidentity:UpdateWorkloadIdentity",
"agentidentitydata:GetWorkloadAccessTokenForJWT",
"stream:ActOnBehalfOfAnotherUser",
"stream:Describe*",
"stream:Get*",
"stream:List*",
"swa:List*",
"tag:DescribeRegions",
"tag:ListTagKeys",
"tag:ListTagResources",
"tag:ListTagValues",
"tai:Describe*",
"vp:Describe*",
"vpc:Describe*",
"vpc:List*",
"vpc:ModifyBypassToaAttribute",
"vpcpee:List*",
"waf-openapi:Describe*",
"waf-openapi:Get*",
"waf-openapi:List*",
"xtrace:Get*",
"yundun-antiddosbag:Describe*",
"yundun-cloudfirewall:Describe*",
"yundun-ddoscoo:Describe*",
"yundun-hsm:Get*",
"yundun-hsm:List*",
"yundun-sas:InstallCloudMonitor",
"yundun-waf:Describe*",
"grace:GetFile",
"grace:FetchFileAnalysis",
"grace:ListFiles",
"grace:CleanFile",
"grace:DeleteFile",
"grace:TransferFile",
"grace:UpdateFile",
"grace:UploadFileByOSS",
"grace:UploadFileByURL",
"openapiexplorer:ListApiMcpServers"
],
"Resource": "*"
},
{
"Action": [
"ecs:DeleteSecurityGroup"
],
"Effect": "Allow",
"Resource": [
"*"
],
"Condition": {
"StringEquals": {
"ecs:tag/serverless/sg-creator": "containernetworking"
}
}
},
{
"Action": [
"ecs:DeleteNetworkInterface"
],
"Effect": "Allow",
"Resource": [
"*"
],
"Condition": {
"StringEquals": {
"ecs:tag/eni-creator": "function-compute"
}
}
},
{
"Action": [
"ecs:DeleteNetworkInterface"
],
"Effect": "Allow",
"Resource": [
"*"
],
"Condition": {
"StringEquals": {
"ecs:tag/serverless/eni-creator": "asi-cni-service"
}
}
},
{
"Action": [
"ecs:DeleteNetworkInterface"
],
"Effect": "Allow",
"Resource": [
"*"
],
"Condition": {
"StringEqualsIgnoreCase": {
"acs:ResourceTag/acs:eci:Product": [
"CloudMonitor",
"ARMS"
]
}
}
},
{
"Action": [
"fc:CreateService"
],
"Resource": "acs:fc:*:*:services/*",
"Effect": "Allow"
},
{
"Effect": "Allow",
"Action": [
"kms:CreateSecret",
"kms:DeleteSecret",
"kms:DescribeSecret",
"kms:PutSecretValue",
"kms:UpdateSecret",
"kms:UpdateSecretVersionStage",
"kms:ListSecretVersionIds",
"kms:GetSecretValue"
],
"Resource": [
"acs:kms:*:*:secret/agentloop!*"
]
},
{
"Effect": "Allow",
"Action": [
"kms:DescribeSecret",
"kms:ListSecretVersionIds",
"kms:GetSecretValue"
],
"Resource": [
"acs:kms:*:*:secret/*"
],
"Condition": {
"StringEqualsIgnoreCase": {
"kms:tag/acs:cms:agentloop": "true"
}
}
},
{
"Effect": "Allow",
"Action": [
"airegistry:Read",
"airegistry:List*",
"airegistry:Get*",
"airegistry:CreatePrompt",
"airegistry:CreatePromptVersion",
"airegistry:UpdatePrompt",
"airegistry:UpdatePromptVersion",
"airegistry:SubmitPromptVersion",
"airegistry:DeletePromptVersion",
"airegistry:DeletePrompt",
"airegistry:InvokePromptDebugStream",
"airegistry:InvokePromptOptimizeStream",
"airegistry:CreateNamespace",
"airegistry:CreateNamespaceWithSource",
"airegistry:UpdateNamespace",
"airegistry:DeleteNamespace"
],
"Resource": "acs:airegistry:*:*:instance/saas/*"
}
]
}相关文档
该文章对您有帮助吗?