AliyunServiceRolePolicyForCloudSSO

AliyunServiceRolePolicyForCloudSSO 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForCloudSSO 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2021-06-08 02:27:56

  • 更新时间:2022-09-16 07:24:29

  • 当前版本:v5

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Action": [
        "ram:CreateSAMLProvider",
        "ram:CreatePolicy",
        "ram:ListRoles",
        "ram:ListPolicies"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ram:ListPolicyVersions",
        "ram:DeletePolicyVersion",
        "ram:CreatePolicyVersion",
        "ram:DeletePolicy"
      ],
      "Resource": "acs:ram:*:*:policy/AliyunReservedSSO*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ram:GetSAMLProvider",
        "ram:DeleteSAMLProvider",
        "ram:GetRole",
        "ram:CreateRole",
        "ram:DeleteRole",
        "ram:GetPolicy",
        "ram:AttachPolicyToRole",
        "ram:DetachPolicyFromRole",
        "ram:ListPoliciesForRole"
      ],
      "Resource": [
        "acs:ram:*:*:saml-provider/AliyunReservedSSO*",
        "acs:ram:*:*:role/aliyunreservedsso*",
        "acs:ram:*:*:policy/*"
      ],
      "Effect": "Allow"
    },
    {
      "Action": [
        "ram:CreateUser",
        "ram:DeleteUser",
        "ram:GetUser",
        "ram:UpdateUserProvisionType",
        "ram:UnBindMFADevice",
        "ram:DeleteLoginProfile",
        "ram:UnbindUserPersonalDingTalk",
        "ram:ListAccessKeys",
        "ram:DeleteAccessKey",
        "ram:ListGroupsForUser",
        "ram:RemoveUserFromGroup",
        "ram:ListPublicKeys",
        "ram:DeletePublicKey"
      ],
      "Resource": [
        "acs:ram:*:*:user/*",
        "acs:ram:*:*:group/*"
      ],
      "Effect": "Allow"
    },
    {
      "Action": [
        "ram:DeleteServiceLinkedRole",
        "ram:GetServiceLinkedRoleDeletionStatus"
      ],
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "cloudsso.aliyuncs.com"
        }
      }
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "cloudsso.aliyuncs.com"
        }
      }
    }
  ]
}

相关文档