AliyunServiceRolePolicyForCMHPrivate

AliyunServiceRolePolicyForCMHPrivate 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForCMHPrivate 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2025-01-14 11:52:37

  • 更新时间:2025-01-14 11:52:37

  • 当前版本:v1

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "smc:DescribeSourceServers",
        "smc:DescribeReplicationJobs",
        "smc:CreateReplicationJob",
        "smc:StartReplicationJob",
        "smc:StopReplicationJob",
        "smc:CreateCrossZoneMigrationJob",
        "smc:CreateAccessToken",
        "smc:DescribeTestRunReports",
        "smc:CreateAccessToken",
        "smc:ListAccessTokens",
        "smc:CutOverReplicationJob",
        "smc:ModifyReplicationJobAttribute",
        "smc:DeleteSourceServer",
        "smc:DeleteReplicationJob",
        "smc:DescribeGlobalVariables"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "dts:DescribeDtsJobs",
        "dts:ConfigureDtsJob",
        "dts:StartDtsJob",
        "dts:CreateDtsInstance",
        "dts:DescribeDatabases",
        "dts:DescribePreCheckStatus",
        "dts:DescribeDtsJobDetail",
        "dts:ModifyDynamicConfig",
        "dts:DescribeDynamicConfig",
        "dts:SuspendDtsJob",
        "dts:DeleteDtsJobs",
        "dts:StopDtsJobs"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "rds:CreateDBInstance",
        "rds:DescribeDBInstanceAttribute",
        "rds:MigrateToOtherZone",
        "rds:DescribeAvailableClasses",
        "rds:DescribeAvailableZones",
        "rds:DescribeDatabases",
        "rds:DescribeDBInstanceHAConfig",
        "rds:DescribeDBInstanceNetInfo",
        "rds:DescribeDBInstances",
        "rds:CheckServiceLinkedRole",
        "rds:DescribeDatabases",
        "rds:DescribeDescribeRegions",
        "rds:CheckInstanceExist"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "polardb:DescribeDBClusterAvailableResources",
        "polardb:DescribeClassList",
        "polardb:DescribeDatabases",
        "polardb:DescribeDBClusters",
        "polardb:DescribeDBClusterEndpoints"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "polardbx:DescribeDBInstances",
        "polardbx:DescribeDBInstanceAttribute"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "vpc:DescribeVpcs",
        "vpc:DescribeZones",
        "vpc:DescribeVSwitches",
        "vpc:CheckCanAllocateVpcPrivateIpAddress",
        "vpc:CreateVSwitch",
        "vpc:CreateVpc",
        "vpc:DescribeVpcAttribute",
        "vpc:AssociateVpcCidrBlock",
        "ecs:DescribeInstanceAttribute",
        "ecs:DescribeAvailableResource",
        "ecs:CloneInstanceWithIncrementSnapshot",
        "ecs:DescribeDisks",
        "ecs:DescribeAvailableResource",
        "ecs:StartInstance",
        "ecs:DescribeVSwitches",
        "ecs:RunInstances",
        "ecs:DescribeSnapshots",
        "ecs:CreateImage",
        "ecs:DescribeInstances",
        "ecs:DescribeImages",
        "ecs:CreateSnapshot",
        "ecs:DescribePrice",
        "ecs:DescribeSecurityGroups",
        "ecs:DescribeSecurityGroupAttribute",
        "ecs:ModifyLaunchTemplateDefaultVersion",
        "ecs:CreateLaunchTemplateVersion",
        "ecs:DescribeInvocationResults",
        "ecs:DescribeRegions",
        "ecs:DeleteLaunchTemplateVersion",
        "ecs:DescribeLaunchTemplateVersions",
        "ecs:DescribeInvocations",
        "ecs:CopyImage",
        "ecs:DescribeLaunchTemplates",
        "ecs:DescribeKeyPairs",
        "ecs:DescribeDeploymentSets",
        "ecs:DescribeInstanceCrossZoneModifyConstraint",
        "ecs:DescribeResourcesModification",
        "ecs:DescribeInstanceTypes",
        "ecs:DescribePrice",
        "ecs:DescribeCloudAssistantStatus",
        "ecs:CreateSecurityGroup",
        "ecs:AuthorizeSecurityGroup",
        "ecs:AuthorizeSecurityGroupEgress",
        "ecs:RevokeSecurityGroup",
        "ecs:RevokeSecurityGroupEgress",
        "ecs:DeleteSecurityGroup",
        "ecs:JoinSecurityGroup",
        "ecs:LeaveSecurityGroup",
        "ecs:ModifySecurityGroupRule",
        "ecs:ModifySecurityGroupEgressRule",
        "ecs:RunCommand",
        "ecs:DeleteInstance",
        "ecs:ModifyInstanceAttribute",
        "ecs:StopInstance"
      ],
      "Resource": "*"
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "apds-private.apds.aliyuncs.com"
        }
      }
    }
  ]
}

相关文档