AliyunServiceRolePolicyForLingjunRein

更新时间:
复制 MD 格式

AliyunServiceRolePolicyForLingjunRein 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForLingjunRein 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2026-06-14 14:10:42

  • 更新时间:2026-08-11 10:05:14

  • 当前版本:v54

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cs:DescribeClusterDetail",
        "cs:CreateCluster",
        "cs:DescribeClusterNodePools",
        "cs:CreateClusterNodePool",
        "cs:DescribeClusterAttachScripts",
        "cs:DescribeClusterNodes",
        "cs:DeleteClusterNodes",
        "cs:RemoveNodePoolNodes",
        "cs:GetClusters",
        "cs:DescribeClusters",
        "cs:DeleteCluster",
        "cs:DescribeClusterUserKubeconfig",
        "cs:AttachInstancesToNodePool",
        "cs:DescribeTaskInfo",
        "cs:DescribeClusterNodePoolDetail",
        "cs:UpdateUserPermissions",
        "cs:DescribeClusterDetail",
        "cs:AttachInstances",
        "cs:GetUserPermissions",
        "cs:ListAddons",
        "cs:ModifyClusterNodePool",
        "cs:ListClusterAddonInstances",
        "cs:InstallClusterAddons",
        "cs:GetClusterAddonInstance",
        "cs:ListAddons",
        "cs:DescribeAddon",
        "cs:ModifyClusterAddon",
        "cs:UpgradeK8sComponents",
        "cs:ListClusterAddonInstanceResources",
        "cs:UnInstallClusterAddons",
        "cr:PullRepository"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "asi:DescribeNodeTicketDetail",
        "asi:RetryNodeTicket",
        "asi:OfflineNodes",
        "asi:DescribeNodes",
        "asi:ImportNodes"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ecs:CreateSecurityGroup",
        "ecs:AuthorizeSecurityGroup",
        "ecs:AuthorizeSecurityGroupEgress",
        "ecs:JoinSecurityGroup",
        "ecs:DescribeSecurityGroups",
        "ecs:DescribeSecurityGroupAttribute",
        "ecs:DescribeInvocationResults",
        "ecs:DescribeInstances",
        "ecs:DescribeKeyPairs",
        "ecs:CreateNetworkInterface",
        "ecs:DeleteNetworkInterface",
        "ecs:DescribeNetworkInterfaces",
        "ecs:CreateNetworkInterfacePermission",
        "ecs:DeleteNetworkInterfacePermission",
        "ecs:DescribeNetworkInterfacePermissions",
        "ecs:CreateSecurityGroup",
        "ecs:DeleteSecurityGroup",
        "ecs:AuthorizeSecurityGroup",
        "ecs:DescribeSecurityGroups",
        "ecs:DescribeInstanceAttribute"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "vpc:DescribeVpcAttribute",
        "vpc:DescribeVpcs",
        "vpc:DescribeVSwitches",
        "vpc:DescribeEipAddresses",
        "vpc:CreateNatGateway",
        "vpc:DeleteNatGateway",
        "vpc:DescribeNatGateways",
        "vpc:CreateForwardEntry",
        "vpc:DeleteForwardEntry",
        "vpc:DescribeForwardTableEntries",
        "vpc:CreateFullNatEntry",
        "vpc:ListFullNatEntries",
        "vpc:ListNatIps",
        "vpc:DescribeNatGatewayAssociateNetworkInterfaces",
        "vpc:CreateVSwitch",
        "vpc:DescribeRouteEntryList",
        "vpc:DescribeRouteTableList",
        "vpc:DeleteFullNatEntry",
        "vpc:DescribeVSwitchAttributes"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "eflo:ListUserMachineTypes",
        "eflo:ListClusterNodes",
        "eflo:CreateCluster",
        "eflo:DeleteCluster",
        "eflo:CreateNodeGroup",
        "eflo:ExtendCluster",
        "eflo:ListNodeGroups",
        "eflo:DescribeTask",
        "eflo:DescribeCluster",
        "eflo:ListFreeHyperNodes",
        "eflo:ListFreeNodes",
        "eflo:DescribeNodeGroup",
        "eflo:ListClusters",
        "eflo:CreateTrainJob",
        "eflo:CreateWorkspace",
        "eflo:DeleteWorkspace",
        "eflo:GetMetricsInstantQuery",
        "eflo:GetMetricsRangeQuery",
        "eflo:GetTrainJob",
        "eflo:GetWorkspace",
        "eflo:ListPodEvents",
        "eflo:ListPodLogs",
        "eflo:ListTrainJobs",
        "eflo:ListWorkspaces",
        "eflo:PauseTrainJob",
        "eflo:RestartTrainJob",
        "eflo:ResumeTrainJob",
        "eflo:ScaleOutResourcePool",
        "eflo:ScaleInResourcePool",
        "eflo:TerminateTrainJob",
        "eflo:DescribeNode",
        "eflo:ApproveOperation",
        "eflo:ShrinkCluster",
        "eflo:DeleteNode",
        "eflo:RunCommand",
        "eflo:DescribeInvocations",
        "eflo:DescribeHyperNode",
        "eflo:List*",
        "eflo:Get*",
        "eflo:StartInferenceService",
        "eflo:StopInferenceService",
        "eflo:RestartInferenceService",
        "eflo:ScaleInferenceService",
        "eflo:ScaleInInferenceService",
        "eflo:ScaleOutInferenceService",
        "eflo:CreateInferenceService",
        "eflo:DeleteInferenceService",
        "eflo:UpdateInferenceService",
        "eflo:CreateInferenceServiceApiKey",
        "eflo:DeleteInferenceServiceApiKey"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "privatelink:CreateVpcEndpointService",
        "privatelink:DeleteVpcEndpointService",
        "privatelink:GetVpcEndpointServiceAttribute",
        "privatelink:AddUserToVpcEndpointService",
        "privatelink:RemoveUserFromVpcEndpointService",
        "privatelink:GetVpcEndpointAttribute",
        "privatelink:CreateVpcEndpoint",
        "privatelink:CreateVpcEndpointService",
        "privatelink:DeleteVpcEndpointService",
        "privatelink:GetVpcEndpointServiceAttribute",
        "privatelink:AddUserToVpcEndpointService",
        "privatelink:RemoveUserFromVpcEndpointService",
        "privatelink:CreateVpcEndpoint",
        "privatelink:DeleteVpcEndpoint",
        "privatelink:GetVpcEndpointAttribute",
        "privatelink:ListVpcEndpointZones",
        "privatelink:CheckProductOpen",
        "privatelink:OpenPrivateLinkService",
        "privatelink:ListVpcEndpointServiceResources",
        "privatelink:AttachResourceToVpcEndpointService",
        "privatelink:ListVpcEndpointServices",
        "privatelink:RemoveZoneFromVpcEndpoint",
        "privatelink:ListVpcEndpoints"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "nlb:CreateLoadBalancer",
        "nlb:DeleteLoadBalancer",
        "nlb:GetLoadBalancerAttribute",
        "nlb:CreateServerGroup",
        "nlb:DeleteServerGroup",
        "nlb:AddServersToServerGroup",
        "nlb:CreateListener",
        "nlb:DeleteListener",
        "nlb:GetJobStatus",
        "nlb:ListListeners"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "bss:ModifyInstance",
        "bss:RefundBatchRemainRefund"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "vpc:DescribeVpcAttribute"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "cr:GetAuthorizationToken",
        "cr:ListInstanceEndpoint",
        "cr:CreateInstanceVpcEndpointLinkedVpc",
        "cr:ListInstance",
        "cr:GetInstanceVpcEndpoint",
        "cr:DeleteInstanceVpcEndpointLinkedVpc"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "slb:DescribeLoadBalancerTCPListenerAttribute",
        "slb:CreateAccessControlList",
        "slb:AddAccessControlListEntry",
        "slb:SetLoadBalancerTCPListenerAttribute",
        "slb:DescribeAccessControlLists",
        "slb:DescribeAccessControlListAttribute",
        "slb:RemoveAccessControlListEntry"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "resourcesharing:CreateResourceShare",
        "resourcesharing:AssociateResourceShare",
        "resourcesharing:ListResourceShareAssociations",
        "resourcesharing:ListResourceShareInvitations",
        "resourcesharing:AcceptResourceShareInvitation",
        "resourcesharing:DisassociateResourceShare",
        "resourcesharing:DeleteResourceShare",
        "resourcesharing:ListResourceShares"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "cms:ListPrometheusInstances",
        "cms:GetPrometheusInstance",
        "cms:GetPrometheusView",
        "cms:ListPrometheusViews",
        "cms:ListPrometheusMetrics",
        "cms:ListIntegrationPolicyStorageRequirements",
        "cms:ListIntegrationPolicies",
        "cms:CreateIntegrationPolicy",
        "cms:ListAddonReleases",
        "cms:CreateAddonRelease",
        "cms:GetAddonRelease",
        "cms:DeleteAddonRelease",
        "cms:DescribeSystemEventAttribute",
        "log:QueryMetrics",
        "log:QueryPrometheusMetrics",
        "log:GetLogStoreLogs",
        "log:UpdateMachineGroup",
        "log:CreateMachineGroup",
        "log:UpdateMachineGroupMachine",
        "log:GetMachineGroup"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "apig:CreateGateway",
        "apig:GetGateway",
        "apig:DeleteGateway",
        "apig:ListGateways",
        "apig:CreateSource",
        "apig:GetSource",
        "apig:DeleteSource",
        "apig:ListSources",
        "apig:CreateService",
        "apig:GetService",
        "apig:DeleteService",
        "apig:ListServices",
        "apig:CreateHttpApi",
        "apig:GetHttpApi",
        "apig:DeleteHttpApi",
        "apig:ListHttpApis",
        "apig:CreateHttpApiRoute",
        "apig:GetHttpApiRoute",
        "apig:DeleteHttpApiRoute",
        "apig:ListHttpApiRoutes",
        "apig:UpdateHttpApiRoute",
        "apig:DeployHttpApi",
        "apig:UpdateHttpApi",
        "apig:CreateConsumer",
        "apig:GetConsumer",
        "apig:UpdateConsumer",
        "apig:ListConsumers",
        "apig:DeleteConsumer",
        "apig:CreateConsumerAuthorizationRule",
        "apig:ListConsumerAuthorizationRules",
        "apig:RemoveConsumerAuthorizationRule",
        "apig:CreateConsumerAuthorizationRules",
        "apig:QueryConsumerAuthorizationRules",
        "apig:ListPolicyClasses",
        "apig:CreatePolicy",
        "apig:ListPolicies",
        "apig:CreatePolicyAttachment",
        "apig:CreateAndAttachPolicy",
        "apig:UpdatePolicy",
        "apig:UpdateAndAttachPolicy",
        "apig:GetPolicy",
        "apig:GetPolicyAttachment",
        "apig:DeletePolicy",
        "apig:CreateDomain",
        "apig:GetDomain",
        "apig:ListDomains",
        "apig:DeleteDomain",
        "apig:UpdateDomain"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ram:GetRole"
      ],
      "Resource": "*"
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "eflo.aliyuncs.com"
        }
      }
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "nlb.aliyuncs.com"
        }
      }
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "privatelink.aliyuncs.com"
        }
      }
    }
  ]
}

相关文档