AliyunServiceRolePolicyForLingjunRein 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForLingjunRein 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。
策略详情
类型:系统策略
创建时间:2026-06-14 14:10:42
更新时间:2026-08-11 10:05:14
当前版本:v54
策略内容
{
"Version": "1",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cs:DescribeClusterDetail",
"cs:CreateCluster",
"cs:DescribeClusterNodePools",
"cs:CreateClusterNodePool",
"cs:DescribeClusterAttachScripts",
"cs:DescribeClusterNodes",
"cs:DeleteClusterNodes",
"cs:RemoveNodePoolNodes",
"cs:GetClusters",
"cs:DescribeClusters",
"cs:DeleteCluster",
"cs:DescribeClusterUserKubeconfig",
"cs:AttachInstancesToNodePool",
"cs:DescribeTaskInfo",
"cs:DescribeClusterNodePoolDetail",
"cs:UpdateUserPermissions",
"cs:DescribeClusterDetail",
"cs:AttachInstances",
"cs:GetUserPermissions",
"cs:ListAddons",
"cs:ModifyClusterNodePool",
"cs:ListClusterAddonInstances",
"cs:InstallClusterAddons",
"cs:GetClusterAddonInstance",
"cs:ListAddons",
"cs:DescribeAddon",
"cs:ModifyClusterAddon",
"cs:UpgradeK8sComponents",
"cs:ListClusterAddonInstanceResources",
"cs:UnInstallClusterAddons",
"cr:PullRepository"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"asi:DescribeNodeTicketDetail",
"asi:RetryNodeTicket",
"asi:OfflineNodes",
"asi:DescribeNodes",
"asi:ImportNodes"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"ecs:CreateSecurityGroup",
"ecs:AuthorizeSecurityGroup",
"ecs:AuthorizeSecurityGroupEgress",
"ecs:JoinSecurityGroup",
"ecs:DescribeSecurityGroups",
"ecs:DescribeSecurityGroupAttribute",
"ecs:DescribeInvocationResults",
"ecs:DescribeInstances",
"ecs:DescribeKeyPairs",
"ecs:CreateNetworkInterface",
"ecs:DeleteNetworkInterface",
"ecs:DescribeNetworkInterfaces",
"ecs:CreateNetworkInterfacePermission",
"ecs:DeleteNetworkInterfacePermission",
"ecs:DescribeNetworkInterfacePermissions",
"ecs:CreateSecurityGroup",
"ecs:DeleteSecurityGroup",
"ecs:AuthorizeSecurityGroup",
"ecs:DescribeSecurityGroups",
"ecs:DescribeInstanceAttribute"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"vpc:DescribeVpcAttribute",
"vpc:DescribeVpcs",
"vpc:DescribeVSwitches",
"vpc:DescribeEipAddresses",
"vpc:CreateNatGateway",
"vpc:DeleteNatGateway",
"vpc:DescribeNatGateways",
"vpc:CreateForwardEntry",
"vpc:DeleteForwardEntry",
"vpc:DescribeForwardTableEntries",
"vpc:CreateFullNatEntry",
"vpc:ListFullNatEntries",
"vpc:ListNatIps",
"vpc:DescribeNatGatewayAssociateNetworkInterfaces",
"vpc:CreateVSwitch",
"vpc:DescribeRouteEntryList",
"vpc:DescribeRouteTableList",
"vpc:DeleteFullNatEntry",
"vpc:DescribeVSwitchAttributes"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"eflo:ListUserMachineTypes",
"eflo:ListClusterNodes",
"eflo:CreateCluster",
"eflo:DeleteCluster",
"eflo:CreateNodeGroup",
"eflo:ExtendCluster",
"eflo:ListNodeGroups",
"eflo:DescribeTask",
"eflo:DescribeCluster",
"eflo:ListFreeHyperNodes",
"eflo:ListFreeNodes",
"eflo:DescribeNodeGroup",
"eflo:ListClusters",
"eflo:CreateTrainJob",
"eflo:CreateWorkspace",
"eflo:DeleteWorkspace",
"eflo:GetMetricsInstantQuery",
"eflo:GetMetricsRangeQuery",
"eflo:GetTrainJob",
"eflo:GetWorkspace",
"eflo:ListPodEvents",
"eflo:ListPodLogs",
"eflo:ListTrainJobs",
"eflo:ListWorkspaces",
"eflo:PauseTrainJob",
"eflo:RestartTrainJob",
"eflo:ResumeTrainJob",
"eflo:ScaleOutResourcePool",
"eflo:ScaleInResourcePool",
"eflo:TerminateTrainJob",
"eflo:DescribeNode",
"eflo:ApproveOperation",
"eflo:ShrinkCluster",
"eflo:DeleteNode",
"eflo:RunCommand",
"eflo:DescribeInvocations",
"eflo:DescribeHyperNode",
"eflo:List*",
"eflo:Get*",
"eflo:StartInferenceService",
"eflo:StopInferenceService",
"eflo:RestartInferenceService",
"eflo:ScaleInferenceService",
"eflo:ScaleInInferenceService",
"eflo:ScaleOutInferenceService",
"eflo:CreateInferenceService",
"eflo:DeleteInferenceService",
"eflo:UpdateInferenceService",
"eflo:CreateInferenceServiceApiKey",
"eflo:DeleteInferenceServiceApiKey"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"privatelink:CreateVpcEndpointService",
"privatelink:DeleteVpcEndpointService",
"privatelink:GetVpcEndpointServiceAttribute",
"privatelink:AddUserToVpcEndpointService",
"privatelink:RemoveUserFromVpcEndpointService",
"privatelink:GetVpcEndpointAttribute",
"privatelink:CreateVpcEndpoint",
"privatelink:CreateVpcEndpointService",
"privatelink:DeleteVpcEndpointService",
"privatelink:GetVpcEndpointServiceAttribute",
"privatelink:AddUserToVpcEndpointService",
"privatelink:RemoveUserFromVpcEndpointService",
"privatelink:CreateVpcEndpoint",
"privatelink:DeleteVpcEndpoint",
"privatelink:GetVpcEndpointAttribute",
"privatelink:ListVpcEndpointZones",
"privatelink:CheckProductOpen",
"privatelink:OpenPrivateLinkService",
"privatelink:ListVpcEndpointServiceResources",
"privatelink:AttachResourceToVpcEndpointService",
"privatelink:ListVpcEndpointServices",
"privatelink:RemoveZoneFromVpcEndpoint",
"privatelink:ListVpcEndpoints"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"nlb:CreateLoadBalancer",
"nlb:DeleteLoadBalancer",
"nlb:GetLoadBalancerAttribute",
"nlb:CreateServerGroup",
"nlb:DeleteServerGroup",
"nlb:AddServersToServerGroup",
"nlb:CreateListener",
"nlb:DeleteListener",
"nlb:GetJobStatus",
"nlb:ListListeners"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"bss:ModifyInstance",
"bss:RefundBatchRemainRefund"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"vpc:DescribeVpcAttribute"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"cr:GetAuthorizationToken",
"cr:ListInstanceEndpoint",
"cr:CreateInstanceVpcEndpointLinkedVpc",
"cr:ListInstance",
"cr:GetInstanceVpcEndpoint",
"cr:DeleteInstanceVpcEndpointLinkedVpc"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"slb:DescribeLoadBalancerTCPListenerAttribute",
"slb:CreateAccessControlList",
"slb:AddAccessControlListEntry",
"slb:SetLoadBalancerTCPListenerAttribute",
"slb:DescribeAccessControlLists",
"slb:DescribeAccessControlListAttribute",
"slb:RemoveAccessControlListEntry"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"resourcesharing:CreateResourceShare",
"resourcesharing:AssociateResourceShare",
"resourcesharing:ListResourceShareAssociations",
"resourcesharing:ListResourceShareInvitations",
"resourcesharing:AcceptResourceShareInvitation",
"resourcesharing:DisassociateResourceShare",
"resourcesharing:DeleteResourceShare",
"resourcesharing:ListResourceShares"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"cms:ListPrometheusInstances",
"cms:GetPrometheusInstance",
"cms:GetPrometheusView",
"cms:ListPrometheusViews",
"cms:ListPrometheusMetrics",
"cms:ListIntegrationPolicyStorageRequirements",
"cms:ListIntegrationPolicies",
"cms:CreateIntegrationPolicy",
"cms:ListAddonReleases",
"cms:CreateAddonRelease",
"cms:GetAddonRelease",
"cms:DeleteAddonRelease",
"cms:DescribeSystemEventAttribute",
"log:QueryMetrics",
"log:QueryPrometheusMetrics",
"log:GetLogStoreLogs",
"log:UpdateMachineGroup",
"log:CreateMachineGroup",
"log:UpdateMachineGroupMachine",
"log:GetMachineGroup"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"apig:CreateGateway",
"apig:GetGateway",
"apig:DeleteGateway",
"apig:ListGateways",
"apig:CreateSource",
"apig:GetSource",
"apig:DeleteSource",
"apig:ListSources",
"apig:CreateService",
"apig:GetService",
"apig:DeleteService",
"apig:ListServices",
"apig:CreateHttpApi",
"apig:GetHttpApi",
"apig:DeleteHttpApi",
"apig:ListHttpApis",
"apig:CreateHttpApiRoute",
"apig:GetHttpApiRoute",
"apig:DeleteHttpApiRoute",
"apig:ListHttpApiRoutes",
"apig:UpdateHttpApiRoute",
"apig:DeployHttpApi",
"apig:UpdateHttpApi",
"apig:CreateConsumer",
"apig:GetConsumer",
"apig:UpdateConsumer",
"apig:ListConsumers",
"apig:DeleteConsumer",
"apig:CreateConsumerAuthorizationRule",
"apig:ListConsumerAuthorizationRules",
"apig:RemoveConsumerAuthorizationRule",
"apig:CreateConsumerAuthorizationRules",
"apig:QueryConsumerAuthorizationRules",
"apig:ListPolicyClasses",
"apig:CreatePolicy",
"apig:ListPolicies",
"apig:CreatePolicyAttachment",
"apig:CreateAndAttachPolicy",
"apig:UpdatePolicy",
"apig:UpdateAndAttachPolicy",
"apig:GetPolicy",
"apig:GetPolicyAttachment",
"apig:DeletePolicy",
"apig:CreateDomain",
"apig:GetDomain",
"apig:ListDomains",
"apig:DeleteDomain",
"apig:UpdateDomain"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"ram:GetRole"
],
"Resource": "*"
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "eflo.aliyuncs.com"
}
}
},
{
"Action": "ram:CreateServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "nlb.aliyuncs.com"
}
}
},
{
"Action": "ram:CreateServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "privatelink.aliyuncs.com"
}
}
}
]
}相关文档
该文章对您有帮助吗?