AliyunServiceRolePolicyForPaiFeatureStore

AliyunServiceRolePolicyForPaiFeatureStore 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForPaiFeatureStore 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。

策略详情

  • 类型:系统策略

  • 创建时间:2025-10-09 13:55:39

  • 更新时间:2025-10-09 13:55:39

  • 当前版本:v1

策略内容

{
  "Version": "1",
  "Statement": [
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "featurestore.pai.aliyuncs.com"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "oss:GetObject",
        "oss:PutObject",
        "oss:DeleteObject",
        "oss:ListParts",
        "oss:AbortMultipartUpload",
        "oss:ListObjects",
        "oss:ListBuckets",
        "oss:PutBucketCors",
        "oss:GetBucketCors",
        "oss:DeleteBucketCors"
      ],
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "oss:BucketTag/featurestore": "1"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "dataworks:CreateDataSource",
        "dataworks:ListDataSources",
        "dataworks:ListResourceGroups",
        "dataworks:DeleteDataSource",
        "dataworks:CreateDISyncTask",
        "dataworks:GetDeployment",
        "dataworks:ListNodes",
        "dataworks:RunSmokeTest",
        "dataworks:ListInstances",
        "dataworks:GetInstanceLog",
        "dataworks:ListProjects",
        "dataworks:GetProject",
        "dataworks:ListBusiness",
        "dataworks:ListFolders",
        "dataworks:ListFiles",
        "dataworks:DeployFile",
        "dataworks:SubmitFile",
        "dataworks:CreateFile",
        "dataworks:UpdateFile",
        "dataworks:CreateImportMigration",
        "dataworks:StartMigration"
      ],
      "Resource": "*"
    },
    {
      "Action": [
        "hologram:ListInstances",
        "hologram:GetInstance",
        "hologram:GetInstanceMetrics"
      ],
      "Effect": "Allow",
      "Resource": "*"
    },
    {
      "Action": [
        "graphcompute:CreateGraph",
        "graphcompute:CreateGraphSchema",
        "graphcompute:ListGraphSchemas",
        "graphcompute:TriggerLabelBackflow",
        "graphcompute:GetIgraphLabelLastBackflow"
      ],
      "Effect": "Allow",
      "Resource": "*"
    },
    {
      "Action": [
        "kvstore:DescribeInstanceAttribute",
        "kvstore:DescribeInstances"
      ],
      "Effect": "Allow",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "odps:ActOnBehalfOfAUser",
        "odps:ActOnBehalfOfAnotherUser"
      ],
      "Resource": "acs:odps:*:*:users/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "odps:ListProjects",
        "odps:ListTables",
        "odps:GetTableInfo",
        "odps:Describe"
      ],
      "Resource": "*"
    },
    {
      "Action": [
        "ots:ListTable",
        "ots:DescribeTable",
        "ots:CreateTable",
        "ots:DeleteTable",
        "ots:BatchGetRow",
        "ots:GetRange",
        "ots:PutRow",
        "ots:UpdateRow",
        "ots:BatchWriteRow"
      ],
      "Effect": "Allow",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "featurestore:ListInstances",
        "featurestore:GetInstance",
        "featurestore:GetProject",
        "featurestore:ExportModelFeatureTrainingSetTable",
        "featurestore:ListProjects",
        "featurestore:ListProjectFeatureViews",
        "featurestore:GetProjectModelFeature",
        "featurestore:GetProjectFeatureView",
        "featurestore:GetProjectFeatureEntity",
        "featurestore:ListDatasources",
        "featurestore:GetDatasource",
        "featurestore:ListDatasourceTables",
        "featurestore:GetDatasourceTable",
        "featurestore:CreateFeatureEntity",
        "featurestore:ListFeatureEntities",
        "featurestore:GetFeatureEntity",
        "featurestore:DeleteFeatureEntity",
        "featurestore:PublishFeatureViewTable",
        "featurestore:ListFeatureViews",
        "featurestore:GetFeatureView",
        "featurestore:DeleteFeatureView",
        "featurestore:CreateFeatureView",
        "featurestore:UpdateLabelTable",
        "featurestore:ListLabelTables",
        "featurestore:GetLabelTable",
        "featurestore:DeleteLabelTable",
        "featurestore:CreateLabelTable",
        "featurestore:ListModelFeatures",
        "featurestore:GetModelFeature",
        "featurestore:DeleteModelFeature",
        "featurestore:CreateModelFeature",
        "featurestore:UpdateModelFeature",
        "featurestore:GetTask",
        "featurestore:ListTaskLogs",
        "featurestore:ListTasks"
      ],
      "Resource": "*"
    },
    {
      "Action": [
        "privatelink:ListVpcEndpoints",
        "privatelink:GetVpcEndpointAttribute",
        "privatelink:CreateVpcEndpoint",
        "privatelink:AddZoneToVpcEndpoint",
        "privatelink:ListVpcEndpointSecurityGroups"
      ],
      "Effect": "Allow",
      "Resource": "*"
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "privatelink.aliyuncs.com"
        }
      }
    },
    {
      "Action": [
        "ecs:CreateSecurityGroup",
        "ecs:AuthorizeSecurityGroup",
        "ecs:AuthorizeSecurityGroupEgress"
      ],
      "Effect": "Allow",
      "Resource": "*"
    },
    {
      "Action": [
        "vpc:DescribeVSwitchAttributes",
        "vpc:DescribeVpcAttribute"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}

相关文档