AliyunServiceRolePolicyForPAINextIDE 是专用于服务关联角色的授权策略,会在创建服务关联角色 AliyunServiceRoleForPAINextIDE 时自动授权,以允许服务关联角色代您访问其他云服务。本策略由对应的阿里云服务按需更新,请勿将本策略授权给服务关联角色之外的 RAM 身份使用。
策略详情
类型:系统策略
创建时间:2025-04-23 22:16:49
更新时间:2025-04-23 22:16:49
当前版本:v1
策略内容
{
"Version": "1",
"Statement": [
{
"Action": [
"odps:ActOnBehalfOfAnotherUser",
"odps:GetJobCount",
"odps:GetTableInfo",
"odps:GetFunctionInfo",
"odps:ListTablePartitions",
"odps:PreviewTable",
"odps:ListProjects",
"odps:CreateProject",
"odps:GetProject",
"odps:ListOutboundInternetAddress",
"odps:UpdateOutboundInternetAddress",
"odps:CreateRole",
"odps:UpdateRole",
"odps:UpdateUsersToAdmin",
"odps:UpdateUsersToSuperAdmin",
"odps:UpdateUsersToRole",
"odps:UpdateProjectStatus",
"odps:GetRoleAcl",
"odps:GetRoleAclOnObject",
"odps:GetRolePolicy",
"odps:ListResources",
"odps:ListRoles",
"odps:GetPackage",
"odps:CreatePackage",
"odps:ListPackages",
"odps:UpdatePackage",
"odps:ListUserPermissionsAsStringByProject",
"odps:ListUserPermissionsByProject",
"odps:ListUsersInfoByProject",
"odps:ListProjectUsers",
"odps:CreateSchema",
"odps:ListSchemas",
"odps:ListFunctions",
"odps:GetTrustedProjects",
"odps:GetAclAuthInfo",
"odps:CheckRamRole",
"odps:GetAsyncJobResult",
"odps:ListTables",
"odps:ListUsersByRole",
"odps:ListQuotaRoutingRules",
"odps:GetQuotaRoutingRule",
"odps:GetQuota",
"odps:ListQuotas",
"odps:ListQuotasPlans",
"odps:GetQuotaPlan",
"odps:GetQuotaSchedule",
"odps:ListUsers",
"odps:GetMetric",
"odps:GetQuotaUsage",
"odps:ListTopJobInfo",
"odps:ListJobInfos",
"odps:ListJobSnapshotInfos",
"odps:KillJobs",
"odps:GetJobResourceUsage",
"odps:GetRunningJobs",
"odps:GetJobSummaryByPreCompute",
"odps:GetJobLogView",
"odps:GetJobAnalyzeQuotaUsage",
"odps:GetJobAnalyzeQuotaDistribution",
"odps:GetJobInfo",
"odps:ListSimilarJobInfos",
"odps:ListJobMetric"
],
"Effect": "Allow",
"Resource": "*"
},
{
"Action": [
"stream:ActOnBehalfOfAnotherUser",
"stream:CreateDeployment",
"stream:StartJobWithParams",
"stream:ListDeployments",
"stream:GetDeployment",
"stream:GetJob",
"stream:StopJob",
"stream:DeleteDeployment"
],
"Effect": "Allow",
"Resource": "*"
},
{
"Action": "dlf-auth:ActOnBehalfOfAnotherUser",
"Effect": "Allow",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"emr-serverless-spark:CreateSqlStatement",
"emr-serverless-spark:GetSqlStatement",
"emr-serverless-spark:TerminateSqlStatement",
"emr-serverless-spark:ListSessionClusters",
"emr-serverless-spark:CancelJobRun",
"emr-serverless-spark:ListJobRuns",
"emr-serverless-spark:GetJobRun",
"emr-serverless-spark:StartJobRun",
"emr-serverless-spark:AddMembers"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"adb:SubmitSparkApp",
"adb:GetSparkAppState",
"adb:GetSparkAppLog",
"adb:GetSparkAppWebUiAddress",
"adb:ListSparkApps",
"adb:GetSparkAppInfo",
"adb:KillSparkApp",
"adb:DescribeAdbMySqlTables",
"adb:getDatabaseObjectsByFilter",
"adb:getTable"
],
"Resource": "*"
},
{
"Action": [
"searchengine:GetInstance",
"searchengine:ListInstances",
"searchengine:GetTable",
"searchengine:ListTables"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "nextide.pai.aliyuncs.com"
}
}
}
]
}
相关文档
该文章对您有帮助吗?