限制项 | 权限策略名称 | 代码 | 说明 |
实例创建 | CreateRdsWithNonDiskEncryptionForbidden | 点击展开 {
"Statement": [
{
"Action": [
"rds:CreateDBInstance",
"rds:PreCheckCreateOrder",
"rds:CreateOrder"
],
"Effect": "Deny",
"Resource": "*",
"Condition": {
"Bool": {
"rds:DiskEncryptionRequired": "false"
}
}
}
],
"Version": "1"
}
| 防止目标用户创建磁盘没有加密的RDS实例。
说明 本功能当前仅适用于新建主实例,除此之外的所有场景下(例如创建只读实例、恢复数据到新实例),本功能不会生效。 |
CreateRdsWithNonVPCNetworkTypeForbidden | 点击展开 {
"Statement": [
{
"Action": [
"rds:CreateDBInstance",
"rds:PreCheckCreateOrder",
"rds:CreateOrder"
],
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:InstanceNetworkType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目标用户创建网络类型为非专有网络VPC的RDS实例。
说明 本功能当前仅适用于新建主实例,除此之外的所有场景下(例如创建只读实例、恢复数据到新实例),本功能不会生效。 |
网络配置 | DatabaseConnectionNonVPCNetworkTypeForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyDBInstanceNetworkType",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:InstanceNetworkType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目标用户切换RDS实例的网络类型为经典网络。 |
安全配置 | DataSecuritySSLDisabledForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyDBInstanceSSL",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:SSLEnabled": "0"
}
}
}
],
"Version": "1"
}
| 防止目标用户关闭RDS实例的SSL加密。 |
DataSecurityTDEDisabledForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyDBInstanceTDE",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:TDEStatus": "Enabled"
}
}
}
],
"Version": "1"
}
| 防止目标用户关闭RDS实例的透明数据加密TDE。 |
数据库代理配置 | DatabaseProxyWithNonVPCNetworkTypeForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyDBProxy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:InstanceNetworkType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目标用户在开启RDS实例的数据库代理服务时,指定网络地址类型为外网。 |
DatabaseProxyCreateEndpointAddressWithNonVPCNetworkTypeForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:CreateDBProxyEndpointAddress",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:DBProxyConnectStringNetType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目标用户在创建RDS实例的数据库代理连接地址时,指定网络地址类型为外网。 |
DatabaseProxyModifyEndpointAddressWithNonVPCNetworkTypeForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyDBProxyEndpointAddress",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:DBProxyConnectStringNetType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目标用户在修改RDS实例的数据库代理连接地址时,指定网络地址类型为外网。 |
DatabaseProxyDbProxyInstanceSslDisabledForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyDbProxyInstanceSsl",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:DbProxySslEnabled": "0"
}
}
}
],
"Version": "1"
}
| 防止目标用户关闭RDS实例的数据库代理SSL加密功能。 |
备份相关配置 | BackupAndRestorationCrossBackupDisabledForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyInstanceCrossBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:BackupEnabled": "1"
}
}
},
{
"Action": "rds:ModifyInstanceCrossBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:LogBackupEnabled": "1"
}
}
}
],
"Version": "1"
}
| 防止目标用户关闭RDS实例的跨地域备份功能。 |
BackupAndRestorationBackupPolicyDisabledForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:EnableBackupLog": "0"
}
}
},
{
"Action": "rds:ModifyBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:BackupLog": "Disabled"
}
}
}
],
"Version": "1"
}
| 防止目标用户关闭RDS实例的日志备份功能。 |
历史事件 | EventCenterActionEventEnableEventLogForbidden | 点击展开 {
"Statement": [
{
"Action": "rds:ModifyActionEventPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:EnableEventLog": "False"
}
}
}
],
"Version": "1"
}
| 防止目标用户开启RDS实例的历史事件功能。 |