授权信息

更新时间:
复制为 MD 格式

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 无影云电脑 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 无影云电脑 的 RAM 代码(RamCode)为 ecd,eds-user,gws,wss ,支持的授权粒度为 操作级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是无影云电脑定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

ecd:SetDesktopGroupTimerStatus SetDesktopGroupTimerStatus update

*全部资源

*

ecd:DescribeImages DescribeImages get

*全部资源

*

ecd:ListTransferFiles ListTransferFiles get

*全部资源

*

ecd:ModifyCustomizedListHeaders ModifyCustomizedListHeaders update

*全部资源

*

ecd:DescribePrice DescribePrice none

*全部资源

*

ecd:DescribeFlowMetric DescribeFlowMetric get

*全部资源

*

ecd:DescribeGlobalDesktopRecords DescribeGlobalDesktopRecords list

*全部资源

*

ecd:CreateNASFileSystem CreateNASFileSystem create

*全部资源

*

ecd:DescribeConfigGroup DescribeConfigGroup list

*全部资源

*

ecd:DeleteBundles DeleteBundles delete

*全部资源

*

ecd:DescribeFotaPendingDesktops DescribeFotaPendingDesktops get

*全部资源

*

ecd:RenewDesktops RenewDesktops none

*全部资源

*

ecd:ModifyCdsFileShareLink ModifyCdsFileShareLink

*全部资源

*

ecd:ModifyTemplate ModifyTemplate update

*全部资源

*

ecd:CreateBundle CreateBundle create

*全部资源

*

ecd:DescribeCens DescribeCens get

*全部资源

*

ecd:DescribeUsersPassword DescribeUsersPassword get

*全部资源

*

ecd:CancelAutoSnapshotPolicy CancelAutoSnapshotPolicy update

*全部资源

*

ecd:GetSpMetadata GetSpMetadata get

*全部资源

*

ecd:MoveCdsFile MoveCdsFile

*全部资源

*

ecd:ApproveFotaUpdate ApproveFotaUpdate none

*全部资源

*

ecd:ModifyOfficeSiteMfaEnabled ModifyOfficeSiteMfaEnabled update

*全部资源

*

ecd:DescribeAutoSnapshotPolicy DescribeAutoSnapshotPolicy list

*全部资源

*

ecd:CancelCoordinationForMonitoring CancelCoordinationForMonitoring

*全部资源

*

ecd:ModifyImageAttribute ModifyImageAttribute update

*全部资源

*

ecd:ModifyDesktopHostName ModifyDesktopHostName update

*全部资源

*

ecd:SetOfficeSiteSsoStatus SetOfficeSiteSsoStatus update

*全部资源

*

ecd:ExportClientEvents ExportClientEvents

*全部资源

*

ecd:RemoveFilePermission RemoveFilePermission

*全部资源

*

ecd:ConfigADConnectorTrust ConfigADConnectorTrust

*全部资源

*

ecd:ClonePolicyGroup ClonePolicyGroup

*全部资源

*

ecd:ListTagResources ListTagResources get

*全部资源

*

ecd:CreateSimpleOfficeSite CreateSimpleOfficeSite create

*全部资源

*

ecd:AddUserToDesktopGroup AddUserToDesktopGroup create

*全部资源

*

ecd:ExportDesktopListInfo ExportDesktopListInfo

*全部资源

*

ecd:DetachCen DetachCen update

*全部资源

*

ecd:CreateCloudDriveGroup CreateCloudDriveGroup create

*全部资源

*

ecd:ListDirectoryUsers ListDirectoryUsers get

*全部资源

*

ecd:DescribeAclEntries DescribeAclEntries list

*全部资源

*

ecd:CreateCdsFileShareLink CreateCdsFileShareLink

*全部资源

*

ecd:ModifyCloudDriveUsers ModifyCloudDriveUsers update

*全部资源

*

ecd:DescribeGlobalTimerBatches DescribeGlobalTimerBatches list

*全部资源

*

ecd:DescribeModificationPrice DescribeModificationPrice none

*全部资源

*

ecd:MigrateImageProtocol MigrateImageProtocol

*全部资源

*

ecd:ListInstalledApps ListInstalledApps none

*全部资源

*

ecd:UntagResources UntagResources update

*全部资源

*

ecd:ModifyTemplateBaseInfo ModifyTemplateBaseInfo update

*全部资源

*

ecd:DescribeCloudDiskGroups DescribeCloudDiskGroups list

*全部资源

*

ecd:ModifyConfigGroup ModifyConfigGroup list

*全部资源

*

ecd:CreateTemplate CreateTemplate create

*全部资源

*

ecd:ApplyAutoSnapshotPolicy ApplyAutoSnapshotPolicy update

*全部资源

*

ecd:GetDesktopGroupDetail GetDesktopGroupDetail get

*全部资源

*

ecd:DescribeClientEvents DescribeClientEvents get

*全部资源

*

ecd:SetDesktopGroupScaleTimer SetDesktopGroupScaleTimer update

*全部资源

*

ecd:UploadImage UploadImage create

*全部资源

*

ecd:RebootDesktops RebootDesktops update

*全部资源

*

ecd:CreateRAMDirectory CreateRAMDirectory create

*全部资源

*

ecd:DescribeDesktopTypes DescribeDesktopTypes list

*全部资源

*

ecd:RemoveUserFromDesktopGroup RemoveUserFromDesktopGroup delete

*全部资源

*

ecd:DeleteImages DeleteImages delete

*全部资源

*

ecd:DescribeDesktopGroupSessions DescribeDesktopGroupSessions list

*全部资源

*

ecd:RenewNetworkPackages RenewNetworkPackages update

*全部资源

*

ecd:ModifyOfficeSiteDnsInfo ModifyOfficeSiteDnsInfo update

*全部资源

*

ecd:ModifyTimerGroup ModifyTimerGroup list

*全部资源

*

ecd:AddDevices AddDevices create

*全部资源

*

ecd:DeleteVirtualMFADevice DeleteVirtualMFADevice delete

*全部资源

*

ecd:CloneCenterPolicy CloneCenterPolicy none

*全部资源

*

ecd:SetDesktopMaintenance SetDesktopMaintenance update

*全部资源

*

ecd:DeleteNASFileSystems DeleteNASFileSystems delete

*全部资源

*

ecd:DescribeRecordFile DescribeRecordFile list

*全部资源

*

ecd:ModifyCenterPolicy ModifyCenterPolicy update

*全部资源

*

ecd:DeleteOfficeSites DeleteOfficeSites delete

*全部资源

*

ecd:CreateCloudDriveService CreateCloudDriveService create

*全部资源

*

ecd:DetachEndUser DetachEndUser update

*全部资源

*

ecd:CreateDesktops CreateDesktops create

*全部资源

*

ecd:ModifyDesktopsPolicyGroup ModifyDesktopsPolicyGroup update

*全部资源

*

ecd:DeleteCenterPolicy DeleteCenterPolicy none

*全部资源

*

ecd:ModifyNASDefaultMountTarget ModifyNASDefaultMountTarget update

*全部资源

*

ecd:CreatePolicyGroup CreatePolicyGroup create

*全部资源

*

ecd:DeleteDesktops DeleteDesktops delete

*全部资源

*

ecd:DescribeUsersInGroup DescribeUsersInGroup get

*全部资源

*

ecd:DescribeDesktopsInGroup DescribeDesktopsInGroup get

*全部资源

*

ecd:DeleteCdsFile DeleteCdsFile

*全部资源

*

ecd:ModifyDesktopChargeType ModifyDesktopChargeType update

*全部资源

*

ecd:BindConfigGroup BindConfigGroup list

*全部资源

*

ecd:GetCoordinateTicket GetCoordinateTicket

*全部资源

*

ecd:ModifyUserEntitlement ModifyUserEntitlement update

*全部资源

*

ecd:DownloadCdsFile DownloadCdsFile

*全部资源

*

ecd:DeleteDevices DeleteDevices delete

*全部资源

*

ecd:ModifyNetworkPackageBandwidth ModifyNetworkPackageBandwidth update

*全部资源

*

ecd:ModifyResourceCenterPolicy ModifyResourceCenterPolicy none

*全部资源

*

ecd:CompleteCdsFile CompleteCdsFile update

*全部资源

*

ecd:DescribeCdsFileShareLinks DescribeCdsFileShareLinks

*全部资源

*

ecd:TagResources TagResources update

*全部资源

*

ecd:DisableDesktopsInGroup DisableDesktopsInGroup update

*全部资源

*

ecd:CreateCdsFile CreateCdsFile create

*全部资源

*

ecd:DescribeImagePermission DescribeImagePermission get

*全部资源

*

ecd:SetDesktopGroupTimer SetDesktopGroupTimer update

*全部资源

*

ecd:DescribeCloudDriveGroups DescribeCloudDriveGroups list

*全部资源

*

ecd:ModifyDiskSpec ModifyDiskSpec update

*全部资源

*

ecd:DescribeRenewalPrice DescribeRenewalPrice list

*全部资源

*

ecd:ModifyAutoSnapshotPolicy ModifyAutoSnapshotPolicy update

*全部资源

*

ecd:DescribeDirectories DescribeDirectories get

*全部资源

*

ecd:DeleteDrive DeleteDrive delete

*全部资源

*

ecd:DescribeCustomizedListHeaders DescribeCustomizedListHeaders get

*全部资源

*

ecd:SetIdpMetadata SetIdpMetadata update

*全部资源

*

ecd:DescribeDesktopGroups DescribeDesktopGroups list

*全部资源

*

ecd:CopyCdsFile CopyCdsFile

*全部资源

*

ecd:ListTransferFileDownloadUrl ListTransferFileDownloadUrl get

*全部资源

*

ecd:ModifyPolicyGroup ModifyPolicyGroup update

*全部资源

*

ecd:DescribeDesktopSessions DescribeDesktopSessions list

*全部资源

*

ecd:ListUserAdOrganizationUnits ListUserAdOrganizationUnits get

*全部资源

*

ecd:DescribeGlobalTimerRecords DescribeGlobalTimerRecords list

*全部资源

*

ecd:ModifyCdsFile ModifyCdsFile

*全部资源

*

ecd:CreateNetworkPackage CreateNetworkPackage create

*全部资源

*

ecd:StartDesktops StartDesktops update

*全部资源

*

ecd:DeleteDirectories DeleteDirectories delete

*全部资源

*

ecd:DissociateNetworkPackage DissociateNetworkPackage

*全部资源

*

ecd:DescribeZones DescribeZones get

*全部资源

*

ecd:CreateCloudDriveUsers CreateCloudDriveUsers create

*全部资源

*

ecd:DeleteCloudDriveGroups DeleteCloudDriveGroups delete

*全部资源

*

ecd:ModifyADConnectorOfficeSite ModifyADConnectorOfficeSite update

*全部资源

*

ecd:ModifyCloudDriveGroups ModifyCloudDriveGroups update

*全部资源

*

ecd:DescribeSnapshots DescribeSnapshots get

*全部资源

*

ecd:ModifyImagePermission ModifyImagePermission update

*全部资源

*

ecd:GetOfficeSiteSsoStatus GetOfficeSiteSsoStatus get

*全部资源

*

ecd:UnlockVirtualMFADevice UnlockVirtualMFADevice

*全部资源

*

ecd:ModifyCloudDrivePermission ModifyCloudDrivePermission update

*全部资源

*

ecd:CreateAutoSnapshotPolicy CreateAutoSnapshotPolicy create

*全部资源

*

ecd:ResetDesktops ResetDesktops update

*全部资源

*

ecd:TransferTaskApprovalCallback TransferTaskApprovalCallback update

*全部资源

*

ecd:DescribeDesktops DescribeDesktops get

*全部资源

*

ecd:DeleteSnapshot DeleteSnapshot delete

*全部资源

*

ecd:DeletePolicyGroups DeletePolicyGroups delete

*全部资源

*

ecd:CreateConfigGroup CreateConfigGroup list

*全部资源

*

ecd:StopInvocation StopInvocation update

*全部资源

*

ecd:StopDesktops StopDesktops update

*全部资源

*

ecd:DescribeTimerGroup DescribeTimerGroup list

*全部资源

*

ecd:DescribeNASFileSystems DescribeNASFileSystems list

*全部资源

*

ecd:CreateDiskEncryptionService CreateDiskEncryptionService

*全部资源

*

ecd:DescribeFotaTasks DescribeFotaTasks

*全部资源

*

ecd:DescribeDesktopMetadata DescribeDesktopMetadata list

*全部资源

*

ecd:DescribeUserConnectionRecords DescribeUserConnectionRecords get

*全部资源

*

ecd:DescribeCloudDriveUsers DescribeCloudDriveUsers get

*全部资源

*

ecd:ExportDesktopGroupInfo ExportDesktopGroupInfo none

*全部资源

*

ecd:ModifyAclEntries ModifyAclEntries update

*全部资源

*

ecd:CancelCopyImage CancelCopyImage

*全部资源

*

ecd:DeleteTemplates DeleteTemplates delete

*全部资源

*

ecd:ModifyEntitlement ModifyEntitlement update

*全部资源

*

ecd:DeleteAutoSnapshotPolicy DeleteAutoSnapshotPolicy delete

*全部资源

*

ecd:ModifyDesktopGroup ModifyDesktopGroup update

*全部资源

*

ecd:SetDirectorySsoStatus SetDirectorySsoStatus

*全部资源

*

ecd:CreateImage CreateImage create

*全部资源

*

ecd:RunCommand RunCommand create

*全部资源

*

ecd:AttachEndUser AttachEndUser update

*全部资源

*

ecd:CreateBandwidthResourcePackages CreateBandwidthResourcePackages create

*全部资源

*

ecd:ModifyOfficeSiteAttribute ModifyOfficeSiteAttribute update

*全部资源

*

ecd:DescribeKmsKeys DescribeKmsKeys list

*全部资源

*

ecd:DescribeImageModifiedRecords DescribeImageModifiedRecords get

*全部资源

*

ecd:ModifyDesktopSpec ModifyDesktopSpec update

*全部资源

*

ecd:UnbindConfigGroup UnbindConfigGroup list

*全部资源

*

ecd:DescribeCenterPolicyList DescribeCenterPolicyList get

*全部资源

*

ecd:DescribeRegions DescribeRegions get

*全部资源

*

ecd:ModifyNetworkPackageEnabled ModifyNetworkPackageEnabled update

*全部资源

*

ecd:CopyImage CopyImage

*全部资源

*

ecd:ResetNASDefaultMountTarget ResetNASDefaultMountTarget update

*全部资源

*

ecd:RebuildDesktops RebuildDesktops update

*全部资源

*

ecd:DescribeCloudDrivePermissions DescribeCloudDrivePermissions

*全部资源

*

ecd:CancelCdsFileShareLink CancelCdsFileShareLink

*全部资源

*

ecd:BatchModifyEntitlement BatchModifyEntitlement

*全部资源

*

ecd:ListCdsFiles ListCdsFiles

*全部资源

*

ecd:AddFilePermission AddFilePermission

*全部资源

*

ecd:WakeupDesktops WakeupDesktops

*全部资源

*

ecd:HibernateDesktops HibernateDesktops

*全部资源

*

ecd:RevokeCoordinatePrivilege RevokeCoordinatePrivilege

*全部资源

*

ecd:ModifyDesktopTimer ModifyDesktopTimer update

*全部资源

*

ecd:DescribeInvocations DescribeInvocations get

*全部资源

*

ecd:SendVerifyCode SendVerifyCode

*全部资源

*

ecd:AssociateNetworkPackage AssociateNetworkPackage

*全部资源

*

ecd:ModifyDesktopName ModifyDesktopName update

*全部资源

*

ecd:DescribeRecordings DescribeRecordings list

*全部资源

*

ecd:ResetSnapshot ResetSnapshot update

*全部资源

*

ecd:DescribeRefundPrice DescribeRefundPrice none

*全部资源

*

ecd:ModifyBundle ModifyBundle update

*全部资源

*

ecd:DeleteCloudDriveUsers DeleteCloudDriveUsers delete

*全部资源

*

ecd:CreateADConnectorOfficeSite CreateADConnectorOfficeSite create

*全部资源

*

ecd:DescribeDevices DescribeDevices get

*全部资源

*

ecd:DescribePolicyGroups DescribePolicyGroups get

*全部资源

*

ecd:ConfigADConnectorUser ConfigADConnectorUser

*全部资源

*

ecd:RenewDesktopGroup RenewDesktopGroup none

*全部资源

*

ecd:ListOfficeSiteUsers ListOfficeSiteUsers get

*全部资源

*

ecd:ActivateOfficeSite ActivateOfficeSite

*全部资源

*

ecd:ApplyCoordinationForMonitoring ApplyCoordinationForMonitoring

*全部资源

*

ecd:CreateSnapshot CreateSnapshot create

*全部资源

*

ecd:CreateDrive CreateDrive create

*全部资源

*

ecd:DescribeEcdReportTasks DescribeEcdReportTasks none

*全部资源

*

ecd:LockVirtualMFADevice LockVirtualMFADevice

*全部资源

*

ecd:AttachCen AttachCen update

*全部资源

*

ecd:CreateADConnectorDirectory CreateADConnectorDirectory create

*全部资源

*

ecd:CreateDesktopGroup CreateDesktopGroup create

*全部资源

*

ecd:DescribeGuestApplications DescribeGuestApplications get

*全部资源

*

ecd:DescribeOfficeSites DescribeOfficeSites get

*全部资源

*

ecd:ApplyCoordinatePrivilege ApplyCoordinatePrivilege

*全部资源

*

ecd:DisconnectDesktopSessions DisconnectDesktopSessions update

*全部资源

*

ecd:DeleteNetworkPackages DeleteNetworkPackages delete

*全部资源

*

ecd:DescribeDrives DescribeDrives

*全部资源

*

ecd:ListFilePermission ListFilePermission

*全部资源

*

ecd:VerifyCen VerifyCen none

*全部资源

*

ecd:DescribeVirtualMFADevices DescribeVirtualMFADevices get

*全部资源

*

ecd:DescribeSessionStatistic DescribeSessionStatistic

*全部资源

*

ecd:DeleteConfigGroup DeleteConfigGroup list

*全部资源

*

ecd:GetConnectionTicket GetConnectionTicket get

*全部资源

*

ecd:DescribeBundles DescribeBundles get

*全部资源

*

ecd:UpdateFotaTask UpdateFotaTask update

*全部资源

*

ecd:DescribeTemplates DescribeTemplates list

*全部资源

*

ecd:DescribeDesktopInfo DescribeDesktopInfo list

*全部资源

*

ecd:DescribeResourceByCenterPolicyId DescribeResourceByCenterPolicyId none

*全部资源

*

ecd:CreateEcdReportTask CreateEcdReportTask none

*全部资源

*

ecd:DescribeCloudDiskGroupDrives DescribeCloudDiskGroupDrives list

*全部资源

*

ecd:DescribeNetworkPackages DescribeNetworkPackages get

*全部资源

*

ecd:ModifyUserToDesktopGroup ModifyUserToDesktopGroup update

*全部资源

*

ecd:MigrateDesktops MigrateDesktops update

*全部资源

*

ecd:ListOfficeSiteOverview ListOfficeSiteOverview get

*全部资源

*

ecd:CreateAndBindNasFileSystem CreateAndBindNasFileSystem create

*全部资源

*

ecd:DescribeFlowStatistic DescribeFlowStatistic get

*全部资源

*

ecd:ModifyADConnectorDirectory ModifyADConnectorDirectory update

*全部资源

*

ecd:CreateCenterPolicy CreateCenterPolicy none

*全部资源

*

ecd:ModifyOfficeSiteCrossDesktopAccess ModifyOfficeSiteCrossDesktopAccess update

*全部资源

*

ecd:DeleteDesktopGroup DeleteDesktopGroup delete

*全部资源

*

ecd:GetAsyncTask GetAsyncTask

*全部资源

*

资源(Resource)

下表是无影云电脑定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

条件(Condition)

无影云电脑未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: