AliyunServiceRoleForCEN
本文為您介紹服務(wù)關(guān)聯(lián)角色AliyunServiceRoleForCEN以及如何刪除該服務(wù)關(guān)聯(lián)角色。
背景信息
服務(wù)關(guān)聯(lián)角色SLR(Service Linked Role)是指與某個(gè)云服務(wù)關(guān)聯(lián)的RAM角色。在某些場(chǎng)景下,為了完成云服務(wù)的某個(gè)功能,需要獲取其他云服務(wù)的訪問權(quán)限。通過服務(wù)關(guān)聯(lián)角色,您可以更好地創(chuàng)建云服務(wù)正常操作所需的權(quán)限,避免誤操作帶來的風(fēng)險(xiǎn)。關(guān)于服務(wù)關(guān)聯(lián)角色的更多信息,請(qǐng)參見服務(wù)關(guān)聯(lián)角色。
創(chuàng)建服務(wù)關(guān)聯(lián)角色AliyunServiceRoleForCEN
您在企業(yè)版轉(zhuǎn)發(fā)路由器中創(chuàng)建專有網(wǎng)絡(luò)VPC(Virtual Private Cloud)網(wǎng)絡(luò)實(shí)例連接時(shí),系統(tǒng)將會(huì)為您自動(dòng)創(chuàng)建一個(gè)名稱為AliyunServiceRoleForCEN的服務(wù)關(guān)聯(lián)角色,并且為該角色添加名稱為AliyunServiceRolePolicyForCEN的權(quán)限策略,該權(quán)限會(huì)允許企業(yè)版轉(zhuǎn)發(fā)路由器在VPC中創(chuàng)建彈性網(wǎng)卡,作為VPC發(fā)往企業(yè)版轉(zhuǎn)發(fā)路由器的流量入口。權(quán)限策略內(nèi)容如下:
如果服務(wù)關(guān)聯(lián)角色AliyunServiceRoleForCEN已存在,系統(tǒng)則不會(huì)重復(fù)創(chuàng)建。
{
"Version": "1",
"Statement": [
{
"Action": [
"vpc:DescribeVSwitchAttributes",
"vpc:CreateRouteEntries",
"vpc:DeleteRouteEntries",
"vpc:DescribeRouteEntryList",
"vpc:GetVpcRouteEntrySummary"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"ecs:CreateNetworkInterface",
"ecs:CreateSecurityGroup",
"ecs:AuthorizeSecurityGroup",
"ecs:RevokeSecurityGroup",
"ecs:DeleteSecurityGroup",
"ecs:JoinSecurityGroup",
"ecs:DeleteSecurityGroup",
"ecs:LeaveSecurityGroup",
"ecs:DescribeSecurityGroups",
"ecs:AttachNetworkInterface",
"ecs:DetachNetworkInterface",
"ecs:DeleteNetworkInterface",
"ecs:DescribeNetworkInterfaces",
"ecs:CreateNetworkInterfacePermission",
"ecs:DescribeNetworkInterfacePermissions",
"ecs:DeleteNetworkInterfacePermission",
"ecs:CreateSecurityGroupPermission",
"ecs:AuthorizeSecurityGroupPermission",
"ecs:RevokeSecurityGroupPermission",
"ecs:DeleteSecurityGroupPermission",
"ecs:JoinSecurityGroupPermission",
"ecs:DeleteSecurityGroupPermission",
"ecs:LeaveSecurityGroupPermission",
"ecs:DescribeSecurityGroupPermissions",
"ecs:AttachNetworkInterfacePermissions",
"ecs:DetachNetworkInterfacePermissions"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"expressconnectrouter:CreateExpressConnectRouterAssociation",
"expressconnectrouter:DeleteExpressConnectRouterAssociation"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "cen.aliyuncs.com"
}
}
}
]
}
刪除服務(wù)關(guān)聯(lián)角色AliyunServiceRoleForCEN
系統(tǒng)不會(huì)自動(dòng)刪除服務(wù)關(guān)聯(lián)角色AliyunServiceRoleForCEN。如果您要?jiǎng)h除服務(wù)關(guān)聯(lián)角色AliyunServiceRoleForCEN,請(qǐng)先刪除所有云企業(yè)網(wǎng)實(shí)例下企業(yè)版轉(zhuǎn)發(fā)路由器下的VPC網(wǎng)絡(luò)實(shí)例連接。具體操作,請(qǐng)參見: