DataWorks服務(wù)關(guān)聯(lián)角色
首次使用獨(dú)享資源組時(shí),系統(tǒng)會自動創(chuàng)建AliyunServiceRoleForDataWorks
服務(wù)關(guān)聯(lián)角色,用來訪問專有網(wǎng)絡(luò)VPC(Virtual Private Cloud)、彈性網(wǎng)卡ENI(Elastic Network Interface)及安全組中的資源。本文為您介紹如何查看該角色詳情并使用RAM用戶創(chuàng)建該服務(wù)關(guān)聯(lián)角色。
背景信息
更多服務(wù)關(guān)聯(lián)角色的介紹,詳情請參見服務(wù)關(guān)聯(lián)角色。
查看AliyunServiceRoleForDataWorks服務(wù)關(guān)聯(lián)角色的權(quán)限策略
您可登錄RAM控制臺,按照下圖所示步驟進(jìn)入AliyunServiceRoleForDataWorks
服務(wù)關(guān)聯(lián)角色的詳情頁,查看角色名稱、創(chuàng)建時(shí)間等基本信息。
如果無需使用AliyunServiceRoleForDataWorks
角色,則可將其刪除。刪除后,將無法為獨(dú)享資源組綁定專有網(wǎng)絡(luò)VPC,但已綁定的網(wǎng)絡(luò)鏈路不受影響。
在AliyunServiceRoleForDataWorks
角色詳情頁的權(quán)限管理頁簽,可查看該角色被授予的權(quán)限策略詳情,具體如下。
{
"Version": "1",
"Statement": [
{
"Action": [
"ecs:AttachNetworkInterface",
"ecs:AuthorizeSecurityGroup",
"ecs:AuthorizeSecurityGroupEgress",
"ecs:CreateNetworkInterface",
"ecs:CreateNetworkInterfacePermission",
"ecs:CreateSecurityGroup",
"ecs:DeleteNetworkInterface",
"ecs:DeleteNetworkInterfacePermission",
"ecs:DeleteSecurityGroup",
"ecs:DescribeNetworkInterfacePermissions",
"ecs:DescribeNetworkInterfaces",
"ecs:DescribeSecurityGroupAttribute",
"ecs:DescribeSecurityGroupReferences",
"ecs:DescribeSecurityGroups",
"ecs:DetachNetworkInterface",
"ecs:JoinSecurityGroup",
"ecs:LeaveSecurityGroup",
"ecs:ModifyNetworkInterfaceAttribute",
"ecs:ModifySecurityGroupAttribute",
"ecs:ModifySecurityGroupPolicy",
"ecs:ModifySecurityGroupRule",
"ecs:RevokeSecurityGroup",
"ecs:RevokeSecurityGroupEgress",
"ecs:AssignIpv6Addresses",
"ecs:UnassignIpv6Addresses"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"vpc:DescribeVpcs",
"vpc:DescribeVpcAttribute",
"vpc:DescribeVSwitches",
"vpc:DescribeVSwitchAttributes"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "dataworks.aliyuncs.com"
}
}
}
]
}
RAM用戶創(chuàng)建AliyunServiceRoleForDataWorks服務(wù)關(guān)聯(lián)角色的權(quán)限說明
RAM用戶如需創(chuàng)建AliyunServiceRoleForDataWorks
服務(wù)關(guān)聯(lián)角色,則需被授權(quán)AliyunDataWorksFullAccess
權(quán)限策略或下文代碼所示的指定策略。
創(chuàng)建權(quán)限策略并授權(quán)給目標(biāo)RAM用戶,操作詳情請參見創(chuàng)建自定義權(quán)限策略及為RAM用戶授權(quán)。
{
"Version": "1",
"Statement": [
{
"Action": "dataworks:*",
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:CreateServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": [
"dataworks.aliyuncs.com"
]
}
}
}
]
}