日本熟妇hd丰满老熟妇,中文字幕一区二区三区在线不卡 ,亚洲成片在线观看,免费女同在线一区二区

授權(quán)信息

更新時(shí)間:
訪問(wèn)控制(RAM)是阿里云提供的管理用戶身份與資源訪問(wèn)權(quán)限的服務(wù)。使用RAM可以讓您避免與其他用戶共享阿里云賬號(hào)密鑰,并可按需為用戶授予最小權(quán)限。RAM中使用權(quán)限策略描述授權(quán)的具體內(nèi)容。
本文為您介紹云服務(wù)器 ECS為RAM權(quán)限策略定義的操作(Action)、資源(Resource)和條件(Condition)。云服務(wù)器 ECS的RAM代碼(RamCode)為[{"popCode":"Ecs","ramCodes":["ecs","vpc"]},{"popCode":"ecs-workbench","ramCodes":["ecs-workbench"]}],支持的授權(quán)粒度為RESOURCE

權(quán)限策略通用結(jié)構(gòu)

權(quán)限策略支持JSON格式,其通用結(jié)構(gòu)如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含義如下:
  • Effect:權(quán)限策略效果。取值:Allow(允許)、Deny(拒絕)。
  • Action:授予允許或拒絕權(quán)限的具體操作。具體信息,請(qǐng)參見(jiàn)操作(Action)
  • Resource:受操作影響的具體對(duì)象,您可以使用資源ARN來(lái)描述指定資源。具體信息,請(qǐng)參見(jiàn)資源(Resource)
  • Condition:指授權(quán)生效的條件。可選字段。具體信息,請(qǐng)參見(jiàn)條件(Condition)
    • Condition_operator:條件運(yùn)算符,不同類型的條件對(duì)應(yīng)不同的條件運(yùn)算符。具體信息,請(qǐng)參見(jiàn)權(quán)限策略基本元素
    • Condition_key:條件關(guān)鍵字。
    • Condition_value:條件關(guān)鍵字對(duì)應(yīng)的值。

操作(Action)

下表是云服務(wù)器 ECS定義的操作,這些操作可以在RAM權(quán)限策略語(yǔ)句的Action元素中使用,用來(lái)授予執(zhí)行該操作的權(quán)限。下面對(duì)表中的具體項(xiàng)提供說(shuō)明:
  • 操作:是指具體的權(quán)限點(diǎn)。
  • API:是指操作對(duì)應(yīng)的API接口。
  • 訪問(wèn)級(jí)別:是指每個(gè)操作的訪問(wèn)級(jí)別,取值為寫(xiě)入(Write)、讀取(Read)或列出(List)。
  • 資源類型:是指操作中支持授權(quán)的資源類型。具體說(shuō)明如下:
    • 對(duì)于必選的資源類型,用背景高亮的方式表示。
    • 對(duì)于不支持資源級(jí)授權(quán)的操作,用全部資源表示。
  • 條件關(guān)鍵字:是指云產(chǎn)品自身定義的條件關(guān)鍵字。該列不體現(xiàn)適用于任何操作的通用條件關(guān)鍵字
  • 關(guān)聯(lián)操作:是指成功執(zhí)行操作所需要的其他權(quán)限。操作者必須同時(shí)具備關(guān)聯(lián)操作的權(quán)限,操作才能成功。
操作API訪問(wèn)級(jí)別資源類型條件關(guān)鍵字關(guān)聯(lián)操作
ecs:DescribeDedicatedHostClustersDescribeDedicatedHostClustersget
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/*
無(wú)無(wú)
ecs:ModifyDedicatedHostAutoReleaseTimeModifyDedicatedHostAutoReleaseTimeupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:DescribeDedicatedHostsDescribeDedicatedHostsget
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/*
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:RedeployDedicatedHostRedeployDedicatedHostupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:AllocateDedicatedHostsAllocateDedicatedHostscreate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/*
無(wú)無(wú)
ecs:DescribeDedicatedHostAutoRenewDescribeDedicatedHostAutoRenewget
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:ModifyDedicatedHostClusterAttributeModifyDedicatedHostClusterAttributeupdate
ddhcluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
無(wú)無(wú)
ecs:RenewDedicatedHostsRenewDedicatedHostsupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:ModifyDedicatedHostAttributeModifyDedicatedHostAttributeupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
無(wú)無(wú)
ecs:ModifyInstanceDeploymentModifyInstanceDeploymentupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
無(wú)無(wú)
ecs:ReleaseDedicatedHostReleaseDedicatedHostdelete
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:ModifyDedicatedHostAutoRenewAttributeModifyDedicatedHostAutoRenewAttributeupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
無(wú)無(wú)
ecs:DeleteDedicatedHostClusterDeleteDedicatedHostClusterdelete
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
無(wú)無(wú)
ecs:ModifyDedicatedHostsChargeTypeModifyDedicatedHostsChargeTypeupdate
全部資源
*
無(wú)無(wú)
ecs:CreateDedicatedHostClusterCreateDedicatedHostClustercreate
全部資源
*
無(wú)無(wú)

資源(Resource)

下表是云服務(wù)器 ECS定義的資源,這些資源可以在RAM權(quán)限策略語(yǔ)句的Resource元素中使用,用來(lái)授予對(duì)該資源執(zhí)行具體操作的權(quán)限。 其中,資源ARN是資源在阿里云上的唯一標(biāo)識(shí)。具體說(shuō)明如下:
  • {#}為變量標(biāo)識(shí),需要您替換為實(shí)際值。例如:{#ramcode}需要您替換為實(shí)際的云服務(wù)RAM代碼。
  • *表示全部。例如:
    • {#resourceType}*時(shí):表示全部資源。
    • {#regionId}*時(shí):表示全部地域。
    • {#accountId}*時(shí):表示全部阿里云賬號(hào)。
資源類型資源ARN
PrefixListacs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
Snapshotacs:ecs:{#regionId}:{#accountId}:snapshot/*
SnapshotGroupacs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
Instanceacs:ecs:{#regionId}:{#accountId}:instance/*
DedicatedHostacs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Diskacs:ecs:{#regionId}:{#accountId}:disk/*
Diskacs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
NetworkInterfaceacs:ecs:{#regionId}:{#accountId}:eni/*
NetworkInterfaceacs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Imageacs:ecs:{#regionId}:{#accountId}:image/*
Imageacs:ecs:{#regionId}:{#accountId}:image/{#imageId}
Instanceacs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPairacs:ecs:{#regionId}:{#accountId}:keypair/*
KeyPairacs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
ReservedInstanceacs:ecs:{#regionId}:{#accountId}:reservedinstance/*
ReservedInstanceacs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
SecurityGroupacs:ecs:{#regionId}:{#accountId}:securitygroup/*
SecurityGroupacs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
Snapshotacs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
DedicatedHostacs:ecs:{#regionId}:{#accountId}:ddh/*
DedicatedHostClusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
DedicatedHostClusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/*
ElasticityAssuranceacs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
Commandacs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ImagePipelineacs:ecs:{#regionId}:{#accountId}:imagepipeline/*
ImagePipelineacs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
CapacityReservationacs:ecs:{#regionId}:{#accountId}:capacityreservation/*
AutoSnapshotPolicyacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
StorageCapacityUnitacs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
DeploymentSetacs:ecs:{#regionId}:{#accountId}:deploymentset/{#DeploymentSetId}
Volumeacs:ecs:{#regionId}:{#accountId}:volume/*
VSwitchacs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
LaunchTemplateacs:ecs:{#regionId}:{#accountId}:launchtemplate/*
LaunchTemplateacs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
Volumeacs:ecs:{#regionId}:{#accountId}:volume/{#volumeId}
KeyPairacs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
Activationacs:ecs:{#regionId}:{#accountId}:activation/{#ActivationId}
HpcClusteracs:ecs:{#regionId}:{#accountId}:hpc/*
Fleetacs:ecs:{#regionId}:{#accountId}:fleet/*
ddhclusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
Commandacs:ecs:{#regionId}:{#accountId}:command/*
Demandacs:ecs:*:{#accountId}:*
StorageCapacityUnitacs:ecs:{#regionId}:{#accountId}:scu/*
AutoProvisioningGroupacs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
Activationacs:ecs:{#regionId}:{#accountId}:activation/*
AutoSnapshotPolicyacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
VPCacs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
ElasticityAssuranceacs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
AutoSnapshotPolicyacs:ecs:{#regionId}:{#accountId}:autosnapshotpolicy/*
snapshotpolicyacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
Snapshotacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#autoSnapshotPolicyId}
AutoProvisioningGroupacs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/*
ImageComponentacs:ecs:{#regionId}:{#accountId}:imagecomponent/*
VSwitchacs:vpc:{#regionId}:{#accountId}:vswitch/*
Demandacs:ecs:{#regionId}:{#accountId}:ecsdemand/*
SnapshotGroupacs:ecs:{#regionId}:{#accountId}:snapshotgroup/*
ServiceSettingsacs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
activationacs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
ImageComponentacs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
Roleacs:ram:*:{#accountId}:role/{#roleName}
DeploymentSetacs:ecs:{#regionId}:{#accountId}:deploymentset/*
Invocationacs:ecs:{#regionId}:{#accountId}:invocation/{#invocationId}
autoprovisioninggroupacs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ddhclusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/*
RouteTableacs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
HaVipacs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
Addressacs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
VirtualBorderRouteracs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VbrId}
RouterInterfaceacs:vpc:{#regionId}:{#accountId}:routerinterface/*
Addressacs:vpc:{#regionId}:{#accountId}:eip/*
NatGatewayacs:vpc:{#regionId}:{#accountId}:natgateway/*
PhysicalConnectionacs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
ForwardTableacs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
NatGatewayacs:vpc:{#regionId}:{#accountId}:natgateway/{#natgatewayid}
VirtualBorderRouteracs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
BandwidthPackageacs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
RouterInterfaceacs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
Instanceacs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
BandwidthPackageacs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*
Associationacs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
VPCacs:vpc:{#regionId}:{#accountId}:vpc/*
HaVipacs:vpc:{#regionId}:{#accountId}:havip/*
PhysicalConnectionacs:vpc:{#regionId}:{#accountId}:physicalconnection/*
VRouteracs:vpc:{#regionId}:{#accountId}:vrouter/*
VRouteracs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}
VirtualBorderRouteracs:vpc:{#regionId}:{#AccountId}:virtualborderrouter/*

條件(Condition)

下表是云服務(wù)器 ECS定義的產(chǎn)品級(jí)條件關(guān)鍵字,這些條件關(guān)鍵字可以在RAM權(quán)限策略語(yǔ)句的Condition元素中使用,用來(lái)描述授予權(quán)限的條件。以下僅列舉產(chǎn)品級(jí)的條件關(guān)鍵字,阿里云定義的通用條件關(guān)鍵字也同樣適用云服務(wù)器 ECS
其中,數(shù)據(jù)類型決定了您可以使用哪些條件運(yùn)算符將請(qǐng)求中的值與權(quán)限策略語(yǔ)句中的值進(jìn)行比較。您必須使用與數(shù)據(jù)類型匹配的條件運(yùn)算符,否則無(wú)法匹配策略語(yǔ)句,授權(quán)行為無(wú)效。數(shù)據(jù)類型與條件運(yùn)算符的對(duì)應(yīng)關(guān)系,請(qǐng)參見(jiàn)條件操作類型
條件關(guān)鍵字描述類型
vpc:VPCVPC信息String
vpc:IsDefaultVSwitch是否為默認(rèn)VSwitch,是否可以使用默認(rèn)VSwitchBoolean
vpc:IsDefaultVpc是否為默認(rèn)VPCBoolean
ecs:IsDiskEncrypted是否為加密數(shù)據(jù)盤(pán)String
ecs:InstanceType實(shí)例規(guī)格String
ecs:InstanceTypeFamily實(shí)例規(guī)格族String
ecs:ImagePlatform鏡像的操作系統(tǒng)類型String
ecs:ImageSource鏡像來(lái)源String
ecs:CommandRunAs執(zhí)行云助手命令的操作系統(tǒng)內(nèi)用戶String
ecs:IsSystemDiskEncrypted是否為加密系統(tǒng)盤(pán)String
ecs:ImageOwnerId鏡像的所有者UID。String
ecs:AssociatePublicIpAddress是否支持資源在創(chuàng)建和變配過(guò)程中進(jìn)行公網(wǎng)IP分配,即是否允許操作資源使公網(wǎng)帶寬大于0。Boolean
ecs:PasswordCustomized是否使用了自定義密碼Boolean
ecs:PasswordInherit實(shí)例是否繼承鏡像密碼Boolean
ecs:SecurityEnhancementStrategy是否開(kāi)啟安全加固。String
ecs:SecurityHardeningMode訪問(wèn)實(shí)例元數(shù)據(jù)時(shí)是否強(qiáng)制使用加固模式(IMDSv2)Boolean
vpc:CreateDefaultVpc是否可以創(chuàng)建默認(rèn)VPCBoolean
ecs:SecurityGroupIpProtocols安全組開(kāi)放的傳輸層協(xié)議String
ecs:SecurityGroupSourceCidrIps安全組設(shè)置訪問(wèn)權(quán)限的源端IPv4 CIDR地址段String
ecs:NotSpecifySecurityGroupId是否沒(méi)有指定安全組IDBoolean

相關(guān)操作

您可以創(chuàng)建自定義權(quán)限策略,并將權(quán)限策略授予RAM用戶、RAM用戶組或RAM角色。具體操作如下: