本文為您介紹OpenSearch-行業算法版服務關聯角色(AliyunServiceRoleForOpenSearch)的應用場景以及如何刪除服務關聯角色。
背景信息
OpenSearch-行業算法版服務關聯角色(AliyunServiceRoleForOpenSearch)是在某些情況下,為了完成OpenSearch-行業算法版自身的某個功能,需要獲取其他云服務的訪問權限,而提供的RAM角色。更多關于服務關聯角色的信息請參見服務關聯角色。
應用場景
OpenSearch-行業算法版的數據源功能需要訪問云服務Rds/PolarDB/DRDS的資源,通過服務關聯角色功能獲取訪問權限。
AliyunServiceRoleForOpenSearch介紹
角色名稱:AliyunServiceRoleForOpenSearch角色權限策略:AliyunServiceRolePolicyForOpenSearch授權策略:
{
"Version": "1",
"Statement": [
{
"Action": [
"rds:DescribeDBInstanceAttribute",
"rds:DescribeDBInstances",
"rds:DescribeDatabases",
"rds:DescribeDBInstanceIPArrayList",
"rds:DescribeAccounts",
"rds:DescribeAbnormalDBInstances",
"rds:ModifySecurityIps",
"rds:DescribeResourceUsage"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"polardb:DescribeDBClusterAttribute",
"polardb:DescribeDBClusterEndpoints",
"polardb:ModifyDBClusterAccessWhitelist",
"polardb:DescribeDBClusterAccessWhitelist",
"polardb:DescribeDBClusterParameters"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"drds:DescribeDrdsInstance",
"drds:ModifyDrdsIpWhiteList",
"drds:DescribeDrdsDBIpWhiteList",
"drds:DescribeRdsList",
"drds:DescribeDrdsDB"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"dts:ConfigureSubscriptionInstance",
"dts:CreateConsumerGroup",
"dts:StartSubscriptionInstance",
"dts:DescribeSubscriptionInstanceStatus",
"dts:DescribeConsumerGroup",
"dts:DeleteConsumerGroup"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "opensearch.aliyuncs.com"
}
}
}
]
}
刪除服務關聯角色
如果您需要刪除AliyunServiceRoleForOpenSearch(服務關聯角色),需要先釋放掉依賴這個服務關聯角色的OpenSearch-行業算法版的應用,刪除服務關聯角色具體操作請參見刪除服務關聯角色。
文檔內容是否對您有幫助?