AliyunGovernanceReadOnlyAccess
更新時間:
AliyunGovernanceReadOnlyAccess 是阿里云管理的產(chǎn)品系統(tǒng)策略,您可以將 AliyunGovernanceReadOnlyAccess 授權(quán)給 RAM 身份(RAM 用戶、RAM 用戶組和 RAM 角色),本策略定義了只讀管理云治理中心(Governance)的權(quán)限。
策略詳情
類型:系統(tǒng)策略
創(chuàng)建時間:2021-07-08 09:30:13
更新時間:2023-08-08 06:17:12
當(dāng)前版本:v9
策略內(nèi)容
{
"Statement": [
{
"Effect": "Allow",
"Action": [
"governance:List*",
"governance:Get*"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"resourcemanager:GetResourceDirectory",
"resourcemanager:ListResources",
"resourcemanager:ListFoldersForParent",
"resourcemanager:GetAccount",
"resourcemanager:GetPayerForAccount",
"resourcemanager:GetFolder",
"resourcemanager:ListAccountRecordsForParent",
"resourcemanager:ListChildrenForParent",
"resourcemanager:ListAccounts",
"resourcemanager:ListAccountsForParent",
"resourcemanager:ListAncestors",
"resourcemanager:ListDelegatedAdministrators"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"ram:GetAccountSummary",
"ram:ListSAMLProviders"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"config:DescribeDeliveryChannels",
"config:GetAggregateConfigRuleComplianceByPack",
"config:ListSupportedProducts",
"config:ListAggregateConfigRuleEvaluationResults",
"config:ListCompliancePackTemplates",
"config:GetManagedRule",
"config:GetConfigRule",
"config:ListAggregators",
"config:DescribeConfigurationRecorder",
"config:GetAggregateDiscoveredResource",
"config:ListAggregateResourceEvaluationResults",
"config:ListAggregateConfigDeliveryChannels",
"actiontrail:DescribeTrails",
"config:GetAggregateResourceComplianceByConfigRule"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"cloudsso:GetServiceStatus",
"cloudsso:ListDirectories",
"cloudsso:GetExternalSAMLIdentityProvider",
"cloudsso:GetDirectorySAMLServiceProviderInfo",
"cloudsso:GetMFAAuthenticationStatus"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"cen:ListTransitRouterAvailableResource"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "ram:ListPolicies",
"Resource": "acs:ram:*:system:policy/*"
},
{
"Effect": "Allow",
"Action": [
"ecs:DescribeImages",
"ecs:DescribeImageSharePermission",
"ecs:DescribeRegions"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "log:ListProject",
"Resource": "acs:log:*:*:project/*"
},
{
"Effect": "Allow",
"Action": [
"quotas:GetProductQuota"
],
"Resource": "*"
}
],
"Version": "1"
}
相關(guān)文檔
文檔內(nèi)容是否對您有幫助?