限制項 | 權限策略名稱 | 代碼 | 說明 |
實例創建 | CreateRdsWithNonDiskEncryptionForbidden | 點擊展開 {
"Statement": [
{
"Action": [
"rds:CreateDBInstance",
"rds:PreCheckCreateOrder",
"rds:CreateOrder"
],
"Effect": "Deny",
"Resource": "*",
"Condition": {
"Bool": {
"rds:DiskEncryptionRequired": "false"
}
}
}
],
"Version": "1"
}
| 防止目標用戶創建磁盤沒有加密的RDS實例。
說明 本功能當前僅適用于新建主實例,除此之外的所有場景下(例如創建只讀實例、恢復數據到新實例),本功能不會生效。 |
CreateRdsWithNonVPCNetworkTypeForbidden | 點擊展開 {
"Statement": [
{
"Action": [
"rds:CreateDBInstance",
"rds:PreCheckCreateOrder",
"rds:CreateOrder"
],
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:InstanceNetworkType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目標用戶創建網絡類型為非專有網絡VPC的RDS實例。
說明 本功能當前僅適用于新建主實例,除此之外的所有場景下(例如創建只讀實例、恢復數據到新實例),本功能不會生效。 |
網絡配置 | DatabaseConnectionNonVPCNetworkTypeForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyDBInstanceNetworkType",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:InstanceNetworkType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目標用戶切換RDS實例的網絡類型為經典網絡。 |
安全配置 | DataSecuritySSLDisabledForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyDBInstanceSSL",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:SSLEnabled": "0"
}
}
}
],
"Version": "1"
}
| 防止目標用戶關閉RDS實例的SSL加密。 |
DataSecurityTDEDisabledForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyDBInstanceTDE",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:TDEStatus": "Enabled"
}
}
}
],
"Version": "1"
}
| 防止目標用戶關閉RDS實例的透明數據加密TDE。 |
數據庫代理配置 | DatabaseProxyWithNonVPCNetworkTypeForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyDBProxy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:InstanceNetworkType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目標用戶在開啟RDS實例的數據庫代理服務時,指定網絡地址類型為外網。 |
DatabaseProxyCreateEndpointAddressWithNonVPCNetworkTypeForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:CreateDBProxyEndpointAddress",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:DBProxyConnectStringNetType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目標用戶在創建RDS實例的數據庫代理連接地址時,指定網絡地址類型為外網。 |
DatabaseProxyModifyEndpointAddressWithNonVPCNetworkTypeForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyDBProxyEndpointAddress",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:DBProxyConnectStringNetType": "VPC"
}
}
}
],
"Version": "1"
}
| 防止目標用戶在修改RDS實例的數據庫代理連接地址時,指定網絡地址類型為外網。 |
DatabaseProxyDbProxyInstanceSslDisabledForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyDbProxyInstanceSsl",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:DbProxySslEnabled": "0"
}
}
}
],
"Version": "1"
}
| 防止目標用戶關閉RDS實例的數據庫代理SSL加密功能。 |
備份相關配置 | BackupAndRestorationCrossBackupDisabledForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyInstanceCrossBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:BackupEnabled": "1"
}
}
},
{
"Action": "rds:ModifyInstanceCrossBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:LogBackupEnabled": "1"
}
}
}
],
"Version": "1"
}
| 防止目標用戶關閉RDS實例的跨地域備份功能。 |
BackupAndRestorationBackupPolicyDisabledForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:EnableBackupLog": "0"
}
}
},
{
"Action": "rds:ModifyBackupPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:BackupLog": "Disabled"
}
}
}
],
"Version": "1"
}
| 防止目標用戶關閉RDS實例的日志備份功能。 |
歷史事件 | EventCenterActionEventEnableEventLogForbidden | 點擊展開 {
"Statement": [
{
"Action": "rds:ModifyActionEventPolicy",
"Effect": "Deny",
"Resource": "*",
"Condition": {
"StringNotEquals": {
"rds:EnableEventLog": "False"
}
}
}
],
"Version": "1"
}
| 防止目標用戶開啟RDS實例的歷史事件功能。 |