The service-linked role for CloudMonitor, AliyunServiceRoleForCloudMonitor, is a RAM role that authorizes CloudMonitor to access other Alibaba Cloud services in specific scenarios.
Note For more information about service-linked roles, see Service-linked roles.
Scenarios
- When CloudMonitor automatically installs the CloudMonitor agent on hosts, CloudMonitor uses the service-linked role to obtain the permissions to use Cloud Assistant.
- When you use the log monitoring feature, CloudMonitor uses the service-linked role to obtain the permissions to read data from Log Service.
- When you import metric data from Alibaba Cloud services to CloudMonitor and use the resource usage report feature in Hybrid Cloud Monitoring, CloudMonitor uses the service-linked role to obtain the permissions to query the instances of other Alibaba Cloud services.
- When you use the alert service of CloudMonitor, CloudMonitor uses the service-linked role to obtain the permissions to query the instances of other Alibaba Cloud services.
Permission description
This section describes the permissions of the service-linked role.
- Name: AliyunServiceRoleForCloudMonitor
- Policy attached to the role: AliyunServiceRolePolicyForCloudMonitor
- Policy description: grants CloudMonitor the permissions to use Cloud Assistant to
view status, run commands, and view command output on all instances of the current
account.
Note For more information about the policy, see AliyunServiceRolePolicyForCloudMonitor.
Create the service-linked role
When CloudMonitor automatically installs the CloudMonitor agent on hosts, CloudMonitor automatically creates the service-linked role.
Delete the service-linked role
To delete the service-linked role, perform the following steps: