When you create an auto provisioning group, the system checks whether your Alibaba Cloud account has the AliyunServiceRoleForAutoProvisioning service-linked role. If your account does not have this role, you will be prompted to create it. After the role is created, Auto Provisioning manages the instances in the group based on the permissions of this service-linked role.
Prerequisites
If you log on as a RAM user, you must have the following permissions to create the service-linked role for Auto Provisioning. For more information, see Grant permissions to a RAM user.
Create AliyunServiceRoleForAutoProvisioning
When you create an auto provisioning group, the system checks whether your Alibaba Cloud account has the AliyunServiceRoleForAutoProvisioning service-linked role. If your account does not have the role, you are prompted to create the role. After you confirm the prompt, the role is automatically created. You can also manually create the role. For more information, see Create a service-linked role.
The permissions of service-linked roles are defined and used by cloud services. You cannot add permissions to, remove permissions from, or modify permissions for service-linked roles. You can view the permissions of the role on the role details page. For more information, see View the information about a RAM role.
Delete AliyunServiceRoleForAutoProvisioning
If you no longer require AliyunServiceRoleForAutoProvisioning, you can delete it. For more information, see Delete a RAM role.
Before you can delete AliyunServiceRoleForAutoProvisioning, you must delete the auto provisioning groups in all regions in your account. Otherwise, the role cannot be deleted. For more information, see Delete auto provisioning groups.
After AliyunServiceRoleForAutoProvisioning is deleted, you cannot use Auto Provisioning to create or manage resources.
Reference
For information about how to create an auto provisioning group, see Create an auto provisioning group.