All Products
Search
Document Center

Resource Access Management:AliyunServiceRolePolicyForWorkshop

Last Updated:Jun 27, 2024

AliyunServiceRolePolicyForWorkshop is the authorization policy dedicated to a service-linked role. The policy is automatically attached to a service role when the service role is created. Then, the service-linked role is authorized to access other cloud services. This policy is updated by the relevant Alibaba Cloud service. Do not attach this policy to a RAM identity other than a service-linked role.

Policy details

  • Type: service system policy

  • Creation time: 14:09:29 on June 27, 2024

  • Update time: 14:09:29 on June 27, 2024

  • Current version: v1

Policy content

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "ecs:TagResources",
                "ecs:CreateDisk",
                "ecs:AttachDisk",
                "ecs:DetachDisk",
                "ecs:DeleteDisk",
                "ecs:CreateSnapshot",
                "ecs:DeleteSnapshot"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "cr:PullRepository",
                "cr:PushRepository",
                "cr:GetAuthorizationToken",
                "cr:GetRepositoryLayers",
                "cr:GetRepositoryManifest",
                "cr:GetRepositoryTag",
                "cr:GetRepository",
                "cr:ListInstance",
                "cr:ListInstanceEndpoint"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "workshop.eci.aliyuncs.com"
                }
            }
        }
    ]
}

References