本文為您介紹 Oceanbase 遷移評估服務關聯角色(AliyunServiceRoleForOceanbaseMigrationAssessment)的權限原則和應用情境等資訊,以及如何刪除服務關聯角色。
背景資訊
在某些情境下,為了完成 OceanBase 遷移評估服務自身的某個功能,需要擷取您雲帳號下的其他雲端服務的存取權限。AliyunServiceRoleForOceanbaseMigrationAssessment 是阿里雲為實現此類情境而提供的 RAM 角色。詳情請參見 服務關聯角色。
角色名稱:AliyunServiceRoleForOceanbaseMigrationAssessment
角色權限原則:AliyunServicePolicyForOceanbaseMigrationAssessment
許可權說明:
{ "Version": "1", "Statement": [ { "Effect": "Allow", "Action": [ "ecs:CreateSecurityGroup", "ecs:DescribeSecurityGroups", "ecs:DeleteSecurityGroup", "ecs:AuthorizeSecurityGroup", "ecs:DescribeSecurityGroupAttribute" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "privatelink:ListVpcEndpoints", "privatelink:ListVpcEndpointZones", "privatelink:CreateVpcEndpoint", "privatelink:RemoveZoneFromVpcEndpoint", "privatelink:GetVpcEndpointAttribute", "privatelink:DeleteVpcEndpoint" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "vpc:ListFullNatEntries", "vpc:CreateFullNatEntry", "vpc:DeleteFullNatEntry" ], "Resource": "*" }, { "Action": "ram:DeleteServiceLinkedRole", "Resource": "*", "Effect": "Allow", "Condition": { "StringEquals": { "ram:ServiceName": "migration-assessment.oceanbase.aliyuncs.com" } } }, { "Action": "ram:CreateServiceLinkedRole", "Resource": "*", "Effect": "Allow", "Condition": { "StringEquals": { "ram:ServiceName": "privatelink.aliyuncs.com" } } } ] }
應用情境
OceanBase 遷移評估服務需要在您的帳號下建立安全性群組、終端節點,以打通您的 VPC 到雲端服務 VPC 的網路通道。當您完成評估後,OceanBase 遷移評估服務需要刪除您雲帳號下的由遷移評估服務建立的安全性群組和終端節點。