全部產品
Search
文件中心

Elastic Container Instance:AliyunServiceRoleForECIVnode

更新時間:Jul 06, 2024

本文為您介紹虛擬節點服務關聯角色AliyunServiceRoleForECIVnode以及如何刪除該服務關聯角色。

背景資訊

虛擬節點服務關聯角色AliyunServiceRoleForECIVnode是ECI為了實現虛擬節點功能,需要擷取其他雲端服務的存取權限而提供的RAM角色。更多關於服務關聯角色的資訊,請參見服務關聯角色

AliyunServiceRoleForECIVnode應用情境

在建立虛擬節點(VNode)的過程中,系統需要訪問Elastic Container Instance、Elastic Compute Service、Virtual Private Cloud的資源時,可以通過自動建立的虛擬節點服務關聯角色AliyunServiceRoleForECIVnode擷取存取權限。

AliyunServiceRoleForECIVnode許可權說明

虛擬節點服務關聯角色AliyunServiceRoleForECIVnode對應的角色權限原則為AliyunServiceRolePolicyForECIVnode,包含的雲端服務存取權限如下:

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "eci:CreateContainerGroup",
                "eci:CreateContainerGroupFromTemplate",
                "eci:UpdateContainerGroup",
                "eci:UpdateContainerGroupByTemplate",
                "eci:RestartContainerGroup",
                "eci:DeleteContainerGroup",
                "eci:DescribeContainerGroups",
                "eci:ExportContainerGroupTemplate",
                "eci:ExecContainerCommand",
                "eci:CreateImageCache",
                "eci:DeleteImageCache",
                "eci:UpdateImageCache",
                "eci:DescribeImageCaches",
                "eci:DescribeContainerGroupMetric",
                "eci:DescribeMultiContainerGroupMetric",
                "eci:DescribeContainerLog",
                "eci:DescribeContainerGroupPrice",
                "eci:DescribeRegions"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "vpc:DescribeVSwitches",
                "vpc:DescribeVpcs",
                "vpc:DescribeEipAddresses"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "ecs:CreateNetworkInterfacePermission",
                "ecs:DeleteNetworkInterfacePermission",
                "ecs:CreateNetworkInterface",
                "ecs:DescribeNetworkInterfaces",
                "ecs:DescribeSecurityGroups"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "vnode.eci.aliyuncs.com"
                }
            }
        }
    ]
}

刪除AliyunServiceRoleForECIVnode

如果您需要刪除虛擬節點服務關聯角色AliyunServiceRoleForECIVnode,請先通過openAPI刪除依賴該服務關聯角色的虛擬節點資源。刪除虛擬節點後,您可以刪除AliyunServiceRoleForECIVnode。具體操作,請參見刪除RAM角色