授權信息

更新時間:2025-03-06 12:14
访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍ECS为RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。ECS的RAM代码(RamCode)为 ecs、vpc,支持的授权粒度为ECS RESOURCE

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是ECS定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用前面加 * 表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
操作API访问级别资源类型条件关键字关联操作
ecs:AcceptInquiredSystemEventAcceptInquiredSystemEventupdate
*全部资源
*
ecs:AddTagsAddTagscreate
*全部资源
*
ecs:AllocateDedicatedHostsAllocateDedicatedHostscreate
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/*
ecs:AllocatePublicIpAddressAllocatePublicIpAddresscreate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ApplyAutoSnapshotPolicyApplyAutoSnapshotPolicyupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
*AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
ecs:AssignIpv6AddressesAssignIpv6Addressescreate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:AssignPrivateIpAddressesAssignPrivateIpAddressescreate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:AttachClassicLinkVpcAttachClassicLinkVpcupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
vpc:tag
ecs:AttachDiskAttachDiskupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:LoginAsNonRoot
ecs:PasswordCustomized
ecs:AttachInstanceRamRoleAttachInstanceRamRoleupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*Role
acs:ram:{#regionId}:{#accountId}:role/{#roleName}
ecs:AttachKeyPairAttachKeyPairupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
ecs:AttachNetworkInterfaceAttachNetworkInterfaceupdate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:AuthorizeSecurityGroupAuthorizeSecurityGroupcreate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:AuthorizeSecurityGroupEgressAuthorizeSecurityGroupEgresscreate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:CancelAutoSnapshotPolicyCancelAutoSnapshotPolicyupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
ecs:CancelCopyImageCancelCopyImageupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:CancelImagePipelineExecutionCancelImagePipelineExecutionupdate
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:CancelSimulatedSystemEventsCancelSimulatedSystemEventsupdate
*全部资源
*
ecs:CancelTaskCancelTaskupdate
*全部资源
*
ecs:ConvertNatPublicIpToEipConvertNatPublicIpToEipupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CopyImageCopyImageupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/*
ecs:CopySnapshotCopySnapshotcreate
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:CreateActivationCreateActivationcreate
*Activation
acs:ecs:{#regionId}:{#accountId}:activation/*
ecs:CreateAutoProvisioningGroupCreateAutoProvisioningGroupcreate
*全部资源
*
ecs:CreateAutoSnapshotPolicyCreateAutoSnapshotPolicycreate
*AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
ecs:CreateCapacityReservationCreateCapacityReservationcreate
*CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/*
ecs:CreateCommandCreateCommandcreate
*Command
acs:ecs:{#regionId}:{#accountId}:command/*
ecs:CreateDedicatedHostClusterCreateDedicatedHostClustercreate
*全部资源
*
ecs:CreateDemandCreateDemandcreate
*全部资源
*
ecs:CreateDeploymentSetCreateDeploymentSetcreate
*全部资源
*
ecs:CreateDiagnosticMetricSetCreateDiagnosticMetricSetcreate
*全部资源
*
ecs:CreateDiagnosticReportCreateDiagnosticReportcreate
*全部资源
*
ecs:CreateDiskCreateDiskcreate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/*
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:IsDiskEncrypted
ecs:IsDiskByokEncrypted
ecs:CreateElasticityAssuranceCreateElasticityAssurancecreate
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
ecs:CreateHpcClusterCreateHpcClustercreate
*HpcCluster
acs:ecs:{#regionId}:{#accountId}:hpc/*
ecs:CreateImageCreateImagecreate
*Image
acs:ecs:{#regionId}:{#accountId}:image/*
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:CreateImageComponentCreateImageComponentcreate
*ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/*
ecs:CreateImagePipelineCreateImagePipelinecreate
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/*
ecs:CreateInstanceCreateInstancecreate
*全部资源
*
vpc:VPC
vpc:IsDefaultVSwitch
vpc:IsDefaultVpc
ecs:IsDiskEncrypted
ecs:InstanceType
ecs:InstanceTypeFamily
ecs:ImageOwnerId
ecs:ImageSource
ecs:NotSpecifySecurityGroupId
ecs:LoginAsNonRoot
ecs:IsSystemDiskByokEncrypted
ecs:IsDiskByokEncrypted
ecs:PasswordInherit
ecs:PasswordCustomized
ecs:IsSystemDiskEncrypted
ecs:ImagePlatform
ecs:LoginAsNonRoot
ecs:IsSystemDiskByokEncrypted
ecs:IsDiskByokEncrypted
ecs:PasswordInherit
ecs:PasswordCustomized
ecs:IsSystemDiskEncrypted
ecs:ImagePlatform
ecs:SecurityHardeningMode
ecs:CreateKeyPairCreateKeyPaircreate
*KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/*
ecs:CreateLaunchTemplateCreateLaunchTemplatecreate
*LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/*
ecs:CreateLaunchTemplateVersionCreateLaunchTemplateVersioncreate
*LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ecs:CreateNetworkInterfaceCreateNetworkInterfacecreate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/*
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
*VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
vpc:IsDefaultVSwitch
vpc:IsDefaultVpc
vpc:VPC
vpc:tag
vpc:tag
vpc:tag
ecs:CreateNetworkInterfacePermissionCreateNetworkInterfacePermissioncreate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:CreatePrefixListCreatePrefixListcreate
*全部资源
*
ecs:CreateSecurityGroupCreateSecurityGroupcreate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/*
*VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
ecs:CreateSimulatedSystemEventsCreateSimulatedSystemEventscreate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CreateSnapshotCreateSnapshotcreate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/*
ecs:CreateSnapshotGroupCreateSnapshotGroupcreate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#DiskId}
ecs:DeleteActivationDeleteActivationdelete
*activation
acs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
ecs:DeleteAutoProvisioningGroupDeleteAutoProvisioningGroupdelete
*AutoProvisioningGroup
acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ecs:DeleteAutoSnapshotPolicyDeleteAutoSnapshotPolicydelete
*AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#SnapshotPolicyId}
ecs:DeleteCommandDeleteCommanddelete
*Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:DeleteDedicatedHostClusterDeleteDedicatedHostClusterdelete
*DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ecs:DeleteDemandDeleteDemanddelete
*全部资源
*
ecs:DeleteDeploymentSetDeleteDeploymentSetdelete
*DeploymentSet
acs:ecs:{#regionid}:{#accountId}:deploymentset/{#deploymentSetId}
ecs:DeleteDiagnosticMetricSetsDeleteDiagnosticMetricSetsdelete
*全部资源
*
ecs:DeleteDiagnosticReportsDeleteDiagnosticReportsdelete
*全部资源
*
ecs:DeleteDiskDeleteDiskdelete
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:DeleteHpcClusterDeleteHpcClusterdelete
*全部资源
*
ecs:DeleteImageDeleteImagedelete
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DeleteImageComponentDeleteImageComponentdelete
*ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
ecs:DeleteImagePipelineDeleteImagePipelinedelete
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:DeleteInstanceDeleteInstancedelete
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteInstancesDeleteInstancesdelete
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteKeyPairsDeleteKeyPairsdelete
*KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
ecs:DeleteLaunchTemplateDeleteLaunchTemplatedelete
*全部资源
*
ecs:DeleteLaunchTemplateVersionDeleteLaunchTemplateVersiondelete
*LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ecs:DeleteNetworkInterfaceDeleteNetworkInterfacedelete
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DeleteNetworkInterfacePermissionDeleteNetworkInterfacePermissiondelete
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DeletePrefixListDeletePrefixListdelete
*PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:DeleteSecurityGroupDeleteSecurityGroupdelete
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:DeleteSnapshotDeleteSnapshotdelete
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:DeleteSnapshotGroupDeleteSnapshotGroupdelete
*SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
ecs:DeregisterManagedInstanceDeregisterManagedInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeAccountAttributesDescribeAccountAttributesget
*全部资源
*
ecs:DescribeActivationsDescribeActivationsget
Activation
acs:ecs:{#regionId}:{#accountId}:activation/*
Activation
acs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
ecs:DescribeAutoProvisioningGroupHistoryDescribeAutoProvisioningGroupHistoryget
*全部资源
*
ecs:DescribeAutoProvisioningGroupInstancesDescribeAutoProvisioningGroupInstancesget
*AutoProvisioningGroup
acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ecs:DescribeAutoProvisioningGroupsDescribeAutoProvisioningGroupsget
*全部资源
*
ecs:DescribeAutoSnapshotPolicyExDescribeAutoSnapshotPolicyExget
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
ecs:DescribeBandwidthLimitationDescribeBandwidthLimitationget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeCapacityReservationInstancesDescribeCapacityReservationInstancesget
*CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/{#CapacityReservationId}
ecs:DescribeCapacityReservationsDescribeCapacityReservationsget
*CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/*
ecs:DescribeClassicLinkInstancesDescribeClassicLinkInstancesget
*全部资源
*
ecs:DescribeCloudAssistantSettingsDescribeCloudAssistantSettingslist
*ServiceSettings
acs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
ecs:DescribeCloudAssistantStatusDescribeCloudAssistantStatusget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeCommandsDescribeCommandsget
Command
acs:ecs:{#regionId}:{#accountId}:command/*
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:DescribeDedicatedHostAutoRenewDescribeDedicatedHostAutoRenewget
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeDedicatedHostClustersDescribeDedicatedHostClustersget
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/*
ecs:DescribeDedicatedHostsDescribeDedicatedHostsget
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/*
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeDemandsDescribeDemandsget
*全部资源
*
ecs:DescribeDeploymentSetsDescribeDeploymentSetsget
*DeploymentSet
acs:ecs:{#regionId}:{#accountId}:deploymentset/*
ecs:DescribeDiagnosticMetricSetsDescribeDiagnosticMetricSetsget
*全部资源
*
ecs:DescribeDiagnosticMetricsDescribeDiagnosticMetricsget
*全部资源
*
ecs:DescribeDiagnosticReportAttributesDescribeDiagnosticReportAttributesget
*全部资源
*
ecs:DescribeDiagnosticReportsDescribeDiagnosticReportsget
*全部资源
*
ecs:DescribeDiskEncryptionByDefaultStatusDescribeDiskEncryptionByDefaultStatusnone
*DiskEncryptionDefaultConfig
acs:ecs:{#regionId}:{#accountId}:diskencryptiondefaultconfig/*
ecs:DescribeDiskMonitorDataDescribeDiskMonitorDataget
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:DescribeDisksDescribeDiskslist
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/*
ecs:DescribeDisksFullStatusDescribeDisksFullStatuslist
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/*
ecs:DescribeElasticityAssuranceAutoRenewAttributeDescribeElasticityAssuranceAutoRenewAttributeget
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
ecs:DescribeElasticityAssuranceInstancesDescribeElasticityAssuranceInstancesget
*全部资源
*
ecs:DescribeElasticityAssurancesDescribeElasticityAssurancesget
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
ecs:DescribeEniMonitorDataDescribeEniMonitorDataget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeHpcClustersDescribeHpcClustersget
*HpcCluster
acs:ecs:{#regionId}:{#accountId}:hpc/*
ecs:DescribeImageComponentsDescribeImageComponentsget
*ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/*
*ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
ecs:DescribeImageFromFamilyDescribeImageFromFamilyget
*全部资源
*
ecs:DescribeImagePipelineExecutionsDescribeImagePipelineExecutionsget
*ImagePipelineExecution
acs:ecs:{#regionId}:{#accountId}:imagepipelineexecution/*
*ImagePipelineExecution
acs:ecs:{#regionId}:{#accountId}:imagepipelineexecution/{#ImagePipelineExecutionId}
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/*
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#ImagePipelineId}
ecs:DescribeImagePipelinesDescribeImagePipelinesget
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/*
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:DescribeImageSharePermissionDescribeImageSharePermissionget
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DescribeImageSupportInstanceTypesDescribeImageSupportInstanceTypesget
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DescribeImagesDescribeImagesget
Image
acs:ecs:{#regionId}:{#accountId}:image/*
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DescribeInstanceAttachmentAttributesDescribeInstanceAttachmentAttributesget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstanceAttributeDescribeInstanceAttributeget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstanceAutoRenewAttributeDescribeInstanceAutoRenewAttributeget
*全部资源
*
ecs:DescribeInstanceHistoryEventsDescribeInstanceHistoryEventsget
*全部资源
*
ecs:DescribeInstanceMaintenanceAttributesDescribeInstanceMaintenanceAttributesget
*全部资源
*
ecs:DescribeInstanceModificationPriceDescribeInstanceModificationPriceget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}
ecs:DescribeInstanceMonitorDataDescribeInstanceMonitorDataget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstanceRamRoleDescribeInstanceRamRoleget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Role
acs:ram:{#regionId}:{#accountId}:role/{#roleName}
ecs:DescribeInstanceStatusDescribeInstanceStatuslist
*全部资源
*
ecs:DescribeInstanceVncUrlDescribeInstanceVncUrlget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstancesDescribeInstanceslist
Instance
acs:ecs:{#regionId}:{#accountId}:instance/*
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ResourceOwner
ecs:DescribeInstancesFullStatusDescribeInstancesFullStatuslist
*全部资源
*
ecs:DescribeInvocationResultsDescribeInvocationResultsget
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInvocationsDescribeInvocationsget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:DescribeKeyPairsDescribeKeyPairsget
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/*
ecs:DescribeLaunchTemplateVersionsDescribeLaunchTemplateVersionsget
*全部资源
*
ecs:DescribeLaunchTemplatesDescribeLaunchTemplatesget
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/*
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ecs:DescribeLimitationDescribeLimitationget
*全部资源
*
ecs:DescribeManagedInstancesDescribeManagedInstancesget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeNetworkInterfaceAttributeDescribeNetworkInterfaceAttributeget
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribeNetworkInterfacePermissionsDescribeNetworkInterfacePermissionsget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribeNetworkInterfacesDescribeNetworkInterfacesget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribePrefixListAssociationsDescribePrefixListAssociationsget
*PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:DescribePrefixListAttributesDescribePrefixListAttributesget
*PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:DescribePrefixListsDescribePrefixListsget
*PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:DescribePriceDescribePriceget
*全部资源
*
ecs:DescribeRenewalPriceDescribeRenewalPriceget
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeReservedInstanceAutoRenewAttributeDescribeReservedInstanceAutoRenewAttributeget
*ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
ecs:DescribeReservedInstancesDescribeReservedInstancesget
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/*
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
ecs:DescribeResourceByTagsDescribeResourceByTagsget
*全部资源
*
ecs:DescribeResourcesModificationDescribeResourcesModificationget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeSecurityGroupAttributeDescribeSecurityGroupAttributeget
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:DescribeSecurityGroupReferencesDescribeSecurityGroupReferencesget
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:DescribeSecurityGroupsDescribeSecurityGroupsget
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/*
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:tag
ecs:DescribeSendFileResultsDescribeSendFileResultsget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeSnapshotGroupsDescribeSnapshotGroupsget
SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/*
SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
ecs:DescribeSnapshotLinksDescribeSnapshotLinksget
*全部资源
*
ecs:DescribeSnapshotMonitorDataDescribeSnapshotMonitorDataget
*全部资源
*
ecs:DescribeSnapshotPackageDescribeSnapshotPackageget
*全部资源
*
ecs:DescribeSnapshotsDescribeSnapshotsget
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/*
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:DescribeSnapshotsUsageDescribeSnapshotsUsageget
*全部资源
*
ecs:DescribeStorageCapacityUnitsDescribeStorageCapacityUnitsget
StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/*
StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
ecs:DescribeTagsDescribeTagsget
*全部资源
*
ecs:DescribeTaskAttributeDescribeTaskAttributeget
*全部资源
*
ecs:DescribeTasksDescribeTasksget
*全部资源
*
ecs:DescribeTerminalSessionsDescribeTerminalSessionslist
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}
ecs:DescribeUserBusinessBehaviorDescribeUserBusinessBehaviorget
*全部资源
*
ecs:DescribeUserDataDescribeUserDataget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DetachClassicLinkVpcDetachClassicLinkVpcupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
ecs:DetachDiskDetachDiskupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DetachInstanceRamRoleDetachInstanceRamRoleupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*Role
acs:ram:{#regionId}:{#accountId}:role/{#roleName}
ecs:DetachKeyPairDetachKeyPairupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
ecs:DetachNetworkInterfaceDetachNetworkInterfaceupdate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DisableActivationDisableActivationupdate
*Activation
acs:ecs:{#regionId}:{#accountId}:activation/{#ActivationId}
ecs:EndTerminalSessionEndTerminalSessionupdate
*全部资源
*
ecs:ExportImageExportImageupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ExportSnapshotExportSnapshotcreate
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:GetInstanceConsoleOutputGetInstanceConsoleOutputget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:GetInstanceScreenshotGetInstanceScreenshotget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ImportImageImportImageupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/*
ecs:ImportKeyPairImportKeyPaircreate
*KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/*
ecs:InstallCloudAssistantInstallCloudAssistantupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:InvokeCommandInvokeCommandupdate
*Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CommandRunAs
ecs:JoinResourceGroupJoinResourceGroupupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#SnapshotId}
ecs:JoinSecurityGroupJoinSecurityGroupupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:LeaveSecurityGroupLeaveSecurityGroupupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:ListPluginStatusListPluginStatusget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}
ecs:ListTagResourcesListTagResourcesget
*全部资源
*
ecs:ModifyAutoProvisioningGroupModifyAutoProvisioningGroupupdate
*autoprovisioninggroup
acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ecs:ModifyAutoSnapshotPolicyExModifyAutoSnapshotPolicyExupdate
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#autoSnapshotPolicyId}
ecs:ModifyCapacityReservationModifyCapacityReservationupdate
*CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/{#CapacityReservationId}
ecs:ModifyCloudAssistantSettingsModifyCloudAssistantSettingsupdate
*ServiceSettings
acs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
ecs:ModifyCommandModifyCommandupdate
*Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:ModifyDedicatedHostAttributeModifyDedicatedHostAttributeupdate
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ecs:ModifyDedicatedHostAutoReleaseTimeModifyDedicatedHostAutoReleaseTimeupdate
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:ModifyDedicatedHostAutoRenewAttributeModifyDedicatedHostAutoRenewAttributeupdate
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:ModifyDedicatedHostClusterAttributeModifyDedicatedHostClusterAttributeupdate
*ddhcluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ecs:ModifyDedicatedHostsChargeTypeModifyDedicatedHostsChargeTypeupdate
*全部资源
*
ecs:ModifyDeploymentSetAttributeModifyDeploymentSetAttributeupdate
*DeploymentSet
acs:ecs:{#regionId}:{#accountId}:deploymentset/{#DeploymentSetId}
ecs:ModifyDiagnosticMetricSetModifyDiagnosticMetricSetupdate
*全部资源
*
ecs:ModifyDiskAttributeModifyDiskAttributeupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:ModifyDiskChargeTypeModifyDiskChargeTypeupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyDiskDeploymentModifyDiskDeploymentupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:ModifyDiskSpecModifyDiskSpecupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:ModifyElasticityAssuranceModifyElasticityAssuranceupdate
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
ecs:ModifyElasticityAssuranceAutoRenewAttributeModifyElasticityAssuranceAutoRenewAttributeupdate
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
ecs:ModifyHpcClusterAttributeModifyHpcClusterAttributeupdate
*全部资源
*
ecs:ModifyImageAttributeModifyImageAttributeupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyImageShareGroupPermissionModifyImageShareGroupPermissionupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyImageSharePermissionModifyImageSharePermissionupdate
*Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyInstanceAttachmentAttributesModifyInstanceAttachmentAttributesupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceAttributeModifyInstanceAttributeupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#SecurityGroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:tag
ecs:ModifyInstanceAutoReleaseTimeModifyInstanceAutoReleaseTimeupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceAutoRenewAttributeModifyInstanceAutoRenewAttributeupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceChargeTypeModifyInstanceChargeTypeupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceDeploymentModifyInstanceDeploymentupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceMaintenanceAttributesModifyInstanceMaintenanceAttributesupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceMetadataOptionsModifyInstanceMetadataOptionsupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceNetworkSpecModifyInstanceNetworkSpecupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceSpecModifyInstanceSpecupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceVncPasswdModifyInstanceVncPasswdupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceVpcAttributeModifyInstanceVpcAttributeupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
*VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
vpc:tag
vpc:VPC
ecs:ModifyInvocationAttributeModifyInvocationAttributeupdate
*Invocation
acs:ecs:{#regionId}:{#accountId}:invocation/{#invocationId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyLaunchTemplateDefaultVersionModifyLaunchTemplateDefaultVersionupdate
*全部资源
*
ecs:ModifyManagedInstanceModifyManagedInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyNetworkInterfaceAttributeModifyNetworkInterfaceAttributeupdate
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:ModifyPrefixListModifyPrefixListupdate
*PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:ModifyPrepayInstanceSpecModifyPrepayInstanceSpecupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyReservedInstanceAttributeModifyReservedInstanceAttributeupdate
*ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
ecs:ModifyReservedInstanceAutoRenewAttributeModifyReservedInstanceAutoRenewAttributeupdate
*ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
ecs:ModifyReservedInstancesModifyReservedInstancesupdate
*ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
ecs:ModifySecurityGroupAttributeModifySecurityGroupAttributeupdate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:ModifySecurityGroupEgressRuleModifySecurityGroupEgressRuleupdate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:ModifySecurityGroupPolicyModifySecurityGroupPolicyupdate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:ModifySecurityGroupRuleModifySecurityGroupRuleupdate
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:ModifySnapshotAttributeModifySnapshotAttributeupdate
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:ModifySnapshotCategoryModifySnapshotCategoryupdate
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:tag
ecs:tag
ecs:ModifySnapshotGroupModifySnapshotGroupupdate
*SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#SnapshotGroupId}
ecs:ModifyStorageCapacityUnitAttributeModifyStorageCapacityUnitAttributeupdate
*StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
ecs:ModifyUserBusinessBehaviorModifyUserBusinessBehaviorupdate
*全部资源
*
ecs:PurchaseElasticityAssurancePurchaseElasticityAssuranceupdate
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
ecs:PurchaseReservedInstancesOfferingPurchaseReservedInstancesOfferingcreate
*ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/*
ecs:PurchaseStorageCapacityUnitPurchaseStorageCapacityUnitcreate
*StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/*
ecs:ReActivateInstancesReActivateInstancesupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ReInitDiskReInitDiskupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:RebootInstanceRebootInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RebootInstancesRebootInstancesupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RedeployDedicatedHostRedeployDedicatedHostupdate
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:RedeployInstanceRedeployInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ReleaseCapacityReservationReleaseCapacityReservationdelete
*CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/{#CapacityReservationId}
ecs:ReleaseDedicatedHostReleaseDedicatedHostdelete
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:ReleasePublicIpAddressReleasePublicIpAddressdelete
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RemoveTagsRemoveTagsdelete
*全部资源
*
ecs:RenewDedicatedHostsRenewDedicatedHostsupdate
*DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:RenewElasticityAssurancesRenewElasticityAssurancescreate
*ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
ecs:RenewInstanceRenewInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RenewReservedInstancesRenewReservedInstancescreate
*ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
ecs:ReplaceSystemDiskReplaceSystemDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:IsDiskEncrypted
ecs:IsSystemDiskEncrypted
ecs:PasswordInherit
ecs:PasswordCustomized
ecs:IsDiskByokEncrypted
ecs:IsSystemDiskByokEncrypted
ecs:LoginAsNonRoot
ecs:ImagePlatform
ecs:ReportInstancesStatusReportInstancesStatusget
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ResetDiskResetDiskupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:ResetDisksResetDisksupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
*Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:ResizeDiskResizeDiskupdate
*Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:RevokeSecurityGroupRevokeSecurityGroupdelete
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:RevokeSecurityGroupEgressRevokeSecurityGroupEgressdelete
*SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:RunCommandRunCommandupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CommandRunAs
ecs:RunInstancesRunInstancescreate
*全部资源
*
vpc:IsDefaultVSwitch
vpc:IsDefaultVpc
vpc:VPC
ecs:IsDiskEncrypted
ecs:InstanceTypeFamily
ecs:InstanceType
ecs:ImageOwnerId
ecs:ImageSource
ecs:NotSpecifySecurityGroupId
ecs:LoginAsNonRoot
ecs:IsSystemDiskByokEncrypted
ecs:IsDiskByokEncrypted
ecs:PasswordInherit
ecs:PasswordCustomized
ecs:IsSystemDiskEncrypted
ecs:ImagePlatform
ecs:IsDiskEncrypted
ecs:SecurityHardeningMode
ecs:SendFileSendFileupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StartImagePipelineExecutionStartImagePipelineExecutionupdate
*ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:StartInstanceStartInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StartInstancesStartInstancesupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StartTerminalSessionStartTerminalSessionupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StopInstanceStopInstanceupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StopInstancesStopInstancesupdate
*Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StopInvocationStopInvocationupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:TagResourcesTagResourcescreate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#SnapshotPolicyId}
ecs:UnassignIpv6AddressesUnassignIpv6Addressesdelete
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:UnassignPrivateIpAddressesUnassignPrivateIpAddressesdelete
*NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:UntagResourcesUntagResourcesdelete
*全部资源
*
vpc:ActivateRouterInterfaceActivateRouterInterfaceupdate
*RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:AddBandwidthPackageIpsAddBandwidthPackageIpscreate
*BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:AllocateEipAddressAllocateEipAddressupdate
*全部资源
*
vpc:AssociateEipAddressAssociateEipAddressupdate
*全部资源
*
vpc:AssociateHaVipAssociateHaVipupdate
*Instance
acs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
*HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:CancelPhysicalConnectionCancelPhysicalConnectionupdate
*PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:ConnectRouterInterfaceConnectRouterInterfaceupdate
*RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:CreateForwardEntryCreateForwardEntrycreate
*ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:CreateHaVipCreateHaVipcreate
*全部资源
*
vpc:CreateNatGatewayCreateNatGatewaycreate
*全部资源
*
vpc:CreatePhysicalConnectionCreatePhysicalConnectioncreate
*全部资源
*
vpc:CreateRouteEntryCreateRouteEntrycreate
*RouteTable
acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
vpc:CreateRouterInterfaceCreateRouterInterfacecreate
*全部资源
*
vpc:TargetAccountRDId
vpc:CreateVSwitchCreateVSwitchcreate
*全部资源
*
vpc:tag
vpc:CreateVirtualBorderRouterCreateVirtualBorderRoutercreate
*全部资源
*
vpc:CreateVpcCreateVpccreate
*全部资源
*
vpc:DeactivateRouterInterfaceDeactivateRouterInterfaceupdate
*RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:DeleteBandwidthPackageDeleteBandwidthPackagedelete
*BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:DeleteForwardEntryDeleteForwardEntrydelete
*ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:DeleteHaVipDeleteHaVipdelete
*HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:DeleteNatGatewayDeleteNatGatewaydelete
*NatGateway
acs:vpc:{#regionId}:{#accountId}:natgateway/{#natgatewayid}
vpc:DeletePhysicalConnectionDeletePhysicalConnectiondelete
*PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:DeleteRouteEntryDeleteRouteEntrydelete
*RouteTable
acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
vpc:DeleteRouterInterfaceDeleteRouterInterfacedelete
*RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:DeleteVSwitchDeleteVSwitchdelete
*VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}
vpc:DeleteVirtualBorderRouterDeleteVirtualBorderRouterdelete
*VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:DeleteVpcDeleteVpcdelete
*VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}
vpc:tag
vpc:DescribeAccessPointsDescribeAccessPointsget
*全部资源
*
vpc:DescribeBandwidthPackagesDescribeBandwidthPackagesget
*全部资源
*
vpc:DescribeEipAddressesDescribeEipAddressesget
*Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:DescribeEipMonitorDataDescribeEipMonitorDataget
*Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:DescribeForwardTableEntriesDescribeForwardTableEntriesget
*ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:DescribeHaVipsDescribeHaVipsget
*全部资源
*
vpc:DescribeNatGatewaysDescribeNatGatewaysget
*全部资源
*
vpc:DescribeNewProjectEipMonitorDataDescribeNewProjectEipMonitorDataget
*Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:DescribePhysicalConnectionsDescribePhysicalConnectionsget
*全部资源
*
vpc:DescribeRouteTablesDescribeRouteTablesget
*RouteTable
acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
vpc:VBR
vpc:VRouter
vpc:DescribeRouterInterfacesDescribeRouterInterfacesget
*全部资源
*
vpc:DescribeVRoutersDescribeVRoutersget
*全部资源
*
vpc:VPC
vpc:DescribeVSwitchesDescribeVSwitchesget
*全部资源
*
vpc:VPC
vpc:DescribeVirtualBorderRoutersDescribeVirtualBorderRoutersget
*全部资源
*
vpc:DescribeVirtualBorderRoutersForPhysicalConnectionDescribeVirtualBorderRoutersForPhysicalConnectionget
*PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:PhysicalConnection
vpc:DescribeVpcsDescribeVpcsget
*全部资源
*
vpc:tag
vpc:EnablePhysicalConnectionEnablePhysicalConnectionupdate
*PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:ModifyBandwidthPackageSpecModifyBandwidthPackageSpecupdate
*BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:ModifyEipAddressAttributeModifyEipAddressAttributeupdate
*Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:ModifyForwardEntryModifyForwardEntryupdate
*ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:ModifyHaVipAttributeModifyHaVipAttributeupdate
*HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:ModifyPhysicalConnectionAttributeModifyPhysicalConnectionAttributeupdate
*PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:ModifyRouterInterfaceAttributeModifyRouterInterfaceAttributeupdate
*RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:TargetAccountRDId
vpc:ModifyRouterInterfaceSpecModifyRouterInterfaceSpecupdate
*RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:ModifyVRouterAttributeModifyVRouterAttributeupdate
*VRouter
acs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}
vpc:ModifyVSwitchAttributeModifyVSwitchAttributeupdate
*VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}
vpc:ModifyVirtualBorderRouterAttributeModifyVirtualBorderRouterAttributeupdate
*VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:ModifyVpcAttributeModifyVpcAttributeupdate
*VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}
vpc:tag
vpc:RecoverVirtualBorderRouterRecoverVirtualBorderRouterupdate
*VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:ReleaseEipAddressReleaseEipAddressupdate
*Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:tag
vpc:RemoveBandwidthPackageIpsRemoveBandwidthPackageIpsdelete
*BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:TerminatePhysicalConnectionTerminatePhysicalConnectionupdate
*PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:TerminateVirtualBorderRouterTerminateVirtualBorderRouterupdate
*VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:UnassociateEipAddressUnassociateEipAddressupdate
*全部资源
*
vpc:UnassociateHaVipUnassociateHaVipdelete
*Instance
acs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
*HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}

资源(Resource)

下表是ECS定义的资源,这些资源可以在RAM权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源ARN是资源在阿里云上的唯一标识。具体说明如下:
  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。
  • *表示全部。例如:
    • {#resourceType}*时:表示全部资源。
    • {#regionId}*时:表示全部地域。
    • {#accountId}*时:表示全部阿里云账号。
资源类型资源ARN
资源类型资源ARN
Activation
  • acs:ecs:{#regionId}:{#accountId}:activation/*
  • acs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
Address
  • acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
  • acs:vpc:{#regionId}:{#accountId}:eip/*
Association
  • acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
AutoProvisioningGroup
  • acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
  • acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/*
AutoSnapshotPolicy
  • acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
  • acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
  • acs:ecs:{#regionId}:{#accountId}:autosnapshotpolicy/*
BandwidthPackage
  • acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
  • acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*
CapacityReservation
  • acs:ecs:{#regionId}:{#accountId}:capacityreservation/*
  • acs:ecs:{#regionId}:{#accountId}:capacityreservation/{#CapacityReservationId}
Command
  • acs:ecs:{#regionId}:{#accountId}:command/*
  • acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
DedicatedHost
  • acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
  • acs:ecs:{#regionId}:{#accountId}:ddh/*
DedicatedHostCluster
  • acs:ecs:{#regionId}:{#accountId}:ddhcluster/*
  • acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
Demand
  • acs:ecs:*:{#accountId}:*
  • acs:ecs:{#regionId}:{#accountId}:ecsdemand/*
DeploymentSet
  • acs:ecs:{#regionId}:{#accountId}:deploymentset/{#DeploymentSetId}
  • acs:ecs:{#regionId}:{#accountId}:deploymentset/*
Disk
  • acs:ecs:{#regionId}:{#accountId}:disk/*
  • acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
DiskEncryptionDefaultConfig
  • acs:ecs:{#regionId}:{#accountId}:diskencryptiondefaultconfig/*
ElasticityAssurance
  • acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
  • acs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
Fleet
  • acs:ecs:{#regionId}:{#accountId}:fleet/*
ForwardTable
  • acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
HaVip
  • acs:vpc:{#regionId}:{#accountId}:havip/*
  • acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
HpcCluster
  • acs:ecs:{#regionId}:{#accountId}:hpc/*
  • acs:ecs:{#regionId}:{#accountId}:hpc/{#hpcClusterId}
Image
  • acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
  • acs:ecs:{#regionId}:{#accountId}:image/*
ImageComponent
  • acs:ecs:{#regionId}:{#accountId}:imagecomponent/*
  • acs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
ImagePipeline
  • acs:ecs:{#regionId}:{#accountId}:imagepipeline/*
  • acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#ImagePipelineId}
ImagePipelineExecution
  • acs:ecs:{#regionId}:{#accountId}:imagepipelineexecution/*
  • acs:ecs:{#regionId}:{#accountId}:imagepipelineexecution/{#ImagePipelineExecutionId}
Instance
  • acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
  • acs:ecs:{#regionId}:{#accountId}:instance/*
  • acs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
Invocation
  • acs:ecs:{#regionId}:{#accountId}:invocation/{#invocationId}
KeyPair
  • acs:ecs:{#regionId}:{#accountId}:keypair/*
  • acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
  • acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
LaunchTemplate
  • acs:ecs:{#regionId}:{#accountId}:launchtemplate/*
  • acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
NatGateway
  • acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}
  • acs:vpc:{#regionId}:{#accountId}:natgateway/*
NetworkInterface
  • acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
  • acs:ecs:{#regionId}:{#accountId}:eni/*
PhysicalConnection
  • acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
  • acs:vpc:{#regionId}:{#accountId}:physicalconnection/*
PrefixList
  • acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ReservedInstance
  • acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
  • acs:ecs:{#regionId}:{#accountId}:reservedinstance/*
Role
  • acs:ram:{#regionId}:{#accountId}:role/{#roleName}
RouteTable
  • acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
RouterInterface
  • acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
  • acs:vpc:{#regionId}:{#accountId}:routerinterface/*
SecurityGroup
  • acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
  • acs:ecs:{#regionId}:{#accountId}:securitygroup/*
ServiceSettings
  • acs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
Snapshot
  • acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
  • acs:ecs:{#regionId}:{#accountId}:snapshot/*
  • acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#autoSnapshotPolicyId}
SnapshotGroup
  • acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
  • acs:ecs:{#regionId}:{#accountId}:snapshotgroup/*
StorageCapacityUnit
  • acs:ecs:{#regionId}:{#accountId}:scu/*
  • acs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
StorageSet
  • acs:ecs:{#regionId}:{#accountId}:storageset/*
VPC
  • acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
  • acs:vpc:{#regionId}:{#accountId}:vpc/*
VRouter
  • acs:vpc:{#regionId}:{#accountId}:vrouter/*
  • acs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}
VSwitch
  • acs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
  • acs:vpc:{#regionId}:{#accountId}:vswitch/*
VirtualBorderRouter
  • acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
  • acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VbrId}
  • acs:vpc:{#regionId}:{#AccountId}:virtualborderrouter/*
Volume
  • acs:ecs:{#regionId}:{#accountId}:volume/{#volumeId}
  • acs:ecs:{#regionId}:{#accountId}:volume/*
activation
  • acs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
autoprovisioninggroup
  • acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ddhcluster
  • acs:ecs:{#regionId}:{#accountId}:ddhcluster/*
  • acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
snapshotpolicy
  • acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}

条件(Condition)

下表是ECS定义的产品级条件关键字,这些条件关键字可以在RAM权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的ECS也同样适用通用条件关键字
其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型
条件关键字描述类型
条件关键字描述类型
ecs:AssociatePublicIpAddressWhether to support the allocation of public network IP in the process of resource creation and change, that is, whether to allow the operation of resources to make the public network bandwidth greater than 0.Boolean
ecs:CommandRunAsUser in the operating system that executes cloud assistant commandsString
ecs:ImageOwnerIdOwner UID of the image.String
ecs:ImagePlatformOperating system type of the imageString
ecs:ImageSourceImage SourceString
ecs:InstanceTypeInstance specificationsString
ecs:InstanceTypeFamilyinstance specification familyString
ecs:IsDiskByokEncryptedWhether to encrypt the data disk with the primary key.String
ecs:IsDiskEncryptedWhether it is an encrypted data diskString
ecs:IsSystemDiskByokEncryptedWhether the master key encrypts the system disk.String
ecs:IsSystemDiskEncryptedWhether it is an encryption system diskString
ecs:LoginAsNonRootWhether to log on to the instance as non-rootBoolean
ecs:NotSpecifySecurityGroupIdWhether the security group ID is not specifiedBoolean
ecs:PasswordCustomizedWhether a custom password is usedBoolean
ecs:PasswordInheritWhether the instance inherits the image password.Boolean
ecs:SecurityEnhancementStrategyWhether to open security reinforcement.String
ecs:SecurityGroupIpProtocolsTransport layer protocol with security group openString
ecs:SecurityGroupSourceCidrIpsThe source IPv4 CIDR segment of the security group that sets access permissionsString
ecs:SecurityHardeningModeWhether to enforce hardened mode (IMDSv2) when accessing instance metadataBoolean
vpc:CreateDefaultVpcWhether a default VPC can be createdBoolean
vpc:IsDefaultVSwitchWhether it is the default VSwitch and whether the default VSwitch can be usedBoolean
vpc:IsDefaultVpcWhether it is the default VPCBoolean
vpc:VPCVPC InformationString

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下:
  • 本頁導讀 (1)
  • 权限策略通用结构
  • 操作(Action)
  • 资源(Resource)
  • 条件(Condition)
  • 相关操作
文檔反饋
phone 聯絡我們

立即和Alibaba Cloud在線服務人員進行交談,獲取您想了解的產品信息以及最新折扣。

alicare alicarealicarealicare