全部產品
Search
文件中心

Elastic Compute Service:授權信息

更新時間:Dec 24, 2024
访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用RAM可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM中使用权限策略描述授权的具体内容。
本文为您介绍ECS为RAM权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。ECS的RAM代码(RamCode)为[{"popCode":"Ecs","ramCodes":["ecs","vpc"]},{"popCode":"ecs-workbench","ramCodes":["ecs-workbench"]}],支持的授权粒度为ECS RESOURCE

权限策略通用结构

权限策略支持JSON格式,其通用结构如下:
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}
各字段含义如下:
  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。
  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)
  • Resource:受操作影响的具体对象,您可以使用资源ARN来描述指定资源。具体信息,请参见资源(Resource)
  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)
    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素
    • Condition_key:条件关键字。
    • Condition_value:条件关键字对应的值。

操作(Action)

下表是ECS定义的操作,这些操作可以在RAM权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:
  • 操作:是指具体的权限点。
  • API:是指操作对应的API接口。
  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。
  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:
    • 对于必选的资源类型,用背景高亮的方式表示。
    • 对于不支持资源级授权的操作,用全部资源表示。
  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字
  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。
操作API访问级别资源类型条件关键字关联操作
ecs:DeletePrefixListDeletePrefixListdelete
PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:CreateDiskCreateDiskcreate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/*
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:IsDiskEncrypted
ecs:AuthorizeSecurityGroupAuthorizeSecurityGroupcreate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:AllocatePublicIpAddressAllocatePublicIpAddresscreate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyStorageCapacityUnitAttributeModifyStorageCapacityUnitAttributeupdate
StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
ecs:ModifySnapshotAttributeModifySnapshotAttributeupdate
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:ResetDiskResetDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:DescribeImagePipelinesDescribeImagePipelinesget
ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/*
ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:ReplaceSystemDiskReplaceSystemDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RunCommandRunCommandupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CommandRunAs
ecs:StartInstanceStartInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeAccountAttributesDescribeAccountAttributesget
全部资源
*
ecs:ModifyElasticityAssuranceModifyElasticityAssuranceupdate
全部资源
*
ecs:ModifyHpcClusterAttributeModifyHpcClusterAttributeupdate
全部资源
*
ecs:DetachNetworkInterfaceDetachNetworkInterfaceupdate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstanceModificationPriceDescribeInstanceModificationPriceget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}
ecs:ModifyReservedInstancesModifyReservedInstancesupdate
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
ecs:CreateLaunchTemplateCreateLaunchTemplatecreate
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/*
ecs:DeleteLaunchTemplateVersionDeleteLaunchTemplateVersiondelete
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ecs:DescribeReservedInstanceAutoRenewAttributeDescribeReservedInstanceAutoRenewAttributeget
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
ecs:DescribeCloudAssistantSettingsDescribeCloudAssistantSettingslist
ServiceSettings
acs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
ecs:CreateLaunchTemplateVersionCreateLaunchTemplateVersioncreate
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ecs:ApplyAutoSnapshotPolicyApplyAutoSnapshotPolicyupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
ecs:CreateAutoProvisioningGroupCreateAutoProvisioningGroupcreate
全部资源
*
ecs:AttachInstanceRamRoleAttachInstanceRamRoleupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Role
acs:ram:{#regionId}:{#accountId}:role/{#roleName}
ecs:ConvertNatPublicIpToEipConvertNatPublicIpToEipupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CopySnapshotCopySnapshotcreate
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:DescribeInstanceAutoRenewAttributeDescribeInstanceAutoRenewAttributeget
全部资源
*
ecs:DescribeSnapshotMonitorDataDescribeSnapshotMonitorDataget
全部资源
*
ecs:DisableActivationDisableActivationupdate
Activation
acs:ecs:{#regionId}:{#accountId}:activation/{#ActivationId}
ecs:DescribeNetworkInterfacePermissionsDescribeNetworkInterfacePermissionsget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:CancelAutoSnapshotPolicyCancelAutoSnapshotPolicyupdate
全部资源
*
ecs:DescribeInstanceVncUrlDescribeInstanceVncUrlget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeKeyPairsDescribeKeyPairsget
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/*
ecs:ReleaseDedicatedHostReleaseDedicatedHostdelete
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeImageComponentsDescribeImageComponentsget
ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/*
ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
ecs:CreateInstanceCreateInstancecreate
全部资源
*
vpc:VPC
vpc:IsDefaultVSwitch
vpc:IsDefaultVpc
ecs:IsDiskEncrypted
ecs:InstanceType
ecs:InstanceTypeFamily
ecs:ImageOwnerId
ecs:ImageSource
ecs:NotSpecifySecurityGroupId
ecs:CreateHpcClusterCreateHpcClustercreate
HpcCluster
acs:ecs:{#regionId}:{#accountId}:hpc/*
ecs:DetachDiskDetachDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeNetworkInterfacesDescribeNetworkInterfacesget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:ListPluginStatusListPluginStatusget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}
ecs:RedeployInstanceRedeployInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeActivationsDescribeActivationsget
Activation
acs:ecs:{#regionId}:{#accountId}:activation/*
Activation
acs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
ecs:ModifyInstanceAttributeModifyInstanceAttributeupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#SecurityGroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:tag
ecs:DeregisterManagedInstanceDeregisterManagedInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RevokeSecurityGroupRevokeSecurityGroupdelete
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:CreateImageComponentCreateImageComponentcreate
ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/*
ecs:CreateCommandCreateCommandcreate
Command
acs:ecs:{#regionId}:{#accountId}:command/*
ecs:DescribeElasticityAssurancesDescribeElasticityAssurancesget
ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
ecs:AuthorizeSecurityGroupEgressAuthorizeSecurityGroupEgresscreate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:ModifyInstanceDeploymentModifyInstanceDeploymentupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstanceHistoryEventsDescribeInstanceHistoryEventsget
全部资源
*
ecs:ModifyImageSharePermissionModifyImageSharePermissionupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DescribePriceDescribePriceget
全部资源
*
ecs:ModifyDiskChargeTypeModifyDiskChargeTypeupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteImagePipelineDeleteImagePipelinedelete
ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:ModifyImageAttributeModifyImageAttributeupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:StartImagePipelineExecutionStartImagePipelineExecutionupdate
ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:CancelImagePipelineExecutionCancelImagePipelineExecutionupdate
ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
ecs:RenewInstanceRenewInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeSecurityGroupsDescribeSecurityGroupsget
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/*
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:tag
ecs:DeleteHpcClusterDeleteHpcClusterdelete
全部资源
*
ecs:CreateImagePipelineCreateImagePipelinecreate
ImagePipeline
acs:ecs:{#regionId}:{#accountId}:imagepipeline/*
ecs:DeleteNetworkInterfacePermissionDeleteNetworkInterfacePermissiondelete
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribeLaunchTemplateVersionsDescribeLaunchTemplateVersionsget
全部资源
*
ecs:DescribeInstancesFullStatusDescribeInstancesFullStatuslist
全部资源
*
ecs:DescribePrefixListAssociationsDescribePrefixListAssociationsget
PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:ModifyPrepayInstanceSpecModifyPrepayInstanceSpecupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CreateCapacityReservationCreateCapacityReservationcreate
CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/*
ecs:CreateDemandCreateDemandcreate
全部资源
*
ecs:ModifyDedicatedHostAttributeModifyDedicatedHostAttributeupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ecs:DescribeImageSharePermissionDescribeImageSharePermissionget
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyManagedInstanceModifyManagedInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteDedicatedHostClusterDeleteDedicatedHostClusterdelete
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ecs:ModifyDiskDeploymentModifyDiskDeploymentupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:ModifySecurityGroupRuleModifySecurityGroupRuleupdate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:ModifyInvocationAttributeModifyInvocationAttributeupdate
Invocation
acs:ecs:{#regionId}:{#accountId}:invocation/{#invocationId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInvocationsDescribeInvocationsget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:DescribeAutoProvisioningGroupInstancesDescribeAutoProvisioningGroupInstancesget
AutoProvisioningGroup
acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ecs:DescribeSnapshotLinksDescribeSnapshotLinksget
全部资源
*
ecs:ModifyAutoSnapshotPolicyModifyAutoSnapshotPolicyupdate
全部资源
*
ecs:DescribeSnapshotPackageDescribeSnapshotPackageget
全部资源
*
ecs:AddTagsAddTagscreate
全部资源
*
ecs:ModifyDiskAttributeModifyDiskAttributeupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:DescribeDemandsDescribeDemandsget
全部资源
*
ecs:CreateKeyPairCreateKeyPaircreate
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/*
ecs:DeleteAutoSnapshotPolicyDeleteAutoSnapshotPolicydelete
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#SnapshotPolicyId}
ecs:DeleteImageDeleteImagedelete
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyReservedInstanceAutoRenewAttributeModifyReservedInstanceAutoRenewAttributeupdate
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
ecs:DeleteDeploymentSetDeleteDeploymentSetdelete
DeploymentSet
acs:ecs:{#regionid}:{#accountId}:deploymentset/{#deploymentSetId}
ecs:CreateDiagnosticReportCreateDiagnosticReportcreate
全部资源
*
ecs:DescribeInstanceStatusDescribeInstanceStatusget
全部资源
*
ecs:DeleteDiagnosticReportsDeleteDiagnosticReportsdelete
全部资源
*
ecs:DetachClassicLinkVpcDetachClassicLinkVpcupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
ecs:DescribeDiagnosticReportsDescribeDiagnosticReportsget
全部资源
*
ecs:RunInstancesRunInstancescreate
全部资源
*
vpc:IsDefaultVSwitch
vpc:IsDefaultVpc
vpc:VPC
ecs:IsDiskEncrypted
ecs:InstanceTypeFamily
ecs:InstanceType
ecs:ImageOwnerId
ecs:ImageSource
ecs:NotSpecifySecurityGroupId
ecs:ModifyDeploymentSetAttributeModifyDeploymentSetAttributeupdate
DeploymentSet
acs:ecs:{#regionId}:{#accountId}:deploymentset/{#DeploymentSetId}
ecs:CreateElasticityAssuranceCreateElasticityAssurancecreate
ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
ecs:ModifyInstanceAutoRenewAttributeModifyInstanceAutoRenewAttributeupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyDedicatedHostsChargeTypeModifyDedicatedHostsChargeTypeupdate
全部资源
*
ecs:DescribeDedicatedHostClustersDescribeDedicatedHostClustersget
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
DedicatedHostCluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/*
ecs:GetInstanceScreenshotGetInstanceScreenshotget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:AssignIpv6AddressesAssignIpv6Addressescreate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribeSnapshotGroupsDescribeSnapshotGroupsget
SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/*
SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
ecs:DescribeLaunchTemplatesDescribeLaunchTemplatesget
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/*
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ecs:RemoveTagsRemoveTagsdelete
全部资源
*
ecs:RenewElasticityAssurancesRenewElasticityAssurancescreate
ElasticityAssurance
acs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
ecs:GetInstanceConsoleOutputGetInstanceConsoleOutputget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeTasksDescribeTasksget
全部资源
*
ecs:ExportImageExportImageupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DeleteInstanceDeleteInstancedelete
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:SendFileSendFileupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeSendFileResultsDescribeSendFileResultsget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:StopInstancesStopInstancesupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:PurchaseElasticityAssurancePurchaseElasticityAssuranceupdate
全部资源
*
ecs:StopInvocationStopInvocationupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifySecurityGroupAttributeModifySecurityGroupAttributeupdate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:DeleteCommandDeleteCommanddelete
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:AttachDiskAttachDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ExportSnapshotExportSnapshotcreate
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:DescribeCommandsDescribeCommandsget
Command
acs:ecs:{#regionId}:{#accountId}:command/*
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:RebootInstancesRebootInstancesupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyUserBusinessBehaviorModifyUserBusinessBehaviorupdate
全部资源
*
ecs:DescribeCloudAssistantStatusDescribeCloudAssistantStatusget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeSnapshotsDescribeSnapshotsget
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/*
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:DeleteSnapshotDeleteSnapshotdelete
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:ModifyInstanceChargeTypeModifyInstanceChargeTypeupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifySecurityGroupPolicyModifySecurityGroupPolicyupdate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:DescribeSecurityGroupReferencesDescribeSecurityGroupReferencesget
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:DescribeDiskMonitorDataDescribeDiskMonitorDataget
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:DescribeNetworkInterfaceAttributeDescribeNetworkInterfaceAttributeget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:ModifyInstanceMaintenanceAttributesModifyInstanceMaintenanceAttributesupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DetachInstanceRamRoleDetachInstanceRamRoleupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Role
acs:ram:{#regionId}:{#accountId}:role/{#roleName}
ecs:DescribeTagsDescribeTagsget
全部资源
*
ecs:DescribeInstanceAttributeDescribeInstanceAttributeget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeSecurityGroupAttributeDescribeSecurityGroupAttributeget
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:CreateDeploymentSetCreateDeploymentSetcreate
全部资源
*
ecs:DeleteDiskDeleteDiskdelete
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:ModifyDedicatedHostAutoReleaseTimeModifyDedicatedHostAutoReleaseTimeupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:ModifyInstanceNetworkSpecModifyInstanceNetworkSpecupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RebootInstanceRebootInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ImportKeyPairImportKeyPaircreate
全部资源
*
ecs:AssignPrivateIpAddressesAssignPrivateIpAddressescreate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribeSnapshotsUsageDescribeSnapshotsUsageget
全部资源
*
ecs:DeleteNetworkInterfaceDeleteNetworkInterfacedelete
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribeDiskEncryptionByDefaultStatusDescribeDiskEncryptionByDefaultStatusnone
全部资源
*
ecs:ModifyLaunchTemplateDefaultVersionModifyLaunchTemplateDefaultVersionupdate
全部资源
*
ecs:ModifyCloudAssistantSettingsModifyCloudAssistantSettingsupdate
ServiceSettings
acs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
ecs:ModifyInstanceSpecModifyInstanceSpecupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeTerminalSessionsDescribeTerminalSessionslist
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}
ecs:DescribeAutoSnapshotPolicyEXDescribeAutoSnapshotPolicyExget
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
ecs:DetachKeyPairDetachKeyPairupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
ecs:ModifySecurityGroupEgressRuleModifySecurityGroupEgressRuleupdate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:SecurityGroupIpProtocols
ecs:SecurityGroupSourceCidrIps
ecs:ModifySnapshotGroupModifySnapshotGroupupdate
SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#SnapshotGroupId}
ecs:AcceptInquiredSystemEventAcceptInquiredSystemEventupdate
全部资源
*
ecs:ModifyNetworkInterfaceAttributeModifyNetworkInterfaceAttributeupdate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:JoinSecurityGroupJoinSecurityGroupupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:CreateAutoSnapshotPolicyCreateAutoSnapshotPolicycreate
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
ecs:DescribeDisksDescribeDiskslist
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/*
ecs:CreateNetworkInterfacePermissionCreateNetworkInterfacePermissioncreate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:DescribePrefixListAttributesDescribePrefixListAttributesget
PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:ModifyDedicatedHostClusterAttributeModifyDedicatedHostClusterAttributeupdate
ddhcluster
acs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ecs:ModifyInstanceMetadataOptionsModifyInstanceMetadataOptionsupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeInstanceAttachmentAttributesDescribeInstanceAttachmentAttributesget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CopyImageCopyImageupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/*
ecs:DeleteSecurityGroupDeleteSecurityGroupdelete
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:AttachNetworkInterfaceAttachNetworkInterfaceupdate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:RenewDedicatedHostsRenewDedicatedHostsupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:ModifyDedicatedHostAutoRenewAttributeModifyDedicatedHostAutoRenewAttributeupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeInstanceMonitorDataDescribeInstanceMonitorDataget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CreateImageCreateImagecreate
Image
acs:ecs:{#regionId}:{#accountId}:image/*
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:CreateSnapshotGroupCreateSnapshotGroupcreate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ReportInstancesStatusReportInstancesStatusget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ReleaseCapacityReservationReleaseCapacityReservationdelete
全部资源
*
ecs:DescribeReservedInstancesDescribeReservedInstancesget
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/*
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
ecs:DescribeBandwidthLimitationDescribeBandwidthLimitationget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:UntagResourcesUntagResourcesdelete
全部资源
*
ecs:DescribeInstanceMaintenanceAttributesDescribeInstanceMaintenanceAttributesget
全部资源
*
ecs:CreateActivationCreateActivationcreate
Activation
acs:ecs:{#regionId}:{#accountId}:activation/*
ecs:AttachClassicLinkVpcAttachClassicLinkVpcupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
vpc:tag
ecs:CreateSecurityGroupCreateSecurityGroupcreate
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/*
VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
ecs:DescribeDisksFullStatusDescribeDisksFullStatuslist
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/*
ecs:DescribeImageSupportInstanceTypesDescribeImageSupportInstanceTypesget
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyImageShareGroupPermissionModifyImageShareGroupPermissionupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:CreatePrefixListCreatePrefixListcreate
全部资源
*
ecs:DescribeUserDataDescribeUserDataget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribePrefixListsDescribePrefixListsget
PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:InvokeCommandInvokeCommandupdate
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:CommandRunAs
ecs:ListTagResourcesListTagResourcesget
全部资源
*
ecs:DescribeDedicatedHostsDescribeDedicatedHostsget
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/*
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeDedicatedHostAutoRenewDescribeDedicatedHostAutoRenewget
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeRenewalPriceDescribeRenewalPriceget
全部资源
*
ecs:RevokeSecurityGroupEgressRevokeSecurityGroupEgressdelete
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:tag
ecs:tag
ecs:tag
ecs:TagResourcesTagResourcescreate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
AutoSnapshotPolicy
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#SnapshotPolicyId}
ecs:DescribeCapacityReservationsDescribeCapacityReservationsget
CapacityReservation
acs:ecs:{#regionId}:{#accountId}:capacityreservation/*
ecs:DeleteLaunchTemplateDeleteLaunchTemplatedelete
全部资源
*
ecs:DeleteActivationDeleteActivationdelete
activation
acs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
ecs:CancelTaskCancelTaskupdate
全部资源
*
ecs:DescribeAutoProvisioningGroupsDescribeAutoProvisioningGroupsget
全部资源
*
ecs:CreateSnapshotCreateSnapshotcreate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/*
ecs:DescribeStorageCapacityUnitsDescribeStorageCapacityUnitsget
StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/*
StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
ecs:ModifyInstanceVpcAttributeModifyInstanceVpcAttributeupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
vpc:tag
vpc:VPC
ecs:DeleteKeyPairsDeleteKeyPairsdelete
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
ecs:ModifyPrefixListModifyPrefixListupdate
PrefixList
acs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
ecs:CreateSimulatedSystemEventsCreateSimulatedSystemEventscreate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeHpcClustersDescribeHpcClustersget
HpcCluster
acs:ecs:{#regionId}:{#accountId}:hpc/*
ecs:AttachKeyPairAttachKeyPairupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
ecs:DescribeUserBusinessBehaviorDescribeUserBusinessBehaviorget
全部资源
*
ecs:ModifyInstanceAttachmentAttributesModifyInstanceAttachmentAttributesupdate
全部资源
*
ecs:DescribeDiagnosticMetricSetsDescribeDiagnosticMetricSetsget
全部资源
*
ecs:JoinResourceGroupJoinResourceGroupupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
KeyPair
acs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
LaunchTemplate
acs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#SnapshotId}
ecs:DescribeManagedInstancesDescribeManagedInstancesget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeDiagnosticReportAttributesDescribeDiagnosticReportAttributesget
全部资源
*
ecs:ModifyAutoSnapshotPolicyExModifyAutoSnapshotPolicyExupdate
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#autoSnapshotPolicyId}
ecs:DescribeEniMonitorDataDescribeEniMonitorDataget
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeResourcesModificationDescribeResourcesModificationget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeAutoProvisioningGroupHistoryDescribeAutoProvisioningGroupHistoryget
全部资源
*
ecs:StartInstancesStartInstancesupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeImageFromFamilyDescribeImageFromFamilyget
全部资源
*
ecs:ModifyCapacityReservationModifyCapacityReservationupdate
全部资源
*
ecs:DescribeDeploymentSetsDescribeDeploymentSetsget
DeploymentSet
acs:ecs:{#regionId}:{#accountId}:deploymentset/*
ecs:DescribeInstanceRamRoleDescribeInstanceRamRoleget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
Role
acs:ram:{#regionId}:{#accountId}:role/{#roleName}
ecs:DeleteDemandDeleteDemanddelete
全部资源
*
ecs:PurchaseStorageCapacityUnitPurchaseStorageCapacityUnitcreate
StorageCapacityUnit
acs:ecs:{#regionId}:{#accountId}:scu/*
ecs:LeaveSecurityGroupLeaveSecurityGroupupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
ecs:DescribeTaskAttributeDescribeTaskAttributeget
全部资源
*
ecs:ReleasePublicIpAddressReleasePublicIpAddressdelete
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:UnassignPrivateIpAddressesUnassignPrivateIpAddressesdelete
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:CreateNetworkInterfaceCreateNetworkInterfacecreate
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/*
SecurityGroup
acs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
vpc:IsDefaultVSwitch
vpc:IsDefaultVpc
vpc:VPC
vpc:tag
vpc:tag
vpc:tag
ecs:DescribeInstancesDescribeInstancesget
Instance
acs:ecs:{#regionId}:{#accountId}:instance/*
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ResourceOwner
ecs:DescribeImagesDescribeImagesget
Image
acs:ecs:{#regionId}:{#accountId}:image/*
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:DeleteSnapshotGroupDeleteSnapshotGroupdelete
SnapshotGroup
acs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
ecs:AllocateDedicatedHostsAllocateDedicatedHostscreate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/*
ecs:DescribeImagePipelineExecutionsDescribeImagePipelineExecutionsget
全部资源
*
ecs:ModifyCommandModifyCommandupdate
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
ecs:StopInstanceStopInstanceupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ResizeDiskResizeDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:ResetDisksResetDisksupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Snapshot
acs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
ecs:ImportImageImportImageupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/*
ecs:InstallCloudAssistantInstallCloudAssistantupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyInstanceVncPasswdModifyInstanceVncPasswdupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteInstancesDeleteInstancesdelete
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DescribeClassicLinkInstancesDescribeClassicLinkInstancesget
全部资源
*
ecs:CreateDedicatedHostClusterCreateDedicatedHostClustercreate
全部资源
*
ecs:CancelCopyImageCancelCopyImageupdate
Image
acs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ecs:ModifyDiskSpecModifyDiskSpecupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:DescribeResourceByTagsDescribeResourceByTagsget
全部资源
*
ecs:ModifyInstanceAutoReleaseTimeModifyInstanceAutoReleaseTimeupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyAutoProvisioningGroupModifyAutoProvisioningGroupupdate
autoprovisioninggroup
acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ecs:RedeployDedicatedHostRedeployDedicatedHostupdate
DedicatedHost
acs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ecs:DescribeInvocationResultsDescribeInvocationResultsget
Command
acs:ecs:{#regionId}:{#accountId}:command/{#commandId}
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:ModifyDiagnosticMetricSetModifyDiagnosticMetricSetupdate
全部资源
*
ecs:DescribeElasticityAssuranceInstancesDescribeElasticityAssuranceInstancesget
全部资源
*
ecs:ReActivateInstancesReActivateInstancesupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteAutoProvisioningGroupDeleteAutoProvisioningGroupdelete
AutoProvisioningGroup
acs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
ecs:UnassignIpv6AddressesUnassignIpv6Addressesdelete
NetworkInterface
acs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ecs:CancelSimulatedSystemEventsCancelSimulatedSystemEventsupdate
全部资源
*
ecs:DescribeDiagnosticMetricsDescribeDiagnosticMetricsget
全部资源
*
ecs:DescribeCapacityReservationInstancesDescribeCapacityReservationInstancesget
全部资源
*
ecs:RenewReservedInstancesRenewReservedInstancescreate
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#ReservedInstanceId}
ecs:ReInitDiskReInitDiskupdate
Disk
acs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
ecs:DeleteImageComponentDeleteImageComponentdelete
ImageComponent
acs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
ecs:CreateDiagnosticMetricSetCreateDiagnosticMetricSetcreate
全部资源
*
ecs:ModifyReservedInstanceAttributeModifyReservedInstanceAttributeupdate
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
ecs:DescribeLimitationDescribeLimitationget
全部资源
*
ecs:StartTerminalSessionStartTerminalSessionupdate
Instance
acs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
ecs:DeleteDiagnosticMetricSetsDeleteDiagnosticMetricSetsdelete
全部资源
*
ecs:PurchaseReservedInstancesOfferingPurchaseReservedInstancesOfferingcreate
ReservedInstance
acs:ecs:{#regionId}:{#accountId}:reservedinstance/*
vpc:DescribeEipAddressesDescribeEipAddressesget
Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:AssociateEipAddressAssociateEipAddressupdate
全部资源
*
vpc:CreateForwardEntryCreateForwardEntrycreate
ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:CreateRouterInterfaceCreateRouterInterfacecreate
全部资源
*
vpc:TargetAccountRDId
vpc:DescribeRouteTablesDescribeRouteTablesget
RouteTable
acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
vpc:VBR
vpc:VRouter
vpc:ModifyForwardEntryModifyForwardEntryupdate
ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:ReleaseEipAddressReleaseEipAddressupdate
Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:tag
vpc:AssociateHaVipAssociateHaVipupdate
Instance
acs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:CreatePhysicalConnectionCreatePhysicalConnectioncreate
全部资源
*
vpc:DescribeNatGatewaysDescribeNatGatewaysget
全部资源
*
vpc:CreateVirtualBorderRouterCreateVirtualBorderRoutercreate
全部资源
*
vpc:ModifyEipAddressAttributeModifyEipAddressAttributeupdate
Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:CancelPhysicalConnectionCancelPhysicalConnectionupdate
PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:RecoverVirtualBorderRouterRecoverVirtualBorderRouterupdate
VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:DeleteVSwitchDeleteVSwitchdelete
VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}
vpc:TerminatePhysicalConnectionTerminatePhysicalConnectionupdate
PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:DescribeEipMonitorDataDescribeEipMonitorDataget
Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:UnassociateHaVipUnassociateHaVipdelete
Instance
acs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:ConnectRouterInterfaceConnectRouterInterfaceupdate
RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:ModifyHaVipAttributeModifyHaVipAttributeupdate
HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:UnassociateEipAddressUnassociateEipAddressupdate
全部资源
*
vpc:CreateNatGatewayCreateNatGatewaycreate
全部资源
*
vpc:DeleteRouteEntryDeleteRouteEntrydelete
RouteTable
acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
vpc:DescribeVpcsDescribeVpcsget
全部资源
*
vpc:tag
vpc:CreateVSwitchCreateVSwitchcreate
全部资源
*
vpc:tag
vpc:ModifyRouterInterfaceSpecModifyRouterInterfaceSpecupdate
RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:DeleteRouterInterfaceDeleteRouterInterfacedelete
RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:DescribeAccessPointsDescribeAccessPointsget
全部资源
*
vpc:RemoveBandwidthPackageIpsRemoveBandwidthPackageIpsdelete
BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:EnablePhysicalConnectionEnablePhysicalConnectionupdate
PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:DescribeHaVipsDescribeHaVipsget
全部资源
*
vpc:DescribeRouterInterfacesDescribeRouterInterfacesget
全部资源
*
vpc:ModifyVirtualBorderRouterAttributeModifyVirtualBorderRouterAttributeupdate
VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:DeactivateRouterInterfaceDeactivateRouterInterfaceupdate
RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:ModifyVpcAttributeModifyVpcAttributeupdate
VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}
vpc:tag
vpc:TerminateVirtualBorderRouterTerminateVirtualBorderRouterupdate
VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:CreateVpcCreateVpccreate
全部资源
*
vpc:DescribeNewProjectEipMonitorDataDescribeNewProjectEipMonitorDataget
Address
acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
vpc:DeleteNatGatewayDeleteNatGatewaydelete
NatGateway
acs:vpc:{#regionId}:{#accountId}:natgateway/{#natgatewayid}
vpc:ModifyRouterInterfaceAttributeModifyRouterInterfaceAttributeupdate
RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:TargetAccountRDId
vpc:ModifyVSwitchAttributeModifyVSwitchAttributeupdate
VSwitch
acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}
vpc:DescribeVirtualBorderRoutersForPhysicalConnectionDescribeVirtualBorderRoutersForPhysicalConnectionget
PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:PhysicalConnection
vpc:ModifyPhysicalConnectionAttributeModifyPhysicalConnectionAttributeupdate
PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
vpc:DescribePhysicalConnectionsDescribePhysicalConnectionsget
全部资源
*
vpc:DescribeVRoutersDescribeVRoutersget
全部资源
*
vpc:VPC
vpc:CreateRouteEntryCreateRouteEntrycreate
RouteTable
acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
vpc:ModifyVRouterAttributeModifyVRouterAttributeupdate
VRouter
acs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}
vpc:DeleteVirtualBorderRouterDeleteVirtualBorderRouterdelete
VirtualBorderRouter
acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
vpc:ModifyBandwidthPackageSpecModifyBandwidthPackageSpecupdate
BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:DescribeVirtualBorderRoutersDescribeVirtualBorderRoutersget
全部资源
*
vpc:ActivateRouterInterfaceActivateRouterInterfaceupdate
RouterInterface
acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
vpc:DescribeVSwitchesDescribeVSwitchesget
全部资源
*
vpc:VPC
vpc:AllocateEipAddressAllocateEipAddressupdate
全部资源
*
vpc:DeleteBandwidthPackageDeleteBandwidthPackagedelete
BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:CreateHaVipCreateHaVipcreate
全部资源
*
vpc:DescribeForwardTableEntriesDescribeForwardTableEntriesget
ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:DeleteVpcDeleteVpcdelete
VPC
acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}
vpc:tag
vpc:DeleteHaVipDeleteHaVipdelete
HaVip
acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
vpc:AddBandwidthPackageIpsAddBandwidthPackageIpscreate
BandwidthPackage
acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
vpc:DescribeBandwidthPackagesDescribeBandwidthPackagesget
全部资源
*
vpc:DeleteForwardEntryDeleteForwardEntrydelete
ForwardTable
acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
vpc:DeletePhysicalConnectionDeletePhysicalConnectiondelete
PhysicalConnection
acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}

资源(Resource)

下表是ECS定义的资源,这些资源可以在RAM权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源ARN是资源在阿里云上的唯一标识。具体说明如下:
  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。
  • *表示全部。例如:
    • {#resourceType}*时:表示全部资源。
    • {#regionId}*时:表示全部地域。
    • {#accountId}*时:表示全部阿里云账号。
资源类型资源ARN
PrefixListacs:ecs:{#regionId}:{#accountId}:prefixlist/{#PrefixListId}
Diskacs:ecs:{#regionId}:{#accountId}:disk/*
Diskacs:ecs:{#regionId}:{#accountId}:disk/{#diskId}
Snapshotacs:ecs:{#regionId}:{#accountId}:snapshot/{#snapshotId}
SecurityGroupacs:ecs:{#regionId}:{#accountId}:securitygroup/{#securitygroupId}
Instanceacs:ecs:{#regionId}:{#accountId}:instance/{#instanceId}
StorageCapacityUnitacs:ecs:{#regionId}:{#accountId}:scu/{#scuId}
ImagePipelineacs:ecs:{#regionId}:{#accountId}:imagepipeline/*
ImagePipelineacs:ecs:{#regionId}:{#accountId}:imagepipeline/{#imagepipelineId}
Imageacs:ecs:{#regionId}:{#accountId}:image/{#imageId}
ElasticityAssuranceacs:ecs:{#regionId}:{#accountId}:elasticityassurance/*
HpcClusteracs:ecs:{#regionId}:{#accountId}:hpc/*
NetworkInterfaceacs:ecs:{#regionId}:{#accountId}:eni/{#eniId}
ReservedInstanceacs:ecs:{#regionId}:{#accountId}:reservedinstance/{#reservedinstanceId}
LaunchTemplateacs:ecs:{#regionId}:{#accountId}:launchtemplate/*
LaunchTemplateacs:ecs:{#regionId}:{#accountId}:launchtemplate/{#launchtemplateId}
ServiceSettingsacs:ecs:{#regionId}:{#accountId}:servicesettings/{#servicesettingId}
AutoSnapshotPolicyacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
Fleetacs:ecs:{#regionId}:{#accountId}:fleet/*
Roleacs:ram:{#regionId}:{#accountId}:role/{#roleName}
Instanceacs:ecs:{#regionId}:{#accountId}:instance/*
Snapshotacs:ecs:{#regionId}:{#accountId}:snapshot/*
Activationacs:ecs:{#regionId}:{#accountId}:activation/{#ActivationId}
AutoSnapshotPolicyacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/*
KeyPairacs:ecs:{#regionId}:{#accountId}:keypair/{#keypairName}
KeyPairacs:ecs:{#regionId}:{#accountId}:keypair/*
DedicatedHostacs:ecs:{#regionId}:{#accountId}:ddh/{#ddhId}
ImageComponentacs:ecs:{#regionId}:{#accountId}:imagecomponent/*
ImageComponentacs:ecs:{#regionId}:{#accountId}:imagecomponent/{#imagecomponentId}
KeyPairacs:ecs:{#regionId}:{#accountId}:keypair/{#keypairId}
VSwitchacs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}
VSwitchacs:vpc:{#regionId}:{#accountId}:vswitch/*
AutoProvisioningGroupacs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/*
Activationacs:ecs:{#regionId}:{#accountId}:activation/*
AutoSnapshotPolicyacs:ecs:{#regionId}:{#accountId}:autosnapshotpolicy/*
Volumeacs:ecs:{#regionId}:{#accountId}:volume/{#volumeId}
Commandacs:ecs:{#regionId}:{#accountId}:command/*
AutoProvisioningGroupacs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
SecurityGroupacs:ecs:{#regionId}:{#accountId}:securitygroup/*
CapacityReservationacs:ecs:{#regionId}:{#accountId}:capacityreservation/*
DedicatedHostClusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
Invocationacs:ecs:{#regionId}:{#accountId}:invocation/{#invocationId}
Commandacs:ecs:{#regionId}:{#accountId}:command/{#commandId}
snapshotpolicyacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#snapshotpolicyId}
Demandacs:ecs:{#regionId}:{#accountId}:ecsdemand/*
DeploymentSetacs:ecs:{#regionid}:{#accountId}:deploymentset/{#deploymentSetId}
VPCacs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}
DedicatedHostClusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/*
SnapshotGroupacs:ecs:{#regionId}:{#accountId}:snapshotgroup/*
SnapshotGroupacs:ecs:{#regionId}:{#accountId}:snapshotgroup/{#snapshotgroupId}
ElasticityAssuranceacs:ecs:{#regionId}:{#accountId}:elasticityassurance/{#ElasticityAssuranceId}
Volumeacs:ecs:{#regionId}:{#accountId}:volume/*
DedicatedHostacs:ecs:{#regionId}:{#accountId}:ddh/*
NetworkInterfaceacs:ecs:{#regionId}:{#accountId}:eni/*
Imageacs:ecs:{#regionId}:{#accountId}:image/*
ddhclusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/{#ddhclusterId}
ReservedInstanceacs:ecs:{#regionId}:{#accountId}:reservedinstance/*
activationacs:ecs:{#regionId}:{#accountId}:activation/{#activationId}
StorageCapacityUnitacs:ecs:{#regionId}:{#accountId}:scu/*
Snapshotacs:ecs:{#regionId}:{#accountId}:snapshotpolicy/{#autoSnapshotPolicyId}
DeploymentSetacs:ecs:{#regionId}:{#accountId}:deploymentset/*
ddhclusteracs:ecs:{#regionId}:{#accountId}:ddhcluster/*
autoprovisioninggroupacs:ecs:{#regionId}:{#accountId}:autoprovisioninggroup/{#autoprovisioninggroupId}
Demandacs:ecs:*:{#accountId}:*
Addressacs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}
NatGatewayacs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}
Instanceacs:vpc:{#regionId}:{#accountId}:instance/{#InstanceId}
Associationacs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
ForwardTableacs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}
VirtualBorderRouteracs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VbrId}
RouterInterfaceacs:vpc:{#regionId}:{#accountId}:routerinterface/*
RouteTableacs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}
HaVipacs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}
PhysicalConnectionacs:vpc:{#regionId}:{#accountId}:physicalconnection/*
NatGatewayacs:vpc:{#regionId}:{#accountId}:natgateway/*
PhysicalConnectionacs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}
VirtualBorderRouteracs:vpc:{#regionId}:{#AccountId}:virtualborderrouter/*
VirtualBorderRouteracs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}
RouterInterfaceacs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}
VPCacs:vpc:{#regionId}:{#accountId}:vpc/*
BandwidthPackageacs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}
HaVipacs:vpc:{#regionId}:{#accountId}:havip/*
VRouteracs:vpc:{#regionId}:{#accountId}:vrouter/*
VRouteracs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}
Addressacs:vpc:{#regionId}:{#accountId}:eip/*
BandwidthPackageacs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*

条件(Condition)

下表是ECS定义的产品级条件关键字,这些条件关键字可以在RAM权限策略语句的Condition元素中使用,用来描述授予权限的条件。以下仅列举产品级的条件关键字,阿里云定义的ECS也同样适用通用条件关键字
其中,数据类型决定了您可以使用哪些条件运算符将请求中的值与权限策略语句中的值进行比较。您必须使用与数据类型匹配的条件运算符,否则无法匹配策略语句,授权行为无效。数据类型与条件运算符的对应关系,请参见条件操作类型
条件关键字描述类型
vpc:VPCVPC InformationString
vpc:IsDefaultVSwitchWhether it is the default VSwitch and whether the default VSwitch can be usedBoolean
vpc:IsDefaultVpcWhether it is the default VPCBoolean
ecs:IsDiskEncryptedWhether it is an encrypted data diskString
ecs:InstanceTypeInstance specificationsString
ecs:InstanceTypeFamilyinstance specification familyString
ecs:ImagePlatformOperating system type of the imageString
ecs:ImageSourceImage SourceString
ecs:CommandRunAsUser in the operating system that executes cloud assistant commandsString
ecs:IsSystemDiskEncryptedWhether it is an encryption system diskString
ecs:ImageOwnerIdOwner UID of the image.String
ecs:AssociatePublicIpAddressWhether to support the allocation of public network IP in the process of resource creation and change, that is, whether to allow the operation of resources to make the public network bandwidth greater than 0.Boolean
ecs:PasswordCustomizedWhether a custom password is usedBoolean
ecs:PasswordInheritWhether the instance inherits the image password.Boolean
ecs:SecurityEnhancementStrategyWhether to open security reinforcement.String
ecs:SecurityHardeningModeWhether to enforce hardened mode (IMDSv2) when accessing instance metadataBoolean
vpc:CreateDefaultVpcWhether a default VPC can be createdBoolean
ecs:SecurityGroupIpProtocolsTransport layer protocol with security group openString
ecs:SecurityGroupSourceCidrIpsThe source IPv4 CIDR segment of the security group that sets access permissionsString
ecs:NotSpecifySecurityGroupIdWhether the security group ID is not specifiedBoolean

相关操作

您可以创建自定义权限策略,并将权限策略授予RAM用户、RAM用户组或RAM角色。具体操作如下: