全部產品
Search
文件中心

OpenSearch:OpenSearch服務關聯角色

更新時間:Jul 13, 2024

本文為您介紹OpenSearch服務關聯角色(AliyunServiceRoleForOpenSearch)的應用情境以及如何刪除服務關聯角色。

背景資訊

OpenSearch服務關聯角色(AliyunServiceRoleForOpenSearch)是在某些情況下,為了完成OpenSearch自身的某個功能,需要擷取其他雲端服務的存取權限,而提供的RAM角色。更多關於服務關聯角色的資訊請參見服務關聯角色

應用情境

OpenSearch的資料來源功能需要訪問雲端服務Rds/PolarDB/DRDS的資源,通過服務關聯角色功能擷取存取權限。

AliyunServiceRoleForOpenSearch介紹

角色名稱:AliyunServiceRoleForOpenSearch角色權限原則:AliyunServiceRolePolicyForOpenSearch授權策略:

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "rds:DescribeDBInstanceAttribute",
                "rds:DescribeDBInstances",
                "rds:DescribeDatabases",
                "rds:DescribeDBInstanceIPArrayList",
                "rds:DescribeAccounts",
                "rds:DescribeAbnormalDBInstances",
                "rds:ModifySecurityIps",
                "rds:DescribeResourceUsage"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "polardb:DescribeDBClusterAttribute",
                "polardb:DescribeDBClusterEndpoints",
                "polardb:ModifyDBClusterAccessWhitelist",
                "polardb:DescribeDBClusterAccessWhitelist",
                "polardb:DescribeDBClusterParameters"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "drds:DescribeDrdsInstance",
                "drds:ModifyDrdsIpWhiteList",
                "drds:DescribeDrdsDBIpWhiteList",
                "drds:DescribeRdsList",
                "drds:DescribeDrdsDB"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": [
                "dts:ConfigureSubscriptionInstance",
                "dts:CreateConsumerGroup",
                "dts:StartSubscriptionInstance",
                "dts:DescribeSubscriptionInstanceStatus",
                "dts:DescribeConsumerGroup",
                "dts:DeleteConsumerGroup"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "opensearch.aliyuncs.com"
                }
            }
        }
    ]
}

刪除服務關聯角色

如果您需要刪除AliyunServiceRoleForOpenSearch(服務關聯角色),需要先釋放掉依賴這個服務關聯角色的OpenSearch應用,刪除服務關聯角色具體操作請參見刪除服務關聯角色