全部产品
Search
文档中心

应用身份服务:IDaaS EIAM 服务关联角色

更新时间:Mar 03, 2026

本文为您介绍 IDaaS EIAM 服务关联角色(AliyunServiceRoleForEiam)的应用场景以及如何删除服务关联角色。

背景信息

IDaaS EIAM 服务关联角色(AliyunServiceRoleForEiam)是在某些情况下,为了完成 IDaaS EIAM 自身的某个功能,需要获取其他云服务的访问权限,而提供的RAM角色。更多关于服务关联角色的信息请参见服务关联角色

应用场景

  • IDaaS EIAM 的专属端点需要访问您的 ECS、VPC 云资源,允许 IDaaS 管理自身创建的辅助弹性网卡。基于该权限,IDaaS 可以通过私网连接到 VPC 内的 AD、LDAP 或其它应用,无需开放公网端口。IDaaS 也可通过专属端点 IP 访问公网,从而满足企业微信的可信 IP 要求。

  • IDaaS EIAM 的凭据管理需要访问您的 KMS 云资源。基于该权限,IDaaS 可将凭据安全地托管至凭据管家,实现凭据安全存储和管理。

AliyunServiceRoleForEiam 介绍

角色名称:AliyunServiceRoleForEiam

角色权限策略:AliyunServiceRolePolicyForEiam

权限说明:

{
  "Version": "1",
  "Statement": [
    {
      "Action": [
        "ecs:CreateNetworkInterfacePermission",
        "ecs:DescribeNetworkInterfacePermissions",
        "ecs:DeleteNetworkInterfacePermission",
        "ecs:CreateNetworkInterface",
        "ecs:DeleteNetworkInterface",
        "ecs:DescribeNetworkInterfaces",
        "ecs:ModifyNetworkInterfaceAttribute",
        "ecs:DescribeNetworkInterfaceAttribute",
        "ecs:CreateSecurityGroup",
        "ecs:RevokeSecurityGroup",
        "ecs:DeleteSecurityGroup",
        "ecs:DescribeSecurityGroups",
        "ecs:DescribeSecurityGroupAttribute",
        "ecs:DescribeSecurityGroupReferences",
        "ecs:ModifySecurityGroupAttribute",
        "ecs:ModifySecurityGroupRule",
        "ecs:DetachNetworkInterface",
        "ecs:AttachNetworkInterface",
        "ecs:ModifySecurityGroupPolicy",
        "ecs:AuthorizeSecurityGroup",
        "ecs:DescribeInstances",
        "ecs:DescribeImages",
        "ecs:DescribeZones",
        "ecs:DescribeRegions",
        "ecs:DescribeTags"
      ],
      "Resource": "",
      "Effect": "Allow"
    },
    {
      "Action": [
        "vpc:DescribeVpcs",
        "vpc:DescribeVSwitches",
        "vpc:DescribeNatGateways",
        "vpc:DescribeSnatTableEntries"
      ],
      "Resource": "",
      "Effect": "Allow"
    },
    {
      "Effect": "Allow",
      "Action": [
        "kms:CreateSecret",
        "kms:DeleteSecret",
        "kms:DescribeSecret",
        "kms:PutSecretValue",
        "kms:UpdateSecret",
        "kms:UpdateSecretVersionStage",
        "kms:ListSecretVersionIds",
        "kms:GetSecretValue"
      ],
      "Resource": [
        "acs:kms:::secret/idaas-eiam!"
      ]
    },
    {
      "Effect": "Allow",
      "Action": [
        "kms:ListManagedQuotas",
        "kms:GenerateDataKey",
        "kms:Decrypt",
        "kms:TagResource",
        "kms:UntagResource"
      ],
      "Resource": [
        ""
      ]
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "eiam.aliyuncs.com"
        }
      }
    }
  ]
}

删除服务关联角色

如果您需要删除 AliyunServiceRoleForEiam(服务关联角色),需要先释放所有 IDaaS EIAM 实例。