All Products
Search
Document Center

ApsaraVideo Live:Service-linked role for video encryption

Last Updated:Feb 06, 2026

This topic describes the AliyunServiceRoleForLiveKes service-linked role for video encryption in ApsaraVideo Live, including its purpose and how to delete it.

Overview

AliyunServiceRoleForLiveKes is a service-linked role that ApsaraVideo Live uses to obtain access permissions on Key Management Service (KMS) and create encrypted key pairs.

Scenarios

ApsaraVideo Live automatically creates the AliyunServiceRoleForLiveKes role when you use video encryption.

Permissions

The following code shows the access permissions granted to the AliyunServiceRoleForLiveKes role:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:GenerateDataKey"
      ],
      "Resource": "*",
      "Effect": "Allow"
    }
  ]
}

Delete AliyunServiceRoleForLiveKes

If you no longer use video encryption, delete the AliyunServiceRoleForLiveKes role as follows:

  1. Log on to the RAM console. In the left navigation pane, click Roles.

  2. On the Roles page, enter AliyunServiceRoleForLiveKes in the search box and press Enter.

  3. In the Actions column, click Delete.

  4. In the Delete Role dialog box, click OK.

Note

After it is deleted, the system automatically recreates it when you use the video encryption feature again.

References

Service-linked roles are RAM roles whose trusted entities are set to Alibaba Cloud services. These roles resolve cross-service authorization issues.