All Products
Search
Document Center

Edge Security Acceleration:System policies for ESA

Last Updated:Apr 07, 2025

This topic describes the system policies supported by Edge Security Acceleration (ESA) for you to attach to Resource Access Management (RAM) identities based on your business requirements.

What is a system policy

A policy defines a set of permissions that are described based on the policy structure and syntax. You can use policies to describe the authorized resource sets, authorized operation sets, and authorization conditions. Alibaba Cloud RAM provides system policies and custom policies. All system policies are created and updated by Alibaba Cloud.

You can use system policies, but you cannot modify them. You can manage and update custom policies based on your business requirements. You can create, update, and delete custom policies. During service iteration, ESA adds new permissions to system policies to support new features and capabilities. The update of a system policy affects all RAM identities to which the policy is attached, including RAM users, RAM user groups, and RAM roles. For more information about RAM policies, see Policy overview.

Note

System policies are designed for new users to quickly get started with Alibaba Cloud services on the management console, though they also enable the use of more advanced methods like API operations or CLI commands. If you are familiar with the advanced methods, we recommend that you use custom policies to implement finer-grained control on who is permitted to call what API operations, thereby improving security.

System policies can be classified into service system policies, service role policies, and service-linked role policies. Some cloud services provide only one or two of the three types of policies. For more information, see the policy types that are described in the following section.

Service system policies

AliyunESAFullAccess

You can attach the AliyunESAFullAccess policy to RAM identities. This policy defines the permissions to manage ESA.

AliyunESAFullAccess

AliyunESAReadOnlyAccess

You can attach the AliyunESAReadOnlyAccess to RAM identities. This policy grants the read-only permissions on ESA.

AliyunESAReadOnlyAccess

Service role policies

AliyunESAAccessingPrivateOSSRolePolicy

The AliyunESAAccessingPrivateOSSRolePolicy policy is the dedicated authorization policy of the AliyunESAAccessingPrivateOSSRole service role. ESA assumes this role to access your resources in a private Object Storage Service (OSS) bucket. Do not attach this policy to a RAM identity other than the AliyunESAAccessingPrivateOSSRole service role. If a service provides precise authorization capabilities, refer to the documentation provided by the service.

AliyunESAAccessingPrivateOSSRolePolicy

AliyunESARealtimeLogPushOSSRolePolicy

The AliyunESARealtimeLogPushOSSRolePolicy policy is the dedicated authorization policy of the AliyunESARealtimeLogPushOSSRole service role. esaservices assumes this role to access your resources in other cloud services. Do not attach this policy to a RAM identity other than the AliyunESARealtimeLogPushOSSRole service role. If a service provides precise authorization capabilities, refer to the documentation provided by the service.

AliyunESARealtimeLogPushOSSRolePolicy

Service-linked role policies

AliyunServiceRolePolicyForESAEdgeImage

ESA assumes the AliyunServiceRoleForESAEdgeImage service-linked role to access your resources in other cloud services. The AliyunServiceRolePolicyForESAEdgeImage policy is the dedicated authorization policy of the AliyunServiceRoleForESAEdgeImage service-linked role. This policy is defined and used by ESA. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the AliyunServiceRoleForESAEdgeImage service-linked role.

AliyunServiceRolePolicyForESAEdgeImage

AliyunServiceRolePolicyForESARealtimeLogPushSLS

ESA assumes the AliyunServiceRoleForESARealtimeLogPushSLS service-linked role to access your resources in other cloud services. The AliyunServiceRolePolicyForESARealtimeLogPushSLS policy is the dedicated authorization policy of the AliyunServiceRoleForESARealtimeLogPushSLS service-linked role. This policy is defined and used by ESA. You cannot modify or delete the policy. Do not attach this policy to a RAM identity other than the AliyunServiceRoleForESARealtimeLogPushSLS service-linked role.

AliyunServiceRolePolicyForESARealtimeLogPushSLS

References

By default, RAM identities do not have any permissions. RAM identities can access cloud resources within an Alibaba Cloud account only after an account administrator grants the required permissions to the RAM identities. To ensure resource security, we recommend that you grant only the required permissions to the RAM identities based on the principle of least privilege. For more information, see the following topics: