edit-icon download-icon

ActionTrail operations and resources supported by RAM

Last Updated: Mar 22, 2018

You can create a RAM account by using Alibaba Cloud RAM, and authorize the RAM account to operate ActionTrail. We strongly recommend this approach for security consideration.

List of ActionTrail operations that can be authorized to a RAM account

  • CreateTrail
  • UpdateTrail
  • DeleteTrail
  • DescribeTrails
  • GetTrailStatus
  • StartLogging
  • StopLogging
  • LookupEvents

Format resources

Alibaba Cloud resources are formatted as follows when granting permissions to RAM accounts.

Resource Description
* All cloud resources.
acs:actiontrail:${region}:${AccountId}:* Resources in a specified region.

Authorization policy example

  • Allow requests of performing ActionTrail read-only operations on all resources
  1. {
  2. "Version": "1",
  3. "Statement": [{
  4. "Effect": "Allow",
  5. "Action": [
  6. "actiontrail:LookupEvents",
  7. "actiontrail:Describe*",
  8. "actiontrail:Get*"
  9. ],
  10. "Resource": "*"
  11. }]
  12. }
  • Allow requests from a specified IP range of performing ActionTrail read-only operations on all resources
  1. {
  2. "Version": "1",
  3. "Statement": [{
  4. "Effect": "Allow",
  5. "Action": [
  6. "actiontrail:LookupEvents",
  7. "actiontrail:Describe*",
  8. "actiontrail:Get*"
  9. ],
  10. "Resource": "*",
  11. "Condition":{
  12. "IpAddress": {
  13. "acs:SourceIp": "42.120.66.0/24"
  14. }
  15. }
  16. }]
  17. }
Thank you! We've received your feedback.