All Products
Search
Document Center

Virtual Private Cloud (VPC)

Last Updated: Oct 08, 2021

Resource Access Management (RAM) users or RAM roles must be granted permissions before they can access cloud resources. RAM uses policies to define permissions. A cloud service defines elements that can be used in a policy statement, such as Action, Resource, and Condition. This topic describes the permissions on Virtual Private Cloud (VPC).

The code (RamCode) in RAM that is used to indicate Virtual Private Cloud is vpc. You can grant permissions on Virtual Private Cloud at the resource level.

Action

The following table describes the values that you can use in the Action element of a policy statement. The values are defined by Virtual Private Cloud. The following list describes the columns in the table:
  • Action: the value that you can use in the Action element to specify the operation on a resource.

  • API: the API operation that you can call to perform the action. In most cases, only one API operation of a cloud service is required to perform an action. In some cases, multiple API operations must be called to perform an action, or an API operation can be called to perform multiple actions.

  • Access level: the access level of each action. The levels are read, write, and list.

  • Resource type: the type of the resource on which you can authorize a RAM user or a RAM role to perform the operation. Take note of the following items:

    • The required resource types are displayed in bold characters.

    • If the permissions cannot be granted at the resource level, All resources is used in the Resource type column of the action.

  • Condition key: the condition keys that are defined by a cloud service. The Condition key column does not list the common condition keys that are defined by Alibaba Cloud. For more information about the common condition keys, see Policy elements.

  • Dependent action: other actions that a RAM user or a RAM role must have permissions to perform the action. To successfully call the action, a RAM user or a RAM role must have the permissions to perform the dependent action.

Actions

APIs

Access level

Resource types

Condition keys

Dependent actions

vpc:ActivateRouterInterface

ActivateRouterInterface

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:ActiveFlowLog

ActiveFlowLog

Write


FlowLog


acs:vpc:{#regionId}:{#accountId}:flowlog/{#FlowLogId}


N/A

N/A

vpc:AddBandwidthPackageIps

N/A

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:AddBgpNetwork

AddBgpNetwork

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:AddCommonBandwidthPackageIp

AddCommonBandwidthPackageIp

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:AddCommonBandwidthPackageIps

AddCommonBandwidthPackageIps

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:AddGlobalAccelerationInstanceIp

AddGlobalAccelerationInstanceIp

Write


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


Eip


acs:vpc:{#regionId}:{#accountId}:eip/{#EipId}


N/A

N/A

vpc:AddIPv6TranslatorAclListEntry

AddIPv6TranslatorAclListEntry

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:AddSourcesToTrafficMirrorSession

AddSourcesToTrafficMirrorSession

Write


TrafficMirrorSession


acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/{#TrafficMirrorSessionId}


N/A

N/A

vpc:AdminQueryVpcInfo

N/A

Read


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:AllocateIpv6InternetBandwidth

AllocateIpv6InternetBandwidth

Write


Ipv6Bandwidth


acs:vpc:{#regionId}:{#accountId}:ipv6bandwidth/*


N/A

N/A

vpc:AllocateVpcIpv6Cidr

N/A

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:ApplyPhysicalConnectionLOA

ApplyPhysicalConnectionLOA

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:AssociateGlobalAccelerationInstance

AssociateGlobalAccelerationInstance

Write


ECS:Instance


acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


N/A

N/A

vpc:AssociateHaVip

AssociateHaVip

Write


ECS:Instance


acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}


HaVip


acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}


N/A

N/A

vpc:AssociateNetworkAcl

AssociateNetworkAcl

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:AssociatePhysicalConnectionToVirtualBorderRouter

AssociatePhysicalConnectionToVirtualBorderRouter

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:AssociateRouteTable

AssociateRouteTable

Write


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#vswitchId}


N/A

N/A

vpc:AssociateRouteTablesWithVpcGatewayEndpoint

AssociateRouteTablesWithVpcGatewayEndpoint

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/{#GatewayEndpointId}


N/A

N/A

vpc:AssociateVpcCidrBlock

AssociateVpcCidrBlock

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:AttachDhcpOptionsSetToVpc

AttachDhcpOptionsSetToVpc

Write


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:CancelCommonBandwidthPackageIpBandwidth

CancelCommonBandwidthPackageIpBandwidth

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:CancelExpressCloudConnection

CancelExpressCloudConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CancelExpressCloudConnection

DeleteExpressCloudConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CancelPhysicalConnection

CancelPhysicalConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:CompletePhysicalConnectionLOA

CompletePhysicalConnectionLOA

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:ConfirmPhysicalConnection

ConfirmPhysicalConnection

Write


PhysicalConnection


acs:vpc:{#regionid}:{#accountid}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:ConnectRouterInterface

ConnectRouterInterface

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:ConvertBandwidthPackage

ConvertBandwidthPackage

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/*


N/A

N/A

vpc:CopyNetworkAclEntries

CopyNetworkAclEntries

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


N/A

N/A

vpc:CreateBandwidthPackage

N/A

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*


N/A

N/A

vpc:CreateBgpGroup

CreateBgpGroup

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:CreateBgpPeer

CreateBgpPeer

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:CreateCommonBandwidthPackage

CreateCommonBandwidthPackage

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/*


N/A

N/A

vpc:CreateCustomerGateway

CreateCustomerGateway

Write


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/*


N/A

N/A

vpc:CreateDefaultVSwitch

N/A

Write


VSwitch


acs:vpc:{#regionid}:{#accountId}:vswitch/*


N/A

N/A

vpc:CreateDefaultVpc

N/A

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/*


N/A

N/A

vpc:CreateDhcpOptionsSet

CreateDhcpOptionsSet

Write


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/*


N/A

N/A

vpc:CreateExpressCloudConnection

CreateExpressCloudConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CreateFlowLog

CreateFlowLog

Write


VSwitch


acs:vpc:{#regionid}:{#accountId}:vswitch/{#VSwitchId}


FlowLog


acs:vpc:{#regionId}:{#accountId}:flowlog/*


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:CreateForwardEntry

CreateForwardEntry

Write


ForwardTable


acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}


N/A

N/A

vpc:CreateGlobalAccelerationInstance

CreateGlobalAccelerationInstance

Write


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/*


N/A

N/A

vpc:CreateHaVip

CreateHaVip

Write


HaVip


acs:vpc:{#regionId}:{#accountId}:havip/*


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:CreateIPv6Translator

CreateIPv6Translator

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/*


N/A

N/A

vpc:CreateIPv6TranslatorAclList

CreateIPv6TranslatorAclList

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/*


N/A

N/A

vpc:CreateIPv6TranslatorEntry

CreateIPv6TranslatorEntry

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:CreateIpv6EgressOnlyRule

CreateIpv6EgressOnlyRule

Write


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/*


N/A

N/A

vpc:CreateIpv6Gateway

CreateIpv6Gateway

Write


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/*


N/A

N/A

vpc:CreateNatGateway

CreateNatGateway

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/*


N/A

N/A

vpc:CreateNetworkAcl

CreateNetworkAcl

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/*


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:CreatePhysicalConnection

CreatePhysicalConnection

Write


physicalconnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CreatePhysicalConnectionNew

N/A

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CreatePhysicalConnectionOccupancyOrder

CreatePhysicalConnectionOccupancyOrder

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CreatePhysicalConnectionSetupOrder

CreatePhysicalConnectionSetupOrder

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:CreateRouteEntry

CreateRouteEntry

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


N/A

N/A

vpc:CreateRouteTable

CreateRouteTable

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/*


N/A

N/A

vpc:CreateRouterInterface

CreateRouterInterface

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/*


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


VRouter


acs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}


N/A

N/A

vpc:CreateSnatEntry

CreateSnatEntry

Write


SnatTable


acs:vpc:{#regionId}:{#accountId}:snattable/*


N/A

N/A

vpc:CreateSslVpnClientCert

CreateSslVpnClientCert

Write


SslVpnClientCert


acs:vpc:{#regionId}:{#accountId}:sslvpnclientcert/*


SslVpnServer


acs:vpc:{#regionId}:{#accountId}:sslvpnserver/{#SslVpnServerId}


N/A

N/A

vpc:CreateSslVpnServer

CreateSslVpnServer

Write


SslVpnServer


acs:vpc:{#regionId}:{#accountId}:sslvpnserver/*


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:CreateTrafficMirrorFilter

CreateTrafficMirrorFilter

Write


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/*


N/A

N/A

vpc:CreateTrafficMirrorFilterRules

CreateTrafficMirrorFilterRules

Write


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:CreateTrafficMirrorSession

CreateTrafficMirrorSession

Write


TrafficMirrorSession


acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/*


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:CreateVSwitch

CreateVSwitch

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/*



vpc:tag


N/A

vpc:CreateVbrHa

CreateVbrHa

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:CreateVirtualBorderRouter

CreateVirtualBorderRouter

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:CreateVpc

CreateVpc

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:CreateVpcGatewayEndpoint

CreateVpcGatewayEndpoint

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#vpcId}


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/*


N/A

N/A

vpc:CreateVpnConnection

CreateVpnConnection

Write


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/{#CustomerGatewayId}


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/*


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:CreateVpnGateway

CreateVpnGateway

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/*


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:CreateVpnPbrRouteEntry

CreateVpnPbrRouteEntry

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:CreateVpnRouteEntry

CreateVpnRouteEntry

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DeactivateRouterInterface

DeactivateRouterInterface

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:DeactiveFlowLog

DeactiveFlowLog

Write


FlowLog


acs:vpc:{#regionId}:{#accountId}:flowlog/{#FlowLogId}


N/A

N/A

vpc:DeleteBandwidthPackage

N/A

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:DeleteBgpGroup

DeleteBgpGroup

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:DeleteBgpNetwork

DeleteBgpNetwork

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:DeleteBgpPeer

DeleteBgpPeer

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:DeleteCommonBandwidthPackage

DeleteCommonBandwidthPackage

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:DeleteCustomerGateway

DeleteCustomerGateway

Write


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/{#CustomerGatewayId}


N/A

N/A

vpc:DeleteDhcpOptionsSet

DeleteDhcpOptionsSet

Write


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


N/A

N/A

vpc:DeleteFlowLog

DeleteFlowLog

Write


FlowLog


acs:vpc:{#regionId}:{#accountId}:flowlog/{#FlowLogId}


N/A

N/A

vpc:DeleteForwardEntry

DeleteForwardEntry

Write


ForwardTable


acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}


N/A

N/A

vpc:DeleteGlobalAccelerationInstance

DeleteGlobalAccelerationInstance

Write


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


N/A

N/A

vpc:DeleteHaVip

DeleteHaVip

Write


HaVip


acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}


N/A

N/A

vpc:DeleteIPv6Translator

DeleteIPv6Translator

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:DeleteIPv6TranslatorAclList

DeleteIPv6TranslatorAclList

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:DeleteIPv6TranslatorEntry

DeleteIPv6TranslatorEntry

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/*


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:DeleteIpv6EgressOnlyRule

DeleteIpv6EgressOnlyRule

Write


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:DeleteIpv6Gateway

DeleteIpv6Gateway

Write


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:DeleteIpv6InternetBandwidth

DeleteIpv6InternetBandwidth

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6bandwidth/*


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6bandwidth/{#Ipv6TranslatorId}


N/A

N/A

vpc:DeleteNatGateway

DeleteNatGateway

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/*


N/A

N/A

vpc:DeleteNetworkAcl

DeleteNetworkAcl

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


N/A

N/A

vpc:DeletePhysicalConnection

DeletePhysicalConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:DeleteRouteEntry

DeleteRouteEntry

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


N/A

N/A

vpc:DeleteRouteTable

DeleteRouteTable

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


N/A

N/A

vpc:DeleteRouterInterface

DeleteExpressConnect

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:DeleteRouterInterface

DeleteRouterInterface

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:DeleteSnatEntry

DeleteSnatEntry

Write


SnatTable


acs:vpc:{#regionId}:{#accountId}:snattable/{#SnatTableId}


N/A

N/A

vpc:DeleteSslVpnClientCert

DeleteSslVpnClientCert

Write


SslVpnClientCert


acs:vpc:{#regionId}:{#accountId}:sslvpnclientcert/{#SslVpnClientCertId}


N/A

N/A

vpc:DeleteSslVpnServer

DeleteSslVpnServer

Write


SslVpnServer


acs:vpc:{#regionId}:{#accountId}:sslvpnserver/{#SslVpnServerId}


N/A

N/A

vpc:DeleteTrafficMirrorFilter

DeleteTrafficMirrorFilter

Write


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:DeleteTrafficMirrorFilterRules

DeleteTrafficMirrorFilterRules

Write


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:DeleteTrafficMirrorSession

DeleteTrafficMirrorSession

Write


TrafficMirrorSession


acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/{#TrafficMirrorSessionId}


N/A

N/A

vpc:DeleteVSwitch

DeleteVSwitch

Write


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:DeleteVbrHa

DeleteVbrHa

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:DeleteVirtualBorderRouter

DeleteVirtualBorderRouter

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:DeleteVpc

DeleteVpc

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}



vpc:tag


N/A

vpc:DeleteVpcGatewayEndpoint

DeleteVpcGatewayEndpoint

Write


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/{#GatewayEndpointId}


N/A

N/A

vpc:DeleteVpnConnection

DeleteVpnConnection

Write


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/{#VpnConnectionId}


N/A

N/A

vpc:DeleteVpnGateway

DeleteVpnGateway

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DeleteVpnPbrRouteEntry

DeleteVpnPbrRouteEntry

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DeleteVpnRouteEntry

DeleteVpnRouteEntry

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DeletionProtection

DeletionProtection

Write


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


N/A

N/A

vpc:Describe95Traffic

N/A

Read


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:DescribeAdvancedResources

N/A

Read


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:DescribeBandwidthPackageMonitorData

N/A

Read


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:DescribeBandwidthPackagePublicIpMonitorData

N/A

Read


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*


N/A

N/A

vpc:DescribeBandwidthPackages

N/A

Read


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/*


N/A

N/A

vpc:DescribeBgpGroups

DescribeBgpGroups

Read


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:DescribeBgpNetworks

DescribeBgpNetworks

Read


virtualborderrouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:DescribeBgpPeers

DescribeBgpPeers

Read


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:DescribeCommonBandwidthPackages

DescribeCommonBandwidthPackages

Read


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/*


N/A

N/A

vpc:DescribeCustomerGateway

DescribeCustomerGateway

Read


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/{#CustomerGatewayId}


N/A

N/A

vpc:DescribeCustomerGateways

DescribeCustomerGateways

Read


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/*


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/{#CustomerGatewayId}


N/A

N/A

vpc:DescribeEipAddressesByBwp

N/A

List


Address


acs:vpc:{#regionid}:{#accountid}:eip/*


N/A

N/A

vpc:DescribeExpressCloudConnections

DescribeExpressCloudConnections

List


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:DescribeFlowLogs

DescribeFlowLogs

List


FlowLog


acs:vpc:{#regionId}:{#accountId}:flowlog/*


N/A

N/A

vpc:DescribeForwardTableEntries

DescribeForwardTableEntries

Read


ForwardTable


acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}


N/A

N/A

vpc:DescribeGlobalAccelerationInstances

DescribeGlobalAccelerationInstances

List


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/*


N/A

N/A

vpc:DescribeGrantRulesToCen

DescribeGrantRulesToCen

Read


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:DescribeHaVips

DescribeHaVips

List


HaVip


acs:vpc:{#regionId}:{#accountId}:havip/*


N/A

N/A

vpc:DescribeIPv6TranslatorAclListAttributes

DescribeIPv6TranslatorAclListAttributes

Read


IPv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#IPv6TranslatorId}


N/A

N/A

vpc:DescribeIPv6TranslatorAclLists

DescribeIPv6TranslatorAclLists

Read


IPv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/*


IPv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#IPv6TranslatorId}


N/A

N/A

vpc:DescribeIPv6TranslatorEntries

DescribeIPv6TranslatorEntries

Read


IPv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/*


IPv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#IPv6TranslatorId}


N/A

N/A

vpc:DescribeIPv6Translators

DescribeIPv6Translators

Read


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/*


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:DescribeIpv6Addresses

DescribeIpv6Addresses

List


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:DescribeIpv6EgressOnlyRules

DescribeIpv6EgressOnlyRules

Read


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:DescribeIpv6GatewayAttribute

DescribeIpv6GatewayAttribute

Read


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:DescribeIpv6Gateways

DescribeIpv6Gateways

Read


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/*


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:DescribeNatGateways

DescribeNatGateways

Read


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/*


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:DescribeNetworkAclAttributes

DescribeNetworkAclAttributes

Read


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


N/A

N/A

vpc:DescribeNetworkAcls

DescribeNetworkAcls

List


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/*


N/A

N/A

vpc:DescribeNetworkQuotas

N/A

Read


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:DescribeNewProjectEipMonitorData

DescribeNewProjectEipMonitorData

Read


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


N/A

N/A

vpc:DescribePhysicalConnectionLOA

DescribePhysicalConnectionLOA

List


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:DescribePhysicalConnectionOrder

N/A

Read


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:DescribePhysicalConnections

DescribePhysicalConnections

List


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:DescribeRouteEntryList

DescribeRouteEntryList

List


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


N/A

N/A

vpc:DescribeRouteTableList

DescribeRouteTableList

List


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/*



vpc:VRouter


vpc:VBR


N/A

vpc:DescribeRouteTables

DescribeRouteTables

Read


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/*


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}



vpc:VBR


vpc:VRouter


N/A

vpc:DescribeRouterInterfaceAttribute

DescribeRouterInterfaceAttribute

Read


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/*


N/A

N/A

vpc:DescribeRouterInterfaces

DescribeRouterInterfaces

List


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/*


N/A

N/A

vpc:DescribeRouterInterfacesForGlobal

N/A

List


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/*


N/A

N/A

vpc:DescribeServerRelatedGlobalAccelerationInstances

DescribeServerRelatedGlobalAccelerationInstances

Read


ECS:Instance


acs:ecs:{#regionId}:{#accountId}:instance/{#Instanceid}


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/*


N/A

N/A

vpc:DescribeSnatTableEntries

DescribeSnatTableEntries

Read


SnatTable


acs:vpc:{#regionId}:{#accountId}:snattable/{#SnatTableId}


N/A

N/A

vpc:DescribeSslVpnClientCert

DescribeSslVpnClientCert

Read


SslVpnClientCert


acs:vpc:{#regionId}:{#accountId}:sslvpnclientcert/{#SslVpnClientCertId}


N/A

N/A

vpc:DescribeSslVpnClientCerts

DescribeSslVpnClientCerts

Read


SslVpnClientCert


acs:vpc:{#regionId}:{#accountId}:sslvpnclientcert/*


SslVpnClientCert


acs:vpc:{#regionId}:{#accountId}:sslvpnclientcert/{#SslVpnClientCertId}


N/A

N/A

vpc:DescribeSslVpnServers

DescribeSslVpnServers

Read


SslVpnServer


acs:vpc:{#regionId}:{#accountId}:sslvpnserver/*


SslVpnServer


acs:vpc:{#regionId}:{#accountId}:sslvpnserver/{#SslVpnServerId}


N/A

N/A

vpc:DescribeTagKeys

N/A

Read


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:DescribeTags

N/A

Read


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}



vpc:tag


N/A

vpc:DescribeVRouters

DescribeVRouters

List


VRouter


acs:vpc:{#regionId}:{#accountId}:vrouter/*



vpc:VPC


N/A

vpc:DescribeVSwitchAttributes

DescribeVSwitchAttributes

Read


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:DescribeVSwitches

DescribeVSwitches

Read


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/*


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}



vpc:VPC


N/A

vpc:DescribeVbrHa

DescribeVbrHa

Read


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:DescribeVirtualBorderRouters

DescribeVirtualBorderRouters

List


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*


N/A

N/A

vpc:DescribeVirtualBorderRoutersForPhysicalConnection

DescribeVirtualBorderRoutersForPhysicalConnection

List


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/*



vpc:PhysicalConnection


N/A

vpc:DescribeVpcAttribute

DescribeVpcAttribute

Read


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}



vpc:tag


N/A

vpc:DescribeVpcs

DescribeVpcs

Read


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VPCId}



vpc:tag


N/A

vpc:DescribeVpcs

N/A

List


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:DescribeVpnConnection

DescribeVpnConnection

Read


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/{#VpnConnectionId}


N/A

N/A

vpc:DescribeVpnConnections

DescribeVpnConnections

Read


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/*


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/{#VpnConnectionId}


N/A

N/A

vpc:DescribeVpnGateway

DescribeVpnGateway

Read


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DescribeVpnGateways

DescribeVpnGateways

Read


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/*


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DescribeVpnPbrRouteEntries

DescribeVpnPbrRouteEntries

Read


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DescribeVpnRouteEntries

DescribeVpnRouteEntries

Read


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:DetachDhcpOptionsSetFromVpc

DetachDhcpOptionsSetFromVpc

Write


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:DisableNatGatewayEcsMetric

DisableNatGatewayEcsMetric

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:DisableVpcClassicLink

DisableVpcClassicLink

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:DissociateRouteTablesFromVpcGatewayEndpoint

DissociateRouteTablesFromVpcGatewayEndpoint

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/{#GatewayEndpointId}


N/A

N/A

vpc:DownloadVpnConnectionConfig

DownloadVpnConnectionConfig

Read


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/{#VpnConnectionId}


N/A

N/A

vpc:EnableNatGatewayEcsMetric

EnableNatGatewayEcsMetric

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:EnablePhysicalConnection

EnablePhysicalConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:EnableVpcClassicLink

EnableVpcClassicLink

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:GetDhcpOptionsSet

GetDhcpOptionsSet

Read


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


N/A

N/A

vpc:GetNatGatewayAttribute

GetNatGatewayAttribute

Read


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:GetNatGatewayConvertStatus

GetNatGatewayConvertStatus

Read


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:GetPhysicalConnectionServiceStatus

GetPhysicalConnectionServiceStatus

Read


All resources


acs:vpc::{#accountId}:*


N/A

N/A

vpc:GetTrafficMirrorServiceStatus

GetTrafficMirrorServiceStatus

Read


All resources


acs:vpc::{#accountid}:*


N/A

N/A

vpc:GetVpcCloudInstanceSummary

N/A

Read


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:GetVpcGatewayEndpointAttribute

GetVpcGatewayEndpointAttribute

Read


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/{#GatewayEndpointId}


N/A

N/A

vpc:GrantInstanceToCen

GrantInstanceToCen

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:ListBlockStorageLatencyInfo

ListBlockStorageLatencyInfo

List


NetworkIntelligence


acs:vpc:*:{#accountId}:networkintelligence/*


N/A

N/A

vpc:ListDhcpOptionsSets

ListDhcpOptionsSets

Read


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/*


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


N/A

N/A

vpc:ListEnhanhcedNatGatewayAvailableZones

ListEnhanhcedNatGatewayAvailableZones

List


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/*


N/A

N/A

vpc:ListLatencyInfoBetweenRegions

ListLatencyInfoBetweenRegions

List


NetworkIntelligence


acs:vpc:*:{#accountId}:networkintelligence/*


N/A

N/A

vpc:ListLatencyInfoBetweenZones

ListLatencyInfoBetweenZones

List


NetworkIntelligence


acs:vpc:*:{#accountId}:networkintelligence/*


N/A

N/A

vpc:ListNatGatewayConvertReservations

N/A

List


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:ListNatGatewayEcsMetric

ListNatGatewayEcsMetric

List


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:ListPackageLossInfoBetweenRegions

ListPackageLossInfoBetweenRegions

List


NetworkIntelligence


acs:vpc:*:{#accountId}:networkintelligence/*


N/A

N/A

vpc:ListPackageLossInfoBetweenZones

ListPackageLossInfoBetweenZones

List


NetworkIntelligence


acs:vpc:*:{#accountId}:networkintelligence/*


N/A

N/A

vpc:ListPhysicalConnectionFeatures

ListPhysicalConnectionFeatures

List


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/*


N/A

N/A

vpc:ListTagResources

ListTagResources

List


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTable}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}



vpc:tag


N/A

vpc:ListTrafficMirrorFilters

ListTrafficMirrorFilters

List


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/*


N/A

N/A

vpc:ListTrafficMirrorSessions

ListTrafficMirrorSessions

List


TrafficMirrorSession


acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/*


N/A

N/A

vpc:ListVpcEndpointServicesByEndUser

ListVpcEndpointServicesByEndUser

List


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/*


N/A

N/A

vpc:ListVpcGatewayEndpoints

ListVpcGatewayEndpoints

List


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/*


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/{#GatewayEndpointId}


N/A

N/A

vpc:ModifyBandwidthPackageSpec

N/A

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:ModifyBgpGroupAttribute

ModifyBgpGroupAttribute

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:ModifyBgpPeerAttribute

ModifyBgpPeerAttribute

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:ModifyBypassToaAttribute

N/A

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/*


N/A

N/A

vpc:ModifyCommonBandwidthPackageAttribute

ModifyCommonBandwidthPackageAttribute

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:ModifyCommonBandwidthPackageInternetChargeType

ModifyCommonBandwidthPackageInternetChargeType

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:ModifyCommonBandwidthPackageIpBandwidth

ModifyCommonBandwidthPackageIpBandwidth

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:ModifyCommonBandwidthPackagePayType

ModifyCommonBandwidthPackagePayType

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:ModifyCommonBandwidthPackageSpec

ModifyCommonBandwidthPackageSpec

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:ModifyCustomerGatewayAttribute

ModifyCustomerGatewayAttribute

Write


CustomerGateway


acs:vpc:{#regionId}:{#accountId}:customergateway/{#CustomerGatewayId}


N/A

N/A

vpc:ModifyEipForwardMode

N/A

Write


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


N/A

N/A

vpc:ModifyExpressCloudConnectionAttribute

ModifyExpressCloudConnectionAttribute

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:ModifyExpressCloudConnectionBandwidth

ModifyExpressCloudConnectionBandwidth

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:ModifyFlowLogAttribute

ModifyFlowLogAttribute

Write


FlowLog


acs:vpc:{#regionId}:{#accountId}:flowlog/{#FlowLogId}


N/A

N/A

vpc:ModifyForwardEntry

ModifyForwardEntry

Write


ForwardTable


acs:vpc:{#regionId}:{#accountId}:forwardtable/{#ForwardTableId}


N/A

N/A

vpc:ModifyGlobalAccelerationInstanceAttributes

ModifyGlobalAccelerationInstanceAttributes

Write


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


N/A

N/A

vpc:ModifyGlobalAccelerationInstanceSpec

ModifyGlobalAccelerationInstanceSpec

Write


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


N/A

N/A

vpc:ModifyHaVipAttribute

ModifyHaVipAttribute

Write


HaVip


acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}


N/A

N/A

vpc:ModifyIPv6TranslatorAclAttribute

ModifyIPv6TranslatorAclAttribute

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:ModifyIPv6TranslatorAclListEntry

ModifyIPv6TranslatorAclListEntry

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:ModifyIPv6TranslatorAttribute

ModifyIPv6TranslatorAttribute

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:ModifyIPv6TranslatorBandwidth

ModifyIPv6TranslatorBandwidth

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:ModifyIPv6TranslatorEntry

ModifyIPv6TranslatorEntry

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:ModifyIpv6AddressAttribute

ModifyIpv6AddressAttribute

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:ModifyIpv6GatewayAttribute

ModifyIpv6GatewayAttribute

Write


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:ModifyIpv6GatewaySpec

ModifyIpv6GatewaySpec

Write


Ipv6Gateway


acs:vpc:{#regionId}:{#accountId}:ipv6gateway/{#Ipv6GatewayId}


N/A

N/A

vpc:ModifyIpv6InternetBandwidth

ModifyIpv6InternetBandwidth

Write


Ipv6Bandwidth


acs:vpc:{#regionId}:{#accountId}:ipv6bandwidth/*


Ipv6Bandwidth


acs:vpc:{#regionId}:{#accountId}:ipv6bandwidth/{#Ipv6BandwidthId}


N/A

N/A

vpc:ModifyNatGatewayAttribute

ModifyNatGatewayAttribute

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:ModifyNatGatewaySpec

ModifyNatGatewaySpec

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:ModifyNetworkAclAttributes

ModifyNetworkAclAttributes

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


N/A

N/A

vpc:ModifyPhysicalConnectionAttribute

ModifyPhysicalConnectionAttribute

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:ModifyRouteEntry

ModifyRouteEntry

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


N/A

N/A

vpc:ModifyRouteTableAttributes

ModifyRouteTableAttributes

Write


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}



vpc:VRouter


N/A

vpc:ModifyRouterInterfaceAttribute

ModifyRouterInterfaceAttribute

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:ModifyRouterInterfaceSpec

ModifyRouterInterfaceSpec

Write


RouterInterface


acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}


N/A

N/A

vpc:ModifySnatEntry

ModifySnatEntry

Write


SnatTable


acs:vpc:{#regionId}:{#accountId}:snattable/{#SnatTableId}


N/A

N/A

vpc:ModifySslVpnClientCert

ModifySslVpnClientCert

Write


SslVpnClientCert


acs:vpc:{#regionId}:{#accountId}:sslvpnclientcert/{#SslVpnClientCertId}


N/A

N/A

vpc:ModifySslVpnServer

ModifySslVpnServer

Write


SslVpnServer


acs:vpc:{#regionId}:{#accountId}:sslvpnserver/{#SslVpnServerId}


N/A

N/A

vpc:ModifyVRouterAttribute

ModifyVRouterAttribute

Write


VRouter


acs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}


N/A

N/A

vpc:ModifyVSwitchAttribute

ModifyVSwitchAttribute

Write


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:ModifyVirtualBorderRouterAttribute

ModifyVirtualBorderRouterAttribute

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:ModifyVpcAttribute

ModifyVpcAttribute

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}



vpc:tag


N/A

vpc:ModifyVpnConnectionAttribute

ModifyVpnConnectionAttribute

Write


VpnConnection


acs:vpc:{#regionId}:{#accountId}:vpnconnection/{#VpnConnectionId}


N/A

N/A

vpc:ModifyVpnGatewayAttribute

ModifyVpnGatewayAttribute

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:ModifyVpnPbrRouteEntryWeight

ModifyVpnPbrRouteEntryWeight

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:ModifyVpnRouteEntryWeight

ModifyVpnRouteEntryWeight

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:MoveResourceGroup

MoveResourceGroup

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


Eip


acs:vpc:{#regionId}:{#accountId}:eip/{#EipId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:OpenPhysicalConnectionService

OpenPhysicalConnectionService

Read


All resources


acs:vpc:*:{#accountId}:*


N/A

N/A

vpc:OpenTrafficMirrorService

OpenTrafficMirrorService

Write


All resources


acs:vpc::{#accountid}:*


N/A

N/A

vpc:PublishVpnRouteEntry

PublishVpnRouteEntry

Write


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


N/A

N/A

vpc:RecoverVirtualBorderRouter

RecoverVirtualBorderRouter

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:RemoveBandwidthPackageIps

N/A

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:RemoveCommonBandwidthPackageIp

RemoveCommonBandwidthPackageIp

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


N/A

N/A

vpc:RemoveGlobalAccelerationInstanceIp

RemoveGlobalAccelerationInstanceIp

Write


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


N/A

N/A

vpc:RemoveIPv6TranslatorAclListEntry

RemoveIPv6TranslatorAclListEntry

Write


Ipv6Translator


acs:vpc:{#regionId}:{#accountId}:ipv6trans/{#Ipv6TranslatorId}


N/A

N/A

vpc:RemoveSourcesFromTrafficMirrorSession

RemoveSourcesFromTrafficMirrorSession

Write


TrafficMirrorSession


acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/{#TrafficMirrorSessionId}


N/A

N/A

vpc:ReplaceVpcDhcpOptionsSet

ReplaceVpcDhcpOptionsSet

Write


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:RevokeInstanceFromCen

RevokeInstanceFromCen

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:SetHighDefinitionMonitorLogStatus

N/A

Write


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


N/A

N/A

vpc:TagResources

TagResources

Write


BandwidthPackage


acs:vpc:{#regionId}:{#accountId}:combandwidthpackage/{#BandwidthPackageId}


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VpnGateway


acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}



vpc:tag


N/A

vpc:TerminatePhysicalConnection

TerminatePhysicalConnection

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


N/A

N/A

vpc:TerminateVirtualBorderRouter

TerminateVirtualBorderRouter

Write


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:UnTagResources

UnTagResources

Write


Address


acs:vpc:{#regionId}:{#accountId}:eip/{#AllocationId}


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


RouteTable


acs:vpc:{#regionId}:{#accountId}:routetable/{#RouteTableId}


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}



vpc:tag


N/A

vpc:UnassociateGlobalAccelerationInstance

UnassociateGlobalAccelerationInstance

Write


ECS:Instance


acs:ecs:{#regionId}:{#accountId}:instance/*


GlobalAccelerationInstance


acs:vpc:{#regionId}:{#accountId}:globalaccelerationinstance/{#GlobalAccelerationInstanceId}


N/A

N/A

vpc:UnassociateHaVip

UnassociateHaVip

Write


ECS:Instance


acs:ecs:{#regionId}:{#accountId}:instance/{#InstanceId}


HaVip


acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}


N/A

N/A

vpc:UnassociateNetworkAcl

UnassociateNetworkAcl

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:UnassociatePhysicalConnectionFromVirtualBorderRouter

UnassociatePhysicalConnectionFromVirtualBorderRouter

Write


PhysicalConnection


acs:vpc:{#regionId}:{#accountId}:physicalconnection/{#PhysicalConnectionId}


VirtualBorderRouter


acs:vpc:{#regionId}:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:UnassociateRouteTable

UnassociateRouteTable

Write


VSwitch


acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}


N/A

N/A

vpc:UnassociateVpcCidrBlock

UnassociateVpcCidrBlock

Write


VPC


acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}


N/A

N/A

vpc:UpdateDhcpOptionsSetAttribute

UpdateDhcpOptionsSetAttribute

Write


DhcpOptionsSet


acs:vpc:{#regionId}:{#accountId}:dhcpoptionsset/{#DhcpOptionsSetId}


N/A

N/A

vpc:UpdateNatGatewayConvertReservation

N/A

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#natgatewayId}


N/A

N/A

vpc:UpdateNatGatewayNatType

UpdateNatGatewayNatType

Write


NatGateway


acs:vpc:{#regionId}:{#accountId}:natgateway/{#NatGatewayId}


N/A

N/A

vpc:UpdateNetworkAclEntries

UpdateNetworkAclEntries

Write


NetworkAcl


acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}


N/A

N/A

vpc:UpdateTrafficMirrorFilterAttribute

UpdateTrafficMirrorFilterAttribute

Write


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:UpdateTrafficMirrorFilterRuleAttribute

UpdateTrafficMirrorFilterRuleAttribute

Write


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:UpdateTrafficMirrorSessionAttribute

UpdateTrafficMirrorSessionAttribute

Write


TrafficMirrorSession


acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/{#TrafficMirrorSessionId}


TrafficMirrorFilter


acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}


N/A

N/A

vpc:UpdateVirtualBorderBandwidth

UpdateVirtualBorderBandwidth

Write


VirtualBorderRouter


acs:vpc:*:{#accountId}:virtualborderrouter/{#VirtualBorderRouterId}


N/A

N/A

vpc:UpdateVpcGatewayEndpointAttribute

UpdateVpcGatewayEndpointAttribute

Write


GatewayEndpoint


acs:vpc:{#regionId}:{#accountId}:gatewayendpoint/{#GatewayEndpointId}


N/A

N/A

Resource

The following table describes the values that you can use in the Resource element of a policy statement. The values are defined by Virtual Private Cloud.

The Alibaba Cloud Resource Name (ARN) is the unique identifier of the resource on Alibaba Cloud. Take note of the following items:

  • {#} indicates a variable. {#} must be replaced with an actual value. For example, {#regionId} must be replaced with the actual ID of the region where your resource resides.

  • An asterisk (*) is used as a wildcard. Examples:

    • If you specify {#resourceType}/*, all resources are specified.

    • If {#regionId} is set to *, all regions are specified.

    • If {#accountId} is set to *, all Alibaba Cloud accounts are specified.

Resource type

ARN

RouterInterface

acs:vpc:{#regionId}:{#accountId}:routerinterface/{#RouterInterfaceId}

FlowLog

acs:vpc:{#regionId}:{#accountId}:flowlog/{#FlowLogId}

BandwidthPackage

acs:vpc:{#regionId}:{#accountId}:bandwidthpackage/{#BandwidthPackageId}

VPC

acs:vpc:{#regionId}:{#accountId}:vpc/{#VpcId}

HaVip

acs:vpc:{#regionId}:{#accountId}:havip/{#HaVipId}

NetworkAcl

acs:vpc:{#regionId}:{#accountId}:networkacl/{#NetworkAclId}

VSwitch

acs:vpc:{#regionId}:{#accountId}:vswitch/{#VSwitchId}

VRouter

acs:vpc:{#regionId}:{#accountId}:vrouter/{#VRouterId}

NetworkIntelligence

acs:vpc:*:{#accountId}:networkintelligence/{#NetworkIntelligenceId}

TrafficMirrorFilter

acs:vpc:{#regionId}:{#accountId}:trafficmirrorfilter/{#TrafficMirrorFilterId}

TrafficMirrorSession

acs:vpc:{#regionId}:{#accountId}:trafficmirrorsession/{#TrafficMirrorSessionId}

Condition

The following table describes the values that you can use in the Condition element of a policy statement. The values are defined by Virtual Private Cloud. The following table describes the service-specific condition keys. The common condition keys that are defined by Alibaba Cloud also apply to Virtual Private Cloud. For more information about the common condition keys, see Policy elements.

The data type determines which condition operators you can use to compare the value in a request with the value in a policy statement. You must use condition operators that are supported by the data type. Otherwise, you cannot compare the value in the request with the value in the policy statement. In this case, the authorization is invalid. For more information about the condition operators that are supported by each data type, see Policy elements.

Condition keys

Description

Type

vpc:PhysicalConnection

The resource ARN of a physical connection.

String

vpc:VBR

The resource ARN of a VBR (Virtual Border Router) instance.

String

vpc:VPC

The resource ARN of a VPC Instance. You can use Condition to restrict access to a specified VPC.

String

vpc:VRouter

The resource ARN of a VRouter instance.

String

vpc:tag

A tag key and value pair that are attached to a VPC resource.

String