When you use a Resource Access Management (RAM) user to create a data transformation job, you can specify custom roles to transfer data across different Alibaba Cloud accounts.
Prerequisites
- A project is created. A source Logstore and a destination Logstore are created in the project. The names of the source and destination Logstores and the name of the project are obtained. For more information, see Manage a Logstore and Manage a project.
- A RAM user is created, and the RAM user is granted the required permissions to perform data transformation operations. For more information, see Grant a RAM user the permissions to manage a data transformation job.
Background information
In a cross-account scenario, a RAM user is used to create a data transformation job. Role A must have the read permissions on the source Logstore, and Role B must have the write permissions on the destination Logstores. The data transformation job is run within Alibaba Cloud Account 1. Therefore, you must modify the trust policy of Role B within Alibaba Cloud Account 2 to allow Alibaba Cloud Account 1 to assume Role B.
