All Products
Search
Document Center

RAM

Last Updated: May 29, 2020

1. Create a RAM user

Log on to the Resource Access Management (RAM) console. In the left-side navigation pane, choose Identities > Users. On the page that appears, click Create User to create a RAM user. For more information, see Create a RAM user.

2. Grant the read-only permission of PrivateZone to the RAM user

Log on to the RAM console. In the left-side navigation pane, choose Identities > Users. On the Users page, find the target RAM user and click Add Permissions in the Actions column. In the Add Permissions dialog box that appears, add the AliyunPvtzReadOnlyAccess policy to the Selected section and click OK.
ram-1

3. Grant the full permission of PrivateZone to the RAM user

Log on to the RAM console. In the left-side navigation pane, choose Identities > Users. On the Users page, find the target RAM user and click Add Permissions in the Actions column. In the Add Permissions dialog box that appears, add the AliyunPvtzFullAccess policy to the Selected section and click OK.
ram-2

4. Authorize the RAM user to manage specific private zones

You can create custom authorization policies to authorize the RAM user to manage specific private zones. Assume that you have two private zones whose IDs are djiow001 and djiow002.

  • Log on to the RAM console. In the left-side navigation pane, choose Permissions > Policies. On the Policies page, click Create Policy in the upper-left corner. On the Create Custom Policy page that appears, set Policy Name to AliyunPvtzSingleAccess and Configuration Mode to Script and enter the following command in the editor.

ram-3

  1. {
  2. "Version": "1",
  3. "Statement": [
  4. {
  5. "Action": "pvtz:*",
  6. "Resource": [
  7. "acs:pvtz:*:*:zone/djiow001",
  8. "acs:pvtz:*:*:zone/djiow002"
  9. ],
  10. "Effect": "Allow"
  11. },
  12. {
  13. "Action": [
  14. "pvtz:DescribeUserServiceStatus",
  15. "pvtz:DescribeZones",
  16. "pvtz:DescribeRegions",
  17. "pvtz:DescribeVpcs"
  18. ],
  19. "Resource": "acs:pvtz:*:*:*",
  20. "Effect": "Allow"
  21. }
  22. ]
  23. }
  • Then, grant the created AliyunPvtzSingleAccess permission to the RAM user by following the preceding procedure.