AI Gateway service-linked roles are predefined RAM roles that grant AI Gateway the permissions required to access other Alibaba Cloud services on your behalf.
Use cases
-
AliyunServiceRoleForNativeApiGw: When AI Gateway needs to access the resources of other cloud services, such as Virtual Private Cloud (VPC), Container Service for Kubernetes (ACK), Function Compute (FC), Enterprise Distributed Application Service (EDAS), Microservices Engine (MSE), Server Load Balancer (SLB), Network Load Balancer (NLB), Elastic Compute Service (ECS), and Application Real-Time Monitoring Service (ARMS), it uses the automatically created service-linked role AliyunServiceRoleForNativeApiGw to gain the required access permissions.
-
AliyunServiceRoleForNativeApiGwInvokeFC: When AI Gateway needs to call Function Compute (FC), it uses the automatically created service-linked role AliyunServiceRoleForNativeApiGwInvokeFC to enable gateway features.
-
AliyunServiceRoleForNativeApiGwInvokeKMS: When Cloud-native API Gateway needs to call Key Management Service (KMS), it uses the automatically created service-linked role
AliyunServiceRoleForNativeApiGwInvokeKMSto gain access permissions.
Permissions for RAM users
For a RAM user to create or delete service-linked roles, an administrator must grant the RAM user administrator permissions (AliyunNativeApiGwFullAccess) or add the following permissions to the Action statement of a custom permission policy:
-
Create a service-linked role:
ram:CreateServiceLinkedRole -
Delete a service-linked role:
ram:DeleteServiceLinkedRole
For more information about how to grant permissions, see Permissions required to manage service-linked roles.
Permissions
AliyunServiceRoleForNativeApiGw
The following permissions are granted to the service-linked role for AI Gateway (AliyunServiceRoleForNativeApiGw):
VPC
{
"Effect": "Allow",
"Action": [
"vpc:AllocateEipAddress",
"vpc:AllocateEipAddressPro",
"vpc:DescribeEipAddresses",
"vpc:AssociateEipAddress",
"vpc:UnassociateEipAddress",
"vpc:ReleaseEipAddress",
"vpc:ModifyEipAddressAttribute",
"vpc:ModifyBypassToaAttribute",
"vpc:AddCommonBandwidthPackageIp",
"vpc:RemoveCommonBandwidthPackageIp",
"vpc:TagResources",
"vpc:DescribeVSwitches",
"vpc:DescribeVSwitchAttributes",
"vpc:DescribeVpcs",
"vpc:CreateVSwitch",
"vpc:DescribeVpcAttribute",
"vpc:DescribeVRouters",
"vpc:DescribeRouteTables",
"vpc:DescribeRouteEntryList"
],
"Resource": "*"
}
ACK
{
"Effect": "Allow",
"Action": [
"cs:DescribeClusterDetail",
"cs:DescribeClusterInnerServiceKubeconfig",
"cs:RevokeClusterInnerServiceKubeconfig",
"cs:GetUserConfig",
"cs:DescribeClusterUserKubeconfig",
"cs:GetClusterById",
"cs:GetClustersByUid",
"cs:DescribeClustersV1",
"cs:ListClusters",
"cs:GetClusters",
"cs:DescribeClusterNodePools"
],
"Resource": "*"
}
FC
{
"Effect": "Allow",
"Action": [
"fc:ListAliases",
"fc:ListServices",
"fc:ListServiceVersions",
"fc:ListFunctions",
"fc:ListFunctionVersions",
"fc:ListTriggers"
],
"Resource": "*"
}
EDAS
{
"Effect": "Allow",
"Action": [
"edas:ReadNamespace",
"edas:ReadService",
"edas:ListUserDefineRegion"
],
"Resource": "*"
}
MSE
{
"Effect": "Allow",
"Action": [
"mse:ListAnsServices",
"mse:ListEngineNamespaces",
"mse:ListClusters",
"mse:QueryConfig"
],
"Resource": "*"
}
SLB
{
"Effect": "Allow",
"Action": [
"slb:SetLoadBalancerName",
"slb:CreateLoadBalancer",
"slb:AddBackendServers",
"slb:SetBackendServers",
"slb:RemoveBackendServers",
"slb:CreateLoadBalancerTCPListener",
"slb:DescribeLoadBalancerTCPListenerAttribute",
"slb:SetLoadBalancerTCPListenerAttribute",
"slb:CreateLoadBalancerHTTPListener",
"slb:DescribeLoadBalancerHTTPListenerAttribute",
"slb:SetLoadBalancerHTTPListenerAttribute",
"slb:CreateLoadBalancerHTTPSListener",
"slb:DescribeLoadBalancerHTTPSListenerAttribute",
"slb:SetLoadBalancerHTTPSListenerAttribute",
"slb:StartLoadBalancerListener",
"slb:StopLoadBalancerListener",
"slb:DeleteLoadBalancerListener",
"slb:DescribeLoadBalancers",
"slb:DescribeLoadBalancerAttribute",
"slb:DescribeHealthStatus",
"slb:CreateLoadBalancerForCloudService",
"slb:DeleteLoadBalancer",
"slb:ModifyLoadBalancerInternetSpec",
"slb:RemoveTags",
"slb:AddTags",
"slb:SetLoadBalancerUDPListenerAttribute",
"slb:CreateLoadBalancerUDPListener",
"slb:CreateVServerGroup",
"slb:DeleteVServerGroup",
"slb:SetVServerGroupAttribute",
"slb:ModifyVServerGroupBackendServers",
"slb:AddVServerGroupBackendServers",
"slb:ModifyLoadBalancerInstanceSpec",
"slb:ModifyLoadBalancerInternetSpec",
"slb:RemoveVServerGroupBackendServers",
"slb:SetLoadBalancerModificationProtection",
"slb:SetLoadBalancerDeleteProtection",
"slb:DescribeLoadBalancerUDPListenerAttribute ",
"slb:DescribeTags",
"slb:DescribeVServerGroups",
"slb:DescribeVServerGroupAttribute",
"slb:DescribeLoadBalancerListeners",
"slb:ListTagResources",
"slb:TagResources",
"slb:UntagResources"
],
"Resource": "*"
}
NLB
{
"Effect": "Allow",
"Action": [
"nlb:TagResources",
"nlb:UnTagResources",
"nlb:ListTagResources",
"nlb:CreateLoadBalancer",
"nlb:DeleteLoadBalancer",
"nlb:GetLoadBalancerAttribute",
"nlb:ListLoadBalancers",
"nlb:UpdateLoadBalancerAttribute",
"nlb:UpdateLoadBalancerAddressTypeConfig",
"nlb:UpdateLoadBalancerZones",
"nlb:CreateListener",
"nlb:DeleteListener",
"nlb:ListListeners",
"nlb:UpdateListenerAttribute",
"nlb:StopListener",
"nlb:StartListener",
"nlb:GetListenerAttribute",
"nlb:GetListenerHealthStatus",
"nlb:CreateServerGroup",
"nlb:DeleteServerGroup",
"nlb:UpdateServerGroupAttribute",
"nlb:AddServersToServerGroup",
"nlb:RemoveServersFromServerGroup",
"nlb:UpdateServerGroupServersAttribute",
"nlb:ListServerGroups",
"nlb:ListServerGroupServers",
"nlb:LoadBalancerLeaveSecurityGroup",
"nlb:LoadBalancerJoinSecurityGroup",
"nlb:GetJobStatus",
"nlb:UpdateLoadBalancerProtection"
],
"Resource": "*"
}
ECS
{
"Effect": "Allow",
"Action": [
"ecs:CreateSecurityGroup",
"ecs:AuthorizeSecurityGroup",
"ecs:AuthorizeSecurityGroupEgress",
"ecs:RevokeSecurityGroup",
"ecs:RevokeSecurityGroupEgress",
"ecs:DeleteSecurityGroup",
"ecs:JoinSecurityGroup",
"ecs:LeaveSecurityGroup",
"ecs:DescribeSecurityGroups",
"ecs:DescribeInstances",
"ecs:CreateNetworkInterface",
"ecs:DeleteNetworkInterface",
"ecs:DescribeNetworkInterfaces",
"ecs:CreateNetworkInterfacePermission",
"ecs:DescribeNetworkInterfacePermissions",
"ecs:DeleteNetworkInterfacePermission",
"ecs:DescribeSecurityGroupAttribute",
"ecs:AddTags",
"ecs:DescribeEipAddresses",
"ecs:DescribeNetworkInterfaceAttribute",
"ecs:ModifyNetworkInterfaceAttribute",
"ecs:AssignPrivateIpAddresses",
"ecs:UnassignPrivateIpAddresses",
"ecs:AssignIpv6Addresses",
"ecs:UnassignIpv6Addresses",
"ecs:AttachNetworkInterface",
"ecs:DetachNetworkInterface",
"ecs:ListTagResources"
],
"Resource": "*"
}
ARMS
{
"Effect": "Allow",
"Action": [
"arms:OpenArmsService",
"arms:GetAlertRules",
"arms:ReportCustomIncidents",
"arms:AddPrometheusInstance",
"arms:GetAuthToken",
"arms:GetClusterAllUrl",
"arms:OpenArmsServiceSecondVersion",
"arms:CheckServiceStatus",
"arms:OpenVCluster",
"arms:GetPrometheusApiToken",
"arms:ListDashboards",
"arms:GetExploreUrl",
"arms:CreateDefaultCloudProductPrometheusAlertRule",
"arms:ListNotificationPolicies",
"arms:ListDispatchRule",
"arms:CreateDispatchRule",
"arms:CreateOrUpdateNotificationPolicy",
"arms:DescribeContactGroups",
"arms:SearchContactGroup",
"arms:CreatePrometheusAlertRule"
],
"Resource": "*"
}
AliyunServiceRoleForNativeApiGwInvokeFC
The following permissions are granted to the service-linked role for AI Gateway (AliyunServiceRoleForNativeApiGwInvokeFC):
{
"Effect": "Allow",
"Action": "fc:InvokeFunction",
"Resource": "*"
}
AliyunServiceRoleForNativeApiGwInvokeKMS
The following permissions are granted to the service-linked role for AI Gateway (AliyunServiceRoleForNativeApiGwInvokeKMS):
{
"Effect": "Allow",
"Action": [
"kms:ListKmsInstances",
"kms:ListKeys",
"kms:GenerateDataKey",
"kms:Decrypt",
"kms:CreateSecret",
"kms:DeleteSecret",
"kms:UpdateSecret",
"kms:DescribeSecret",
"kms:GetSecretValue",
"kms:PutSecretValue",
"kms:TagResource",
"kms:UntagResource"
],
"Resource": "*"
}
View a service-linked role
After a service-linked role is created, you can go to the Roles page of the RAM console and search for the role name, such as AliyunServiceRoleForNativeApiGw or AliyunServiceRoleForNativeApiGwInvokeFC, to view the following information:
-
Basic information
On the role's details page, go to the Basic Information section to view its name, creation time, ARN, and description.
-
Permission policy
On the details page of the AliyunServiceRoleForNativeApiGw or AliyunServiceRoleForNativeApiGwInvokeFC role, click the Permissions tab. Then, click a policy name to view the policy document and the cloud resources the role can access.
-
Trust policy
On the details page of the AliyunServiceRoleForNativeApiGw or AliyunServiceRoleForNativeApiGwInvokeFC role, click the Trust Policy Management tab to view the trust policy. A trust policy defines the trusted entities that can assume a RAM role. The trusted entity of a service-linked role is a cloud service, which you can identify in the
Servicefield of the trust policy.
For more information about how to view a RAM role, see View the information about a RAM role.
Delete a service-linked role
If you no longer use AI Gateway, you can manually delete the service-linked role on the RAM console.
-
Log on to the RAM console by using your Alibaba Cloud account. In the navigation pane on the left, choose .
-
On the Roles page, enter the name of the role that you want to delete in the search box, for example,
AliyunServiceRoleForNativeApiGw. -
Find the target role in the search results and click Delete Role in the Actions column.
-
In the confirmation dialog box, enter the role name for verification and click Delete Role.
After you delete the service-linked role for Cloud-native API Gateway, features that depend on the role will no longer function correctly. Proceed with caution.
FAQ
Why a RAM user cannot create the AliyunServiceRoleForNativeApiGw role
Creating or deleting the AliyunServiceRoleForNativeApiGw role requires specific permissions. If a RAM user cannot automatically create the role, an administrator must attach the following permission policy to the RAM user.
{
"Statement": [
{
"Action": [
"ram:CreateServiceLinkedRole"
],
"Resource": "acs:ram:*:Alibaba Cloud account ID:role/*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": [
"nativeapigw.aliyuncs.com"
]
}
}
}
],
"Version": "1"
}
Replace Alibaba Cloud account ID with the ID of your Alibaba Cloud account.
Why a RAM user cannot create the AliyunServiceRoleForNativeApiGwInvokeFC role
Creating or deleting the AliyunServiceRoleForNativeApiGwInvokeFC role requires specific permissions. If a RAM user cannot automatically create the role, an administrator must attach the following permission policy to the RAM user.
{
"Statement": [
{
"Action": [
"ram:CreateServiceLinkedRole"
],
"Resource": "acs:ram:*:Alibaba Cloud account ID:role/*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": [
"invokefc.nativeapigw.aliyuncs.com"
]
}
}
}
],
"Version": "1"
}
Replace Alibaba Cloud account ID with the ID of your Alibaba Cloud account.
References
For more information about service-linked roles, see Service-linked roles.