ApsaraMQ for Kafka accesses other Alibaba Cloud services on your behalf to manage messaging infrastructure. Before you use the service, assign the default Resource Access Management (RAM) role to your account to authorize this access.
Prerequisites
Before you begin, make sure that you have:
How authorization works
When you activate ApsaraMQ for Kafka, the service creates a default RAM role named AliyunKafkaDefaultRole in your account. This role grants ApsaraMQ for Kafka the permissions required to access your Alibaba Cloud resources.
The one-click authorization on the RAM Quick Authorization page assigns this role automatically. No manual policy configuration is required.
RAM is the identity and access management service of Alibaba Cloud. To configure fine-grained access control, such as granting permissions to specific RAM users or RAM roles, see Authorize RAM users and RAM roles.
Authorize the service
Log on to the Alibaba Cloud international site (alibabacloud.com).
Open the RAM Quick Authorization page and click Authorize.

Result
After authorization completes, the ApsaraMQ for Kafka console opens automatically.
Next step
Purchase and deploy an ApsaraMQ for Kafka instance. Choose a deployment option based on your network requirements:
Purchase and deploy a VPC-connected instance -- Access the instance only from within a VPC.
Purchase and deploy an Internet- and VPC-connected instance -- Access the instance from both the internet and a VPC.