Use Role-Based Access Control (RBAC) in Service Mesh (ASM) to manage permissions for RAM users and RAM roles on custom resources. You must grant the necessary permissions to any user or role that needs to manage these resources.
Configuration
Both Alibaba Cloud accounts and other RAM users can grant RBAC permissions to RAM users.
Procedure
-
Log on to the ASM console. In the left-side navigation pane, choose .
On the Authorization page, configure permissions.
To grant permissions to a RAM user: On the RAM User tab, find the target user in the list and click Manage Permissions in the user's row.
To grant permissions to a RAM role: Click the RAM Role tab, search for the RAM role by its name, and then click Manage Permissions.
In the Permission Management dialog box, click +Add Permissions. Configure permissions for the target RAM user or RAM role at the Instance Information and Namespaces levels, select a predefined role, and then click Submit Permissions.
The following table describes the permissions of each role.
Role Permissions Administrator Read and write access to all custom ASM resources in all namespaces Istio resource administrator Read and write access to all resources except ASM gateways (IstioGateway) in a specified namespace or all namespaces Restricted user Read-only access to custom ASM resources visible in the ASM console, in a specified namespace or all namespaces No permission No access to any custom ASM resources in all namespaces