All Products
Search
Document Center

Alibaba Cloud Service Mesh:Grant RBAC permissions

Last Updated:Aug 25, 2026

Use Role-Based Access Control (RBAC) in Service Mesh (ASM) to manage permissions for RAM users and RAM roles on custom resources. You must grant the necessary permissions to any user or role that needs to manage these resources.

Configuration

Both Alibaba Cloud accounts and other RAM users can grant RBAC permissions to RAM users.

Procedure

  1. Log on to the ASM console. In the left-side navigation pane, choose Service Mesh > Authorization.

  2. On the Authorization page, configure permissions.

    1. To grant permissions to a RAM user: On the RAM User tab, find the target user in the list and click Manage Permissions in the user's row.

    2. To grant permissions to a RAM role: Click the RAM Role tab, search for the RAM role by its name, and then click Manage Permissions.

  3. In the Permission Management dialog box, click +Add Permissions. Configure permissions for the target RAM user or RAM role at the Instance Information and Namespaces levels, select a predefined role, and then click Submit Permissions.

    The following table describes the permissions of each role.

    RolePermissions
    AdministratorRead and write access to all custom ASM resources in all namespaces
    Istio resource administratorRead and write access to all resources except ASM gateways (IstioGateway) in a specified namespace or all namespaces
    Restricted userRead-only access to custom ASM resources visible in the ASM console, in a specified namespace or all namespaces
    No permissionNo access to any custom ASM resources in all namespaces