API standards and multilingual preset SDKs
The OpenAPI of this product (Yundun-bastionhost/2019-12-09) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.
Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.
Custom signature scenarios
If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.
Account and security preparation
Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.
Bastion host instances (only for V3.2.X)
|
API |
Title |
Description |
| DescribeInstanceAttribute | Query instance attribute information | Queries all attribute information of an instance, such as the instance ID and instance description. |
| DescribeInstances | DescribeInstances | Retrieves a list of Bastionhost instances. |
| ConfigInstanceSecurityGroups | ConfigInstanceSecurityGroups | Configures the security groups that control inbound and outbound network traffic for a Bastionhost instance. |
| ConfigInstanceWhiteList | ConfigInstanceWhiteList | After enabling public network access for a Bastionhost instance, you can add IP addresses to a whitelist to control access. |
| StartInstance | StartInstance | Starts a specified Bastionhost instance. |
| EnableInstancePublicAccess | Enable public network access for a specified bastionhost instance | Enables public network access for a specified Bastionhost instance. |
| DisableInstancePublicAccess | DisableInstancePublicAccess | Disables public network access for a Bastionhost instance. |
| ModifyInstanceAttribute | Modify the information of a specified bastion host instance | Modifies the information of a specified bastion host instance. |
| MoveResourceGroup | MoveResourceGroup | Moves a Bastionhost instance to a specified resource group. |
| AddInstanceRdMember | AddInstanceRdMember | Adds a Resource Directory (RD) member account to a Bastionhost instance so that you can import and manage the cloud assets of the member account through Bastionhost. |
| ListInstanceRdMembers | ListInstanceRdMembers | Lists the member accounts in a Resource Directory (RD). |
| RemoveInstanceRdMember | RemoveInstanceRdMember | Removes a Resource Directory (RD) member account from a Bastionhost instance. You must remove all assets of the member account from Bastionhost before you call this operation. |
Tags (only for V3.2.X)
|
API |
Title |
Description |
| ListTagKeys | ListTagKeys | Queries the tag keys on resources. |
| ListTagResources | Query tags bound to bastionhost instances | Queries the tags that are bound to one or more Bastionhost instances. |
| UntagResources | Batch unbind and delete tags from a specified bastionhost instance | Unbinds and deletes tags from a specified Bastionhost instance in batches. |
| TagResources | TagResources | Creates and attaches tags to one or more Bastionhost instances. |
Regions (only for V3.2.X)
|
API |
Title |
Description |
| DescribeRegions | DescribeRegions | Queries the Alibaba Cloud regions that support Bastionhost instances. |
Hosts (only for V3.2.17 and later)
|
API |
Title |
Description |
| CreateHost | Create a host in bastionhost | Creates a host in a Bastionhost instance. Bastionhost supports O&M for hosts from different sources, including Alibaba Cloud ECS instances, on-premises IDC servers, and servers on other clouds. Before you perform O&M on a host through Bastionhost, you must first import the host into Bastionhost. You can call this operation to create a host that you want to manage in Bastionhost. |
| GetHost | GetHost | Retrieves the details of a host, such as the name, source, address, protocol, and service port. |
| ListHosts | ListHosts | Queries the hosts in a bastion host. |
| DeleteHost | Delete a single host | Deletes a single host. |
| ModifyHostsPort | ModifyHostsPort | Changes the port for the O\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\&M protocol on one or more hosts. |
| ModifyHostsActiveAddressType | ModifyHostsActiveAddressType | Changes the endpoint type of one or more hosts for O\\\\\\\\\\\\&M. Public and private IP addresses are supported. |
| ModifyHost | ModifyHost | Modifies information about a host. The information includes the address, name, and description of the host and the operating system that the host runs. |
Databases (only for V3.2.40 and later)
|
API |
Title |
Description |
| CreateDatabase | Create a database for O&M in a bastion host | Imports database assets into a bastion host. Supported database types include MySQL, SQL Server, and PostgreSQL for ApsaraDB RDS instances, MySQL, PostgreSQL, and PostgreSQL (Compatible with Oracle) for PolarDB clusters, and MySQL, SQL Server, PostgreSQL, and Oracle for self-managed databases. |
| ModifyDatabase | ModifyDatabase | Modifies the basic information about a database. |
| GetDatabase | GetDatabase | Queries the detailed information about a database. |
| ListDatabases | ListDatabases | Queries the databases that are managed by a bastion host. |
| DeleteDatabase | Delete a single database instance | Deletes a single database instance. |
Network domains (only for V3.2.40 and later)
|
API |
Title |
Description |
| CreateNetworkDomain | Create a network domain | If you want to perform unified O&M on assets that are distributed across different network environments or that are not connected to the virtual private cloud (VPC) where Bastionhost resides, use the network domain feature of Bastionhost. You can configure a proxy server for these assets, create a network domain in Bastionhost and add the proxy server, and then add the assets to the network domain to manage them through Bastionhost. |
| GetNetworkDomain | GetNetworkDomain | Retrieves the details of a specified network domain. |
| ListNetworkDomains | ListNetworkDomains | Lists the network domains configured in a Bastionhost instance. Network domains define the connectivity between Bastionhost and the hosts or databases that it manages. |
| DeleteNetworkDomain | DeleteNetworkDomain | Deletes a network domain. |
| ModifyNetworkDomain | ModifyNetworkDomain | Modifies the basic information about a network domain. |
| MoveHostsToNetworkDomain | MoveHostsToNetworkDomain | Adds multiple hosts to a network domain at a time. |
| MoveDatabasesToNetworkDomain | MoveDatabasesToNetworkDomain | Adds multiple databases to a network domain at a time. |
Host accounts (only for V3.2.17 and later)
|
API |
Title |
Description |
| CreateHostAccount | Create a host account for a specified host | After you create a host in Bastionhost, you can create a host account for the host to manage the existing account of the host in Bastionhost. After you create a host account, O&M engineers can use the account to log on to the host through Bastionhost for O&M operations. |
| GetHostAccount | GetHostAccount | Retrieves the details of a host account on a host managed by a Bastionhost instance, such as the protocol type and account name. |
| ListHostAccounts | ListHostAccounts | Lists the host accounts that are configured for a host in a Bastionhost instance. Host accounts are the credentials used by O&M engineers to log on to the host. |
| ModifyHostAccount | Modify host account information | Modifies host account information, including the name, password, and private key of a host account. |
| DeleteHostAccount | Delete a single host account | Deletes a single host account. |
| ResetHostAccountCredential | ResetHostAccountCredential | Clears the credential (password or SSH private key) for a specified host account. |
| ListImportableKMSSecretsForHost | ListImportableKMSSecretsForHost | Lists all importable KMS secrets for a specified host. |
| ImportKMSSecretsForHost | ImportKMSSecretsForHost | Imports KMS secrets for a specified host. |
Database accounts (only for V3.2.40 and later)
|
API |
Title |
Description |
| CreateDatabaseAccount | Create a database account for a specified database instance | After a database is created, you can create a database account for it. After the account is created, O&M engineers can use the account to log on to and manage the database. |
| ModifyDatabaseAccount | ModifyDatabaseAccount | Modifies the basic information about a database account. |
| GetDatabaseAccount | GetDatabaseAccount | Queries the detailed information about a database account. |
| ListDatabaseAccounts | ListDatabaseAccounts | Queries the database accounts of a database. |
| ListDatabaseAccountsForUserGroup | ListDatabaseAccountsForUserGroup | Queries the database accounts of a database and whether a user group is authorized to manage each database account. |
| DeleteDatabaseAccount | DeleteDatabaseAccount | Deletes a database account. |
Users (only for V3.2.17 and later)
|
API |
Title |
Description |
| CreateUser | CreateUser | Adds a user to a bastion host. |
| GetUser | Get user information | Retrieves the details of a specified Bastionhost user. |
| ListUsers | Query user list | Retrieves the list of users for a specified bastion host. |
| ModifyUser | ModifyUser | Modifies the information about a user of a bastion host. |
| DeleteUser | DeleteUser | Deletes a bastion host user. |
| CreateUserPublicKey | CreateUserPublicKey | Creates a public key for a bastion host user and hosts the public key in the bastion host. This way, O\\\\\\\\\\\\\\\\\\\\\\\\&M engineers can use the private key that corresponds to the public key to log on to the bastion host from an O\\\\\\\\\\\\\\\\\\\\\\\\&M client. |
| ListUserPublicKeys | ListUserPublicKeys | Lists the SSH public keys that are configured for a Bastionhost user. Users can use these public keys for key-based authentication when logging on to hosts through Bastionhost. |
| ModifyUserPublicKey | ModifyUserPublicKey | Modifies the public key of the user. |
| DeleteUserPublicKey | DeleteUserPublicKey | Deletes a public key from the specified user. |
| LockUsers | LockUsers | Locks one or more users of a bastion host. |
| UnlockUsers | UnlockUsers | Unlocks one or more users of a bastion host. |
User groups (only for V3.2.17 and later)
|
API |
Title |
Description |
| CreateUserGroup | CreateUserGroup | Creates a user group for a bastion host. |
| GetUserGroup | GetUserGroup | Retrieves the details of a user group in a bastion host. |
| ListUserGroups | ListUserGroups | Queries a list of user groups on a bastion host. |
| ModifyUserGroup | ModifyUserGroup | Modifies the information about a user group. |
| DeleteUserGroup | Delete a user group | Deletes a single user group from a bastion host. |
| AddUsersToGroup | Add multiple users to a user group | Adds users to a user group in a batch. |
| RemoveUsersFromGroup | RemoveUsersFromGroup | Removes one or more users from a user group. |
Asset groups (only for V3.2.17 and later)
|
API |
Title |
Description |
| CreateHostGroup | Create an asset group | You can create different asset groups based on your business requirements, add assets of the same type to an asset group, and manage assets by category and perform batch operations. |
| AddDatabasesToGroup | AddDatabasesToGroup | Adds multiple databases to a specified asset group. |
| AddHostsToGroup | Add hosts to a specified asset group in a batch | Adds multiple hosts to a specified asset group in a batch. |
| RemoveDatabasesFromGroup | RemoveDatabasesFromGroup | Removes multiple databases from an asset group at a time. |
| DeleteHostGroup | Delete a single asset group | Deletes a single asset group. |
| RemoveHostsFromGroup | RemoveHostsFromGroup | Removes multiple hosts from an asset group at a time. |
| ModifyHostGroup | ModifyHostGroup | Modifies the name or description of the specified host group. |
| GetHostGroup | GetHostGroup | Retrieves the details of a host group. |
| ListHostGroups | ListHostGroups | Queries a list of asset groups that are managed by a bastion host. |
Host authorization (only for V3.2.17 and later)
|
API |
Title |
Description |
| AttachHostAccountsToUser | AttachHostAccountsToUser | After you add a user to your bastion host, you must authorize the user to manage assets. Only authorized users can log on to the bastion host to perform O\\\\\\\\\\\\&M operations on the assets. |
| ListHostsForUser | ListHostsForUser | Queries the hosts that a user group is authorized or not authorized to manage. |
| ListHostAccountsForUser | ListHostAccountsForUser | Queries the host accounts of a host and whether a user is authorized to manage each host account. |
| DetachHostAccountsFromUser | DetachHostAccountsFromUser | Revokes permissions on hosts and host accounts from a user. |
| DetachHostAccountsFromUserGroup | DetachHostAccountsFromUserGroup | Revokes the permissions on one or more hosts and host accounts from a user group. |
| DetachHostGroupAccountsFromUser | DetachHostGroupAccountsFromUser | Removes host groups and host accounts from the list of host groups and host accounts that a user is authorized to manage. |
| AttachHostAccountsToUserGroup | Grant a user group permissions on hosts and host accounts | Grants a user group permissions on hosts and host accounts. |
| DetachHostGroupAccountsFromUserGroup | DetachHostGroupAccountsFromUserGroup | Revokes permissions on one or more host groups and host accounts from a user group. |
| AttachHostGroupAccountsToUser | AttachHostGroupAccountsToUser | Authorizes a user to manage one or more host groups and host accounts. |
| AttachHostGroupAccountsToUserGroup | AttachHostGroupAccountsToUserGroup | Authorizes a user to manage one or more host groups and host accounts. |
| ListHostAccountsForUserGroup | ListHostAccountsForUserGroup | Queries the host accounts of a host and whether a user group is authorized to manage each host account. |
| ListHostGroupAccountNamesForUser | ListHostGroupAccountNamesForUser | Queries the names of the host accounts that a specified user is authorized to manage in a specified host group. |
| ListHostGroupAccountNamesForUserGroup | ListHostGroupAccountNamesForUserGroup | Queries the names of the host accounts that a user group is authorized to manage in a host group. |
| ListHostGroupsForUser | ListHostGroupsForUser | Queries a list of host groups that a bastion host user is authorized or is not authorized to manage. |
| ListHostGroupsForUserGroup | ListHostGroupsForUserGroup | Queries the hosts that a specified user group is authorized or not authorized to manage. |
| ListHostsForUserGroup | ListHostsForUserGroup | Lists the authorized or unauthorized hosts for a bastion host user group. |
Database authorization (only for V3.2.40 and later)
|
API |
Title |
Description |
| AttachDatabaseAccountsToUser | AttachDatabaseAccountsToUser | Authorizes a user to manage databases and database accounts. |
| ListDatabasesForUser | ListDatabasesForUser | Queries the databases that a user is authorized to manage. |
| DetachDatabaseAccountsFromUserGroup | DetachDatabaseAccountsFromUserGroup | Revokes permissions on databases and database accounts from a user group. |
| ListDatabaseAccountsForUser | ListDatabaseAccountsForUser | Queries the database accounts of a database and whether a user is authorized to manage each database account. |
| DetachDatabaseAccountsFromUser | DetachDatabaseAccountsFromUser | Revokes permissions on databases and database accounts from a user. |
| AttachDatabaseAccountsToUserGroup | Grant a user group permissions on databases and database accounts | Grants a user group permissions on databases and database accounts. |
| ListDatabasesForUserGroup | ListDatabasesForUserGroup | Lists the databases that a user group is authorized to manage through a Bastionhost instance. |
O&M tokens (only for V3.2.40 and later)
|
API |
Title |
Description |
| ListOperationDatabases | ListOperationDatabases | Lists the databases that the current Resource Access Management (RAM) user is authorized to access. |
| ListOperationHosts | ListOperationHosts | Lists the hosts that the current Resource Access Management (RAM) user is authorized to perform O&M operations on through a Bastionhost instance. |
| ListOperationHostAccounts | ListOperationHostAccounts | Queries a list of host accounts that the current Resource Access Management (RAM) user is authorized to manage. |
| ListOperationDatabaseAccounts | ListOperationDatabaseAccounts | Queries a list of database accounts that the current Resource Access Management (RAM) user is authorized to manage. |
| GenerateAssetOperationToken | GenerateAssetOperationToken | Call this operation to request O&M tokens for bastions or databases, which allows you to manage assets. |
| RenewAssetOperationToken | RenewAssetOperationToken | Renews an O\\\\\\&M token for one hour. |
| CreateOperationTicket | Create an O&M request (supported only in V3.2.44 and later) | Creates an O&M request. When an administrator enables O&M approval in control policies, O&M engineers must create an O&M request and obtain administrator approval before performing O&M operations. |
Authorization rules (only for V3.2.40 and later)
|
API |
Title |
Description |
| CreateRule | CreateRule | You can create authorization rules to authorize multiple users to manage assets. You can also specify a validity period for an authorization rule. This way, you can manage users and assets in a more efficient manner and limit the time periods during which users can access assets. |
| ModifyRule | ModifyRule | Modifies the basic information of an authorization rule. |
| GetRule | GetRule | Queries the detailed information about an authorization rule. |
| ListRules | ListRules | Queries a list of authorization rules of a bastion host. |
| EnableRule | Enable an authorization rule | Enables an authorization rule. |
| DisableRule | DisableRule | Disables an authorization rule. |
| DeleteRule | DeleteRule | Deletes an authorization rule. |
Control policies (only for V3.2.40 and later)
|
API |
Title |
Description |
| CreatePolicy | Create control policy | Controls O&M behaviors through Settings for command control, command approval, protocol control, and access control policy to effectively prevent users from executing high-risk commands or performing misoperations, ensuring O&M security. |
| ModifyPolicy | ModifyPolicy | Modifies the basic information about a control policy. |
| GetPolicy | GetPolicy | Gets the details of a specified control policy. |
| ListPolicies | ListPolicies | Queries a list of control policies. |
| GetPolicyAssetScope | GetPolicyAssetScope | Queries the assets to which a control policy applies. |
| SetPolicyProtocolConfig | SetPolicyProtocolConfig | Sets the Remote Desktop Protocol (RDP), Secure Shell (SSH), and SSH File Transfer Protocol (SFTP) options for a control policy. |
| SetPolicyCommandConfig | SetPolicyCommandConfig | Specifies the commands that can or cannot be run by the users or on the assets associated with the policy and the commands that must be reviewed. |
| SetPolicyIPAclConfig | SetPolicyIPAclConfig | Specifies whether a source IP address can access the assets to which a control policy applies. |
| GetPolicyUserScope | GetPolicyUserScope | Queries the scope of users to whom a control policy applies. |
| SetPolicyAccessTimeRangeConfig | SetPolicyAccessTimeRangeConfig | Configures the logon period limits in a control policy. |
| SetPolicyAssetScope | Set the asset scope for a specified control policy | Sets the asset scope for a specified control policy. |
| SetPolicyUserScope | SetPolicyUserScope | Specifies the users to whom a control policy applies. |
| SetPolicyApprovalConfig | SetPolicyApprovalConfig | Configures the O\\&M approval setting in a control policy. |
| DeletePolicy | Delete a single control policy | Deletes a single control policy. |
Approvals (only for V3.2.37 and later)
|
API |
Title |
Description |
| ListApproveCommands | ListApproveCommands | Queries commands to be reviewed. |
| AcceptApproveCommand | Approve a single command | If an O&M engineer executes a command configured in a command approval control policy, the administrator receives an approval request for the command in the Bastionhost console. The command can be executed only after the administrator approves it. If the approval is rejected, the command cannot be executed. |
| RejectApproveCommand | RejectApproveCommand | If an O\\\\\\&M engineer attempts to run a command specified in the Command Approval section of the Create Control Policy page, the administrator is notified to review the command in the Bastionhost console. The command can be run only after it is approved by the administrator. |
| ListOperationTickets | Retrieve O&M applications pending approval | Retrieves the list of O&M applications that require approval. |
| AcceptOperationTicket | Approve an O&M request | If an administrator enables O&M approval in a control policy, an O&M engineer must submit an O&M request and obtain administrator approval before logging on to an asset. |
| RejectOperationTicket | RejectOperationTicket | If a Bastionhost administrator enables O\\\\\\\\\\\\&M Approval on the Create Control Policy page, O\\\\\\\\\\\\&M engineers can log on to assets to perform O\\\\\\\\\\\\&M operations only after the administrator approves their O\\\\\\\\\\\\&M applications. |
| ListTodoOpsTaskApprovals | Retrieve pending O&M approval tasks | Retrieves the list of pending automated O&M approval requests. |
| GetAutoOpsTask | Queries the details of a specified O&M task (supported only in V3.2.50 and later) | Queries the details of a specified O&M task. |
| AllowOperationTaskApproval | Approves an O&M task execution request | Approves an O&M task execution request. |
| RejectOperationTaskApproval | Reject an O&M task execution request | Rejects an O&M task execution request. |
System settings (only for V3.2.X)
|
API |
Title |
Description |
| GetInstanceADAuthServer | GetInstanceADAuthServer | Queries the settings of Active Directory (AD) authentication on a bastion host. |
| ModifyInstanceADAuthServer | ModifyInstanceADAuthServer | Updates the settings of the Active Directory (AD) authentication server of a bastion host. |
| GetInstanceTwoFactor | GetInstanceTwoFactor | Queries the settings of two-factor authentication on a bastion host. |
| ModifyInstanceTwoFactor | ModifyInstanceTwoFactor | Modifies the two-factor authentication settings of a bastion host. |
| ModifyInstanceLDAPAuthServer | ModifyInstanceLDAPAuthServer | Updates the settings of the Lightweight Directory Access Protocol (LDAP) authentication server of a bastion host. |
| GetInstanceLDAPAuthServer | GetInstanceLDAPAuthServer | Queries the settings of Lightweight Directory Access Protocol (LDAP) authentication on a bastion host. |
| GetInstanceStoreInfo | GetInstanceStoreInfo | Queries the storage usage of a Bastionhost instance. |
| CreateExportConfigJob | CreateExportConfigJob | Creates a configuration backup export task. Only one configuration backup export task can run at a time for a Bastionhost instance. |
| GetExportConfigJob | GetExportConfigJob | Retrieves the details of a configuration export task for a Bastionhost instance. |
Project management (canary release)
|
API |
Title |
Description |
| VerifyInstanceLDAPAuthServer | VerifyInstanceLDAPAuthServer | Tests the connectivity to the Lightweight Directory Access Protocol (LDAP) authentication server configured for a Bastionhost instance. Use this operation to validate your LDAP settings before you save them. |
| VerifyInstanceADAuthServer | VerifyInstanceADAuthServer | Tests the connectivity to the Active Directory (AD) authentication server configured for a Bastionhost instance. Use this operation to validate your AD settings before you save them. |
| ListUserGroupsForUser | Query user groups joined by a user | Queries the list of user groups that a user has joined. |
| AttachMembersToProject | Associate member accounts with a specified project | Associates members with a project. |
| AttachProjectManagersToProjectAuthorization | Associate project administrators in project authorization | Associates project authorization administrators. |
| AttachProjectsToProjectAuthorization | Specify manageable projects in a project authorization | Specifies manageable projects in a project authorization. This operation can be called only when the ScopeType parameter returned by the GetProjectAuthorization operation is 2 for the corresponding project authorization. |
| AttachProjectsToReviewRule | Specify auditable projects in an audit rule | Associates projects with the scope of an audit policy. This operation can be invoked only when the ScopeType parameter returned by the GetReviewRule operation is 2. |
| AttachReviewersToReviewRule | Associate auditors with a specified audit policy | Associates auditors with an audit policy. |
| CreateProject | Create a project | Creates a project. |
| CreateProjectAuthorization | Create project authorization | Creates a project authorization. |
| CreateProjectNotifyReceiver | Add a notification recipient to a project | Creates a notification recipient for a project. |
| CreateReviewRule | Create an audit policy | Creates an audit policy. |
| DeleteProjectAuthorizations | Delete a project authorization | Deletes a project authorization. |
| DeleteProjectNotifyReceivers | Delete notification recipients from a specified project | Deletes notification recipients from a project. |
| DeleteProjects | Delete projects | Deletes projects in batches. |
| DeleteReviewRules | Delete an audit policy | Deletes an audit policy. |
| DetachMembersFromProject | Remove associated member accounts from a project | Removes members from a project. |
| DetachProjectManagersFromProjectAuthorization | Remove a project administrator from project authorization | Removes a project administrator from project authorization management. |
| DetachProjectsFromProjectAuthorization | Remove projects from a specified project authorization | Removes projects from the scope of a project authorization. This operation can be called only when the ScopeType parameter returned by the GetProjectAuthorization operation is 2. |
| DetachProjectsFromReviewRule | Remove projects associated with an audit policy | Removes projects from the scope of an audit policy. This operation can be called only when the ScopeType parameter in the corresponding audit policy returned by the GetReviewRule operation has a value of 2. |
| DetachReviewersFromReviewRule | Remove an auditor associated with an audit policy | Unbinds an auditor from an audit rule. |
| GetProject | Query project details | Queries the details of a specified project. |
| GetProjectAuthorization | Get project authorization details | Queries the details of a project authorization. |
| GetReviewRule | Get audit policy details | Queries the details of an audit policy. |
| ListMembersNotForProject | Query associable member accounts | Queries the list of members that are not occupied by other projects. |
| ListProjectNotifyReceivers | Query notification recipients for a specified project | Queries the list of notification recipients for a project. |
| ListProjectsForProjectAuthorizationPrincipal | Query projects manageable by the current user | Queries the list of projects that the current user can manage. |
| ListProjectsNotForProjectAuthorization | Query projects not associated with a project authorization | Queries the list of projects that are not associated with a project authorization. |
| ListProjectsNotForReviewRule | Get projects not associated with a specified audit policy | Queries the list of projects that are not associated with an audit policy. |
| ListReviewRules | Query audit policies | Queries the list of audit policies. |
| ModifyDatabasesProject | Move database instances to a different project in batches | Moves database instances to a different project in batches. |
| ModifyHostsProject | Move hosts to a different project in a batch | Moves hosts to a different project in a batch. |
| ModifyProject | Edit project information | Modifies a project. |
| ModifyProjectAuthorization | Edit project authorization information | Modifies project authorization. |
| ModifyProjectNotifyReceiver | Edit notification recipient information for a specified project | Modifies the notification recipient of a project. |
| ModifyReviewRule | Edit audit policy | Modifies an audit policy. |