Before a RAM user calls the CloudMonitor API, the Alibaba Cloud account to which the RAM user belongs must attach policies to the RAM user.
In CloudMonitor, you can grant permissions only by action rather than by resource.
You can describe resources only by using the wildcard character (
The actions on CloudMonitor are divided into two types: the actions on monitoring data and the actions on the instances of the cloud services that CloudMonitor monitors. The RAM user must have the permissions to perform both types of actions because the monitoring data in CloudMonitor is collected from the monitored instances of the cloud services. If the RAM user does not have the permissions to perform the actions on the monitored instances, the RAM user cannot query the monitored instances, query the monitoring data collected from the instances, and configure alerts based on the monitoring data.
If you have no special requirements, we recommend that you use the default system policies provided by Resource Access Management (RAM): AliyunCloudMonitorFullAccess and AliyunCloudMonitorReadOnlyAccess. These two system policies contain the permissions to read and manage CloudMonitor data and the permissions to read data about the monitored instances.
*) to describe resources. Example:
- Action for managing CloudMonitor permissions is
- The following actions can be used to grant the read-only permissions on CloudMonitor.
- The following table describes the actions for querying the instances in Alibaba Cloud
services that CloudMonitor monitors.
Note The number of cloud services that CloudMonitor can monitor continually increases. Therefore, the following table lists only the actions for querying instances in main cloud services.
Alibaba Cloud service Action Elastic Compute Service (ECS)
Server Load Balancer (SLB)
Virtual Private Cloud (VPC)
Object Storage Service (OSS)
Alibaba Cloud CDN
Message Service (MNS)
Auto Scaling (ESS)
ApsaraDB for Memcache
ApsaraDB for Redis
ApsaraDB for HBase
Time Series Database (TSDB)
HybridDB for MySQL
AnalyticDB for PostgreSQL
ApsaraDB for MongoDB
Anti-DDoS Pro and Anti-DDoS Premium
Cloud Enterprise Network (CEN)
Message Queue for Apache Kafka
Secure CDN (SCDN)
Dynamic Route for CDN (DCDN)