The service-linked role AliyunServiceRoleForCloudMonitor is a Resource Access Management (RAM) role that CloudMonitor uses to access other Alibaba Cloud services in specific scenarios, such as agent installation, log monitoring, hybrid cloud monitoring, and alert processing.
Use cases
CloudMonitor uses the service-linked role in the following scenarios:
Host Monitoring agent installation: CloudMonitor uses the service-linked role to access Cloud Assistant when automatically installing the Host Monitoring agent.
Log monitoring: CloudMonitor uses the service-linked role to gain read access to Log Service.
Hybrid Cloud Monitoring: When you use Hybrid Cloud Monitoring to import data from Alibaba Cloud services and analyze resource usage, CloudMonitor uses the service-linked role to query instances of other Alibaba Cloud services.
Alert feature: CloudMonitor uses the service-linked role to query instances of other Alibaba Cloud services when processing alerts.
Permissions
The service-linked role for CloudMonitor has the following role name and policy:
Role name: AliyunServiceRoleForCloudMonitor
Policy name: AliyunServiceRolePolicyForCloudMonitor
-
Policy description: Grants permission to use Cloud Assistant to view instance status, run commands, and view command output for all instances in your account.
Create the service-linked role
CloudMonitor automatically creates the service-linked role when it installs the Host Monitoring agent. No manual action is required.
Delete the service-linked role
Before deleting the service-linked role, turn off the automatic agent installation switch. If the switch is on, the role cannot be deleted.
-
On the Host Monitoring page, ensure the Automatically Install CloudMonitor Agent on Newly Purchased ECS Instances switch is off.
If the
Automatically Install CloudMonitor Agent on Newly Purchased ECS Instances
switch is On, click the switch to turn it Off.
-
Delete the service-linked role.
For details, see
.