All Products
Search
Document Center

Resource Access Management:AliyunServiceRolePolicyForSFMAccessApiGateway

Last Updated:Sep 19, 2025

AliyunServiceRolePolicyForSFMAccessApiGateway is the authorization policy dedicated to a service-linked role. The policy is automatically attached to a service role when the service role is created. Then, the service-linked role is authorized to access other cloud services. This policy is updated by the relevant Alibaba Cloud service. Do not attach this policy to a RAM identity other than a service-linked role.

Policy details

  • Type: service system policy

  • Creation time: 16:45:16 on September 11, 2025

  • Update time: 07:15:00 on September 19, 2025

  • Current version: v6

Policy content

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "apig:GetService",
        "apig:CreateService",
        "apig:ListServices",
        "apig:DeleteService",
        "apig:GetHttpApiRoute",
        "apig:DeleteHttpApiRoute",
        "apig:UndeployHttpApi",
        "apig:CreateHttpApi",
        "apig:GetEnvironment",
        "apig:GetGateway",
        "apig:GetConsumer",
        "apig:QueryConsumerAuthorizationRules",
        "apig:RemoveConsumerAuthorizationRule",
        "apig:CreateConsumerAuthorizationRules",
        "apig:CreateConsumer",
        "apig:DeleteConsumer",
        "apig:ListConsumers",
        "apig:UpdateConsumer",
        "apig:DeployHttpApi",
        "apig:UpdateHttpApiRoute",
        "apig:CreateHttpApiRoute",
        "apig:ListDomains",
        "apig:GetDomain",
        "apig:CreateDomain",
        "apig:DeleteDomain",
        "apig:UpdateDomain",
        "apig:ListHttpApis",
        "apig:ListGateways",
        "apig:CreateAndAttachPolicy",
        "apig:UpdateAndAttachPolicy",
        "apig:DeletePolicyAttachment",
        "apig:ListPolicies",
        "apig:ListPolicyClasses"
      ],
      "Resource": "*"
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "api-gateway-access.sfm.aliyuncs.com"
        }
      }
    }
  ]
}

References