All Products
Search
Document Center

Resource Access Management:AliyunServiceRolePolicyForSFMFineTuning

Last Updated:Apr 14, 2026

AliyunServiceRolePolicyForSFMFineTuning is the authorization policy dedicated to a service-linked role. The policy is automatically attached to a service role when the service role is created. Then, the service-linked role is authorized to access other cloud services. This policy is updated by the relevant Alibaba Cloud service. Do not attach this policy to a RAM identity other than a service-linked role.

Policy details

  • Type: service system policy

  • Creation time: 11:17:44 on February 28, 2026

  • Update time: 08:56:54 on April 14, 2026

  • Current version: v4

Policy content

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "fc:ListFunctions",
        "fc:InvokeFunction",
        "fc:GetConcurrencyConfig",
        "fc:GetFunction",
        "fc:GetProvisionConfig",
        "fc:GetTrigger",
        "fc:CreateFunction",
        "fc:CreateTrigger",
        "fc:CreateVpcBinding",
        "fc:DeleteConcurrencyConfig",
        "fc:DeleteFunction",
        "fc:DeleteProvisionConfig",
        "fc:DeleteTrigger",
        "fc:DeleteVpcBinding",
        "fc:InvokeFunction",
        "fc:PutConcurrencyConfig",
        "fc:PutProvisionConfig",
        "fc:UpdateFunction",
        "fc:UpdateTrigger",
        "fc:ListConcurrencyConfigs",
        "fc:ListProvisionConfigs",
        "fc:ListTriggers",
        "fc:ListVpcBindings",
        "fc:ListInstances",
        "fc:EnableFunctionInvocation",
        "fc:DisableFunctionInvocation",
        "fc:DeleteConcurrencyConfig",
        "fc:GetConcurrencyConfig",
        "fc:ListConcurrencyConfigs",
        "fc:PutConcurrencyConfig",
        "fc:CreateLayerVersion",
        "fc:DeleteLayerVersion",
        "fc:GetLayerVersion",
        "fc:GetLayerVersionByArn",
        "fc:ListLayerVersions",
        "fc:ListLayers",
        "fc:PutLayerACL",
        "fc:CreateSession",
        "fc:GetSession",
        "fc:UpdateSession",
        "fc:ListSessions",
        "fc:PutScalingConfig",
        "fc:DeleteScalingConfig",
        "fc:GetScalingConfig",
        "fc:ListScalingConfigs",
        "fc:PublishFunctionVersion",
        "fc:ListFunctionVersions",
        "fc:DeleteFunctionVersion"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "log:GetLogStoreLogs",
        "log:GetLogStoreHistogram",
        "log:GetLogStore",
        "log:CreateLogStore",
        "log:DeleteLogStore",
        "log:CreateProject",
        "log:DeleteProject",
        "log:GetProject",
        "log:CreateIndex",
        "log:GetIndex"
      ],
      "Resource": "acs:log:*:*:project/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "nas:ClientMount",
        "nas:DescribeCpfsAccessPoints",
        "nas:DescribeFileSystems"
      ],
      "Resource": "*"
    },
    {
      "Action": "ram:DeleteServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "fine-tuning.sfm.aliyuncs.com"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "oss:ListBuckets",
        "oss:GetBucketLocation",
        "oss:GetBucketTagging"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "oss:DoMetaQuery",
        "oss:GetBucketInfo",
        "oss:GetBucketStat",
        "oss:GetBucketTransferAcceleration",
        "oss:GetCnameToken",
        "oss:GetMetaQueryStatus",
        "oss:GetObject",
        "oss:GetObjectTagging",
        "oss:DescribeRegions",
        "oss:ListObjects",
        "oss:ListObjectVersions",
        "oss:DoMetaQuery",
        "oss:GetMetaQueryStatus"
      ],
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "oss:BucketTag/bailian-finetune-access": [
            "read"
          ]
        }
      }
    }
  ]
}

References