You can use Resource Access Management (RAM) to grant a RAM user the permissions required to manage Data Transmission Service (DTS), and then use the RAM user to access DTS.
Prerequisites
The RAM user must have permissions to access cloud resources under your Alibaba Cloud account, such as ApsaraDB RDS and ECS instances. This allows DTS to retrieve related resource information when you configure a DTS task. For more information, see Authorize DTS to access cloud resources.
Limitations
-
You cannot use a RAM user to configure a data synchronization task whose destination is a MaxCompute project. Use your Alibaba Cloud account instead.
-
When you configure a DTS task as a RAM user, if the database is accessed through Database Gateway (DG) or Cloud Enterprise Network (CEN), you must also attach the AliyunDGFullAccess or AliyunCENFullAccess policy to the RAM user.
System policies
DTS provides two system policies for authorization: a read-write policy and a read-only policy.
The authorization policies do not support API-level access control.
-
Read-write policy: AliyunDTSFullAccess.
Grants full permissions on DTS. A RAM user with this policy can purchase, configure, and manage DTS instances.
-
Read-only policy: AliyunDTSReadOnlyAccess.
Grants read-only permissions on DTS. A RAM user with this policy can view the details and configurations of all DTS tasks under the Alibaba Cloud account but cannot modify them.
NoteChanges include purchasing, configuring, and managing DTS instances.
Procedure
-
Log on to the RAM console with your Alibaba Cloud account.
-
Optional: Create a RAM user.
For more information, see Create a RAM user.
-
In the left-side navigation pane, choose .
-
On the User page, find the target RAM user and click Add Permissions in the Operation column.
-
In the Add Permissions panel, select an authorization scope. Choose Alibaba Cloud Account to apply the policy to all resources in your account, or Specific Resource Group to limit the policy to a specified resource group. Important: Authorization by resource group is effective only for supported cloud services and resource types. For more information, see Services that work with resource group.
-
From the Select Policy drop-down list, select System Policy.
-
In the search box, enter dts to display the system policies related to DTS.
-
Click the desired policy to add it to the Selected section.
NoteFor more information about the policies, see System policies.
-
- Click OK.
-
Click Cancel to grant the permissions.
NoteFor more information, see Manage the permissions of a RAM user.
What to do next
Log on to the Alibaba Cloud Management Console as a RAM user.