All Products
Search
Document Center

Elastic High Performance Computing:Reference for E-HPC system policies

Last Updated:Aug 21, 2025

This topic describes all system policies supported by Alibaba Cloud Elastic High Performance Computing (E-HPC) and the corresponding permission descriptions for you to refer to when you grant permissions to Resource Access Management (RAM) identities.

What is a system policy?

A policy defines a set of permissions that are described based on the policy structure and syntax. You can use policies to describe the authorized resource sets, authorized operation sets, and authorization conditions. Alibaba Cloud RAM provides system policies and custom policies. All system policies are created and updated by Alibaba Cloud. You can use system policies, but you cannot modify them. You can manage and update custom policies based on your business requirements. You can create, update, and delete custom policies. During service iteration, E-HPC adds new permissions to system policies to support new features and capabilities. The update of a system policy affects all RAM identities to which the policy is attached. RAM identities include RAM users, RAM user groups, and RAM roles. For more information about RAM policies, see Policy overview.

Note

System policies are designed for new users to quickly get started with Alibaba Cloud services in the Alibaba Cloud Management Console. System policies also apply to programmatic access methods, such as API operations and CLI commands. However, in programmatic access scenarios, we recommend that you use finer-grained custom policies to allow only the designated users to access only the specified resources based on actual requirements.

System policies can be classified into service system policies, service role policies, and service-linked role policies. Some cloud services support only one or two of the three types of policies. For more information about the policy types supported by Cloud Control API, see the following section.

System policies

AliyunEHPCFullAccess

You can attach the AliyunEHPCFullAccess policy to RAM users and roles to grant them full permissions on E-HPC.

For more information, see AliyunEHPCFullAccess.

AliyunEHPCReadOnlyAccess

You can attach the AliyunEHPCReadOnlyAccess policy to RAM users and roles to grant them read-only permissions on E-HPC.

For more information, see AliyunEHPCReadOnlyAccess.

References

By default, RAM identities do not have any permissions. RAM identities can access cloud resources within an Alibaba Cloud account only after an account administrator grants the required permissions to the RAM identities. To ensure resource security, we recommend that you grant only required permissions to the RAM identities based on the principle of least privilege. For more information, see the following topics: