All Products
Search
Document Center

E-MapReduce:Alibaba Cloud account role authorization

Last Updated:Aug 20, 2026

Before you use EMR on ACK, you must grant the default system role AliyunEMROnACKDefaultRole to your Alibaba Cloud account. This topic describes two methods to grant this role.

Automated authorization

Typically, when you use EMR on ACK for the first time, you are prompted to authorize automatically.

  1. Log on to the E-MapReduce console.

  2. In the left navigation pane, click EMR on ACK.

  3. On the EMR on ACK page, click Authorize Now.

  4. On the RAM Quick Authorization page, click Authorize at the bottom of the page.

    The AliyunEMROnACKDefaultRole role is selected by default.

Manual authorization

If you accidentally delete the AliyunEMROnACKDefaultRole role or change a policy, making EMR on ACK unavailable, follow these steps to authorize again.

  1. Create a role.

    1. Log on to the Resource Access Management (RAM) console.

    2. In the left navigation pane, choose Identities > Role.

    3. On the Role page, click Create Role.

    4. In the Create Role panel, set principal type to cloud service and principal name to ECS. Then, click OK.

      For more information about trusted entities, see Create a RAM role and grant permissions to the role.

    5. Enter the required role information and click OK.

      Set role name to AliyunEMROnACKDefaultRole. If the AliyunEMROnACKDefaultRole role already exists, do not create it again.

  2. Attach policies.

    1. On the Permission Settings tab, click Input and Attach.

    2. In the Input and Attach panel, select a permission type, enter a policy name, and then click OK.

      You must attach the following three policies to the AliyunEMROnACKDefaultRole role:

      • Policy 1: system policy (AliyunEMROnACKDefaultRolePolicy)

        {
            "Version": "1",
            "Statement": [
                {
                    "Action": [
                        "cs:CreateCluster",
                        "cs:GetClusterById",
                        "cs:GetClusters",
                        "cs:GetUserConfig",
                        "cs:DeleteCluster",
                        "cs:AttachInstances",
                        "cs:DescribeClusterLogsRequest",
                        "cs:GetClusterLogs",
                        "cs:GetUserQuota",
                        "cs:DescribeClusterNodes",
                        "cs:GetNodepoolDetail",
                        "cs:GetNodepools",
                        "cs:UpdateNodepool",
                        "cs:ScaleNodepools",
                        "cs:DescribeClusterInnerServiceKubeconfig",
                        "cs:RevokeClusterInnerServiceKubeconfig",
                        "ecs:DescribeInstances"
                    ],
                    "Resource": "*",
                    "Effect": "Allow"
                }
            ]
        }
      • Policy 2: system policy (AliyunEMRFullAccess)

        {
            "Version": "1",
            "Statement": [
                {
                    "Action": "emr:*",
                    "Resource": "*",
                    "Effect": "Allow"
                },
                {
                    "Action": [
                        "cms:QueryMetricList",
                        "ram:GetRole",
                        "ram:ListRoles",
                        "ram:ListUserBasicInfos",
                        "ecs:DescribeZones",
                        "ecs:DescribeInstanceTypes",
                        "ecs:DescribeKeyPairs",
                        "ecs:DescribeAvailableResource",
                        "ecs:DescribeInstances",
                        "ecs:DescribeSpotPriceHistory",
                        "ecs:DescribeSpotAdvice",
                        "ecs:DescribeInstanceStatus",
                        "ecs:DescribeDeploymentSets",
                        "vpc:DescribeVpcs",
                        "vpc:DescribeVSwitches",
                        "oss:ListBuckets",
                        "dlf:DescribeRegions",
                        "dlf:GetRegionStatus",
                        "dlf:ListCatalogs"
                    ],
                    "Resource": "*",
                    "Effect": "Allow"
                },
                {
                    "Action": "ram:PassRole",
                    "Resource": "*",
                    "Effect": "Allow",
                    "Condition": {
                        "StringEquals": {
                            "acs:Service": "emr.aliyuncs.com"
                        }
                    }
                },
                {
                    "Action": "quotas:ListProductQuotas",
                    "Resource": "acs:quotas:*:*:quota/ecs/*",
                    "Effect": "Allow"
                },
                {
                    "Action": "kms:DescribeAccountKmsStatus",
                    "Resource": "*",
                    "Effect": "Allow"
                }
            ]
        }
      • Policy 3: custom policy (EmrOnAckPolicyV2)

        {
            "Version": "1",
            "Statement": [
                {
                    "Action": [
                        "ram:*"
                    ],
                    "Resource": [
                        "acs:ram:*:*:domain/*",
                        "acs:ram:*:*:application/*"
                    ],
                    "Effect": "Allow"
                }
            ]
        }
      Note

      After creating the role and attaching the preceding policies, you can use EMR on ACK.