All Products
Search
Document Center

E-MapReduce:Grant OSS and DLF permissions

Last Updated:Jun 20, 2026

This topic describes how to grant the AliyunOSSFullAccess and AliyunDLFFullAccess permissions, which allow you to use the DLF service and enable components to access OSS without an AccessKey.

Prerequisites

A Kubernetes cluster is required. For more information, see Create an ACK dedicated cluster (discontinued) or Create an ACK managed cluster.

Procedure

  1. Log on to the ACK console.

  2. On the Clusters page, find the target cluster and click Details in the Actions column.

  3. On the Basic Information page, in the Cluster Resources section, click the link for Worker RAM Role.

  4. Grant permissions.

    1. On the Role page, click Add Authorization.

    2. In the Add Authorization panel, select and add the AliyunOSSFullAccess and AliyunDLFFullAccess system policies.

    3. Click Grant permissions.