All Products
Search
Document Center

Realtime Compute for Apache Flink:Authorize access to a Fluss cluster

Last Updated:Aug 10, 2026

This topic describes the permission model of Stream Storage for Apache Fluss and explains how to grant RAM users access to a Fluss cluster.

Authorization scenarios

Cannot access the Realtime Compute Fluss console

  • The console reports an error and fails to load the content.

    The error message No permission to perform this action is displayed, the error code is NoPermission, and the Stream Storage Fluss cluster list shows No Data.

  • After you enter the cluster console, a message appears stating that you do not have the required access permissions.

Note

You do not have the required permissions to access the Realtime Compute Fluss console. Contact your Alibaba Cloud account administrator and follow the steps in RAM authorization to grant your account at least read-only access to Stream Storage Fluss (AliyunFlussReadOnlyAccess). Once authorized, access the console again or refresh the page.

No accessible Fluss clusters

When you access a Fluss cluster by using a direct link, the page reports that no clusters are accessible.

image

Note

You do not have permissions for the current Fluss cluster. Contact the cluster owner or a user with the Super Admin role to follow the steps in User authorization and grant you the General User role or a higher role.

No or missing databases

On the Data Management page, the Catalog section shows No Data.

Note

You do not have resource permissions for a database in the current Fluss cluster. Contact the cluster owner or a user with the Super Admin role to follow the steps in Resource authorization and grant you at least read-only access to the relevant database.

RAM authorization

By default, RAM users cannot access the Fluss console. To allow a RAM user to view the console, you must attach a Fluss-related RAM system policy to the user.

Permission policies

Permission policy

Description

AliyunFlussReadOnlyAccess

Read-only access. Users with this policy can log on to the Fluss console to view information for all clusters, such as the cluster list, configurations, and monitoring data.

AliyunFlussFullAccess

Full management access. Users with this policy can perform any operation on all Fluss resources within the account, including creating and purchasing clusters.

Procedure

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Identities > Users.

  3. On the Users page, find the target RAM user and click Add Permissions in the Actions column.

  4. In the Add authorization panel, add a permission for the RAM user.

    Set Authorize Scope to Alibaba Cloud Account. In the permission policy search box, enter Flus, and then select AliyunFlussReadOnlyAccess (read-only access to Stream Storage Fluss) or AliyunFlussFullAccess (management access to Stream Storage Fluss) as needed.

  5. Click OK.

  6. Click Close.

Note

After you complete RAM authorization, you must also perform User authorization or Resource authorization to grant the RAM user access to the corresponding Fluss cluster or resources.

User authorization

If a RAM user needs to perform operations in a specific cluster, a cluster administrator must add the RAM user as a member of the cluster in the Fluss console.

  1. Log on to the Realtime Compute console.

  2. Select the Streaming Storage Fluss tab, find the target cluster, and click Console in the Actions column to go to the Fluss cluster console.

  3. In the left-side navigation pane, click Security. On the User Management tab, click Add User.

  4. Enter the user's Account ID and select a role.

    Role

    Description

    Super Admin

    Grants the highest administrative permissions for the cluster. This role can manage users and view all resources.

    General User

    Grants access to the cluster. To specify which databases this user can operate on, you must also perform Resource authorization.

  5. Click OK to complete the authorization.

Resource authorization

You can grant a RAM user specific resource permissions directly. This action also automatically adds the user as a member of the cluster.

  1. Log on to the Realtime Compute console.

  2. Select the Streaming Storage Fluss tab, find the target cluster, and click Console in the Actions column to go to the Fluss cluster console.

  3. In the left-side navigation pane, click Security. On the Resource Authorization tab, click Add Authorization.

  4. Select the database to authorize, enter the user's Account ID, and select a role.

    Role

    Description

    Admin

    Grants all permissions for the specified database. This role can grant roles to other users, but only within the scope of its own permissions.

    Developer

    Grants permissions to create, delete, update, query, and perform read and write operations on the specified database and all tables in it.

    Read/Write User

    Grants permissions to perform read and write operations on the specified database and all tables in it.

    Analyst

    Grants permissions to perform read operations on the specified database and all tables in it.

  5. Click OK to complete the authorization.