All Products
Search
Document Center

Hologres:Service-linked role for Hologres

Last Updated:Aug 20, 2026

A service-linked role (SLR) is a type of Resource Access Management (RAM) role that is linked to a specific Alibaba Cloud service. It provides a secure way to delegate permissions, allowing one service to access another's resources on your behalf. To use Hologres to access services such as MaxCompute or Data Lake Formation (DLF), you must create the AliyunServiceRoleForHologresIdentityMgmt service-linked role. This topic describes how to create, authorize, view, and delete this role.

For more information about service-linked roles, see Service-linked roles.

AliyunServiceRoleForHologresIdentityMgmt

Role details

  • Service name: identity.hologres.aliyuncs.com

  • Role name: AliyunServiceRoleForHologresIdentityMgmt

  • Role description: Hologres uses this role to access your resources in MaxCompute on your behalf.

Create and authorize the role

You can create and authorize the AliyunServiceRoleForHologresIdentityMgmt role for new and existing instances.

Note

When a RAM user creates the AliyunServiceRoleForHologresIdentityMgmt role, the RAM user must have the CreateServiceLinkedRole permission. For more information, see Permissions required to create a service-linked role.

New instance

On the Hologres instance purchase page, you grant permissions by clicking Create Service-linked Role. This step occurs after you configure various instance parameters, such as Region, Instance Type, Availability Zone, Number of Gateway Nodes, Reserved Compute Units for Compute Group, Assign to Initial Compute Group, VPC, vSwitch, and an Instance Name. Clicking Create Service-linked Role completes the process.

Existing instance

If you do not need to purchase or upgrade an instance, you can create and authorize the service-linked role using the RAM Quick Authorization page or OpenAPI.

  • Log on to the Hologres console and go to RAM Quick Authorization.

  • Create and authorize the role by using OpenAPI

    1. Go to OpenAPI.

    2. On the Parameters tab, set ServiceName to identity.hologres.aliyuncs.com.

    3. Click Initiate Call.

      After the call is successful, you can view the role in the RAM console. On the Identities > Roles page of the Resource Access Management (RAM) console, search for AliyunServiceRoleForHologresIdentityMgmt to confirm that the service-linked role was created. The role type is displayed as Service-linked Role.

View the role

After the AliyunServiceRoleForHologresIdentityMgmt role is created, follow these steps to view its permission details.

  1. Log on to the RAM console using an Alibaba Cloud account or a RAM user with administrative permissions.

  2. In the navigation pane on the left, choose Identities > Role.

  3. On the Role page, search for AliyunServiceRoleForHologresIdentityMgmt and click the role name.

  4. On the Access Control tab, click the permission policy that is attached to the role.

  5. On the Policy Document tab, view the policy details.

    Note

    You can only view the permission policy for the AliyunServiceRoleForHologresIdentityMgmt service-linked role. You cannot modify it.

Delete the role

When you need to prevent Hologres from accessing the MaxCompute service, you can manually delete the AliyunServiceRoleForHologresIdentityMgmt role in the RAM console. This action revokes the permissions for Hologres to access other services. For detailed instructions, see Delete a RAM role.

Note
  • When you delete the AliyunServiceRoleForHologresIdentityMgmt service-linked role, its permissions are automatically revoked.

  • To delete the role as a RAM user, the user must have the DeleteServiceLinkedRole permission. For more information, see Permissions required to delete a service-linked role.

FAQ

  • Problem: When clicking Create Service-linked Role on the Hologres instance purchase page, the following error message appears: "The current user does not have the permissions to create a service-linked role. Contact your main account administrator or a permissions administrator to grant the required permissions to the user."

    Solution: Use your Alibaba Cloud account to grant the CreateServiceLinkedRole permission to the RAM user. For more information, see Service-linked roles.

  • Problem: When you try to access a MaxCompute foreign table from Hologres, one of the following errors might occur:

    • Error 1: ERROR: Fail to access foreign data as user 1063806044629636, AliyunServiceRoleForHologresIdentityMgmt does not exist.

    • Error 2: ErrorMessage=ODPS-0420095: Access Denied - Authorization Failed [4111], You have NO privilege 'odps:ActOnBehalfOfAnotherUser' on {acs:odps:regions_id:xxxxxx:users/default/aliyun/xxxxxx. Not pass by ram permission check.

    Solution: Re-authorize the AliyunServiceRoleForHologresIdentityMgmt service-linked role. For instructions, see the steps for an existing instance in the Create and authorize the AliyunServiceRoleForHologresIdentityMgmt role section.