Create a Resource Access Management (RAM) user and grant permissions to the user. This lets you assign different permissions to different users to access your resources. Using RAM users helps you avoid security risks caused by leaked AccessKey pairs or logon passwords. To use ApsaraVideo Media Processing (MPS), a RAM user requires permissions for the following services: ApsaraVideo Media Processing (MPS), Object Storage Service (OSS), Resource Access Management (RAM), Alibaba Cloud CDN (CDN), and Simple Message Queue (formerly MNS). This topic describes how to create a RAM user and grant the required permissions to use MPS.
If you receive the error message User not authorized to operate on the specified resource when you use MPS, check whether your RAM user has full control permissions for MPS. If not, grant the required permissions as described in this topic.
Procedure
Log on to the RAM console by using an Alibaba Cloud account or a RAM user who has administrative rights.
In the left-side navigation pane, choose Identities > Users.
On the Users page, click Create User.
In the User Account Information section of the Create User page, configure the following parameters:
Logon Name: The logon name can be up to 64 characters in length, and can contain letters, digits, periods (.), hyphens (-), and underscores (_).
Display Name: The display name can be up to 128 characters in length.
Tag: Click the
icon and enter a tag key and a tag value. You can add one or more tags to the RAM user. This way, you can manage the RAM user based on the tags.
NoteYou can click Add User to create multiple RAM users at a time.
For Access Mode, select Access with permanent AccessKey.
Click OK and complete the phone verification. The system automatically generates an AccessKey for the RAM user.
In the Actions column, click Copy to save the user information, such as the logon name, logon password, and AccessKey.
ImportantMake sure to save the logon password and AccessKey information (AccessKey ID and AccessKey secret). You cannot retrieve this information later.
Return to the user list. In the Actions column of the new RAM user, click Add Permissions.
In the Add Permissions panel, configure the authorization information.
Select the scope of the authorization.
Type
Description
Entire Alibaba Cloud Account
The permissions take effect within the current Alibaba Cloud account.
Specify a resource group
The permissions take effect within the specified resource group.
Enter the principal.
The principal is the RAM user to whom you want to grant permissions.
Select an access policy. For more information about the services that require authorization and the supported access policies, see Access policy details.
Use a system policy
Enter the policy name in the search box and click the name in the search results to select it.
Use a custom policy
A custom policy allows for more fine-grained permission management. You must create a custom policy before you can select it. For more information, see Create a custom policy.
Click Confirm New Authorization.
Access policy details
To use MPS, you must grant permissions for MPS and OSS. You can also grant permissions for Simple Message Queue (formerly MNS) and Alibaba Cloud CDN. You must use a system policy to grant permissions for MPS. For other services, you can use a system policy or a custom policy.
Required products | Description | Required | System policy | Custom policy |
ApsaraVideo Media Processing (MPS) | To use MPS, you must grant all permissions for MPS. | Yes | Full read and write permissions for MPS: AliyunMTSFullAccess | Not supported |
Object Storage Service (OSS) | To use MPS, you must grant read and write permissions for OSS. | Yes | Full read and write permissions for OSS: AliyunOSSFullAccess | Supported. Create the policy first, and then grant the permissions. |
Simple Message Queue (formerly MNS) | If you use Simple Message Queue (formerly MNS) to subscribe to tracking tasks, you must grant permissions for MNS. | No, optional | Full read and write permissions for MNS: AliyunMNSFullAccess | |
CDN Playback Acceleration | If you use MPS to configure CDN for accelerated playback, you must grant permissions for CDN. | No, optional | Full read and write permissions for CDN: AliyunCDNFullAccess |
Create a custom policy
Log on to the RAM console with your Alibaba Cloud account.
In the navigation pane on the left, choose Permission Management > Access Policies.
Click Create Policy and select the Script Editor tab.
Configure the access policy. Enter the policy content, and then click OK.
NoteYou can import a system policy or copy the required policy code from the examples below into the code box.
Enter basic information such as the Name and Note.
Click OK to create the custom policy.
Example: Restrict access to MPS by IP address and time period
The RAM user can access MPS only from the 192.0.2.0/24 and 203.0.113.2 IP addresses.
The RAM user can access MPS only before 17:00 on August 12, 2019 (UTC+8).
{
"Version": "1",
"Statement": [{
"Effect": "Allow",
"Action": [
"mts:*",
"mts-inner:*"
],
"Resource": "*",
"Condition": {
"NotIpAddress": {
"acs:SourceIp": [
"192.0.2.0/24",
"203.0.113.2"
]},
"DateLessThan": {
"acs:CurrentTime": "2019-08-12T17:00:00+08:00"
}
}
]
}Example: OSS custom policy
Grants all permissions on the specified input and output buckets.
Grants the permission to view the bucket list.
{
"Version": "1",
"Statement": [{
"Effect": "Allow",
"Action": [
"oss:ListBuckets"
],
"Resource": "*"
}, {
"Effect": "Allow",
"Action": [
"oss:*"
],
"Resource": [
"acs:oss:*:*:$InputBucket",
"acs:oss:*:*:$InputBucket/*",
"acs:oss:*:*:$OutputBucket",
"acs:oss:*:*:$OutputBucket/*
]
}
]
}Parameter description:
Parameter | Description |
oss:ListBuckets | This is a required permission for a RAM user to operate OSS with a visualization tool. After logging on, the RAM user can see the list of all buckets. However, the user can only operate the $InputBucket and $OutputBucket buckets that are granted permissions. This permission can only be granted for all buckets, not for a specific bucket. |
oss:* | Represents all OSS permissions. You can replace it with more specific operation permissions as needed. "oss:GetObject", "oss:PutObject", "oss:GetObjectAcl", "oss:PutObjectAcl", "oss:AbortMultipartUpload", "oss:ListParts", "oss:RestoreObject", "oss:GetVodPlaylist", "oss:PostVodPlaylist", "oss:PublishRtmpStream", "oss:ListObjectVersions", "oss:GetObjectVersion", "oss:GetObjectVersionAcl", "oss:RestoreObjectVersion" |
$InputBucket | Replace this with the bucket where the MPS input files are located. |
$OutputBucket | Replace this with the bucket where the MPS output files are located. |
For more information, see Common examples of bucket policies.
Example: RAM authorization policy
Grants the permission to view roles.
{
"Version": "1",
"Statement": [{
"Effect": "Allow",
"Action": [
"ram:ListPoliciesForRole"
],
"Resource": "*"
}
]
}Example: MNS custom policy
Grants the permission to view all queue and topic lists.
Grants full read and write permissions only for the specified $QueueName and $TopicName.
{
"Version": "1",
"Statement": [{
"Effect":"Allow",
"Action":[
"mns:ListQueue",
"mns:ListTopic",
"mns:GetQueueAttributes",
"mns:GetTopicAttributes"
],
"Resource":"acs:mns:*:*:*"
}, {
"Effect": "Allow",
"Action": "mns:*",
"Resource": [
"acs:mns:$Region:$Uid:/queues/$QueueName",
"acs:mns:$Region:$Uid:/topics/$TopicName"
]
}
]
}Parameter description:
Parameter | Description |
$QueueName | The name of the MNS queue to be attached to the MPS queue or workflow. |
$TopicName | The name of the MNS notification subject and the name of the queue to attach to the pipeline or workflow. |
For more information, see Authorization policies and examples.
Example: CDN authorization policy
Grants the permission to view all CDN-accelerated domain names.
Grants full read and write permissions only for the specified CDN-accelerated domain name $DomainName.
{
"Version": "1",
"Statement": [{
"Effect": "Allow",
"Action": "cdn:*",
"Resource": "acs:cdn:*:$Uid:domain/$DomainName"
},{
"Effect": "Allow",
"Action": "cdn:Describe*",
"Resource": "*"
}
]
}Parameter description:
Parameter | Description |
$DomainName | The CDN-accelerated domain name. |
What to do next
After you create a RAM user and grant permissions, you can log on to the console as the RAM user. For more information, see Log on to the Alibaba Cloud Management Console as a RAM user.