A RAM role that trusts an Alibaba Cloud account enables cross-account access and temporary authorization, allowing a RAM user from the trusted account to assume the role. This topic describes how to grant permissions to a RAM role for tasks, such as decrypting content with Media Processing Service (MPS).
Prerequisites
A RAM user must be created and authorized to access Media Processing Service (MPS). For more information, see Create and authorize a RAM user.
Create a RAM role
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
On the Roles page, click Create Role.
-
On the Create Role page, set Principal Type to Cloud Account, specify the details of the Alibaba Cloud account, and then click OK.
-
Current Account: Select this option to allow all RAM users and RAM roles under the current Alibaba Cloud account to assume the role. SelectCurrent Account.
-
Other Account: Select this option to allow all RAM users and RAM roles from another Alibaba Cloud account to assume the role. SelectOther Account and then enter the ID of the other Alibaba Cloud account (main account). This is primarily used for cross-account resource access. For more information, see Access resources across Alibaba Cloud accounts.You can find your Alibaba Cloud account (main account) ID on the Security Settings page.
-
-
(Optional) To restrict the role to specific RAM users or RAM roles, click Switch to Policy Editor to modify the trust policy.
The editor supports two modes: Visual Editor and JSON Editor. In the following example, the RAM role can only be assumed by the RAM user
Aliceunder the current Alibaba Cloud account (AccountID=100******0719).-
Visual Editor
In the Principal section, add the RAM user.
Click the Edit link next to Cloud Account and enter the ID of the trusted account.
In the Add Principal dialog box, select Current Account for Cloud Account and RAM user for Identity Type. Enter the target username, such as Alice, in the User Name field, and then click OK.
-
JSON Editor
In the
RAMfield of thePrincipalobject, enter the full ARN of the RAM user.{ "Version": "1", "Statement": [ { "Effect": "Allow", "Principal": { "RAM": "acs:ram::100******0719:user/Alice" }, "Action": "sts:AssumeRole" } ] }
-
-
In the Create Role dialog box, enter a Role Name, and then click OK.
Grant permissions to the role
Grant permissions to the RAM role.
On the Roles page, find the RAM role and click Grant Permission in the Actions column.
For Resource Scope, select Account.
Resource scope
Description
Account
The permissions take effect on resources within the current Alibaba Cloud account.
resource
The permissions take effect on resources in the specified resource group.
The Principal is automatically set to the current role. You do not need to change it.
For Policies, select System Policy. In the Policy Name column, click the name of a policy to add it. After adding the required policies, click OK, and then click Close.
NoteTo adjust the permissions for the role, such as by adding or removing policies, repeat this step.
Grant a RAM user the permission to assume the role.
In the left-side navigation pane of the RAM console, choose . On the Policies page, click Create Policy.
Click the JSON Editor tab.
In the policy editor, set the Resource field to the ARN of the RAM role that you created. Set the Action field as needed.
Click Optimize at the top of the page, and then click Perform to apply advanced optimizations to the policy content.
The advanced policy optimization feature does the following:
Splits resources or conditions for incompatible actions.
Narrows down resource scopes.
Removes duplicate statements or merges statements.
On the Create Policy page, click OK.
In the Create Policy dialog box, enter a policy name and Description, and then click OK.
In the left-side navigation pane, choose .
Find the RAM user to authorize and click Add Permissions in the Actions column.
For Select Policy, select Custom Policy, and then click the policy you created. Click OK.