Using PAI involves two types of authorization: RAM user authorization for activating and accessing cloud services, and service authorization for PAI to access other Alibaba Cloud services.
Authorize RAM users
An Alibaba Cloud account doesn't require additional authorization. A RAM user must be authorized before they can log on to the console or use APIs to access resources under the account. This section describes the following authorization methods for RAM users in PAI:
Attach Product system policies to a RAM user to quickly grant permissions for console access to PAI and its dependent cloud services.
Attach a custom policy to a RAM user.
Authorize a RAM user to activate PAI and purchase PAI resources
Attach the AliyunPAIFullAccess policy to a RAM user to allow them to activate PAI and purchase PAI resources. For more information, see Manage RAM user permissions.
AliyunPAIFullAccess includes administrator permissions for purchasing, creating, and deleting resources, as well as full workspace management. Use this policy with caution.
We recommend that you use the Alibaba Cloud account or configure a minimum required policy for the RAM user. For more information, see Create a custom policy.
Authorize a RAM user to use PAI sub-products
PAI provides Use workspaces to manage permissions for managing permissions. Add a RAM user as a workspace member and assign one of the following roles: Owner, Administrator, Algorithm Developer, Algorithm O&M, Labeling Administrator, or Visitor. For the permissions of each role, see Appendix: Roles and permissions.
For iTAG, also configure additional permissions. For more information, see Assign user roles.
EAS provides system policies for RAM user authorization:
Full EAS permissions:
AliyunPAIEASFullAccess.Read-only EAS permissions:
AliyunPAIEASReadOnlyAccess.
For most AI Acceleration features, only sub-product permissions for model development, training, and inference are required. No additional authorization is needed. However, the dataset acceleration feature requires the RAM user to have both
AliyunPAIFullAccessandAliyunDatasetAccFullAccesspermissions.
Authorize a RAM user to activate or use other cloud services
PAI depends on the following cloud services:
Use the Alibaba Cloud account to activate cloud services. Then, use RAM policies to control access for RAM users. See the RAM user authorization column in the following table.
If a RAM user is added as a workspace member, they inherit partial permissions for the dependent cloud services based on their assigned role. If you encounter permission issues when activating or using a cloud service, refer to the following table.
For example, to activate OSS with a RAM user, attach the AliyunOSSFullAccess system policy to the RAM user. For more information about OSS permissions, see OSS RAM Policy.
Cloud service | Policy for activation | RAM user authorization | Documentation |
OSS | AliyunOSSFullAccess |
| |
MaxCompute | AliyunBSSOrderAccess, AliyunDataWorksFullAccess | Add the RAM user with the MaxCompute Developer role in the workspace. For more information, see Create and manage a workspace. |
|
Flink | AliyunStreamFullAccess | Activation: Activate Realtime Compute for Apache Flink | |
NAS | AliyunNASFullAccess |
| |
API Gateway | AliyunApiGatewayFullAccess | ||
SLS | AliyunLogFullAccess |
| |
VPC | AliyunVPCFullAccess |
| |
CloudMonitor | AliyunCloudMonitorFullAccess | Common operations: Step 1: Configure alert contacts, Step 2: Configure alert rules | |
Tracing Analysis | AliyunARMSFullAccess | Activation: Quick start | |
ACR | AliyunContainerRegistryFullAccess | Common operations: Build images on an Enterprise Edition instance |
Authorize PAI to access other cloud services
Authorization for PAI to access other services is typically completed when you activate PAI. If any authorization steps were missed during activation, the console prompts you to complete them. You can also check the authorization status by following these steps. The following example uses Designer and OSS:
Log on to the PAI console.
In the left-side navigation pane, choose . Find OSS in the Designer section.
Check the authorization status of OSS in the Actions column.
If OSS is not authorized, click Actions > Authorize Now and follow the prompts to complete the authorization.
If OSS is already authorized, click Actions > View Authorization to view the authorization details.
PAI sub-products access other cloud services through service roles and service-linked roles. The preceding list doesn't cover all scenarios. For more information about specific sub-products, see: