All Products
Search
Document Center

Resource Access Management:AliyunCASRolePolicy

Last Updated:Aug 13, 2026

AliyunCASRolePolicy is the authorization policy dedicated to a service role. In most cases, when a service role is created, the policy is attached to the service role. Then, the service role is authorized to access other cloud services. This policy is updated by the relevant Alibaba Cloud service. Do not attach this policy to a RAM identity other than a service role.

Policy details

  • Type: service system policy

  • Creation time: 13:47:32 on August 13, 2026

  • Update time: 13:47:32 on August 13, 2026

  • Current version: v1

Policy content

{
  "Version": "1",
  "Statement": [
    {
      "Action": [
        "yundun-ddoscoo:DescribeWebRules",
        "yundun-ddoscoo:DescribeDomains",
        "yundun-ddoscoo:AssociateWebCert",
        "yundun-ddoscoo:DescribeCerts"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "live:DescribeLiveUserDomains",
        "live:SetLiveDomainCertificate",
        "live:DescribeLiveDomainCertificateInfo"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cdn:DescribeUserDomains",
        "cdn:SetDomainServerCertificate",
        "cdn:DescribeDomainCertificateInfo",
        "cdn:BatchSetCdnDomainServerCertificate",
        "cdn:SetCdnDomainSSLCertificate"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "slb:UploadServerCertificate",
        "slb:DeleteServerCertificate",
        "slb:DescribeServerCertificates",
        "slb:DescribeLoadBalancers",
        "slb:DescribeLoadBalancerAttribute",
        "slb:DescribeLoadBalancerHTTPSListenerAttribute",
        "slb:SetLoadBalancerHTTPSListenerAttribute",
        "slb:SetDomainExtensionAttribute",
        "slb:DescribeLoadBalancerSummaryForGlobal"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "scdn:DescribeScdnUserDomains",
        "scdn:SetScdnDomainCertificate",
        "scdn:DescribeScdnDomainCertificateInfo"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "dcdn:DescribeDcdnUserDomains",
        "dcdn:SetDcdnDomainCertificate",
        "dcdn:DescribeDcdnDomainCertificateInfo",
        "dcdn:SetDcdnDomainSSLCertificate"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "alb:ListListenerCertificates",
        "alb:ListListeners",
        "alb:ListLoadBalancers",
        "alb:AssociateAdditionalCertificatesWithListener",
        "alb:DissociateAdditionalCertificatesFromListener",
        "alb:UpdateListenerAttribute",
        "alb:ListAsynJobs",
        "alb:GetGlobalLoadBalancerSummary"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "alidns:AddDomainRecord",
        "alidns:DescribeDomainNs",
        "alidns:GetMainDomainName",
        "alidns:DeleteSubDomainRecords",
        "alidns:DescribeDomains",
        "alidns:DescribeDomainRecords"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "oss:ListBuckets",
        "oss:ListCname",
        "oss:PutCname"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "vod:SetVodDomainCertificate",
        "vod:DescribeVodDomainCertificateInfo",
        "vod:DescribeVodUserDomains"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "apigateway:DescribeApiGroups",
        "apigateway:DescribeApiGroup",
        "apigateway:SetDomainCertificate",
        "apigateway:ModifyApiGroup"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-cert:DescribeSSLCertificatePrivateKey",
        "yundun-cert:DescribeSSLCertificatePublicKeyDetail"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ga:ListAccelerators",
        "ga:DescribeAccelerator",
        "ga:DescribeListener",
        "ga:ListListeners",
        "ga:UpdateListener",
        "ga:AssociateAdditionalCertificatesWithListener",
        "ga:DissociateAdditionalCertificatesFromListener",
        "ga:UpdateAdditionalCertificateWithListener",
        "ga:ListListenerCertificates",
        "ga:DescribeRegions"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "fc:ListCustomDomains",
        "fc:GetCustomDomain",
        "fc:UpdateCustomDomain"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cr:UpdateInstanceCustomizedDomain",
        "cr:ListInstanceDomain",
        "cr:ListInstance",
        "cr:ListInstanceRegion"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "mse:QueryBusinessLocations",
        "mse:ListGatewayDomainSSL",
        "mse:UpdateSSLCertSSL",
        "mse:ListGateway",
        "mse:ListGatewayDomain",
        "mse:UpdateSSLCert",
        "mse:AddSSLCert"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "nlb:ListLoadBalancers",
        "nlb:ListListeners",
        "nlb:UpdateListenerAttribute",
        "nlb:GetGlobalLoadBalancerSummary",
        "nlb:AssociateAdditionalCertificatesWithListener",
        "nlb:DisassociateAdditionalCertificatesWithListener",
        "nlb:ListListenerCertificates",
        "nlb:GetJobStatus"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "webhosting:DeployCert",
        "webhosting:DescribeUserDomains"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "swas:CreateInstances",
        "swas:ListInstanceStatus",
        "swas:UpdateInstanceAttribute",
        "swas:ListInstances",
        "swas:UpgradeInstance"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "swas-open:ListInstanceStatus",
        "swas-open:ListInstances",
        "swas-open:RebootInstance",
        "swas-open:InvokeCommand",
        "swas-open:InstallCloudAssistant",
        "swas-open:DescribeCloudAssistantStatus",
        "swas-open:DescribeInvocationResult",
        "swas-open:RunCommand",
        "swas-open:DescribeInvocations",
        "swas-open:UploadFile",
        "swas-open:DescribeUploadFileResults",
        "swas-open:DescribeCommandInvocations"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ecs:DescribeRegions",
        "ecs:DescribeInstanceStatus",
        "ecs:DescribeInstances",
        "ecs:DescribeCloudAssistantStatus",
        "ecs:DescribeInvocationResults",
        "ecs:DescribeResourceByTags"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-cert:ListPcaCaCertificate"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "eas:AttachGatewayDomain",
        "eas:ListGatewayDomains",
        "eas:ListGateway"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "pai:ListProducts"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "apig:ListDomains",
        "apig:UpdateDomain",
        "apig:GetDomain"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "cs:DescribeRegions",
        "cs:DescribeClustersV1",
        "cs:GetClusters",
        "cs:DescribeUserClusterNamespaces",
        "cs:DescribeTaskInfo"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "esa:ListSites",
        "esa:ListHttpsBasicConfigurations",
        "esa:ListCertificates",
        "esa:GetCertificate",
        "esa:SetCertificate",
        "esa:ListInstanceQuotasWithUsage"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "privatelink:ListVpcEndpoints",
        "privatelink:CreateVpcEndpoint",
        "privatelink:GetVpcEndpointAttribute"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "ecs:CreateSecurityGroup",
        "ecs:AuthorizeSecurityGroup"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "vpc:CreateVSwitch",
        "vpc:DescribeVSwitches",
        "vpc:DescribeVpcAttribute"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-hsm:GetCluster",
        "yundun-hsm:GetInstance",
        "yundun-hsm:DownloadClusterManagedCert",
        "yundun-hsm:ConfigClusterWhitelist"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "actiontrail:CreateServiceTrail",
        "actiontrail:DeleteServiceTrail",
        "actiontrail:GetServiceTrail",
        "actiontrail:GetServiceTrailDeliveryStatus"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": [
        "yundun-waf:DescribeCloudResources",
        "yundun-waf:DescribeInstance",
        "yundun-waf:DescribeDomains",
        "yundun-waf:DescribeCloudResourceAccessPortDetails",
        "yundun-waf:ModifyCloudResourceCert",
        "yundun-waf:ModifyDomainCert",
        "yundun-waf:DescribeDomainDetail",
        "yundun-waf:CreateCloudResourceExtensionCert",
        "yundun-waf:DeleteCloudResourceExtensionCert",
        "yundun-waf:ModifyCloudResourceDefaultCert"
      ],
      "Resource": "*",
      "Effect": "Allow"
    },
    {
      "Action": "ram:CreateServiceLinkedRole",
      "Resource": "*",
      "Effect": "Allow",
      "Condition": {
        "StringEquals": {
          "ram:ServiceName": "privatelink.aliyuncs.com"
        }
      }
    }
  ]
}

References