AliyunKMSReadOnlyAccess is a service system policy that is managed by Alibaba Cloud. You can attach the AliyunKMSReadOnlyAccess policy to a Resource Access Management (RAM) identity, such as a RAM user, RAM user group, and RAM role. The AliyunKMSReadOnlyAccess policy: Provides read-only access to Key Management Service via Management Console.
Policy details
Type: service system policy
Creation time: 07:41:41 on March 09, 2018
Update time: 07:48:22 on September 23, 2025
Current version: v3
Policy content
{
"Version": "1",
"Statement": [
{
"Action": [
"kms:List*",
"kms:Describe*",
"kms:GetPublicKey",
"kms:GetUploadBackupDataInfo",
"kms:GetKmsInstanceSharedAccounts",
"kms:GetKmsInstanceQuotaInfos",
"kms:GetCheckAssociateResourceTaskResults",
"kms:GetKeyPolicy",
"kms:GetKeyDefaultPolicy",
"kms:GetSecretPolicy",
"kms:GetSecretDefaultPolicy",
"kms:GetKmsInstance",
"kms:GetDefaultKmsInstance"
],
"Resource": "*",
"Effect": "Allow"
}
]
}