All Products
Search
Document Center

Resource Access Management:AliyunServiceRolePolicyForMobilcdpRuntimeDNS

Last Updated:Apr 02, 2025

AliyunServiceRolePolicyForMobilcdpRuntimeDNS is the authorization policy dedicated to a service-linked role. The policy is automatically attached to a service role when the service role is created. Then, the service-linked role is authorized to access other cloud services. This policy is updated by the relevant Alibaba Cloud service. Do not attach this policy to a RAM identity other than a service-linked role.

Policy details

  • Type: service system policy

  • Creation time: 19:01:41 on February 13, 2025

  • Update time: 11:24:55 on April 02, 2025

  • Current version: v4

Policy content

{
    "Version": "1",
    "Statement": [
      {
        "Effect": "Allow",
        "Action": [
          "alidns:DescribeDomains",
          "alidns:AddDomainRecord",
          "alidns:DescribeSubDomainRecords",
          "yundun-cert:UploadUserCertificate",
          "yundun-waf:DescribeCertificates",
          "yundun-waf:DescribeInstanceInfo",
          "yundun-waf:CreateDomain",
          "yundun-waf:CreateCertificateByCertificateId",
          "yundun-waf:DescribeDomain",
          "yundun-waf:DescribeCerts",
          "yundun-waf:DescribeDomains",
          "yundun-waf:ModifyDomain",
          "yundun-waf:DescribeDomainDetail",
          "yundun-waf:DescribeDomainNames",
          "yundun-waf:DescribeInstance"
        ],
        "Resource": "*"
      },
      {
        "Action": "ram:DeleteServiceLinkedRole",
        "Resource": "*",
        "Effect": "Allow",
        "Condition": {
          "StringEquals": {
            "ram:ServiceName": "runtime-dns.mobilcdp.aliyuncs.com"
          }
        }
      }
    ]
  }

References