All Products
Search
Document Center

Resource Access Management:AliyunServiceRolePolicyForSFMAccessAppFlow

Last Updated:Oct 28, 2024

AliyunServiceRolePolicyForSFMAccessAppFlow is the authorization policy dedicated to a service-linked role. The policy is automatically attached to a service role when the service role is created. Then, the service-linked role is authorized to access other cloud services. This policy is updated by the relevant Alibaba Cloud service. Do not attach this policy to a RAM identity other than a service-linked role.

Policy details

  • Type: service system policy

  • Creation time: 16:26:00 on May 10, 2024

  • Update time: 16:26:00 on May 10, 2024

  • Current version: v1

Policy content

{
    "Version": "1",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "appflow:ListFlows",
                "appflow:StartFlow",
                "appflow:CreateFlow",
                "appflow:CreateUserAuthConfig",
                "appflow:DeleteFlow",
                "appflow:DeleteUserAuthConfig",
                "appflow:GetFlow",
                "appflow:GetUserAuthConfig",
                "appflow:LaunchFlow",
                "appflow:UpdateUserAuthConfig",
                "appflow:Validation",
                "appflow:EnableFlow",
                "appflow:DisableFlow",
                "appflow:ListUserAuthConfigs",
                "ros:CreateStack",
                "ros:GetStack",
                "ros:DeleteStack",
                "ros:UpdateStack"
            ],
            "Resource": "*"
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "appflow-access.sfm.aliyuncs.com"
                }
            }
        }
    ]
}

References