Creates a RAM role.
Operation description
Operation description
For more information about RAM roles, see RAM role overview.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ram:CreateRole |
create |
*Role
|
|
None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RoleName |
string |
No |
The name of the RAM role. The name must be 1 to 64 characters in length and can contain letters, digits, periods (.), and hyphens (-). |
ECSAdmin |
| Description |
string |
No |
The description of the RAM role. The description must be 1 to 1024 characters in length. |
ECS management role. |
| AssumeRolePolicyDocument |
string |
No |
The trust policy. Specifies one or more principals that are allowed to assume the RAM role. The principal can be an Alibaba Cloud account, an Alibaba Cloud service, or an identity provider. Note
Resource Access Management (RAM) users cannot assume RAM roles whose trusted entity is an Alibaba Cloud service. |
{"Statement":[{"Action":"sts:AssumeRole","Effect":"Allow","Principal":{"RAM":"acs:ram::123456789012****:root"}}],"Version":"1"} |
| MaxSessionDuration |
integer |
No |
The maximum session duration of the RAM role. Valid values: 3600 to 43200. Unit: seconds. Default value: 3600. If you leave this parameter empty, the default value is used. |
3600 |
| Tag |
array<object> |
No |
The tags. |
|
|
object |
No |
The tags. |
||
| Key |
string |
No |
The tag key. |
k1 |
| Value |
string |
No |
The tag value. |
v1 |
| AllowConsoleLogin |
boolean |
No |
Specifies whether console logon is allowed for the RAM role. Valid values:
|
true |
AssumeRolePolicyDocument examples
The following policy indicates that the trusted entity allowed to assume the RAM role is any authorized Resource Access Management (RAM) user under the Alibaba Cloud account (AccountID=
123456789012****).
{
"Statement": [{
"Action": "sts:AssumeRole",
"Effect": "Allow",
"Principal": {
"RAM": [
"acs:ram::123456789012****:root"
]
}
}],
"Version": "1"
}
The following policy indicates that the trusted entity allowed to assume the RAM role is the RAM user
testuserunder the Alibaba Cloud account (AccountID=123456789012****).
Before creating this role, make sure that the RAM user testuser has been created (logon name: testuser@123456789012****.onaliyun.com).
{
"Statement": [{
"Action": "sts:AssumeRole",
"Effect": "Allow",
"Principal": {
"RAM": [
"acs:ram::123456789012****:user/testuser"
]
}
}],
"Version": "1"
}
The following policy indicates that the trusted entity allowed to assume the RAM role is the ECS service under the current Alibaba Cloud account.
{
"Statement": [{
"Action": "sts:AssumeRole",
"Effect": "Allow",
"Principal": {
"Service": [
"ecs.aliyuncs.com"
]
}
}],
"Version": "1"
}
The following policy indicates that the trusted entity allowed to assume the RAM role is the SAML identity provider
testproviderunder the current Alibaba Cloud account (AccountID=123456789012****).
Before creating this role, make sure that the SAML identity provider testprovider has been created.
{
"Statement": [{
"Action": "sts:AssumeRole",
"Effect": "Allow",
"Principal": {
"Federated": [
"acs:ram::123456789012****:saml-provider/testprovider"
]
},
"Condition": {
"StringEquals": {
"saml:recipient": "https://signin.aliyun.com/saml-role/sso"
}
}
}],
"Version": "1"
}
The following policy indicates that the trusted entity allowed to assume the RAM role is the OIDC identity provider
TestOIDCProviderunder the current Alibaba Cloud account (AccountID=123456789012****).
Before creating this role, make sure that the OIDC identity provider TestOIDCProvider has been created.
{
"Statement": [{
"Action": "sts:AssumeRole",
"Effect": "Allow",
"Principal": {
"Federated": [
"acs:ram::123456789012****:oidc-provider/TestOIDCProvider"
]
},
"Condition": {
"StringEquals": {
"oidc:aud": [
"496271242565057****"
],
"oidc:iss": "https://dev-xxxxxx.okta.com",
"oidc:sub": "KryrkIdjylZb7agUgCEf****"
}
}
}],
"Version": "1"
}
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| Role |
object |
The information about the RAM role. |
|
| AssumeRolePolicyDocument |
string |
The trust policy of the RAM role. |
{ "Statement": [ { "Action": "sts:AssumeRole", "Effect": "Allow", "Principal": { "RAM": "acs:ram::123456789012****:root" } } ], "Version": "1" } |
| Description |
string |
The description of the RAM role. |
ECS management role. |
| MaxSessionDuration |
integer |
The maximum session duration of the RAM role. |
3600 |
| RoleName |
string |
The name of the RAM role. |
ECSAdmin |
| CreateDate |
string |
The time when the RAM role was created. |
2015-01-23T12:33:18Z |
| RoleId |
string |
The ID of the RAM role. |
901234567890**** |
| Arn |
string |
The resource descriptor of the RAM role. |
acs:ram::123456789012****:role/ECSAdmin |
| AllowConsoleLogin |
boolean |
Indicates whether console logon is allowed for the RAM role. |
true |
| RequestId |
string |
The request ID. |
04F0F334-1335-436C-A1D7-6C044FE73368 |
Examples
Success response
JSON format
{
"Role": {
"AssumeRolePolicyDocument": "{ \"Statement\": [ { \"Action\": \"sts:AssumeRole\", \"Effect\": \"Allow\", \"Principal\": { \"RAM\": \"acs:ram::123456789012****:root\" } } ], \"Version\": \"1\" }",
"Description": "ECS management role",
"MaxSessionDuration": 3600,
"RoleName": "ECSAdmin",
"CreateDate": "2015-01-23T12:33:18Z",
"RoleId": "901234567890****",
"Arn": "acs:ram::123456789012****:role/ECSAdmin",
"AllowConsoleLogin": true
},
"RequestId": "04F0F334-1335-436C-A1D7-6C044FE73368"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.