All Products
Search
Document Center

Resource Access Management:Alibaba Cloud services that support RAM

Last Updated:Nov 08, 2025

This topic lists the Alibaba Cloud services that support Resource Access Management (RAM). It also describes the authorization granularity, system policies, and related documents for each service.

Overview

Each table in this topic contains the following information:

  • Service: The name of the Alibaba Cloud service that supports RAM.

  • Sub-service/Sub-module: The sub-service or sub-module of the service. A hyphen (-) indicates that none is available.

  • RAM code: The RAM code of the service.

  • Console: Indicates whether the service supports access control in the console. Supported indicates that access control is supported. Not supported indicates that access control is not supported. ○ indicates that the service is not available in the console.

  • API: Indicates whether the service supports access control through APIs. Supported indicates that access control is supported. Not supported indicates that access control is not supported. ○ indicates that the service does not provide APIs.

  • Authorization granularity: The minimum authorization granularity that the service provides. A hyphen (-) indicates that none is available.

    When integrated with RAM, each service defines different levels of authorization granularity for RAM users or RAM roles:

    • Service level: Authorization is granted for the entire service. A RAM user or RAM role can have either all permissions or no permissions for the service.

    • Operation level: Authorization is granted at the API operation level. A RAM user or RAM role can perform specific operations on certain types of resources for a specified service.

    • Resource level: Authorization is granted for specific operations on specific resources. This is the finest authorization granularity. For example, a RAM user can be granted the permission to restart only a specific Elastic Compute Service (ECS) instance.

  • System policy: The system policies that the service supports. A hyphen (-) indicates that none is available.

  • References: Links to documents related to the service and RAM. A hyphen (-) indicates that none is available.

Elastic computing

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Elastic Compute Service (ECS)

ECS

ecs

Supported

Supported

Resource-level

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

  • AliyunECSWorkbenchFullAccess

ECS authorization information

Elastic Block Storage

Elastic Block Storage

ecs

Supported

Supported

Resource-level

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

-

Elastic Block Storage

Elastic Block Storage (EBS)

ebs

Supported

Supported

Resource-level

  • AliyunEBSFullAccess

  • AliyunEBSReadOnlyAccess

-

ECS

Elastic GPU Service

ecs

Supported

Supported

Resource-level

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

ECS authorization information

ECS

ECS Bare Metal Instance

ecs

Supported

Supported

Resource-level

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

ECS authorization information

ECS

Dedicated Host

ecs

Supported

Supported

Resource-level

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

ECS authorization information

ECS

Alibaba Cloud Linux 2

ecs

Supported

Supported

Resource-level

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

ECS authorization information

Auto Scaling

-

ess

Supported

Supported

Operation-level

  • AliyunESSFullAccess

  • AliyunESSReadOnlyAccess

Notes on using Auto Scaling APIs

Container Service for Kubernetes

-

cs

Supported

Supported

Resource-level

  • AliyunCSFullAccess

  • AliyunCSReadOnlyAccess

RAM authorization for Container Service for Kubernetes

BatchCompute

-

batchcompute

Supported

Supported

Service-level

-

-

Resource Orchestration Service

-

ros

Supported

Supported

Resource-level

  • AliyunROSFullAccess

  • AliyunROSReadOnlyAccess

RAM authorization for Resource Orchestration Service

Function Compute

-

fc

Supported

Supported

Resource-level

  • AliyunFCFullAccess

  • AliyunFCReadOnlyAccess

  • AliyunFCInvocationAccess

Grant permissions across Alibaba Cloud accounts using a RAM role

Simple Application Server

-

swas

Supported

Service-level

AliyunSWASFullAccess

-

Elastic High Performance Computing

-

ehpc

Supported

Supported

Service-level

  • AliyunEHPCFullAccess

  • AliyunEHPCReadOnlyAccess

-

Container Registry

-

cr

Supported

Supported

Resource-level

  • AliyunContainerRegistryFullAccess

  • AliyunContainerRegistryReadOnlyAccess

RAM authorization information

Cloud Desktop

Elastic Desktop Service

ecd

Supported

Supported

Operation-level

  • AliyunECDFullAccess

  • AliyunECDReadOnlyAccess

  • AliyunECDRamUserAccess

  • AliyunECDTagFullAccess

  • AliyunECDOfficeSiteFullAccess

  • AliyunECDUserFullAccess

  • AliyunECDPolicyGroupFullAccess

  • AliyunECDDesktopFullAccess

  • AliyunECDTechnicalSupportFullAccess

Grant permissions to a RAM user

Elastic Container Instance

-

eci

Supported

Supported

Resource-level

  • AliyunECIFullAccess

  • AliyunECIReadOnlyAccess

Grant permissions to a RAM user

CloudFlow

-

fnf

Supported

Supported

Resource-level

  • AliyunFnFFullAccess

  • AliyunFnFReadOnlyAccess

RAM authorization for CloudFlow

Web App Service

-

webplus

Supported

Supported

Operation-level

  • AliyunWebPlusFullAccess

  • AliyunWebPlusReadOnlyAccess

-

Compute Nest

-

  • computenest

  • computenestsupplier

Supported

Resource-level

  • AliyunComputeNestSupplierFullAccess

  • AliyunComputeNestUserFullAccess

  • AliyunComputeNestUserReadOnlyAccess

  • AliyunComputeNestSupplierReadOnlyAccess

-

Distributed Cloud Container Platform for Kubernetes

-

adcp

Supported

Supported

Operation-level

  • AliyunAdcpFullAccess

  • AliyunAdcpReadOnlyAccess

-

Database

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Relational database

Relational database

RDS

Supported

Supported

Resource level

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

  • AliyunRDSGADFullAccess

  • AliyunRDSGADReadOnlyAccess

  • AliyunRDSReadOnlyWithSQLLogArchiveAccess

RAM authorization for RDS resources

Relational database

ApsaraDB RDS for MySQL

rds

Supported

Supported

Resource level

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

RAM authorization for RDS

Relational database

ApsaraDB for SQL Server

RDS

Supported

Supported

Resource level

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

RAM authorization for RDS resources

Relational database

ApsaraDB for PostgreSQL

rds

Supported

Supported

Resource level

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

RAM authorization for RDS

Relational database

ApsaraDB for MyBase

RDS

Supported

Supported

Resource level

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

-

ApsaraDB for Tair (compatible with Redis®)

-

kvstore

Supported

Supported

Resource level

  • AliyunKvstoreFullAccess

  • AliyunKvstoreReadOnlyAccess

RAM authentication for Redis

ApsaraDB for MongoDB

-

dds

Supported

Supported

Resource level

  • AliyunMongoDBFullAccess

  • AliyunMongoDBReadOnlyAccess

-

AnalyticDB for PostgreSQL

-

gpdb

Supported

Supported

Resource level

  • AliyunGPDBFullAccess

  • AliyunGPDBReadOnlyAccess

-

Data Transmission Service

-

DTS

Supported

Supported

Operation level

  • AliyunDTSFullAccess

  • AliyunDTSReadOnlyAccess

RAM authorization for Data Transmission Service

Data Management

-

dms

Supported

Supported

Service level

  • AliyunDMSFullAccess

  • AliyunDMSReadOnlyAccess

Grant DMS access to cloud resources

AnalyticDB for MySQL

-

adb

Supported

Supported

Operation level

  • AliyunADBFullAccess

  • AliyunADBReadOnlyAccess

  • AliyunADBDeveloperAccess

RAM authorization for AnalyticDB for MySQL

Cloud-native distributed database PolarDB-X

-

  • drds

  • polardbx

Supported

Supported

Resource level

  • AliyunDRDSReadOnlyAccess

  • AliyunDRDSFullAccess

  • AliyunDRDSReadOnlyWithSQLLogArchiveAccess

RAM authentication for PolarDB-X

ApsaraDB for HBase

-

HBase

Supported

Supported

Resource level

  • AliyunHBaseFullAccess

  • AliyunHBaseReadOnlyAccess

RAM authentication for HBase

Advanced Database & Application Migration

-

adam

Supported

Service level

  • AliyunADAMReadOnlyAccess

  • AliyunADAMFullAccess

RAM authentication for Advanced Database & Application Migration

PolarDB

-

PolarDB

Supported

Supported

Operation level

  • AliyunPolardbReadOnlyAccess

  • AliyunPolardbFullAccess

  • AliyunPolardbReadOnlyWithSQLLogArchiveAccess

RAM authorization for PolarDB

Data Disaster Recovery

-

dbs

Supported

Supported

Service level

  • AliyunDBSFullAccess

  • AliyunDBSReadOnlyAccess

-

Database Autonomy Service

-

hdm

Supported

Supported

Service Level

  • AliyunHDMReadOnlyAccess

  • AliyunHDMFullAccess

  • AliyunHDMReadOnlyWithSQLLogArchiveAccess

How a RAM user uses DAS

ApsaraDB for OceanBase

-

oceanbase

Supported

Service level

  • AliyunOceanBaseFullAccess

  • AliyunOceanBaseReadOnlyAccess

-

ApsaraDB for Cassandra

-

Cassandra

Supported

Supported

Resource level

  • AliyunCassandraFullAccess

  • AliyunCassandraReadOnlyAccess

RAM authentication for Cassandra

LedgerDB

-

ledgerdb

Supported

Supported

Resource level

  • AliyunLedgerDBFullAccess

  • AliyunLedgerDBReadOnlyAccess

RAM authentication for LedgerDB

ApsaraDB for ClickHouse

-

ClickHouse

Supported

Supported

Resource level

  • AliyunClickHouseFullAccess

  • AliyunClickHouseReadOnlyAccess

ClickHouse RAM authorization

Database Gateway (DG)

-

dg

Supported

Supported

Resource level

  • AliyunDGFullAccess

  • AliyunDGReadOnlyAccess

-

ApsaraDB for SelectDB

-

selectdb

Supported

Supported

Operation level

  • AliyunSelectDBFullAccess

  • AliyunSelectDBReadOnlyAccess

ApsaraDB for SelectDB authorization information

Storage

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Object Storage Service

-

oss

Supported

Supported

Resource level

  • AliyunOSSFullAccess

  • AliyunOSSReadOnlyAccess

  • AliyunOSSImportReadOnlyAccess

  • AliyunOSSImportFullAccess

RAM authorization for Object Storage Service

File Storage NAS

-

nas

Supported

Supported

Resource level

  • AliyunNASFullAccess

  • AliyunNASReadOnlyAccess

Use RAM access policies to control access to NAS

Tablestore

-

ots

Supported

Supported

Resource level

  • AliyunOTSFullAccess

  • AliyunOTSReadOnlyAccess

  • AliyunOTSWriteOnlyAccess

RAM authorization for Tablestore

Cloud Storage Gateway

-

hcs-sgw

Supported

Supported

Service level

AliyunHCSSGWFullAccess

RAM authorization for Cloud Storage Gateway

Cloud Backup

-

hbr

Supported

Supported

Resource level

  • AliyunHBRFullAccess

  • AliyunHBRReadOnlyAccess

Create a RAM user for Cloud Backup operations

Hybrid Cloud Storage

Hybrid Cloud Storage

hgw

Supported

Operation level

  • AliyunHgwFullAccess

  • AliyunHgwReadOnlyAccess

-

Hybrid Cloud Storage

Remote Service

asrs

Supported

Resource level

  • ASRSFullAccess

  • ASRSReadonlyAccess

-

Cloud communications

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Short Message Service

-

dysms

Supported

Supported

Service level

-

-

Network

Alibaba Cloud service

Sub-service/sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Virtual Private Cloud (VPC)

-

vpc

Supported

Supported

Resource level

  • AliyunVPCFullAccess

  • AliyunVPCReadOnlyAccess

  • AliyunVPCNetworkIntelligenceReadOnlyAccess

  • AliyunVPCPrefixListAccess

  • AliyunVPCPrefixListReadOnlyAccess

  • AliyunVpcPeerFullAccess

  • AliyunVpcPeerReadOnlyAccess

RAM authorization for VPC

Server Load Balancer

Classic Load Balancer

SLB

Supported

Supported

Resource-level

  • AliyunSLBReadOnlyAccess

  • AliyunSLBFullAccess

RAM authorization for Classic Load Balancer

Server Load Balancer

Application Load Balancer

ALB

Supported

Supported

Resource level

  • AliyunALBFullAccess

  • AliyunALBReadOnlyAccess

RAM authorization information for Application Load Balancer

Server Load Balancer

Network Load Balancer (NLB)

nlb

Supported

Supported

Resource level

  • AliyunNLBFullAccess

  • AliyunNLBReadOnlyAccess

RAM authorization for Network Load Balancer

Server Load Balancer

Gateway Load Balancer

gwlb

Supported

Supported

Resource level

  • AliyunGWLBFullAccess

  • AliyunGWLBReadOnlyAccess

RAM authorization for Gateway Load Balancer

Express Connect

-

VPC

Supported

Supported

Resource level

  • AliyunExpressConnectFullAccess

  • AliyunExpressConnectReadOnlyAccess

Express Connect access policies and examples

Elastic IP Address

Elastic IP Address

VPC

Supported

Supported

Resource level

  • AliyunEIPFullAccess

  • AliyunEIPReadOnlyAccess

RAM authorization for EIP

Elastic IP Address

Anycast Elastic IP Address

eipanycast

Supported

Supported

Resource level

  • AliyunAnycastEIPFullAccess

  • AliyunAnycastEIPReadOnlyAccess

Authorization information for Anycast Elastic IP Addresses

NAT Gateway

-

VPC

Supported

Supported

Resource level

  • AliyunNATGatewayReadOnlyAccess

  • AliyunNATGatewayFullAccess

RAM authorization for NAT Gateway

VPN Gateway

-

VPC

Supported

Supported

Resource level

  • AliyunVPNGatewayFullAccess

  • AliyunVPNGatewayReadOnlyAccess

RAM authorization for VPN Gateway

Internet Shared Bandwidth

-

VPC

Supported

Supported

Resource level

  • AliyunCommonBandwidthPackageReadOnlyAccess

  • AliyunCommonBandwidthPackageFullAccess

-

Global Accelerator

-

ga

Supported

Supported

Resource level

  • AliyunGlobalAccelerationReadOnlyAccess

  • AliyunGlobalAccelerationFullAccess

RAM authentication for Global Accelerator

Smart Access Gateway

-

smartag

Supported

Supported

Resource level

-

RAM authentication for Smart Access Gateway

Cloud Enterprise Network

-

CEN

Supported

Supported

Resource level

  • AliyunCENReadOnlyAccess

  • AliyunCENFullAccess

RAM authentication for Cloud Enterprise Network

PrivateLink

-

privatelink

Supported

Supported

Resource-level

  • AliyunPrivateLinkFullAccess

  • AliyunPrivateLinkReadOnlyAccess

  • AliyunPrivatelinkEndpointServiceReadOnlyAccess

  • AliyunPrivatelinkEndpointServiceFullAccess

  • AliyunPrivatelinkEndpointReadOnlyAccess

  • AliyunPrivatelinkEndpointFullAccess

RAM authentication for PrivateLink

PrivateZone

-

PVTZ

Supported

Supported

Resource level

  • AliyunPvtzFullAccess

  • AliyunPvtzReadOnlyAccess

RAM authorization for PrivateZone

Cloud Data Transfer

-

cdt

Supported

Supported

Operation level

  • AliyunCDTFullAccess

  • AliyunCDTReadOnlyAccess

Cloud Data Transfer system access policy reference

VPC peering connection

-

VPC

Supported

Supported

Resource level

  • AliyunVpcPeerFullAccess

  • AliyunVpcPeerReadOnlyAccess

-

IPv6 gateway

-

VPC

Supported

Supported

Resource level

  • AliyunIpv6FullAccess

  • AliyunIpv6ReadOnlyAccess

-

Operations management

Alibaba Cloud service

Sub-service/Sub-module

Code

Console

API

Authorization granularity

System policy

References

Application Real-Time Monitoring Service

-

arms

Supported

Supported

Service level

  • AliyunARMSFullAccess

  • AliyunARMSReadOnlyAccess

RAM authorization for ARMS

Cloud Monitor

-

cms

Supported

Supported

Operation level

  • AliyunCloudMonitorFullAccess

  • AliyunCloudMonitorReadOnlyAccess

  • AliyunCloudMonitorMetricDataReadOnlyAccess

RAM authorization for Cloud Monitor

Intelligent Advisor

-

advisor-intl

Supported

Supported

Operation level

  • AliyunAdvisorFullAccess

  • AliyunAdvisorReadOnlyAccess

-

Cloud Shell

-

cloudshell

Supported

Operation level

AliyunCloudShellFullAccess

-

CloudConfig

-

config

Supported

Supported

Operation level

  • AliyunConfigFullAccess

  • AliyunConfigReadOnlyAccess

RAM authorization

Logic Composer

-

composer

Supported

Supported

Resource level

  • AliyunLogicComposerFullAccess

  • AliyunLogicComposerReadOnlyAccess

RAM authorization for Logic Composer

CloudOps Orchestration Service (OOS)

-

oos

Supported

Supported

Resource level

  • AliyunOOSFullAccess

  • AliyunOOSReadOnlyAccess

RAM authorization for CloudOps Orchestration Service (OOS)

Cloud Governance Center

Cloud Governance Center

governance

Supported

Operation level

  • AliyunGovernanceFullAccess

  • AliyunGovernanceReadOnlyAccess

-

Cloud Governance Center

Service Catalog

servicecatalog

Supported

Supported

Resource level

  • AliyunServiceCatalogAdminFullAccess

  • AliyunServiceCatalogEndUserFullAccess

  • AliyunServiceCatalogAdminReadOnlyAccess

  • AliyunServiceCatalogEndUserReadOnlyAccess

Internet middleware

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Enterprise Distributed Application Service

-

edas

Supported

Supported

Resource level

  • AliyunEDASFullAccess

  • AliyunEDASReadOnlyAccess

  • AliyunEDASApplicationFullAccess

  • AliyunEDASApplicationReadOnlyAccess

  • AliyunEDASResourceReadOnlyAccess

  • AliyunEDASResourceFullAccess

RAM authorization for EDAS

Message Queue

Message Queue for Apache RocketMQ

mq

Supported

Supported

Resource level

  • AliyunMQFullAccess

  • AliyunMQReadOnlyAccess

  • AliyunMQPubOnlyAccess

  • AliyunMQSubOnlyAccess

RAM authorization for Message Queue for Apache RocketMQ

Message Queue

Message Queue for MQTT

mq

Supported

Supported

Resource level

  • AliyunMQFullAccess

  • AliyunMQReadOnlyAccess

  • AliyunMQPubOnlyAccess

  • AliyunMQSubOnlyAccess

RAM authorization for Message Queue for MQTT

Message Queue

Message Queue for RabbitMQ

amqp

Supported

Supported

Resource level

  • AliyunAMQPFullAccess

  • AliyunAMQPReadOnlyAccess

RAM authorization for Message Queue for RabbitMQ

Message Service (formerly MNS)

-

mns

Supported

Supported

Resource level

  • AliyunMNSFullAccess

  • AliyunMNSReadOnlyAccess

RAM authorization for Message Service (MNS)

Message Queue for Apache Kafka

-

alikafka

Supported

Supported

Resource level

  • AliyunKafkaFullAccess

  • AliyunKafkaReadOnlyAccess

RAM authorization for Message Queue for Apache Kafka

Application High Availability Service

-

ahas

Supported

Supported

Service level

  • AliyunAHASFullAccess

  • AliyunAHASReadOnlyAccess

-

Service Mesh

-

servicemesh

Supported

Supported

Resource level

  • AliyunASMFullAccess

  • AliyunASMReadOnlyAccess

RAM authorization for Service Mesh

EventBridge

-

eventbridge

Supported

Supported

Resource level

  • AliyunEventBridgeFullAccess

  • AliyunEventBridgeReadOnlyAccess

  • AliyunEventBridgeResourceCreatePolicy

  • AliyunEventBridgeResourceDeletePolicy

  • AliyunEventBridgeResourceUpdatePolicy

  • AliyunEventBridgePutEventsPolicy

RAM authorization for EventBridge

Video and CDN

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

CDN

-

cdn

Supported

Supported

Resource level

  • AliyunCDNFullAccess

  • AliyunCDNReadOnlyAccess

RAM authorization for CDN

ApsaraVideo Media Processing

-

mts

Supported

Supported

Service level

  • AliyunMTSFullAccess

  • AliyunMTSPlayerAuth

-

ApsaraVideo VOD

-

vod

Supported

Supported

Operation level

  • AliyunVODFullAccess

  • AliyunVODReadOnlyAccess

  • AliyunVODPlayAuth

  • AliyunVODUploadAuth

-

ApsaraVideo Live

-

live

Supported

Supported

Resource level

  • AliyunLiveFullAccess

  • AliyunLiveReadOnlyAccess

RAM authorization for ApsaraVideo Live

Real-Time Communication

-

rtc

Supported

Supported

Resource level

-

-

Whole Site Acceleration

-

dcdn

Supported

Supported

Resource level

  • AliyunDCDNFullAccess

  • AliyunDCDNReadOnlyAccess

-

Edge Security Acceleration

-

esa

Supported

Supported

Resource level

  • AliyunESAFullAccess

  • AliyunESAReadOnlyAccess

RAM authorization for Edge Security Acceleration

Enterprise applications

Alibaba Cloud service

Sub-service / Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Direct Mail

-

dm

Supported

Supported

Operation level

  • AliyunDirectMailFullAccess

  • AliyunDirectMailReadOnlyAccess

-

API Gateway

-

API Gateway

Supported

Supported

Service level

  • AliyunApiGatewayFullAccess

  • AliyunApiGatewayReadOnlyAccess

RAM authentication for API Gateway

Alibaba Mail

-

alimail

Supported

Operation level

  • AliyunAlimailFullAccess

  • AliyunAlimailReadOnlyAccess

-

Resource Management

Resource Management

ResourceManager

Supported

Supported

Operation level

  • AliyunResourceDirectoryFullAccess

  • AliyunResourceDirectoryReadOnlyAccess

RAM authentication for Resource Directory

Resource Management

Resource sharing

resourcesharing

Supported

Supported

Operation level

  • AliyunResourceSharingFullAccess

  • AliyunResourceSharingReadOnlyAccess

-

Resource Management

Tag

Tag

Supported

Supported

Operation level

  • AliyunTagManagerAccess

  • AliyunTagReadOnlyAccess

  • AliyunTagAdministratorAccess

Tag-based authentication list

Resource Management

Resource Center

Resource Center

Supported

Supported

Operation level

  • AliyunResourceCenterFullAccess

  • AliyunResourceCenterReadOnlyAccess

Use the Resource Center as a RAM user

Blockchain as a Service

Blockchain as a Service

BaaS

Supported

Supported

Resource level

  • AliyunBaaSFullAccess

  • AliyunBaaSReadOnlyAccess

Hyperledger Fabric RAM authorization

CloudQuotation

-

assettech

Supported

Service level

  • AliyunCQLoudFullAccess

  • AliyunCQLoudReadOnlyAccess

-

BizWorks

-

BizWorks

Supported

Service Level

  • AliyunBizWorksFullAccess

  • AliyunBizWorksReadOnlyAccess

-

Domain Names and Websites

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Alibaba Cloud DNS

Alibaba Cloud DNS

alidns

Supported

Supported

Resource level

  • AliyunDNSFullAccess

  • AliyunDNSReadOnlyAccess

Alibaba Cloud DNS

Public DNS

pubdns

Supported

Supported

Resource level

  • AliyunPubDNSReadOnlyAccess

  • AliyunPubDNSFullAccess

-

Domain Names

-

domain

Supported

Supported

Resource level

  • AliyunDomainFullAccess

  • AliyunDomainReadonlyAccess

RAM authorization for Domain Names

Artificial intelligence

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Intelligent Speech Interaction

Intelligent Speech Interaction

nls

Supported

Supported

Service level

  • AliyunNLSFullAccess

  • AliyunNLSReadOnlyAccess

  • AliyunNLSSpeechServiceAccess

  • AliyunNLSSlpAccess

-

Artificial Intelligence Platform

-

PAI

Supported

Supported

Service level

-

-

Artificial Intelligence Platform

-

paiplugin

Supported

Operation level

  • AliyunPaiPluginFullAccess

  • AliyunPaiPluginReadOnlyAccess

-

Image Search

-

imagesearch

Supported

Supported

Resource level

  • AliyunImagesearchReadOnlyAccess

  • AliyunImagesearchFullAccess

RAM authorization for Image Search

Machine Translation

-

alimt

Supported

Supported

Operation level

  • AliyunMTFullAccess

  • AliyunMTReadOnlyAccess

-

Alibaba Cloud Model Studio

-

sfm

Not supported

Supported

Resource level

  • AliyunSFMFullAccess

  • AliyunSFMReadOnlyAccess

  • AliyunBailianFullAccess

  • AliyunBailianReadOnlyAccess

Configuring team collaboration permissions

IoT

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

IoT Platform

-

iot

Supported

Supported

Resource level

  • AliyunIOTFullAccess

  • AliyunIOTReadOnlyAccess

  • AliyunIOTConsoleCommonAccess

RAM authorization for IoT Platform

IoT Edge

-

iot

Supported

Supported

Resource level

  • AliyunIOTFullAccess

  • AliyunIOTReadOnlyAccess

  • AliyunIOTConsoleCommonAccess

RAM authorization for IoT Edge

Lindorm

Time Series Database (TSDB)

hitsdb

Supported

Supported

Operation level

-

-

Big data

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

DataWorks

-

dataworks

Supported

Supported

Operation level

  • AliyunDataWorksFullAccess

  • AliyunDataWorksReadOnlyAccess

  • AliyunDataWorksExclusiveResourceGroupModify

  • AliyunDataWorksAccessingRdsReadOnlyPolicy

  • AliyunDataWorksAccessingDLFReadOnlyPolicy

  • AliyunDataWorksAccessingEMRReadOnlyPolicy

  • AliyunDataWorksAccessingAlikafkaPolicy

RAM policy for product and console access control

Quick BI

-

-

Supported

Supported

Service level

-

-

DataV

-

datav

Supported

Service level

AliyunDataVFullAccess

-

Realtime Compute for Apache Flink

-

stream

Supported

Supported

Resource level

  • AliyunStreamFullAccess

  • AliyunStreamReadOnlyAccess

RAM authorization for Realtime Compute for Apache Flink

Elasticsearch

-

elasticsearch

Supported

Supported

Resource level

  • AliyunElasticsearchReadOnlyAccess

  • AliyunElasticsearchFullAccess

  • AliyunElasticsearchServerlessFullAccess

  • AliyunElasticsearchServerlessReadOnlyAccess

RAM authorization for Elasticsearch

E-MapReduce

E-MapReduce

emr

Supported

Supported

Service level

  • AliyunEMRFullAccess

  • AliyunEMRFlowAdmin

  • AliyunEMRDevelopAccess

  • AliyunEMRDlsFullAccess

  • AliyunEMRDlsReadOnlyAccess

Grant permissions to a RAM user

Simple Log Service

-

log

Supported

Supported

Resource level

  • AliyunLogFullAccess

  • AliyunLogReadOnlyAccess

  • AliyunLogPutOpenEventPolicy

  • AliyunLogInvokeFCAccess

RAM authorization for Simple Log Service

Interactive Analysis

-

hologram

Supported

Supported

Resource level

  • AliyunHologresFullAccess

  • AliyunHologresReadOnlyAccess

Quick Start for granting permissions to RAM users

Developer services

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Apsara Devops

-

rdc

Supported

Supported

Resource level

  • AliyunRDCFullAccess

  • AliyunRDCReadOnlyAccess

-

Tracing Analysis

-

xtrace

Supported

Supported

Operation level

  • AliyunTracingAnalysisFullAccess

  • AliyunTracingAnalysisReadOnlyAccess

-

Security

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Security Center (Threat Detection Service)

-

  • yundun-sas

  • yundun-aegis

Supported

Supported

Operation level

  • AliyunYundunSASFullAccess

  • AliyunYundunSASReadOnlyAccess

-

Server Guard

-

yundun-aegis

Supported

Supported

Service level

  • AliyunYundunAegisFullAccess

  • AliyunYundunAegisReadOnlyAccess

-

Anti-DDoS

Anti-DDoS

yundun-ddos

Supported

Supported

Service level

  • AliyunYundunDDoSFullAccess

  • AliyunYundunDDoSReadOnlyAccess

  • AlibabaCloudSecurityDDoSRewardsReadOnlyA

  • AliyunYundunDDoSRewardsFullAccess

-

Anti-DDoS

Anti-DDoS Pro and Anti-DDoS Premium

  • yundun-high

  • yundun-ddoscoo

Supported

Supported

Service-level

  • AliyunYundunHighFullAccess

  • AliyunYundunHighReadOnlyAccess

-

Anti-DDoS

Anti-DDoS Premium

  • yundun-high

  • yundun-ddoscoo

Supported

Service level

  • AliyunYundunAntiDDoSPremiumFullAccess

  • AliyunYundunAntiDDoSPremiumReadOnlyAccess

-

Web Application Firewall

Web Application Firewall

yundun-waf

Supported

Supported

Operation level

  • AliyunYundunWAFFullAccess

  • AliyunYundunWAFReadOnlyAccess

  • AliyunYundunWAFv3FullAccess

  • AliyunYundunWAFv3ReadOnlyAccess

-

SSL Certificate

-

yundun-cert

Supported

Supported

Service level

  • AliyunYundunCertFullAccess

  • AliyunYundunCertReadOnlyAccess

-

Cloud Firewall

-

Cloud Firewall

Supported

Supported

Resource level

  • AliyunYundunCloudFirewallReadOnlyAccess

  • AliyunYundunCloudFirewallFullAccess

Cloud Firewall authorization information

Managed Security Service

-

mssp

Supported

Service level

-

-

Content Moderation

-

yundun-greenweb

Supported

Supported

Service level

  • AliyunYundunGreenWebFullAccess

  • AliyunYundunGreenWebConsoleOnlyAccess

  • AliyunYundunGreenWebReadOnlyAccess

-

Bastionhost

Bastionhost

yundun-bastionhost

Supported

Service level

  • AliyunYundunBastionHostFullAccess

  • AliyunYundunBastionHostReadOnlyAccess

  • AliyunYundunBastionHostOperateOnlyAccess

  • AliyunYundunBastionHostAuditOnlyAccess

-

Data Security Center

-

yundun-sddp

Supported

Supported

Service level

  • AliyunYundunSDDPFullAccess

  • AliyunYundunSDDPReadOnlyAccess

  • AliyunYundunSDDPDataManager

-

Identity as a Service

IDaaS

yundun-idaas

Supported

Operation level

  • AliyunYundunIdaasFullAccess

  • AliyunYundunIdaasReadOnlyAccess

-

Key Management Service

-

KMS

Supported

Supported

Resource level

  • AliyunKMSFullAccess

  • AliyunKMSReadOnlyAccess

  • AliyunKMSSecretUserAccess

  • AliyunKMSCryptoAdminAccess

  • AliyunKMSCryptoUserAccess

  • AliyunKMSSecretAdminAccess

Use RAM to control access to resources

Resource Access Management

Resource Access Management

  • RAM

  • STS

  • IMS

Supported

Supported

Resource level

  • AliyunRAMFullAccess

  • AliyunRAMReadOnlyAccess

RAM Authentication

Resource Access Management

CloudSSO

Cloud SSO

Supported

Resource level

  • AliyunCloudSSOReadOnlyAccess

  • AliyunCloudSSOFullAccess

-

ActionTrail

-

ActionTrail

Supported

Supported

Operation Level

-

RAM authorization for ActionTrail

Support and services

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Ticket

-

support

Supported

Supported

Service level

AliyunSupportFullAccess

-

Alibaba Cloud Marketplace

Service

Sub-service

RAM code

Console

API

Authorization granularity

System policy

References

Alibaba Cloud Marketplace

-

acm

Supported

Not supported

Service level

AliyunMarketplaceFullAccess

-

Others

Alibaba Cloud service

Sub-service/Sub-module

RAM code

Console

API

Authorization granularity

System policy

References

Cost Center

-

  • bss

  • bssapi

  • efc

Supported

Supported

Action level

  • AliyunBSSFullAccess

  • AliyunBSSReadOnlyAccess

  • AliyunBSSOrderAccess

  • AliyunBSSRefundAccess

  • AliyunBSSRenewReadOnlyAccess

  • AliyunBSSRenewFullAccess

  • AliyunBSSCartReadOnlyAccess

  • AliyunBSSCartFullAccess

  • AliyunBSSMyFreetierFullAccess

-

ICP filing

-

  • beian

  • bsn

Supported

Service level

AliyunBeianFullAccess

-