All Products
Search
Document Center

Resource Access Management:Services that work with RAM

Last Updated:Dec 02, 2025

This topic lists the Alibaba Cloud services that work with Resource Access Management (RAM), the authorization granularity and system policies for each service, and the links of related topics.

Overview

Each table in this topic contains the following columns:

  • Service: the name of the Alibaba Cloud service that supports RAM.

  • Sub-service or sub-module: the sub-service or sub-module of the service. A hyphen (-) indicates that this does not apply.

  • RAM code: the unique code used in RAM to identify the service.

  • Console: indicates whether RAM can be used for access control in the service's console. Supported indicates support, Unsupported indicates no support, and a circle (○) indicates that the service does not have a console.

  • API: indicates whether RAM can be used for access control when calling the service's API. Supported indicates support, Unsupported indicates no support, and a circle (○) indicates that the service does not provide an API.

  • Authorization granularity: the most specific level at which permissions can be granted for the service. A hyphen (-) indicates that a specific granularity is not defined.

    The following authorization granularities are defined:

    • Service level: Permissions are granted to the entire service. A RAM user or role can either access all resources within the service or none.

    • Operation level: Permissions are granted for specific API operations on certain types of resources within the service.

    • Resource level: Permissions are granted for specific operations on individual resources. This is the most granular level. For example, you can authorize a RAM user to restart a specific Elastic Compute Service (ECS) instance.

  • System policy: the system policies that RAM provides for the service. A hyphen (-) indicates that no system policies are provided.

  • References: links to relevant documentation about RAM integration for the service. A hyphen (-) indicates that no specific documentation is available.

Elastic computing

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

ECS

ECS

ecs

Supported

Supported

Resource

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

  • AliyunECSWorkbenchFullAccess

RAM authorization

Elastic Block Storage (EBS)

EBS

ecs

Supported

Supported

Resource

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

-

EBS

EBS

ebs

Supported

Supported

Resource

  • AliyunEBSFullAccess

  • AliyunEBSReadOnlyAccess

-

ECS

Elastic GPU Service

ecs

Supported

Supported

Resource

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

RAM authorization

ECS

ECS Bare Metal Instance

ecs

Supported

Supported

Resource

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

RAM authorization

ECS

Dedicated Host (DDH)

ecs

Supported

Supported

Resource

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

RAM authorization

ECS

Alibaba Cloud Linux 2

ecs

Supported

Supported

Resource

  • AliyunECSFullAccess

  • AliyunECSReadOnlyAccess

  • AliyunECSAssistantFullAccess

  • AliyunECSAssistantReadonlyAccess

  • AliyunECSNetworkInterfaceManagementAccess

RAM authorization

Auto Scaling

-

ess

Supported

Supported

Operation

  • AliyunESSFullAccess

  • AliyunESSReadOnlyAccess

API usage notes

Container Service for Kubernetes (ACK)

-

cs

Supported

Supported

Resource

  • AliyunCSFullAccess

  • AliyunCSReadOnlyAccess

RAM authorization

Batch Compute

-

batchcompute

Supported

Supported

Service

-

-

Resource Orchestration Service (ROS)

-

ros

Supported

Supported

Resource

  • AliyunROSFullAccess

  • AliyunROSReadOnlyAccess

Use RAM to control access to resources

Function Compute

-

fc

Supported

Supported

Resource

  • AliyunFCFullAccess

  • AliyunFCReadOnlyAccess

  • AliyunFCInvocationAccess

Grant permissions across Alibaba Cloud accounts by using RAM roles

Simple Application Server

-

swas

Supported

Service

AliyunSWASFullAccess

-

Elastic High Performance Computing (E-HPC)

-

ehpc

Supported

Supported

Service

  • AliyunEHPCFullAccess

  • AliyunEHPCReadOnlyAccess

-

Container Registry

-

cr

Supported

Supported

Resource

  • AliyunContainerRegistryFullAccess

  • AliyunContainerRegistryReadOnlyAccess

RAM authentication rules

Elastic Desktop Service (EDS)

EDS

ecd

Supported

Supported

Operation

  • AliyunECDFullAccess

  • AliyunECDReadOnlyAccess

  • AliyunECDRamUserAccess

  • AliyunECDTagFullAccess

  • AliyunECDOfficeSiteFullAccess

  • AliyunECDUserFullAccess

  • AliyunECDPolicyGroupFullAccess

  • AliyunECDDesktopFullAccess

  • AliyunECDTechnicalSupportFullAccess

Attach EDS Enterprise system policies to a RAM user

Elastic Container Instance

-

eci

Supported

Supported

Resource

  • AliyunECIFullAccess

  • AliyunECIReadOnlyAccess

Grant permissions to a RAM user

CloudFlow

-

fnf

Supported

Supported

Resource

  • AliyunFnFFullAccess

  • AliyunFnFReadOnlyAccess

RAM authorization

Web App Service

-

webplus

Supported

Supported

Operation

  • AliyunWebPlusFullAccess

  • AliyunWebPlusReadOnlyAccess

-

Compute Nest

-

  • computenest

  • computenestsupplier

Supported

Resource

  • AliyunComputeNestSupplierFullAccess

  • AliyunComputeNestUserFullAccess

  • AliyunComputeNestUserReadOnlyAccess

  • AliyunComputeNestSupplierReadOnlyAccess

-

Distributed Cloud Container Platform for Kubernetes (ACK One)

-

adcp

Supported

Supported

Operation

  • AliyunAdcpFullAccess

  • AliyunAdcpReadOnlyAccess

-

Databases

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

ApsaraDB RDS

ApsaraDB RDS

rds

Supported

Supported

Resource

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

  • AliyunRDSGADFullAccess

  • AliyunRDSGADReadOnlyAccess

  • AliyunRDSReadOnlyWithSQLLogArchiveAccess

Use RAM for resource authorization

ApsaraDB RDS

ApsaraDB RDS for MySQL

rds

Supported

Supported

Resource

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

Use RAM for resource authorization

ApsaraDB RDS

ApsaraDB RDS for SQL Server

rds

Supported

Supported

Resource

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

Use RAM for resource authorization

ApsaraDB RDS

ApsaraDB RDS for PostgreSQL

rds

Supported

Supported

Resource

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

Use RAM for resource authorization

ApsaraDB RDS

ApsaraDB for MyBase

rds

Supported

Supported

Resource

  • AliyunRDSFullAccess

  • AliyunRDSReadOnlyAccess

-

Tair (Redis® OSS-Compatible)

-

kvstore

Supported

Supported

Resource

  • AliyunKvstoreFullAccess

  • AliyunKvstoreReadOnlyAccess

RAM authorization

ApsaraDB for MongoDB

-

dds

Supported

Supported

Resource

  • AliyunMongoDBFullAccess

  • AliyunMongoDBReadOnlyAccess

-

AnalyticDB for PostgreSQL

-

gpdb

Supported

Supported

Resource

  • AliyunGPDBFullAccess

  • AliyunGPDBReadOnlyAccess

-

Data Transmission Service (DTS)

-

dts

Supported

Supported

Operation

  • AliyunDTSFullAccess

  • AliyunDTSReadOnlyAccess

Use a system policy to authorize a RAM user to manage DTS instances

Data Management

-

dms

Supported

Supported

Service

  • AliyunDMSFullAccess

  • AliyunDMSReadOnlyAccess

Authorize DMS to access cloud resources

AnalyticDB for MySQL

-

adb

Supported

Supported

Operation

  • AliyunADBFullAccess

  • AliyunADBReadOnlyAccess

  • AliyunADBDeveloperAccess

RAM users and permissions

PolarDB for Xscale (PolarDB-X)

-

  • drds

  • polardbx

Supported

Supported

Resource

  • AliyunDRDSReadOnlyAccess

  • AliyunDRDSFullAccess

  • AliyunDRDSReadOnlyWithSQLLogArchiveAccess

Use RAM for resource authorization

ApsaraDB for HBase

-

hbase

Supported

Supported

Resource

  • AliyunHBaseFullAccess

  • AliyunHBaseReadOnlyAccess

Customize a RAM policy

Advanced Database & Application Migration

-

adam

Supported

Service

  • AliyunADAMReadOnlyAccess

  • AliyunADAMFullAccess

Logon accounts

PolarDB

-

polardb

Supported

Supported

Operation

  • AliyunPolardbReadOnlyAccess

  • AliyunPolardbFullAccess

  • AliyunPolardbReadOnlyWithSQLLogArchiveAccess

Create and grant permissions to a RAM user

Data Disaster Recovery

-

dbs

Supported

Supported

Service

  • AliyunDBSFullAccess

  • AliyunDBSReadOnlyAccess

-

Database Autonomy Service (DAS)

-

hdm

Supported

Supported

Service

  • AliyunHDMReadOnlyAccess

  • AliyunHDMFullAccess

  • AliyunHDMReadOnlyWithSQLLogArchiveAccess

How do I use DAS as a RAM user?

ApsaraDB for OceanBase

-

oceanbase

Supported

Service

  • AliyunOceanBaseFullAccess

  • AliyunOceanBaseReadOnlyAccess

-

ApsaraDB for Cassandra

-

cassandra

Supported

Supported

Resource

  • AliyunCassandraFullAccess

  • AliyunCassandraReadOnlyAccess

Manage RAM users

ApsaraDB for ClickHouse

-

clickhouse

Supported

Supported

Resource

  • AliyunClickHouseFullAccess

  • AliyunClickHouseReadOnlyAccess

Authorize RAM users to access resources

Database Gateway (DG)

-

dg

Supported

Supported

Resource

  • AliyunDGFullAccess

  • AliyunDGReadOnlyAccess

-

ApsaraDB for SelectDB

-

selectdb

Supported

Supported

Operation

  • AliyunSelectDBFullAccess

  • AliyunSelectDBReadOnlyAccess

RAM authorization

Storage

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Object Storage Service (OSS)

-

oss

Supported

Supported

Resource

  • AliyunOSSFullAccess

  • AliyunOSSReadOnlyAccess

  • AliyunOSSImportReadOnlyAccess

  • AliyunOSSImportFullAccess

RAM policies

File Storage NAS (NAS)

-

nas

Supported

Supported

Resource

  • AliyunNASFullAccess

  • AliyunNASReadOnlyAccess

Perform access control based on RAM policies

Tablestore

-

ots

Supported

Supported

Resource

  • AliyunOTSFullAccess

  • AliyunOTSReadOnlyAccess

  • AliyunOTSWriteOnlyAccess

Create a custom policy

Cloud Storage Gateway (CSG)

-

hcs-sgw

Supported

Supported

Service

AliyunHCSSGWFullAccess

Use RAM to implement account-based access control

Cloud Backup

-

hbr

Supported

Supported

Resource

  • AliyunHBRFullAccess

  • AliyunHBRReadOnlyAccess

Create a RAM user and authorize the RAM user to access Cloud Backup

Hybrid Cloud Storage

Hybrid Cloud Storage

hgw

Supported

Operation

  • AliyunHgwFullAccess

  • AliyunHgwReadOnlyAccess

-

Hybrid Cloud Storage

Remote Service

asrs

Supported

Resource

  • ASRSFullAccess

  • ASRSReadonlyAccess

-

Cloud communication

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Short Message Service (SMS)

-

dysms

Supported

Supported

Service

-

-

Networking

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Virtual Private Cloud (VPC)

-

vpc

Supported

Supported

Resource

  • AliyunVPCFullAccess

  • AliyunVPCReadOnlyAccess

  • AliyunVPCNetworkIntelligenceReadOnlyAccess

  • AliyunVPCPrefixListAccess

  • AliyunVPCPrefixListReadOnlyAccess

  • AliyunVpcPeerFullAccess

  • AliyunVpcPeerReadOnlyAccess

RAM authorization

Server Load Balancer (SLB)

Classic Load Balancer (CLB)

slb

Supported

Supported

Resource

  • AliyunSLBReadOnlyAccess

  • AliyunSLBFullAccess

RAM authorization

SLB

Application Load Balancer (ALB)

alb

Supported

Supported

Resource

  • AliyunALBFullAccess

  • AliyunALBReadOnlyAccess

RAM authorization

SLB

Network Load Balancer (NLB)

nlb

Supported

Supported

Resource

  • AliyunNLBFullAccess

  • AliyunNLBReadOnlyAccess

RAM authorization

SLB

Gateway Load Balancer (GWLB)

gwlb

Supported

Supported

Resource

  • AliyunGWLBFullAccess

  • AliyunGWLBReadOnlyAccess

RAM authorization

Express Connect

-

vpc

Supported

Supported

Resource

  • AliyunExpressConnectFullAccess

  • AliyunExpressConnectReadOnlyAccess

Policies and examples

Elastic IP Address (EIP)

EIP

vpc

Supported

Supported

Resource

  • AliyunEIPFullAccess

  • AliyunEIPReadOnlyAccess

Grant permissions to a RAM user

EIP

Anycast Elastic IP Address (Anycast EIP)

eipanycast

Supported

Supported

Resource

  • AliyunAnycastEIPFullAccess

  • AliyunAnycastEIPReadOnlyAccess

RAM authorization

NAT Gateway

-

vpc

Supported

Supported

Resource

  • AliyunNATGatewayReadOnlyAccess

  • AliyunNATGatewayFullAccess

Grant permissions to a RAM user

VPN Gateway

-

vpc

Supported

Supported

Resource

  • AliyunVPNGatewayFullAccess

  • AliyunVPNGatewayReadOnlyAccess

Grant permissions to a RAM user

Internet Shared Bandwidth

-

vpc

Supported

Supported

Resource

  • AliyunCommonBandwidthPackageReadOnlyAccess

  • AliyunCommonBandwidthPackageFullAccess

-

Global Accelerator (GA)

-

ga

Supported

Supported

Resource

  • AliyunGlobalAccelerationReadOnlyAccess

  • AliyunGlobalAccelerationFullAccess

Grant permissions to a RAM user

Smart Access Gateway (SAG)

-

smartag

Supported

Supported

Resource

-

RAM authentication

Cloud Enterprise Network (CEN)

-

cen

Supported

Supported

Resource

  • AliyunCENReadOnlyAccess

  • AliyunCENFullAccess

RAM authentication

PrivateLink

-

privatelink

Supported

Supported

Resource

  • AliyunPrivateLinkFullAccess

  • AliyunPrivateLinkReadOnlyAccess

  • AliyunPrivatelinkEndpointServiceReadOnlyAccess

  • AliyunPrivatelinkEndpointServiceFullAccess

  • AliyunPrivatelinkEndpointReadOnlyAccess

  • AliyunPrivatelinkEndpointFullAccess

RAM authorization

Alibaba Cloud DNS PrivateZone

-

pvtz

Supported

Supported

Resource

  • AliyunPvtzFullAccess

  • AliyunPvtzReadOnlyAccess

RAM

Cloud Data Transfer (CDT)

-

cdt

Supported

Supported

Operation

  • AliyunCDTFullAccess

  • AliyunCDTReadOnlyAccess

System policies for CDT

VPC peering connection

-

vpc

Supported

Supported

Resource

  • AliyunVpcPeerFullAccess

  • AliyunVpcPeerReadOnlyAccess

-

IPv6 Gateway

-

vpc

Supported

Supported

Resource

  • AliyunIpv6FullAccess

  • AliyunIpv6ReadOnlyAccess

-

O&M and management

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Application Real-Time Monitoring Service (ARMS)

-

arms

Supported

Supported

Service

  • AliyunARMSFullAccess

  • AliyunARMSReadOnlyAccess

Use RAM users to manage permissions

CloudMonitor

-

cms

Supported

Supported

Operation

  • AliyunCloudMonitorFullAccess

  • AliyunCloudMonitorReadOnlyAccess

  • AliyunCloudMonitorMetricDataReadOnlyAccess

RAM authentication

Intelligent Advisor

-

advisor-intl

Supported

Supported

Operation

  • AliyunAdvisorFullAccess

  • AliyunAdvisorReadOnlyAccess

-

Cloud Shell

-

cloudshell

Supported

Operation

AliyunCloudShellFullAccess

-

Cloud Config

-

config

Supported

Supported

Operation

  • AliyunConfigFullAccess

  • AliyunConfigReadOnlyAccess

RAM user authorization

Logic Composer

-

composer

Supported

Supported

Resource

  • AliyunLogicComposerFullAccess

  • AliyunLogicComposerReadOnlyAccess

Grant permissions to a RAM user

CloudOps Orchestration Service (OOS)

-

oos

Supported

Supported

Resource

  • AliyunOOSFullAccess

  • AliyunOOSReadOnlyAccess

RAM authorization

Cloud Governance Center (CGC)

CGC

governance

Supported

Operation

  • AliyunGovernanceFullAccess

  • AliyunGovernanceReadOnlyAccess

-

CGC

Service Catalog

servicecatalog

Supported

Supported

Resource

  • AliyunServiceCatalogAdminFullAccess

  • AliyunServiceCatalogEndUserFullAccess

  • AliyunServiceCatalogAdminReadOnlyAccess

  • AliyunServiceCatalogEndUserReadOnlyAccess

Middleware

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Enterprise Distributed Application Service (EDAS)

-

edas

Supported

Supported

Resource

  • AliyunEDASFullAccess

  • AliyunEDASReadOnlyAccess

  • AliyunEDASApplicationFullAccess

  • AliyunEDASApplicationReadOnlyAccess

  • AliyunEDASResourceReadOnlyAccess

  • AliyunEDASResourceFullAccess

Manage RAM users

ApsaraMQ

ApsaraMQ for RocketMQ

mq

Supported

Supported

Resource

  • AliyunMQFullAccess

  • AliyunMQReadOnlyAccess

  • AliyunMQPubOnlyAccess

  • AliyunMQSubOnlyAccess

Grant permissions to RAM users

ApsaraMQ

ApsaraMQ for MQTT

mq

Supported

Supported

Resource

  • AliyunMQFullAccess

  • AliyunMQReadOnlyAccess

  • AliyunMQPubOnlyAccess

  • AliyunMQSubOnlyAccess

Grant permissions to RAM users

ApsaraMQ

ApsaraMQ for RabbitMQ

amqp

Supported

Supported

Resource

  • AliyunAMQPFullAccess

  • AliyunAMQPReadOnlyAccess

Grant permissions to RAM users

Simple Message Queue (formerly MNS) (SMQ)

-

mns

Supported

Supported

Resource

  • AliyunMNSFullAccess

  • AliyunMNSReadOnlyAccess

Authorize a RAM user

ApsaraMQ for Kafka

-

alikafka

Supported

Supported

Resource

  • AliyunKafkaFullAccess

  • AliyunKafkaReadOnlyAccess

Grant permissions to RAM users

Application High Availability Service

-

ahas

Supported

Supported

Service

  • AliyunAHASFullAccess

  • AliyunAHASReadOnlyAccess

-

Alibaba Cloud Service Mesh (ASM)

-

servicemesh

Supported

Supported

Resource

  • AliyunASMFullAccess

  • AliyunASMReadOnlyAccess

Authorization overview

EventBridge

-

eventbridge

Supported

Supported

Resource

  • AliyunEventBridgeFullAccess

  • AliyunEventBridgeReadOnlyAccess

  • AliyunEventBridgeResourceCreatePolicy

  • AliyunEventBridgeResourceDeletePolicy

  • AliyunEventBridgeResourceUpdatePolicy

  • AliyunEventBridgePutEventsPolicy

Policies and examples

Media services and CDN

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

CDN

-

cdn

Supported

Supported

Resource

  • AliyunCDNFullAccess

  • AliyunCDNReadOnlyAccess

RAM authorization

ApsaraVideo Media Processing (MPS)

-

mts

Supported

Supported

Service

  • AliyunMTSFullAccess

  • AliyunMTSPlayerAuth

-

ApsaraVideo VOD (VOD)

-

vod

Supported

Supported

Operation

  • AliyunVODFullAccess

  • AliyunVODReadOnlyAccess

  • AliyunVODPlayAuth

  • AliyunVODUploadAuth

-

ApsaraVideo Live

-

live

Supported

Supported

Resource

  • AliyunLiveFullAccess

  • AliyunLiveReadOnlyAccess

Authentication rules on API requests

Real-Time Communication

-

rtc

Supported

Supported

Resource

-

-

Dynamic Content Delivery Network (DCDN)

-

dcdn

Supported

Supported

Resource

  • AliyunDCDNFullAccess

  • AliyunDCDNReadOnlyAccess

-

Edge Security Acceleration (ESA)

-

esa

Supported

Supported

Resource

  • AliyunESAFullAccess

  • AliyunESAReadOnlyAccess

RAM authorization

Enterprise applications

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Direct Mail

-

dm

Supported

Supported

Operation

  • AliyunDirectMailFullAccess

  • AliyunDirectMailReadOnlyAccess

-

API Gateway

-

apigateway

Supported

Supported

Service

  • AliyunApiGatewayFullAccess

  • AliyunApiGatewayReadOnlyAccess

Use RAM to manage the permissions on API resources

Alibaba Mail

-

alimail

Supported

Operation

  • AliyunAlimailFullAccess

  • AliyunAlimailReadOnlyAccess

-

Resource Management

Resource Management

resourcemanager

Supported

Supported

Operation

  • AliyunResourceDirectoryFullAccess

  • AliyunResourceDirectoryReadOnlyAccess

RAM authorization

Resource Management

Resource Sharing

resourcesharing

Supported

Supported

Operation

  • AliyunResourceSharingFullAccess

  • AliyunResourceSharingReadOnlyAccess

-

Resource Management

Tag

tag

Supported

Supported

Operation

  • AliyunTagManagerAccess

  • AliyunTAGReadOnlyAccess

  • AliyunTagAdministratorAccess

RAM authorization

Resource Management

Resource Center

resourcecenter

Supported

Supported

Operation

  • AliyunResourceCenterFullAccess

  • AliyunResourceCenterReadOnlyAccess

Grant a RAM user the permissions to use Resource Center

Blockchain as a Service (BaaS)

BaaS

baas

Supported

Supported

Resource

  • AliyunBaaSFullAccess

  • AliyunBaaSReadOnlyAccess

Hyperledger Fabric RAM authentication

CloudQuotation (CQ)

-

assettech

Supported

Service

  • AliyunCQLoudFullAccess

  • AliyunCQLoudReadOnlyAccess

-

BizWorks

-

bizworks

Supported

Service

  • AliyunBizWorksFullAccess

  • AliyunBizWorksReadOnlyAccess

-

Domains and websites

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Alibaba Cloud DNS (DNS)

DNS

alidns

Supported

Supported

Resource

  • AliyunDNSFullAccess

  • AliyunDNSReadOnlyAccess

DNS

Alibaba Cloud Public DNS

pubdns

Supported

Supported

Resource

  • AliyunPubDNSReadOnlyAccess

  • AliyunPubDNSFullAccess

-

Domain Names and Websites

-

domain

Supported

Supported

Resource

  • AliyunDomainFullAccess

  • AliyunDomainReadonlyAccess

Authentication rules for the Domains API

AI

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Intelligent Speech Interaction

Intelligent Speech Interaction

nls

Supported

Supported

Service

  • AliyunNLSFullAccess

  • AliyunNLSReadOnlyAccess

  • AliyunNLSSpeechServiceAccess

  • AliyunNLSSlpAccess

-

Platform for AI (PAI)

-

pai

Supported

Supported

Service

-

-

PAI

-

paiplugin

Supported

Operation

  • AliyunPaiPluginFullAccess

  • AliyunPaiPluginReadOnlyAccess

-

Image Search

-

imagesearch

Supported

Supported

Resource

  • AliyunImagesearchReadOnlyAccess

  • AliyunImagesearchFullAccess

Grant permissions to RAM users

Machine Translation

-

alimt

Supported

Supported

Operation

  • AliyunMTFullAccess

  • AliyunMTReadOnlyAccess

-

Alibaba Cloud Model Studio

-

sfm

Unsupported

Supported

Resource

  • AliyunSFMFullAccess

  • AliyunSFMReadOnlyAccess

  • AliyunBailianFullAccess

  • AliyunBailianReadOnlyAccess

Configure permissions for team collaboration

IoT

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

IoT Platform

-

iot

Supported

Supported

Resource

  • AliyunIOTFullAccess

  • AliyunIOTReadOnlyAccess

  • AliyunIOTConsoleCommonAccess

Access IoT Platform as a RAM user

Link IoT Edge

-

iot

Supported

Supported

Resource

  • AliyunIOTFullAccess

  • AliyunIOTReadOnlyAccess

  • AliyunIOTConsoleCommonAccess

Access resources of other Alibaba Cloud services

Lindorm

Time Series Database (TSDB)

hitsdb

Supported

Supported

Operation

-

-

Analytics computing

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

DataWorks

-

dataworks

Supported

Supported

Operation

  • AliyunDataWorksFullAccess

  • AliyunDataWorksReadOnlyAccess

  • AliyunDataWorksExclusiveResourceGroupModify

  • AliyunDataWorksAccessingRdsReadOnlyPolicy

  • AliyunDataWorksAccessingDLFReadOnlyPolicy

  • AliyunDataWorksAccessingEMRReadOnlyPolicy

  • AliyunDataWorksAccessingAlikafkaPolicy

Manage permissions on the DataWorks services and the entities in the DataWorks console by using RAM policies

Quick BI

-

-

Supported

Supported

Service

-

-

DataV

-

datav

Supported

Service

AliyunDataVFullAccess

-

Realtime Compute for Apache Flink

-

stream

Supported

Supported

Resource

  • AliyunStreamFullAccess

  • AliyunStreamReadOnlyAccess

Grant permissions to a RAM user

Elasticsearch

-

elasticsearch

Supported

Supported

Resource

  • AliyunElasticsearchReadOnlyAccess

  • AliyunElasticsearchFullAccess

  • AliyunElasticsearchServerlessFullAccess

  • AliyunElasticsearchServerlessReadOnlyAccess

Elasticsearch objects supported for authorization

E-MapReduce (EMR)

E-MapReduce

emr

Supported

Supported

Service

  • AliyunEMRFullAccess

  • AliyunEMRFlowAdmin

  • AliyunEMRDevelopAccess

  • AliyunEMRDlsFullAccess

  • AliyunEMRDlsReadOnlyAccess

Grant permissions to RAM users

Simple Log Service (SLS)

-

log

Supported

Supported

Resource

  • AliyunLogFullAccess

  • AliyunLogReadOnlyAccess

  • AliyunLogPutOpenEventPolicy

  • AliyunLogInvokeFCAccess

Authorization rules

Hologres

-

hologram

Supported

Supported

Resource

  • AliyunHologresFullAccess

  • AliyunHologresReadOnlyAccess

Grant permissions to a RAM user

Developer services

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Alibaba Cloud DevOps

-

rdc

Supported

Supported

Resource

  • AliyunRDCFullAccess

  • AliyunRDCReadOnlyAccess

-

Managed Service for OpenTelemetry

-

xtrace

Supported

Supported

Operation

  • AliyunTracingAnalysisFullAccess

  • AliyunTracingAnalysisReadOnlyAccess

-

Security

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Security Center

-

  • yundun-sas

  • yundun-aegis

Supported

Supported

Operation

  • AliyunYundunSASFullAccess

  • AliyunYundunSASReadOnlyAccess

-

Server Guard

-

yundun-aegis

Supported

Supported

Service

  • AliyunYundunAegisFullAccess

  • AliyunYundunAegisReadOnlyAccess

-

Anti-DDoS

Anti-DDoS

yundun-ddos

Supported

Supported

Service

  • AliyunYundunDDosFullAccess

  • AliyunYundunDDosReadOnlyAccess

  • AliyunYundunDDoSRewardsReadOnlyA

  • AliyunYundunDDoSRewardsFullAccess

-

Anti-DDoS

Anti-DDoS Proxy (Chinese Mainland)

  • yundun-high

  • yundun-ddoscoo

Supported

Supported

Service

  • AliyunYundunHighFullAccess

  • AliyunYundunHighReadOnlyAccess

-

Anti-DDoS

Anti-DDoS Proxy (Outside Chinese Mainland)

  • yundun-high

  • yundun-ddoscoo

Supported

Service

  • AliyunYundunAntiDDoSPremiumFullAccess

  • AliyunYundunAntiDDoSPremiumReadOnlyAccess

-

Web Application Firewall (WAF)

WAF

yundun-waf

Supported

Supported

Operation

  • AliyunYundunWAFFullAccess

  • AliyunYundunWAFReadOnlyAccess

  • AliyunYundunWAFv3FullAccess

  • AliyunYundunWAFv3ReadOnlyAccess

-

Certificate Management Service (Original SSL Certificate)

-

yundun-cert

Supported

Supported

Service

  • AliyunYundunCertFullAccess

  • AliyunYundunCertReadOnlyAccess

-

Cloud Firewall

-

yundun-cloudfirewall

Supported

Supported

Resource

  • AliyunYundunCloudFirewallReadOnlyAccess

  • AliyunYundunCloudFirewallFullAccess

RAM authorization

Managed Security Service (MSSP)

-

mssp

Supported

Service

-

-

Content Moderation

-

yundun-greenweb

Supported

Supported

Service

  • AliyunYundunGreenWebFullAccess

  • AliyunYundunGreenWebConsoleOnlyAccess

  • AliyunYundunGreenWebReadOnlyAccess

-

Bastionhost

Bastionhost

yundun-bastionhost

Supported

Service

  • AliyunYundunBastionHostFullAccess

  • AliyunYundunBastionHostReadOnlyAccess

  • AliyunYundunBastionHostOperateOnlyAccess

  • AliyunYundunBastionHostAuditOnlyAccess

-

Data Security Center (DSC)

-

yundun-sddp

Supported

Supported

Service

  • AliyunYundunSDDPFullAccess

  • AliyunYundunSDDPReadOnlyAccess

  • AliyunYundunSDDPDataManager

-

Identity as a Service (IDaaS)

IDaaS

yundun-idaas

Supported

Operation

  • AliyunYundunIdaasFullAccess

  • AliyunYundunIdaasReadOnlyAccess

-

Key Management Service (KMS)

-

kms

Supported

Supported

Resource

  • AliyunKMSFullAccess

  • AliyunKMSReadOnlyAccess

  • AliyunKMSSecretUserAccess

  • AliyunKMSCryptoAdminAccess

  • AliyunKMSCryptoUserAccess

  • AliyunKMSSecretAdminAccess

Use RAM to control access to KMS resources

Resource Access Management (RAM)

RAM

  • ram

  • sts

  • ims

Supported

Supported

Resource

  • AliyunRAMFullAccess

  • AliyunRAMReadOnlyAccess

RAM authorization

RAM

CloudSSO

cloudsso

Supported

Resource

  • AliyunCloudSSOReadOnlyAccess

  • AliyunCloudSSOFullAccess

-

ActionTrail

-

actiontrail

Supported

Supported

Operation

-

RAM account authentication

Technical support

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Ticket Management

-

support

Supported

Supported

Service

AliyunSupportFullAccess

-

Marketplace

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Alibaba Cloud Marketplace

-

acm

Supported

Unsupported

Service

AliyunMarketplaceFullAccess

-

Other

Service

Sub-service or sub-module

RAM code

Console

API

Authorization granularity

System policies

References

Expenses and Costs

-

  • bss

  • bssapi

  • efc

Supported

Supported

Operation

  • AliyunBSSFullAccess

  • AliyunBSSReadOnlyAccess

  • AliyunBSSOrderAccess

  • AliyunBSSRefundAccess

  • AliyunBSSRenewReadOnlyAccess

  • AliyunBSSRenewFullAccess

  • AliyunBSSCartReadOnlyAccess

  • AliyunBSSCartFullAccess

  • AliyunBSSMyFreetierFullAccess

-

ICP Filing

-

  • beian

  • bsn

Supported

Service

AliyunBeianFullAccess

-