This topic describes how to use Resource Access Management (RAM) to grant permissions to O&M engineers and manage the permissions.
An enterprise has purchased multiple Alibaba Cloud services and deployed its application systems on the cloud. This poses the following O&M requirements:
Different O&M engineers are responsible for different Alibaba Cloud services.
Different O&M engineers require different permissions to access and manage Alibaba Cloud resources.
The enterprise can create RAM users and attach different policies to the RAM users to meet different O&M requirements.
Cloud O&M engineers
Permissions to manage all Alibaba Cloud resources.
VM O&M engineers
Permissions to manage Elastic Compute Service (ECS).
Permissions to manage Auto Scaling (ESS).
Permissions to manage Server Load Balancer (SLB).
Permissions to manage Apsara File Storage NAS (NAS).
Permissions to manage Object Storage Service (OSS).
Permissions to manage Tablestore (OTS).
Network O&M engineers
Permissions to manage Alibaba Cloud CDN (CDN).
Permissions to manage Cloud Enterprise Network (CEN).
Permissions to manage Internet Shared Bandwidth.
Permissions to manage Elastic IP Address (EIP).
Permissions to manage Express Connect.
Permissions to manage NAT Gateway (NAT).
Permissions to manage Secure CDN (SCDN).
Permissions to manage Smart Access Gateway.
Permissions to manage Virtual Private Cloud (VPC).
Permissions to manage VPN Gateway.
Database O&M engineers
Permissions to manage ApsaraDB RDS.
Permissions to manage Data Transmission Service (DTS).
Security O&M engineers
Permissions to manage all Alibaba Cloud Security services.
Monitoring O&M engineers
Permissions to manage ActionTrail.
Permissions to manage Application Real-Time Monitoring Service (ARMS).
Permissions to manage CloudMonitor.
Permissions only to read all Alibaba Cloud resources.
Permissions to manage Ticket Management.
This example describes how to set the RAM user
firstname.lastname@example.org as a database O&M engineer. Then, the RAM user can manage ApsaraDB RDS and DTS.
Log on to the RAM console by using your Alibaba Cloud account.
Create a RAM user named
For more information, see Create a RAM user.
AliyunDTSFullAccesspolicies to the RAM user
For more information, see Grant permissions to RAM users.