This topic lists the services that work with Resource Access Management (RAM), the authorization granularity and system policies for each service, and the links of related topics.
Overview
Each table in this topic contains the following columns:
- Alibaba Cloud service: the name of the cloud service that supports RAM.
- Sub-service or sub-module: the sub-service or sub-module of the cloud service. A hyphen (-) indicates none.
- RAM code: the code that is used in RAM to indicate the cloud service.
- Console: indicates whether RAM can be used to implement access control in the console of the service. A tick (√) indicates that RAM is supported. A cross (×) indicates that RAM is not supported. A circle (○) indicates that no console is provided for that service.
- API: indicates whether RAM can be used to implement access control by calling the API of the service. A tick (√) indicates that RAM is supported by calling the API of the service. A cross (×) indicates that RAM is not supported by calling the API of the service. A circle (○) indicates that no API is provided for that service.
- Authorization granularity: the minimum authorization granularity of the service. A hyphen (-) indicates that no authorization granularity is defined.
The following authorization granularity is defined:
- Service: You can control whether RAM users can access the service. You can grant RAM users or RAM roles the permissions to access all or none of the resources in the service.
- Operation: You can control whether RAM users or RAM roles can perform specific operations on a specific type of resource in the service.
- Resource: You can control whether RAM users can perform a specific operation on a specific resource in the service. For example, you can authorize a RAM user to restart a specific Elastic Compute Service (ECS) instance.
- System policy: the system policies that RAM provides for the service. A hyphen (-) indicates that no system policies are provided for the service.
- References: the topics that are related to both RAM and the service. A hyphen (-) indicates that no topics are related to RAM or the service.
Elastic computing
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
ECS | ECS | ecs | √ | √ | Resource |
| Authentication rules |
Elastic Block Storage (EBS) | EBS | ecs | √ | √ | Resource |
| - |
EBS | EBS | ebs | √ | √ | Resource |
| - |
ECS | Elastic GPU Service | ecs | √ | √ | Resource |
| Authentication rules |
ECS | ECS Bare Metal Instance | ecs | √ | √ | Resource |
| Authentication rules |
ECS | Super Computing Cluster | ecs | √ | √ | Resource |
| Authentication rules |
ECS | Dedicated Host (DDH) | ecs | √ | √ | Resource |
| Authentication rules |
ECS | Alibaba Cloud Linux 2 | ecs | √ | √ | Resource |
| Authentication rules |
Auto Scaling | - | ess | √ | √ | Operation |
| API usage instructions |
Container Service for Kubernetes (ACK) | - | cs | √ | √ | Resource |
| Use sub-accounts |
Batch Compute | - | batchcompute | √ | √ | Service | - | - |
Resource Orchestration Service (ROS) | - | ros | √ | √ | Resource |
| Use RAM to control resource access |
Function Compute | - | fc | √ | √ | Resource |
| Grant permissions across Alibaba Cloud accounts by using a RAM role |
Simple Application Server | - | swas | √ | ○ | Service | AliyunSWASFullAccess | - |
Elastic High Performance Computing (E-HPC) | - | ehpc | √ | √ | Service |
| - |
Container Registry | - | cr | √ | √ | Resource |
| Configure policies for RAM users to access Container Registry |
Elastic Desktop Service (EDS) | Wuying Cloud Desktop | ecd | √ | √ | Operation |
| Grant permissions to RAM users |
Elastic Container Instance | - | eci | √ | √ | Resource |
| Grant permissions to a RAM user |
Serverless Workflow (SWF) | - | fnf | √ | √ | Resource |
| Authorization policy |
Web App Service | - | webplus | √ | √ | Operation |
| - |
Compute Nest | - |
| √ | ○ | Resource |
| - |
Alibaba Cloud Distributed Cloud Container Platform (ACK One) | - | adcp | √ | √ | Operation |
| - |
Database
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
ApsaraDB RDS | ApsaraDB RDS | rds | √ | √ | Resource |
| Use RAM for resource authorization |
ApsaraDB RDS | ApsaraDB RDS for MySQL | rds | √ | √ | Resource |
| Use RAM for resource authorization |
ApsaraDB RDS | ApsaraDB RDS for SQL Server | rds | √ | √ | Resource |
| Use RAM for resource authorization |
ApsaraDB RDS | ApsaraDB RDS for PostgreSQL | rds | √ | √ | Resource |
| Use RAM for resource authorization |
ApsaraDB RDS | ApsaraDB MyBase | rds | √ | √ | Resource |
| - |
ApsaraDB for Redis | - | kvstore | √ | √ | Resource |
| RAM authentication |
ApsaraDB for MongoDB | - | dds | √ | √ | Resource |
| - |
AnalyticDB for PostgreSQL | - | gpdb | √ | √ | Resource |
| Authentication rules for APIs |
Data Transmission Service (DTS) | - | dts | √ | √ | Operation |
| Authorize a RAM user to use DTS |
Data Management (DMS) | - | dms | √ | √ | Service |
| Authorize DMS to access Alibaba Cloud resources |
AnalyticDB for MySQL | - | adb | √ | √ | Operation |
| RAM users and permissions |
PolarDB-X | - |
| √ | √ | Resource |
| Use RAM for resource authorization |
ApsaraDB for HBase | - | hbase | √ | √ | Resource |
| Use RAM for resource authorization |
Advanced Database & Application Migration (ADAM) | - | adam | √ | ○ | Service |
| Authorize a RAM user to log on to the ADAM console |
PolarDB | - | polardb | √ | √ | Operation |
| Create and authorize a RAM user |
Database Backup (DBS) | - | dbs | √ | √ | Service |
| - |
Database Autonomy Service (DAS) | - | hdm | √ | √ | Service |
| What do I do if I fail to access DAS as a RAM user due to lack of permissions? |
Data Lake Analytics (DLA) | - | openanalytics | √ | √ | Resource |
| Grant RAM users fine-grained permissions to access DLA |
ApsaraDB for OceanBase | - | oceanbase | √ | ○ | Service |
| - |
ApsaraDB for Cassandra | - | cassandra | √ | √ | Resource |
| Manage RAM users |
LedgerDB | - | ledgerdb | √ | √ | Resource |
| RAM user authorization |
ApsaraDB for ClickHouse | - | clickhouse | √ | √ | Resource |
| RAM-based authorization |
Database Gateway (DG) | - | dg | √ | √ | Resource |
| - |
Storage
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Object Storage Service (OSS) | - | oss | √ | √ | Resource |
| Overview |
Apsara File Storage NAS (NAS) | - | nas | √ | √ | Resource |
| Perform access control based on RAM policies |
Tablestore | - | ots | √ | √ | Resource |
| Custom permissions |
Cloud Storage Gateway (CSG) | - | hcs-sgw | √ | √ | Service | AliyunHCSSGWFullAccess | Use RAM to implement account-based access control |
Hybrid Backup Recovery (HBR) | - | hbr | √ | √ | Resource |
| Create a RAM user and authorize the RAM user to access HBR |
Cloud communications
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Short Message Service (SMS) | - | dysms | √ | √ | Service | - | - |
Networking
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Virtual private cloud (VPC) | - | vpc | √ | √ | Resource |
| RAM user authorization |
Server Load Balancer (SLB) | SLB | slb | √ | √ | Resource |
| Authorize a RAM user |
SLB | Application Load Balancer (ALB) | alb | √ | √ | Resource |
| - |
SLB | Network Load Balancer (NLB) | nlb | √ | √ | Resource |
| - |
Express Connect | - | vpc | √ | √ | Resource |
| System policies and sample custom policies for Express Connect |
Elastic IP Address (EIP) | EIP | vpc | √ | √ | Resource |
| RAM user authorization |
EIP | Anycast Elastic IP Address (Anycast EIP) | eipanycast | √ | √ | Resource |
| RAM authorization |
NAT Gateway | - | vpc | √ | √ | Resource |
| RAM user authorization |
VPN Gateway | - | vpc | √ | √ | Resource |
| RAM user authorization |
EIP Bandwidth Plan | - | vpc | √ | √ | Resource |
| - |
Global Accelerator | - | ga | √ | √ | Resource |
| RAM user authorization |
Smart Access Gateway (SAG) | - | smartag | √ | √ | Resource | - | RAM authentication |
Cloud Enterprise Network (CEN) | - | cen | √ | √ | Resource |
| RAM authentication |
PrivateLink | - | privatelink | √ | √ | Resource |
| RAM user authorization |
Alibaba Cloud DNS PrivateZone | - | pvtz | √ | √ | Resource |
| RAM |
Cloud Data Transfer (CDT) | - | cdt | √ | √ | Operation |
| RAM permission policy |
VPC peering connection | - | vpc | √ | √ | Resource |
| - |
IPv6 Gateway | - | vpc | √ | √ | Resource |
| - |
O&M management
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Application Real-Time Monitoring Service (ARMS) | - | arms | √ | √ | Service |
| Grant different permissions to RAM users |
CloudMonitor | - | cms | √ | √ | Operation |
| Control permissions of RAM users |
Intelligent Advisor | - | advisor-intl | √ | √ | Operation |
| - |
Cloud Shell | - | cloudshell | √ | ○ | Operation | - | - |
Cloud Config | - | config | √ | √ | Operation |
| RAM user authorization |
Logic Composer | - | composer | √ | √ | Resource |
| Grant permissions to a RAM user |
Operation Orchestration Service (OOS) | - | oos | √ | √ | Resource |
| RAM authorization policies |
Cloud Governance Center | Cloud Governance Center | governance | √ | ○ | Operation |
| - |
Middleware
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Enterprise Distributed Application Service (EDAS) | - | edas | √ | √ | Resource |
| Manage RAM users |
Message Queue | Message Queue for Apache RocketMQ | mq | √ | √ | Resource |
| Grant permissions to RAM users |
Message Queue | Message Queue for MQTT | mq | √ | √ | Resource |
| Grant permissions to RAM users |
Message Queue | Message Queue for RabbitMQ | amqp | √ | √ | Resource |
| Grant permissions to RAM users |
Message Service | - | mns | √ | √ | Resource |
| Create a custom policy |
Application Configuration Management | - | acms | √ | √ | Resource | AliyunACMFullAccess | Access control |
Message Queue for Apache Kafka | - | alikafka | √ | √ | Service |
| Grant permissions to RAM users |
Application High Availability Service | - | ahas | √ | √ | Service |
| - |
Alibaba Cloud Service Mesh (ASM) | - | servicemesh | √ | √ | Resource | - | Overview |
EventBridge | - | eventbridge | √ | √ | Resource |
| Policies |
Media services and CDN
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
CDN | - | cdn | √ | √ | Resource |
| RAM authentication |
ApsaraVideo Media Processing (MPS) | - | mts | √ | √ | Service |
| - |
ApsaraVideo VOD (VOD) | - | vod | √ | √ | Operation |
| - |
ApsaraVideo Live | - | live | √ | √ | Resource |
| Sub-account console operating instructions |
Real-Time Communication | - | rtc | √ | √ | Resource | - | - |
Dynamic Route for CDN (DCDN) | - | dcdn | √ | √ | Resource |
| - |
Enterprise applications
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Direct Mail | - | dm | √ | √ | Operation |
| - |
API Gateway | - | apigateway | √ | √ | Service |
| Use RAM to manage user permissions for API Gateway |
Alibaba Mail | - | alimail | √ | ○ | Operation |
| - |
Resource Management | Resource Management | resourcemanager | √ | √ | Operation |
| RAM authorization |
Resource Management | Resource Sharing | resourcesharing | √ | √ | Operation |
| - |
Resource Management | the Tag service | tag | √ | √ | Operation |
| Tag |
Resource Management | Resource Center | resourcecenter | √ | √ | Operation |
| Permissions for a RAM user to access Resource Center |
BaaS | BaaS | baas | √ | √ | Resource |
| Hyperledger Fabric RAM authentication |
CloudQuotation (CQ) | - | assettech | √ | ○ | Service |
| - |
BizWorks | - | bizworks | √ | ○ | Service |
| - |
Domains and websites
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Alibaba Cloud DNS (DNS) | DNS | alidns | √ | √ | Resource |
| RAM authorization |
DNS | Alibaba Cloud Public DNS | pubdns | √ | √ | Resource |
| - |
Domains | - | domain | √ | √ | Resource | AliyunDomainFullAccess | Authentication rules for the Domains API |
Artificial intelligence
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Intelligent Speech Interaction | Intelligent Speech Interaction | nls | √ | √ | Service |
| - |
Machine Learning | - | pai | √ | √ | Service | - | - |
Machine Learning | - | paiplugin | ○ | √ | Operation |
| - |
Image search | - | imagesearch | √ | √ | Resource |
| Grant permissions to RAM users |
Machine Translation | - | alimt | √ | √ | Operation |
| - |
IoT
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
IoT Platform | - | iot | √ | √ | Resource |
| RAM user access |
Link IoT Edge | - | iot | √ | √ | Resource |
| Access resources of other Alibaba Cloud services |
Lindorm | Time Series Database (TSDB) | hitsdb | √ | √ | Operation | - | - |
Big data
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
DataWorks | - | dataworks | √ | √ | Operation | AliyunDataWorksFullAccess | Manage permissions on the DataWorks services and the entities in the DataWorks console by using RAM policies |
Quick BI | - | - | √ | √ | Service | - | - |
DataV | - | datav | √ | ○ | Service | AliyunDataVFullAccess | - |
Realtime Compute for Apache Flink | - | stream | √ | √ | Resource |
| Grant permissions to a RAM user |
Elasticsearch | - | elasticsearch | √ | √ | Resource |
| Types of resources that can be authorized |
E-MapReduce | E-MapReduce | emr | √ | √ | Service |
| - |
Log Service | - | log | √ | √ | Resource |
| RAM authentication rules |
Hologres | - | hologram | √ | √ | Resource |
| Grant permissions to a RAM user |
Developer services
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Apsara Devops | - | rdc | √ | √ | Resource |
| - |
Tracing Analysis | - | xtrace | √ | √ | Operation |
| - |
Security
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Security Center | - |
| √ | √ | Operation |
| - |
Server Guard | - | yundun-aegis | √ | √ | Service |
| - |
Anti-DDoS | Anti-DDoS | yundun-ddos | √ | √ | Service |
| - |
Anti-DDoS | Anti-DDoS Pro |
| √ | √ | Service |
| - |
Anti-DDoS | Anti-DDoS Premium |
| √ | ○ | Service |
| - |
GameShield | - | yundun-gameshield | √ | ○ | Service | AliyunYundunGameShieldReadOnlyAccess | - |
Web Application Firewall (WAF) | WAF | yundun-waf | √ | √ | Operation |
| - |
Certificate Management Service | - | yundun-cert | √ | √ | Service |
| - |
Cloud Firewall | - | yundun-cloudfirewall | √ | √ | Service |
| - |
Managed Security Service (MSSP) | - | mssp | √ | ○ | Service | - | - |
Content Moderation | - | yundun-greenweb | √ | √ | Service | AliyunYundunGreenWebFullAccess | - |
Bastionhost | Bastionhost | yundun-bastionhost | √ | ○ | Service |
| - |
Data Security Center (DSC) | - | yundun-sddp | √ | √ | Service |
| - |
Identity as a Service (IDaaS) | IDaaS | yundun-idaas | √ | ○ | Operation |
| - |
Key Management Service (KMS) | - | kms | √ | √ | Resource |
| Use RAM to control access to KMS resources |
RAM | RAM |
| √ | √ | Resource |
| RAM authentication |
RAM | CloudSSO | cloudsso | √ | ○ | Resource |
| - |
ActionTrail | - | actiontrail | √ | √ | Operation | - | RAM account authentication |
Technical support
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Ticket Management | - | support | √ | √ | Service | AliyunSupportFullAccess | - |
Alibaba Cloud Marketplace
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Alibaba Cloud Marketplace | - | acm | √ | × | Service | AliyunMarketplaceFullAccess | - |
Others
Alibaba Cloud service | Sub-service or sub-module | RAM code | Console | API | Authorization granularity | System policy | References |
---|---|---|---|---|---|---|---|
Billing Management | - |
| √ | √ | Operation |
| - |
ICP Filing | - |
| √ | ○ | Service | AliyunBeianFullAccess | - |