Resource Center uses service-linked roles (SLRs) to access other cloud services on your behalf. You can create, view, and delete these roles as needed.
Overview
A service-linked role (SLR) is a RAM role whose trusted entity is an Alibaba Cloud service. SLRs enable secure cross-service access. The following table lists the SLRs provided by Resource Center.
|
Service-linked role for Resource Center |
Service identifier |
Permission policy |
|
rmc.resourcemanager.aliyuncs.com |
AliyunServiceRolePolicyForResourceMetaCenter |
|
|
delivery.resourcecenter.aliyuncs.com |
AliyunServiceRolePolicyForResourceCenterDelivery |
For more information about SLR concepts, see Service-linked roles.
AliyunServiceRoleForResourceMetaCenter
Scenarios
Resource Center assumes this role to access resources across cloud services, providing a unified view of your resources and enabling search across accounts, services, and regions.
Each resource retrieval generates an ActionTrail event for security compliance auditing.
Create the service-linked role
The system automatically creates this role when you:
-
Activate Resource Center. The role is created in the current logon account.
-
Enable cross-account resource search. The role is created for each member in your resource directory.
View role details
After the role is created, go to the Roles page of the RAM console and search for AliyunServiceRoleForResourceMetaCenter. The role details page shows:
-
Basic information
The Basic Information section shows the role name, creation time, Alibaba Cloud Resource Name (ARN), and description.
-
Permission policy
On the Permissions tab, click AliyunServiceRolePolicyForResourceMetaCenter to view the policy.
NoteThis policy is visible only on the role details page, not on the main Policy Name page of the RAM console.
-
Trust policy
On the Trust Policy tab, view the trust policy attached to the role. A trust policy defines the trusted entities that can assume a RAM role. For an SLR, the trusted entity is a cloud service. Check the
Servicefield to identify the trusted entity.
For detailed steps, see View the information about a RAM role.
Delete the service-linked role
After a service-linked role is deleted, the features that depend on the role cannot be used. Proceed with caution.
After you deactivate Resource Center, you can delete this role in the RAM console. For detailed steps, see Delete a RAM role.
AliyunServiceRoleForResourceCenterDelivery
Scenarios
Resource Center assumes this role during resource delivery tasks to access resources across other cloud services.
Create the service-linked role
The system automatically creates this role in the current logon account when you create a resource delivery task. For more information, see Create a resource delivery task in single-account mode.
View role details
After the role is created, go to the Roles page of the RAM console and search for AliyunServiceRoleForResourceCenterDelivery. The role details page shows:
-
Basic information
The Basic Information section shows the role name, creation time, ARN, and description.
-
Permission policy
On the Permissions tab, click AliyunServiceRolePolicyForResourceCenterDelivery to view the policy.
NoteThis policy is visible only on the role details page, not on the main Policy Name page of the RAM console.
-
Trust policy
On the Trust Policy tab, view the trust policy attached to the role. A trust policy defines the trusted entities that can assume a RAM role. For an SLR, the trusted entity is a cloud service. Check the
Servicefield to identify the trusted entity.
For detailed steps, see View the information about a RAM role.
Delete the service-linked role
After a service-linked role is deleted, the features that depend on the role cannot be used. Proceed with caution.
After you deactivate Resource Center, you can delete this role in the RAM console. For detailed steps, see Delete a RAM role.