When an Alibaba Cloud account has multiple RAM users, you can create approval rules to reduce operational risks. With these rules, critical operations performed by a RAM user in SAE must be approved by the Alibaba Cloud account or another RAM user with approval permissions. This enables fine-grained control over RAM user permissions. This topic describes how to create approval rules, deploy an application that requires approval, and manage approval records.
Prerequisites
-
An application is created and is enabled.
-
A contact has been created. Only contacts can become approvers.
Step 1: Grant permissions to a RAM user
-
If an Alibaba Cloud account initiates the operation, you can skip this step because no additional permissions are required.
-
If a RAM user with the
AliyunSAEFullAccesspermission initiates the operation, you can skip this step.
1. Create a custom permission policy
-
Log on to the RAM console by using your Alibaba Cloud account. In the left-side navigation pane, choose . On the Policies page, click Create Policy.
-
On the Create Policy page, click the JSON tab. Paste the following policy into the editor and click Next to edit policy information.
{ "Version": "1", "Statement": [ { "Effect": "Allow", "Action": [ "sae:*OperationApproval*" ], "Resource": [ "acs:sae:*:*:*" ] } ] } -
On the Edit Policy Information page, specify a Name and Note for the custom policy and click OK.
2. Grant permissions to a RAM user
-
In the left-side navigation pane, choose . On the Users page, click the logon name of the target user.
-
On the user details page, click the Permissions tab. On the User Policies tab, click Grant Permission.
-
In the Grant Permission panel, click the Custom Policy tab, select the custom policy you created, and then click OK.
In the Added section, verify the permission and click Grant Permission.
After granting the permissions, you can view them on the User Policies tab of the RAM user's details page.
Step 2: Create an approval rule
Both Alibaba Cloud accounts and RAM users who will manage approvals must create approval rules.
-
Log on to the SAE console. In the left-side navigation pane, choose .
-
In the left-side navigation pane, click Approval Settings. On the Approval Settings page, click Create Approval Setting.
-
In the Create Approval Setting panel, configure the following parameters and click OK.
-
Approval Scope Settings:
-
Resources: Filter resources by selecting a Region, Namespace, and Application from the drop-down lists.
-
Region: You can select All Regions or a specific region.
-
If you select All Regions, all applications in all namespaces across all regions are selected by default.
-
If you select a specific region, you can further filter by selecting a namespace and an application.
-
-
Namespace: You can select All Namespaces or a specific namespace.
-
If you select All Namespaces, all applications in all namespaces within the target region are selected by default.
-
If you select a specific namespace, you can then filter for specific applications.
-
-
Application or Task: You can select all applications, or one or more specific applications.
-
-
Operation Type: Only the Publish Change type is supported. This includes the Deploy Application and Roll Back to a Previous Version actions.
-
-
Whitelist Settings: From the drop-down list, select the target RAM users. You can select multiple users and use fuzzy search.
RAM users in the whitelist can perform operations on applications within the approval scope without requiring approval.
-
Approver Settings: From the Approver drop-down list, select one or more approvers.
Note-
Only contacts can be approvers. If the account that you need is not in the drop-down list, click Contact Management to add it. For more information, see Manage contacts.
-
The Alibaba Cloud account is the default approver for all rules. It can receive all approval notifications and manage all approval records. If you do not add contact information for the Alibaba Cloud account owner, the owner does not receive approval notifications, but can still perform approval operations.
-
An Alibaba Cloud account can add all RAM users as approvers. If a RAM user does not have the
ListUserspermission, they can add only themselves as a contact. If they have theListUserspermission, they can add other RAM users as contacts. For more information about how to grant permissions, see Grant permissions to a RAM user.
-
-
-
Optional: On the Approval Settings page, you can Edit or Delete existing approval rules.
-
Edit: In the Actions column, click Edit. In the Change Approval Settings panel, modify the parameters.
-
Delete: In the Actions column, click Delete. In the dialog box that appears, click OK.
-
Step 3: Change applications with a RAM user
The deployment process for a RAM user varies depending on whether approval rules are configured.
-
Without approval rules: RAM users can operate on resources directly without requiring approval.
-
With approval rules: If a RAM user is not on the whitelist for a matching approval rule, their operation requires approval before it can proceed. Perform the following steps:
After an approver approves or rejects a request, the system sends a notification with the result to the contact methods you defined. For more information, see Manage contacts.
-
Log on to the SAE console by using a RAM user. In the left-side navigation pane, choose . Then, select the target region and namespace, and click the name of the target application.
-
Change the application.
Deploy application
-
On the Basic Information page of the target application, click Deploy Application. Then, modify the configuration as needed and select a release strategy.
SAE supports the Phased Release and Canary Release strategies. For more information, see Deploy an application in a single batch, Deploy an application in batches, and Deploy an application by canary release.
-
Click OK.
Roll back version
-
On the Basic Information page of the target application, click Roll Back to a Previous Version.
-
In the Roll Back to a Previous Version panel, select the version to which you want to roll back, set a release strategy, and then click OK. For more information, see Roll back to a previous version.
-
-
After you initiate an application deployment, a Deploy Application Request dialog box appears and indicates that your change request has been submitted. You can click OK and then check the approval progress on the Approval Records page.
If you perform a Roll Back to a Previous Version, this dialog box does not appear. You can view the details directly on the Change Details page.
You can also configure your contact methods on the Contact Management page to receive SMS notifications upon approval.
NoteAfter you submit an approval request, check the Change Details page of the application. The execution status of this change remains To Be Approved until an approver takes action.
-
If the approver approves the request: The execution status on the Change Details page changes to Approved. You can then click Deploy Application and wait for the change to complete.
-
If the approver rejects the request: The execution status on the Change Details page automatically changes to Execution Terminated. See the optional steps below for details on viewing the rejection reason.
-
-
Optional: In the left-side navigation pane, choose . On the Approval Records page, click the Initiated by Me tab to view the approval progress.
On the Initiated by Me tab of the Approval Records page, you can perform the following operations:
-
Send a reminder: In the Actions column, click Reminder. In the dialog box that appears, click OK to send a reminder to the approvers.
-
Cancel the request: In the Actions column, click Cancel. In the dialog box that appears, click OK to withdraw the change request.
-
View the application for this change: Click the application name in the Namespace: Application column to go to the Basic Information page of the target application.
-
View rejection reason: Hover over the
icon next to Rejected to view the reason for the rejection.
-
Step 4: Manage approval records as an approver
-
Log on to the SAE console by using an account that has approval permissions. In the left-side navigation pane, choose .
-
In the left-side navigation pane, click Approval Records. On the To Be Approved tab, manage change requests submitted by other RAM users.
Optional: You can perform the following operations on this page:
-
View Details: In the Actions column of the target record, click View Details to view the details of the application change.
-
Approve: In the Actions column of the target record, click Approve. In the dialog box that appears, click OK to approve the change request.
-
Reject: In the Actions column, click Reject. In the Confirm Approval Rejection dialog box, enter a reason for the rejection and click OK.
-
Transfer: In the Actions column, click Transfer. In the Approval Transfer dialog box, select a new approver and click OK.
NoteIf you have multiple pending approval records, you can select the check boxes next to the target records and then perform Batch Approve, Batch Reject, or Batch Transfer operations.
-
-
Related operations: On the Handled tab of the Approval Records page, you can view the change requests that you have processed. You can also click an application name in the Namespace: Application column to go to the application's Basic Information page for more details.