Create a RAM role that trusts an Alibaba Cloud account to enable cross-account access to Serverless App Engine (SAE) resources.
Use cases
Enterprise A has activated SAE and wants to delegate some of its business operations to Enterprise B:
-
Enterprise A wants to focus on its business systems and act only as the owner of SAE resources, delegating operations such as application deployment, management, auto scaling, one-click start and stop, and monitoring to Enterprise B.
-
Enterprise A does not need to manage permissions when employees join or leave Enterprise B. Enterprise B manages its own RAM users' access to Enterprise A's resources, including fine-grained permissions for its employees or applications.
-
If the partnership ends, Enterprise A can revoke Enterprise B's access at any time.
Step 1: Enterprise A creates a RAM role
Assume that Enterprise A and Enterprise B each have an Alibaba Cloud account: Account A and Account B.
-
Alibaba Cloud account A has the ID
1234************and the account aliascompany-a. -
Alibaba Cloud account B has the ID
2345************and the account aliascompany-b.
-
Log on to the RAM console by using Alibaba Cloud account A.
-
In the left-side navigation pane, choose .
-
On the Roles page, click Create Role.
-
On the Create Role page, configure the role.
-
Set Trusted Entity Type to Alibaba Cloud Account. For Select Trusted Alibaba Cloud Account, select Other Alibaba Cloud Account, and enter the ID of Alibaba Cloud account B. Then, click OK.
-
Enter
sae-adminfor Role Name and then click OK.ImportantTo allow only specific RAM users to assume this RAM role, use one of the following methods:
-
Modify the trust policy of the RAM role. For more information, see Example 1: Change the trusted entity of a RAM role to an Alibaba Cloud account.
-
Modify the permission policy that specifies which roles a RAM user can assume. For more information, see How do I specify the RAM role that a RAM user can assume?.
-
-
-
On the Basic Information page of the role, you can view details such as the RAM role name, creation time, and ARN.
-
RAM role name: sae-admin.
-
ARN:
acs:ram::1234************:role/sae-admin. -
trust policy:
NoteThe following policy allows RAM users in Alibaba Cloud account B to assume this RAM role.
{ "Statement": [ { "Action": "sts:AssumeRole", "Effect": "Allow", "Principal": { "RAM": [ "acs:ram::2345************:root" ] } } ], "Version": "1" }
-
Step 2: Enterprise A grants permissions to the RAM role
From the Roles page
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
On the Roles page, find the RAM role and click Grant Permission in the Actions column.
To grant permissions to multiple RAM roles at the same time, select the RAM roles and click Grant Permission below the list.
-
In the Grant Permission panel, grant permissions to the RAM role.
-
Select a scope for the authorization.
-
Alibaba Cloud Account: The permissions take effect on all resources within the current Alibaba Cloud account.
-
Resource Group: The permissions take effect only on resources within the specified resource group.
NotePermissions that are granted on a resource group take effect only if the cloud service and resource type support resource groups. For more information, see Services that work with Resource Group.
-
-
Select principals.
A principal is a RAM role that receives permissions. The system automatically selects the current RAM role.
-
Select permission policies.
A permission policy defines a set of permissions. You can select multiple policies.
-
System policy: A system policy is created and maintained by Alibaba Cloud. You can use system policies but you cannot modify them. For more information, see the "Cloud services and system policies" section of the Services that work with RAM topic.
NoteThe system automatically identifies high-risk system policies, such as AdministratorAccess and AliyunRAMFullAccess. Avoid granting high-risk permissions unless necessary.
-
Custom policy: You create and manage a custom policy. You can create, update, and delete custom policies. For more information about how to create a custom policy, see Create a custom permission policy.
-
-
Click OK.
-
-
Click close.
From the Grants page
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
On the Grants page, click Grant Permission.
-
In the Grant Permission panel, grant permissions to the RAM role.
-
Select a scope for the authorization.
-
Account: The permissions take effect on all resources within the current Alibaba Cloud account.
-
Resource Group: The permissions take effect only on resources within the specified resource group.
NotePermissions that are granted on a resource group take effect only if the cloud service and resource type support resource groups. For more information, see Services that work with Resource Group.
-
-
Select principals.
A principal is a RAM role that receives permissions. You can select multiple RAM roles.
-
Select permission policies.
A permission policy defines a set of permissions. You can select multiple policies.
-
System policy: A system policy is created and maintained by Alibaba Cloud. You can use system policies but you cannot modify them. For more information, see the "Cloud services and system policies" section of the Services that work with RAM topic.
NoteThe system automatically identifies high-risk system policies, such as AdministratorAccess and AliyunRAMFullAccess. Avoid granting high-risk permissions unless necessary.
-
Custom policy: You create and manage a custom policy. You can create, update, and delete custom policies. For more information about how to create a custom policy, see Create a custom permission policy.
-
-
Click OK.
-
-
Click close.
Step 3: Enterprise B creates a RAM user
-
Log on to the RAM console by using Alibaba Cloud account B.
-
Create a RAM user. For detailed instructions, see Create a RAM user.
Step 4: Enterprise B grants permissions to the RAM user
-
Log on to the RAM console by using Alibaba Cloud account B.
-
In the left-side navigation pane, choose .
-
On the Users page, find the target RAM user and click Add Permissions in the Actions column.
To grant permissions to multiple RAM users at the same time, select the RAM users and click Add Permissions below the list.
-
In the Policies section, enter AliyunSTSAssumeRoleAccess in the search box, select the policy to add it to the Selected list on the right, and then click OK.
-
Click Complete.
Step 5: Access cross-account resources
Security Token Service (STS) provides temporary access tokens with a custom validity period and specific permissions. An authorized principal, such as a RAM user or role, can obtain a token and then access Alibaba Cloud resources in one of the following ways:
Method 1: Use the console
The RAM user of Enterprise B can log on to the console to access the SAE resources of Enterprise A.
-
Log on to the RAM console as the RAM user of Alibaba Cloud account B.
For more information, see Log on to the Alibaba Cloud Management Console as a RAM user.
-
In the upper-right corner of the console, move the pointer over your profile picture and click Switch Role.
-
On the Switch Role page, enter the Account Alias and Role Name of Enterprise A and then click Submit.
After the role switch, the RAM user of Enterprise B can manage the Serverless App Engine resources of Enterprise A.
Method 2: Use an SDK
-
Obtain an access credential. This example uses the Java SDK.
-
Set the following environment variables in your runtime environment.
Parameter
Value
ALIBABA_CLOUD_ACCESS_KEY_ID
The AccessKey ID of the RAM user of Enterprise B
ALIBABA_CLOUD_ACCESS_KEY_SECRET
The AccessKey secret of the RAM user of Enterprise B
-
Run the following code. For more information, see Java SDK example and AssumeRole.
package com.aliyun.sample; import com.aliyun.sts20150401.models.AssumeRoleResponse; import com.aliyun.tea.TeaException; import com.google.gson.Gson; public class Sample { /** * <b>description</b> : * <p> * Initialize the client with credentials. * </p> * * @return Client * * @throws Exception */ public static com.aliyun.sts20150401.Client createClient() throws Exception { com.aliyun.credentials.Client credential = new com.aliyun.credentials.Client(); com.aliyun.teaopenapi.models.Config config = new com.aliyun.teaopenapi.models.Config().setCredential(credential); // For more information about endpoints, see https://api.alibabacloud.com/product/Sts. config.endpoint = "sts.cn-hangzhou.aliyuncs.com"; return new com.aliyun.sts20150401.Client(config); } public static void main(String[] args_) throws Exception { com.aliyun.sts20150401.Client client = Sample.createClient(); com.aliyun.sts20150401.models.AssumeRoleRequest assumeRoleRequest = new com.aliyun.sts20150401.models.AssumeRoleRequest(); com.aliyun.teautil.models.RuntimeOptions runtime = new com.aliyun.teautil.models.RuntimeOptions(); // Replace the value of RoleArn with the ARN of your role and specify a custom RoleSessionName. assumeRoleRequest.setRoleArn("acs:ram::1234************:role/sae-admin"); assumeRoleRequest.setRoleSessionName("Alice"); try { // If you copy the code to run it, print the API response. AssumeRoleResponse response = client.assumeRoleWithOptions(assumeRoleRequest, runtime); System.out.println(new Gson().toJson(response.body)); } catch (TeaException error) { // This is for demonstration only. In a production project, handle exceptions with care and do not ignore them. // Error message System.out.println(error.getMessage()); // Troubleshooting URL System.out.println(error.getData().get("Recommend")); com.aliyun.teautil.Common.assertAsString(error.message); } catch (Exception _error) { TeaException error = new TeaException(_error.getMessage(), _error); // This is for demonstration only. In a production project, handle exceptions with care and do not ignore them. // Error message System.out.println(error.getMessage()); // Troubleshooting URL System.out.println(error.getData().get("Recommend")); com.aliyun.teautil.Common.assertAsString(error.message); } } }NoteYou can call SAE API operations by using HTTP requests, SDKs, or OpenAPI Explorer. For more information, see API overview.
Expected output:
{ "requestId": "964E0EC5-575B-4FF5-8FD0-D4BD8025****", "assumedRoleUser": { "arn": "acs:ram::*************", "assumedRoleId": "*************" }, "credentials": { "securityToken": "*************", "accessKeyId": "STS.*************", "accessKeySecret": "*************", "expiration": "2021-05-28T11:23:19Z" } }
-
-
Use the returned access key pair and security token to create a new client. This grants Enterprise B's RAM user permission to manage SAE resources in Alibaba Cloud account A. The following example queries the namespaces in the SAE China (Hangzhou) region.
-
Set the following environment variables in your code's runtime environment.
Parameter
Value
ALIBABA_CLOUD_ACCESS_KEY_ID
The
credentials.accessKeyIdfrom the response in the previous stepALIBABA_CLOUD_ACCESS_KEY_SECRET
The
credentials.accessKeySecretfrom the response in the previous stepALIBABA_CLOUD_SECURITY_TOKEN
The
credentials.securityTokenfrom the response in the previous step -
Run the following code.
package com.aliyun.sample; import com.aliyun.sae20190506.models.DescribeNamespacesResponse; import com.aliyun.tea.*; import com.google.gson.Gson; public class Sample { /** * <b>description</b> : * <p> * Initialize the client with credentials. * </p> * * @return Client * * @throws Exception */ public static com.aliyun.sae20190506.Client createClient() throws Exception { com.aliyun.credentials.Client credential = new com.aliyun.credentials.Client(); com.aliyun.teaopenapi.models.Config config = new com.aliyun.teaopenapi.models.Config().setCredential(credential); // For more information about endpoints, see https://api.alibabacloud.com/product/sae. config.endpoint = "sae.cn-hangzhou.aliyuncs.com"; return new com.aliyun.sae20190506.Client(config); } public static void main(String[] args_) throws Exception { com.aliyun.sae20190506.Client client = Sample.createClient(); com.aliyun.sae20190506.models.DescribeNamespacesRequest describeNamespacesRequest = new com.aliyun.sae20190506.models.DescribeNamespacesRequest(); com.aliyun.teautil.models.RuntimeOptions runtime = new com.aliyun.teautil.models.RuntimeOptions(); java.util.Map<String, String> headers = new java.util.HashMap<>(); // Replace the following parameters based on your requirements. describeNamespacesRequest.setCurrentPage(1); describeNamespacesRequest.setPageSize(10); try { DescribeNamespacesResponse response = client .describeNamespacesWithOptions(describeNamespacesRequest, headers, runtime); System.out.println(new Gson().toJson(response.body)); } catch (TeaException error) { // This is for demonstration only. In a production project, handle exceptions with care and do not ignore them. // Error message System.out.println(error.getMessage()); // Troubleshooting URL System.out.println(error.getData().get("Recommend")); com.aliyun.teautil.Common.assertAsString(error.message); } catch (Exception _error) { TeaException error = new TeaException(_error.getMessage(), _error); // This is for demonstration only. In a production project, handle exceptions with care and do not ignore them. // Error message System.out.println(error.getMessage()); // Troubleshooting URL System.out.println(error.getData().get("Recommend")); com.aliyun.teautil.Common.assertAsString(error.message); } } }
-
Revoke access
When the partnership between Enterprise A and Enterprise B ends, Enterprise A can revoke access by removing permissions from the RAM role and then deleting it. This prevents RAM users in Alibaba Cloud account B from assuming the role to access resources in Alibaba Cloud account A.
Before you delete a RAM role, you must revoke the permissions granted to it. For more information, see Revoke permissions from a RAM role.
-
Log on to the RAM console by using Alibaba Cloud account A.
-
In the navigation pane on the left, go to .
-
On the Roles page, find the RAM role that you want to delete and click Delete Role in the Actions column.
-
In the Delete Role dialog box, enter the RAM role name and click Delete Role.
Role names are case-sensitive. The name you enter must exactly match the name displayed in the role list. Otherwise, the Delete Role button remains disabled. Service-linked roles often use camelCase names, such as
AliyunServiceRoleForSmartService. To avoid errors, copy the role name from the role list and paste it into the confirmation text box.If policies are attached to the RAM role, they are automatically detached when you delete the role.
Deleting a service-linked role that is in use by its corresponding cloud service will fail. You must first go to the cloud service console to remove its dependency on the role, and then retry the deletion. For more information about service-linked roles, see Service-linked roles.
After you submit the deletion request, the role's status changes to Deleting. Once the asynchronous deletion is complete, the role is removed from the role list.
If a deletion task fails, click Role Deletion Tasks in the upper-right corner of the role list to view the details.