All Products
Search
Document Center

Simple Log Service:,

Last Updated:Aug 28, 2026

An Alibaba Cloud account can grant another Alibaba Cloud account specific permissions on its resources by creating and authorizing a Resource Access Management (RAM) role. The other Alibaba Cloud account then grants the AssumeRole permission to a RAM user that belongs to it. That RAM user calls a Security Token Service (STS) API operation to obtain a temporary AccessKey pair and a token, and then calls Simple Log Service API operations.

Solution overview

Assume that Enterprise A owns Alibaba Cloud account A and Enterprise B owns Alibaba Cloud account B. To meet requirements such as business isolation or project outsourcing, Enterprise A wants to authorize Enterprise B to maintain part of its Simple Log Service business. The requirements are as follows:

  • Alibaba Cloud account B has the permissions to write data to Simple Log Service of Alibaba Cloud account A and to use consumer groups.

  • The specified RAM user of Alibaba Cloud account B also has the write and consumer group permissions on Simple Log Service.

  • Alibaba Cloud account B can obtain temporary STS credentials to access Simple Log Service API operations. For more information, see What is STS?.

    Based on the preceding requirements, perform the following steps to complete the configuration:

  1. Step 1: Alibaba Cloud account A creates and authorizes a RAM role for Alibaba Cloud account B

  2. Step 2: Alibaba Cloud account B creates and authorizes the RAM user user-b

  3. Step 3: The RAM user user-b obtains temporary STS credentials

    A complete Java example that calls the AssumeRole operation and then writes data to Simple Log Service is provided in Sample code.

Prerequisites

  • Alibaba Cloud accounts — Alibaba Cloud account A owns the Simple Log Service resources, and Alibaba Cloud account B is the account that Alibaba Cloud account A authorizes.

  • Simple Log Service resources — A project and a LogStore exist in Alibaba Cloud account A. The RAM user of Alibaba Cloud account B writes data to this project and LogStore.

Limits

Before you configure cross-account access to Simple Log Service, note the following limits:

  • Caller identity — Only a RAM user (sub-account) can call the AssumeRole operation. The AccessKey pair of an Alibaba Cloud account cannot call AssumeRole.

  • Credential validity — The temporary AccessKey pair and the security token expire in one hour. Call the AssumeRole operation again after they expire.

  • Region — STS currently supports only cn-hangzhou. Therefore, the project that you write data to must reside in the cn-hangzhou region.

Step 1: Alibaba Cloud account A creates and authorizes a RAM role for Alibaba Cloud account B

In Alibaba Cloud account A, create a RAM role, specify Alibaba Cloud account B as the account that assumes the role, and grant the role the specified Simple Log Service permissions.

Create the RAM role in the RAM console. The following steps describe the console method in detail. To create the RAM role programmatically, call the CreateRole operation of the RAM API instead. For details, see CreateRole. For details about how to create RAM identities and grant permissions to them, see Create a RAM user and grant permissions.

  1. Use Alibaba Cloud account A to log on to the RAM console.

  2. Create a RAM role and specify Alibaba Cloud account B as the account that assumes the role. For instructions, see Create a RAM role for a trusted Alibaba Cloud account. Record the ARN of the role. Step 3 uses the ARN as the value of RoleArn. You can obtain the ARN on the details page of the role in the RAM console: https://ram.console.alibabacloud.com/#/role/detail/<specified_rolename>/info.

  3. Create a custom policy. On the JSON tab of the Create Policy page, replace the existing script in the code editor with the following policy document. For more information, see Using the script editor.

    Select the authorization script based on the permissions that you grant to the RAM role:

    • Write data only — Use the script on the Write data only tab.

    • Obtain data by using the consumer library — Use the script on the Obtain data by using the consumer library tab.

    • (Recommended for the scenario in this topic) Both write and consumer group permissions — Merge the two scripts into one policy document: keep "Version": "1", "Effect": "Allow", and "Resource": "*" unchanged, and list the action from the Write data only tab together with the seven actions from the Obtain data by using the consumer library tab in a single Action array. The scenario in this topic requires write permissions and consumer group permissions.

    Write data only

    Write data only

    {
      "Version": "1",
      "Statement": [
        {
          "Action": "log:PostLogStoreLogs",
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }

    Obtain data by using the consumer library

    Obtain data by using the consumer library

    {
      "Version": "1",
      "Statement": [
        {
          "Action": [
             "log:GetCursorOrData",
             "log:CreateConsumerGroup",
             "log:ListConsumerGroup",
             "log:ConsumerGroupUpdateCheckPoint",
             "log:ConsumerGroupHeartBeat",
             "log:GetConsumerGroupCheckPoint",
             "log:UpdateConsumerGroup"
          ],
          "Resource": "*",
          "Effect": "Allow"
        }
      ]
    }
  4. Attach the created custom policy to the RAM role. For more information, see Manage permissions for a RAM role.

Resource scope

Both of the preceding authorization scripts set "Resource": "*", which grants permissions on all projects and LogStores of the specified user. To grant permissions on a specific project or LogStore, replace "Resource": "*" with one of the following values:

  • To grant permissions on a specific project: acs:log::{projectOwnerAliUid}:project/{projectName}/.

  • To grant permissions on a specific LogStore: acs:log::{projectOwnerAliUid}:project/{projectName}/logstore/{logstoreName}/.

    For the complete description of resources, see Resources.

Step 2: Alibaba Cloud account B creates and authorizes the RAM user user-b

In Alibaba Cloud account B, create the RAM user user-b and grant the user the AliyunSTSAssumeRoleAccess system policy, which allows the user to call the AssumeRole operation of STS.

  1. Use Alibaba Cloud account B to log on to the RAM console.

  2. Create a RAM user named user-b. For Access Mode, select Console Access and Using permanent AccessKey to access. For more information, see Create a RAM user. Record the AccessKey ID and the AccessKey secret of user-b. Step 3 uses them to call the AssumeRole operation.

  3. Attach the AliyunSTSAssumeRoleAccess policy to the RAM user. This way, the RAM user can assume the RAM role to obtain Security Token Service (STS) tokens. For more information, see Manage RAM user permissions.

Step 3: The RAM user user-b obtains temporary STS credentials

In Alibaba Cloud account B, use the AccessKey pair of the RAM user user-b to obtain temporary STS credentials, and then use the credentials to access the Simple Log Service resources of Alibaba Cloud account A. This step requires the ARN of the RAM role from Step 1 and the AccessKey pair of user-b from Step 2.

  1. Call the STS AssumeRole operation to obtain a temporary AccessKey pair and a token. For details, see AssumeRole.

    Call the operation by using an STS SDK. For details, see STS SDK overview.

  2. Call Simple Log Service API operations with the temporary credentials. For information about Simple Log Service SDKs, see SDK Reference. For an example that calls AssumeRole and then writes data, see Sample code.

Sample code

The following sample code is based on the Java SDK. It uses the scenario in which the RAM user user-b writes data to a project of Alibaba Cloud account A by using STS as an example. The sample uses the Simple Log Service Java SDK (the com.aliyun.openservices.log packages) and the STS SDK (the com.aliyuncs packages). Before you run the sample, replace the AccessKey pair, the role ARN, the project name, and the LogStore name with your own values.

Warning

The sample hardcodes the AccessKey pair of the RAM user in the source code and prints the temporary AccessKey pair and the security token to the standard output. Both practices are for demonstration only.

package com.aliyun.openservices.log.sample;

import java.util.Date;
import java.util.Vector;

import com.aliyun.openservices.log.Client;
import com.aliyun.openservices.log.common.LogItem;
import com.aliyun.openservices.log.exception.LogException;
import com.aliyun.openservices.log.request.PutLogsRequest;
import com.aliyuncs.DefaultAcsClient;
import com.aliyuncs.exceptions.ClientException;
import com.aliyuncs.http.MethodType;
import com.aliyuncs.http.ProtocolType;
import com.aliyuncs.profile.DefaultProfile;
import com.aliyuncs.profile.IClientProfile;
import com.aliyuncs.sts.model.v20150401.AssumeRoleRequest;
import com.aliyuncs.sts.model.v20150401.AssumeRoleResponse;

public class StsSample {
      // STS currently supports only "cn-hangzhou".
      public static final String REGION_CN_HANGZHOU = "cn-hangzhou";
      // The current STS API version.
      public static final String STS_API_VERSION = "2015-04-01";
      static AssumeRoleResponse assumeRole(String accessKeyId, String accessKeySecret,
                                           String roleArn, String roleSessionName, String policy,
                                           ProtocolType protocolType) throws ClientException {
        try {
          // Construct an Alibaba Cloud AcsClient to call OpenAPI.
          IClientProfile profile = DefaultProfile.getProfile(REGION_CN_HANGZHOU, accessKeyId, accessKeySecret);
          DefaultAcsClient client = new DefaultAcsClient(profile);
          // Create an AssumeRoleRequest object.
          final AssumeRoleRequest request = new AssumeRoleRequest();
          request.setVersion(STS_API_VERSION);
          request.setMethod(MethodType.POST);
          request.setProtocol(protocolType);
          request.setRoleArn(roleArn);
          request.setRoleSessionName(roleSessionName);
          request.setPolicy(policy);
          // Send the request.
          final AssumeRoleResponse response = client.getAcsResponse(request);
          return response;
        } catch (ClientException e) {
          throw e;
        }
      }
      public static void main(String[] args) {
        // Only a RAM user (sub-account) can call the AssumeRole operation.
        // The AccessKey pair of an Alibaba Cloud account cannot call AssumeRole.
        // Create a RAM user in the RAM console (https://ram.console.alibabacloud.com) and create an AccessKey pair for this RAM user.
        String accessKeyId = "<subaccountaccesskey>";
        String accessKeySecret = "<subaccountaccesssecret>";
        // The AssumeRole API parameters are RoleArn, RoleSessionName, Policy, and DurationSeconds.
        // You can obtain the RoleArn in the RAM console.
        // https://ram.console.alibabacloud.com/#/role/detail/<specified_rolename>/info
        String roleArn = "<rolearn found in web console>";
        // RoleSessionName is the name of the temporary token, which is mainly used for auditing.
        String roleSessionName = "bluemix-001";
        String policy = "{\n" +
                "    \"Version\": \"1\", \n" +
                "    \"Statement\": [\n" +
                "        {\n" +
                "            \"Action\": \"log:PostLogStoreLogs\",\n" +
                "            \"Resource\": \"*\",\n" +
                "            \"Effect\": \"Allow\"\n" +
                "        }\n" +
                "    ]\n" +
                "}";
        System.out.println(policy);
        // Only HTTPS is supported here.
        ProtocolType protocolType = ProtocolType.HTTPS;
        AssumeRoleResponse response = new AssumeRoleResponse();
        try {
          response = assumeRole(accessKeyId, accessKeySecret,
                  roleArn, roleSessionName, policy, protocolType);
          System.out.println("Expiration: " + response.getCredentials().getExpiration());
          System.out.println("Access Key Id: " + response.getCredentials().getAccessKeyId());
          System.out.println("Access Key Secret: " + response.getCredentials().getAccessKeySecret());
          System.out.println("Security Token: " + response.getCredentials().getSecurityToken());
        } catch (ClientException e) {
          System.out.println("Failed to get a token.");
          System.out.println("Error code: " + e.getErrCode());
          System.out.println("Error message: " + e.getErrMsg());
        }

        // Simple Log Service parameters.
        // For information about Simple Log Service endpoints, see https://www.alibabacloud.com/help/en/sls/developer-reference/api-sls-2020-12-30-endpoint
        String logServiceEndpoint = "cn-hangzhou.log.aliyuncs.com";
        // This means that the project must reside in the cn-hangzhou region.
        String project = "<log service project name>";
        String logstore = "<log service logstore name>";

        // Construct a Simple Log Service client object.
        Client client = new Client(logServiceEndpoint, 
                response.getCredentials().getAccessKeyId(), 
                response.getCredentials().getAccessKeySecret());
        // Note: The AccessKey pair and the security token expire in one hour.
        // You must call the AssumeRole operation again after they expire.
        client.SetSecurityToken(response.getCredentials().getSecurityToken());
        Vector<LogItem> logGroup = new Vector<LogItem>();
        LogItem logItem = new LogItem((int) (new Date().getTime() / 1000));
        logItem.PushBack("StsSample", "Send Data");
        logGroup.add(logItem);

        PutLogsRequest req2 = new PutLogsRequest(project, logstore, "", "", logGroup);
        try {
            client.PutLogs(req2);
        } catch (LogException e) {
            System.out.println("Failed to send data.");
            System.out.println("Error code: " + e.GetErrorCode());
            System.out.println("Error message: " + e.GetErrorMessage());
        }
      }
}

When the AssumeRole call succeeds, the sample prints the expiration time of the credentials, the temporary AccessKey ID, the AccessKey secret, and the security token. If the call fails, the sample prints Failed to get a token. with the error code and the error message. If the data write fails, the sample prints Failed to send data. with the Simple Log Service error code and error message.