All Products
Search
Document Center

Virtual Private Cloud:System policies for VPC

Last Updated:Jun 06, 2024

What is a system policy?

A policy defines a set of permissions that are described based on the policy structure and syntax. You can use policies to describe the authorized resource sets, authorized operation sets, and authorization conditions. Alibaba Cloud Resource Access Management (RAM) provides system policies and custom policies. All system policies are created and updated by Alibaba Cloud. You can use system policies, but you cannot modify them. You can manage and update custom policies based on your business requirements. You can create, update, and delete custom policies. During service iteration, VPC adds new permissions to system policies to support new features and capabilities. The update of a system policy affects all RAM identities to which the policy is attached, including RAM users, RAM user groups, and RAM roles. For more information about RAM policies, see Policy overview.

Note

System policies are designed for new users to quickly get started with Alibaba Cloud products on the management console, though they also enable the use of more advanced methods like API operations or CLI commands. If you are familiar with the advanced methods, we recommend that you use custom policies to implement finer-grained control on who is permitted to call what API operations, thereby improving security.

System policies can be classified into service system policies, service role policies, and service-linked role policies. Some cloud services provide only one or two of the three types of policies. For more information, see the policy types that are described in the following section.

Service system policies

AliyunIpv6FullAccess

The AliyunIpv6FullAccess policy: Ipv6 All permission policies. It can be attached to RAM identities.

AliyunIpv6FullAccess

AliyunIpv6ReadOnlyAccess

The AliyunIpv6ReadOnlyAccess policy: Ipv6 Read-only policy. It can be attached to RAM identities.

AliyunIpv6ReadOnlyAccess

AliyunTrafficMirrorFullAccess

The AliyunTrafficMirrorFullAccess policy: Provides full access to Traffic Mirror via Management Console. It can be attached to RAM identities.

AliyunTrafficMirrorFullAccess

AliyunTrafficMirrorReadOnlyAccess

The AliyunTrafficMirrorReadOnlyAccess policy: Provides read-only access to Traffic Mirror via Management Console. It can be attached to RAM identities.

AliyunTrafficMirrorReadOnlyAccess

AliyunVPCFullAccess

The AliyunVPCFullAccess policy: Provides full access to Virtual Private Cloud(VPC) via Management Console. It can be attached to RAM identities.

AliyunVPCFullAccess

AliyunVPCNetworkIntelligenceReadOnlyAccess

The AliyunVPCNetworkIntelligenceReadOnlyAccess policy: Provides read-only access to Network Intelligence via Management Console. It can be attached to RAM identities.

AliyunVPCNetworkIntelligenceReadOnlyAccess

AliyunVPCPrefixListAccess

The AliyunVPCPrefixListAccess policy: Provides access to Vpc PrefixList via Management Console. It can be attached to RAM identities.

AliyunVPCPrefixListAccess

AliyunVPCPrefixListReadOnlyAccess

The AliyunVPCPrefixListReadOnlyAccess policy: Provides read-only access to Vpc PrefixList via Management Console. It can be attached to RAM identities.

AliyunVPCPrefixListReadOnlyAccess

AliyunVPCReadOnlyAccess

The AliyunVPCReadOnlyAccess policy: Provides read-only access to Virtual Private Cloud(VPC) via Management Console. It can be attached to RAM identities.

AliyunVPCReadOnlyAccess

References

By default, RAM identities do not have any permissions. RAM identities can access cloud resources within an Alibaba Cloud account only after an account administrator grants the required permissions to the RAM identities. To ensure resource security, we recommend that you grant only the required permissions to the RAM identities based on the principle of least privilege. For more information, see the following topics: