Mengkueri detail aturan tertentu dalam grup akun yang ditentukan.
Deskripsi operasi
Topik ini memberikan contoh cara mengkueri detail aturan cr-7f7d626622af0041**** dalam grup akun ca-7f00626622af0041****.
Coba sekarang
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
config:GetAggregateConfigRule |
get |
*AggregateConfigRule
|
None | None |
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| ConfigRuleId |
string |
Yes |
ID aturan. Untuk informasi selengkapnya, lihat ListAggregateConfigRules. |
cr-7f7d626622af0041**** |
| AggregatorId |
string |
Yes |
ID grup akun. Untuk informasi selengkapnya, lihat ListAggregators. |
ca-7f00626622af0041**** |
Tag
deprecated
|
array<object> |
No |
Tag. Parameter ini tidak digunakan lagi. Jika Anda menentukan parameter ini, nilainya tidak akan berlaku. |
|
|
object |
No |
Tag dari sumber daya. Parameter ini tidak digunakan lagi. Jika Anda menentukan parameter ini, nilainya tidak akan berlaku. Anda dapat menambahkan maksimal 20 tag. |
||
| Key |
string |
No |
Kunci tag dari sumber daya. Anda dapat menambahkan maksimal 20 kunci tag. |
key-1 |
| Value |
string |
No |
Nilai tag dari sumber daya. Anda dapat menambahkan maksimal 20 nilai tag. |
value-1 |
Untuk informasi selengkapnya tentang parameter permintaan umum, lihat Parameter umum.
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
Tidak ada. |
||
| RequestId |
string |
ID permintaan. |
811234F4-C3AB-4D15-B90B-F55016D1B5AA |
| ConfigRule |
object |
Detail aturan. |
|
| RiskLevel |
integer |
Tingkat risiko aturan. Nilai yang valid:
|
1 |
| InputParameters |
object |
Parameter input aturan. |
{"tag1Key":"ECS","tag1Value":"test"} |
| Source |
object |
Sumber aturan. |
|
| SourceDetails |
array<object> |
The details of the rule source. |
|
|
object |
Not applicable. |
||
| MessageType |
string |
The trigger type of the rule. Valid values:
|
ConfigurationItemChangeNotification |
| EventSource |
string |
The event source. Catatan
Only Cloud Config events are supported: aliyun.config. |
aliyun.config |
| MaximumExecutionFrequency |
string |
The frequency at which the rule is executed. Valid values:
|
One_Hour |
| Owner |
string |
The owner of the rule. Valid values:
|
ALIYUN |
| Identifier |
string |
The identifier of the rule.
|
acs:fc:cn-hangzhou:100931896542****:services/ConfigService.LATEST/functions/specific-config |
| ConfigRuleState |
string |
Status aturan. Nilai yang valid:
|
ACTIVE |
| MaximumExecutionFrequency |
string |
Frekuensi eksekusi aturan.
|
One_Hour |
| ManagedRule |
object |
Detail aturan terkelola. |
|
| SourceDetails |
array<object> |
The details of the managed rule source. |
|
|
object |
No description is available. |
||
| MessageType |
string |
The trigger type of the rule. Valid values:
|
ConfigurationItemChangeNotification |
| EventSource |
string |
The event source. Catatan
Only Cloud Config events are supported: aliyun.config. |
aliyun.config |
| MaximumExecutionFrequency |
string |
The frequency at which the rule is executed.
|
One_Hour |
| Description |
string |
The description of the managed rule. |
ECS磁盘未因欠费或安全等原因而被锁定,视为“合规”。 |
| Labels |
array |
A list of labels for the managed rule. |
|
|
string |
The label of the managed rule. |
["RAM","USer"] |
|
| Identifier |
string |
The identifier of the managed rule. |
ram-user-mfa-check |
| OptionalInputParameterDetails |
object |
The details of the optional input parameters for the managed rule. |
{} |
| ManagedRuleName |
string |
The name of the managed rule. |
RAM用户开启MFA |
| CompulsoryInputParameterDetails |
object |
The details of the required input parameters for the managed rule. |
{} |
| ConfigRuleArn |
string |
ARN dari aturan. |
acs:config::100931896542****:rule/cr-7f7d626622af0041**** |
| Description |
string |
Deskripsi aturan. |
RAM用户开启MFA,视为“合规”。 |
| CreateBy |
object |
Informasi tentang pembuat aturan. |
|
| CompliancePackId |
string |
The ID of the compliance package. |
cp-541e626622af008**** |
| AggregatorName |
string |
The name of the account group. |
Test_Group |
| CompliancePackName |
string |
The name of the compliance package. |
OSS合规基线 |
| CreatorName |
string |
The name of the rule creator. |
Alice |
| CreatorType |
string |
The type of the rule creator. Only |
AGGREGATOR |
| CreatorId |
string |
The ID of the account that created the rule. |
100931896542**** |
| AggregatorId |
string |
The ID of the account group. |
ca-04b3fd170e340007**** |
| ConfigRuleName |
string |
Nama aturan. |
RAM用户开启MFA |
| ConfigRuleEvaluationStatus |
object |
Status eksekusi aturan. |
|
| LastErrorCode |
string |
The error code returned for the last failed execution of the rule. |
TimeOut |
| LastSuccessfulEvaluationTimestamp |
integer |
The timestamp of the last successful evaluation. Unit: milliseconds. |
1624932227486 |
| FirstActivatedTimestamp |
integer |
The timestamp when the rule was first activated. |
1624932221993 |
| FirstEvaluationStarted |
boolean |
Indicates whether the rule has been evaluated. Valid values:
|
true |
| LastSuccessfulInvocationTimestamp |
integer |
The timestamp of the last successful invocation. Unit: milliseconds. |
1624932227476 |
| LastErrorMessage |
string |
The error message returned for the last failed execution of the rule. |
time out |
| LastFailedEvaluationTimestamp |
integer |
The timestamp of the last failed evaluation. Unit: milliseconds. |
1614687022000 |
| LastFailedInvocationTimestamp |
integer |
The timestamp of the last failed invocation. Unit: milliseconds. |
1614687022000 |
| ConfigRuleId |
string |
ID aturan. |
cr-7f7d626622af0041**** |
| ModifiedTimestamp |
integer |
Stempel waktu saat aturan terakhir diperbarui. Unit: milidetik. |
1614687022000 |
| CreateTimestamp |
integer |
Stempel waktu saat aturan dibuat. Unit: milidetik. |
1604684022000 |
| ResourceTypesScope |
string |
Tipe sumber daya yang dievaluasi oleh aturan. |
ACS::RAM::User |
| ExcludeRegionIdsScope |
string |
Aturan tidak berlaku untuk sumber daya di region yang ditentukan. Sistem tidak mengevaluasi sumber daya di region tersebut. Pisahkan beberapa ID region dengan koma (,). |
cn-hangzhou |
| RegionIdsScope |
string |
Aturan hanya berlaku untuk sumber daya di region yang ditentukan. |
global |
| ExcludeResourceIdsScope |
string |
ID sumber daya yang tidak dievaluasi oleh aturan. |
23642660635687**** |
| ResourceIdsScope |
string |
Aturan hanya berlaku untuk sumber daya yang ditentukan. Pisahkan beberapa ID sumber daya dengan koma (,). |
eip-8vbf3x310fn56ijfd**** |
| ResourceGroupIdsScope |
string |
Aturan hanya berlaku untuk sumber daya di grup sumber daya yang ditentukan. |
rg-aekzdibsjjc**** |
| ExcludeResourceGroupIdsScope |
string |
Aturan tidak berlaku untuk sumber daya di grup sumber daya yang ditentukan. Sistem tidak mengevaluasi sumber daya di grup sumber daya tersebut. Pisahkan beberapa ID grup sumber daya dengan koma (,). |
rg-aekzdibsjjc**** |
TagKeyScope
deprecated
|
string |
Parameter ini tidak digunakan lagi. Gunakan parameter Aturan hanya berlaku untuk sumber daya yang memiliki kunci tag yang ditentukan. |
RAM |
TagValueScope
deprecated
|
string |
Parameter ini tidak digunakan lagi. Gunakan parameter Aturan hanya berlaku untuk sumber daya yang memiliki nilai tag yang ditentukan. |
MFA |
| TagsScope |
array<object> |
Cakupan tag. |
|
|
object |
|||
| TagKey |
string |
The tag key. |
key-1 |
| TagValue |
string |
The tag value. |
value-1 |
| ExcludeTagsScope |
array<object> |
Cakupan tag yang dikecualikan. |
|
|
object |
|||
| TagKey |
string |
The tag key. |
key-2 |
| TagValue |
string |
The tag value. |
value-2 |
| ConfigRuleTriggerTypes |
string |
Tipe pemicu aturan. Nilai yang valid:
|
ConfigurationItemChangeNotification |
| TagKeyLogicScope |
string |
Parameter ini tidak dikembalikan untuk aturan yang dibuat menggunakan parameter Parameter ini hanya dikembalikan untuk aturan yang dibuat menggunakan parameter Nilai yang valid:
|
AND |
| FolderIdsScope |
string |
Aturan hanya berlaku untuk sumber daya dalam akun anggota di folder yang ditentukan dari direktori sumber daya. |
fd-ZtHsRH**** |
| ExcludeFolderIdsScope |
string |
Aturan tidak berlaku untuk sumber daya dalam akun anggota di folder yang ditentukan dari direktori sumber daya. Sistem tidak mengevaluasi sumber daya di folder tersebut. |
fd-pWmkqZ**** |
| ExcludeAccountIdsScope |
string |
Aturan tidak berlaku untuk sumber daya di akun anggota yang ditentukan. Sistem tidak mengevaluasi sumber daya di akun tersebut. |
120886317861**** |
| ResourceNameScope |
string |
Aturan hanya berlaku untuk sumber daya yang memiliki nama yang ditentukan. |
i-xxx |
| Compliance |
object |
Statistik kepatuhan aturan. |
|
| ComplianceType |
string |
The compliance evaluation result. Valid values:
|
NON_COMPLIANT |
| Count |
integer |
The number of resources that have the corresponding compliance evaluation result. |
3 |
| AccountId |
integer |
ID akun Alibaba Cloud tempat aturan berada. |
120886317861**** |
| ExtendContent |
string |
Konten yang diperluas. Parameter ini digunakan untuk mengonfigurasi waktu pemicu aturan yang dipicu pada siklus 24 jam. |
{"fixedHour":"12"} |
| Tags |
array<object> |
Tag sumber daya. |
|
|
object |
Tag sumber daya. |
||
| TagKey |
string |
The tag key. |
key-1 |
| TagValue |
string |
The tag value. |
value-1 |
| AccountIdsScope |
string |
Aturan hanya berlaku untuk sumber daya di akun anggota yang ditentukan. Pisahkan beberapa ID akun anggota dengan koma (,). |
120886317861**** |
Contoh
Respons sukses
JSONformat
{
"RequestId": "811234F4-C3AB-4D15-B90B-F55016D1B5AA",
"ConfigRule": {
"RiskLevel": 1,
"InputParameters": {
"tag1Key": "ECS",
"tag1Value": "test"
},
"Source": {
"SourceDetails": [
{
"MessageType": "ConfigurationItemChangeNotification",
"EventSource": "aliyun.config",
"MaximumExecutionFrequency": "One_Hour"
}
],
"Owner": "ALIYUN",
"Identifier": "acs:fc:cn-hangzhou:100931896542****:services/ConfigService.LATEST/functions/specific-config"
},
"ConfigRuleState": "ACTIVE",
"MaximumExecutionFrequency": "One_Hour",
"ManagedRule": {
"SourceDetails": [
{
"MessageType": "ConfigurationItemChangeNotification",
"EventSource": "aliyun.config",
"MaximumExecutionFrequency": "One_Hour"
}
],
"Description": "ECS磁盘未因欠费或安全等原因而被锁定,视为“合规”。",
"Labels": [
"[\"RAM\",\"USer\"]"
],
"Identifier": "ram-user-mfa-check",
"OptionalInputParameterDetails": {},
"ManagedRuleName": "RAM用户开启MFA",
"CompulsoryInputParameterDetails": {}
},
"ConfigRuleArn": "acs:config::100931896542****:rule/cr-7f7d626622af0041****",
"Description": "RAM用户开启MFA,视为“合规”。",
"CreateBy": {
"CompliancePackId": "cp-541e626622af008****",
"AggregatorName": "Test_Group",
"CompliancePackName": "OSS合规基线",
"CreatorName": "Alice",
"CreatorType": "AGGREGATOR",
"CreatorId": "100931896542****",
"AggregatorId": "ca-04b3fd170e340007****"
},
"ConfigRuleName": "RAM用户开启MFA",
"ConfigRuleEvaluationStatus": {
"LastErrorCode": "TimeOut",
"LastSuccessfulEvaluationTimestamp": 1624932227486,
"FirstActivatedTimestamp": 1624932221993,
"FirstEvaluationStarted": true,
"LastSuccessfulInvocationTimestamp": 1624932227476,
"LastErrorMessage": "time out",
"LastFailedEvaluationTimestamp": 1614687022000,
"LastFailedInvocationTimestamp": 1614687022000
},
"ConfigRuleId": "cr-7f7d626622af0041****",
"ModifiedTimestamp": 1614687022000,
"CreateTimestamp": 1604684022000,
"ResourceTypesScope": "ACS::RAM::User",
"ExcludeRegionIdsScope": "cn-hangzhou",
"RegionIdsScope": "global",
"ExcludeResourceIdsScope": "23642660635687****",
"ResourceIdsScope": "eip-8vbf3x310fn56ijfd****\n",
"ResourceGroupIdsScope": "rg-aekzdibsjjc****",
"ExcludeResourceGroupIdsScope": "rg-aekzdibsjjc****",
"TagKeyScope": "RAM",
"TagValueScope": "MFA",
"TagsScope": [
{
"TagKey": "key-1",
"TagValue": "value-1"
}
],
"ExcludeTagsScope": [
{
"TagKey": "key-2",
"TagValue": "value-2"
}
],
"ConfigRuleTriggerTypes": "ConfigurationItemChangeNotification",
"TagKeyLogicScope": "AND",
"FolderIdsScope": "fd-ZtHsRH****",
"ExcludeFolderIdsScope": "fd-pWmkqZ****",
"ExcludeAccountIdsScope": "120886317861****",
"ResourceNameScope": "i-xxx",
"Compliance": {
"ComplianceType": "NON_COMPLIANT",
"Count": 3
},
"AccountId": 0,
"ExtendContent": "{\"fixedHour\":\"12\"}",
"Tags": [
{
"TagKey": "key-1",
"TagValue": "value-1"
}
],
"AccountIdsScope": "120886317861****\n"
}
}
Kode kesalahan
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | ConfigRuleNotExists | The ConfigRule does not exist. | |
| 400 | NoPermission | You are not authorized to perform this operation. | |
| 400 | Invalid.AggregatorId.Value | The specified AggregatorId is invalid. | |
| 404 | AccountNotExisted | Your account does not exist. | |
| 503 | ServiceUnavailable | The request has failed due to a temporary failure of the server. |
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.