Meminta detail aturan yang ditentukan.
Deskripsi operasi
Topik ini memberikan contoh cara meminta detail aturan cr-7f7d626622af0041****.
Coba sekarang
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
config:GetConfigRule |
get |
*Rule
|
None | None |
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| ConfigRuleId |
string |
Yes |
ID aturan. Untuk informasi lebih lanjut, lihat ListConfigRules. |
cr-7f7d626622af0041**** |
Tag
deprecated
|
array<object> |
No |
Tag sumber daya. Parameter ini sudah usang dan tidak berpengaruh. Anda dapat menambahkan maksimal 20 tag ke sebuah sumber daya. |
|
|
object |
No |
Tag sumber daya. |
||
| Key |
string |
No |
Kunci tag sumber daya. Anda dapat menambahkan maksimal 20 kunci tag ke sebuah sumber daya. |
key-1 |
| Value |
string |
No |
Nilai tag sumber daya. Anda dapat menambahkan maksimal 20 nilai tag ke sebuah sumber daya. |
value-1 |
For more information about common request parameters, see Common parameters.
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
|||
| ConfigRule |
object |
Detail aturan. |
|
| AccountId |
integer |
ID akun Alibaba Cloud tempat aturan tersebut berada. |
120886317861**** |
| Compliance |
object |
Statistik kepatuhan aturan. |
|
| ComplianceType |
string |
The compliance evaluation result. Valid values:
|
NON_COMPLIANT |
| Count |
integer |
The number of resources that are evaluated based on the compliance result. |
3 |
| ConfigRuleArn |
string |
Alibaba Cloud Resource Name (ARN) dari aturan. |
acs:config::100931896542****:rule/cr-7f7d626622af0041**** |
| ConfigRuleEvaluationStatus |
object |
Status eksekusi aturan. |
|
| FirstActivatedTimestamp |
integer |
The timestamp when the rule was first activated. Unit: milliseconds. |
1624932221993 |
| FirstEvaluationStarted |
boolean |
Indicates whether the rule has been evaluated. Valid values:
|
true |
| LastErrorCode |
string |
The error code returned for the last failed execution of the rule. |
TimeOut |
| LastErrorMessage |
string |
The error message returned for the last failed execution of the rule. |
Time out |
| LastFailedEvaluationTimestamp |
integer |
The timestamp when the last failed evaluation of the rule ended. Unit: milliseconds. |
1614687022000 |
| LastFailedInvocationTimestamp |
integer |
The timestamp when the last failed invocation of the rule started. Unit: milliseconds. |
1614687022000 |
| LastSuccessfulEvaluationTimestamp |
integer |
The timestamp when the last successful evaluation of the rule ended. Unit: milliseconds. |
1624932227486 |
| LastSuccessfulInvocationTimestamp |
integer |
The timestamp when the last successful invocation of the rule started. Unit: milliseconds. |
1624932227476 |
| ConfigRuleId |
string |
ID aturan. |
cr-7f7d626622af0041**** |
| ConfigRuleName |
string |
Nama aturan. |
RAM用户开启MFA |
| ConfigRuleState |
string |
Status aturan. Nilai yang valid:
|
ACTIVE |
| ConfigRuleTriggerTypes |
string |
Jenis pemicu aturan. Nilai yang valid:
|
ConfigurationItemChangeNotification |
| CreateBy |
object |
Informasi tentang pembuat aturan. |
|
| CompliancePackId |
string |
The ID of the compliance package. |
cp-541e626622af008**** |
| CompliancePackName |
string |
The name of the compliance package. |
OSS合规基线 |
| CreatorId |
string |
The ID of the Alibaba Cloud account that was used to create the rule. |
100931896542**** |
| CreatorName |
string |
The name of the creator. |
Alice |
| CreateTimestamp |
integer |
Stempel waktu saat aturan dibuat. Satuan: milidetik. |
1604684022000 |
| Description |
string |
Deskripsi aturan. |
RAM用户开启MFA,视为“合规”。 |
| ExcludeRegionIdsScope |
string |
ID region tempat aturan tidak berlaku. Aturan tidak mengevaluasi sumber daya di region tersebut. Pisahkan beberapa ID region dengan koma (,). |
cn-hangzhou |
| ExcludeResourceGroupIdsScope |
string |
ID grup sumber daya tempat aturan tidak berlaku. Aturan tidak mengevaluasi sumber daya dalam grup sumber daya tersebut. Pisahkan beberapa ID grup sumber daya dengan koma (,). |
rg-aekzdibsjjc**** |
| ExcludeResourceIdsScope |
string |
ID sumber daya yang tidak dievaluasi oleh aturan. Pisahkan beberapa ID sumber daya dengan koma (,). |
23642660635687**** |
| ExcludeTagsScope |
array<object> |
Tag sumber daya yang tidak dievaluasi oleh aturan. |
|
|
object |
Tag sumber daya yang tidak dievaluasi oleh aturan. |
||
| TagKey |
string |
The tag key. |
key-2 |
| TagValue |
string |
The tag value. |
value-2 |
| InputParameters |
object |
Parameter input aturan. |
|
| ManagedRule |
object |
Detail aturan terkelola. |
|
| CompulsoryInputParameterDetails |
object |
The details of the required input parameters of the managed rule. |
{} |
| Description |
string |
The description of the managed rule. |
ECS磁盘未因欠费或安全等原因而被锁定,视为“合规”。 |
| Identifier |
string |
The identifier of the managed rule. |
ram-user-mfa-check |
| Labels |
array |
The list of rule labels. |
|
|
string |
The label of the managed rule. |
["RAM","User"] |
|
| ManagedRuleName |
string |
The name of the managed rule. |
RAM用户开启MFA |
| OptionalInputParameterDetails |
object |
The details of the optional input parameters of the managed rule. |
{} |
| SourceDetails |
array<object> |
The source details of the managed rule. |
|
|
object |
The source details of the managed rule. |
||
| EventSource |
string |
The event source. Catatan
Only Cloud Config events are supported. The value is aliyun.config. |
aliyun.config |
| MaximumExecutionFrequency |
string |
The execution frequency of the rule. Valid values:
Catatan
This parameter is returned only when the rule is triggered periodically. |
One_Hour |
| MessageType |
string |
The trigger type of the rule. Valid values:
|
ConfigurationItemChangeNotification |
| MaximumExecutionFrequency |
string |
Frekuensi eksekusi aturan. Nilai yang valid:
Catatan
Parameter ini hanya dikembalikan jika aturan dipicu secara berkala. |
One_Hour |
| ModifiedTimestamp |
integer |
Stempel waktu saat aturan terakhir diperbarui. Satuan: milidetik. |
1614687022000 |
| RegionIdsScope |
string |
ID region tempat aturan berlaku. Aturan hanya mengevaluasi sumber daya di region tersebut. |
global |
| ResourceGroupIdsScope |
string |
ID grup sumber daya tempat aturan berlaku. Aturan hanya mengevaluasi sumber daya dalam grup sumber daya tersebut. |
rg-aekzdibsjjc**** |
| ResourceIdsScope |
string |
ID sumber daya yang dievaluasi oleh aturan. Pisahkan beberapa ID sumber daya dengan koma (,). |
eip-8vbf3x310fn56ijfd**** |
| ResourceTypesScope |
string |
Jenis sumber daya yang dievaluasi oleh aturan. |
ACS::RAM::User |
| RiskLevel |
integer |
Tingkat risiko aturan. Nilai yang valid:
|
1 |
| Scope |
object |
Cakupan efektif aturan. |
|
| ComplianceResourceTypes |
array |
The list of resource types that are evaluated by the rule. You can also view this information in the ResourceTypesScope field. |
|
|
string |
The type of the resource that is evaluated by the rule. |
ACS::RAM::User |
|
| Source |
object |
Sumber aturan. |
|
| Identifier |
string |
The identifier of the rule.
|
acs:fc:cn-hangzhou:100931896542****:services/ConfigService.LATEST/functions/specific-config |
| Owner |
string |
The owner of the rule. Valid values:
|
ALIYUN |
| SourceDetails |
array<object> |
The source details. |
|
|
object |
The source details. |
||
| EventSource |
string |
The event source. Catatan
Only Cloud Config events are supported. The value is aliyun.config. |
aliyun.config |
| MaximumExecutionFrequency |
string |
The execution frequency of the rule. Valid values:
Catatan
This parameter is returned only when the rule is triggered periodically. |
One_Hour |
| MessageType |
string |
The trigger type of the rule. Valid values:
|
ConfigurationItemChangeNotification |
| TagKeyLogicScope |
string |
Parameter ini tidak dikembalikan untuk aturan yang dibuat menggunakan parameter Parameter ini dikembalikan untuk aturan yang dibuat menggunakan parameter TagKeyScope yang sudah usang. Kami tidak menyarankan Anda menggunakan parameter Nilai yang valid:
|
OR |
TagKeyScope
deprecated
|
string |
Parameter ini sudah usang. Gunakan parameter Aturan hanya berlaku untuk sumber daya dengan tag yang ditentukan. Catatan
Parameter |
RAM |
TagValueScope
deprecated
|
string |
Parameter ini sudah usang. Gunakan parameter Aturan hanya berlaku untuk sumber daya dengan tag yang ditentukan. Catatan
Parameter |
MFA |
| TagsScope |
array<object> |
Cakupan berbasis tag. |
|
|
object |
Tag yang mendefinisikan cakupan. |
||
| TagKey |
string |
The tag key. |
key-1 |
| TagValue |
string |
The tag value. |
value-1 |
| Tags |
array<object> |
Tag sumber daya. |
|
|
object |
Tag sumber daya. |
||
| TagKey |
string |
The tag key. |
key-1 |
| TagValue |
string |
The tag value. |
value-1 |
| ResourceNameScope |
string |
Aturan hanya mengevaluasi sumber daya yang memiliki nama yang ditentukan. |
i-xxx |
| ExtendContent |
string |
Konten yang diperluas. Parameter ini hanya digunakan untuk menentukan waktu pemicu aturan yang dipicu pada siklus 24 jam. |
{"fixedHour":"12"} |
| RequestId |
string |
ID permintaan. |
811234F4-C3AB-4D15-B90B-F55016D1B5AA |
Contoh
Respons sukses
JSONformat
{
"ConfigRule": {
"AccountId": 0,
"Compliance": {
"ComplianceType": "NON_COMPLIANT",
"Count": 3
},
"ConfigRuleArn": "acs:config::100931896542****:rule/cr-7f7d626622af0041****",
"ConfigRuleEvaluationStatus": {
"FirstActivatedTimestamp": 1624932221993,
"FirstEvaluationStarted": true,
"LastErrorCode": "TimeOut",
"LastErrorMessage": "Time out",
"LastFailedEvaluationTimestamp": 1614687022000,
"LastFailedInvocationTimestamp": 1614687022000,
"LastSuccessfulEvaluationTimestamp": 1624932227486,
"LastSuccessfulInvocationTimestamp": 1624932227476
},
"ConfigRuleId": "cr-7f7d626622af0041****",
"ConfigRuleName": "RAM用户开启MFA",
"ConfigRuleState": "ACTIVE",
"ConfigRuleTriggerTypes": "ConfigurationItemChangeNotification",
"CreateBy": {
"CompliancePackId": "cp-541e626622af008****",
"CompliancePackName": "OSS合规基线",
"CreatorId": "100931896542****",
"CreatorName": "Alice"
},
"CreateTimestamp": 1604684022000,
"Description": "RAM用户开启MFA,视为“合规”。",
"ExcludeRegionIdsScope": "cn-hangzhou",
"ExcludeResourceGroupIdsScope": "rg-aekzdibsjjc****",
"ExcludeResourceIdsScope": "23642660635687****",
"ExcludeTagsScope": [
{
"TagKey": "key-2",
"TagValue": "value-2"
}
],
"InputParameters": {
"test": "test",
"test2": 1
},
"ManagedRule": {
"CompulsoryInputParameterDetails": {},
"Description": "ECS磁盘未因欠费或安全等原因而被锁定,视为“合规”。",
"Identifier": "ram-user-mfa-check",
"Labels": [
"[\"RAM\",\"User\"]"
],
"ManagedRuleName": "RAM用户开启MFA",
"OptionalInputParameterDetails": {},
"SourceDetails": [
{
"EventSource": "aliyun.config",
"MaximumExecutionFrequency": "One_Hour",
"MessageType": "ConfigurationItemChangeNotification"
}
]
},
"MaximumExecutionFrequency": "One_Hour",
"ModifiedTimestamp": 1614687022000,
"RegionIdsScope": "global",
"ResourceGroupIdsScope": "rg-aekzdibsjjc****",
"ResourceIdsScope": "eip-8vbf3x310fn56ijfd****\n",
"ResourceTypesScope": "ACS::RAM::User",
"RiskLevel": 1,
"Scope": {
"ComplianceResourceTypes": [
"ACS::RAM::User"
]
},
"Source": {
"Identifier": "acs:fc:cn-hangzhou:100931896542****:services/ConfigService.LATEST/functions/specific-config",
"Owner": "ALIYUN",
"SourceDetails": [
{
"EventSource": "aliyun.config",
"MaximumExecutionFrequency": "One_Hour",
"MessageType": "ConfigurationItemChangeNotification"
}
]
},
"TagKeyLogicScope": "OR",
"TagKeyScope": "RAM",
"TagValueScope": "MFA",
"TagsScope": [
{
"TagKey": "key-1",
"TagValue": "value-1"
}
],
"Tags": [
{
"TagKey": "key-1",
"TagValue": "value-1"
}
],
"ResourceNameScope": "i-xxx",
"ExtendContent": "{\"fixedHour\":\"12\"}"
},
"RequestId": "811234F4-C3AB-4D15-B90B-F55016D1B5AA"
}
Kode kesalahan
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | ConfigRuleNotExists | The ConfigRule does not exist. | The rule does not exist. |
| 400 | NoPermission | You are not authorized to perform this operation. | You are not authorized to perform this operation. |
| 404 | AccountNotExisted | Your account does not exist. | |
| 503 | ServiceUnavailable | The request has failed due to a temporary failure of the server. | The request has failed due to a temporary failure of the server. |
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.