名前、ID、説明、ステージ、リソース詳細メタデータ、修正ガイダンスなど、利用可能なすべてのガバナンス評価項目に関する情報を取得します。
今すぐお試しください
テスト
RAM 認証
|
アクション |
アクセスレベル |
リソースタイプ |
条件キー |
依存アクション |
|
governance:ListEvaluationMetadata |
get |
*All Resource
|
なし | なし |
リクエストパラメーター
|
パラメーター |
型 |
必須 / 任意 |
説明 |
例 |
| RegionId |
string |
任意 |
リージョンID。 |
cn-hangzhou |
| Language |
string |
任意 |
言語タイプ。ガバナンス評価定義はこの言語で返されます。有効な値:
|
zh |
| LensCode |
string |
任意 |
専門評価コード。有効な値:
|
ack |
| TopicCode |
string |
任意 |
ガバナンストピックコード。 |
ResourceUtilization |
レスポンスフィールド
|
フィールド |
型 |
説明 |
例 |
|
object |
レスポンスパラメーター。 |
||
| EvaluationMetadata |
array<object> |
ガバナンス評価定義メタデータ。 |
|
|
array<object> |
ガバナンス評価定義メタデータ。 |
||
| Metadata |
array<object> |
特定のメタデータタイプに属するメタデータオブジェクトのリスト。 |
|
|
array<object> |
特定のメタデータタイプに属するメタデータオブジェクトのリスト。 |
||
| Category |
string |
確認項目が属するピラーです。 |
Security |
| Description |
string |
確認項目の説明です。 |
If you use an AccessKey pair of an Alibaba Cloud account, you have full permissions that cannot be restricted by conditions such as source IP address or access time. Once leaked, the risk is extremely high. If an AccessKey pair exists for the Alibaba Cloud account, it is considered non-compliant. |
| DisplayName |
string |
確認項目の表示名です。 |
An AccessKey pair is enabled for the Alibaba Cloud account. |
| Id |
string |
メタデータエントリの一意な ID です。 |
pxgtda**** |
| RecommendationLevel |
string |
推奨されるガバナンスレベルです。 |
High |
| RemediationMetadata |
object |
修正メタデータです。 |
|
| Remediation |
array<object> |
修正項目です。 |
|
|
array<object> |
修正項目です。 |
||
| Actions |
array<object> |
修正アクションです。 |
|
|
array<object> |
修正アクションです。 |
||
| Classification |
string |
修正方法のカテゴリです。 説明
このパラメーターは、 |
UnusedAccessKeyInRamUser |
| CostDescription |
string |
修正にかかるコストです。 |
You are not charged for this operation. |
| Description |
string |
修正の説明です。 説明
このパラメーターは、 |
A RAM user has both console logon and an AccessKey pair enabled, but the AccessKey pair has never been used. |
| Guidance |
array<object> |
修正ガイダンスの手順です。 |
|
|
object |
修正ガイダンスの単一ステップです。 |
||
| ButtonName |
string |
修正ステップのボタンの表示名です。 |
Manual fix |
| ButtonRef |
string |
修正ボタンのリダイレクト URL です。 |
https://ram.console.alibabacloud.com/users |
| Content |
string |
修正ステップの内容です。 |
You must replace the AccessKey pair of your Alibaba Cloud account. To do so, perform the following steps:1. Log on to the RAM console. In the left-side navigation pane, choose Identities > Users. On the Users page, click Create User.2. On the Create User page, enter a logon name and select OpenAPI Access for the Access Mode parameter.3. After the RAM user is created, save the AccessKey pair. Then, find the user that you created on the Users page and click Add Permissions in the Actions column. In the Grant Permission panel, find the AdministratorAccess policy and attach it to the RAM user.4. In a program, replace the AccessKey pair of the Alibaba Cloud account with the AccessKey pair of the RAM user created in the previous step and check whether the program runs as expected in the test environment.5. If the program runs as expected, publish the program to the production environment and disable the previous AccessKey pair of your Alibaba Cloud account. Then, check whether the program runs as expected.6. If the program runs as expected, delete the disabled AccessKey pair after the specified period of time, such as 90 days. |
| Title |
string |
修正ステップのタイトルです。 |
Scenario 3: AccessKey pair that is used within the last 90 days |
| Notice |
string |
修正に関する注意事項です。 |
This governance item enables the Best Practices for AccessKey and Permission Governance compliance package in Cloud Config to check the settings and usage of AccessKey pairs, Alibaba Cloud accounts, and RAM users. |
| Suggestion |
string |
修正に関する提案です。 説明
このパラメーターは、 |
Console logon is enabled for the RAM user and the RAM user owns an AccessKey pair, while the AccessKey pair has never been used by the RAM user. We recommend that you disable the AccessKey pair for 90 days. If no related issue occurs during this period, you can delete the AccessKey pair. |
| RemediationType |
string |
修正タイプです。有効な値は次のとおりです。
|
Manual |
| ResourceMetadata |
object |
確認項目のリソースメタデータです。 |
|
| ResourcePropertyMetadata |
array<object> |
リソースプロパティメタデータです。 |
|
|
object |
リソースプロパティメタデータです。 |
||
| DisplayName |
string |
プロパティの表示名です。 |
Last time the AccessKey pair was used |
| PropertyName |
string |
リソースプロパティの名前です。 |
AkLastUsedTime |
| PropertyType |
string |
リソースプロパティのタイプです。 |
String |
| Scope |
string |
確認項目の範囲です。有効な値は次のとおりです。
|
Account |
| Stage |
string |
確認項目のステージです。有効な値は次のとおりです。
|
Released |
| TopicCode |
string |
確認項目が属するトピックのコードです。 |
ResourceUtilization |
| Type |
string |
メタデータタイプ。有効な値:
|
Metric |
| RequestId |
string |
リクエストID。 |
16B208DD-86BD-5E7D-AC93-FFD44B6FBDF1 |
例
成功レスポンス
JSONJSON
{
"EvaluationMetadata": [
{
"Metadata": [
{
"Category": "Security",
"Description": "If you use an AccessKey pair of an Alibaba Cloud account, you have full permissions that cannot be restricted by conditions such as source IP address or access time. Once leaked, the risk is extremely high. If an AccessKey pair exists for the Alibaba Cloud account, it is considered non-compliant.",
"DisplayName": "An AccessKey pair is enabled for the Alibaba Cloud account.",
"Id": "pxgtda****",
"RecommendationLevel": "High",
"RemediationMetadata": {
"Remediation": [
{
"Actions": [
{
"Classification": "UnusedAccessKeyInRamUser",
"CostDescription": "You are not charged for this operation.",
"Description": "A RAM user has both console logon and an AccessKey pair enabled, but the AccessKey pair has never been used.",
"Guidance": [
{
"ButtonName": "Manual fix",
"ButtonRef": "https://ram.console.alibabacloud.com/users",
"Content": "You must replace the AccessKey pair of your Alibaba Cloud account. To do so, perform the following steps:1. Log on to the RAM console. In the left-side navigation pane, choose Identities > Users. On the Users page, click Create User.2. On the Create User page, enter a logon name and select OpenAPI Access for the Access Mode parameter.3. After the RAM user is created, save the AccessKey pair. Then, find the user that you created on the Users page and click Add Permissions in the Actions column. In the Grant Permission panel, find the AdministratorAccess policy and attach it to the RAM user.4. In a program, replace the AccessKey pair of the Alibaba Cloud account with the AccessKey pair of the RAM user created in the previous step and check whether the program runs as expected in the test environment.5. If the program runs as expected, publish the program to the production environment and disable the previous AccessKey pair of your Alibaba Cloud account. Then, check whether the program runs as expected.6. If the program runs as expected, delete the disabled AccessKey pair after the specified period of time, such as 90 days.",
"Title": "Scenario 3: AccessKey pair that is used within the last 90 days"
}
],
"Notice": "This governance item enables the Best Practices for AccessKey and Permission Governance compliance package in Cloud Config to check the settings and usage of AccessKey pairs, Alibaba Cloud accounts, and RAM users.",
"Suggestion": "Console logon is enabled for the RAM user and the RAM user owns an AccessKey pair, while the AccessKey pair has never been used by the RAM user. We recommend that you disable the AccessKey pair for 90 days. If no related issue occurs during this period, you can delete the AccessKey pair."
}
],
"RemediationType": "Manual"
}
]
},
"ResourceMetadata": {
"ResourcePropertyMetadata": [
{
"DisplayName": "Last time the AccessKey pair was used",
"PropertyName": "AkLastUsedTime",
"PropertyType": "String"
}
]
},
"Scope": "Account",
"Stage": "Released",
"TopicCode": "ResourceUtilization"
}
],
"Type": "Metric"
}
],
"RequestId": "16B208DD-86BD-5E7D-AC93-FFD44B6FBDF1"
}
エラーコード
|
HTTP ステータスコード |
エラーコード |
エラーメッセージ |
説明 |
|---|---|---|---|
| 500 | InternalError | A system error occurred. | |
| 404 | InvalidEnterpriseRealName.NotFound | The specified account has not passed enterprise real name verification. Please complete the verification for the account first. |
完全なリストについては、「エラーコード」をご参照ください。
変更履歴
完全なリストについては、「変更履歴」をご参照ください。