すべてのプロダクト
Search
ドキュメントセンター

Compute Nest:ホステッド O&M 権限

最終更新日:Jun 08, 2025

サービスプロバイダーがホステッド O&M サービスを作成する場合、O&M 操作を実行するために必要なポリシーを指定する必要があります。お客様がホステッド O&M サービスインスタンスを作成すると、Compute Nest は指定されたポリシーを作成し、Compute Nest のサービスリンクロールが作成されます。 Compute Nest は、作成されたポリシーをサービスプロバイダーにアタッチして、サービスインスタンスに含まれるリソースに対して特定の O&M 操作を実行できるようにします。

リソースの制限

  1. ホステッド O&M 機能が有効になっているプライベートサービスの場合、サービスプロバイダーには、お客様が作成したプライベートサービスインスタンスのリソースに対する権限のみが付与されます。

  2. ピュアホステッド O&M サービスの場合、サービスプロバイダーには、指定された Elastic Compute Service(ECS)インスタンス、または指定されたサービスインスタンスのリソースに対する権限のみが付与されます。サービスプロバイダーは、サービスインスタンスの詳細ページで、O&M 権限が付与されているリソースを表示できます。

権限の制限

サービスプロバイダーに付与できるホステッド O&M 権限は、AliyunComputeNestPolicyForSupplierRole システムポリシーの範囲内です。サービスプロバイダーに実際に付与される権限は、AliyunComputeNestPolicyForSupplierRole ポリシーと、サービスの構成時に指定したポリシーの共通部分です。

AliyunComputeNestPolicyForSupplierRole ポリシーの内容

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "ecs:StartInstance",
                "ecs:DescribeInstances",
                "ecs:RebootInstance",
                "ecs:StopInstance",
                "ecs:RunCommand",
                "ecs:DescribeInvocations",
                "ecs:DescribeInvocationResults",
                "ecs:StartTerminalSession",
                "ecs:DescribeTerminalSessions",
                "ecs:CloseTerminalSession",
                "ecs:DescribeInstanceHistoryEvents",
                "ecs:DescribeDiagnosticReports",
                "ecs:CreateDiagnosticReport",
                "ecs:DescribeSecurityGroups",
                "ecs:DescribeDisks",
                "ecs:DescribeImages",
                "cms:DescribeMetricData",
                "cms:DescribeMetricList",
                "cms:QueryMetricList",
                "cms:DescribeMetricRuleList",
                "cms:DescribeAlertHistoryList",
                "cms:DescribeAlertLogList",
                "cms:DescribeLogHistogram",
                "cms:DescribeLogCount",
                "cms:DescribeDynamicTagRuleList",
                "cms:DescribeMonitorGroups",
                "tag:ListTagResources",
                "vpc:DescribeVpcs",
                "vpc:DescribeVSwitches",
                "vpc:DescribeVSwitchAttributes",
                "vpc:DescribeVpcAttribute",
                "vpc:DescribeRouteEntryList",
                "vpc:DescribeRouteTableList",
                "vpc:DescribeRouteTables",
                "vpc:DescribeRouterInterfaces",
                "vpc:DescribeRouterInterfaceAttribute",
                "slb:DescribeLoadBalancers",
                "slb:DescribeLoadBalancerListeners",
                "slb:DescribeLoadBalancerAttribute",
                "slb:DescribeVServerGroups",
                "rds:DescribeDBInstances",
                "rds:DescribeDBInstanceAttribute",
                "rds:RestartDBInstance",
                "actiontrail:LookupEvents"
            ],
            "Resource": "*",
            "Effect": "Allow"
        }
    ]
}

ホステッド O&M ポリシー

次の表は、サービスプロバイダーがサービスを構成するときに選択できるポリシーについて説明しています。

権限

ポリシー

説明

すべての権限

AliyunComputeNestPolicyForFullAccess

指定された ECS インスタンス、または指定されたサービスインスタンス内の Alibaba Cloud リソースに対するすべての権限。

読み取り専用権限

AliyunComputeNestPolicyForReadOnly

指定された ECS インスタンス、または指定されたサービスインスタンス内の Alibaba Cloud リソース、および ActionTrail によって記録されたこれらのリソースの監査ログに対する読み取り専用権限。

ターミナルログオン権限

AliyunComputeNestPolicyForTerminalLogin

指定された ECS インスタンス、または指定されたサービスインスタンス内の ECS インスタンスにリモートでログオンする権限。

操作監査権限

AliyunComputeNestPolicyForTrails

ActionTrail が指定された ECS インスタンス、または指定されたサービスインスタンス内の Alibaba Cloud リソースに対して記録する監査ログを表示する権限。

監視権限

AliyunComputeNestPolicyForAlarm

指定された ECS インスタンス、または指定されたサービスインスタンス内の Alibaba Cloud リソースのしきい値トリガーおよびイベントトリガーのアラートルールを管理する権限。

アップグレード権限

AliyunComputeNestPolicyForUpgrade

指定されたサービスインスタンスのアプリケーションとサービス構成をアップグレードおよびロールバックする権限。

O&M 権限

AliyunComputeNestPolicyForOperation

指定されたサービスインスタンスで O&M 操作を実行する権限。

上記のポリシーは、Resource Access Management(RAM)ポリシーです。詳細については、「ポリシー要素」をご参照ください。

AliyunComputeNestPolicyForFullAccess

すべての権限

ポリシーの内容

{
  "Action": [
    "*"
  ],
  "Effect": "Allow",
  "Resource": [
    "*"
  ]
}

実際の効果

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "ecs:StartInstance",
                "ecs:DescribeInstances",
                "ecs:RebootInstance",
                "ecs:StopInstance",
                "ecs:RunCommand",
                "ecs:DescribeInvocations",
                "ecs:DescribeInvocationResults",
                "ecs:StartTerminalSession",
                "ecs:DescribeTerminalSessions",
                "ecs:CloseTerminalSession",
                "ecs:DescribeInstanceHistoryEvents",
                "ecs:DescribeDiagnosticReports",
                "ecs:CreateDiagnosticReport",
                "ecs:DescribeSecurityGroups",
                "ecs:DescribeDisks",
                "ecs:DescribeImages",
                "cms:DescribeMetricData",
                "cms:DescribeMetricList",
                "cms:QueryMetricList",
                "cms:DescribeMetricRuleList",
                "cms:DescribeAlertHistoryList",
                "cms:DescribeAlertLogList",
                "cms:DescribeLogHistogram",
                "cms:DescribeLogCount",
                "cms:DescribeDynamicTagRuleList",
                "cms:DescribeMonitorGroups",
                "tag:ListTagResources",
                "vpc:DescribeVpcs",
                "vpc:DescribeVSwitches",
                "vpc:DescribeVSwitchAttributes",
                "vpc:DescribeVpcAttribute",
                "vpc:DescribeRouteEntryList",
                "vpc:DescribeRouteTableList",
                "vpc:DescribeRouteTables",
                "vpc:DescribeRouterInterfaces",
                "vpc:DescribeRouterInterfaceAttribute",
                "slb:DescribeLoadBalancers",
                "slb:DescribeLoadBalancerListeners",
                "slb:DescribeLoadBalancerAttribute",
                "slb:DescribeVServerGroups",
                "rds:DescribeDBInstances",
                "rds:DescribeDBInstanceAttribute",
                "rds:RestartDBInstance",
                "actiontrail:LookupEvents"
            ],
            "Resource": "*",
            "Effect": "Allow"
        }
    ]
}

AliyunComputeNestPolicyForReadOnly

読み取り専用権限

ポリシーの内容

{
  "Action": [
    "*:Describe*",
    "*:List*",
    "*:Get*",
    "*:BatchGet*",
    "*:Query*",
    "*:BatchQuery*",
    "actiontrail:LookupEvents"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

実際の効果

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "ecs:DescribeInstances",
                "ecs:DescribeInvocations",
                "ecs:DescribeInvocationResults",
                "ecs:DescribeTerminalSessions",
                "ecs:DescribeInstanceHistoryEvents",
                "ecs:DescribeDiagnosticReports",
                "ecs:DescribeSecurityGroups",
                "ecs:DescribeDisks",
                "ecs:DescribeImages",
                "cms:DescribeMetricData",
                "cms:DescribeMetricList",
                "cms:QueryMetricList",
                "cms:DescribeMetricRuleList",
                "cms:DescribeAlertHistoryList",
                "cms:DescribeAlertLogList",
                "cms:DescribeLogHistogram",
                "cms:DescribeLogCount",
                "cms:DescribeDynamicTagRuleList",
                "cms:DescribeMonitorGroups",
                "tag:ListTagResources",
                "vpc:DescribeVpcs",
                "vpc:DescribeVSwitches",
                "vpc:DescribeVSwitchAttributes",
                "vpc:DescribeVpcAttribute",
                "vpc:DescribeRouteEntryList",
                "vpc:DescribeRouteTableList",
                "vpc:DescribeRouteTables",
                "vpc:DescribeRouterInterfaces",
                "vpc:DescribeRouterInterfaceAttribute",
                "slb:DescribeLoadBalancers",
                "slb:DescribeLoadBalancerListeners",
                "slb:DescribeLoadBalancerAttribute",
                "slb:DescribeVServerGroups",
                "rds:DescribeDBInstances",
                "rds:DescribeDBInstanceAttribute",
                "actiontrail:LookupEvents"
            ],
            "Resource": "*",
            "Effect": "Allow"
        }
    ]
}

AliyunComputeNestPolicyForTerminalLogin

ターミナルログオン権限

ポリシーの内容

{
  "Action": [
    "ecs:*TerminalSession*",
    "tag:List*",
    "tag:DescribeRegions",
    "ecs:Describe*Instance*",
    "cs:Describe*Cluster*",
    "cs:GetClusters",
    "eci:DescribeContainerGroups",
    "eci:ExecContainerCommand"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

実際の効果

{
  "Action": [
    "ecs:StartTerminalSession",
    "ecs:DescribeTerminalSessions",
    "ecs:CloseTerminalSession",
    "tag:ListSupportResourceTypes",
    "tag:ListTagResources",
    "tag:DescribeRegions",
    "ecs:DescribeInstances",
    "ecs:DescribeInstanceTypes",
    "ecs:DescribeInstanceHistoryEvents",
    "ecs:DescribeInstanceVncUrl",
    "cs:DescribeClusterUserKubeconfig",
    "cs:DescribeClusterDetail",
    "cs:GetClusters",
    "cs:DescribeClusterEndpoints",
    "cs:DescribeEdasClusterToken",
    "eci:DescribeContainerGroups",
    "eci:ExecContainerCommand"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

AliyunComputeNestPolicyForTrails

操作監査権限

ポリシーの内容

{
  "Action": [
    "actiontrail:LookupEvents",
    "tag:ListTagResources",
    "tag:ListSupportResourceTypes",
    "tag:DescribeRegions"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

実際の効果

{
  "Action": [
    "actiontrail:LookupEvents",
    "tag:ListTagResources",
    "tag:ListSupportResourceTypes",
    "tag:DescribeRegions"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

AliyunComputeNestPolicyForAlarm

監視権限

ポリシーの内容

{
  "Action": [
    "cms:Describe*",
    "cms:CheckRamRoleForCloudMonitor",
    "cms:QueryMetricList",
    "cms:*MetricRule*",
    "cms:*EventRule*",
    "cms:*HostAvailability",
    "tag:List*",
    "tag:DescribeRegions"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

実際の効果

{
  "Action": [
    "cms:DescribeMetricData",
    "cms:DescribeMetricList",
    "cms:QueryMetricList",
    "cms:DescribeMetricRuleList",
    "cms:DescribeAlertHistoryList",
    "cms:DescribeAlertLogList",
    "cms:DescribeLogHistogram",
    "cms:DescribeLogCount",
    "cms:DescribeDynamicTagRuleList",
    "cms:DescribeMonitorGroups",
    "cms:DescribeMonitorGroupInstances",
    "cms:DescribeMonitorGroupCategories",
    "cms:DescribeMonitorGroupDynamicRules",
    "cms:DescribeMetricRuleTemplateList",
    "cms:DescribeAlertingMetricRuleResources",
    "cms:DescribeContactGroupList",
    "cms:DescribeMonitorGroupInstanceAttribute",
    "cms:DescribeMetricListFromProxy",
    "cms:DescribeMetricLastFromProxy",
    "cms:DescribeMonitoringAgentHosts",
    "cms:DescribeMetricTopFromProxy",
    "cms:DescribeRegions",
    "cms:DescribeDashboardGroupList",
    "cms:DescribeHostAvailabilityList",
    "cms:DescribeUnhealthyHostAvailability",
    "cms:DescribeGroupMonitoringAgentProcess",
    "cms:DescribeSystemEventMetaList",
    "cms:CheckRamRoleForCloudMonitor",
    "cms:DescribeSystemEventHistogram",
    "cms:DescribeSystemEventAttribute",
    "cms:DescribeEventRuleList",
    "cms:DescribeEventRuleTargetList",
    "cms:DescribeCustomEventAttribute",
    "cms:DescribeCustomEventHistogram",
    "cms:DescribeContactListByContactGroup",
    "cms:DescribeAlertLogList",
    "cms:DescribeCustomMetricList",
    "cms:DescribeAlertLogCount",
    "cms:DescribeMetricMetaList",
    "cms:DescribeConsoleViews",
    "cms:DescribeProjectMeta",
    "cms:DescribeAlertLogHistogram",
    "cms:CreateHostAvailability",
    "cms:ModifyHostAvailability",
    "tag:DescribeRegions",
    "tag:ListSupportResourceTypes",
    "tag:ListTagResources"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

AliyunComputeNestPolicyForUpgrade

アップグレード権限

ポリシーの内容

{
  "Effect": "Allow",
  "Action": [
    "ros:*Stack",
    "ros:ListStack*",
    "tag:List*Resource*",
    "tag:DescribeRegions",
    "vpc:Describe*",
    "slb:Describe*",
    "slb:ListTagResources",
    "slb:*AccessControlListEntry",
    "slb:ModifyLoadBalancer*",
    "ecs:*Instance*",
    "ecs:Describe*",
    "ecs:RunCommand",
    "ecs:*SecurityGroup*",
    "ecs:*Disk*",
    "ess:ListTagResources",
    "ess:DescribeScaling*",
    "ess:*ScalingRule",
    "ess:*Instances",
    "cs:GetUserPermissions",
    "cs:Describe*Cluster*",
    "cs:GetClusters",
    "cs:CreateEdasClusterRole*"
  ],
  "Resource": [
    "*"
  ]
}

実際の効果

{
  "Action": [
    "ros:UpdateStack",
    "ros:GetStack",
    "ros:ListStackEvents",
    "ros:ListStackResources",
    "tag:DescribeRegions",
    "tag:ListSupportResourceTypes",
    "tag:ListTagResources",
    "vpc:DescribeVpcs",
    "vpc:DescribeVSwitches",
    "vpc:DescribeVSwitchAttributes",
    "vpc:DescribeVpcAttribute",
    "vpc:DescribeRouteEntryList",
    "vpc:DescribeRouteTableList",
    "vpc:DescribeRouteTables",
    "vpc:DescribeRouterInterfaces",
    "vpc:DescribeRouterInterfaceAttribute",
    "vpc:DescribeEipAddresses",
    "slb:DescribeLoadBalancers",
    "slb:DescribeLoadBalancerListeners",
    "slb:DescribeLoadBalancerAttribute",
    "slb:DescribeVServerGroups",
    "slb:ListTagResources",
    "slb:DescribeAccessControlLists",
    "slb:DescribeAccessControlListAttribute",
    "slb:AddAccessControlListEntry",
    "slb:RemoveAccessControlListEntry",
    "slb:ModifyLoadBalancerInternetSpec",
    "slb:ModifyLoadBalancerInstanceSpec",
    "ecs:ModifyInstanceAttribute",
    "ecs:ReplaceSystemDisk",
    "ecs:RunInstances",
    "ecs:ModifySecurityGroupAttribute",
    "ecs:StartInstance",
    "ecs:DescribeInstances",
    "ecs:RebootInstance",
    "ecs:StopInstance",
    "ecs:ModifyInstanceSpec",
    "ecs:DescribeInstanceTypes",
    "ecs:ModifyPrepayInstanceSpec",
    "ecs:ModifyInstanceNetworkSpec",
    "ecs:RunCommand",
    "ecs:DescribeInvocations",
    "ecs:DescribeInvocationResults",
    "ecs:StartTerminalSession",
    "ecs:DescribeTerminalSessions",
    "ecs:CloseTerminalSession",
    "ecs:DescribeInstanceHistoryEvents",
    "ecs:DescribeDiagnosticReports",
    "ecs:CreateDiagnosticReport",
    "ecs:DescribeSecurityGroups",
    "ecs:DescribeSecurityGroupAttribute",
    "ecs:AuthorizeSecurityGroup",
    "ecs:RevokeSecurityGroup",
    "ecs:DescribeDisks",
    "ecs:ResizeDisk",
    "ecs:ModifyDiskSpec",
    "ecs:DescribeImages",
    "ecs:DescribeInstanceVncUrl",
    "ecs:DescribeManagedInstances",
    "ecs:CreateSnapshot",
    "ecs:CreateAutoSnapshotPolicy",
    "ecs:ApplyAutoSnapshotPolicy",
    "ecs:StopInstances",
    "ecs:ResetDisk",
    "ecs:DescribeSnapshots",
    "ess:ListTagResources",
    "ess:DescribeScalingGroups",
    "ess:CreateScalingRule",
    "ess:DeleteScalingRule",
    "ess:DescribeScalingActivityDetail",
    "ess:DescribeScalingActivities",
    "ess:ExecuteScalingRule",
    "ess:RemoveInstances",
    "ess:DetachInstances",
    "cs:DescribeClusterUserKubeconfig",
    "cs:DescribeClusterDetail",
    "cs:GetClusters",
    "cs:DescribeClusterEndpoints",
    "cs:DescribeEdasClusterToken",
    "cs:GetUserPermissions",
    "cs:CreateEdasClusterRole",
    "cs:CreateEdasClusterRoleBinding"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

AliyunComputeNestPolicyForOperation

O&M 権限

ポリシーの内容

{
  "Action": [
    "ros:*Stack",
    "ros:ListStack*",
    "cs:Get*",
    "cs:Describe*Cluster*",
    "oos:StartExecution",
    "oos:ListExecutions",
    "ecs:*Instance*"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}

実際の効果

{
  "Action": [
    "ros:UpdateStack",
    "ros:GetStack",
    "ros:ListStackEvents",
    "ros:ListStackResources",
    "cs:GetClusters",
    "cs:GetUserPermissions",
    "cs:DescribeClusterUserKubeconfig",
    "cs:DescribeClusterDetail",
    "cs:DescribeClusterEndpoints",
    "cs:DescribeEdasClusterToken",
    "oos:StartExecution",
    "oos:ListExecutions",
    "ecs:StartInstance",
    "ecs:DescribeInstances",
    "ecs:RebootInstance",
    "ecs:StopInstance",
    "ecs:ModifyInstanceSpec",
    "ecs:DescribeInstanceTypes",
    "ecs:ModifyPrepayInstanceSpec",
    "ecs:ModifyInstanceNetworkSpec",
    "ecs:DescribeInstanceHistoryEvents",
    "ecs:DescribeInstanceVncUrl",
    "ecs:DescribeManagedInstances",
    "ecs:StopInstances"
  ],
  "Resource": [
    "*"
  ],
  "Effect": "Allow"
}