AliyunNASFullAccess is a service system policy that is managed by Alibaba Cloud. You can attach the AliyunNASFullAccess policy to a Resource Access Management (RAM) identity, such as a RAM user, RAM user group, and RAM role. The AliyunNASFullAccess policy: Provides full access to Network Attached Storage via Management Console.
Policy details
Type: service system policy
Creation time: 03:34:09 on March 29, 2016
Update time: 02:42:42 on March 25, 2025
Current version: v5
Policy content
{
"Version": "1",
"Statement": [
{
"Action": "nas:*",
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "bssapi:QueryResourcePackageInstances",
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "cms:QueryMetricList",
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"vpc:DescribeVpcs",
"vpc:DescribeVSwitches"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "ram:GetRole",
"Resource": [
"acs:ram:*:*:role/aliyunservicerolefornasstandard",
"acs:ram:*:*:role/aliyunservicerolefornasextreme",
"acs:ram:*:*:role/aliyunservicerolefornasencryption",
"acs:ram:*:*:role/aliyunservicerolefornaslogdelivery",
"acs:ram:*:*:role/aliyunservicerolefornasecshandler",
"acs:ram:*:*:role/aliyunservicerolefornascpfsnetwork",
"acs:ram:*:*:role/aliyunservicerolefornascpfsclient",
"acs:ram:*:*:role/aliyunservicerolefornasossdataflow",
"acs:ram:*:*:role/aliyunservicerolefornaseventnotification",
"acs:ram:*:*:role/aliyunnastieringrole",
"acs:ram:*:*:role/aliyunnasencryptdefaultrole",
"acs:ram:*:*:role/aliyunnasdefaultrole",
"acs:ram:*:*:role/aliyunnaslogarchiverole",
"acs:ram:*:*:role/aliyunnasmanageenirole"
],
"Effect": "Allow"
},
{
"Action": "ram:CreateServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": [
"extreme.nas.aliyuncs.com",
"encryption.nas.aliyuncs.com",
"logdelivery.nas.aliyuncs.com",
"ecs-handler.nas.aliyuncs.com",
"cpfs-network.nas.aliyuncs.com",
"cpfs-client.nas.aliyuncs.com",
"oss-dataflow.nas.aliyuncs.com",
"event-notification.nas.aliyuncs.com"
]
}
}
},
{
"Action": [
"kms:ListAliasesByKeyId",
"kms:ListKeys"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": "bss:ModifyAgreementRecord",
"Resource": "*",
"Effect": "Allow"
}
]
}