全部產品
Search
文件中心

PolarDB:PolarDB服務關聯角色

更新時間:Nov 26, 2024

本文為您介紹PolarDB服務關聯角色(AliyunServiceRoleForPolarDB)的應用情境以及如何刪除服務關聯角色。

背景資訊

PolarDB服務關聯角色(AliyunServiceRoleForPolarDB)是在某些情況下,為了完成PolarDB自身的某個功能,需要擷取其他雲端服務的存取權限,而提供的RAM角色。

應用情境

AliyunServiceRoleForPolarDB介紹

角色名稱:AliyunServiceRoleForPolarDB

角色權限原則:AliyunServiceRolePolicyForPolarDB

許可權說明:

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "pvtz:DescribeUserServiceStatus",
                "pvtz:DescribeZones",
                "pvtz:DescribeZoneInfo",
                "pvtz:DescribeZoneRecords",
                "pvtz:CheckZoneName",
                "pvtz:AddZone",
                "pvtz:BindZoneVpc",
                "pvtz:DeleteZone",
                "pvtz:AddZoneRecord",
                "pvtz:UpdateZoneRecord",
                "pvtz:DeleteZoneRecord",
                "dts:CreateDtsInstance",
                "dts:ConfigureDtsJob",
                "dts:StartDtsJob",
                "dts:DescribePreCheckStatus",
                "dts:DescribeDtsJobDetail",
                "dts:DescribeDtsJobs",
                "dts:ModifyDtsJob",
                "dts:SuspendDtsJob",
                "dts:StopDtsJob",
                "dts:DeleteDtsJob",
                "dts:CheckDefaultRole",
                "dts:ReverseTwoWayDirection",
                "dts:ModifyDtsJobEndpoint",
                "privatelink:ListVpcEndpointServicesByEndUser",
                "privatelink:CreateVpcEndpoint",
                "privatelink:ListVpcEndpoints",
                "privatelink:UpdateVpcEndpointAttribute",
                "privatelink:GetVpcEndpointAttribute",
                "privatelink:ListVpcEndpointSecurityGroups",
                "privatelink:AttachSecurityGroupToVpcEndpoint",
                "privatelink:DetachSecurityGroupFromVpcEndpoint",
                "privatelink:AddZoneToVpcEndpoint",
                "privatelink:RemoveZoneFromVpcEndpoint",
                "privatelink:ListVpcEndpointZones",
                "privatelink:DeleteVpcEndpoint",
                "ecs:CreateNetworkInterface",
                "ecs:DeleteNetworkInterface",
                "ecs:DeleteNetworkInterfacePermission",
                "ecs:AttachNetworkInterface",
                "ecs:DetachNetworkInterface",
                "ecs:DescribeNetworkInterfaceAttribute",
                "ecs:DescribeNetworkInterfaces",
                "ecs:ModifyNetworkInterfaceAttribute",
                "ecs:CreateNetworkInterfacePermission",
                "ecs:DescribeNetworkInterfacePermissions",
                "ecs:DescribeSecurityGroupAttribute",
                "ecs:DescribeSecurityGroups",
                "vpc:DescribeVSwitches",
                "vpc:DescribeVpcs",
                "dms:AddInstance",
                "dms:ListInstances",
                "dms:GetInstance"
            ],
            "Resource": "*",
            "Effect": "Allow"
        },
        {
            "Action": "ram:DeleteServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "polardb.aliyuncs.com"
                }
            }
        },
        {
            "Action": "ram:CreateServiceLinkedRole",
            "Resource": "*",
            "Effect": "Allow",
            "Condition": {
                "StringEquals": {
                    "ram:ServiceName": "privatelink.aliyuncs.com"
                }
            }
        }
    ]
}

刪除服務關聯角色

如果您需要刪除AliyunServiceRoleForPolarDB(服務關聯角色),需要先釋放依賴這個服務關聯角色的PolarDB叢集。