本文介紹時序資料庫服務關聯角色(AliyunServiceRoleForTSDB)。
背景資訊
時序資料庫服務關聯角色(AliyunServiceRoleForTSDB)是在某些情境下,為了完成時序資料庫自身的某個功能,需要擷取其他雲端服務的存取權限。更多關於服務關聯角色的資訊,請參見服務關聯角色。
應用情境
時序資料庫InfluxDB®️版需要訪問ECS、MongoDB和Redis相關的資源,通過服務關聯角色能夠擷取存取權限。
AliyunServiceRoleForTSDB介紹
角色名稱: AliyunServiceRoleForTSDB
角色權限原則:AliyunServiceRolePolicyForTSDB
許可權說明:允許時序資料庫服務訪問您ECS、MongoDB和Redis中的資料。
使用該許可權的作用有以下兩點:
管理彈性網卡(ENI),管理安全性群組, 以開通雙向VPC訪問。
查詢MongoDB和Redis的執行個體資訊,以完成雲執行個體監控。
{
"Version":"1",
"Statement":[
{
"Action":[
"ecs:CreateNetworkInterface",
"ecs:DescribeNetworkInterfaces",
"ecs:DeleteNetworkINterface",
"ecs:AttachNetworkInterface",
"ecs:DetachNetworkInterface",
"ecs:CreateNetworkInterfacePermission",
"ecs:DescribeNetworkInterfacePermissions",
"ecs:DeleteNetworkInterfacePermission",
"ecs:CreateSecurityGroup",
"ecs:DescirbeSecurityGroups",
"ecs:DescribeSecurityGroupAttribute",
"ecs:DeleteSecurityGroup",
"ecs:AuthorizeSecurityGroup",
"ecs:AuthorizeSecurityGroupEgress",
"ecs:RevokeSecurityGroup",
"ecs:RevokeSecurityGroupEgress"
],
"Resource":"*",
"Effect":"Allow"
},
{
"Action":[
"dds:DescribeDBInstances",
"dds:DescribeDBInstanceAttribute"
],
"Resource":"*",
"Effect":"Allow"
},
{
"Action":[
"kvstore:DescribeRegions",
"kvstore:DescribeInstances",
"kvstore:DescribeInstanceAttribute"
],
"Resource":"*",
"Effect":"Allow"
},
{
"Action":"ram:DeleteServiceLinkedRole",
"Resource":"*",
"Effect":"Allow",
"Condition":{
"StringEquals":{
"ram:ServiceName":"hitsdb.aliyuncs.com"
}
}
}
]
}刪除服務關聯角色
如果您需要刪除AliyunServiceRoleForTSDB(服務關聯角色),請先確保您帳號下沒有執行個體正在使用該角色,方可進行刪除。具體操作請參見服務關聯角色。
子帳號建立服務關聯角色所需的許可權
{
"Action":"ram:CreateServiceLinkedRole",
"Resource":"*",
"Effect":"Allow",
"Condition":{
"StringEquals":{
"ram:ServiceName":"hitsdb.aliyuncs.com"
}
}
}