全部产品
Search
文档中心

专有网络 VPC:RAM鉴权

更新时间:Aug 02, 2023

在使用RAM用户调用VPC API前,需要阿里云账号通过创建授权策略对RAM用户进行授权。在授权策略中,使用资源描述符(Alibaba Cloud Resource Name, ARN)指定授权资源。

可授权的专有网络资源类型

下表列举了VPC中可授权的资源及其描述方式,其中$regionid/$accoutid/$vrouterid... 为具体的资源ID,*代表对应的所有资源。

资源类型授权策略中的资源描述方法
专有网络(VPC)acs:vpc:$regionid:$accountid:vpc/$vpcid
acs:vpc:$regionid:$accountid:vpc/*
acs:vpc:*:$accountid:vpc/*
路由器(vRouter)acs:vpc:$regionid:$accountid:vrouter/$vrouterid
acs:vpc:$regionid:$accountid:vrouter/*
acs:vpc:*:$accountid:vrouter/*
交换机(vSwitch)acs:vpc:$regionid:$accountid:vswitch/$vswitchid
acs:vpc:$regionid:$accountid:vswitch/*
acs:vpc:*:$accountid:vswitch/*
路由表(Route Table)acs:vpc:$regionid:$accountid:routetable/$routetableid
acs:vpc:$regionid:$accountid:routetable/*
acs:vpc:*:$accountid:routetable/*
DHCP选项集(DHCP Options Set)acs:vpc:$regionid:$accountid:dhcpoptionsset/$dhcpoptionssetid
acs:vpc:$regionid:$accountid:dhcpoptionsset/*
acs:vpc:*:$accountid:dhcpoptionsset/*
高可用IP (HaVip)acs:vpc:$regionid:$accountid:havip/$havipid
acs:vpc:$regionid:$accountid:havip/*
acs:vpc:*:$accountid:havip/*
弹性公网IP(EIP)acs:vpc:$regionid:$accountid:eip/$allocationid
acs:vpc:$regionid:$accountid:eip/*
acs:vpc:*:$accountid:eip/*
NAT网关(NAT Gateway)acs:vpc:$regionid:$accountid:natgateway/$natgatewayid
acs:vpc:$regionid:$accountid:natgateway/*
acs:vpc*:$accountid:vpc/*
NAT网关带宽包(NAT Gateway Bandwidth Package)acs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
acs:vpc:$regionid:$accountid:bandwidthpackage/*
aacs:vpc:*:$accountid:vpc/*
端口转发表(Forward Table)acs:vpc:$regionid:$accountid:forwardtable/$forwardtableid
acs:vpc:$regionid:$accountid:forwardtable/*
acs:vpc:*:$accountid:vpc/*
SNAT表(SNAT Table)acs:vpc:$regionid:$accountid:snattable/$snattableid
acs:vpc:$regionid:$accountid:snattable/*
acs:vpc:*:$accountid:vpc/*
用户网关(Customer Gateway)acs:vpc:$regionid:$accountid:customergateway/$customergatewayid
acs:vpc:$regionid:$accountid:customergateway/*
acs:vpc:*:$accountid:customergateway/*
IPsec连接(IPsec Connection)acs:vpc:$regionid:$accountid:vpnconnection/$vpnconnectionid
acs:vpc:$regionid:$accountid:vpnconnection/*
acs:vpc:*:$accountid:vpnconnection/*
VPN网关(VPN Gateway)acs:vpc:$regionid:$accountid:vpngateway/$vpngatewayid
acs:vpc:$regionid:$accountid:vpngateway/*
acs:vpc:*:$accountid:vpngateway/*
网络ACL(Network ACL)acs:vpc:$regionid:$accountid:networkacl/$networkaclid
acs:vpc:$regionid:$accountid:networkacl/*
acs:vpc:*:$accountid:networkacl/*
附加网段(SecondaryCidrBlock)acs:vpc:$regionid:$accountid:vpc/$vpcid
IPv6网关(IPv6 Gateway)acs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
acs:vpc:$regionid:$accountid:ipv6gateway/*
acs:vpc:*:$accountid:ipv6gateway/*
IPv6公网带宽(IPV6 Bandwidth)acs:vpc:$regionid:$accountid:ipv6bandwidth/$ipv6instanceid
acs:vpc:$regionid:$accountid:ipv6bandwidth/*
acs:vpc:*:$accountid:ipv6bandwidth/*
通用资源acs:vpc:$regionid:$accountid:*
acs:vpc:*:$accountid:*

可授权的VPC接口

下表列举了VPC中可授权的API及其描述方式,其中$regionid/accoutid/vrouterid... 为具体的资源ID,*代表对应的所有资源。

API资源描述
CreateVpcacs:vpc:$regionid:$accountid:vpc/*
DeleteVpcacs:vpc:$regionid:$accountid:vpc/$vpcid
DescribeVpcsacs:vpc:$regionid:$accountid:vpc/*
ModifyVpcAttributeacs:vpc:$regionid:$accountid:vpc/$vpcid
DescribeVRoutersacs:vpc:$regionid:$accountid:vrouter/*
ModifyVRouterAttributeacs:vpc:*:$accountid:*
CreateVSwitchacs:vpc:$regionid:$accountid:vswitch/*
DescribeVSwitchAttributesacs:vpc:$regionid:$accountid:vswitch/$VSwitchId
DeleteVSwitchacs:vpc:$regionid:$accountid:vswitch/$vswitchid
DescribeVSwitchesacs:vpc:$regionid:$accountid:vswitch/*
acs:vpc:$regionId:$accountId}:vpc/$VpcId
acs:vpc:$regionId:$accountId:vswitch/$VSwitchId
ModifyVSwitchAttributeacs:vpc:$regionid:$accountid:vswitch/$vswitchid
CreateRouteEntryacs:vpc:$regionid:$accountid:routetable/$routetableid
DeleteRouteEntryacs:vpc:$regionid:$accountid:routetable/$routetableid
DescribeRouteTablesacs:vpc:$regionid:$accountid:routetable/*
"vpc:VRouter":"acs:vpc$regionid:$accountid:vrouter/$vrouterid"
CreateDHCPOptionsSetacs:vpc:$regionid:$accountid:dhcpoptionsset/*
DescribeCreateDHCPOptionsSetsacs:vpc:$regionid:$accountid:dhcpoptionsset/*
ModifyDHCPOptionsSetAttributesacs:vpc:$regionid:$accountid:dhcpoptionsset/$dhcpoptionssetid
DeleteDHCPOptionsSetacs:vpc:$regionid:$accountid:dhcpoptionsset/$dhcpoptionssetid
AssociatedDHCPOptionsSetacs:vpc:$regionid:$accountid:dhcpoptionsset/$dhcpoptionssetid
acs:vpc:$regionid:$accountid:vpc/$vpcid
UnassociateDHCPOptionsSetacs:vpc:$regionid:$accountid:dhcpoptionsset/$dhcpoptionssetid
acs:vpc:$regionid:$accountid:vpc/$vpcid
CreateHaVipacs:vpc:$regionid:$accountid:havip/*
acs:vpc:$regionid:$accountid:vswitch/$vswitchid
DeleteHaVipacs:vpc:$regionid:$accountid:havip/$havipid
AssociateHaVipacs:vpc:$regionid:$accountid:havip/$havipid
acs:vpc:%s:%s:certificate/%
acs:ecs:$regionid:$accountid:instance/$instanceid
UnassociateHaVipacs:vpc:$regionid:$accountid:havip/$havipid
acs:ecs:$regionid:$accountid:instance/$instanceid
DescribeHaVipsacs:vpc:$regionid:$accountid:havip/*
AllocateEipAddressacs:vpc:$regionid:$accountid:eip/*
AssociateEipAddressacs:vpc:$regionid:$accountid:eip/*
绑定ECS实例

acs:vpc:$regionid:$accountid:eip/$allocationid

acs:ecs:$regionid:$accountid:instance/$instanceid

绑定HAVIP

acs:vpc:$regionid:$accountid:eip/$allocationid

acs:vpc:$regionid:$accountid:havip/$havipid

DescribeEipAddressesacs:vpc:$regionid:$accountid:eip/*
UnassociateEipAddress绑定ECS实例

acs:vpc:$regionid:$accountid:eip/$allocationid

acs:ecs:$regionid:$accountid:instance/$instanceid

绑定HAVIP

acs:vpc:$regionid:$accountid:eip/$allocationid

acs:vpc:$regionid:$accountid:havip/$havipid

ReleaseEipAddressacs:vpc:$regionid:$accountid:eip/$allocationid
DescribeEipMonitorDataacs:vpc:$regionid:$accountid:eip/$allocationid
acs:ecs:$regionid:$accountid:instance/$instanceid
CreateNatGatewayacs:vpc:$regionid:$accountid:natgateway/*
DescribeNatGatewaysacs:vpc:$regionid:$accountid:natgateway/$natgatewayid
acs:vpc:$regionid:$accountid:natgateway/*
ModifyNatGatewaySpecacs:vpc:$regionid:$accountid:natgateway/$natgatewayid
ModifyNatGatewayAttributeacs:vpc:$regionid:$accountid:natgateway/$natgatewayid
acs:ecs:$regionid:$accountid:instance/$instanceid
DeleteNatGatewayacs:vpc:$regionid:$accountid:natgateway/$natgatewayid
acs:ecs:$regionid:$accountid:instance/$instanceid
CreateBandwidthPackageacs:vpc:$regionid:$accountid:bandwidthpackage/*
DescribeBandwidthPackagesacs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
acs:vpc:$regionid:$accountid:bandwidthpackage/*
ModifyBandwidthPackageSpecacs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
ModifyBandwidthPackageAttributeacs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
AddBandwidthPackageIpsacs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
RemoveBandwidthPackageIpsacs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
DeleteBandwidthPackageacs:vpc:$regionid:$accountid:bandwidthpackage/$bandwidthpackageid
CreateForwardEntryacs:vpc:$regionid:$accountid:forwardtable/$forwardtableid
DeleteForwardEntryacs:vpc:$regionid:$accountid:forwardtable/$forwardtableid
ModifyForwardEntryacs:vpc:$regionid:$accountid:forwardtable/$forwardtableid
DescribeForwardTableEntriesacs:vpc:$regionid:$accountid:forwardtable/$forwardtableid
CreateSnatEntryacs:vpc:$regionid:$accountid:snattable/*
ModifySnatEntryacs:vpc:$regionid:$accountid:snattable/$snattableid
DescribeSnatTableEntriesacs:vpc:$regionid:$accountid:snattable/$snattableid
DeleteSnatEntryacs:vpc:$regionid:$accountid:snattable/$snattableid
CreateCustomerGatewayacs:vpc:$regionid:$accountid:customergateway/*
DeleteCustomerGatewayacs:vpc:$regionid:$accountid:customergateway/$customergatewayid
DescribeCustomerGatewayacs:vpc:$regionid:$accountid:customergateway/$customergatewayid
DescribeCustomerGatewaysacs:vpc:$regionid:$accountid:customergateway/*
ModifyCustomerGatewayAttributeacs:vpc:$regionid:$accountid:customergateway/$customergatewayid
CreateVpnConnectionacs:vpc:$regionid:$accountid:vpnconnection/*
DeleteVpnConnectionacs:vpc:$regionid:$accountid:vpnconnection/$vpnconnectionid
DescribeVpnConnectionacs:vpc:$regionid:$accountid:vpnconnection/$vpnconnectionid
DescribeVpnConnectionsacs:vpc:$regionid:$accountid:vpnconnection/*
ModifyVpnConnectionAttributeacs:vpc:$regionid:$accountid:vpnconnection/$vpnconnectionid
DownloadVpnConnectionConfigacs:vpc:$regionid:$accountid:vpnconnection/$vpnconnectionid
DeleteVpnGatewayacs:vpc:$regionid:$accountid:vpngateway/$vpngatewayid
DescribeVpnGatewayacs:vpc:$regionid:$accountid:vpngateway/$vpngatewayid
DescribeVpnGatewaysacs:vpc:$regionid:$accountid:vpngateway/*
ModifyVpnGatewayAttributeacs:vpc:$regionid:$accountid:vpngateway/$vpngatewayid
CreateNetworkAclacs:vpc:$regionid:$accountid: networkacl/*
DeleteNetworkAclacs:vpc:$regionid:$accountid: networkacl/$networkaclid
DescribeNetworkAclsacs:vpc:$regionid:$accountid: networkacl/*
DescribeNetworkAclAttributesacs:vpc:$regionid:$accountid: networkacl/$networkaclid
ModifyNetworkAclAttributesacs:vpc:$regionid:$accountid: networkacl/$networkaclid
AssociateNetworkAclacs:vpc:$regionid:$accountid: networkacl/$networkaclid
acs:vpc:$regionid:$accountid:vswitch/$vswitchid
UnassociateNetworkAclacs:vpc:$regionid:$accountid: networkacl/$networkaclid
acs:vpc:$regionid:$accountid:vswitch/$vswitchid
UpdateNetworkAclEntriesacs:vpc:$regionid:$accountid: networkacl/$networkaclid
CopyNetworkAclEntriesacs:vpc:$regionid:$accountid: networkacl/$networkaclid
AssociateVpcCidrBlockacs:vpc:$regionid:$accountid: vpc/$vpcid
UnassociateVpcCidrBlockacs:vpc:$regionid:$accountid: vpc/$vpcid
CreateIpv6Gatewayacs:vpc:$regionid:$accountid:ipv6gateway/*
DeleteIpv6Gatewayacs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
DescribeIpv6Gatewaysacs:vpc:$regionid:$accountid:ipv6gateway/*
acs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
AllocateIpv6InternetBandwidthacs:vpc:$regionid:$accountid:ipv6bandwidth/*
CreateIpv6EgressOnlyRuleacs:vpc:$regionid:$accountid:ipv6gateway/*
DeleteIpv6EgressOnlyRuleacs:vpc:$regionid:$accountid:ipv6gateway/$ruleid
DeleteIpv6InternetBandwidthacs:vpc:$regionid:$accountid:ipv6bandwidth/$ipv6bandwidthid
DescribeIpv6Addressesacs:vpc:$regionid:$accountid:vpc/*
DescribeIpv6EgressOnlyRulesacs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
DescribeIpv6GatewayAttributeacs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
ModifyIpv6AddressAttributeacs:vpc:$regionid:$accountid:vpc/$ipv6instanceid
ModifyIpv6GatewayAttributeacs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
ModifyIpv6GatewaySpecacs:vpc:$regionid:$accountid:ipv6gateway/$ipv6gatewayid
ModifyIpv6InternetBandwidthacs:vpc:$regionid:$accountid:ipv6bandwidth/$ipv6instanceid