全部产品
Search
文档中心

Web 应用防火墙:授权信息

更新时间:Jun 12, 2025

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 Web应用防火墙 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 Web应用防火墙 的 RAM 代码(RamCode)为 yundun-waf ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是Web应用防火墙定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

yundun-waf:DescribeSlsLogStore DescribeSlsLogStore get
*全部资源
*
yundun-waf:ModifyPauseProtectionStatus ModifyPauseProtectionStatus update
*全部资源
*
yundun-waf:DescribeLogDeliveryConfigs DescribeLogDeliveryConfigs list
*全部资源
*
yundun-waf:DeleteApisecEvents DeleteApisecEvents delete
*全部资源
*
yundun-waf:ModifyMigrateSuggestion ModifyMigrateSuggestion update
*全部资源
*
yundun-waf:CopyDefenseTemplate CopyDefenseTemplate create
*全部资源
*
yundun-waf:DeleteDefenseResource DeleteDefenseResource delete
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DeleteRuleGroup DeleteRuleGroup delete
*全部资源
*
yundun-waf:DescribeTgwDomainBindings DescribeTgwDomainBindings get
*全部资源
*
yundun-waf:DeleteLogDeliveryConfig DeleteLogDeliveryConfig delete
*全部资源
*
yundun-waf:DescribeMajorProtectionIntelligenceCount DescribeMajorProtectionIntelligenceCount get
*全部资源
*
yundun-waf:DescribeDomainDNSRecord DescribeDomainDNSRecord get
*全部资源
*
yundun-waf:DescribeApisecProtectionGroups DescribeApisecProtectionGroups list
*全部资源
*
yundun-waf:ListTagValues ListTagValues get
*全部资源
*
yundun-waf:ModifyHybridCloudGroupShrinkServer ModifyHybridCloudGroupShrinkServer update
*全部资源
*
yundun-waf:DescribeApisecSlsLogStores DescribeApisecSlsLogStores get
*全部资源
*
yundun-waf:DescribeUserEventType DescribeUserEventType get
*全部资源
*
yundun-waf:DescribeHybridCloudPullXagentRule DescribeHybridCloudPullXagentRule get
*全部资源
*
yundun-waf:DescribeRuleHitsTopResource DescribeRuleHitsTopResource get
*全部资源
*
yundun-waf:DescribeAssetDomainAttacks DescribeAssetDomainAttacks get
*全部资源
*
yundun-waf:DescribeRegularRules DescribeRegularRules get
*全部资源
*
yundun-waf:DescribeResponseCodeTrendGraph DescribeResponseCodeTrendGraph get
*全部资源
*
yundun-waf:DescribeCustomBaseRuleCompileResult DescribeCustomBaseRuleCompileResult get
*全部资源
*
yundun-waf:DescribeFreeUserEventCount DescribeFreeUserEventCount get
*全部资源
*
yundun-waf:ModifyResourceLogStatus ModifyResourceLogStatus update
*全部资源
*
yundun-waf:DescribeMajorProtectionBlackIps DescribeMajorProtectionBlackIps get
*全部资源
*
yundun-waf:DescribeUserSlsLogRegions DescribeUserSlsLogRegions get
*全部资源
*
yundun-waf:CreateMigrateTask CreateMigrateTask create
*全部资源
*
yundun-waf:ModifyDefenseTemplate ModifyDefenseTemplate update
*全部资源
*
yundun-waf:DescribeDomainValidateConfig DescribeDomainValidateConfig get
*全部资源
*
yundun-waf:DescribeDefaultHttps DescribeDefaultHttps get
*全部资源
*
yundun-waf:DescribeUserEventTrend DescribeUserEventTrend get
*全部资源
*
yundun-waf:DescribeProductInstances DescribeProductInstances get
*全部资源
*
yundun-waf:ModifyHybridCloudPushSdkInfo ModifyHybridCloudPushSdkInfo update
*全部资源
*
yundun-waf:DescribePauseProtectionStatus DescribePauseProtectionStatus get
*全部资源
*
yundun-waf:CreateDefenseRule CreateDefenseRule create
*全部资源
*
yundun-waf:ModifyResourceLogFieldConfig ModifyResourceLogFieldConfig update
*全部资源
*
yundun-waf:DescribeAccountDelegatedStatus DescribeAccountDelegatedStatus get
*全部资源
*
yundun-waf:DescribeCnameCount DescribeCnameCount get
*全部资源
*
yundun-waf:DeleteCustomBaseRule DeleteCustomBaseRule delete
*全部资源
*
yundun-waf:DescribeDomainUsedPorts DescribeDomainUsedPorts get
*全部资源
*
yundun-waf:CreateApisecRule CreateApisecRule create
*全部资源
*
yundun-waf:DescribeHybridCloudProtectableCount DescribeHybridCloudProtectableCount get
*全部资源
*
yundun-waf:DescribeNetworkFlowTopNMetric DescribeNetworkFlowTopNMetric get
*全部资源
*
yundun-waf:DescribeRobotHitsTopClientIp DescribeRobotHitsTopClientIp get
*全部资源
*
yundun-waf:ModifyLogDeliveryConfig ModifyLogDeliveryConfig create
*全部资源
*
yundun-waf:ModifyApisecEvents ModifyApisecEvents update
*全部资源
*
yundun-waf:DescribeUnprotectAssetSubDomainStatisticsInfo DescribeUnprotectAssetSubDomainStatisticsInfo get
*全部资源
*
yundun-waf:DescribeFreeUserEventTypes DescribeFreeUserEventTypes get
*全部资源
*
yundun-waf:DescribeHybridCloudGroups DescribeHybridCloudGroups list
*全部资源
*
yundun-waf:DescribeAlarmList DescribeAlarmList get
*全部资源
*
yundun-waf:DescribeUserApiRequest DescribeUserApiRequest get
*全部资源
*
yundun-waf:DescribeUploadBlackIpFormInfo DescribeUploadBlackIpFormInfo get
*全部资源
*
yundun-waf:DescribeThreatEventAttackToolDistribute DescribeThreatEventAttackToolDistribute list
*全部资源
*
yundun-waf:ModifyDefenseResourceGroup ModifyDefenseResourceGroup update
*全部资源
*
yundun-waf:ModifyAssetCenterStatus ModifyAssetCenterStatus none
*全部资源
*
yundun-waf:DescribeGrayFeature DescribeGrayFeature get
*全部资源
*
yundun-waf:DescribeRobotOverview DescribeRobotOverview none
*全部资源
*
yundun-waf:DescribeSecurityEventTimeSeriesMetric DescribeSecurityEventTimeSeriesMetric get
*全部资源
*
yundun-waf:DescribeSensitiveRequests DescribeSensitiveRequests list
*全部资源
*
yundun-waf:DescribeBotIntelligenceInfos DescribeBotIntelligenceInfos get
*全部资源
*
yundun-waf:ModifyUserLogFieldConfig ModifyUserLogFieldConfig update
*全部资源
*
yundun-waf:DescribeUserLogFieldConfig DescribeUserLogFieldConfig get
*全部资源
*
yundun-waf:DescribeApisecEventDomainStatistic DescribeApisecEventDomainStatistic get
*全部资源
*
yundun-waf:ModifyApisecModuleStatus ModifyApisecModuleStatus update
*全部资源
*
yundun-waf:DescribeAlarmBanner DescribeAlarmBanner get
*全部资源
*
yundun-waf:DescribeComplianceRules DescribeComplianceRules get
*全部资源
*
yundun-waf:DescribeApisecSensitiveDomainStatistic DescribeApisecSensitiveDomainStatistic get
*全部资源
*
yundun-waf:DescribeMigratePreCheckResult DescribeMigratePreCheckResult get
*全部资源
*
yundun-waf:DescribeRoleAuthStatus DescribeRoleAuthStatus get
*全部资源
*
yundun-waf:DescribeApisecUserOperations DescribeApisecUserOperations get
*全部资源
*
yundun-waf:AddIpToBlackWhiteList AddIpToBlackWhiteList create
*全部资源
*
yundun-waf:DeleteDefenseRule DeleteDefenseRule delete
*全部资源
*
yundun-waf:DescribeUserHourlyBill DescribeUserHourlyBill list
*全部资源
*
yundun-waf:DescribeMajorProtectionBlackIp DescribeMajorProtectionBlackIp get
*全部资源
*
yundun-waf:DescribeApisecAbnormalDomainStatistic DescribeApisecAbnormalDomainStatistic get
*全部资源
*
yundun-waf:ModifyHybridCloudGroup ModifyHybridCloudGroup update
*全部资源
*
yundun-waf:DescribeApisecApiResources DescribeApisecApiResources get
*全部资源
*
yundun-waf:DescribeDefenseResourceGroupNames DescribeDefenseResourceGroupNames list
*全部资源
*
yundun-waf:DescribeElasticBills DescribeElasticBills get
*全部资源
*
yundun-waf:DescribeRuleHitsTopTuleType DescribeRuleHitsTopTuleType get
*全部资源
*
yundun-waf:DescribeHybridCloudServerRegions DescribeHybridCloudServerRegions get
*全部资源
*
yundun-waf:DescribeBaseRuleStaticsInfo DescribeBaseRuleStaticsInfo get
*全部资源
*
yundun-waf:DescribeResourceSupportRegions DescribeResourceSupportRegions get
*全部资源
*
yundun-waf:DescribeHybridCloudResources DescribeHybridCloudResources get
*全部资源
*
yundun-waf:DescribeUserAbnormalType DescribeUserAbnormalType get
*全部资源
*
yundun-waf:DescribeResourceRegionId DescribeResourceRegionId list
*全部资源
*
yundun-waf:DescribeCloudResourceAccessedPorts DescribeCloudResourceAccessedPorts get
*全部资源
*
yundun-waf:DescribeSceneHitsTopUrl DescribeSceneHitsTopUrl get
*全部资源
*
yundun-waf:DescribeHybridCloudUnassignedMachines DescribeHybridCloudUnassignedMachines get
*全部资源
*
yundun-waf:DescribePunishedDomains DescribePunishedDomains get
*全部资源
*
yundun-waf:ModifyHybridCloudServer ModifyHybridCloudServer update
*全部资源
*
yundun-waf:DescribeSlbAttackUrl DescribeSlbAttackUrl list
*全部资源
*
yundun-waf:DescribeRuleGroups DescribeRuleGroups get
*全部资源
*
yundun-waf:CreateCustomBaseRule CreateCustomBaseRule create
*全部资源
*
yundun-waf:CreateMigrateCloudNativeResource CreateMigrateCloudNativeResource create
*全部资源
*
yundun-waf:CreateApiExport CreateApiExport create
*全部资源
*
yundun-waf:DescribeApisecSuggestions DescribeApisecSuggestions get
*全部资源
*
yundun-waf:DeleteExpiredMajorProtectionBlackIp DeleteExpiredMajorProtectionBlackIp delete
*全部资源
*
yundun-waf:DeleteMajorProtectionBlackIp DeleteMajorProtectionBlackIp delete
*全部资源
*
yundun-waf:DescribeWebSourceIpPv DescribeWebSourceIpPv list
*全部资源
*
yundun-waf:DescribeMigrateCheckResult DescribeMigrateCheckResult get
*全部资源
*
yundun-waf:DescribeCloudResourceAccessPortDetails DescribeCloudResourceAccessPortDetails get
*全部资源
*
yundun-waf:DescribePrepayDailyBills DescribePrepayDailyBills get
*全部资源
*
yundun-waf:DeleteMemberAccount DeleteMemberAccount delete
*全部资源
*
yundun-waf:DescribeAssetDomainStatisticsInfo DescribeAssetDomainStatisticsInfo get
*全部资源
*
yundun-waf:DescribeHybridCloudCluster DescribeHybridCloudCluster get
*全部资源
*
yundun-waf:ModifyHybridCloudGroupExpansionServer ModifyHybridCloudGroupExpansionServer update
*全部资源
*
yundun-waf:DescribeSecurityEventTopNMetric DescribeSecurityEventTopNMetric get
*全部资源
*
yundun-waf:ReleaseInstance ReleaseInstance delete
*全部资源
*
yundun-waf:ConfirmMigrateTask ConfirmMigrateTask update
*全部资源
*
yundun-waf:DescribeThreatEventTargetDistribute DescribeThreatEventTargetDistribute list
*全部资源
*
yundun-waf:DescribeResourcePort DescribeResourcePort get
*全部资源
*
yundun-waf:DescribeMajorProtectionIntelligenceDetail DescribeMajorProtectionIntelligenceDetail get
*全部资源
*
yundun-waf:DescribeDomainDetail DescribeDomainDetail get
*全部资源
*
yundun-waf:DescribeBotRuleInfos DescribeBotRuleInfos get
*全部资源
*
yundun-waf:ModifyDefenseResourceXff ModifyDefenseResourceXff update
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeFreeUserEvents DescribeFreeUserEvents get
*全部资源
*
yundun-waf:RollbackMigrateDomains RollbackMigrateDomains update
*全部资源
*
yundun-waf:DescribeSceneHitsTopClientIp DescribeSceneHitsTopClientIp get
*全部资源
*
yundun-waf:ModifyWebFingerScanStatus ModifyWebFingerScanStatus update
*全部资源
*
yundun-waf:DescribeDDoSStatus DescribeDDoSStatus get
*全部资源
*
yundun-waf:DescribeAbnormalCloudResources DescribeAbnormalCloudResources none
*全部资源
*
yundun-waf:ModifyMemberAccount ModifyMemberAccount update
*全部资源
*
yundun-waf:DescribeSensitiveRequestLog DescribeSensitiveRequestLog get
*全部资源
*
yundun-waf:DescribeSlsOpenStatus DescribeSlsOpenStatus get
*全部资源
*
yundun-waf:DescribeUserAsset DescribeUserAsset get
*全部资源
*
yundun-waf:DescribeResourceLogDeliveryStatus DescribeResourceLogDeliveryStatus list
*全部资源
*
yundun-waf:DescribeWafSourceIpSegment DescribeWafSourceIpSegment get
*全部资源
*
yundun-waf:DescribeRobotHitsTopUrl DescribeRobotHitsTopUrl get
*全部资源
*
yundun-waf:DescribeCloudResources DescribeCloudResources list
*全部资源
*
yundun-waf:DescribeApisecLogDeliveries DescribeApisecLogDeliveries get
*全部资源
*
yundun-waf:DescribeSceneHitsTopResource DescribeSceneHitsTopResource get
*全部资源
*
yundun-waf:DescribeTemplateResources DescribeTemplateResources list
*全部资源
*
yundun-waf:DescribeCloudNativeOpenInstanceNumber DescribeCloudNativeOpenInstanceNumber get
*全部资源
*
yundun-waf:DescribeRuleHitsTopClientIp DescribeRuleHitsTopClientIp get
*全部资源
*
yundun-waf:CreateDefenseResourceGroup CreateDefenseResourceGroup create
*全部资源
*
yundun-waf:DescribeDefenseGroupValidResources DescribeDefenseGroupValidResources list
*全部资源
*
yundun-waf:DescribeFlowTopResource DescribeFlowTopResource get
*全部资源
*
yundun-waf:DescribeWebFingerScanStatus DescribeWebFingerScanStatus get
*全部资源
*
yundun-waf:DescribeBotRuleStatisticsInfos DescribeBotRuleStatisticsInfos get
*全部资源
*
yundun-waf:VerifyDomainOwner VerifyDomainOwner update
*全部资源
*
yundun-waf:DescribeHybridCloudSdkServers DescribeHybridCloudSdkServers get
*全部资源
*
yundun-waf:DeleteDomain DeleteDomain delete
*全部资源
*
yundun-waf:DescribeSceneAttackLogs DescribeSceneAttackLogs get
*全部资源
*
yundun-waf:DescribeDefenseResourceTemplates DescribeDefenseResourceTemplates list
*全部资源
*
yundun-waf:DescribeMigrateCloudNativeResources DescribeMigrateCloudNativeResources get
*全部资源
*
yundun-waf:TagResources TagResources create
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeApiExports DescribeApiExports get
*全部资源
*
yundun-waf:CreateHybridCloudGroup CreateHybridCloudGroup create
*全部资源
*
yundun-waf:CreateInstance CreateInstance create
*全部资源
*
yundun-waf:ClearMajorProtectionBlackIp ClearMajorProtectionBlackIp delete
*全部资源
*
yundun-waf:CreateDomainCertificates CreateDomainCertificates
*全部资源
*
yundun-waf:DescribeBaseRuleVersion DescribeBaseRuleVersion get
*全部资源
*
yundun-waf:DeleteApisecAbnormals DeleteApisecAbnormals delete
*全部资源
*
yundun-waf:ModifyTemplateResources ModifyTemplateResources update
*全部资源
*
yundun-waf:DescribeDefenseResourceNames DescribeDefenseResourceNames list
*全部资源
*
yundun-waf:ModifyApisecApiResource ModifyApisecApiResource update
*全部资源
*
yundun-waf:DescribeDomainCertificates DescribeDomainCertificates list
*全部资源
*
yundun-waf:CreatePocFunction CreatePocFunction create
*全部资源
*
yundun-waf:DescribeVisitUas DescribeVisitUas get
*全部资源
*
yundun-waf:DescribeMajorProtectionIntelligenceInfos DescribeMajorProtectionIntelligenceInfos get
*全部资源
*
yundun-waf:DescribeAclStatisticsInfo DescribeAclStatisticsInfo list
*全部资源
*
yundun-waf:DescribeBotRuleActionHitsTopClientIp DescribeBotRuleActionHitsTopClientIp get
*全部资源
*
yundun-waf:DescribeHybridCloudClusterRule DescribeHybridCloudClusterRule get
*全部资源
*
yundun-waf:DescribeUserAbnormalTrend DescribeUserAbnormalTrend get
*全部资源
*
yundun-waf:DescribeSensitiveOutboundStatistic DescribeSensitiveOutboundStatistic get
*全部资源
*
yundun-waf:DescribeProtectionModuleCodeConfig DescribeProtectionModuleCodeConfig get
*全部资源
*
yundun-waf:DescribeTemplateResourceCount DescribeTemplateResourceCount list
*全部资源
*
yundun-waf:CreateMemberAccounts CreateMemberAccounts create
*全部资源
*
yundun-waf:DescribeAssetSubDomains DescribeAssetSubDomains get
*全部资源
*
yundun-waf:DescribeDefenseRule DescribeDefenseRule get
*全部资源
*
yundun-waf:CreateSM2Cert CreateSM2Cert create
*全部资源
*
yundun-waf:DescribeDefenseResourceGroup DescribeDefenseResourceGroup get
*全部资源
*
yundun-waf:DescribeUserTraffic DescribeUserTraffic get
*全部资源
*
yundun-waf:DescribeExclusiveIpCount DescribeExclusiveIpCount get
*全部资源
*
yundun-waf:DescribeResourceInstanceCerts DescribeResourceInstanceCerts get
*全部资源
*
yundun-waf:DescribeHybridCloudProcessMonitor DescribeHybridCloudProcessMonitor get
*全部资源
*
yundun-waf:CreateDomain CreateDomain create
*全部资源
*
yundun-waf:ModifyDefenseResource ModifyDefenseResource
*全部资源
*
yundun-waf:DescribeApisecConfig DescribeApisecConfig get
*全部资源
*
yundun-waf:DescribeThreatEventSourceIpDistribute DescribeThreatEventSourceIpDistribute list
*全部资源
*
yundun-waf:DescribeBotRuleTypeGraph DescribeBotRuleTypeGraph get
*全部资源
*
yundun-waf:DescribeThreatEventAttackTypeDistribute DescribeThreatEventAttackTypeDistribute list
*全部资源
*
yundun-waf:CreateDefenseAutoRule CreateDefenseAutoRule create
*全部资源
*
yundun-waf:DescribePeakTrend DescribePeakTrend get
*全部资源
*
yundun-waf:CreateLogDeliveryConfig CreateLogDeliveryConfig create
*全部资源
*
yundun-waf:DescribeRobotHitsTopClientId DescribeRobotHitsTopClientId get
*全部资源
*
yundun-waf:ModifyMigrateDomainsGrayscale ModifyMigrateDomainsGrayscale create
*全部资源
*
yundun-waf:DescribeSceneAttackTypePv DescribeSceneAttackTypePv get
*全部资源
*
yundun-waf:DeleteHybridCloudGroup DeleteHybridCloudGroup delete
*全部资源
*
yundun-waf:ModifyElasticityWafLogStatus ModifyElasticityWafLogStatus update
*全部资源
*
yundun-waf:CreateCloudResource CreateCloudResource create
*全部资源
*
yundun-waf:ModifySlsOpenStatus ModifySlsOpenStatus
*全部资源
*
yundun-waf:DescribeAssetRootDomains DescribeAssetRootDomains get
*全部资源
*
yundun-waf:DescribeBaseRuleChangeLog DescribeBaseRuleChangeLog get
*全部资源
*
yundun-waf:ModifyHybridCloudClusterRule ModifyHybridCloudClusterRule update
*全部资源
*
yundun-waf:DescribeFreeUserAssetCount DescribeFreeUserAssetCount get
*全部资源
*
yundun-waf:DescribeBotAttackInfos DescribeBotAttackInfos get
*全部资源
*
yundun-waf:DescribeCommonLogFields DescribeCommonLogFields list
*全部资源
*
yundun-waf:DescribeApisecStatistics DescribeApisecStatistics get
*全部资源
*
yundun-waf:DescribeRule DescribeRule get
*全部资源
*
yundun-waf:ModifyHybridCloudCluster ModifyHybridCloudCluster update
*全部资源
*
yundun-waf:DescribeSlsLogStoreStatus DescribeSlsLogStoreStatus get
*全部资源
*
yundun-waf:DeleteDefenseRuleBlockIp DeleteDefenseRuleBlockIp delete
*全部资源
*
yundun-waf:DescribeApisecRules DescribeApisecRules get
*全部资源
*
yundun-waf:ModifyCloudResource ModifyCloudResource update
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeVagentCommon DescribeVagentCommon get
*全部资源
*
yundun-waf:DescribeRuleHitsTopUrl DescribeRuleHitsTopUrl get
*全部资源
*
yundun-waf:DescribeDefenseResourceOwnerUid DescribeDefenseResourceOwnerUid list
*全部资源
*
yundun-waf:DescribeInstanceForCms DescribeInstanceForCms get
*全部资源
*
yundun-waf:DescribeResourceLogFieldConfig DescribeResourceLogFieldConfig get
*全部资源
*
yundun-waf:ModifyApisecConfig ModifyApisecConfig update
*全部资源
*
yundun-waf:DescribeSensitiveOutboundTrend DescribeSensitiveOutboundTrend get
*全部资源
*
yundun-waf:DescribeDomains DescribeDomains get
*全部资源
*
yundun-waf:CreateAssetDomainExport CreateAssetDomainExport create
*全部资源
*
yundun-waf:DeleteApisecRule DeleteApisecRule delete
*全部资源
*
yundun-waf:CreateDefenseResource CreateDefenseResource create
*全部资源
*
yundun-waf:DescribeFlowChart DescribeFlowChart get
*全部资源
*
yundun-waf:ModifyApisecRule ModifyApisecRule update
*全部资源
*
yundun-waf:DescribeBotRuleActionGraph DescribeBotRuleActionGraph get
*全部资源
*
yundun-waf:CreateMigrateDomains CreateMigrateDomains create
*全部资源
*
yundun-waf:DescribePocFunctions DescribePocFunctions get
*全部资源
*
yundun-waf:DescribeSensitiveOutboundDistribution DescribeSensitiveOutboundDistribution get
*全部资源
*
yundun-waf:DescribeDefenseResources DescribeDefenseResources list
*全部资源
*
yundun-waf:ModifyResourceLogDeliveryStatus ModifyResourceLogDeliveryStatus update
*全部资源
*
yundun-waf:DescribeUserWafLogStatus DescribeUserWafLogStatus get
*全部资源
*
yundun-waf:DescribeBotProtectionTestResult DescribeBotProtectionTestResult get
*全部资源
*
yundun-waf:DescribeWebAttackTypePv DescribeWebAttackTypePv list
*全部资源
*
yundun-waf:DescribePortsBindToTgw DescribePortsBindToTgw get
*全部资源
*
yundun-waf:CreateSlsLogStore CreateSlsLogStore create
*全部资源
*
yundun-waf:DescribeSecurityEventLogs DescribeSecurityEventLogs get
*全部资源
*
yundun-waf:DescribeMemberAccounts DescribeMemberAccounts list
*全部资源
*
yundun-waf:DescribeBaseCustomRules DescribeBaseCustomRules get
*全部资源
*
yundun-waf:DescribeNotice DescribeNotice get
*全部资源
*
yundun-waf:ModifyRuleGroup ModifyRuleGroup update
*全部资源
*
yundun-waf:DescribeHybridCloudBasicMonitor DescribeHybridCloudBasicMonitor get
*全部资源
*
yundun-waf:CreateTgwBySyncResource CreateTgwBySyncResource create
*全部资源
*
yundun-waf:ModifyPrepayWafLogStatus ModifyPrepayWafLogStatus update
*全部资源
*
yundun-waf:DescribeVisitTopIp DescribeVisitTopIp get
*全部资源
*
yundun-waf:DescribeInstanceCompatible DescribeInstanceCompatible get
*全部资源
*
yundun-waf:DescribeThreatEventDetail DescribeThreatEventDetail get
*全部资源
*
yundun-waf:DescribeHybridCloudPullLuaSdk DescribeHybridCloudPullLuaSdk get
*全部资源
*
yundun-waf:InitializeWafOperationRole InitializeWafOperationRole create
*全部资源
*
yundun-waf:DescribeHybridCloudUnsupportPorts DescribeHybridCloudUnsupportPorts list
*全部资源
*
yundun-waf:ModifyDefenseRuleStatus ModifyDefenseRuleStatus update
*全部资源
*
yundun-waf:DescribeSensitiveApiStatistic DescribeSensitiveApiStatistic get
*全部资源
*
yundun-waf:ModifyMajorProtectionBlackIp ModifyMajorProtectionBlackIp update
*全部资源
*
yundun-waf:DescribeBlockRequestInfo DescribeBlockRequestInfo get
*全部资源
*
yundun-waf:CreateBotProtectionTest CreateBotProtectionTest create
*全部资源
*
yundun-waf:RollbackMigrateCloudNativeResource RollbackMigrateCloudNativeResource create
*全部资源
*
yundun-waf:DescribeHybridCloudPullClusterSdkRule DescribeHybridCloudPullClusterSdkRule get
*全部资源
*
yundun-waf:DescribeApisecProtectionResources DescribeApisecProtectionResources list
*全部资源
*
yundun-waf:DescribeResourceLogStatus DescribeResourceLogStatus get
*全部资源
*
yundun-waf:DescribeHybridCloudUser DescribeHybridCloudUser get
*全部资源
*
yundun-waf:DescribeMultiCloudPullLogDockingConfig DescribeMultiCloudPullLogDockingConfig get
*全部资源
*
yundun-waf:ChangeResourceGroup ChangeResourceGroup update
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeMigrateTask DescribeMigrateTask get
*全部资源
*
yundun-waf:ModifyDefenseRuleCache ModifyDefenseRuleCache update
*全部资源
*
yundun-waf:DescribeApisecDefenseRules DescribeApisecDefenseRules get
*全部资源
*
yundun-waf:DescribeCerts DescribeCerts get
*全部资源
*
yundun-waf:DescribeApisecEvents DescribeApisecEvents get
*全部资源
*
yundun-waf:ModifyApisecLogDeliveryStatus ModifyApisecLogDeliveryStatus update
*全部资源
*
yundun-waf:SyncProductInstance SyncProductInstance create
*全部资源
*
yundun-waf:DescribeVerifyContent DescribeVerifyContent get
*全部资源
*
yundun-waf:DescribeMigrateBeforeAfter DescribeMigrateBeforeAfter get
*全部资源
*
yundun-waf:DeleteDefenseResourceGroup DeleteDefenseResourceGroup delete
*全部资源
*
yundun-waf:DescribeMajorProtectionOverview DescribeMajorProtectionOverview get
*全部资源
*
yundun-waf:DescribeHybridCloudClusters DescribeHybridCloudClusters get
*全部资源
*
yundun-waf:DescribeCertDetail DescribeCertDetail get
*全部资源
*
yundun-waf:DescribeWebAttackLogs DescribeWebAttackLogs list
*全部资源
*
yundun-waf:ModifyCustomBaseRule ModifyCustomBaseRule update
*全部资源
*
yundun-waf:ModifyDefaultHttps ModifyDefaultHttps update
*全部资源
*
yundun-waf:UploadMajorProtectionBlackIp UploadMajorProtectionBlackIp create
*全部资源
*
yundun-waf:DescribeHybridCloudResourceDetail DescribeHybridCloudResourceDetail get
*全部资源
*
yundun-waf:DescribeFlowTopUrl DescribeFlowTopUrl get
*全部资源
*
yundun-waf:DescribeDefenseScenes DescribeDefenseScenes list
*全部资源
*
yundun-waf:CreateCustomAssetDomain CreateCustomAssetDomain create
*全部资源
*
yundun-waf:DescribeApisecMatchedHosts DescribeApisecMatchedHosts get
*全部资源
*
yundun-waf:DescribeRuleHitsTopUa DescribeRuleHitsTopUa get
*全部资源
*
yundun-waf:DescribeMigrateDomains DescribeMigrateDomains get
*全部资源
*
yundun-waf:DescribeLogDeliveryConfig DescribeLogDeliveryConfig get
*全部资源
*
yundun-waf:DescribeBotAppKey DescribeBotAppKey get
*全部资源
*
yundun-waf:ModifyRulesInGroup ModifyRulesInGroup update
*全部资源
*
yundun-waf:DescribeTgwAccessedPorts DescribeTgwAccessedPorts get
*全部资源
*
yundun-waf:DeleteDefenseTemplate DeleteDefenseTemplate delete
*全部资源
*
yundun-waf:DeleteBotProtectionTest DeleteBotProtectionTest delete
*全部资源
*
yundun-waf:ModifyHybridCloudSdkPullinStatus ModifyHybridCloudSdkPullinStatus update
*全部资源
*
yundun-waf:RollbackMigrateTask RollbackMigrateTask update
*全部资源
*
yundun-waf:ModifyDefenseTemplateStatus ModifyDefenseTemplateStatus update
*全部资源
*
yundun-waf:DescribeApisecSlsProjects DescribeApisecSlsProjects get
*全部资源
*
yundun-waf:DescribeAntiscanStatisticsInfo DescribeAntiscanStatisticsInfo list
*全部资源
*
yundun-waf:ModifyDomain ModifyDomain update
*全部资源
*
yundun-waf:DescribeAssetDomainExports DescribeAssetDomainExports get
*全部资源
*
yundun-waf:DescribeBaseSystemRules DescribeBaseSystemRules get
*全部资源
*
yundun-waf:ListTagKeys ListTagKeys list
*全部资源
*
yundun-waf:CopyRuleGroup CopyRuleGroup create
*全部资源
*
yundun-waf:DescribeThreatEventAttackTimeDistribute DescribeThreatEventAttackTimeDistribute list
*全部资源
*
yundun-waf:ModifyApisecLogDelivery ModifyApisecLogDelivery update
*全部资源
*
yundun-waf:DescribeNetworkFlowTimeSeriesMetric DescribeNetworkFlowTimeSeriesMetric get
*全部资源
*
yundun-waf:DescribeSlsAuthStatus DescribeSlsAuthStatus get
*全部资源
*
yundun-waf:CreateDefenseTemplate CreateDefenseTemplate create
*全部资源
*
yundun-waf:ModifyHybridCloudClusterBypassStatus ModifyHybridCloudClusterBypassStatus update
*全部资源
*
yundun-waf:DescribeSlbAttackCount DescribeSlbAttackCount get
*全部资源
*
yundun-waf:CreatePostpaidInstance CreatePostpaidInstance create
*全部资源
*
yundun-waf:DescribeDefenseTemplate DescribeDefenseTemplate get
*全部资源
*
yundun-waf:ModifyDomainPunishStatus ModifyDomainPunishStatus update
*全部资源
*
yundun-waf:CreateRuleGroup CreateRuleGroup create
*全部资源
*
yundun-waf:CreateMigratePreCheck CreateMigratePreCheck create
*全部资源
*
yundun-waf:DescribeHybridCloudPullPostXagentRule DescribeHybridCloudPullPostXagentRule get
*全部资源
*
yundun-waf:DescribeDefenseRules DescribeDefenseRules list
*全部资源
*
yundun-waf:DescribeDefenseTemplates DescribeDefenseTemplates list
*全部资源
*
yundun-waf:DescribeHybridCloudSupportRegions DescribeHybridCloudSupportRegions get
*全部资源
*
yundun-waf:DescribeWebRegionPv DescribeWebRegionPv list
*全部资源
*
yundun-waf:DescribeNotices DescribeNotices list
*全部资源
*
yundun-waf:RefreshMigrateCloudNativeResources RefreshMigrateCloudNativeResources create
*全部资源
*
yundun-waf:ListTagResources ListTagResources get
*全部资源
*
yundun-waf:DescribeInstanceExtend DescribeInstanceExtend get
*全部资源
*
yundun-waf:CreateMajorProtectionBlackIp CreateMajorProtectionBlackIp create
*全部资源
*
yundun-waf:ModifyApisecAbnormals ModifyApisecAbnormals update
*全部资源
*
yundun-waf:DescribeRobotStatisticsInfos DescribeRobotStatisticsInfos list
*全部资源
*
yundun-waf:DescribeSceneDefenseRules DescribeSceneDefenseRules get
*全部资源
*
yundun-waf:DescribeRuleGroupAssociatedTemplates DescribeRuleGroupAssociatedTemplates get
*全部资源
*
yundun-waf:DescribeSensitiveStatistic DescribeSensitiveStatistic get
*全部资源
*
yundun-waf:DescribeHybridCloudClusterServers DescribeHybridCloudClusterServers get
*全部资源
*
yundun-waf:DescribeDefenseTemplateValidResources DescribeDefenseTemplateValidResources list
*全部资源
*
yundun-waf:ModifyApisecStatus ModifyApisecStatus update
*全部资源
*
yundun-waf:DescribeAttackTypeSummary DescribeAttackTypeSummary get
*全部资源
*
yundun-waf:DescribeUserDomainVerifyWhitelist DescribeUserDomainVerifyWhitelist get
*全部资源
*
yundun-waf:DeleteTgw DeleteTgw delete
*全部资源
*
yundun-waf:DescribeDefenseTemplateValidGroups DescribeDefenseTemplateValidGroups list
*全部资源
*
yundun-waf:DescribeHybridCloudLogDockingConfig DescribeHybridCloudLogDockingConfig get
*全部资源
*
yundun-waf:DeleteCloudResource DeleteCloudResource delete
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeDefenseResourceGroups DescribeDefenseResourceGroups list
*全部资源
*
yundun-waf:CreateHybridCloudCluster CreateHybridCloudCluster create
*全部资源
*
yundun-waf:DescribeInstance DescribeInstance get
*全部资源
*
yundun-waf:DescribeApisecAbnormals DescribeApisecAbnormals get
*全部资源
*
yundun-waf:DescribeRuleHitsTopRuleId DescribeRuleHitsTopRuleId get
*全部资源
*
yundun-waf:DescribeThreatEvent DescribeThreatEvent list
*全部资源
*
yundun-waf:CreateCerts CreateCerts create
*全部资源
*
yundun-waf:ModifyTgwDomainBindingProduct ModifyTgwDomainBindingProduct update
*全部资源
*
yundun-waf:UntagResources UntagResources delete
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeSensitiveDetectionResult DescribeSensitiveDetectionResult get
*全部资源
*
yundun-waf:DescribeDefenseResource DescribeDefenseResource get
*DefenseResource
acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
yundun-waf:DescribeApisecAssetTrend DescribeApisecAssetTrend get
*全部资源
*
yundun-waf:ModifyDefenseRule ModifyDefenseRule update
*全部资源
*

资源(Resource)

下表是Web应用防火墙定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

DefenseResource acs:yundun-waf:{#regionId}:{#accountId}:defenseresource/{#Resource}
Instance acs:yundun-waf::{#accountId}:instance/{#InstanceId}
Domain acs:yundun-waf:{#regionId}:{#accountId}:domain/{#Domain}
HybridCloudGroup acs:yundun-waf:{#regionId}:{#accountId}:hybridcloudgroup/*
Instance acs:yundun-waf:{#regionId}:{#accountId}:instance/{#InstanceId}
DefenseResource acs:yundun-waf:{#regionId}:{#accountId}:instance/{InstanceId}/defenseresource/{#Resource}
HybridCloudCluster acs:yundun-waf:{#regionId}:{#accountId}:hybridcloudcluster/{#HybridCloudClusterId}
Instance acs:yundun-waf:{#regionId}:{#accountId}:Instance/*

条件(Condition)

Web应用防火墙未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: