閱讀554 返回首頁    go 阿裏雲


高速通道相關API的鑒權規則__借助RAM實現子賬號對主賬號資源訪問_API使用手冊_高速通道-阿裏雲

當子賬號通過Open API 對主賬號的高速通道資源進行訪問時,高速通道後台向 RAM 進行權限檢查,以確保資源擁有者的確將相關資源的相關權限授予了調用者。

每個不同的Open API 會根據涉及到的資源以及 API 的語義來確定需要檢查哪些資源的權限。具體地,每個 API 的鑒權規則見下表:

Action Resource Condition
vpc:DescribeAccessPoints acs:vpc:*:$accountid:*
vpc:CreatePhysicalConnection acs:vpc:$regionid:$accountid:physicalconnection/*
vpc:DescribePhysicalConnections acs:vpc:$regionid:$accountid:physicalconnection/*
vpc:ModifyPhysicalConnectionAttribute acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid
vpc:EnablePhysicalConnection acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid
vpc:CancelPhysicalConnection acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid
vpc:TerminatePhysicalConnection acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid
vpc:DeletePhysicalConnection acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid
vpc:CreateVirtualBorderRouter acs:vpc:$regionid:$accountid:virtualborderrouter/*
acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid
vpc:DescribeVirtualBorderRouters acs:vpc:$regionid:$accountid:virtualborderrouter/*
vpc:ModifyVirtualBorderRouterAttribute acs:vpc:$regionid:$accountid:virtualborderrouter/$virtualborderrouterid
vpc:DeleteVirtualBorderRouter acs:vpc:$regionid:$accountid:virtualborderrouter/$virtualborderrouterid
vpc:DescribeVirtualBorderRoutersForPhysicalConnection acs:vpc:$regionid:$accountid:virtualborderrouter/* “vpd:PhysicalConnection”:”acs:vpc:$regionid:$accountid:physicalconnection/$physicalconnectionid”
vpc:TerminateVirtualBorderRouter acs:vpc:$regionid:$accountid:virtualborderrouter/$virtualborderrouterid
vpc:RecoverVirtualBorderRouter acs:vpc:$regionid:$accountid:virtualborderrouter/$virtualborderrouterid
vpc:CreateRouteEntry acs:vpc:$regionid:$accountid:routertable/$routertableid
vpc:DescribeRouteTables acs:vpc:$regionid:$accountid:routertable/* VRouter中的路由表:
“vpc:VRouter”:”acs:vpc$regionid:$accountid:vrouter/$vrouterid”
VirtualBorderRouter中的路由表:
“vpc:VirtualBorderRouter”:”acs:vpc:$regionid:$accountid:virtualborderrouter/$virtualborderrouterid”
vpc:DeleteRouteEntry acs:vpc:$regionid:$accountid:routertable/$routertableid
vpc:CreateRouterInterface 所屬路由器RouterType為VRouter:
acs:vpc:$regionid:$accountid:routerinterface/*
acs:vpc:$regionid:$accountid:vrouter/$vrouterid
所屬路由器RouterType為VirtualBorderRouter:
acs:vpc:$regionid:$accountid:routerinterface/*
acs:vpc:$regionid:$accountid:virtualborderrouter/$virtualborderrouterid
vpc:ConnectRouterInterface acs:vpc:$regionid:$accountid:routerinterface/$routerinterfaceid
vpc:DescribeRouterInterfaces acs:vpc:$regionid:$accountid:routerinterface/*
vpc:DeactivateRouterInterface acs:vpc:$regionid:$accountid:routerinterface/$routerinterfaceid
vpc:ActivateRouterInterface acs:vpc:$regionid:$accountid:routerinterface/$routerinterfaceid
vpc:ModifyRouterInterfaceAttribute acs:vpc:$regionid:$accountid:routerinterface/$routerinterfaceid
vpc:ModifyRouterInterfaceSpec acs:vpc:$regionid:$accountid:routerinterface/$routerinterfaceid
vpc:DeleteRouterInterface acs:vpc:$regionid:$accountid:routerinterface/$routerinterfaceid

最後更新:2016-11-23 17:16:07

  上一篇:go RAM中可對高速通道資源進行授權的Action__借助RAM實現子賬號對主賬號資源訪問_API使用手冊_高速通道-阿裏雲
  下一篇:go 曆史發展__產品簡介_加密服務-阿裏雲