Список стандартных ролей и политик

Policy/Role Name

Type

Description

System-defined policy

All permissions of Application Operations Monitor service

System-defined policy

The read-only permissions to Application Operations Monitor service

System-defined policy

APIG Administrator

System-defined policy

All permissions for API Gateway

System-defined policy

Read-only permissions for viewing API Gateway

System-defined policy

All permissions of Application Performance Monitor service.

System-defined role

Application Performance Monitor Administrator

System-defined policy

The read-only permissions to Application Performance Monitor service

System-defined role

Permissions for switching roles to access services of a delegating account

System-defined policy

All permissions template of AutoScaling Service

System-defined role

AutoScaling Administrator

System-defined policy

Full permissions for Auto Scaling

System-defined policy

The read-only permissions to all AutoScaling resources, which can be used for statistics and survey

System-defined policy

All permissions of BMS service

System-defined policy

Permissions for basic BMS operations, such as starting, stopping, restarting a BMS, querying BMS details, and attaching data disks to or detaching data disks from a BMS

System-defined policy

All permissions of BMS service

System-defined policy

The read-only permissions to all BMS resources, which can be used for statistics and survey.

System-defined policy

Common permissions of BMS service, except installation, delete, reinstallation and so on.

System-defined policy

The read-only permissions to all BMS resources, which can be used for statistics and survey

System-defined policy

All permissions for all CBH instances

System-defined policy

Read-only permissions for CBH instances. Users granted with read-only permissions can only view but not configure the CBH service

System-defined policy

All permissions of Cloud Backup and Recovery service

System-defined policy

General permissions of Cloud Backup and Recovery service (exclude policy create, update, and delete permission)

System-defined policy

The read-only permissions to all Cloud Backup and Recovery resources

System-defined role

CCE Administrator

System-defined policy

Common operation permissions on CCE cluster resources, excluding the namespace-level permissions for the clusters (with Kubernetes RBAC enabled) and the privileged administrator operations, such as agency configuration and cluster certificate generation

System-defined policy

Permissions to view CCE cluster resources, excluding the namespace-level permissions of the clusters (with Kubernetes RBAC enabled)

System-defined policy

Operation permissions on Cloud Data Migration jobs and links

System-defined policy

All permissions on Cloud Data Migration

System-defined policy

All permissions on Cloud Data Migration except elastic IP address binding and unbinding

System-defined policy

Read-only permission on Cloud Data Migration

System-defined policy

All permissions of Cloud Eye service

System-defined role

CloudEye Service Administrator

System-defined policy

The read-only permissions to all Cloud Eye service

System-defined policy

Full permissions of Container Guard Service

System-defined policy

Read-only permissions for Container Guard Service

System-defined policy

All permissions of CSE service

System-defined policy

The read-only permissions to all CSE resources

System-defined role

Cloud Search Service Administrator

System-defined policy

All permissions for Cloud Search Service

System-defined policy

Read-only permissions for viewing Cloud Search Service

System-defined role

CloudTrace Service Administrator

System-defined policy

Full permissions for Cloud Trace Service

System-defined policy

Read-only permissions for Cloud Trace Service

System-defined policy

Full permissions for Data Admin Service

System-defined role

DAYU Administrator

System-defined role

DAYU User

System-defined policy

Full permissions for Database Security Service

System-defined policy

Read-only permissions for Database Security Service

System-defined policy

All permissions of DCS service

System-defined role

Distributed Cache Service Administrator

System-defined policy

Permissions to assign to DCS agencies

System-defined policy

All permissions for Distributed Cache Service

System-defined policy

Read-only permissions for Distributed Cache Service

System-defined policy

Common permissions of DCS service, except create, modify, delete and scale-up

System-defined policy

Common permissions of DCS service, except create, modify, delete and scale-up

System-defined policy

The read-only permissions to all DCS resources, which can be used for statistics and survey

System-defined policy

Common user permissions for DDM, except for permissions of creating, deleting, and scaling out DDM instances, scaling out schemas, rolling back schema scaling tasks, and changing instance class

System-defined policy

Full permissions for Distributed Database Middleware

System-defined policy

Read-only permissions for Distributed Database Middleware

System-defined policy

Full permissions for Document Database Service

System-defined policy

All permissions of DDS service

System-defined role

Document Database Service Administrator

System-defined policy

DBA permissions of DDS service, except delete

System-defined policy

Full permissions for Document Database Service

System-defined policy

Database administrator permissions for all operations except deleting DDS resources

System-defined policy

Read-only permissions for Document Database Service

System-defined policy

Read-only permissions for Document Database Service

System-defined role

All permissions for Data Lake Insight

System-defined role

Users who were granted this permission can view the queue list, table structure, and create packages and package groups

System-defined policy

All permissions of Distributed Message Service

System-defined role

Administrator to control DMS API access

System-defined role

Administrator to control DMS API access

System-defined policy

Common permissions of Distributed Message Service, except install, modify, delete and so on

System-defined policy

The read-only permissions to all Distributed Message Service resources

System-defined policy

DNS administrator permissions, which allow users to perform all operations, including creating, deleting, querying, and modifying DNS resources

System-defined role

DNS Administrator

System-defined policy

Read-only permissions, which only allow users to query DNS resources

System-defined policy

Full permissions for Data Replication Service

System-defined policy

Read-only permissions for Data Replication Service

System-defined policy

All permissions of DWS service

System-defined policy

The read-only permissions to all DWS resources

System-defined role

Direct Connect Administrator

System-defined policy

All permissions of ECS service

System-defined policy

Common permissions of ECS service, except installation, delete, reinstallation and so on

System-defined policy

The read-only permissions to all ECS resources, which can be used for statistics and survey

System-defined policy

All permissions of ELB service

System-defined role

ELB Service Administrator

System-defined policy

The read-only permissions to all ELB resources, which can be used for statistics and survey

System-defined policy

All permissions of EVS service

System-defined policy

The read-only permissions to all EVS resources, which can be used for statistics and survey

System-defined role

Elasticsearch Administrator

System-defined policy

All permissions of all services

System-defined policy

Common operations for functiongraph service, include query and invoke function

System-defined policy

All permissions of FunctionGraph service

System-defined policy

The read-only permissions to all functiongraph resources

System-defined policy

Usage permissions for Graph Engine Service

System-defined policy

Full permissions for Graph Engine Service

System-defined policy

Read-only permissions for Graph Engine Service

System-defined role

Full permissions for Host Security Service

System-defined policy

All permissions of Host Security Service

System-defined policy

Read-only permission for Host Security Service

System-defined policy

Read-only permissions for Identity and Access Management

System-defined policy

All permissions of Image Management Service

System-defined role

IMS Administrator

System-defined policy

The read-only permissions to all IMS resources, which can be used for statistics and survey

System-defined role

KMS Administrator

System-defined policy

All permissions for custom keys in Key Management Service

System-defined policy

All permissions of Log Tank service

System-defined policy

The read-only permissions to all Log Tank service resources

System-defined policy

MapReduce all permissions for the service

System-defined role

MRS Administrator

System-defined policy

MapReduce Service Usage Permissions

System-defined policy

MapReduce Service read-only permissions

System-defined policy

Common permissions of ModelArts service,except create,update,delete pool

System-defined policy

All permissions of ModelArts service

System-defined policy

All permissions of NAT Gateway service

System-defined role

NAT Gateway Administrator

System-defined policy

The read-only permissions to all NAT Gateway resources

System-defined policy

Object Storage Service Administrator

System-defined role

Permissions to view the bucket list, obtain bucket metadata, and query bucket location

System-defined policy

Basic operation permissions to view the bucket list, obtain bucket metadata, list objects in a bucket, query bucket location, upload objects, download objects, delete objects, and obtain object ACLs

System-defined policy

Permissions to view the bucket list, obtain bucket metadata, list objects in a bucket, and query bucket location

System-defined policy

All permissions of RDS service

System-defined role

RDS Administrator

System-defined policy

DBA permissions of RDS service, except delete

System-defined policy

Full permissions for Relational Database Service

System-defined policy

Database administrator permissions for all operations except deleting RDS resources

System-defined policy

Read-only permissions for Relational Database Service

System-defined policy

The read-only permissions to all RDS resources, which can be used for statistics and survey

System-defined policy

Full permissions for Resource Management Service

System-defined policy

Read-only permissions for Resource Management Service

System-defined policy

All permissions of Scalable File Service

System-defined role

SFS Administrator

System-defined policy

All permissions of Scalable File Service (SFS Turbo)

System-defined policy

The read-only permissions to all Scalable File Service (SFS Turbo) resources

System-defined policy

The read-only permissions to all Scalable File Service resources

System-defined role

SMN Administrator

System-defined policy

Full permissions for the Simple Message Notification service

System-defined policy

Read-only access to the Simple Message Notification service

System-defined policy

Full permissions for Server Migration Service

System-defined policy

Read-only permissions Server Migration Service

System-defined role

Software Repository Administrator

System-defined role

Full permissions for Identity and Access Management. This role does not have permissions for switching roles

System-defined role

Server Administrator

System-defined policy

All permissions of ServiceStage service

System-defined role

ServiceStage administrator, who has full permissions for this service

System-defined policy

Developer permissions of ServiceStage service(exclude review and approve)

System-defined policy

The read-only permissions to all ServiceStage resources

System-defined role

Tag Management Service Administrator

System-defined role

Tenant Administrator (Exclude IAM)

System-defined role

Tenant Guest (Exclude IAM)

System-defined policy

All permissions of VPC service

System-defined role

Project-level services

System-defined policy

The read-only permissions to all VPC resources, which can be used for statistics and survey

System-defined role

VPCEndpoint service enables you to privately connect your VPC to supported services

System-defined role

Virtual Private Network Administrator

System-defined role

Web application firewall service administrator of instance and policy

System-defined policy

All permissions of waf service

System-defined policy

The read-only permissions to all Web application firewall resources, which can be used for statistics and survey

Advanced