开发者社区> 问答> 正文

授权访问鉴权规则是什么

当子用户通过RDS Open API进行资源访问时,RDS后台向RAM进行权限检查,以确保调用者拥有响应权限。 每个不同的RDS API会根据涉及到的资源以及API的语义来确定需要检查哪些资源的权限。具体地,每个API的鉴权规则见下表

Action鉴权规则
CreateDBInstanceacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DeleteDBInstanceacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeDBInstancesacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
SwitchDBInstanceNetTypeacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyDBInstanceDescriptionacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyDBInstanceMaintainTimeacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
PurgeDBInstanceLogacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DeleteDatabaseacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyDBDescriptionacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeFilesForSQLServeracs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeImportsForSQLServeracs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CancelImportacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ResetAccountPasswordacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
RevokeAccountPrivilegeacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DeleteAccountacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreateBackupacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreateTempDBInstanceacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyBackupPolicyacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeDBInstancePerformanceacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeSlowLogRecordsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeBinlogFilesacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeSQLLogRecordsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeOptimizeAdviceOnMissPKacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeOptimizeAdviceOnMissIndexacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeParametersacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreatePrepaidDBInstanceForChannelacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyPrepaidDBInstanceSpecacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreatePostpaidDBInstanceForChannelacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyPostpaidDBInstanceSpecacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeDBInstanceAttributeacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
RestartDBInstanceacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifySecurityIpsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
UpgradeDBInstanceEngineVersionacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreateDatabaseacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeDatabasesacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreateUploadPathForSQLServeracs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ImportDataForSQLServeracs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ImportDataBaseBetweenInstancesacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
CreateAccountacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
GrantAccountPrivilegeacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeAccountsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyAccountDescriptionacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeBackupsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeBackupPolicyacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeResourceUsageacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeSlowLogsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeErrorLogsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeSQLLogReportsacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeOptimizeAdviceOnStorageacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeOptimizeAdviceOnExcessIndexacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
DescribeOptimizeAdviceByDBAacs:rds:$regionid:$accountid:dbinstance/$dbinstanceid
ModifyeParameteracs:rds:$regionid:$accountid:dbinstance/$dbinstanceid

展开
收起
云栖大讲堂 2017-10-19 13:48:37 1911 0
0 条回答
写回答
取消 提交回答
问答排行榜
最热
最新

相关电子书

更多
《用管控策略设定多账号组织全局访问边界》 立即下载
低代码开发师(初级)实战教程 立即下载
阿里巴巴DevOps 最佳实践手册 立即下载