Authorized ECS resource types in RAM
Currently, the types of resources that you can authorize in RAM and how they are described are shown in the following table:
Resource description in the
Resource type |
authorization policy |
instance |
acs:ecs: $regionid: $accountid: instance/$instanceid acs:ecs:$ RegionID: $accountid: instance/* acs:ecs:*: $accountid: instance/* |
disk |
acs:ecs: $regionid: $accountid:d isk/$diskid Acs:ecs: $regionid: $ accountid:disk/* acs:ecs:*: $accountid:d isk/* |
snapshot |
acs:ecs: $regionid: $accountid: snapshot/$snapshotid Acs:ecs: $regionid: $ accountid:snapshot/* acs:ecs:*: $accountid: snapshot/* |
imag E |
acs:ecs: $regionid: $accountid: image/$imageid Acs:ecs: $regionid: $ accountid:image/* acs:ecs:*: $accountid: IMage/* |
securitygroup |
acs:ecs: $regionid: $accountid: securitygroup/$securitygroupid Acs:ecs: $regionid: $accountid: securitygroup/* acs:ecs:*: $accountid: securitygroup/* |
special generic expression |
acs:ecs: $regionid: $ accountid:* acs:ecs:*: $accountid:* |
Where: All $regionid should be the ID of a region, or "*"; all $instanceid should be the ID of a instance, or "*";