RDS 标签授权
{
"Statement": [
{
"Action": "rds:*",
"Effect": "Allow",
"Resource": "*",
"Condition": {
"StringEquals": {
"rds:ResourceTag/team": "dev"
}
}
},
{
"Action": "rds:DescribeTag*",
"Effect": "Allow",
"Resource": "*"
}
],
"Version": "1"
}
下载备份的权限
{
"Version": "1",
"Statement": [
{
"Effect": "Allow",
"Action": [
"rds:ModifyBackupPolicy"
],
"Resource": [
"*"
],
"Condition": {}
}
]
}
RDS修改白名单权限
{
"Statement": [
{
"Action": "rds:ModifySecurityIps",
"Effect": "Allow",
"Resource": [
"*"
]
},
{
"Action": "rds:Describe*",
"Effect": "Allow",
"Resource": "*"
}
],
"Version": "1"
}
cloudDBA相关的接口不支持标签授权。可通过单独授权的方式把这相关操作的权限加上。策略示例如下: 注意使用的时候要把“$InstanceId”换成实际的实例Id
{
"Version": "1",
"Statement": [
{
"Action": [
"rds:DescribeCloudDBAService",
"rds:DescribeDiagnosticReportList",
"rds:DescribeResourceDiagnosis",
"rds:DescribeSQLDiagnosisList"
],
"Resource": "acs:rds:*:*:*/$InstanceID",
"Effect": "Allow"
}
]
}