在您第一次使用DTS时,需要您将名称为AliyunDTSDefaultRole的默认角色授权给DTS使用。经过授权后,DTS可访问当前云账号下的RDS、ECS等云资源,在执行数据迁移、同步或订阅任务的配置时可调用相关云资源信息。
注意事项
如果使用主账号登录数据传输控制台后,没有弹出提示授权的对话框,说明当前主账号已执行过授权,可跳过本文的操作。
权限策略说明
AliyunDTSDefaultRole权限策略是DTS服务默认角色的授权策略,包含RDS、ECS、PolarDB、MongoDB、Redis、PolarDB-X 云原生分布式数据库(原)、DataHub、Elasticsearch等云资源的部分管理权限,具体权限定义如下。
{ "Version": "1", "Statement": [ { "Action": [ "rds:Describe*", "rds:CreateDBInstance", "rds:CreateAccount*", "rds:CreateDataBase*", "rds:ModifySecurityIps", "rds:GrantAccountPrivilege" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "ecs:DescribeSecurityGroupAttribute", "ecs:DescribeInstances", "ecs:DescribeRegions", "ecs:AuthorizeSecurityGroup" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "dhs:ListProject", "dhs:GetProject", "dhs:CreateTopic", "dhs:ListTopic", "dhs:GetTopic", "dhs:UpdateTopic", "dhs:ListShard", "dhs:MergeShard", "dhs:SplitShard", "dhs:PutRecords", "dhs:GetRecords", "dhs:GetCursors" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "elasticsearch:DescribeInstance", "elasticsearch:ListInstance", "elasticsearch:UpdateAdminPwd", "elasticsearch:UpdatePublicNetwork", "elasticsearch:UpdateBlackIps", "elasticsearch:UpdateKibanaIps", "elasticsearch:UpdatePublicIps", "elasticsearch:UpdateWhiteIps" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "drds:DescribeDrds*", "drds:ModifyDrdsIpWhiteList", "drds:DescribeRegions", "drds:DescribeRdsList", "drds:CeateDrdsDB", "drds:DescribeShardDBs" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "polardb:DescribeDBClusterIPArrayList", "polardb:DescribeDBClusterNetInfo", "polardb:DescribeDBClusters", "polardb:DescribeRegions", "polardb:ModifySecurityIps" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "dds:DescribeDBInstanceAttribute", "dds:DescribeReplicaSetRole", "dds:DescribeSecurityIps", "dds:DescribeDBInstances", "dds:ModifySecurityIps", "dds:DescribeRegions" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "kvstore:DescribeSecurityIps", "kvstore:DescribeInstances", "kvstore:DescribeRegions", "kvstore:ModifySecurityIps" ], "Resource": "*", "Effect": "Allow" }, { "Action": [ "petadata:DescribeInstanceInfo", "petadata:DescribeSecurityIPs", "petadata:DescribeInstances", "petadata:ModifySecurityIPs" ], "Resource": "*", "Effect": "Allow" } ] }
说明 更多关于权限策略的介绍,请参见
权限策略语法和结构。