帮助文档 Logo
平台使用
阿里云
百度云
移动云
智算服务
教育生态
登录 →
帮助文档 Logo
平台使用 阿里云 百度云 移动云 智算服务 教育生态
登录
  1. 首页
  2. 阿里云
  3. 容器服务 Kubernetes 版 ACK
  4. 产品概述
  5. 动态与公告
  6. 产品变更
  7. 【产品变更】专有版集群节点RAM角色权限收敛公告

【产品变更】专有版集群节点RAM角色权限收敛公告

  • 产品变更
  • 发布于 2025-04-18
  • 0 次阅读
文档编辑
文档编辑

由于专有版集群节点默认绑定的ECS RAM角色权限较大,为了加强专有版集群的默认安全性,容器服务ACK将对新建的专有版集群进一步收敛RAM角色的绑定权限。

变更影响

  • 该变更只影响新创建的ACK专有版集群节点的默认权限,不影响托管版集群、ACK Serverless集群等其他类型的集群。

  • 该变更不会影响存量ACK专有版集群节点的默认权限。如需收敛存量ACK专有版集群节点的角色绑定权限,请修改指定存量集群对应的节点角色的权限策略内容,更多最小化权限策略内容,请参见Master节点绑定角色权限和Worker节点绑定角色权限。

    重要

    修改存量ACK专有版集群的权限前,请确保集群节点上运行的组件没有依赖待删除的权限。如果存在,请不要实施变更,修改前请您备份原有权限模板策略内容,便于及时回滚权限配置。

Master节点绑定角色权限

专有版集群Master节点的RAM角色权限收敛后,默认绑定了CCM、CSI存储、网络和日志组件所需的最小化权限策略。

  • CCM组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "ecs:Describe*",
                    "ecs:CreateRouteEntry",
                    "ecs:DeleteRouteEntry",
                    "ecs:CreateNetworkInterface",
                    "ecs:DeleteNetworkInterface",
                    "ecs:CreateNetworkInterfacePermission",
                    "ecs:DeleteNetworkInterfacePermission",
                    "ecs:ModifyInstanceAttribute",
                    "ecs:AttachKeyPair",
                    "ecs:StopInstance",
                    "ecs:StartInstance",
                    "ecs:ReplaceSystemDisk"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            },
            {
                "Action": [
                    "slb:Describe*",
                    "slb:CreateLoadBalancer",
                    "slb:DeleteLoadBalancer",
                    "slb:ModifyLoadBalancerInternetSpec",
                    "slb:RemoveBackendServers",
                    "slb:AddBackendServers",
                    "slb:RemoveTags",
                    "slb:AddTags",
                    "slb:StopLoadBalancerListener",
                    "slb:StartLoadBalancerListener",
                    "slb:SetLoadBalancerHTTPListenerAttribute",
                    "slb:SetLoadBalancerHTTPSListenerAttribute",
                    "slb:SetLoadBalancerTCPListenerAttribute",
                    "slb:SetLoadBalancerUDPListenerAttribute",
                    "slb:CreateLoadBalancerHTTPSListener",
                    "slb:CreateLoadBalancerHTTPListener",
                    "slb:CreateLoadBalancerTCPListener",
                    "slb:CreateLoadBalancerUDPListener",
                    "slb:DeleteLoadBalancerListener",
                    "slb:CreateVServerGroup",
                    "slb:DescribeVServerGroups",
                    "slb:DeleteVServerGroup",
                    "slb:SetVServerGroupAttribute",
                    "slb:DescribeVServerGroupAttribute",
                    "slb:ModifyVServerGroupBackendServers",
                    "slb:AddVServerGroupBackendServers",
                    "slb:ModifyLoadBalancerInstanceSpec",
                    "slb:ModifyLoadBalancerInternetSpec",
                    "slb:SetLoadBalancerModificationProtection",
                    "slb:SetLoadBalancerDeleteProtection",
                    "slb:SetLoadBalancerName",
                    "slb:ModifyLoadBalancerInstanceChargeType",
                    "slb:RemoveVServerGroupBackendServers"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            },
            {
                "Action": [
                    "vpc:Describe*",
                    "vpc:DeleteRouteEntry",
                    "vpc:CreateRouteEntry"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }
  • CSI存储组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "ecs:DescribeDisks",
                    "ecs:DescribeInstances",
                    "ecs:DescribeAvailableResource",
                    "ecs:DescribeInstanceTypes",
                    "nas:DescribeFileSystems",
                    "ecs:AttachDisk",
                    "ecs:CreateDisk",
                    "ecs:CreateSnapshot",
                    "ecs:DeleteDisk",
                    "ecs:DeleteSnapshot",
                    "ecs:DetachDisk"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }
  • 网络组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "ecs:CreateNetworkInterface",
                    "ecs:DescribeNetworkInterfaces",
                    "ecs:AttachNetworkInterface",
                    "ecs:DetachNetworkInterface",
                    "ecs:DeleteNetworkInterface",
                    "ecs:DescribeInstanceAttribute",
                    "ecs:DescribeInstanceTypes",
                    "ecs:AssignPrivateIpAddresses",
                    "ecs:UnassignPrivateIpAddresses",
                    "ecs:DescribeInstances",
                    "ecs:ModifyNetworkInterfaceAttribute"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            },
            {
                "Action": [
                    "vpc:DescribeVSwitches"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }
  • 日志组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "log:CreateProject",
                    "log:GetProject",
                    "log:DeleteProject",
                    "log:CreateLogStore",
                    "log:GetLogStore",
                    "log:UpdateLogStore",
                    "log:DeleteLogStore",
                    "log:CreateConfig",
                    "log:UpdateConfig",
                    "log:GetConfig",
                    "log:DeleteConfig",
                    "log:CreateMachineGroup",
                    "log:UpdateMachineGroup",
                    "log:GetMachineGroup",
                    "log:DeleteMachineGroup",
                    "log:ApplyConfigToGroup",
                    "log:GetAppliedMachineGroups",
                    "log:GetAppliedConfigs",
                    "log:RemoveConfigFromMachineGroup",
                    "log:CreateIndex",
                    "log:GetIndex",
                    "log:UpdateIndex",
                    "log:DeleteIndex",
                    "log:CreateSavedSearch",
                    "log:GetSavedSearch",
                    "log:UpdateSavedSearch",
                    "log:DeleteSavedSearch",
                    "log:CreateDashboard",
                    "log:GetDashboard",
                    "log:UpdateDashboard",
                    "log:DeleteDashboard",
                    "log:CreateJob",
                    "log:GetJob",
                    "log:DeleteJob",
                    "log:UpdateJob",
                    "log:PostLogStoreLogs",
                    "log:CreateSortedSubStore",
                    "log:GetSortedSubStore",
                    "log:ListSortedSubStore",
                    "log:UpdateSortedSubStore",
                    "log:DeleteSortedSubStore",
                    "log:CreateApp",
                    "log:UpdateApp",
                    "log:GetApp",
                    "log:DeleteApp",
                    "log:GetLogStoreLogs",
                    "log:TagResources",
                    "log:ListJobs",
                    "log:ListTagResources",
                    "log:UntagResources",
                    "log:CreateResourceRecord",
                    "log:UpdateResourceRecord",
                    "log:UpsertResourceRecord",
                    "log:GetResourceRecord",
                    "log:DeleteResourceRecord",
                    "log:ListResourceRecords",
                    "log:ListResources",
                    "log:GetResource",
                    "cs:UpdateContactGroup",
                    "cs:DescribeTemplates",
                    "cs:DescribeTemplateAttribute",
                    "eventbridge:PutEvents"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }

Worker节点绑定角色权限

专有版集群Worker节点的RAM角色权限收敛后,默认绑定了CSI存储、网络和日志组件所需的最小化权限策略。

  • CSI存储组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "ecs:DescribeDisks",
                    "ecs:DescribeInstances",
                    "ecs:DescribeAvailableResource",
                    "ecs:DescribeInstanceTypes",
                    "nas:DescribeFileSystems",
                    "ecs:AttachDisk",
                    "ecs:CreateDisk",
                    "ecs:CreateSnapshot",
                    "ecs:DeleteSnapshot",
                    "ecs:DetachDisk"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }
  • 网络组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "ecs:CreateNetworkInterface",
                    "ecs:DescribeNetworkInterfaces",
                    "ecs:AttachNetworkInterface",
                    "ecs:DetachNetworkInterface",
                    "ecs:DeleteNetworkInterface",
                    "ecs:DescribeInstanceAttribute",
                    "ecs:DescribeInstanceTypes",
                    "ecs:AssignPrivateIpAddresses",
                    "ecs:UnassignPrivateIpAddresses",
                    "ecs:DescribeInstances",
                    "ecs:ModifyNetworkInterfaceAttribute"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            },
            {
                "Action": [
                    "vpc:DescribeVSwitches"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }
  • 日志组件权限策略内容

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "log:CreateProject",
                    "log:GetProject",
                    "log:DeleteProject",
                    "log:CreateLogStore",
                    "log:GetLogStore",
                    "log:UpdateLogStore",
                    "log:DeleteLogStore",
                    "log:CreateConfig",
                    "log:UpdateConfig",
                    "log:GetConfig",
                    "log:DeleteConfig",
                    "log:CreateMachineGroup",
                    "log:UpdateMachineGroup",
                    "log:GetMachineGroup",
                    "log:DeleteMachineGroup",
                    "log:ApplyConfigToGroup",
                    "log:GetAppliedMachineGroups",
                    "log:GetAppliedConfigs",
                    "log:RemoveConfigFromMachineGroup",
                    "log:CreateIndex",
                    "log:GetIndex",
                    "log:UpdateIndex",
                    "log:DeleteIndex",
                    "log:CreateSavedSearch",
                    "log:GetSavedSearch",
                    "log:UpdateSavedSearch",
                    "log:DeleteSavedSearch",
                    "log:CreateDashboard",
                    "log:GetDashboard",
                    "log:UpdateDashboard",
                    "log:DeleteDashboard",
                    "log:CreateJob",
                    "log:GetJob",
                    "log:DeleteJob",
                    "log:UpdateJob",
                    "log:PostLogStoreLogs",
                    "log:CreateSortedSubStore",
                    "log:GetSortedSubStore",
                    "log:ListSortedSubStore",
                    "log:UpdateSortedSubStore",
                    "log:DeleteSortedSubStore",
                    "log:CreateApp",
                    "log:UpdateApp",
                    "log:GetApp",
                    "log:DeleteApp",
                    "log:GetLogStoreLogs",
                    "log:TagResources",
                    "log:ListJobs",
                    "log:ListTagResources",
                    "log:UntagResources",
                    "log:CreateResourceRecord",
                    "log:UpdateResourceRecord",
                    "log:UpsertResourceRecord",
                    "log:GetResourceRecord",
                    "log:DeleteResourceRecord",
                    "log:ListResourceRecords",
                    "log:ListResources",
                    "log:GetResource",
                    "cs:UpdateContactGroup",
                    "cs:DescribeTemplates",
                    "cs:DescribeTemplateAttribute",
                    "eventbridge:PutEvents"
                ],
                "Resource": [
                    "*"
                ],
                "Effect": "Allow"
            }
        ]
    }
相关文章

【产品公告】关于停止维护CoreDNS v1.6.7及以下版本的公告 2025-04-18 11:44

为了提升服务质量,增强系统的安全性与稳定性,自2025年03月19日起,容器服务 Kubernetes 版对所有v1.6.7及以下版本的CoreDNS 组件将不再进行维护和更新,请您尽快升级组件版本。 变更内容及影响范围 自2025年03月19日起,CoreDNS v1.6.7及以下版本将停止维护,

【产品变更】关于默认关闭ACK集群内新建ECS实例源目的IP检查的公告 2025-04-18 11:44

由于云服务器 ECS 新建实例、网卡默认开启源/目的IP检查会影响使用Terway和Flannel网络插件的集群容器网络连通性,自2025年04月22日0时0分起,ACK将默认关闭集群内新建ECS实例源/目的IP检查。 影响范围 ACK集群的Cloud Controller Manager和T

【产品公告】关于停止维护ACK NodeLocal DNSCache v1.4.0及以下版本的公告 2025-04-18 11:44

为了提升服务质量,增强系统的安全性与稳定性,自2025年02月27日起,容器服务 Kubernetes 版对所有v1.4及以下版本的ACK NodeLocal DNSCache将不再进行维护和更新。

【产品变更】关于ACK Serverless集群对新用户关闭新建入口的公告 2025-04-18 11:44

从2025年02月17日起,阿里云容器服务 Serverless 版将对尚未创建过集群的新用户关闭创建集群的入口。您可以通过

【产品变更】关于ACK控制台调整为按地域维度管理集群的通知 2025-04-18 11:44

为了进一步提高控制台的易用性,容器服务Kubernetes版控制台将于 2025 年 02 月 07 日起调整为按地域维度显示集群列表。 变更时间 自 2025 年 02 月 07 日 10:00:00 起逐步灰度,于 2025 年 02 月 14 日 11:00:00 完成全量灰度。

【产品变更】关于云原生AI套件AI控制台转为白名单开放的公告 2025-04-18 11:44

阿里云提供的云原生AI套件的AI控制台(包括开发控制台、运维控制台)于2025年01月22日起以白名单功能的形式开放。如果您已部署开发控制台或运维控制台,您的使用将不会受到影响。

目录
Copyright © 2025 your company All Rights Reserved. Powered by 博智数字服务平台.
闽ICP备08105208号-1