Skip to main content
Version: v0.14.0

权限

为了正常使用 ack-ram-tool,您需要为使用改工具的阿里云 RAM 用户或 RAM 角色授予所需的 RAM 权限和 RBAC 权限。 各个子命令所需的最小权限信息如下表所示:

子命令RAM 权限RBAC 权限
rrsa statuscs:DescribeClusterDetail
rrsa enablecs:DescribeClusterDetail
cs:ModifyCluster
cs:DescribeClusterLogs
rrsa associate-rolecs:DescribeClusterDetail
ram:GetRole
ram:CreateRole
ram:UpdateRole
rrsa install-helper-addoncs:DescribeClusterDetail
cs:DescribeClusterAddonsVersion
cs:InstallClusterAddons
rrsa assumerole
rrsa disablecs:DescribeClusterDetail
cs:ModifyCluster
cs:DescribeClusterLogs
rrsa setup-addoncs:DescribeClusterDetail
ram:GetRole
ram:CreateRole
ram:UpdateRole
ram:CreatePolicy
ram:ListPoliciesForRole
ram:AttachPolicyToRole
rrsa demo
credential-plugin get-kubeconfigcs:DescribeClusterUserKubeconfig
credential-plugin get-credentialcs:DescribeClusterUserKubeconfig
credential-plugin get-token
export-credentials