CAMの概要
製品機能
適用シーン
基本概念
使用制限
ユーザータイプ

{ } [ ] " , :
= < > ( ) |
[<resource_string>, < resource_string>, ...]<principal_map> = { <principal_map_entry>, <principal_map_entry>, ... }
"resource": [<resource_string>]"resource": <resource_string>
<condition_block?>
("allow" | "deny")
<version_block> = "version" : "2.0"
policy = {<version_block><principal_block?>,<statement_block>}<version_block> = "version" : "2.0"<statement_block> = "statement" : [ <statement>, <statement>, ... ]<statement> = {<effect_block>,<action_block>,<resource_block>,<condition_block?>}<effect_block> = "effect" : ("allow" | "deny")<principal_block> = "principal": ("*" | <principal_map>)<principal_map> = { <principal_map_entry>, <principal_map_entry>, ... }<principal_map_entry> = "qcs":[<principal_id_string>, <principal_id_string>, ...]<action_block> = "action":("*" | [<action_string>, <action_string>, ...])<resource_block> = "resource":("*" | [<resource_string>, <resource_string>, ...])<condition_block> = "condition" : { <condition_map> }<condition_map> {<condition_type_string> : { <condition_key_string> : <condition_value_list> },<condition_type_string> : { <condition_key_string> : <condition_value_list> }, ...}<condition_value_list> = [<condition_value>, <condition_value>, ...]<condition_value> = ("string" | "number")
//すべての製品のすべての操作"action":"*""action":"*:*"// COS製品のすべての操作"action":"cos:*"// COS製品のGetBucketPolicyという操作"action":"cos:GetBucketPolicy"// COS製品のBucketに部分一致する操作"action":"cos:*Bucket*"// cos製品のGetBucketPolicy、PutBucketPolicy、DeleteBucketPolicyという操作リスト"action":["cos:GetBucketPolicy","cos:PutBucketPolicy","cos: DeleteBucketPolicy"]
qcs: project :serviceType:region:account:resource
// COS製品のオブジェクトリソース、上海リージョン、リソース所有者のuidは10001234、リソース名はbucket1/object2qcs::cos:sh:uid/10001234:prefix//10001234/bucket1/object2// CMQ製品のキュー、上海リージョン、リソース所有者のuinは12345678、リソース名は12345678/queueName1、リソースプレフィックスはqueueNameqcs::cmqqueue:sh:uin/12345678:queueName/12345678/queueName1// Cloud Virtual Machine (CVM)製品のクラウドサーバー、上海リージョン、リソース所有者のuinは12345678、リソース名はins-abcdefg、リソースプレフィックスはinstanceqcs::cvm:sh:uin/12345678:instance/ins-abcdefg
"condition":{"string_equal":{"cvm:region":["sh","gz"]},"ip_equal":{"qcs:ip":"10.131.12.12/24"}}
"principal": {"qcs":["qcs::cam::uin/1238423:uin/3232","qcs::cam::uin/1238423:groupid/13"]}
フィードバック