You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

阿里云跨账号访问:AWS Switch Role等价功能咨询

AliCloud Equivalent to AWS Switch Role (Cross-Account Role-Based Access)

Absolutely! AliCloud has a direct equivalent to AWS's switch role functionality, built right into its Resource Access Management (RAM) service. This lets you grab temporary credentials by assuming a role in another AliCloud account, then use those credentials to create and access resources exactly as that role is permitted.

Key Concepts & Workflow

It maps closely to AWS's model, with these core pieces:

  • RAM Role (Target Account): The role in the destination account that defines the permissions you want to use (just like an AWS IAM cross-account role).
  • Trust Relationship: The target account must explicitly grant your source account (or a specific RAM user/role in it) permission to assume this role.
  • Temporary Credentials: After assuming the role, you get short-lived AccessKeyId, AccessKeySecret, and SecurityToken—similar to AWS STS tokens.

Step-by-Step Implementation

1. Create a Cross-Account RAM Role in the Target Account

First, in the account where you need to access resources:

  • Head to the RAM Console, create a new role, and select "Another AliCloud account" as the trusted entity.
  • Enter the ID of your source account (the one you're starting from).
  • Attach permission policies to this role (e.g., AliECSFullAccess for full ECS control, or custom policies for granular resource access).

2. Allow AssumeRole Access in the Source Account

In your source account:

  • If using a RAM user, attach a policy that lets them call the ram:AssumeRole action for the target role's ARN. Example policy snippet:
    {
        "Version": "1",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": "ram:AssumeRole",
                "Resource": "acs:ram::TARGET_ACCOUNT_ID:role/TARGET_ROLE_NAME"
            }
        ]
    }
    

3. Retrieve Temporary Credentials via STS

Use AliCloud's Security Token Service (STS) via CLI or SDK to assume the role:

  • CLI Command:
    aliyun sts AssumeRole --RoleArn "acs:ram::TARGET_ACCOUNT_ID:role/TARGET_ROLE_NAME" --RoleSessionName "my-cross-account-session"
    
    The response will include a Credentials object with your temporary access keys and security token.

4. Use Temporary Credentials to Manage Resources

You can use these credentials with AliCloud tools immediately:

  • For CLI, set these environment variables:
    export ALIBABA_CLOUD_ACCESS_KEY_ID="TEMP_ACCESS_KEY"
    export ALIBABA_CLOUD_ACCESS_KEY_SECRET="TEMP_SECRET_KEY"
    export ALIBABA_CLOUD_SECURITY_TOKEN="TEMP_SECURITY_TOKEN"
    
    Now commands like aliyun ecs DescribeInstances will run under the assumed role's permissions in the target account.

Quick Notes

  • Temporary credentials expire by default after 1 hour, but you can adjust this up to 12 hours when calling AssumeRole.
  • Role chaining (assuming a role from another assumed role) is also supported, just make sure to set up nested trust relationships correctly.

内容的提问来源于stack exchange,提问作者axon_synapse

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:40:10