You need to enable JavaScript to run this app.
IAM

IAM

Copy page
Download PDF
Policy Grammar
Logical non-syntax (NotAction, etc.)
Copy page
Download PDF
Logical non-syntax (NotAction, etc.)

grammar description

You can use logical nonsyntax when defining an action or resource to express "exclusion" semantics for some actions or resources. The specific keywords are as follows:

  • **NotAction: **Define the scope of the action to be excluded, which must be used with the Action , meaning that it contains the actions defined in the Action but excludes the actions defined in the NotAction .
  • **NotResource: **Define the scope of resources to be excluded and must be used with NotResource , meaning that it contains resources defined in Resource but excludes resources defined in NotResource .

For example, the following policy includes permissions to the Cloud as a Service except for the private network:

{ 
  "Statement": [ 
    { 
      "Effect": "Allow", 
      "Action": [ 
        "*" 
      ], 
      "NotAction":[ 
        "vpc:*" 
      ], 
      "Resource": [ 
        "*" 
      ] 
    } 
  ] 
}

The following policies contain permissions to operate on all VPC resources except the private network vpc-bp15zckdt37pq72zv**** :

{ 
  "Statement": [ 
    { 
      "Effect": "Allow", 
      "Action": [ 
        "vpc:*" 
      ], 
      "Resource": [ 
        "*" 
      ], 
      "NotResource": [ 
        "trn:vpc:cn-beijing:2000001234:vpc/vpc-bp15zckdt37pq72zv****" 
      ] 
    } 
  ] 
}

Cloud as a Service with NotAction and NotResource support

At present, only some Cloud as a Service support NotAction and NotResource syntax. For Cloud as a Service that is not supported, you cannot use NotAction or NotResource keywords in policies. Here is a list of supported services:

Product classificationProduct Name (Volcano Engine)ServiceCodeSupport NotAction/NotResource
calculateCloud as a ServiceecsNot supported
calculateelastic stretchingauto_scalingsupport
calculateveLinuxvelinuxsupport
calculateServer Migration Centersmcsupport
networkprivate networkvpcsupport
networkPublic IPvpcsupport
networkNAT gatewaynatgatewaysupport
networkCloud enterprise networkcensupport
networkTransit routertransitroutersupport
networkload balanceclbsupport
networkApplication Load Balanceralbsupport
networkNAT64 gatewaynat64gatewaysupport
networkprivate line connectiondirectconnectsupport
networkVPN connectionvpnsupport
networkprivate network connectionprivatelinksupport
networkcross-domain bandwidth packetcrbsupport
networkAnycast Elastic Public IPanycasteipsupport
networkInternet Expressfasttracksupport
storageobject storagetosNot supported
storagelog serviceTLSNot supported
storageElastic Block Storestorage_ebssupport
storageFile Storage NASFileNASsupport
storageFile storage vePFSvepfssupport
storageBig data file storagecfsNot supported
storageStorage Migration Servicedmssupport
storagedata flash servicedessupport
databaseCloud Database MySQL Editionrds_mysqlsupport
databaseCloud Database PostgreSQL Editionrds_postgresqlsupport
databaseCloud Database RDS SQL Server Editionrds_mssqlsupport
databaseCloud database veDB MySQL editionvedbmsupport
databaseCloud Database MySQL Sharding Editionmysql_shardingsupport
databaseCloud Database NewSQL MySQL Editionndbsupport
databaseCache Database Redis EditionRedissupport
databaseDocument Database MongoDB Editionmongodbsupport
databaseTable Database HBase Editionhbasesupport
databasegraph database veGraphgraphsupport
databaseTime series database InfluxDBinfluxdbNot supported
databaseConfiguration Centerconfigcentersupport
databaseDatabase Transfer Servicedtssupport
databaseDatabase Workbenchdbwsupport
Containers and Middlewarecontainer servicevkesupport
Containers and Middlewaremirror warehousecrNot supported
Containers and MiddlewareMessage queue Kafka versionKafkasupport
Containers and MiddlewareMessage queue RocketMQ versionRocketMQsupport
Containers and MiddlewareMessage queue RabbitMQ versionRabbitMQsupport
Containers and MiddlewareCloud monitoringVolc_Observesupport
Containers and Middlewareapplication observability serviceaossupport
Containers and MiddlewareApplication Performance Monitor Full Link Editionapmplus_apiNot supported
apmplus_serverNot supported
Containers and MiddlewareHosting PrometheusvmpNot supported
Containers and Middlewarefunction servicevefaassupport
Containers and MiddlewareMicroservice Enginemsesupport
Containers and MiddlewareAPI Gatewayapigsupport
Containers and MiddlewareApplied toughness enhancementaressupport
Containers and MiddlewareService Meshamssupport
Containers and MiddlewareCloud search serviceESCloudsupport
Containers and MiddlewareInternet of Things PlatformiotNot supported
Containers and Middlewaredistributed cloud native platformdcpsupport
Containers and MiddlewareSimple Queue Servicesqssupport
Containers and Middlewarecloud automated testingcloud_detectsupport
Containers and MiddlewareCloud Native SpendSmartfinopssupport
Containers and Middlewarecloud native messaging enginebmqsupport
Containers and Middlewareproduct warehouseartifactsNot supported
Containers and MiddlewareContinuous DeliverycpNot supported
Containers and Middlewarecode hosting veCodevecodesupport
Big DataStream computing Flinkflinksupport
Big DataE-MapReduceemrsupport
Big DataLake and warehouse integrated analysis service LASlasNot supported
Big DataBig Data R & D Governance Suitedataleapsupport
Big DataE-MapReduce(EMR) Serverlessemr_serverlessNot supported
Big DataBatch Computing Spark Editionsparksupport
Big DataE-MapReduce OLAPemr_olapsupport
Big DataGrowth Marketing PlatformgmpNot supported
Big Datagrowth analysisubaNot supported
Big DataA/B Testingab_testNot supported
Big DataByteHousebytehouseNot supported
Big DataByteHouse Enterprise Editionbytehouse_ceNot supported
Big DataGlobal Data Transmission ServicedatasailNot supported
Big DataDatawinddatawindNot supported
Big DataCustomer Data Platformcdp_saasNot supported
Big Datadata elementsdata_tob_rtaNot supported
data_tobNot supported
CDN and the EdgeInformation delivery networkCDNNot supported
CDN and the EdgeEdge Computing Nodeveen_edgesupport
veenedgesupport
CDN and the Edgesite-wide accelerationdcdnNot supported
CDN and the EdgeGlobal accelerationgasupport
CDN and the Edgeedge containerveecp_openapisupport
CDN and the EdgeEdge Intelligencevei_apisupport
CDN and the EdgeEdge rendering farmverendersupport
CDN and the Edgemarginal functionveefapisupport
CDN and the EdgeVideo Networkaiotvideosupport
CDN and the EdgeBusiness Servicesindustry_commercesupport
CDN and the Edgeedge accessedxsupport
CDN and the Edgeedge containerveeccsupport
CDN and the EdgeEdge Access Gatewayeagsupport
CDN and the EdgeGame Network Acceleration (GNA)gnasupport
CDN and the EdgeMulti-cloud CDNmcdnNot supported
Artificial intelligence and algorithmsVolcano Arkarksupport
Artificial intelligence and algorithmsIntelligent Vision Servicecvsupport
cv_consolesupport
Artificial intelligence and algorithmsMachine learning platformml_platformNot supported
Artificial intelligence and algorithmsmachine translationtranslateNot supported
Artificial intelligence and algorithmsnatural language processingnlp_consolesupport
nlp_gatewaysupport
Artificial intelligence and algorithmsVoice Technologyspeech_saas_prodsupport
Artificial intelligence and algorithmsWisdom Listeningighsupport
Artificial intelligence and algorithmscontent customizationcontent_customizationsupport
volc_torchlight_apisupport
contentsupport
Artificial intelligence and algorithmsMatrix ButlerCreativeManagementPlatformsupport
Artificial intelligence and algorithmsAudio Intelligencesamisupport
Artificial intelligence and algorithmsInternational Translation Platformi18n_consolesupport
Artificial intelligence and algorithmsPara Cloud Platformparasupport
Artificial intelligence and algorithmsIntelligent outbound callbytebotNot supported
Artificial intelligence and algorithmsIntelligent Creation Cloudic_iamNot supported
Artificial intelligence and algorithmsAudio Content Creation Platformaccpsupport
Artificial intelligence and algorithmsContent Management Platformmpsupport
tcssupport
volc_content_platformsupport
Artificial intelligence and algorithmsIntelligent Video Analytics PlatformivaNot supported
Artificial intelligence and algorithmsLarge model platform maasml_maasNot supported
Artificial intelligence and algorithmsContent Insights Platforminsightsupport
Artificial intelligence and algorithmsmangamodelweb_apisupport
Artificial intelligence and algorithmsIntelligent driving dataadvc_datasupport
Artificial intelligence and algorithmsSmart vlogvlogsupport
Artificial intelligence and algorithmsIntelligent advertising marketing platformiadNot supported
Artificial intelligence and algorithmsSmart Recommendation PlatformairNot supported
Artificial intelligence and algorithmsOmniverseovesupport
Video Cloudlive videoliveNot supported
Video CloudVideo-On-DemandvodNot supported
Video CloudimagexImageXsupport
Video CloudLive audio & videortcNot supported
Video CloudIntelligent processingimpsupport
Video CloudEnterprise live broadcastlivesaasNot supported
Video CloudCloud phoneACEPsupport
Video CloudWTNwtnsupport
Video CloudCloud phone ipaasipaassupport
Video CloudCube proprietary computing platformcubesupport
Video Cloudcloud editingeditsupport
Video CloudCloud gamingvegamesupport
safetyCloud bastion hostingvbhsupport
safetyCloud Security Centerseccentersupport
safetyDDoS High DefenseAdvDefencesupport
safetyDDoS Basic ProtectionDDoSsupport
safetyDDoS native protectionorigin_defencesupport
safetyWeb Application Firewallwafsupport
safetyAdvanced Cyber Threat Detection Systemntasupport
safetyCloud Firewallfw_centersupport
safetyKey Management SystemkmsNot supported
safetyCloud encryption machinehsmsupport
safetyManaged Security Servicessec_managedsupport
safetybusiness risk identificationBusinessSecuritysupport
safetyAttack Surface Management SaaS Editionasmsupport
safetyMulti-cloud security management platformmcssupport
safetyCloud Security Centercspcsupport
safetyMobile game anti-pluggame_protectsupport
safetyAdvance Anti-DDoS Protection Globaladvantiddos_globalsupport
safetyOnline game anti-pull personAdBlockersupport
safetySealSuitecorplinksupport
Enterprise ApplicationCloud communication, SMS servicevolcSMSsupport
Enterprise ApplicationCloud communication, voice servicesvmssupport
Enterprise ApplicationDomain Name Servicedomain_servicesupport
Enterprise ApplicationPublic Resolving PublicDNSpublic_dnssupport
Enterprise ApplicationCloud resolution DNSdnssupport
Enterprise ApplicationGlobal Traffic Managementgtmsupport
Enterprise ApplicationPrivate Network Analysis PrivateZoneprivate_zonesupport
Enterprise ApplicationSSL certificatecertificate_servicesupport
Enterprise ApplicationBio-OSbioNot supported
Enterprise ApplicationEdge Cloud Trademark Servicetrademarksupport
Enterprise ApplicationMobile Parsing HTTPDNShttpdnssupport
Enterprise ApplicationPrivate CApcasupport
Management and Governanceaccess controliamNot supported
Management and Governanceenterprise organizationorganizationsupport
Management and Governanceexpense centerbill_volcano_engineNot supported
Management and Governancebillsupport
Management and Governancebillingsupport
Management and Governancevolc_contract_processsupport
Management and Governancequotaquotasupport
Management and Governancelabeltagsupport
Management and GovernanceResource Centerresourcecentersupport
Management and Governanceresource sharingresource_sharesupport
Management and GovernanceCloud Auditcloud_trailsupport
Management and Governancesecurity certificate servicestssupport
Management and GovernanceCorporate Identity Centercloudidentitysupport
Management and GovernanceNews Centerconsolemessagesupport
Management and GovernanceAccount serviceaccountsupport
Management and Governancereal-name authentication serviceaccount_verifysupport
Management and GovernanceNews Centercloud_message_volcsupport
Management and Governanceticketticketsupport
Management and GovernancerecordbeianNot supported
Management and Governanceapplication servicebafsupport
Management and Governancepartner consolepartnerNot supported
Management and GovernanceCloud Marketmarketplacesupport
Management and GovernanceCloud Marketmarketplace_partnerNot supported
Last updated: 2025.06.23 19:21:30