View a markdown version of this page

将服务相关角色用于 Amazon Web Services Support 计划 - Amazon Web Services Support
Amazon Web Services 文档中描述的 Amazon Web Services 服务或功能可能因区域而异。要查看适用于中国区域的差异,请参阅 中国的 Amazon Web Services 服务入门 (PDF)

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

将服务相关角色用于 Amazon Web Services Support 计划

Amazon Web Services Support 计划使用 Amazon Identity and Access Management (IAM) 服务相关角色来读取和更新用于代表您管理账户支持计划的 Amazon 资源。

AWSServiceRoleForSupportPlans服务相关角色是一种独特的 IAM 角色,直接与支持计划相关联。此服务相关角色是预定义的,它包括支持计划代表您拨打其他 Amazon 服务所需的权限。

AWSServiceRoleForSupportPlans 服务关联角色信任 supportplans.amazonaws.com 服务来代入角色。

Service-linked 的角色权限 Amazon Web Services Support 计划

此角色使用AWSSupportPlansServiceRolePolicy Amazon 托管策略。此托管策略已附加到角色,并授予角色代表您完成操作的权限。

该角色的权限政策允许支持计划代表您执行以下操作:

  • organizations:ListAccounts

  • supportplans:AcceptSupportAgreement

  • supportplans:CancelSupportAgreement

  • supportplans:CreateSupportAgreement

  • supportplans:GetSupportAgreement

  • supportplans:ListSupportAgreementRevisions

  • supportplans:ListSupportAgreements

  • supportplans:RejectSupportAgreement

  • supportplans:StartSupportPlanUpdate

  • supportplans:UpdateSupportAgreement

有关允许的操作的更多信息,请参阅 IAM 控制台中的AWSSupportPlansServiceRolePolicy策略。

为 创建服务相关角色 Amazon Web Services Support 计划

您无需手动创建 AWSServiceRoleForSupportPlans 角色。当您通过中的支持计划管理页面创建支持计划时 Amazon Web Services 管理控制台,支持计划会自动为您创建此角色。

注意

如果您需要手动创建此角色,则可以使用 IAM 控制台或 IAM API。 Amazon CLI有关更多信息,请参阅 IAM 用户指南 中的创建服务相关角色

为 编辑服务相关角色 Amazon Web Services Support 计划

您可以使用 IAM 编辑 AWSServiceRoleForSupportPlans 服务关联角色的描述。您无法编辑信任策略或权限策略,也无法向该角色附加其他策略。有关更多信息,请参阅《IAM 用户指南》中的编辑服务相关角色

删除 的服务相关角色 Amazon Web Services Support 计划

支持计划不会代表您删除AWSServiceRoleForSupportPlans服务相关角色。如果您想删除此角色,则必须先取消有效的支持计划。为此,请联系 Amazon Web Services Support。 Amazon Web Services Support 确认取消后,您可以使用 IAM 控制台或 IAM API 删除该角色。 Amazon CLI有关更多信息,请参阅《IAM 用户指南》中的删除服务关联角色