跳到主要内容
版本:3.2.16.3

权限策略 Actions 和 Resources

网关组

ActionResourceAPI
gateway:DeleteGatewayGrouparn:api7:gateway:gatewaygroup/%sDELETE /api/gateway_groups/:gateway_group_id
gateway:GetGatewayGrouparn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id
gateway:CreateGatewayGrouparn:api7:gateway:gatewaygroup/*POST /api/gateway_groups
gateway:UpdateGatewayGrouparn:api7:gateway:gatewaygroup/%sPUT /api/gateway_groups/:gateway_group_id
gateway:UpdateGatewayGrouparn:api7:gateway:gatewaygroup/%sPUT /api/gateway_groups/:gateway_group_id/admin_key

网关实例

ActionResourceAPI
gateway:GetGatewayInstancearn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/instances
gateway:GetGatewayInstanceCorearn:api7:gateway:gatewaygroup/*GET /api/instances/cores
gateway:CreateGatewayInstancearn:api7:gateway:gatewaygroup/%sPOST /api/gateway_groups/:gateway_group_id/dp_client_certificates
gateway:CreateGatewayInstancearn:api7:gateway:gatewaygroup/%sPOST /api/gateway_groups/:gateway_group_id/instance_token

消费者

ActionResourceAPI
gateway:GetConsumerarn:api7:gateway:gatewaygroup/%sGET /apisix/admin/consumers
gateway:GetConsumerarn:api7:gateway:gatewaygroup/%sGET /apisix/admin/consumers/:consumer_username
gateway:CreateConsumerarn:api7:gateway:gatewaygroup/%sPOST /apisix/admin/consumers
gateway:UpdateConsumerarn:api7:gateway:gatewaygroup/%sPATCH /apisix/admin/consumers/:consumer_username
gateway:UpdateConsumerarn:api7:gateway:gatewaygroup/%sPUT /apisix/admin/consumers/:consumer_username
gateway:DeleteConsumerarn:api7:gateway:gatewaygroup/%sDELETE /apisix/admin/consumers/:consumer_username

SSL 证书

ActionResourceAPI
gateway:GetSSLCertificatearn:api7:gateway:gatewaygroup/%sGET /apisix/admin/ssls
gateway:GetSSLCertificatearn:api7:gateway:gatewaygroup/%sGET /apisix/admin/ssls/:ssl_id
gateway:CreateSSLCertificatearn:api7:gateway:gatewaygroup/%sPOST /apisix/admin/ssls
gateway:UpdateSSLCertificatearn:api7:gateway:gatewaygroup/%sPUT /apisix/admin/ssls/:ssl_id
gateway:DeleteSSLCertificatearn:api7:gateway:gatewaygroup/%sDELETE /apisix/admin/ssls/:ssl_id

插件全局规则

ActionResourceAPI
gateway:GetGlobalPluginRulearn:api7:gateway:gatewaygroup/%sGET /apisix/admin/global_rules
gateway:GetGlobalPluginRulearn:api7:gateway:gatewaygroup/%sGET /apisix/admin/global_rules/:global_rule_id
gateway:CreateGlobalPluginRulearn:api7:gateway:gatewaygroup/%sPOST /apisix/admin/global_rules
gateway:UpdateGlobalPluginRulearn:api7:gateway:gatewaygroup/%sPUT /apisix/admin/global_rules/:global_rule_id
gateway:DeleteGlobalPluginRulearn:api7:gateway:gatewaygroup/%sDELETE /apisix/admin/global_rules/:global_rule_id

插件元数据

ActionResourceAPI
gateway:GetPluginMetadataarn:api7:gateway:gatewaygroup/%sGET /apisix/admin/plugin_metadata
gateway:GetPluginMetadataarn:api7:gateway:gatewaygroup/%sGET /apisix/admin/plugin_metadata/:plugin_name
gateway:UpdatePluginMetadataarn:api7:gateway:gatewaygroup/%sPUT /apisix/admin/plugin_metadata/:plugin_name
gateway:DeletePluginMetadataarn:api7:gateway:gatewaygroup/%sDELETE /apisix/admin/plugin_metadata/:plugin_name

密钥

ActionResourceAPI
gateway:GetSecretarn:api7:gateway:gatewaygroup/%sGET /apisix/admin/secrets
gateway:GetSecretarn:api7:gateway:gatewaygroup/%sGET /apisix/admin/secrets/:secret_manager/:secret_id
gateway:PutSecretarn:api7:gateway:gatewaygroup/%sPUT /apisix/admin/secrets/:secret_manager/:secret_id
gateway:DeleteSecretarn:api7:gateway:gatewaygroup/%sDELETE /apisix/admin/secrets/:secret_manager/:secret_id

服务注册中心

ActionResourceAPI
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/connected_services
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/health_check_history
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/kubernetes/internal_services
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/nacos/namespaces
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/nacos/namespaces/:nacos_namespace/groups
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/nacos/namespaces/:nacos_namespace/groups/:nacos_group/services
gateway:GetServiceRegistryarn:api7:gateway:gatewaygroup/%sGET /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id/nacos/namespaces/:nacos_namespace/groups/:nacos_group/services/:nacos_service/instances_metadata
gateway:ConnectServiceRegistryarn:api7:gateway:gatewaygroup/%sPOST /api/gateway_groups/:gateway_group_id/service_registries
gateway:UpdateServiceRegistryarn:api7:gateway:gatewaygroup/%sPUT /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id
gateway:DisconnectServiceRegistryarn:api7:gateway:gatewaygroup/%sDELETE /api/gateway_groups/:gateway_group_id/service_registries/:service_registry_id

服务中心(模板)

ActionResourceAPI
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/routes/template/:route_id
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/service_versions/:service_version_id
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/service_versions/:service_version_id/routes
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/service_versions/:service_version_id/routes/:route_version_id
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/service_versions/:service_version_id/stream_routes
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/service_versions/:service_version_id/stream_routes/:stream_route_version_id
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/services/:service_id/versions/:version
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/services/template/:service_id
gateway:GetServiceTemplatearn:api7:gateway:servicetemplate/%sGET /api/stream_routes/template/:stream_route_id
gateway:CreateServiceTemplatearn:api7:gateway:servicetemplate/*POST /api/import/services/template
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPUT /api/services/template/:service_id
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPATCH /api/services/template/:service_id
gateway:DeleteServiceTemplatearn:api7:gateway:servicetemplate/%sDELETE /api/services/template/:service_id
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPOST /api/routes/template
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPATCH /api/routes/template/:route_id
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPUT /api/routes/template/:route_id
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sDELETE /api/routes/template/:route_id
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPOST /api/stream_routes/template
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sPUT /api/stream_routes/template/:stream_route_id
gateway:UpdateServiceTemplatearn:api7:gateway:servicetemplate/%sDELETE /api/stream_routes/template/:stream_route_id

已发布服务

ActionResourceAPI
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /api/gateway_groups/:gateway_group_id/services/:service_version_service_id
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /api/gateway_groups/:gateway_group_id/services/:service_version_service_id/healthcheck
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /api/gateway_groups/:gateway_group_id/services/:service_version_service_id/runtime_configuration
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /api/gateway_groups/:gateway_group_id/services/:service_version_service_id/versions
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /apisix/admin/routes/:apisix_route_id
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /apisix/admin/services/:apisix_service_id
gateway:GetPublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sGET /apisix/admin/stream_routes/:apisix_stream_route_id
gateway:PublishServicesarn:api7:gateway:gatewaygroup/%s/publishedservice/*POST /api/services/publish
gateway:CreatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sPOST /apisix/admin/services
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sPATCH /apisix/admin/services/:apisix_service_id
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sPUT /apisix/admin/services/:apisix_service_id
gateway:DeletePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sDELETE /apisix/admin/services/:apisix_service_id
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sPUT /apisix/admin/routes/:apisix_route_id
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sPATCH /apisix/admin/routes/:apisix_route_id
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sDELETE /apisix/admin/routes/:apisix_route_id
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sPUT /apisix/admin/stream_routes/:apisix_stream_route_id
gateway:UpdatePublishedServicearn:api7:gateway:gatewaygroup/%s/publishedservice/%sDELETE /apisix/admin/stream_routes/:apisix_stream_route_id

部署设置

ActionResourceAPI
gateway:GetDeploymentSettingarn:api7:gateway:gatewaysetting/*GET /api/system_settings
gateway:UpdateDeploymentSettingarn:api7:gateway:gatewaysetting/*PUT /api/system_settings

自定义插件

ActionResourceAPI
gateway:GetCustomPluginarn:api7:gateway:gatewaysetting/*GET /api/custom_plugins
gateway:GetCustomPluginarn:api7:gateway:gatewaysetting/*GET /api/custom_plugins/:custom_plugin_id
gateway:CreateCustomPluginarn:api7:gateway:gatewaysetting/*POST /api/custom_plugins
gateway:UpdateCustomPluginarn:api7:gateway:gatewaysetting/*PUT /api/custom_plugins/:custom_plugin_id
gateway:DeleteCustomPluginarn:api7:gateway:gatewaysetting/*DELETE /api/custom_plugins/:custom_plugin_id

告警

ActionResourceAPI
gateway:GetAlertPolicyarn:api7:gateway:alert/*GET /api/alert/policies
gateway:GetAlertPolicyarn:api7:gateway:alert/*GET /api/alert/policies/:alert_policy_id
gateway:GetAlertPolicyarn:api7:gateway:alert/*GET /api/alert/policies/histories
gateway:CreateAlertPolicyarn:api7:gateway:alert/*POST /api/alert/policies
gateway:UpdateAlertPolicyarn:api7:gateway:alert/*PUT /api/alert/policies/:alert_policy_id
gateway:UpdateAlertPolicyarn:api7:gateway:alert/*PUT /api/alert/policies/:alert_policy_id/triggers
gateway:UpdateAlertPolicyarn:api7:gateway:alert/*PATCH /api/alert/policies/:alert_policy_id
gateway:DeleteAlertPolicyarn:api7:gateway:alert/*DELETE /api/alert/policies/:alert_policy_id
gateway:GetWebhookTemplatearn:api7:gateway:alert/*GET /api/alert/webhook_templates/:webhook_template_id
gateway:GetWebhookTemplatearn:api7:gateway:alert/*GET /api/alert/webhook_templates/:webhook_template_id/refer
gateway:CreateWebhookTemplatearn:api7:gateway:alert/*POST /api/alert/webhook_templates
gateway:UpdateWebhookTemplatearn:api7:gateway:alert/*PUT /api/alert/webhook_templates/:webhook_template_id
gateway:DeleteWebhookTemplatearn:api7:gateway:alert/*DELETE /api/alert/webhook_templates/:webhook_template_id

权限策略

ActionResourceAPI
iam:GetPermissionPolicyarn:api7:iam:permissionpolicy/%sGET /api/permission_policies/:permission_policy_id
iam:CreatePermissionPolicyarn:api7:iam:permissionpolicy/*POST /api/permission_policies
iam:UpdatePermissionPolicyarn:api7:iam:permissionpolicy/%sPUT /api/permission_policies/:permission_policy_id
iam:DeletePermissionPolicyarn:api7:iam:permissionpolicy/%sDELETE /api/permission_policies/:permission_policy_id

角色

ActionResourceAPI
iam:GetRolearn:api7:iam:role/%sGET /api/roles/:role_id
iam:GetRolearn:api7:iam:role/%sGET /api/roles/:role_id/permission_policies
iam:CreateCustomRolearn:api7:iam:role/*POST /api/roles
iam:UpdateCustomRolearn:api7:iam:role/%sPOST /api/roles/:role_id/attach_permission_policies
iam:UpdateCustomRolearn:api7:iam:role/%sPOST /api/roles/:role_id/detach_permission_policies
iam:UpdateCustomRolearn:api7:iam:role/%sPUT /api/roles/:role_id
iam:DeleteCustomRolearn:api7:iam:role/%sDELETE /api/roles/:role_id

用户

ActionResourceAPI
iam:GetUserarn:api7:iam:user/%sGET /api/users/:user_id
iam:InviteUserarn:api7:iam:user/*POST /api/invites
iam:UpdateUserRolearn:api7:iam:user/%sPUT /api/users/:user_id/assigned_roles
iam:ResetPasswordarn:api7:iam:user/%sPUT /api/users/:user_id/password_reset
iam:DeleteUserarn:api7:iam:user/%sDELETE /api/users/:user_id

证书

ActionResourceAPI
iam:UpdateLicensearn:api7:iam:organization/*PUT /api/license

审计

ActionResourceAPI
iam:GetAuditarn:api7:iam:organization/*GET /api/audit_logs
iam:ExportAuditsarn:api7:iam:organization/*GET /api/audit_logs/export

设置

ActionResourceAPI
iam:GetSCIMProvisioningarn:api7:iam:organization/*GET /api/system_settings/scim
iam:UpdateSCIMProvisioningarn:api7:iam:organization/*PUT /api/system_settings/scim
iam:UpdateSCIMProvisioningarn:api7:iam:organization/*PUT /api/system_settings/scim/token
iam:GetLoginOptionarn:api7:iam:organization/*GET /api/login_options/:login_option_id
iam:CreateLoginOptionarn:api7:iam:organization/*POST /api/login_options
iam:UpdateLoginOptionarn:api7:iam:organization/*PUT /api/login_options/:login_option_id
iam:UpdateLoginOptionarn:api7:iam:organization/*PATCH /api/login_options/:login_option_id
iam:DeleteLoginOptionarn:api7:iam:organization/*DELETE /api/login_options/:login_option_id